gpsd before commit dc966aa contains a heap-based out-of-bounds write vulnerability in the drivers/driver_nmea2000.c file. The hnd_129540 function, which handles NMEA2000 PGN 129540 (GNSS Satellites in View) packets, fails to validate the user-supplied satellite count against the size of the skyview array (184 elements). This allows an attacker to write beyond the bounds of the array by providing a satellite count up to 255, leading to memory corruption, Denial of Service (DoS), and potentially arbitrary code execution.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade gpsd-minimalUpgrade gpsd-minimal-clients | Jan 22, 2026 | Jan 19, 2026 |
| Debian | — | Upgrade gpsd | Jan 20, 2026 | Jan 20, 2026 |
| Oracle_linux | — | Upgrade python3-gpsdUpgrade gpsd-clientsUpgrade gpsdUpgrade gpsd-minimal-clientsUpgrade gpsd-minimal | Jan 20, 2026 | Jan 2, 2026 |
| Redhat_linux | — | Upgrade gpsd-clientsUpgrade gpsd-minimal-clients-debuginfoUpgrade gpsd-clients-debuginfoUpgrade gpsd-debuginfoUpgrade python3-gpsd-debuginfoUpgrade gpsd-minimal-clientsUpgrade gpsd-minimal-debugsourceUpgrade gpsdUpgrade gpsd-minimalUpgrade gpsd-debugsourceUpgrade python3-gpsdUpgrade gpsd-minimal-debuginfo | Jan 20, 2026 | Jan 2, 2026 |
| Rocky_linux | — | Upgrade python3-gpsdUpgrade gpsd-minimal-debuginfoUpgrade gpsd-debugsourceUpgrade gpsd-minimal-clientsUpgrade gpsd-clientsUpgrade gpsd-minimalUpgrade python3-gpsd-debuginfoUpgrade gpsdUpgrade gpsd-minimal-debugsourceUpgrade gpsd-clients-debuginfoUpgrade gpsd-debuginfoUpgrade gpsd-minimal-clients-debuginfo | Jan 22, 2026 | Jan 20, 2026 |
| Ubuntu | — | Upgrade libgps28Upgrade libgps30t64Upgrade gpsd | Jan 9, 2026 | Jan 2, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | May 27, 2026 | Jan 2, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub