Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Openafs packages have been updated to 1.9.1 for various bugfixes, and added a fix for security vulnerability: There exist in the wild AFS3 clients that improperly construct access control lists which are then stored to directories via RXAFS_StoreACL . MGASA-2021-0509 - Updated openafs packages fix security vulnerability Publication date: 11 Nov 2021 URL: https://advisories.mageia.org/MGASA-2021-0509.html Type: security Affected Mageia releases: 8 CVE: CVE-2018-7168 Openafs packages have been updated to 1.9.1 for various bugfixes, and added a fix for security vulnerability: There exist in the wild AFS3 clients that improperly construct access control lists which are then stored to directories via RXAFS_StoreACL (opcode 134). These clients add negative access control entries (if any) to the normal rights list. As there is no method by which a fileserver can determine that the ACL is improperly constructed, the only method to defend the storage of broken ACLs is to identify clients that are known to properly construct ACLs by introducing a new RXAFS_StoreACL opcode (164) (CVE-2018-7168). Additionally the CellServDB has been updated to latest version and fixes for suppoorting kernel 5.14 and 5.15 series have been added. References: - https://bugs.mageia.org/show_bug.cgi?id=29639 - https://www.cve.org/CVERecord?id=CVE-2018-7168 SRPMS: - 8/core/openafs-1.9.1-1.mga8 . A significant security enhancement for Mageia has been released, targeting a vital flaw in access permissions within AFS3 client applications.. OpenAFS Security Update,Mageia Access Control Fix,Security Patch Mageia,OpenAFS Version 1.9.1. . LinuxSecurity.com Team
Update to security-release 1.8.5, adresses: * OPENAFS-SA-2019-001: Skip server OUT args on error * OPENAFS-SA-2019-002: Zero all server RPC args * OPENAFS-SA-2019-003: ubik: Avoid unlocked ubik_currentTrans deref . MGASA-2019-0383 - Updated openafs packages fix security vulnerabilities Publication date: 13 Dec 2019 URL: https://advisories.mageia.org/MGASA-2019-0383.html Type: security Affected Mageia releases: 7 Update to security-release 1.8.5, adresses: * OPENAFS-SA-2019-001: Skip server OUT args on error * OPENAFS-SA-2019-002: Zero all server RPC args * OPENAFS-SA-2019-003: ubik: Avoid unlocked ubik_currentTrans deref Update to official version 1.8.4: * support Linux-kernel 5.3 * Avoid non-dir ENOENT errors in afs_lookup * fix parsing of fileservers with -vlruthresh, etc. * other bugfixes References: - https://bugs.mageia.org/show_bug.cgi?id=25816 - https://openafs.org/pages/security/OPENAFS-SA-2019-001.txt - https://openafs.org/pages/security/OPENAFS-SA-2019-002.txt - https://openafs.org/pages/security/OPENAFS-SA-2019-003.txt - - http://openafs.org/dl/openafs/1.8.4/RELNOTES-1.8.4 - http://openafs.org/dl/openafs/1.8.5/RELNOTES-1.8.5 SRPMS: - 7/core/openafs-1.8.5-1.mga7 . OpenAFS security enhancements address vulnerabilities involving RPC configurations and server malfunctions on Mageia 7. Discover more details here.. Mageia Security Updates, OpenAFS Vulnerabilities, Mageia 7 Security. . LinuxSecurity.com Team
An update that contains security fixes can now be installed.. openSUSE Security Update: Recommended update for openafs ______________________________________________________________________________ Announcement ID: openSUSE-SU-2019:2607-1 Rating: moderate References: Affected Products: openSUSE Leap 15.1 ______________________________________________________________________________ An update that contains security fixes can now be installed. Description: This update for openafs fixes the following issues: Update to security-release 1.8.5, adresses: * OPENAFS-SA-2019-001: Skip server OUT args on error * OPENAFS-SA-2019-002: Zero all server RPC args * OPENAFS-SA-2019-003: ubik: Avoid unlocked ubik_currentTrans deref update to official version 1.8.4 * support Linux-kernel 5.3 * Avoid non-dir ENOENT errors in afs_lookup * fix parsing of fileservers with -vlruthresh, etc. * other bugfixes update to pre-release 1.8.4pre2 * fix builds for Linux-kernels 5.3 update to 1.8.3 - fix broken directory layout - allow crypt to be set/unset on startup of client update to pre-release 1.8.3pre1 * fix builds for Linux-kernels 4.20 and 5.0 * other fixes, see RELNOTES-1.8.3pre1 Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.1: zypper in -t patch openSUSE-2019-2607=1 Package List: - openSUSE Leap 15.1 (x86_64): openafs-1.8.5-lp151.2.3.1 openafs-authlibs-1.8.5-lp151.2.3.1 openafs-authlibs-debuginfo-1.8.5-lp151.2.3.1 openafs-authlibs-devel-1.8.5-lp151.2.3.1 openafs-client-1.8.5-lp151.2.3.1 openafs-client-debuginfo-1.8.5-lp151.2.3.1 openafs-debuginfo-1.8.5-lp151.2.3.1 openafs-debugsource-1.8.5-lp151.2.3.1 openafs-devel-1.8.5-lp151.2.3.1 openafs-devel-debuginfo-1.8.5-lp151.2.3.1 openafs-fuse_client-1.8.5-lp151.2.3.1 openafs-fuse_client-debuginfo-1.8.5-lp151.2.3.1 openafs-kernel-source-1.8.5-lp151.2.3.1 openafs-kmp-default-1.8.5_k4.12.14_lp151.28.32-lp151.2.3.1 openafs-kmp-default-debuginfo-1.8.5_k4.12.14_lp151.28.32-lp151.2.3.1 openafs-server-1.8.5-lp151.2.3.1 openafs-server-debuginfo-1.8.5-lp151.2.3.1 References: -- . This patch for Fedora addresses vulnerabilities in samba with a moderate impact, promoting better system security.. openSUSE Security Update, openafs, system security fixes, moderate severity updates. . LinuxSecurity.com Team
Several security vulnerabilities were discovered in OpenAFS, a distributed file system. CVE-2019-18601 . Package : openafs Version : 1.6.9-2+deb8u9 CVE ID : CVE-2019-18601 CVE-2019-18602 CVE-2019-18603 Debian Bug : 943587 Several security vulnerabilities were discovered in OpenAFS, a distributed file system. CVE-2019-18601 OpenAFS is prone to denial of service from unserialized data access because remote attackers can make a series of VOTE_Debug RPC calls to crash a database server within the SVOTE_Debug RPC handler. CVE-2019-18602 OpenAFS is prone to an information disclosure vulnerability because uninitialized scalars are sent over the network to a peer. CVE-2019-18603 OpenAFS is prone to information leakage upon certain error conditions because uninitialized RPC output variables are sent over the network to a peer. For Debian 8 "Jessie", these problems have been fixed in version 1.6.9-2+deb8u9. We recommend that you upgrade your openafs packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . The latest OpenAFS update rectifies vulnerabilities related to denial of service and information exposure in Debian 8, incorporating numerous security enhancements.. OpenAFS Security Update, Debian LTS, Denial Of Service, Information Disclosure. . Severity: Critical. LinuxSecurity.com Team
Jeffrey Altman reported that the backup tape controller (butc) process does accept incoming RPCs but does not require (or allow for) authentication of those RPCs, allowing an unauthenticated attacker to perform volume operations with administrator credentials (CVE-2018-16947). . MGASA-2019-0021 - Updated openafs packages fix security vulnerabilities Publication date: 08 Jan 2019 URL: https://advisories.mageia.org/MGASA-2019-0021.html Type: security Affected Mageia releases: 6 CVE: CVE-2018-16947, CVE-2018-16948, CVE-2018-16949 Jeffrey Altman reported that the backup tape controller (butc) process does accept incoming RPCs but does not require (or allow for) authentication of those RPCs, allowing an unauthenticated attacker to perform volume operations with administrator credentials (CVE-2018-16947). Mark Vitale reported that several RPC server routines do not fully initialize output variables, leaking memory contents (from both the stack and the heap) to the remote caller for otherwise-successful RPCs (CVE-2018-16948). Mark Vitale reported that an unauthenticated attacker can consume large amounts of server memory and network bandwidth via specially crafted requests, resulting in denial of service to legitimate clients (CVE-2018-16949). References: - https://bugs.mageia.org/show_bug.cgi?id=23663 - https://openafs.org/pages/security/OPENAFS-SA-2018-001.txt - https://openafs.org/pages/security/OPENAFS-SA-2018-002.txt - https://openafs.org/pages/security/OPENAFS-SA-2018-003.txt - http://openafs.org/dl/openafs/1.6.23/RELNOTES-1.6.23 - https://lists.debian.org/debian-security-announce/2018/msg00233.html - https://www.cve.org/CVERecord?id=CVE-2018-16947 - https://www.cve.org/CVERecord?id=CVE-2018-16948 - https://www.cve.org/CVERecord?id=CVE-2018-16949 SRPMS: - 6/core/openafs-1.6.23-1.mga6 . MGASA-2019-0021 - Updated openafs packages fix security vulnerabilities Publication date: 08 Jan 201. jeffrey, altman, reported, backup, controller, (butc), process, accept, incoming. . Severity: Critical.LinuxSecurity.com Team
Several vulnerabilities were discovered in openafs, an implementation of the distributed filesystem AFS. The Common Vulnerabilities and Exposures project identifies the following problems: . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4302-1
Moderate: openafs security and enhancement update . Date: Tue, 13 Dec 2016 16:02:09 +0000 Reply-To: Scott Reid Sender: Security Errata for Scientific Linux From: Scott Reid Subject: FASTBUGS for SL 6x i386, x86_64 now available Comments: To: scientific-linux-errata MIME-Version: 1.0 Message-ID: --_000_D475779F33B8Csvreidfnalgov_ The following FASTBUGS have been uploaded to i386: 6x/i386/chrony-2.1.1-2.el6_8.i686.rpm x86_64: 6x/x86_64/chrony-2.1.1-2.el6_8.x86_64.rpm --_000_D475779F33B8Csvreidfnalgov_ 6x/i386/chrony-2.1.1-2.el6_8.i686.rpm 6x/x86_64/chrony-2.1.1-2.el6_8.x86_64.rpm --_000_D475779F33B8Csvreidfnalgov_-- Date: Wed, 14 Dec 2016 17:38:25 +0000 Reply-To: Scott Reid Sender: Security Errata for Scientific Linux From: Scott Reid Subject: Security ERRATA Moderate: OpenAFS on SL5.x, SL6.x, SL7.x i386/x86_64 Comments: To: scientific-linux-errata MIME-Version: 1.0 Message-ID: --_000_D476DFB033EA1svreidfnalgov_ Synopsis: Moderate: openafs security and enhancement update Advisory ID: OPENAFS-SA-2016-003 Issue Date: 2016-12-14 -- Security Fix(es): There are three different kinds of "dead" residual directory entry leaks, each with a different cause: 1. There may be partial name data after the null terminator in a live directory entry. This happens when a previously used directory entry becomes free, then is reused for a directory entry with a shorter name. 2. "Dead" directory entries are left uncleared after an object is deleted or renamed. 3. Residual directory entries may be inadvertently picked up when a new directory is created or an existing directory is extended by a 2kiB page. This happens because the fileserver shares a buffer pool for directories of all AFS users, but does not clear each buffer upon reuse. This is the most severe problembecause the leaked information may be from other directories or volumes for which the AFS user is not authorized. SL5 packages feature a backported patch to the vulnerable code. Enhancement(s): * OpenAFS on SL6 and SL7 has been rebased to1.6.20 -- SL5 x86_64 kernel-module-openafs-2.6.18-416.el5-1.4.15-90.sl5.x86_64.rpm kernel-module-openafs-2.6.18-416.el5xen-1.4.15-90.sl5.x86_64.rpm openafs-1.4.15-90.sl5.x86_64.rpm openafs-authlibs-1.4.15-90.sl5.x86_64.rpm openafs-authlibs-devel-1.4.15-90.sl5.x86_64.rpm openafs-client-1.4.15-90.sl5.x86_64.rpm openafs-compat-1.4.15-90.sl5.x86_64.rpm openafs-debug-1.4.15-90.sl5.x86_64.rpm openafs-devel-1.4.15-90.sl5.x86_64.rpm openafs-kernel-source-1.4.15-90.sl5.x86_64.rpm openafs-kpasswd-1.4.15-90.sl5.x86_64.rpm openafs-krb5-1.4.15-90.sl5.x86_64.rpm openafs-server-1.4.15-90.sl5.x86_64.rpm i386 kernel-module-openafs-2.6.18-416.el5-1.4.15-90.sl5.i686.rpm kernel-module-openafs-2.6.18-416.el5PAE-1.4.15-90.sl5.i686.rpm kernel-module-openafs-2.6.18-416.el5xen-1.4.15-90.sl5.i686.rpm openafs-1.4.15-90.sl5.i386.rpm openafs-authlibs-1.4.15-90.sl5.i386.rpm openafs-authlibs-devel-1.4.15-90.sl5.i386.rpm openafs-client-1.4.15-90.sl5.i386.rpm openafs-compat-1.4.15-90.sl5.i386.rpm openafs-debug-1.4.15-90.sl5.i386.rpm openafs-devel-1.4.15-90.sl5.i386.rpm openafs-kernel-source-1.4.15-90.sl5.i386.rpm openafs-kpasswd-1.4.15-90.sl5.i386.rpm openafs-krb5-1.4.15-90.sl5.i386.rpm openafs-server-1.4.15-90.sl5.i386.rpm SL6 x86_64 kmod-openafs-642-1.6.20-256.sl6.642.6.2.x86_64.rpm openafs-1.6.20-256.sl6.x86_64.rpm openafs-authlibs-1.6.20-256.sl6.x86_64.rpm openafs-authlibs-devel-1.6.20-256.sl6.x86_64.rpm openafs-client-1.6.20-256.sl6.x86_64.rpm openafs-compat-1.6.20-256.sl6.x86_64.rpm openafs-devel-1.6.20-256.sl6.x86_64.rpm openafs-kernel-source-1.6.20-256.sl6.x86_64.rpm openafs-kpasswd-1.6.20-256.sl6.x86_64.rpm openafs-krb5-1.6.20-256.sl6.x86_64.rpm openafs-module-tools-1.6.20-256.sl6.x86_64.rpm openafs-plumbing-tools-1.6.20-256.sl6.x86_64.rpm openafs-server-1.6.20-256.sl6.x86_64.rpm i386 kmod-openafs-642-1.6.20-256.sl6.642.6.2.i686.rpm openafs-1.6.20-256.sl6.i686.rpm openafs-authlibs-1.6.20-256.sl6.i686.rpm openafs-authlibs-devel-1.6.20-256.sl6.i686.rpm openafs-client-1.6.20-256.sl6.i686.rpm openafs-compat-1.6.20-256.sl6.i686.rpm openafs-devel-1.6.20-256.sl6.i686.rpm openafs-kernel-source-1.6.20-256.sl6.i686.rpm openafs-kpasswd-1.6.20-256.sl6.i686.rpm openafs-krb5-1.6.20-256.sl6.i686.rpm openafs-module-tools-1.6.20-256.sl6.i686.rpm openafs-plumbing-tools-1.6.20-256.sl6.i686.rpm openafs-server-1.6.20-256.sl6.i686.rpm SL7 x86_64 kmod-openafs-1.6-sl-514-1.6.20-256.7.514.x86_64.rpm openafs-1.6-sl-1.6.20-256.7.x86_64.rpm openafs-1.6-sl-authlibs-1.6.20-256.7.x86_64.rpm openafs-1.6-sl-authlibs-devel-1.6.20-256.7.x86_64.rpm openafs-1.6-sl-client-1.6.20-256.7.x86_64.rpm openafs-1.6-sl-compat-1.6.20-256.7.x86_64.rpm openafs-1.6-sl-devel-1.6.20-256.7.x86_64.rpm openafs-1.6-sl-kernel-source-1.6.20-256.7.x86_64.rpm openafs-1.6-sl-kpasswd-1.6.20-256.7.x86_64.rpm openafs-1.6-sl-krb5-1.6.20-256.7.x86_64.rpm openafs-1.6-sl-module-tools-1.6.20-256.7.x86_64.rpm openafs-1.6-sl-plumbing-tools-1.6.20-256.7.x86_64.rpm openafs-1.6-sl-server-1.6.20-256.7.x86_64.rpm - Scientific Linux Development Team --_000_D476DFB033EA1svreidfnalgov_ Issue Date: 2016-12-14 There are three different kinds of "dead" residual directory entry
Two vulnerabilities were discovered in openafs, an implementation of the distributed filesystem AFS. The Common Vulnerabilities and Exposures project identifies the following problems: . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3569-1
Get the latest Linux and open source security news straight to your inbox.