Debian alert DLA-4626-1 (libinput)
| From: | Santiago Ruano Rincón <santiagorr@riseup.net> | |
| To: | debian-lts-announce@lists.debian.org | |
| Subject: | [SECURITY] [DLA 4626-1] libinput security update | |
| Date: | Fri, 12 Jun 2026 00:07:01 -0300 | |
| Message-ID: | <ait31c1pjm_xM1qu@voleno> |
------------------------------------------------------------------------- Debian LTS Advisory DLA-4626-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Santiago Ruano Rincón June 11, 2026 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : libinput Version : 1.16.4-3+deb11u1 CVE ID : CVE-2022-1215 CVE-2026-50292 Two vulnerabilities were found in libinput, an input device management and event handling library. CVE-2022-1215 libinput did not properly handled evdev devices, which may potentially be exploited by malicious local users in specific setup to execute arbitrary code. Reported by Albin Eldstål-Ahrens and Lukas Lamster. CVE-2026-50292 A udev helper provided by libinput performed insufficient sanitising of device properties, which can result in local privilege escalation in some setups. Reported by Csome. For Debian 11 bullseye, these problems have been fixed in version 1.16.4-3+deb11u1. We recommend that you upgrade your libinput packages. For the detailed security status of libinput please refer to its security tracker page at: https://security-tracker.debian.org/tracker/libinput Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iHUEABYKAB0WIQR+lHTq7mkJOyB6t2Un3j1FEEiG7wUCait31QAKCRAn3j1FEEiG 79dIAP455NjxSiQrtX50Ryv/+u+hgOe6E9qvjanvSQE0a9FQeQEAkxIoHkAOx0M9 C6k2PcFroyyC/vcnkgu1YsBq6N3tawc= =LkVX -----END PGP SIGNATURE-----
