Bugzilla – Bug 1198111
VUL-0: CVE-2022-1215: libinput: format string vulnerability
Last modified: 2024-06-07 12:18:51 UTC
Created attachment 857846 [details] 0001-evdev-strip-the-device-name-of-format-directives.patch 0001-evdev-strip-the-device-name-of-format-directives.patch
Created attachment 857857 [details] 0001-evdev-strip-the-device-name-of-format-directives.patch incremental fixed patch 0001-evdev-strip-the-device-name-of-format-directives.patch
Scott, libinput is maintained by gnome-bugs, can you assign to an engineer?
Public on OSS mailing list, and on upstream advisory
The issue has been made public earlier than expected... @Mike, can you please submit to SUSE:SLE-12-SP1:Update and SUSE:SLE-15-SP4:Update? :)
SLE-12-SP1 has libinput 1.1.1. I'm not sure if it is affected. The announcement states that versions 1.10 and newer are affected.
SLES 12 SP1 libinpout does not use the sysname anywhere, so its not affected.
SUSE-SU-2022:1305-1: An update that fixes one vulnerability is now available. Category: security (important) Bug References: 1198111 CVE References: CVE-2022-1215 JIRA References: Sources used: openSUSE Leap 15.3 (src): libinput-1.10.5-150000.3.3.1 SUSE Manager Server 4.1 (src): libinput-1.10.5-150000.3.3.1 SUSE Manager Retail Branch Server 4.1 (src): libinput-1.10.5-150000.3.3.1 SUSE Manager Proxy 4.1 (src): libinput-1.10.5-150000.3.3.1 SUSE Linux Enterprise Server for SAP 15-SP2 (src): libinput-1.10.5-150000.3.3.1 SUSE Linux Enterprise Server for SAP 15-SP1 (src): libinput-1.10.5-150000.3.3.1 SUSE Linux Enterprise Server for SAP 15 (src): libinput-1.10.5-150000.3.3.1 SUSE Linux Enterprise Server 15-SP2-LTSS (src): libinput-1.10.5-150000.3.3.1 SUSE Linux Enterprise Server 15-SP2-BCL (src): libinput-1.10.5-150000.3.3.1 SUSE Linux Enterprise Server 15-SP1-LTSS (src): libinput-1.10.5-150000.3.3.1 SUSE Linux Enterprise Server 15-SP1-BCL (src): libinput-1.10.5-150000.3.3.1 SUSE Linux Enterprise Server 15-LTSS (src): libinput-1.10.5-150000.3.3.1 SUSE Linux Enterprise Realtime Extension 15-SP2 (src): libinput-1.10.5-150000.3.3.1 SUSE Linux Enterprise Module for Basesystem 15-SP3 (src): libinput-1.10.5-150000.3.3.1 SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS (src): libinput-1.10.5-150000.3.3.1 SUSE Linux Enterprise High Performance Computing 15-SP2-ESPOS (src): libinput-1.10.5-150000.3.3.1 SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS (src): libinput-1.10.5-150000.3.3.1 SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS (src): libinput-1.10.5-150000.3.3.1 SUSE Linux Enterprise High Performance Computing 15-LTSS (src): libinput-1.10.5-150000.3.3.1 SUSE Linux Enterprise High Performance Computing 15-ESPOS (src): libinput-1.10.5-150000.3.3.1 SUSE Enterprise Storage 7 (src): libinput-1.10.5-150000.3.3.1 SUSE Enterprise Storage 6 (src): libinput-1.10.5-150000.3.3.1 SUSE CaaS Platform 4.0 (src): libinput-1.10.5-150000.3.3.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
All done, closing.