CVE-2026-84268High· 8.8▾ TwilightA flaw was found in the SFTP backend in gvfs. When mounting a share and reading a file, a malicious SFTP server can cause read_reply() to process a length that exceeds the size requested by the client. The function does not verify the se…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
A flaw was found in the SFTP backend in gvfs. When mounting a share and reading a file, a malicious SFTP server can cause read_reply() to process a length that exceeds the size requested by the client. The function does not verify the server-provided length against the allocated buffer size, causing the operation to write past the intended boundaries. This issue allows a malicious server to corrupt adjacent heap memory in the gvfsd-sftp process, resulting in a denial of service as the process aborts upon detecting the heap corruption or potentially allowing arbitrary code execution.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-88924High· 7.0Gvfs: gvfs-admin socket ownership race permits local root
CVE-2026-2604Medium· 5.6A flaw was found in evolution-data-server
CVE-2026-91839High· 7.8A flaw was found in NetworkManager-fortisslvpn, the FortiSSLVPN plugin for NetworkManager
CVE-2026-91838High· 7.8A flaw was found in NetworkManager-sstp, the SSTP VPN plugin for NetworkManager
CVE-2026-91841High· 7.8A flaw was found in NetworkManager-vpnc, a VPN plugin for NetworkManager
CVE-2026-91840High· 7.8A flaw was found in NetworkManager-vpnc