Home / mailings [USN-8845-1] GVfs vulnerabilities
Posted on 01 October 2026
Ubuntu Security==========================================================================Ubuntu Security Notice USN-8845-1
September 30, 2026
gvfs vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 26.04 LTS
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
Summary:
Several security issues were fixed in GVfs.
Software Description:
- gvfs: Userspace virtual file system
Details:
Keith Linneman discovered that GVfs did not properly validate data
received from SFTP servers. An attacker could possibly use this issue to
cause a heap buffer overflow, resulting in arbitrary code execution or a
denial of service. (CVE-2026-84268)
It was discovered that GVfs incorrectly handled file ownership when
creating private D-Bus sockets in the admin backend. A local attacker
could possibly use this issue to change the ownership of arbitrary
system files, resulting in privilege escalation to root. This issue only
affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.
(CVE-2026-88924)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 26.04 LTS
gvfs-backends 1.60.0-1ubuntu0.1
gvfs-libs 1.60.0-1ubuntu0.1
Ubuntu 24.04 LTS
gvfs-backends 1.54.4-0ubuntu1~24.04.4
gvfs-libs 1.54.4-0ubuntu1~24.04.4
Ubuntu 22.04 LTS
gvfs-backends 1.48.2-0ubuntu1.2
gvfs-libs 1.48.2-0ubuntu1.2
Ubuntu 20.04 LTS
gvfs-backends 1.44.1-1ubuntu1.2+esm1
Available with Ubuntu Pro
gvfs-libs 1.44.1-1ubuntu1.2+esm1
Available with Ubuntu Pro
Ubuntu 18.04 LTS
gvfs-backends 1.36.1-0ubuntu1.3.3+esm1
Available with Ubuntu Pro
gvfs-libs 1.36.1-0ubuntu1.3.3+esm1
Available with Ubuntu Pro
Ubuntu 16.04 LTS
gvfs-backends 1.28.2-1ubuntu1~16.04.3+esm1
Available with Ubuntu Pro
gvfs-libs 1.28.2-1ubuntu1~16.04.3+esm1
Available with Ubuntu Pro
After a standard system update you need to restart your session to make
all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-8845-1
CVE-2026-84268, CVE-2026-88924
Package Information:
https://launchpad.net/ubuntu/+source/gvfs/1.60.0-1ubuntu0.1
https://launchpad.net/ubuntu/+source/gvfs/1.54.4-0ubuntu1~24.04.4
https://launchpad.net/ubuntu/+source/gvfs/1.48.2-0ubuntu1.2
--===============1061038055743252516==Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
