CVE-2026-71224
- EPSS 0.12%
- Veröffentlicht 03.09.2026 12:23:31
- Zuletzt bearbeitet 22.09.2026 16:40:21
A stack overflow vulnerability was found in gfs2-utils. The metadata walk code in metawalk.c uses alloca() with an untrusted inode height value from on-disk metadata without bounds validation, causing stack exhaustion and a denial of service when pro...
- EPSS 0.14%
- Veröffentlicht 03.09.2026 12:23:17
- Zuletzt bearbeitet 22.09.2026 16:36:42
A stack out-of-bounds write vulnerability was found in gfs2-utils. In savemeta, the height value from on-disk inode metadata is used as a loop bound without bounds checking, causing a stack buffer overflow that may lead to arbitrary code execution wh...
- EPSS 0.14%
- Veröffentlicht 03.09.2026 12:23:12
- Zuletzt bearbeitet 22.09.2026 16:31:31
A stack out-of-bounds write vulnerability was found in gfs2-utils. In gfs2_edit, the di_height field from on-disk inode metadata is used as an array index without bounds checking, causing a stack buffer overflow that may lead to arbitrary code execut...
CVE-2008-6552
- EPSS 0.39%
- Veröffentlicht 30.03.2009 16:30:00
- Zuletzt bearbeitet 16.06.2026 23:02:26
Red Hat Cluster Project 2.x allows local users to modify or overwrite arbitrary files via symlink attacks on files in /tmp, involving unspecified components in Resource Group Manager (aka rgmanager) before 2.03.09-1, gfs2-utils before 2.03.09-1, and ...