Multiple vulnerabilities have been found in libinput, the worst of which could result in privilege escalation. Affected packages Package dev-libs/libinput on all architectures Affected versions < 1.31.3 Unaffected versions >= 1.31.3 Background A library to handle input devices in Wayland and, via xf86-input-libinput, in X.org. Description Multiple vulnerabilities have been discovered in libinput. Please review the CVE identifiers referenced below for details. Impact Please review the referenced CVE identifiers for details. Workaround There is no known workaround at this time. Resolution All libinput users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=dev-libs/libinput-1.31.3" References CVE-2026-35093 CVE-2026-35094 Release date August 14, 2026 Latest revision August 14, 2026: 1 Severity high Exploitable local Bugzilla entries 971879 976730
Multiple vulnerabilities in libinput, including a high-severity local privilege escalation flaw (CVE-2026-35093, CVSS 8.8), affect freedesktop libinput versions prior to 1.30.3 and versions from 1.30.4 through 1.31.0. The fixed versions are 1.30.3 and 1.31.1, and there is no known workaround at this time.