Skip to main content
EPSS 1.8%top 23%

Red Hat Security Advisory: gpsd security update

0
High
Published: 08/06/2026 (08/06/2026, 13:54:26 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

gpsd is a service daemon that mediates access to a GPS sensor connected to the host computer by serial or USB interface, making its data on the location/course/velocity of the sensor available to be queried on TCP port 2947 of the host computer. The Red Hat support for this package is limited. See https://access.redhat.com/support/policy/gpsd-support for more details. Security Fix(es): * gpsd: gpsd: Command Injection via GPS device subtype allows arbitrary code execution (CVE-2026-58459) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Affected software

Ubuntu:16.04:LTSmore threats →ghsa
gpsd
pkg:deb/ubuntu/[email protected]?arch=source&distro=xenial
Affected versions
=3.11-3=3.15-2=3.15-2build1
Ubuntu:18.04:LTSmore threats →ghsa
gpsd
pkg:deb/ubuntu/[email protected]?arch=source&distro=bionic
Affected versions
=3.16-4=3.17-3=3.17-5
Ubuntu:20.04:LTSmore threats →ghsa
gpsd
pkg:deb/ubuntu/[email protected]?arch=source&distro=focal
Affected versions
=3.17-7=3.19-3=3.20-1=3.20-3=3.20-4=3.20-4build1=3.20-5ubuntu1=3.20-6=3.20-8=3.20-8ubuntu0.1=3.20-8ubuntu0.2=3.20-8ubuntu0.4
Ubuntu:22.04:LTSmore threats →ghsa
gpsd
pkg:deb/ubuntu/[email protected]?arch=source&distro=jammy
Affected versions
=3.22-4=3.22-4ubuntu1=3.22-4ubuntu2=3.22-4ubuntu2.1
Ubuntu:24.04:LTSmore threats →ghsa
gpsd
pkg:deb/ubuntu/[email protected]?arch=source&distro=noble
Affected versions
=3.25-2ubuntu2=3.25-3ubuntu2=3.25-3ubuntu3=3.25-3ubuntu3.1=3.25-3ubuntu3.2
Ubuntu:26.04:LTSmore threats →ghsa
gpsd
pkg:deb/ubuntu/[email protected]?arch=source&distro=resolute
Affected versions
=3.25-5ubuntu1=3.27-1.1=3.27-1.1ubuntu1=3.27.5-0.1

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/07/2026, 00:39:24 UTC

Technical Analysis

The gpsd daemon mediates access to GPS sensors connected via serial or USB interfaces and listens on TCP port 2947. A command injection vulnerability exists in the handling of the GPS device subtype, which allows an attacker to execute arbitrary code on the host system. This vulnerability is tracked as CVE-2026-58459 and is rated with high severity. Red Hat has released updated gpsd packages for Red Hat Enterprise Linux 10 to fix this issue. The vulnerability affects multiple specific versions of gpsd as listed in the advisory and Ubuntu LTS versions 16.04 through 26.04. No known exploits in the wild have been reported.

Potential Impact

Successful exploitation of this vulnerability allows an attacker to execute arbitrary code on the affected system with the privileges of the gpsd service. This could lead to full system compromise depending on the service context. The vulnerability impacts systems running vulnerable versions of gpsd on Red Hat Enterprise Linux 10 and various Ubuntu LTS versions.

Mitigation Recommendations

Red Hat has released updated gpsd packages that fix this command injection vulnerability. Users should apply the security update provided in Red Hat Advisory RHSA-2026:51075 to remediate the issue. For detailed update instructions, refer to https://access.redhat.com/articles/11258. Since this is not a cloud service, remediation requires manual patching by system administrators. No additional mitigations are indicated by the vendor advisory.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
UBUNTU-CVE-2026-58459
Osv Schema Version
1.7.0
Ecosystems
["Ubuntu:16.04:LTS","Ubuntu:18.04:LTS","Ubuntu:20.04:LTS","Ubuntu:22.04:LTS","Ubuntu:24.04:LTS","Ubuntu:26.04:LTS"]
Cvss Version
4.0
State
PUBLISHED

Threat ID: 6a58b45d68715ace43d6be1b

Added to database: 07/16/2026, 10:37:17 UTC

Last enriched: 08/07/2026, 00:39:24 UTC

Last updated: 09/11/2026, 19:31:56 UTC

Views: 26

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses