Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package gvfs for openSUSE:Factory checked in 
at 2026-09-15 17:09:27
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/gvfs (Old)
 and      /work/SRC/openSUSE:Factory/.gvfs.new.383539 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "gvfs"

Tue Sep 15 17:09:27 2026 rev:212 rq:1377828 version:1.60.3

Changes:
--------
--- /work/SRC/openSUSE:Factory/gvfs/gvfs.changes        2026-08-09 
21:32:07.363600807 +0200
+++ /work/SRC/openSUSE:Factory/.gvfs.new.383539/gvfs.changes    2026-09-15 
17:10:10.034724762 +0200
@@ -1,0 +2,18 @@
+Fri Sep 11 10:06:48 UTC 2026 - Dominique Leuenberger <[email protected]>
+
+- Update to version 1.60.3:
+  + CVE-2026-88924: admin: Set socket ownership before creation
+  + trash: Fix metadata handling when restoring or emptying
+  + dav: Fix response body leaks to prevent hangs
+  + Some other fixes
+  + Updated translations.
+
+-------------------------------------------------------------------
+Fri Sep 11 02:04:06 UTC 2026 - Jonathan Kang <[email protected]>
+
+- Add gvfs-CVE-2026-84268.patch: sftp: Clamp `read_reply` count to
+  requested buffer size (bsc#1278158, CVE-2026-84268).
+- Add gvfs-CVE-2026-84270.patch: mtp: Validate read size returned
+  by device (bsc#1278156, CVE-2026-84270).
+
+-------------------------------------------------------------------
@@ -11,0 +30,10 @@
+- Drop gvfs-CVE-2026-84267.patch: fixed upstream.
+- Drop gvfs-CVE-2026-84269.patch: fixed upstream.
+
+-------------------------------------------------------------------
+Wed Jul 29 02:07:11 UTC 2026 - Jonathan Kang <[email protected]>
+
+- Add gvfs-CVE-2026-84267.patch: sftp: Validate that reads fully
+  complete before using data (bsc#1278157, CVE-2026-84267).
+- Add gvfs-CVE-2026-84269.patch: afp: Validate reply size in DSI
+  read reply handling (bsc#1278159, CVE-2026-84269).

Old:
----
  gvfs-1.60.2.tar.xz

New:
----
  gvfs-1.60.3.tar.xz
  gvfs-CVE-2026-84268.patch
  gvfs-CVE-2026-84270.patch

----------(New B)----------
  New:
- Add gvfs-CVE-2026-84268.patch: sftp: Clamp `read_reply` count to
  requested buffer size (bsc#1278158, CVE-2026-84268).
  New:  requested buffer size (bsc#1278158, CVE-2026-84268).
- Add gvfs-CVE-2026-84270.patch: mtp: Validate read size returned
  by device (bsc#1278156, CVE-2026-84270).
----------(New E)----------

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ gvfs.spec ++++++
--- /var/tmp/diff_new_pack.CHeL7R/_old  2026-09-15 17:10:11.697794363 +0200
+++ /var/tmp/diff_new_pack.CHeL7R/_new  2026-09-15 17:10:11.700794489 +0200
@@ -20,7 +20,7 @@
 %bcond_without  onedrive
 
 Name:           gvfs
-Version:        1.60.2
+Version:        1.60.3
 Release:        0
 Summary:        Virtual File System functionality for GLib
 License:        GPL-3.0-only AND LGPL-2.0-or-later
@@ -30,6 +30,11 @@
 Source1:        README.SUSE
 Source99:       baselibs.conf
 
+# PATCH-FIX-UPSTREAM gvfs-CVE-2026-84268.patch bsc#1278158, CVE-2026-84268 
[email protected] --  sftp: Clamp `read_reply` count to requested buffer size
+Patch0:         gvfs-CVE-2026-84268.patch
+# PATCH-FIX-UPSTREAM gvfs-CVE-2026-84270.patch bsc#1278156, CVE-2026-84270 
[email protected] --  mtp: Validate read size returned by device
+Patch1:         gvfs-CVE-2026-84270.patch
+
 ### NOTE: Please, keep SLE-only patches at bottom (starting on 1000).
 # PATCH-FEATURE-SLE gvfs-nds.patch [email protected] -- Provides NDS browsing 
for nautilus
 Patch1000:      gvfs-nds.patch

++++++ _scmsync.obsinfo ++++++
--- /var/tmp/diff_new_pack.CHeL7R/_old  2026-09-15 17:10:11.761797042 +0200
+++ /var/tmp/diff_new_pack.CHeL7R/_new  2026-09-15 17:10:11.770797418 +0200
@@ -1,6 +1,7 @@
-mtime: 1785505407
-commit: 52f4780bd80a5e050f1c522dbbb725ca4647ea765ab06abd26ed92c0bb3215b6
+mtime: 1789121351
+commit: 853f83d249abac5817e9b1f0d6c085f668cac596b3cfd8808d4f290f5b55cd76
 url: https://src.opensuse.org/GNOME/gvfs
-revision: 52f4780bd80a5e050f1c522dbbb725ca4647ea765ab06abd26ed92c0bb3215b6
+revision: 853f83d249abac5817e9b1f0d6c085f668cac596b3cfd8808d4f290f5b55cd76
+trackingbranch: factory
 projectscmsync: https://src.opensuse.org/GNOME/_ObsPrj
 

++++++ _service ++++++
--- /var/tmp/diff_new_pack.CHeL7R/_old  2026-09-15 17:10:11.806798925 +0200
+++ /var/tmp/diff_new_pack.CHeL7R/_new  2026-09-15 17:10:11.811799134 +0200
@@ -3,7 +3,7 @@
   <service name="obs_scm" mode="manual">
     <param name="scm">git</param>
     <param name="url">https://gitlab.gnome.org/GNOME/gvfs.git</param>
-    <param name="revision">1.60.2</param>
+    <param name="revision">1.60.3</param>
     <param name="versionformat">@PARENT_TAG@+@TAG_OFFSET@</param>
     <param name="versionrewrite-pattern">(.*)\+0</param>
     <param name="versionrewrite-replacement">\1</param>

++++++ build.specials.obscpio ++++++

++++++ build.specials.obscpio ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/.gitignore new/.gitignore
--- old/.gitignore      1970-01-01 01:00:00.000000000 +0100
+++ new/.gitignore      2026-09-11 12:09:11.000000000 +0200
@@ -0,0 +1,5 @@
+*.obscpio
+*.osc
+_build.*
+.pbuild
+osc-collab.*

++++++ gvfs-1.60.2.tar.xz -> gvfs-1.60.3.tar.xz ++++++
++++ 2070 lines of diff (skipped)

++++++ gvfs-CVE-2026-84268.patch ++++++
>From a9a4059ea086a3e5dc675b82d922ba5afb46b96d Mon Sep 17 00:00:00 2001
From: Jonathan Kang <[email protected]>
Date: Fri, 11 Sep 2026 09:43:03 +0800
Subject: [PATCH] sftp: Clamp `read_reply` count to requested buffer size

Currently, the `count` value from the server response is used
as the read length without checking it against
`bytes_requested`. A buggy server returning a larger count
would overflow the job buffer. Let's clamp `count` to
`bytes_requested`.

Fixes: #862
---
 daemon/gvfsbackendsftp.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/daemon/gvfsbackendsftp.c b/daemon/gvfsbackendsftp.c
index 2c9a45e0..44c01b2f 100644
--- a/daemon/gvfsbackendsftp.c
+++ b/daemon/gvfsbackendsftp.c
@@ -2892,6 +2892,7 @@ read_reply (GVfsBackendSftp *backend,
     }
   
   count = g_data_input_stream_read_uint32 (reply, NULL, NULL);
+  count = MIN (count, G_VFS_JOB_READ (job)->bytes_requested);
   if (count > G_VFS_JOB_READ (job)->bytes_requested)
     {
       g_vfs_job_failed (job, G_IO_ERROR, G_IO_ERROR_FAILED,
-- 
2.55.0


++++++ gvfs-CVE-2026-84270.patch ++++++
>From 070e5e4223c97f7e793a342ba6e64df1095ccb0d Mon Sep 17 00:00:00 2001
From: Ondrej Holy <[email protected]>
Date: Mon, 27 Jul 2026 15:38:21 +0200
Subject: [PATCH] mtp: Validate read size returned by device

Currently, `do_read` copies `actual` bytes from the device response
into `buffer` without checking that `actual` does not exceed
`bytes_requested`. If the device returns more data than requested,
this causes a heap buffer overflow. Let's validate the size and
return an "Invalid reply received" error instead.

Fixes: https://gitlab.gnome.org/GNOME/gvfs/-/issues/864

Co-Authored-By: Claude Opus 4.6 <[email protected]>
---
 daemon/gvfsbackendmtp.c | 8 ++++++++
 1 file changed, 8 insertions(+)

diff --git a/daemon/gvfsbackendmtp.c b/daemon/gvfsbackendmtp.c
index 9a8ac502..f2a26adf 100644
--- a/daemon/gvfsbackendmtp.c
+++ b/daemon/gvfsbackendmtp.c
@@ -2575,6 +2575,14 @@ do_read (GVfsBackend *backend,
       goto exit;
     }
 
+    if (actual > bytes_requested) {
+      free (temp);
+      g_vfs_job_failed_literal (G_VFS_JOB (job),
+                                G_IO_ERROR, G_IO_ERROR_FAILED,
+                                _("Invalid reply received"));
+      goto exit;
+    }
+
     memcpy (buffer, temp, actual);
     free (temp);
   } else {
-- 
GitLab


++++++ gvfs.obsinfo ++++++
--- /var/tmp/diff_new_pack.CHeL7R/_old  2026-09-15 17:10:12.526829059 +0200
+++ /var/tmp/diff_new_pack.CHeL7R/_new  2026-09-15 17:10:12.541829687 +0200
@@ -1,5 +1,5 @@
 name: gvfs
-version: 1.60.2
-mtime: 1785483414
-commit: 5651571370400cf0a114f61af2fa96e0ff4784d5
+version: 1.60.3
+mtime: 1789114032
+commit: bbf41f8a234bef8e51c012d68e78ce43fd8a6751
 

Reply via email to