Skip to main content

Threats Tagged 'cve-2025-67269'

View all threats tagged with 'cve-2025-67269'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2025-67269

Threats Tagged 'cve-2025-67269'

Click on any threat for detailed analysis and mitigation recommendations

0

Red Hat has issued a security advisory for gpsd-minimal addressing two vulnerabilities: a denial of service caused by malformed NAVCOM packet parsing (CVE-2025-67269) and arbitrary code execution via a heap-based out-of-bounds write in NMEA2000 packet handling (CVE-2025-67268). These issues affect gpsd, a daemon that provides GPS sensor data over TCP port 2947. The advisory covers Red Hat Enterprise Linux 9 and related variants. The update is rated as Important by Red Hat Product Security. A fix is available in updated gpsd-minimal packages for affected Red Hat Enterprise Linux 9 versions.

Join the discussion
CVE-2025-67268: n/aCVE-2025-67268
0

A heap-based out-of-bounds write vulnerability exists in gpsd prior to commit dc966aa in the handling of NMEA2000 PGN 129540 packets. The vulnerability arises because the satellite count provided by a user is not properly validated against the fixed size of the skyview array, allowing writes beyond its bounds. This can lead to memory corruption, denial of service, and potentially arbitrary code execution. Red Hat has issued a security update for gpsd in Red Hat Enterprise Linux 10.0 Extended Update Support to address this issue.

Join the discussion
CVE-2025-67269: n/aCVE-2025-67269
0

An integer underflow vulnerability exists in the `nextstate()` function in `gpsd/packet.c` of gpsd versions prior to commit `ffa1d6f40bca0b035fc7f5e563160ebb67199da7`. When parsing a NAVCOM packet, the payload length is calculated using `lexer->length = (size_t)c - 4` without checking if the input byte `c` is less than 4. This results in an unsigned integer underflow, setting `lexer->length` to a very large value (near `SIZE_MAX`). The parser then enters a loop attempting to consume this massive number of bytes, causing 100% CPU utilization and a Denial of Service (DoS) condition.

Join the discussion

Showing 1 to 3 of 3 results

Filters:Tag: cve-2025-67269
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses