Описание
Security update for libinput
This update for libinput fixes the following issues
- CVE-2026-50265,CVE-2026-50292: crafted uinput devices can lead to local privilege escalation (bsc#1267852).
Список пакетов
openSUSE Leap 16.0
libinput-debug-gui-1.28.1-160000.3.1
libinput-devel-1.28.1-160000.3.1
libinput-tools-1.28.1-160000.3.1
libinput-udev-1.28.1-160000.3.1
libinput10-1.28.1-160000.3.1
Ссылки
- SUSE Security Ratings
- SUSE Bug 1267852
- SUSE CVE CVE-2026-50265 page
- SUSE CVE CVE-2026-50292 page
Описание
This CVE ID was assigned as a duplicate of CVE-2026-50292
Затронутые продукты
openSUSE Leap 16.0:libinput-debug-gui-1.28.1-160000.3.1
openSUSE Leap 16.0:libinput-devel-1.28.1-160000.3.1
openSUSE Leap 16.0:libinput-tools-1.28.1-160000.3.1
openSUSE Leap 16.0:libinput-udev-1.28.1-160000.3.1
Ссылки
- CVE-2026-50265
- SUSE Bug 1267852
Описание
In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitrary root code execution
Затронутые продукты
openSUSE Leap 16.0:libinput-debug-gui-1.28.1-160000.3.1
openSUSE Leap 16.0:libinput-devel-1.28.1-160000.3.1
openSUSE Leap 16.0:libinput-tools-1.28.1-160000.3.1
openSUSE Leap 16.0:libinput-udev-1.28.1-160000.3.1
Ссылки
- CVE-2026-50292
- SUSE Bug 1267852