← GrokBot Source Archive

LC-2 · Software Danger Reports

LrrK Kinematic Software Danger Report

Source-imported record. This page is not a QSVFF-sealed filing or a verification certificate.
Recorded date
Date not recorded
Drive source path
quiet-systems-archive/LC-2/months/2013-05.md
Imported-content SHA-256
d63358ba73674dcdf16b90d3b2343ac8b0879a002490314dc440dfdb62350da5
Imported representation
Drive UTF-8 text
Open original Drive locator ↗ · View source Markdown
# LrrK Kinematic Software Danger Report

**LRRK Watch / Software Assurance** — Monthly filing.

| Field | Value |
| --- | --- |
| Collection cutoff | 31 May 2013 |
| Platform | Quiet Systems |
| Series | DKSR-M-2013-05 |
| Status | short |
| Data label | Open-source intelligence // LRRK analytic product |
| Handling | Public-source material. Retrospective monthly. Image rights require separate verification before publication. |

## Executive read

### BLUF

gpsd before 3.9 crashes on a malformed $GPGGA. The GNSS mediator that robots and ground stations use to turn NMEA into navigation state does not fully validate the sentence.

### Key judgments

1. **[Assessment — High confidence]** CVE-2013-2038 assigned 2 May 2013 (oss-security). Fixed in gpsd 3.9 the same week. Ubuntu USN-1820-1.
2. **[Assessment — High confidence]** NVD published 6 February 2014 — after this window; dating is the May public disclosure.
3. **[Uncertainty]** Upstream said the crash had been seen in the wild on SiRFStar-III output, not as an identified attack. A separate AIS-driver overrun was discussed as hypothetical and is not filed.

### Analytic labels

- **Fact** — verified reporting or primary record
- **Assessment** — analytic judgment
- **Inference** — reasoned but not directly observed
- **Uncertainty** — unresolved information gap

### Source grades

- **A1** — authoritative primary record / directly confirmed
- **B1–B2** — generally reliable and corroborated
- **C3** — useful but requires caution

## 01. gpsd NMEA0183 parser crash

*Event / publication dates: Public disclosure 2 May 2013 (oss-security; CVE-2013-2038 assigned that day). Eric S. Raymond confirmation 7 May 2013. NVD 6 February 2014 not used for dating.*

| Field | Value |
| --- | --- |
| Component | software / dependency |
| Product | gpsd before 3.9 (NMEA0183 driver) |
| CVE / advisory | CVE-2013-2038. Ubuntu USN-1820-1. Fixed in gpsd 3.9. |
| Patch | available — gpsd 3.9 (May 2013) |
| Exploit status | catalogued |
| Taxonomy | CWE-20 (NVD) |

**Verified record — [Fact — A1]** oss-security, 2 May 2013; Eric S. Raymond, oss-security, 7 May 2013 (NMEA0183, not NMEA2000; crash observed); NVD CVE-2013-2038; gpsd commit dd9c3c2830cb8f8fd8491ce68c82698dc5538f50. https://www.openwall.com/lists/oss-security/2013/05/02/17 · https://www.openwall.com/lists/oss-security/2013/05/08/1 · https://nvd.nist.gov/vuln/detail/CVE-2013-2038

**Exposure.** GNSS daemon NMEA ingest. Sense path for robots, vehicles, and ground stations. Not a named UAS product.

**Intelligence assessment.** [Assessment — High confidence] CVE, fix, and NVD CWE-20. [Assessment — Moderate confidence] Kinematic-tracker inclusion is general GPS-mediator, not a named airframe.

**Opportunity.** Passport gpsd (or equivalent mediator) version on GCS and vehicles. Do not file the AIS-driver note as a CVE.

**LRRK relevance.** Watch. Sense (GNSS ingest). Same class as 2010-01 caster NMEA.

**Confidence.** High on the CVE. Moderate on UAS-product mapping.

## Forward indicators

1. NVD page 6 February 2014 — index only.
2. A named UAS/GCS product that pins a vulnerable gpsd.

> **Collection integrity.** One GNSS-software CVE. Dating is oss-security 2 May, not NVD February 2014. AIS-driver overrun discussed as hypothetical — excluded. Not padded. Public sources only. No invented CVEs. No exploit steps.

*LRRK — security assurance for systems that sense, move, and act.*

<p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C2</span></p>