
PEACH
Un cadre d’isolation des locataires
CVE-2026-84269 is a heap-based buffer overflow vulnerability in the AFP (Apple Filing Protocol) backend of gvfs, the GNOME virtual filesystem implementation. When a user mounts an AFP share, a malicious AFP server can cause the DSI read path to process a server-provided length that exceeds the size requested by the client, overflowing the pre-sized reply buffer and crashing the gvfsd-afp process. The vulnerability affects all gvfs versions and was disclosed on September 1, 2026, with a fix available in version 1.60.2. It carries a CVSS v3.1 base score of 6.5 (Medium) (Red Hat Advisory, GitHub Advisory).
The root cause is classified as CWE-122 (Heap-based Buffer Overflow): the DSI read path function in the gvfs AFP backend does not validate the server-provided data length against the pre-allocated reply buffer size, allowing a server response to write beyond the buffer's intended boundaries (Red Hat Advisory, Red Hat Bugzilla). Exploitation requires user interaction — specifically, a user must connect to a malicious AFP server (e.g., by clicking a crafted afp:// link). The attack vector is network-based with low complexity, and no authentication is required on the attacker's side. The issue is tracked upstream in the GNOME GitLab issue tracker (Red Hat Advisory).
Successful exploitation results in a denial of service by crashing the gvfsd-afp process, disrupting AFP share mounting functionality for the affected user. There is no confidentiality or integrity impact — the vulnerability does not expose sensitive data or allow unauthorized modification of files. While heap-based buffer overflows can theoretically be leveraged for code execution, Red Hat has assessed the direct security impact as limited to denial of service in this context, rating it as moderate severity (Red Hat Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the disclosure date (GitHub Advisory). The EPSS score is 0.0, reflecting a very low probability of exploitation in the near term (Red Hat Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is constrained by the requirement for user interaction — a victim must actively connect to a malicious AFP server.
afp:// URI to the target user via phishing email, malicious web page, or other social engineering vector to induce them to mount the malicious AFP share.gvfsd-afp process does not validate this length against the buffer size.gvfsd-afp process to crash, resulting in denial of service of the AFP mounting functionality (Red Hat Advisory, Red Hat Bugzilla).gvfsd-afp process in system logs (e.g., /var/log/syslog, journalctl) shortly after a user attempts to mount an AFP share.gvfsd-afp process following AFP share mount attempts; core dump files generated by gvfsd-afp in system crash directories.gvfsd-afp process.Update gvfs to version 1.60.2 or later, which contains the fix for this vulnerability (Red Hat Bugzilla). As a workaround, Red Hat recommends not connecting to untrusted AFP servers; organizations that do not require AFP functionality should consider disabling AFP mounting entirely (Red Hat Advisory). Users should be cautious of unsolicited afp:// links received via email or web pages.
Red Hat credited Keith Linneman of LinnemanLabs for responsibly reporting this issue (Red Hat Advisory). Red Hat rated the vulnerability as moderate severity, noting that exploitation requires user interaction and the direct impact is limited to denial of service. No significant broader media coverage or notable researcher commentary beyond the initial disclosure has been observed.
Source: Ce rapport a été généré à l’aide de l’IA
Évaluation gratuite des vulnérabilités
Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.
Obtenez une démo personnalisée
"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."