Game Over? Critical InputPlumber Flaws Expose Linux Gamers to Hijacking
ID: 3cdb9024-941c-57c8-8edb-183fe90f57d1
STIX ID: report--3cdb9024-941c-57c8-8edb-183fe90f57d1
Feed Name: securityonline.info
Threat Score
SUSE Security discovered that InputPlumber (used in SteamOS) exposed an unauthenticated D-Bus interface and a Polkit race condition (CVE-2025-66005, CVE-2025-14338), enabling local attackers to create virtual devices, inject keystrokes into active sessions (potentially leading to arbitrary code execution), and leak privileged files; upstream fixes were released in v0.69.0 and updated SteamOS images — users should upgrade immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
