Arbitrary Code Injection Affecting gpsd package, versions <3.27.5-1


Severity

Recommended
0.0
high
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
0.27% (18th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIANUNSTABLE-GPSD-18300109
  • published25 Jul 2026
  • disclosed23 Jul 2026

Introduced: 23 Jul 2026

CVE-2026-60122  (opens in a new tab)
CWE-94  (opens in a new tab)

How to fix?

Upgrade Debian:unstable gpsd to version 3.27.5-1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream gpsd package and not the gpsd package as distributed by Debian. See How to fix? for Debian:unstable relevant fixed versions and status.

gpsd through release-3.27.5, fixed at commit 4c06658, contains a code injection vulnerability in the gpsprof utility that allows an attacker who controls GPS input data to execute arbitrary OS commands by injecting malicious content into the SKY.satellites[].used field, which is inserted unsanitized into a gnuplot heredoc data block. Attackers can supply a used value containing the string EOD to terminate the heredoc early and append gnuplot system() calls, achieving OS command execution as the user running gpsprof when the generated plot script is processed by gnuplot in polar mode.

CVSS Base Scores

version 3.1