Debian Patches
Status for gfs2-utils/3.6.1-2
| Patch | Description | Author | Forwarded | Bugs | Origin | Last update |
|---|---|---|---|---|---|---|
| gfs2_withdraw_helper | update udev script to work in Debian | Valentin Vidic <Valentin.Vidic@CARNet.hr> | not-needed | 2018-04-05 | ||
| python3 | update python scripts for python3 | Valentin Vidic <Valentin.Vidic@CARNet.hr> | not-needed | 2018-04-05 | ||
| CVE-2026-71219 | Fix stack overflow / out-of-bounds read with large di_depth (CVE-2026-71219) The directory hash table traversal code derives the hash table size exponentially from the on-disk di_depth field (hsize = 1 << i_depth) without bounds validation. . In gfs2/fsck/metawalk.c the derived size is used to size an alloca() buffer in dir_leaf_reada(); di_depth is read from untrusted filesystem metadata and can be up to 65535, so a crafted GFS2 filesystem image with a large di_depth value causes an excessively large stack allocation, leading to stack exhaustion and a denial of service when processed by fsck.gfs2. . In gfs2/edit/gfs2hex.c the same unbounded di_depth value is used as a loop bound in do_dinode_extended(), reading leaf pointers past the end of the single-block buffer, causing a heap out-of-bounds read when processed by gfs2_edit. . Validate that i_depth does not exceed GFS2_DIR_MAX_DEPTH before computing the hash table size, rejecting such directories as corrupt. The check is also enforced in the shared get_dir_hash() helper so all callers, including pass2, are covered, and the gfs2_edit leaf pointer walk is bounded to the block size with a depth clamped to avoid a shift overflow. |
Valentin Vidic <vvidic@debian.org> | no | 2026-10-06 | ||
| CVE-2026-71220 | Fix stack out-of-bounds write / recursion with large di_height (CVE-2026-71220) In gfs2_edit, the on-disk di_height field (an unbounded uint16_t read from untrusted filesystem metadata) is used without bounds checking. . In metapath_to_lblock() in gfs2/edit/extended.c it is used as an index into the stack array factor[GFS2_MAX_META_HEIGHT] (factor[height - 1] = 1ull), causing a stack buffer overflow that may lead to arbitrary code execution. . In display_indirect() the same unbounded di_height value drives the recursion into print_block_details()/display_indirect() and the mp.mp_list[cur_height + 1] indexing, so a crafted image with a large di_height causes deep recursion (stack exhaustion) and an out-of-bounds write when processed by gfs2_edit. . Validate that di_height does not exceed GFS2_MAX_META_HEIGHT before using it as an array index, and cap the display recursion depth so that the metapath index stays in bounds. |
Valentin Vidic <vvidic@debian.org> | no | 2026-10-06 | ||
| CVE-2026-71221 | Fix stack out-of-bounds write in savemeta (CVE-2026-71221) In savemeta, save_inode_data() in gfs2/edit/savemeta.c reads the on-disk di_height field (an unbounded uint16_t from untrusted filesystem metadata) and uses it, after an optional adjustment for exhash directories, as the bound of a loop and as an index into the stack array indq[GFS2_MAX_META_HEIGHT] without any bounds checking. A crafted GFS2 filesystem image with a large di_height value therefore causes a stack buffer overflow that may lead to arbitrary code execution when processed by savemeta. . Validate that the derived height does not exceed GFS2_MAX_META_HEIGHT before using it as a loop bound or array index, skipping such inodes. The height is widened from uint16_t to unsigned so the exhash increment (di_height + 1) cannot wrap around and bypass the bounds check. |
Valentin Vidic <vvidic@debian.org> | no | 2026-10-06 | ||
| CVE-2026-71222 | Fix heap out-of-bounds read in savemeta EA handling (CVE-2026-71222) In savemeta, save_ea_block() in gfs2/edit/savemeta.c consumes the on-disk ea_num_ptrs field of a gfs2_ea_header without validating it against the space actually available in the block. The loop reads block pointers at b[charoff + i] from a heap buffer of sd_bsize bytes, so a crafted GFS2 filesystem image with a large ea_num_ptrs value causes a heap buffer over-read that may disclose sensitive memory contents or cause a crash when processed by savemeta. . Bound the number of pointers read so that the pointer array stays within the block buffer. |
Valentin Vidic <vvidic@debian.org> | no | 2026-10-06 | ||
| CVE-2026-71223 | Fix integer overflow in rgrp allocation size (CVE-2026-71223) The resource group (rgrp) allocation size is computed as rt_length * sd_bsize where both operands are 32-bit. rt_length comes from the on-disk rindex and is not otherwise bounded, so on 32-bit platforms (and for oversized rgrps on 64-bit) this multiplication can overflow, producing an undersized buffer allocation that is later accessed using the full rt_length, resulting in an out-of-bounds read/write. . Perform the size computation in size_t arithmetic and reject resource groups whose size cannot be represented before allocating. |
Valentin Vidic <vvidic@debian.org> | no | 2026-10-06 | ||
| CVE-2026-71224 | Fix stack overflow in metadata walk (CVE-2026-71224) The metadata walk code in gfs2/fsck/metawalk.c uses alloca() in check_metatree() with a size derived from the on-disk i_height field (alloca((height + 1) * sizeof(osi_list_t))) without bounds validation. i_height is an unbounded uint16_t read from untrusted filesystem metadata, so a crafted GFS2 filesystem image with a large height value causes an excessively large stack allocation, leading to stack exhaustion and a denial of service when processed by fsck.gfs2. . Validate that i_height does not exceed GFS2_MAX_META_HEIGHT before performing the stack allocation, rejecting such inodes as corrupt. |
Valentin Vidic <vvidic@debian.org> | no | 2026-10-06 |
