CVE-2019-18602: Debian Linux

High severity, CVSS 7.5. EPSS: 1.5% chance of exploitation in the next 30 days.

OpenAFS before 1.6.24 and 1.8.x before 1.8.5 is prone to an information disclosure vulnerability because uninitialized scalars are sent over the network to a peer.

Affected products

  • Debian Debian Linux: version 8.0 only
  • Openafs Openafs: before 1.6.24 (fixed in 1.6.24); from 1.8.0, before 1.8.5 (fixed in 1.8.5)

Published 2019-10-29. Last modified 2026-06-17.