Debian Package Tracker
Register | Log in
Subscribe

gfs2-utils

Global File System 2 - filesystem tools

Choose email to subscribe with

general
  • source: gfs2-utils (main)
  • version: 3.6.1-2
  • maintainer: Debian HA Maintainers (archive) (DMD)
  • uploaders: Valentin Vidic [DMD]
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 3.3.0-2
  • oldstable: 3.5.0-2
  • stable: 3.6.1-1
  • testing: 3.6.1-1
  • unstable: 3.6.1-2
versioned links
  • 3.3.0-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 3.5.0-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 3.6.1-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 3.6.1-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • gfs2-utils (1 bugs: 0, 1, 0, 0)
action needed
6 security issues in forky high

There are 6 open security issues in forky.

6 important issues:
  • CVE-2026-71219: A stack overflow vulnerability was found in gfs2-utils. The hash table traversal code in metawalk.c uses alloca() with an exponentially-derived size from the untrusted on-disk di_depth field without bounds validation. A crafted GFS2 filesystem image with a large di_depth value causes stack exhaustion and a denial of service when processed by fsck.gfs2, gfs2_edit, or savemeta.
  • CVE-2026-71220: A stack out-of-bounds write vulnerability was found in gfs2-utils. In gfs2_edit, the di_height field from on-disk inode metadata is used as an array index without bounds checking, causing a stack buffer overflow that may lead to arbitrary code execution when processing crafted GFS2 filesystem images.
  • CVE-2026-71221: A stack out-of-bounds write vulnerability was found in gfs2-utils. In savemeta, the height value from on-disk inode metadata is used as a loop bound without bounds checking, causing a stack buffer overflow that may lead to arbitrary code execution when processing crafted GFS2 filesystem images.
  • CVE-2026-71222: A heap out-of-bounds read vulnerability was found in gfs2-utils. The ea_num_ptrs field from on-disk extended attribute metadata is consumed without bounds validation, causing a heap buffer over-read that may disclose sensitive memory contents or cause a crash when processing crafted GFS2 filesystem images.
  • CVE-2026-71223:
  • CVE-2026-71224: A stack overflow vulnerability was found in gfs2-utils. The metadata walk code in metawalk.c uses alloca() with an untrusted inode height value from on-disk metadata without bounds validation, causing stack exhaustion and a denial of service when processing crafted GFS2 filesystem images.
Created: 2026-09-04 Last update: 2026-10-07 01:00
1 bug tagged patch in the BTS normal
The BTS contains patches fixing 1 bug, consider including or untagging them.
Created: 2026-10-09 Last update: 2026-10-10 00:18
debian/patches: 6 patches to forward upstream low

Among the 8 debian patches available in version 3.6.1-2 of the package, we noticed the following issues:

  • 6 patches where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2026-10-07 Last update: 2026-10-07 09:19
6 low-priority security issues in trixie low

There are 6 open security issues in trixie.

6 issues left for the package maintainer to handle:
  • CVE-2026-71219: (needs triaging) A stack overflow vulnerability was found in gfs2-utils. The hash table traversal code in metawalk.c uses alloca() with an exponentially-derived size from the untrusted on-disk di_depth field without bounds validation. A crafted GFS2 filesystem image with a large di_depth value causes stack exhaustion and a denial of service when processed by fsck.gfs2, gfs2_edit, or savemeta.
  • CVE-2026-71220: (needs triaging) A stack out-of-bounds write vulnerability was found in gfs2-utils. In gfs2_edit, the di_height field from on-disk inode metadata is used as an array index without bounds checking, causing a stack buffer overflow that may lead to arbitrary code execution when processing crafted GFS2 filesystem images.
  • CVE-2026-71221: (needs triaging) A stack out-of-bounds write vulnerability was found in gfs2-utils. In savemeta, the height value from on-disk inode metadata is used as a loop bound without bounds checking, causing a stack buffer overflow that may lead to arbitrary code execution when processing crafted GFS2 filesystem images.
  • CVE-2026-71222: (needs triaging) A heap out-of-bounds read vulnerability was found in gfs2-utils. The ea_num_ptrs field from on-disk extended attribute metadata is consumed without bounds validation, causing a heap buffer over-read that may disclose sensitive memory contents or cause a crash when processing crafted GFS2 filesystem images.
  • CVE-2026-71223: (needs triaging)
  • CVE-2026-71224: (needs triaging) A stack overflow vulnerability was found in gfs2-utils. The metadata walk code in metawalk.c uses alloca() with an untrusted inode height value from on-disk metadata without bounds validation, causing stack exhaustion and a denial of service when processing crafted GFS2 filesystem images.

You can find information about how to handle these issues in the security team's documentation.

Created: 2026-09-04 Last update: 2026-10-07 01:00
testing migrations
  • excuses:
    • Migration status for gfs2-utils (3.6.1-1 to 3.6.1-2): Waiting for test results or another package, or too young (no action required now - check later)
    • Issues preventing migration:
    • ∙ ∙ Autopkgtest for gfs2-utils/3.6.1-2: amd64: Pass, arm64: Pass, armhf: Pass, i386: Test triggered, ppc64el: Pass, riscv64: Pass, s390x: Pass
    • ∙ ∙ Too young, only 3 of 5 days old
    • Additional info (not blocking):
    • ∙ ∙ Piuparts tested OK - https://piuparts.debian.org/sid/source/g/gfs2-utils.html
    • ∙ ∙ Reproduced on amd64 - info
    • ∙ ∙ Reproduced on arm64 - info
    • ∙ ∙ Reproduced on armhf - info
    • ∙ ∙ Reproduced on i386 - info
    • Not considered
news
[rss feed]
  • [2026-10-06] Accepted gfs2-utils 3.6.1-2 (source) into unstable (Valentin Vidic)
  • [2025-03-06] gfs2-utils 3.6.1-1 MIGRATED to testing (Debian testing watch)
  • [2025-03-06] gfs2-utils 3.6.1-1 MIGRATED to testing (Debian testing watch)
  • [2025-03-02] Accepted gfs2-utils 3.6.1-1 (source) into unstable (Valentin Vidic)
  • [2025-03-01] gfs2-utils 3.6.0-1 MIGRATED to testing (Debian testing watch)
  • [2025-02-26] Accepted gfs2-utils 3.6.0-1 (source) into unstable (Valentin Vidic)
  • [2024-04-17] gfs2-utils 3.5.1-2 MIGRATED to testing (Debian testing watch)
  • [2024-04-14] Accepted gfs2-utils 3.5.1-2 (source) into unstable (Valentin Vidic)
  • [2023-06-25] gfs2-utils 3.5.1-1 MIGRATED to testing (Debian testing watch)
  • [2023-06-25] gfs2-utils 3.5.1-1 MIGRATED to testing (Debian testing watch)
  • [2023-06-22] Accepted gfs2-utils 3.5.1-1 (source) into unstable (Valentin Vidic)
  • [2023-02-24] gfs2-utils 3.5.0-2 MIGRATED to testing (Debian testing watch)
  • [2023-02-13] Accepted gfs2-utils 3.5.0-2 (source) into unstable (Valentin Vidic)
  • [2023-02-11] Accepted gfs2-utils 3.5.0-1 (source) into unstable (Valentin Vidic)
  • [2022-11-23] gfs2-utils 3.4.1-3 MIGRATED to testing (Debian testing watch)
  • [2022-11-20] Accepted gfs2-utils 3.4.1-3 (source) into unstable (Valentin Vidic)
  • [2021-10-01] gfs2-utils 3.4.1-2 MIGRATED to testing (Debian testing watch)
  • [2021-09-28] Accepted gfs2-utils 3.4.1-2 (source) into unstable (Valentin Vidic)
  • [2021-08-23] gfs2-utils 3.4.1-1 MIGRATED to testing (Debian testing watch)
  • [2021-08-21] Accepted gfs2-utils 3.4.1-1 (source) into unstable (Valentin Vidic)
  • [2020-10-19] gfs2-utils 3.3.0-2 MIGRATED to testing (Debian testing watch)
  • [2020-10-16] Accepted gfs2-utils 3.3.0-2 (source) into unstable (Valentin Vidic)
  • [2020-09-07] gfs2-utils 3.3.0-1 MIGRATED to testing (Debian testing watch)
  • [2020-09-03] Accepted gfs2-utils 3.3.0-1 (source) into unstable (Valentin Vidic)
  • [2020-02-18] gfs2-utils 3.2.0-3 MIGRATED to testing (Debian testing watch)
  • [2020-02-15] Accepted gfs2-utils 3.2.0-3 (source) into unstable (Valentin Vidic)
  • [2019-07-14] gfs2-utils 3.2.0-2 MIGRATED to testing (Debian testing watch)
  • [2019-07-11] Accepted gfs2-utils 3.2.0-2 (source) into unstable (Valentin Vidic)
  • [2018-06-01] gfs2-utils 3.2.0-1 MIGRATED to testing (Debian testing watch)
  • [2018-05-30] Accepted gfs2-utils 3.2.0-1 (source) into unstable (Valentin Vidic)
  • 1
  • 2
bugs [bug history graph]
  • all: 1
  • RC: 0
  • I&N: 1
  • M&W: 0
  • F&P: 0
  • patch: 1
links
  • homepage
  • lintian
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 3.6.1-1build1
  • 2 bugs (1 patch)

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing