diff --git a/advisories/unreviewed/2023/06/GHSA-5gxg-33gj-54pc/GHSA-5gxg-33gj-54pc.json b/advisories/unreviewed/2023/06/GHSA-5gxg-33gj-54pc/GHSA-5gxg-33gj-54pc.json index b7062a6eac3..8b3d8c52320 100644 --- a/advisories/unreviewed/2023/06/GHSA-5gxg-33gj-54pc/GHSA-5gxg-33gj-54pc.json +++ b/advisories/unreviewed/2023/06/GHSA-5gxg-33gj-54pc/GHSA-5gxg-33gj-54pc.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-94" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-hr5f-9r38-h32r/GHSA-hr5f-9r38-h32r.json b/advisories/unreviewed/2023/06/GHSA-hr5f-9r38-h32r/GHSA-hr5f-9r38-h32r.json index 55302eb7655..6772ad9847d 100644 --- a/advisories/unreviewed/2023/06/GHSA-hr5f-9r38-h32r/GHSA-hr5f-9r38-h32r.json +++ b/advisories/unreviewed/2023/06/GHSA-hr5f-9r38-h32r/GHSA-hr5f-9r38-h32r.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-mm93-3hgx-48rj/GHSA-mm93-3hgx-48rj.json b/advisories/unreviewed/2023/06/GHSA-mm93-3hgx-48rj/GHSA-mm93-3hgx-48rj.json index 1a5c2016ac3..eb2299af599 100644 --- a/advisories/unreviewed/2023/06/GHSA-mm93-3hgx-48rj/GHSA-mm93-3hgx-48rj.json +++ b/advisories/unreviewed/2023/06/GHSA-mm93-3hgx-48rj/GHSA-mm93-3hgx-48rj.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-94" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-qp5q-f4cm-wxh9/GHSA-qp5q-f4cm-wxh9.json b/advisories/unreviewed/2023/06/GHSA-qp5q-f4cm-wxh9/GHSA-qp5q-f4cm-wxh9.json index 89dbbebf618..c689c518443 100644 --- a/advisories/unreviewed/2023/06/GHSA-qp5q-f4cm-wxh9/GHSA-qp5q-f4cm-wxh9.json +++ b/advisories/unreviewed/2023/06/GHSA-qp5q-f4cm-wxh9/GHSA-qp5q-f4cm-wxh9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qp5q-f4cm-wxh9", - "modified": "2024-04-04T04:43:29Z", + "modified": "2025-01-06T18:30:50Z", "published": "2023-06-12T18:30:18Z", "aliases": [ "CVE-2023-30198" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://github.com/PrestaShop/PrestaShop/blob/6c05518b807d014ee8edb811041e3de232520c28/classes/Tools.php#L1247" }, + { + "type": "WEB", + "url": "https://packetstorm.news/files/id/173136" + }, { "type": "WEB", "url": "http://packetstormsecurity.com/files/173136/PrestaShop-Winbiz-Payment-Improper-Limitation.html" diff --git a/advisories/unreviewed/2023/06/GHSA-r8vm-pxwg-4rmm/GHSA-r8vm-pxwg-4rmm.json b/advisories/unreviewed/2023/06/GHSA-r8vm-pxwg-4rmm/GHSA-r8vm-pxwg-4rmm.json index 60b3eeb73b1..dab33be5018 100644 --- a/advisories/unreviewed/2023/06/GHSA-r8vm-pxwg-4rmm/GHSA-r8vm-pxwg-4rmm.json +++ b/advisories/unreviewed/2023/06/GHSA-r8vm-pxwg-4rmm/GHSA-r8vm-pxwg-4rmm.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-287" + "CWE-287", + "CWE-863" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-rh7w-47gg-jp4c/GHSA-rh7w-47gg-jp4c.json b/advisories/unreviewed/2023/06/GHSA-rh7w-47gg-jp4c/GHSA-rh7w-47gg-jp4c.json index d55ca091e40..9011fb700c4 100644 --- a/advisories/unreviewed/2023/06/GHSA-rh7w-47gg-jp4c/GHSA-rh7w-47gg-jp4c.json +++ b/advisories/unreviewed/2023/06/GHSA-rh7w-47gg-jp4c/GHSA-rh7w-47gg-jp4c.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-400" + "CWE-400", + "CWE-770" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-vr4q-p49j-hq95/GHSA-vr4q-p49j-hq95.json b/advisories/unreviewed/2023/06/GHSA-vr4q-p49j-hq95/GHSA-vr4q-p49j-hq95.json index be6e1a7ec47..7dd8e8edc7f 100644 --- a/advisories/unreviewed/2023/06/GHSA-vr4q-p49j-hq95/GHSA-vr4q-p49j-hq95.json +++ b/advisories/unreviewed/2023/06/GHSA-vr4q-p49j-hq95/GHSA-vr4q-p49j-hq95.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/07/GHSA-xh9q-jvq8-p253/GHSA-xh9q-jvq8-p253.json b/advisories/unreviewed/2023/07/GHSA-xh9q-jvq8-p253/GHSA-xh9q-jvq8-p253.json index 20c103e2538..078918021f3 100644 --- a/advisories/unreviewed/2023/07/GHSA-xh9q-jvq8-p253/GHSA-xh9q-jvq8-p253.json +++ b/advisories/unreviewed/2023/07/GHSA-xh9q-jvq8-p253/GHSA-xh9q-jvq8-p253.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/11/GHSA-53mx-8hhc-gmp3/GHSA-53mx-8hhc-gmp3.json b/advisories/unreviewed/2024/11/GHSA-53mx-8hhc-gmp3/GHSA-53mx-8hhc-gmp3.json index fc1c547cc77..36546b98a63 100644 --- a/advisories/unreviewed/2024/11/GHSA-53mx-8hhc-gmp3/GHSA-53mx-8hhc-gmp3.json +++ b/advisories/unreviewed/2024/11/GHSA-53mx-8hhc-gmp3/GHSA-53mx-8hhc-gmp3.json @@ -53,7 +53,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/11/GHSA-qxg5-mcmp-m3m9/GHSA-qxg5-mcmp-m3m9.json b/advisories/unreviewed/2024/11/GHSA-qxg5-mcmp-m3m9/GHSA-qxg5-mcmp-m3m9.json index 28a6cd8adfa..e79986aa5b8 100644 --- a/advisories/unreviewed/2024/11/GHSA-qxg5-mcmp-m3m9/GHSA-qxg5-mcmp-m3m9.json +++ b/advisories/unreviewed/2024/11/GHSA-qxg5-mcmp-m3m9/GHSA-qxg5-mcmp-m3m9.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qxg5-mcmp-m3m9", - "modified": "2024-12-03T21:31:21Z", + "modified": "2025-01-06T18:31:00Z", "published": "2024-11-13T00:30:48Z", "aliases": [ "CVE-2024-11168" ], "details": "The urllib.parse.urlsplit() and urlparse() functions improperly validated bracketed hosts (`[]`), allowing hosts that weren't IPv6 or IPvFuture. This behavior was not conformant to RFC 3986 and potentially enabled SSRF if a URL is processed by more than one URL parser.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/12/GHSA-2j8h-rq7h-37cq/GHSA-2j8h-rq7h-37cq.json b/advisories/unreviewed/2024/12/GHSA-2j8h-rq7h-37cq/GHSA-2j8h-rq7h-37cq.json index 36af37b3266..2e054c18726 100644 --- a/advisories/unreviewed/2024/12/GHSA-2j8h-rq7h-37cq/GHSA-2j8h-rq7h-37cq.json +++ b/advisories/unreviewed/2024/12/GHSA-2j8h-rq7h-37cq/GHSA-2j8h-rq7h-37cq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2j8h-rq7h-37cq", - "modified": "2024-12-27T15:31:52Z", + "modified": "2025-01-06T18:31:00Z", "published": "2024-12-27T15:31:52Z", "aliases": [ "CVE-2024-53231" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncpufreq: CPPC: Fix possible null-ptr-deref for cpufreq_cpu_get_raw()\n\ncpufreq_cpu_get_raw() may return NULL if the cpu is not in\npolicy->cpus cpu mask and it will cause null pointer dereference.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T14:15:31Z" diff --git a/advisories/unreviewed/2024/12/GHSA-2rgr-w2hf-5v57/GHSA-2rgr-w2hf-5v57.json b/advisories/unreviewed/2024/12/GHSA-2rgr-w2hf-5v57/GHSA-2rgr-w2hf-5v57.json index b7ae535d2e0..0a61b452e1e 100644 --- a/advisories/unreviewed/2024/12/GHSA-2rgr-w2hf-5v57/GHSA-2rgr-w2hf-5v57.json +++ b/advisories/unreviewed/2024/12/GHSA-2rgr-w2hf-5v57/GHSA-2rgr-w2hf-5v57.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2rgr-w2hf-5v57", - "modified": "2024-12-05T12:31:28Z", + "modified": "2025-01-06T18:31:00Z", "published": "2024-12-04T12:31:45Z", "aliases": [ "CVE-2024-52276" ], "details": "** INITIAL LIMITED RELEASE **\n\nUser Interface (UI) Misrepresentation of Critical Information vulnerability in [WITHHELD] allows Content Spoofing.This issue affects [WITHHELD]: through 2024-12-04.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Red" diff --git a/advisories/unreviewed/2024/12/GHSA-32x8-xhwp-vhg9/GHSA-32x8-xhwp-vhg9.json b/advisories/unreviewed/2024/12/GHSA-32x8-xhwp-vhg9/GHSA-32x8-xhwp-vhg9.json index 89d415e037d..7df74169aa2 100644 --- a/advisories/unreviewed/2024/12/GHSA-32x8-xhwp-vhg9/GHSA-32x8-xhwp-vhg9.json +++ b/advisories/unreviewed/2024/12/GHSA-32x8-xhwp-vhg9/GHSA-32x8-xhwp-vhg9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-32x8-xhwp-vhg9", - "modified": "2024-12-27T15:31:56Z", + "modified": "2025-01-06T18:31:00Z", "published": "2024-12-27T15:31:56Z", "aliases": [ "CVE-2024-56670" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: u_serial: Fix the issue that gs_start_io crashed due to accessing null pointer\n\nConsidering that in some extreme cases,\nwhen u_serial driver is accessed by multiple threads,\nThread A is executing the open operation and calling the gs_open,\nThread B is executing the disconnect operation and calling the\ngserial_disconnect function,The port->port_usb pointer will be set to NULL.\n\nE.g.\n Thread A Thread B\n gs_open() gadget_unbind_driver()\n gs_start_io() composite_disconnect()\n gs_start_rx() gserial_disconnect()\n ... ...\n spin_unlock(&port->port_lock)\n status = usb_ep_queue() spin_lock(&port->port_lock)\n spin_lock(&port->port_lock) port->port_usb = NULL\n gs_free_requests(port->port_usb->in) spin_unlock(&port->port_lock)\n Crash\n\nThis causes thread A to access a null pointer (port->port_usb is null)\nwhen calling the gs_free_requests function, causing a crash.\n\nIf port_usb is NULL, the release request will be skipped as it\nwill be done by gserial_disconnect.\n\nSo add a null pointer check to gs_start_io before attempting\nto access the value of the pointer port->port_usb.\n\nCall trace:\n gs_start_io+0x164/0x25c\n gs_open+0x108/0x13c\n tty_open+0x314/0x638\n chrdev_open+0x1b8/0x258\n do_dentry_open+0x2c4/0x700\n vfs_open+0x2c/0x3c\n path_openat+0xa64/0xc60\n do_filp_open+0xb8/0x164\n do_sys_openat2+0x84/0xf0\n __arm64_sys_openat+0x70/0x9c\n invoke_syscall+0x58/0x114\n el0_svc_common+0x80/0xe0\n do_el0_svc+0x1c/0x28\n el0_svc+0x38/0x68", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T15:15:26Z" diff --git a/advisories/unreviewed/2024/12/GHSA-376g-f56r-v5h4/GHSA-376g-f56r-v5h4.json b/advisories/unreviewed/2024/12/GHSA-376g-f56r-v5h4/GHSA-376g-f56r-v5h4.json index 8633575d72b..7adf7020d5b 100644 --- a/advisories/unreviewed/2024/12/GHSA-376g-f56r-v5h4/GHSA-376g-f56r-v5h4.json +++ b/advisories/unreviewed/2024/12/GHSA-376g-f56r-v5h4/GHSA-376g-f56r-v5h4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-376g-f56r-v5h4", - "modified": "2024-12-27T15:31:52Z", + "modified": "2025-01-06T18:31:00Z", "published": "2024-12-27T15:31:52Z", "aliases": [ "CVE-2024-53221" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix null-ptr-deref in f2fs_submit_page_bio()\n\nThere's issue as follows when concurrently installing the f2fs.ko\nmodule and mounting the f2fs file system:\nKASAN: null-ptr-deref in range [0x0000000000000020-0x0000000000000027]\nRIP: 0010:__bio_alloc+0x2fb/0x6c0 [f2fs]\nCall Trace:\n \n f2fs_submit_page_bio+0x126/0x8b0 [f2fs]\n __get_meta_page+0x1d4/0x920 [f2fs]\n get_checkpoint_version.constprop.0+0x2b/0x3c0 [f2fs]\n validate_checkpoint+0xac/0x290 [f2fs]\n f2fs_get_valid_checkpoint+0x207/0x950 [f2fs]\n f2fs_fill_super+0x1007/0x39b0 [f2fs]\n mount_bdev+0x183/0x250\n legacy_get_tree+0xf4/0x1e0\n vfs_get_tree+0x88/0x340\n do_new_mount+0x283/0x5e0\n path_mount+0x2b2/0x15b0\n __x64_sys_mount+0x1fe/0x270\n do_syscall_64+0x5f/0x170\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\nAbove issue happens as the biset of the f2fs file system is not\ninitialized before register \"f2fs_fs_type\".\nTo address above issue just register \"f2fs_fs_type\" at the last in\ninit_f2fs_fs(). Ensure that all f2fs file system resources are\ninitialized.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T14:15:30Z" diff --git a/advisories/unreviewed/2024/12/GHSA-4fc4-p432-gw7h/GHSA-4fc4-p432-gw7h.json b/advisories/unreviewed/2024/12/GHSA-4fc4-p432-gw7h/GHSA-4fc4-p432-gw7h.json index 68704cedca2..3855d203b4f 100644 --- a/advisories/unreviewed/2024/12/GHSA-4fc4-p432-gw7h/GHSA-4fc4-p432-gw7h.json +++ b/advisories/unreviewed/2024/12/GHSA-4fc4-p432-gw7h/GHSA-4fc4-p432-gw7h.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4fc4-p432-gw7h", - "modified": "2024-12-29T12:30:41Z", + "modified": "2025-01-06T18:31:01Z", "published": "2024-12-29T12:30:41Z", "aliases": [ "CVE-2024-56751" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: release nexthop on device removal\n\nThe CI is hitting some aperiodic hangup at device removal time in the\npmtu.sh self-test:\n\nunregister_netdevice: waiting for veth_A-R1 to become free. Usage count = 6\nref_tracker: veth_A-R1@ffff888013df15d8 has 1/5 users at\n\tdst_init+0x84/0x4a0\n\tdst_alloc+0x97/0x150\n\tip6_dst_alloc+0x23/0x90\n\tip6_rt_pcpu_alloc+0x1e6/0x520\n\tip6_pol_route+0x56f/0x840\n\tfib6_rule_lookup+0x334/0x630\n\tip6_route_output_flags+0x259/0x480\n\tip6_dst_lookup_tail.constprop.0+0x5c2/0x940\n\tip6_dst_lookup_flow+0x88/0x190\n\tudp_tunnel6_dst_lookup+0x2a7/0x4c0\n\tvxlan_xmit_one+0xbde/0x4a50 [vxlan]\n\tvxlan_xmit+0x9ad/0xf20 [vxlan]\n\tdev_hard_start_xmit+0x10e/0x360\n\t__dev_queue_xmit+0xf95/0x18c0\n\tarp_solicit+0x4a2/0xe00\n\tneigh_probe+0xaa/0xf0\n\nWhile the first suspect is the dst_cache, explicitly tracking the dst\nowing the last device reference via probes proved such dst is held by\nthe nexthop in the originating fib6_info.\n\nSimilar to commit f5b51fe804ec (\"ipv6: route: purge exception on\nremoval\"), we need to explicitly release the originating fib info when\ndisconnecting a to-be-removed device from a live ipv6 dst: move the\nfib6_info cleanup into ip6_dst_ifdown().\n\nTested running:\n\n./pmtu.sh cleanup_ipv6_exception\n\nin a tight loop for more than 400 iterations with no spat, running an\nunpatched kernel I observed a splat every ~10 iterations.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -37,7 +42,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-29T12:15:08Z" diff --git a/advisories/unreviewed/2024/12/GHSA-5546-cr76-j66r/GHSA-5546-cr76-j66r.json b/advisories/unreviewed/2024/12/GHSA-5546-cr76-j66r/GHSA-5546-cr76-j66r.json index 2ebd54a1312..7c0249b74a3 100644 --- a/advisories/unreviewed/2024/12/GHSA-5546-cr76-j66r/GHSA-5546-cr76-j66r.json +++ b/advisories/unreviewed/2024/12/GHSA-5546-cr76-j66r/GHSA-5546-cr76-j66r.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5546-cr76-j66r", - "modified": "2024-12-29T09:30:46Z", + "modified": "2025-01-06T18:31:01Z", "published": "2024-12-29T09:30:46Z", "aliases": [ "CVE-2024-56712" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nudmabuf: fix memory leak on last export_udmabuf() error path\n\nIn export_udmabuf(), if dma_buf_fd() fails because the FD table is full, a\ndma_buf owning the udmabuf has already been created; but the error handling\nin udmabuf_create() will tear down the udmabuf without doing anything about\nthe containing dma_buf.\n\nThis leaves a dma_buf in memory that contains a dangling pointer; though\nthat doesn't seem to lead to anything bad except a memory leak.\n\nFix it by moving the dma_buf_fd() call out of export_udmabuf() so that we\ncan give it different error handling.\n\nNote that the shape of this code changed a lot in commit 5e72b2b41a21\n(\"udmabuf: convert udmabuf driver to use folios\"); but the memory leak\nseems to have existed since the introduction of udmabuf.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-29T09:15:06Z" diff --git a/advisories/unreviewed/2024/12/GHSA-67vx-3f64-r6h9/GHSA-67vx-3f64-r6h9.json b/advisories/unreviewed/2024/12/GHSA-67vx-3f64-r6h9/GHSA-67vx-3f64-r6h9.json index 80df0aaaa0f..0858ba40ef6 100644 --- a/advisories/unreviewed/2024/12/GHSA-67vx-3f64-r6h9/GHSA-67vx-3f64-r6h9.json +++ b/advisories/unreviewed/2024/12/GHSA-67vx-3f64-r6h9/GHSA-67vx-3f64-r6h9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-67vx-3f64-r6h9", - "modified": "2024-12-27T15:31:56Z", + "modified": "2025-01-06T18:31:00Z", "published": "2024-12-27T15:31:56Z", "aliases": [ "CVE-2024-56666" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdkfd: Dereference null return value\n\nIn the function pqm_uninit there is a call-assignment of \"pdd =\nkfd_get_process_device_data\" which could be null, and this value was\nlater dereferenced without checking.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T15:15:26Z" diff --git a/advisories/unreviewed/2024/12/GHSA-6h2p-g88j-gcm9/GHSA-6h2p-g88j-gcm9.json b/advisories/unreviewed/2024/12/GHSA-6h2p-g88j-gcm9/GHSA-6h2p-g88j-gcm9.json index 9f16b0db54f..1209dff7d08 100644 --- a/advisories/unreviewed/2024/12/GHSA-6h2p-g88j-gcm9/GHSA-6h2p-g88j-gcm9.json +++ b/advisories/unreviewed/2024/12/GHSA-6h2p-g88j-gcm9/GHSA-6h2p-g88j-gcm9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6h2p-g88j-gcm9", - "modified": "2024-12-27T15:31:56Z", + "modified": "2025-01-06T18:31:00Z", "published": "2024-12-27T15:31:56Z", "aliases": [ "CVE-2024-56667" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/i915: Fix NULL pointer dereference in capture_engine\n\nWhen the intel_context structure contains NULL,\nit raises a NULL pointer dereference error in drm_info().\n\n(cherry picked from commit 754302a5bc1bd8fd3b7d85c168b0a1af6d4bba4d)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T15:15:26Z" diff --git a/advisories/unreviewed/2024/12/GHSA-6hfh-2mvq-2jjc/GHSA-6hfh-2mvq-2jjc.json b/advisories/unreviewed/2024/12/GHSA-6hfh-2mvq-2jjc/GHSA-6hfh-2mvq-2jjc.json index 32d1eb609ed..3447fedabfa 100644 --- a/advisories/unreviewed/2024/12/GHSA-6hfh-2mvq-2jjc/GHSA-6hfh-2mvq-2jjc.json +++ b/advisories/unreviewed/2024/12/GHSA-6hfh-2mvq-2jjc/GHSA-6hfh-2mvq-2jjc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6hfh-2mvq-2jjc", - "modified": "2024-12-27T15:31:54Z", + "modified": "2025-01-06T18:31:00Z", "published": "2024-12-27T15:31:54Z", "aliases": [ "CVE-2024-56577" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: mtk-jpeg: Fix null-ptr-deref during unload module\n\nThe workqueue should be destroyed in mtk_jpeg_core.c since commit\n09aea13ecf6f (\"media: mtk-jpeg: refactor some variables\"), otherwise\nthe below calltrace can be easily triggered.\n\n[ 677.862514] Unable to handle kernel paging request at virtual address dfff800000000023\n[ 677.863633] KASAN: null-ptr-deref in range [0x0000000000000118-0x000000000000011f]\n...\n[ 677.879654] CPU: 6 PID: 1071 Comm: modprobe Tainted: G O 6.8.12-mtk+gfa1a78e5d24b+ #17\n...\n[ 677.882838] pc : destroy_workqueue+0x3c/0x770\n[ 677.883413] lr : mtk_jpegdec_destroy_workqueue+0x70/0x88 [mtk_jpeg_dec_hw]\n[ 677.884314] sp : ffff80008ad974f0\n[ 677.884744] x29: ffff80008ad974f0 x28: ffff0000d7115580 x27: ffff0000dd691070\n[ 677.885669] x26: ffff0000dd691408 x25: ffff8000844af3e0 x24: ffff80008ad97690\n[ 677.886592] x23: ffff0000e051d400 x22: ffff0000dd691010 x21: dfff800000000000\n[ 677.887515] x20: 0000000000000000 x19: 0000000000000000 x18: ffff800085397ac0\n[ 677.888438] x17: 0000000000000000 x16: ffff8000801b87c8 x15: 1ffff000115b2e10\n[ 677.889361] x14: 00000000f1f1f1f1 x13: 0000000000000000 x12: ffff7000115b2e4d\n[ 677.890285] x11: 1ffff000115b2e4c x10: ffff7000115b2e4c x9 : ffff80000aa43e90\n[ 677.891208] x8 : 00008fffeea4d1b4 x7 : ffff80008ad97267 x6 : 0000000000000001\n[ 677.892131] x5 : ffff80008ad97260 x4 : ffff7000115b2e4d x3 : 0000000000000000\n[ 677.893054] x2 : 0000000000000023 x1 : dfff800000000000 x0 : 0000000000000118\n[ 677.893977] Call trace:\n[ 677.894297] destroy_workqueue+0x3c/0x770\n[ 677.894826] mtk_jpegdec_destroy_workqueue+0x70/0x88 [mtk_jpeg_dec_hw]\n[ 677.895677] devm_action_release+0x50/0x90\n[ 677.896211] release_nodes+0xe8/0x170\n[ 677.896688] devres_release_all+0xf8/0x178\n[ 677.897219] device_unbind_cleanup+0x24/0x170\n[ 677.897785] device_release_driver_internal+0x35c/0x480\n[ 677.898461] device_release_driver+0x20/0x38\n...\n[ 677.912665] ---[ end trace 0000000000000000 ]---", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T15:15:16Z" diff --git a/advisories/unreviewed/2024/12/GHSA-6jfc-jg7w-jc55/GHSA-6jfc-jg7w-jc55.json b/advisories/unreviewed/2024/12/GHSA-6jfc-jg7w-jc55/GHSA-6jfc-jg7w-jc55.json index 04a926afc6d..479557f46b8 100644 --- a/advisories/unreviewed/2024/12/GHSA-6jfc-jg7w-jc55/GHSA-6jfc-jg7w-jc55.json +++ b/advisories/unreviewed/2024/12/GHSA-6jfc-jg7w-jc55/GHSA-6jfc-jg7w-jc55.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6jfc-jg7w-jc55", - "modified": "2024-12-27T15:31:54Z", + "modified": "2025-01-06T18:31:00Z", "published": "2024-12-27T15:31:54Z", "aliases": [ "CVE-2024-56574" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: ts2020: fix null-ptr-deref in ts2020_probe()\n\nKASAN reported a null-ptr-deref issue when executing the following\ncommand:\n\n # echo ts2020 0x20 > /sys/bus/i2c/devices/i2c-0/new_device\n KASAN: null-ptr-deref in range [0x0000000000000010-0x0000000000000017]\n CPU: 53 UID: 0 PID: 970 Comm: systemd-udevd Not tainted 6.12.0-rc2+ #24\n Hardware name: QEMU Standard PC (Q35 + ICH9, 2009)\n RIP: 0010:ts2020_probe+0xad/0xe10 [ts2020]\n RSP: 0018:ffffc9000abbf598 EFLAGS: 00010202\n RAX: dffffc0000000000 RBX: 0000000000000000 RCX: ffffffffc0714809\n RDX: 0000000000000002 RSI: ffff88811550be00 RDI: 0000000000000010\n RBP: ffff888109868800 R08: 0000000000000001 R09: fffff52001577eb6\n R10: 0000000000000000 R11: ffffc9000abbff50 R12: ffffffffc0714790\n R13: 1ffff92001577eb8 R14: ffffffffc07190d0 R15: 0000000000000001\n FS: 00007f95f13b98c0(0000) GS:ffff888149280000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 0000555d2634b000 CR3: 0000000152236000 CR4: 00000000000006f0\n DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n Call Trace:\n \n ts2020_probe+0xad/0xe10 [ts2020]\n i2c_device_probe+0x421/0xb40\n really_probe+0x266/0x850\n ...\n\nThe cause of the problem is that when using sysfs to dynamically register\nan i2c device, there is no platform data, but the probe process of ts2020\nneeds to use platform data, resulting in a null pointer being accessed.\n\nSolve this problem by adding checks to platform data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T15:15:16Z" diff --git a/advisories/unreviewed/2024/12/GHSA-6wm7-jp97-x8j3/GHSA-6wm7-jp97-x8j3.json b/advisories/unreviewed/2024/12/GHSA-6wm7-jp97-x8j3/GHSA-6wm7-jp97-x8j3.json index 32faca945f2..8487b25460d 100644 --- a/advisories/unreviewed/2024/12/GHSA-6wm7-jp97-x8j3/GHSA-6wm7-jp97-x8j3.json +++ b/advisories/unreviewed/2024/12/GHSA-6wm7-jp97-x8j3/GHSA-6wm7-jp97-x8j3.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-7hpx-3fcf-fxr2/GHSA-7hpx-3fcf-fxr2.json b/advisories/unreviewed/2024/12/GHSA-7hpx-3fcf-fxr2/GHSA-7hpx-3fcf-fxr2.json index 1c7d3a1d5db..34f1dfee6dc 100644 --- a/advisories/unreviewed/2024/12/GHSA-7hpx-3fcf-fxr2/GHSA-7hpx-3fcf-fxr2.json +++ b/advisories/unreviewed/2024/12/GHSA-7hpx-3fcf-fxr2/GHSA-7hpx-3fcf-fxr2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7hpx-3fcf-fxr2", - "modified": "2024-12-27T15:31:56Z", + "modified": "2025-01-06T18:31:00Z", "published": "2024-12-27T15:31:56Z", "aliases": [ "CVE-2024-56668" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\niommu/vt-d: Fix qi_batch NULL pointer with nested parent domain\n\nThe qi_batch is allocated when assigning cache tag for a domain. While\nfor nested parent domain, it is missed. Hence, when trying to map pages\nto the nested parent, NULL dereference occurred. Also, there is potential\nmemleak since there is no lock around domain->qi_batch allocation.\n\nTo solve it, add a helper for qi_batch allocation, and call it in both\nthe __cache_tag_assign_domain() and __cache_tag_assign_parent_domain().\n\n BUG: kernel NULL pointer dereference, address: 0000000000000200\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\n PGD 8104795067 P4D 0\n Oops: Oops: 0000 [#1] PREEMPT SMP NOPTI\n CPU: 223 UID: 0 PID: 4357 Comm: qemu-system-x86 Not tainted 6.13.0-rc1-00028-g4b50c3c3b998-dirty #2632\n Call Trace:\n ? __die+0x24/0x70\n ? page_fault_oops+0x80/0x150\n ? do_user_addr_fault+0x63/0x7b0\n ? exc_page_fault+0x7c/0x220\n ? asm_exc_page_fault+0x26/0x30\n ? cache_tag_flush_range_np+0x13c/0x260\n intel_iommu_iotlb_sync_map+0x1a/0x30\n iommu_map+0x61/0xf0\n batch_to_domain+0x188/0x250\n iopt_area_fill_domains+0x125/0x320\n ? rcu_is_watching+0x11/0x50\n iopt_map_pages+0x63/0x100\n iopt_map_common.isra.0+0xa7/0x190\n iopt_map_user_pages+0x6a/0x80\n iommufd_ioas_map+0xcd/0x1d0\n iommufd_fops_ioctl+0x118/0x1c0\n __x64_sys_ioctl+0x93/0xc0\n do_syscall_64+0x71/0x140\n entry_SYSCALL_64_after_hwframe+0x76/0x7e", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T15:15:26Z" diff --git a/advisories/unreviewed/2024/12/GHSA-8367-hgvv-7m56/GHSA-8367-hgvv-7m56.json b/advisories/unreviewed/2024/12/GHSA-8367-hgvv-7m56/GHSA-8367-hgvv-7m56.json index 96d71d76db4..0156ae1d807 100644 --- a/advisories/unreviewed/2024/12/GHSA-8367-hgvv-7m56/GHSA-8367-hgvv-7m56.json +++ b/advisories/unreviewed/2024/12/GHSA-8367-hgvv-7m56/GHSA-8367-hgvv-7m56.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8367-hgvv-7m56", - "modified": "2024-12-29T12:30:41Z", + "modified": "2025-01-06T18:31:01Z", "published": "2024-12-29T12:30:41Z", "aliases": [ "CVE-2024-56748" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: qedf: Fix a possible memory leak in qedf_alloc_and_init_sb()\n\nHook \"qed_ops->common->sb_init = qed_sb_init\" does not release the DMA\nmemory sb_virt when it fails. Add dma_free_coherent() to free it. This\nis the same way as qedr_alloc_mem_sb() and qede_alloc_mem_sb().", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-29T12:15:08Z" diff --git a/advisories/unreviewed/2024/12/GHSA-896f-hp7f-gqr7/GHSA-896f-hp7f-gqr7.json b/advisories/unreviewed/2024/12/GHSA-896f-hp7f-gqr7/GHSA-896f-hp7f-gqr7.json index f63ec353ee8..7f6ed26bbe1 100644 --- a/advisories/unreviewed/2024/12/GHSA-896f-hp7f-gqr7/GHSA-896f-hp7f-gqr7.json +++ b/advisories/unreviewed/2024/12/GHSA-896f-hp7f-gqr7/GHSA-896f-hp7f-gqr7.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-8qpf-rmpc-xxmw/GHSA-8qpf-rmpc-xxmw.json b/advisories/unreviewed/2024/12/GHSA-8qpf-rmpc-xxmw/GHSA-8qpf-rmpc-xxmw.json index 466e5b38781..5d220deef60 100644 --- a/advisories/unreviewed/2024/12/GHSA-8qpf-rmpc-xxmw/GHSA-8qpf-rmpc-xxmw.json +++ b/advisories/unreviewed/2024/12/GHSA-8qpf-rmpc-xxmw/GHSA-8qpf-rmpc-xxmw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8qpf-rmpc-xxmw", - "modified": "2024-12-27T15:31:52Z", + "modified": "2025-01-06T18:31:00Z", "published": "2024-12-27T15:31:52Z", "aliases": [ "CVE-2024-53230" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncpufreq: CPPC: Fix possible null-ptr-deref for cppc_get_cpu_cost()\n\ncpufreq_cpu_get_raw() may return NULL if the cpu is not in\npolicy->cpus cpu mask and it will cause null pointer dereference,\nso check NULL for cppc_get_cpu_cost().", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T14:15:31Z" diff --git a/advisories/unreviewed/2024/12/GHSA-9r43-p7wr-7396/GHSA-9r43-p7wr-7396.json b/advisories/unreviewed/2024/12/GHSA-9r43-p7wr-7396/GHSA-9r43-p7wr-7396.json index 58261d855af..5707dc65a7a 100644 --- a/advisories/unreviewed/2024/12/GHSA-9r43-p7wr-7396/GHSA-9r43-p7wr-7396.json +++ b/advisories/unreviewed/2024/12/GHSA-9r43-p7wr-7396/GHSA-9r43-p7wr-7396.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9r43-p7wr-7396", - "modified": "2024-12-29T12:30:41Z", + "modified": "2025-01-06T18:31:01Z", "published": "2024-12-29T12:30:41Z", "aliases": [ "CVE-2024-56749" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndlm: fix dlm_recover_members refcount on error\n\nIf dlm_recover_members() fails we don't drop the references of the\nprevious created root_list that holds and keep all rsbs alive during the\nrecovery. It might be not an unlikely event because ping_members() could\nrun into an -EINTR if another recovery progress was triggered again.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -29,7 +34,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-29T12:15:08Z" diff --git a/advisories/unreviewed/2024/12/GHSA-c62g-6hm9-x69q/GHSA-c62g-6hm9-x69q.json b/advisories/unreviewed/2024/12/GHSA-c62g-6hm9-x69q/GHSA-c62g-6hm9-x69q.json index 1cfab303e31..a54e3a55164 100644 --- a/advisories/unreviewed/2024/12/GHSA-c62g-6hm9-x69q/GHSA-c62g-6hm9-x69q.json +++ b/advisories/unreviewed/2024/12/GHSA-c62g-6hm9-x69q/GHSA-c62g-6hm9-x69q.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c62g-6hm9-x69q", - "modified": "2025-01-02T15:31:57Z", + "modified": "2025-01-06T18:31:01Z", "published": "2024-12-29T09:30:46Z", "aliases": [ "CVE-2024-56710" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nceph: fix memory leak in ceph_direct_read_write()\n\nThe bvecs array which is allocated in iter_get_bvecs_alloc() is leaked\nand pages remain pinned if ceph_alloc_sparse_ext_map() fails.\n\nThere is no need to delay the allocation of sparse_ext map until after\nthe bvecs array is set up, so fix this by moving sparse_ext allocation\na bit earlier. Also, make a similar adjustment in __ceph_sync_read()\nfor consistency (a leak of the same kind in __ceph_sync_read() has been\naddressed differently).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-29T09:15:05Z" diff --git a/advisories/unreviewed/2024/12/GHSA-c96h-hhgw-4533/GHSA-c96h-hhgw-4533.json b/advisories/unreviewed/2024/12/GHSA-c96h-hhgw-4533/GHSA-c96h-hhgw-4533.json index 72aad0c03da..283c6247e60 100644 --- a/advisories/unreviewed/2024/12/GHSA-c96h-hhgw-4533/GHSA-c96h-hhgw-4533.json +++ b/advisories/unreviewed/2024/12/GHSA-c96h-hhgw-4533/GHSA-c96h-hhgw-4533.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c96h-hhgw-4533", - "modified": "2024-12-27T15:31:56Z", + "modified": "2025-01-06T18:31:01Z", "published": "2024-12-27T15:31:56Z", "aliases": [ "CVE-2024-56671" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ngpio: graniterapids: Fix vGPIO driver crash\n\nMove setting irq_chip.name from probe() function to the initialization\nof \"irq_chip\" struct in order to fix vGPIO driver crash during bootup.\n\nCrash was caused by unauthorized modification of irq_chip.name field\nwhere irq_chip struct was initialized as const.\n\nThis behavior is a consequence of suboptimal implementation of\ngpio_irq_chip_set_chip(), which should be changed to avoid\ncasting away const qualifier.\n\nCrash log:\nBUG: unable to handle page fault for address: ffffffffc0ba81c0\n/#PF: supervisor write access in kernel mode\n/#PF: error_code(0x0003) - permissions violation\nCPU: 33 UID: 0 PID: 1075 Comm: systemd-udevd Not tainted 6.12.0-rc6-00077-g2e1b3cc9d7f7 #1\nHardware name: Intel Corporation Kaseyville RP/Kaseyville RP, BIOS KVLDCRB1.PGS.0026.D73.2410081258 10/08/2024\nRIP: 0010:gnr_gpio_probe+0x171/0x220 [gpio_graniterapids]", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -25,7 +30,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T15:15:26Z" diff --git a/advisories/unreviewed/2024/12/GHSA-cm7x-4mvp-c2jf/GHSA-cm7x-4mvp-c2jf.json b/advisories/unreviewed/2024/12/GHSA-cm7x-4mvp-c2jf/GHSA-cm7x-4mvp-c2jf.json index 7ce5d4fc320..f06cb5d56a3 100644 --- a/advisories/unreviewed/2024/12/GHSA-cm7x-4mvp-c2jf/GHSA-cm7x-4mvp-c2jf.json +++ b/advisories/unreviewed/2024/12/GHSA-cm7x-4mvp-c2jf/GHSA-cm7x-4mvp-c2jf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cm7x-4mvp-c2jf", - "modified": "2024-12-27T15:31:56Z", + "modified": "2025-01-06T18:31:01Z", "published": "2024-12-27T15:31:56Z", "aliases": [ "CVE-2024-56669" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\niommu/vt-d: Remove cache tags before disabling ATS\n\nThe current implementation removes cache tags after disabling ATS,\nleading to potential memory leaks and kernel crashes. Specifically,\nCACHE_TAG_DEVTLB type cache tags may still remain in the list even\nafter the domain is freed, causing a use-after-free condition.\n\nThis issue really shows up when multiple VFs from different PFs\npassed through to a single user-space process via vfio-pci. In such\ncases, the kernel may crash with kernel messages like:\n\n BUG: kernel NULL pointer dereference, address: 0000000000000014\n PGD 19036a067 P4D 1940a3067 PUD 136c9b067 PMD 0\n Oops: Oops: 0000 [#1] PREEMPT SMP NOPTI\n CPU: 74 UID: 0 PID: 3183 Comm: testCli Not tainted 6.11.9 #2\n RIP: 0010:cache_tag_flush_range+0x9b/0x250\n Call Trace:\n \n ? __die+0x1f/0x60\n ? page_fault_oops+0x163/0x590\n ? exc_page_fault+0x72/0x190\n ? asm_exc_page_fault+0x22/0x30\n ? cache_tag_flush_range+0x9b/0x250\n ? cache_tag_flush_range+0x5d/0x250\n intel_iommu_tlb_sync+0x29/0x40\n intel_iommu_unmap_pages+0xfe/0x160\n __iommu_unmap+0xd8/0x1a0\n vfio_unmap_unpin+0x182/0x340 [vfio_iommu_type1]\n vfio_remove_dma+0x2a/0xb0 [vfio_iommu_type1]\n vfio_iommu_type1_ioctl+0xafa/0x18e0 [vfio_iommu_type1]\n\nMove cache_tag_unassign_domain() before iommu_disable_pci_caps() to fix\nit.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T15:15:26Z" diff --git a/advisories/unreviewed/2024/12/GHSA-g2f4-7x3w-9r2x/GHSA-g2f4-7x3w-9r2x.json b/advisories/unreviewed/2024/12/GHSA-g2f4-7x3w-9r2x/GHSA-g2f4-7x3w-9r2x.json index 3f2de06d84e..92584e2b43d 100644 --- a/advisories/unreviewed/2024/12/GHSA-g2f4-7x3w-9r2x/GHSA-g2f4-7x3w-9r2x.json +++ b/advisories/unreviewed/2024/12/GHSA-g2f4-7x3w-9r2x/GHSA-g2f4-7x3w-9r2x.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-g2f4-7x3w-9r2x", - "modified": "2024-12-27T15:31:55Z", + "modified": "2025-01-06T18:31:00Z", "published": "2024-12-27T15:31:55Z", "aliases": [ "CVE-2024-56643" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndccp: Fix memory leak in dccp_feat_change_recv\n\nIf dccp_feat_push_confirm() fails after new value for SP feature was accepted\nwithout reconciliation ('entry == NULL' branch), memory allocated for that value\nwith dccp_feat_clone_sp_val() is never freed.\n\nHere is the kmemleak stack for this:\n\nunreferenced object 0xffff88801d4ab488 (size 8):\n comm \"syz-executor310\", pid 1127, jiffies 4295085598 (age 41.666s)\n hex dump (first 8 bytes):\n 01 b4 4a 1d 80 88 ff ff ..J.....\n backtrace:\n [<00000000db7cabfe>] kmemdup+0x23/0x50 mm/util.c:128\n [<0000000019b38405>] kmemdup include/linux/string.h:465 [inline]\n [<0000000019b38405>] dccp_feat_clone_sp_val net/dccp/feat.c:371 [inline]\n [<0000000019b38405>] dccp_feat_clone_sp_val net/dccp/feat.c:367 [inline]\n [<0000000019b38405>] dccp_feat_change_recv net/dccp/feat.c:1145 [inline]\n [<0000000019b38405>] dccp_feat_parse_options+0x1196/0x2180 net/dccp/feat.c:1416\n [<00000000b1f6d94a>] dccp_parse_options+0xa2a/0x1260 net/dccp/options.c:125\n [<0000000030d7b621>] dccp_rcv_state_process+0x197/0x13d0 net/dccp/input.c:650\n [<000000001f74c72e>] dccp_v4_do_rcv+0xf9/0x1a0 net/dccp/ipv4.c:688\n [<00000000a6c24128>] sk_backlog_rcv include/net/sock.h:1041 [inline]\n [<00000000a6c24128>] __release_sock+0x139/0x3b0 net/core/sock.c:2570\n [<00000000cf1f3a53>] release_sock+0x54/0x1b0 net/core/sock.c:3111\n [<000000008422fa23>] inet_wait_for_connect net/ipv4/af_inet.c:603 [inline]\n [<000000008422fa23>] __inet_stream_connect+0x5d0/0xf70 net/ipv4/af_inet.c:696\n [<0000000015b6f64d>] inet_stream_connect+0x53/0xa0 net/ipv4/af_inet.c:735\n [<0000000010122488>] __sys_connect_file+0x15c/0x1a0 net/socket.c:1865\n [<00000000b4b70023>] __sys_connect+0x165/0x1a0 net/socket.c:1882\n [<00000000f4cb3815>] __do_sys_connect net/socket.c:1892 [inline]\n [<00000000f4cb3815>] __se_sys_connect net/socket.c:1889 [inline]\n [<00000000f4cb3815>] __x64_sys_connect+0x6e/0xb0 net/socket.c:1889\n [<00000000e7b1e839>] do_syscall_64+0x33/0x40 arch/x86/entry/common.c:46\n [<0000000055e91434>] entry_SYSCALL_64_after_hwframe+0x67/0xd1\n\nClean up the allocated memory in case of dccp_feat_push_confirm() failure\nand bail out with an error reset code.\n\nFound by Linux Verification Center (linuxtesting.org) with Syzkaller.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T15:15:24Z" diff --git a/advisories/unreviewed/2024/12/GHSA-h3jg-w72m-c86w/GHSA-h3jg-w72m-c86w.json b/advisories/unreviewed/2024/12/GHSA-h3jg-w72m-c86w/GHSA-h3jg-w72m-c86w.json index 9063b1fdfa1..31088dd6d0e 100644 --- a/advisories/unreviewed/2024/12/GHSA-h3jg-w72m-c86w/GHSA-h3jg-w72m-c86w.json +++ b/advisories/unreviewed/2024/12/GHSA-h3jg-w72m-c86w/GHSA-h3jg-w72m-c86w.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-h99j-qmgw-6ggg/GHSA-h99j-qmgw-6ggg.json b/advisories/unreviewed/2024/12/GHSA-h99j-qmgw-6ggg/GHSA-h99j-qmgw-6ggg.json index 2bc7510e193..05a84baa822 100644 --- a/advisories/unreviewed/2024/12/GHSA-h99j-qmgw-6ggg/GHSA-h99j-qmgw-6ggg.json +++ b/advisories/unreviewed/2024/12/GHSA-h99j-qmgw-6ggg/GHSA-h99j-qmgw-6ggg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h99j-qmgw-6ggg", - "modified": "2024-12-31T12:30:44Z", + "modified": "2025-01-06T18:31:02Z", "published": "2024-12-31T12:30:44Z", "aliases": [ "CVE-2024-12106" diff --git a/advisories/unreviewed/2024/12/GHSA-hgqw-cwmr-4h32/GHSA-hgqw-cwmr-4h32.json b/advisories/unreviewed/2024/12/GHSA-hgqw-cwmr-4h32/GHSA-hgqw-cwmr-4h32.json index a403c914251..f100eb292ee 100644 --- a/advisories/unreviewed/2024/12/GHSA-hgqw-cwmr-4h32/GHSA-hgqw-cwmr-4h32.json +++ b/advisories/unreviewed/2024/12/GHSA-hgqw-cwmr-4h32/GHSA-hgqw-cwmr-4h32.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hgqw-cwmr-4h32", - "modified": "2024-12-29T12:30:40Z", + "modified": "2025-01-06T18:31:01Z", "published": "2024-12-29T12:30:40Z", "aliases": [ "CVE-2024-56726" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nocteontx2-pf: handle otx2_mbox_get_rsp errors in cn10k.c\n\nAdd error pointer check after calling otx2_mbox_get_rsp().", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-29T12:15:06Z" diff --git a/advisories/unreviewed/2024/12/GHSA-hm8f-4wxj-jx75/GHSA-hm8f-4wxj-jx75.json b/advisories/unreviewed/2024/12/GHSA-hm8f-4wxj-jx75/GHSA-hm8f-4wxj-jx75.json index bebfee87886..525d2664566 100644 --- a/advisories/unreviewed/2024/12/GHSA-hm8f-4wxj-jx75/GHSA-hm8f-4wxj-jx75.json +++ b/advisories/unreviewed/2024/12/GHSA-hm8f-4wxj-jx75/GHSA-hm8f-4wxj-jx75.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-j6hf-9p86-c354/GHSA-j6hf-9p86-c354.json b/advisories/unreviewed/2024/12/GHSA-j6hf-9p86-c354/GHSA-j6hf-9p86-c354.json index 360b7daf795..256e6c118fd 100644 --- a/advisories/unreviewed/2024/12/GHSA-j6hf-9p86-c354/GHSA-j6hf-9p86-c354.json +++ b/advisories/unreviewed/2024/12/GHSA-j6hf-9p86-c354/GHSA-j6hf-9p86-c354.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-j6hf-9p86-c354", - "modified": "2024-12-29T12:30:40Z", + "modified": "2025-01-06T18:31:01Z", "published": "2024-12-29T12:30:40Z", "aliases": [ "CVE-2024-56727" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nocteontx2-pf: handle otx2_mbox_get_rsp errors in otx2_flows.c\n\nAdding error pointer check after calling otx2_mbox_get_rsp().", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-29T12:15:06Z" diff --git a/advisories/unreviewed/2024/12/GHSA-mgx9-r76h-gvxf/GHSA-mgx9-r76h-gvxf.json b/advisories/unreviewed/2024/12/GHSA-mgx9-r76h-gvxf/GHSA-mgx9-r76h-gvxf.json index afee5d8f2ab..699177c9224 100644 --- a/advisories/unreviewed/2024/12/GHSA-mgx9-r76h-gvxf/GHSA-mgx9-r76h-gvxf.json +++ b/advisories/unreviewed/2024/12/GHSA-mgx9-r76h-gvxf/GHSA-mgx9-r76h-gvxf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mgx9-r76h-gvxf", - "modified": "2024-12-29T12:30:41Z", + "modified": "2025-01-06T18:31:01Z", "published": "2024-12-29T12:30:41Z", "aliases": [ "CVE-2024-56750" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nerofs: fix blksize < PAGE_SIZE for file-backed mounts\n\nAdjust sb->s_blocksize{,_bits} directly for file-backed\nmounts when the fs block size is smaller than PAGE_SIZE.\n\nPreviously, EROFS used sb_set_blocksize(), which caused\na panic if bdev-backed mounts is not used.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -25,7 +30,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-29T12:15:08Z" diff --git a/advisories/unreviewed/2024/12/GHSA-ph84-rcj2-fxxm/GHSA-ph84-rcj2-fxxm.json b/advisories/unreviewed/2024/12/GHSA-ph84-rcj2-fxxm/GHSA-ph84-rcj2-fxxm.json index 76070b79536..443ff55c2e3 100644 --- a/advisories/unreviewed/2024/12/GHSA-ph84-rcj2-fxxm/GHSA-ph84-rcj2-fxxm.json +++ b/advisories/unreviewed/2024/12/GHSA-ph84-rcj2-fxxm/GHSA-ph84-rcj2-fxxm.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-ph84-rcj2-fxxm", - "modified": "2024-12-06T21:30:39Z", + "modified": "2025-01-06T18:31:00Z", "published": "2024-12-06T18:30:45Z", "aliases": [ "CVE-2024-12254" ], "details": "Starting in Python 3.12.0, the asyncio._SelectorSocketTransport.writelines()\n method would not \"pause\" writing and signal to the Protocol to drain \nthe buffer to the wire once the write buffer reached the \"high-water \nmark\". Because of this, Protocols would not periodically drain the write\n buffer potentially leading to memory exhaustion.\n\n\n\n\n\nThis\n vulnerability likely impacts a small number of users, you must be using\n Python 3.12.0 or later, on macOS or Linux, using the asyncio module \nwith protocols, and using .writelines() method which had new \nzero-copy-on-write behavior in Python 3.12.0 and later. If not all of \nthese factors are true then your usage of Python is unaffected.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/12/GHSA-qgw7-mg2m-3x6f/GHSA-qgw7-mg2m-3x6f.json b/advisories/unreviewed/2024/12/GHSA-qgw7-mg2m-3x6f/GHSA-qgw7-mg2m-3x6f.json index 84a6b45efc5..cb7b3b5c218 100644 --- a/advisories/unreviewed/2024/12/GHSA-qgw7-mg2m-3x6f/GHSA-qgw7-mg2m-3x6f.json +++ b/advisories/unreviewed/2024/12/GHSA-qgw7-mg2m-3x6f/GHSA-qgw7-mg2m-3x6f.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qgw7-mg2m-3x6f", - "modified": "2024-12-27T15:31:56Z", + "modified": "2025-01-06T18:31:01Z", "published": "2024-12-27T15:31:56Z", "aliases": [ "CVE-2024-56672" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nblk-cgroup: Fix UAF in blkcg_unpin_online()\n\nblkcg_unpin_online() walks up the blkcg hierarchy putting the online pin. To\nwalk up, it uses blkcg_parent(blkcg) but it was calling that after\nblkcg_destroy_blkgs(blkcg) which could free the blkcg, leading to the\nfollowing UAF:\n\n ==================================================================\n BUG: KASAN: slab-use-after-free in blkcg_unpin_online+0x15a/0x270\n Read of size 8 at addr ffff8881057678c0 by task kworker/9:1/117\n\n CPU: 9 UID: 0 PID: 117 Comm: kworker/9:1 Not tainted 6.13.0-rc1-work-00182-gb8f52214c61a-dirty #48\n Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS unknown 02/02/2022\n Workqueue: cgwb_release cgwb_release_workfn\n Call Trace:\n \n dump_stack_lvl+0x27/0x80\n print_report+0x151/0x710\n kasan_report+0xc0/0x100\n blkcg_unpin_online+0x15a/0x270\n cgwb_release_workfn+0x194/0x480\n process_scheduled_works+0x71b/0xe20\n worker_thread+0x82a/0xbd0\n kthread+0x242/0x2c0\n ret_from_fork+0x33/0x70\n ret_from_fork_asm+0x1a/0x30\n \n ...\n Freed by task 1944:\n kasan_save_track+0x2b/0x70\n kasan_save_free_info+0x3c/0x50\n __kasan_slab_free+0x33/0x50\n kfree+0x10c/0x330\n css_free_rwork_fn+0xe6/0xb30\n process_scheduled_works+0x71b/0xe20\n worker_thread+0x82a/0xbd0\n kthread+0x242/0x2c0\n ret_from_fork+0x33/0x70\n ret_from_fork_asm+0x1a/0x30\n\nNote that the UAF is not easy to trigger as the free path is indirected\nbehind a couple RCU grace periods and a work item execution. I could only\ntrigger it with artifical msleep() injected in blkcg_unpin_online().\n\nFix it by reading the parent pointer before destroying the blkcg's blkg's.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T15:15:27Z" diff --git a/advisories/unreviewed/2024/12/GHSA-qj49-7rgr-pfmq/GHSA-qj49-7rgr-pfmq.json b/advisories/unreviewed/2024/12/GHSA-qj49-7rgr-pfmq/GHSA-qj49-7rgr-pfmq.json index 9a8c87aff3e..a7d44b7284d 100644 --- a/advisories/unreviewed/2024/12/GHSA-qj49-7rgr-pfmq/GHSA-qj49-7rgr-pfmq.json +++ b/advisories/unreviewed/2024/12/GHSA-qj49-7rgr-pfmq/GHSA-qj49-7rgr-pfmq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qj49-7rgr-pfmq", - "modified": "2024-12-27T15:31:51Z", + "modified": "2025-01-06T18:31:00Z", "published": "2024-12-27T15:31:51Z", "aliases": [ "CVE-2024-53185" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix NULL ptr deref in crypto_aead_setkey()\n\nNeither SMB3.0 or SMB3.02 supports encryption negotiate context, so\nwhen SMB2_GLOBAL_CAP_ENCRYPTION flag is set in the negotiate response,\nthe client uses AES-128-CCM as the default cipher. See MS-SMB2\n3.3.5.4.\n\nCommit b0abcd65ec54 (\"smb: client: fix UAF in async decryption\") added\na @server->cipher_type check to conditionally call\nsmb3_crypto_aead_allocate(), but that check would always be false as\n@server->cipher_type is unset for SMB3.02.\n\nFix the following KASAN splat by setting @server->cipher_type for\nSMB3.02 as well.\n\nmount.cifs //srv/share /mnt -o vers=3.02,seal,...\n\nBUG: KASAN: null-ptr-deref in crypto_aead_setkey+0x2c/0x130\nRead of size 8 at addr 0000000000000020 by task mount.cifs/1095\nCPU: 1 UID: 0 PID: 1095 Comm: mount.cifs Not tainted 6.12.0 #1\nHardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-3.fc41\n04/01/2014\nCall Trace:\n \n dump_stack_lvl+0x5d/0x80\n ? crypto_aead_setkey+0x2c/0x130\n kasan_report+0xda/0x110\n ? crypto_aead_setkey+0x2c/0x130\n crypto_aead_setkey+0x2c/0x130\n crypt_message+0x258/0xec0 [cifs]\n ? __asan_memset+0x23/0x50\n ? __pfx_crypt_message+0x10/0x10 [cifs]\n ? mark_lock+0xb0/0x6a0\n ? hlock_class+0x32/0xb0\n ? mark_lock+0xb0/0x6a0\n smb3_init_transform_rq+0x352/0x3f0 [cifs]\n ? lock_acquire.part.0+0xf4/0x2a0\n smb_send_rqst+0x144/0x230 [cifs]\n ? __pfx_smb_send_rqst+0x10/0x10 [cifs]\n ? hlock_class+0x32/0xb0\n ? smb2_setup_request+0x225/0x3a0 [cifs]\n ? __pfx_cifs_compound_last_callback+0x10/0x10 [cifs]\n compound_send_recv+0x59b/0x1140 [cifs]\n ? __pfx_compound_send_recv+0x10/0x10 [cifs]\n ? __create_object+0x5e/0x90\n ? hlock_class+0x32/0xb0\n ? do_raw_spin_unlock+0x9a/0xf0\n cifs_send_recv+0x23/0x30 [cifs]\n SMB2_tcon+0x3ec/0xb30 [cifs]\n ? __pfx_SMB2_tcon+0x10/0x10 [cifs]\n ? lock_acquire.part.0+0xf4/0x2a0\n ? __pfx_lock_release+0x10/0x10\n ? do_raw_spin_trylock+0xc6/0x120\n ? lock_acquire+0x3f/0x90\n ? _get_xid+0x16/0xd0 [cifs]\n ? __pfx_SMB2_tcon+0x10/0x10 [cifs]\n ? cifs_get_smb_ses+0xcdd/0x10a0 [cifs]\n cifs_get_smb_ses+0xcdd/0x10a0 [cifs]\n ? __pfx_cifs_get_smb_ses+0x10/0x10 [cifs]\n ? cifs_get_tcp_session+0xaa0/0xca0 [cifs]\n cifs_mount_get_session+0x8a/0x210 [cifs]\n dfs_mount_share+0x1b0/0x11d0 [cifs]\n ? __pfx___lock_acquire+0x10/0x10\n ? __pfx_dfs_mount_share+0x10/0x10 [cifs]\n ? lock_acquire.part.0+0xf4/0x2a0\n ? find_held_lock+0x8a/0xa0\n ? hlock_class+0x32/0xb0\n ? lock_release+0x203/0x5d0\n cifs_mount+0xb3/0x3d0 [cifs]\n ? do_raw_spin_trylock+0xc6/0x120\n ? __pfx_cifs_mount+0x10/0x10 [cifs]\n ? lock_acquire+0x3f/0x90\n ? find_nls+0x16/0xa0\n ? smb3_update_mnt_flags+0x372/0x3b0 [cifs]\n cifs_smb3_do_mount+0x1e2/0xc80 [cifs]\n ? __pfx_vfs_parse_fs_string+0x10/0x10\n ? __pfx_cifs_smb3_do_mount+0x10/0x10 [cifs]\n smb3_get_tree+0x1bf/0x330 [cifs]\n vfs_get_tree+0x4a/0x160\n path_mount+0x3c1/0xfb0\n ? kasan_quarantine_put+0xc7/0x1d0\n ? __pfx_path_mount+0x10/0x10\n ? kmem_cache_free+0x118/0x3e0\n ? user_path_at+0x74/0xa0\n __x64_sys_mount+0x1a6/0x1e0\n ? __pfx___x64_sys_mount+0x10/0x10\n ? mark_held_locks+0x1a/0x90\n do_syscall_64+0xbb/0x1d0\n entry_SYSCALL_64_after_hwframe+0x77/0x7f", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T14:15:25Z" diff --git a/advisories/unreviewed/2024/12/GHSA-vf7h-r8hg-75jj/GHSA-vf7h-r8hg-75jj.json b/advisories/unreviewed/2024/12/GHSA-vf7h-r8hg-75jj/GHSA-vf7h-r8hg-75jj.json index 6bd7feb95ad..4b8b75c67c5 100644 --- a/advisories/unreviewed/2024/12/GHSA-vf7h-r8hg-75jj/GHSA-vf7h-r8hg-75jj.json +++ b/advisories/unreviewed/2024/12/GHSA-vf7h-r8hg-75jj/GHSA-vf7h-r8hg-75jj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vf7h-r8hg-75jj", - "modified": "2024-12-31T12:30:44Z", + "modified": "2025-01-06T18:31:01Z", "published": "2024-12-31T12:30:44Z", "aliases": [ "CVE-2024-12105" diff --git a/advisories/unreviewed/2024/12/GHSA-vmhm-g2hv-x7wj/GHSA-vmhm-g2hv-x7wj.json b/advisories/unreviewed/2024/12/GHSA-vmhm-g2hv-x7wj/GHSA-vmhm-g2hv-x7wj.json index b0e99dba6c2..391bba654e7 100644 --- a/advisories/unreviewed/2024/12/GHSA-vmhm-g2hv-x7wj/GHSA-vmhm-g2hv-x7wj.json +++ b/advisories/unreviewed/2024/12/GHSA-vmhm-g2hv-x7wj/GHSA-vmhm-g2hv-x7wj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vmhm-g2hv-x7wj", - "modified": "2024-12-27T15:31:55Z", + "modified": "2025-01-06T18:31:00Z", "published": "2024-12-27T15:31:55Z", "aliases": [ "CVE-2024-56611" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/mempolicy: fix migrate_to_node() assuming there is at least one VMA in a MM\n\nWe currently assume that there is at least one VMA in a MM, which isn't\ntrue.\n\nSo we might end up having find_vma() return NULL, to then de-reference\nNULL. So properly handle find_vma() returning NULL.\n\nThis fixes the report:\n\nOops: general protection fault, probably for non-canonical address 0xdffffc0000000000: 0000 [#1] PREEMPT SMP KASAN PTI\nKASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]\nCPU: 1 UID: 0 PID: 6021 Comm: syz-executor284 Not tainted 6.12.0-rc7-syzkaller-00187-gf868cd251776 #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/30/2024\nRIP: 0010:migrate_to_node mm/mempolicy.c:1090 [inline]\nRIP: 0010:do_migrate_pages+0x403/0x6f0 mm/mempolicy.c:1194\nCode: ...\nRSP: 0018:ffffc9000375fd08 EFLAGS: 00010246\nRAX: 0000000000000000 RBX: ffffc9000375fd78 RCX: 0000000000000000\nRDX: ffff88807e171300 RSI: dffffc0000000000 RDI: ffff88803390c044\nRBP: ffff88807e171428 R08: 0000000000000014 R09: fffffbfff2039ef1\nR10: ffffffff901cf78f R11: 0000000000000000 R12: 0000000000000003\nR13: ffffc9000375fe90 R14: ffffc9000375fe98 R15: ffffc9000375fdf8\nFS: 00005555919e1380(0000) GS:ffff8880b8700000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00005555919e1ca8 CR3: 000000007f12a000 CR4: 00000000003526f0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nCall Trace:\n \n kernel_migrate_pages+0x5b2/0x750 mm/mempolicy.c:1709\n __do_sys_migrate_pages mm/mempolicy.c:1727 [inline]\n __se_sys_migrate_pages mm/mempolicy.c:1723 [inline]\n __x64_sys_migrate_pages+0x96/0x100 mm/mempolicy.c:1723\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xcd/0x250 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\n[akpm@linux-foundation.org: add unlikely()]", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T15:15:20Z" diff --git a/advisories/unreviewed/2024/12/GHSA-xfj9-6vm8-7xwg/GHSA-xfj9-6vm8-7xwg.json b/advisories/unreviewed/2024/12/GHSA-xfj9-6vm8-7xwg/GHSA-xfj9-6vm8-7xwg.json index cde75a672b1..307fa0b3afe 100644 --- a/advisories/unreviewed/2024/12/GHSA-xfj9-6vm8-7xwg/GHSA-xfj9-6vm8-7xwg.json +++ b/advisories/unreviewed/2024/12/GHSA-xfj9-6vm8-7xwg/GHSA-xfj9-6vm8-7xwg.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xfj9-6vm8-7xwg", - "modified": "2024-12-05T12:31:28Z", + "modified": "2025-01-06T18:31:00Z", "published": "2024-12-04T12:31:45Z", "aliases": [ "CVE-2024-52269" ], "details": "** INITIAL LIMITED RELEASE **\n\nUser Interface (UI) Misrepresentation of Critical Information vulnerability in [WITHHELD] allows Content Spoofing.\nThe SaaS AI assistant ignores hidden content that is rendered after signing, misleading the user.\nThis issue affects [WITHHELD]: through 2024-12-04.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Red" diff --git a/advisories/unreviewed/2025/01/GHSA-2423-2c9w-8vgr/GHSA-2423-2c9w-8vgr.json b/advisories/unreviewed/2025/01/GHSA-2423-2c9w-8vgr/GHSA-2423-2c9w-8vgr.json new file mode 100644 index 00000000000..ca2284902e7 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2423-2c9w-8vgr/GHSA-2423-2c9w-8vgr.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2423-2c9w-8vgr", + "modified": "2025-01-06T18:31:05Z", + "published": "2025-01-06T18:31:05Z", + "aliases": [ + "CVE-2024-56828" + ], + "details": "File Upload vulnerability in ChestnutCMS through 1.5.0. Based on the code analysis, it was determined that the /api/member/avatar API endpoint receives a base64 string as input. This string is then passed to the memberService.uploadAvatarByBase64 method for processing. Within the service, the base64-encoded image is parsed. For example, given a string like: data:image/html;base64,PGh0bWw+PGltZyBzcmM9eCBvbmVycm9yPWFsZXJ0KDEpPjwvaHRtbD4= the content after the comma is extracted and decoded using Base64.getDecoder().decode(). The substring from the 11th character up to the first occurrence of a semicolon (;) is assigned to the suffix variable (representing the file extension). The decoded content is then written to a file. However, the file extension is not validated, and since this functionality is exposed to the frontend, it poses significant security risks.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56828" + }, + { + "type": "WEB", + "url": "https://gitee.com/liweiyi/ChestnutCMS" + }, + { + "type": "WEB", + "url": "https://github.com/Zerone0x00/CVE/blob/main/ChestnutCMS/CVE-2024-56828.md" + }, + { + "type": "WEB", + "url": "https://www.1000mz.com" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-06T18:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-2r77-fvv3-mm9j/GHSA-2r77-fvv3-mm9j.json b/advisories/unreviewed/2025/01/GHSA-2r77-fvv3-mm9j/GHSA-2r77-fvv3-mm9j.json new file mode 100644 index 00000000000..0d24073304d --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2r77-fvv3-mm9j/GHSA-2r77-fvv3-mm9j.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2r77-fvv3-mm9j", + "modified": "2025-01-06T18:31:04Z", + "published": "2025-01-06T18:31:04Z", + "aliases": [ + "CVE-2024-55529" + ], + "details": "Z-BlogPHP 1.7.3 is vulnerable to arbitrary code execution via \\zb_users\\theme\\shell\\template.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55529" + }, + { + "type": "WEB", + "url": "https://github.com/fengyijiu520/Z-Blog-" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-06T18:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-533j-w77v-fmxv/GHSA-533j-w77v-fmxv.json b/advisories/unreviewed/2025/01/GHSA-533j-w77v-fmxv/GHSA-533j-w77v-fmxv.json new file mode 100644 index 00000000000..5d74a3a9dc1 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-533j-w77v-fmxv/GHSA-533j-w77v-fmxv.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-533j-w77v-fmxv", + "modified": "2025-01-06T18:31:04Z", + "published": "2025-01-06T18:31:04Z", + "aliases": [ + "CVE-2024-54880" + ], + "details": "SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user to register accounts in bulk.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54880" + }, + { + "type": "WEB", + "url": "https://blog.csdn.net/weixin_46686336/article/details/144797063" + }, + { + "type": "WEB", + "url": "https://www.seacms.net" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-06T18:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-54xr-rm2r-p8mq/GHSA-54xr-rm2r-p8mq.json b/advisories/unreviewed/2025/01/GHSA-54xr-rm2r-p8mq/GHSA-54xr-rm2r-p8mq.json new file mode 100644 index 00000000000..31c3a91e572 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-54xr-rm2r-p8mq/GHSA-54xr-rm2r-p8mq.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-54xr-rm2r-p8mq", + "modified": "2025-01-06T18:31:03Z", + "published": "2025-01-06T18:31:03Z", + "aliases": [ + "CVE-2024-56758" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: check folio mapping after unlock in relocate_one_folio()\n\nWhen we call btrfs_read_folio() to bring a folio uptodate, we unlock the\nfolio. The result of that is that a different thread can modify the\nmapping (like remove it with invalidate) before we call folio_lock().\nThis results in an invalid page and we need to try again.\n\nIn particular, if we are relocating concurrently with aborting a\ntransaction, this can result in a crash like the following:\n\n BUG: kernel NULL pointer dereference, address: 0000000000000000\n PGD 0 P4D 0\n Oops: 0000 [#1] SMP\n CPU: 76 PID: 1411631 Comm: kworker/u322:5\n Workqueue: events_unbound btrfs_reclaim_bgs_work\n RIP: 0010:set_page_extent_mapped+0x20/0xb0\n RSP: 0018:ffffc900516a7be8 EFLAGS: 00010246\n RAX: ffffea009e851d08 RBX: ffffea009e0b1880 RCX: 0000000000000000\n RDX: 0000000000000000 RSI: ffffc900516a7b90 RDI: ffffea009e0b1880\n RBP: 0000000003573000 R08: 0000000000000001 R09: ffff88c07fd2f3f0\n R10: 0000000000000000 R11: 0000194754b575be R12: 0000000003572000\n R13: 0000000003572fff R14: 0000000000100cca R15: 0000000005582fff\n FS: 0000000000000000(0000) GS:ffff88c07fd00000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 0000000000000000 CR3: 000000407d00f002 CR4: 00000000007706f0\n DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n PKRU: 55555554\n Call Trace:\n \n ? __die+0x78/0xc0\n ? page_fault_oops+0x2a8/0x3a0\n ? __switch_to+0x133/0x530\n ? wq_worker_running+0xa/0x40\n ? exc_page_fault+0x63/0x130\n ? asm_exc_page_fault+0x22/0x30\n ? set_page_extent_mapped+0x20/0xb0\n relocate_file_extent_cluster+0x1a7/0x940\n relocate_data_extent+0xaf/0x120\n relocate_block_group+0x20f/0x480\n btrfs_relocate_block_group+0x152/0x320\n btrfs_relocate_chunk+0x3d/0x120\n btrfs_reclaim_bgs_work+0x2ae/0x4e0\n process_scheduled_works+0x184/0x370\n worker_thread+0xc6/0x3e0\n ? blk_add_timer+0xb0/0xb0\n kthread+0xae/0xe0\n ? flush_tlb_kernel_range+0x90/0x90\n ret_from_fork+0x2f/0x40\n ? flush_tlb_kernel_range+0x90/0x90\n ret_from_fork_asm+0x11/0x20\n \n\nThis occurs because cleanup_one_transaction() calls\ndestroy_delalloc_inodes() which calls invalidate_inode_pages2() which\ntakes the folio_lock before setting mapping to NULL. We fail to check\nthis, and subsequently call set_extent_mapping(), which assumes that\nmapping != NULL (in fact it asserts that in debug mode)\n\nNote that the \"fixes\" patch here is not the one that introduced the\nrace (the very first iteration of this code from 2009) but a more recent\nchange that made this particular crash happen in practice.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56758" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3e74859ee35edc33a022c3f3971df066ea0ca6b9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d508e56270389b3a16f5b3cf247f4eb1bbad1578" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-06T17:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-5jx8-96f6-fv22/GHSA-5jx8-96f6-fv22.json b/advisories/unreviewed/2025/01/GHSA-5jx8-96f6-fv22/GHSA-5jx8-96f6-fv22.json index 14ab47699c3..814224f7c72 100644 --- a/advisories/unreviewed/2025/01/GHSA-5jx8-96f6-fv22/GHSA-5jx8-96f6-fv22.json +++ b/advisories/unreviewed/2025/01/GHSA-5jx8-96f6-fv22/GHSA-5jx8-96f6-fv22.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5jx8-96f6-fv22", - "modified": "2025-01-04T03:33:08Z", + "modified": "2025-01-06T18:31:02Z", "published": "2025-01-04T03:33:08Z", "aliases": [ "CVE-2025-22384" ], "details": "An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity issue concerning business logic exists in the Commerce B2B application, which allows storefront visitors to purchase discontinued products in specific scenarios where requests are altered before reaching the server.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-472" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-04T02:15:06Z" diff --git a/advisories/unreviewed/2025/01/GHSA-5r7w-j22r-58j4/GHSA-5r7w-j22r-58j4.json b/advisories/unreviewed/2025/01/GHSA-5r7w-j22r-58j4/GHSA-5r7w-j22r-58j4.json new file mode 100644 index 00000000000..180e72e4987 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-5r7w-j22r-58j4/GHSA-5r7w-j22r-58j4.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5r7w-j22r-58j4", + "modified": "2025-01-06T18:31:04Z", + "published": "2025-01-06T18:31:04Z", + "aliases": [ + "CVE-2024-56766" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmtd: rawnand: fix double free in atmel_pmecc_create_user()\n\nThe \"user\" pointer was converted from being allocated with kzalloc() to\nbeing allocated by devm_kzalloc(). Calling kfree(user) will lead to a\ndouble free.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56766" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6ea15205d7e2b811fbbdf79783f686f58abfb4b7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d2f090ea57f8d6587e09d4066f740a8617767b3d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d8e4771f99c0400a1873235704b28bb803c83d17" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/dd45c87782738715d5e7c167f8dabf0814a7394a" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-06T17:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-6574-vqv8-9334/GHSA-6574-vqv8-9334.json b/advisories/unreviewed/2025/01/GHSA-6574-vqv8-9334/GHSA-6574-vqv8-9334.json new file mode 100644 index 00000000000..f9e37f8ba08 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-6574-vqv8-9334/GHSA-6574-vqv8-9334.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6574-vqv8-9334", + "modified": "2025-01-06T18:31:03Z", + "published": "2025-01-06T18:31:03Z", + "aliases": [ + "CVE-2024-56759" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix use-after-free when COWing tree bock and tracing is enabled\n\nWhen a COWing a tree block, at btrfs_cow_block(), and we have the\ntracepoint trace_btrfs_cow_block() enabled and preemption is also enabled\n(CONFIG_PREEMPT=y), we can trigger a use-after-free in the COWed extent\nbuffer while inside the tracepoint code. This is because in some paths\nthat call btrfs_cow_block(), such as btrfs_search_slot(), we are holding\nthe last reference on the extent buffer @buf so btrfs_force_cow_block()\ndrops the last reference on the @buf extent buffer when it calls\nfree_extent_buffer_stale(buf), which schedules the release of the extent\nbuffer with RCU. This means that if we are on a kernel with preemption,\nthe current task may be preempted before calling trace_btrfs_cow_block()\nand the extent buffer already released by the time trace_btrfs_cow_block()\nis called, resulting in a use-after-free.\n\nFix this by moving the trace_btrfs_cow_block() from btrfs_cow_block() to\nbtrfs_force_cow_block() before the COWed extent buffer is freed.\nThis also has a side effect of invoking the tracepoint in the tree defrag\ncode, at defrag.c:btrfs_realloc_node(), since btrfs_force_cow_block() is\ncalled there, but this is fine and it was actually missing there.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56759" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/44f52bbe96dfdbe4aca3818a2534520082a07040" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c3a403d8ce36f5a809a492581de5ad17843e4701" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-06T17:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-65qh-mp3r-v4jr/GHSA-65qh-mp3r-v4jr.json b/advisories/unreviewed/2025/01/GHSA-65qh-mp3r-v4jr/GHSA-65qh-mp3r-v4jr.json new file mode 100644 index 00000000000..294408ba912 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-65qh-mp3r-v4jr/GHSA-65qh-mp3r-v4jr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-65qh-mp3r-v4jr", + "modified": "2025-01-06T18:31:03Z", + "published": "2025-01-06T18:31:03Z", + "aliases": [ + "CVE-2024-47475" + ], + "details": "Dell PowerScale OneFS 8.2.2.x through 9.8.0.x contains an incorrect permission assignment for critical resource vulnerability. A locally authenticated attacker could potentially exploit this vulnerability, leading to denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47475" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000242681/dsa-2024-417-security-update-for-dell-powerscale-onefs-for-security-vulnerability" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-732" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-06T17:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-6jp6-9w8r-589w/GHSA-6jp6-9w8r-589w.json b/advisories/unreviewed/2025/01/GHSA-6jp6-9w8r-589w/GHSA-6jp6-9w8r-589w.json new file mode 100644 index 00000000000..097a40de0d9 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-6jp6-9w8r-589w/GHSA-6jp6-9w8r-589w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6jp6-9w8r-589w", + "modified": "2025-01-06T18:31:02Z", + "published": "2025-01-06T18:31:02Z", + "aliases": [ + "CVE-2024-31913" + ], + "details": "IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31913" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7176081" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-06T16:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-6r4h-f9rf-frm2/GHSA-6r4h-f9rf-frm2.json b/advisories/unreviewed/2025/01/GHSA-6r4h-f9rf-frm2/GHSA-6r4h-f9rf-frm2.json new file mode 100644 index 00000000000..7044645a5ed --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-6r4h-f9rf-frm2/GHSA-6r4h-f9rf-frm2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6r4h-f9rf-frm2", + "modified": "2025-01-06T18:31:03Z", + "published": "2025-01-06T18:31:03Z", + "aliases": [ + "CVE-2023-6605" + ], + "details": "A flaw was found in FFmpeg's DASH playlist support. This vulnerability allows arbitrary HTTP GET requests to be made on behalf of the machine running FFmpeg via a crafted DASH playlist containing malicious URLs.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6605" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2334336" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-99" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-06T17:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-6wf9-7vfw-cj9r/GHSA-6wf9-7vfw-cj9r.json b/advisories/unreviewed/2025/01/GHSA-6wf9-7vfw-cj9r/GHSA-6wf9-7vfw-cj9r.json new file mode 100644 index 00000000000..8269d02e4e6 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-6wf9-7vfw-cj9r/GHSA-6wf9-7vfw-cj9r.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6wf9-7vfw-cj9r", + "modified": "2025-01-06T18:31:04Z", + "published": "2025-01-06T18:31:04Z", + "aliases": [ + "CVE-2024-56762" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nio_uring/sqpoll: fix sqpoll error handling races\n\nBUG: KASAN: slab-use-after-free in __lock_acquire+0x370b/0x4a10 kernel/locking/lockdep.c:5089\nCall Trace:\n\n...\n_raw_spin_lock_irqsave+0x3d/0x60 kernel/locking/spinlock.c:162\nclass_raw_spinlock_irqsave_constructor include/linux/spinlock.h:551 [inline]\ntry_to_wake_up+0xb5/0x23c0 kernel/sched/core.c:4205\nio_sq_thread_park+0xac/0xe0 io_uring/sqpoll.c:55\nio_sq_thread_finish+0x6b/0x310 io_uring/sqpoll.c:96\nio_sq_offload_create+0x162/0x11d0 io_uring/sqpoll.c:497\nio_uring_create io_uring/io_uring.c:3724 [inline]\nio_uring_setup+0x1728/0x3230 io_uring/io_uring.c:3806\n...\n\nKun Hu reports that the SQPOLL creating error path has UAF, which\nhappens if io_uring_alloc_task_context() fails and then io_sq_thread()\nmanages to run and complete before the rest of error handling code,\nwhich means io_sq_thread_finish() is looking at already killed task.\n\nNote that this is mostly theoretical, requiring fault injection on\nthe allocation side to trigger in practice.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56762" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6237331361711810d8f2e3fbfe2f7a6f9548f5e0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/80120bb4eef7848d5aa3b1a0cd88367cd05fbe03" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8e8494c83cf73168118587e9567e4f7e50ce4fd8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e33ac68e5e21ec1292490dfe061e75c0dbdd3bd4" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-06T17:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-73m7-qfq5-gqj4/GHSA-73m7-qfq5-gqj4.json b/advisories/unreviewed/2025/01/GHSA-73m7-qfq5-gqj4/GHSA-73m7-qfq5-gqj4.json new file mode 100644 index 00000000000..6f472722d9c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-73m7-qfq5-gqj4/GHSA-73m7-qfq5-gqj4.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-73m7-qfq5-gqj4", + "modified": "2025-01-06T18:31:04Z", + "published": "2025-01-06T18:31:04Z", + "aliases": [ + "CVE-2024-56768" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix bpf_get_smp_processor_id() on !CONFIG_SMP\n\nOn x86-64 calling bpf_get_smp_processor_id() in a kernel with CONFIG_SMP\ndisabled can trigger the following bug, as pcpu_hot is unavailable:\n\n [ 8.471774] BUG: unable to handle page fault for address: 00000000936a290c\n [ 8.471849] #PF: supervisor read access in kernel mode\n [ 8.471881] #PF: error_code(0x0000) - not-present page\n\nFix by inlining a return 0 in the !CONFIG_SMP case.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56768" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/23579010cf0a12476e96a5f1acdf78a9c5843657" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f4ab7d74247b0150547cf909b3f6f24ee85183df" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-06T17:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-7vgm-4f6w-wj5f/GHSA-7vgm-4f6w-wj5f.json b/advisories/unreviewed/2025/01/GHSA-7vgm-4f6w-wj5f/GHSA-7vgm-4f6w-wj5f.json new file mode 100644 index 00000000000..3fc6f9dc697 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-7vgm-4f6w-wj5f/GHSA-7vgm-4f6w-wj5f.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7vgm-4f6w-wj5f", + "modified": "2025-01-06T18:31:03Z", + "published": "2025-01-06T18:31:03Z", + "aliases": [ + "CVE-2024-56760" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nPCI/MSI: Handle lack of irqdomain gracefully\n\nAlexandre observed a warning emitted from pci_msi_setup_msi_irqs() on a\nRISCV platform which does not provide PCI/MSI support:\n\n WARNING: CPU: 1 PID: 1 at drivers/pci/msi/msi.h:121 pci_msi_setup_msi_irqs+0x2c/0x32\n __pci_enable_msix_range+0x30c/0x596\n pci_msi_setup_msi_irqs+0x2c/0x32\n pci_alloc_irq_vectors_affinity+0xb8/0xe2\n\nRISCV uses hierarchical interrupt domains and correctly does not implement\nthe legacy fallback. The warning triggers from the legacy fallback stub.\n\nThat warning is bogus as the PCI/MSI layer knows whether a PCI/MSI parent\ndomain is associated with the device or not. There is a check for MSI-X,\nwhich has a legacy assumption. But that legacy fallback assumption is only\nvalid when legacy support is enabled, but otherwise the check should simply\nreturn -ENOTSUPP.\n\nLoongarch tripped over the same problem and blindly enabled legacy support\nwithout implementing the legacy fallbacks. There are weak implementations\nwhich return an error, so the problem was papered over.\n\nCorrect pci_msi_domain_supports() to evaluate the legacy mode and add\nthe missing supported check into the MSI enable path to complete it.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56760" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a60b990798eb17433d0283788280422b1bd94b18" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/aed157301c659a48f5564cc4568cf0e5c8831af0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b1f7476e07b93d65a1a3643dcb4a7bed80d4328d" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-06T17:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-92hg-q4w2-pmcv/GHSA-92hg-q4w2-pmcv.json b/advisories/unreviewed/2025/01/GHSA-92hg-q4w2-pmcv/GHSA-92hg-q4w2-pmcv.json new file mode 100644 index 00000000000..16bae478409 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-92hg-q4w2-pmcv/GHSA-92hg-q4w2-pmcv.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-92hg-q4w2-pmcv", + "modified": "2025-01-06T18:31:02Z", + "published": "2025-01-06T18:31:02Z", + "aliases": [ + "CVE-2024-51112" + ], + "details": "Open Redirect vulnerability in Pnetlab 5.3.11 allows an attacker to manipulate URLs to redirect users to arbitrary external websites via a crafted script", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51112" + }, + { + "type": "WEB", + "url": "https://github.com/Zehraakmanlar/Bortecine-s_CVEs/blob/main/README.md" + }, + { + "type": "WEB", + "url": "http://pnetlab.com" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-06T16:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-c9h3-5qgq-g7wx/GHSA-c9h3-5qgq-g7wx.json b/advisories/unreviewed/2025/01/GHSA-c9h3-5qgq-g7wx/GHSA-c9h3-5qgq-g7wx.json new file mode 100644 index 00000000000..ea192387724 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-c9h3-5qgq-g7wx/GHSA-c9h3-5qgq-g7wx.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c9h3-5qgq-g7wx", + "modified": "2025-01-06T18:31:04Z", + "published": "2025-01-06T18:31:04Z", + "aliases": [ + "CVE-2024-56767" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: at_xdmac: avoid null_prt_deref in at_xdmac_prep_dma_memset\n\nThe at_xdmac_memset_create_desc may return NULL, which will lead to a\nnull pointer dereference. For example, the len input is error, or the\natchan->free_descs_list is empty and memory is exhausted. Therefore, add\ncheck to avoid this.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56767" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/54376d8d26596f98ed7432a788314bb9154bf3e3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c43ec96e8d34399bd9dab2f2dc316b904892133f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e658f1c133b854b2ae799147301d82dddb8f3162" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fdba6d5e455388377ec7e82a5913ddfcc7edd93b" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-06T17:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-f2h8-4w6p-535w/GHSA-f2h8-4w6p-535w.json b/advisories/unreviewed/2025/01/GHSA-f2h8-4w6p-535w/GHSA-f2h8-4w6p-535w.json index 8a7e8836c09..1e67c6a449b 100644 --- a/advisories/unreviewed/2025/01/GHSA-f2h8-4w6p-535w/GHSA-f2h8-4w6p-535w.json +++ b/advisories/unreviewed/2025/01/GHSA-f2h8-4w6p-535w/GHSA-f2h8-4w6p-535w.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-f2h8-4w6p-535w", - "modified": "2025-01-06T15:31:00Z", + "modified": "2025-01-06T18:31:02Z", "published": "2025-01-06T15:31:00Z", "aliases": [ "CVE-2024-5594" ], "details": "OpenVPN before 2.6.11 does not santize PUSH_REPLY messages properly which attackers can use to inject unexpected arbitrary data into third-party executables or plug-ins.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -27,7 +32,7 @@ "cwe_ids": [ "CWE-1287" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-06T14:15:08Z" diff --git a/advisories/unreviewed/2025/01/GHSA-f4vp-28x5-837r/GHSA-f4vp-28x5-837r.json b/advisories/unreviewed/2025/01/GHSA-f4vp-28x5-837r/GHSA-f4vp-28x5-837r.json index b6c1fc8a161..5306df30e0c 100644 --- a/advisories/unreviewed/2025/01/GHSA-f4vp-28x5-837r/GHSA-f4vp-28x5-837r.json +++ b/advisories/unreviewed/2025/01/GHSA-f4vp-28x5-837r/GHSA-f4vp-28x5-837r.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-f4vp-28x5-837r", - "modified": "2025-01-04T03:33:08Z", + "modified": "2025-01-06T18:31:02Z", "published": "2025-01-04T03:33:08Z", "aliases": [ "CVE-2025-22390" ], "details": "An issue was discovered in Optimizely EPiServer.CMS.Core before 12.32.0. A medium-severity vulnerability exists in the CMS due to insufficient enforcement of password complexity requirements. The application permits users to set passwords with a minimum length of 6 characters, lacking adequate complexity to resist modern attack techniques such as password spraying or offline password cracking.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-521" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-04T02:15:07Z" diff --git a/advisories/unreviewed/2025/01/GHSA-f6j3-h537-397p/GHSA-f6j3-h537-397p.json b/advisories/unreviewed/2025/01/GHSA-f6j3-h537-397p/GHSA-f6j3-h537-397p.json new file mode 100644 index 00000000000..d2e4dab0b60 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-f6j3-h537-397p/GHSA-f6j3-h537-397p.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f6j3-h537-397p", + "modified": "2025-01-06T18:31:04Z", + "published": "2025-01-06T18:31:04Z", + "aliases": [ + "CVE-2024-56765" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\npowerpc/pseries/vas: Add close() callback in vas_vm_ops struct\n\nThe mapping VMA address is saved in VAS window struct when the\npaste address is mapped. This VMA address is used during migration\nto unmap the paste address if the window is active. The paste\naddress mapping will be removed when the window is closed or with\nthe munmap(). But the VMA address in the VAS window is not updated\nwith munmap() which is causing invalid access during migration.\n\nThe KASAN report shows:\n[16386.254991] BUG: KASAN: slab-use-after-free in reconfig_close_windows+0x1a0/0x4e8\n[16386.255043] Read of size 8 at addr c00000014a819670 by task drmgr/696928\n\n[16386.255096] CPU: 29 UID: 0 PID: 696928 Comm: drmgr Kdump: loaded Tainted: G B 6.11.0-rc5-nxgzip #2\n[16386.255128] Tainted: [B]=BAD_PAGE\n[16386.255148] Hardware name: IBM,9080-HEX Power11 (architected) 0x820200 0xf000007 of:IBM,FW1110.00 (NH1110_016) hv:phyp pSeries\n[16386.255181] Call Trace:\n[16386.255202] [c00000016b297660] [c0000000018ad0ac] dump_stack_lvl+0x84/0xe8 (unreliable)\n[16386.255246] [c00000016b297690] [c0000000006e8a90] print_report+0x19c/0x764\n[16386.255285] [c00000016b297760] [c0000000006e9490] kasan_report+0x128/0x1f8\n[16386.255309] [c00000016b297880] [c0000000006eb5c8] __asan_load8+0xac/0xe0\n[16386.255326] [c00000016b2978a0] [c00000000013f898] reconfig_close_windows+0x1a0/0x4e8\n[16386.255343] [c00000016b297990] [c000000000140e58] vas_migration_handler+0x3a4/0x3fc\n[16386.255368] [c00000016b297a90] [c000000000128848] pseries_migrate_partition+0x4c/0x4c4\n...\n\n[16386.256136] Allocated by task 696554 on cpu 31 at 16377.277618s:\n[16386.256149] kasan_save_stack+0x34/0x68\n[16386.256163] kasan_save_track+0x34/0x80\n[16386.256175] kasan_save_alloc_info+0x58/0x74\n[16386.256196] __kasan_slab_alloc+0xb8/0xdc\n[16386.256209] kmem_cache_alloc_noprof+0x200/0x3d0\n[16386.256225] vm_area_alloc+0x44/0x150\n[16386.256245] mmap_region+0x214/0x10c4\n[16386.256265] do_mmap+0x5fc/0x750\n[16386.256277] vm_mmap_pgoff+0x14c/0x24c\n[16386.256292] ksys_mmap_pgoff+0x20c/0x348\n[16386.256303] sys_mmap+0xd0/0x160\n...\n\n[16386.256350] Freed by task 0 on cpu 31 at 16386.204848s:\n[16386.256363] kasan_save_stack+0x34/0x68\n[16386.256374] kasan_save_track+0x34/0x80\n[16386.256384] kasan_save_free_info+0x64/0x10c\n[16386.256396] __kasan_slab_free+0x120/0x204\n[16386.256415] kmem_cache_free+0x128/0x450\n[16386.256428] vm_area_free_rcu_cb+0xa8/0xd8\n[16386.256441] rcu_do_batch+0x2c8/0xcf0\n[16386.256458] rcu_core+0x378/0x3c4\n[16386.256473] handle_softirqs+0x20c/0x60c\n[16386.256495] do_softirq_own_stack+0x6c/0x88\n[16386.256509] do_softirq_own_stack+0x58/0x88\n[16386.256521] __irq_exit_rcu+0x1a4/0x20c\n[16386.256533] irq_exit+0x20/0x38\n[16386.256544] interrupt_async_exit_prepare.constprop.0+0x18/0x2c\n...\n\n[16386.256717] Last potentially related work creation:\n[16386.256729] kasan_save_stack+0x34/0x68\n[16386.256741] __kasan_record_aux_stack+0xcc/0x12c\n[16386.256753] __call_rcu_common.constprop.0+0x94/0xd04\n[16386.256766] vm_area_free+0x28/0x3c\n[16386.256778] remove_vma+0xf4/0x114\n[16386.256797] do_vmi_align_munmap.constprop.0+0x684/0x870\n[16386.256811] __vm_munmap+0xe0/0x1f8\n[16386.256821] sys_munmap+0x54/0x6c\n[16386.256830] system_call_exception+0x1a0/0x4a0\n[16386.256841] system_call_vectored_common+0x15c/0x2ec\n\n[16386.256868] The buggy address belongs to the object at c00000014a819670\n which belongs to the cache vm_area_struct of size 168\n[16386.256887] The buggy address is located 0 bytes inside of\n freed 168-byte region [c00000014a819670, c00000014a819718)\n\n[16386.256915] The buggy address belongs to the physical page:\n[16386.256928] page: refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x14a81\n[16386.256950] memcg:c0000000ba430001\n[16386.256961] anon flags: 0x43ffff800000000(node=4|zone=0|lastcpupid=0x7ffff)\n[16386.256975] page_type: 0xfdffffff(slab)\n[16386\n---truncated---", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56765" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/05aa156e156ef3168e7ab8a68721945196495c17" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6d9cd27105459f169993a4c5f216499a946dbf34" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8b2282b5084521254a2cd9742a3f4e1d5b77f843" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b7f60ffdfd96f8fc826f1d61a1c6067d828e20b9" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-06T17:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-f98m-7gfc-g33x/GHSA-f98m-7gfc-g33x.json b/advisories/unreviewed/2025/01/GHSA-f98m-7gfc-g33x/GHSA-f98m-7gfc-g33x.json index d067df3f7b4..c053579d9fb 100644 --- a/advisories/unreviewed/2025/01/GHSA-f98m-7gfc-g33x/GHSA-f98m-7gfc-g33x.json +++ b/advisories/unreviewed/2025/01/GHSA-f98m-7gfc-g33x/GHSA-f98m-7gfc-g33x.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-f98m-7gfc-g33x", - "modified": "2025-01-04T03:33:08Z", + "modified": "2025-01-06T18:31:02Z", "published": "2025-01-04T03:33:08Z", "aliases": [ "CVE-2025-22385" ], "details": "An issue was discovered in Optimizely Configured Commerce before 5.2.2408. For newly created accounts, the Commerce B2B application does not require email confirmation. This medium-severity issue allows the mass creation of accounts. This could affect database storage; also, non-requested storefront accounts can be created on behalf of visitors.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-862" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-04T02:15:07Z" diff --git a/advisories/unreviewed/2025/01/GHSA-fj69-f9qp-jh4f/GHSA-fj69-f9qp-jh4f.json b/advisories/unreviewed/2025/01/GHSA-fj69-f9qp-jh4f/GHSA-fj69-f9qp-jh4f.json new file mode 100644 index 00000000000..e32d2f32ca9 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-fj69-f9qp-jh4f/GHSA-fj69-f9qp-jh4f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fj69-f9qp-jh4f", + "modified": "2025-01-06T18:31:03Z", + "published": "2025-01-06T18:31:03Z", + "aliases": [ + "CVE-2024-51472" + ], + "details": "IBM UrbanCode Deploy (UCD) 7.2 through 7.2.3.13, 7.3 through 7.3.2.8, and IBM DevOps Deploy 8.0 through 8.0.1.3 are vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web UI potentially leading to sensitive information disclosure.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51472" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7177856" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-80" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-06T17:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-gw7h-65mp-jqvp/GHSA-gw7h-65mp-jqvp.json b/advisories/unreviewed/2025/01/GHSA-gw7h-65mp-jqvp/GHSA-gw7h-65mp-jqvp.json new file mode 100644 index 00000000000..bf2507d24d3 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-gw7h-65mp-jqvp/GHSA-gw7h-65mp-jqvp.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gw7h-65mp-jqvp", + "modified": "2025-01-06T18:31:03Z", + "published": "2025-01-06T18:31:03Z", + "aliases": [ + "CVE-2024-56757" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: btusb: mediatek: add intf release flow when usb disconnect\n\nMediaTek claim an special usb intr interface for ISO data transmission.\nThe interface need to be released before unregistering hci device when\nusb disconnect. Removing BT usb dongle without properly releasing the\ninterface may cause Kernel panic while unregister hci device.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56757" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/489304e67087abddc2666c5af0159cb95afdcf59" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cc569d791ab2a0de74f76e470515d25d24c9b84b" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-06T17:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-j6rq-mppc-h3jr/GHSA-j6rq-mppc-h3jr.json b/advisories/unreviewed/2025/01/GHSA-j6rq-mppc-h3jr/GHSA-j6rq-mppc-h3jr.json new file mode 100644 index 00000000000..5550832dad4 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-j6rq-mppc-h3jr/GHSA-j6rq-mppc-h3jr.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j6rq-mppc-h3jr", + "modified": "2025-01-06T18:31:03Z", + "published": "2025-01-06T18:31:03Z", + "aliases": [ + "CVE-2023-6604" + ], + "details": "A flaw was found in FFmpeg. This vulnerability allows unexpected additional CPU load and storage consumption, potentially leading to degraded performance or denial of service via the demuxing of arbitrary data as XBIN-formatted data without proper format validation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6604" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2334337" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94", + "CWE-99" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-06T17:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-jcgv-xjw5-6wp4/GHSA-jcgv-xjw5-6wp4.json b/advisories/unreviewed/2025/01/GHSA-jcgv-xjw5-6wp4/GHSA-jcgv-xjw5-6wp4.json index 48e4e704a6e..b65d5e6db4b 100644 --- a/advisories/unreviewed/2025/01/GHSA-jcgv-xjw5-6wp4/GHSA-jcgv-xjw5-6wp4.json +++ b/advisories/unreviewed/2025/01/GHSA-jcgv-xjw5-6wp4/GHSA-jcgv-xjw5-6wp4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jcgv-xjw5-6wp4", - "modified": "2025-01-04T03:33:08Z", + "modified": "2025-01-06T18:31:02Z", "published": "2025-01-04T03:33:08Z", "aliases": [ "CVE-2025-22386" ], "details": "An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity session issue exists in the Commerce B2B application, affecting the longevity of active sessions in the storefront. This allows session tokens tied to logged-out sessions to still be active and usable.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-613" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-04T02:15:07Z" diff --git a/advisories/unreviewed/2025/01/GHSA-mq6g-3vj7-6g88/GHSA-mq6g-3vj7-6g88.json b/advisories/unreviewed/2025/01/GHSA-mq6g-3vj7-6g88/GHSA-mq6g-3vj7-6g88.json new file mode 100644 index 00000000000..42f20d812ed --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-mq6g-3vj7-6g88/GHSA-mq6g-3vj7-6g88.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mq6g-3vj7-6g88", + "modified": "2025-01-06T18:31:04Z", + "published": "2025-01-06T18:31:04Z", + "aliases": [ + "CVE-2024-56764" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nublk: detach gendisk from ublk device if add_disk() fails\n\nInside ublk_abort_requests(), gendisk is grabbed for aborting all\ninflight requests. And ublk_abort_requests() is called when exiting\nthe uring context or handling timeout.\n\nIf add_disk() fails, the gendisk may have been freed when calling\nublk_abort_requests(), so use-after-free can be caused when getting\ndisk's reference in ublk_abort_requests().\n\nFixes the bug by detaching gendisk from ublk device if add_disk() fails.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56764" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/75cd4005da5492129917a4a4ee45e81660556104" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7d680f2f76a3417fdfc3946da7471e81464f7b41" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-06T17:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-p626-9v99-xc4x/GHSA-p626-9v99-xc4x.json b/advisories/unreviewed/2025/01/GHSA-p626-9v99-xc4x/GHSA-p626-9v99-xc4x.json index b06352c46ca..0aa8aa484fd 100644 --- a/advisories/unreviewed/2025/01/GHSA-p626-9v99-xc4x/GHSA-p626-9v99-xc4x.json +++ b/advisories/unreviewed/2025/01/GHSA-p626-9v99-xc4x/GHSA-p626-9v99-xc4x.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p626-9v99-xc4x", - "modified": "2025-01-04T03:33:08Z", + "modified": "2025-01-06T18:31:02Z", "published": "2025-01-04T03:33:08Z", "aliases": [ "CVE-2025-22387" ], "details": "An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity issue exists in requests for resources where the session token is submitted as a URL parameter. This exposes information about the authenticated session, which can be leveraged for session hijacking.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-598" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-04T02:15:07Z" diff --git a/advisories/unreviewed/2025/01/GHSA-phw5-fqgg-rhr7/GHSA-phw5-fqgg-rhr7.json b/advisories/unreviewed/2025/01/GHSA-phw5-fqgg-rhr7/GHSA-phw5-fqgg-rhr7.json new file mode 100644 index 00000000000..c19d5110a0e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-phw5-fqgg-rhr7/GHSA-phw5-fqgg-rhr7.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-phw5-fqgg-rhr7", + "modified": "2025-01-06T18:31:02Z", + "published": "2025-01-06T18:31:02Z", + "aliases": [ + "CVE-2024-51111" + ], + "details": "Cross-Site Scripting (XSS) vulnerability in Pnetlab 5.3.11 allows an attacker to inject malicious scripts into a web page, which are executed in the context of the victim's browser.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51111" + }, + { + "type": "WEB", + "url": "https://github.com/Zehraakmanlar/Bortecine-s_CVEs/blob/main/README.md" + }, + { + "type": "WEB", + "url": "http://pnetlab.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-06T16:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-q23h-j65c-73m4/GHSA-q23h-j65c-73m4.json b/advisories/unreviewed/2025/01/GHSA-q23h-j65c-73m4/GHSA-q23h-j65c-73m4.json new file mode 100644 index 00000000000..86c4f88b843 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-q23h-j65c-73m4/GHSA-q23h-j65c-73m4.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q23h-j65c-73m4", + "modified": "2025-01-06T18:31:04Z", + "published": "2025-01-06T18:31:04Z", + "aliases": [ + "CVE-2024-56769" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: dvb-frontends: dib3000mb: fix uninit-value in dib3000_write_reg\n\nSyzbot reports [1] an uninitialized value issue found by KMSAN in\ndib3000_read_reg().\n\nLocal u8 rb[2] is used in i2c_transfer() as a read buffer; in case\nthat call fails, the buffer may end up with some undefined values.\n\nSince no elaborate error handling is expected in dib3000_write_reg(),\nsimply zero out rb buffer to mitigate the problem.\n\n[1] Syzkaller report\ndvb-usb: bulk message failed: -22 (6/0)\n=====================================================\nBUG: KMSAN: uninit-value in dib3000mb_attach+0x2d8/0x3c0 drivers/media/dvb-frontends/dib3000mb.c:758\n dib3000mb_attach+0x2d8/0x3c0 drivers/media/dvb-frontends/dib3000mb.c:758\n dibusb_dib3000mb_frontend_attach+0x155/0x2f0 drivers/media/usb/dvb-usb/dibusb-mb.c:31\n dvb_usb_adapter_frontend_init+0xed/0x9a0 drivers/media/usb/dvb-usb/dvb-usb-dvb.c:290\n dvb_usb_adapter_init drivers/media/usb/dvb-usb/dvb-usb-init.c:90 [inline]\n dvb_usb_init drivers/media/usb/dvb-usb/dvb-usb-init.c:186 [inline]\n dvb_usb_device_init+0x25a8/0x3760 drivers/media/usb/dvb-usb/dvb-usb-init.c:310\n dibusb_probe+0x46/0x250 drivers/media/usb/dvb-usb/dibusb-mb.c:110\n...\nLocal variable rb created at:\n dib3000_read_reg+0x86/0x4e0 drivers/media/dvb-frontends/dib3000mb.c:54\n dib3000mb_attach+0x123/0x3c0 drivers/media/dvb-frontends/dib3000mb.c:758\n...", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56769" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1d6de21f00293d819b5ca6dbe75ff1f3b6392140" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2dd59fe0e19e1ab955259978082b62e5751924c7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3876e3a1c31a58a352c6bf5d2a90e3304445a637" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c1197c1457bb7098cf46366e898eb52b41b6876a" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-06T17:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-q9hp-vwf8-w58f/GHSA-q9hp-vwf8-w58f.json b/advisories/unreviewed/2025/01/GHSA-q9hp-vwf8-w58f/GHSA-q9hp-vwf8-w58f.json new file mode 100644 index 00000000000..4b44a72cd36 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-q9hp-vwf8-w58f/GHSA-q9hp-vwf8-w58f.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q9hp-vwf8-w58f", + "modified": "2025-01-06T18:31:04Z", + "published": "2025-01-06T18:31:04Z", + "aliases": [ + "CVE-2024-56761" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/fred: Clear WFE in missing-ENDBRANCH #CPs\n\nAn indirect branch instruction sets the CPU indirect branch tracker\n(IBT) into WAIT_FOR_ENDBRANCH (WFE) state and WFE stays asserted\nacross the instruction boundary. When the decoder finds an\ninappropriate instruction while WFE is set ENDBR, the CPU raises a #CP\nfault.\n\nFor the \"kernel IBT no ENDBR\" selftest where #CPs are deliberately\ntriggered, the WFE state of the interrupted context needs to be\ncleared to let execution continue. Otherwise when the CPU resumes\nfrom the instruction that just caused the previous #CP, another\nmissing-ENDBRANCH #CP is raised and the CPU enters a dead loop.\n\nThis is not a problem with IDT because it doesn't preserve WFE and\nIRET doesn't set WFE. But FRED provides space on the entry stack\n(in an expanded CS area) to save and restore the WFE state, thus the\nWFE state is no longer clobbered, so software must clear it.\n\nClear WFE to avoid dead looping in ibt_clear_fred_wfe() and the\n!ibt_fatal code path when execution is allowed to continue.\n\nClobbering WFE in any other circumstance is a security-relevant bug.\n\n[ dhansen: changelog rewording ]", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56761" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b939f108e86b76119428a6fa4e92491e09ac7867" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/dc81e556f2a017d681251ace21bf06c126d5a192" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-06T17:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-qcg2-98h8-485j/GHSA-qcg2-98h8-485j.json b/advisories/unreviewed/2025/01/GHSA-qcg2-98h8-485j/GHSA-qcg2-98h8-485j.json index ed8d2a8984c..505585dbf96 100644 --- a/advisories/unreviewed/2025/01/GHSA-qcg2-98h8-485j/GHSA-qcg2-98h8-485j.json +++ b/advisories/unreviewed/2025/01/GHSA-qcg2-98h8-485j/GHSA-qcg2-98h8-485j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qcg2-98h8-485j", - "modified": "2025-01-06T15:31:00Z", + "modified": "2025-01-06T18:31:02Z", "published": "2025-01-06T15:31:00Z", "aliases": [ "CVE-2024-8474" ], "details": "OpenVPN Connect before version 3.5.0 can contain the configuration profile's clear-text private key which is logged in the application log, which an unauthorized actor can use to decrypt the VPN traffic", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-212" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-06T15:15:14Z" diff --git a/advisories/unreviewed/2025/01/GHSA-rqp2-5j8f-59r3/GHSA-rqp2-5j8f-59r3.json b/advisories/unreviewed/2025/01/GHSA-rqp2-5j8f-59r3/GHSA-rqp2-5j8f-59r3.json new file mode 100644 index 00000000000..bd0b7d2437a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-rqp2-5j8f-59r3/GHSA-rqp2-5j8f-59r3.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rqp2-5j8f-59r3", + "modified": "2025-01-06T18:31:04Z", + "published": "2025-01-06T18:31:04Z", + "aliases": [ + "CVE-2024-46622" + ], + "details": "An Escalation of Privilege security vulnerability was found in SecureAge Security Suite software 7.0.x before 7.0.38, 7.1.x before 7.1.11, 8.0.x before 8.0.18, and 8.1.x before 8.1.18 that allows arbitrary file creation, modification and deletion.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46622" + }, + { + "type": "WEB", + "url": "https://www.secureage.com" + }, + { + "type": "WEB", + "url": "https://www.secureage.com/blog/resolved-escalation-of-privilege" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-06T18:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-vj55-2cxj-5mrc/GHSA-vj55-2cxj-5mrc.json b/advisories/unreviewed/2025/01/GHSA-vj55-2cxj-5mrc/GHSA-vj55-2cxj-5mrc.json new file mode 100644 index 00000000000..42032cc6143 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-vj55-2cxj-5mrc/GHSA-vj55-2cxj-5mrc.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vj55-2cxj-5mrc", + "modified": "2025-01-06T18:31:04Z", + "published": "2025-01-06T18:31:04Z", + "aliases": [ + "CVE-2024-56763" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: Prevent bad count for tracing_cpumask_write\n\nIf a large count is provided, it will trigger a warning in bitmap_parse_user.\nAlso check zero for it.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56763" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/03041e474a6a8f1bfd4b96b164bb3165c48fa1a3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1cca920af19df5dd91254e5ff35e68e911683706" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3d15f4c2449558ffe83b4dba30614ef1cd6937c3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/98feccbf32cfdde8c722bc4587aaa60ee5ac33f0" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-06T17:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-vw24-gw6x-f64v/GHSA-vw24-gw6x-f64v.json b/advisories/unreviewed/2025/01/GHSA-vw24-gw6x-f64v/GHSA-vw24-gw6x-f64v.json new file mode 100644 index 00000000000..cc283a394f8 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-vw24-gw6x-f64v/GHSA-vw24-gw6x-f64v.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vw24-gw6x-f64v", + "modified": "2025-01-06T18:31:04Z", + "published": "2025-01-06T18:31:04Z", + "aliases": [ + "CVE-2024-54879" + ], + "details": "SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user to recharge members indefinitely.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54879" + }, + { + "type": "WEB", + "url": "https://blog.csdn.net/weixin_46686336/article/details/144797242" + }, + { + "type": "WEB", + "url": "http://seacms.com" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-06T18:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-wj7r-cv36-mxr3/GHSA-wj7r-cv36-mxr3.json b/advisories/unreviewed/2025/01/GHSA-wj7r-cv36-mxr3/GHSA-wj7r-cv36-mxr3.json new file mode 100644 index 00000000000..6d924b3436c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-wj7r-cv36-mxr3/GHSA-wj7r-cv36-mxr3.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wj7r-cv36-mxr3", + "modified": "2025-01-06T18:31:03Z", + "published": "2025-01-06T18:31:03Z", + "aliases": [ + "CVE-2023-6601" + ], + "details": "A flaw was found in FFmpeg's HLS demuxer. This vulnerability allows bypassing unsafe file extension checks and triggering arbitrary demuxers via base64-encoded data URIs appended with specific file extensions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6601" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2253172" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94", + "CWE-99" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-06T17:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-x3j3-jwh6-pfh4/GHSA-x3j3-jwh6-pfh4.json b/advisories/unreviewed/2025/01/GHSA-x3j3-jwh6-pfh4/GHSA-x3j3-jwh6-pfh4.json index 545a2e61a6a..9962e0d2174 100644 --- a/advisories/unreviewed/2025/01/GHSA-x3j3-jwh6-pfh4/GHSA-x3j3-jwh6-pfh4.json +++ b/advisories/unreviewed/2025/01/GHSA-x3j3-jwh6-pfh4/GHSA-x3j3-jwh6-pfh4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x3j3-jwh6-pfh4", - "modified": "2025-01-03T06:32:09Z", + "modified": "2025-01-06T18:31:02Z", "published": "2025-01-03T06:32:09Z", "aliases": [ "CVE-2024-53833" ], "details": "In prepare_response_locked of lwis_transaction.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-03T04:15:06Z" diff --git a/advisories/unreviewed/2025/01/GHSA-x492-3p6g-fmvm/GHSA-x492-3p6g-fmvm.json b/advisories/unreviewed/2025/01/GHSA-x492-3p6g-fmvm/GHSA-x492-3p6g-fmvm.json new file mode 100644 index 00000000000..6debfddf889 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-x492-3p6g-fmvm/GHSA-x492-3p6g-fmvm.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x492-3p6g-fmvm", + "modified": "2025-01-06T18:31:04Z", + "published": "2025-01-06T18:31:04Z", + "aliases": [ + "CVE-2024-46073" + ], + "details": "A reflected Cross-Site Scripting (XSS) vulnerability exists in the login page of IceHRM v32.4.0.OS. The vulnerability is due to improper sanitization of the \"next\" parameter, which is included in the application's response without adequate escaping. An attacker can exploit this flaw by tricking a user into visiting a specially crafted URL, causing the execution of arbitrary JavaScript code in the context of the victim's browser. The issue occurs even though the application has sanitization mechanisms in place.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46073" + }, + { + "type": "WEB", + "url": "https://github.com/gamonoid/icehrm" + }, + { + "type": "WEB", + "url": "https://github.com/manisashank/CVE-Publish/blob/main/CVE-2024-46073.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-06T18:15:19Z" + } +} \ No newline at end of file