在 gfs2-utils 中发现了一个栈越界写漏洞。在 savemeta 中,从磁盘 inode 元数据中读取的 height 值被直接用作循环边界,而未进行边界检查,导致在处理特制的 GFS2 文件系统镜像时发生栈缓冲区溢出,可能导致任意代码执行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 7 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 8 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 9 | any |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-85150 | 7.5 HIGH | Gstreamer1-plugins-base: gstreamer: null/invalid-pointer dereference in gst_rtsp_message_p |
| CVE-2026-71220 | 7.0 HIGH | Gfs2-utils: gfs2-utils: stack out-of-bounds write via unchecked di_height in gfs2_edit |
| CVE-2026-84185 | 5.9 MEDIUM | Jwcrypto: jwcrypto: general json jws kid binding bypass during jwkset verification |
| CVE-2026-71222 | 5.3 MEDIUM | Gfs2-utils: gfs2-utils: heap out-of-bounds read via unchecked ea_num_ptrs in extended attr |
| CVE-2026-71224 | 4.7 MEDIUM | Gfs2-utils: gfs2-utils: stack overflow via alloca(i_height) in metadata walk |
| CVE-2026-71219 | 4.7 MEDIUM | Gfs2-utils: gfs2-utils: stack overflow via alloca(1<<di_depth) in hash table traversal |
No comments yet