rootpwn

high · CVSS v3 7.5 · CVSS v4 8.7

CVE-2026-97362

HFS2 2.4.0 and earlier are vulnerable to a denial‑of‑service that can be triggered by an unauthenticated attacker with a single crafted requ

Overview

HFS2 2.4.0 and earlier are vulnerable to a denial‑of‑service that can be triggered by an unauthenticated attacker with a single crafted request. The flaw causes a server thread to enter a busy loop, rendering the file server permanently unresponsive until a manual restart. This impacts all clients and administrators relying on the service.

Description

HFS2 version 2.4.0 and earlier contains a denial of service vulnerability that allows unauthenticated attackers to cause a complete and persistent loss of availability by sending a single crafted request. Attackers can trigger a hung serving thread that enters a busy loop, rendering the entire file server unresponsive to all clients without self-recovery until an operator manually restarts the service.

Impact

Availability is completely lost for the file server, preventing all client access. Administrators cannot serve files until the service is restarted. The vulnerability does not expose data or allow privilege escalation.

Remediation

Apply the vendor‑issued patch that updates HFS2 to a version newer than 2.4.0. If a patch is unavailable, restart the HFS2 service immediately and configure a watchdog or health‑check to auto‑restart. Additionally, restrict access to the server via firewall rules and monitor for repeated hung‑thread patterns.

Risk context

The CVSS v3 score of 7.5 and v4 score of 8.7 classify this as a high‑severity denial‑of‑service. With no EPSS data, the urgency remains high due to the persistent nature of the outage.

Affected products

  • HFS2 2.4.0 and earlier

Scores

Severity
high
CVSS v2
7.8
CVSS v3
7.5
CVSS v4
8.7
EPSS
—

denial-of-service availability HFS2 file-server persistent patch restart

← All CVEs