CVE-2024-10934

CRITICAL

Openbsd < 7.4 - Double Free

Title source: rule

Description

In OpenBSD 7.5 before errata 008 and OpenBSD 7.4 before errata 021, avoid possible mbuf double free in NFS client and server implementation, do not use uninitialized variable in error handling of NFS server.

Scores

CVSS v3 9.8
EPSS 0.0027
EPSS Percentile 50.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-415 CWE-457
Status published

Affected Products (30)

openbsd/openbsd < 7.4
openbsd/openbsd
openbsd/openbsd
openbsd/openbsd
openbsd/openbsd
openbsd/openbsd
openbsd/openbsd
openbsd/openbsd
openbsd/openbsd
openbsd/openbsd
openbsd/openbsd
openbsd/openbsd
openbsd/openbsd
openbsd/openbsd
openbsd/openbsd
... and 15 more

Timeline

Published Nov 15, 2024
Tracked Since Feb 18, 2026