{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aredhatgfs2-utils/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:redhat:gfs2-utils:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7,"id":"CVE-2026-71220"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["gfs2-utils"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Red Hat"],"content_html":"\u003cp\u003eA stack out-of-bounds write vulnerability, tracked as CVE-2026-71220, exists within the gfs2_edit utility provided by the gfs2-utils package. The flaw is triggered when the application processes a GFS2 filesystem image containing malicious inode metadata. Specifically, the di_height field from the on-disk inode is utilized as an array index without sufficient bounds checking. By providing a specially crafted filesystem image, an attacker can cause a stack buffer overflow. This condition potentially permits an attacker to achieve arbitrary code execution on systems that process untrusted GFS2 images using the gfs2_edit tool. This vulnerability is significant for system administrators and security teams managing storage environments where integrity of filesystem metadata is critical.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability could lead to arbitrary code execution on the target system, potentially resulting in full system compromise. The impact is limited to systems where privileged users run gfs2_edit against untrusted or maliciously crafted GFS2 filesystem images.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize patching of the gfs2-utils package across all Linux distributions where GFS2 filesystems are managed. Monitor system logs for unexpected execution of the gfs2_edit binary, particularly in environments where automated storage auditing or forensic analysis occurs. Organizations should restrict access to gfs2_edit to authorized personnel only and avoid running it on filesystem images of unknown or untrusted origin.\u003c/p\u003e\n","date_modified":"2026-09-03T13:21:11Z","date_published":"2026-09-03T13:21:11Z","id":"https://feed.craftedsignal.io/briefs/2026-09-03-gfs2-utils-cve-2026-71220/","summary":"A stack-based out-of-bounds write vulnerability in the gfs2_edit utility allows arbitrary code execution via crafted GFS2 filesystem images.","title":"Stack Out-of-Bounds Write in gfs2-utils","url":"https://feed.craftedsignal.io/briefs/2026-09-03-gfs2-utils-cve-2026-71220/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:redhat:gfs2-Utils:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}