Description: Fix stack overflow in metadata walk (CVE-2026-71224)
 The metadata walk code in gfs2/fsck/metawalk.c uses alloca() in
 check_metatree() with a size derived from the on-disk i_height field
 (alloca((height + 1) * sizeof(osi_list_t))) without bounds validation.
 i_height is an unbounded uint16_t read from untrusted filesystem
 metadata, so a crafted GFS2 filesystem image with a large height value
 causes an excessively large stack allocation, leading to stack exhaustion
 and a denial of service when processed by fsck.gfs2.
 .
 Validate that i_height does not exceed GFS2_MAX_META_HEIGHT before
 performing the stack allocation, rejecting such inodes as corrupt.
Author: Valentin Vidic <vvidic@debian.org>
Last-Update: 2026-10-06
---
This patch header follows DEP-3: http://dep.debian.net/deps/dep3/
--- a/gfs2/fsck/metawalk.c
+++ b/gfs2/fsck/metawalk.c
@@ -1431,8 +1431,8 @@
  */
 int check_metatree(struct fsck_cx *cx, struct lgfs2_inode *ip, struct metawalk_fxns *pass)
 {
-	unsigned int height = ip->i_height;
-	osi_list_t *metalist = alloca((height + 1) * sizeof(*metalist));
+	unsigned int height;
+	osi_list_t *metalist;
 	osi_list_t *list, *tmp;
 	struct lgfs2_buffer_head *bh;
 	unsigned int i;
@@ -1442,6 +1442,16 @@
 	struct error_block error_blk = {0, 0, 0};
 	int hit_error_blk = 0;
 
+	if (ip->i_height > GFS2_MAX_META_HEIGHT) {
+		log_err(_("Inode #%"PRIu64" (0x%"PRIx64") has an invalid height "
+		          "of %u (maximum is %u); skipping it.\n"),
+		        ip->i_num.in_addr, ip->i_num.in_addr, (unsigned)ip->i_height,
+		        (unsigned)GFS2_MAX_META_HEIGHT);
+		return 1;
+	}
+	height = ip->i_height;
+	metalist = alloca((height + 1) * sizeof(*metalist));
+
 	if (!height && !is_dir(ip))
 		return 0;
 
