CVE-2026-84268
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2026-84268 is a heap-based buffer overflow vulnerability in the SFTP backend of GNOME's gvfs (GNOME Virtual File System). When a user mounts an SFTP share and reads a file, a malicious SFTP server can cause the read_reply() function to process a server-provided length that exceeds the client's requested size, writing past the allocated buffer boundaries and corrupting adjacent heap memory in the gvfsd-sftp process. All gvfs versions prior to 1.60.2 are affected; Red Hat Enterprise Linux systems running gvfs are also listed as affected (Red Hat Advisory, Red Hat Bugzilla). The vulnerability was reported by Keith Linneman (LinnemanLabs), disclosed on September 1, 2026, and carries a CVSS v3.1 base score of 8.8 (High) (Red Hat Advisory, Github Advisory).

Technical details

The root cause is classified as CWE-122 (Heap-based Buffer Overflow): the read_reply() function in gvfs's SFTP backend trusts the length value returned by the server without validating it against the size of the allocated receive buffer (Red Hat Advisory, Github Advisory). An attacker operating or controlling a malicious SFTP server can craft a response with an inflated length field, causing read_reply() to write beyond the heap buffer's boundaries and corrupt adjacent memory in the gvfsd-sftp process. Exploitation requires user interaction — specifically, a victim must connect to the attacker-controlled SFTP server (e.g., by clicking a crafted sftp:// link or via a man-in-the-middle interception of an unverified connection) (Red Hat Advisory). No public proof-of-concept exploit code has been identified at this time (Github Advisory).

Impact

Successful exploitation results in heap memory corruption within the gvfsd-sftp process, leading to a denial of service (process abort upon heap corruption detection) or potentially arbitrary code execution in the context of the gvfs daemon (Red Hat Advisory). All three CIA pillars are rated High: confidentiality, integrity, and availability of the affected process are fully compromised if code execution is achieved. Red Hat notes that default RHEL mitigations — SELinux enforcement, ASLR, and NX memory protection — significantly increase the difficulty of achieving arbitrary code execution, limiting practical impact on hardened systems (Red Hat Advisory).

Exploitability

There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (Github Advisory). The NVD SSVC assessment classifies exploitation as "none" and the attack as non-automatable, reflecting the requirement for user interaction. The EPSS score is approximately 0.33%, placing this vulnerability in the 26th percentile for exploitation likelihood within 30 days (Github Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no threat actor attribution has been reported.

Exploitation steps

  1. Set up a malicious SFTP server: The attacker configures a server that responds to SFTP protocol requests but crafts read_reply() responses with a length field that exceeds the actual data and the client's requested buffer size.
  2. Lure the victim: The attacker delivers a crafted sftp:// URI to the target user (e.g., via phishing email, malicious web page, or document) or positions themselves as a man-in-the-middle on an unverified SFTP connection.
  3. Trigger the connection: The victim clicks the link or mounts the SFTP share using a GNOME file manager or other gvfs-integrated application, causing gvfsd-sftp to connect to the attacker's server.
  4. Trigger the overflow: When the victim's client reads a file from the malicious share, the attacker's server returns a response with an inflated length value. The read_reply() function writes beyond the allocated heap buffer, corrupting adjacent memory in the gvfsd-sftp process.
  5. Achieve objective: Depending on heap layout and platform mitigations, the outcome is either a process crash (DoS) or, in the absence of effective ASLR/SELinux controls, potential arbitrary code execution within the gvfsd-sftp process context (Red Hat Advisory, Red Hat Bugzilla).

Indicators of compromise

  • Process: Unexpected crash or abort of the gvfsd-sftp process; repeated restarts of the gvfs SFTP daemon.
  • Logs: System logs (e.g., /var/log/messages, journalctl) showing gvfsd-sftp process aborts with heap corruption errors or segmentation faults; gvfs debug logs indicating abnormal SFTP response lengths.
  • Network: Outbound SFTP connections (TCP port 22) from user workstations to unfamiliar or suspicious IP addresses; SFTP sessions initiated from sftp:// URIs delivered via email or web.
  • File System: Core dump files generated by gvfsd-sftp in /var/lib/systemd/coredump/ or /tmp/ following process crashes.

Mitigation and workarounds

The upstream fix is included in gvfs version 1.60.2; users should upgrade to this version or later as soon as packages are available for their distribution (Red Hat Bugzilla). A Fedora 43 advisory has been issued for updated gvfs packages (Linux Security). As an immediate workaround, Red Hat recommends not connecting to untrusted SFTP servers; organizations should restrict SFTP mounting to known, trusted servers and consider disabling SFTP mounting capabilities via gvfs if not operationally required (Red Hat Advisory). On RHEL systems, ensuring SELinux is in enforcing mode and ASLR is enabled provides additional mitigation against arbitrary code execution.

Community reactions

Red Hat rated this vulnerability as "Important" severity and acknowledged that default RHEL security features (SELinux, ASLR, NX) reduce the practical risk of code execution (Red Hat Advisory). The vulnerability was credited to Keith Linneman of LinnemanLabs. Community discussion appeared on Reddit's r/pwnhub CVE daily brief and on Bluesky, with general awareness-level coverage rather than significant alarm, consistent with the lack of active exploitation.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

gvfs

Affected

sid

gvfs: 1.62.0-1

Fixed

trixie

gvfs

Affected

Ubuntu

Unknown

bionic (esm-infra)

gvfs

Unknown

devel

gvfs

Unknown

focal (esm-infra)

gvfs

Unknown

jammy

gvfs

Unknown

noble

gvfs

Unknown

resolute

gvfs

Unknown

xenial (esm-infra-legacy)

gvfs

Unknown

RHEL / CentOS

Affected

RHEL 8

gvfs.src

Affected

RHEL 9

gvfs.src

Affected

RHEL 10

gvfs.src

Affected

SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-94106HIGH8.7
  • Linux Debian logoLinux Debian
  • php-getid3
NoNoSep 20, 2026
CVE-2026-93990HIGH8.7
  • Linux Debian logoLinux Debian
  • expat
NoYesSep 19, 2026
CVE-2026-94108HIGH8.3
  • Linux Debian logoLinux Debian
  • php-getid3
NoNoSep 20, 2026
CVE-2026-93962MEDIUM5.5
  • Linux Debian logoLinux Debian
  • kamailio
NoNoSep 20, 2026
CVE-2026-82560NONEN/A
  • Linux Debian logoLinux Debian
  • seal-perl
NoYesSep 19, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management