Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Critical InputPlumber Flaw Enables UI Input Injection and Denial-of-Service

Security researchers have identified critical vulnerabilities in InputPlumber, a Linux input device utility used in SteamOS. These vulnerabilities could allow attackers to inject keystrokes, leak sensitive information, and cause denial-of-service…

Security researchers have identified critical vulnerabilities in InputPlumber, a Linux input device utility used in SteamOS. These vulnerabilities could allow attackers to inject keystrokes, leak sensitive information, and cause denial-of-service conditions.

The identified vulnerabilities, tracked as CVE-2025-66005 and CVE-2025-14338, affect InputPlumber versions before v0.69.0. They stem from inadequate D-Bus authorization checks.

CVE ID Description Affected Versions Impact

CVE-2025-66005 Lack of authorization on InputManager D-Bus interface Before v0.63.0 Local DoS, information leak, privilege escalation

CVE-2025-14338 Polkit authentication disabled by default and race condition Before v0.69.0 Authentication bypass, same impacts as CVE-2025-66005

Security researchers have identified critical vulnerabilities in InputPlumber, a Linux input device utility used in SteamOS.
Anna Fields · Thehackingpost

InputPlumber combines Linux input devices into virtual controllers and operates with full root privileges. These vulnerabilities allow unprivileged users to exploit two D-Bus methods:

The CreateCompositeDevice method accepts file paths without proper validation, enabling attackers to test for the existence of restricted files, exhaust memory, or leak sensitive data. The CreateTargetDevice method allows the creation of virtual keyboard devices, enabling the injection of arbitrary keystrokes into active user sessions.

These vulnerabilities affect any Linux distribution running vulnerable versions of InputPlumber, including SteamOS.

InputPlumber version v0.69.0 addresses most issues by:

Advertisement

Switching to secure "system bus name" Polkit subject Enabling Polkit authorization by default Applying systemd hardening parameters

SteamOS has released version 3.7.20, which includes these fixes. Users should update immediately. System administrators are advised to verify that InputPlumber is updated to v0.69.0 or later and review Polkit policies to ensure proper authentication requirements are in place.

The vulnerabilities were discovered during a SUSE security review and disclosed through coordinated disclosure with upstream developers.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories