CVE-2008-4934

Linux Kernel < 2.6.28 - Improper Input Validation

Title source: rule

Description

The hfsplus_block_allocate function in fs/hfsplus/bitmap.c in the Linux kernel before 2.6.28-rc1 does not check a certain return value from the read_mapping_page function before calling kmap, which allows attackers to cause a denial of service (system crash) via a crafted hfsplus filesystem image.

Scores

EPSS 0.0128
EPSS Percentile 79.3%

Classification

CWE
CWE-20
Status draft

Affected Products (6)

linux/linux_kernel < 2.6.28
debian/debian_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux

Timeline

Published Nov 05, 2008
Tracked Since Feb 18, 2026