Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-51153

Опубликовано: 07 авг. 2026
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2026-51153: gpsd-minimal security update (IMPORTANT)

[3.26.1-2.0.1.el9_8.1]

  • Replaced upstream reference [Orabug: 35865525]

[1:3.26.1-2.el9_8.1]

  • fix command injection in gpsprof (CVE-2026-58459)

[1:3.26.1-2]

  • fix buffer overflow in NMEA2000 driver (CVE-2025-67268)
  • fix integer underflow in handling of Navcom packets (CVE-2025-67269)

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

gpsd-minimal

3.26.1-2.0.1.el9_8.1

gpsd-minimal-clients

3.26.1-2.0.1.el9_8.1

Oracle Linux x86_64

gpsd-minimal

3.26.1-2.0.1.el9_8.1

gpsd-minimal-clients

3.26.1-2.0.1.el9_8.1

Связанные CVE

Связанные уязвимости

CVSS3: 7.8
ubuntu
2 месяца назад

gpsd through release-3.27.5, fixed at commit 4c06658, contains a command injection vulnerability in gpsprof that allows attackers who control the GPS device subtype value to execute arbitrary shell commands by embedding backtick payloads in the gnuplot plot title without proper escaping. The subtype field sourced from a DEVICES JSON log entry or NMEA PGRMT sentence is written into a generated gnuplot program via a set title statement with only double-quote characters escaped, enabling arbitrary shell command execution as the user running gnuplot when the victim renders the generated plot through the gpsprof and gnuplot workflow.

CVSS3: 7.8
redhat
2 месяца назад

gpsd through release-3.27.5, fixed at commit 4c06658, contains a command injection vulnerability in gpsprof that allows attackers who control the GPS device subtype value to execute arbitrary shell commands by embedding backtick payloads in the gnuplot plot title without proper escaping. The subtype field sourced from a DEVICES JSON log entry or NMEA PGRMT sentence is written into a generated gnuplot program via a set title statement with only double-quote characters escaped, enabling arbitrary shell command execution as the user running gnuplot when the victim renders the generated plot through the gpsprof and gnuplot workflow.

CVSS3: 7.8
nvd
2 месяца назад

gpsd through release-3.27.5, fixed at commit 4c06658, contains a command injection vulnerability in gpsprof that allows attackers who control the GPS device subtype value to execute arbitrary shell commands by embedding backtick payloads in the gnuplot plot title without proper escaping. The subtype field sourced from a DEVICES JSON log entry or NMEA PGRMT sentence is written into a generated gnuplot program via a set title statement with only double-quote characters escaped, enabling arbitrary shell command execution as the user running gnuplot when the victim renders the generated plot through the gpsprof and gnuplot workflow.

CVSS3: 7.8
debian
2 месяца назад

gpsd through release-3.27.5, fixed at commit 4c06658, contains a comma ...

rocky
около 1 месяца назад

Important: gpsd-minimal security update