Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-89378.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-89378
Upstream
Published
2026-06-04T18:16:32Z
Modified
2026-08-31T05:26:27Z
Summary
CVE-2026-50292 affecting package libinput for versions less than 1.25.0-2
Details

In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitrary root code execution

References

Affected packages

Azure Linux:3 / libinput

Package

Name
libinput
Purl
pkg:rpm/azure-linux/libinput

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.25.0-2

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-89378.json"