https://seclists.org/oss-sec/2026/q2/5: FW: libinput Security Advisory: multiple security issues in libinput
Published Apr 2, 2026
·Updated
Affected Software
1 affected component
freedesktop.org libinput>=1.30.0<=1.30.2, =1.31.0
Frequently Asked Questions
1
What is the severity of CVE-2026-35093?
CVE-2026-35093 has been classified as a high severity vulnerability due to its potential for sandbox escape in libinput plugins.
2
How do I fix CVE-2026-35093?
To address CVE-2026-35093, you should update libinput to the latest version where the vulnerability has been patched.
3
What type of systems are affected by CVE-2026-35093?
CVE-2026-35093 affects systems that use freedesktop.org's libinput for handling input devices.
4
What impact does CVE-2026-35093 have on users?
CVE-2026-35093 can lead to unauthorized access to the host operating environment due to a sandbox escape.
5
Are there any workarounds for CVE-2026-35093?
Currently, the best workaround for CVE-2026-35093 is to disable Lua plugins in libinput if possible until an update can be applied.