Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-84268

Опубликовано: 03 июл. 2026
Источник: redhat
CVSS3: 8.8

Описание

A flaw was found in the SFTP backend in gvfs. When mounting a share and reading a file, a malicious SFTP server can cause read_reply() to process a length that exceeds the size requested by the client. The function does not verify the server-provided length against the allocated buffer size, causing the operation to write past the intended boundaries. This issue allows a malicious server to corrupt adjacent heap memory in the gvfsd-sftp process, resulting in a denial of service as the process aborts upon detecting the heap corruption or potentially allowing arbitrary code execution.

Отчет

To exploit this issue, an attacker needs a user to connect to a malicious SFTP share (for example, by clicking a crafted sftp:// link or intercepting an unverified connection), limiting its exposure. However, this flaw can cause memory corruption, resulting in a denial of service or potentially allowing arbitrary code execution. For these reasons, this vulnerability has been rated with an important severity. Default Red Hat Enterprise Linux security features, including SELinux enforcement, Address Space Layout Randomization (ASLR) and NX (No-Execute) memory protection, significantly increase the difficulty of achieving arbitrary code execution, limiting the impact of this vulnerability.

Меры по смягчению последствий

To mitigate this vulnerability, do not connect to untrusted SFTP servers.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10gvfsAffected
Red Hat Enterprise Linux 6gvfsAffected
Red Hat Enterprise Linux 7gvfsAffected
Red Hat Enterprise Linux 8gvfsAffected
Red Hat Enterprise Linux 9gvfsAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=2526485gvfs: SFTP: heap-based buffer overflow in read_reply()

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
15 дней назад

(A flaw was found in the SFTP backend in gvfs. When mounting a share an ...)

CVSS3: 8.8
nvd
15 дней назад

A flaw was found in the SFTP backend in gvfs. When mounting a share and reading a file, a malicious SFTP server can cause read_reply() to process a length that exceeds the size requested by the client. The function does not verify the server-provided length against the allocated buffer size, causing the operation to write past the intended boundaries. This issue allows a malicious server to corrupt adjacent heap memory in the gvfsd-sftp process, resulting in a denial of service as the process aborts upon detecting the heap corruption or potentially allowing arbitrary code execution.

CVSS3: 8.8
debian
15 дней назад

A flaw was found in the SFTP backend in gvfs. When mounting a share an ...

CVSS3: 8.8
github
15 дней назад

A flaw was found in the SFTP backend in gvfs. When mounting a share and reading a file, a malicious SFTP server can cause read_reply() to process a length that exceeds the size requested by the client. The function does not verify the server-provided length against the allocated buffer size, causing the operation to write past the intended boundaries. This issue allows a malicious server to corrupt adjacent heap memory in the gvfsd-sftp process, resulting in a denial of service as the process aborts upon detecting the heap corruption or potentially allowing arbitrary code execution.

8.8 High

CVSS3