A flaw was found in the FTP GVfs backend. A malicious FTP server can exploit this vulnerability by providing an arbitrary IP address and port in its passive mode (PASV) response. The client unconditionally trusts this information and attempts to connect to the specified endpoint, allowing the malicious server to probe for open ports accessible from the client's network.
CVSS Details
- CVSS 3.1 Base Score: 4.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade gvfsUpgrade gvfs-debuginfoUpgrade gvfs-smbUpgrade gvfs-clientUpgrade gvfs-goaUpgrade gvfs-develUpgrade gvfs-afcUpgrade gvfs-gphoto2Upgrade gvfs-archiveUpgrade gvfs-mtpUpgrade gvfs-fuseUpgrade gvfs-afpUpgrade gvfs-tests | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade gvfs-fuseUpgrade gvfs-archiveUpgrade gvfs-archive-debuginfoUpgrade gvfs-debugsourceUpgrade gvfs-nfs-debuginfoUpgrade gvfs-smb-debuginfoUpgrade gvfsUpgrade gvfs-client-debuginfoUpgrade gvfs-debuginfoUpgrade gvfs-clientUpgrade gvfs-fuse-debuginfoUpgrade gvfs-nfsUpgrade gvfs-goa-debuginfoUpgrade gvfs-goaUpgrade gvfs-smb | Mar 27, 2026 | Feb 26, 2026 |
| Debian | — | Upgrade gvfs | Mar 30, 2026 | Mar 30, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Feb 26, 2026 |
| Ubuntu | — | Upgrade gvfsUpgrade gvfs-backends | Mar 24, 2026 | Mar 23, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub