CVE-2026-84270

Source
https://cve.org/CVERecord?id=CVE-2026-84270
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-84270.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-84270
Downstream
Published
2026-09-01T15:19:14.312Z
Modified
2026-09-04T03:30:17.336474639Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Gvfs: mtp: out-of-bounds read in do_read()
Details

A flaw was found in the MTP backend in gvfs. When reading a file from a mounted MTP device, do_read() in gvfsbackendmtp.c trusts the data length returned by the device without limiting it to the original size requested by the client. If a malicious MTP device responds with more bytes than requested, this unrestricted length is passed directly to memcpy(). This causes the operation to read memory outside the intended boundaries. This allows an attacker who plugs in a malicious MTP device to cause a segmentation fault when a file is read and crash the gvfsd-mtp process, resulting in a denial of service.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/84xxx/CVE-2026-84270.json",
    "cna_assigner": "redhat",
    "cwe_ids": [
        "CWE-125"
    ]
}
References

Affected packages

Git / gitlab.gnome.org/gnome/gvfs

Affected ranges

Type
GIT
Repo
https://gitlab.gnome.org/gnome/gvfs
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.60.2"
        }
    ]
}

Affected versions

1.*
1.10.0
1.11.3
1.11.4
1.11.5
1.12.0
1.12.1
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.13.5
1.13.6
1.13.7
1.13.8
1.13.9
1.14.0
1.15.0
1.15.1
1.15.2
1.15.3
1.15.4
1.16.0
1.17.0
1.17.1
1.17.2
1.17.3
1.17.90
1.18.0
1.18.1
1.18.2
1.19.1
1.19.2
1.19.3
1.19.4
1.19.5
1.19.90
1.20.0
1.21.1
1.21.2
1.21.3
1.21.4
1.21.90
1.21.92
1.22.0
1.23.1
1.23.2
1.23.3
1.23.4
1.23.90
1.23.92
1.24.0
1.25.1
1.25.2
1.25.3
1.25.4
1.25.4.1
1.25.90
1.25.91
1.25.92
1.26.0
1.26.1
1.26.1.1
1.26.2
1.27.3
1.27.4
1.27.90
1.27.91
1.27.92
1.28.0
1.28.1
1.29.1
1.29.2
1.29.3
1.29.4
1.29.90
1.29.91
1.29.92
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.30.0
1.31.1
1.31.2
1.31.3
1.31.4
1.31.90
1.31.91
1.31.92
1.32.0
1.33.1
1.33.3
1.33.90
1.33.91
1.33.92
1.34.0
1.35.1
1.35.2
1.35.3
1.35.4
1.35.90
1.35.91
1.35.92
1.36.0
1.37.1
1.37.2
1.37.4
1.37.90
1.37.91
1.38.0
1.39.1
1.39.3
1.39.4
1.39.90
1.39.91
1.39.92
1.4.0
1.40.0
1.41.1
1.41.2
1.41.3
1.41.4
1.41.90
1.41.91
1.42.0
1.43.1
1.43.2
1.43.90
1.43.91
1.43.92
1.44.0
1.44.1
1.45.2
1.45.3
1.45.90
1.45.92
1.46.0
1.46.1
1.47.1
1.47.90
1.47.91
1.48.0
1.48.1
1.49.1
1.49.90
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.50.0
1.50.1
1.50.2
1.50.3
1.50.4
1.51.1
1.51.90
1.51.91
1.52.0
1.52.1
1.53.1
1.53.90
1.53.91
1.54.0
1.54.1
1.55.1
1.55.90
1.56.0
1.56.1
1.57.1
1.57.2
1.58.0
1.59.1
1.59.90
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.60.0
1.60.1
1.7.0
1.7.1
1.7.2
1.7.3
1.9.0
1.9.1
1.9.2
1.9.3
1.9.4
1.9.5
Other
GVFS_0_0_1
GVFS_0_0_2
GVFS_0_1_0
GVFS_0_1_1
GVFS_0_1_10
GVFS_0_1_11
GVFS_0_1_2
GVFS_0_1_3
GVFS_0_1_4
GVFS_0_1_5
GVFS_0_1_6
GVFS_0_1_7
GVFS_0_1_8
GVFS_0_1_9
GVFS_0_2_0
GVFS_0_2_0_1
GVFS_0_2_1
GVFS_0_2_2
GVFS_0_2_4
GVFS_0_99_1
GVFS_0_99_2
GVFS_0_99_3
GVFS_0_99_4
GVFS_0_99_5
GVFS_0_99_6
GVFS_0_99_7
GVFS_1_1_1
GVFS_1_1_2
GVFS_1_1_3
GVFS_1_1_4
GVFS_1_1_5
GVFS_1_1_6
GVFS_1_1_7
GVFS_1_1_8
GVFS_1_2_1
GVFS_1_2_2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-84270.json"