PT-2026-84307 · Gnome · Gvfs
CVE-2026-84267
·
Published
2026-09-01
·
Updated
2026-09-02
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
gvfs (affected versions not specified)
Description
A flaw in the SFTP backend allows a malicious SFTP server to cause the
read string() function to allocate a buffer without verifying if it is completely filled. This leaves the remainder of the buffer containing uninitialized heap contents. If the server sends a short FXP HANDLE reply, these uninitialized bytes are used as the file handle and subsequently echoed back to the server in following requests. This allows the server to read uninitialized heap memory from the gvfsd-sftp process, leaking the heap base and the load address of the libgio library, which defeats Address Space Layout Randomization (ASLR), a security technique that randomly arranges the address space positions of key data areas to prevent exploitation of memory vulnerabilities.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Use of Uninitialized Resource
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gvfs