PT-2026-84307 · Gnome · Gvfs

CVE-2026-84267

·

Published

2026-09-01

·

Updated

2026-09-02

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions gvfs (affected versions not specified)
Description A flaw in the SFTP backend allows a malicious SFTP server to cause the read string() function to allocate a buffer without verifying if it is completely filled. This leaves the remainder of the buffer containing uninitialized heap contents. If the server sends a short FXP HANDLE reply, these uninitialized bytes are used as the file handle and subsequently echoed back to the server in following requests. This allows the server to read uninitialized heap memory from the gvfsd-sftp process, leaking the heap base and the load address of the libgio library, which defeats Address Space Layout Randomization (ASLR), a security technique that randomly arranges the address space positions of key data areas to prevent exploitation of memory vulnerabilities.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use of Uninitialized Resource

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-84267

Affected Products

Gvfs