<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
	<DocumentTitle xml:lang="en">An update for gpsd is now available for openEuler-24.03-LTS-SP4</DocumentTitle>
	<DocumentType>Security Advisory</DocumentType>
	<DocumentPublisher Type="Vendor">
		<ContactDetails>openeuler-security@openeuler.org</ContactDetails>
		<IssuingAuthority>openEuler security committee</IssuingAuthority>
	</DocumentPublisher>
	<DocumentTracking>
		<Identification>
			<ID>openEuler-SA-2026-4220</ID>
		</Identification>
		<Status>Final</Status>
		<Version>1.0</Version>
		<RevisionHistory>
			<Revision>
				<Number>1.0</Number>
				<Date>2026-09-30</Date>
				<Description>Initial</Description>
			</Revision>
		</RevisionHistory>
		<InitialReleaseDate>2026-09-30</InitialReleaseDate>
		<CurrentReleaseDate>2026-09-30</CurrentReleaseDate>
		<Generator>
			<Engine>openEuler SA Tool V1.0</Engine>
			<Date>2026-09-30</Date>
		</Generator>
	</DocumentTracking>
	<DocumentNotes>
		<Note Title="Synopsis" Type="General" Ordinal="1" xml:lang="en">gpsd security update</Note>
		<Note Title="Summary" Type="General" Ordinal="2" xml:lang="en">An update for gpsd is now available for openEuler-24.03-LTS-SP4</Note>
		<Note Title="Description" Type="General" Ordinal="3" xml:lang="en">gpsd is a service daemon that mediates access to a GPS sensor connected to the host computer by serial or USB interface, making its data on the location/course/velocity of the sensor available to be queried on TCP port 2947 of the host computer.  With gpsd, multiple GPS client applications (such as navigational and war-driving software) can share access to a GPS without contention or loss of data.  Also, gpsd responds to queries with a format that is substantially easier to parse than NMEA 0183.

Security Fix(es):

gpsd through release-3.27.5, fixed at commit 4c06658, contains a command injection vulnerability in gpsprof that allows attackers who control the GPS device subtype value to execute arbitrary shell commands by embedding backtick payloads in the gnuplot plot title without proper escaping. The subtype field sourced from a DEVICES JSON log entry or NMEA PGRMT sentence is written into a generated gnuplot program via a set title statement with only double-quote characters escaped, enabling arbitrary shell command execution as the user running gnuplot when the victim renders the generated plot through the gpsprof and gnuplot workflow.(CVE-2026-58459)

gpsd through release-3.27.5, fixed at commit 4c06658, contains a code injection vulnerability in the gpsprof utility that allows an attacker who controls GPS input data to execute arbitrary OS commands by injecting malicious content into the SKY.satellites[].used field, which is inserted unsanitized into a gnuplot heredoc data block. Attackers can supply a used value containing the string EOD to terminate the heredoc early and append gnuplot system() calls, achieving OS command execution as the user running gpsprof when the generated plot script is processed by gnuplot in polar mode.(CVE-2026-60122)</Note>
		<Note Title="Topic" Type="General" Ordinal="4" xml:lang="en">An update for gpsd is now available for openEuler-24.03-LTS-SP4.

openEuler Security has rated this update as having a security impact of critical. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.</Note>
		<Note Title="Severity" Type="General" Ordinal="5" xml:lang="en">Critical</Note>
		<Note Title="Affected Component" Type="General" Ordinal="6" xml:lang="en">gpsd</Note>
	</DocumentNotes>
	<DocumentReferences>
		<Reference Type="Self">
			<URL>https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-4220</URL>
		</Reference>
		<Reference Type="openEuler CVE">
			<URL>https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-58459</URL>
			<URL>https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-60122</URL>
		</Reference>
		<Reference Type="Other">
			<URL>https://nvd.nist.gov/vuln/detail/CVE-2026-58459</URL>
			<URL>https://nvd.nist.gov/vuln/detail/CVE-2026-60122</URL>
		</Reference>
	</DocumentReferences>
	<ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
		<Branch Type="Product Name" Name="openEuler">
			<FullProductName ProductID="openEuler-24.03-LTS-SP4" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4">openEuler-24.03-LTS-SP4</FullProductName>
		</Branch>
		<Branch Type="Package Arch" Name="src">
			<FullProductName ProductID="gpsd-3.25-6" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4" EPOL="true">gpsd-3.25-6.oe2403sp4.src.rpm</FullProductName>
		</Branch>
		<Branch Type="Package Arch" Name="x86_64">
			<FullProductName ProductID="gpsd-3.25-6" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4" EPOL="true">gpsd-3.25-6.oe2403sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="gpsd-clients-3.25-6" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4" EPOL="true">gpsd-clients-3.25-6.oe2403sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="gpsd-debuginfo-3.25-6" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4" EPOL="true">gpsd-debuginfo-3.25-6.oe2403sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="gpsd-debugsource-3.25-6" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4" EPOL="true">gpsd-debugsource-3.25-6.oe2403sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="gpsd-devel-3.25-6" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4" EPOL="true">gpsd-devel-3.25-6.oe2403sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="gpsd-libs-3.25-6" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4" EPOL="true">gpsd-libs-3.25-6.oe2403sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="gpsd-qt-3.25-6" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4" EPOL="true">gpsd-qt-3.25-6.oe2403sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="gpsd-qt-devel-3.25-6" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4" EPOL="true">gpsd-qt-devel-3.25-6.oe2403sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="gpsd-xclients-3.25-6" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4" EPOL="true">gpsd-xclients-3.25-6.oe2403sp4.x86_64.rpm</FullProductName>
			<FullProductName ProductID="python3-gpsd-3.25-6" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4" EPOL="true">python3-gpsd-3.25-6.oe2403sp4.x86_64.rpm</FullProductName>
		</Branch>
		<Branch Type="Package Arch" Name="aarch64">
			<FullProductName ProductID="gpsd-3.25-6" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4" EPOL="true">gpsd-3.25-6.oe2403sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="gpsd-clients-3.25-6" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4" EPOL="true">gpsd-clients-3.25-6.oe2403sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="gpsd-debuginfo-3.25-6" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4" EPOL="true">gpsd-debuginfo-3.25-6.oe2403sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="gpsd-debugsource-3.25-6" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4" EPOL="true">gpsd-debugsource-3.25-6.oe2403sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="gpsd-devel-3.25-6" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4" EPOL="true">gpsd-devel-3.25-6.oe2403sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="gpsd-libs-3.25-6" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4" EPOL="true">gpsd-libs-3.25-6.oe2403sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="gpsd-qt-3.25-6" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4" EPOL="true">gpsd-qt-3.25-6.oe2403sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="gpsd-qt-devel-3.25-6" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4" EPOL="true">gpsd-qt-devel-3.25-6.oe2403sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="gpsd-xclients-3.25-6" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4" EPOL="true">gpsd-xclients-3.25-6.oe2403sp4.aarch64.rpm</FullProductName>
			<FullProductName ProductID="python3-gpsd-3.25-6" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP4" EPOL="true">python3-gpsd-3.25-6.oe2403sp4.aarch64.rpm</FullProductName>
		</Branch>
	</ProductTree>
	<Vulnerability Ordinal="1" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
		<Notes>
			<Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">gpsd through release-3.27.5, fixed at commit 4c06658, contains a command injection vulnerability in gpsprof that allows attackers who control the GPS device subtype value to execute arbitrary shell commands by embedding backtick payloads in the gnuplot plot title without proper escaping. The subtype field sourced from a DEVICES JSON log entry or NMEA PGRMT sentence is written into a generated gnuplot program via a set title statement with only double-quote characters escaped, enabling arbitrary shell command execution as the user running gnuplot when the victim renders the generated plot through the gpsprof and gnuplot workflow.</Note>
		</Notes>
		<ReleaseDate>2026-09-30</ReleaseDate>
		<CVE>CVE-2026-58459</CVE>
		<ProductStatuses>
			<Status Type="Fixed">
				<ProductID>openEuler-24.03-LTS-SP4</ProductID>
			</Status>
		</ProductStatuses>
		<Threats>
			<Threat Type="Impact">
				<Description>Critical</Description>
			</Threat>
		</Threats>
		<CVSSScoreSets>
			<ScoreSet>
				<BaseScore>9.6</BaseScore>
				<Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
			</ScoreSet>
		</CVSSScoreSets>
		<Remediations>
			<Remediation Type="Vendor Fix">
				<Description>gpsd security update</Description>
				<DATE>2026-09-30</DATE>
				<URL>https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-4220</URL>
			</Remediation>
		</Remediations>
	</Vulnerability>
	<Vulnerability Ordinal="2" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
		<Notes>
			<Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">gpsd through release-3.27.5, fixed at commit 4c06658, contains a code injection vulnerability in the gpsprof utility that allows an attacker who controls GPS input data to execute arbitrary OS commands by injecting malicious content into the SKY.satellites[].used field, which is inserted unsanitized into a gnuplot heredoc data block. Attackers can supply a used value containing the string EOD to terminate the heredoc early and append gnuplot system() calls, achieving OS command execution as the user running gpsprof when the generated plot script is processed by gnuplot in polar mode.</Note>
		</Notes>
		<ReleaseDate>2026-09-30</ReleaseDate>
		<CVE>CVE-2026-60122</CVE>
		<ProductStatuses>
			<Status Type="Fixed">
				<ProductID>openEuler-24.03-LTS-SP4</ProductID>
			</Status>
		</ProductStatuses>
		<Threats>
			<Threat Type="Impact">
				<Description>High</Description>
			</Threat>
		</Threats>
		<CVSSScoreSets>
			<ScoreSet>
				<BaseScore>7.8</BaseScore>
				<Vector>AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
			</ScoreSet>
		</CVSSScoreSets>
		<Remediations>
			<Remediation Type="Vendor Fix">
				<Description>gpsd security update</Description>
				<DATE>2026-09-30</DATE>
				<URL>https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-4220</URL>
			</Remediation>
		</Remediations>
	</Vulnerability>
</cvrfdoc>