CVE-2026-50292 - Fixes for AlmaLinux 8/9?

CVE-2026-50292 was fixed in libinput in the upstream repository in June and in AlmaLinux 10 in July due to upgrading to 1.30.1 and subsequently backporting the required fix to the branch. The vulnerable code is also present in AlmaLinux 8 and 9, which are stuck with their respective versions 1.16 and 1.19, but I think that it should be possible to backport the fix for them relatively effortless as well. As it is a very critical vulnerability, I would be glad to see if the developers step up to fix them in a timely manner, especially as AlmaLinux 9 is still in the Full Support Phase.

Just provide a patch. It is welcome!

Red Hat currently rates this vulnerability as High rather than Critical.

Since AlmaLinux generally follows RHEL package updates, AlmaLinux 8 and 9 may not receive patched packages unless Red Hat releases corresponding fixes for RHEL 8 and 9.

In the meantime, Red Hat recommends restricting access to /dev/uinput to trusted users only. You may want to verify the current permissions and apply this mitigation if necessary.

Now it shows Moderate and for both RHEL 8 and 9 the status is thus “Will not fix”

@jlehtone

Thanks for pointing that out.
By the way, I get the impression that you have a great deal of expertise. Have you ever seen an issue marked “will not fix” actually get fixed?
I haven’t.

I have not paid attention to that, but probably never.

1 Like