Debian Package Tracker
Register | Log in
Subscribe

gpsd

Global Positioning System - daemon

Choose email to subscribe with

general
  • source: gpsd (main)
  • version: 3.27.5-0.1
  • maintainer: Boian Bonev (DMD) (DM)
  • arch: any
  • std-ver: 4.7.2
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 3.22-4
  • o-o-sec: 3.22-4+deb11u1
  • oldstable: 3.22-4.1
  • stable: 3.25-5
  • testing: 3.27.5-0.1
  • unstable: 3.27.5-0.1
versioned links
  • 3.22-4: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 3.22-4+deb11u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 3.22-4.1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 3.25-5: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 3.27.5-0.1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • gpsd (15 bugs: 0, 11, 4, 0)
  • gpsd-clients (4 bugs: 0, 3, 1, 0)
  • gpsd-tools (2 bugs: 0, 2, 0, 0)
  • libgps-dev
  • libgps32
  • libqgpsmm-dev
  • libqgpsmm32
  • python3-gps (2 bugs: 0, 2, 0, 0)
action needed
debian/patches: 1 patch with invalid metadata, 5 patches to forward upstream high

Among the 6 debian patches available in version 3.27.5-0.1 of the package, we noticed the following issues:

  • 1 patch with invalid metadata that ought to be fixed.
  • 5 patches where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2023-02-26 Last update: 2026-01-20 11:00
AppStream hints: 2 errors and 2 warnings high
AppStream found metadata issues for packages:
  • gpsd-clients: 2 errors and 2 warnings
You should get rid of them to provide more metadata about this software.
Created: 2020-06-01 Last update: 2022-01-21 06:05
Depends on packages which need a new maintainer normal
The packages that gpsd depends on which need a new maintainer are:
  • docbook-xml (#802368)
    • Build-Depends: docbook-xml
  • docbook-xsl (#802370)
    • Build-Depends: docbook-xsl
Created: 2023-09-01 Last update: 2026-02-05 03:31
2 low-priority security issues in trixie low

There are 2 open security issues in trixie.

2 issues left for the package maintainer to handle:
  • CVE-2025-67268: (needs triaging) gpsd before commit dc966aa contains a heap-based out-of-bounds write vulnerability in the drivers/driver_nmea2000.c file. The hnd_129540 function, which handles NMEA2000 PGN 129540 (GNSS Satellites in View) packets, fails to validate the user-supplied satellite count against the size of the skyview array (184 elements). This allows an attacker to write beyond the bounds of the array by providing a satellite count up to 255, leading to memory corruption, Denial of Service (DoS), and potentially arbitrary code execution.
  • CVE-2025-67269: (needs triaging) An integer underflow vulnerability exists in the `nextstate()` function in `gpsd/packet.c` of gpsd versions prior to commit `ffa1d6f40bca0b035fc7f5e563160ebb67199da7`. When parsing a NAVCOM packet, the payload length is calculated using `lexer->length = (size_t)c - 4` without checking if the input byte `c` is less than 4. This results in an unsigned integer underflow, setting `lexer->length` to a very large value (near `SIZE_MAX`). The parser then enters a loop attempting to consume this massive number of bytes, causing 100% CPU utilization and a Denial of Service (DoS) condition.

You can find information about how to handle these issues in the security team's documentation.

Created: 2026-01-23 Last update: 2026-01-23 14:00
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.3 instead of 4.7.2).
Created: 2025-12-23 Last update: 2026-01-19 22:19
news
[rss feed]
  • [2026-01-22] gpsd 3.27.5-0.1 MIGRATED to testing (Debian testing watch)
  • [2026-01-19] Accepted gpsd 3.27.5-0.1 (source) into unstable (Bastien Roucariès) (signed by: Bastien ROUCARIÈS)
  • [2026-01-18] Accepted gpsd 3.22-4+deb11u1 (source) into oldoldstable-security (Bastien Roucariès) (signed by: Bastien ROUCARIÈS)
  • [2025-11-29] gpsd 3.27-1.1 MIGRATED to testing (Debian testing watch)
  • [2025-11-27] Accepted gpsd 3.27-1.1 (source) into unstable (Bastian Germann) (signed by: bage@debian.org)
  • [2025-11-26] Accepted gpsd 3.27-1 (source amd64) into experimental (Debian FTP Masters) (signed by: bage@debian.org)
  • [2025-11-19] gpsd 3.26.1-1 MIGRATED to testing (Debian testing watch)
  • [2025-11-16] Accepted gpsd 3.26.1-1 (source amd64) into unstable (Debian FTP Masters) (signed by: Alexandre Detiste)
  • [2025-01-22] gpsd 3.25-5 MIGRATED to testing (Debian testing watch)
  • [2025-01-19] Accepted gpsd 3.25-5 (source) into unstable (Boian Bonev)
  • [2024-05-26] gpsd 3.25-4 MIGRATED to testing (Debian testing watch)
  • [2024-05-23] Accepted gpsd 3.25-4 (source) into unstable (Boian Bonev)
  • [2024-05-03] gpsd 3.25-3 MIGRATED to testing (Debian testing watch)
  • [2024-02-29] Accepted gpsd 3.25-3 (source) into unstable (Boian Bonev)
  • [2024-02-11] Accepted gpsd 3.25-3~exp1 (source) into experimental (Boian Bonev)
  • [2024-02-06] Accepted gpsd 3.25-2.1~exp1 (source) into experimental (Steve Langasek)
  • [2023-09-14] gpsd 3.25-2 MIGRATED to testing (Debian testing watch)
  • [2023-09-11] Accepted gpsd 3.25-2 (source) into unstable (Boian Bonev)
  • [2023-07-01] gpsd 3.25-1 MIGRATED to testing (Debian testing watch)
  • [2023-06-28] Accepted gpsd 3.25-1 (source) into unstable (Boian Bonev)
  • [2023-06-26] Accepted gpsd 3.25-1~exp2 (source) into experimental (Boian Bonev) (signed by: bage@debian.org)
  • [2023-06-13] Accepted gpsd 3.25-1~exp1 (source amd64) into experimental (Debian FTP Masters) (signed by: bage@debian.org)
  • [2022-09-14] gpsd 3.22-4.1 MIGRATED to testing (Debian testing watch)
  • [2022-09-11] Accepted gpsd 3.22-4.1 (source) into unstable (Paul Gevers)
  • [2021-10-28] Accepted gpsd 3.16-4+deb9u1 (source) into oldoldstable (Adrian Bunk)
  • [2021-08-16] Accepted gpsd 3.22-4~bpo10+1 (source amd64) into buster-backports->backports-policy, buster-backports (Debian FTP Masters) (signed by: Bernd Zeimetz)
  • [2021-08-04] gpsd 3.22-4 MIGRATED to testing (Debian testing watch)
  • [2021-08-01] Accepted gpsd 3.22-4 (source) into unstable (Bernd Zeimetz)
  • [2021-04-30] gpsd 3.22-3 MIGRATED to testing (Debian testing watch)
  • [2021-04-25] Accepted gpsd 3.22-3 (source) into unstable (Bernd Zeimetz)
  • 1
  • 2
bugs [bug history graph]
  • all: 29 30
  • RC: 0
  • I&N: 23 24
  • M&W: 6
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • screenshots
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 3.27.5-0.1
  • 2 bugs

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing