{"id":181900,"date":"2026-06-05T02:48:04","date_gmt":"2026-06-05T00:48:04","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/libinput-1-31-3-s-ispravleniem-uyazvimosti-vedushhej-k-vypolneniyu-koda-ot-root"},"modified":"2026-06-05T02:48:04","modified_gmt":"2026-06-05T00:48:04","slug":"libinput-1-31-3-s-ispravleniem-uyazvimosti-vedushhej-k-vypolneniyu-koda-ot-root","status":"publish","type":"post","link":"https:\/\/prohoster.info\/ro\/blog\/news\/libinput-1-31-3-s-ispravleniem-uyazvimosti-vedushhej-k-vypolneniyu-koda-ot-root","title":{"rendered":"libinput 1.31.3 cu corectura vulnerabilit\u0103\u021bii care duce la executarea codului de la root","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>A fost publicat un release corectiv <strong>libinput 1.31.3<\/strong> \u2014 o bibliotec\u0103 pentru procesarea dispozitivelor de input, utilizat\u0103 de desktopurile moderne Linux \u00een combina\u021bie cu compozitorii Wayland \u0219i X.Org. libinput este responsabil\u0103 pentru detectarea dispozitivelor, procesarea evenimentelor \u0219i abstractizarea inputului: de la mouse-uri \u0219i touchpad-uri p\u00e2n\u0103 la tablete grafice. Proiectul este distribuit sub licen\u021ba MIT.<\/p>\n<p><noindex><noindex><\/p>\n<p>Principala modificare a release-ului este <a rel=\"nofollow\" href=\"https:\/\/www.phoronix.com\/news\/libinput-1.31.2-Security-Fix\">corectarea unei vulnerabilit\u0103\u021bi<\/a> \u00een programul auxiliar udev <strong>libinput-device-group<\/strong>. Problema era legat\u0103 de faptul c\u0103 valoarea PHYS, ob\u021binut\u0103 de la dispozitiv, era inclus\u0103 \u00een ie\u0219ire pentru udev sub form\u0103 de \u0219ir KEY=VALUE f\u0103r\u0103 o cur\u0103\u021bare adecvat\u0103 a caracterelor speciale. Un dispozitiv mali\u021bios, creat prin <strong>uinput<\/strong> sau <strong>uhid<\/strong>, putea introduce \u00een PHYS un caracter de linie nou\u0103, ceea ce f\u0103cea ca udev s\u0103 perceap\u0103 ie\u0219irea ca fiind dou\u0103 variabile separate. Aceasta ar fi putut duce la executarea de cod arbitrar cu privilegii de root.<\/p>\n<p><\/noindex><\/noindex><\/p>\n<p>Vulnerabilitatea nu este de la distan\u021b\u0103: atacatorul are nevoie de acces local \u0219i de posibilitatea de a crea un dispozitiv mali\u021bios de tip uinput sau uhid. Accesul la astfel de interfe\u021be este, \u00een general, limitat la root, dar riscul apare pe sistemele cu reguli udev mai permisive. Ca exemplu, se men\u021bioneaz\u0103 configura\u021bii unde accesul este deschis utilizatorilor obi\u0219nui\u021bi conecta\u021bi la sistem pentru a sus\u021bine controlerele de joc \u0219i Steam Input, de exemplu prin pachetul <strong>steam-devices<\/strong> sau reguli similare.<\/p>\n<p>Precizare important\u0103: anterior, \u00een \u0219tiri a fost men\u021bionat\u0103 versiunea <strong>libinput 1.31.2<\/strong>, dar \u00een advisory-ul oficial, versiunile corectate men\u021bionate sunt <strong>libinput 1.31.3<\/strong> \u0219i <strong>1.30.4<\/strong>. Sunt afectate versiunile p\u00e2n\u0103 la <strong>1.31.2<\/strong> \u0219i <strong>1.30.3<\/strong> inclusiv; CVE la momentul public\u0103rii \u00eenc\u0103 nu fusese alocat.<\/p>\n<p><noindex><\/p>\n<p>Utilizatorilor li se recomand\u0103 s\u0103 actualizeze pachetul de sistem <strong>libinput<\/strong> prin managerul de pachete standard al distribu\u021biei. \u00cen Arch Linux <a rel=\"nofollow\" href=\"https:\/\/archlinux.org\/packages\/extra\/x86_64\/libinput\/\">package<\/a> <strong>libinput 1.31.3-1<\/strong> a ap\u0103rut deja \u00een depozitul Extra pe 4 iunie 2026, \u00een Debian versiunea <strong>1.31.3-1<\/strong> a fost acceptat\u0103 \u00een unstable \u00een aceea\u0219i zi.<\/p>\n<p><\/noindex><\/p>\n<p>Sursa: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.linux.org.ru\/news\/opensource\/18310635\">linux.org.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u0443\u044e\u0449\u0438\u0439 \u0432\u044b\u043f\u0443\u0441\u043a libinput 1.31.3 \u2014 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0438 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0438 \u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432 \u0432\u0432\u043e\u0434\u0430, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u043e\u0439 \u0441\u043e\u0432\u0440\u0435\u043c\u0435\u043d\u043d\u044b\u043c\u0438 Linux-\u0434\u0435\u0441\u043a\u0442\u043e\u043f\u0430\u043c\u0438 \u0432 \u0441\u0432\u044f\u0437\u043a\u0435 \u0441 Wayland-\u043a\u043e\u043c\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0430\u043c\u0438 \u0438 X.Org. libinput \u043e\u0442\u0432\u0435\u0447\u0430\u0435\u0442 \u0437\u0430 \u043e\u0431\u043d\u0430\u0440\u0443\u0436\u0435\u043d\u0438\u0435 \u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432, \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0443 \u0441\u043e\u0431\u044b\u0442\u0438\u0439 \u0438 \u0430\u0431\u0441\u0442\u0440\u0430\u043a\u0446\u0438\u044e \u0432\u0432\u043e\u0434\u0430: \u043e\u0442 \u043c\u044b\u0448\u0435\u0439 \u0438 \u0442\u0430\u0447\u043f\u0430\u0434\u043e\u0432 \u0434\u043e \u0433\u0440\u0430\u0444\u0438\u0447\u0435\u0441\u043a\u0438\u0445 \u043f\u043b\u0430\u043d\u0448\u0435\u0442\u043e\u0432. \u041f\u0440\u043e\u0435\u043a\u0442 \u0440\u0430\u0441\u043f\u0440\u043e\u0441\u0442\u0440\u0430\u043d\u044f\u0435\u0442\u0441\u044f \u043f\u043e\u0434 \u043b\u0438\u0446\u0435\u043d\u0437\u0438\u0435\u0439 MIT. \u0413\u043b\u0430\u0432\u043d\u043e\u0435 \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u0435 \u0432\u044b\u043f\u0443\u0441\u043a\u0430 \u2014 \u0438\u0441\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 udev-\u0432\u0441\u043f\u043e\u043c\u043e\u0433\u0430\u0442\u0435\u043b\u044c\u043d\u043e\u0439 \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u0435 libinput-device-group. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u0431\u044b\u043b\u0430 \u0441\u0432\u044f\u0437\u0430\u043d\u0430 \u0441 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":8,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-181900","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u0443\u044e\u0449\u0438\u0439 \u0432\u044b\u043f\u0443\u0441\u043a libinput 1.31.3 \u2014 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0438 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0438 \u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432 \u0432\u0432\u043e\u0434\u0430, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u043e\u0439 \u0441\u043e\u0432\u0440\u0435\u043c\u0435\u043d\u043d\u044b\u043c\u0438 Linux-\u0434\u0435\u0441\u043a\u0442\u043e\u043f\u0430\u043c\u0438 \u0432 \u0441\u0432\u044f\u0437\u043a\u0435 \u0441 Wayland-\u043a\u043e\u043c\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0430\u043c\u0438 \u0438 X.Org.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Erik Peterson\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/ro\/blog\/news\/libinput-1-31-3-s-ispravleniem-uyazvimosti-vedushhej-k-vypolneniyu-koda-ot-root\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"ro_RO\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47libinput 1.31.3 \u0441 \u0438\u0441\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u0435\u043c \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438, \u0432\u0435\u0434\u0443\u0449\u0435\u0439 \u043a \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044e \u043a\u043e\u0434\u0430 \u043e\u0442 root | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u0443\u044e\u0449\u0438\u0439 \u0432\u044b\u043f\u0443\u0441\u043a libinput 1.31.3 \u2014 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0438 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0438 \u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432 \u0432\u0432\u043e\u0434\u0430, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u043e\u0439 \u0441\u043e\u0432\u0440\u0435\u043c\u0435\u043d\u043d\u044b\u043c\u0438 Linux-\u0434\u0435\u0441\u043a\u0442\u043e\u043f\u0430\u043c\u0438 \u0432 \u0441\u0432\u044f\u0437\u043a\u0435 \u0441 Wayland-\u043a\u043e\u043c\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0430\u043c\u0438 \u0438 X.Org.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/ro\/blog\/news\/libinput-1-31-3-s-ispravleniem-uyazvimosti-vedushhej-k-vypolneniyu-koda-ot-root\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-06-05T00:48:04+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-06-05T00:48:04+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47libinput 1.31.3 cu corectarea vulnerabilit\u0103\u021bii care duce la executarea de cod de la root | ProHoster","description":"A fost publicat un release corectiv libinput 1.31.3 \u2014 o bibliotec\u0103 pentru procesarea dispozitivelor de input, utilizat\u0103 de desktopurile moderne Linux \u00een combina\u021bie cu compozitorii Wayland \u0219i X.Org.","canonical_url":"https:\/\/prohoster.info\/ro\/blog\/news\/libinput-1-31-3-s-ispravleniem-uyazvimosti-vedushhej-k-vypolneniyu-koda-ot-root","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"ro_RO","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47libinput 1.31.3 \u0441 \u0438\u0441\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u0435\u043c \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438, \u0432\u0435\u0434\u0443\u0449\u0435\u0439 \u043a \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u044e \u043a\u043e\u0434\u0430 \u043e\u0442 root | ProHoster","og:description":"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u043a\u043e\u0440\u0440\u0435\u043a\u0442\u0438\u0440\u0443\u044e\u0449\u0438\u0439 \u0432\u044b\u043f\u0443\u0441\u043a libinput 1.31.3 \u2014 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0438 \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0438 \u0443\u0441\u0442\u0440\u043e\u0439\u0441\u0442\u0432 \u0432\u0432\u043e\u0434\u0430, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u043e\u0439 \u0441\u043e\u0432\u0440\u0435\u043c\u0435\u043d\u043d\u044b\u043c\u0438 Linux-\u0434\u0435\u0441\u043a\u0442\u043e\u043f\u0430\u043c\u0438 \u0432 \u0441\u0432\u044f\u0437\u043a\u0435 \u0441 Wayland-\u043a\u043e\u043c\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0430\u043c\u0438 \u0438 X.Org.","og:url":"https:\/\/prohoster.info\/ro\/blog\/news\/libinput-1-31-3-s-ispravleniem-uyazvimosti-vedushhej-k-vypolneniyu-koda-ot-root","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2026-06-05T00:48:04+00:00","article:modified_time":"2026-06-05T00:48:04+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":[],"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/181900","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/comments?post=181900"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/181900\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/media?parent=181900"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/categories?post=181900"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/tags?post=181900"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}