在 gvfs 的 MTP 后端中发现了缺陷。当从已挂载的 MTP 设备读取文件时, 中的 函数直接信任设备返回的数据长度,未将其限制为客户端最初请求的大小。如果恶意的 MTP 设备返回的字节数超过请求的量,这个未受限制的长度会被直接传递给 。这会导致该操作读取预期边界之外的内存。因此,插入恶意 MTP 设备的攻击者可以在读取文件时导致 进程发生段错误(segmentation fault)并崩溃,从而造成服务拒绝(DoS)。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-84268 | 8.8 HIGH | Gvfs: sftp: heap-based buffer overflow in read_reply() |
| CVE-2026-84218 | 8.1 HIGH | Org.jolokia/jolokia-core: incomplete jndi denylist in jolokia jsr-160 proxy (bypass of cve |
| CVE-2026-49329 | 7.5 HIGH | Openshift/oauth-server: openshift/oauth-server: quadratic-time dos via accept-language hea |
| CVE-2026-84233 | 7.0 HIGH | Rpm: command execution via macro expansion in `rpmuncompress -x` for crafted `.gem` filena |
| CVE-2026-84269 | 6.5 MEDIUM | Gvfs: afp: heap-based buffer overflow in dsi read path |
| CVE-2026-11873 | 6.5 MEDIUM | Pki-core: dogtag-pki: empty request to dogtag /ca/rest/certrequests causes http 500, java |
| CVE-2026-84232 | 5.4 MEDIUM | Pulpcore: python-pulpcore: stored cross-site scripting via inline rendering of uploaded ht |
| CVE-2026-53682 | 5.3 MEDIUM | Pki-core: dogtag-pki: unauthenticated dogtag ca rest api exposes security domain hosts |
| CVE-2026-84267 | 4.3 MEDIUM | Gvfs: sftp: uninitialized heap disclosure in read_string() |
No comments yet