It was discovered that libinput did not properly escape device
properties. A local attacker could possibly use this issue to inject
arbitrary udev properties and execute arbitrary code as root.