Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2025-03-17 15:33:11 +00:00
parent c69fd60300
commit 1854ef5652
94 changed files with 1867 additions and 143 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3866-98fq-wg7f",
"modified": "2022-04-30T18:10:39Z",
"modified": "2025-03-17T15:31:34Z",
"published": "2022-04-30T18:10:39Z",
"aliases": [
"CVE-1999-0472"
@@ -17,6 +17,10 @@
{
"type": "WEB",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0472"
},
{
"type": "WEB",
"url": "https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2017-240"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-46xg-4hcp-2ppj",
"modified": "2022-04-30T18:09:57Z",
"modified": "2025-03-17T15:31:33Z",
"published": "2022-04-30T18:09:57Z",
"aliases": [
"CVE-1999-0103"
@@ -17,6 +17,10 @@
{
"type": "WEB",
"url": "https://ics-cert.us-cert.gov/advisories/ICSMA-18-233-01"
},
{
"type": "WEB",
"url": "http://www.securityfocus.com/bid/80171"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5mw4-cxpf-cxvj",
"modified": "2022-04-30T18:09:48Z",
"modified": "2025-03-17T15:31:34Z",
"published": "2022-04-30T18:09:48Z",
"aliases": [
"CVE-1999-0016"
@@ -14,6 +14,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-1999-0016"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20170815-0001"
},
{
"type": "WEB",
"url": "http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9801-076"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5qg4-5cpf-4r9p",
"modified": "2022-04-30T18:10:45Z",
"modified": "2025-03-17T15:31:34Z",
"published": "2022-04-30T18:10:45Z",
"aliases": [
"CVE-1999-0524"
@@ -26,6 +26,10 @@
"type": "WEB",
"url": "https://kc.mcafee.com/corporate/index?page=content&id=SB10053"
},
{
"type": "WEB",
"url": "https://support.f5.com/csp/article/K15277"
},
{
"type": "WEB",
"url": "http://descriptions.securescout.com/tc/11010"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-926f-mjrv-g5m6",
"modified": "2022-04-30T18:10:45Z",
"modified": "2025-03-17T15:31:33Z",
"published": "2022-04-30T18:10:45Z",
"aliases": [
"CVE-1999-0532"
@@ -17,6 +17,10 @@
{
"type": "WEB",
"url": "https://www.cve.org/CVERecord?id=CVE-1999-0532"
},
{
"type": "WEB",
"url": "http://www.us-cert.gov/ncas/alerts/TA15-103A"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-92cr-5v4q-xgj9",
"modified": "2022-04-30T18:10:06Z",
"modified": "2025-03-17T15:31:34Z",
"published": "2022-04-30T18:10:06Z",
"aliases": [
"CVE-1999-0186"
@@ -14,6 +14,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-1999-0186"
},
{
"type": "WEB",
"url": "https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2017-238"
},
{
"type": "WEB",
"url": "http://support.novell.com/cgi-bin/search/searchtid.cgi?/10080762.htm"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p4hh-f88r-4p2r",
"modified": "2022-04-30T18:10:17Z",
"modified": "2025-03-17T15:31:34Z",
"published": "2022-04-30T18:10:17Z",
"aliases": [
"CVE-1999-0254"
@@ -17,6 +17,10 @@
{
"type": "WEB",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0254"
},
{
"type": "WEB",
"url": "https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2017-239"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p65v-7qg9-x6wf",
"modified": "2022-04-30T18:10:44Z",
"modified": "2025-03-17T15:31:34Z",
"published": "2022-04-30T18:10:44Z",
"aliases": [
"CVE-1999-0516"
@@ -17,6 +17,10 @@
{
"type": "WEB",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0516"
},
{
"type": "WEB",
"url": "https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2017-243"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wvmj-jgmg-4ghq",
"modified": "2022-04-30T18:10:43Z",
"modified": "2025-03-17T15:31:33Z",
"published": "2022-04-30T18:10:43Z",
"aliases": [
"CVE-1999-0517"
@@ -17,6 +17,10 @@
{
"type": "WEB",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0517"
},
{
"type": "WEB",
"url": "https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2017-244"
}
],
"database_specific": {
@@ -29,7 +29,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-511"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-25m9-3j97-v6cg",
"modified": "2024-11-04T15:31:53Z",
"modified": "2025-03-17T15:31:36Z",
"published": "2024-03-26T18:32:06Z",
"aliases": [
"CVE-2023-52622"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\next4: avoid online resizing failures due to oversized flex bg\n\nWhen we online resize an ext4 filesystem with a oversized flexbg_size,\n\n mkfs.ext4 -F -G 67108864 $dev -b 4096 100M\n mount $dev $dir\n resize2fs $dev 16G\n\nthe following WARN_ON is triggered:\n==================================================================\nWARNING: CPU: 0 PID: 427 at mm/page_alloc.c:4402 __alloc_pages+0x411/0x550\nModules linked in: sg(E)\nCPU: 0 PID: 427 Comm: resize2fs Tainted: G E 6.6.0-rc5+ #314\nRIP: 0010:__alloc_pages+0x411/0x550\nCall Trace:\n <TASK>\n __kmalloc_large_node+0xa2/0x200\n __kmalloc+0x16e/0x290\n ext4_resize_fs+0x481/0xd80\n __ext4_ioctl+0x1616/0x1d90\n ext4_ioctl+0x12/0x20\n __x64_sys_ioctl+0xf0/0x150\n do_syscall_64+0x3b/0x90\n==================================================================\n\nThis is because flexbg_size is too large and the size of the new_group_data\narray to be allocated exceeds MAX_ORDER. Currently, the minimum value of\nMAX_ORDER is 8, the minimum value of PAGE_SIZE is 4096, the corresponding\nmaximum number of groups that can be allocated is:\n\n (PAGE_SIZE << MAX_ORDER) / sizeof(struct ext4_new_group_data) ≈ 21845\n\nAnd the value that is down-aligned to the power of 2 is 16384. Therefore,\nthis value is defined as MAX_RESIZE_BG, and the number of groups added\neach time does not exceed this value during resizing, and is added multiple\ntimes to complete the online resizing. The difference is that the metadata\nin a flex_bg may be more dispersed.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [],
"references": [
{
@@ -56,8 +61,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-770"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-26T18:15:08Z"
File diff suppressed because one or more lines are too long
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3q2v-922f-6rc3",
"modified": "2024-03-25T12:30:52Z",
"modified": "2025-03-17T15:31:35Z",
"published": "2024-03-25T12:30:52Z",
"aliases": [
"CVE-2021-47177"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\niommu/vt-d: Fix sysfs leak in alloc_iommu()\n\niommu_device_sysfs_add() is called before, so is has to be cleaned on subsequent\nerrors.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [],
"references": [
{
@@ -40,8 +45,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-401"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-25T10:15:09Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6r42-gm3x-9xx3",
"modified": "2024-07-05T09:33:43Z",
"modified": "2025-03-17T15:31:37Z",
"published": "2024-03-28T09:31:13Z",
"aliases": [
"CVE-2023-52628"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nftables: exthdr: fix 4-byte stack OOB write\n\nIf priv->len is a multiple of 4, then dst[len / 4] can write past\nthe destination array which leads to stack corruption.\n\nThis construct is necessary to clean the remainder of the register\nin case ->len is NOT a multiple of the register size, so make it\nconditional just like nft_payload.c does.\n\nThe bug was added in 4.1 cycle and then copied/inherited when\ntcp/sctp and ip option support was added.\n\nBug reported by Zero Day Initiative project (ZDI-CAN-21950,\nZDI-CAN-21951, ZDI-CAN-21961).",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
}
],
"affected": [],
"references": [
{
@@ -48,8 +53,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-787"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-28T08:15:25Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-78r6-645f-335q",
"modified": "2024-03-26T18:32:06Z",
"modified": "2025-03-17T15:31:36Z",
"published": "2024-03-26T18:32:06Z",
"aliases": [
"CVE-2023-52625"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Refactor DMCUB enter/exit idle interface\n\n[Why]\nWe can hang in place trying to send commands when the DMCUB isn't\npowered on.\n\n[How]\nWe need to exit out of the idle state prior to sending a command,\nbut the process that performs the exit also invokes a command itself.\n\nFixing this issue involves the following:\n\n1. Using a software state to track whether or not we need to start\n the process to exit idle or notify idle.\n\nIt's possible for the hardware to have exited an idle state without\ndriver knowledge, but entering one is always restricted to a driver\nallow - which makes the SW state vs HW state mismatch issue purely one\nof optimization, which should seldomly be hit, if at all.\n\n2. Refactor any instances of exit/notify idle to use a single wrapper\n that maintains this SW state.\n\nThis works simialr to dc_allow_idle_optimizations, but works at the\nDMCUB level and makes sure the state is marked prior to any notify/exit\nidle so we don't enter an infinite loop.\n\n3. Make sure we exit out of idle prior to sending any commands or\n waiting for DMCUB idle.\n\nThis patch takes care of 1/2. A future patch will take care of wrapping\nDMCUB command submission with calls to this new interface.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [],
"references": [
{
@@ -25,7 +30,7 @@
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-26T18:15:09Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8229-hhm6-4mmc",
"modified": "2024-03-25T12:30:52Z",
"modified": "2025-03-17T15:31:35Z",
"published": "2024-03-25T12:30:52Z",
"aliases": [
"CVE-2021-47168"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nNFS: fix an incorrect limit in filelayout_decode_layout()\n\nThe \"sizeof(struct nfs_fh)\" is two bytes too large and could lead to\nmemory corruption. It should be NFS_MAXFHSIZE because that's the size\nof the ->data[] buffer.\n\nI reversed the size of the arguments to put the variable on the left.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [],
"references": [
{
@@ -48,8 +53,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-787"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-25T10:15:08Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8gg9-98mh-rcwr",
"modified": "2024-03-25T12:30:52Z",
"modified": "2025-03-17T15:31:35Z",
"published": "2024-03-25T12:30:52Z",
"aliases": [
"CVE-2021-47176"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ns390/dasd: add missing discipline function\n\nFix crash with illegal operation exception in dasd_device_tasklet.\nCommit b72949328869 (\"s390/dasd: Prepare for additional path event handling\")\nrenamed the verify_path function for ECKD but not for FBA and DIAG.\nThis leads to a panic when the path verification function is called for a\nFBA or DIAG device.\n\nFix by defining a wrapper function for dasd_generic_verify_path().",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [],
"references": [
{
@@ -33,7 +38,7 @@
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-25T10:15:09Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8qqh-mhqw-2cp3",
"modified": "2024-03-26T18:32:06Z",
"modified": "2025-03-17T15:31:36Z",
"published": "2024-03-26T18:32:06Z",
"aliases": [
"CVE-2023-52624"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Wake DMCUB before executing GPINT commands\n\n[Why]\nDMCUB can be in idle when we attempt to interface with the HW through\nthe GPINT mailbox resulting in a system hang.\n\n[How]\nAdd dc_wake_and_execute_gpint() to wrap the wake, execute, sleep\nsequence.\n\nIf the GPINT executes successfully then DMCUB will be put back into\nsleep after the optional response is returned.\n\nIt functions similar to the inbox command interface.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-77"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-26T18:15:08Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c673-578f-v4xm",
"modified": "2024-03-25T12:30:52Z",
"modified": "2025-03-17T15:31:35Z",
"published": "2024-03-25T12:30:52Z",
"aliases": [
"CVE-2021-47170"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: usbfs: Don't WARN about excessively large memory allocations\n\nSyzbot found that the kernel generates a WARNing if the user tries to\nsubmit a bulk transfer through usbfs with a buffer that is way too\nlarge. This isn't a bug in the kernel; it's merely an invalid request\nfrom the user and the usbfs code does handle it correctly.\n\nIn theory the same thing can happen with async transfers, or with the\npacket descriptor table for isochronous transfers.\n\nTo prevent the MM subsystem from complaining about these bad\nallocation requests, add the __GFP_NOWARN flag to the kmalloc calls\nfor these buffers.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [],
"references": [
{
@@ -36,8 +41,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-770"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-25T10:15:08Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gqm5-q6hv-hp8w",
"modified": "2024-03-25T12:30:52Z",
"modified": "2025-03-17T15:31:34Z",
"published": "2024-03-25T12:30:52Z",
"aliases": [
"CVE-2021-47166"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nNFS: Don't corrupt the value of pg_bytes_written in nfs_do_recoalesce()\n\nThe value of mirror->pg_bytes_written should only be updated after a\nsuccessful attempt to flush out the requests on the list.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [],
"references": [
{
@@ -48,8 +53,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-787"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-25T10:15:08Z"

Some files were not shown because too many files have changed in this diff Show More