CVE-2026-84270: Gvfs: mtp: out-of-bounds read in do_read()

Published Sep 1, 2026
·
Updated

A flaw was found in the MTP backend in gvfs. When reading a file from a mounted MTP device, doread() in gvfsbackendmtp.c trusts the data length returned by the device without limiting it to the original size requested by the client. If a malicious MTP device responds with more bytes than requested, this unrestricted length is passed directly to memcpy(). This causes the operation to read memory outside the intended boundaries. This allows an attacker who plugs in a malicious MTP device to cause a segmentation fault when a file is read and crash the gvfsd-mtp process, resulting in a denial of service.

Affected Software

1 affected component
Gnome gvfs

Event History

Sep 1, 2026
CVE Published
via MITRE·03:19 PM
Data Sourced
via MITRE·03:19 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Systems that use the gvfs MTP backend and read files from a mounted MTP device are exposed. Exploitation requires a malicious physical MTP device to be plugged in and a file on that device to be read.

2

Does exploitation require authentication or user interaction?

No authentication is required. A user must interact with the malicious device by mounting it and reading a file from it.

3

What is the expected impact of a successful exploit?

A malicious device can cause gvfsd-mtp to crash through an out-of-bounds read, resulting in denial of service for the MTP backend process. The provided information does not describe confidentiality or integrity impact.

4

What can be done if patching is not immediately possible?

Avoid mounting or reading files from untrusted MTP devices. Restrict physical access to systems where feasible and use only trusted devices until an update is available.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203