In OpenAFS before 1.6.17, users from foreign Kerberos realms can create groups as if they were administrators (CVE-2016-2860).
In OpenAFS before 1.6.17, information leakage over the network due to uninitialized memory (CVE-2016-4536).
{ "section": "core" }
"https://advisories.mageia.org/MGASA-2016-0121.json"