CVE-2026-71219: Red Hat Enterprise Linux
Medium severity, CVSS 4.7. EPSS: 0.1% chance of exploitation in the next 30 days.
A stack overflow vulnerability was found in gfs2-utils. The hash table traversal code in metawalk.c uses alloca() with an exponentially-derived size from the untrusted on-disk di_depth field without bounds validation. A crafted GFS2 filesystem image with a large di_depth value causes stack exhaustion and a denial of service when processed by fsck.gfs2, gfs2_edit, or savemeta.
Affected products
- Red Hat Enterprise Linux: version 7.0 only; version 8.0 only; version 9.0 only
Published 2026-09-03. Last modified 2026-09-22.