PT-2026-22158 · Gnome+2 · Gvfs+3

Published

2026-01-01

·

Updated

2026-03-31

·

CVE-2026-28296

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions FTP GVfs backend (affected versions not specified)
Description An input validation issue exists in the FTP GVfs backend. A remote attacker can exploit this by providing specially crafted file paths with carriage return and line feed (CRLF) sequences. These sequences, if not properly sanitized, can terminate FTP commands and allow the injection of arbitrary FTP commands. Successful exploitation could lead to arbitrary code execution or other significant consequences.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2026-28296
OPENSUSE-SU-2026:10275-1
OPENSUSE-SU-2026:20451-1
SUSE-SU-2026:0916-1
SUSE-SU-2026:0923-1
SUSE-SU-2026:0960-1
SUSE-SU-2026:20988-1
USN-8114-1

Affected Products

Ftp Gvfs Backend
Gvfs
Linuxmint
Ubuntu