{"id":181900,"date":"2026-06-05T02:48:04","date_gmt":"2026-06-05T00:48:04","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/libinput-1-31-3-s-ispravleniem-uyazvimosti-vedushhej-k-vypolneniyu-koda-ot-root"},"modified":"2026-06-05T02:48:04","modified_gmt":"2026-06-05T00:48:04","slug":"libinput-1-31-3-s-ispravleniem-uyazvimosti-vedushhej-k-vypolneniyu-koda-ot-root","status":"publish","type":"post","link":"https:\/\/prohoster.info\/fr\/blog\/news\/libinput-1-31-3-s-ispravleniem-uyazvimosti-vedushhej-k-vypolneniyu-koda-ot-root","title":{"rendered":"libinput 1.31.3 corrige une vuln\u00e9rabilit\u00e9 permettant l'ex\u00e9cution de code avec les privil\u00e8ges root","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Publication d'une mise \u00e0 jour corrective <strong>libinput 1.31.3<\/strong> \u2014 une biblioth\u00e8que de traitement des dispositifs d'entr\u00e9e utilis\u00e9e par les environnement de bureau Linux modernes en association avec les compositeurs Wayland et X.Org. libinput est responsable de la d\u00e9tection des dispositifs, du traitement des \u00e9v\u00e9nements et de l'abstraction des entr\u00e9es : des souris et des pav\u00e9s tactiles aux tablettes graphiques. Le projet est distribu\u00e9 sous la licence MIT.<\/p>\n<p><noindex><noindex><\/p>\n<p>Le principal changement de cette version est <a rel=\"nofollow\" href=\"https:\/\/www.phoronix.com\/news\/libinput-1.31.2-Security-Fix\">la correction d'une vuln\u00e9rabilit\u00e9<\/a> dans l'outil d'assistance udev <strong>libinput-device-group<\/strong>. Le probl\u00e8me \u00e9tait li\u00e9 \u00e0 la valeur PHYS, obtenue du dispositif, qui \u00e9tait int\u00e9gr\u00e9e dans la sortie pour udev sous forme de cha\u00eene KEY=VALUE sans un nettoyage ad\u00e9quat des caract\u00e8res sp\u00e9ciaux. Un dispositif malveillant cr\u00e9\u00e9 via <strong>uinput<\/strong> ou <strong>ou<\/strong>uhid<\/p>\n<p><\/noindex><\/noindex><\/p>\n<p>, pouvait introduire un caract\u00e8re de retour \u00e0 la ligne dans PHYS, ce qui amenait udev \u00e0 traiter la sortie comme deux variables distinctes. Cela pouvait potentiellement conduire \u00e0 l'ex\u00e9cution de code arbitraire avec des droits root. <strong>La vuln\u00e9rabilit\u00e9 n'est pas \u00e0 distance : l'attaquant a besoin d'un acc\u00e8s local et de la possibilit\u00e9 de cr\u00e9er un dispositif uinput ou uhid malveillant. G\u00e9n\u00e9ralement, l'acc\u00e8s \u00e0 ces interfaces est restreint \u00e0 root, mais des risques se pr\u00e9sentent sur des syst\u00e8mes avec des r\u00e8gles udev plus larges. \u00c0 titre d'exemple, des configurations o\u00f9 l'acc\u00e8s est ouvert aux utilisateurs normaux pour le soutien des contr\u00f4leurs de jeux et de Steam Input, par exemple via le package<\/strong> steam-devices<\/p>\n<p>ou des r\u00e8gles similaires. <strong>\u00c0 noter : une version<\/strong>libinput 1.31.2 <strong>libinput 1.31.3<\/strong> et <strong>1.30.4<\/strong>, mentionn\u00e9e pr\u00e9c\u00e9demment dans les nouvelles, a \u00e9t\u00e9 corrig\u00e9e dans l'avis officiel avec les versions corrig\u00e9es indiqu\u00e9es. <strong>1.31.2<\/strong> et <strong>1.30.3<\/strong> Les versions jusqu'\u00e0<\/p>\n<p><noindex><\/p>\n<p>inclusivement ; le CVE n'avait pas encore \u00e9t\u00e9 attribu\u00e9 au moment de la publication. <strong>Les utilisateurs sont invit\u00e9s \u00e0 mettre \u00e0 jour le package syst\u00e8me<\/strong> libinput <a rel=\"nofollow\" href=\"https:\/\/archlinux.org\/packages\/extra\/x86_64\/libinput\/\">via le gestionnaire de packages standard de leur distribution. Sur Arch Linux,<\/a> <strong>le package<\/strong> libinput 1.31.3-1 <strong>1.31.3-1<\/strong> est d\u00e9j\u00e0 disponible dans le d\u00e9p\u00f4t Extra depuis le 4 juin 2026, tandis qu'en Debian, la version<\/p>\n<p><\/noindex><\/p>\n<p>Source : <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.linux.org.ru\/news\/opensource\/18310635\">linux.org.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u0443\u044e\u0449\u0438\u0439 \u0432\u044b\u043f\u0443\u0441\u043a libinput 1.31.3 \u2014 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0438 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0438 \u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432 \u0432\u0432\u043e\u0434\u0430, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u043e\u0439 \u0441\u043e\u0432\u0440\u0435\u043c\u0435\u043d\u043d\u044b\u043c\u0438 Linux-\u0434\u0435\u0441\u043a\u0442\u043e\u043f\u0430\u043c\u0438 \u0432 \u0441\u0432\u044f\u0437\u043a\u0435 \u0441 Wayland-\u043a\u043e\u043c\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0430\u043c\u0438 \u0438 X.Org. libinput \u043e\u0442\u0432\u0435\u0447\u0430\u0435\u0442 \u0437\u0430 \u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0435\u043d\u0438\u0435 \u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432, \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0443 \u0441\u043e\u0431\u044b\u0442\u0438\u0439 \u0438 \u0430\u0431\u0441\u0442\u0440\u0430\u043a\u0446\u0438\u044e \u0432\u0432\u043e\u0434\u0430: \u043e\u0442 \u043c\u044b\u0448\u0435\u0439 \u0438 \u0442\u0430\u0447\u043f\u0430\u0434\u043e\u0432 \u0434\u043e \u0433\u0440\u0430\u0444\u0438\u0447\u0435\u0441\u043a\u0438\u0445 \u043f\u043b\u0430\u043d\u0448\u0435\u0442\u043e\u0432. \u041f\u0440\u043e\u0435\u043a\u0442 \u0440\u0430\u0441\u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u044f\u0435\u0442\u0441\u044f \u043f\u043e\u0434 \u043b\u0438\u0446\u0435\u043d\u0437\u0438\u0435\u0439 MIT. \u0413\u043b\u0430\u0432\u043d\u043e\u0435 \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u0435 \u0432\u044b\u043f\u0443\u0441\u043a\u0430 \u2014 \u0438\u0441\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 udev-\u0432\u0441\u043f\u043e\u043c\u043e\u0433\u0430\u0442\u0435\u043b\u044c\u043d\u043e\u0439 \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u0435 libinput-device-group. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u0431\u044b\u043b\u0430 \u0441\u0432\u044f\u0437\u0430\u043d\u0430 \u0441 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":8,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-181900","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u0443\u044e\u0449\u0438\u0439 \u0432\u044b\u043f\u0443\u0441\u043a libinput 1.31.3 \u2014 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0438 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0438 \u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432 \u0432\u0432\u043e\u0434\u0430, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u043e\u0439 \u0441\u043e\u0432\u0440\u0435\u043c\u0435\u043d\u043d\u044b\u043c\u0438 Linux-\u0434\u0435\u0441\u043a\u0442\u043e\u043f\u0430\u043c\u0438 \u0432 \u0441\u0432\u044f\u0437\u043a\u0435 \u0441 Wayland-\u043a\u043e\u043c\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0430\u043c\u0438 \u0438 X.Org.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Erik Peterson\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/fr\/blog\/news\/libinput-1-31-3-s-ispravleniem-uyazvimosti-vedushhej-k-vypolneniyu-koda-ot-root\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"fr_FR\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47libinput 1.31.3 \u0441 \u0438\u0441\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u0435\u043c \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438, \u0432\u0435\u0434\u0443\u0449\u0435\u0439 \u043a \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044e \u043a\u043e\u0434\u0430 \u043e\u0442 root | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u0443\u044e\u0449\u0438\u0439 \u0432\u044b\u043f\u0443\u0441\u043a libinput 1.31.3 \u2014 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0438 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0438 \u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432 \u0432\u0432\u043e\u0434\u0430, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u043e\u0439 \u0441\u043e\u0432\u0440\u0435\u043c\u0435\u043d\u043d\u044b\u043c\u0438 Linux-\u0434\u0435\u0441\u043a\u0442\u043e\u043f\u0430\u043c\u0438 \u0432 \u0441\u0432\u044f\u0437\u043a\u0435 \u0441 Wayland-\u043a\u043e\u043c\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0430\u043c\u0438 \u0438 X.Org.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/fr\/blog\/news\/libinput-1-31-3-s-ispravleniem-uyazvimosti-vedushhej-k-vypolneniyu-koda-ot-root\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-06-05T00:48:04+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-06-05T00:48:04+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47libinput 1.31.3 corrige la vuln\u00e9rabilit\u00e9 entra\u00eenant l'ex\u00e9cution de code par root | ProHoster","description":"a \u00e9t\u00e9 accept\u00e9e dans unstable le m\u00eame jour.","canonical_url":"https:\/\/prohoster.info\/fr\/blog\/news\/libinput-1-31-3-s-ispravleniem-uyazvimosti-vedushhej-k-vypolneniyu-koda-ot-root","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"fr_FR","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47libinput 1.31.3 \u0441 \u0438\u0441\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u0435\u043c \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438, \u0432\u0435\u0434\u0443\u0449\u0435\u0439 \u043a \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044e \u043a\u043e\u0434\u0430 \u043e\u0442 root | ProHoster","og:description":"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u0443\u044e\u0449\u0438\u0439 \u0432\u044b\u043f\u0443\u0441\u043a libinput 1.31.3 \u2014 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0438 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0438 \u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432 \u0432\u0432\u043e\u0434\u0430, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u043e\u0439 \u0441\u043e\u0432\u0440\u0435\u043c\u0435\u043d\u043d\u044b\u043c\u0438 Linux-\u0434\u0435\u0441\u043a\u0442\u043e\u043f\u0430\u043c\u0438 \u0432 \u0441\u0432\u044f\u0437\u043a\u0435 \u0441 Wayland-\u043a\u043e\u043c\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0430\u043c\u0438 \u0438 X.Org.","og:url":"https:\/\/prohoster.info\/fr\/blog\/news\/libinput-1-31-3-s-ispravleniem-uyazvimosti-vedushhej-k-vypolneniyu-koda-ot-root","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2026-06-05T00:48:04+00:00","article:modified_time":"2026-06-05T00:48:04+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":[],"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/181900","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/comments?post=181900"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/181900\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/media?parent=181900"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/categories?post=181900"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/tags?post=181900"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}