Executive brief
GNOME gvfs is a virtual filesystem implementation used to mount and access remote storage devices. A malicious MTP device can trick the gvfs MTP backend into reading more data than requested from memory, causing the gvfsd-mtp process to crash and making the device inaccessible to users until the service is restarted.
Technical details
The vulnerability is a buffer overflow in the MTP backend's do_read() function in gvfsbackendmtp.c. The root cause is that the code trusts the data length returned by an MTP device without validating it against the original request size. When a malicious MTP device responds with more bytes than requested, this unchecked length is passed directly to memcpy(), causing an out-of-bounds read that crashes the gvfsd-mtp daemon. The attack requires physical access to connect a malicious MTP device; no authentication or network access is required. An attacker can achieve denial of service by triggering a segmentation fault when any file is read from the compromised device.
Affected products
- GNOME gvfs <UNKNOWN>
Timeline
- 2026-09-01: disclosed