Advisories ยป MGASA-2026-0107

Updated gvfs packages fix security vulnerabilities

Publication date: 22 Apr 2026
Modification date: 22 Apr 2026
Type: security
Affected Mageia releases : 9
CVE: CVE-2026-28295 , CVE-2026-28296

Description

Gvfs: gvfs ftp backend: information disclosure via untrusted pasv
responses. (CVE-2026-28295)
Gvfs: ftp gvfs backend: arbitrary ftp command injection via crlf
sequences in file paths. (CVE-2026-28296)
                

References

SRPMS

9/core