#VU121180 Integer underflow in gpsd - CVE-2025-67269
Published: January 12, 2026
gpsd
Eric S. Raymond
Description
The vulnerability allows a remote attacker to perform a denial of service attack.
The vulnerability exists due to integer underflow within the nextstate() function in gpsd/packet.c. A remote attacker can send a specially crafted NAVCOM packet to the affected application, trigger an integer underflow and perform a denial of service attack.