PT-2026-85016 · Red Hat · Red Hat Enterprise Linux 7+2
CVE-2026-71219
·
Published
2026-09-03
·
Updated
2026-09-03
CVSS v3.1
4.7
Medium
| Vector | AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H |
A stack overflow vulnerability was found in gfs2-utils. The hash table traversal code in metawalk.c uses alloca() with an exponentially-derived size from the untrusted on-disk di depth field without bounds validation. A crafted GFS2 filesystem image with a large di depth value causes stack exhaustion and a denial of service when processed by fsck.gfs2, gfs2 edit, or savemeta.
Fix
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Red Hat Enterprise Linux 7
Red Hat Enterprise Linux 8
Red Hat Enterprise Linux 9