CVE-2024-10397: Preallocated buffer overflows in XDR responses
A malicious server can crash the OpenAFS cache manager and other client utilities, and possibly execute arbitrary code.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10397?
CVE-2024-10397 is classified with high severity due to its potential to crash the OpenAFS cache manager and execute arbitrary code.
How do I fix CVE-2024-10397?
To mitigate CVE-2024-10397, update your OpenAFS installation to version 1.9.1 or higher, as these versions include patches for the vulnerability.
What software is affected by CVE-2024-10397?
CVE-2024-10397 affects OpenAFS versions from 1.0 up to 1.6.25, and from 1.8.0 up to 1.8.13, as well as version 1.9.0.
What are the risks associated with CVE-2024-10397?
The primary risk of CVE-2024-10397 is the capability of a malicious server to crash client utilities and potentially execute arbitrary code.
Is there a workaround for CVE-2024-10397?
Currently, the only effective workaround for CVE-2024-10397 is to update to a patched version of OpenAFS.