CVE-2026-84268: Gnome Gvfs

High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.

A flaw was found in the SFTP backend in gvfs. When mounting a share and reading a file, a malicious SFTP server can cause read_reply() to process a length that exceeds the size requested by the client. The function does not verify the server-provided length against the allocated buffer size, causing the operation to write past the intended boundaries. This issue allows a malicious server to corrupt adjacent heap memory in the gvfsd-sftp process, resulting in a denial of service as the process aborts upon detecting the heap corruption or potentially allowing arbitrary code execution.

Affected products

  • Gnome Gvfs: before 1.60.2 (fixed in 1.60.2)
  • Red Hat Red Hat Enterprise Linux 10: before 0:1.54.4-4.el10_2.1 (fixed in 0:1.54.4-4.el10_2.1)
  • Red Hat Red Hat Enterprise Linux 6
  • Red Hat Red Hat Enterprise Linux 7
  • Red Hat Red Hat Enterprise Linux 8: before 0:1.36.2-22.el8_10 (fixed in 0:1.36.2-22.el8_10)
  • Red Hat Red Hat Enterprise Linux 9: before 0:1.48.1-8.el9_8.1 (fixed in 0:1.48.1-8.el9_8.1)

Published 2026-09-01. Last modified 2026-10-01.