USN-8753-1: libinput vulnerability
AI summary · glm-5.3
Ubuntu patches libinput flaw letting local attackers inject udev properties and execute arbitrary code as root.
USN-8753-1 fixes a libinput vulnerability where device properties are not properly escaped. A local attacker could inject arbitrary udev properties and execute arbitrary code as root, a full local privilege escalation on affected Linux desktop systems. Ubuntu shipped updated packages.
- libinput fails to escape device properties passed to udev
- Local attacker can inject udev properties and execute code as root
- Affects Linux desktop systems using libinput
- Local privilege escalation to root is possible
Full article
It was discovered that libinput did not properly escape device properties. A local attacker could possibly use this issue to inject arbitrary udev properties and execute arbitrary code as root.
This source does not provide full text. Read it at ubuntu.com.