Junglewise Threat Intelligence

CVE-2026-71224: gfs2-utils stack overflow in metadata walk

CVE-2026-71224 · Severity: medium · CVSS 4.7 · Published 2026-09-03

Vendors: Linux.

Executive brief

gfs2-utils is a utility suite for managing GFS2 clustered filesystems. A stack overflow vulnerability in the metadata parsing code can cause the utility to crash when processing maliciously crafted filesystem images, resulting in denial of service. An attacker with local access and the ability to provide a crafted filesystem image could prevent legitimate filesystem maintenance operations.

Technical details

The vulnerability is a stack overflow caused by unbounded use of alloca() with an untrusted inode height value from on-disk GFS2 filesystem metadata. The metawalk.c code does not validate the inode height against maximum limits before allocating stack memory, leading to stack exhaustion. Attack vector is local; exploitation requires user interaction (an administrator must run gfs2-utils tools such as fsck.gfs2 on the crafted filesystem image). The vulnerability results in a process crash (SIGSEGV) rather than memory corruption, confined to denial of service. The kernel GFS2 driver is not affected because it validates i_height. Patches are expected.

Affected products

  • Linux gfs2-utils

Timeline

  • 2026-09-03: disclosed

References