Security
Headlines
HeadlinesLatestCVEs

Headline

Red Hat Security Advisory 2022-5257-01

Red Hat Security Advisory 2022-5257-01 - libinput is a library that handles input devices for display servers and other applications that need to directly deal with input devices. Issues addressed include format string and privilege escalation vulnerabilities.

Packet Storm
#vulnerability#linux#red_hat#js

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

====================================================================
Red Hat Security Advisory

Synopsis: Moderate: libinput security update
Advisory ID: RHSA-2022:5257-01
Product: Red Hat Enterprise Linux
Advisory URL: https://access.redhat.com/errata/RHSA-2022:5257
Issue date: 2022-06-28
CVE Names: CVE-2022-1215
====================================================================

  1. Summary:

An update for libinput is now available for Red Hat Enterprise Linux 9.

Red Hat Product Security has rated this update as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.

  1. Relevant releases/architectures:

Red Hat CodeReady Linux Builder (v. 9) - aarch64, ppc64le, s390x, x86_64
Red Hat Enterprise Linux AppStream (v. 9) - aarch64, ppc64le, s390x, x86_64

  1. Description:

libinput is a library that handles input devices for display servers and
other applications that need to directly deal with input devices.

Security Fix(es):

  • libinput: format string vulnerability may lead to privilege escalation
    (CVE-2022-1215)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

  1. Solution:

For details on how to apply this update, which includes the changes
described in this advisory, refer to:

https://access.redhat.com/articles/11258

  1. Bugs fixed (https://bugzilla.redhat.com/):

2074952 - CVE-2022-1215 libinput: format string vulnerability may lead to privilege escalation

  1. Package List:

Red Hat Enterprise Linux AppStream (v. 9):

Source:
libinput-1.19.3-2.el9_0.src.rpm

aarch64:
libinput-1.19.3-2.el9_0.aarch64.rpm
libinput-debuginfo-1.19.3-2.el9_0.aarch64.rpm
libinput-debugsource-1.19.3-2.el9_0.aarch64.rpm
libinput-test-debuginfo-1.19.3-2.el9_0.aarch64.rpm
libinput-utils-1.19.3-2.el9_0.aarch64.rpm
libinput-utils-debuginfo-1.19.3-2.el9_0.aarch64.rpm

ppc64le:
libinput-1.19.3-2.el9_0.ppc64le.rpm
libinput-debuginfo-1.19.3-2.el9_0.ppc64le.rpm
libinput-debugsource-1.19.3-2.el9_0.ppc64le.rpm
libinput-test-debuginfo-1.19.3-2.el9_0.ppc64le.rpm
libinput-utils-1.19.3-2.el9_0.ppc64le.rpm
libinput-utils-debuginfo-1.19.3-2.el9_0.ppc64le.rpm

s390x:
libinput-1.19.3-2.el9_0.s390x.rpm
libinput-debuginfo-1.19.3-2.el9_0.s390x.rpm
libinput-debugsource-1.19.3-2.el9_0.s390x.rpm
libinput-test-debuginfo-1.19.3-2.el9_0.s390x.rpm
libinput-utils-1.19.3-2.el9_0.s390x.rpm
libinput-utils-debuginfo-1.19.3-2.el9_0.s390x.rpm

x86_64:
libinput-1.19.3-2.el9_0.i686.rpm
libinput-1.19.3-2.el9_0.x86_64.rpm
libinput-debuginfo-1.19.3-2.el9_0.i686.rpm
libinput-debuginfo-1.19.3-2.el9_0.x86_64.rpm
libinput-debugsource-1.19.3-2.el9_0.i686.rpm
libinput-debugsource-1.19.3-2.el9_0.x86_64.rpm
libinput-test-debuginfo-1.19.3-2.el9_0.i686.rpm
libinput-test-debuginfo-1.19.3-2.el9_0.x86_64.rpm
libinput-utils-1.19.3-2.el9_0.x86_64.rpm
libinput-utils-debuginfo-1.19.3-2.el9_0.i686.rpm
libinput-utils-debuginfo-1.19.3-2.el9_0.x86_64.rpm

Red Hat CodeReady Linux Builder (v. 9):

aarch64:
libinput-debuginfo-1.19.3-2.el9_0.aarch64.rpm
libinput-debugsource-1.19.3-2.el9_0.aarch64.rpm
libinput-devel-1.19.3-2.el9_0.aarch64.rpm
libinput-test-debuginfo-1.19.3-2.el9_0.aarch64.rpm
libinput-utils-debuginfo-1.19.3-2.el9_0.aarch64.rpm

ppc64le:
libinput-debuginfo-1.19.3-2.el9_0.ppc64le.rpm
libinput-debugsource-1.19.3-2.el9_0.ppc64le.rpm
libinput-devel-1.19.3-2.el9_0.ppc64le.rpm
libinput-test-debuginfo-1.19.3-2.el9_0.ppc64le.rpm
libinput-utils-debuginfo-1.19.3-2.el9_0.ppc64le.rpm

s390x:
libinput-debuginfo-1.19.3-2.el9_0.s390x.rpm
libinput-debugsource-1.19.3-2.el9_0.s390x.rpm
libinput-devel-1.19.3-2.el9_0.s390x.rpm
libinput-test-debuginfo-1.19.3-2.el9_0.s390x.rpm
libinput-utils-debuginfo-1.19.3-2.el9_0.s390x.rpm

x86_64:
libinput-debuginfo-1.19.3-2.el9_0.i686.rpm
libinput-debuginfo-1.19.3-2.el9_0.x86_64.rpm
libinput-debugsource-1.19.3-2.el9_0.i686.rpm
libinput-debugsource-1.19.3-2.el9_0.x86_64.rpm
libinput-devel-1.19.3-2.el9_0.i686.rpm
libinput-devel-1.19.3-2.el9_0.x86_64.rpm
libinput-test-debuginfo-1.19.3-2.el9_0.i686.rpm
libinput-test-debuginfo-1.19.3-2.el9_0.x86_64.rpm
libinput-utils-debuginfo-1.19.3-2.el9_0.i686.rpm
libinput-utils-debuginfo-1.19.3-2.el9_0.x86_64.rpm

These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/

  1. References:

https://access.redhat.com/security/cve/CVE-2022-1215
https://access.redhat.com/security/updates/classification/#moderate

  1. Contact:

The Red Hat security contact is [email protected]. More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2022 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBYr6Vx9zjgjWX9erEAQgDZQ/+LE4gkZAB/xKeUf1ieMYdn9/AAJBGvcCk
9L2SpD+HSW/f5zsmceT3lpl92BT6PgPUdvH6FJ6pV2CH+K0USpdogEKmVu4fAKcw
jc+hykKTB1hkb2gIizhCKoFK44sz5oYDTRJJJl3Mlfez7KZSHitqRCC3RuQ+xqGq
rbb/Ul7flJjsklJRjB6uowrUoM5N0fS5YQEiCUA7o52qNORD3nLryM8Kg0cinWPB
pvjaK+khdt/Nq8o4i8+SdynF393ZYK9LSBtSsdw8Niro3V62eBp4ibWWin7wfsmD
8y+UiXMTVrE6B2keO9Ap1P54KkLTr+Vl2agYYpBj3E9ZRCBvX2PSbtv4EulpdjbQ
vnBrN8/wyxPjvGS4qkWReY33YHNHu5Sf2+wklgO+3E9L7vnIuWYbWtc53sQfT0e5
vUhMnw1kMgXf3rWiZeDjSNaBkVNyDSqNVPotMMbLPWtuCw12fCCBSY73AawGGy2Z
1QsmM4S8hqsX/CH+MMHDxzKuzKN70HBT87Ubqghc7wOF5jVhHWCMq1nhyymN+Pty
bDoBq26qS5/Wff43Y4LHfu23BYs6IRq9HZjYeD9vZTwTJ7TsL1WZ7VHNFOHBnuXL
wy0Y0mZEwUHbw9eWBWR2w62RSLCN+afPjTdz/itIibv/3tulrS/9LVVIJLI+wWp6
XMLK800/ihM=Xcgo
-----END PGP SIGNATURE-----

RHSA-announce mailing list
[email protected]
https://listman.redhat.com/mailman/listinfo/rhsa-announce

Related news

Gentoo Linux Security Advisory 202310-14

Gentoo Linux Security Advisory 202310-14 - A vulnerability has been discovered in libinput where an attacker may run malicious code by exploiting a format string vulnerability. Versions greater than or equal to 1.20.1 are affected.

Red Hat Security Advisory 2022-5069-01

Red Hat Security Advisory 2022-5069-01 - Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.11.0. Issues addressed include code execution, cross site scripting, denial of service, information leakage, and traversal vulnerabilities.

RHSA-2022:5069: Red Hat Security Advisory: OpenShift Container Platform 4.11.0 bug fix and security update

Red Hat OpenShift Container Platform release 4.11.0 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.11. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original. Related CVEs: * CVE-2021-23566: nanoid: Information disclosure via valueOf() function * CVE-2021-23648: sanitize-url: XSS * CVE-2021-41190: opencontainers: OCI manifest and index parsing confusion * CVE-2021-44906:...

RHSA-2022:5257: Red Hat Security Advisory: libinput security update

An update for libinput is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original. Related CVEs: * CVE-2022-1215: libinput: format string vulnerability may lead to privilege escalation

RHSA-2022:5331: Red Hat Security Advisory: libinput security update

An update for libinput is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original. Related CVEs: * CVE-2022-1215: libinput: format string vulnerability may lead to privilege escalation

Packet Storm: Latest News

Acronis Cyber Protect/Backup Remote Code Execution