CVE-2024-10394: Openafs
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
A local user can bypass the OpenAFS PAG (Process Authentication Group) throttling mechanism in Unix clients, allowing the user to create a PAG using an existing id number, effectively joining the PAG and letting the user steal the credentials in that PAG.
Affected products
- Openafs Openafs: from 1.0, before 1.6.25 (fixed in 1.6.25); from 1.8.0, before 1.8.13 (fixed in 1.8.13); version 1.9.0 only
Published 2024-11-14. Last modified 2026-06-17.