UBUNTU-CVE-2026-60122

Source
https://ubuntu.com/security/CVE-2026-60122
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-60122.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2026-60122
Upstream
Published
2026-07-27T00:00:00Z
Modified
2026-07-27T16:30:20.235921436Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
  • 8.5 (High) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

gpsd through release-3.27.5, fixed at commit 4c06658, contains a code injection vulnerability in the gpsprof utility that allows an attacker who controls GPS input data to execute arbitrary OS commands by injecting malicious content into the SKY.satellites[].used field, which is inserted unsanitized into a gnuplot heredoc data block. Attackers can supply a used value containing the string EOD to terminate the heredoc early and append gnuplot system() calls, achieving OS command execution as the user running gpsprof when the generated plot script is processed by gnuplot in polar mode.

References

Affected packages

Ubuntu:16.04:LTS
gpsd

Package

Name
gpsd
Purl
pkg:deb/ubuntu/gpsd?arch=source&distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.11-3
3.15-2
3.15-2build1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "3.15-2build1",
            "binary_name": "gpsd"
        },
        {
            "binary_version": "3.15-2build1",
            "binary_name": "gpsd-clients"
        },
        {
            "binary_version": "3.15-2build1",
            "binary_name": "libgps22"
        },
        {
            "binary_version": "3.15-2build1",
            "binary_name": "libqgpsmm22"
        },
        {
            "binary_version": "3.15-2build1",
            "binary_name": "python-gps"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-60122.json"
Ubuntu:18.04:LTS
gpsd

Package

Name
gpsd
Purl
pkg:deb/ubuntu/gpsd?arch=source&distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.16-4
3.17-3
3.17-5

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "3.17-5",
            "binary_name": "gpsd"
        },
        {
            "binary_version": "3.17-5",
            "binary_name": "gpsd-clients"
        },
        {
            "binary_version": "3.17-5",
            "binary_name": "libgps23"
        },
        {
            "binary_version": "3.17-5",
            "binary_name": "libqgpsmm23"
        },
        {
            "binary_version": "3.17-5",
            "binary_name": "python-gps"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-60122.json"
Ubuntu:20.04:LTS
gpsd

Package

Name
gpsd
Purl
pkg:deb/ubuntu/gpsd?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.17-7
3.19-3
3.20-1
3.20-3
3.20-4
3.20-4build1
3.20-5ubuntu1
3.20-6
3.20-8
3.20-8ubuntu0.1
3.20-8ubuntu0.2
3.20-8ubuntu0.4

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "3.20-8ubuntu0.4",
            "binary_name": "gpsd"
        },
        {
            "binary_version": "3.20-8ubuntu0.4",
            "binary_name": "gpsd-clients"
        },
        {
            "binary_version": "3.20-8ubuntu0.4",
            "binary_name": "libgps26"
        },
        {
            "binary_version": "3.20-8ubuntu0.4",
            "binary_name": "libqgpsmm26"
        },
        {
            "binary_version": "3.20-8ubuntu0.4",
            "binary_name": "python3-gps"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-60122.json"
Ubuntu:22.04:LTS
gpsd

Package

Name
gpsd
Purl
pkg:deb/ubuntu/gpsd?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.22-4
3.22-4ubuntu1
3.22-4ubuntu2
3.22-4ubuntu2.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "3.22-4ubuntu2.1",
            "binary_name": "gpsd"
        },
        {
            "binary_version": "3.22-4ubuntu2.1",
            "binary_name": "gpsd-clients"
        },
        {
            "binary_version": "3.22-4ubuntu2.1",
            "binary_name": "gpsd-tools"
        },
        {
            "binary_version": "3.22-4ubuntu2.1",
            "binary_name": "libgps28"
        },
        {
            "binary_version": "3.22-4ubuntu2.1",
            "binary_name": "libqgpsmm28"
        },
        {
            "binary_version": "3.22-4ubuntu2.1",
            "binary_name": "python3-gps"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-60122.json"
Ubuntu:24.04:LTS
gpsd

Package

Name
gpsd
Purl
pkg:deb/ubuntu/gpsd?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.25-2ubuntu2
3.25-3ubuntu2
3.25-3ubuntu3
3.25-3ubuntu3.1
3.25-3ubuntu3.2

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "3.25-3ubuntu3.2",
            "binary_name": "gpsd"
        },
        {
            "binary_version": "3.25-3ubuntu3.2",
            "binary_name": "gpsd-clients"
        },
        {
            "binary_version": "3.25-3ubuntu3.2",
            "binary_name": "gpsd-tools"
        },
        {
            "binary_version": "3.25-3ubuntu3.2",
            "binary_name": "libgps30t64"
        },
        {
            "binary_version": "3.25-3ubuntu3.2",
            "binary_name": "libqgpsmm30t64"
        },
        {
            "binary_version": "3.25-3ubuntu3.2",
            "binary_name": "python3-gps"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-60122.json"
Ubuntu:26.04:LTS
gpsd

Package

Name
gpsd
Purl
pkg:deb/ubuntu/gpsd?arch=source&distro=resolute

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.25-5ubuntu1
3.27-1.1
3.27-1.1ubuntu1
3.27.5-0.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "3.27.5-0.1",
            "binary_name": "gpsd"
        },
        {
            "binary_version": "3.27.5-0.1",
            "binary_name": "gpsd-clients"
        },
        {
            "binary_version": "3.27.5-0.1",
            "binary_name": "gpsd-tools"
        },
        {
            "binary_version": "3.27.5-0.1",
            "binary_name": "libgps32"
        },
        {
            "binary_version": "3.27.5-0.1",
            "binary_name": "libqgpsmm32"
        },
        {
            "binary_version": "3.27.5-0.1",
            "binary_name": "python3-gps"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-60122.json"