Threats Tagged 'cve-2025-67269'
View all threats tagged with 'cve-2025-67269'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2025-67269'
Click on any threat for detailed analysis and mitigation recommendations
0 Red Hat has issued a security advisory for gpsd-minimal addressing two vulnerabilities: a denial of service caused by malformed NAVCOM packet parsing (CVE-2025-67269) and arbitrary code execution via a heap-based out-of-bounds write in NMEA2000 packet handling (CVE-2025-67268). These issues affect gpsd, a daemon that provides GPS sensor data over TCP port 2947. The advisory covers Red Hat Enterprise Linux 9 and related variants. The update is rated as Important by Red Hat Product Security. A fix is available in updated gpsd-minimal packages for affected Red Hat Enterprise Linux 9 versions. Join the discussion | GCVE Database | 01/19/2026, 06:22:09 UTC Added: 06/09/2026, 10:23:27 UTC |
0 A heap-based out-of-bounds write vulnerability exists in gpsd prior to commit dc966aa in the handling of NMEA2000 PGN 129540 packets. The vulnerability arises because the satellite count provided by a user is not properly validated against the fixed size of the skyview array, allowing writes beyond its bounds. This can lead to memory corruption, denial of service, and potentially arbitrary code execution. Red Hat has issued a security update for gpsd in Red Hat Enterprise Linux 10.0 Extended Update Support to address this issue. Join the discussion | GCVE Database | 01/02/2026, 00:00:00 UTC Added: 06/09/2026, 10:23:27 UTC |
0 An integer underflow vulnerability exists in the `nextstate()` function in `gpsd/packet.c` of gpsd versions prior to commit `ffa1d6f40bca0b035fc7f5e563160ebb67199da7`. When parsing a NAVCOM packet, the payload length is calculated using `lexer->length = (size_t)c - 4` without checking if the input byte `c` is less than 4. This results in an unsigned integer underflow, setting `lexer->length` to a very large value (near `SIZE_MAX`). The parser then enters a loop attempting to consume this massive number of bytes, causing 100% CPU utilization and a Denial of Service (DoS) condition. Join the discussion | CVE Database V5 | 01/02/2026, 00:00:00 UTC Added: 01/02/2026, 15:58:45 UTC |
Showing 1 to 3 of 3 results