CVE-2024-10396

An authenticated user can provide a malformed ACL to the fileserver's StoreACL RPC, causing the fileserver to crash, possibly expose uninitialized memory, and possibly store garbage data in the audit log. Malformed ACLs provided in responses to client FetchACL RPCs can cause client processes to crash and possibly expose uninitialized memory into other ACLsstored on the server.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
fedoraCNA
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CISA-ADPADP
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 40%
VendorProductVersion
openafsopenafs
1.0 ≤
𝑥
< 1.6.25
openafsopenafs
1.8.0 ≤
𝑥
< 1.8.13
openafsopenafs
1.9.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
openafs
bullseye
vulnerable
bullseye (security)
1.8.6-5+deb11u2
fixed
bookworm
1.8.9-1+deb12u1
fixed
bookworm (security)
1.8.9-1+deb12u1
fixed
trixie
1.8.13.2-1
fixed
sid
1.8.14-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
openafs
questing
not-affected
plucky
not-affected
oracular
ignored
noble
needs-triage
jammy
needs-triage
focal
needs-triage
bionic
needs-triage
xenial
needs-triage