Bug 2526784 (CVE-2026-84269) - CVE-2026-84269 gvfs: AFP: heap-based buffer overflow in DSI read path
Summary: CVE-2026-84269 gvfs: AFP: heap-based buffer overflow in DSI read path
Keywords:
Status: NEW
Alias: CVE-2026-84269
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2526945
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-01 12:54 UTC by OSIDB Bzimport
Modified: 2026-09-01 17:43 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-01 12:54:28 UTC
A flaw was found in the AFP backend in gvfs. When mounting a share, a malicious AFP server can cause the DSI read path to process a length that exceeds the size requested by the client. The function does not verify the server-provided length against the pre-sized reply buffer, causing the operation to access past the intended boundaries. This issue allows a malicious server to overflow a heap buffer and crash the gvfsd-afp process, resulting in a denial of service. This vulnerability affects all gvfs versions and is fixed in version 1.60.2.


Note You need to log in before you can comment on or make changes to this bug.