An issue was discovered in GNOME gvfs 1.29.4 through 1.41.2. daemon/gvfsbackendadmin.c mishandles a file's user and group ownership during move (and copy with GFILECOPYALLMETADATA) operations from admin:// to file:// URIs, because root privileges are unavailable.
{
"unresolved_ranges": [
{
"extracted_events": [
{
"last_affected": "16.04"
},
{
"last_affected": "18.04"
},
{
"last_affected": "18.10"
},
{
"last_affected": "19.04"
}
],
"source": "CPE_FIELD",
"vendor_product": "canonical:ubuntu_linux",
"cpes": [
"cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*",
"cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*",
"cpe:2.3:o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:*",
"cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:*"
]
},
{
"extracted_events": [
{
"last_affected": "29"
},
{
"last_affected": "30"
}
],
"source": "CPE_FIELD",
"vendor_product": "fedoraproject:fedora",
"cpes": [
"cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*",
"cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*"
]
},
{
"extracted_events": [
{
"last_affected": "15.0"
},
{
"last_affected": "15.1"
}
],
"source": "CPE_FIELD",
"vendor_product": "opensuse:leap",
"cpes": [
"cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:*",
"cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*"
]
}
]
}"2026-05-18T13:12:16Z"
[
{
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 1225.0,
"function_hash": "231020120805253815594800467972206124585"
},
"source": "https://gitlab.gnome.org/gnome/gvfs@409619412e11be146a31b9a99ed965925f1aabb8",
"signature_version": "v1",
"target": {
"function": "g_vfs_backend_admin_class_init",
"file": "daemon/gvfsbackendadmin.c"
},
"id": "CVE-2019-12449-17e19b87"
},
{
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"188400266217883493317486595327510648447",
"84370787118236718112280869999792270972",
"235841846821089703407745877082633987750",
"22225832117781730001295094493184023477",
"10481938479286945038407544721119377788",
"223840719794277329878536154385692187910",
"85960072603906379813090528892411735538"
]
},
"source": "https://gitlab.gnome.org/gnome/gvfs@409619412e11be146a31b9a99ed965925f1aabb8",
"signature_version": "v1",
"target": {
"file": "daemon/gvfsbackendadmin.c"
},
"id": "CVE-2019-12449-f73544ba"
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-12449.json"