CVE-2026-71221
nicheStack out-of-bounds write in gfs2-utils savemeta tool
gfs2-utils contains a stack out-of-bounds write (CWE-787): the 'savemeta' metadata-dumping utility takes the height value from on-disk GFS2 inode metadata and uses it as a loop bound without bounds checking, so a crafted or corrupted filesystem image can drive writes past a stack buffer. The flaw is triggered locally when a user or administrator runs savemeta against such an image, which matches the CVSS vector (AV:L, AC:H, UI:R) and its high-impact confidentiality, integrity, and availability ratings. A successful attack may allow arbitrary code execution with the privileges of the account running the tool. Affected parties are administrators and users who process GFS2 filesystem images with gfs2-utils, primarily in clustered-storage environments on enterprise Linux. No public proof-of-concept, no CISA KEV listing, and a low EPSS score (0.1%) indicate exploitation is not currently known to be occurring.
What to do: Treat GFS2 filesystem images from untrusted sources as untrusted input and avoid running gfs2-utils savemeta on them until a fix is available. Inventory systems where gfs2-utils is installed, monitor the Red Hat advisory (CNA: [email protected]) for patched package versions, and update gfs2-utils accordingly when released.
| Red Hat / upstream gfs2-utils project gfs2-utils (savemeta utility) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A stack out-of-bounds write vulnerability was found in gfs2-utils. In savemeta, the height value from on-disk inode metadata is used as a loop bound without bounds checking, causing a stack buffer overflow that may lead to arbitrary code execution when processing crafted GFS2 filesystem images.
- Weakness
- CWE-787
- Vector
- CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.