← All Advisories

CVE-2026-71221

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-71221

Key Details

CVECVE-2026-71221
CVSS Score / Version7.0 (High) / CVSS v3.1
Updated2026-09-22
CVSS VectorCVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is high; privileges required is none; user interaction is required; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsRed Hat Enterprise Linux, Red Hat Red Hat Enterprise Linux 8, Red Hat Red Hat Enterprise Linux 9, and Red Hat Red Hat Enterprise Linux 7
Classified asCWE-787 (Out-of-bounds Write)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Red HatEnterprise Linux
Red HatRed Hat Enterprise Linux 8
Red HatRed Hat Enterprise Linux 9
Red HatRed Hat Enterprise Linux 7
SubsystemsEWS Workstation Delivery/Virtualization
SectorsAll Sectors

What to Know

A stack out-of-bounds write vulnerability was found in gfs2-utils. In savemeta, the height value from on-disk inode metadata is used as a loop bound without bounds checking, causing a stack buffer overflow that may lead to arbitrary code execution when processing crafted GFS2 filesystem images. (NVD)

What to Do

Monitor Red Hat's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-71221
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-71221
Vendor advisoryhttps://access.redhat.com/security/cve/CVE-2026-71221