A flaw was found in the SFTP backend in gvfs. When mounting a share and reading a file, a malicious SFTP server can cause read_reply() to process a length that exceeds the size requested by the client. The function does not verify the server-provided length ag
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-84218 | 8.1 HIGH | Org.jolokia/jolokia-core: incomplete jndi denylist in jolokia jsr-160 proxy (bypass of cve |
| CVE-2026-49329 | 7.5 HIGH | Openshift/oauth-server: openshift/oauth-server: quadratic-time dos via accept-language hea |
| CVE-2026-84233 | 7.0 HIGH | Rpm: command execution via macro expansion in `rpmuncompress -x` for crafted `.gem` filena |
| CVE-2026-84269 | 6.5 MEDIUM | Gvfs: afp: heap-based buffer overflow in dsi read path |
| CVE-2026-11873 | 6.5 MEDIUM | Pki-core: dogtag-pki: empty request to dogtag /ca/rest/certrequests causes http 500, java |
| CVE-2026-84232 | 5.4 MEDIUM | Pulpcore: python-pulpcore: stored cross-site scripting via inline rendering of uploaded ht |
| CVE-2026-53682 | 5.3 MEDIUM | Pki-core: dogtag-pki: unauthenticated dogtag ca rest api exposes security domain hosts |
| CVE-2026-84270 | 4.3 MEDIUM | Gvfs: mtp: out-of-bounds read in do_read() |
| CVE-2026-84267 | 4.3 MEDIUM | Gvfs: sftp: uninitialized heap disclosure in read_string() |
No comments yet