USN-8753-1: libinput vulnerability
Ubuntu patches libinput flaw letting local attackers inject udev properties and execute arbitrary code as root.
USN-8753-1 fixes a libinput vulnerability where device properties are not properly escaped. A local attacker could inject arbitrary udev properties and execute arbitrary code as root, a full local privilege escalation on affected Linux desktop systems. Ubuntu shipped updated packages.
40