InputPlumber versions before v0.63.0 can lead to local Denial-of-Service,
information leak or even privilege escalation in the context of the
currently active user session.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 15 Jan 2026 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Shadowblip
Shadowblip inputplumber |
|
| Vendors & Products |
Shadowblip
Shadowblip inputplumber |
Wed, 14 Jan 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 14 Jan 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Lack of authorization of the InputManager D-Bus interface in InputPlumber versions before v0.63.0 can lead to local Denial-of-Service, information leak or even privilege escalation in the context of the currently active user session. | |
| Title | Lack of Authentication in the InputManager D-Bus interface | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: suse
Published:
Updated: 2026-01-14T15:46:07.870Z
Reserved: 2025-11-19T08:52:54.077Z
Link: CVE-2025-66005
Updated: 2026-01-14T15:29:52.478Z
Status : Awaiting Analysis
Published: 2026-01-14T12:16:32.100
Modified: 2026-01-14T16:25:12.057
Link: CVE-2025-66005
No data.
OpenCVE Enrichment
Updated: 2026-01-15T08:03:42Z