Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package gvfs for openSUSE:Factory checked in at 2026-09-15 17:09:27 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/gvfs (Old) and /work/SRC/openSUSE:Factory/.gvfs.new.383539 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "gvfs" Tue Sep 15 17:09:27 2026 rev:212 rq:1377828 version:1.60.3 Changes: -------- --- /work/SRC/openSUSE:Factory/gvfs/gvfs.changes 2026-08-09 21:32:07.363600807 +0200 +++ /work/SRC/openSUSE:Factory/.gvfs.new.383539/gvfs.changes 2026-09-15 17:10:10.034724762 +0200 @@ -1,0 +2,18 @@ +Fri Sep 11 10:06:48 UTC 2026 - Dominique Leuenberger <[email protected]> + +- Update to version 1.60.3: + + CVE-2026-88924: admin: Set socket ownership before creation + + trash: Fix metadata handling when restoring or emptying + + dav: Fix response body leaks to prevent hangs + + Some other fixes + + Updated translations. + +------------------------------------------------------------------- +Fri Sep 11 02:04:06 UTC 2026 - Jonathan Kang <[email protected]> + +- Add gvfs-CVE-2026-84268.patch: sftp: Clamp `read_reply` count to + requested buffer size (bsc#1278158, CVE-2026-84268). +- Add gvfs-CVE-2026-84270.patch: mtp: Validate read size returned + by device (bsc#1278156, CVE-2026-84270). + +------------------------------------------------------------------- @@ -11,0 +30,10 @@ +- Drop gvfs-CVE-2026-84267.patch: fixed upstream. +- Drop gvfs-CVE-2026-84269.patch: fixed upstream. + +------------------------------------------------------------------- +Wed Jul 29 02:07:11 UTC 2026 - Jonathan Kang <[email protected]> + +- Add gvfs-CVE-2026-84267.patch: sftp: Validate that reads fully + complete before using data (bsc#1278157, CVE-2026-84267). +- Add gvfs-CVE-2026-84269.patch: afp: Validate reply size in DSI + read reply handling (bsc#1278159, CVE-2026-84269). Old: ---- gvfs-1.60.2.tar.xz New: ---- gvfs-1.60.3.tar.xz gvfs-CVE-2026-84268.patch gvfs-CVE-2026-84270.patch ----------(New B)---------- New: - Add gvfs-CVE-2026-84268.patch: sftp: Clamp `read_reply` count to requested buffer size (bsc#1278158, CVE-2026-84268). New: requested buffer size (bsc#1278158, CVE-2026-84268). - Add gvfs-CVE-2026-84270.patch: mtp: Validate read size returned by device (bsc#1278156, CVE-2026-84270). ----------(New E)---------- ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ gvfs.spec ++++++ --- /var/tmp/diff_new_pack.CHeL7R/_old 2026-09-15 17:10:11.697794363 +0200 +++ /var/tmp/diff_new_pack.CHeL7R/_new 2026-09-15 17:10:11.700794489 +0200 @@ -20,7 +20,7 @@ %bcond_without onedrive Name: gvfs -Version: 1.60.2 +Version: 1.60.3 Release: 0 Summary: Virtual File System functionality for GLib License: GPL-3.0-only AND LGPL-2.0-or-later @@ -30,6 +30,11 @@ Source1: README.SUSE Source99: baselibs.conf +# PATCH-FIX-UPSTREAM gvfs-CVE-2026-84268.patch bsc#1278158, CVE-2026-84268 [email protected] -- sftp: Clamp `read_reply` count to requested buffer size +Patch0: gvfs-CVE-2026-84268.patch +# PATCH-FIX-UPSTREAM gvfs-CVE-2026-84270.patch bsc#1278156, CVE-2026-84270 [email protected] -- mtp: Validate read size returned by device +Patch1: gvfs-CVE-2026-84270.patch + ### NOTE: Please, keep SLE-only patches at bottom (starting on 1000). # PATCH-FEATURE-SLE gvfs-nds.patch [email protected] -- Provides NDS browsing for nautilus Patch1000: gvfs-nds.patch ++++++ _scmsync.obsinfo ++++++ --- /var/tmp/diff_new_pack.CHeL7R/_old 2026-09-15 17:10:11.761797042 +0200 +++ /var/tmp/diff_new_pack.CHeL7R/_new 2026-09-15 17:10:11.770797418 +0200 @@ -1,6 +1,7 @@ -mtime: 1785505407 -commit: 52f4780bd80a5e050f1c522dbbb725ca4647ea765ab06abd26ed92c0bb3215b6 +mtime: 1789121351 +commit: 853f83d249abac5817e9b1f0d6c085f668cac596b3cfd8808d4f290f5b55cd76 url: https://src.opensuse.org/GNOME/gvfs -revision: 52f4780bd80a5e050f1c522dbbb725ca4647ea765ab06abd26ed92c0bb3215b6 +revision: 853f83d249abac5817e9b1f0d6c085f668cac596b3cfd8808d4f290f5b55cd76 +trackingbranch: factory projectscmsync: https://src.opensuse.org/GNOME/_ObsPrj ++++++ _service ++++++ --- /var/tmp/diff_new_pack.CHeL7R/_old 2026-09-15 17:10:11.806798925 +0200 +++ /var/tmp/diff_new_pack.CHeL7R/_new 2026-09-15 17:10:11.811799134 +0200 @@ -3,7 +3,7 @@ <service name="obs_scm" mode="manual"> <param name="scm">git</param> <param name="url">https://gitlab.gnome.org/GNOME/gvfs.git</param> - <param name="revision">1.60.2</param> + <param name="revision">1.60.3</param> <param name="versionformat">@PARENT_TAG@+@TAG_OFFSET@</param> <param name="versionrewrite-pattern">(.*)\+0</param> <param name="versionrewrite-replacement">\1</param> ++++++ build.specials.obscpio ++++++ ++++++ build.specials.obscpio ++++++ diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/.gitignore new/.gitignore --- old/.gitignore 1970-01-01 01:00:00.000000000 +0100 +++ new/.gitignore 2026-09-11 12:09:11.000000000 +0200 @@ -0,0 +1,5 @@ +*.obscpio +*.osc +_build.* +.pbuild +osc-collab.* ++++++ gvfs-1.60.2.tar.xz -> gvfs-1.60.3.tar.xz ++++++ ++++ 2070 lines of diff (skipped) ++++++ gvfs-CVE-2026-84268.patch ++++++ >From a9a4059ea086a3e5dc675b82d922ba5afb46b96d Mon Sep 17 00:00:00 2001 From: Jonathan Kang <[email protected]> Date: Fri, 11 Sep 2026 09:43:03 +0800 Subject: [PATCH] sftp: Clamp `read_reply` count to requested buffer size Currently, the `count` value from the server response is used as the read length without checking it against `bytes_requested`. A buggy server returning a larger count would overflow the job buffer. Let's clamp `count` to `bytes_requested`. Fixes: #862 --- daemon/gvfsbackendsftp.c | 1 + 1 file changed, 1 insertion(+) diff --git a/daemon/gvfsbackendsftp.c b/daemon/gvfsbackendsftp.c index 2c9a45e0..44c01b2f 100644 --- a/daemon/gvfsbackendsftp.c +++ b/daemon/gvfsbackendsftp.c @@ -2892,6 +2892,7 @@ read_reply (GVfsBackendSftp *backend, } count = g_data_input_stream_read_uint32 (reply, NULL, NULL); + count = MIN (count, G_VFS_JOB_READ (job)->bytes_requested); if (count > G_VFS_JOB_READ (job)->bytes_requested) { g_vfs_job_failed (job, G_IO_ERROR, G_IO_ERROR_FAILED, -- 2.55.0 ++++++ gvfs-CVE-2026-84270.patch ++++++ >From 070e5e4223c97f7e793a342ba6e64df1095ccb0d Mon Sep 17 00:00:00 2001 From: Ondrej Holy <[email protected]> Date: Mon, 27 Jul 2026 15:38:21 +0200 Subject: [PATCH] mtp: Validate read size returned by device Currently, `do_read` copies `actual` bytes from the device response into `buffer` without checking that `actual` does not exceed `bytes_requested`. If the device returns more data than requested, this causes a heap buffer overflow. Let's validate the size and return an "Invalid reply received" error instead. Fixes: https://gitlab.gnome.org/GNOME/gvfs/-/issues/864 Co-Authored-By: Claude Opus 4.6 <[email protected]> --- daemon/gvfsbackendmtp.c | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/daemon/gvfsbackendmtp.c b/daemon/gvfsbackendmtp.c index 9a8ac502..f2a26adf 100644 --- a/daemon/gvfsbackendmtp.c +++ b/daemon/gvfsbackendmtp.c @@ -2575,6 +2575,14 @@ do_read (GVfsBackend *backend, goto exit; } + if (actual > bytes_requested) { + free (temp); + g_vfs_job_failed_literal (G_VFS_JOB (job), + G_IO_ERROR, G_IO_ERROR_FAILED, + _("Invalid reply received")); + goto exit; + } + memcpy (buffer, temp, actual); free (temp); } else { -- GitLab ++++++ gvfs.obsinfo ++++++ --- /var/tmp/diff_new_pack.CHeL7R/_old 2026-09-15 17:10:12.526829059 +0200 +++ /var/tmp/diff_new_pack.CHeL7R/_new 2026-09-15 17:10:12.541829687 +0200 @@ -1,5 +1,5 @@ name: gvfs -version: 1.60.2 -mtime: 1785483414 -commit: 5651571370400cf0a114f61af2fa96e0ff4784d5 +version: 1.60.3 +mtime: 1789114032 +commit: bbf41f8a234bef8e51c012d68e78ce43fd8a6751
