CVE-2026-35093
DOCUMENTATION: A flaw was found in libinput. A local attacker who can place a specially crafted Lua bytecode file in certain system or user configuration directories can bypass security restrictions. This allows the attacker to run unauthorized code with the same permissions as the program using libinput, such as a graphical compositor. This could lead to the attacker monitoring keyboard input and sending that information to an external location.
STATEMENT: This Important flaw in libinput allows a local attacker to achieve unauthorized code execution and information disclosure. Exploitation requires the attacker to place a specially crafted Lua bytecode file in a system or user configuration directory, and for Lua plugins to be enabled and loaded by the graphical compositor.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://access.redhat.com/security/cve/CVE-2026-35093
