https://seclists.org/oss-sec/2026/q2/824: libinput: libinput-device-group unescaped phys output can inject udev properties
Published Jun 5, 2026
·Updated
Affected Software
1 affected component
libinput libinput<=1.31.2, <=1.30.3
Frequently Asked Questions
1
What is the severity of CVE-2026-0604?
The severity of CVE-2026-0604 is considered to be medium due to its potential impact on system security.
2
How do I fix CVE-2026-0604?
To fix CVE-2026-0604, you should update to the latest version of libinput that addresses this vulnerability.
3
What systems are affected by CVE-2026-0604?
CVE-2026-0604 affects all versions of libinput prior to the patched release that mitigates the issue.
4
What type of vulnerability is CVE-2026-0604?
CVE-2026-0604 is a denial-of-service vulnerability that allows unescaped physical output to inject udev properties.
5
Who reported CVE-2026-0604?
CVE-2026-0604 was reported by Peter Hutterer in the libinput security advisory.