Fedora Account System
Red Hat Associate
Red Hat Customer
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process. gpsd through release-3.27.5, fixed at commit 4c06658, contains a command injection vulnerability in gpsprof that allows attackers who control the GPS device subtype value to execute arbitrary shell commands by embedding backtick payloads in the gnuplot plot title without proper escaping. The subtype field sourced from a DEVICES JSON log entry or NMEA PGRMT sentence is written into a generated gnuplot program via a set title statement with only double-quote characters escaped, enabling arbitrary shell command execution as the user running gnuplot when the victim renders the generated plot through the gpsprof and gnuplot workflow.
Waiting for release in RHEL 10 so I can build this for epel.
New version available, it seems (this is on Alma 10.2): [root@mypc ~] # dnf list --showduplicates gpsd\* Last metadata expiration check: 0:00:33 ago on jue 13 ago 2026 13:31:42. Installed Packages gpsd-libs.x86_64 1:3.26.1-3.el10_2 @System Available Packages gpsd.x86_64 1:3.26.1-3.el10 appstream gpsd.x86_64 1:3.26.1-3.el10_2.1 appstream gpsd-clients.x86_64 1:3.26.1-3.el10 appstream gpsd-clients.x86_64 1:3.26.1-3.el10_2.1 appstream gpsd-devel.x86_64 1:3.26.1-3.el10_2 epel gpsd-libs.x86_64 1:3.26.1-3.el10_2 epel This update (from upstream) breaks updating due to plasma5support requiring libgps.so.31, see https://bugzilla.redhat.com/show_bug.cgi?id=2428239 Thanks!
Ugg. It looks like they are going to have a different version for 10.2 and 10.3. And that plasma5support ticket ... needs to be assigned to the correct package. It looks like they literally just picked something random to assign it to. I had no idea about that problem. Anyway, thank you for the heads up. I'll start working on 10.2, and wait for the package in CentOS Stream 10 / 10.3. And I'll take the plasma5support ticket and do them both at the same update.
FEDORA-EPEL-2026-70d981126c (gpsd-epel-3.26.1-3.el10_2.1) has been submitted as an update to Fedora EPEL 10.2. https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-70d981126c
FEDORA-EPEL-2026-70d981126c has been pushed to the Fedora EPEL 10.2 testing repository. You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-70d981126c See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.
FEDORA-EPEL-2026-70d981126c (gpsd-epel-3.26.1-3.el10_2.1) has been pushed to the Fedora EPEL 10.2 stable repository. If problem still persists, please make note of it in this bug report.