Executive brief
GNOME Virtual File System (gvfs) is used to mount and access remote file shares, including SFTP servers. A malicious SFTP server can trigger a heap buffer overflow in the gvfsd-sftp process when a client reads a file, causing the service to crash or potentially allowing code execution. This could be exploited by attackers who control or intercept an SFTP connection to take down the file access service or gain unauthorized access to the affected system.
Technical details
The vulnerability exists in the SFTP backend's read_reply() function, which processes responses from an SFTP server. The function fails to validate that the server-provided length value is consistent with the buffer size allocated by the client, leading to a heap buffer overflow. An attacker controlling a malicious SFTP server can respond to a client file read request with a length field exceeding the client's expected allocation, causing out-of-bounds memory writes. The attack vector is network-based and requires the victim to connect to the attacker's malicious SFTP server. This can result in heap memory corruption, denial of service (process abort), or potentially arbitrary code execution within the gvfsd-sftp process context.
Affected products
- GNOME gvfs <UNKNOWN>
Timeline
- 2026-09-01: disclosed