From 0e7d833675df354e81fdad717cc9192dd7dcc151 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 22 Aug 2024 15:32:59 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-6r3r-qjm5-8fvp.json | 9 +++-- .../GHSA-cwf3-fx63-9w5f.json | 9 +++-- .../GHSA-j6qv-9fc5-fqqg.json | 11 ++++-- .../GHSA-mp67-wx57-8m4f.json | 11 ++++-- .../GHSA-xcvq-77qq-2wpx.json | 2 +- .../GHSA-wpv3-6qr5-9rmx.json | 9 +++-- .../GHSA-22g9-jc7j-7rgj.json | 11 ++++-- .../GHSA-2qvq-p8h3-vf5j.json | 11 ++++-- .../GHSA-2wm2-45c2-f92h.json | 1 + .../GHSA-4f32-8hqj-hvcg.json | 9 +++-- .../GHSA-54p6-r4cp-p6qq.json | 9 +++-- .../GHSA-79hg-h6r6-64mm.json | 6 ++- .../GHSA-7f9h-6jq6-8gmx.json | 11 ++++-- .../GHSA-7x54-v488-56pj.json | 11 ++++-- .../GHSA-95g8-7cpf-mp2q.json | 11 ++++-- .../GHSA-hxr9-q428-7jhg.json | 11 ++++-- .../GHSA-jh57-6wf8-c6gg.json | 11 ++++-- .../GHSA-p776-rxgv-h888.json | 11 ++++-- .../GHSA-pc3q-4rr7-6vrq.json | 11 ++++-- .../GHSA-q423-q7jg-m3rq.json | 11 ++++-- .../GHSA-q935-8vhv-gg93.json | 11 ++++-- .../GHSA-rqqp-4vhv-fqrg.json | 11 ++++-- .../GHSA-wccc-2qv8-6647.json | 11 ++++-- .../GHSA-28c6-pjxj-5qxg.json | 3 +- .../GHSA-2xmp-f94r-wqm9.json | 2 +- .../GHSA-36c7-h45p-9hch.json | 39 +++++++++++++++++++ .../GHSA-3fc7-hxmq-f35p.json | 11 ++++-- .../GHSA-45wm-mg4w-2536.json | 11 ++++-- .../GHSA-482h-w5qp-gfxw.json | 11 ++++-- .../GHSA-4wrj-qhhf-3c55.json | 9 +++-- .../GHSA-57cq-jgq2-x7vg.json | 12 ++++-- .../GHSA-5wm9-5344-qrrj.json | 2 +- .../GHSA-7fgx-pmw9-49h5.json | 1 + .../GHSA-7r79-ppgg-4h8m.json | 39 +++++++++++++++++++ .../GHSA-gqg7-4h7v-f4hf.json | 3 +- .../GHSA-jqxg-gg5c-r85j.json | 11 ++++-- .../GHSA-mchm-hhh8-w57p.json | 39 +++++++++++++++++++ .../GHSA-pq5w-h3jm-m95c.json | 9 +++-- .../GHSA-qgv4-x6mv-vh78.json | 39 +++++++++++++++++++ .../GHSA-rq5p-j687-h2vf.json | 39 +++++++++++++++++++ .../GHSA-w4h5-9mg2-vv6r.json | 9 ++++- .../GHSA-wcph-x6mx-4gh6.json | 11 ++++-- .../GHSA-x38q-hvmx-rwhg.json | 11 ++++-- .../GHSA-x7fm-xq4g-7h9j.json | 39 +++++++++++++++++++ 44 files changed, 452 insertions(+), 117 deletions(-) create mode 100644 advisories/unreviewed/2024/08/GHSA-36c7-h45p-9hch/GHSA-36c7-h45p-9hch.json create mode 100644 advisories/unreviewed/2024/08/GHSA-7r79-ppgg-4h8m/GHSA-7r79-ppgg-4h8m.json create mode 100644 advisories/unreviewed/2024/08/GHSA-mchm-hhh8-w57p/GHSA-mchm-hhh8-w57p.json create mode 100644 advisories/unreviewed/2024/08/GHSA-qgv4-x6mv-vh78/GHSA-qgv4-x6mv-vh78.json create mode 100644 advisories/unreviewed/2024/08/GHSA-rq5p-j687-h2vf/GHSA-rq5p-j687-h2vf.json create mode 100644 advisories/unreviewed/2024/08/GHSA-x7fm-xq4g-7h9j/GHSA-x7fm-xq4g-7h9j.json diff --git a/advisories/unreviewed/2024/02/GHSA-6r3r-qjm5-8fvp/GHSA-6r3r-qjm5-8fvp.json b/advisories/unreviewed/2024/02/GHSA-6r3r-qjm5-8fvp/GHSA-6r3r-qjm5-8fvp.json index c60ce394afe..b5f84f15241 100644 --- a/advisories/unreviewed/2024/02/GHSA-6r3r-qjm5-8fvp/GHSA-6r3r-qjm5-8fvp.json +++ b/advisories/unreviewed/2024/02/GHSA-6r3r-qjm5-8fvp/GHSA-6r3r-qjm5-8fvp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6r3r-qjm5-8fvp", - "modified": "2024-02-18T06:30:32Z", + "modified": "2024-08-22T15:31:15Z", "published": "2024-02-18T06:30:32Z", "aliases": [ "CVE-2023-52376" ], "details": "Information management vulnerability in the Gallery module.Successful exploitation of this vulnerability may affect service confidentiality.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-18T06:15:08Z" diff --git a/advisories/unreviewed/2024/02/GHSA-cwf3-fx63-9w5f/GHSA-cwf3-fx63-9w5f.json b/advisories/unreviewed/2024/02/GHSA-cwf3-fx63-9w5f/GHSA-cwf3-fx63-9w5f.json index 3dfd4c35434..03aa08e7a77 100644 --- a/advisories/unreviewed/2024/02/GHSA-cwf3-fx63-9w5f/GHSA-cwf3-fx63-9w5f.json +++ b/advisories/unreviewed/2024/02/GHSA-cwf3-fx63-9w5f/GHSA-cwf3-fx63-9w5f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cwf3-fx63-9w5f", - "modified": "2024-02-16T00:30:28Z", + "modified": "2024-08-22T15:31:15Z", "published": "2024-02-16T00:30:28Z", "aliases": [ "CVE-2023-40110" ], "details": "In multiple functions of MtpPacket.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-15T23:15:08Z" diff --git a/advisories/unreviewed/2024/02/GHSA-j6qv-9fc5-fqqg/GHSA-j6qv-9fc5-fqqg.json b/advisories/unreviewed/2024/02/GHSA-j6qv-9fc5-fqqg/GHSA-j6qv-9fc5-fqqg.json index e689eb1d5a5..880a64f8891 100644 --- a/advisories/unreviewed/2024/02/GHSA-j6qv-9fc5-fqqg/GHSA-j6qv-9fc5-fqqg.json +++ b/advisories/unreviewed/2024/02/GHSA-j6qv-9fc5-fqqg/GHSA-j6qv-9fc5-fqqg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j6qv-9fc5-fqqg", - "modified": "2024-02-21T09:31:01Z", + "modified": "2024-08-22T15:31:15Z", "published": "2024-02-21T09:31:01Z", "aliases": [ "CVE-2023-42945" ], "details": "A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.1. An app may gain unauthorized access to Bluetooth.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-21T07:15:51Z" diff --git a/advisories/unreviewed/2024/02/GHSA-mp67-wx57-8m4f/GHSA-mp67-wx57-8m4f.json b/advisories/unreviewed/2024/02/GHSA-mp67-wx57-8m4f/GHSA-mp67-wx57-8m4f.json index e794115078f..14d05d0f2db 100644 --- a/advisories/unreviewed/2024/02/GHSA-mp67-wx57-8m4f/GHSA-mp67-wx57-8m4f.json +++ b/advisories/unreviewed/2024/02/GHSA-mp67-wx57-8m4f/GHSA-mp67-wx57-8m4f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mp67-wx57-8m4f", - "modified": "2024-02-16T03:30:51Z", + "modified": "2024-08-22T15:31:15Z", "published": "2024-02-16T03:30:51Z", "aliases": [ "CVE-2024-0038" ], "details": "In injectInputEventToInputFilter of AccessibilityManagerService.java, there is a possible arbitrary input event injection due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-16T02:15:51Z" diff --git a/advisories/unreviewed/2024/02/GHSA-xcvq-77qq-2wpx/GHSA-xcvq-77qq-2wpx.json b/advisories/unreviewed/2024/02/GHSA-xcvq-77qq-2wpx/GHSA-xcvq-77qq-2wpx.json index e857736a3e1..2cd033c80d1 100644 --- a/advisories/unreviewed/2024/02/GHSA-xcvq-77qq-2wpx/GHSA-xcvq-77qq-2wpx.json +++ b/advisories/unreviewed/2024/02/GHSA-xcvq-77qq-2wpx/GHSA-xcvq-77qq-2wpx.json @@ -52,7 +52,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-617" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-wpv3-6qr5-9rmx/GHSA-wpv3-6qr5-9rmx.json b/advisories/unreviewed/2024/04/GHSA-wpv3-6qr5-9rmx/GHSA-wpv3-6qr5-9rmx.json index df5bac0c3b4..9b419e452f8 100644 --- a/advisories/unreviewed/2024/04/GHSA-wpv3-6qr5-9rmx/GHSA-wpv3-6qr5-9rmx.json +++ b/advisories/unreviewed/2024/04/GHSA-wpv3-6qr5-9rmx/GHSA-wpv3-6qr5-9rmx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wpv3-6qr5-9rmx", - "modified": "2024-05-01T18:30:38Z", + "modified": "2024-08-22T15:31:15Z", "published": "2024-04-06T12:30:56Z", "aliases": [ "CVE-2024-24746" ], "details": "Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache NimBLE. \n\nSpecially crafted GATT operation can cause infinite loop in GATT server leading to denial of service in Bluetooth stack or device.\n\nThis issue affects Apache NimBLE: through 1.6.0.\nUsers are recommended to upgrade to version 1.7.0, which fixes the issue.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ "CWE-835" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-06T12:15:08Z" diff --git a/advisories/unreviewed/2024/07/GHSA-22g9-jc7j-7rgj/GHSA-22g9-jc7j-7rgj.json b/advisories/unreviewed/2024/07/GHSA-22g9-jc7j-7rgj/GHSA-22g9-jc7j-7rgj.json index 54c10e8fc05..f668e88863c 100644 --- a/advisories/unreviewed/2024/07/GHSA-22g9-jc7j-7rgj/GHSA-22g9-jc7j-7rgj.json +++ b/advisories/unreviewed/2024/07/GHSA-22g9-jc7j-7rgj/GHSA-22g9-jc7j-7rgj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-22g9-jc7j-7rgj", - "modified": "2024-07-30T09:31:51Z", + "modified": "2024-08-22T15:31:18Z", "published": "2024-07-30T09:31:51Z", "aliases": [ "CVE-2024-42101" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/nouveau: fix null pointer dereference in nouveau_connector_get_modes\n\nIn nouveau_connector_get_modes(), the return value of drm_mode_duplicate()\nis assigned to mode, which will lead to a possible NULL pointer\ndereference on failure of drm_mode_duplicate(). Add a check to avoid npd.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-30T08:15:02Z" diff --git a/advisories/unreviewed/2024/07/GHSA-2qvq-p8h3-vf5j/GHSA-2qvq-p8h3-vf5j.json b/advisories/unreviewed/2024/07/GHSA-2qvq-p8h3-vf5j/GHSA-2qvq-p8h3-vf5j.json index f2b878952de..418396e2993 100644 --- a/advisories/unreviewed/2024/07/GHSA-2qvq-p8h3-vf5j/GHSA-2qvq-p8h3-vf5j.json +++ b/advisories/unreviewed/2024/07/GHSA-2qvq-p8h3-vf5j/GHSA-2qvq-p8h3-vf5j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2qvq-p8h3-vf5j", - "modified": "2024-07-29T18:30:38Z", + "modified": "2024-08-22T15:31:18Z", "published": "2024-07-29T18:30:38Z", "aliases": [ "CVE-2024-41085" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncxl/mem: Fix no cxl_nvd during pmem region auto-assembling\n\nWhen CXL subsystem is auto-assembling a pmem region during cxl\nendpoint port probing, always hit below calltrace.\n\n BUG: kernel NULL pointer dereference, address: 0000000000000078\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\n RIP: 0010:cxl_pmem_region_probe+0x22e/0x360 [cxl_pmem]\n Call Trace:\n \n ? __die+0x24/0x70\n ? page_fault_oops+0x82/0x160\n ? do_user_addr_fault+0x65/0x6b0\n ? exc_page_fault+0x7d/0x170\n ? asm_exc_page_fault+0x26/0x30\n ? cxl_pmem_region_probe+0x22e/0x360 [cxl_pmem]\n ? cxl_pmem_region_probe+0x1ac/0x360 [cxl_pmem]\n cxl_bus_probe+0x1b/0x60 [cxl_core]\n really_probe+0x173/0x410\n ? __pfx___device_attach_driver+0x10/0x10\n __driver_probe_device+0x80/0x170\n driver_probe_device+0x1e/0x90\n __device_attach_driver+0x90/0x120\n bus_for_each_drv+0x84/0xe0\n __device_attach+0xbc/0x1f0\n bus_probe_device+0x90/0xa0\n device_add+0x51c/0x710\n devm_cxl_add_pmem_region+0x1b5/0x380 [cxl_core]\n cxl_bus_probe+0x1b/0x60 [cxl_core]\n\nThe cxl_nvd of the memdev needs to be available during the pmem region\nprobe. Currently the cxl_nvd is registered after the endpoint port probe.\nThe endpoint probe, in the case of autoassembly of regions, can cause a\npmem region probe requiring the not yet available cxl_nvd. Adjust the\nsequence so this dependency is met.\n\nThis requires adding a port parameter to cxl_find_nvdimm_bridge() that\ncan be used to query the ancestor root port. The endpoint port is not\nyet available, but will share a common ancestor with its parent, so\nstart the query from there instead.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T16:15:03Z" diff --git a/advisories/unreviewed/2024/07/GHSA-2wm2-45c2-f92h/GHSA-2wm2-45c2-f92h.json b/advisories/unreviewed/2024/07/GHSA-2wm2-45c2-f92h/GHSA-2wm2-45c2-f92h.json index 409f70486ac..1ca26099762 100644 --- a/advisories/unreviewed/2024/07/GHSA-2wm2-45c2-f92h/GHSA-2wm2-45c2-f92h.json +++ b/advisories/unreviewed/2024/07/GHSA-2wm2-45c2-f92h/GHSA-2wm2-45c2-f92h.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-287", "CWE-288" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2024/07/GHSA-4f32-8hqj-hvcg/GHSA-4f32-8hqj-hvcg.json b/advisories/unreviewed/2024/07/GHSA-4f32-8hqj-hvcg/GHSA-4f32-8hqj-hvcg.json index bb77b710365..15f07b8a438 100644 --- a/advisories/unreviewed/2024/07/GHSA-4f32-8hqj-hvcg/GHSA-4f32-8hqj-hvcg.json +++ b/advisories/unreviewed/2024/07/GHSA-4f32-8hqj-hvcg/GHSA-4f32-8hqj-hvcg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4f32-8hqj-hvcg", - "modified": "2024-07-29T18:30:39Z", + "modified": "2024-08-22T15:31:18Z", "published": "2024-07-29T18:30:38Z", "aliases": [ "CVE-2024-41097" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: atm: cxacru: fix endpoint checking in cxacru_bind()\n\nSyzbot is still reporting quite an old issue [1] that occurs due to\nincomplete checking of present usb endpoints. As such, wrong\nendpoints types may be used at urb sumbitting stage which in turn\ntriggers a warning in usb_submit_urb().\n\nFix the issue by verifying that required endpoint types are present\nfor both in and out endpoints, taking into account cmd endpoint type.\n\nUnfortunately, this patch has not been tested on real hardware.\n\n[1] Syzbot report:\nusb 1-1: BOGUS urb xfer, pipe 1 != type 3\nWARNING: CPU: 0 PID: 8667 at drivers/usb/core/urb.c:502 usb_submit_urb+0xed2/0x18a0 drivers/usb/core/urb.c:502\nModules linked in:\nCPU: 0 PID: 8667 Comm: kworker/0:4 Not tainted 5.14.0-rc4-syzkaller #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011\nWorkqueue: usb_hub_wq hub_event\nRIP: 0010:usb_submit_urb+0xed2/0x18a0 drivers/usb/core/urb.c:502\n...\nCall Trace:\n cxacru_cm+0x3c0/0x8e0 drivers/usb/atm/cxacru.c:649\n cxacru_card_status+0x22/0xd0 drivers/usb/atm/cxacru.c:760\n cxacru_bind+0x7ac/0x11a0 drivers/usb/atm/cxacru.c:1209\n usbatm_usb_probe+0x321/0x1ae0 drivers/usb/atm/usbatm.c:1055\n cxacru_usb_probe+0xdf/0x1e0 drivers/usb/atm/cxacru.c:1363\n usb_probe_interface+0x315/0x7f0 drivers/usb/core/driver.c:396\n call_driver_probe drivers/base/dd.c:517 [inline]\n really_probe+0x23c/0xcd0 drivers/base/dd.c:595\n __driver_probe_device+0x338/0x4d0 drivers/base/dd.c:747\n driver_probe_device+0x4c/0x1a0 drivers/base/dd.c:777\n __device_attach_driver+0x20b/0x2f0 drivers/base/dd.c:894\n bus_for_each_drv+0x15f/0x1e0 drivers/base/bus.c:427\n __device_attach+0x228/0x4a0 drivers/base/dd.c:965\n bus_probe_device+0x1e4/0x290 drivers/base/bus.c:487\n device_add+0xc2f/0x2180 drivers/base/core.c:3354\n usb_set_configuration+0x113a/0x1910 drivers/usb/core/message.c:2170\n usb_generic_driver_probe+0xba/0x100 drivers/usb/core/generic.c:238\n usb_probe_device+0xd9/0x2c0 drivers/usb/core/driver.c:293", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -55,7 +58,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T16:15:04Z" diff --git a/advisories/unreviewed/2024/07/GHSA-54p6-r4cp-p6qq/GHSA-54p6-r4cp-p6qq.json b/advisories/unreviewed/2024/07/GHSA-54p6-r4cp-p6qq/GHSA-54p6-r4cp-p6qq.json index 69f239b04b3..fe9eedb6be4 100644 --- a/advisories/unreviewed/2024/07/GHSA-54p6-r4cp-p6qq/GHSA-54p6-r4cp-p6qq.json +++ b/advisories/unreviewed/2024/07/GHSA-54p6-r4cp-p6qq/GHSA-54p6-r4cp-p6qq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-54p6-r4cp-p6qq", - "modified": "2024-07-29T18:30:38Z", + "modified": "2024-08-22T15:31:18Z", "published": "2024-07-29T18:30:38Z", "aliases": [ "CVE-2024-41094" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/fbdev-dma: Only set smem_start is enable per module option\n\nOnly export struct fb_info.fix.smem_start if that is required by the\nuser and the memory does not come from vmalloc().\n\nSetting struct fb_info.fix.smem_start breaks systems where DMA\nmemory is backed by vmalloc address space. An example error is\nshown below.\n\n[ 3.536043] ------------[ cut here ]------------\n[ 3.540716] virt_to_phys used for non-linear address: 000000007fc4f540 (0xffff800086001000)\n[ 3.552628] WARNING: CPU: 4 PID: 61 at arch/arm64/mm/physaddr.c:12 __virt_to_phys+0x68/0x98\n[ 3.565455] Modules linked in:\n[ 3.568525] CPU: 4 PID: 61 Comm: kworker/u12:5 Not tainted 6.6.23-06226-g4986cc3e1b75-dirty #250\n[ 3.577310] Hardware name: NXP i.MX95 19X19 board (DT)\n[ 3.582452] Workqueue: events_unbound deferred_probe_work_func\n[ 3.588291] pstate: 60400009 (nZCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n[ 3.595233] pc : __virt_to_phys+0x68/0x98\n[ 3.599246] lr : __virt_to_phys+0x68/0x98\n[ 3.603276] sp : ffff800083603990\n[ 3.677939] Call trace:\n[ 3.680393] __virt_to_phys+0x68/0x98\n[ 3.684067] drm_fbdev_dma_helper_fb_probe+0x138/0x238\n[ 3.689214] __drm_fb_helper_initial_config_and_unlock+0x2b0/0x4c0\n[ 3.695385] drm_fb_helper_initial_config+0x4c/0x68\n[ 3.700264] drm_fbdev_dma_client_hotplug+0x8c/0xe0\n[ 3.705161] drm_client_register+0x60/0xb0\n[ 3.709269] drm_fbdev_dma_setup+0x94/0x148\n\nAdditionally, DMA memory is assumed to by contiguous in physical\naddress space, which is not guaranteed by vmalloc().\n\nResolve this by checking the module flag drm_leak_fbdev_smem when\nDRM allocated the instance of struct fb_info. Fbdev-dma then only\nsets smem_start only if required (via FBINFO_HIDE_SMEM_START). Also\nguarantee that the framebuffer is not located in vmalloc address\nspace.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T16:15:04Z" diff --git a/advisories/unreviewed/2024/07/GHSA-79hg-h6r6-64mm/GHSA-79hg-h6r6-64mm.json b/advisories/unreviewed/2024/07/GHSA-79hg-h6r6-64mm/GHSA-79hg-h6r6-64mm.json index 37fdb6a1e2c..a5bda3d4106 100644 --- a/advisories/unreviewed/2024/07/GHSA-79hg-h6r6-64mm/GHSA-79hg-h6r6-64mm.json +++ b/advisories/unreviewed/2024/07/GHSA-79hg-h6r6-64mm/GHSA-79hg-h6r6-64mm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-79hg-h6r6-64mm", - "modified": "2024-08-07T18:30:40Z", + "modified": "2024-08-22T15:31:16Z", "published": "2024-07-08T18:31:18Z", "aliases": [ "CVE-2024-6409" @@ -65,6 +65,10 @@ "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-6409" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:5444" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:4960" diff --git a/advisories/unreviewed/2024/07/GHSA-7f9h-6jq6-8gmx/GHSA-7f9h-6jq6-8gmx.json b/advisories/unreviewed/2024/07/GHSA-7f9h-6jq6-8gmx/GHSA-7f9h-6jq6-8gmx.json index aa1f700655f..a647e0072c8 100644 --- a/advisories/unreviewed/2024/07/GHSA-7f9h-6jq6-8gmx/GHSA-7f9h-6jq6-8gmx.json +++ b/advisories/unreviewed/2024/07/GHSA-7f9h-6jq6-8gmx/GHSA-7f9h-6jq6-8gmx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7f9h-6jq6-8gmx", - "modified": "2024-07-29T15:30:43Z", + "modified": "2024-08-22T15:31:17Z", "published": "2024-07-29T15:30:43Z", "aliases": [ "CVE-2024-41054" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: ufs: core: Fix ufshcd_clear_cmd racing issue\n\nWhen ufshcd_clear_cmd is racing with the completion ISR, the completed tag\nof the request's mq_hctx pointer will be set to NULL by the ISR. And\nufshcd_clear_cmd's call to ufshcd_mcq_req_to_hwq will get NULL pointer KE.\nReturn success when the request is completed by ISR because sq does not\nneed cleanup.\n\nThe racing flow is:\n\nThread A\nufshcd_err_handler\t\t\t\t\tstep 1\n\tufshcd_try_to_abort_task\n\t\tufshcd_cmd_inflight(true)\t\tstep 3\n\t\tufshcd_clear_cmd\n\t\t\t...\n\t\t\tufshcd_mcq_req_to_hwq\n\t\t\tblk_mq_unique_tag\n\t\t\t\trq->mq_hctx->queue_num\tstep 5\n\nThread B\nufs_mtk_mcq_intr(cq complete ISR)\t\t\tstep 2\n\tscsi_done\n\t\t...\n\t\t__blk_mq_free_request\n\t\t\trq->mq_hctx = NULL;\t\tstep 4\n\nBelow is KE back trace:\n\n ufshcd_try_to_abort_task: cmd pending in the device. tag = 6\n Unable to handle kernel NULL pointer dereference at virtual address 0000000000000194\n pc : [0xffffffd589679bf8] blk_mq_unique_tag+0x8/0x14\n lr : [0xffffffd5862f95b4] ufshcd_mcq_sq_cleanup+0x6c/0x1cc [ufs_mediatek_mod_ise]\n Workqueue: ufs_eh_wq_0 ufshcd_err_handler [ufs_mediatek_mod_ise]\n Call trace:\n dump_backtrace+0xf8/0x148\n show_stack+0x18/0x24\n dump_stack_lvl+0x60/0x7c\n dump_stack+0x18/0x3c\n mrdump_common_die+0x24c/0x398 [mrdump]\n ipanic_die+0x20/0x34 [mrdump]\n notify_die+0x80/0xd8\n die+0x94/0x2b8\n __do_kernel_fault+0x264/0x298\n do_page_fault+0xa4/0x4b8\n do_translation_fault+0x38/0x54\n do_mem_abort+0x58/0x118\n el1_abort+0x3c/0x5c\n el1h_64_sync_handler+0x54/0x90\n el1h_64_sync+0x68/0x6c\n blk_mq_unique_tag+0x8/0x14\n ufshcd_clear_cmd+0x34/0x118 [ufs_mediatek_mod_ise]\n ufshcd_try_to_abort_task+0x2c8/0x5b4 [ufs_mediatek_mod_ise]\n ufshcd_err_handler+0xa7c/0xfa8 [ufs_mediatek_mod_ise]\n process_one_work+0x208/0x4fc\n worker_thread+0x228/0x438\n kthread+0x104/0x1d4\n ret_from_fork+0x10/0x20", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T15:15:13Z" diff --git a/advisories/unreviewed/2024/07/GHSA-7x54-v488-56pj/GHSA-7x54-v488-56pj.json b/advisories/unreviewed/2024/07/GHSA-7x54-v488-56pj/GHSA-7x54-v488-56pj.json index b1b4dac3108..c2fcc761bed 100644 --- a/advisories/unreviewed/2024/07/GHSA-7x54-v488-56pj/GHSA-7x54-v488-56pj.json +++ b/advisories/unreviewed/2024/07/GHSA-7x54-v488-56pj/GHSA-7x54-v488-56pj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7x54-v488-56pj", - "modified": "2024-07-29T15:30:43Z", + "modified": "2024-08-22T15:31:17Z", "published": "2024-07-29T15:30:43Z", "aliases": [ "CVE-2024-41055" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm: prevent derefencing NULL ptr in pfn_section_valid()\n\nCommit 5ec8e8ea8b77 (\"mm/sparsemem: fix race in accessing\nmemory_section->usage\") changed pfn_section_valid() to add a READ_ONCE()\ncall around \"ms->usage\" to fix a race with section_deactivate() where\nms->usage can be cleared. The READ_ONCE() call, by itself, is not enough\nto prevent NULL pointer dereference. We need to check its value before\ndereferencing it.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T15:15:13Z" diff --git a/advisories/unreviewed/2024/07/GHSA-95g8-7cpf-mp2q/GHSA-95g8-7cpf-mp2q.json b/advisories/unreviewed/2024/07/GHSA-95g8-7cpf-mp2q/GHSA-95g8-7cpf-mp2q.json index 3f0433c2b24..bf4613c3503 100644 --- a/advisories/unreviewed/2024/07/GHSA-95g8-7cpf-mp2q/GHSA-95g8-7cpf-mp2q.json +++ b/advisories/unreviewed/2024/07/GHSA-95g8-7cpf-mp2q/GHSA-95g8-7cpf-mp2q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-95g8-7cpf-mp2q", - "modified": "2024-07-29T15:30:47Z", + "modified": "2024-08-22T15:31:18Z", "published": "2024-07-29T15:30:47Z", "aliases": [ "CVE-2024-41076" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nNFSv4: Fix memory leak in nfs4_set_security_label\n\nWe leak nfs_fattr and nfs4_label every time we set a security xattr.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-401" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T15:15:15Z" diff --git a/advisories/unreviewed/2024/07/GHSA-hxr9-q428-7jhg/GHSA-hxr9-q428-7jhg.json b/advisories/unreviewed/2024/07/GHSA-hxr9-q428-7jhg/GHSA-hxr9-q428-7jhg.json index b8901184519..496bd033ffd 100644 --- a/advisories/unreviewed/2024/07/GHSA-hxr9-q428-7jhg/GHSA-hxr9-q428-7jhg.json +++ b/advisories/unreviewed/2024/07/GHSA-hxr9-q428-7jhg/GHSA-hxr9-q428-7jhg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hxr9-q428-7jhg", - "modified": "2024-07-29T15:30:47Z", + "modified": "2024-08-22T15:31:18Z", "published": "2024-07-29T15:30:47Z", "aliases": [ "CVE-2024-41080" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nio_uring: fix possible deadlock in io_register_iowq_max_workers()\n\nThe io_register_iowq_max_workers() function calls io_put_sq_data(),\nwhich acquires the sqd->lock without releasing the uring_lock.\nSimilar to the commit 009ad9f0c6ee (\"io_uring: drop ctx->uring_lock\nbefore acquiring sqd->lock\"), this can lead to a potential deadlock\nsituation.\n\nTo resolve this issue, the uring_lock is released before calling\nio_put_sq_data(), and then it is re-acquired after the function call.\n\nThis change ensures that the locks are acquired in the correct\norder, preventing the possibility of a deadlock.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-667" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T15:15:15Z" diff --git a/advisories/unreviewed/2024/07/GHSA-jh57-6wf8-c6gg/GHSA-jh57-6wf8-c6gg.json b/advisories/unreviewed/2024/07/GHSA-jh57-6wf8-c6gg/GHSA-jh57-6wf8-c6gg.json index b46e44f61a2..fe3a68cb1a3 100644 --- a/advisories/unreviewed/2024/07/GHSA-jh57-6wf8-c6gg/GHSA-jh57-6wf8-c6gg.json +++ b/advisories/unreviewed/2024/07/GHSA-jh57-6wf8-c6gg/GHSA-jh57-6wf8-c6gg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jh57-6wf8-c6gg", - "modified": "2024-07-29T18:30:38Z", + "modified": "2024-08-22T15:31:18Z", "published": "2024-07-29T18:30:38Z", "aliases": [ "CVE-2024-41088" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: mcp251xfd: fix infinite loop when xmit fails\n\nWhen the mcp251xfd_start_xmit() function fails, the driver stops\nprocessing messages, and the interrupt routine does not return,\nrunning indefinitely even after killing the running application.\n\nError messages:\n[ 441.298819] mcp251xfd spi2.0 can0: ERROR in mcp251xfd_start_xmit: -16\n[ 441.306498] mcp251xfd spi2.0 can0: Transmit Event FIFO buffer not empty. (seq=0x000017c7, tef_tail=0x000017cf, tef_head=0x000017d0, tx_head=0x000017d3).\n... and repeat forever.\n\nThe issue can be triggered when multiple devices share the same SPI\ninterface. And there is concurrent access to the bus.\n\nThe problem occurs because tx_ring->head increments even if\nmcp251xfd_start_xmit() fails. Consequently, the driver skips one TX\npackage while still expecting a response in\nmcp251xfd_handle_tefif_one().\n\nResolve the issue by starting a workqueue to write the tx obj\nsynchronously if err = -EBUSY. In case of another error, decrement\ntx_ring->head, remove skb from the echo stack, and drop the message.\n\n[mkl: use more imperative wording in patch description]", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-835" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T16:15:04Z" diff --git a/advisories/unreviewed/2024/07/GHSA-p776-rxgv-h888/GHSA-p776-rxgv-h888.json b/advisories/unreviewed/2024/07/GHSA-p776-rxgv-h888/GHSA-p776-rxgv-h888.json index 48dbc5c605b..6f16093d343 100644 --- a/advisories/unreviewed/2024/07/GHSA-p776-rxgv-h888/GHSA-p776-rxgv-h888.json +++ b/advisories/unreviewed/2024/07/GHSA-p776-rxgv-h888/GHSA-p776-rxgv-h888.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p776-rxgv-h888", - "modified": "2024-07-29T18:30:38Z", + "modified": "2024-08-22T15:31:18Z", "published": "2024-07-29T18:30:38Z", "aliases": [ "CVE-2024-41084" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncxl/region: Avoid null pointer dereference in region lookup\n\ncxl_dpa_to_region() looks up a region based on a memdev and DPA.\nIt wrongly assumes an endpoint found mapping the DPA is also of\na fully assembled region. When not true it leads to a null pointer\ndereference looking up the region name.\n\nThis appears during testing of region lookup after a failure to\nassemble a BIOS defined region or if the lookup raced with the\nassembly of the BIOS defined region.\n\nFailure to clean up BIOS defined regions that fail assembly is an\nissue in itself and a fix to that problem will alleviate some of\nthe impact. It will not alleviate the race condition so let's harden\nthis path.\n\nThe behavior change is that the kernel oops due to a null pointer\ndereference is replaced with a dev_dbg() message noting that an\nendpoint was mapped.\n\nAdditional comments are added so that future users of this function\ncan more clearly understand what it provides.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T16:15:03Z" diff --git a/advisories/unreviewed/2024/07/GHSA-pc3q-4rr7-6vrq/GHSA-pc3q-4rr7-6vrq.json b/advisories/unreviewed/2024/07/GHSA-pc3q-4rr7-6vrq/GHSA-pc3q-4rr7-6vrq.json index fd04f5ef58b..48f582fa81a 100644 --- a/advisories/unreviewed/2024/07/GHSA-pc3q-4rr7-6vrq/GHSA-pc3q-4rr7-6vrq.json +++ b/advisories/unreviewed/2024/07/GHSA-pc3q-4rr7-6vrq/GHSA-pc3q-4rr7-6vrq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pc3q-4rr7-6vrq", - "modified": "2024-07-29T15:30:46Z", + "modified": "2024-08-22T15:31:18Z", "published": "2024-07-29T15:30:46Z", "aliases": [ "CVE-2024-41070" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: PPC: Book3S HV: Prevent UAF in kvm_spapr_tce_attach_iommu_group()\n\nAl reported a possible use-after-free (UAF) in kvm_spapr_tce_attach_iommu_group().\n\nIt looks up `stt` from tablefd, but then continues to use it after doing\nfdput() on the returned fd. After the fdput() the tablefd is free to be\nclosed by another thread. The close calls kvm_spapr_tce_release() and\nthen release_spapr_tce_table() (via call_rcu()) which frees `stt`.\n\nAlthough there are calls to rcu_read_lock() in\nkvm_spapr_tce_attach_iommu_group() they are not sufficient to prevent\nthe UAF, because `stt` is used outside the locked regions.\n\nWith an artifcial delay after the fdput() and a userspace program which\ntriggers the race, KASAN detects the UAF:\n\n BUG: KASAN: slab-use-after-free in kvm_spapr_tce_attach_iommu_group+0x298/0x720 [kvm]\n Read of size 4 at addr c000200027552c30 by task kvm-vfio/2505\n CPU: 54 PID: 2505 Comm: kvm-vfio Not tainted 6.10.0-rc3-next-20240612-dirty #1\n Hardware name: 8335-GTH POWER9 0x4e1202 opal:skiboot-v6.5.3-35-g1851b2a06 PowerNV\n Call Trace:\n dump_stack_lvl+0xb4/0x108 (unreliable)\n print_report+0x2b4/0x6ec\n kasan_report+0x118/0x2b0\n __asan_load4+0xb8/0xd0\n kvm_spapr_tce_attach_iommu_group+0x298/0x720 [kvm]\n kvm_vfio_set_attr+0x524/0xac0 [kvm]\n kvm_device_ioctl+0x144/0x240 [kvm]\n sys_ioctl+0x62c/0x1810\n system_call_exception+0x190/0x440\n system_call_vectored_common+0x15c/0x2ec\n ...\n Freed by task 0:\n ...\n kfree+0xec/0x3e0\n release_spapr_tce_table+0xd4/0x11c [kvm]\n rcu_core+0x568/0x16a0\n handle_softirqs+0x23c/0x920\n do_softirq_own_stack+0x6c/0x90\n do_softirq_own_stack+0x58/0x90\n __irq_exit_rcu+0x218/0x2d0\n irq_exit+0x30/0x80\n arch_local_irq_restore+0x128/0x230\n arch_local_irq_enable+0x1c/0x30\n cpuidle_enter_state+0x134/0x5cc\n cpuidle_enter+0x6c/0xb0\n call_cpuidle+0x7c/0x100\n do_idle+0x394/0x410\n cpu_startup_entry+0x60/0x70\n start_secondary+0x3fc/0x410\n start_secondary_prolog+0x10/0x14\n\nFix it by delaying the fdput() until `stt` is no longer in use, which\nis effectively the entire function. To keep the patch minimal add a call\nto fdput() at each of the existing return paths. Future work can convert\nthe function to goto or __cleanup style cleanup.\n\nWith the fix in place the test case no longer triggers the UAF.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -49,9 +52,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T15:15:14Z" diff --git a/advisories/unreviewed/2024/07/GHSA-q423-q7jg-m3rq/GHSA-q423-q7jg-m3rq.json b/advisories/unreviewed/2024/07/GHSA-q423-q7jg-m3rq/GHSA-q423-q7jg-m3rq.json index 7243de060b0..40193d9de13 100644 --- a/advisories/unreviewed/2024/07/GHSA-q423-q7jg-m3rq/GHSA-q423-q7jg-m3rq.json +++ b/advisories/unreviewed/2024/07/GHSA-q423-q7jg-m3rq/GHSA-q423-q7jg-m3rq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q423-q7jg-m3rq", - "modified": "2024-07-29T15:30:46Z", + "modified": "2024-08-22T15:31:18Z", "published": "2024-07-29T15:30:46Z", "aliases": [ "CVE-2024-41073" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnvme: avoid double free special payload\n\nIf a discard request needs to be retried, and that retry may fail before\na new special payload is added, a double free will result. Clear the\nRQF_SPECIAL_LOAD when the request is cleaned.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-415" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T15:15:15Z" diff --git a/advisories/unreviewed/2024/07/GHSA-q935-8vhv-gg93/GHSA-q935-8vhv-gg93.json b/advisories/unreviewed/2024/07/GHSA-q935-8vhv-gg93/GHSA-q935-8vhv-gg93.json index 7826773ece2..ae0d11eedf7 100644 --- a/advisories/unreviewed/2024/07/GHSA-q935-8vhv-gg93/GHSA-q935-8vhv-gg93.json +++ b/advisories/unreviewed/2024/07/GHSA-q935-8vhv-gg93/GHSA-q935-8vhv-gg93.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q935-8vhv-gg93", - "modified": "2024-07-01T21:31:16Z", + "modified": "2024-08-22T15:31:15Z", "published": "2024-07-01T21:31:16Z", "aliases": [ "CVE-2024-32230" ], "details": "FFmpeg 7.0 is vulnerable to Buffer Overflow. There is a negative-size-param bug at libavcodec/mpegvideo_enc.c:1216:21 in load_input_picture in FFmpeg7.0", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-01T21:15:03Z" diff --git a/advisories/unreviewed/2024/07/GHSA-rqqp-4vhv-fqrg/GHSA-rqqp-4vhv-fqrg.json b/advisories/unreviewed/2024/07/GHSA-rqqp-4vhv-fqrg/GHSA-rqqp-4vhv-fqrg.json index 97a95c819e4..d3092c2cab8 100644 --- a/advisories/unreviewed/2024/07/GHSA-rqqp-4vhv-fqrg/GHSA-rqqp-4vhv-fqrg.json +++ b/advisories/unreviewed/2024/07/GHSA-rqqp-4vhv-fqrg/GHSA-rqqp-4vhv-fqrg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rqqp-4vhv-fqrg", - "modified": "2024-07-29T15:30:44Z", + "modified": "2024-08-22T15:31:17Z", "published": "2024-07-29T15:30:44Z", "aliases": [ "CVE-2024-41057" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncachefiles: fix slab-use-after-free in cachefiles_withdraw_cookie()\n\nWe got the following issue in our fault injection stress test:\n\n==================================================================\nBUG: KASAN: slab-use-after-free in cachefiles_withdraw_cookie+0x4d9/0x600\nRead of size 8 at addr ffff888118efc000 by task kworker/u78:0/109\n\nCPU: 13 PID: 109 Comm: kworker/u78:0 Not tainted 6.8.0-dirty #566\nCall Trace:\n \n kasan_report+0x93/0xc0\n cachefiles_withdraw_cookie+0x4d9/0x600\n fscache_cookie_state_machine+0x5c8/0x1230\n fscache_cookie_worker+0x91/0x1c0\n process_one_work+0x7fa/0x1800\n [...]\n\nAllocated by task 117:\n kmalloc_trace+0x1b3/0x3c0\n cachefiles_acquire_volume+0xf3/0x9c0\n fscache_create_volume_work+0x97/0x150\n process_one_work+0x7fa/0x1800\n [...]\n\nFreed by task 120301:\n kfree+0xf1/0x2c0\n cachefiles_withdraw_cache+0x3fa/0x920\n cachefiles_put_unbind_pincount+0x1f6/0x250\n cachefiles_daemon_release+0x13b/0x290\n __fput+0x204/0xa00\n task_work_run+0x139/0x230\n do_exit+0x87a/0x29b0\n [...]\n==================================================================\n\nFollowing is the process that triggers the issue:\n\n p1 | p2\n------------------------------------------------------------\n fscache_begin_lookup\n fscache_begin_volume_access\n fscache_cache_is_live(fscache_cache)\ncachefiles_daemon_release\n cachefiles_put_unbind_pincount\n cachefiles_daemon_unbind\n cachefiles_withdraw_cache\n fscache_withdraw_cache\n fscache_set_cache_state(cache, FSCACHE_CACHE_IS_WITHDRAWN);\n cachefiles_withdraw_objects(cache)\n fscache_wait_for_objects(fscache)\n atomic_read(&fscache_cache->object_count) == 0\n fscache_perform_lookup\n cachefiles_lookup_cookie\n cachefiles_alloc_object\n refcount_set(&object->ref, 1);\n object->volume = volume\n fscache_count_object(vcookie->cache);\n atomic_inc(&fscache_cache->object_count)\n cachefiles_withdraw_volumes\n cachefiles_withdraw_volume\n fscache_withdraw_volume\n __cachefiles_free_volume\n kfree(cachefiles_volume)\n fscache_cookie_state_machine\n cachefiles_withdraw_cookie\n cache = object->volume->cache;\n // cachefiles_volume UAF !!!\n\nAfter setting FSCACHE_CACHE_IS_WITHDRAWN, wait for all the cookie lookups\nto complete first, and then wait for fscache_cache->object_count == 0 to\navoid the cookie exiting after the volume has been freed and triggering\nthe above issue. Therefore call fscache_withdraw_volume() before calling\ncachefiles_withdraw_objects().\n\nThis way, after setting FSCACHE_CACHE_IS_WITHDRAWN, only the following two\ncases will occur:\n1) fscache_begin_lookup fails in fscache_begin_volume_access().\n2) fscache_withdraw_volume() will ensure that fscache_count_object() has\n been executed before calling fscache_wait_for_objects().", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T15:15:13Z" diff --git a/advisories/unreviewed/2024/07/GHSA-wccc-2qv8-6647/GHSA-wccc-2qv8-6647.json b/advisories/unreviewed/2024/07/GHSA-wccc-2qv8-6647/GHSA-wccc-2qv8-6647.json index 8d358f3ddad..e540b46ac4e 100644 --- a/advisories/unreviewed/2024/07/GHSA-wccc-2qv8-6647/GHSA-wccc-2qv8-6647.json +++ b/advisories/unreviewed/2024/07/GHSA-wccc-2qv8-6647/GHSA-wccc-2qv8-6647.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wccc-2qv8-6647", - "modified": "2024-07-06T12:31:05Z", + "modified": "2024-08-22T15:31:16Z", "published": "2024-07-06T12:31:05Z", "aliases": [ "CVE-2024-39486" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/drm_file: Fix pid refcounting race\n\n\nfilp->pid is supposed to be a refcounted pointer; however, before this\npatch, drm_file_update_pid() only increments the refcount of a struct\npid after storing a pointer to it in filp->pid and dropping the\ndev->filelist_mutex, making the following race possible:\n\nprocess A process B\n========= =========\n begin drm_file_update_pid\n mutex_lock(&dev->filelist_mutex)\n rcu_replace_pointer(filp->pid, , 1)\n mutex_unlock(&dev->filelist_mutex)\nbegin drm_file_update_pid\nmutex_lock(&dev->filelist_mutex)\nrcu_replace_pointer(filp->pid, , 1)\nmutex_unlock(&dev->filelist_mutex)\nget_pid()\nsynchronize_rcu()\nput_pid() *** pid B reaches refcount 0 and is freed here ***\n get_pid() *** UAF ***\n synchronize_rcu()\n put_pid()\n\nAs far as I know, this race can only occur with CONFIG_PREEMPT_RCU=y\nbecause it requires RCU to detect a quiescent state in code that is not\nexplicitly calling into the scheduler.\n\nThis race leads to use-after-free of a \"struct pid\".\nIt is probably somewhat hard to hit because process A has to pass\nthrough a synchronize_rcu() operation while process B is between\nmutex_unlock() and get_pid().\n\nFix it by ensuring that by the time a pointer to the current task's pid\nis stored in the file, an extra reference to the pid has been taken.\n\nThis fix also removes the condition for synchronize_rcu(); I think\nthat optimization is unnecessary complexity, since in that case we\nwould usually have bailed out on the lockless check above.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-06T10:15:03Z" diff --git a/advisories/unreviewed/2024/08/GHSA-28c6-pjxj-5qxg/GHSA-28c6-pjxj-5qxg.json b/advisories/unreviewed/2024/08/GHSA-28c6-pjxj-5qxg/GHSA-28c6-pjxj-5qxg.json index efb3a980351..e546d5b2b3e 100644 --- a/advisories/unreviewed/2024/08/GHSA-28c6-pjxj-5qxg/GHSA-28c6-pjxj-5qxg.json +++ b/advisories/unreviewed/2024/08/GHSA-28c6-pjxj-5qxg/GHSA-28c6-pjxj-5qxg.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-288" + "CWE-288", + "CWE-306" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-2xmp-f94r-wqm9/GHSA-2xmp-f94r-wqm9.json b/advisories/unreviewed/2024/08/GHSA-2xmp-f94r-wqm9/GHSA-2xmp-f94r-wqm9.json index 57fced183e5..d4ef5a5d507 100644 --- a/advisories/unreviewed/2024/08/GHSA-2xmp-f94r-wqm9/GHSA-2xmp-f94r-wqm9.json +++ b/advisories/unreviewed/2024/08/GHSA-2xmp-f94r-wqm9/GHSA-2xmp-f94r-wqm9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2xmp-f94r-wqm9", - "modified": "2024-08-13T18:31:15Z", + "modified": "2024-08-22T15:31:18Z", "published": "2024-08-13T18:31:15Z", "aliases": [ "CVE-2022-27486" diff --git a/advisories/unreviewed/2024/08/GHSA-36c7-h45p-9hch/GHSA-36c7-h45p-9hch.json b/advisories/unreviewed/2024/08/GHSA-36c7-h45p-9hch/GHSA-36c7-h45p-9hch.json new file mode 100644 index 00000000000..233a22acd78 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-36c7-h45p-9hch/GHSA-36c7-h45p-9hch.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-36c7-h45p-9hch", + "modified": "2024-08-22T15:31:19Z", + "published": "2024-08-22T15:31:19Z", + "aliases": [ + "CVE-2024-36443" + ], + "details": "Swissphone DiCal-RED 4009 devices allow a remote attacker to gain read access to almost the whole file system via anonymous FTP.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36443" + }, + { + "type": "WEB", + "url": "https://www.swissphone.com/en-us/solutions/components/terminals/radio-data-module-dical-red" + }, + { + "type": "WEB", + "url": "https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-036.txt" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-22T14:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-3fc7-hxmq-f35p/GHSA-3fc7-hxmq-f35p.json b/advisories/unreviewed/2024/08/GHSA-3fc7-hxmq-f35p/GHSA-3fc7-hxmq-f35p.json index 205cc920ed5..f17b4e0c1eb 100644 --- a/advisories/unreviewed/2024/08/GHSA-3fc7-hxmq-f35p/GHSA-3fc7-hxmq-f35p.json +++ b/advisories/unreviewed/2024/08/GHSA-3fc7-hxmq-f35p/GHSA-3fc7-hxmq-f35p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3fc7-hxmq-f35p", - "modified": "2024-08-21T18:31:28Z", + "modified": "2024-08-22T15:31:18Z", "published": "2024-08-21T18:31:28Z", "aliases": [ "CVE-2024-42784" ], "details": "A SQL injection vulnerability in \"/music/controller.php?page=view_music\" in Kashipara Music Management System v1.0 allows an attacker to execute arbitrary SQL commands via the \"id\" parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-21T18:15:10Z" diff --git a/advisories/unreviewed/2024/08/GHSA-45wm-mg4w-2536/GHSA-45wm-mg4w-2536.json b/advisories/unreviewed/2024/08/GHSA-45wm-mg4w-2536/GHSA-45wm-mg4w-2536.json index 817d05b03be..ef132731ea8 100644 --- a/advisories/unreviewed/2024/08/GHSA-45wm-mg4w-2536/GHSA-45wm-mg4w-2536.json +++ b/advisories/unreviewed/2024/08/GHSA-45wm-mg4w-2536/GHSA-45wm-mg4w-2536.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-45wm-mg4w-2536", - "modified": "2024-08-21T18:31:28Z", + "modified": "2024-08-22T15:31:18Z", "published": "2024-08-21T18:31:28Z", "aliases": [ "CVE-2024-42781" ], "details": "A SQL injection vulnerability in \"/music/ajax.php?action=login\" of Kashipara Music Management System v1.0 allows remote attackers to execute arbitrary SQL commands and bypass Login via the email parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-21T18:15:10Z" diff --git a/advisories/unreviewed/2024/08/GHSA-482h-w5qp-gfxw/GHSA-482h-w5qp-gfxw.json b/advisories/unreviewed/2024/08/GHSA-482h-w5qp-gfxw/GHSA-482h-w5qp-gfxw.json index 4bc5516f4c5..f91870a8dc1 100644 --- a/advisories/unreviewed/2024/08/GHSA-482h-w5qp-gfxw/GHSA-482h-w5qp-gfxw.json +++ b/advisories/unreviewed/2024/08/GHSA-482h-w5qp-gfxw/GHSA-482h-w5qp-gfxw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-482h-w5qp-gfxw", - "modified": "2024-08-22T06:30:29Z", + "modified": "2024-08-22T15:31:18Z", "published": "2024-08-22T06:30:29Z", "aliases": [ "CVE-2024-45166" ], "details": "An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Due to improper input validation, improper deserialization, and improper restriction of operations within the bounds of a memory buffer, IDOL2 is vulnerable to Denial-of-Service (DoS) attacks and possibly remote code execution. There is an access violation and EIP overwrite after five logins.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-22T04:15:24Z" diff --git a/advisories/unreviewed/2024/08/GHSA-4wrj-qhhf-3c55/GHSA-4wrj-qhhf-3c55.json b/advisories/unreviewed/2024/08/GHSA-4wrj-qhhf-3c55/GHSA-4wrj-qhhf-3c55.json index 61e3bf424df..96bd3b360b5 100644 --- a/advisories/unreviewed/2024/08/GHSA-4wrj-qhhf-3c55/GHSA-4wrj-qhhf-3c55.json +++ b/advisories/unreviewed/2024/08/GHSA-4wrj-qhhf-3c55/GHSA-4wrj-qhhf-3c55.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4wrj-qhhf-3c55", - "modified": "2024-08-13T15:31:35Z", + "modified": "2024-08-22T15:31:18Z", "published": "2024-08-13T15:31:35Z", "aliases": [ "CVE-2024-41623" ], "details": "An issue in D3D Security D3D IP Camera (D8801) v.V9.1.17.1.4-20180428 allows a local attacker to execute arbitrary code via a crafted payload", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-13T14:15:12Z" diff --git a/advisories/unreviewed/2024/08/GHSA-57cq-jgq2-x7vg/GHSA-57cq-jgq2-x7vg.json b/advisories/unreviewed/2024/08/GHSA-57cq-jgq2-x7vg/GHSA-57cq-jgq2-x7vg.json index e4ee28484ab..2ad7c673f6b 100644 --- a/advisories/unreviewed/2024/08/GHSA-57cq-jgq2-x7vg/GHSA-57cq-jgq2-x7vg.json +++ b/advisories/unreviewed/2024/08/GHSA-57cq-jgq2-x7vg/GHSA-57cq-jgq2-x7vg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-57cq-jgq2-x7vg", - "modified": "2024-08-21T21:30:46Z", + "modified": "2024-08-22T15:31:18Z", "published": "2024-08-21T21:30:46Z", "aliases": [ "CVE-2024-7967" ], "details": "Heap buffer overflow in Fonts in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,10 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-79" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-21T21:15:09Z" diff --git a/advisories/unreviewed/2024/08/GHSA-5wm9-5344-qrrj/GHSA-5wm9-5344-qrrj.json b/advisories/unreviewed/2024/08/GHSA-5wm9-5344-qrrj/GHSA-5wm9-5344-qrrj.json index 69f2753e649..760d0da5549 100644 --- a/advisories/unreviewed/2024/08/GHSA-5wm9-5344-qrrj/GHSA-5wm9-5344-qrrj.json +++ b/advisories/unreviewed/2024/08/GHSA-5wm9-5344-qrrj/GHSA-5wm9-5344-qrrj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5wm9-5344-qrrj", - "modified": "2024-08-20T21:30:35Z", + "modified": "2024-08-22T15:31:18Z", "published": "2024-08-20T21:30:35Z", "aliases": [ "CVE-2024-6800" diff --git a/advisories/unreviewed/2024/08/GHSA-7fgx-pmw9-49h5/GHSA-7fgx-pmw9-49h5.json b/advisories/unreviewed/2024/08/GHSA-7fgx-pmw9-49h5/GHSA-7fgx-pmw9-49h5.json index 10ffcf4ebd1..cb28fa3626e 100644 --- a/advisories/unreviewed/2024/08/GHSA-7fgx-pmw9-49h5/GHSA-7fgx-pmw9-49h5.json +++ b/advisories/unreviewed/2024/08/GHSA-7fgx-pmw9-49h5/GHSA-7fgx-pmw9-49h5.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1321", "CWE-94" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2024/08/GHSA-7r79-ppgg-4h8m/GHSA-7r79-ppgg-4h8m.json b/advisories/unreviewed/2024/08/GHSA-7r79-ppgg-4h8m/GHSA-7r79-ppgg-4h8m.json new file mode 100644 index 00000000000..aa12e620fc3 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-7r79-ppgg-4h8m/GHSA-7r79-ppgg-4h8m.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7r79-ppgg-4h8m", + "modified": "2024-08-22T15:31:19Z", + "published": "2024-08-22T15:31:19Z", + "aliases": [ + "CVE-2024-36440" + ], + "details": "An issue was discovered on Swissphone DiCal-RED 4009 devices. An attacker with access to the file /etc/deviceconfig may recover the administrative device password via password-cracking methods, because unsalted MD5 is used.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36440" + }, + { + "type": "WEB", + "url": "https://www.swissphone.com/en-us/solutions/components/terminals/radio-data-module-dical-red" + }, + { + "type": "WEB", + "url": "https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-037.txt" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-22T15:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-gqg7-4h7v-f4hf/GHSA-gqg7-4h7v-f4hf.json b/advisories/unreviewed/2024/08/GHSA-gqg7-4h7v-f4hf/GHSA-gqg7-4h7v-f4hf.json index 0050d2ea2f1..d84403b95ac 100644 --- a/advisories/unreviewed/2024/08/GHSA-gqg7-4h7v-f4hf/GHSA-gqg7-4h7v-f4hf.json +++ b/advisories/unreviewed/2024/08/GHSA-gqg7-4h7v-f4hf/GHSA-gqg7-4h7v-f4hf.json @@ -44,7 +44,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-jqxg-gg5c-r85j/GHSA-jqxg-gg5c-r85j.json b/advisories/unreviewed/2024/08/GHSA-jqxg-gg5c-r85j/GHSA-jqxg-gg5c-r85j.json index ba891eaaf8e..3d126396ec6 100644 --- a/advisories/unreviewed/2024/08/GHSA-jqxg-gg5c-r85j/GHSA-jqxg-gg5c-r85j.json +++ b/advisories/unreviewed/2024/08/GHSA-jqxg-gg5c-r85j/GHSA-jqxg-gg5c-r85j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jqxg-gg5c-r85j", - "modified": "2024-08-21T18:31:28Z", + "modified": "2024-08-22T15:31:18Z", "published": "2024-08-21T18:31:28Z", "aliases": [ "CVE-2024-42779" ], "details": "An Unrestricted file upload vulnerability was found in \"/music/ajax.php?action=save_music\" in Kashipara Music Management System v1.0. This allows attackers to execute arbitrary code via uploading a crafted PHP file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-21T18:15:10Z" diff --git a/advisories/unreviewed/2024/08/GHSA-mchm-hhh8-w57p/GHSA-mchm-hhh8-w57p.json b/advisories/unreviewed/2024/08/GHSA-mchm-hhh8-w57p/GHSA-mchm-hhh8-w57p.json new file mode 100644 index 00000000000..5355f15a6fe --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-mchm-hhh8-w57p/GHSA-mchm-hhh8-w57p.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mchm-hhh8-w57p", + "modified": "2024-08-22T15:31:19Z", + "published": "2024-08-22T15:31:19Z", + "aliases": [ + "CVE-2024-36439" + ], + "details": "Swissphone DiCal-RED 4009 devices allow a remote attacker to gain access to the administrative web interface via the device password's hash value, without knowing the actual device password.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36439" + }, + { + "type": "WEB", + "url": "https://www.swissphone.com/en-us/solutions/components/terminals/radio-data-module-dical-red" + }, + { + "type": "WEB", + "url": "https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-038.txt" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-22T15:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-pq5w-h3jm-m95c/GHSA-pq5w-h3jm-m95c.json b/advisories/unreviewed/2024/08/GHSA-pq5w-h3jm-m95c/GHSA-pq5w-h3jm-m95c.json index 831b5535bf6..3610bdd1988 100644 --- a/advisories/unreviewed/2024/08/GHSA-pq5w-h3jm-m95c/GHSA-pq5w-h3jm-m95c.json +++ b/advisories/unreviewed/2024/08/GHSA-pq5w-h3jm-m95c/GHSA-pq5w-h3jm-m95c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pq5w-h3jm-m95c", - "modified": "2024-08-21T21:30:46Z", + "modified": "2024-08-22T15:31:18Z", "published": "2024-08-21T21:30:46Z", "aliases": [ "CVE-2024-7971" ], "details": "Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-843" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-21T21:15:09Z" diff --git a/advisories/unreviewed/2024/08/GHSA-qgv4-x6mv-vh78/GHSA-qgv4-x6mv-vh78.json b/advisories/unreviewed/2024/08/GHSA-qgv4-x6mv-vh78/GHSA-qgv4-x6mv-vh78.json new file mode 100644 index 00000000000..daf64502f7e --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-qgv4-x6mv-vh78/GHSA-qgv4-x6mv-vh78.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qgv4-x6mv-vh78", + "modified": "2024-08-22T15:31:19Z", + "published": "2024-08-22T15:31:19Z", + "aliases": [ + "CVE-2024-36445" + ], + "details": "Swissphone DiCal-RED 4009 devices allow a remote attacker to gain a root shell via TELNET without authentication.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36445" + }, + { + "type": "WEB", + "url": "https://www.swissphone.com/en-us/solutions/components/terminals/radio-data-module-dical-red" + }, + { + "type": "WEB", + "url": "https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-035.txt" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-22T15:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-rq5p-j687-h2vf/GHSA-rq5p-j687-h2vf.json b/advisories/unreviewed/2024/08/GHSA-rq5p-j687-h2vf/GHSA-rq5p-j687-h2vf.json new file mode 100644 index 00000000000..b181db6f9f5 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-rq5p-j687-h2vf/GHSA-rq5p-j687-h2vf.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rq5p-j687-h2vf", + "modified": "2024-08-22T15:31:19Z", + "published": "2024-08-22T15:31:19Z", + "aliases": [ + "CVE-2024-36442" + ], + "details": "cgi-bin/fdmcgiwebv2.cgi on Swissphone DiCal-RED 4009 devices allows an authenticated attacker to gain access to arbitrary files on the device's file system.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36442" + }, + { + "type": "WEB", + "url": "https://www.swissphone.com/en-us/solutions/components/terminals/radio-data-module-dical-red" + }, + { + "type": "WEB", + "url": "https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-039.txt" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-22T15:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-w4h5-9mg2-vv6r/GHSA-w4h5-9mg2-vv6r.json b/advisories/unreviewed/2024/08/GHSA-w4h5-9mg2-vv6r/GHSA-w4h5-9mg2-vv6r.json index 054aa21d4b8..76b07aab571 100644 --- a/advisories/unreviewed/2024/08/GHSA-w4h5-9mg2-vv6r/GHSA-w4h5-9mg2-vv6r.json +++ b/advisories/unreviewed/2024/08/GHSA-w4h5-9mg2-vv6r/GHSA-w4h5-9mg2-vv6r.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w4h5-9mg2-vv6r", - "modified": "2024-08-13T18:31:15Z", + "modified": "2024-08-22T15:31:18Z", "published": "2024-08-13T18:31:15Z", "aliases": [ "CVE-2024-7746" ], "details": "Use of Default Credentials vulnerability in Tananaev Solutions Traccar Server on Administrator Panel modules allows Authentication Abuse.This issue affects the privileged transactions implemented by the Traccar solution that should otherwise be protected by the authentication mechanism. \nThese transactions could have an impact on any sensitive aspect of the platform, including Confidentiality, Integrity and Availability.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" @@ -28,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-1392" + "CWE-1392", + "CWE-287" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-wcph-x6mx-4gh6/GHSA-wcph-x6mx-4gh6.json b/advisories/unreviewed/2024/08/GHSA-wcph-x6mx-4gh6/GHSA-wcph-x6mx-4gh6.json index e4985db6a21..c47056c2935 100644 --- a/advisories/unreviewed/2024/08/GHSA-wcph-x6mx-4gh6/GHSA-wcph-x6mx-4gh6.json +++ b/advisories/unreviewed/2024/08/GHSA-wcph-x6mx-4gh6/GHSA-wcph-x6mx-4gh6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wcph-x6mx-4gh6", - "modified": "2024-08-22T06:30:30Z", + "modified": "2024-08-22T15:31:18Z", "published": "2024-08-22T06:30:29Z", "aliases": [ "CVE-2024-45168" ], "details": "An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Data is transferred over a raw socket without any authentication mechanism. Thus, communication endpoints are not verifiable.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-22T04:15:27Z" diff --git a/advisories/unreviewed/2024/08/GHSA-x38q-hvmx-rwhg/GHSA-x38q-hvmx-rwhg.json b/advisories/unreviewed/2024/08/GHSA-x38q-hvmx-rwhg/GHSA-x38q-hvmx-rwhg.json index 4ce46001f37..09fd75aa2dd 100644 --- a/advisories/unreviewed/2024/08/GHSA-x38q-hvmx-rwhg/GHSA-x38q-hvmx-rwhg.json +++ b/advisories/unreviewed/2024/08/GHSA-x38q-hvmx-rwhg/GHSA-x38q-hvmx-rwhg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x38q-hvmx-rwhg", - "modified": "2024-08-21T21:30:46Z", + "modified": "2024-08-22T15:31:18Z", "published": "2024-08-21T21:30:46Z", "aliases": [ "CVE-2024-7965" ], "details": "Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-358" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-21T21:15:08Z" diff --git a/advisories/unreviewed/2024/08/GHSA-x7fm-xq4g-7h9j/GHSA-x7fm-xq4g-7h9j.json b/advisories/unreviewed/2024/08/GHSA-x7fm-xq4g-7h9j/GHSA-x7fm-xq4g-7h9j.json new file mode 100644 index 00000000000..b0f2780c424 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-x7fm-xq4g-7h9j/GHSA-x7fm-xq4g-7h9j.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x7fm-xq4g-7h9j", + "modified": "2024-08-22T15:31:19Z", + "published": "2024-08-22T15:31:19Z", + "aliases": [ + "CVE-2024-36444" + ], + "details": "cgi-bin/fdmcgiwebv2.cgi on Swissphone DiCal-RED 4009 devices allows an unauthenticated attacker to gain access to device logs.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36444" + }, + { + "type": "WEB", + "url": "https://www.swissphone.com/en-us/solutions/components/terminals/radio-data-module-dical-red" + }, + { + "type": "WEB", + "url": "https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-040.txt" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-22T15:15:16Z" + } +} \ No newline at end of file