UbuntuUpdates.org

Package "gvfs-backends"

Name: gvfs-backends

Description:

userspace virtual filesystem - backends

Latest version: 1.54.4-0ubuntu1~24.04.2
Release: noble (24.04)
Level: updates
Repository: main
Head package: gvfs
Homepage: https://wiki.gnome.org/Projects/gvfs

Links


Download "gvfs-backends"


Other versions of "gvfs-backends" in Noble

Repository Area Version
base main 1.54.0-1ubuntu2
security main 1.54.4-0ubuntu1~24.04.2

Changelog

Version: 1.54.4-0ubuntu1~24.04.2 2026-03-24 02:08:05 UTC

  gvfs (1.54.4-0ubuntu1~24.04.2) noble-security; urgency=medium

  * SECURITY UPDATE: open port probe via FTP backend
    - debian/patches/CVE-2026-28295.patch: use control connection address
      for PASV data in daemon/gvfsbackendftp.c, daemon/gvfsbackendftp.h,
      daemon/gvfsftptask.c.
    - CVE-2026-28295
  * SECURITY UPDATE: arbitrary FTP command injection via CRLF
    - debian/patches/CVE-2026-28296.patch: reject paths containing CR/LF
      characters in daemon/gvfsbackendftp.c, daemon/gvfsftpfile.c,
      daemon/gvfsftpfile.h.
    - CVE-2026-28296

 -- Marc Deslauriers <email address hidden> Wed, 18 Mar 2026 12:12:50 -0400

Source diff to previous version
CVE-2026-28295 A flaw was found in the FTP GVfs backend. A malicious FTP server can exploit this vulnerability by providing an arbitrary IP address and port in its
CVE-2026-28296 A flaw was found in the FTP GVfs backend. A remote attacker could exploit this input validation vulnerability by supplying specially crafted file pat

Version: 1.54.4-0ubuntu1~24.04.1 2025-07-17 01:07:39 UTC

  gvfs (1.54.4-0ubuntu1~24.04.1) noble; urgency=medium

  * New upstream release (LP: #2109540):
    - disks2: Increasing reference count when updating volume to fix crashes
      when mounting encrypted partitions (LP: #2109538)
  * debian/{rules,install}: Enable burn backend again.
    We don't want to disable a feature in a SRU, so even if it doesn't work
    well with nautilus, it may be required by some command line tools.
  * debian/watch Limit to 1.54 branch
  * debian: Update vcs references to the noble branch
  * debian/rules: Enable burn backend again

 -- Marco Trevisan (Treviño) <email address hidden> Fri, 23 May 2025 14:30:56 +0200

2109540 [SRU] Update gvfs to 1.54.4
2109538 gvfs-udisks2-volume-monitor crashes on on_udisks_client_changed() \u2192 g_task_get_task_data()



About   -   Send Feedback to @ubuntu_updates