[Debian-ha-maintainers] Bug#1146712: gfs2-utils: CVE-2026-71219 CVE-2026-71220 CVE-2026-71221 CVE-2026-71222 CVE-2026-71223 CVE-2026-71224

Salvatore Bonaccorso carnil at debian.org
Fri Sep 4 18:33:02 BST 2026


Source: gfs2-utils
Version: 3.6.1-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: carnil at debian.org, Debian Security Team <team at security.debian.org>

Hi,

The following vulnerabilities were published for gfs2-utils.

Unfortunately the available information right now is limited to what
we have in the references referring to Red Hat's bugzilla entries
which do not contain upstream references. Could you plese invstigate
the individual issues?

CVE-2026-71219[0]:
| A stack overflow vulnerability was found in gfs2-utils. The hash
| table traversal code in metawalk.c uses alloca() with an
| exponentially-derived size from the untrusted on-disk di_depth field
| without bounds validation. A crafted GFS2 filesystem image with a
| large di_depth value causes stack exhaustion and a denial of service
| when processed by fsck.gfs2, gfs2_edit, or savemeta.


CVE-2026-71220[1]:
| A stack out-of-bounds write vulnerability was found in gfs2-utils.
| In gfs2_edit, the di_height field from on-disk inode metadata is
| used as an array index without bounds checking, causing a stack
| buffer overflow that may lead to arbitrary code execution when
| processing crafted GFS2 filesystem images.


CVE-2026-71221[2]:
| A stack out-of-bounds write vulnerability was found in gfs2-utils.
| In savemeta, the height value from on-disk inode metadata is used as
| a loop bound without bounds checking, causing a stack buffer
| overflow that may lead to arbitrary code execution when processing
| crafted GFS2 filesystem images.


CVE-2026-71222[3]:
| A heap out-of-bounds read vulnerability was found in gfs2-utils. The
| ea_num_ptrs field from on-disk extended attribute metadata is
| consumed without bounds validation, causing a heap buffer over-read
| that may disclose sensitive memory contents or cause a crash when
| processing crafted GFS2 filesystem images.


CVE-2026-71223[4]:
| gfs2-utils: integer overflow in resource group allocation size on 32-
| bit platforms


CVE-2026-71224[5]:
| A stack overflow vulnerability was found in gfs2-utils. The metadata
| walk code in metawalk.c uses alloca() with an untrusted inode height
| value from on-disk metadata without bounds validation, causing stack
| exhaustion and a denial of service when processing crafted GFS2
| filesystem images.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-71219
    https://www.cve.org/CVERecord?id=CVE-2026-71219
[1] https://security-tracker.debian.org/tracker/CVE-2026-71220
    https://www.cve.org/CVERecord?id=CVE-2026-71220
[2] https://security-tracker.debian.org/tracker/CVE-2026-71221
    https://www.cve.org/CVERecord?id=CVE-2026-71221
[3] https://security-tracker.debian.org/tracker/CVE-2026-71222
    https://www.cve.org/CVERecord?id=CVE-2026-71222
[4] https://security-tracker.debian.org/tracker/CVE-2026-71223
    https://www.cve.org/CVERecord?id=CVE-2026-71223
[5] https://security-tracker.debian.org/tracker/CVE-2026-71224
    https://www.cve.org/CVERecord?id=CVE-2026-71224

Regards,
Salvatore



More information about the Debian-ha-maintainers mailing list