VYPR

rpm package

almalinux/python3-gpsd

pkg:rpm/almalinux/python3-gpsd

Vulnerabilities (3)

  • CVE-2026-58459HigJul 9, 2026
    affected < 1:3.26.1-3.el10_2.1fixed 1:3.26.1-3.el10_2.1

    gpsd through release-3.27.5, fixed at commit 4c06658, contains a command injection vulnerability in gpsprof that allows attackers who control the GPS device subtype value to execute arbitrary shell commands by embedding backtick payloads in the gnuplot plot title without proper e

  • CVE-2025-67269HigJan 2, 2026
    affected < 1:3.26.1-1.el10_1.1fixed 1:3.26.1-1.el10_1.1

    An integer underflow vulnerability exists in the `nextstate()` function in `gpsd/packet.c` of gpsd versions prior to commit `ffa1d6f40bca0b035fc7f5e563160ebb67199da7`. When parsing a NAVCOM packet, the payload length is calculated using `lexer->length = (size_t)c - 4` without che

  • CVE-2025-67268CriJan 2, 2026
    affected < 1:3.26.1-1.el10_1.1fixed 1:3.26.1-1.el10_1.1

    gpsd before commit dc966aa contains a heap-based out-of-bounds write vulnerability in the drivers/driver_nmea2000.c file. The hnd_129540 function, which handles NMEA2000 PGN 129540 (GNSS Satellites in View) packets, fails to validate the user-supplied satellite count against the