← Back to CVEs
CVE-2024-10934
CRITICAL9.8
Description
In OpenBSD 7.5 before errata 008 and OpenBSD 7.4 before errata 021, avoid possible mbuf double free in NFS client and server implementation, do not use uninitialized variable in error handling of NFS server.
CVE Details
CVSS v3.1 Score9.8
SeverityCRITICAL
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
Published11/15/2024
Last Modified10/2/2025
Sourcenvd
Honeypot Sightings0
Affected Products
openbsd:openbsd
Weaknesses (CWE)
CWE-415CWE-457
References
https://ftp.openbsd.org/pub/OpenBSD/patches/7.4/common/021_nfs.patch.sig(9119a7d8-5eab-497f-8521-727c672e3725)
https://ftp.openbsd.org/pub/OpenBSD/patches/7.5/common/008_nfs.patch.sig(9119a7d8-5eab-497f-8521-727c672e3725)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.