logo

Game Over? Critical InputPlumber Flaws Expose Linux Gamers to Hijacking

ID: 3cdb9024-941c-57c8-8edb-183fe90f57d1

STIX ID: report--3cdb9024-941c-57c8-8edb-183fe90f57d1

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-01-12

Date Updated: 2026-04-23

Author: Ddos

...
...

SUSE Security discovered that InputPlumber (used in SteamOS) exposed an unauthenticated D-Bus interface and a Polkit race condition (CVE-2025-66005, CVE-2025-14338), enabling local attackers to create virtual devices, inject keystrokes into active sessions (potentially leading to arbitrary code execution), and leak privileged files; upstream fixes were released in v0.69.0 and updated SteamOS images — users should upgrade immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.