SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-71222

MEDIUM · CVSS 5.3 EPSS 0.11%

Source: NVD + CISA KEV + EPSS · Published 2026-09-03 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A heap out-of-bounds read vulnerability in gfs2-utils allows for the ea_num_ptrs field from on-disk extended attribute metadata to be processed without proper bounds validation. This can lead to sensitive memory disclosure or application crashes when handling specially crafted GFS2 filesystem images. Organizations utilizing gfs2-utils should prioritize addressing this vulnerability to mitigate potential data exposure and system stability issues.

CVE
CVE-2026-71222
Severity
MEDIUM
CVSS
5.3
EPSS
0.11%

Original NVD Description

A heap out-of-bounds read vulnerability was found in gfs2-utils. The ea_num_ptrs field from on-disk extended attribute metadata is consumed without bounds validation, causing a heap buffer over-read that may disclose sensitive memory contents or cause a crash when processing crafted GFS2 filesystem images.