CVE-2026-60122
gpsd · gpsd
The gpsd software is susceptible to code injection via the sky satellites used field, which may allow for arbitrary code execution.
Executive summary
A code injection vulnerability in the gpsd service could allow a local attacker with user interaction to execute arbitrary code.
Vulnerability
This vulnerability (CWE-94) stems from improper control of code generation when processing specific fields, allowing an attacker to inject malicious code. The attack vector requires local access and user interaction to trigger the flaw.
Business impact
Successful exploitation could lead to full system compromise, as the vulnerability allows for arbitrary code execution with the privileges of the gpsd process. With a CVSS score of 7.8, the impact on system integrity and availability is critical, potentially resulting in unauthorized system control.
Remediation
Immediate Action: Update gpsd to the version incorporating fix commit 5a9c44a42136b9bb98d460a8a716e9fd344a8d93 or later.
Proactive Monitoring: Monitor system logs for unusual process execution or unauthorized modifications to the gpsd configuration.
Compensating Controls: Restrict local access to the system and ensure that only trusted users can interact with the gpsd service.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Users of the gpsd service must move to apply the necessary patches provided by the vendor. Prioritizing this update is essential to prevent potential code injection attacks that could lead to unauthorized system access.