VYPR

Gfs2 Utils

by Red Hat

CVEs (6)

  • CVE-2026-71221HigSep 3, 2026
    risk 0.46cvss 7.0epss 0.00

    A stack out-of-bounds write vulnerability was found in gfs2-utils. In savemeta, the height value from on-disk inode metadata is used as a loop bound without bounds checking, causing a stack buffer overflow that may lead to arbitrary code execution when processing crafted GFS2…

  • CVE-2026-71220HigSep 3, 2026
    risk 0.46cvss 7.0epss 0.00

    A stack out-of-bounds write vulnerability was found in gfs2-utils. In gfs2_edit, the di_height field from on-disk inode metadata is used as an array index without bounds checking, causing a stack buffer overflow that may lead to arbitrary code execution when processing crafted…

  • CVE-2026-71222MedSep 3, 2026
    risk 0.34cvss 5.3epss 0.00

    A heap out-of-bounds read vulnerability was found in gfs2-utils. The ea_num_ptrs field from on-disk extended attribute metadata is consumed without bounds validation, causing a heap buffer over-read that may disclose sensitive memory contents or cause a crash when processing…

  • CVE-2026-71224MedSep 3, 2026
    risk 0.31cvss 4.7epss 0.00

    A stack overflow vulnerability was found in gfs2-utils. The metadata walk code in metawalk.c uses alloca() with an untrusted inode height value from on-disk metadata without bounds validation, causing stack exhaustion and a denial of service when processing crafted GFS2…

  • CVE-2026-71219MedSep 3, 2026
    risk 0.31cvss 4.7epss 0.00

    A stack overflow vulnerability was found in gfs2-utils. The hash table traversal code in metawalk.c uses alloca() with an exponentially-derived size from the untrusted on-disk di_depth field without bounds validation. A crafted GFS2 filesystem image with a large di_depth value…

  • CVE-2008-6552Mar 30, 2009
    risk 0.00cvss —epss 0.00

    Red Hat Cluster Project 2.x allows local users to modify or overwrite arbitrary files via symlink attacks on files in /tmp, involving unspecified components in Resource Group Manager (aka rgmanager) before 2.03.09-1, gfs2-utils before 2.03.09-1, and CMAN - The Cluster Manager…