Bug 2527996

Summary: CVE-2026-71224 gfs2-utils: gfs2-utils: stack overflow via alloca(i_height) in metadata walk [fedora-all]
Product: [Fedora] Fedora Reporter: Samuele Negrini <snegrini>
Component: gfs2-utilsAssignee: Andrew Price <anprice>
Status: NEW --- QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: medium Docs Contact:
Priority: medium    
Version: rawhideCC: agk, agruenba, anprice, bmarzins, cfeist
Target Milestone: ---Keywords: Security, SecurityTracking
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard: {"flaws": ["196c5616-e4c0-4380-801f-bb84fb4f1673"]}
Fixed In Version: Doc Type: ---
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 2511397    

Description Samuele Negrini 2026-09-03 11:58:04 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

A flaw was found in gfs2-utils. The metadata walk code in metawalk.c uses alloca((height + 1) * sizeof(*metalist)) where height is the i_height field from the on-disk inode (uint16, max 65535, valid range 0-10). No bounds validation is performed before the alloca call. An attacker can craft a GFS2 filesystem image with a large i_height value to cause excessive stack allocation (~1MB for i_height=65535 with sizeof(osi_list_t)=16), leading to stack exhaustion and a denial of service (SIGSEGV). The metadata walk in metawalk.c involves recursive traversal, and each level could invoke this alloca, compounding the stack usage. The Linux kernel GFS2 driver validates i_height against sd_max_height in gfs2_dinode_in() and stores it as u8, but the userspace gfs2-utils performs no equivalent validation.