gpsd through release-3.27.5, fixed at commit 4c06658, contains a code injection vulnerability in the gpsprof utility that allows an attacker who controls GPS input data to execute arbitrary OS commands by injecting malicious content into the SKY.satellites[].used field, which is inserted unsanitized into a gnuplot heredoc data block. Attackers can supply a used value containing the string EOD to terminate the heredoc early and append gnuplot system() calls, achieving OS command execution as the user running gpsprof when the generated plot script is processed by gnuplot in polar mode.
CVSS Details
- CVSS 4.0 Base Score: 8.5 (HIGH)
- CVSS 4.0 Vector: (CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade gpsd | Sep 21, 2026 | Jul 23, 2026 |
| Redhat_linux | — | Upgrade gpsd-clientsUpgrade python3-gpsd-debuginfoUpgrade gpsd-minimal-clients-debuginfoUpgrade gpsd-debuginfoUpgrade gpsd-minimal-debuginfoUpgrade gpsd-debugsourceUpgrade gpsd-minimalUpgrade gpsd-minimal-debugsourceUpgrade gpsd-clients-debuginfoUpgrade gpsd-minimal-clientsUpgrade gpsdUpgrade python3-gpsd | Aug 13, 2026 | Jul 23, 2026 |
| Rocky_linux | — | Upgrade gpsd-debuginfoUpgrade gpsd-clientsUpgrade gpsdUpgrade gpsd-clients-debuginfoUpgrade gpsd-minimal-clientsUpgrade gpsd-minimal-debugsourceUpgrade python3-gpsdUpgrade gpsd-debugsourceUpgrade python3-gpsd-debuginfoUpgrade gpsd-minimal-debuginfoUpgrade gpsd-minimalUpgrade gpsd-minimal-clients-debuginfo | Sep 15, 2026 | Sep 9, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub