9.8

CVE-2024-10934

In OpenBSD 7.5 before errata 008 and OpenBSD 7.4 before errata 021, 
avoid possible mbuf double free in NFS client and server implementation, do not use uninitialized variable in error handling of NFS server.

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users.
Data is provided by the National Vulnerability Database (NVD)
OpenbsdOpenbsd Version < 7.4
OpenbsdOpenbsd Version7.4 Update-
OpenbsdOpenbsd Version7.4 Updateerrata_001
OpenbsdOpenbsd Version7.4 Updateerrata_002
OpenbsdOpenbsd Version7.4 Updateerrata_003
OpenbsdOpenbsd Version7.4 Updateerrata_004
OpenbsdOpenbsd Version7.4 Updateerrata_005
OpenbsdOpenbsd Version7.4 Updateerrata_006
OpenbsdOpenbsd Version7.4 Updateerrata_007
OpenbsdOpenbsd Version7.4 Updateerrata_008
OpenbsdOpenbsd Version7.4 Updateerrata_009
OpenbsdOpenbsd Version7.4 Updateerrata_010
OpenbsdOpenbsd Version7.4 Updateerrata_011
OpenbsdOpenbsd Version7.4 Updateerrata_012
OpenbsdOpenbsd Version7.4 Updateerrata_013
OpenbsdOpenbsd Version7.4 Updateerrata_014
OpenbsdOpenbsd Version7.4 Updateerrata_015
OpenbsdOpenbsd Version7.4 Updateerrata_016
OpenbsdOpenbsd Version7.4 Updateerrata_017
OpenbsdOpenbsd Version7.4 Updateerrata_018
OpenbsdOpenbsd Version7.4 Updateerrata_019
OpenbsdOpenbsd Version7.4 Updateerrata_020
OpenbsdOpenbsd Version7.5 Update-
OpenbsdOpenbsd Version7.5 Updateerrata_001
OpenbsdOpenbsd Version7.5 Updateerrata_002
OpenbsdOpenbsd Version7.5 Updateerrata_003
OpenbsdOpenbsd Version7.5 Updateerrata_004
OpenbsdOpenbsd Version7.5 Updateerrata_005
OpenbsdOpenbsd Version7.5 Updateerrata_006
OpenbsdOpenbsd Version7.5 Updateerrata_007
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.24% 0.465
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
9119a7d8-5eab-497f-8521-727c672e3725 9.2 0 0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:X/U:X
9119a7d8-5eab-497f-8521-727c672e3725 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-415 Double Free

The product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations.

CWE-457 Use of Uninitialized Variable

The code uses a variable that has not been initialized, leading to unpredictable or unintended results.