Package "gvfs-backends"
| Name: |
gvfs-backends
|
Description: |
userspace virtual filesystem - backends
|
| Latest version: |
1.60.0-1ubuntu0.1 |
| Release: |
resolute (26.04) |
| Level: |
security |
| Repository: |
main |
| Head package: |
gvfs |
| Homepage: |
https://wiki.gnome.org/Projects/gvfs |
Links
Download "gvfs-backends"
Other versions of "gvfs-backends" in Resolute
Changelog
|
gvfs (1.60.0-1ubuntu0.1) resolute-security; urgency=medium
* SECURITY UPDATE: Heap buffer overflow in SFTP backend during file read
- debian/patches/CVE-2026-84268_1.patch: Clamp `read_reply` count to
requested buffer size in daemon/gvfsbackendsftp.c.
- debian/patches/CVE-2026-84268_2.patch: Return error when server sends
more data than requested in daemon/gvfsbackendsftp.c.
- CVE-2026-84268
* SECURITY UPDATE: Privilege escalation via TOCTOU race in admin backend
- debian/patches/CVE-2026-88924.patch: Set socket ownership before
creation in daemon/gvfsdaemon.c.
- CVE-2026-88924
-- Shafayat Hossain Majumder Fri, 25 Sep 2026 13:26:45 -0400
|
| CVE-2026-84268 |
A flaw was found in the SFTP backend in gvfs. When mounting a share and reading a file, a malicious SFTP server can cause read_reply() to process a l |
| CVE-2026-88924 |
A flaw was found in the admin backend of gvfs. The privileged gvfsd-admin daemon changes the ownership of newly created private D-Bus sockets by call |
|
About
-
Send Feedback to @ubuntu_updates