|
|
Log in / Subscribe / Register

Ubuntu alert USN-8114-1 (gvfs)

From:  noreply+usn-bot@canonical.com
To:  ubuntu-security-announce@lists.ubuntu.com
Subject:  [USN-8114-1] GVfs vulnerabilities
Date:  Mon, 23 Mar 2026 13:59:29 +0000
Message-ID:  <E1w4foX-0007EZ-1f@lists.ubuntu.com>

========================================================================== Ubuntu Security Notice USN-8114-1 March 23, 2026 gvfs vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Several security issues were fixed in GVfs. Software Description: - gvfs: Userspace virtual file system Details: It was discovered that the GVfs FTP backend incorrectly handled IP addresses and ports returned by passive mode responses. A malicious remote server could possibly use this issue to help scan for open ports. (CVE-2026-28295) It was discovered that the GVfs FTP backend incorrectly handled crafted file paths. A remote attacker could use this issue to terminate or inject arbitrary FTP commands, or possibly execute arbitrary code. (CVE-2026-28296) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 gvfs 1.57.2-2ubuntu5.1 gvfs-backends 1.57.2-2ubuntu5.1 Ubuntu 24.04 LTS gvfs 1.54.4-0ubuntu1~24.04.2 gvfs-backends 1.54.4-0ubuntu1~24.04.2 Ubuntu 22.04 LTS gvfs 1.48.2-0ubuntu1.1 gvfs-backends 1.48.2-0ubuntu1.1 After a standard system update you need to restart your session to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8114-1 CVE-2026-28295, CVE-2026-28296 Package Information: https://launchpad.net/ubuntu/+source/gvfs/1.57.2-2ubuntu5.1 https://launchpad.net/ubuntu/+source/gvfs/1.54.4-0ubuntu1... https://launchpad.net/ubuntu/+source/gvfs/1.48.2-0ubuntu1.1


Attachment: signature.asc (type=application/pgp-signature)

-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmnBRqMACgkQcpJm3tlz hgE1Zg/+L9wjYHb941ih3xZTXGiKPWvwlOjHUDPXaO2uWo2TaCCpQXKJZHApK11w Yt4TGzheRJBrWKAZis+phSuM/qxFJyiVeuYUyzMfYfZ14/90x05Nqae9v8bh6dj4 F1ivdsGqfgtNANZsnUN/yNpMI9gzCI38+vCcXT6C4W4BUzklUe0OvtlgJYgtBOF5 w9tXyYLXlX8jekAsSzOMw13WRi3ZyNP+/GAy7SYQNlH8wUq0KqeIZzHVjnWe9a9H uqrmU1s6i/bq2TAI1+e7vG/e6nLVJaP86cq1+cWx4yKX8vrfDo17XfExej4oaGb8 rLNQ+ViMSlCFWtp1G+/mOk3Y+amLOL0mD/8M1V1hIG1BZA2Nox7Doz1zC30t5ULk ewn41dV+axlKzQQ4MFinuwD9j/5L0OxyqShHZyrBUhuRZKB4tnVFyO6g7/nzavMC 8PEPdkmp78X9PK/hQx9gGw+GqIsk+A/b73hyEIhf6cGoY0/t2QiEYpiJGF35Nhj6 vfPTMyNL/SGfNKLH6WXccMqCnmsJ+TJqw2vUlhZObu7eveoLLxljsXNaJJm2H1q8 Jz3i5XLnQGuL9wRzL9bKcAko/LnluctuxcZlK75afmxMrLE+BlLDkqH3QXpdfZoF yQTO103oxO0o2aMS1KGIf4bkkloho6guOV3pBWSoJWbGFEU3gZY= =WIec -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds