[ GLSA 202608-08 ] libinput: Multiple Vulnerabilities

[email protected]
Newsgroups gmane.linux.gentoo.announce
Message-ID <178666959642.1.12049934177757533523@cdebd0f5f1fc>
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 202608-08
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                           https://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

 Severity: High
    Title: libinput: Multiple Vulnerabilities
     Date: August 14, 2026
     Bugs: #971879, #976730
       ID: 202608-08

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

Multiple vulnerabilities have been found in libinput, the worst of which
could result in privilege escalation.

Background
==========

A library to handle input devices in Wayland and, via xf86-input-
libinput, in X.org.

Affected packages
=================

Package            Vulnerable    Unaffected
-----------------  ------------  ------------
dev-libs/libinput  < 1.31.3      >= 1.31.3

Description
===========

Multiple vulnerabilities have been discovered in libinput. Please review
the CVE identifiers referenced below for details.

Impact
======

Please review the referenced CVE identifiers for details.

Workaround
==========

There is no known workaround at this time.

Resolution
==========

All libinput users should upgrade to the latest version:

  # emerge --sync
  # emerge --ask --oneshot --verbose ">=dev-libs/libinput-1.31.3"

References
==========

[ 1 ] CVE-2026-35093
      https://nvd.nist.gov/vuln/detail/CVE-2026-35093
[ 2 ] CVE-2026-35094
      https://nvd.nist.gov/vuln/detail/CVE-2026-35094

Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

 https://security.gentoo.org/glsa/202608-08

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
[email protected] or alternatively, you may file a bug at
https://bugs.gentoo.org.

License
=======

Copyright 2026 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.

https://creativecommons.org/licenses/by-sa/2.5
signature.asc (application/pgp-signature, 870 B)
-----BEGIN PGP SIGNATURE-----

iQJPBAEBCAA5FiEEpqTA6ABLMxh/aChGFMQkOaVy+9kFAmp+ahwbFIAAAAAABAAO
bWFudTIsMi41KzEuMTIsMiwyAAoJEBTEJDmlcvvZiKcP/1hmVQo3quJTmEVW9YQU
YlszOweZRmLo+wE94xG2Zc6pb6wptUv2zjrpMpiKevNhPUHJdpwxXnZX8rtD1vrl
OKgnsyRtelWteVLGdD4qBGJM/DoZCaSW7bFljRBRtNbiiTR9AbNh76Aott+GcyWX
6GuVaKtkdaWk7qba7wzMplNH7ogMRUDCLBfxCAJgmgxDg1TZf6oaWSOkn9363N7u
OZqi19NDaW9igRUNMGcjkI/SqIIkKDKcZlGwxbl6uDT4Hhc7wlcYRTs2PLNdRGyn
bYZYWmEq+HxcraMKcqL/B5Pv9KCwQm7EAigcP3snjInNs2tQGp7s0zExJ9bzsVru
MdrkCsPxbBESdNS8lKwHmsWATdlOLU7kRJz64JZGUfTxXhjXMe1CBa2DqNrXcNfE
8ZVnjqBr2CLsDgubOtBhTMnY7W8Hnyz1wjyZndLjRMdsltEU8ieJZ24wZRVLxHon
8MM1uSNy8bDQ+mo85Pgk++0E9rX72EoHslKyeT7Yv5aucUfLrMdCbFrJkQeisYCO
6KWaq4yG383yOOH4itKzr0VwiDv1oNqSpxI2V7qISe1wjP3WLSOj/eZwHkeRoQ57
zXw9hycEFVl0QJpnm5pnJzHvg0zj4rvXzQL765zb0cBElTos1H4+b6gGo1e96xml
dnQp5zsV0e7i+v8D9YI86urR
=jjU6
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.