UbuntuUpdates.org

Package "gvfs"

Name: gvfs

Description:

userspace virtual filesystem - GIO module

Latest version: 1.48.2-0ubuntu1.1
Release: jammy (22.04)
Level: security
Repository: main
Homepage: https://wiki.gnome.org/Projects/gvfs

Links


Download "gvfs"


Other versions of "gvfs" in Jammy

Repository Area Version
base main 1.48.1-4
updates main 1.48.2-0ubuntu1

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 1.48.2-0ubuntu1.1 2026-03-23 14:07:59 UTC

  gvfs (1.48.2-0ubuntu1.1) jammy-security; urgency=medium

  * SECURITY UPDATE: open port probe via FTP backend
    - debian/patches/CVE-2026-28295.patch: use control connection address
      for PASV data in daemon/gvfsbackendftp.c, daemon/gvfsbackendftp.h,
      daemon/gvfsftptask.c.
    - CVE-2026-28295
  * SECURITY UPDATE: arbitrary FTP command injection via CRLF
    - debian/patches/CVE-2026-28296.patch: reject paths containing CR/LF
      characters in daemon/gvfsbackendftp.c, daemon/gvfsftpfile.c,
      daemon/gvfsftpfile.h.
    - CVE-2026-28296

 -- Marc Deslauriers <email address hidden> Wed, 18 Mar 2026 12:17:40 -0400

CVE-2026-28295 A flaw was found in the FTP GVfs backend. A malicious FTP server can exploit this vulnerability by providing an arbitrary IP address and port in its
CVE-2026-28296 A flaw was found in the FTP GVfs backend. A remote attacker could exploit this input validation vulnerability by supplying specially crafted file pat



About   -   Send Feedback to @ubuntu_updates