Status: UPDATED
| Advisory ID: CVE-2026-71221
Key Details
| CVE | CVE-2026-71221 |
| CVSS Score / Version | 7.0 (High) / CVSS v3.1 |
| Updated | 2026-09-22 |
| CVSS Vector | CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H |
| CVSS Prose | attack vector is local; attack complexity is high; privileges required is none; user interaction is required; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high. |
| Affected products | Red Hat Enterprise Linux, Red Hat Red Hat Enterprise Linux 8, Red Hat Red Hat Enterprise Linux 9, and Red Hat Red Hat Enterprise Linux 7 |
| Classified as | CWE-787 (Out-of-bounds Write) |
Affected Products, Subsystems & Sectors
| Subsystems | EWS Workstation Delivery/Virtualization |
| Sectors | All Sectors |
What to Know
A stack out-of-bounds write vulnerability was found in gfs2-utils. In savemeta, the height value from on-disk inode metadata is used as a loop bound without bounds checking, causing a stack buffer overflow that may lead to arbitrary code execution when processing crafted GFS2 filesystem images. (NVD)
What to Do
Monitor Red Hat's web page for any future patch releases. See vendor advisory link below.
References