libinput vulnerability
It was discovered that libinput did not properly escape device properties. A local attacker could possibly use this issue to inject arbitrary udev properties and execute arbitrary code as root.
1.20.0-1ubuntu0.4
1.15.5-1ubuntu0.3+esm1