CVE-2026-84269: Gnome Gvfs

Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.

A flaw was found in the AFP backend in gvfs. When mounting a share, a malicious AFP server can cause the DSI read path to process a length that exceeds the size requested by the client. The function does not verify the server-provided length against the pre-sized reply buffer, causing the operation to access past the intended boundaries. This issue allows a malicious server to overflow a heap buffer and crash the gvfsd-afp process, resulting in a denial of service.

Affected products

  • Gnome Gvfs: before 1.60.2 (fixed in 1.60.2)
  • Red Hat Red Hat Enterprise Linux 10
  • Red Hat Red Hat Enterprise Linux 6
  • Red Hat Red Hat Enterprise Linux 7
  • Red Hat Red Hat Enterprise Linux 8
  • Red Hat Red Hat Enterprise Linux 9

Published 2026-09-01. Last modified 2026-09-04.