Description
A heap out-of-bounds read vulnerability was found in gfs2-utils. The ea_num_ptrs field from on-disk extended attribute metadata is consumed without bounds validation, causing a heap buffer over-read that may disclose sensitive memory contents or cause a crash when processing crafted GFS2 filesystem images.
Published: 2026-09-03
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Possible information disclosure or crash due to a heap out-of-bounds read
Action: Apply Workaround
AI Analysis

Impact

A heap out-of-bounds read was discovered in gfs2-utils. The ea_num_ptrs field from extended attribute metadata is consumed without bounds validation, allowing crafted GFS2 filesystem images to trigger a heap buffer over-read that can expose sensitive memory contents or crash the utility. No remote code execution or privilege escalation was reported.

Affected Systems

Red Hat Enterprise Linux 7, RHEL 8, and RHEL 9 are affected by this vulnerability.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting a relatively low to moderate exploitation likelihood. The attack vector is inferred to be users who process untrusted GFS2 filesystem images with gfs2-utils, which could be an insider or attacker with access to an image file. Successful exploitation can result in memory disclosure or local crash, potentially disrupting services that rely on gfs2-utils.

Generated by OpenCVE AI on September 3, 2026 at 13:42 UTC.

Remediation

Vendor Workaround

Do not process untrusted GFS2 filesystem images with gfs2-utils tools. Run gfs2-utils tools in a containerized or VM-isolated environment when processing untrusted images.


OpenCVE Recommended Actions

  • Avoid processing untrusted GFS2 filesystem images with gfs2-utils tools
  • Run gfs2-utils utilities within a containerized or virtual‑machine isolated environment when handling untrusted images
  • Monitor system logs and behavior for unusual failures or memory access anomalies after processing GFS2 images

Generated by OpenCVE AI on September 3, 2026 at 13:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*

Sat, 05 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 04 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Thu, 03 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Redhat gfs2-utils
Vendors & Products Redhat gfs2-utils

Thu, 03 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description A heap out-of-bounds read vulnerability was found in gfs2-utils. The ea_num_ptrs field from on-disk extended attribute metadata is consumed without bounds validation, causing a heap buffer over-read that may disclose sensitive memory contents or cause a crash when processing crafted GFS2 filesystem images.
Title Gfs2-utils: gfs2-utils: heap out-of-bounds read via unchecked ea_num_ptrs in extended attribute processing
First Time appeared Redhat
Redhat enterprise Linux
Weaknesses CWE-125
CPEs cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:L'}


Subscriptions

Redhat Enterprise Linux Gfs2-utils
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-05T01:20:51.104Z

Reserved: 2026-08-05T08:51:19.853Z

Link: CVE-2026-71222

cve-icon Vulnrichment

Updated: 2026-09-05T01:20:47.111Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-03T13:06:03.050

Modified: 2026-09-22T16:37:22.450

Link: CVE-2026-71222

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-03T11:49:24Z

Links: CVE-2026-71222 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T15:33:03Z

Weaknesses