high · CVSS v3 7.5 · CVSS v4 8.7
CVE-2026-97362
HFS2 2.4.0 and earlier are vulnerable to a denial‑of‑service that can be triggered by an unauthenticated attacker with a single crafted requ
Overview
HFS2 2.4.0 and earlier are vulnerable to a denial‑of‑service that can be triggered by an unauthenticated attacker with a single crafted request. The flaw causes a server thread to enter a busy loop, rendering the file server permanently unresponsive until a manual restart. This impacts all clients and administrators relying on the service.
Description
HFS2 version 2.4.0 and earlier contains a denial of service vulnerability that allows unauthenticated attackers to cause a complete and persistent loss of availability by sending a single crafted request. Attackers can trigger a hung serving thread that enters a busy loop, rendering the entire file server unresponsive to all clients without self-recovery until an operator manually restarts the service.
Impact
Availability is completely lost for the file server, preventing all client access. Administrators cannot serve files until the service is restarted. The vulnerability does not expose data or allow privilege escalation.
Remediation
Apply the vendor‑issued patch that updates HFS2 to a version newer than 2.4.0. If a patch is unavailable, restart the HFS2 service immediately and configure a watchdog or health‑check to auto‑restart. Additionally, restrict access to the server via firewall rules and monitor for repeated hung‑thread patterns.
Risk context
The CVSS v3 score of 7.5 and v4 score of 8.7 classify this as a high‑severity denial‑of‑service. With no EPSS data, the urgency remains high due to the persistent nature of the outage.
Affected products
- HFS2 2.4.0 and earlier
Scores
- Severity
- high
- CVSS v2
- 7.8
- CVSS v3
- 7.5
- CVSS v4
- 8.7
- EPSS
- —