Arbitrary Code Execution Affecting libinput/libinput package, versions [, 1.18.2)[1.19.0, 1.19.4)[1.20.0, 1.20.1)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.37% (30th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-LIBINPUTLIBINPUT-2803378
  • published26 Apr 2022
  • disclosed20 Apr 2022
  • creditLukas Lamster

Introduced: 20 Apr 2022

CVE-2022-1215  (opens in a new tab)
CWE-94  (opens in a new tab)

How to fix?

Upgrade libinput/libinput to version 1.18.2, 1.19.4, 1.20.1 or higher.

Overview

Affected versions of this package are vulnerable to Arbitrary Code Execution via logging of several messages through log handlers set up by the callers. These log handlers usually eventually result in a printf call. Logging happens with the privileges of the caller, in the case of Xorg this may be root. The device name ends up as part of the format string and a kernel device with printf-style format string placeholders in the device name can enable an attacker to run malicious code. An exploit is possible through any device where the attacker controls the device name, e.g. /dev/uinput or Bluetooth devices.

CVSS Base Scores

version 3.1