Impact
A heap-based buffer overflow occurs in the AFP backend of gvfs when the DSI read path processes a server‑supplied length that exceeds the allocated reply buffer. The flaw does not validate the length against the pre‑sized buffer, allowing a malicious AFP server to overflow the heap and crash the gvfsd‑afp process. The result is a denial of service because the affected process terminates, interrupting file operations over AFP shares. This weakness maps to CWE‑122 "Heap Based Buffer Overflow".
Affected Systems
The vulnerability affects Red Hat Enterprise Linux releases 6 through 10. The specific impacted product is the gvfs component that manages AFP shares, and all systems running these operating‑system versions include it by default. No sub‑version details are provided; users should assume all releases contain the unpatched gvfs package.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. EPSS is not available, but the vulnerability is not listed in CISA KEV, suggesting no known widespread exploitation at this time. The attack requires the ability to mount an AFP share, so access can be granted by an attacker who controls or tricks a client into connecting to a malicious AFP server. The crash is local to the gvfsd‑afp process; it does not directly compromise system integrity or confidentiality, but repeated crashes can cause significant availability disruption.
OpenCVE Enrichment