UbuntuUpdates.org

Package "gvfs"

Name: gvfs

Description:

userspace virtual filesystem - GIO module

Latest version: 1.48.2-0ubuntu1.2
Release: jammy (22.04)
Level: security
Repository: main
Homepage: https://wiki.gnome.org/Projects/gvfs

Links


Download "gvfs"


Other versions of "gvfs" in Jammy

Repository Area Version
base main 1.48.1-4
updates main 1.48.2-0ubuntu1.2

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 1.48.2-0ubuntu1.2 2026-09-30 18:07:17 UTC

gvfs (1.48.2-0ubuntu1.2) jammy-security; urgency=medium

  * SECURITY UPDATE: Heap buffer overflow in SFTP backend during file read
    - debian/patches/CVE-2026-84268_1.patch: Clamp `read_reply` count to
      requested buffer size in daemon/gvfsbackendsftp.c.
    - debian/patches/CVE-2026-84268_2.patch: Return error when server sends
      more data than requested in daemon/gvfsbackendsftp.c.
    - CVE-2026-84268
  * SECURITY UPDATE: Privilege escalation via TOCTOU race in admin backend
    - debian/patches/CVE-2026-88924.patch: Set socket ownership before
      creation in daemon/gvfsdaemon.c.
    - CVE-2026-88924

 -- Shafayat Hossain Majumder Fri, 25 Sep 2026 13:26:38 -0400

Source diff to previous version
CVE-2026-84268 A flaw was found in the SFTP backend in gvfs. When mounting a share and reading a file, a malicious SFTP server can cause read_reply() to process a l
CVE-2026-88924 A flaw was found in the admin backend of gvfs. The privileged gvfsd-admin daemon changes the ownership of newly created private D-Bus sockets by call

Version: 1.48.2-0ubuntu1.1 2026-03-23 14:07:59 UTC

  gvfs (1.48.2-0ubuntu1.1) jammy-security; urgency=medium

  * SECURITY UPDATE: open port probe via FTP backend
    - debian/patches/CVE-2026-28295.patch: use control connection address
      for PASV data in daemon/gvfsbackendftp.c, daemon/gvfsbackendftp.h,
      daemon/gvfsftptask.c.
    - CVE-2026-28295
  * SECURITY UPDATE: arbitrary FTP command injection via CRLF
    - debian/patches/CVE-2026-28296.patch: reject paths containing CR/LF
      characters in daemon/gvfsbackendftp.c, daemon/gvfsftpfile.c,
      daemon/gvfsftpfile.h.
    - CVE-2026-28296

 -- Marc Deslauriers <email address hidden> Wed, 18 Mar 2026 12:17:40 -0400

CVE-2026-28295 A flaw was found in the FTP GVfs backend. A malicious FTP server can exploit this vulnerability by providing an arbitrary IP address and port in its
CVE-2026-28296 A flaw was found in the FTP GVfs backend. A remote attacker could exploit this input validation vulnerability by supplying specially crafted file pat



About   -   Send Feedback to @ubuntu_updates