{"id":"MGASA-2026-0208","summary":"Updated libinput packages fix security vulnerability","details":"In libinput before 1.30.4 and 1.31.x before 1.31.3,\nlibinput-device-group unescaped phys output can inject udev properties\nleading to arbitrary root code execution\n","modified":"2026-06-15T16:00:03.968496534Z","published":"2026-06-15T15:56:35Z","upstream":["CVE-2026-50292"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2026-0208.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=35635"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2026/06/04/5"},{"type":"WEB","url":"https://www.openwall.com/lists/oss-security/2026/06/04/16"}],"affected":[{"package":{"name":"libinput","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/libinput?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.23.0-2.1.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0208.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}