libinput是freedesktop开源的一个库,它为显示服务器和其他需要处理内核提供的输入设备的应用程序提供完整的输入堆栈。 libinput存在代码注入漏洞,该漏洞源于本地攻击者可在特定配置目录放置特制Lua字节码文件以绕过安全限制,可能导致运行未授权代码并监控键盘输入。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | any |
unaffected |
| Red Hat | Red Hat Enterprise Linux 7 | any |
unknown |
| Red Hat | Red Hat Enterprise Linux 8 | any |
unaffected |
| Red Hat | Red Hat Enterprise Linux 9 | any |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-35091 | 8.2 HIGH | Corosync: corosync: denial of service and information disclosure via crafted udp packet |
| CVE-2026-35092 | 7.5 HIGH | Corosync: corosync: denial of service via integer overflow in join message validation |
| CVE-2026-35094 | 3.3 LOW | Libinput: libinput: information disclosure via dangling pointer in lua plugin handling |
No comments yet