HFS2 version 2.4.0 and earlier contains a denial of service vulnerability that allows unauthenticated attackers to cause a complete and persistent loss of availability by sending a single crafted request. Attackers can trigger a hung serving thread that enters a busy loop, rendering the entire file server unresponsive to all clients without self-recovery until an operator manually restarts the service.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 24 Sep 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | HFS2 version 2.4.0 and earlier contains a denial of service vulnerability that allows unauthenticated attackers to cause a complete and persistent loss of availability by sending a single crafted request. Attackers can trigger a hung serving thread that enters a busy loop, rendering the entire file server unresponsive to all clients without self-recovery until an operator manually restarts the service. | |
| Title | HFS2 2.4.0 Unauthenticated Denial of Service via Hung Serving Thread | |
| First Time appeared |
Rejetto
Rejetto hfs2 |
|
| Weaknesses | CWE-835 | |
| CPEs | cpe:2.3:a:rejetto:hfs2:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Rejetto
Rejetto hfs2 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-24T15:47:35.811Z
Reserved: 2026-09-24T13:33:30.061Z
Link: CVE-2026-97362
No data.
Status : Received
Published: 2026-09-24T15:18:01.393
Modified: 2026-09-24T15:18:01.393
Link: CVE-2026-97362
No data.
OpenCVE Enrichment
No data.
Weaknesses