{"api_version":"1","generated_at":"2026-07-23T12:04:54+00:00","cve":"CVE-2009-4020","urls":{"html":"https://cve.report/CVE-2009-4020","api":"https://cve.report/api/cve/CVE-2009-4020.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2009-4020","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2009-4020"},"summary":{"title":"CVE-2009-4020","description":"Stack-based buffer overflow in the hfs subsystem in the Linux kernel 2.6.32 allows remote attackers to have an unspecified impact via a crafted Hierarchical File System (HFS) filesystem, related to the hfs_readdir function in fs/hfs/dir.c.","state":"PUBLISHED","assigner":"redhat","published_at":"2009-12-04 21:30:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-119","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.8","severity":"","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:C","baseScore":7.8,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://secunia.com/advisories/39742","name":"http://secunia.com/advisories/39742","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SUSE update for kernel - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://rhn.redhat.com/errata/RHSA-2010-0046.html","name":"https://rhn.redhat.com/errata/RHSA-2010-0046.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"rhn.redhat.com | Red Hat Support","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.debian.org/security/2010/dsa-2005","name":"http://www.debian.org/security/2010/dsa-2005","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Debian -- Security Information -- DSA-2005-1 linux-2.6.24","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6750","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6750","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.novell.com/linux/security/advisories/2010_23_kernel.html","name":"http://www.novell.com/linux/security/advisories/2010_23_kernel.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Security Announcement","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.openwall.com/lists/oss-security/2009/12/04/1","name":"http://www.openwall.com/lists/oss-security/2009/12/04/1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"oss-security - CVE-2009-4020 kernel: hfs buffer overflow","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00005.html","name":"http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00005.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[security-announce] SUSE Security Announcement: Linux kernel (SUSE-SA:20","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/38276","name":"http://secunia.com/advisories/38276","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SUSE update for kernel - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://marc.info/?l=linux-mm-commits&m=125987755823047&w=2","name":"http://marc.info/?l=linux-mm-commits&m=125987755823047&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'+ hfs-fix-a-potential-buffer-overflow.patch added to -mm tree' - MARC","mime":"text/x-diff","httpstatus":"200","archivestatus":"200"},{"url":"http://userweb.kernel.org/~akpm/mmotm/broken-out/hfs-fix-a-potential-buffer-overflow.patch","name":"http://userweb.kernel.org/~akpm/mmotm/broken-out/hfs-fix-a-potential-buffer-overflow.patch","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"","mime":"","httpstatus":"-1","archivestatus":"404"},{"url":"https://rhn.redhat.com/errata/RHSA-2010-0095.html","name":"https://rhn.redhat.com/errata/RHSA-2010-0095.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10091","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10091","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://support.avaya.com/css/P8/documents/100073666","name":"http://support.avaya.com/css/P8/documents/100073666","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"ASA-2010-026 (RHSA-2010-0046)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=540736","name":"https://bugzilla.redhat.com/show_bug.cgi?id=540736","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"540736 – (CVE-2009-4020) CVE-2009-4020 kernel: hfs buffer overflow","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00007.html","name":"http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00007.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[security-announce] SUSE Security Announcement: Linux kernel (SUSE-SA:20","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://access.redhat.com/errata/RHSA-2010:0046","name":"MISC:https://access.redhat.com/errata/RHSA-2010:0046","refsource":"MITRE","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://access.redhat.com/errata/RHSA-2010:0076","name":"MISC:https://access.redhat.com/errata/RHSA-2010:0076","refsource":"MITRE","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://access.redhat.com/security/cve/CVE-2009-4020","name":"MISC:https://access.redhat.com/security/cve/CVE-2009-4020","refsource":"MITRE","tags":[],"title":"access.redhat.com | CVE-2009-4020","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2009-4020","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2009-4020","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2009","cve_id":"4020","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"2.6.32","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[{"cvename":"CVE-2009-4020","organization":"Red Hat","lastmodified":"2010-02-04","contributor":"Mark J Cox","statementText":"This issue did not affect the version of the Linux kernel as shipped with Red Hat Enterprise MRG as the affected driver is not enabled in this kernel. It was addressed in Red Hat Enterprise Linux 4 and 5 via https://rhn.redhat.com/errata/RHSA-2010-0076.html and https://rhn.redhat.com/errata/RHSA-2010-0046.html respectively. Red Hat Enterprise Linux 3 is now in Production 3 of the maintenance life-cycle, http://www.redhat.com/security/updates/errata, and this issue is rated as having low impact, therefore the fix for this issue is not currently planned to be included in the future updates.","cve_year":"2009","cve_id":"4020","crc32":"8a71df6a"}],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T06:45:50.888Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"[linux-mm-commits] 20091203 + hfs-fix-a-potential-buffer-overflow.patch added to -mm tree","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://marc.info/?l=linux-mm-commits&m=125987755823047&w=2"},{"name":"38276","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/38276"},{"name":"oval:org.mitre.oval:def:10091","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10091"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://support.avaya.com/css/P8/documents/100073666"},{"name":"[oss-security] 20091204 CVE-2009-4020 kernel: hfs buffer overflow","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2009/12/04/1"},{"name":"oval:org.mitre.oval:def:6750","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6750"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=540736"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://userweb.kernel.org/~akpm/mmotm/broken-out/hfs-fix-a-potential-buffer-overflow.patch"},{"name":"SUSE-SA:2010:019","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00007.html"},{"name":"SUSE-SA:2010:023","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://www.novell.com/linux/security/advisories/2010_23_kernel.html"},{"name":"RHSA-2010:0095","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"https://rhn.redhat.com/errata/RHSA-2010-0095.html"},{"name":"39742","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/39742"},{"name":"SUSE-SA:2010:005","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00005.html"},{"name":"RHSA-2010:0046","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"https://rhn.redhat.com/errata/RHSA-2010-0046.html"},{"name":"DSA-2005","tags":["vendor-advisory","x_refsource_DEBIAN","x_transferred"],"url":"http://www.debian.org/security/2010/dsa-2005"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2009-12-04T00:00:00.000Z","descriptions":[{"lang":"en","value":"Stack-based buffer overflow in the hfs subsystem in the Linux kernel 2.6.32 allows remote attackers to have an unspecified impact via a crafted Hierarchical File System (HFS) filesystem, related to the hfs_readdir function in fs/hfs/dir.c."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-09-18T12:57:01.000Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"name":"[linux-mm-commits] 20091203 + hfs-fix-a-potential-buffer-overflow.patch added to -mm tree","tags":["mailing-list","x_refsource_MLIST"],"url":"http://marc.info/?l=linux-mm-commits&m=125987755823047&w=2"},{"name":"38276","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/38276"},{"name":"oval:org.mitre.oval:def:10091","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10091"},{"tags":["x_refsource_CONFIRM"],"url":"http://support.avaya.com/css/P8/documents/100073666"},{"name":"[oss-security] 20091204 CVE-2009-4020 kernel: hfs buffer overflow","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.openwall.com/lists/oss-security/2009/12/04/1"},{"name":"oval:org.mitre.oval:def:6750","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6750"},{"tags":["x_refsource_CONFIRM"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=540736"},{"tags":["x_refsource_CONFIRM"],"url":"http://userweb.kernel.org/~akpm/mmotm/broken-out/hfs-fix-a-potential-buffer-overflow.patch"},{"name":"SUSE-SA:2010:019","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2010-03/msg00007.html"},{"name":"SUSE-SA:2010:023","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://www.novell.com/linux/security/advisories/2010_23_kernel.html"},{"name":"RHSA-2010:0095","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"https://rhn.redhat.com/errata/RHSA-2010-0095.html"},{"name":"39742","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/39742"},{"name":"SUSE-SA:2010:005","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2010-01/msg00005.html"},{"name":"RHSA-2010:0046","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"https://rhn.redhat.com/errata/RHSA-2010-0046.html"},{"name":"DSA-2005","tags":["vendor-advisory","x_refsource_DEBIAN"],"url":"http://www.debian.org/security/2010/dsa-2005"}]}},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2009-4020","datePublished":"2009-12-04T21:00:00.000Z","dateReserved":"2009-11-20T00:00:00.000Z","dateUpdated":"2024-08-07T06:45:50.888Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2009-12-04 21:30:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-119","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:C","baseScore":7.8,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:2.6.32:*:*:*:*:*:*:*","matchCriteriaId":"46568A0D-F374-4DAB-9B64-FCC74A9AA07B"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2009","CveId":"4020","Ordinal":"1","Title":"CVE-2009-4020","CVE":"CVE-2009-4020","Year":"2009"},"notes":[{"CveYear":"2009","CveId":"4020","Ordinal":"1","NoteData":"Stack-based buffer overflow in the hfs subsystem in the Linux kernel 2.6.32 allows remote attackers to have an unspecified impact via a crafted Hierarchical File System (HFS) filesystem, related to the hfs_readdir function in fs/hfs/dir.c.","Type":"Description","Title":"CVE-2009-4020"},{"CveYear":"2009","CveId":"4020","Ordinal":"2","NoteData":"2009-12-04","Type":"Other","Title":"Published"},{"CveYear":"2009","CveId":"4020","Ordinal":"3","NoteData":"2017-09-18","Type":"Other","Title":"Modified"}]}}}