← back
CVE-2024-10934

OpenBSD NFS double-free vulnerability

CVSS 9.2 CRITICALEPSS 0.4%CWE-415CWE-457
In OpenBSD 7.5 before errata 008 and OpenBSD 7.4 before errata 021, avoid possible mbuf double free in NFS client and server implementation, do not use uninitialized variable in error handling of NFS server.
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/AU:Y
Affected products
OpenBSD · OpenBSD

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →