Skip to content
Debian libinput Vulnerabilities Lead to Local Privilege Escalation Risks

Debian libinput Vulnerabilities Lead to Local Privilege Escalation Risks

First seen 12 Jun 2026, 04:06 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 13, 2026 at 03:55 UTC

Two vulnerabilities in the Debian libinput package have been identified, affecting local users. CVE-2022-1215, published on 2022-05-31, allows exploitation of evdev devices to execute arbitrary code. CVE-2026-50292, published on 2026-06-04, involves insufficient sanitization of device properties, leading to local privilege escalation. Debian 11 bullseye has patched these issues in version 1.16.4-3+deb11u1, while versions for the oldstable (bookworm) and stable (trixie) distributions have also received updates. Users are advised to upgrade their libinput packages to mitigate these risks. The vulnerabilities could potentially allow malicious local users to gain elevated privileges in specific setups.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 90d ago How this analysis works

Timeline

2022-05-31
CVE-2022-1215 published
A vulnerability in libinput allows local users to execute arbitrary code via evdev devices.
Linuxsecurity
2026-06-04
CVE-2026-50292 published
Insufficient sanitization in libinput's udev helper can lead to local privilege escalation.
Linuxsecurity
2026-06-12
Debian releases patches for vulnerabilities
Debian has fixed the vulnerabilities in libinput for bullseye, bookworm, and trixie distributions.
Linuxsecurity

More articles in this cluster (2)

Following this threat?

Track Debian and CVE-2022-1215 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed