logo

Breaking the Input: Sandbox Escape Hits libinput, Exposing Leading Linux Desktops

ID: e4e6303d-a81f-5dc8-9263-0abc58a9404c

STIX ID: report--e4e6303d-a81f-5dc8-9263-0abc58a9404c

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-04-03

Date Updated: 2026-04-23

Author: Ddos

...
...

Two vulnerabilities in libinput were disclosed: CVE-2026-35093 is a critical sandbox bypass in the Lua plugin loader (CVSS 8.8) that can load precompiled bytecode and evade sandbox restrictions, and CVE-2026-35094 is a Use-After-Free (CVSS 3.3) that may leak memory. Affected versions include libinput 1.31.0 and 1.30.0–1.30.2; impacted compositors include GNOME 50’s mutter, KWin (git), and Niri (git), with Fedora 43/44 explicitly called out. Patches are available (libinput 1.31.1 and 1.30.3) and users/operators are advised to update and audit root-privileged utilities using libinput.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.