No advisories yet.
Solution
No solution given by the vendor.
Workaround
Restrict access to /dev/uinput to trusted users only. This is the default on virtually all distributions but some packages install udev rules that allow a logged-in user to create uinput devices. Examples for this on Fedora are steam-device, antimicrox, kdeconnectd.
Fri, 05 Jun 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 05 Jun 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in libinput. A local attacker with access to /dev/uinput can inject arbitrary udev properties through the libinput-device-group helper. This injection can lead to root code execution, for example, by exploiting REMOVE_CMD properties that are executed when a device is removed. This vulnerability allows an attacker to gain elevated privileges on the system. | |
| Title | Libinput: local privilege escalation via crafted uinput devices | |
| First Time appeared |
Redhat
Redhat enterprise Linux |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-06-05T11:11:13.444Z
Reserved: 2026-06-04T14:55:24.012Z
Link: CVE-2026-50265
Updated: 2026-06-05T10:48:06.182Z
Status : Received
Published: 2026-06-05T11:16:36.853
Modified: 2026-06-05T11:16:36.853
Link: CVE-2026-50265
No data.
OpenCVE Enrichment
Updated: 2026-06-05T11:30:39Z