#1146712 gfs2-utils: CVE-2026-71219 CVE-2026-71220 CVE-2026-71221 CVE-2026-71222 CVE-2026-71223 CVE-2026-71224 #1146712
- Package:
- src:gfs2-utils
- Source:
- src:gfs2-utils
- Submitter:
- Salvatore Bonaccorso
- Date:
- 2026-10-06 19:35:07 UTC
- Severity:
- normal
- Tags:
Hi, The following vulnerabilities were published for gfs2-utils. Unfortunately the available information right now is limited to what we have in the references referring to Red Hat's bugzilla entries which do not contain upstream references. Could you plese invstigate the individual issues? CVE-2026-71219[0]: | A stack overflow vulnerability was found in gfs2-utils. The hash | table traversal code in metawalk.c uses alloca() with an | exponentially-derived size from the untrusted on-disk di_depth field | without bounds validation. A crafted GFS2 filesystem image with a | large di_depth value causes stack exhaustion and a denial of service | when processed by fsck.gfs2, gfs2_edit, or savemeta. CVE-2026-71220[1]: | A stack out-of-bounds write vulnerability was found in gfs2-utils. | In gfs2_edit, the di_height field from on-disk inode metadata is | used as an array index without bounds checking, causing a stack | buffer overflow that may lead to arbitrary code execution when | processing crafted GFS2 filesystem images. CVE-2026-71221[2]: | A stack out-of-bounds write vulnerability was found in gfs2-utils. | In savemeta, the height value from on-disk inode metadata is used as | a loop bound without bounds checking, causing a stack buffer | overflow that may lead to arbitrary code execution when processing | crafted GFS2 filesystem images. CVE-2026-71222[3]: | A heap out-of-bounds read vulnerability was found in gfs2-utils. The | ea_num_ptrs field from on-disk extended attribute metadata is | consumed without bounds validation, causing a heap buffer over-read | that may disclose sensitive memory contents or cause a crash when | processing crafted GFS2 filesystem images. CVE-2026-71223[4]: | gfs2-utils: integer overflow in resource group allocation size on 32- | bit platforms CVE-2026-71224[5]: | A stack overflow vulnerability was found in gfs2-utils. The metadata | walk code in metawalk.c uses alloca() with an untrusted inode height | value from on-disk metadata without bounds validation, causing stack | exhaustion and a denial of service when processing crafted GFS2 | filesystem images. If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-71219 https://www.cve.org/CVERecord?id=CVE-2026-71219 [1] https://security-tracker.debian.org/tracker/CVE-2026-71220 https://www.cve.org/CVERecord?id=CVE-2026-71220 [2] https://security-tracker.debian.org/tracker/CVE-2026-71221 https://www.cve.org/CVERecord?id=CVE-2026-71221 [3] https://security-tracker.debian.org/tracker/CVE-2026-71222 https://www.cve.org/CVERecord?id=CVE-2026-71222 [4] https://security-tracker.debian.org/tracker/CVE-2026-71223 https://www.cve.org/CVERecord?id=CVE-2026-71223 [5] https://security-tracker.debian.org/tracker/CVE-2026-71224 https://www.cve.org/CVERecord?id=CVE-2026-71224 Regards, Salvatore
We believe that the bug you reported is fixed in the latest version of
gfs2-utils, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1146712@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Valentin Vidic <vvidic@debian.org> (supplier of updated gfs2-utils package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Tue, 06 Oct 2026 21:02:34 +0200
Source: gfs2-utils
Architecture: source
Version: 3.6.1-2
Distribution: unstable
Urgency: medium
Maintainer: Debian HA Maintainers <debian-ha-maintainers@lists.alioth.debian.org>
Changed-By: Valentin Vidic <vvidic@debian.org>
Closes: 1146712
Changes:
gfs2-utils (3.6.1-2) unstable; urgency=medium
.
* debian/patches: add CVE fixes (Closes: #1146712)
- CVE-2026-71219: stack overflow vulnerability
- CVE-2026-71220: stack out-of-bounds write vulnerability
- CVE-2026-71221: stack out-of-bounds write vulnerability
- CVE-2026-71222: heap out-of-bounds read vulnerability
- CVE-2026-71223: integer overflow in resource group allocation
- CVE-2026-71224: stack overflow vulnerability
* debian/control: update Standards-Version to 4.7.4
Checksums-Sha1:
1ca78b555809c5db3988d7a6cd24365e05ef36e3 2161 gfs2-utils_3.6.1-2.dsc
7df47833bc36f72f237ca9741bf949995814539f 9172 gfs2-utils_3.6.1-2.debian.tar.xz
c00b557ca060f24ba03d248c0fb914ba64d5bf8f 6090 gfs2-utils_3.6.1-2_source.buildinfo
Checksums-Sha256:
2abe5296a27981c383bb638603182f5f12c3736481ff3017602f6827ab9dff69 2161 gfs2-utils_3.6.1-2.dsc
0917574ccf404f9a89ee12df7053d79af778a49ad27411c94fb03cdcd1003da1 9172 gfs2-utils_3.6.1-2.debian.tar.xz
aa614d09e5289d656c5f59e18bc271642d875ba1a63560c6101fc359c0100252 6090 gfs2-utils_3.6.1-2_source.buildinfo
Files:
cda59efe266b3929bb72c298e8395f57 2161 admin optional gfs2-utils_3.6.1-2.dsc
db15cee9ead75f71050360f0d378bbb1 9172 admin optional gfs2-utils_3.6.1-2.debian.tar.xz
99148352fac22a486bd23cf41d348de0 6090 admin optional gfs2-utils_3.6.1-2_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQJGBAEBCgAwFiEExaW53cM9k/u2PWfIMofYmpfNqHsFAmrFTG8SHHZ2aWRpY0Bk
ZWJpYW4ub3JnAAoJEDKH2JqXzah7KlMP/3iAY/ngmKmO9iM7plb/e7ow0mH/4/rA
IT/Vb/fhKRx3+dftRnZHKGtjjuoInCUr2H+2W4GLMahkxCwGTVZlofBPtRZdcRKW
IyTliehXB0JgZhPYwkNQELGvZ0H7+PViB5PCFGXiGL3bqI7y6qKZLCWUyDeKTxj6
rTfCCLO4M62NueXbLI8NPvN084NLRUeE9cW4RX3ZeFt3bes2jggtqYz6BXiEajZd
AQIx3c5hKWYhJi4brZ/SCQSdvZlUFh2W7+1iUlksyz5eGBYYFJC1GRnHwr3ajhxn
OQlu816E9xC1/flFNn4Ehcvz7hxs9JrQiP8Lr9BPovme/Cer5rOnPPCrLaDzTLbq
QI5N1yUnvMPeXorhn1wTjjLAf9g7ND3pZRJYtoXCwCYTsv+U+7kAlBEb8blEhoaJ
X5BUTO+wIUTc4pdjoN5x9b09elsW1v/mnCj+kHmHWejDygRN3csUYOwNZtSpsB3Q
ZxO5NPcOU5e2gJVXy4bmh2+6RcJzSzUOKrrOzUldZo8nirI8v9I3jHuNtbTW/zEB
u9wHc/MDbSWdFKx2BSKYJkEqHSEDuP5u0pBJffzz/CV67njgxlzzTiRJ2OgqM4gI
+n26ZbWQWqI1cXDSvAKjWKbrh1zXmxk4UfaV894zhKCIs8ImlNtpdF1EMY1tRPlY
u9pvgdI1TNr2
=FqOe
-----END PGP SIGNATURE-----