Critical vulnerabilities in InputPlumber, a Linux input device management tool used in SteamOS, could allow attackers to inject commands into the graphical user interface and cause denial of service (DoS) conditions on affected systems.
See also: New React RSC vulnerabilities allow DoS and source code exposure

SUSE researchers have documented the issues with the identifiers CVE-2025-66005 and CVE-2025-14338 . The vulnerabilities affect versions of InputPlumber prior to v0.69.0 and are due to inadequate authorization mechanisms via D-Bus .
InputPlumber encapsulates Linux input devices into virtual devices and runs with full root privileges, which makes security vulnerabilities particularly dangerous. These vulnerabilities allow any user on the system, even with low privileges, to access InputPlumber's D-Bus service without authentication.
The impact primarily affects Linux gaming systems that use InputPlumber, including SteamOS. Valve has already released SteamOS 3.7.20, which incorporates the fixed InputPlumber v0.69.0.
See also: Vulnerability in NVIDIA Triton allows attackers to cause DoS attack

The project developers have resolved most of the issues by adopting proper authentication via Polkit, enabling authorization by default, and implementing systemd hardening mechanisms.
However, some improvements to the D-Bus API, which use file descriptors instead of pathnames, have not yet been integrated.
SUSE researchers recommend that system administrators immediately upgrade InputPlumber to v0.69.0 or later, especially on gaming systems and SteamOS installations.
See also: OpenVPN: Vulnerabilities allow DoS and bypass of security mechanisms

The coordinated responsible disclosure process between SUSE security researchers and InputPlumber developers ensured that fixes were available before the vulnerabilities were publicly announced.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
