CVE-2024-10224: Debian Linux

High severity, CVSS 7.8. EPSS: 9% chance of exploitation in the next 30 days.

Qualys discovered that if unsanitized input was used with the library Modules::ScanDeps, before version 1.36 a local attacker could possibly execute arbitrary shell commands by open()ing a "pesky pipe" (such as passing "commands|" as a filename) or by passing arbitrary strings to eval().

Affected products

  • Debian Debian Linux: version 11.0 only
  • Rschupp Modules::scandeps: before 1.36 (fixed in 1.36)

Published 2024-11-19. Last modified 2026-06-17.