Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-50292

Опубликовано: 04 июн. 2026
Источник: nvd
CVSS3: 7.4
CVSS3: 9.8
EPSS Низкий

Описание

In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitrary root code execution

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:freedesktop:libinput:*:*:*:*:*:*:*:*
Версия до 1.30.4 (исключая)
cpe:2.3:a:freedesktop:libinput:*:*:*:*:*:*:*:*
Версия от 1.31.0 (включая) до 1.31.3 (исключая)

EPSS

Процентиль: 40%
0.00498
Низкий

7.4 High

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-93

Связанные уязвимости

CVSS3: 7.4
ubuntu
около 2 месяцев назад

In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitrary root code execution

CVSS3: 6.7
redhat
около 2 месяцев назад

In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitrary root code execution

CVSS3: 7.4
msrc
около 2 месяцев назад

In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitrary root code execution

CVSS3: 7.4
debian
около 2 месяцев назад

In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-gr ...

rocky
16 дней назад

Moderate: libinput security update

EPSS

Процентиль: 40%
0.00498
Низкий

7.4 High

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-93