{"id":"CVE-2026-84268","title":"A flaw was found in the SFTP backend in gvfs","summary":"A flaw was found in the SFTP backend in gvfs. When mounting a share and reading a file, a malicious SFTP server can cause read_reply() to process a length that exceeds the size requested by the client. The function does not verify the se…","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cwe":["CWE-122"],"vendor":"GNOME","product":"gvfs","affected":["gvfs < 1.60.2","gvfs (all versions)","gvfs (all versions)","gvfs (all versions)","gvfs (all versions)","gvfs (all versions)"],"published":"2026-09-01","updated":"2026-09-30","sourceUpdated":"2026-09-30T23:17:01.340","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-84268","references":[{"url":"https://access.redhat.com/errata/RHSA-2026:73997","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:73998","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2026-84268","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2526485","label":"secalert@redhat.com"},{"url":"https://gitlab.gnome.org/GNOME/gvfs/-/issues/862","label":"secalert@redhat.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-01T18:01:43.116734Z"},"epss":0.00328,"epssPercentile":0.23454,"ingestedAt":"2026-09-30T23:29:32.576Z","slug":"CVE-2026-84268","body":"## Overview\n\nA flaw was found in the SFTP backend in gvfs. When mounting a share and reading a file, a malicious SFTP server can cause read_reply() to process a length that exceeds the size requested by the client. The function does not verify the server-provided length against the allocated buffer size, causing the operation to write past the intended boundaries. This issue allows a malicious server to corrupt adjacent heap memory in the gvfsd-sftp process, resulting in a denial of service as the process aborts upon detecting the heap corruption or potentially allowing arbitrary code execution.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":48.4,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}