Debian Package Tracker
Register | Log in
Subscribe

gpsd

Global Positioning System - daemon

Choose email to subscribe with

general
  • source: gpsd (main)
  • version: 3.27.5-1
  • maintainer: Boian Bonev (DMD) (DM)
  • arch: any
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 3.22-4
  • o-o-sec: 3.22-4+deb11u1
  • oldstable: 3.22-4.1+deb12u1
  • stable: 3.25-5+deb13u1
  • testing: 3.27.5-0.1
  • unstable: 3.27.5-1
versioned links
  • 3.22-4: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 3.22-4+deb11u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 3.22-4.1+deb12u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 3.25-5+deb13u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 3.27.5-0.1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 3.27.5-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • gpsd (17 bugs: 0, 13, 4, 0)
  • gpsd-clients (4 bugs: 0, 3, 1, 0)
  • gpsd-tools (2 bugs: 0, 2, 0, 0)
  • libgps-dev
  • libgps32
  • libqgpsmm-dev
  • libqgpsmm32
  • python3-gps (2 bugs: 0, 2, 0, 0)
action needed
2 security issues in forky high

There are 2 open security issues in forky.

2 important issues:
  • CVE-2026-58459: gpsd through release-3.27.5, fixed at commit 4c06658, contains a command injection vulnerability in gpsprof that allows attackers who control the GPS device subtype value to execute arbitrary shell commands by embedding backtick payloads in the gnuplot plot title without proper escaping. The subtype field sourced from a DEVICES JSON log entry or NMEA PGRMT sentence is written into a generated gnuplot program via a set title statement with only double-quote characters escaped, enabling arbitrary shell command execution as the user running gnuplot when the victim renders the generated plot through the gpsprof and gnuplot workflow.
  • CVE-2026-60122: gpsd through release-3.27.5, fixed at commit 4c06658, contains a code injection vulnerability in the gpsprof utility that allows an attacker who controls GPS input data to execute arbitrary OS commands by injecting malicious content into the SKY.satellites[].used field, which is inserted unsanitized into a gnuplot heredoc data block. Attackers can supply a used value containing the string EOD to terminate the heredoc early and append gnuplot system() calls, achieving OS command execution as the user running gpsprof when the generated plot script is processed by gnuplot in polar mode.
Created: 2026-07-10 Last update: 2026-07-26 11:00
2 security issues in bullseye high

There are 2 open security issues in bullseye.

1 important issue:
  • CVE-2026-60122: gpsd through release-3.27.5, fixed at commit 4c06658, contains a code injection vulnerability in the gpsprof utility that allows an attacker who controls GPS input data to execute arbitrary OS commands by injecting malicious content into the SKY.satellites[].used field, which is inserted unsanitized into a gnuplot heredoc data block. Attackers can supply a used value containing the string EOD to terminate the heredoc early and append gnuplot system() calls, achieving OS command execution as the user running gpsprof when the generated plot script is processed by gnuplot in polar mode.
1 issue postponed or untriaged:
  • CVE-2026-58459: (postponed; to be fixed through a stable update) gpsd through release-3.27.5, fixed at commit 4c06658, contains a command injection vulnerability in gpsprof that allows attackers who control the GPS device subtype value to execute arbitrary shell commands by embedding backtick payloads in the gnuplot plot title without proper escaping. The subtype field sourced from a DEVICES JSON log entry or NMEA PGRMT sentence is written into a generated gnuplot program via a set title statement with only double-quote characters escaped, enabling arbitrary shell command execution as the user running gnuplot when the victim renders the generated plot through the gpsprof and gnuplot workflow.
Created: 2026-07-25 Last update: 2026-07-26 11:00
2 security issues in bookworm high

There are 2 open security issues in bookworm.

1 important issue:
  • CVE-2026-60122: gpsd through release-3.27.5, fixed at commit 4c06658, contains a code injection vulnerability in the gpsprof utility that allows an attacker who controls GPS input data to execute arbitrary OS commands by injecting malicious content into the SKY.satellites[].used field, which is inserted unsanitized into a gnuplot heredoc data block. Attackers can supply a used value containing the string EOD to terminate the heredoc early and append gnuplot system() calls, achieving OS command execution as the user running gpsprof when the generated plot script is processed by gnuplot in polar mode.
1 issue left for the package maintainer to handle:
  • CVE-2026-58459: (postponed; to be fixed through a stable update) gpsd through release-3.27.5, fixed at commit 4c06658, contains a command injection vulnerability in gpsprof that allows attackers who control the GPS device subtype value to execute arbitrary shell commands by embedding backtick payloads in the gnuplot plot title without proper escaping. The subtype field sourced from a DEVICES JSON log entry or NMEA PGRMT sentence is written into a generated gnuplot program via a set title statement with only double-quote characters escaped, enabling arbitrary shell command execution as the user running gnuplot when the victim renders the generated plot through the gpsprof and gnuplot workflow.

You can find information about how to handle this issue in the security team's documentation.

Created: 2026-07-10 Last update: 2026-07-26 11:00
debian/patches: 1 patch with invalid metadata, 5 patches to forward upstream high

Among the 8 debian patches available in version 3.27.5-1 of the package, we noticed the following issues:

  • 1 patch with invalid metadata that ought to be fixed.
  • 5 patches where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2023-02-26 Last update: 2026-07-26 06:00
AppStream hints: 2 errors and 2 warnings high
AppStream found metadata issues for packages:
  • gpsd-clients: 2 errors and 2 warnings
You should get rid of them to provide more metadata about this software.
Created: 2020-06-01 Last update: 2022-01-21 06:05
2 bugs tagged patch in the BTS normal
The BTS contains patches fixing 2 bugs, consider including or untagging them.
Created: 2026-06-02 Last update: 2026-07-26 13:00
Depends on packages which need a new maintainer normal
The packages that gpsd depends on which need a new maintainer are:
  • docbook-xsl (#802370)
    • Build-Depends: docbook-xsl
Created: 2023-09-01 Last update: 2026-07-26 10:18
6 new commits since last upload, is it time to release? normal
vcswatch reports that this package seems to have new commits in its VCS but has not yet updated debian/changelog. You should consider updating the Debian changelog and uploading this new version into the archive.

Here are the relevant commit logs:
commit 8b95dd6572c3a2da560a5fe62274127066d8d1c9
Author: Boian Bonev <bbonev@ipacct.com>
Date:   Sat Jul 25 22:12:12 2026 +0000

    Updating debian/control from debian/control.in

commit c7db0fe7757410d49f9995e4396c2cdd4e2ac8d9
Author: Boian Bonev <bbonev@ipacct.com>
Date:   Sat Jul 25 22:11:48 2026 +0000

    bump std to 4.7.4, dh to 14; remove prio

commit 1295bedf5021560d4d3b05cd15c9e5d868dc8c1e
Author: Boian Bonev <bbonev@ipacct.com>
Date:   Sat Jul 25 22:06:17 2026 +0000

    Updating debian/control from debian/control.in

commit 719780c4d0703ed982762650ec411cf529f4482e
Author: Boian Bonev <bbonev@ipacct.com>
Date:   Sat Jul 25 22:05:59 2026 +0000

    bump std to 4.7.4, dh to 14; remove prio

commit 3fe6ba0551826d3c23a1ce8fffe2e0894ec56f9e
Author: Boian Bonev <bbonev@ipacct.com>
Date:   Sat Jul 25 22:05:22 2026 +0000

    bump std to 4.7.4, dh to 14; remove prio

commit fcb91ffb83b0aa72048b43d571f845c96c9954e3
Author: Boian Bonev <bbonev@ipacct.com>
Date:   Sat Jul 25 21:53:08 2026 +0000

    fix CVE-2026-58459 & CVE-2026-60122


https://salsa.debian.org/api/v4/projects/debian-gps-team%2Fpkg-gpsd API request failed: 401 Unauthorized at /srv/qa.debian.org/data/vcswatch/vcswatch line 410.
Created: 2026-07-25 Last update: 2026-07-26 04:02
2 low-priority security issues in trixie low

There are 2 open security issues in trixie.

2 issues left for the package maintainer to handle:
  • CVE-2026-58459: (needs triaging) gpsd through release-3.27.5, fixed at commit 4c06658, contains a command injection vulnerability in gpsprof that allows attackers who control the GPS device subtype value to execute arbitrary shell commands by embedding backtick payloads in the gnuplot plot title without proper escaping. The subtype field sourced from a DEVICES JSON log entry or NMEA PGRMT sentence is written into a generated gnuplot program via a set title statement with only double-quote characters escaped, enabling arbitrary shell command execution as the user running gnuplot when the victim renders the generated plot through the gpsprof and gnuplot workflow.
  • CVE-2026-60122: (needs triaging) gpsd through release-3.27.5, fixed at commit 4c06658, contains a code injection vulnerability in the gpsprof utility that allows an attacker who controls GPS input data to execute arbitrary OS commands by injecting malicious content into the SKY.satellites[].used field, which is inserted unsanitized into a gnuplot heredoc data block. Attackers can supply a used value containing the string EOD to terminate the heredoc early and append gnuplot system() calls, achieving OS command execution as the user running gpsprof when the generated plot script is processed by gnuplot in polar mode.

You can find information about how to handle these issues in the security team's documentation.

Created: 2026-07-10 Last update: 2026-07-26 11:00
testing migrations
  • excuses:
    • Migration status for gpsd (3.27.5-0.1 to 3.27.5-1): Waiting for test results or another package, or too young (no action required now - check later)
    • Issues preventing migration:
    • ∙ ∙ Autopkgtest for gpsd/3.27.5-1: amd64: Test triggered, arm64: Test triggered, armhf: Pass, i386: Test triggered, loong64: Test triggered, ppc64el: Test triggered, riscv64: Pass, s390x: Test triggered
    • ∙ ∙ Reproducibility check waiting for results on arm64 - info
    • ∙ ∙ Reproducibility check waiting for results on i386 - info
    • ∙ ∙ Too young, only 0 of 5 days old
    • Additional info (not blocking):
    • ∙ ∙ Piuparts tested OK - https://piuparts.debian.org/sid/source/g/gpsd.html
    • ∙ ∙ Reproduced on amd64 - info
    • ∙ ∙ Reproduced on armhf - info
    • Not considered
news
[rss feed]
  • [2026-07-25] Accepted gpsd 3.27.5-1 (source) into unstable (Boian Bonev)
  • [2026-05-02] Accepted gpsd 3.22-4.1+deb12u1 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Bastien ROUCARIÈS)
  • [2026-03-01] Accepted gpsd 3.25-5+deb13u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Bastien ROUCARIÈS)
  • [2026-01-22] gpsd 3.27.5-0.1 MIGRATED to testing (Debian testing watch)
  • [2026-01-19] Accepted gpsd 3.27.5-0.1 (source) into unstable (Bastien Roucariès) (signed by: Bastien ROUCARIÈS)
  • [2026-01-18] Accepted gpsd 3.22-4+deb11u1 (source) into oldoldstable-security (Bastien Roucariès) (signed by: Bastien ROUCARIÈS)
  • [2025-11-29] gpsd 3.27-1.1 MIGRATED to testing (Debian testing watch)
  • [2025-11-27] Accepted gpsd 3.27-1.1 (source) into unstable (Bastian Germann) (signed by: bage@debian.org)
  • [2025-11-26] Accepted gpsd 3.27-1 (source amd64) into experimental (Debian FTP Masters) (signed by: bage@debian.org)
  • [2025-11-19] gpsd 3.26.1-1 MIGRATED to testing (Debian testing watch)
  • [2025-11-16] Accepted gpsd 3.26.1-1 (source amd64) into unstable (Debian FTP Masters) (signed by: Alexandre Detiste)
  • [2025-01-22] gpsd 3.25-5 MIGRATED to testing (Debian testing watch)
  • [2025-01-19] Accepted gpsd 3.25-5 (source) into unstable (Boian Bonev)
  • [2024-05-26] gpsd 3.25-4 MIGRATED to testing (Debian testing watch)
  • [2024-05-23] Accepted gpsd 3.25-4 (source) into unstable (Boian Bonev)
  • [2024-05-03] gpsd 3.25-3 MIGRATED to testing (Debian testing watch)
  • [2024-02-29] Accepted gpsd 3.25-3 (source) into unstable (Boian Bonev)
  • [2024-02-11] Accepted gpsd 3.25-3~exp1 (source) into experimental (Boian Bonev)
  • [2024-02-06] Accepted gpsd 3.25-2.1~exp1 (source) into experimental (Steve Langasek)
  • [2023-09-14] gpsd 3.25-2 MIGRATED to testing (Debian testing watch)
  • [2023-09-11] Accepted gpsd 3.25-2 (source) into unstable (Boian Bonev)
  • [2023-07-01] gpsd 3.25-1 MIGRATED to testing (Debian testing watch)
  • [2023-06-28] Accepted gpsd 3.25-1 (source) into unstable (Boian Bonev)
  • [2023-06-26] Accepted gpsd 3.25-1~exp2 (source) into experimental (Boian Bonev) (signed by: bage@debian.org)
  • [2023-06-13] Accepted gpsd 3.25-1~exp1 (source amd64) into experimental (Debian FTP Masters) (signed by: bage@debian.org)
  • [2022-09-14] gpsd 3.22-4.1 MIGRATED to testing (Debian testing watch)
  • [2022-09-11] Accepted gpsd 3.22-4.1 (source) into unstable (Paul Gevers)
  • [2021-10-28] Accepted gpsd 3.16-4+deb9u1 (source) into oldoldstable (Adrian Bunk)
  • [2021-08-16] Accepted gpsd 3.22-4~bpo10+1 (source amd64) into buster-backports->backports-policy, buster-backports (Debian FTP Masters) (signed by: Bernd Zeimetz)
  • [2021-08-04] gpsd 3.22-4 MIGRATED to testing (Debian testing watch)
  • 1
  • 2
bugs [bug history graph]
  • all: 32 33
  • RC: 0
  • I&N: 26 27
  • M&W: 6
  • F&P: 0
  • patch: 2
links
  • homepage
  • lintian
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 3.27.5-0.1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing