Description: Fix heap out-of-bounds read in savemeta EA handling (CVE-2026-71222)
 In savemeta, save_ea_block() in gfs2/edit/savemeta.c consumes the on-disk
 ea_num_ptrs field of a gfs2_ea_header without validating it against the
 space actually available in the block.  The loop reads block pointers at
 b[charoff + i] from a heap buffer of sd_bsize bytes, so a crafted GFS2
 filesystem image with a large ea_num_ptrs value causes a heap buffer
 over-read that may disclose sensitive memory contents or cause a crash
 when processed by savemeta.
 .
 Bound the number of pointers read so that the pointer array stays within
 the block buffer.
Author: Valentin Vidic <vvidic@debian.org>
Last-Update: 2026-10-06
---
This patch header follows DEP-3: http://dep.debian.net/deps/dep3/
--- a/gfs2/edit/savemeta.c
+++ b/gfs2/edit/savemeta.c
@@ -696,13 +696,14 @@ static void save_ea_block(struct metafd *mfd, char *buf, uint64_t owner)
 
 		ea = (void *)(buf + e);
 		/* ea_num_ptrs and ea_name_len are u8 so no endianness worries */
-		for (i = 0; i < ea->ea_num_ptrs; i++) {
+		charoff = e + ea->ea_name_len +
+			sizeof(struct gfs2_ea_header) +
+			sizeof(uint64_t) - 1;
+		charoff /= sizeof(uint64_t);
+		for (i = 0; i < ea->ea_num_ptrs &&
+			    (size_t)charoff + i < sbd.sd_bsize / sizeof(uint64_t); i++) {
 			char *_buf;
 
-			charoff = e + ea->ea_name_len +
-				sizeof(struct gfs2_ea_header) +
-				sizeof(uint64_t) - 1;
-			charoff /= sizeof(uint64_t);
 			b = (__be64 *)buf;
 			b += charoff + i;
 			blk = be64_to_cpu(*b);
