Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-84269

Опубликовано: 03 авг. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

A flaw was found in the AFP backend in gvfs. When mounting a share, a malicious AFP server can cause the DSI read path to process a length that exceeds the size requested by the client. The function does not verify the server-provided length against the pre-sized reply buffer, causing the operation to access past the intended boundaries. This issue allows a malicious server to overflow a heap buffer and crash the gvfsd-afp process, resulting in a denial of service.

Отчет

To exploit this issue, an attacker needs a user to connect to a malicious AFP share (for example, by clicking a crafted afp:// link), limiting its exposure. Furthermore, the direct security impact of this flaw is a denial of service due to the heap-based buffer overflow. For these reasons, this vulnerability has been rated with a moderate severity.

Меры по смягчению последствий

To mitigate this vulnerability, do not connect to untrusted AFP servers.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10gvfsFix deferred
Red Hat Enterprise Linux 6gvfsOut of support scope
Red Hat Enterprise Linux 7gvfsFix deferred
Red Hat Enterprise Linux 8gvfsFix deferred
Red Hat Enterprise Linux 9gvfsFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=2526784gvfs: AFP: heap-based buffer overflow in DSI read path

EPSS

Процентиль: 16%
0.00249
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
15 дней назад

(A flaw was found in the AFP backend in gvfs. When mounting a share, a ...)

CVSS3: 6.5
nvd
15 дней назад

A flaw was found in the AFP backend in gvfs. When mounting a share, a malicious AFP server can cause the DSI read path to process a length that exceeds the size requested by the client. The function does not verify the server-provided length against the pre-sized reply buffer, causing the operation to access past the intended boundaries. This issue allows a malicious server to overflow a heap buffer and crash the gvfsd-afp process, resulting in a denial of service.

CVSS3: 6.5
debian
15 дней назад

A flaw was found in the AFP backend in gvfs. When mounting a share, a ...

CVSS3: 6.5
github
15 дней назад

A flaw was found in the AFP backend in gvfs. When mounting a share, a malicious AFP server can cause the DSI read path to process a length that exceeds the size requested by the client. The function does not verify the server-provided length against the pre-sized reply buffer, causing the operation to access past the intended boundaries. This issue allows a malicious server to overflow a heap buffer and crash the gvfsd-afp process, resulting in a denial of service.

EPSS

Процентиль: 16%
0.00249
Низкий

6.5 Medium

CVSS3