HomeSecurityCritical vulnerabilities in InputPlumber allow DoS

Critical vulnerabilities in InputPlumber allow DoS

Critical vulnerabilities in InputPlumber, a Linux input device management tool used in SteamOS, could allow attackers to inject commands into the graphical user interface and cause denial of service (DoS) conditions on affected systems.

See also: New React RSC vulnerabilities allow DoS and source code exposure

InputPlumber

SUSE researchers have documented the issues with the identifiers CVE-2025-66005 and CVE-2025-14338 . The vulnerabilities affect versions of InputPlumber prior to v0.69.0 and are due to inadequate authorization mechanisms via D-Bus .

InputPlumber encapsulates Linux input devices into virtual devices and runs with full root privileges, which makes security vulnerabilities particularly dangerous. These vulnerabilities allow any user on the system, even with low privileges, to access InputPlumber's D-Bus service without authentication.

The impact primarily affects Linux gaming systems that use InputPlumber, including SteamOS. Valve has already released SteamOS 3.7.20, which incorporates the fixed InputPlumber v0.69.0.

See also: Vulnerability in NVIDIA Triton allows attackers to cause DoS attack

Critical vulnerabilities in InputPlumber allow DoS

The project developers have resolved most of the issues by adopting proper authentication via Polkit, enabling authorization by default, and implementing systemd hardening mechanisms.

However, some improvements to the D-Bus API, which use file descriptors instead of pathnames, have not yet been integrated.

SUSE researchers recommend that system administrators immediately upgrade InputPlumber to v0.69.0 or later, especially on gaming systems and SteamOS installations.

See also: OpenVPN: Vulnerabilities allow DoS and bypass of security mechanisms

Critical vulnerabilities in InputPlumber allow DoS

The coordinated responsible disclosure process between SUSE security researchers and InputPlumber developers ensured that fixes were available before the vulnerabilities were publicly announced.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS