CVE-2019-14822: Canonical Ubuntu Linux

High severity, CVSS 7.1. EPSS: 0.4% chance of exploitation in the next 30 days.

A flaw was discovered in ibus in versions before 1.5.22 that allows any unprivileged user to monitor and send method calls to the ibus bus of another user due to a misconfiguration in the DBus server setup. A local attacker may use this flaw to intercept all keystrokes of a victim user who is using the graphical interface, change the input method engine, or modify other input related configurations of the victim user.

Affected products

  • Canonical Ubuntu Linux: version 16.04 only; version 18.04 only; version 19.10 only
  • Ibus Project Ibus: before 1.5.22 (fixed in 1.5.22)
  • Oracle ZFS Storage Appliance Kit: version 8.8 only
  • Red Hat Enterprise Linux: version 7.0 only; version 8.0 only

Published 2019-11-25. Last modified 2026-06-17.