Stack Out-of-Bounds Write Vulnerability in gfs2-utils from Red Hat
CVE-2026-71220

7HIGH

What is CVE-2026-71220?

A stack out-of-bounds write vulnerability has been identified in gfs2-utils, specifically within the gfs2_edit component. The issue arises when the di_height field from on-disk inode metadata is incorrectly utilized as an array index without adequate bounds checking. This oversight can lead to a stack buffer overflow that may enable the execution of arbitrary code when processing specifically crafted GFS2 filesystem images. It is crucial for users to review and apply necessary patches to mitigate potential risks associated with this vulnerability.

References

CVSS V3.1

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Tristan Madani (Talence Security) for reporting this issue.
.