Impact
A flaw in the MTP backend of gvfs allows an attacker who connects a malicious MTP device to supply a data length larger than requested during a file read operation. The backend trusts the device’s length when calling memcpy(), causing an out‑of‑bounds read and producing a segmentation fault in the gvfsd-mtp process. This results in a denial of service for any application relying on gvfs to access MTP devices.
Affected Systems
Red Hat Enterprise Linux 10, 6, 7, 8, and 9 are affected. No specific package version information is listed, so all released gvfs versions on these distributions may be vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting low exploitation likelihood in the wild. Attackers would need physical or local access to plug a malicious MTP device; the vulnerability primarily causes a crash of gvfsd-mtp, denying services that depend on that daemon. No active exploitation reports are known.
OpenCVE Enrichment