CVE-2007-6599
published 2008-01-04CVE-2007-6599: Race condition in fileserver in OpenAFS 1.3.50 through 1.4.5 and 1.5.0 through 1.5.27 allows remote attackers to cause a denial of service (daemon crash) by…
PriorityP415medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
1.66%
74.2th percentile
Race condition in fileserver in OpenAFS 1.3.50 through 1.4.5 and 1.5.0 through 1.5.27 allows remote attackers to cause a denial of service (daemon crash) by simultaneously acquiring and giving back file callbacks, which causes the handler for the GiveUpAllCallBacks RPC to perform linked-list operations without the host_glock lock.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | openafs | < openafs 1.4.6.dfsg1-1 (bookworm) | openafs 1.4.6.dfsg1-1 (bookworm) |
| openafs | openafs | >= 0 < 1.4.6.dfsg1-1 | 1.4.6.dfsg1-1 |
| openafs | openafs | >= 0 < 1.4.6.dfsg1-1 | 1.4.6.dfsg1-1 |
| openafs | openafs | >= 0 < 1.4.6.dfsg1-1 | 1.4.6.dfsg1-1 |
| openafs | openafs | 1.3.50 – 1.4.5 | — |
| openafs | openafs | 1.5.0 – 1.5.27 | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_debian4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q3ff-m98v-rj6m: Race condition in fileserver in OpenAFS 1
ghsa_unreviewed·2022-05-01
CVE-2007-6599 [MEDIUM] CWE-362 GHSA-q3ff-m98v-rj6m: Race condition in fileserver in OpenAFS 1
Race condition in fileserver in OpenAFS 1.3.50 through 1.4.5 and 1.5.0 through 1.5.27 allows remote attackers to cause a denial of service (daemon crash) by simultaneously acquiring and giving back file callbacks, which causes the handler for the GiveUpAllCallBacks RPC to perform linked-list operations without the host_glock lock.
OSV
CVE-2007-6599: Race condition in fileserver in OpenAFS 1
osv·2008-01-04·CVSS 4.3
CVE-2007-6599 [MEDIUM] CVE-2007-6599: Race condition in fileserver in OpenAFS 1
Race condition in fileserver in OpenAFS 1.3.50 through 1.4.5 and 1.5.0 through 1.5.27 allows remote attackers to cause a denial of service (daemon crash) by simultaneously acquiring and giving back file callbacks, which causes the handler for the GiveUpAllCallBacks RPC to perform linked-list operations without the host_glock lock.
Debian
CVE-2007-6599: openafs - Race condition in fileserver in OpenAFS 1.3.50 through 1.4.5 and 1.5.0 through 1...
vendor_debian·2007·CVSS 4.3
CVE-2007-6599 [MEDIUM] CVE-2007-6599: openafs - Race condition in fileserver in OpenAFS 1.3.50 through 1.4.5 and 1.5.0 through 1...
Race condition in fileserver in OpenAFS 1.3.50 through 1.4.5 and 1.5.0 through 1.5.27 allows remote attackers to cause a denial of service (daemon crash) by simultaneously acquiring and giving back file callbacks, which causes the handler for the GiveUpAllCallBacks RPC to perform linked-list operations without the host_glock lock.
Scope: local
bookworm: resolved (fixed in 1.4.6.dfsg1-1)
bullseye: resolved (fixed in 1.4.6.dfsg1-1)
sid: resolved (fixed in 1.4.6.dfsg1-1)
trixie: resolved (fixed in 1.4.6.dfsg1-1)
No detection rules found.
No public exploits indexed.
http://lists.openafs.org/pipermail/openafs-announce/2007/000220.htmlhttp://secunia.com/advisories/28327http://secunia.com/advisories/28401http://secunia.com/advisories/28433http://secunia.com/advisories/28636http://security.gentoo.org/glsa/glsa-200801-04.xmlhttp://www.debian.org/security/2008/dsa-1458http://www.mandriva.com/security/advisories?name=MDVSA-2008:207http://www.novell.com/linux/security/advisories/suse_security_summary_report.htmlhttp://www.openafs.org/security/OPENAFS-SA-2007-003.txthttp://www.securityfocus.com/bid/27132http://www.vupen.com/english/advisories/2008/0046http://lists.openafs.org/pipermail/openafs-announce/2007/000220.htmlhttp://secunia.com/advisories/28327http://secunia.com/advisories/28401http://secunia.com/advisories/28433http://secunia.com/advisories/28636http://security.gentoo.org/glsa/glsa-200801-04.xmlhttp://www.debian.org/security/2008/dsa-1458http://www.mandriva.com/security/advisories?name=MDVSA-2008:207http://www.novell.com/linux/security/advisories/suse_security_summary_report.htmlhttp://www.openafs.org/security/OPENAFS-SA-2007-003.txthttp://www.securityfocus.com/bid/27132http://www.vupen.com/english/advisories/2008/0046
2008-01-04
Published