Integer underflow in gpsd - CVE-2025-67269
Published: January 12, 2026
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service attack.
The vulnerability exists due to integer underflow within the nextstate() function in gpsd/packet.c. A remote attacker can send a specially crafted NAVCOM packet to the affected application, trigger an integer underflow and perform a denial of service attack.
Affected software
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Ubuntu
Anolis OS
openEuler
gpsd (Ubuntu package)
gpsd
python3-gpsd
gpsd-clients
gpsd-debuginfo
gpsd-debugsource
gpsd-devel
gpsd-libs
gpsd-qt
gpsd-qt-devel
gpsd-xclients
gpsd-minimal (Red Hat package)
gpsd (Red Hat package)
How to mitigate CVE-2025-67269
gpsd (Ubuntu package) - addressed in versions 3.22-4ubuntu2.1, 3.25-3ubuntu3.2, 3.25-5ubuntu1.25.04.1, 3.25-5ubuntu1.25.10.1
gpsd - update to 3.25-3
python3-gpsd - update to 3.25-3
gpsd-clients - update to 3.25-3
gpsd-debuginfo - update to 3.25-3
gpsd-debugsource - update to 3.25-3
gpsd-devel - update to 3.25-3
gpsd-libs - update to 3.25-3
gpsd-qt - update to 3.25-3
gpsd-qt-devel - update to 3.25-3
gpsd-xclients - update to 3.25-3
gpsd - update to 3.25-3
gpsd-clients - update to 3.25-3
gpsd-devel - update to 3.25-3
gpsd-libs - update to 3.25-3
gpsd-qt - update to 3.25-3
gpsd-qt-devel - update to 3.25-3
gpsd-xclients - update to 3.25-3
python3-gpsd - update to 3.25-3
gpsd-minimal (Red Hat package) - update to 3.26.1-1.el9_7.1
gpsd (Red Hat package) - update to 3.26.1-1.el10_1.1