Alerts This Week
Warning Icon 1 1,149
Alerts This Week
Warning Icon 1 1,149

Debian 11 gvfs Critical FTP Command Injection and Network Probing Advisory

debian lts
Calendar Grey March 28, 2026
Dist Debian Esm H88
Multiple vulnerabilities found in gvfs could allow remote attackers to execute FTP command injections and probe networks.
Codean Labs found that gvfs, a virtual filesystem implementation, was affected by multiple vulnerabililies including FTP bounce attack which could lead to probing open ports on cli...

Summary

CVE-2026-28295

A malicious FTP server can exploit this vulnerability by providing an
arbitrary IP address and port in its passive mode (PASV) response. The
client unconditionally trusts this information and attempts to connect to
the specified endpoint, allowing the malicious server to probe for open
ports accessible from the client's network.

CVE-2026-28296

A remote attacker could exploit this input validation vulnerability by
supplying specially crafted file paths containing carriage return and line
feed (CRLF) sequences. These unsanitized sequences allow the attacker to
terminate intended FTP commands and inject arbitrary FTP commands,
potentially leading to arbitrary code execution or other severe impacts.

For Debian 11 bullseye, these problems have been fixed in version
1.46.2-2+deb11u1.

We recommend that you upgrade your gvfs packages.

For the detailed security status of gvfs please refer to
its security tracker page at:

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

Package: gvfs
Version: 1.46.2-2+deb11u1
CVE ID: CVE-2026-28295 CVE-2026-28296
Debian Bug: 1129285 1129286

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here