CVE-2008-4934: Input Validation
The hfsplusblockallocate function in fs/hfsplus/bitmap.c in the Linux kernel before 2.6.28-rc1 does not check a certain return value from the readmappingpage function before calling kmap, which allows attackers to cause a denial of service (system crash) via a crafted hfsplus filesystem image.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2008-4934?
CVE-2008-4934 is considered to be of medium severity due to its potential to cause denial of service.
How do I fix CVE-2008-4934?
To fix CVE-2008-4934, upgrade the Linux kernel to version 2.6.28 or later.
What systems are affected by CVE-2008-4934?
CVE-2008-4934 affects various versions of the Linux kernel prior to 2.6.28 as well as specific versions of Debian and Ubuntu.
What type of attack does CVE-2008-4934 enable?
CVE-2008-4934 allows attackers to launch a denial of service attack, potentially crashing the system.
Is CVE-2008-4934 specific to any particular Linux distribution?
Yes, CVE-2008-4934 specifically affects certain versions of Debian and Ubuntu Linux.