Skip to content
Red HatCVE-2026-84268

Red Hat SFTP backend: denial of service

High8.8CVE-2026-84268 · Published Sep 1, 2026 · updated Sep 2, 2026

A flaw was found in the SFTP backend in gvfs. When mounting a share and reading a file, a malicious SFTP server can cause read_reply() to process a length that exceeds the size requested by the client. The function does not verify the server-provided length against the allocated buffer size, causing the operation to write past the intended boundaries. This issue allows a malicious server to corrupt adjacent heap memory in the gvfsd-sftp process, resulting in a denial of service as the process aborts upon detecting the heap corruption or potentially allowing arbitrary code execution.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Enterprise Linux 10
Product
all versionsNo fix yet
Red Hat Enterprise Linux 6
Product
all versionsNo fix yet
Red Hat Enterprise Linux 7
Product
all versionsNo fix yet
Red Hat Enterprise Linux 8
Product
all versionsNo fix yet
Red Hat Enterprise Linux 9
Product
all versionsNo fix yet
gvfs
Product
< 1.60.21.60.2
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat Ansible Automation Platform: missing authorization
Medium6.4Sep 1
Red Hat SFTP backend: uninitialized resource
Medium4.3Sep 1
Red Hat AFP backend: denial of service
Medium6.5Sep 1
Red Hat MTP backend: denial of service
Medium4.3Sep 1
Red Hat pulpcore: cross-site scripting
Medium5.4Sep 1
Red Hat OpenShift Container Platform 4: resource exhaustion
High7.5Sep 1

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.