Impact
An integer overflow occurs during resource group allocation size calculation in gfs2-utils on 32‑bit platforms. The subsequent undersized buffer allocation allows heap out-of-bounds writes when processing crafted GFS2 filesystem images. This flaw can enable an attacker to overwrite critical data structures and potentially execute arbitrary code or crash the system.
Affected Systems
The gfs2-utils package on 32‑bit Linux distributions is affected; the vulnerability does not apply to 64‑bit builds. No specific vendors are listed in the advisory.
Risk and Exploitability
The CVSS score of 7.0 indicates a high severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation yet. The likely attack vector involves an attacker with the ability to create or modify GFS2 filesystem images on a target system. Precise exploitation requires local access or privilege to write to the filesystem; no remote exploit path is described.
OpenCVE Enrichment