fix command injection in gpsprof (CVE-2026-58459)

Resolves: RHEL-193991
This commit is contained in:
Miroslav Lichvar 2026-07-13 11:33:15 +02:00
parent e0716f2a1c
commit 6f4e5ab82d
2 changed files with 132 additions and 0 deletions

130
gpsd-cve-2026-58459.patch Normal file
View File

@ -0,0 +1,130 @@
commit 5581ba196d826a984fbfaf792b7d58535f9911ce
Author: Gary E. Miller <gem@rellim.com>
Date: Wed Jul 1 17:55:57 2026 -0700
clients/gpsprof.py.in: Quote double quotes in title.
Someone could use the double quote to break out of the
string and add gnuplot commnds.
For issue 404.
Reported by: CuB3y0nd, and Wade Sparks <wsparks@vulncheck.com>
diff --git a/clients/gpsprof.py.in b/clients/gpsprof.py.in
index 5c18f50ff..261e72665 100644
--- a/clients/gpsprof.py.in
+++ b/clients/gpsprof.py.in
@@ -198,6 +198,10 @@ class plotter(object):
if 'subtype' in self.device:
desc += "\\n%s" % self.device['subtype']
+ # escape ", and \n, for gnuplot, to not break strings
+ desc = desc.replace('"', '\\042')
+ desc = desc.replace('\n', '')
+
return desc
def collect(self, verb, log_fp=None):
@@ -1262,10 +1266,10 @@ if __name__ == '__main__':
# Ship the plot to standard output
if not options.title:
options.title = plot.whatami()
- # escape " for gnuplot
- options.title = options.title.replace('"', '\\"')
if options.subtitle:
options.title += '\\n' + options.subtitle
+ # escape " for gnuplot, to not break strings
+ options.title = options.title.replace('"', '\\042')
term_opts = ""
truecolor_terms = ['png', 'sixelgd', 'wxt']
if options.terminal in truecolor_terms:
commit 1a6bb7bcbdf58aa940132e630870af061dc88537
Author: Gary E. Miller <gem@rellim.com>
Date: Tue Jul 7 13:41:54 2026 -0700
clients/gpsprof.py.in: Quote back ticks in title.
Someone could use the back tick to break out of the string and add
gnuplot commnds.
For issue 404.
Reported by: CuB3y0nd, and Wade Sparks <wsparks@vulncheck.com>
diff --git a/clients/gpsprof.py.in b/clients/gpsprof.py.in
index 261e72665..202214769 100644
--- a/clients/gpsprof.py.in
+++ b/clients/gpsprof.py.in
@@ -198,8 +198,9 @@ class plotter(object):
if 'subtype' in self.device:
desc += "\\n%s" % self.device['subtype']
- # escape ", and \n, for gnuplot, to not break strings
+ # escape ", `, and \n, for gnuplot, to not break strings
desc = desc.replace('"', '\\042')
+ desc = desc.replace('`', '\\140')
desc = desc.replace('\n', '')
return desc
@@ -1268,8 +1269,9 @@ if __name__ == '__main__':
options.title = plot.whatami()
if options.subtitle:
options.title += '\\n' + options.subtitle
- # escape " for gnuplot, to not break strings
+ # escape ", and`, for gnuplot, to not break strings
options.title = options.title.replace('"', '\\042')
+ options.title = options.title.replace('"', '\\140')
term_opts = ""
truecolor_terms = ['png', 'sixelgd', 'wxt']
if options.terminal in truecolor_terms:
commit 4c06658e988f4ced1a7a574ce082a22ef625df56
Author: Gary E. Miller <gem@rellim.com>
Date: Tue Jul 7 14:23:56 2026 -0700
clients/gpsprof.py.in: Quote back ticks in title.
Second try. Also quote "terminal".
Someone could use the back tick to break out of the string and add
gnuplot commnds.
For issue 404.
Reported by: CuB3y0nd, and Wade Sparks <wsparks@vulncheck.com>
diff --git a/clients/gpsprof.py.in b/clients/gpsprof.py.in
index 202214769..e91367ee3 100644
--- a/clients/gpsprof.py.in
+++ b/clients/gpsprof.py.in
@@ -200,7 +200,7 @@ class plotter(object):
# escape ", `, and \n, for gnuplot, to not break strings
desc = desc.replace('"', '\\042')
- desc = desc.replace('`', '\\140')
+ desc = desc.replace("\x60", '\\140')
desc = desc.replace('\n', '')
return desc
@@ -1271,13 +1271,19 @@ if __name__ == '__main__':
options.title += '\\n' + options.subtitle
# escape ", and`, for gnuplot, to not break strings
options.title = options.title.replace('"', '\\042')
- options.title = options.title.replace('"', '\\140')
+ options.title = options.title.replace("\x60", '\\140')
term_opts = ""
truecolor_terms = ['png', 'sixelgd', 'wxt']
if options.terminal in truecolor_terms:
term_opts = 'truecolor'
- sys.stdout.write("set terminal %s size 800,950 %s\n"
- "set termoption enhanced\n"
+
+ # escape ", `, and \n, for gnuplot, to not break strings
+ options.terminal = options.terminal.replace('"', '\\042')
+ options.terminal = options.terminal.replace("\x60", '\\140')
+ options.terminal = options.terminal.replace('\n', '')
+
+ sys.stdout.write('set terminal "%s" size 800,950 %s\n'
+ 'set termoption enhanced\n'
% (options.terminal, term_opts))
# double quotes on title so \n is parsed by gnuplot
sys.stdout.write('set title noenhanced "%s\\n\\n"\n' % options.title)

View File

@ -29,6 +29,8 @@ Source11: gpsd.sysconfig
Patch1: gpsd-cve-2025-67268.patch
# fix integer underflow in handling of Navcom packets
Patch2: gpsd-cve-2025-67269.patch
# fix command injection in gpsprof
Patch3: gpsd-cve-2026-58459.patch
BuildRequires: gcc
BuildRequires: dbus-devel