HIGHVulnerability
Verified
Global
NVD HIGH: CVE-2026-97362 — HFS2 version 2.4.0 and earlier contains a denial of service vulnerability that a...
·Source: NIST NVD
Updated:
Executive Summary
HFS2 version 2.4.0 and earlier contains a denial of service vulnerability that allows unauthenticated attackers to cause a complete and persistent loss of availability by sending a single crafted request. Attackers can trigger a hung serving thread that enters a busy loop, rendering the entire file server unresponsive to all clients without self-recovery until an operator manually restarts the ser
Analysis
HFS2 version 2.4.0 and earlier contains a denial of service vulnerability that allows unauthenticated attackers to cause a complete and persistent loss of availability by sending a single crafted request. Attackers can trigger a hung serving thread that enters a busy loop, rendering the entire file server unresponsive to all clients without self-recovery until an operator manually restarts the service. CVSS Score: 7.5. Published: 2026-09-24T15:18:01.393.