A vulnerability in libinput, the input device handling library used with Wayland and X.Org Server, can allow local privilege escalation to root by abusing how the library passes device attributes into udev. Researchers found that crafted newline characters in values associated with virtual devices created through uinput or uhid can inject unintended extra udev properties, including dangerous keys such as REMOVE_CMD, potentially leading to command execution as root when the device is processed or removed.
The issue affects systems where non-root users can write to /dev/uinput or /dev/uhid, a capability that is normally restricted but may be exposed by permissive desktop-oriented udev rules or group memberships. Fedora was highlighted as an example where packages such as steam-devices, antimicrox, and kdeconnectd may open that path for local users. The vulnerability has been fixed in libinput 1.31.3 and 1.30.4, and exploitation requires local access plus the ability to create malicious virtual input devices.

Get the actors, campaigns, and ATT&CK mapping behind it.
4 events from the most recent confirmed update back to the earliest known activity.
Debian published security advisory DSA 6339-1 for libinput, announcing a distribution-level security update addressing the libinput vulnerability tracked as CVE-2026-50265. This represents downstream remediation by the Debian project following the upstream fix and CVE assignment.
The previously disclosed libinput vulnerability was subsequently assigned CVE-2026-50265. The issue affects libinput versions up to 1.31.2 and 1.30.3 and can allow root-level code execution via injected udev properties from crafted uinput or uhid devices.
The vulnerability was fixed in libinput releases 1.31.3 and 1.30.4. The fix addresses unsafe handling of udev properties that could otherwise be abused for command execution as root.
A vulnerability in libinput was disclosed that can allow local privilege escalation to root by injecting additional udev properties through crafted virtual input device attributes via uinput or uhid. The issue affects systems where non-root users can access /dev/uinput or /dev/uhid through permissive rules or group membership.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
8 references tracked. Mallory keeps watching after this page renders.
lists.debian.org
Open sourceseclists.org
Open sourceseclists.org
Open sourcelore.freedesktop.org
Open sourceseclists.org
Open sourcegitlab.freedesktop.org
Open sourceopennet.me
Open sourceopennet.ru
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.