PT-2026-56825 · Gpsd+1 · Gpsd+1

·

CVE-2026-58459

·

Published

2026-07-09

·

Updated

2026-08-06

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions gpsd versions prior to 3.27.6
Description A command injection issue exists in the gpsprof tool. Attackers who can control the GPS device subtype value can execute arbitrary shell commands by embedding backtick payloads in the gnuplot plot title. This occurs because the subtype field, sourced from a DEVICES JSON log entry or NMEA PGRMT sentence, is written into a generated gnuplot program via a set title statement where only double-quote characters are escaped. The execution happens as the user running gnuplot when the plot is rendered through the gpsprof and gnuplot workflow.
Recommendations Update to the version containing commit 4c06658 or newer.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:51075
ALSA-2026:51153
CVE-2026-58459
OPENSUSE-SU-2026:11276-1
RHSA-2026:51075
RHSA-2026:51153

Affected Products

Rocky Linux
Gpsd