ELA-1799-1 libinput security update

local privilege escalation

2026-08-10
Packagelibinput
Version1.6.3-1+deb9u1 (stretch)
Related CVEs CVE-2026-50292


A vulnerability was found in libinput, an input device management and event handling library.

CVE-2026-50292

A udev helper provided by libinput performed insufficient sanitising of
device properties, which can result in local privilege escalation in
some setups. Reported by Csome.


For Debian 9 stretch, these problems have been fixed in version 1.6.3-1+deb9u1.

We recommend that you upgrade your libinput packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.