cvedb.io
CVE-2018-16948
HIGH · CVSS 7.5
EPSS exploitation probability: 0%
Published 2018-09-12T01:29:00.517 · Last modified 2026-06-17T01:45:06.417

Summary

An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2. Several RPC server routines did not fully initialize their output variables before returning, leaking memory contents from both the stack and the heap. Because the OpenAFS cache manager functions as an Rx server for the AFSCB service, clients are also susceptible to information leakage. For example, RXAFSCB_TellMeAboutYourself leaks kernel memory and KAM_ListEntry leaks kaserver memory.

Affected products

openafs — openafs

Does this affect you?

Add your gear to cvedb and we'll alert you only when openafs ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.