<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T09:35:40.318013+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:39296</id>
    <title>ALSA-2026:39296 — Moderate: libinput security update</title>
    <updated>2026-10-04T09:35:40.554498+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:10: libinput, AlmaLinux:10: libinput-devel, AlmaLinux:10: libinput-utils</p>
<p>libinput is a library that handles input devices for display servers and other applications that need to directly deal with input devices.</p>
<p>Security Fix(es):</p>
<p>* libinput: local privilege escalation via crafted uinput devices (CVE-2026-50292)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:39296"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0731</id>
    <title>certfr-2026-avi-0731 — De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Certaines d'entre elles permettent à un at…</title>
    <updated>2026-10-04T09:35:40.554562+00:00</updated>
    <content>certfr-2026-avi-0731</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0731"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-324680</id>
    <title>EUVD-2026-324680</title>
    <updated>2026-10-04T09:35:40.554583+00:00</updated>
    <content>EUVD-2026-324680</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-324680"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-50292</id>
    <title>fkie_cve-2026-50292</title>
    <updated>2026-10-04T09:35:40.554596+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitrary root code execution</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-50292"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-jcq8-v68h-2c44</id>
    <title>GHSA-jcq8-v68h-2c44</title>
    <updated>2026-10-04T09:35:40.554618+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitrary root code execution</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-jcq8-v68h-2c44"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-50292</id>
    <title>msrc_CVE-2026-50292 — In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev propert…</title>
    <updated>2026-10-04T09:35:40.554633+00:00</updated>
    <content>msrc_CVE-2026-50292</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-50292"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-2628</id>
    <title>OESA-2026-2628 — libinput security update</title>
    <updated>2026-10-04T09:35:40.554650+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP4: libinput, openEuler:22.03-LTS-SP4: libinput, openEuler:24.03-LTS-SP1: libinput, openEuler:24.03-LTS-SP3: libinput</p>
<p>libinput is a library to handle input devices in Wayland compositors and to provide  a generic X.Org input driver.It provides device detection, device handling, input  device event processing and abstraction so minimize the amount of custom input code compositors need to provide the common set of functionality that users expect.

Security Fix(es):</p>
<p>In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitrary root code execution(CVE-2026-50292)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-2628"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21091-1</id>
    <title>openSUSE-SU-2026:21091-1 — Security update for libinput</title>
    <updated>2026-10-04T09:35:40.554716+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for libinput</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:21091-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:43290</id>
    <title>RHSA-2026:43290 — Red Hat Security Advisory: libinput security update</title>
    <updated>2026-10-04T09:35:40.554733+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libinput: local privilege escalation via crafted uinput devices</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:43290"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:39296</id>
    <title>RLSA-2026:39296 — Moderate: libinput security update</title>
    <updated>2026-10-04T09:35:40.554749+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:10: libinput</p>
<p>libinput is a library that handles input devices for display servers and other applications that need to directly deal with input devices.</p>
<p>Security Fix(es):</p>
<p>* libinput: local privilege escalation via crafted uinput devices (CVE-2026-50292)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:39296"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:22165-1</id>
    <title>SUSE-SU-2026:22165-1 — Security update for libinput</title>
    <updated>2026-10-04T09:35:40.554772+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for libinput</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:22165-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-50292</id>
    <title>UBUNTU-CVE-2026-50292</title>
    <updated>2026-10-04T09:35:40.554787+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: libinput, Ubuntu:18.04:LTS: libinput, Ubuntu:Pro:20.04:LTS: libinput, Ubuntu:22.04:LTS: libinput, Ubuntu:24.04:LTS: libinput, Ubuntu:25.10: libinput, Ubuntu:26.04:LTS: libinput</p>
<p>In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitrary root code execution</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-50292"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2318</id>
    <title>WID-SEC-W-2026-2318 — Red Hat Enterprise Linux (libinput): Schwachstelle ermöglicht Privilegieneskalation</title>
    <updated>2026-10-04T09:35:40.554814+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux (libinput) ausnutzen, um seine Privilegien zu erhöhen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2318"/>
  </entry>
</feed>
