CVE-2026-71219Medium· 4.7▾ SunlitA stack overflow vulnerability was found in gfs2-utils. The hash table traversal code in metawalk.c uses alloca() with an exponentially-derived size from the untrusted on-disk di_depth field without bounds validation. A crafted GFS2 file…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 25.9 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 22.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.1%
A stack overflow vulnerability was found in gfs2-utils. The hash table traversal code in metawalk.c uses alloca() with an exponentially-derived size from the untrusted on-disk di_depth field without bounds validation. A crafted GFS2 filesystem image with a large di_depth value causes stack exhaustion and a denial of service when processed by fsck.gfs2, gfs2_edit, or savemeta.
enterprise_linux = 7.0enterprise_linux = 8.0enterprise_linux = 9.0Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-71224Medium· 4.7A stack overflow vulnerability was found in gfs2-utils
CVE-2026-16100Medium· 6.5A flaw was found in the user-event metrics recording of Keycloak
CVE-2023-5379High· 7.5A flaw was found in Undertow
CVE-2026-71220High· 7.0A stack out-of-bounds write vulnerability was found in gfs2-utils
CVE-2026-71221High· 7.0A stack out-of-bounds write vulnerability was found in gfs2-utils
CVE-2023-6563High· 7.7An unconstrained memory consumption vulnerability was discovered in Keycloak