Stack Out-of-Bounds Write Vulnerability in gfs2-utils from Red Hat
CVE-2026-71220
7HIGH
What is CVE-2026-71220?
A stack out-of-bounds write vulnerability has been identified in gfs2-utils, specifically within the gfs2_edit component. The issue arises when the di_height field from on-disk inode metadata is incorrectly utilized as an array index without adequate bounds checking. This oversight can lead to a stack buffer overflow that may enable the execution of arbitrary code when processing specifically crafted GFS2 filesystem images. It is crucial for users to review and apply necessary patches to mitigate potential risks associated with this vulnerability.
References
CVSS V3.1
Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Tristan Madani (Talence Security) for reporting this issue.