[ALSA-2026:51153] Important: gpsd-minimal security update
Type:
security
Severity:
important
Release date:
2026-08-10
Description:
gpsd is a service daemon that mediates access to a GPS sensor connected to the host computer by serial or USB interface, making its data on the location/course/velocity of the sensor available to be queried on TCP port 2947 of the host computer. The AlmaLinux support for this package is limited. See for more details. Security Fix(es): * gpsd: gpsd: Command Injection via GPS device subtype allows arbitrary code execution (CVE-2026-58459) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 gpsd-minimal-clients-3.26.1-2.el9_8.1.aarch64.rpm 66c5c308e5995aef2efc3dfcd7829a45ac2af473b828b686a76c88c701777865
aarch64 gpsd-minimal-3.26.1-2.el9_8.1.aarch64.rpm 901ebb2a50a226edac7356993d99ab543b7df799117ab8891341d354b43effac
ppc64le gpsd-minimal-clients-3.26.1-2.el9_8.1.ppc64le.rpm 760a7de4bedef6aed8b00ef1fe94cbb64289e8f6c5f53419f40038d9dc6aa196
ppc64le gpsd-minimal-3.26.1-2.el9_8.1.ppc64le.rpm a8de90bb73056660b7f33c616cea051f61610b83e1c5fa8c39bd8d3ae717effe
s390x gpsd-minimal-3.26.1-2.el9_8.1.s390x.rpm 1068c154e22b68ed36c11e128979e108ebb4518a90bfe351baff0cac73902ab3
s390x gpsd-minimal-clients-3.26.1-2.el9_8.1.s390x.rpm ce7b36e98fbade6db22682021aec0d11e7d632ae970202b1113eb9ef7e82d219
x86_64 gpsd-minimal-3.26.1-2.el9_8.1.x86_64.rpm 39fa3f05448aac610677e3478938ea80d2531f090818de0769551d6ded7b9c1a
x86_64 gpsd-minimal-clients-3.26.1-2.el9_8.1.x86_64.rpm fb68944b6a2d5d6bfdf15c558beef910d9369f7f23ac0251be8eff16c9a6ad02
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.