Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-35094

Опубликовано: 01 апр. 2026
Источник: debian

Описание

A flaw was found in libinput. An attacker capable of deploying a Lua plugin file in specific system directories can exploit a dangling pointer vulnerability. This occurs when a garbage collection cleanup function is called, leaving a pointer that can then be printed to system logs. This could potentially expose sensitive data if the memory location is re-used, leading to information disclosure. For this exploit to work, Lua plugins must be enabled in libinput and loaded by the compositor.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libinputfixed1.31.1-1package
libinputnot-affectedtrixiepackage
libinputnot-affectedbookwormpackage
libinputnot-affectedbullseyepackage

Примечания

  • https://gitlab.freedesktop.org/libinput/libinput/-/work_items/1272

  • Fixed by: https://gitlab.freedesktop.org/libinput/libinput/-/commit/45506c7b3c8acbe36008975a2ae30d2c1eaf782f (1.31.1)

  • Fixed by: https://gitlab.freedesktop.org/libinput/libinput/-/commit/af041ea9ed725482e831fa1f6e33cbeb98fcc54f (1.30.3)

Связанные уязвимости

CVSS3: 3.3
ubuntu
4 месяца назад

A flaw was found in libinput. An attacker capable of deploying a Lua plugin file in specific system directories can exploit a dangling pointer vulnerability. This occurs when a garbage collection cleanup function is called, leaving a pointer that can then be printed to system logs. This could potentially expose sensitive data if the memory location is re-used, leading to information disclosure. For this exploit to work, Lua plugins must be enabled in libinput and loaded by the compositor.

CVSS3: 3.3
redhat
4 месяца назад

A flaw was found in libinput. An attacker capable of deploying a Lua plugin file in specific system directories can exploit a dangling pointer vulnerability. This occurs when a garbage collection cleanup function is called, leaving a pointer that can then be printed to system logs. This could potentially expose sensitive data if the memory location is re-used, leading to information disclosure. For this exploit to work, Lua plugins must be enabled in libinput and loaded by the compositor.

CVSS3: 3.3
nvd
4 месяца назад

A flaw was found in libinput. An attacker capable of deploying a Lua plugin file in specific system directories can exploit a dangling pointer vulnerability. This occurs when a garbage collection cleanup function is called, leaving a pointer that can then be printed to system logs. This could potentially expose sensitive data if the memory location is re-used, leading to information disclosure. For this exploit to work, Lua plugins must be enabled in libinput and loaded by the compositor.

CVSS3: 3.3
github
4 месяца назад

A flaw was found in libinput. An attacker capable of deploying a Lua plugin file in specific system directories can exploit a dangling pointer vulnerability. This occurs when a garbage collection cleanup function is called, leaving a pointer that can then be printed to system logs. This could potentially expose sensitive data if the memory location is re-used, leading to information disclosure. For this exploit to work, Lua plugins must be enabled in libinput and loaded by the compositor.