Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package gpsd for openSUSE:Factory checked in at 2026-09-28 10:35:13 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/gpsd (Old) and /work/SRC/openSUSE:Factory/.gpsd.new.383539 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "gpsd" Mon Sep 28 10:35:13 2026 rev:72 rq:1380151 version:3.27.5 Changes: -------- --- /work/SRC/openSUSE:Factory/gpsd/gpsd.changes 2026-07-15 16:30:57.540699958 +0200 +++ /work/SRC/openSUSE:Factory/.gpsd.new.383539/gpsd.changes 2026-09-28 10:35:44.501033820 +0200 @@ -1,0 +2,9 @@ +Wed Sep 23 10:22:10 UTC 2026 - Martin Jungblut Schreiner <[email protected]> + +- Fix for gpsprof arbitrary OS command execution via code injection in + the attacker-controlled SKY.satellites[].used field, inserted + unsanitized into a gnuplot heredoc data block; sat.used is now forced + to a boolean (CVE-2026-60122 [bsc#1280016]) + + 5a9c44a4.patch + +------------------------------------------------------------------- New: ---- 5a9c44a4.patch ----------(New B)---------- New: to a boolean (CVE-2026-60122 [bsc#1280016]) + 5a9c44a4.patch ----------(New E)---------- ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ gpsd.spec ++++++ --- /var/tmp/diff_new_pack.h0GLJW/_old 2026-09-28 10:35:45.215063749 +0200 +++ /var/tmp/diff_new_pack.h0GLJW/_new 2026-09-28 10:35:45.216063791 +0200 @@ -42,6 +42,9 @@ Patch3: https://github.com/ntpsec/gpsd/commit/5581ba1.patch Patch4: https://github.com/ntpsec/gpsd/commit/1a6bb7b.patch Patch5: https://github.com/ntpsec/gpsd/commit/4c06658.patch +# PATCH-FIX-UPSTREAM CVE-2026-60122 bsc#1280016 gpsprof code injection via +# SKY.satellites[].used - https://gitlab.com/gpsd/gpsd/-/work_items/406 +Patch6: https://github.com/ntpsec/gpsd/commit/5a9c44a4.patch BuildRequires: chrpath BuildRequires: fdupes BuildRequires: gcc-c++ ++++++ 5a9c44a4.patch ++++++ >From 5a9c44a42136b9bb98d460a8a716e9fd344a8d93 Mon Sep 17 00:00:00 2001 From: "Gary E. Miller" <[email protected]> Date: Mon, 20 Jul 2026 20:12:16 -0700 Subject: [PATCH] clients/gpsprof.py.in: ensure sats.used is boolean. Issue 406 Prevfent command injection by sates.used. Force to boolean. --- clients/gpsprof.py.in | 9 ++++++++- 1 file changed, 8 insertions(+), 1 deletion(-) diff --git a/clients/gpsprof.py.in b/clients/gpsprof.py.in index e91367ee3..07123d417 100644 --- a/clients/gpsprof.py.in +++ b/clients/gpsprof.py.in @@ -334,8 +334,11 @@ class spaceplot(plotter): # get sat used count sats_used = 0 for sat in self.session.satellites: - if sat.used: + if sat.used is True: sats_used += 1 + else: + # ensure it is boolean. + sat.used = False if 'altHAE' not in self.session.data: self.session.data['altHAE'] = gps.NaN @@ -783,6 +786,10 @@ class polarplot(plotter): used += 1 if 'polarunused' == self.name: continue + else: + # ensure it is boolean. + sat['used'] = False; + if (('polarused' == self.name and sat['used'] is False)): continue
