Fedora Account System
Red Hat Associate
Red Hat Customer
A local attacker with /dev/uinput access can inject arbitrary udev properties through the libinput-device-group helper. Depending on downstream udev rules, this can result in root code execution (e.g. via injected REMOVE_CMD properties executed at device removal time). REMOVE_CMD is in the default udev rules and expected to be present on virtually all machines.
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:39296 https://access.redhat.com/errata/RHSA-2026:39296
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:43290 https://access.redhat.com/errata/RHSA-2026:43290