← All Advisories

CVE-2026-84268

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-84268

Key Details

CVECVE-2026-84268
CVSS Score / Version8.8 (High) / CVSS v3.1
Updated2026-10-01
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is required; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productssee table below
Classified asCWE-122 (Heap-based Buffer Overflow)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Red HatRed Hat Enterprise Linux 10
Red HatRed Hat Enterprise Linux 8
Red HatRed Hat Enterprise Linux 9
Red HatRed Hat Enterprise Linux 7
GNOMEgvfs
Red HatRed Hat Enterprise Linux 6
SubsystemsGeneral OT
SectorsMultiple

What to Know

A flaw was found in the SFTP backend in gvfs. When mounting a share and reading a file, a malicious SFTP server can cause read_reply() to process a length that exceeds the size requested by the client. The function does not verify the server-provided length against the allocated buffer size, causing the operation to write past the intended boundaries. This issue allows a malicious server to corrupt adjacent heap memory in the gvfsd-sftp process, resulting in a denial of service as the process aborts upon detecting the heap corruption or potentially allowing arbitrary code execution. (NVD)

What to Do

Monitor Red Hat's and GNOME's web pages for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-84268
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-84268