Vulnerability Description
A flaw was found in libinput. An attacker capable of deploying a Lua plugin file in specific system directories can exploit a dangling pointer vulnerability. This occurs when a garbage collection cleanup function is called, leaving a pointer that can then be printed to system logs. This could potentially expose sensitive data if the memory location is re-used, leading to information disclosure. For this exploit to work, Lua plugins must be enabled in libinput and loaded by the compositor.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Freedesktop | Libinput | - |
| Fedoraproject | Fedora | 43 |
Related Weaknesses (CWE)
References
- https://access.redhat.com/security/cve/CVE-2026-35094VDB EntryThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2453840Issue TrackingThird Party Advisory
- https://gitlab.freedesktop.org/libinput/libinput/-/work_items/1272Broken Link
FAQ
What is CVE-2026-35094?
CVE-2026-35094 is a vulnerability with a CVSS score of 3.3 (LOW). A flaw was found in libinput. An attacker capable of deploying a Lua plugin file in specific system directories can exploit a dangling pointer vulnerability. This occurs when a garbage collection clea...
How severe is CVE-2026-35094?
CVE-2026-35094 has been rated LOW with a CVSS base score of 3.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-35094?
Check the references section above for vendor advisories and patch information. Affected products include: Freedesktop Libinput, Fedoraproject Fedora.