A flaw was found in the FTP GVfs backend. A remote attacker could exploit this input validation vulnerability by supplying specially crafted file paths containing carriage return and line feed (CRLF) sequences. These unsanitized sequences allow the attacker to terminate intended FTP commands and inject arbitrary FTP commands, potentially leading to arbitrary code execution or other severe impacts.
CVSS Details
- CVSS 3.1 Base Score: 4.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade gvfsUpgrade gvfs-fuseUpgrade gvfs-testsUpgrade gvfs-debuginfoUpgrade gvfs-gphoto2Upgrade gvfs-clientUpgrade gvfs-archiveUpgrade gvfs-smbUpgrade gvfs-develUpgrade gvfs-goaUpgrade gvfs-afcUpgrade gvfs-afpUpgrade gvfs-mtp | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade gvfs-fuseUpgrade gvfs-debuginfoUpgrade gvfsUpgrade gvfs-archive-debuginfoUpgrade gvfs-client-debuginfoUpgrade gvfs-smbUpgrade gvfs-archiveUpgrade gvfs-goa-debuginfoUpgrade gvfs-nfs-debuginfoUpgrade gvfs-nfsUpgrade gvfs-fuse-debuginfoUpgrade gvfs-clientUpgrade gvfs-smb-debuginfoUpgrade gvfs-debugsourceUpgrade gvfs-goa | Mar 27, 2026 | Feb 26, 2026 |
| Debian | — | Upgrade gvfs | Mar 30, 2026 | Mar 30, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Feb 26, 2026 |
| Ubuntu | — | Upgrade gvfsUpgrade gvfs-backends | Mar 24, 2026 | Mar 23, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub