Open Source Security mailing list@oss_securityDisclosure
Two new CVEs for libinput plugins were disclosed—CVE-2026-35093 (sandbox escape) and CVE-2026-35094 (use-after-free info leak)—with no PoC, exploit, or active exploitation details provided.
CVEFind.com@CveFindComDisclosure
The post announces CVE-2026-35093, a libinput flaw that allows local attackers to bypass security checks and execute code with the same permissions, highlighting its HIGH severity.
CVE@CVEnewDisclosure
The CVE describes a local privilege escalation flaw in libinput, where a specially crafted Lua bytecode file placed in configuration directories can bypass security checks; no PoC, exploit, or active exploitation is reported.
CyberDudeBivash® | Global Cybersecurity Company@cyberbivashDisclosure
The alert announces CVE-2026-35093, citing an Intel report and indicating unauthorized code execution and information disclosure through Lua bytecode plugins, but provides no PoC, exploit, or patch details.
The Hacker Wire@TheHackerWireDisclosure
A local vulnerability in libinput permits an attacker to bypass security restrictions by placing crafted Lua bytecode in configuration directories, with no current evidence of exploitation or patch.