CVE-2026-97362: HFS2 2.4.0 Unauthenticated Denial of Service via Hung Serving Thread
HFS2 version 2.4.0 and earlier contains a denial of service vulnerability that allows unauthenticated attackers to cause a complete and persistent loss of availability by sending a single crafted request. Attackers can trigger a hung serving thread that enters a busy loop, rendering the entire file server unresponsive to all clients without self-recovery until an operator manually restarts the service.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any unauthenticated attacker who can send a request to the HFS2 service can trigger the denial of service. No privileges or user interaction are required.
What is the operational impact after exploitation?
A single crafted request can cause a serving thread to hang in a busy loop, making the entire file server unresponsive to all clients. The service does not recover on its own and requires an operator to manually restart it.
Which versions are affected?
HFS2 version 2.4.0 and earlier are affected.