CVE-2024-43688: OpenBSD

High severity, CVSS 7.3. EPSS: 0.5% chance of exploitation in the next 30 days.

cron/entry.c in vixie cron before 9cc8ab1, as used in OpenBSD 7.4 and 7.5, allows a heap-based buffer underflow and memory corruption. NOTE: this issue was introduced during a May 2023 refactoring.

Affected products

  • OpenBSD OpenBSD: version 7.4 only; version 7.5 only
  • Vixie Cron: before 9cc8ab1 (fixed in 9cc8ab1)

Published 2024-08-20. Last modified 2026-06-17.