OSV 1.4.0 · unreviewed · 修改于 2026-09-02 02:30
发布时间
2026-09-02 02:30
GitHub 审查时间
—
NVD 发布时间
2026-09-02 00:17
源文件
advisories/unreviewed/2026/09/GHSA-7jmj-69v2-2vjf/GHSA-7jmj-69v2-2vjf.json
A flaw was found in the AFP backend in gvfs. When mounting a share, a malicious AFP server can cause the DSI read path to process a length that exceeds the size requested by the client. The function does not verify the server-provided length against the pre-sized reply buffer, causing the operation to access past the intended boundaries. This issue allows a malicious server to overflow a heap buffer and crash the gvfsd-afp process, resulting in a denial of service.
该公告没有提供结构化的受影响软件包信息。