UBUNTU-CVE-2026-58459
gpsd versions through release 3.27.5 contain a command injection vulnerability in the gpsprof component. This flaw allows attackers controlling the GPS device subtype value to execute arbitrary shell commands by embedding backtick payloads in the gnuplot plot title. The vulnerability arises because only double-quote characters are escaped when writing the subtype field into a generated gnuplot program, enabling command execution as the user running gnuplot. The issue is fixed at commit 4c06658.
AI Analysis
Technical Summary
The gpsd software up to version 3.27.5 has a command injection vulnerability in gpsprof. The subtype field from GPS device data, sourced from DEVICES JSON log entries or NMEA PGRMT sentences, is embedded into a gnuplot plot title with insufficient escaping (only double quotes are escaped). This allows an attacker who controls the subtype value to inject shell commands via backtick payloads, which are executed when the victim renders the plot using gpsprof and gnuplot. The vulnerability is fixed in commit 4c06658.
Potential Impact
An attacker able to control the GPS device subtype value can execute arbitrary shell commands with the privileges of the user running gnuplot. This can lead to unauthorized command execution on the affected system. There are no known exploits in the wild at this time.
Mitigation Recommendations
A fix is available and was introduced in commit 4c06658. Users should upgrade gpsd to a version that includes this commit to remediate the vulnerability. Until patched, avoid processing untrusted GPS device subtype data with gpsprof and gnuplot.
UBUNTU-CVE-2026-58459
Description
gpsd versions through release 3.27.5 contain a command injection vulnerability in the gpsprof component. This flaw allows attackers controlling the GPS device subtype value to execute arbitrary shell commands by embedding backtick payloads in the gnuplot plot title. The vulnerability arises because only double-quote characters are escaped when writing the subtype field into a generated gnuplot program, enabling command execution as the user running gnuplot. The issue is fixed at commit 4c06658.
CVSS v4.0
Affected software
pkg:deb/ubuntu/[email protected]?arch=source&distro=xenialpkg:deb/ubuntu/[email protected]?arch=source&distro=bionicpkg:deb/ubuntu/[email protected]?arch=source&distro=focalpkg:deb/ubuntu/[email protected]?arch=source&distro=jammypkg:deb/ubuntu/[email protected]?arch=source&distro=noblepkg:deb/ubuntu/[email protected]?arch=source&distro=resoluteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The gpsd software up to version 3.27.5 has a command injection vulnerability in gpsprof. The subtype field from GPS device data, sourced from DEVICES JSON log entries or NMEA PGRMT sentences, is embedded into a gnuplot plot title with insufficient escaping (only double quotes are escaped). This allows an attacker who controls the subtype value to inject shell commands via backtick payloads, which are executed when the victim renders the plot using gpsprof and gnuplot. The vulnerability is fixed in commit 4c06658.
Potential Impact
An attacker able to control the GPS device subtype value can execute arbitrary shell commands with the privileges of the user running gnuplot. This can lead to unauthorized command execution on the affected system. There are no known exploits in the wild at this time.
Mitigation Recommendations
A fix is available and was introduced in commit 4c06658. Users should upgrade gpsd to a version that includes this commit to remediate the vulnerability. Until patched, avoid processing untrusted GPS device subtype data with gpsprof and gnuplot.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2026-58459
- Osv Schema Version
- 1.7.0
- Aliases
- []
- Ecosystems
- ["Ubuntu:16.04:LTS","Ubuntu:18.04:LTS","Ubuntu:20.04:LTS","Ubuntu:22.04:LTS","Ubuntu:24.04:LTS","Ubuntu:26.04:LTS"]
- Database Specific Severity
- null
- Cvss Version
- 4.0
Threat ID: 6a58b45d68715ace43d6be1b
Added to database: 07/16/2026, 10:37:17 UTC
Last enriched: 07/16/2026, 11:35:03 UTC
Last updated: 07/31/2026, 19:24:49 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.