Resource exhaustion in OpenAFS - CVE-2018-16949
Published: January 1, 2019
OpenAFS
Detailed vulnerability description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to several data types used as RPC input variables were implemented as unbounded array types, limited only by the inherent 32-bit length field to 4 GB. A remote attacker can send, or claim to send, large input values, trigger resource exhaustion and perform a denial of service (DoS) attack.