What is CVE-2026-60122?
gpsd through version 3.27.5, fixed in commit 4c06658, contains a code injection vulnerability in the gpsprof utility. An attacker controlling GPS input data can execute arbitrary OS commands by injecting malicious content into the unsanitized SKY.satellites[].used field. Immediate update to the patched version is required.
Azərbaycanca: gpsd proqramının 3.27.5 versiyasına qədər olan versiyalarında gpsprof utilitində code injection zəifliyi aşkarlanıb. GPS giriş məlumatlarını idarə edən hücumçu, SKY.satellites[].used sahəsinə təmizlənməmiş zərərli məzmun daxil edərək ixtiyari OS əmrləri icra edə bilər. dərhal commit 4c06658 ilə düzəldilmiş versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-94
FAQ1
Which input field in gpsprof utility causes the code injection vulnerability?
The unsanitized SKY.satellites[].used field allows injection of malicious content.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.