gvfs-1.48.1-8.el9_8.1

エラータID: AXSA:2026-1955:04

リリース日: 
2026/10/02 Friday - 16:23
題名: 
gvfs-1.48.1-8.el9_8.1
影響のあるチャネル: 
MIRACLE LINUX 9 for x86_64
Severity: 
High
Description: 

GVFS is the GNOME Desktop Virtual File System layer that allows users to easily access local and remote data using File Transfer Protocol (FTP), Secure Shell File Transfer Protocol (SFTP), Web Distributed Authoring and Versioning (WebDAV), Common Internet File System (CIFS), Server Message Block (SMB), and other protocols. GVFS integrates with the GNOME I/O (GIO) abstraction layer.

Security Fix(es):

* gvfs: SFTP: heap-based buffer overflow in read_reply() (CVE-2026-84268)
* gvfs: gvfs-admin socket ownership race permits local root (CVE-2026-88924)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-84268
A flaw was found in the SFTP backend in gvfs. When mounting a share and reading a file, a malicious SFTP server can cause read_reply() to process a length that exceeds the size requested by the client. The function does not verify the server-provided length against the allocated buffer size, causing the operation to write past the intended boundaries. This issue allows a malicious server to corrupt adjacent heap memory in the gvfsd-sftp process, resulting in a denial of service as the process aborts upon detecting the heap corruption or potentially allowing arbitrary code execution.
CVE-2026-88924
A flaw was found in the admin backend of gvfs. The privileged gvfsd-admin daemon changes the ownership of newly created private D-Bus sockets by calling the link-following chown() function on a pathname inside a user-controlled directory. A local attacker can exploit this via a Time-of-Check Time-of-Use (TOCTOU) race condition and exchange the socket pathname with a symbolic link pointing to an arbitrary root-owned file (such as /etc/pam.d/su). The daemon subsequently follows the symlink and changes the ownership of the targeted root-owned file to the attacker's user ID. This allows an authenticated local attacker to modify critical system files, leading to a full local privilege escalation to root.

解決策: 

Update packages.

追加情報: 

N/A

ダウンロード: 

SRPMS
  1. gvfs-1.48.1-8.el9_8.1.src.rpm
    MD5: b316d41a329d5d451bf9b15fcb698439
    SHA-256: b4fd6d8d9c02676b49230e363b211c0a64c9afa70910c9f74261d3c07af9f945
    Size: 1.22 MB

Asianux Server 9 for x86_64
  1. gvfs-1.48.1-8.el9_8.1.i686.rpm
    MD5: bb6af1b1394d844c362e5510ce532cd9
    SHA-256: ef31ef8733de36c9080311ab720f140193236ebce7622e056f29ecef6fb15c09
    Size: 385.70 kB
  2. gvfs-1.48.1-8.el9_8.1.x86_64.rpm
    MD5: 276d8529d8d76c4f4e4961590a774527
    SHA-256: c35a95a31e877684b566e69c68778827b997a7e54351cf7dc1fd2a0fb41ba7b3
    Size: 357.49 kB
  3. gvfs-client-1.48.1-8.el9_8.1.i686.rpm
    MD5: 5967f499c722d69faa963d6119cdd489
    SHA-256: 7a70acf71f2280e006e92b124f6bf348672b08d0233011d0b368123720b97e1c
    Size: 766.72 kB
  4. gvfs-client-1.48.1-8.el9_8.1.x86_64.rpm
    MD5: f4b82460f70d3791b022e7704ca6c4fe
    SHA-256: f35303f3afe61953b2613c102327e8fff4286a0049b4c607417dd4175353498b
    Size: 754.46 kB
  5. gvfs-devel-1.48.1-8.el9_8.1.i686.rpm
    MD5: 8442c55778fd435198d9008e1017a0f6
    SHA-256: 755175b9bab6efed252444313c71cf08c1577aec04d0c38c754b04624975575c
    Size: 9.16 kB
  6. gvfs-devel-1.48.1-8.el9_8.1.x86_64.rpm
    MD5: a4f3ad62f4365014131a6694d780f957
    SHA-256: ffbbe09e0b34335ba913f3c737d51721f6802ea33dd2a23dd2aaa85c0bc3f7cf
    Size: 9.14 kB
  7. gvfs-fuse-1.48.1-8.el9_8.1.x86_64.rpm
    MD5: 5e806617ff9d8bb6d3ba559e65a8d3b3
    SHA-256: 277a2d9c84eaa45b7a80f4cb3f8ed855d5c6bd49322bd90481cb7b5a654d52e2
    Size: 27.05 kB
  8. gvfs-goa-1.48.1-8.el9_8.1.x86_64.rpm
    MD5: bb6aff724625b6214ec88bd289e22343
    SHA-256: 85b852690b92d6b9e0f57ad60a0bf1a457921163f4117bbf853246ca66f64cd1
    Size: 66.72 kB
  9. gvfs-gphoto2-1.48.1-8.el9_8.1.x86_64.rpm
    MD5: 2a75380543baf34af0cf6c57fb371d62
    SHA-256: 73239d8f11b26cc7a2b504f20b51fbc97d9c89304ed2ff595c23c268b558690f
    Size: 59.52 kB
  10. gvfs-mtp-1.48.1-8.el9_8.1.x86_64.rpm
    MD5: 017e9881b7cefb9711d74250116fa071
    SHA-256: 31e0341dcf1bc76f95780a55cf5fd039af4a8435da4bd1a3caf2cced7a20643b
    Size: 60.20 kB
  11. gvfs-smb-1.48.1-8.el9_8.1.x86_64.rpm
    MD5: da95cb82a0ec683311e79a7268f907ba
    SHA-256: 0d805df9ed09d50d39bb7ae4a1cd5155bae6b682ddc0e91c238c51ccfda69839
    Size: 38.81 kB