LC-2 · Software Danger Reports
LrrK Kinematic Software Danger Report
Source-imported record. This page is not a QSVFF-sealed filing or a verification certificate.
# LrrK Kinematic Software Danger Report **LRRK Watch / Software Assurance** — Monthly filing. | Field | Value | | --- | --- | | Collection cutoff | 31 May 2013 | | Platform | Quiet Systems | | Series | DKSR-M-2013-05 | | Status | short | | Data label | Open-source intelligence // LRRK analytic product | | Handling | Public-source material. Retrospective monthly. Image rights require separate verification before publication. | ## Executive read ### BLUF gpsd before 3.9 crashes on a malformed $GPGGA. The GNSS mediator that robots and ground stations use to turn NMEA into navigation state does not fully validate the sentence. ### Key judgments 1. **[Assessment — High confidence]** CVE-2013-2038 assigned 2 May 2013 (oss-security). Fixed in gpsd 3.9 the same week. Ubuntu USN-1820-1. 2. **[Assessment — High confidence]** NVD published 6 February 2014 — after this window; dating is the May public disclosure. 3. **[Uncertainty]** Upstream said the crash had been seen in the wild on SiRFStar-III output, not as an identified attack. A separate AIS-driver overrun was discussed as hypothetical and is not filed. ### Analytic labels - **Fact** — verified reporting or primary record - **Assessment** — analytic judgment - **Inference** — reasoned but not directly observed - **Uncertainty** — unresolved information gap ### Source grades - **A1** — authoritative primary record / directly confirmed - **B1–B2** — generally reliable and corroborated - **C3** — useful but requires caution ## 01. gpsd NMEA0183 parser crash *Event / publication dates: Public disclosure 2 May 2013 (oss-security; CVE-2013-2038 assigned that day). Eric S. Raymond confirmation 7 May 2013. NVD 6 February 2014 not used for dating.* | Field | Value | | --- | --- | | Component | software / dependency | | Product | gpsd before 3.9 (NMEA0183 driver) | | CVE / advisory | CVE-2013-2038. Ubuntu USN-1820-1. Fixed in gpsd 3.9. | | Patch | available — gpsd 3.9 (May 2013) | | Exploit status | catalogued | | Taxonomy | CWE-20 (NVD) | **Verified record — [Fact — A1]** oss-security, 2 May 2013; Eric S. Raymond, oss-security, 7 May 2013 (NMEA0183, not NMEA2000; crash observed); NVD CVE-2013-2038; gpsd commit dd9c3c2830cb8f8fd8491ce68c82698dc5538f50. https://www.openwall.com/lists/oss-security/2013/05/02/17 · https://www.openwall.com/lists/oss-security/2013/05/08/1 · https://nvd.nist.gov/vuln/detail/CVE-2013-2038 **Exposure.** GNSS daemon NMEA ingest. Sense path for robots, vehicles, and ground stations. Not a named UAS product. **Intelligence assessment.** [Assessment — High confidence] CVE, fix, and NVD CWE-20. [Assessment — Moderate confidence] Kinematic-tracker inclusion is general GPS-mediator, not a named airframe. **Opportunity.** Passport gpsd (or equivalent mediator) version on GCS and vehicles. Do not file the AIS-driver note as a CVE. **LRRK relevance.** Watch. Sense (GNSS ingest). Same class as 2010-01 caster NMEA. **Confidence.** High on the CVE. Moderate on UAS-product mapping. ## Forward indicators 1. NVD page 6 February 2014 — index only. 2. A named UAS/GCS product that pins a vulnerable gpsd. > **Collection integrity.** One GNSS-software CVE. Dating is oss-security 2 May, not NVD February 2014. AIS-driver overrun discussed as hypothetical — excluded. Not padded. Public sources only. No invented CVEs. No exploit steps. *LRRK — security assurance for systems that sense, move, and act.* <p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C2</span></p>