Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package gpsd for openSUSE:Factory checked in 
at 2026-09-28 10:35:13
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/gpsd (Old)
 and      /work/SRC/openSUSE:Factory/.gpsd.new.383539 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "gpsd"

Mon Sep 28 10:35:13 2026 rev:72 rq:1380151 version:3.27.5

Changes:
--------
--- /work/SRC/openSUSE:Factory/gpsd/gpsd.changes        2026-07-15 
16:30:57.540699958 +0200
+++ /work/SRC/openSUSE:Factory/.gpsd.new.383539/gpsd.changes    2026-09-28 
10:35:44.501033820 +0200
@@ -1,0 +2,9 @@
+Wed Sep 23 10:22:10 UTC 2026 - Martin Jungblut Schreiner 
<[email protected]>
+
+- Fix for gpsprof arbitrary OS command execution via code injection in
+  the attacker-controlled SKY.satellites[].used field, inserted
+  unsanitized into a gnuplot heredoc data block; sat.used is now forced
+  to a boolean (CVE-2026-60122 [bsc#1280016])
+  + 5a9c44a4.patch
+
+-------------------------------------------------------------------

New:
----
  5a9c44a4.patch

----------(New B)----------
  New:  to a boolean (CVE-2026-60122 [bsc#1280016])
  + 5a9c44a4.patch
----------(New E)----------

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ gpsd.spec ++++++
--- /var/tmp/diff_new_pack.h0GLJW/_old  2026-09-28 10:35:45.215063749 +0200
+++ /var/tmp/diff_new_pack.h0GLJW/_new  2026-09-28 10:35:45.216063791 +0200
@@ -42,6 +42,9 @@
 Patch3:         https://github.com/ntpsec/gpsd/commit/5581ba1.patch
 Patch4:         https://github.com/ntpsec/gpsd/commit/1a6bb7b.patch
 Patch5:         https://github.com/ntpsec/gpsd/commit/4c06658.patch
+# PATCH-FIX-UPSTREAM CVE-2026-60122 bsc#1280016 gpsprof code injection via
+# SKY.satellites[].used - https://gitlab.com/gpsd/gpsd/-/work_items/406
+Patch6:         https://github.com/ntpsec/gpsd/commit/5a9c44a4.patch
 BuildRequires:  chrpath
 BuildRequires:  fdupes
 BuildRequires:  gcc-c++

++++++ 5a9c44a4.patch ++++++
>From 5a9c44a42136b9bb98d460a8a716e9fd344a8d93 Mon Sep 17 00:00:00 2001
From: "Gary E. Miller" <[email protected]>
Date: Mon, 20 Jul 2026 20:12:16 -0700
Subject: [PATCH] clients/gpsprof.py.in: ensure sats.used is boolean.  Issue
 406

Prevfent command injection by sates.used.  Force to boolean.
---
 clients/gpsprof.py.in | 9 ++++++++-
 1 file changed, 8 insertions(+), 1 deletion(-)

diff --git a/clients/gpsprof.py.in b/clients/gpsprof.py.in
index e91367ee3..07123d417 100644
--- a/clients/gpsprof.py.in
+++ b/clients/gpsprof.py.in
@@ -334,8 +334,11 @@ class spaceplot(plotter):
             # get sat used count
             sats_used = 0
             for sat in self.session.satellites:
-                if sat.used:
+                if sat.used is True:
                     sats_used += 1
+                else:
+                    # ensure it is boolean.
+                    sat.used = False
 
             if 'altHAE' not in self.session.data:
                 self.session.data['altHAE'] = gps.NaN
@@ -783,6 +786,10 @@ class polarplot(plotter):
                     used += 1
                     if 'polarunused' == self.name:
                         continue
+                else:
+                    # ensure it is boolean.
+                    sat['used'] = False;
+
                 if (('polarused' == self.name and
                      sat['used'] is False)):
                     continue

Reply via email to