Please read the updated section of the original story, "the second attack does NOT generate an infinite loop within the btrfs code, but merely within the bash expansion code which is responsible to expand the command line rm *."
Posted Dec 18, 2012 15:08 UTC (Tue) by butlerm (subscriber, #13312)
[Link]
Thanks. So in other words, the first problem might possibly be hit in practice, and really ought to be fixed soon, but the second problem isn't likely to yield any real world consequences unless an attacker is in a position to generate tens of thousands of files with names that all hash to the same value. No?