在 gfs2-utils 中发现了一个堆越界读取漏洞。从磁盘扩展属性元数据中的 字段在未经边界检查的情况下被直接消费,导致在处理特制的 GFS2 文件系统镜像时,可能发生堆缓冲区越界读取,从而泄露敏感内存内容或导致程序崩溃。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 7 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 8 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 9 | any |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-85150 | 7.5 HIGH | Gstreamer1-plugins-base: gstreamer: null/invalid-pointer dereference in gst_rtsp_message_p |
| CVE-2026-71221 | 7.0 HIGH | Gfs2-utils: gfs2-utils: stack out-of-bounds write via unchecked height in savemeta |
| CVE-2026-71220 | 7.0 HIGH | Gfs2-utils: gfs2-utils: stack out-of-bounds write via unchecked di_height in gfs2_edit |
| CVE-2026-84185 | 5.9 MEDIUM | Jwcrypto: jwcrypto: general json jws kid binding bypass during jwkset verification |
| CVE-2026-71224 | 4.7 MEDIUM | Gfs2-utils: gfs2-utils: stack overflow via alloca(i_height) in metadata walk |
| CVE-2026-71219 | 4.7 MEDIUM | Gfs2-utils: gfs2-utils: stack overflow via alloca(1<<di_depth) in hash table traversal |
No comments yet