RHSA-2026:51075: Important: gpsd security update
gpsd is a service daemon that mediates access to a GPS sensor connected to the host computer by serial or USB interface, making its data on the location/course/velocity of the sensor available to be queried on TCP port 2947 of the host computer. With gpsd, multiple GPS client applications (such as navigational and war-driving software) can share access to a GPS without contention or loss of data. Also, gpsd responds to queries with a format that is substantially easier to parse than NMEA 0183. The Red Hat support for this package is limited. See https://access.redhat.com/support/policy/gpsd-support for more details.Security Fix(es): gpsd: gpsd: Command Injection via GPS device subtype allows arbitrary code execution (CVE-2026-58459) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/gpsdto a version that resolves this vulnerability.Fixed in 3.26.1-3.el10_2.1 - Upgrade
Upgrade
redhat/gpsd-clientsto a version that resolves this vulnerability.Fixed in 3.26.1-3.el10_2.1 - Upgrade
Upgrade
redhat/gpsd-clients-debuginfoto a version that resolves this vulnerability.Fixed in 3.26.1-3.el10_2.1 - Upgrade
Upgrade
redhat/gpsd-debuginfoto a version that resolves this vulnerability.Fixed in 3.26.1-3.el10_2.1 - Upgrade
Upgrade
redhat/gpsd-debugsourceto a version that resolves this vulnerability.Fixed in 3.26.1-3.el10_2.1 - Upgrade
Upgrade
redhat/python3-gpsdto a version that resolves this vulnerability.Fixed in 3.26.1-3.el10_2.1 - Upgrade
Upgrade
redhat/python3-gpsd-debuginfoto a version that resolves this vulnerability.Fixed in 3.26.1-3.el10_2.1 - Upgrade
Upgrade
redhat/gpsdto a version that resolves this vulnerability.Fixed in 3.26.1-3.el10_2.1.aa - Upgrade
Upgrade
redhat/gpsd-clientsto a version that resolves this vulnerability.Fixed in 3.26.1-3.el10_2.1.aa - Upgrade
Upgrade
redhat/gpsd-clients-debuginfoto a version that resolves this vulnerability.Fixed in 3.26.1-3.el10_2.1.aa - Upgrade
Upgrade
redhat/gpsd-debuginfoto a version that resolves this vulnerability.Fixed in 3.26.1-3.el10_2.1.aa - Upgrade
Upgrade
redhat/gpsd-debugsourceto a version that resolves this vulnerability.Fixed in 3.26.1-3.el10_2.1.aa - Upgrade
Upgrade
redhat/python3-gpsdto a version that resolves this vulnerability.Fixed in 3.26.1-3.el10_2.1.aa - Upgrade
Upgrade
redhat/python3-gpsd-debuginfoto a version that resolves this vulnerability.Fixed in 3.26.1-3.el10_2.1.aa - Upgrade
Upgrade
gpsdto a version that resolves this vulnerability.Patch CVE-2026-58459
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:51075?
The severity of RHSA-2026:51075 is classified as high, with a score of 7.
How do I fix RHSA-2026:51075?
To fix RHSA-2026:51075, update the affected packages through the package manager provided by Red Hat.
What is the impact of the vulnerability identified in RHSA-2026:51075?
The vulnerability in RHSA-2026:51075 involves command injection risks, allowing attackers to execute arbitrary commands.
Which Red Hat products are affected by RHSA-2026:51075?
The affected products include redhat/gpsd, redhat/gpsd-clients, and other associated packages.
What does gpsd do in the context of RHSA-2026:51075?
gpsd serves as a service daemon that mediates access to GPS sensor data, making it accessible to client applications.