Bug 2511397 (CVE-2026-71224)

Summary: CVE-2026-71224 gfs2-utils: gfs2-utils: stack overflow via alloca(i_height) in metadata walk
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: rhel-process-autobot, security-response-team, watson-tool-maintainers
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A stack overflow vulnerability was found in gfs2-utils. The metadata walk code in metawalk.c uses alloca() with an untrusted inode height value from on-disk metadata without bounds validation, causing stack exhaustion and a denial of service when processing crafted GFS2 filesystem images.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2527996    
Bug Blocks:    

Description OSIDB Bzimport 2026-08-05 08:39:42 UTC
A flaw was found in gfs2-utils. The metadata walk code in metawalk.c uses alloca((height + 1) * sizeof(*metalist)) where height is the i_height field from the on-disk inode (uint16, max 65535, valid range 0-10). No bounds validation is performed before the alloca call. An attacker can craft a GFS2 filesystem image with a large i_height value to cause excessive stack allocation (~1MB for i_height=65535 with sizeof(osi_list_t)=16), leading to stack exhaustion and a denial of service (SIGSEGV). The metadata walk in metawalk.c involves recursive traversal, and each level could invoke this alloca, compounding the stack usage. The Linux kernel GFS2 driver validates i_height against sd_max_height in gfs2_dinode_in() and stores it as u8, but the userspace gfs2-utils performs no equivalent validation.