CVE-2026-58459

EUVD-2026-42622
gpsd through release-3.27.5, fixed at commit 4c06658, contains a command injection vulnerability in gpsprof that allows attackers who control the GPS device subtype value to execute arbitrary shell commands by embedding backtick payloads in the gnuplot plot title without proper escaping. The subtype field sourced from a DEVICES JSON log entry or NMEA PGRMT sentence is written into a generated gnuplot program via a set title statement with only double-quote characters escaped, enabling arbitrary shell command execution as the user running gnuplot when the victim renders the generated plot through the gpsprof and gnuplot workflow.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 76.43%
Affected Products (NVD)
VendorProductVersion
gpsd_projectgpsd
𝑥
≤ 3.27.5
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
gpsd
bookworm
postponed
bullseye
postponed
bullseye (security)
vulnerable
forky
3.27.5-3
fixed
sid
3.27.5-3
fixed
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
gpsd
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
resolute
needs-triage
xenial
needs-triage
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
gpsd-minimal
RHEL 9
1:3.26.1-2.el9_8.1
fixed
gpsd-minimal-clients
RHEL 9
1:3.26.1-2.el9_8.1
fixed