cbcvebase.
CVE-2009-4020
published 2009-12-04

CVE-2009-4020: Stack-based buffer overflow in the hfs subsystem in the Linux kernel 2.6.32 allows remote attackers to have an unspecified impact via a crafted Hierarchical…

PriorityP341high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
4.95%
91.2th percentile
Stack-based buffer overflow in the hfs subsystem in the Linux kernel 2.6.32 allows remote attackers to have an unspecified impact via a crafted Hierarchical File System (HFS) filesystem, related to the hfs_readdir function in fs/hfs/dir.c.

Affected

7 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 3.2.17-1 (bookworm)linux 3.2.17-1 (bookworm)
linuxlinux_kernel<= 3.3.3
linuxlinux_kernel
linuxlinux_kernel>= 0 < 3.2.17-13.2.17-1
linuxlinux_kernel>= 0 < 3.2.17-13.2.17-1
linuxlinux_kernel>= 0 < 3.2.17-13.2.17-1
linuxlinux_kernel>= 0 < 3.2.17-13.2.17-1

CVSS provenance

nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
osv7.8HIGH
vendor_debian7.8LOW
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.