CVE-2024-10396

An authenticated user can provide a malformed ACL to the fileserver's StoreACL
RPC, causing the fileserver to crash, possibly expose uninitialized memory, and
possibly store garbage data in the audit log.
Malformed ACLs provided in responses to client FetchACL RPCs can cause client
processes to crash and possibly expose uninitialized memory into other ACLs
stored on the server.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
UNKNOWN
---
fedoraCNA
---
---
CISA-ADPADP
---
---
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 36%
Debian logo
Debian Releases
Debian Product
Codename
openafs
bullseye
vulnerable
bullseye (security)
1.8.6-5+deb11u1
fixed
bookworm
1.8.9-1+deb12u1
fixed
bookworm (security)
1.8.9-1+deb12u1
fixed
sid
1.8.13.2-1
fixed
trixie
1.8.13.2-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
openafs
plucky
not-affected
oracular
needs-triage
noble
needs-triage
jammy
needs-triage
focal
needs-triage
bionic
needs-triage
xenial
needs-triage