Impact
A heap out-of-bounds read was discovered in gfs2-utils. The ea_num_ptrs field from extended attribute metadata is consumed without bounds validation, allowing crafted GFS2 filesystem images to trigger a heap buffer over-read that can expose sensitive memory contents or crash the utility. No remote code execution or privilege escalation was reported.
Affected Systems
Red Hat Enterprise Linux 7, RHEL 8, and RHEL 9 are affected by this vulnerability.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting a relatively low to moderate exploitation likelihood. The attack vector is inferred to be users who process untrusted GFS2 filesystem images with gfs2-utils, which could be an insider or attacker with access to an image file. Successful exploitation can result in memory disclosure or local crash, potentially disrupting services that rely on gfs2-utils.
OpenCVE Enrichment