Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
To mitigate this vulnerability, do not connect to untrusted SFTP servers.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 02 Sep 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 01 Sep 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in the SFTP backend in gvfs. When mounting a share and reading a file, a malicious SFTP server can cause read_reply() to process a length that exceeds the size requested by the client. The function does not verify the server-provided length against the allocated buffer size, causing the operation to write past the intended boundaries. This issue allows a malicious server to corrupt adjacent heap memory in the gvfsd-sftp process, resulting in a denial of service as the process aborts upon detecting the heap corruption or potentially allowing arbitrary code execution. | |
| Title | Gvfs: sftp: heap-based buffer overflow in read_reply() | |
| First Time appeared |
Redhat
Redhat enterprise Linux |
|
| Weaknesses | CWE-122 | |
| CPEs | cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-09-02T13:36:51.481Z
Reserved: 2026-09-01T14:05:54.144Z
Link: CVE-2026-84268
Updated: 2026-09-01T18:01:54.999Z
Status : Awaiting Analysis
Published: 2026-09-01T16:17:37.563
Modified: 2026-09-02T14:17:16.170
Link: CVE-2026-84268
No data.
OpenCVE Enrichment
Updated: 2026-09-02T03:45:04Z
-
CWE-122
Heap-based Buffer Overflow