ZeroHour
Ubuntu Security Noticespublished ()ingested

USN-8753-1: libinput vulnerability

highAdvisoryimportance 40
AI summary · glm-5.3

Ubuntu patches libinput flaw letting local attackers inject udev properties and execute arbitrary code as root.

USN-8753-1 fixes a libinput vulnerability where device properties are not properly escaped. A local attacker could inject arbitrary udev properties and execute arbitrary code as root, a full local privilege escalation on affected Linux desktop systems. Ubuntu shipped updated packages.

  • libinput fails to escape device properties passed to udev
  • Local attacker can inject udev properties and execute code as root
  • Affects Linux desktop systems using libinput
  • Local privilege escalation to root is possible
Full article

It was discovered that libinput did not properly escape device properties. A local attacker could possibly use this issue to inject arbitrary udev properties and execute arbitrary code as root.

This source does not provide full text. Read it at ubuntu.com.