OSV 1.4.0 · unreviewed · 修改于 2026-09-02 02:30
发布时间
2026-09-02 02:30
GitHub 审查时间
—
NVD 发布时间
2026-09-02 00:17
源文件
advisories/unreviewed/2026/09/GHSA-8cxg-v7p7-qc7j/GHSA-8cxg-v7p7-qc7j.json
A flaw was found in the SFTP backend in gvfs. When mounting a share and reading a file, a malicious SFTP server can cause read_reply() to process a length that exceeds the size requested by the client. The function does not verify the server-provided length against the allocated buffer size, causing the operation to write past the intended boundaries. This issue allows a malicious server to corrupt adjacent heap memory in the gvfsd-sftp process, resulting in a denial of service as the process aborts upon detecting the heap corruption or potentially allowing arbitrary code execution.
该公告没有提供结构化的受影响软件包信息。