A flaw was found in the FTP GVfs backend. A malicious FTP server can exploit this vulnerability by providing an arbitrary IP address and port in its passive mode (PASV) response. The client unconditionally trusts this information and attempts to connect to the specified endpoint, allowing the malicious server to probe for open ports accessible from the client's network.
CVSS Details
- CVSS 3.1 Base Score: 4.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade gvfs-afpUpgrade gvfs-fuseUpgrade gvfs-gphoto2Upgrade gvfs-mtpUpgrade gvfs-archiveUpgrade gvfs-testsUpgrade gvfs-develUpgrade gvfs-clientUpgrade gvfs-debuginfoUpgrade gvfsUpgrade gvfs-goaUpgrade gvfs-afcUpgrade gvfs-smb | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade gvfs-client-debuginfoUpgrade gvfs-goa-debuginfoUpgrade gvfs-goaUpgrade gvfs-clientUpgrade gvfs-debuginfoUpgrade gvfs-smbUpgrade gvfs-nfsUpgrade gvfs-fuse-debuginfoUpgrade gvfs-archiveUpgrade gvfs-smb-debuginfoUpgrade gvfs-nfs-debuginfoUpgrade gvfs-fuseUpgrade gvfs-debugsourceUpgrade gvfsUpgrade gvfs-archive-debuginfo | Mar 27, 2026 | Feb 26, 2026 |
| Debian | — | Upgrade gvfs | Mar 30, 2026 | Mar 30, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Feb 26, 2026 |
| Ubuntu | — | Upgrade gvfsUpgrade gvfs-backends | Mar 24, 2026 | Mar 23, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub