<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:redhat:gfs2-Utils:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3aredhatgfs2-utils/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 03 Sep 2026 13:21:11 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3aredhatgfs2-utils/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stack Out-of-Bounds Write in gfs2-utils</title><link>https://feed.craftedsignal.io/briefs/2026-09-03-gfs2-utils-cve-2026-71220/</link><pubDate>Thu, 03 Sep 2026 13:21:11 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-03-gfs2-utils-cve-2026-71220/</guid><description>A stack-based out-of-bounds write vulnerability in the gfs2_edit utility allows arbitrary code execution via crafted GFS2 filesystem images.</description><content:encoded><![CDATA[<p>A stack out-of-bounds write vulnerability, tracked as CVE-2026-71220, exists within the gfs2_edit utility provided by the gfs2-utils package. The flaw is triggered when the application processes a GFS2 filesystem image containing malicious inode metadata. Specifically, the di_height field from the on-disk inode is utilized as an array index without sufficient bounds checking. By providing a specially crafted filesystem image, an attacker can cause a stack buffer overflow. This condition potentially permits an attacker to achieve arbitrary code execution on systems that process untrusted GFS2 images using the gfs2_edit tool. This vulnerability is significant for system administrators and security teams managing storage environments where integrity of filesystem metadata is critical.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability could lead to arbitrary code execution on the target system, potentially resulting in full system compromise. The impact is limited to systems where privileged users run gfs2_edit against untrusted or maliciously crafted GFS2 filesystem images.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize patching of the gfs2-utils package across all Linux distributions where GFS2 filesystems are managed. Monitor system logs for unexpected execution of the gfs2_edit binary, particularly in environments where automated storage auditing or forensic analysis occurs. Organizations should restrict access to gfs2_edit to authorized personnel only and avoid running it on filesystem images of unknown or untrusted origin.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>