We believe that the bug you reported is fixed in the latest version of
gpsd, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1141962@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Boian Bonev <bbonev@ipacct.com> (supplier of updated gpsd package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sat, 25 Jul 2026 21:16:01 +0000
Source: gpsd
Architecture: source
Version: 3.27.5-1
Distribution: unstable
Urgency: medium
Maintainer: Boian Bonev <bbonev@ipacct.com>
Changed-By: Boian Bonev <bbonev@ipacct.com>
Closes: 1141962
Changes:
gpsd (3.27.5-1) unstable; urgency=medium
.
* Fix CVE-2026-58459 (Closes: #1141962). A command injection
vulnerability exists in the gpsprof client. The subtype field,
sourced from a DEVICES JSON log entry or an NMEA PGRMT sentence, is
written into the generated gnuplot program via a set title statement
with only double quote characters escaped. An attacker who controls
the GPS device subtype can embed backtick payloads and execute
arbitrary shell commands as the user running gnuplot when the
generated plot is rendered.
* Fix CVE-2026-60122. A code injection vulnerability exists in the
gpsprof client. The SKY.satellites[].used field is inserted
unsanitized into a gnuplot heredoc data block. An attacker who
controls the GPS input data can supply a used value containing the
string EOD to terminate the heredoc early and append gnuplot
system() calls, achieving OS command execution as the user running
gpsprof when the generated plot script is processed by gnuplot in
polar mode.
* Bump standards to 4.7.4, no changes
* Bump dh to 14
* Remove redundant prio
Checksums-Sha1:
08e4a9af882c216bd0d68f2be03d646f47922b00 3107 gpsd_3.27.5-1.dsc
0bfe688b8264161b2dad3c55ae08866349a66e8c 50600 gpsd_3.27.5-1.debian.tar.xz
cc797304da114e9842d7ef17cbef2aac67699a27 21027 gpsd_3.27.5-1_amd64.buildinfo
Checksums-Sha256:
74e6b6e323a7099db6e4c78e9a35ea11dc98f818eed85e4a3334ac9036fde2cc 3107 gpsd_3.27.5-1.dsc
be36d737fc0323d3461554abe80ca3a6263740f48c9aec046d353f84021ffcd6 50600 gpsd_3.27.5-1.debian.tar.xz
43e2daa575cce3f05f37c3405bcb70a77d27293c49a3583af87e95eaa4fe63e7 21027 gpsd_3.27.5-1_amd64.buildinfo
Files:
10b0724d7f05cc68c4cfd7eb2dc49c64 3107 misc optional gpsd_3.27.5-1.dsc
c8a64a90969c5587dd38ee7d76674e56 50600 misc optional gpsd_3.27.5-1.debian.tar.xz
2104bc3d9418d5ab391e7fc806a2f1e5 21027 misc optional gpsd_3.27.5-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQJGBAEBCgAwFiEEumC8IPN+WURNbSUAE2VyCRPS8i0FAmplNcASHGJib25ldkBp
cGFjY3QuY29tAAoJEBNlcgkT0vIty50P/R/3dLaLbK6OUy41/imKaazh1b6miW9/
YRKHux9x7P6GPqSxoeGpyjFoFEU78RandIL5j0xXfjso1ENABpeYrXr48BxUNbyk
zTZ8PJnh5sy+41+vWDVOHL+GubY835I7oU16dqkrXdFsBiCLVZRctimUaeJ9sruK
9gvlrC04mB4cpPxivPG14AYg0RKLWram5CerwpOvuTGDY/1fWNgcV1oDxGfwLQoB
AWMlkYEochUdcCSlfxCUqTCmYcLBi0BM8Dm10JL/ex3+A/tQHf+5alvZ/DmCe9GD
e1aoDQvPBG7fmMk/RU6pi6NOMBCKmUOlL5PEd0T7RcUdRQwnkIVPIw0u/NqfUIh3
JvhrXjFSL+WOXAw0yukSUQuM/Yc37JcjAqs3rQXaLDvuBOrvTHQA+5ooZpEpDDmx
axdZuwubTzK5cMuh7JpcbT06MkUwkvH06Z2O/FI11TXrNnlLZ4ur5bd7KciG6stK
hZLsqb3MMp3ffMZym+P44gehay79Gy5JqZNk8vIsYyaQJM2R94EcTr0xYvorqstF
87BtDmD1dzL1JIfYCZ9czn+lXmS9oBgvhCFGbcM4efFl7XZTBHY+TtTN5ruFjsVt
mtdVaO1lGAC7b9/1q0kNh/y01ruksVLYOhrHhYJ0y3UPpWHCct/eo9dG83rwI7sR
fwwXo+D68OxW
=RPq1
-----END PGP SIGNATURE-----