Description
In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitrary root code execution
Mitigation
Minimal update. May introduce new vulnerabilities or breaking changes.
|
 debian 11 | | =1.16.4-3 || =1.17.2-1 || =1.18.0-1 || =1.18.1-1 || =1.19.1-1 || =1.19.2-1 || =1.19.3-1 || =1.19.3-2 || =1.20.0-1 || =1.20.1-1 || =1.21.0-1 || =1.22.0-1 || =1.22.1-1 || =1.23.0-1 || =1.23.0-2 || =1.23.0-2.1 || =1.25.0-1 || =1.26.0-1 || =1.26.2-1 || =1.27.1-1 || =1.28.0-1 || =1.28.1-1 || =1.30.0-1 || =1.30.1-1 || =1.31.0-1 || =1.31.1-1 || =1.31.2-1 || =1.31.3-1 |
 debian 12 | | =1.22.1-1 || =1.23.0-1 || =1.23.0-2 || =1.23.0-2.1 || =1.25.0-1 || =1.26.0-1 || =1.26.2-1 || =1.27.1-1 || =1.28.0-1 || =1.28.1-1 || =1.30.0-1 || =1.30.1-1 || =1.31.0-1 || =1.31.1-1 || =1.31.2-1 || =1.31.3-1 |
 debian 13 | | =1.28.1-1 || =1.30.0-1 || =1.30.1-1 || =1.31.0-1 || =1.31.1-1 || =1.31.2-1 || =1.31.3-1 |
 debian 14 | | =1.28.1-1 || =1.30.0-1 || =1.30.1-1 || =1.31.0-1 || =1.31.1-1 || =1.31.2-1 || =1.31.3-1 |