{"id":"CVE-2026-84269","summary":"Gvfs: afp: heap-based buffer overflow in dsi read path","details":"A flaw was found in the AFP backend in gvfs. When mounting a share, a malicious AFP server can cause the DSI read path to process a length that exceeds the size requested by the client. The function does not verify the server-provided length against the pre-sized reply buffer, causing the operation to access past the intended boundaries. This issue allows a malicious server to overflow a heap buffer and crash the gvfsd-afp process, resulting in a denial of service.","modified":"2026-09-03T03:48:20.338526389Z","published":"2026-09-01T15:19:08.794Z","database_specific":{"cna_assigner":"redhat","cwe_ids":["CWE-122"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/84xxx/CVE-2026-84269.json"},"references":[{"type":"WEB","url":"https://access.redhat.com/downloads/content/package-browser/"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2026-84269"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/84xxx/CVE-2026-84269.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-84269"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2526784"},{"type":"REPORT","url":"https://gitlab.gnome.org/GNOME/gvfs/-/issues/863"},{"type":"PACKAGE","url":"https://gitlab.gnome.org/GNOME/gvfs"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://gitlab.gnome.org/gnome/gvfs","events":[{"introduced":"0"},{"fixed":"5651571370400cf0a114f61af2fa96e0ff4784d5"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"1.60.2"}],"source":"AFFECTED_FIELD"}}],"versions":["1.60.1","1.60.0","1.59.90","1.59.1","1.58.0","1.57.2","1.57.1","1.56.1","1.56.0","1.55.90","1.55.1","1.54.1","1.54.0","1.53.91","1.53.90","1.53.1","1.52.1","1.52.0","1.51.91","1.51.90","1.51.1","1.50.4","1.50.3","1.50.2","1.50.1","1.50.0","1.49.90","1.49.1","1.48.1","1.48.0","1.47.91","1.47.90","1.47.1","1.46.1","1.46.0","1.45.92","1.45.90","1.45.3","1.45.2","1.44.1","1.44.0","1.43.92","1.43.91","1.43.90","1.43.2","1.43.1","1.42.0","1.41.91","1.41.90","1.41.4","1.41.3","1.41.2","1.41.1","1.40.0","1.39.92","1.39.91","1.39.90","1.39.4","1.39.3","1.39.1","1.38.0","1.37.91","1.37.90","1.37.4","1.37.2","1.37.1","1.36.0","1.35.92","1.35.91","1.35.90","1.35.4","1.35.3","1.35.2","1.35.1","1.34.0","1.33.92","1.33.91","1.33.90","1.33.3","1.33.1","1.32.0","1.31.92","1.31.91","1.31.90","1.31.4","1.31.3","1.31.2","1.31.1","1.30.0","1.29.92","1.29.91","1.29.90","1.29.4","1.29.3","1.29.2","1.29.1","1.28.1","1.28.0","1.27.92","1.27.91","1.27.90","1.27.4","1.27.3","1.26.2","1.26.1.1","1.26.1","1.26.0","1.25.92","1.25.91","1.25.90","1.25.4.1","1.25.4","1.25.3","1.25.2","1.25.1","1.24.0","1.23.92","1.23.90","1.23.4","1.23.3","1.23.2","1.23.1","1.22.0","1.21.92","1.21.90","1.21.4","1.21.3","1.21.2","1.21.1","1.20.0","1.19.90","1.19.5","1.19.4","1.19.3","1.19.2","1.19.1","1.18.2","1.18.1","1.18.0","1.17.90","1.17.3","1.17.2","1.17.1","1.17.0","1.16.0","1.15.4","1.15.3","1.15.2","1.14.0","1.15.1","1.15.0","1.13.9","1.13.8","1.13.7","1.13.6","1.13.5","1.13.4","1.13.3","1.13.2","1.13.1","1.13.0","1.12.1","1.12.0","1.11.5","1.11.4","1.11.3","1.10.0","1.9.5","1.9.4","1.9.3","1.9.2","1.9.1","1.9.0","1.7.3","1.7.2","1.7.1","1.7.0","1.6.5","1.6.4","1.6.3","1.6.2","1.6.1","1.6.0","1.5.5","1.5.4","1.5.3","1.5.2","1.5.1","1.4.0","1.3.6","1.3.5","1.3.4","1.3.3","1.3.2","1.3.1","GVFS_1_2_2","GVFS_1_2_1","GVFS_1_1_8","GVFS_1_1_7","GVFS_1_1_6","GVFS_1_1_5","GVFS_1_1_4","GVFS_1_1_3","GVFS_1_1_2","GVFS_1_1_1","GVFS_0_99_7","GVFS_0_99_6","GVFS_0_99_5","GVFS_0_99_4","GVFS_0_99_3","GVFS_0_99_2","GVFS_0_99_1","GVFS_0_2_4","GVFS_0_2_2","GVFS_0_2_1","GVFS_0_2_0_1","GVFS_0_2_0","GVFS_0_1_11","GVFS_0_1_10","GVFS_0_1_9","GVFS_0_1_8","GVFS_0_1_7","GVFS_0_1_6","GVFS_0_1_5","GVFS_0_1_4","GVFS_0_1_3","GVFS_0_1_2","GVFS_0_1_1","GVFS_0_1_0","GVFS_0_0_2","GVFS_0_0_1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-84269.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"}]}