Impact
A flaw in the gvfs SFTP backend causes a heap‑based buffer overflow when the read_reply() function processes a length supplied by the server that exceeds the buffer allocated by the client. This overflow corrupts adjacent heap memory in the gvfsd-sftp process, which can either terminate the process with a denial of service or, in the worst case, allow the malicious server to execute arbitrary code in the context of that process.
Affected Systems
The vulnerability is present in Red Hat Enterprise Linux releases 6 through 10, affecting the gvfs component that provides SFTP support. No specific version numbers are listed, so all standard gvfs packages delivered with these OS releases are potentially impacted.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity vulnerability. The EPSS score is not available and the issue is not listed in the CISA KEV catalog, but the attack can be carried out remotely via a malicious SFTP server that a user connects to. Because the flaw allows either a denial of service or remote code execution, the likelihood of exploitation is considered significant for systems that allow untrusted SFTP connections.
OpenCVE Enrichment