[CLSA-2026:1786360070] gpsd-minimal: Fix of CVE-2026-58459
Type:
security
Severity:
Critical
Release date:
2026-08-13 05:08:32 UTC
Description:
- CVE-2026-58459: escape back ticks and double quotes in the gpsprof gnuplot title and terminal to prevent command injection via the device subtype
CVEs fixed:
Updated packages:
  • gpsd-minimal-3.25-4.el9_6.2.tuxcare.els2.x86_64.rpm
    sha:73ca77d0552a8b0832d0941ea55797d0f2909359e11f5048ad5a5889f2ffc6f4
  • gpsd-minimal-clients-3.25-4.el9_6.2.tuxcare.els2.x86_64.rpm
    sha:2ac9f339b51deb21b2e3aee7762a2e345d455ed0dc9917f668be4803442dba24
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.