CVE-2026-84269
Linux Debian Analyse et atténuation des vulnérabilités

Aperçu

CVE-2026-84269 is a heap-based buffer overflow vulnerability in the AFP (Apple Filing Protocol) backend of gvfs, the GNOME virtual filesystem implementation. When a user mounts an AFP share, a malicious AFP server can cause the DSI read path to process a server-provided length that exceeds the size requested by the client, overflowing the pre-sized reply buffer and crashing the gvfsd-afp process. The vulnerability affects all gvfs versions and was disclosed on September 1, 2026, with a fix available in version 1.60.2. It carries a CVSS v3.1 base score of 6.5 (Medium) (Red Hat Advisory, GitHub Advisory).

Détails techniques

The root cause is classified as CWE-122 (Heap-based Buffer Overflow): the DSI read path function in the gvfs AFP backend does not validate the server-provided data length against the pre-allocated reply buffer size, allowing a server response to write beyond the buffer's intended boundaries (Red Hat Advisory, Red Hat Bugzilla). Exploitation requires user interaction — specifically, a user must connect to a malicious AFP server (e.g., by clicking a crafted afp:// link). The attack vector is network-based with low complexity, and no authentication is required on the attacker's side. The issue is tracked upstream in the GNOME GitLab issue tracker (Red Hat Advisory).

Impact

Successful exploitation results in a denial of service by crashing the gvfsd-afp process, disrupting AFP share mounting functionality for the affected user. There is no confidentiality or integrity impact — the vulnerability does not expose sensitive data or allow unauthorized modification of files. While heap-based buffer overflows can theoretically be leveraged for code execution, Red Hat has assessed the direct security impact as limited to denial of service in this context, rating it as moderate severity (Red Hat Advisory).

Exploitabilité

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the disclosure date (GitHub Advisory). The EPSS score is 0.0, reflecting a very low probability of exploitation in the near term (Red Hat Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is constrained by the requirement for user interaction — a victim must actively connect to a malicious AFP server.

Étapes d’exploitation

  1. Set up a malicious AFP server: The attacker configures a rogue AFP server that responds to DSI (Data Stream Interface) read requests with a crafted length field that exceeds the size of the client's pre-allocated reply buffer.
  2. Lure the victim: The attacker delivers a crafted afp:// URI to the target user via phishing email, malicious web page, or other social engineering vector to induce them to mount the malicious AFP share.
  3. Trigger the overflow: When the victim's system initiates a DSI read operation during the share mount process, the malicious server returns a response with an oversized length value. The gvfsd-afp process does not validate this length against the buffer size.
  4. Crash the process: The heap buffer overflow causes the gvfsd-afp process to crash, resulting in denial of service of the AFP mounting functionality (Red Hat Advisory, Red Hat Bugzilla).

Indicateurs de compromis

  • Logs: Unexpected crash or termination entries for the gvfsd-afp process in system logs (e.g., /var/log/syslog, journalctl) shortly after a user attempts to mount an AFP share.
  • Process: Absence or repeated restart of the gvfsd-afp process following AFP share mount attempts; core dump files generated by gvfsd-afp in system crash directories.
  • Network: Outbound connections to unfamiliar AFP server IP addresses on TCP port 548 (AFP default port) initiated by the gvfsd-afp process.

Atténuation et solutions de contournement

Update gvfs to version 1.60.2 or later, which contains the fix for this vulnerability (Red Hat Bugzilla). As a workaround, Red Hat recommends not connecting to untrusted AFP servers; organizations that do not require AFP functionality should consider disabling AFP mounting entirely (Red Hat Advisory). Users should be cautious of unsolicited afp:// links received via email or web pages.

Réactions de la communauté

Red Hat credited Keith Linneman of LinnemanLabs for responsibly reporting this issue (Red Hat Advisory). Red Hat rated the vulnerability as moderate severity, noting that exploitation requires user interaction and the direct impact is limited to denial of service. No significant broader media coverage or notable researcher commentary beyond the initial disclosure has been observed.

Ressources additionnelles


SourceCe rapport a été généré à l’aide de l’IA

Apparenté Linux Debian Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2026-84268HIGH8.8
  • Linux Debian logoLinux Debian
  • gvfs-gphoto2
NonNonSep 01, 2026
CVE-2026-84233HIGH7
  • Linux Debian logoLinux Debian
  • rpm-plugin-fapolicyd
NonNonSep 01, 2026
CVE-2026-84269MEDIUM6.5
  • Linux Debian logoLinux Debian
  • gvfs-gphoto2
NonNonSep 01, 2026
CVE-2026-84270MEDIUM4.3
  • Linux Debian logoLinux Debian
  • gvfs-gphoto2
NonNonSep 01, 2026
CVE-2026-84267MEDIUM4.3
  • Linux Debian logoLinux Debian
  • gvfs-goa
NonNonSep 01, 2026

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités