VDB

GCVE-110-MAGEIA-2025-13

GCVE-110-MAGEIA-2025-13
Advisory Published
Vulnetix · Advisory published January 18, 2025
A local user can bypass the OpenAFS PAG (Process Authentication Group) throttling mechanism in Unix client. (CVE-2024-10394) An authenticated user can provide a malformed ACL to the fileserver's StoreACL RPC, causing the fileserver to crash. (CVE-2024-10396) A malicious server can crash the OpenAFS cache manager and other client utilities, and possibly execute arbitrary code. (CVE-2024-10397)

Affected Products

VendorProductVersionsPlatforms
Mageiaopenafs0 (affected), 1.8.13.1-1.mga9 (unaffected), 0 (affected), 1.8.13.1-1.mga9 (unaffected)
Mageiaxapps2.6.1-1.1.mga9 (unaffected), 0 (affected)
Mageiaxviewer3.2.11-1.1.mga9 (unaffected), 0 (affected)

Browse GCVE Records

74,299 records in the GCVE database · Updated July 22, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›