Impact
A stack out‑of‑bounds write occurs in the gfs2_edit utility when it uses the di_height field from on‑disk inode metadata as an array index without bounds checking. The overflow allows a crafted GFS2 filesystem image to corrupt the stack and potentially lead to arbitrary code execution. The vulnerability is manifested when processing a malicious image, giving an attacker the ability to run code with the privileges of gfs2_edit.
Affected Systems
The bug exists in the gfs2‑utils package shipped with Red Hat Enterprise Linux 7, 8, and 9. Any installation of these operating systems that has not applied the latest Red Hat update is potentially affected.
Risk and Exploitability
The CVSS score of 7 indicates a high‑severity vulnerability, and the EPSS is not available for this issue, suggesting no current weaponization data. The flaw is not listed in the CISA KEV catalog, meaning no known exploit has been observed yet. Attackers would need to supply a crafted GFS2 filesystem image and invoke the vulnerable tool, which could be done locally by a user with access to gfs2_edit or remotely if the image is processed by an administrative service. Successful exploitation could lead to arbitrary code execution, implying significant confidentiality, integrity, and availability impacts.
OpenCVE Enrichment