A flaw was found in the SFTP backend in gvfs. When mounting a share and reading a file, a malicious SFTP server can cause read_reply() to process a length that exceeds the size requested by the client. The function does not verify the server-provided length against the allocated buffer size, causing the operation to write past the intended boundaries. This issue allows a malicious server to corrupt adjacent heap memory in the gvfsd-sftp process, resulting in a denial of service as the process aborts upon detecting the heap corruption or potentially allowing arbitrary code execution.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade gvfs-smb-debuginfoUpgrade gvfs-goaUpgrade gvfs-debugsourceUpgrade gvfs-nfsUpgrade gvfs-clientUpgrade gvfs-nfs-debuginfoUpgrade gvfs-client-debuginfoUpgrade gvfs-archiveUpgrade gvfs-fuseUpgrade gvfs-debuginfoUpgrade gvfs-smbUpgrade gvfsUpgrade gvfs-fuse-debuginfoUpgrade gvfs-archive-debuginfoUpgrade gvfs-goa-debuginfo | Sep 30, 2026 | Sep 1, 2026 |
| Redhat_linux | — | Upgrade gvfs-smb-debuginfoUpgrade gvfs-gphoto2No solution existsUpgrade gvfs-archiveUpgrade gvfs-mtp-debuginfoUpgrade gvfs-archive-debuginfoUpgrade gvfs-afc-debuginfoUpgrade gvfs-afpUpgrade gvfs-afp-debuginfoUpgrade gvfs-gphoto2-debuginfoUpgrade gvfs-debugsourceUpgrade gvfs-clientUpgrade gvfsUpgrade gvfs-goaUpgrade gvfs-fuse-debuginfoUpgrade gvfs-smbUpgrade gvfs-fuseUpgrade gvfs-develUpgrade gvfs-afcUpgrade gvfs-mtpUpgrade gvfs-goa-debuginfoUpgrade gvfs-debuginfoUpgrade gvfs-client-debuginfo | Sep 3, 2026 | Jul 3, 2026 |
| Rocky_linux | — | Upgrade gvfs-debuginfoUpgrade gvfs-gphoto2Upgrade gvfs-archiveUpgrade gvfs-afp-debuginfoUpgrade gvfs-client-debuginfoUpgrade gvfs-mtp-debuginfoUpgrade gvfs-gphoto2-debuginfoUpgrade gvfs-goa-debuginfoUpgrade gvfs-smbUpgrade gvfs-fuseUpgrade gvfsUpgrade gvfs-afc-debuginfoUpgrade gvfs-fuse-debuginfoUpgrade gvfs-smb-debuginfoUpgrade gvfs-mtpUpgrade gvfs-debugsourceUpgrade gvfs-goaUpgrade gvfs-clientUpgrade gvfs-afcUpgrade gvfs-afpUpgrade gvfs-archive-debuginfoUpgrade gvfs-devel | Oct 5, 2026 | Oct 2, 2026 |
| Ubuntu | — | Upgrade gvfs-backendsUpgrade gvfs-backends (Ubuntu Pro)Upgrade gvfs-libsUpgrade gvfs-libs (Ubuntu Pro) | Oct 6, 2026 | Sep 30, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub