libinput vulnerability
It was discovered that libinput did not properly escape device properties. A local attacker could possibly use this issue to inject arbitrary udev properties and execute arbitrary code as root.
1.25.0-1ubuntu3.7
1.31.1-1ubuntu1.2