gpsd before commit dc966aa contains a heap-based out-of-bounds write vulnerability in the drivers/driver_nmea2000.c file. The hnd_129540 function, which handles NMEA2000 PGN 129540 (GNSS Satellites in View) packets, fails to validate the user-supplied satellite count against the size of the skyview array (184 elements). This allows an attacker to write beyond the bounds of the array by providing a satellite count up to 255, leading to memory corruption, Denial of Service (DoS), and potentially arbitrary code execution.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade gpsd-minimal-clientsUpgrade gpsd-minimal | Jan 22, 2026 | Jan 19, 2026 |
| Debian | — | Upgrade gpsd | Jan 20, 2026 | Jan 20, 2026 |
| Oracle_linux | — | Upgrade gpsd-clientsUpgrade python3-gpsdUpgrade gpsdUpgrade gpsd-minimal-clientsUpgrade gpsd-minimal | Jan 20, 2026 | Jan 2, 2026 |
| Redhat_linux | — | Upgrade gpsd-minimal-clients-debuginfoUpgrade gpsd-minimal-clientsUpgrade gpsdUpgrade python3-gpsd-debuginfoUpgrade gpsd-clientsUpgrade gpsd-minimal-debugsourceUpgrade gpsd-clients-debuginfoUpgrade gpsd-debuginfoUpgrade gpsd-minimalUpgrade python3-gpsdUpgrade gpsd-minimal-debuginfoUpgrade gpsd-debugsource | Jan 20, 2026 | Jan 2, 2026 |
| Rocky_linux | — | Upgrade gpsd-minimal-clientsUpgrade gpsd-minimal-debuginfoUpgrade gpsd-minimalUpgrade python3-gpsdUpgrade gpsd-clientsUpgrade gpsd-debugsourceUpgrade python3-gpsd-debuginfoUpgrade gpsd-minimal-clients-debuginfoUpgrade gpsd-minimal-debugsourceUpgrade gpsdUpgrade gpsd-clients-debuginfoUpgrade gpsd-debuginfo | Jan 22, 2026 | Jan 20, 2026 |
| Ubuntu | — | Upgrade gpsdUpgrade libgps30t64Upgrade libgps28 | Jan 9, 2026 | Jan 2, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | May 27, 2026 | Jan 2, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub