[Debian-ha-maintainers] Bug#1146712: gfs2-utils: CVE-2026-71219 CVE-2026-71220 CVE-2026-71221 CVE-2026-71222 CVE-2026-71223 CVE-2026-71224
Salvatore Bonaccorso
carnil at debian.org
Fri Sep 4 18:33:02 BST 2026
Source: gfs2-utils
Version: 3.6.1-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: carnil at debian.org, Debian Security Team <team at security.debian.org>
Hi,
The following vulnerabilities were published for gfs2-utils.
Unfortunately the available information right now is limited to what
we have in the references referring to Red Hat's bugzilla entries
which do not contain upstream references. Could you plese invstigate
the individual issues?
CVE-2026-71219[0]:
| A stack overflow vulnerability was found in gfs2-utils. The hash
| table traversal code in metawalk.c uses alloca() with an
| exponentially-derived size from the untrusted on-disk di_depth field
| without bounds validation. A crafted GFS2 filesystem image with a
| large di_depth value causes stack exhaustion and a denial of service
| when processed by fsck.gfs2, gfs2_edit, or savemeta.
CVE-2026-71220[1]:
| A stack out-of-bounds write vulnerability was found in gfs2-utils.
| In gfs2_edit, the di_height field from on-disk inode metadata is
| used as an array index without bounds checking, causing a stack
| buffer overflow that may lead to arbitrary code execution when
| processing crafted GFS2 filesystem images.
CVE-2026-71221[2]:
| A stack out-of-bounds write vulnerability was found in gfs2-utils.
| In savemeta, the height value from on-disk inode metadata is used as
| a loop bound without bounds checking, causing a stack buffer
| overflow that may lead to arbitrary code execution when processing
| crafted GFS2 filesystem images.
CVE-2026-71222[3]:
| A heap out-of-bounds read vulnerability was found in gfs2-utils. The
| ea_num_ptrs field from on-disk extended attribute metadata is
| consumed without bounds validation, causing a heap buffer over-read
| that may disclose sensitive memory contents or cause a crash when
| processing crafted GFS2 filesystem images.
CVE-2026-71223[4]:
| gfs2-utils: integer overflow in resource group allocation size on 32-
| bit platforms
CVE-2026-71224[5]:
| A stack overflow vulnerability was found in gfs2-utils. The metadata
| walk code in metawalk.c uses alloca() with an untrusted inode height
| value from on-disk metadata without bounds validation, causing stack
| exhaustion and a denial of service when processing crafted GFS2
| filesystem images.
If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-71219
https://www.cve.org/CVERecord?id=CVE-2026-71219
[1] https://security-tracker.debian.org/tracker/CVE-2026-71220
https://www.cve.org/CVERecord?id=CVE-2026-71220
[2] https://security-tracker.debian.org/tracker/CVE-2026-71221
https://www.cve.org/CVERecord?id=CVE-2026-71221
[3] https://security-tracker.debian.org/tracker/CVE-2026-71222
https://www.cve.org/CVERecord?id=CVE-2026-71222
[4] https://security-tracker.debian.org/tracker/CVE-2026-71223
https://www.cve.org/CVERecord?id=CVE-2026-71223
[5] https://security-tracker.debian.org/tracker/CVE-2026-71224
https://www.cve.org/CVERecord?id=CVE-2026-71224
Regards,
Salvatore
More information about the Debian-ha-maintainers
mailing list