Debian Patches

Status for gfs2-utils/3.6.1-2

Patch Description Author Forwarded Bugs Origin Last update
gfs2_withdraw_helper update udev script to work in Debian Valentin Vidic <Valentin.Vidic@CARNet.hr> not-needed 2018-04-05
python3 update python scripts for python3 Valentin Vidic <Valentin.Vidic@CARNet.hr> not-needed 2018-04-05
CVE-2026-71219 Fix stack overflow / out-of-bounds read with large di_depth (CVE-2026-71219) The directory hash table traversal code derives the hash table size
exponentially from the on-disk di_depth field (hsize = 1 << i_depth)
without bounds validation.
.
In gfs2/fsck/metawalk.c the derived size is used to size an alloca()
buffer in dir_leaf_reada(); di_depth is read from untrusted filesystem
metadata and can be up to 65535, so a crafted GFS2 filesystem image with
a large di_depth value causes an excessively large stack allocation,
leading to stack exhaustion and a denial of service when processed by
fsck.gfs2.
.
In gfs2/edit/gfs2hex.c the same unbounded di_depth value is used as a
loop bound in do_dinode_extended(), reading leaf pointers past the end
of the single-block buffer, causing a heap out-of-bounds read when
processed by gfs2_edit.
.
Validate that i_depth does not exceed GFS2_DIR_MAX_DEPTH before computing
the hash table size, rejecting such directories as corrupt. The check is
also enforced in the shared get_dir_hash() helper so all callers,
including pass2, are covered, and the gfs2_edit leaf pointer walk is
bounded to the block size with a depth clamped to avoid a shift overflow.
Valentin Vidic <vvidic@debian.org> no 2026-10-06
CVE-2026-71220 Fix stack out-of-bounds write / recursion with large di_height (CVE-2026-71220) In gfs2_edit, the on-disk di_height field (an unbounded uint16_t read
from untrusted filesystem metadata) is used without bounds checking.
.
In metapath_to_lblock() in gfs2/edit/extended.c it is used as an index
into the stack array factor[GFS2_MAX_META_HEIGHT]
(factor[height - 1] = 1ull), causing a stack buffer overflow that may
lead to arbitrary code execution.
.
In display_indirect() the same unbounded di_height value drives the
recursion into print_block_details()/display_indirect() and the
mp.mp_list[cur_height + 1] indexing, so a crafted image with a large
di_height causes deep recursion (stack exhaustion) and an out-of-bounds
write when processed by gfs2_edit.
.
Validate that di_height does not exceed GFS2_MAX_META_HEIGHT before using
it as an array index, and cap the display recursion depth so that the
metapath index stays in bounds.
Valentin Vidic <vvidic@debian.org> no 2026-10-06
CVE-2026-71221 Fix stack out-of-bounds write in savemeta (CVE-2026-71221) In savemeta, save_inode_data() in gfs2/edit/savemeta.c reads the on-disk
di_height field (an unbounded uint16_t from untrusted filesystem
metadata) and uses it, after an optional adjustment for exhash
directories, as the bound of a loop and as an index into the stack array
indq[GFS2_MAX_META_HEIGHT] without any bounds checking. A crafted GFS2
filesystem image with a large di_height value therefore causes a stack
buffer overflow that may lead to arbitrary code execution when processed
by savemeta.
.
Validate that the derived height does not exceed GFS2_MAX_META_HEIGHT
before using it as a loop bound or array index, skipping such inodes.
The height is widened from uint16_t to unsigned so the exhash increment
(di_height + 1) cannot wrap around and bypass the bounds check.
Valentin Vidic <vvidic@debian.org> no 2026-10-06
CVE-2026-71222 Fix heap out-of-bounds read in savemeta EA handling (CVE-2026-71222) In savemeta, save_ea_block() in gfs2/edit/savemeta.c consumes the on-disk
ea_num_ptrs field of a gfs2_ea_header without validating it against the
space actually available in the block. The loop reads block pointers at
b[charoff + i] from a heap buffer of sd_bsize bytes, so a crafted GFS2
filesystem image with a large ea_num_ptrs value causes a heap buffer
over-read that may disclose sensitive memory contents or cause a crash
when processed by savemeta.
.
Bound the number of pointers read so that the pointer array stays within
the block buffer.
Valentin Vidic <vvidic@debian.org> no 2026-10-06
CVE-2026-71223 Fix integer overflow in rgrp allocation size (CVE-2026-71223) The resource group (rgrp) allocation size is computed as
rt_length * sd_bsize where both operands are 32-bit. rt_length comes
from the on-disk rindex and is not otherwise bounded, so on 32-bit
platforms (and for oversized rgrps on 64-bit) this multiplication can
overflow, producing an undersized buffer allocation that is later
accessed using the full rt_length, resulting in an out-of-bounds
read/write.
.
Perform the size computation in size_t arithmetic and reject resource
groups whose size cannot be represented before allocating.
Valentin Vidic <vvidic@debian.org> no 2026-10-06
CVE-2026-71224 Fix stack overflow in metadata walk (CVE-2026-71224) The metadata walk code in gfs2/fsck/metawalk.c uses alloca() in
check_metatree() with a size derived from the on-disk i_height field
(alloca((height + 1) * sizeof(osi_list_t))) without bounds validation.
i_height is an unbounded uint16_t read from untrusted filesystem
metadata, so a crafted GFS2 filesystem image with a large height value
causes an excessively large stack allocation, leading to stack exhaustion
and a denial of service when processed by fsck.gfs2.
.
Validate that i_height does not exceed GFS2_MAX_META_HEIGHT before
performing the stack allocation, rejecting such inodes as corrupt.
Valentin Vidic <vvidic@debian.org> no 2026-10-06

All known versions for source package 'gfs2-utils'

Links