CVE-2008-4933

Linux Kernel < 2.6.28 - Memory Corruption

Title source: rule

Description

Buffer overflow in the hfsplus_find_cat function in fs/hfsplus/catalog.c in the Linux kernel before 2.6.28-rc1 allows attackers to cause a denial of service (memory corruption or system crash) via an hfsplus filesystem image with an invalid catalog namelength field, related to the hfsplus_cat_build_key_uni function.

References (22)

... and 2 more

Scores

EPSS 0.0117
EPSS Percentile 78.5%

Classification

CWE
CWE-119
Status draft

Affected Products (50)

linux/linux_kernel < 2.6.28
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
... and 35 more

Timeline

Published Nov 05, 2008
Tracked Since Feb 18, 2026