PatchSiren

gpsd CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH gpsd CVE published 2026-07-23

CVE-2026-60122

A HIGH severity vulnerability was found in gpsd's gpsprof utility, which allows code injection via the SKY.satellites[].used field. This vulnerability, tracked as CVE-2026-60122, was publicly disclosed on 2026-07-23T20:17:09.207Z and last modified on 2026-07-27T17:16:37.857Z. The vulnerability allows an attacker who controls GPS input data to execute arbitrary OS commands by injecting malicious content in [truncated]