CVE-2024-10394

Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
14/11/2024
Last modified:
23/12/2025

Description

A local user can bypass the OpenAFS PAG (Process Authentication Group) throttling mechanism in Unix clients, allowing the user to create a PAG using an existing id number, effectively joining the PAG and letting the user steal the credentials in that PAG.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:openafs:openafs:*:*:*:*:*:*:*:* 1.0 (including) 1.6.25 (excluding)
cpe:2.3:a:openafs:openafs:*:*:*:*:*:*:*:* 1.8.0 (including) 1.8.13 (excluding)
cpe:2.3:a:openafs:openafs:1.9.0:*:*:*:*:*:*:*