在 gfs2-utils 中发现了一个栈缓冲区越界写漏洞。在 中,磁盘 inode 元数据中的 字段在作为数组索引使用时未进行边界检查,导致在处理精心构造的 GFS2 文件系统镜像时可能发生栈缓冲区溢出,进而可能导致任意代码执行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 7 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 8 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 9 | any |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-85150 | 7.5 HIGH | Gstreamer1-plugins-base: gstreamer: null/invalid-pointer dereference in gst_rtsp_message_p |
| CVE-2026-71221 | 7.0 HIGH | Gfs2-utils: gfs2-utils: stack out-of-bounds write via unchecked height in savemeta |
| CVE-2026-84185 | 5.9 MEDIUM | Jwcrypto: jwcrypto: general json jws kid binding bypass during jwkset verification |
| CVE-2026-71222 | 5.3 MEDIUM | Gfs2-utils: gfs2-utils: heap out-of-bounds read via unchecked ea_num_ptrs in extended attr |
| CVE-2026-71224 | 4.7 MEDIUM | Gfs2-utils: gfs2-utils: stack overflow via alloca(i_height) in metadata walk |
| CVE-2026-71219 | 4.7 MEDIUM | Gfs2-utils: gfs2-utils: stack overflow via alloca(1<<di_depth) in hash table traversal |
No comments yet