Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
Do not process untrusted GFS2 filesystem images with gfs2-utils tools. Run gfs2-utils tools in a containerized or VM-isolated environment when processing untrusted images.
Thu, 03 Sep 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat gfs2-utils
|
|
| Vendors & Products |
Redhat gfs2-utils
|
Thu, 03 Sep 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A heap out-of-bounds read vulnerability was found in gfs2-utils. The ea_num_ptrs field from on-disk extended attribute metadata is consumed without bounds validation, causing a heap buffer over-read that may disclose sensitive memory contents or cause a crash when processing crafted GFS2 filesystem images. | |
| Title | Gfs2-utils: gfs2-utils: heap out-of-bounds read via unchecked ea_num_ptrs in extended attribute processing | |
| First Time appeared |
Redhat
Redhat enterprise Linux |
|
| Weaknesses | CWE-125 | |
| CPEs | cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-09-03T12:23:22.616Z
Reserved: 2026-08-05T08:51:19.853Z
Link: CVE-2026-71222
No data.
Status : Received
Published: 2026-09-03T13:06:03.050
Modified: 2026-09-03T13:06:03.050
Link: CVE-2026-71222
No data.
OpenCVE Enrichment
Updated: 2026-09-03T15:33:03Z