{"id":"openSUSE-SU-2026:20451-1","summary":"Security update for gnome-online-accounts, gvfs","details":"This update for gnome-online-accounts, gvfs fixes the following issues:\n\nChanges for gvfs:\n\nUpdate gvfs to 1.59.90:\n\n- CVE-2026-28295: information disclosure when processing untrusted PASV responses from FTP servers (bsc#1258953).\n- CVE-2026-28296: arbitrary FTP command injection due to unsanitized CRLF sequences in user supplied file paths\n  (bsc#1258954).\n\nChangelog:\n\nUpdate to version 1.59.90:\n\n + client: Fix use-after-free when creating async proxy failed\n + udisks2: Emit changed signals from update_all()\n + daemon: Fix race on subscribers list when on thread\n + ftp: Validate fe_size when parsing symlink target\n + ftp: Check localtime() return value before use\n + gphoto2: Use g_try_realloc() instead of g_realloc()\n + cdda: Reject path traversal in mount URI host\n + client: Fail when URI has invalid UTF-8 chars\n + udisks2: Fix memory corruption with duplicate mount paths\n + build: Update GOA dependency to \u003e 3.57.0\n + Some other fixes\n + ftp: Use control connection address for PASV data.\n + ftp: Reject paths containing CR/LF characters\n\nUpdate to version 1.59.1:\n\n + mtp: replace Android extension checks with capability checks\n + dav: Add X-OC-Mtime header on push to preserve last modified\n time\n + udisks2: Use hash tables in the volume monitor to improve\n performance\n + onedrive: Check for identity instead of presentation identity\n + build: Disable google option and mark as deprecated\n\nUpdate to version 1.58.2:\n\n + ftp: Use control connection address for PASV data\n + ftp: Reject paths containing CR/LF characters\n\nUpdate to version 1.58.1:\n\n + cdda: Fix duration of last track for some media\n + build: Fix build when google option is disabled\n + Fix various memory leaks\n + Updated translations.\n\nUpdate to version 1.58.0:\n\n + mtp: Allow cancelling ongoing folder enumerations\n + wsdd: Use socket-activated service if available\n + onedrive: Set emblem for remote data\n + fix: Add file rename support in MTP backend move operation\n + mtp: Fix -Wmaybe-uninitialized warning in pad_file\n + fuse: use fuse_(un)set_feature_flag for libfuse 3.17+\n + smbbrowse: Purge server cache for next auth try\n + metatree: Open files with O_CLOEXEC\n + cdda: Fix incorrect track duration for 99-track CDs\n + metadata: Fix journal file permissions inconsistency\n + dav: recognize 308 Permanent Redirect\n\nChanges for gnome-online-accounts:\n\nUpdate to version 3.58.0:\n\n + SMTP server without password cannot be configured\n + Remove unneeded SMTP password escaping\n + build: Disable google provider Files feature\n + MS365: Fix mail address and name\n + Google: Set mail name to presentation identity\n + Updated translations.\n\nUpdate to version 3.57.1:\n\n + Default Microsoft 365 client is unverified\n + Microsoft 365: Make use of email for id\n + goadaemon: Allow manage system notifications\n + goamsgraphprovider: bump credentials generation\n + goaprovider: Allow to disable, instead of enable, selected\n   providers\n\nChanges from version 3.57.0:\n\n + Support for saving a Kerberos password to the keychain after\n the first login\n + changing expired kerberos password is not supported.\n + Provided Files URI does not override undiscovered endpoint\n + DAV client rejects 204 status in OPTIONS request handler\n + Include emblem-default-symbolic.svg\n + Connecting a Runbox CardDAV/CalDAV account hangs/freezes after\n sign in\n + i81n: fix translatable string\n + goaimapsmptprovider: fix accounts without SMTP or\n   authentication-less SMTP\n + build: only install icons for the goabackend build\n + build: don't require goabackend to build documentation\n + ci: test the build without gtk4\n + DAV-client: Added short path for SOGo\n\nUpdate to version 3.56.4:\n\n + Bugs fixed:\n - Unclear which part of \"IMAP+SMTP\" account test failed\n - Adding nextcloud account which has a subfolder does not work\n - goadaemon: Handle broken account configs\n\nUpdate to version 3.56.3:\n\n - Add DAV detection and configuration for SOGo\n - DAV discovery fails when certain SRV lookups fail\n\nUpdate to version 3.56.1:\n\n - Support for saving a Kerberos password after the first login\n - Changing expired kerberos password is not supported\n - Provided Files URI does not override undiscovered endpoint\n - DAV client rejects 204 status in OPTIONS request handler\n\nUpdate to version 3.56.0:\n\n + Code style and logging cleanups\n + Updated translations\n\nUpdate to version 3.55.2:\n\n + goaoauth2provider: improve error handling for auth/token\n   endpoints\n\nUpdate to version 3.55.1:\n\n - Support Webflow authentication for Nextcloud\n - Rename dconf key in gnome-online-accounts settings\n - \"Account Name\" GUI field is a bit ambiguous\n - Failed to generate a new POT file for the user interface of\n   \"gnome-online-accounts\" (domain: \"po\") and some missing files\n    from POTFILES.in\n\nUpdate to version 3.55.0:\n\n - Add progress spinner for OAuth2 dialogs\n - Remove Windows Live! option\n - Improve goa_oauth2_provider_ensure_credentials_sync\n - Authentication failure in goa IMAP accounts\n - Missing files from POTFILES.in\n - WebDAV not detected for mail.ru\n - goaoauth2provider: fix task chaining for subclasses\n - Always lowercase domains when looking up base\n - goadavclient: check Nextcloud fallback last\n - goabackend: add a composite widget for authflow links\n - goadavclient: fix the mailbox.org preconfig\n\nUpdate to version 3.54.5:\n\n - Adding GOA account fails with sonic.net IMAP service\n - Cannot add a ProtonMail bridge with IMAP + TLS\n - Nextcloud login does not work anymore due to OPTIONS /login\n   request\n - Linked online accounts no longer work\n - Invalid URI when adding Google account\n - goamsgraphprovider: ensure a valid PresentationIdentity\n - goadaemon: complete GTasks to avoid a scary debug warning\n","modified":"2026-04-03T17:26:09.683749Z","published":"2026-03-31T09:11:58Z","related":["CVE-2026-28295","CVE-2026-28296"],"upstream":["CVE-2026-28295","CVE-2026-28296"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258953"},{"type":"REPORT","url":"https://bugzilla.suse.com/1258954"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-28295"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-28296"}],"affected":[{"package":{"name":"gnome-online-accounts","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/gnome-online-accounts&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.58.0-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"libgoa-backend-1_0-2":"3.58.0-160000.1.1","gnome-online-accounts-lang":"3.58.0-160000.1.1","gnome-online-accounts":"3.58.0-160000.1.1","gvfs-backend-afc":"1.59.90-160000.1.1","gvfs-backends":"1.59.90-160000.1.1","gvfs-fuse":"1.59.90-160000.1.1","gvfs":"1.59.90-160000.1.1","libgoa-1_0-0":"3.58.0-160000.1.1","typelib-1_0-Goa-1_0":"3.58.0-160000.1.1","gnome-online-accounts-devel":"3.58.0-160000.1.1","gvfs-backend-goa":"1.59.90-160000.1.1","gvfs-backend-gphoto":"1.59.90-160000.1.1","gvfs-backend-samba":"1.59.90-160000.1.1","gvfs-lang":"1.59.90-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20451-1.json"}},{"package":{"name":"gvfs","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/gvfs&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.59.90-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"gnome-online-accounts-devel":"3.58.0-160000.1.1","gnome-online-accounts-lang":"3.58.0-160000.1.1","gnome-online-accounts":"3.58.0-160000.1.1","gvfs-backend-afc":"1.59.90-160000.1.1","gvfs-backend-goa":"1.59.90-160000.1.1","gvfs-backend-samba":"1.59.90-160000.1.1","gvfs":"1.59.90-160000.1.1","libgoa-backend-1_0-2":"3.58.0-160000.1.1","gvfs-backend-gphoto":"1.59.90-160000.1.1","gvfs-backends":"1.59.90-160000.1.1","gvfs-fuse":"1.59.90-160000.1.1","gvfs-lang":"1.59.90-160000.1.1","libgoa-1_0-0":"3.58.0-160000.1.1","typelib-1_0-Goa-1_0":"3.58.0-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20451-1.json"}}],"schema_version":"1.7.5"}