Updated gpsd packages fix a security vulnerability
Publication date: 25 Sep 2026Modification date: 25 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-58459
Description
Command Injection via gnuplot plot title subtype field. (CVE-2026-58459)
References
- https://bugs.mageia.org/show_bug.cgi?id=35953
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/AQ2ORFQ66FNIA3MWLLYYOG4BV4FARQUN/
- https://gitlab.com/gpsd/gpsd/-/work_items/404#note_3534119267
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CFEVG42PGVGT7U55DLZYEB2HKIVYGMPM/
- https://www.cve.org/CVERecord?id=CVE-2026-58459
SRPMS
10/core
- gpsd-3.27.5-1.1.mga10
9/core
- gpsd-3.25-1.2.mga9