CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2024-10934

CVSS 9.2v4.0pub. 2024-11-15upd. 2025-10-02

In OpenBSD 7.5 before errata 008 and OpenBSD 7.4 before errata 021, avoid possible mbuf double free in NFS client and server implementation, do not use uninitialized variable in error handling of NFS server.

🤖 AI Analysis
How it works

The first vulnerability (CWE-415) consists of the possibility of freeing the same memory area twice (mbuf double free) in the NFS client and server code, which can lead to heap corruption. The second vulnerability (CWE-457) concerns the use of an uninitialized variable in the error handling path on the NFS server side, which can result in unpredictable system behavior or disclosure of data from memory. Both vulnerabilities are available to a network attacker without the need for authentication.

Impact

An attacker can lead to unauthorized code execution (RCE), system suspension or crash, and potentially read or modify data in the operating memory of the NFS server or client.

Mitigation & patch

Official manufacturer errata should be applied: for OpenBSD 7.5 — errata 008 (patch available at https://ftp.openbsd.org/pub/OpenBSD/patches/7.5/common/008_nfs.patch.sig), for OpenBSD 7.4 — errata 021 (patch available at https://ftp.openbsd.org/pub/OpenBSD/patches/7.4/common/021_nfs.patch.sig). Until the patch is deployed, it is recommended to restrict access to NFS services at the firewall level.

Who is affected

OpenBSD 7.5 before errata 008 and OpenBSD 7.4 before errata 021 — systems operating as NFS client or server.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:X/U:X
  • Openbsd

    OS
    Openbsd
    7.47.5< 7.4
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2024-29937CRITICAL9.8PL ✓same product

RCE w implementacji NFS w OpenBSD i FreeBSD — zdalne wykonanie kodu

CVE-2023-35784CRITICAL9.8PL ✓same product

Double free / use-after-free w LibreSSL i OpenBSD po wywołaniu SSL_clear

CVE-2021-46880CRITICAL9.8PL ✓same product

Authentication bypass przez odrzucanie błędów weryfikacji certyfikatów w LibreSSL/OpenBSD

CVE-2020-16088CRITICAL9.8PL ✓same product

OpenIKED: pominięcie uwierzytelnienia przez błędną weryfikację klucza publicznego

CVE-2012-1577CRITICAL9.8PL ✓same product

OpenBSD/dietlibc: generator liczb losowych zwraca 0 przy seedzie 0