CVE-2019-14822: Canonical Ubuntu Linux
High severity, CVSS 7.1. EPSS: 0.4% chance of exploitation in the next 30 days.
A flaw was discovered in ibus in versions before 1.5.22 that allows any unprivileged user to monitor and send method calls to the ibus bus of another user due to a misconfiguration in the DBus server setup. A local attacker may use this flaw to intercept all keystrokes of a victim user who is using the graphical interface, change the input method engine, or modify other input related configurations of the victim user.
Affected products
- Canonical Ubuntu Linux: version 16.04 only; version 18.04 only; version 19.10 only
- Ibus Project Ibus: before 1.5.22 (fixed in 1.5.22)
- Oracle ZFS Storage Appliance Kit: version 8.8 only
- Red Hat Enterprise Linux: version 7.0 only; version 8.0 only
Published 2019-11-25. Last modified 2026-06-17.