A September 30, 2026 bulletin reports GVfs issues that could allow code execution, denial of service, or local privilege escalation.
Bulletin USN-8845-1, published on September 30, 2026, describes two GVfs vulnerabilities. Incorrect validation of data received from SFTP servers could cause a heap buffer overflow, potentially resulting in arbitrary code execution or denial of service (CVE-2026-84268). The notice is an automated translation of content from the Ubuntu Security feed.
The second issue concerns file ownership when creating private D-Bus sockets in the admin backend. A local attacker could change ownership of arbitrary system files and escalate privileges to root (CVE-2026-88924). This issue affects Ubuntu 22.04 LTS, 24.04 LTS, and 26.04 LTS. Consult the official Ubuntu Security notice by its identifier, USN-8845-1, and confirm affected versions and update guidance in the original publication; do not assume the translation contains every detail.