Breaking the Input: Sandbox Escape Hits libinput, Exposing Leading Linux Desktops
ID: e4e6303d-a81f-5dc8-9263-0abc58a9404c
STIX ID: report--e4e6303d-a81f-5dc8-9263-0abc58a9404c
Feed Name: securityonline.info
Two vulnerabilities in libinput were disclosed: CVE-2026-35093 is a critical sandbox bypass in the Lua plugin loader (CVSS 8.8) that can load precompiled bytecode and evade sandbox restrictions, and CVE-2026-35094 is a Use-After-Free (CVSS 3.3) that may leak memory. Affected versions include libinput 1.31.0 and 1.30.0–1.30.2; impacted compositors include GNOME 50’s mutter, KWin (git), and Niri (git), with Fedora 43/44 explicitly called out. Patches are available (libinput 1.31.1 and 1.30.3) and users/operators are advised to update and audit root-privileged utilities using libinput.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
