Advisories ยป MGASA-2025-0013

Updated openafs packages fix security vulnerabilities

Publication date: 18 Jan 2025
Modification date: 18 Jan 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2024-10394 , CVE-2024-10396 , CVE-2024-10397

Description

A local user can bypass the OpenAFS PAG (Process Authentication Group)
throttling mechanism in Unix client. (CVE-2024-10394)
An authenticated user can provide a malformed ACL to the fileserver's
StoreACL RPC, causing the fileserver to crash. (CVE-2024-10396)
A malicious server can crash the OpenAFS cache manager and other client
utilities, and possibly execute arbitrary code. (CVE-2024-10397)
                

References

SRPMS

9/core