Libinput Hit By Worrying Security Issues With Its Lua Plug-In System
… The bytecode is executed at the process' privilege level with unrestricted system access. CVE-2026-35094 was also made public as a use-after-free vulnerability for libinput plug-ins. More details on these libinput security issues via today's advisory . …