CVE-2024-10397: Openafs

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

A malicious server can crash the OpenAFS cache manager and other client utilities, and possibly execute arbitrary code.

Affected products

  • Openafs Openafs: from 1.0, before 1.6.25 (fixed in 1.6.25); from 1.8.0, before 1.8.13 (fixed in 1.8.13); version 1.9.0 only

Published 2024-11-14. Last modified 2026-06-17.