Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-51075

Опубликовано: 06 авг. 2026
Источник: oracle-oval
Платформа: Oracle Linux 10

Описание

ELSA-2026-51075: gpsd security update (IMPORTANT)

[3.26.1-3.0.1.el10_2.1]

  • Replace upstream reference [Orabug: 37033219]

[1:3.26.1-3.el10_2.1]

  • fix command injection in gpsprof (CVE-2026-58459)

Обновленные пакеты

Oracle Linux 10

Oracle Linux aarch64

gpsd

3.26.1-3.0.1.el10_2.1

gpsd-clients

3.26.1-3.0.1.el10_2.1

python3-gpsd

3.26.1-3.0.1.el10_2.1

Oracle Linux x86_64

gpsd

3.26.1-3.0.1.el10_2.1

gpsd-clients

3.26.1-3.0.1.el10_2.1

python3-gpsd

3.26.1-3.0.1.el10_2.1

Связанные CVE

Связанные уязвимости

CVSS3: 7.8
ubuntu
2 месяца назад

gpsd through release-3.27.5, fixed at commit 4c06658, contains a command injection vulnerability in gpsprof that allows attackers who control the GPS device subtype value to execute arbitrary shell commands by embedding backtick payloads in the gnuplot plot title without proper escaping. The subtype field sourced from a DEVICES JSON log entry or NMEA PGRMT sentence is written into a generated gnuplot program via a set title statement with only double-quote characters escaped, enabling arbitrary shell command execution as the user running gnuplot when the victim renders the generated plot through the gpsprof and gnuplot workflow.

CVSS3: 7.8
redhat
2 месяца назад

gpsd through release-3.27.5, fixed at commit 4c06658, contains a command injection vulnerability in gpsprof that allows attackers who control the GPS device subtype value to execute arbitrary shell commands by embedding backtick payloads in the gnuplot plot title without proper escaping. The subtype field sourced from a DEVICES JSON log entry or NMEA PGRMT sentence is written into a generated gnuplot program via a set title statement with only double-quote characters escaped, enabling arbitrary shell command execution as the user running gnuplot when the victim renders the generated plot through the gpsprof and gnuplot workflow.

CVSS3: 7.8
nvd
2 месяца назад

gpsd through release-3.27.5, fixed at commit 4c06658, contains a command injection vulnerability in gpsprof that allows attackers who control the GPS device subtype value to execute arbitrary shell commands by embedding backtick payloads in the gnuplot plot title without proper escaping. The subtype field sourced from a DEVICES JSON log entry or NMEA PGRMT sentence is written into a generated gnuplot program via a set title statement with only double-quote characters escaped, enabling arbitrary shell command execution as the user running gnuplot when the victim renders the generated plot through the gpsprof and gnuplot workflow.

CVSS3: 7.8
debian
2 месяца назад

gpsd through release-3.27.5, fixed at commit 4c06658, contains a comma ...

rocky
около 1 месяца назад

Important: gpsd-minimal security update