Red Hat Product Errata RHSA-2026:51075 - Security Advisory Issued: 2026-08-06 Updated: 2026-08-06 RHSA-2026:51075 - Security Advisory Overview Updated Packages Synopsis Important: gpsd security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for gpsd is now available for Red Hat Enterprise Linux 10. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description gpsd is a service daemon that mediates access to a GPS sensor connected to the host computer by serial or USB interface, making its data on the location/course/velocity of the sensor available to be queried on TCP port 2947 of the host computer. With gpsd, multiple GPS client applications (such as navigational and war-driving software) can share access to a GPS without contention or loss of data. Also, gpsd responds to queries with a format that is substantially easier to parse than NMEA 0183. The Red Hat support for this package is limited. See https://access.redhat.com/support/policy/gpsd-support for more details. Security Fix(es): gpsd: gpsd: Command Injection via GPS device subtype allows arbitrary code execution (CVE-2026-58459) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 10 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 x86_64 Red Hat Enterprise Linux for IBM z Systems 10 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 s390x Red Hat Enterprise Linux for Power, little endian 10 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2 ppc64le Red Hat Enterprise Linux for ARM 64 10 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.2 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.2 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.2 s390x Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.2 ppc64le Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.2 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 10.2 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 10.2 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 10.2 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 10.2 s390x Fixes BZ - 2498575 - CVE-2026-58459 gpsd: gpsd: Command Injection via GPS device subtype allows arbitrary code execution CVEs CVE-2026-58459 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 10 SRPM gpsd-3.26.1-3.el10_2.1.src.rpm SHA-256: 1d3410b22531da8bf033f216ef2742afb8fa24749090dc12b87460b6dfa71f6a x86_64 gpsd-3.26.1-3.el10_2.1.x86_64.rpm SHA-256: 8ba709f437d69256762a2320da15408e41fd213e77fa323c799e27269b7f1a24 gpsd-clients-3.26.1-3.el10_2.1.x86_64.rpm SHA-256: f288f32bb72847592cdfa1c405ed0eb81141d6df0731779c97719cdb394821ea gpsd-clients-debuginfo-3.26.1-3.el10_2.1.x86_64.rpm SHA-256: 66ab720896289cc0c436044f5f7dd7a11bf1fa8093a4059c9ec60a9f7dad7886 gpsd-debuginfo-3.26.1-3.el10_2.1.x86_64.rpm SHA-256: ccc187e9f60fe04d7b00fabe982e21b704d10c522a71120f329e7e35fd9c490e gpsd-debugsource-3.26.1-3.el10_2.1.x86_64.rpm SHA-256: 9374a50a2650370f765a15a065ed0a560b0b1491c446940ba4769fb391e76f01 python3-gpsd-3.26.1-3.el10_2.1.x86_64.rpm SHA-256: c9c00f3b275af9da32447a7bd21809adfa5ba12017e4d1bf35317a8f67545053 python3-gpsd-debuginfo-3.26.1-3.el10_2.1.x86_64.rpm SHA-256: 65a5e457e78ca0684916083a3cdbc6a803ea653e6375529d426aae6ee1224bdb Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 SRPM gpsd-3.26.1-3.el10_2.1.src.rpm SHA-256: 1d3410b22531da8bf033f216ef2742afb8fa24749090dc12b87460b6dfa71f6a x86_64 gpsd-3.26.1-3.el10_2.1.x86_64.rpm SHA-256: 8ba709f437d69256762a2320da15408e41fd213e77fa323c799e27269b7f1a24 gpsd-clients-3.26.1-3.el10_2.1.x86_64.rpm SHA-256: f288f32bb72847592cdfa1c405ed0eb81141d6df0731779c97719cdb394821ea gpsd-clients-debuginfo-3.26.1-3.el10_2.1.x86_64.rpm SHA-256: 66ab720896289cc0c436044f5f7dd7a11bf1fa8093a4059c9ec60a9f7dad7886 gpsd-debuginfo-3.26.1-3.el10_2.1.x86_64.rpm SHA-256: ccc187e9f60fe04d7b00fabe982e21b704d10c522a71120f329e7e35fd9c490e gpsd-debugsource-3.26.1-3.el10_2.1.x86_64.rpm SHA-256: 9374a50a2650370f765a15a065ed0a560b0b1491c446940ba4769fb391e76f01 python3-gpsd-3.26.1-3.el10_2.1.x86_64.rpm SHA-256: c9c00f3b275af9da32447a7bd21809adfa5ba12017e4d1bf35317a8f67545053 python3-gpsd-debuginfo-3.26.1-3.el10_2.1.x86_64.rpm SHA-256: 65a5e457e78ca0684916083a3cdbc6a803ea653e6375529d426aae6ee1224bdb Red Hat Enterprise Linux for IBM z Systems 10 SRPM gpsd-3.26.1-3.el10_2.1.src.rpm SHA-256: 1d3410b22531da8bf033f216ef2742afb8fa24749090dc12b87460b6dfa71f6a s390x gpsd-3.26.1-3.el10_2.1.s390x.rpm SHA-256: 7bf7fb55cfe4e24ed052a52c0afd07002f6514f5d44360a4d21b27e9e31d0e49 gpsd-clients-3.26.1-3.el10_2.1.s390x.rpm SHA-256: 76954b764a8e157488a2e12ab53a5e410a76204fe8684114f9cefaee9a2fd572 gpsd-clients-debuginfo-3.26.1-3.el10_2.1.s390x.rpm SHA-256: 0f33e8f77e4ee84a9905d12c59281e7133e116e2ac766ac9bcc8aee6788c9e40 gpsd-debuginfo-3.26.1-3.el10_2.1.s390x.rpm SHA-256: c3926c7c85416bc54f4bad07548dad70b0d6cde670571edb5736f2c50b0dba0f gpsd-debugsource-3.26.1-3.el10_2.1.s390x.rpm SHA-256: a9a8b69804a4859e05f95d810de0b143bd2f34f7a2a4f9e6b547f17ead5e794f python3-gpsd-3.26.1-3.el10_2.1.s390x.rpm SHA-256: 41e630b02c148eda01cd21706c58dca6a468fe7460bcc583e711c6683f2a03fd python3-gpsd-debuginfo-3.26.1-3.el10_2.1.s390x.rpm SHA-256: 8ac895e11ec7e1449d7bb2ddd931cdd1c47a4dc913641e98bdb1deeb3d8906cd Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 SRPM gpsd-3.26.1-3.el10_2.1.src.rpm SHA-256: 1d3410b22531da8bf033f216ef2742afb8fa24749090dc12b87460b6dfa71f6a s390x gpsd-3.26.1-3.el10_2.1.s390x.rpm SHA-256: 7bf7fb55cfe4e24ed052a52c0afd07002f6514f5d44360a4d21b27e9e31d0e49 gpsd-clients-3.26.1-3.el10_2.1.s390x.rpm SHA-256: 76954b764a8e157488a2e12ab53a5e410a76204fe8684114f9cefaee9a2fd572 gpsd-clients-debuginfo-3.26.1-3.el10_2.1.s390x.rpm SHA-256: 0f33e8f77e4ee84a9905d12c59281e7133e116e2ac766ac9bcc8aee6788c9e40 gpsd-debuginfo-3.26.1-3.el10_2.1.s390x.rpm SHA-256: c3926c7c85416bc54f4bad07548dad70b0d6cde670571edb5736f2c50b0dba0f gpsd-debugsource-3.26.1-3.el10_2.1.s390x.rpm SHA-256: a9a8b69804a4859e05f95d810de0b143bd2f34f7a2a4f9e6b547f17ead5e794f python3-gpsd-3.26.1-3.el10_2.1.s390x.rpm SHA-256: 41e630b02c148eda01cd21706c58dca6a468fe7460bcc583e711c6683f2a03fd python3-gpsd-debuginfo-3.26.1-3.el10_2.1.s390x.rpm SHA-256: 8ac895e11ec7e1449d7bb2ddd931cdd1c47a4dc913641e98bdb1deeb3d8906cd Red Hat Enterprise Linux for Power, little endian 10 SRPM gpsd-3.26.1-3.el10_2.1.src.rpm SHA-256: 1d3410b22531da8bf033f216ef2742afb8fa24749090dc12b87460b6dfa71f6a ppc64le gpsd-3.26.1-3.el10_2.1.ppc64le.rpm SHA-256: 769ad662b5de25f51ff3cef45eb8857f513105a8689171ef08b2cfe4de71900e gpsd-clients-3.26.1-3.el10_2.1.ppc64le.rpm SHA-256: f0ef67aaa0343a64f2953b5645048c62cbe0ceedb6e32b9c1e46289858cbd7e4 gpsd-clients-debuginfo-3.26.1-3.el10_2.1.ppc64le.rpm SHA-256: 8bbca1465668913b7ee6c29d8fd687e7261bf304bf2eaa6212988edfcae62f87 gpsd-debuginfo-3.26.1-3.el10_2.1.ppc64le.rpm SHA-256: d1683a47023b15fd9487a63ee4abf539c7c5ac3fa0d159a58f6e3ae64f7868d3 gpsd-debugsource-3.26.1-3.el10_2.1.ppc64le.rpm SHA-256: 6bd78b82edb277be7845eab573729cf0f231d4e89d6772467cc3fa18abff7177 python3-gpsd-3.26.1-3.el10_2.1.ppc64le.rpm SHA-256: 548d29b08cdb7b20aa8f4797d452914b49f58cef3854a3d9a6a6d9728bbc7218 python3-gpsd-debuginfo-3.26.1-3.el10_2.1.ppc64le.rpm SHA-256: 533a285263c103bfe9900eae2a91337989717d173450d4ad1f44e5785220082e Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2 SRPM gpsd-3.26.1-3.el10_2.1.src.rpm SHA-256: 1d3410b22531da8bf033f216ef2742afb8fa24749090dc12b87460b6dfa71f6a ppc64le gpsd-3.26.1-3.el10_2.1.ppc64le.rpm SHA-256: 769ad662b5de25f51ff3cef45eb8857f513105a8689171ef08b2cfe4de71900e gpsd-clients-3.26.1-3.el10_2.1.ppc64le.rpm SHA-256: f0ef67aaa0343a64f2953b5645048c62cbe0ceedb6e32b9c1e46289858cbd7e4 gpsd-clients-debuginfo-3.26.1-3.el10_2.1.ppc64le.rpm SHA-256: 8bbca1465668913b7ee6c29d8fd687e7261bf304bf2eaa6212988edfcae62f87 gpsd-debuginfo-3.26.1-3.el10_2.1.ppc64le.rpm SHA-256: d1683a47023b15fd9487a63ee4abf539c7c5ac3fa0d159a58f6e3ae64f7868d3 gpsd-debugsource-3.26.1-3.el10_2.1.ppc64le.rpm SHA-256: 6bd78b82edb277be7845eab573729cf0f231d4e89d6772467cc3fa18abff7177 python3-gpsd-3.26.1-3.el10_2.1.ppc64le.rpm SHA-256: 548d29b08cdb7b20aa8f4797d452914b49f58cef3854a3d9a6a6d9728bbc7218 python3-gpsd-debuginfo-3.26.1-3.el10_2.1.ppc64le.rpm SHA-256: 533a285263c103bfe9900eae2a91337989717d173450d4ad1f44e5785220082e Red Hat Enterprise Linux for ARM 64 10 SRPM gpsd-3.26.1-3.el10_2.1.src.rpm SHA-256: 1d3410b22531da8bf033f216ef2742afb8fa24749090dc12b87460b6dfa71f6a aarch64 gpsd-3.26.1-3.el10_2.1.aarch64.rpm SHA-256: 0020c5a10cffd9659fa6efac15eb346032fc7fae6ee545286310b4a22113526f gpsd-clients-3.26.1-3.el10_2.1.aarch64.rpm SHA-256: 6ed3bd314b0dd5a2719ad4c267136c15d8d64f6bd332886df68e4704237187f8 gpsd-clients-debuginfo-3.26.1-3.el10_2.1.aarch64.rpm SHA-256: 7dc9df004b2ab163c255e415cfb8aa6934ac6190ea76d446f5de7775b431cc57 gpsd-debuginfo-3.26.1-3.el10_2.1.aarch64.rpm SHA-256: 4ab445079706fff89addbb135bfc7c29c4627bc18537fba31d7bfe8195d567f8 gpsd-debugsource-3.26.1-3.el10_2.1.aarch64.rpm SHA-256: 2854
A command injection vulnerability (CVE-2026-58459, CVSS 7.8 HIGH) in gpsd allows arbitrary code execution via a crafted GPS device subtype. The vulnerability affects gpsd_project gpsd versions up to and including 3.27.5. Red Hat has released a security update rated Important to address this issue for gpsd on Red Hat Enterprise Linux 10.