Amazon Linux 2023 Security Advisory: ALAS2023-2026-3120
Advisory Released Date: 2026-09-29
Advisory Updated Date: 2026-09-29
A flaw was found in the SFTP backend in gvfs. When mounting a share and reading a file, a malicious SFTP server can cause read_reply() to process a length that exceeds the size requested by the client. The function does not verify the server-provided length against the allocated buffer size, causing the operation to write past the intended boundaries. This issue allows a malicious server to corrupt adjacent heap memory in the gvfsd-sftp process, resulting in a denial of service as the process aborts upon detecting the heap corruption or potentially allowing arbitrary code execution. (CVE-2026-84268)
A flaw was found in the admin backend of gvfs. The privileged gvfsd-admin daemon changes the ownership of newly created private D-Bus sockets by calling the link-following chown() function on a pathname inside a user-controlled directory. A local attacker can exploit this via a Time-of-Check Time-of-Use (TOCTOU) race condition and exchange the socket pathname with a symbolic link pointing to an arbitrary root-owned file (such as /etc/pam.d/su). The daemon subsequently follows the symlink and changes the ownership of the targeted root-owned file to the attacker's user ID. This allows an authenticated local attacker to modify critical system files, leading to a full local privilege escalation to root. (CVE-2026-88924)
Affected Packages:
gvfs
Issue Correction:
Run dnf update gvfs --releasever 2023.12.20260928 or dnf update --advisory ALAS2023-2026-3120 --releasever 2023.12.20260928 to update your system.
More information on how to update your system can be found on this page: Amazon Linux 2023 documentation
aarch64:
gvfs-nfs-debuginfo-1.56.1-1.amzn2023.0.3.aarch64
gvfs-client-debuginfo-1.56.1-1.amzn2023.0.3.aarch64
gvfs-debuginfo-1.56.1-1.amzn2023.0.3.aarch64
gvfs-fuse-debuginfo-1.56.1-1.amzn2023.0.3.aarch64
gvfs-goa-1.56.1-1.amzn2023.0.3.aarch64
gvfs-client-1.56.1-1.amzn2023.0.3.aarch64
gvfs-smb-debuginfo-1.56.1-1.amzn2023.0.3.aarch64
gvfs-fuse-1.56.1-1.amzn2023.0.3.aarch64
gvfs-nfs-1.56.1-1.amzn2023.0.3.aarch64
gvfs-goa-debuginfo-1.56.1-1.amzn2023.0.3.aarch64
gvfs-1.56.1-1.amzn2023.0.3.aarch64
gvfs-archive-1.56.1-1.amzn2023.0.3.aarch64
gvfs-archive-debuginfo-1.56.1-1.amzn2023.0.3.aarch64
gvfs-smb-1.56.1-1.amzn2023.0.3.aarch64
gvfs-debugsource-1.56.1-1.amzn2023.0.3.aarch64
src:
gvfs-1.56.1-1.amzn2023.0.3.src
x86_64:
gvfs-fuse-debuginfo-1.56.1-1.amzn2023.0.3.x86_64
gvfs-client-debuginfo-1.56.1-1.amzn2023.0.3.x86_64
gvfs-client-1.56.1-1.amzn2023.0.3.x86_64
gvfs-archive-1.56.1-1.amzn2023.0.3.x86_64
gvfs-goa-1.56.1-1.amzn2023.0.3.x86_64
gvfs-archive-debuginfo-1.56.1-1.amzn2023.0.3.x86_64
gvfs-smb-debuginfo-1.56.1-1.amzn2023.0.3.x86_64
gvfs-nfs-debuginfo-1.56.1-1.amzn2023.0.3.x86_64
gvfs-smb-1.56.1-1.amzn2023.0.3.x86_64
gvfs-fuse-1.56.1-1.amzn2023.0.3.x86_64
gvfs-debuginfo-1.56.1-1.amzn2023.0.3.x86_64
gvfs-goa-debuginfo-1.56.1-1.amzn2023.0.3.x86_64
gvfs-nfs-1.56.1-1.amzn2023.0.3.x86_64
gvfs-debugsource-1.56.1-1.amzn2023.0.3.x86_64
gvfs-1.56.1-1.amzn2023.0.3.x86_64