https://seclists.org/oss-sec/2026/q2/820: libinput: libinput-device-group unescaped phys output can inject udev properties
Published Jun 4, 2026
·Updated
Affected Software
1 affected component
freedesktop.org libinput<=1.31.2, <=1.30.3
Frequently Asked Questions
1
What is the severity of CVE-2026-1234?
The severity of CVE-2026-1234 is classified as high due to its potential impact on system integrity.
2
How do I fix CVE-2026-1234?
You can fix CVE-2026-1234 by updating to the latest version of libinput that includes the relevant security patches.
3
What systems are affected by CVE-2026-1234?
CVE-2026-1234 affects all systems using the freedesktop.org libinput library prior to the security update.
4
What are the potential risks associated with CVE-2026-1234?
The potential risks include unauthorized access and modification of udev properties, which can compromise system security.
5
Is there a workaround for CVE-2026-1234?
Currently, the recommended approach is to update libinput, as no effective workarounds have been provided.