Fedora Account System
Red Hat Associate
Red Hat Customer
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process. A flaw was found in gfs2-utils. The hash table traversal code in fsck.gfs2 (metawalk.c) uses alloca(1 << di_depth) where di_depth is a uint16 field read directly from on-disk directory inode metadata without bounds validation. An attacker can craft a GFS2 filesystem image with a large di_depth value (e.g., 24+) that causes an exponentially large stack allocation (1 << 24 = 16M entries * 8 bytes = 128MB), far exceeding the default 8MB stack limit and crashing the process with SIGSEGV. Additionally, for di_depth >= 31 on platforms where int is 32 bits, the expression 1 << di_depth invokes undefined behavior (signed integer overflow per C11 6.5.7p4), which may produce a small or wrapped alloca result rather than a large one, with unpredictable consequences. The Linux kernel GFS2 driver validates i_depth in gfs2_dinode_in() (see CVE-2025-38710), but the userspace gfs2-utils performs no equivalent validation. This affects fsck.gfs2, gfs2_edit, and savemeta when processing directory metadata from crafted images.