PT-2026-22158 · Gnome+2 · Gvfs+3

CVE-2026-28296

·

Published

2026-01-01

·

Updated

2026-06-12

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions FTP GVfs backend (affected versions not specified)
Description An input validation issue exists in the FTP GVfs backend. A remote attacker can exploit this by providing specially crafted file paths with carriage return and line feed (CRLF) sequences. These sequences, if not properly sanitized, can terminate FTP commands and allow the injection of arbitrary FTP commands. Successful exploitation could lead to arbitrary code execution or other significant consequences.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-28296
OESA-2026-2570
OESA-2026-2571
OESA-2026-2669
OESA-2026-2670
OPENSUSE-SU-2026:10275-1
OPENSUSE-SU-2026:20451-1
SUSE-SU-2026:0916-1
SUSE-SU-2026:0923-1
SUSE-SU-2026:0960-1
SUSE-SU-2026:20988-1
USN-8114-1

Affected Products

Ftp Gvfs Backend
Gvfs
Linuxmint
Ubuntu