cbcvebase.
CVE-2007-6599
published 2008-01-04

CVE-2007-6599: Race condition in fileserver in OpenAFS 1.3.50 through 1.4.5 and 1.5.0 through 1.5.27 allows remote attackers to cause a denial of service (daemon crash) by…

PriorityP415medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
1.66%
74.2th percentile
Race condition in fileserver in OpenAFS 1.3.50 through 1.4.5 and 1.5.0 through 1.5.27 allows remote attackers to cause a denial of service (daemon crash) by simultaneously acquiring and giving back file callbacks, which causes the handler for the GiveUpAllCallBacks RPC to perform linked-list operations without the host_glock lock.

Affected

8 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianopenafs< openafs 1.4.6.dfsg1-1 (bookworm)openafs 1.4.6.dfsg1-1 (bookworm)
openafsopenafs>= 0 < 1.4.6.dfsg1-11.4.6.dfsg1-1
openafsopenafs>= 0 < 1.4.6.dfsg1-11.4.6.dfsg1-1
openafsopenafs>= 0 < 1.4.6.dfsg1-11.4.6.dfsg1-1
openafsopenafs1.3.50 – 1.4.5
openafsopenafs1.5.0 – 1.5.27

CVSS provenance

nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_debian4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.