CVE-2026-50292
HIGHFreedesktop Libinput - Improper Neutralization of CRLF Sequences ('CRLF Injection')
Title source: ruleDescription
In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitrary root code execution
Scores
CVSS v3
7.4
EPSS
0.0030
EPSS Percentile
21.1%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-93
Status
published
Products (2)
freedesktop/libinput
< 1.30.4 (2 CPE variants)
freedesktop/libinput
1.31.0 - 1.31.3
Published
Jun 04, 2026
Tracked Since
Jun 04, 2026