Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-35093

Опубликовано: 01 апр. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 8.8

Описание

A flaw was found in libinput. A local attacker who can place a specially crafted Lua bytecode file in certain system or user configuration directories can bypass security restrictions. This allows the attacker to run unauthorized code with the same permissions as the program using libinput, such as a graphical compositor. This could lead to the attacker monitoring keyboard input and sending that information to an external location.

РелизСтатусПримечание
devel

not-affected

1.31.1-1
esm-infra-legacy/xenial

not-affected

code not present
esm-infra/bionic

not-affected

code not present
esm-infra/focal

not-affected

code not present
esm-infra/xenial

not-affected

code not present
jammy

not-affected

code not present
noble

not-affected

code not present
questing

not-affected

code not present
resolute

not-affected

1.31.1-1
upstream

released

1.31.1-1

Показывать по

Ссылки на источники

EPSS

Процентиль: 8%
0.00184
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
redhat
4 месяца назад

A flaw was found in libinput. A local attacker who can place a specially crafted Lua bytecode file in certain system or user configuration directories can bypass security restrictions. This allows the attacker to run unauthorized code with the same permissions as the program using libinput, such as a graphical compositor. This could lead to the attacker monitoring keyboard input and sending that information to an external location.

CVSS3: 8.8
nvd
4 месяца назад

A flaw was found in libinput. A local attacker who can place a specially crafted Lua bytecode file in certain system or user configuration directories can bypass security restrictions. This allows the attacker to run unauthorized code with the same permissions as the program using libinput, such as a graphical compositor. This could lead to the attacker monitoring keyboard input and sending that information to an external location.

msrc
4 месяца назад

Libinput: libinput: unauthorized code execution and information disclosure through lua bytecode plugins

CVSS3: 8.8
debian
4 месяца назад

A flaw was found in libinput. A local attacker who can place a special ...

CVSS3: 8.8
github
4 месяца назад

A flaw was found in libinput. A local attacker who can place a specially crafted Lua bytecode file in certain system or user configuration directories can bypass security restrictions. This allows the attacker to run unauthorized code with the same permissions as the program using libinput, such as a graphical compositor. This could lead to the attacker monitoring keyboard input and sending that information to an external location.

EPSS

Процентиль: 8%
0.00184
Низкий

8.8 High

CVSS3