High severity7.4NVD Advisory· Published Jun 4, 2026· Updated Jun 5, 2026
CVE-2026-50292
CVE-2026-50292
Description
In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitrary root code execution
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
18- osv-coords16 versionspkg:rpm/almalinux/libinputpkg:rpm/almalinux/libinput-develpkg:rpm/almalinux/libinput-utilspkg:rpm/suse/libinput&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOSpkg:rpm/suse/libinput&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSSpkg:rpm/suse/libinput&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-ESPOSpkg:rpm/suse/libinput&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-LTSSpkg:rpm/suse/libinput&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP7pkg:rpm/suse/libinput&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSSpkg:rpm/suse/libinput&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP5-LTSSpkg:rpm/suse/libinput&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP6-LTSSpkg:rpm/suse/libinput&distro=SUSE%20Linux%20Enterprise%20Server%2016.0pkg:rpm/suse/libinput&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4pkg:rpm/suse/libinput&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP5pkg:rpm/suse/libinput&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP6pkg:rpm/suse/libinput&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0
< 1.30.1-2.el10_2+ 15 more
- (no CPE)range: < 1.30.1-2.el10_2
- (no CPE)range: < 1.30.1-2.el10_2
- (no CPE)range: < 1.30.1-2.el10_2
- (no CPE)range: < 1.19.4-150400.3.3.1
- (no CPE)range: < 1.19.4-150400.3.3.1
- (no CPE)range: < 1.21.0-150500.3.3.1
- (no CPE)range: < 1.21.0-150500.3.3.1
- (no CPE)range: < 1.27.1-150700.3.3.1
- (no CPE)range: < 1.19.4-150400.3.3.1
- (no CPE)range: < 1.21.0-150500.3.3.1
- (no CPE)range: < 1.25.0-150600.3.3.1
- (no CPE)range: < 1.28.1-160000.3.1
- (no CPE)range: < 1.19.4-150400.3.3.1
- (no CPE)range: < 1.21.0-150500.3.3.1
- (no CPE)range: < 1.25.0-150600.3.3.1
- (no CPE)range: < 1.28.1-160000.3.1
Patches
Vulnerability mechanics
References
2- gitlab.freedesktop.org/libinput/libinput/-/commit/76f0d8a7f57e2868882864b4611281f12f704b55nvdPatch
- www.openwall.com/lists/oss-security/2026/06/04/5nvdMailing ListPatchThird Party Advisory
News mentions
1- Patch Tuesday - June 2026Rapid7 Blog · Jun 9, 2026