Executive brief
gfs2-utils is a collection of utilities for managing GFS2 (Global File System 2) filesystems. A stack overflow vulnerability allows an attacker who can provide a crafted GFS2 filesystem image to cause a denial of service (process crash) when an administrator uses fsck.gfs2, gfs2_edit, or savemeta to access or repair the filesystem. The vulnerability requires local access and user interaction, and does not allow data corruption or system compromise.
Technical details
The vulnerability is a stack overflow caused by unbounded use of alloca() in the hash table traversal code in metawalk.c. The function allocates stack memory based on an exponentially-derived size from the untrusted on-disk di_depth field (2^di_depth) without validation, allowing a crafted filesystem image with an artificially large di_depth value to exhaust the stack. Exploitation requires local access and user interaction: an administrator must run one of the affected gfs2-utils tools on a malicious GFS2 filesystem image. The attack vector is local with high complexity and required user interaction. The impact is limited to denial of service (SIGSEGV crash) of the gfs2-utils process; RHEL stack guard pages prevent overflow from reaching heap or other memory regions. The underlying kernel GFS2 driver is not affected as it validates di_depth during mount.
Affected products
- gfs2-utils gfs2-utils <UNKNOWN>
Timeline
- 2026-09-03: disclosed