CVE-2024-10397

Severity CVSS v4.0:
HIGH
Type:
CWE-787 Out-of-bounds Write
Publication date:
14/11/2024
Last modified:
23/12/2025

Description

A malicious server can crash the OpenAFS cache manager and other client utilities, and possibly execute arbitrary code.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:openafs:openafs:*:*:*:*:*:*:*:* 1.0 (including) 1.6.25 (excluding)
cpe:2.3:a:openafs:openafs:*:*:*:*:*:*:*:* 1.8.0 (including) 1.8.13 (excluding)
cpe:2.3:a:openafs:openafs:1.9.0:*:*:*:*:*:*:*