From 1854ef56521730e7b48f8a328f16a83475eab89b Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 17 Mar 2025 15:33:11 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-3866-98fq-wg7f.json | 6 +- .../GHSA-46xg-4hcp-2ppj.json | 6 +- .../GHSA-5mw4-cxpf-cxvj.json | 6 +- .../GHSA-5qg4-5cpf-4r9p.json | 6 +- .../GHSA-926f-mjrv-g5m6.json | 6 +- .../GHSA-92cr-5v4q-xgj9.json | 6 +- .../GHSA-p4hh-f88r-4p2r.json | 6 +- .../GHSA-p65v-7qg9-x6wf.json | 6 +- .../GHSA-wvmj-jgmg-4ghq.json | 6 +- .../GHSA-wr66-4wc3-frfh.json | 4 +- .../GHSA-25m9-3j97-v6cg.json | 15 +++-- .../GHSA-36f6-8vpp-3cqp.json | 15 +++-- .../GHSA-3q2v-922f-6rc3.json | 15 +++-- .../GHSA-6r42-gm3x-9xx3.json | 15 +++-- .../GHSA-78r6-645f-335q.json | 11 +++- .../GHSA-8229-hhm6-4mmc.json | 15 +++-- .../GHSA-8gg9-98mh-rcwr.json | 11 +++- .../GHSA-8qqh-mhqw-2cp3.json | 15 +++-- .../GHSA-c673-578f-v4xm.json | 15 +++-- .../GHSA-gqm5-q6hv-hp8w.json | 15 +++-- .../GHSA-hwc8-wrmm-ch4w.json | 11 +++- .../GHSA-p224-3949-7fhp.json | 11 +++- .../GHSA-p5xw-cvrw-p372.json | 11 +++- .../GHSA-pjqv-pvfh-2w6m.json | 11 +++- .../GHSA-pmx2-4vwx-fc3h.json | 15 +++-- .../GHSA-qggq-gw32-wcq3.json | 15 +++-- .../GHSA-vmqf-grh3-9rrr.json | 15 +++-- .../GHSA-wrwp-f8pq-q3qj.json | 15 +++-- .../GHSA-xr82-8hm6-h468.json | 15 +++-- .../GHSA-2vjc-6f7c-9p77.json | 4 +- .../GHSA-2wjh-rvr2-xxjw.json | 15 +++-- .../GHSA-389h-6rjg-wxc9.json | 15 +++-- .../GHSA-6246-6gx2-c2hw.json | 15 +++-- .../GHSA-7wpv-j3wh-7j6j.json | 15 +++-- .../GHSA-c7h5-f667-cvc5.json | 15 +++-- .../GHSA-cmxf-xmv7-xjq8.json | 15 +++-- .../GHSA-f688-vq7p-p658.json | 15 +++-- .../GHSA-fqg2-664v-fx4j.json | 11 +++- .../GHSA-g65w-rrjg-vx49.json | 15 +++-- .../GHSA-gjgq-73mh-6p69.json | 11 +++- .../GHSA-jp94-w382-qgwr.json | 4 +- .../GHSA-pj2j-w9fr-j7p8.json | 4 +- .../GHSA-qjvp-25fj-gf6v.json | 15 +++-- .../GHSA-vpp3-8c88-m6w7.json | 15 +++-- .../GHSA-wggj-8rcc-246r.json | 15 +++-- .../GHSA-j24x-6m7r-h4gp.json | 4 +- .../GHSA-j6h8-65gx-v495.json | 4 +- .../GHSA-w2wv-53w9-5r3r.json | 10 +++- .../GHSA-xh89-f5vr-hmhw.json | 3 +- .../GHSA-4q9j-5567-rg22.json | 3 +- .../GHSA-7w8f-hj5m-33r5.json | 3 +- .../GHSA-w897-r9c3-5chp.json | 3 +- .../GHSA-2hhx-vp2f-m5hf.json | 3 +- .../GHSA-c649-279m-q7qv.json | 3 +- .../GHSA-hmf6-8vmc-33g5.json | 1 + .../GHSA-v37g-gf72-65f5.json | 1 + .../GHSA-xjq3-p9vw-4qrf.json | 1 + .../GHSA-25cf-wq2p-gqxf.json | 36 ++++++++++++ .../GHSA-427r-3p9f-8q5w.json | 36 ++++++++++++ .../GHSA-5frw-vhr9-h7mp.json | 56 +++++++++++++++++++ .../GHSA-6qvm-8hqf-vwf3.json | 36 ++++++++++++ .../GHSA-78pj-pg5h-qf98.json | 37 ++++++++++++ .../GHSA-8f4x-4qgh-w73f.json | 36 ++++++++++++ .../GHSA-8vm5-7vg4-3f5x.json | 36 ++++++++++++ .../GHSA-9cc9-h5mf-w5fr.json | 36 ++++++++++++ .../GHSA-9x7w-p6r9-4xp9.json | 33 +++++++++++ .../GHSA-c369-gmg5-w8pw.json | 36 ++++++++++++ .../GHSA-ffm8-j238-56p4.json | 33 +++++++++++ .../GHSA-fwm7-53g9-cmxr.json | 36 ++++++++++++ .../GHSA-gf54-mv55-8xgf.json | 36 ++++++++++++ .../GHSA-gjf5-5c3r-89f6.json | 56 +++++++++++++++++++ .../GHSA-gp57-h4hf-v8gp.json | 36 ++++++++++++ .../GHSA-h5vx-hx75-xm9f.json | 36 ++++++++++++ .../GHSA-hcxf-42cf-2vjf.json | 36 ++++++++++++ .../GHSA-j4m5-qgpf-4c8g.json | 36 ++++++++++++ .../GHSA-jqg7-j926-j8mj.json | 36 ++++++++++++ .../GHSA-m27g-7h9f-wrhv.json | 36 ++++++++++++ .../GHSA-m7qh-qcm5-xf88.json | 36 ++++++++++++ .../GHSA-m7rg-5646-hfxm.json | 56 +++++++++++++++++++ .../GHSA-mf6m-3qv8-qp4q.json | 36 ++++++++++++ .../GHSA-mg2f-6rj5-pr3w.json | 36 ++++++++++++ .../GHSA-mwxh-v66f-wcq5.json | 33 +++++++++++ .../GHSA-p53g-v548-5w7v.json | 36 ++++++++++++ .../GHSA-ph9c-99wp-5w5f.json | 36 ++++++++++++ .../GHSA-q62g-355r-cfg2.json | 36 ++++++++++++ .../GHSA-qcqx-4h2x-x43j.json | 36 ++++++++++++ .../GHSA-qh8m-89j4-42jf.json | 36 ++++++++++++ .../GHSA-qqcj-9cvv-63xg.json | 56 +++++++++++++++++++ .../GHSA-r4vm-xmvg-644h.json | 33 +++++++++++ .../GHSA-rg2v-4c8w-w4r4.json | 36 ++++++++++++ .../GHSA-w2mf-wgp6-w934.json | 56 +++++++++++++++++++ .../GHSA-w97p-2hwc-7qx6.json | 44 +++++++++++++++ .../GHSA-wc4q-pc87-7ch2.json | 56 +++++++++++++++++++ .../GHSA-xmvv-w44w-j8wx.json | 40 +++++++++++++ 94 files changed, 1867 insertions(+), 143 deletions(-) create mode 100644 advisories/unreviewed/2025/03/GHSA-25cf-wq2p-gqxf/GHSA-25cf-wq2p-gqxf.json create mode 100644 advisories/unreviewed/2025/03/GHSA-427r-3p9f-8q5w/GHSA-427r-3p9f-8q5w.json create mode 100644 advisories/unreviewed/2025/03/GHSA-5frw-vhr9-h7mp/GHSA-5frw-vhr9-h7mp.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6qvm-8hqf-vwf3/GHSA-6qvm-8hqf-vwf3.json create mode 100644 advisories/unreviewed/2025/03/GHSA-78pj-pg5h-qf98/GHSA-78pj-pg5h-qf98.json create mode 100644 advisories/unreviewed/2025/03/GHSA-8f4x-4qgh-w73f/GHSA-8f4x-4qgh-w73f.json create mode 100644 advisories/unreviewed/2025/03/GHSA-8vm5-7vg4-3f5x/GHSA-8vm5-7vg4-3f5x.json create mode 100644 advisories/unreviewed/2025/03/GHSA-9cc9-h5mf-w5fr/GHSA-9cc9-h5mf-w5fr.json create mode 100644 advisories/unreviewed/2025/03/GHSA-9x7w-p6r9-4xp9/GHSA-9x7w-p6r9-4xp9.json create mode 100644 advisories/unreviewed/2025/03/GHSA-c369-gmg5-w8pw/GHSA-c369-gmg5-w8pw.json create mode 100644 advisories/unreviewed/2025/03/GHSA-ffm8-j238-56p4/GHSA-ffm8-j238-56p4.json create mode 100644 advisories/unreviewed/2025/03/GHSA-fwm7-53g9-cmxr/GHSA-fwm7-53g9-cmxr.json create mode 100644 advisories/unreviewed/2025/03/GHSA-gf54-mv55-8xgf/GHSA-gf54-mv55-8xgf.json create mode 100644 advisories/unreviewed/2025/03/GHSA-gjf5-5c3r-89f6/GHSA-gjf5-5c3r-89f6.json create mode 100644 advisories/unreviewed/2025/03/GHSA-gp57-h4hf-v8gp/GHSA-gp57-h4hf-v8gp.json create mode 100644 advisories/unreviewed/2025/03/GHSA-h5vx-hx75-xm9f/GHSA-h5vx-hx75-xm9f.json create mode 100644 advisories/unreviewed/2025/03/GHSA-hcxf-42cf-2vjf/GHSA-hcxf-42cf-2vjf.json create mode 100644 advisories/unreviewed/2025/03/GHSA-j4m5-qgpf-4c8g/GHSA-j4m5-qgpf-4c8g.json create mode 100644 advisories/unreviewed/2025/03/GHSA-jqg7-j926-j8mj/GHSA-jqg7-j926-j8mj.json create mode 100644 advisories/unreviewed/2025/03/GHSA-m27g-7h9f-wrhv/GHSA-m27g-7h9f-wrhv.json create mode 100644 advisories/unreviewed/2025/03/GHSA-m7qh-qcm5-xf88/GHSA-m7qh-qcm5-xf88.json create mode 100644 advisories/unreviewed/2025/03/GHSA-m7rg-5646-hfxm/GHSA-m7rg-5646-hfxm.json create mode 100644 advisories/unreviewed/2025/03/GHSA-mf6m-3qv8-qp4q/GHSA-mf6m-3qv8-qp4q.json create mode 100644 advisories/unreviewed/2025/03/GHSA-mg2f-6rj5-pr3w/GHSA-mg2f-6rj5-pr3w.json create mode 100644 advisories/unreviewed/2025/03/GHSA-mwxh-v66f-wcq5/GHSA-mwxh-v66f-wcq5.json create mode 100644 advisories/unreviewed/2025/03/GHSA-p53g-v548-5w7v/GHSA-p53g-v548-5w7v.json create mode 100644 advisories/unreviewed/2025/03/GHSA-ph9c-99wp-5w5f/GHSA-ph9c-99wp-5w5f.json create mode 100644 advisories/unreviewed/2025/03/GHSA-q62g-355r-cfg2/GHSA-q62g-355r-cfg2.json create mode 100644 advisories/unreviewed/2025/03/GHSA-qcqx-4h2x-x43j/GHSA-qcqx-4h2x-x43j.json create mode 100644 advisories/unreviewed/2025/03/GHSA-qh8m-89j4-42jf/GHSA-qh8m-89j4-42jf.json create mode 100644 advisories/unreviewed/2025/03/GHSA-qqcj-9cvv-63xg/GHSA-qqcj-9cvv-63xg.json create mode 100644 advisories/unreviewed/2025/03/GHSA-r4vm-xmvg-644h/GHSA-r4vm-xmvg-644h.json create mode 100644 advisories/unreviewed/2025/03/GHSA-rg2v-4c8w-w4r4/GHSA-rg2v-4c8w-w4r4.json create mode 100644 advisories/unreviewed/2025/03/GHSA-w2mf-wgp6-w934/GHSA-w2mf-wgp6-w934.json create mode 100644 advisories/unreviewed/2025/03/GHSA-w97p-2hwc-7qx6/GHSA-w97p-2hwc-7qx6.json create mode 100644 advisories/unreviewed/2025/03/GHSA-wc4q-pc87-7ch2/GHSA-wc4q-pc87-7ch2.json create mode 100644 advisories/unreviewed/2025/03/GHSA-xmvv-w44w-j8wx/GHSA-xmvv-w44w-j8wx.json diff --git a/advisories/unreviewed/2022/04/GHSA-3866-98fq-wg7f/GHSA-3866-98fq-wg7f.json b/advisories/unreviewed/2022/04/GHSA-3866-98fq-wg7f/GHSA-3866-98fq-wg7f.json index 3d6f4351f75..b23eda9ee0f 100644 --- a/advisories/unreviewed/2022/04/GHSA-3866-98fq-wg7f/GHSA-3866-98fq-wg7f.json +++ b/advisories/unreviewed/2022/04/GHSA-3866-98fq-wg7f/GHSA-3866-98fq-wg7f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3866-98fq-wg7f", - "modified": "2022-04-30T18:10:39Z", + "modified": "2025-03-17T15:31:34Z", "published": "2022-04-30T18:10:39Z", "aliases": [ "CVE-1999-0472" @@ -17,6 +17,10 @@ { "type": "WEB", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0472" + }, + { + "type": "WEB", + "url": "https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2017-240" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/04/GHSA-46xg-4hcp-2ppj/GHSA-46xg-4hcp-2ppj.json b/advisories/unreviewed/2022/04/GHSA-46xg-4hcp-2ppj/GHSA-46xg-4hcp-2ppj.json index 9bd57c90676..a17f13021c4 100644 --- a/advisories/unreviewed/2022/04/GHSA-46xg-4hcp-2ppj/GHSA-46xg-4hcp-2ppj.json +++ b/advisories/unreviewed/2022/04/GHSA-46xg-4hcp-2ppj/GHSA-46xg-4hcp-2ppj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-46xg-4hcp-2ppj", - "modified": "2022-04-30T18:09:57Z", + "modified": "2025-03-17T15:31:33Z", "published": "2022-04-30T18:09:57Z", "aliases": [ "CVE-1999-0103" @@ -17,6 +17,10 @@ { "type": "WEB", "url": "https://ics-cert.us-cert.gov/advisories/ICSMA-18-233-01" + }, + { + "type": "WEB", + "url": "http://www.securityfocus.com/bid/80171" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/04/GHSA-5mw4-cxpf-cxvj/GHSA-5mw4-cxpf-cxvj.json b/advisories/unreviewed/2022/04/GHSA-5mw4-cxpf-cxvj/GHSA-5mw4-cxpf-cxvj.json index 3c6772f836c..3ca85cb5a7d 100644 --- a/advisories/unreviewed/2022/04/GHSA-5mw4-cxpf-cxvj/GHSA-5mw4-cxpf-cxvj.json +++ b/advisories/unreviewed/2022/04/GHSA-5mw4-cxpf-cxvj/GHSA-5mw4-cxpf-cxvj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5mw4-cxpf-cxvj", - "modified": "2022-04-30T18:09:48Z", + "modified": "2025-03-17T15:31:34Z", "published": "2022-04-30T18:09:48Z", "aliases": [ "CVE-1999-0016" @@ -14,6 +14,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-1999-0016" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20170815-0001" + }, { "type": "WEB", "url": "http://www1.itrc.hp.com/service/cki/docDisplay.do?docId=HPSBUX9801-076" diff --git a/advisories/unreviewed/2022/04/GHSA-5qg4-5cpf-4r9p/GHSA-5qg4-5cpf-4r9p.json b/advisories/unreviewed/2022/04/GHSA-5qg4-5cpf-4r9p/GHSA-5qg4-5cpf-4r9p.json index be671d3a846..2c0dbacb75f 100644 --- a/advisories/unreviewed/2022/04/GHSA-5qg4-5cpf-4r9p/GHSA-5qg4-5cpf-4r9p.json +++ b/advisories/unreviewed/2022/04/GHSA-5qg4-5cpf-4r9p/GHSA-5qg4-5cpf-4r9p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5qg4-5cpf-4r9p", - "modified": "2022-04-30T18:10:45Z", + "modified": "2025-03-17T15:31:34Z", "published": "2022-04-30T18:10:45Z", "aliases": [ "CVE-1999-0524" @@ -26,6 +26,10 @@ "type": "WEB", "url": "https://kc.mcafee.com/corporate/index?page=content&id=SB10053" }, + { + "type": "WEB", + "url": "https://support.f5.com/csp/article/K15277" + }, { "type": "WEB", "url": "http://descriptions.securescout.com/tc/11010" diff --git a/advisories/unreviewed/2022/04/GHSA-926f-mjrv-g5m6/GHSA-926f-mjrv-g5m6.json b/advisories/unreviewed/2022/04/GHSA-926f-mjrv-g5m6/GHSA-926f-mjrv-g5m6.json index b494f99f6be..58bc543d481 100644 --- a/advisories/unreviewed/2022/04/GHSA-926f-mjrv-g5m6/GHSA-926f-mjrv-g5m6.json +++ b/advisories/unreviewed/2022/04/GHSA-926f-mjrv-g5m6/GHSA-926f-mjrv-g5m6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-926f-mjrv-g5m6", - "modified": "2022-04-30T18:10:45Z", + "modified": "2025-03-17T15:31:33Z", "published": "2022-04-30T18:10:45Z", "aliases": [ "CVE-1999-0532" @@ -17,6 +17,10 @@ { "type": "WEB", "url": "https://www.cve.org/CVERecord?id=CVE-1999-0532" + }, + { + "type": "WEB", + "url": "http://www.us-cert.gov/ncas/alerts/TA15-103A" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/04/GHSA-92cr-5v4q-xgj9/GHSA-92cr-5v4q-xgj9.json b/advisories/unreviewed/2022/04/GHSA-92cr-5v4q-xgj9/GHSA-92cr-5v4q-xgj9.json index 9a986e2e613..0eeabae60de 100644 --- a/advisories/unreviewed/2022/04/GHSA-92cr-5v4q-xgj9/GHSA-92cr-5v4q-xgj9.json +++ b/advisories/unreviewed/2022/04/GHSA-92cr-5v4q-xgj9/GHSA-92cr-5v4q-xgj9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-92cr-5v4q-xgj9", - "modified": "2022-04-30T18:10:06Z", + "modified": "2025-03-17T15:31:34Z", "published": "2022-04-30T18:10:06Z", "aliases": [ "CVE-1999-0186" @@ -14,6 +14,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-1999-0186" }, + { + "type": "WEB", + "url": "https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2017-238" + }, { "type": "WEB", "url": "http://support.novell.com/cgi-bin/search/searchtid.cgi?/10080762.htm" diff --git a/advisories/unreviewed/2022/04/GHSA-p4hh-f88r-4p2r/GHSA-p4hh-f88r-4p2r.json b/advisories/unreviewed/2022/04/GHSA-p4hh-f88r-4p2r/GHSA-p4hh-f88r-4p2r.json index 2d3ae5543c6..6110a996adf 100644 --- a/advisories/unreviewed/2022/04/GHSA-p4hh-f88r-4p2r/GHSA-p4hh-f88r-4p2r.json +++ b/advisories/unreviewed/2022/04/GHSA-p4hh-f88r-4p2r/GHSA-p4hh-f88r-4p2r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p4hh-f88r-4p2r", - "modified": "2022-04-30T18:10:17Z", + "modified": "2025-03-17T15:31:34Z", "published": "2022-04-30T18:10:17Z", "aliases": [ "CVE-1999-0254" @@ -17,6 +17,10 @@ { "type": "WEB", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0254" + }, + { + "type": "WEB", + "url": "https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2017-239" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/04/GHSA-p65v-7qg9-x6wf/GHSA-p65v-7qg9-x6wf.json b/advisories/unreviewed/2022/04/GHSA-p65v-7qg9-x6wf/GHSA-p65v-7qg9-x6wf.json index 1e2e8a436a8..16b168c54a9 100644 --- a/advisories/unreviewed/2022/04/GHSA-p65v-7qg9-x6wf/GHSA-p65v-7qg9-x6wf.json +++ b/advisories/unreviewed/2022/04/GHSA-p65v-7qg9-x6wf/GHSA-p65v-7qg9-x6wf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p65v-7qg9-x6wf", - "modified": "2022-04-30T18:10:44Z", + "modified": "2025-03-17T15:31:34Z", "published": "2022-04-30T18:10:44Z", "aliases": [ "CVE-1999-0516" @@ -17,6 +17,10 @@ { "type": "WEB", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0516" + }, + { + "type": "WEB", + "url": "https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2017-243" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/04/GHSA-wvmj-jgmg-4ghq/GHSA-wvmj-jgmg-4ghq.json b/advisories/unreviewed/2022/04/GHSA-wvmj-jgmg-4ghq/GHSA-wvmj-jgmg-4ghq.json index 94d22b928b1..9c239185723 100644 --- a/advisories/unreviewed/2022/04/GHSA-wvmj-jgmg-4ghq/GHSA-wvmj-jgmg-4ghq.json +++ b/advisories/unreviewed/2022/04/GHSA-wvmj-jgmg-4ghq/GHSA-wvmj-jgmg-4ghq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wvmj-jgmg-4ghq", - "modified": "2022-04-30T18:10:43Z", + "modified": "2025-03-17T15:31:33Z", "published": "2022-04-30T18:10:43Z", "aliases": [ "CVE-1999-0517" @@ -17,6 +17,10 @@ { "type": "WEB", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0517" + }, + { + "type": "WEB", + "url": "https://www.broadcom.com/support/fibre-channel-networking/security-advisories/brocade-security-advisory-2017-244" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/02/GHSA-wr66-4wc3-frfh/GHSA-wr66-4wc3-frfh.json b/advisories/unreviewed/2024/02/GHSA-wr66-4wc3-frfh/GHSA-wr66-4wc3-frfh.json index 4ae0dcde5d4..f6a862c9119 100644 --- a/advisories/unreviewed/2024/02/GHSA-wr66-4wc3-frfh/GHSA-wr66-4wc3-frfh.json +++ b/advisories/unreviewed/2024/02/GHSA-wr66-4wc3-frfh/GHSA-wr66-4wc3-frfh.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-511" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-25m9-3j97-v6cg/GHSA-25m9-3j97-v6cg.json b/advisories/unreviewed/2024/03/GHSA-25m9-3j97-v6cg/GHSA-25m9-3j97-v6cg.json index 91ce9e17947..5153bb7a0b2 100644 --- a/advisories/unreviewed/2024/03/GHSA-25m9-3j97-v6cg/GHSA-25m9-3j97-v6cg.json +++ b/advisories/unreviewed/2024/03/GHSA-25m9-3j97-v6cg/GHSA-25m9-3j97-v6cg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-25m9-3j97-v6cg", - "modified": "2024-11-04T15:31:53Z", + "modified": "2025-03-17T15:31:36Z", "published": "2024-03-26T18:32:06Z", "aliases": [ "CVE-2023-52622" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\next4: avoid online resizing failures due to oversized flex bg\n\nWhen we online resize an ext4 filesystem with a oversized flexbg_size,\n\n mkfs.ext4 -F -G 67108864 $dev -b 4096 100M\n mount $dev $dir\n resize2fs $dev 16G\n\nthe following WARN_ON is triggered:\n==================================================================\nWARNING: CPU: 0 PID: 427 at mm/page_alloc.c:4402 __alloc_pages+0x411/0x550\nModules linked in: sg(E)\nCPU: 0 PID: 427 Comm: resize2fs Tainted: G E 6.6.0-rc5+ #314\nRIP: 0010:__alloc_pages+0x411/0x550\nCall Trace:\n \n __kmalloc_large_node+0xa2/0x200\n __kmalloc+0x16e/0x290\n ext4_resize_fs+0x481/0xd80\n __ext4_ioctl+0x1616/0x1d90\n ext4_ioctl+0x12/0x20\n __x64_sys_ioctl+0xf0/0x150\n do_syscall_64+0x3b/0x90\n==================================================================\n\nThis is because flexbg_size is too large and the size of the new_group_data\narray to be allocated exceeds MAX_ORDER. Currently, the minimum value of\nMAX_ORDER is 8, the minimum value of PAGE_SIZE is 4096, the corresponding\nmaximum number of groups that can be allocated is:\n\n (PAGE_SIZE << MAX_ORDER) / sizeof(struct ext4_new_group_data) ≈ 21845\n\nAnd the value that is down-aligned to the power of 2 is 16384. Therefore,\nthis value is defined as MAX_RESIZE_BG, and the number of groups added\neach time does not exceed this value during resizing, and is added multiple\ntimes to complete the online resizing. The difference is that the metadata\nin a flex_bg may be more dispersed.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -56,8 +61,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-770" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-26T18:15:08Z" diff --git a/advisories/unreviewed/2024/03/GHSA-36f6-8vpp-3cqp/GHSA-36f6-8vpp-3cqp.json b/advisories/unreviewed/2024/03/GHSA-36f6-8vpp-3cqp/GHSA-36f6-8vpp-3cqp.json index 189ebb47825..fdb46e7c47b 100644 --- a/advisories/unreviewed/2024/03/GHSA-36f6-8vpp-3cqp/GHSA-36f6-8vpp-3cqp.json +++ b/advisories/unreviewed/2024/03/GHSA-36f6-8vpp-3cqp/GHSA-36f6-8vpp-3cqp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-36f6-8vpp-3cqp", - "modified": "2024-03-25T12:30:52Z", + "modified": "2025-03-17T15:31:35Z", "published": "2024-03-25T12:30:52Z", "aliases": [ "CVE-2021-47175" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: fq_pie: fix OOB access in the traffic path\n\nthe following script:\n\n # tc qdisc add dev eth0 handle 0x1 root fq_pie flows 2\n # tc qdisc add dev eth0 clsact\n # tc filter add dev eth0 egress matchall action skbedit priority 0x10002\n # ping 192.0.2.2 -I eth0 -c2 -w1 -q\n\nproduces the following splat:\n\n BUG: KASAN: slab-out-of-bounds in fq_pie_qdisc_enqueue+0x1314/0x19d0 [sch_fq_pie]\n Read of size 4 at addr ffff888171306924 by task ping/942\n\n CPU: 3 PID: 942 Comm: ping Not tainted 5.12.0+ #441\n Hardware name: Red Hat KVM, BIOS 1.11.1-4.module+el8.1.0+4066+0f1aadab 04/01/2014\n Call Trace:\n dump_stack+0x92/0xc1\n print_address_description.constprop.7+0x1a/0x150\n kasan_report.cold.13+0x7f/0x111\n fq_pie_qdisc_enqueue+0x1314/0x19d0 [sch_fq_pie]\n __dev_queue_xmit+0x1034/0x2b10\n ip_finish_output2+0xc62/0x2120\n __ip_finish_output+0x553/0xea0\n ip_output+0x1ca/0x4d0\n ip_send_skb+0x37/0xa0\n raw_sendmsg+0x1c4b/0x2d00\n sock_sendmsg+0xdb/0x110\n __sys_sendto+0x1d7/0x2b0\n __x64_sys_sendto+0xdd/0x1b0\n do_syscall_64+0x3c/0x80\n entry_SYSCALL_64_after_hwframe+0x44/0xae\n RIP: 0033:0x7fe69735c3eb\n Code: 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 f3 0f 1e fa 48 8d 05 75 42 2c 00 41 89 ca 8b 00 85 c0 75 14 b8 2c 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 75 c3 0f 1f 40 00 41 57 4d 89 c7 41 56 41 89\n RSP: 002b:00007fff06d7fb38 EFLAGS: 00000246 ORIG_RAX: 000000000000002c\n RAX: ffffffffffffffda RBX: 000055e961413700 RCX: 00007fe69735c3eb\n RDX: 0000000000000040 RSI: 000055e961413700 RDI: 0000000000000003\n RBP: 0000000000000040 R08: 000055e961410500 R09: 0000000000000010\n R10: 0000000000000000 R11: 0000000000000246 R12: 00007fff06d81260\n R13: 00007fff06d7fb40 R14: 00007fff06d7fc30 R15: 000055e96140f0a0\n\n Allocated by task 917:\n kasan_save_stack+0x19/0x40\n __kasan_kmalloc+0x7f/0xa0\n __kmalloc_node+0x139/0x280\n fq_pie_init+0x555/0x8e8 [sch_fq_pie]\n qdisc_create+0x407/0x11b0\n tc_modify_qdisc+0x3c2/0x17e0\n rtnetlink_rcv_msg+0x346/0x8e0\n netlink_rcv_skb+0x120/0x380\n netlink_unicast+0x439/0x630\n netlink_sendmsg+0x719/0xbf0\n sock_sendmsg+0xe2/0x110\n ____sys_sendmsg+0x5ba/0x890\n ___sys_sendmsg+0xe9/0x160\n __sys_sendmsg+0xd3/0x170\n do_syscall_64+0x3c/0x80\n entry_SYSCALL_64_after_hwframe+0x44/0xae\n\n The buggy address belongs to the object at ffff888171306800\n which belongs to the cache kmalloc-256 of size 256\n The buggy address is located 36 bytes to the right of\n 256-byte region [ffff888171306800, ffff888171306900)\n The buggy address belongs to the page:\n page:00000000bcfb624e refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x171306\n head:00000000bcfb624e order:1 compound_mapcount:0\n flags: 0x17ffffc0010200(slab|head|node=0|zone=2|lastcpupid=0x1fffff)\n raw: 0017ffffc0010200 dead000000000100 dead000000000122 ffff888100042b40\n raw: 0000000000000000 0000000000100010 00000001ffffffff 0000000000000000\n page dumped because: kasan: bad access detected\n\n Memory state around the buggy address:\n ffff888171306800: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\n ffff888171306880: 00 00 00 00 00 00 00 00 00 00 00 00 fc fc fc fc\n >ffff888171306900: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc\n ^\n ffff888171306980: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc\n ffff888171306a00: fa fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb\n\nfix fq_pie traffic path to avoid selecting 'q->flows + q->flows_cnt' as a\nvalid flow: it's an address beyond the allocated memory.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-25T10:15:09Z" diff --git a/advisories/unreviewed/2024/03/GHSA-3q2v-922f-6rc3/GHSA-3q2v-922f-6rc3.json b/advisories/unreviewed/2024/03/GHSA-3q2v-922f-6rc3/GHSA-3q2v-922f-6rc3.json index 390b7d247c8..3f80e801bb6 100644 --- a/advisories/unreviewed/2024/03/GHSA-3q2v-922f-6rc3/GHSA-3q2v-922f-6rc3.json +++ b/advisories/unreviewed/2024/03/GHSA-3q2v-922f-6rc3/GHSA-3q2v-922f-6rc3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3q2v-922f-6rc3", - "modified": "2024-03-25T12:30:52Z", + "modified": "2025-03-17T15:31:35Z", "published": "2024-03-25T12:30:52Z", "aliases": [ "CVE-2021-47177" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\niommu/vt-d: Fix sysfs leak in alloc_iommu()\n\niommu_device_sysfs_add() is called before, so is has to be cleaned on subsequent\nerrors.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-25T10:15:09Z" diff --git a/advisories/unreviewed/2024/03/GHSA-6r42-gm3x-9xx3/GHSA-6r42-gm3x-9xx3.json b/advisories/unreviewed/2024/03/GHSA-6r42-gm3x-9xx3/GHSA-6r42-gm3x-9xx3.json index 3f2f7def1fe..e05eac3e045 100644 --- a/advisories/unreviewed/2024/03/GHSA-6r42-gm3x-9xx3/GHSA-6r42-gm3x-9xx3.json +++ b/advisories/unreviewed/2024/03/GHSA-6r42-gm3x-9xx3/GHSA-6r42-gm3x-9xx3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6r42-gm3x-9xx3", - "modified": "2024-07-05T09:33:43Z", + "modified": "2025-03-17T15:31:37Z", "published": "2024-03-28T09:31:13Z", "aliases": [ "CVE-2023-52628" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nftables: exthdr: fix 4-byte stack OOB write\n\nIf priv->len is a multiple of 4, then dst[len / 4] can write past\nthe destination array which leads to stack corruption.\n\nThis construct is necessary to clean the remainder of the register\nin case ->len is NOT a multiple of the register size, so make it\nconditional just like nft_payload.c does.\n\nThe bug was added in 4.1 cycle and then copied/inherited when\ntcp/sctp and ip option support was added.\n\nBug reported by Zero Day Initiative project (ZDI-CAN-21950,\nZDI-CAN-21951, ZDI-CAN-21961).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-28T08:15:25Z" diff --git a/advisories/unreviewed/2024/03/GHSA-78r6-645f-335q/GHSA-78r6-645f-335q.json b/advisories/unreviewed/2024/03/GHSA-78r6-645f-335q/GHSA-78r6-645f-335q.json index b3284fb4ebd..4561deb1c0f 100644 --- a/advisories/unreviewed/2024/03/GHSA-78r6-645f-335q/GHSA-78r6-645f-335q.json +++ b/advisories/unreviewed/2024/03/GHSA-78r6-645f-335q/GHSA-78r6-645f-335q.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-78r6-645f-335q", - "modified": "2024-03-26T18:32:06Z", + "modified": "2025-03-17T15:31:36Z", "published": "2024-03-26T18:32:06Z", "aliases": [ "CVE-2023-52625" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Refactor DMCUB enter/exit idle interface\n\n[Why]\nWe can hang in place trying to send commands when the DMCUB isn't\npowered on.\n\n[How]\nWe need to exit out of the idle state prior to sending a command,\nbut the process that performs the exit also invokes a command itself.\n\nFixing this issue involves the following:\n\n1. Using a software state to track whether or not we need to start\n the process to exit idle or notify idle.\n\nIt's possible for the hardware to have exited an idle state without\ndriver knowledge, but entering one is always restricted to a driver\nallow - which makes the SW state vs HW state mismatch issue purely one\nof optimization, which should seldomly be hit, if at all.\n\n2. Refactor any instances of exit/notify idle to use a single wrapper\n that maintains this SW state.\n\nThis works simialr to dc_allow_idle_optimizations, but works at the\nDMCUB level and makes sure the state is marked prior to any notify/exit\nidle so we don't enter an infinite loop.\n\n3. Make sure we exit out of idle prior to sending any commands or\n waiting for DMCUB idle.\n\nThis patch takes care of 1/2. A future patch will take care of wrapping\nDMCUB command submission with calls to this new interface.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -25,7 +30,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-26T18:15:09Z" diff --git a/advisories/unreviewed/2024/03/GHSA-8229-hhm6-4mmc/GHSA-8229-hhm6-4mmc.json b/advisories/unreviewed/2024/03/GHSA-8229-hhm6-4mmc/GHSA-8229-hhm6-4mmc.json index 7fbd70de3eb..764ec284560 100644 --- a/advisories/unreviewed/2024/03/GHSA-8229-hhm6-4mmc/GHSA-8229-hhm6-4mmc.json +++ b/advisories/unreviewed/2024/03/GHSA-8229-hhm6-4mmc/GHSA-8229-hhm6-4mmc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8229-hhm6-4mmc", - "modified": "2024-03-25T12:30:52Z", + "modified": "2025-03-17T15:31:35Z", "published": "2024-03-25T12:30:52Z", "aliases": [ "CVE-2021-47168" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nNFS: fix an incorrect limit in filelayout_decode_layout()\n\nThe \"sizeof(struct nfs_fh)\" is two bytes too large and could lead to\nmemory corruption. It should be NFS_MAXFHSIZE because that's the size\nof the ->data[] buffer.\n\nI reversed the size of the arguments to put the variable on the left.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-25T10:15:08Z" diff --git a/advisories/unreviewed/2024/03/GHSA-8gg9-98mh-rcwr/GHSA-8gg9-98mh-rcwr.json b/advisories/unreviewed/2024/03/GHSA-8gg9-98mh-rcwr/GHSA-8gg9-98mh-rcwr.json index 23f36b35316..d9bec8cf6fa 100644 --- a/advisories/unreviewed/2024/03/GHSA-8gg9-98mh-rcwr/GHSA-8gg9-98mh-rcwr.json +++ b/advisories/unreviewed/2024/03/GHSA-8gg9-98mh-rcwr/GHSA-8gg9-98mh-rcwr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8gg9-98mh-rcwr", - "modified": "2024-03-25T12:30:52Z", + "modified": "2025-03-17T15:31:35Z", "published": "2024-03-25T12:30:52Z", "aliases": [ "CVE-2021-47176" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ns390/dasd: add missing discipline function\n\nFix crash with illegal operation exception in dasd_device_tasklet.\nCommit b72949328869 (\"s390/dasd: Prepare for additional path event handling\")\nrenamed the verify_path function for ECKD but not for FBA and DIAG.\nThis leads to a panic when the path verification function is called for a\nFBA or DIAG device.\n\nFix by defining a wrapper function for dasd_generic_verify_path().", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -33,7 +38,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-25T10:15:09Z" diff --git a/advisories/unreviewed/2024/03/GHSA-8qqh-mhqw-2cp3/GHSA-8qqh-mhqw-2cp3.json b/advisories/unreviewed/2024/03/GHSA-8qqh-mhqw-2cp3/GHSA-8qqh-mhqw-2cp3.json index 70185c4a720..d7d51da08a5 100644 --- a/advisories/unreviewed/2024/03/GHSA-8qqh-mhqw-2cp3/GHSA-8qqh-mhqw-2cp3.json +++ b/advisories/unreviewed/2024/03/GHSA-8qqh-mhqw-2cp3/GHSA-8qqh-mhqw-2cp3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8qqh-mhqw-2cp3", - "modified": "2024-03-26T18:32:06Z", + "modified": "2025-03-17T15:31:36Z", "published": "2024-03-26T18:32:06Z", "aliases": [ "CVE-2023-52624" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Wake DMCUB before executing GPINT commands\n\n[Why]\nDMCUB can be in idle when we attempt to interface with the HW through\nthe GPINT mailbox resulting in a system hang.\n\n[How]\nAdd dc_wake_and_execute_gpint() to wrap the wake, execute, sleep\nsequence.\n\nIf the GPINT executes successfully then DMCUB will be put back into\nsleep after the optional response is returned.\n\nIt functions similar to the inbox command interface.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-77" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-26T18:15:08Z" diff --git a/advisories/unreviewed/2024/03/GHSA-c673-578f-v4xm/GHSA-c673-578f-v4xm.json b/advisories/unreviewed/2024/03/GHSA-c673-578f-v4xm/GHSA-c673-578f-v4xm.json index a8bd3064062..3d07f8dbf85 100644 --- a/advisories/unreviewed/2024/03/GHSA-c673-578f-v4xm/GHSA-c673-578f-v4xm.json +++ b/advisories/unreviewed/2024/03/GHSA-c673-578f-v4xm/GHSA-c673-578f-v4xm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c673-578f-v4xm", - "modified": "2024-03-25T12:30:52Z", + "modified": "2025-03-17T15:31:35Z", "published": "2024-03-25T12:30:52Z", "aliases": [ "CVE-2021-47170" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: usbfs: Don't WARN about excessively large memory allocations\n\nSyzbot found that the kernel generates a WARNing if the user tries to\nsubmit a bulk transfer through usbfs with a buffer that is way too\nlarge. This isn't a bug in the kernel; it's merely an invalid request\nfrom the user and the usbfs code does handle it correctly.\n\nIn theory the same thing can happen with async transfers, or with the\npacket descriptor table for isochronous transfers.\n\nTo prevent the MM subsystem from complaining about these bad\nallocation requests, add the __GFP_NOWARN flag to the kmalloc calls\nfor these buffers.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-770" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-25T10:15:08Z" diff --git a/advisories/unreviewed/2024/03/GHSA-gqm5-q6hv-hp8w/GHSA-gqm5-q6hv-hp8w.json b/advisories/unreviewed/2024/03/GHSA-gqm5-q6hv-hp8w/GHSA-gqm5-q6hv-hp8w.json index 3940713f699..2826dd59c0d 100644 --- a/advisories/unreviewed/2024/03/GHSA-gqm5-q6hv-hp8w/GHSA-gqm5-q6hv-hp8w.json +++ b/advisories/unreviewed/2024/03/GHSA-gqm5-q6hv-hp8w/GHSA-gqm5-q6hv-hp8w.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gqm5-q6hv-hp8w", - "modified": "2024-03-25T12:30:52Z", + "modified": "2025-03-17T15:31:34Z", "published": "2024-03-25T12:30:52Z", "aliases": [ "CVE-2021-47166" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nNFS: Don't corrupt the value of pg_bytes_written in nfs_do_recoalesce()\n\nThe value of mirror->pg_bytes_written should only be updated after a\nsuccessful attempt to flush out the requests on the list.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-25T10:15:08Z" diff --git a/advisories/unreviewed/2024/03/GHSA-hwc8-wrmm-ch4w/GHSA-hwc8-wrmm-ch4w.json b/advisories/unreviewed/2024/03/GHSA-hwc8-wrmm-ch4w/GHSA-hwc8-wrmm-ch4w.json index dc029a67e99..015b4480e49 100644 --- a/advisories/unreviewed/2024/03/GHSA-hwc8-wrmm-ch4w/GHSA-hwc8-wrmm-ch4w.json +++ b/advisories/unreviewed/2024/03/GHSA-hwc8-wrmm-ch4w/GHSA-hwc8-wrmm-ch4w.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hwc8-wrmm-ch4w", - "modified": "2024-06-27T12:30:44Z", + "modified": "2025-03-17T15:31:36Z", "published": "2024-03-26T18:32:05Z", "aliases": [ "CVE-2024-26645" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: Ensure visibility when inserting an element into tracing_map\n\nRunning the following two commands in parallel on a multi-processor\nAArch64 machine can sporadically produce an unexpected warning about\nduplicate histogram entries:\n\n $ while true; do\n echo hist:key=id.syscall:val=hitcount > \\\n /sys/kernel/debug/tracing/events/raw_syscalls/sys_enter/trigger\n cat /sys/kernel/debug/tracing/events/raw_syscalls/sys_enter/hist\n sleep 0.001\n done\n $ stress-ng --sysbadaddr $(nproc)\n\nThe warning looks as follows:\n\n[ 2911.172474] ------------[ cut here ]------------\n[ 2911.173111] Duplicates detected: 1\n[ 2911.173574] WARNING: CPU: 2 PID: 12247 at kernel/trace/tracing_map.c:983 tracing_map_sort_entries+0x3e0/0x408\n[ 2911.174702] Modules linked in: iscsi_ibft(E) iscsi_boot_sysfs(E) rfkill(E) af_packet(E) nls_iso8859_1(E) nls_cp437(E) vfat(E) fat(E) ena(E) tiny_power_button(E) qemu_fw_cfg(E) button(E) fuse(E) efi_pstore(E) ip_tables(E) x_tables(E) xfs(E) libcrc32c(E) aes_ce_blk(E) aes_ce_cipher(E) crct10dif_ce(E) polyval_ce(E) polyval_generic(E) ghash_ce(E) gf128mul(E) sm4_ce_gcm(E) sm4_ce_ccm(E) sm4_ce(E) sm4_ce_cipher(E) sm4(E) sm3_ce(E) sm3(E) sha3_ce(E) sha512_ce(E) sha512_arm64(E) sha2_ce(E) sha256_arm64(E) nvme(E) sha1_ce(E) nvme_core(E) nvme_auth(E) t10_pi(E) sg(E) scsi_mod(E) scsi_common(E) efivarfs(E)\n[ 2911.174738] Unloaded tainted modules: cppc_cpufreq(E):1\n[ 2911.180985] CPU: 2 PID: 12247 Comm: cat Kdump: loaded Tainted: G E 6.7.0-default #2 1b58bbb22c97e4399dc09f92d309344f69c44a01\n[ 2911.182398] Hardware name: Amazon EC2 c7g.8xlarge/, BIOS 1.0 11/1/2018\n[ 2911.183208] pstate: 61400005 (nZCv daif +PAN -UAO -TCO +DIT -SSBS BTYPE=--)\n[ 2911.184038] pc : tracing_map_sort_entries+0x3e0/0x408\n[ 2911.184667] lr : tracing_map_sort_entries+0x3e0/0x408\n[ 2911.185310] sp : ffff8000a1513900\n[ 2911.185750] x29: ffff8000a1513900 x28: ffff0003f272fe80 x27: 0000000000000001\n[ 2911.186600] x26: ffff0003f272fe80 x25: 0000000000000030 x24: 0000000000000008\n[ 2911.187458] x23: ffff0003c5788000 x22: ffff0003c16710c8 x21: ffff80008017f180\n[ 2911.188310] x20: ffff80008017f000 x19: ffff80008017f180 x18: ffffffffffffffff\n[ 2911.189160] x17: 0000000000000000 x16: 0000000000000000 x15: ffff8000a15134b8\n[ 2911.190015] x14: 0000000000000000 x13: 205d373432323154 x12: 5b5d313131333731\n[ 2911.190844] x11: 00000000fffeffff x10: 00000000fffeffff x9 : ffffd1b78274a13c\n[ 2911.191716] x8 : 000000000017ffe8 x7 : c0000000fffeffff x6 : 000000000057ffa8\n[ 2911.192554] x5 : ffff0012f6c24ec0 x4 : 0000000000000000 x3 : ffff2e5b72b5d000\n[ 2911.193404] x2 : 0000000000000000 x1 : 0000000000000000 x0 : ffff0003ff254480\n[ 2911.194259] Call trace:\n[ 2911.194626] tracing_map_sort_entries+0x3e0/0x408\n[ 2911.195220] hist_show+0x124/0x800\n[ 2911.195692] seq_read_iter+0x1d4/0x4e8\n[ 2911.196193] seq_read+0xe8/0x138\n[ 2911.196638] vfs_read+0xc8/0x300\n[ 2911.197078] ksys_read+0x70/0x108\n[ 2911.197534] __arm64_sys_read+0x24/0x38\n[ 2911.198046] invoke_syscall+0x78/0x108\n[ 2911.198553] el0_svc_common.constprop.0+0xd0/0xf8\n[ 2911.199157] do_el0_svc+0x28/0x40\n[ 2911.199613] el0_svc+0x40/0x178\n[ 2911.200048] el0t_64_sync_handler+0x13c/0x158\n[ 2911.200621] el0t_64_sync+0x1a8/0x1b0\n[ 2911.201115] ---[ end trace 0000000000000000 ]---\n\nThe problem appears to be caused by CPU reordering of writes issued from\n__tracing_map_insert().\n\nThe check for the presence of an element with a given key in this\nfunction is:\n\n val = READ_ONCE(entry->val);\n if (val && keys_match(key, val->key, map->key_size)) ...\n\nThe write of a new entry is:\n\n elt = get_free_elt(map);\n memcpy(elt->key, key, map->key_size);\n entry->val = elt;\n\nThe \"memcpy(elt->key, key, map->key_size);\" and \"entry->val = elt;\"\nstores may become visible in the reversed order on another CPU. This\nsecond CPU might then incorrectly determine that a new key doesn't match\nan already present val->key and subse\n---truncated---", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -57,7 +62,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-26T16:15:12Z" diff --git a/advisories/unreviewed/2024/03/GHSA-p224-3949-7fhp/GHSA-p224-3949-7fhp.json b/advisories/unreviewed/2024/03/GHSA-p224-3949-7fhp/GHSA-p224-3949-7fhp.json index 8deb477c3b7..5139c705e04 100644 --- a/advisories/unreviewed/2024/03/GHSA-p224-3949-7fhp/GHSA-p224-3949-7fhp.json +++ b/advisories/unreviewed/2024/03/GHSA-p224-3949-7fhp/GHSA-p224-3949-7fhp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p224-3949-7fhp", - "modified": "2024-03-25T12:30:52Z", + "modified": "2025-03-17T15:31:35Z", "published": "2024-03-25T12:30:52Z", "aliases": [ "CVE-2021-47167" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nNFS: Fix an Oopsable condition in __nfs_pageio_add_request()\n\nEnsure that nfs_pageio_error_cleanup() resets the mirror array contents,\nso that the structure reflects the fact that it is now empty.\nAlso change the test in nfs_pageio_do_add_request() to be more robust by\nchecking whether or not the list is empty rather than relying on the\nvalue of pg_count.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -33,7 +38,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-25T10:15:08Z" diff --git a/advisories/unreviewed/2024/03/GHSA-p5xw-cvrw-p372/GHSA-p5xw-cvrw-p372.json b/advisories/unreviewed/2024/03/GHSA-p5xw-cvrw-p372/GHSA-p5xw-cvrw-p372.json index 920e7bf30bf..5252d0678b6 100644 --- a/advisories/unreviewed/2024/03/GHSA-p5xw-cvrw-p372/GHSA-p5xw-cvrw-p372.json +++ b/advisories/unreviewed/2024/03/GHSA-p5xw-cvrw-p372/GHSA-p5xw-cvrw-p372.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p5xw-cvrw-p372", - "modified": "2024-03-25T12:30:52Z", + "modified": "2025-03-17T15:31:35Z", "published": "2024-03-25T12:30:52Z", "aliases": [ "CVE-2021-47174" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_set_pipapo_avx2: Add irq_fpu_usable() check, fallback to non-AVX2 version\n\nArturo reported this backtrace:\n\n[709732.358791] WARNING: CPU: 3 PID: 456 at arch/x86/kernel/fpu/core.c:128 kernel_fpu_begin_mask+0xae/0xe0\n[709732.358793] Modules linked in: binfmt_misc nft_nat nft_chain_nat nf_nat nft_counter nft_ct nf_tables nf_conntrack_netlink nfnetlink 8021q garp stp mrp llc vrf intel_rapl_msr intel_rapl_common skx_edac nfit libnvdimm ipmi_ssif x86_pkg_temp_thermal intel_powerclamp coretemp crc32_pclmul mgag200 ghash_clmulni_intel drm_kms_helper cec aesni_intel drm libaes crypto_simd cryptd glue_helper mei_me dell_smbios iTCO_wdt evdev intel_pmc_bxt iTCO_vendor_support dcdbas pcspkr rapl dell_wmi_descriptor wmi_bmof sg i2c_algo_bit watchdog mei acpi_ipmi ipmi_si button nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 ipmi_devintf ipmi_msghandler ip_tables x_tables autofs4 ext4 crc16 mbcache jbd2 dm_mod raid10 raid456 async_raid6_recov async_memcpy async_pq async_xor async_tx xor sd_mod t10_pi crc_t10dif crct10dif_generic raid6_pq libcrc32c crc32c_generic raid1 raid0 multipath linear md_mod ahci libahci tg3 libata xhci_pci libphy xhci_hcd ptp usbcore crct10dif_pclmul crct10dif_common bnxt_en crc32c_intel scsi_mod\n[709732.358941] pps_core i2c_i801 lpc_ich i2c_smbus wmi usb_common\n[709732.358957] CPU: 3 PID: 456 Comm: jbd2/dm-0-8 Not tainted 5.10.0-0.bpo.5-amd64 #1 Debian 5.10.24-1~bpo10+1\n[709732.358959] Hardware name: Dell Inc. PowerEdge R440/04JN2K, BIOS 2.9.3 09/23/2020\n[709732.358964] RIP: 0010:kernel_fpu_begin_mask+0xae/0xe0\n[709732.358969] Code: ae 54 24 04 83 e3 01 75 38 48 8b 44 24 08 65 48 33 04 25 28 00 00 00 75 33 48 83 c4 10 5b c3 65 8a 05 5e 21 5e 76 84 c0 74 92 <0f> 0b eb 8e f0 80 4f 01 40 48 81 c7 00 14 00 00 e8 dd fb ff ff eb\n[709732.358972] RSP: 0018:ffffbb9700304740 EFLAGS: 00010202\n[709732.358976] RAX: 0000000000000001 RBX: 0000000000000003 RCX: 0000000000000001\n[709732.358979] RDX: ffffbb9700304970 RSI: ffff922fe1952e00 RDI: 0000000000000003\n[709732.358981] RBP: ffffbb9700304970 R08: ffff922fc868a600 R09: ffff922fc711e462\n[709732.358984] R10: 000000000000005f R11: ffff922ff0b27180 R12: ffffbb9700304960\n[709732.358987] R13: ffffbb9700304b08 R14: ffff922fc664b6c8 R15: ffff922fc664b660\n[709732.358990] FS: 0000000000000000(0000) GS:ffff92371fec0000(0000) knlGS:0000000000000000\n[709732.358993] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[709732.358996] CR2: 0000557a6655bdd0 CR3: 000000026020a001 CR4: 00000000007706e0\n[709732.358999] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n[709732.359001] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n[709732.359003] PKRU: 55555554\n[709732.359005] Call Trace:\n[709732.359009] \n[709732.359035] nft_pipapo_avx2_lookup+0x4c/0x1cba [nf_tables]\n[709732.359046] ? sched_clock+0x5/0x10\n[709732.359054] ? sched_clock_cpu+0xc/0xb0\n[709732.359061] ? record_times+0x16/0x80\n[709732.359068] ? plist_add+0xc1/0x100\n[709732.359073] ? psi_group_change+0x47/0x230\n[709732.359079] ? skb_clone+0x4d/0xb0\n[709732.359085] ? enqueue_task_rt+0x22b/0x310\n[709732.359098] ? bnxt_start_xmit+0x1e8/0xaf0 [bnxt_en]\n[709732.359102] ? packet_rcv+0x40/0x4a0\n[709732.359121] nft_lookup_eval+0x59/0x160 [nf_tables]\n[709732.359133] nft_do_chain+0x350/0x500 [nf_tables]\n[709732.359152] ? nft_lookup_eval+0x59/0x160 [nf_tables]\n[709732.359163] ? nft_do_chain+0x364/0x500 [nf_tables]\n[709732.359172] ? fib4_rule_action+0x6d/0x80\n[709732.359178] ? fib_rules_lookup+0x107/0x250\n[709732.359184] nft_nat_do_chain+0x8a/0xf2 [nft_chain_nat]\n[709732.359193] nf_nat_inet_fn+0xea/0x210 [nf_nat]\n[709732.359202] nf_nat_ipv4_out+0x14/0xa0 [nf_nat]\n[709732.359207] nf_hook_slow+0x44/0xc0\n[709732.359214] ip_output+0xd2/0x100\n[709732.359221] ? __ip_finish_output+0x210/0x210\n[709732.359226] ip_forward+0x37d/0x4a0\n[709732.359232] ? ip4_key_hashfn+0xb0/0xb0\n[709732.359238] ip_subli\n---truncated---", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -29,7 +34,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-25T10:15:09Z" diff --git a/advisories/unreviewed/2024/03/GHSA-pjqv-pvfh-2w6m/GHSA-pjqv-pvfh-2w6m.json b/advisories/unreviewed/2024/03/GHSA-pjqv-pvfh-2w6m/GHSA-pjqv-pvfh-2w6m.json index aafbcefd6d8..ca96bd1fbf7 100644 --- a/advisories/unreviewed/2024/03/GHSA-pjqv-pvfh-2w6m/GHSA-pjqv-pvfh-2w6m.json +++ b/advisories/unreviewed/2024/03/GHSA-pjqv-pvfh-2w6m/GHSA-pjqv-pvfh-2w6m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pjqv-pvfh-2w6m", - "modified": "2024-06-27T15:30:38Z", + "modified": "2025-03-17T15:31:37Z", "published": "2024-03-27T15:30:37Z", "aliases": [ "CVE-2024-26651" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsr9800: Add check for usbnet_get_endpoints\n\nAdd check for usbnet_get_endpoints() and return the error if it fails\nin order to transfer the error.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -69,7 +74,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-27T14:15:10Z" diff --git a/advisories/unreviewed/2024/03/GHSA-pmx2-4vwx-fc3h/GHSA-pmx2-4vwx-fc3h.json b/advisories/unreviewed/2024/03/GHSA-pmx2-4vwx-fc3h/GHSA-pmx2-4vwx-fc3h.json index e74843e3962..3905457f1fa 100644 --- a/advisories/unreviewed/2024/03/GHSA-pmx2-4vwx-fc3h/GHSA-pmx2-4vwx-fc3h.json +++ b/advisories/unreviewed/2024/03/GHSA-pmx2-4vwx-fc3h/GHSA-pmx2-4vwx-fc3h.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pmx2-4vwx-fc3h", - "modified": "2024-03-26T18:32:06Z", + "modified": "2025-03-17T15:31:36Z", "published": "2024-03-26T18:32:06Z", "aliases": [ "CVE-2023-52621" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Check rcu_read_lock_trace_held() before calling bpf map helpers\n\nThese three bpf_map_{lookup,update,delete}_elem() helpers are also\navailable for sleepable bpf program, so add the corresponding lock\nassertion for sleepable bpf program, otherwise the following warning\nwill be reported when a sleepable bpf program manipulates bpf map under\ninterpreter mode (aka bpf_jit_enable=0):\n\n WARNING: CPU: 3 PID: 4985 at kernel/bpf/helpers.c:40 ......\n CPU: 3 PID: 4985 Comm: test_progs Not tainted 6.6.0+ #2\n Hardware name: QEMU Standard PC (i440FX + PIIX, 1996) ......\n RIP: 0010:bpf_map_lookup_elem+0x54/0x60\n ......\n Call Trace:\n \n ? __warn+0xa5/0x240\n ? bpf_map_lookup_elem+0x54/0x60\n ? report_bug+0x1ba/0x1f0\n ? handle_bug+0x40/0x80\n ? exc_invalid_op+0x18/0x50\n ? asm_exc_invalid_op+0x1b/0x20\n ? __pfx_bpf_map_lookup_elem+0x10/0x10\n ? rcu_lockdep_current_cpu_online+0x65/0xb0\n ? rcu_is_watching+0x23/0x50\n ? bpf_map_lookup_elem+0x54/0x60\n ? __pfx_bpf_map_lookup_elem+0x10/0x10\n ___bpf_prog_run+0x513/0x3b70\n __bpf_prog_run32+0x9d/0xd0\n ? __bpf_prog_enter_sleepable_recur+0xad/0x120\n ? __bpf_prog_enter_sleepable_recur+0x3e/0x120\n bpf_trampoline_6442580665+0x4d/0x1000\n __x64_sys_getpgid+0x5/0x30\n ? do_syscall_64+0x36/0xb0\n entry_SYSCALL_64_after_hwframe+0x6e/0x76\n ", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-617" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-26T18:15:08Z" diff --git a/advisories/unreviewed/2024/03/GHSA-qggq-gw32-wcq3/GHSA-qggq-gw32-wcq3.json b/advisories/unreviewed/2024/03/GHSA-qggq-gw32-wcq3/GHSA-qggq-gw32-wcq3.json index ea2a666439c..8a58f36158e 100644 --- a/advisories/unreviewed/2024/03/GHSA-qggq-gw32-wcq3/GHSA-qggq-gw32-wcq3.json +++ b/advisories/unreviewed/2024/03/GHSA-qggq-gw32-wcq3/GHSA-qggq-gw32-wcq3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qggq-gw32-wcq3", - "modified": "2024-03-26T18:32:07Z", + "modified": "2025-03-17T15:31:36Z", "published": "2024-03-26T18:32:07Z", "aliases": [ "CVE-2023-52626" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: Fix operation precedence bug in port timestamping napi_poll context\n\nIndirection (*) is of lower precedence than postfix increment (++). Logic\nin napi_poll context would cause an out-of-bound read by first increment\nthe pointer address by byte address space and then dereference the value.\nRather, the intended logic was to dereference first and then increment the\nunderlying value.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-26T18:15:09Z" diff --git a/advisories/unreviewed/2024/03/GHSA-vmqf-grh3-9rrr/GHSA-vmqf-grh3-9rrr.json b/advisories/unreviewed/2024/03/GHSA-vmqf-grh3-9rrr/GHSA-vmqf-grh3-9rrr.json index 7d473d0077d..847c7625d6e 100644 --- a/advisories/unreviewed/2024/03/GHSA-vmqf-grh3-9rrr/GHSA-vmqf-grh3-9rrr.json +++ b/advisories/unreviewed/2024/03/GHSA-vmqf-grh3-9rrr/GHSA-vmqf-grh3-9rrr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vmqf-grh3-9rrr", - "modified": "2024-04-04T15:30:33Z", + "modified": "2025-03-17T15:31:36Z", "published": "2024-03-25T12:30:52Z", "aliases": [ "CVE-2021-47178" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: target: core: Avoid smp_processor_id() in preemptible code\n\nThe BUG message \"BUG: using smp_processor_id() in preemptible [00000000]\ncode\" was observed for TCMU devices with kernel config DEBUG_PREEMPT.\n\nThe message was observed when blktests block/005 was run on TCMU devices\nwith fileio backend or user:zbc backend [1]. The commit 1130b499b4a7\n(\"scsi: target: tcm_loop: Use LIO wq cmd submission helper\") triggered the\nsymptom. The commit modified work queue to handle commands and changed\n'current->nr_cpu_allowed' at smp_processor_id() call.\n\nThe message was also observed at system shutdown when TCMU devices were not\ncleaned up [2]. The function smp_processor_id() was called in SCSI host\nwork queue for abort handling, and triggered the BUG message. This symptom\nwas observed regardless of the commit 1130b499b4a7 (\"scsi: target:\ntcm_loop: Use LIO wq cmd submission helper\").\n\nTo avoid the preemptible code check at smp_processor_id(), get CPU ID with\nraw_smp_processor_id() instead. The CPU ID is used for performance\nimprovement then thread move to other CPU will not affect the code.\n\n[1]\n\n[ 56.468103] run blktests block/005 at 2021-05-12 14:16:38\n[ 57.369473] check_preemption_disabled: 85 callbacks suppressed\n[ 57.369480] BUG: using smp_processor_id() in preemptible [00000000] code: fio/1511\n[ 57.369506] BUG: using smp_processor_id() in preemptible [00000000] code: fio/1510\n[ 57.369512] BUG: using smp_processor_id() in preemptible [00000000] code: fio/1506\n[ 57.369552] caller is __target_init_cmd+0x157/0x170 [target_core_mod]\n[ 57.369606] CPU: 4 PID: 1506 Comm: fio Not tainted 5.13.0-rc1+ #34\n[ 57.369613] Hardware name: System manufacturer System Product Name/PRIME Z270-A, BIOS 1302 03/15/2018\n[ 57.369617] Call Trace:\n[ 57.369621] BUG: using smp_processor_id() in preemptible [00000000] code: fio/1507\n[ 57.369628] dump_stack+0x6d/0x89\n[ 57.369642] check_preemption_disabled+0xc8/0xd0\n[ 57.369628] caller is __target_init_cmd+0x157/0x170 [target_core_mod]\n[ 57.369655] __target_init_cmd+0x157/0x170 [target_core_mod]\n[ 57.369695] target_init_cmd+0x76/0x90 [target_core_mod]\n[ 57.369732] tcm_loop_queuecommand+0x109/0x210 [tcm_loop]\n[ 57.369744] scsi_queue_rq+0x38e/0xc40\n[ 57.369761] __blk_mq_try_issue_directly+0x109/0x1c0\n[ 57.369779] blk_mq_try_issue_directly+0x43/0x90\n[ 57.369790] blk_mq_submit_bio+0x4e5/0x5d0\n[ 57.369812] submit_bio_noacct+0x46e/0x4e0\n[ 57.369830] __blkdev_direct_IO_simple+0x1a3/0x2d0\n[ 57.369859] ? set_init_blocksize.isra.0+0x60/0x60\n[ 57.369880] generic_file_read_iter+0x89/0x160\n[ 57.369898] blkdev_read_iter+0x44/0x60\n[ 57.369906] new_sync_read+0x102/0x170\n[ 57.369929] vfs_read+0xd4/0x160\n[ 57.369941] __x64_sys_pread64+0x6e/0xa0\n[ 57.369946] ? lockdep_hardirqs_on+0x79/0x100\n[ 57.369958] do_syscall_64+0x3a/0x70\n[ 57.369965] entry_SYSCALL_64_after_hwframe+0x44/0xae\n[ 57.369973] RIP: 0033:0x7f7ed4c1399f\n[ 57.369979] Code: 08 89 3c 24 48 89 4c 24 18 e8 7d f3 ff ff 4c 8b 54 24 18 48 8b 54 24 10 41 89 c0 48 8b 74 24 08 8b 3c 24 b8 11 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 31 44 89 c7 48 89 04 24 e8 cd f3 ff ff 48 8b\n[ 57.369983] RSP: 002b:00007ffd7918c580 EFLAGS: 00000293 ORIG_RAX: 0000000000000011\n[ 57.369990] RAX: ffffffffffffffda RBX: 00000000015b4540 RCX: 00007f7ed4c1399f\n[ 57.369993] RDX: 0000000000001000 RSI: 00000000015de000 RDI: 0000000000000009\n[ 57.369996] RBP: 00000000015b4540 R08: 0000000000000000 R09: 0000000000000001\n[ 57.369999] R10: 0000000000e5c000 R11: 0000000000000293 R12: 00007f7eb5269a70\n[ 57.370002] R13: 0000000000000000 R14: 0000000000001000 R15: 00000000015b4568\n[ 57.370031] CPU: 7 PID: 1507 Comm: fio Not tainted 5.13.0-rc1+ #34\n[ 57.370036] Hardware name: System manufacturer System Product Name/PRIME Z270-A, BIOS 1302 03/15/2018\n[ 57.370039] Call Trace:\n[ 57.370045] dump_stack+0x6d/0x89\n[ 57.370056] ch\n---truncated---", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-459" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-25T10:15:09Z" diff --git a/advisories/unreviewed/2024/03/GHSA-wrwp-f8pq-q3qj/GHSA-wrwp-f8pq-q3qj.json b/advisories/unreviewed/2024/03/GHSA-wrwp-f8pq-q3qj/GHSA-wrwp-f8pq-q3qj.json index 906141a18bf..8d159304e5b 100644 --- a/advisories/unreviewed/2024/03/GHSA-wrwp-f8pq-q3qj/GHSA-wrwp-f8pq-q3qj.json +++ b/advisories/unreviewed/2024/03/GHSA-wrwp-f8pq-q3qj/GHSA-wrwp-f8pq-q3qj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wrwp-f8pq-q3qj", - "modified": "2024-03-26T18:32:07Z", + "modified": "2025-03-17T15:31:36Z", "published": "2024-03-26T18:32:07Z", "aliases": [ "CVE-2024-26646" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nthermal: intel: hfi: Add syscore callbacks for system-wide PM\n\nThe kernel allocates a memory buffer and provides its location to the\nhardware, which uses it to update the HFI table. This allocation occurs\nduring boot and remains constant throughout runtime.\n\nWhen resuming from hibernation, the restore kernel allocates a second\nmemory buffer and reprograms the HFI hardware with the new location as\npart of a normal boot. The location of the second memory buffer may\ndiffer from the one allocated by the image kernel.\n\nWhen the restore kernel transfers control to the image kernel, its HFI\nbuffer becomes invalid, potentially leading to memory corruption if the\nhardware writes to it (the hardware continues to use the buffer from the\nrestore kernel).\n\nIt is also possible that the hardware \"forgets\" the address of the memory\nbuffer when resuming from \"deep\" suspend. Memory corruption may also occur\nin such a scenario.\n\nTo prevent the described memory corruption, disable HFI when preparing to\nsuspend or hibernate. Enable it when resuming.\n\nAdd syscore callbacks to handle the package of the boot CPU (packages of\nnon-boot CPUs are handled via CPU offline). Syscore ops always run on the\nboot CPU. Additionally, HFI only needs to be disabled during \"deep\" suspend\nand hibernation. Syscore ops only run in these cases.\n\n[ rjw: Comment adjustment, subject and changelog edits ]", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-770" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-26T18:15:09Z" diff --git a/advisories/unreviewed/2024/03/GHSA-xr82-8hm6-h468/GHSA-xr82-8hm6-h468.json b/advisories/unreviewed/2024/03/GHSA-xr82-8hm6-h468/GHSA-xr82-8hm6-h468.json index 1708f2f75f0..2c08f3e9207 100644 --- a/advisories/unreviewed/2024/03/GHSA-xr82-8hm6-h468/GHSA-xr82-8hm6-h468.json +++ b/advisories/unreviewed/2024/03/GHSA-xr82-8hm6-h468/GHSA-xr82-8hm6-h468.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xr82-8hm6-h468", - "modified": "2024-06-26T00:31:35Z", + "modified": "2025-03-17T15:31:36Z", "published": "2024-03-26T18:32:05Z", "aliases": [ "CVE-2024-26644" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: don't abort filesystem when attempting to snapshot deleted subvolume\n\nIf the source file descriptor to the snapshot ioctl refers to a deleted\nsubvolume, we get the following abort:\n\n BTRFS: Transaction aborted (error -2)\n WARNING: CPU: 0 PID: 833 at fs/btrfs/transaction.c:1875 create_pending_snapshot+0x1040/0x1190 [btrfs]\n Modules linked in: pata_acpi btrfs ata_piix libata scsi_mod virtio_net blake2b_generic xor net_failover virtio_rng failover scsi_common rng_core raid6_pq libcrc32c\n CPU: 0 PID: 833 Comm: t_snapshot_dele Not tainted 6.7.0-rc6 #2\n Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-1.fc39 04/01/2014\n RIP: 0010:create_pending_snapshot+0x1040/0x1190 [btrfs]\n RSP: 0018:ffffa09c01337af8 EFLAGS: 00010282\n RAX: 0000000000000000 RBX: ffff9982053e7c78 RCX: 0000000000000027\n RDX: ffff99827dc20848 RSI: 0000000000000001 RDI: ffff99827dc20840\n RBP: ffffa09c01337c00 R08: 0000000000000000 R09: ffffa09c01337998\n R10: 0000000000000003 R11: ffffffffb96da248 R12: fffffffffffffffe\n R13: ffff99820535bb28 R14: ffff99820b7bd000 R15: ffff99820381ea80\n FS: 00007fe20aadabc0(0000) GS:ffff99827dc00000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 0000559a120b502f CR3: 00000000055b6000 CR4: 00000000000006f0\n Call Trace:\n \n ? create_pending_snapshot+0x1040/0x1190 [btrfs]\n ? __warn+0x81/0x130\n ? create_pending_snapshot+0x1040/0x1190 [btrfs]\n ? report_bug+0x171/0x1a0\n ? handle_bug+0x3a/0x70\n ? exc_invalid_op+0x17/0x70\n ? asm_exc_invalid_op+0x1a/0x20\n ? create_pending_snapshot+0x1040/0x1190 [btrfs]\n ? create_pending_snapshot+0x1040/0x1190 [btrfs]\n create_pending_snapshots+0x92/0xc0 [btrfs]\n btrfs_commit_transaction+0x66b/0xf40 [btrfs]\n btrfs_mksubvol+0x301/0x4d0 [btrfs]\n btrfs_mksnapshot+0x80/0xb0 [btrfs]\n __btrfs_ioctl_snap_create+0x1c2/0x1d0 [btrfs]\n btrfs_ioctl_snap_create_v2+0xc4/0x150 [btrfs]\n btrfs_ioctl+0x8a6/0x2650 [btrfs]\n ? kmem_cache_free+0x22/0x340\n ? do_sys_openat2+0x97/0xe0\n __x64_sys_ioctl+0x97/0xd0\n do_syscall_64+0x46/0xf0\n entry_SYSCALL_64_after_hwframe+0x6e/0x76\n RIP: 0033:0x7fe20abe83af\n RSP: 002b:00007ffe6eff1360 EFLAGS: 00000246 ORIG_RAX: 0000000000000010\n RAX: ffffffffffffffda RBX: 0000000000000004 RCX: 00007fe20abe83af\n RDX: 00007ffe6eff23c0 RSI: 0000000050009417 RDI: 0000000000000003\n RBP: 0000000000000003 R08: 0000000000000000 R09: 00007fe20ad16cd0\n R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000\n R13: 00007ffe6eff13c0 R14: 00007fe20ad45000 R15: 0000559a120b6d58\n \n ---[ end trace 0000000000000000 ]---\n BTRFS: error (device vdc: state A) in create_pending_snapshot:1875: errno=-2 No such entry\n BTRFS info (device vdc: state EA): forced readonly\n BTRFS warning (device vdc: state EA): Skipping commit of aborted transaction.\n BTRFS: error (device vdc: state EA) in cleanup_transaction:2055: errno=-2 No such entry\n\nThis happens because create_pending_snapshot() initializes the new root\nitem as a copy of the source root item. This includes the refs field,\nwhich is 0 for a deleted subvolume. The call to btrfs_insert_root()\ntherefore inserts a root with refs == 0. btrfs_get_new_fs_root() then\nfinds the root and returns -ENOENT if refs == 0, which causes\ncreate_pending_snapshot() to abort.\n\nFix it by checking the source root's refs before attempting the\nsnapshot, but after locking subvol_sem to avoid racing with deletion.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-908" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-26T16:15:12Z" diff --git a/advisories/unreviewed/2024/04/GHSA-2vjc-6f7c-9p77/GHSA-2vjc-6f7c-9p77.json b/advisories/unreviewed/2024/04/GHSA-2vjc-6f7c-9p77/GHSA-2vjc-6f7c-9p77.json index b3be4706733..743d6724744 100644 --- a/advisories/unreviewed/2024/04/GHSA-2vjc-6f7c-9p77/GHSA-2vjc-6f7c-9p77.json +++ b/advisories/unreviewed/2024/04/GHSA-2vjc-6f7c-9p77/GHSA-2vjc-6f7c-9p77.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-2wjh-rvr2-xxjw/GHSA-2wjh-rvr2-xxjw.json b/advisories/unreviewed/2024/04/GHSA-2wjh-rvr2-xxjw/GHSA-2wjh-rvr2-xxjw.json index b068e55dccf..715ca434994 100644 --- a/advisories/unreviewed/2024/04/GHSA-2wjh-rvr2-xxjw/GHSA-2wjh-rvr2-xxjw.json +++ b/advisories/unreviewed/2024/04/GHSA-2wjh-rvr2-xxjw/GHSA-2wjh-rvr2-xxjw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2wjh-rvr2-xxjw", - "modified": "2024-04-02T09:30:41Z", + "modified": "2025-03-17T15:31:38Z", "published": "2024-04-02T09:30:41Z", "aliases": [ "CVE-2024-26669" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: flower: Fix chain template offload\n\nWhen a qdisc is deleted from a net device the stack instructs the\nunderlying driver to remove its flow offload callback from the\nassociated filter block using the 'FLOW_BLOCK_UNBIND' command. The stack\nthen continues to replay the removal of the filters in the block for\nthis driver by iterating over the chains in the block and invoking the\n'reoffload' operation of the classifier being used. In turn, the\nclassifier in its 'reoffload' operation prepares and emits a\n'FLOW_CLS_DESTROY' command for each filter.\n\nHowever, the stack does not do the same for chain templates and the\nunderlying driver never receives a 'FLOW_CLS_TMPLT_DESTROY' command when\na qdisc is deleted. This results in a memory leak [1] which can be\nreproduced using [2].\n\nFix by introducing a 'tmplt_reoffload' operation and have the stack\ninvoke it with the appropriate arguments as part of the replay.\nImplement the operation in the sole classifier that supports chain\ntemplates (flower) by emitting the 'FLOW_CLS_TMPLT_{CREATE,DESTROY}'\ncommand based on whether a flow offload callback is being bound to a\nfilter block or being unbound from one.\n\nAs far as I can tell, the issue happens since cited commit which\nreordered tcf_block_offload_unbind() before tcf_block_flush_all_chains()\nin __tcf_block_put(). The order cannot be reversed as the filter block\nis expected to be freed after flushing all the chains.\n\n[1]\nunreferenced object 0xffff888107e28800 (size 2048):\n comm \"tc\", pid 1079, jiffies 4294958525 (age 3074.287s)\n hex dump (first 32 bytes):\n b1 a6 7c 11 81 88 ff ff e0 5b b3 10 81 88 ff ff ..|......[......\n 01 00 00 00 00 00 00 00 e0 aa b0 84 ff ff ff ff ................\n backtrace:\n [] __kmem_cache_alloc_node+0x1e8/0x320\n [] __kmalloc+0x4e/0x90\n [] mlxsw_sp_acl_ruleset_get+0x34d/0x7a0\n [] mlxsw_sp_flower_tmplt_create+0x145/0x180\n [] mlxsw_sp_flow_block_cb+0x1ea/0x280\n [] tc_setup_cb_call+0x183/0x340\n [] fl_tmplt_create+0x3da/0x4c0\n [] tc_ctl_chain+0xa15/0x1170\n [] rtnetlink_rcv_msg+0x3cc/0xed0\n [] netlink_rcv_skb+0x170/0x440\n [] netlink_unicast+0x540/0x820\n [] netlink_sendmsg+0x8d8/0xda0\n [] ____sys_sendmsg+0x30f/0xa80\n [] ___sys_sendmsg+0x13a/0x1e0\n [] __sys_sendmsg+0x11c/0x1f0\n [] do_syscall_64+0x40/0xe0\nunreferenced object 0xffff88816d2c0400 (size 1024):\n comm \"tc\", pid 1079, jiffies 4294958525 (age 3074.287s)\n hex dump (first 32 bytes):\n 40 00 00 00 00 00 00 00 57 f6 38 be 00 00 00 00 @.......W.8.....\n 10 04 2c 6d 81 88 ff ff 10 04 2c 6d 81 88 ff ff ..,m......,m....\n backtrace:\n [] __kmem_cache_alloc_node+0x1e8/0x320\n [] __kmalloc_node+0x51/0x90\n [] kvmalloc_node+0xa6/0x1f0\n [] bucket_table_alloc.isra.0+0x83/0x460\n [] rhashtable_init+0x43b/0x7c0\n [] mlxsw_sp_acl_ruleset_get+0x428/0x7a0\n [] mlxsw_sp_flower_tmplt_create+0x145/0x180\n [] mlxsw_sp_flow_block_cb+0x1ea/0x280\n [] tc_setup_cb_call+0x183/0x340\n [] fl_tmplt_create+0x3da/0x4c0\n [] tc_ctl_chain+0xa15/0x1170\n [] rtnetlink_rcv_msg+0x3cc/0xed0\n [] netlink_rcv_skb+0x170/0x440\n [] netlink_unicast+0x540/0x820\n [] netlink_sendmsg+0x8d8/0xda0\n [] ____sys_sendmsg+0x30f/0xa80\n\n[2]\n # tc qdisc add dev swp1 clsact\n # tc chain add dev swp1 ingress proto ip chain 1 flower dst_ip 0.0.0.0/32\n # tc qdisc del dev\n---truncated---", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-02T07:15:43Z" diff --git a/advisories/unreviewed/2024/04/GHSA-389h-6rjg-wxc9/GHSA-389h-6rjg-wxc9.json b/advisories/unreviewed/2024/04/GHSA-389h-6rjg-wxc9/GHSA-389h-6rjg-wxc9.json index 158b65f3dd5..369f03deed0 100644 --- a/advisories/unreviewed/2024/04/GHSA-389h-6rjg-wxc9/GHSA-389h-6rjg-wxc9.json +++ b/advisories/unreviewed/2024/04/GHSA-389h-6rjg-wxc9/GHSA-389h-6rjg-wxc9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-389h-6rjg-wxc9", - "modified": "2024-06-26T00:31:35Z", + "modified": "2025-03-17T15:31:38Z", "published": "2024-04-02T09:30:40Z", "aliases": [ "CVE-2024-26659" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nxhci: handle isoc Babble and Buffer Overrun events properly\n\nxHCI 4.9 explicitly forbids assuming that the xHC has released its\nownership of a multi-TRB TD when it reports an error on one of the\nearly TRBs. Yet the driver makes such assumption and releases the TD,\nallowing the remaining TRBs to be freed or overwritten by new TDs.\n\nThe xHC should also report completion of the final TRB due to its IOC\nflag being set by us, regardless of prior errors. This event cannot\nbe recognized if the TD has already been freed earlier, resulting in\n\"Transfer event TRB DMA ptr not part of current TD\" error message.\n\nFix this by reusing the logic for processing isoc Transaction Errors.\nThis also handles hosts which fail to report the final completion.\n\nFix transfer length reporting on Babble errors. They may be caused by\ndevice malfunction, no guarantee that the buffer has been filled.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-02T07:15:42Z" diff --git a/advisories/unreviewed/2024/04/GHSA-6246-6gx2-c2hw/GHSA-6246-6gx2-c2hw.json b/advisories/unreviewed/2024/04/GHSA-6246-6gx2-c2hw/GHSA-6246-6gx2-c2hw.json index 502f8f574ee..32ba6da9109 100644 --- a/advisories/unreviewed/2024/04/GHSA-6246-6gx2-c2hw/GHSA-6246-6gx2-c2hw.json +++ b/advisories/unreviewed/2024/04/GHSA-6246-6gx2-c2hw/GHSA-6246-6gx2-c2hw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6246-6gx2-c2hw", - "modified": "2024-04-02T09:30:40Z", + "modified": "2025-03-17T15:31:37Z", "published": "2024-04-02T09:30:40Z", "aliases": [ "CVE-2023-52632" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdkfd: Fix lock dependency warning with srcu\n\n======================================================\nWARNING: possible circular locking dependency detected\n6.5.0-kfd-yangp #2289 Not tainted\n------------------------------------------------------\nkworker/0:2/996 is trying to acquire lock:\n (srcu){.+.+}-{0:0}, at: __synchronize_srcu+0x5/0x1a0\n\nbut task is already holding lock:\n ((work_completion)(&svms->deferred_list_work)){+.+.}-{0:0}, at:\n\tprocess_one_work+0x211/0x560\n\nwhich lock already depends on the new lock.\n\nthe existing dependency chain (in reverse order) is:\n\n-> #3 ((work_completion)(&svms->deferred_list_work)){+.+.}-{0:0}:\n __flush_work+0x88/0x4f0\n svm_range_list_lock_and_flush_work+0x3d/0x110 [amdgpu]\n svm_range_set_attr+0xd6/0x14c0 [amdgpu]\n kfd_ioctl+0x1d1/0x630 [amdgpu]\n __x64_sys_ioctl+0x88/0xc0\n\n-> #2 (&info->lock#2){+.+.}-{3:3}:\n __mutex_lock+0x99/0xc70\n amdgpu_amdkfd_gpuvm_restore_process_bos+0x54/0x740 [amdgpu]\n restore_process_helper+0x22/0x80 [amdgpu]\n restore_process_worker+0x2d/0xa0 [amdgpu]\n process_one_work+0x29b/0x560\n worker_thread+0x3d/0x3d0\n\n-> #1 ((work_completion)(&(&process->restore_work)->work)){+.+.}-{0:0}:\n __flush_work+0x88/0x4f0\n __cancel_work_timer+0x12c/0x1c0\n kfd_process_notifier_release_internal+0x37/0x1f0 [amdgpu]\n __mmu_notifier_release+0xad/0x240\n exit_mmap+0x6a/0x3a0\n mmput+0x6a/0x120\n do_exit+0x322/0xb90\n do_group_exit+0x37/0xa0\n __x64_sys_exit_group+0x18/0x20\n do_syscall_64+0x38/0x80\n\n-> #0 (srcu){.+.+}-{0:0}:\n __lock_acquire+0x1521/0x2510\n lock_sync+0x5f/0x90\n __synchronize_srcu+0x4f/0x1a0\n __mmu_notifier_release+0x128/0x240\n exit_mmap+0x6a/0x3a0\n mmput+0x6a/0x120\n svm_range_deferred_list_work+0x19f/0x350 [amdgpu]\n process_one_work+0x29b/0x560\n worker_thread+0x3d/0x3d0\n\nother info that might help us debug this:\nChain exists of:\n srcu --> &info->lock#2 --> (work_completion)(&svms->deferred_list_work)\n\nPossible unsafe locking scenario:\n\n CPU0 CPU1\n ---- ----\n lock((work_completion)(&svms->deferred_list_work));\n lock(&info->lock#2);\n\t\t\tlock((work_completion)(&svms->deferred_list_work));\n sync(srcu);", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-667" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-02T07:15:41Z" diff --git a/advisories/unreviewed/2024/04/GHSA-7wpv-j3wh-7j6j/GHSA-7wpv-j3wh-7j6j.json b/advisories/unreviewed/2024/04/GHSA-7wpv-j3wh-7j6j/GHSA-7wpv-j3wh-7j6j.json index 20512f5407d..20277925b5e 100644 --- a/advisories/unreviewed/2024/04/GHSA-7wpv-j3wh-7j6j/GHSA-7wpv-j3wh-7j6j.json +++ b/advisories/unreviewed/2024/04/GHSA-7wpv-j3wh-7j6j/GHSA-7wpv-j3wh-7j6j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7wpv-j3wh-7j6j", - "modified": "2024-04-02T09:30:41Z", + "modified": "2025-03-17T15:31:38Z", "published": "2024-04-02T09:30:41Z", "aliases": [ "CVE-2024-26668" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_limit: reject configurations that cause integer overflow\n\nReject bogus configs where internal token counter wraps around.\nThis only occurs with very very large requests, such as 17gbyte/s.\n\nIts better to reject this rather than having incorrect ratelimit.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-190" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-02T07:15:43Z" diff --git a/advisories/unreviewed/2024/04/GHSA-c7h5-f667-cvc5/GHSA-c7h5-f667-cvc5.json b/advisories/unreviewed/2024/04/GHSA-c7h5-f667-cvc5/GHSA-c7h5-f667-cvc5.json index fc4597f3501..5a083a01d80 100644 --- a/advisories/unreviewed/2024/04/GHSA-c7h5-f667-cvc5/GHSA-c7h5-f667-cvc5.json +++ b/advisories/unreviewed/2024/04/GHSA-c7h5-f667-cvc5/GHSA-c7h5-f667-cvc5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c7h5-f667-cvc5", - "modified": "2024-04-02T09:30:40Z", + "modified": "2025-03-17T15:31:37Z", "published": "2024-04-02T09:30:40Z", "aliases": [ "CVE-2023-52633" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\num: time-travel: fix time corruption\n\nIn 'basic' time-travel mode (without =inf-cpu or =ext), we\nstill get timer interrupts. These can happen at arbitrary\npoints in time, i.e. while in timer_read(), which pushes\ntime forward just a little bit. Then, if we happen to get\nthe interrupt after calculating the new time to push to,\nbut before actually finishing that, the interrupt will set\nthe time to a value that's incompatible with the forward,\nand we'll crash because time goes backwards when we do the\nforwarding.\n\nFix this by reading the time_travel_time, calculating the\nadjustment, and doing the adjustment all with interrupts\ndisabled.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-02T07:15:41Z" diff --git a/advisories/unreviewed/2024/04/GHSA-cmxf-xmv7-xjq8/GHSA-cmxf-xmv7-xjq8.json b/advisories/unreviewed/2024/04/GHSA-cmxf-xmv7-xjq8/GHSA-cmxf-xmv7-xjq8.json index c5a75fec52c..0c802438bae 100644 --- a/advisories/unreviewed/2024/04/GHSA-cmxf-xmv7-xjq8/GHSA-cmxf-xmv7-xjq8.json +++ b/advisories/unreviewed/2024/04/GHSA-cmxf-xmv7-xjq8/GHSA-cmxf-xmv7-xjq8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cmxf-xmv7-xjq8", - "modified": "2024-04-03T15:30:41Z", + "modified": "2025-03-17T15:31:37Z", "published": "2024-04-02T09:30:40Z", "aliases": [ "CVE-2024-26656" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: fix use-after-free bug\n\nThe bug can be triggered by sending a single amdgpu_gem_userptr_ioctl\nto the AMDGPU DRM driver on any ASICs with an invalid address and size.\nThe bug was reported by Joonkyo Jung .\nFor example the following code:\n\nstatic void Syzkaller1(int fd)\n{\n\tstruct drm_amdgpu_gem_userptr arg;\n\tint ret;\n\n\targ.addr = 0xffffffffffff0000;\n\targ.size = 0x80000000; /*2 Gb*/\n\targ.flags = 0x7;\n\tret = drmIoctl(fd, 0xc1186451/*amdgpu_gem_userptr_ioctl*/, &arg);\n}\n\nDue to the address and size are not valid there is a failure in\namdgpu_hmm_register->mmu_interval_notifier_insert->__mmu_interval_notifier_insert->\ncheck_shl_overflow, but we even the amdgpu_hmm_register failure we still call\namdgpu_hmm_unregister into amdgpu_gem_object_free which causes access to a bad address.\nThe following stack is below when the issue is reproduced when Kazan is enabled:\n\n[ +0.000014] Hardware name: ASUS System Product Name/ROG STRIX B550-F GAMING (WI-FI), BIOS 1401 12/03/2020\n[ +0.000009] RIP: 0010:mmu_interval_notifier_remove+0x327/0x340\n[ +0.000017] Code: ff ff 49 89 44 24 08 48 b8 00 01 00 00 00 00 ad de 4c 89 f7 49 89 47 40 48 83 c0 22 49 89 47 48 e8 ce d1 2d 01 e9 32 ff ff ff <0f> 0b e9 16 ff ff ff 4c 89 ef e8 fa 14 b3 ff e9 36 ff ff ff e8 80\n[ +0.000014] RSP: 0018:ffffc90002657988 EFLAGS: 00010246\n[ +0.000013] RAX: 0000000000000000 RBX: 1ffff920004caf35 RCX: ffffffff8160565b\n[ +0.000011] RDX: dffffc0000000000 RSI: 0000000000000004 RDI: ffff8881a9f78260\n[ +0.000010] RBP: ffffc90002657a70 R08: 0000000000000001 R09: fffff520004caf25\n[ +0.000010] R10: 0000000000000003 R11: ffffffff8161d1d6 R12: ffff88810e988c00\n[ +0.000010] R13: ffff888126fb5a00 R14: ffff88810e988c0c R15: ffff8881a9f78260\n[ +0.000011] FS: 00007ff9ec848540(0000) GS:ffff8883cc880000(0000) knlGS:0000000000000000\n[ +0.000012] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ +0.000010] CR2: 000055b3f7e14328 CR3: 00000001b5770000 CR4: 0000000000350ef0\n[ +0.000010] Call Trace:\n[ +0.000006] \n[ +0.000007] ? show_regs+0x6a/0x80\n[ +0.000018] ? __warn+0xa5/0x1b0\n[ +0.000019] ? mmu_interval_notifier_remove+0x327/0x340\n[ +0.000018] ? report_bug+0x24a/0x290\n[ +0.000022] ? handle_bug+0x46/0x90\n[ +0.000015] ? exc_invalid_op+0x19/0x50\n[ +0.000016] ? asm_exc_invalid_op+0x1b/0x20\n[ +0.000017] ? kasan_save_stack+0x26/0x50\n[ +0.000017] ? mmu_interval_notifier_remove+0x23b/0x340\n[ +0.000019] ? mmu_interval_notifier_remove+0x327/0x340\n[ +0.000019] ? mmu_interval_notifier_remove+0x23b/0x340\n[ +0.000020] ? __pfx_mmu_interval_notifier_remove+0x10/0x10\n[ +0.000017] ? kasan_save_alloc_info+0x1e/0x30\n[ +0.000018] ? srso_return_thunk+0x5/0x5f\n[ +0.000014] ? __kasan_kmalloc+0xb1/0xc0\n[ +0.000018] ? srso_return_thunk+0x5/0x5f\n[ +0.000013] ? __kasan_check_read+0x11/0x20\n[ +0.000020] amdgpu_hmm_unregister+0x34/0x50 [amdgpu]\n[ +0.004695] amdgpu_gem_object_free+0x66/0xa0 [amdgpu]\n[ +0.004534] ? __pfx_amdgpu_gem_object_free+0x10/0x10 [amdgpu]\n[ +0.004291] ? do_syscall_64+0x5f/0xe0\n[ +0.000023] ? srso_return_thunk+0x5/0x5f\n[ +0.000017] drm_gem_object_free+0x3b/0x50 [drm]\n[ +0.000489] amdgpu_gem_userptr_ioctl+0x306/0x500 [amdgpu]\n[ +0.004295] ? __pfx_amdgpu_gem_userptr_ioctl+0x10/0x10 [amdgpu]\n[ +0.004270] ? srso_return_thunk+0x5/0x5f\n[ +0.000014] ? __this_cpu_preempt_check+0x13/0x20\n[ +0.000015] ? srso_return_thunk+0x5/0x5f\n[ +0.000013] ? sysvec_apic_timer_interrupt+0x57/0xc0\n[ +0.000020] ? srso_return_thunk+0x5/0x5f\n[ +0.000014] ? asm_sysvec_apic_timer_interrupt+0x1b/0x20\n[ +0.000022] ? drm_ioctl_kernel+0x17b/0x1f0 [drm]\n[ +0.000496] ? __pfx_amdgpu_gem_userptr_ioctl+0x10/0x10 [amdgpu]\n[ +0.004272] ? drm_ioctl_kernel+0x190/0x1f0 [drm]\n[ +0.000492] drm_ioctl_kernel+0x140/0x1f0 [drm]\n[ +0.000497] ? __pfx_amdgpu_gem_userptr_ioctl+0x10/0x10 [amdgpu]\n[ +0.004297] ? __pfx_drm_ioctl_kernel+0x10/0x10 [d\n---truncated---", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-02T07:15:42Z" diff --git a/advisories/unreviewed/2024/04/GHSA-f688-vq7p-p658/GHSA-f688-vq7p-p658.json b/advisories/unreviewed/2024/04/GHSA-f688-vq7p-p658/GHSA-f688-vq7p-p658.json index 20962ae0ff4..69ab83dc14b 100644 --- a/advisories/unreviewed/2024/04/GHSA-f688-vq7p-p658/GHSA-f688-vq7p-p658.json +++ b/advisories/unreviewed/2024/04/GHSA-f688-vq7p-p658/GHSA-f688-vq7p-p658.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-f688-vq7p-p658", - "modified": "2024-06-26T00:31:35Z", + "modified": "2025-03-17T15:31:37Z", "published": "2024-04-02T09:30:40Z", "aliases": [ "CVE-2023-52635" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nPM / devfreq: Synchronize devfreq_monitor_[start/stop]\n\nThere is a chance if a frequent switch of the governor\ndone in a loop result in timer list corruption where\ntimer cancel being done from two place one from\ncancel_delayed_work_sync() and followed by expire_timers()\ncan be seen from the traces[1].\n\nwhile true\ndo\n echo \"simple_ondemand\" > /sys/class/devfreq/1d84000.ufshc/governor\n echo \"performance\" > /sys/class/devfreq/1d84000.ufshc/governor\ndone\n\nIt looks to be issue with devfreq driver where\ndevice_monitor_[start/stop] need to synchronized so that\ndelayed work should get corrupted while it is either\nbeing queued or running or being cancelled.\n\nLet's use polling flag and devfreq lock to synchronize the\nqueueing the timer instance twice and work data being\ncorrupted.\n\n[1]\n...\n..\n-0 [003] 9436.209662: timer_cancel timer=0xffffff80444f0428\n-0 [003] 9436.209664: timer_expire_entry timer=0xffffff80444f0428 now=0x10022da1c function=__typeid__ZTSFvP10timer_listE_global_addr baseclk=0x10022da1c\n-0 [003] 9436.209718: timer_expire_exit timer=0xffffff80444f0428\nkworker/u16:6-14217 [003] 9436.209863: timer_start timer=0xffffff80444f0428 function=__typeid__ZTSFvP10timer_listE_global_addr expires=0x10022da2b now=0x10022da1c flags=182452227\nvendor.xxxyyy.ha-1593 [004] 9436.209888: timer_cancel timer=0xffffff80444f0428\nvendor.xxxyyy.ha-1593 [004] 9436.216390: timer_init timer=0xffffff80444f0428\nvendor.xxxyyy.ha-1593 [004] 9436.216392: timer_start timer=0xffffff80444f0428 function=__typeid__ZTSFvP10timer_listE_global_addr expires=0x10022da2c now=0x10022da1d flags=186646532\nvendor.xxxyyy.ha-1593 [005] 9436.220992: timer_cancel timer=0xffffff80444f0428\nxxxyyyTraceManag-7795 [004] 9436.261641: timer_cancel timer=0xffffff80444f0428\n\n[2]\n\n 9436.261653][ C4] Unable to handle kernel paging request at virtual address dead00000000012a\n[ 9436.261664][ C4] Mem abort info:\n[ 9436.261666][ C4] ESR = 0x96000044\n[ 9436.261669][ C4] EC = 0x25: DABT (current EL), IL = 32 bits\n[ 9436.261671][ C4] SET = 0, FnV = 0\n[ 9436.261673][ C4] EA = 0, S1PTW = 0\n[ 9436.261675][ C4] Data abort info:\n[ 9436.261677][ C4] ISV = 0, ISS = 0x00000044\n[ 9436.261680][ C4] CM = 0, WnR = 1\n[ 9436.261682][ C4] [dead00000000012a] address between user and kernel address ranges\n[ 9436.261685][ C4] Internal error: Oops: 96000044 [#1] PREEMPT SMP\n[ 9436.261701][ C4] Skip md ftrace buffer dump for: 0x3a982d0\n...\n\n[ 9436.262138][ C4] CPU: 4 PID: 7795 Comm: TraceManag Tainted: G S W O 5.10.149-android12-9-o-g17f915d29d0c #1\n[ 9436.262141][ C4] Hardware name: Qualcomm Technologies, Inc. (DT)\n[ 9436.262144][ C4] pstate: 22400085 (nzCv daIf +PAN -UAO +TCO BTYPE=--)\n[ 9436.262161][ C4] pc : expire_timers+0x9c/0x438\n[ 9436.262164][ C4] lr : expire_timers+0x2a4/0x438\n[ 9436.262168][ C4] sp : ffffffc010023dd0\n[ 9436.262171][ C4] x29: ffffffc010023df0 x28: ffffffd0636fdc18\n[ 9436.262178][ C4] x27: ffffffd063569dd0 x26: ffffffd063536008\n[ 9436.262182][ C4] x25: 0000000000000001 x24: ffffff88f7c69280\n[ 9436.262185][ C4] x23: 00000000000000e0 x22: dead000000000122\n[ 9436.262188][ C4] x21: 000000010022da29 x20: ffffff8af72b4e80\n[ 9436.262191][ C4] x19: ffffffc010023e50 x18: ffffffc010025038\n[ 9436.262195][ C4] x17: 0000000000000240 x16: 0000000000000201\n[ 9436.262199][ C4] x15: ffffffffffffffff x14: ffffff889f3c3100\n[ 9436.262203][ C4] x13: ffffff889f3c3100 x12: 00000000049f56b8\n[ 9436.262207][ C4] x11: 00000000049f56b8 x10: 00000000ffffffff\n[ 9436.262212][ C4] x9 : ffffffc010023e50 x8 : dead000000000122\n[ 9436.262216][ C4] x7 : ffffffffffffffff x6 : ffffffc0100239d8\n[ 9436.262220][ C4] x5 : 0000000000000000 x4 : 0000000000000101\n[ 9436.262223][ C4] x3 : 0000000000000080 x2 : ffffff8\n---truncated---", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-835" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-02T07:15:41Z" diff --git a/advisories/unreviewed/2024/04/GHSA-fqg2-664v-fx4j/GHSA-fqg2-664v-fx4j.json b/advisories/unreviewed/2024/04/GHSA-fqg2-664v-fx4j/GHSA-fqg2-664v-fx4j.json index c461424cc94..8306ab164da 100644 --- a/advisories/unreviewed/2024/04/GHSA-fqg2-664v-fx4j/GHSA-fqg2-664v-fx4j.json +++ b/advisories/unreviewed/2024/04/GHSA-fqg2-664v-fx4j/GHSA-fqg2-664v-fx4j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fqg2-664v-fx4j", - "modified": "2024-04-02T09:30:40Z", + "modified": "2025-03-17T15:31:37Z", "published": "2024-04-02T09:30:40Z", "aliases": [ "CVE-2023-52636" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: just wait for more data to be available on the socket\n\nA short read may occur while reading the message footer from the\nsocket. Later, when the socket is ready for another read, the\nmessenger invokes all read_partial_*() handlers, including\nread_partial_sparse_msg_data(). The expectation is that\nread_partial_sparse_msg_data() would bail, allowing the messenger to\ninvoke read_partial() for the footer and pick up where it left off.\n\nHowever read_partial_sparse_msg_data() violates that and ends up\ncalling into the state machine in the OSD client. The sparse-read\nstate machine assumes that it's a new op and interprets some piece of\nthe footer as the sparse-read header and returns bogus extents/data\nlength, etc.\n\nTo determine whether read_partial_sparse_msg_data() should bail, let's\nreuse cursor->total_resid. Because once it reaches to zero that means\nall the extents and data have been successfully received in last read,\nelse it could break out when partially reading any of the extents and\ndata. And then osd_sparse_read() could continue where it left off.\n\n[ idryomov: changelog ]", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -29,7 +34,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-02T07:15:41Z" diff --git a/advisories/unreviewed/2024/04/GHSA-g65w-rrjg-vx49/GHSA-g65w-rrjg-vx49.json b/advisories/unreviewed/2024/04/GHSA-g65w-rrjg-vx49/GHSA-g65w-rrjg-vx49.json index 33e60400254..e7425e76e5e 100644 --- a/advisories/unreviewed/2024/04/GHSA-g65w-rrjg-vx49/GHSA-g65w-rrjg-vx49.json +++ b/advisories/unreviewed/2024/04/GHSA-g65w-rrjg-vx49/GHSA-g65w-rrjg-vx49.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-g65w-rrjg-vx49", - "modified": "2024-06-27T12:30:44Z", + "modified": "2025-03-17T15:31:38Z", "published": "2024-04-02T09:30:41Z", "aliases": [ "CVE-2024-26664" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (coretemp) Fix out-of-bounds memory access\n\nFix a bug that pdata->cpu_map[] is set before out-of-bounds check.\nThe problem might be triggered on systems with more than 128 cores per\npackage.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -56,8 +61,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-02T07:15:43Z" diff --git a/advisories/unreviewed/2024/04/GHSA-gjgq-73mh-6p69/GHSA-gjgq-73mh-6p69.json b/advisories/unreviewed/2024/04/GHSA-gjgq-73mh-6p69/GHSA-gjgq-73mh-6p69.json index 480b2a18cac..34b3108ea1e 100644 --- a/advisories/unreviewed/2024/04/GHSA-gjgq-73mh-6p69/GHSA-gjgq-73mh-6p69.json +++ b/advisories/unreviewed/2024/04/GHSA-gjgq-73mh-6p69/GHSA-gjgq-73mh-6p69.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gjgq-73mh-6p69", - "modified": "2024-04-02T09:30:40Z", + "modified": "2025-03-17T15:31:37Z", "published": "2024-04-02T09:30:40Z", "aliases": [ "CVE-2023-52634" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Fix disable_otg_wa logic\n\n[Why]\nWhen switching to another HDMI mode, we are unnecesarilly\ndisabling/enabling FIFO causing both HPO and DIG registers to be set at\nthe same time when only HPO is supposed to be set.\n\nThis can lead to a system hang the next time we change refresh rates as\nthere are cases when we don't disable OTG/FIFO but FIFO is enabled when\nit isn't supposed to be.\n\n[How]\nRemoving the enable/disable FIFO entirely.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -25,7 +30,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-02T07:15:41Z" diff --git a/advisories/unreviewed/2024/04/GHSA-jp94-w382-qgwr/GHSA-jp94-w382-qgwr.json b/advisories/unreviewed/2024/04/GHSA-jp94-w382-qgwr/GHSA-jp94-w382-qgwr.json index 4fa2dff77f3..041ef6b1fa2 100644 --- a/advisories/unreviewed/2024/04/GHSA-jp94-w382-qgwr/GHSA-jp94-w382-qgwr.json +++ b/advisories/unreviewed/2024/04/GHSA-jp94-w382-qgwr/GHSA-jp94-w382-qgwr.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-pj2j-w9fr-j7p8/GHSA-pj2j-w9fr-j7p8.json b/advisories/unreviewed/2024/04/GHSA-pj2j-w9fr-j7p8/GHSA-pj2j-w9fr-j7p8.json index 935dcf2f4a5..5c7bbcbf378 100644 --- a/advisories/unreviewed/2024/04/GHSA-pj2j-w9fr-j7p8/GHSA-pj2j-w9fr-j7p8.json +++ b/advisories/unreviewed/2024/04/GHSA-pj2j-w9fr-j7p8/GHSA-pj2j-w9fr-j7p8.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-250" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-qjvp-25fj-gf6v/GHSA-qjvp-25fj-gf6v.json b/advisories/unreviewed/2024/04/GHSA-qjvp-25fj-gf6v/GHSA-qjvp-25fj-gf6v.json index d62112f561c..047542768a0 100644 --- a/advisories/unreviewed/2024/04/GHSA-qjvp-25fj-gf6v/GHSA-qjvp-25fj-gf6v.json +++ b/advisories/unreviewed/2024/04/GHSA-qjvp-25fj-gf6v/GHSA-qjvp-25fj-gf6v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qjvp-25fj-gf6v", - "modified": "2024-06-27T15:30:38Z", + "modified": "2025-03-17T15:31:38Z", "published": "2024-04-02T09:30:41Z", "aliases": [ "CVE-2024-26671" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nblk-mq: fix IO hang from sbitmap wakeup race\n\nIn blk_mq_mark_tag_wait(), __add_wait_queue() may be re-ordered\nwith the following blk_mq_get_driver_tag() in case of getting driver\ntag failure.\n\nThen in __sbitmap_queue_wake_up(), waitqueue_active() may not observe\nthe added waiter in blk_mq_mark_tag_wait() and wake up nothing, meantime\nblk_mq_mark_tag_wait() can't get driver tag successfully.\n\nThis issue can be reproduced by running the following test in loop, and\nfio hang can be observed in < 30min when running it on my test VM\nin laptop.\n\n\tmodprobe -r scsi_debug\n\tmodprobe scsi_debug delay=0 dev_size_mb=4096 max_queue=1 host_max_queue=1 submit_queues=4\n\tdev=`ls -d /sys/bus/pseudo/drivers/scsi_debug/adapter*/host*/target*/*/block/* | head -1 | xargs basename`\n\tfio --filename=/dev/\"$dev\" --direct=1 --rw=randrw --bs=4k --iodepth=1 \\\n \t\t--runtime=100 --numjobs=40 --time_based --name=test \\\n \t--ioengine=libaio\n\nFix the issue by adding one explicit barrier in blk_mq_mark_tag_wait(), which\nis just fine in case of running out of tag.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -56,8 +61,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-362" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-02T07:15:43Z" diff --git a/advisories/unreviewed/2024/04/GHSA-vpp3-8c88-m6w7/GHSA-vpp3-8c88-m6w7.json b/advisories/unreviewed/2024/04/GHSA-vpp3-8c88-m6w7/GHSA-vpp3-8c88-m6w7.json index 3cb5ae86a25..cad6c2dfbf5 100644 --- a/advisories/unreviewed/2024/04/GHSA-vpp3-8c88-m6w7/GHSA-vpp3-8c88-m6w7.json +++ b/advisories/unreviewed/2024/04/GHSA-vpp3-8c88-m6w7/GHSA-vpp3-8c88-m6w7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vpp3-8c88-m6w7", - "modified": "2024-04-02T09:30:41Z", + "modified": "2025-03-17T15:31:38Z", "published": "2024-04-02T09:30:41Z", "aliases": [ "CVE-2024-26670" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\narm64: entry: fix ARM64_WORKAROUND_SPECULATIVE_UNPRIV_LOAD\n\nCurrently the ARM64_WORKAROUND_SPECULATIVE_UNPRIV_LOAD workaround isn't\nquite right, as it is supposed to be applied after the last explicit\nmemory access, but is immediately followed by an LDR.\n\nThe ARM64_WORKAROUND_SPECULATIVE_UNPRIV_LOAD workaround is used to\nhandle Cortex-A520 erratum 2966298 and Cortex-A510 erratum 3117295,\nwhich are described in:\n\n* https://developer.arm.com/documentation/SDEN2444153/0600/?lang=en\n* https://developer.arm.com/documentation/SDEN1873361/1600/?lang=en\n\nIn both cases the workaround is described as:\n\n| If pagetable isolation is disabled, the context switch logic in the\n| kernel can be updated to execute the following sequence on affected\n| cores before exiting to EL0, and after all explicit memory accesses:\n|\n| 1. A non-shareable TLBI to any context and/or address, including\n| unused contexts or addresses, such as a `TLBI VALE1 Xzr`.\n|\n| 2. A DSB NSH to guarantee completion of the TLBI.\n\nThe important part being that the TLBI+DSB must be placed \"after all\nexplicit memory accesses\".\n\nUnfortunately, as-implemented, the TLBI+DSB is immediately followed by\nan LDR, as we have:\n\n| alternative_if ARM64_WORKAROUND_SPECULATIVE_UNPRIV_LOAD\n| \ttlbi\tvale1, xzr\n| \tdsb\tnsh\n| alternative_else_nop_endif\n| alternative_if_not ARM64_UNMAP_KERNEL_AT_EL0\n| \tldr\tlr, [sp, #S_LR]\n| \tadd\tsp, sp, #PT_REGS_SIZE\t\t// restore sp\n| \teret\n| alternative_else_nop_endif\n|\n| [ ... KPTI exception return path ... ]\n\nThis patch fixes this by reworking the logic to place the TLBI+DSB\nimmediately before the ERET, after all explicit memory accesses.\n\nThe ERET is currently in a separate alternative block, and alternatives\ncannot be nested. To account for this, the alternative block for\nARM64_UNMAP_KERNEL_AT_EL0 is replaced with a single alternative branch\nto skip the KPTI logic, with the new shape of the logic being:\n\n| alternative_insn \"b .L_skip_tramp_exit_\\@\", nop, ARM64_UNMAP_KERNEL_AT_EL0\n| \t[ ... KPTI exception return path ... ]\n| .L_skip_tramp_exit_\\@:\n|\n| \tldr\tlr, [sp, #S_LR]\n| \tadd\tsp, sp, #PT_REGS_SIZE\t\t// restore sp\n|\n| alternative_if ARM64_WORKAROUND_SPECULATIVE_UNPRIV_LOAD\n| \ttlbi\tvale1, xzr\n| \tdsb\tnsh\n| alternative_else_nop_endif\n| \teret\n\nThe new structure means that the workaround is only applied when KPTI is\nnot in use; this is fine as noted in the documented implications of the\nerratum:\n\n| Pagetable isolation between EL0 and higher level ELs prevents the\n| issue from occurring.\n\n... and as per the workaround description quoted above, the workaround\nis only necessary \"If pagetable isolation is disabled\".", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-02T07:15:43Z" diff --git a/advisories/unreviewed/2024/04/GHSA-wggj-8rcc-246r/GHSA-wggj-8rcc-246r.json b/advisories/unreviewed/2024/04/GHSA-wggj-8rcc-246r/GHSA-wggj-8rcc-246r.json index 6681d51e534..8816f991c0a 100644 --- a/advisories/unreviewed/2024/04/GHSA-wggj-8rcc-246r/GHSA-wggj-8rcc-246r.json +++ b/advisories/unreviewed/2024/04/GHSA-wggj-8rcc-246r/GHSA-wggj-8rcc-246r.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wggj-8rcc-246r", - "modified": "2024-04-02T09:30:41Z", + "modified": "2025-03-17T15:31:38Z", "published": "2024-04-02T09:30:41Z", "aliases": [ "CVE-2024-26667" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/msm/dpu: check for valid hw_pp in dpu_encoder_helper_phys_cleanup\n\nThe commit 8b45a26f2ba9 (\"drm/msm/dpu: reserve cdm blocks for writeback\nin case of YUV output\") introduced a smatch warning about another\nconditional block in dpu_encoder_helper_phys_cleanup() which had assumed\nhw_pp will always be valid which may not necessarily be true.\n\nLets fix the other conditional block by making sure hw_pp is valid\nbefore dereferencing it.\n\nPatchwork: https://patchwork.freedesktop.org/patch/574878/", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-459" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-02T07:15:43Z" diff --git a/advisories/unreviewed/2024/06/GHSA-j24x-6m7r-h4gp/GHSA-j24x-6m7r-h4gp.json b/advisories/unreviewed/2024/06/GHSA-j24x-6m7r-h4gp/GHSA-j24x-6m7r-h4gp.json index 2e18dbf82b3..7142259fceb 100644 --- a/advisories/unreviewed/2024/06/GHSA-j24x-6m7r-h4gp/GHSA-j24x-6m7r-h4gp.json +++ b/advisories/unreviewed/2024/06/GHSA-j24x-6m7r-h4gp/GHSA-j24x-6m7r-h4gp.json @@ -53,7 +53,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-j6h8-65gx-v495/GHSA-j6h8-65gx-v495.json b/advisories/unreviewed/2024/06/GHSA-j6h8-65gx-v495/GHSA-j6h8-65gx-v495.json index eae6f43dbd4..bfb740a1f34 100644 --- a/advisories/unreviewed/2024/06/GHSA-j6h8-65gx-v495/GHSA-j6h8-65gx-v495.json +++ b/advisories/unreviewed/2024/06/GHSA-j6h8-65gx-v495/GHSA-j6h8-65gx-v495.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-w2wv-53w9-5r3r/GHSA-w2wv-53w9-5r3r.json b/advisories/unreviewed/2024/07/GHSA-w2wv-53w9-5r3r/GHSA-w2wv-53w9-5r3r.json index 4e3864c9b3d..e55d1f31a20 100644 --- a/advisories/unreviewed/2024/07/GHSA-w2wv-53w9-5r3r/GHSA-w2wv-53w9-5r3r.json +++ b/advisories/unreviewed/2024/07/GHSA-w2wv-53w9-5r3r/GHSA-w2wv-53w9-5r3r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w2wv-53w9-5r3r", - "modified": "2024-08-02T21:31:33Z", + "modified": "2025-03-17T15:31:42Z", "published": "2024-07-03T18:48:30Z", "aliases": [ "CVE-2024-29508" @@ -27,13 +27,19 @@ "type": "WEB", "url": "https://git.ghostscript.com/?p=ghostpdl.git%3Bh=ff1013a0ab485b66783b70145e342a82c670906a" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/10/msg00022.html" + }, { "type": "WEB", "url": "https://www.openwall.com/lists/oss-security/2024/07/03/7" } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-122" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/09/GHSA-xh89-f5vr-hmhw/GHSA-xh89-f5vr-hmhw.json b/advisories/unreviewed/2024/09/GHSA-xh89-f5vr-hmhw/GHSA-xh89-f5vr-hmhw.json index 28a4222ad94..31331c5649f 100644 --- a/advisories/unreviewed/2024/09/GHSA-xh89-f5vr-hmhw/GHSA-xh89-f5vr-hmhw.json +++ b/advisories/unreviewed/2024/09/GHSA-xh89-f5vr-hmhw/GHSA-xh89-f5vr-hmhw.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-120" + "CWE-120", + "CWE-787" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-4q9j-5567-rg22/GHSA-4q9j-5567-rg22.json b/advisories/unreviewed/2025/01/GHSA-4q9j-5567-rg22/GHSA-4q9j-5567-rg22.json index 0c876fc4e42..610b85c7d60 100644 --- a/advisories/unreviewed/2025/01/GHSA-4q9j-5567-rg22/GHSA-4q9j-5567-rg22.json +++ b/advisories/unreviewed/2025/01/GHSA-4q9j-5567-rg22/GHSA-4q9j-5567-rg22.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-120" + "CWE-120", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-7w8f-hj5m-33r5/GHSA-7w8f-hj5m-33r5.json b/advisories/unreviewed/2025/01/GHSA-7w8f-hj5m-33r5/GHSA-7w8f-hj5m-33r5.json index 1cacd2e8822..ebb9bd06233 100644 --- a/advisories/unreviewed/2025/01/GHSA-7w8f-hj5m-33r5/GHSA-7w8f-hj5m-33r5.json +++ b/advisories/unreviewed/2025/01/GHSA-7w8f-hj5m-33r5/GHSA-7w8f-hj5m-33r5.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-120" + "CWE-120", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-w897-r9c3-5chp/GHSA-w897-r9c3-5chp.json b/advisories/unreviewed/2025/01/GHSA-w897-r9c3-5chp/GHSA-w897-r9c3-5chp.json index e5df43e62d4..31eb93a65ab 100644 --- a/advisories/unreviewed/2025/01/GHSA-w897-r9c3-5chp/GHSA-w897-r9c3-5chp.json +++ b/advisories/unreviewed/2025/01/GHSA-w897-r9c3-5chp/GHSA-w897-r9c3-5chp.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-120" + "CWE-120", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/02/GHSA-2hhx-vp2f-m5hf/GHSA-2hhx-vp2f-m5hf.json b/advisories/unreviewed/2025/02/GHSA-2hhx-vp2f-m5hf/GHSA-2hhx-vp2f-m5hf.json index 2d4e64ac83e..1dc61182329 100644 --- a/advisories/unreviewed/2025/02/GHSA-2hhx-vp2f-m5hf/GHSA-2hhx-vp2f-m5hf.json +++ b/advisories/unreviewed/2025/02/GHSA-2hhx-vp2f-m5hf/GHSA-2hhx-vp2f-m5hf.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-120" + "CWE-120", + "CWE-787" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/02/GHSA-c649-279m-q7qv/GHSA-c649-279m-q7qv.json b/advisories/unreviewed/2025/02/GHSA-c649-279m-q7qv/GHSA-c649-279m-q7qv.json index a6e1f866cbd..877313c5fcf 100644 --- a/advisories/unreviewed/2025/02/GHSA-c649-279m-q7qv/GHSA-c649-279m-q7qv.json +++ b/advisories/unreviewed/2025/02/GHSA-c649-279m-q7qv/GHSA-c649-279m-q7qv.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-120" + "CWE-120", + "CWE-787" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/02/GHSA-hmf6-8vmc-33g5/GHSA-hmf6-8vmc-33g5.json b/advisories/unreviewed/2025/02/GHSA-hmf6-8vmc-33g5/GHSA-hmf6-8vmc-33g5.json index 6ce59cac1d3..72d2dc2521d 100644 --- a/advisories/unreviewed/2025/02/GHSA-hmf6-8vmc-33g5/GHSA-hmf6-8vmc-33g5.json +++ b/advisories/unreviewed/2025/02/GHSA-hmf6-8vmc-33g5/GHSA-hmf6-8vmc-33g5.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-532", "CWE-657" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2025/02/GHSA-v37g-gf72-65f5/GHSA-v37g-gf72-65f5.json b/advisories/unreviewed/2025/02/GHSA-v37g-gf72-65f5/GHSA-v37g-gf72-65f5.json index 16ebf86091c..c98bda64b71 100644 --- a/advisories/unreviewed/2025/02/GHSA-v37g-gf72-65f5/GHSA-v37g-gf72-65f5.json +++ b/advisories/unreviewed/2025/02/GHSA-v37g-gf72-65f5/GHSA-v37g-gf72-65f5.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-680" ], "severity": "LOW", diff --git a/advisories/unreviewed/2025/02/GHSA-xjq3-p9vw-4qrf/GHSA-xjq3-p9vw-4qrf.json b/advisories/unreviewed/2025/02/GHSA-xjq3-p9vw-4qrf/GHSA-xjq3-p9vw-4qrf.json index 5bb1de1d01d..064a9462553 100644 --- a/advisories/unreviewed/2025/02/GHSA-xjq3-p9vw-4qrf/GHSA-xjq3-p9vw-4qrf.json +++ b/advisories/unreviewed/2025/02/GHSA-xjq3-p9vw-4qrf/GHSA-xjq3-p9vw-4qrf.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-77", "CWE-94" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2025/03/GHSA-25cf-wq2p-gqxf/GHSA-25cf-wq2p-gqxf.json b/advisories/unreviewed/2025/03/GHSA-25cf-wq2p-gqxf/GHSA-25cf-wq2p-gqxf.json new file mode 100644 index 00000000000..70293c56f1e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-25cf-wq2p-gqxf/GHSA-25cf-wq2p-gqxf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-25cf-wq2p-gqxf", + "modified": "2025-03-17T15:31:48Z", + "published": "2025-03-17T15:31:48Z", + "aliases": [ + "CVE-2025-0596" + ], + "details": "A stored Cross-site Scripting (XSS) vulnerability affecting Bookmark Editor in ENOVIA Collaborative Industry Innovator on Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0596" + }, + { + "type": "WEB", + "url": "https://www.3ds.com/vulnerability/advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T14:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-427r-3p9f-8q5w/GHSA-427r-3p9f-8q5w.json b/advisories/unreviewed/2025/03/GHSA-427r-3p9f-8q5w/GHSA-427r-3p9f-8q5w.json new file mode 100644 index 00000000000..e92b0ef0335 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-427r-3p9f-8q5w/GHSA-427r-3p9f-8q5w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-427r-3p9f-8q5w", + "modified": "2025-03-17T15:31:49Z", + "published": "2025-03-17T15:31:49Z", + "aliases": [ + "CVE-2025-0601" + ], + "details": "A stored Cross-site Scripting (XSS) vulnerability affecting Issue Management in ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0601" + }, + { + "type": "WEB", + "url": "https://www.3ds.com/vulnerability/advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T14:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5frw-vhr9-h7mp/GHSA-5frw-vhr9-h7mp.json b/advisories/unreviewed/2025/03/GHSA-5frw-vhr9-h7mp/GHSA-5frw-vhr9-h7mp.json new file mode 100644 index 00000000000..b291bff0439 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5frw-vhr9-h7mp/GHSA-5frw-vhr9-h7mp.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5frw-vhr9-h7mp", + "modified": "2025-03-17T15:31:50Z", + "published": "2025-03-17T15:31:50Z", + "aliases": [ + "CVE-2025-2380" + ], + "details": "A vulnerability was found in PHPGurukul Apartment Visitors Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin-profile.php. The manipulation of the argument mobilenumber leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2380" + }, + { + "type": "WEB", + "url": "https://github.com/aionman/cve/issues/1" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.299879" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.299879" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.515873" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T14:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6qvm-8hqf-vwf3/GHSA-6qvm-8hqf-vwf3.json b/advisories/unreviewed/2025/03/GHSA-6qvm-8hqf-vwf3/GHSA-6qvm-8hqf-vwf3.json new file mode 100644 index 00000000000..e5f7b5a064b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6qvm-8hqf-vwf3/GHSA-6qvm-8hqf-vwf3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6qvm-8hqf-vwf3", + "modified": "2025-03-17T15:31:48Z", + "published": "2025-03-17T15:31:48Z", + "aliases": [ + "CVE-2021-22126" + ], + "details": "A use of hard-coded password vulnerability in FortiWLC version 8.5.2 and below, version 8.4.8 and below, version 8.3.3 to 8.3.2, version 8.2.7 to 8.2.6 may allow a local, authenticated attacker to connect to the managed Access Point (Meru AP and FortiAP-U) as root using the default hard-coded username and password.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-22126" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-20-147" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T14:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-78pj-pg5h-qf98/GHSA-78pj-pg5h-qf98.json b/advisories/unreviewed/2025/03/GHSA-78pj-pg5h-qf98/GHSA-78pj-pg5h-qf98.json new file mode 100644 index 00000000000..f7b98f6db28 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-78pj-pg5h-qf98/GHSA-78pj-pg5h-qf98.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-78pj-pg5h-qf98", + "modified": "2025-03-17T15:31:50Z", + "published": "2025-03-17T15:31:50Z", + "aliases": [ + "CVE-2025-25650" + ], + "details": "An issue in the storage of NFC card data in Dorset DG 201 Digital Lock H5_433WBSK_v2.2_220605 allows attackers to produce cloned NFC cards to bypass authentication.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25650" + }, + { + "type": "WEB", + "url": "https://github.com/AbhijithAJ/Dorset_SmartLock_Vulnerability/blob/main/Dorset_Smart_Lock_Security_Assessment_Report.pdf" + }, + { + "type": "WEB", + "url": "https://media.blackhat.com/us-13/US-13-Brown-RFID-Hacking-Live-Free-or-RFID-Hard-Slides.pdf" + }, + { + "type": "WEB", + "url": "https://www.getkisi.com/blog/how-to-copy-access-cards-and-keyfobs" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T15:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-8f4x-4qgh-w73f/GHSA-8f4x-4qgh-w73f.json b/advisories/unreviewed/2025/03/GHSA-8f4x-4qgh-w73f/GHSA-8f4x-4qgh-w73f.json new file mode 100644 index 00000000000..d720ee7ba58 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-8f4x-4qgh-w73f/GHSA-8f4x-4qgh-w73f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8f4x-4qgh-w73f", + "modified": "2025-03-17T15:31:48Z", + "published": "2025-03-17T15:31:47Z", + "aliases": [ + "CVE-2019-17659" + ], + "details": "A use of hard-coded cryptographic key vulnerability in FortiSIEM version 5.2.6 may allow a remote unauthenticated attacker to obtain SSH access to the supervisor as the restricted user \"tunneluser\" by leveraging knowledge of the private key from another installation or a firmware image.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-17659" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-19-296" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-798" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T14:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-8vm5-7vg4-3f5x/GHSA-8vm5-7vg4-3f5x.json b/advisories/unreviewed/2025/03/GHSA-8vm5-7vg4-3f5x/GHSA-8vm5-7vg4-3f5x.json new file mode 100644 index 00000000000..be32f23a46e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-8vm5-7vg4-3f5x/GHSA-8vm5-7vg4-3f5x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8vm5-7vg4-3f5x", + "modified": "2025-03-17T15:31:49Z", + "published": "2025-03-17T15:31:49Z", + "aliases": [ + "CVE-2025-0832" + ], + "details": "A stored Cross-site Scripting (XSS) vulnerability affecting Project Gantt in ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0832" + }, + { + "type": "WEB", + "url": "https://www.3ds.com/vulnerability/advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T14:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9cc9-h5mf-w5fr/GHSA-9cc9-h5mf-w5fr.json b/advisories/unreviewed/2025/03/GHSA-9cc9-h5mf-w5fr/GHSA-9cc9-h5mf-w5fr.json new file mode 100644 index 00000000000..142e78f46e2 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-9cc9-h5mf-w5fr/GHSA-9cc9-h5mf-w5fr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9cc9-h5mf-w5fr", + "modified": "2025-03-17T15:31:48Z", + "published": "2025-03-17T15:31:48Z", + "aliases": [ + "CVE-2021-32584" + ], + "details": "An improper access control (CWE-284) vulnerability in FortiWLC version 8.6.0, version 8.5.3 and below, version 8.4.8 and below, version 8.3.3 and below, version 8.2.7 to 8.2.4, version 8.1.3 may allow an unauthenticated and remote attacker to access certain areas of the web management CGI functionality by just specifying the correct URL. The vulnerability applies only to limited CGI resources and might allow the unauthorized party to access configuration details.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-32584" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-20-138" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T14:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9x7w-p6r9-4xp9/GHSA-9x7w-p6r9-4xp9.json b/advisories/unreviewed/2025/03/GHSA-9x7w-p6r9-4xp9/GHSA-9x7w-p6r9-4xp9.json new file mode 100644 index 00000000000..40ddb126d63 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-9x7w-p6r9-4xp9/GHSA-9x7w-p6r9-4xp9.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9x7w-p6r9-4xp9", + "modified": "2025-03-17T15:31:50Z", + "published": "2025-03-17T15:31:50Z", + "aliases": [ + "CVE-2025-25618" + ], + "details": "Incorrect Access Control in Unifiedtransform 2.0 leads to Privilege Escalation allowing the change of Section Name and Room Number by Teachers.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25618" + }, + { + "type": "WEB", + "url": "https://github.com/armaansidana2003/CVE-2025-25618" + }, + { + "type": "WEB", + "url": "https://github.com/changeweb/Unifiedtransform" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T15:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-c369-gmg5-w8pw/GHSA-c369-gmg5-w8pw.json b/advisories/unreviewed/2025/03/GHSA-c369-gmg5-w8pw/GHSA-c369-gmg5-w8pw.json new file mode 100644 index 00000000000..619af5552f3 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-c369-gmg5-w8pw/GHSA-c369-gmg5-w8pw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c369-gmg5-w8pw", + "modified": "2025-03-17T15:31:47Z", + "published": "2025-03-17T15:31:47Z", + "aliases": [ + "CVE-2019-15706" + ], + "details": "An improper neutralization of input during web page generation in the SSL VPN portal of FortiProxy version 2.0.0, version 1.2.9 and below and FortiOS version 6.2.1 and below, version 6.0.8 and below, version 5.6.12 may allow a remote authenticated attacker to perform a stored cross site scripting attack (XSS).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-15706" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-19-223" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T14:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-ffm8-j238-56p4/GHSA-ffm8-j238-56p4.json b/advisories/unreviewed/2025/03/GHSA-ffm8-j238-56p4/GHSA-ffm8-j238-56p4.json new file mode 100644 index 00000000000..234a7e3651b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-ffm8-j238-56p4/GHSA-ffm8-j238-56p4.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ffm8-j238-56p4", + "modified": "2025-03-17T15:31:50Z", + "published": "2025-03-17T15:31:50Z", + "aliases": [ + "CVE-2025-25612" + ], + "details": "FS Inc S3150-8T2F prior to version S3150-8T2F_2.2.0D_135103 is vulnerable to Cross Site Scripting (XSS) in the Time Range Configuration functionality of the administration interface. An attacker can inject malicious JavaScript into the \"Time Range Name\" field, which is improperly sanitized. When this input is saved, it is later executed in the browser of any user accessing the affected page, including administrators, resulting in arbitrary script execution in the user's browser.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25612" + }, + { + "type": "WEB", + "url": "https://github.com/secmuzz/CVE-2025-25612" + }, + { + "type": "WEB", + "url": "http://fs.com" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T15:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-fwm7-53g9-cmxr/GHSA-fwm7-53g9-cmxr.json b/advisories/unreviewed/2025/03/GHSA-fwm7-53g9-cmxr/GHSA-fwm7-53g9-cmxr.json new file mode 100644 index 00000000000..44c37af668b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-fwm7-53g9-cmxr/GHSA-fwm7-53g9-cmxr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fwm7-53g9-cmxr", + "modified": "2025-03-17T15:31:47Z", + "published": "2025-03-17T15:31:47Z", + "aliases": [ + "CVE-2019-6697" + ], + "details": "An Improper Neutralization of Input vulnerability affecting FortiGate version 6.2.0 through 6.2.1, 6.0.0 through 6.0.6 in the hostname parameter of a DHCP packet under DHCP monitor page may allow an unauthenticated attacker in the same network as the FortiGate to perform a Stored Cross Site Scripting attack (XSS) by sending a crafted DHCP packet.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-6697" + }, + { + "type": "WEB", + "url": "https://fortiguard.com/advisory/FG-IR-19-184" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T14:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-gf54-mv55-8xgf/GHSA-gf54-mv55-8xgf.json b/advisories/unreviewed/2025/03/GHSA-gf54-mv55-8xgf/GHSA-gf54-mv55-8xgf.json new file mode 100644 index 00000000000..a7c6964e209 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-gf54-mv55-8xgf/GHSA-gf54-mv55-8xgf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gf54-mv55-8xgf", + "modified": "2025-03-17T15:31:49Z", + "published": "2025-03-17T15:31:49Z", + "aliases": [ + "CVE-2025-0599" + ], + "details": "A stored Cross-site Scripting (XSS) vulnerability affecting Document Management in ENOVIA Collaborative Industry Innovator on Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0599" + }, + { + "type": "WEB", + "url": "https://www.3ds.com/vulnerability/advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T14:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-gjf5-5c3r-89f6/GHSA-gjf5-5c3r-89f6.json b/advisories/unreviewed/2025/03/GHSA-gjf5-5c3r-89f6/GHSA-gjf5-5c3r-89f6.json new file mode 100644 index 00000000000..41e513280c0 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-gjf5-5c3r-89f6/GHSA-gjf5-5c3r-89f6.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gjf5-5c3r-89f6", + "modified": "2025-03-17T15:31:50Z", + "published": "2025-03-17T15:31:50Z", + "aliases": [ + "CVE-2025-2382" + ], + "details": "A vulnerability classified as critical was found in PHPGurukul Online Banquet Booking System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/booking-search.php. The manipulation of the argument searchdata leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2382" + }, + { + "type": "WEB", + "url": "https://github.com/aionman/cve/issues/5" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.299881" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.299881" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.515911" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T15:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-gp57-h4hf-v8gp/GHSA-gp57-h4hf-v8gp.json b/advisories/unreviewed/2025/03/GHSA-gp57-h4hf-v8gp/GHSA-gp57-h4hf-v8gp.json new file mode 100644 index 00000000000..80ca3e4e15e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-gp57-h4hf-v8gp/GHSA-gp57-h4hf-v8gp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gp57-h4hf-v8gp", + "modified": "2025-03-17T15:31:48Z", + "published": "2025-03-17T15:31:47Z", + "aliases": [ + "CVE-2025-2401" + ], + "details": "Buffer overflow vulnerability in Immunity Debugger affecting version 1.85, its exploitation could allow a local attacker to execute arbitrary code, due to the lack of proper boundary checking.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2401" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/buffer-overflow-immunity-debugger" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T13:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-h5vx-hx75-xm9f/GHSA-h5vx-hx75-xm9f.json b/advisories/unreviewed/2025/03/GHSA-h5vx-hx75-xm9f/GHSA-h5vx-hx75-xm9f.json new file mode 100644 index 00000000000..da3be04622f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-h5vx-hx75-xm9f/GHSA-h5vx-hx75-xm9f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h5vx-hx75-xm9f", + "modified": "2025-03-17T15:31:49Z", + "published": "2025-03-17T15:31:49Z", + "aliases": [ + "CVE-2025-0600" + ], + "details": "A stored Cross-site Scripting (XSS) vulnerability affecting Product Explorer in ENOVIA Collaborative Industry Innovator on Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0600" + }, + { + "type": "WEB", + "url": "https://www.3ds.com/vulnerability/advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T14:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hcxf-42cf-2vjf/GHSA-hcxf-42cf-2vjf.json b/advisories/unreviewed/2025/03/GHSA-hcxf-42cf-2vjf/GHSA-hcxf-42cf-2vjf.json new file mode 100644 index 00000000000..7a9fbce88fa --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hcxf-42cf-2vjf/GHSA-hcxf-42cf-2vjf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hcxf-42cf-2vjf", + "modified": "2025-03-17T15:31:49Z", + "published": "2025-03-17T15:31:49Z", + "aliases": [ + "CVE-2025-0828" + ], + "details": "A stored Cross-site Scripting (XSS) vulnerability affecting Engineering Release in ENOVIA Product Engineering Specialist from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0828" + }, + { + "type": "WEB", + "url": "https://www.3ds.com/vulnerability/advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T14:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-j4m5-qgpf-4c8g/GHSA-j4m5-qgpf-4c8g.json b/advisories/unreviewed/2025/03/GHSA-j4m5-qgpf-4c8g/GHSA-j4m5-qgpf-4c8g.json new file mode 100644 index 00000000000..e62917d834c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-j4m5-qgpf-4c8g/GHSA-j4m5-qgpf-4c8g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j4m5-qgpf-4c8g", + "modified": "2025-03-17T15:31:48Z", + "published": "2025-03-17T15:31:48Z", + "aliases": [ + "CVE-2025-0595" + ], + "details": "A stored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0595" + }, + { + "type": "WEB", + "url": "https://www.3ds.com/vulnerability/advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T14:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jqg7-j926-j8mj/GHSA-jqg7-j926-j8mj.json b/advisories/unreviewed/2025/03/GHSA-jqg7-j926-j8mj/GHSA-jqg7-j926-j8mj.json new file mode 100644 index 00000000000..eee5c285f49 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-jqg7-j926-j8mj/GHSA-jqg7-j926-j8mj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jqg7-j926-j8mj", + "modified": "2025-03-17T15:31:48Z", + "published": "2025-03-17T15:31:48Z", + "aliases": [ + "CVE-2021-26087" + ], + "details": "An improper neutralization of input during web page generation in FortiWLC version 8.6.0, version 8.5.3 and below, version 8.4.8 and below, version 8.3.3 web interface may allow both authenticated remote attackers and non-authenticated attackers in the same network as the appliance to perform a stored cross site scripting attack (XSS) via injecting malicious payloads in different locations.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-26087" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-20-137" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T14:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-m27g-7h9f-wrhv/GHSA-m27g-7h9f-wrhv.json b/advisories/unreviewed/2025/03/GHSA-m27g-7h9f-wrhv/GHSA-m27g-7h9f-wrhv.json new file mode 100644 index 00000000000..cd4b369b0d7 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-m27g-7h9f-wrhv/GHSA-m27g-7h9f-wrhv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m27g-7h9f-wrhv", + "modified": "2025-03-17T15:31:49Z", + "published": "2025-03-17T15:31:49Z", + "aliases": [ + "CVE-2025-0829" + ], + "details": "A stored Cross-site Scripting (XSS) vulnerability affecting 3D Markup in ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0829" + }, + { + "type": "WEB", + "url": "https://www.3ds.com/vulnerability/advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T14:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-m7qh-qcm5-xf88/GHSA-m7qh-qcm5-xf88.json b/advisories/unreviewed/2025/03/GHSA-m7qh-qcm5-xf88/GHSA-m7qh-qcm5-xf88.json new file mode 100644 index 00000000000..05755b6465c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-m7qh-qcm5-xf88/GHSA-m7qh-qcm5-xf88.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m7qh-qcm5-xf88", + "modified": "2025-03-17T15:31:49Z", + "published": "2025-03-17T15:31:49Z", + "aliases": [ + "CVE-2025-0833" + ], + "details": "A stored Cross-site Scripting (XSS) vulnerability affecting Route Management in ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0833" + }, + { + "type": "WEB", + "url": "https://www.3ds.com/vulnerability/advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T14:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-m7rg-5646-hfxm/GHSA-m7rg-5646-hfxm.json b/advisories/unreviewed/2025/03/GHSA-m7rg-5646-hfxm/GHSA-m7rg-5646-hfxm.json new file mode 100644 index 00000000000..05518a9fc60 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-m7rg-5646-hfxm/GHSA-m7rg-5646-hfxm.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m7rg-5646-hfxm", + "modified": "2025-03-17T15:31:47Z", + "published": "2025-03-17T15:31:47Z", + "aliases": [ + "CVE-2025-2377" + ], + "details": "A vulnerability was found in SourceCodester Vehicle Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /confirmbooking.php. The manipulation of the argument id leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The initial researcher advisory mentions contradicting product names.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2377" + }, + { + "type": "WEB", + "url": "https://github.com/Keyand/Multi-Restaurant-Table-Reservation-System-Search/blob/main/Vehicle%20Management%20System%20confirmbooking.php%20has%20Cross-site%20Scripting%20(XSS).pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.299876" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.299876" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.515797" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T13:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-mf6m-3qv8-qp4q/GHSA-mf6m-3qv8-qp4q.json b/advisories/unreviewed/2025/03/GHSA-mf6m-3qv8-qp4q/GHSA-mf6m-3qv8-qp4q.json new file mode 100644 index 00000000000..5b51e75cba4 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-mf6m-3qv8-qp4q/GHSA-mf6m-3qv8-qp4q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mf6m-3qv8-qp4q", + "modified": "2025-03-17T15:31:48Z", + "published": "2025-03-17T15:31:48Z", + "aliases": [ + "CVE-2020-9295" + ], + "details": "FortiOS 6.2 running AV engine version 6.00142 and below, FortiOS 6.4 running AV engine version 6.00144 and below and FortiClient 6.2 running AV engine version 6.00137 and below may not immediately detect certain types of malformed or non-standard RAR archives, potentially containing malicious files. Based on the samples provided, FortiClient will detect the malicious files upon trying extraction by real-time scanning and FortiGate will detect the malicious archive if Virus Outbreak Prevention is enabled.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-9295" + }, + { + "type": "WEB", + "url": "https://fortiguard.com/psirt/FG-IR-20-037" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-358" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T14:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-mg2f-6rj5-pr3w/GHSA-mg2f-6rj5-pr3w.json b/advisories/unreviewed/2025/03/GHSA-mg2f-6rj5-pr3w/GHSA-mg2f-6rj5-pr3w.json new file mode 100644 index 00000000000..667592d590e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-mg2f-6rj5-pr3w/GHSA-mg2f-6rj5-pr3w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mg2f-6rj5-pr3w", + "modified": "2025-03-17T15:31:49Z", + "published": "2025-03-17T15:31:49Z", + "aliases": [ + "CVE-2025-0830" + ], + "details": "A stored Cross-site Scripting (XSS) vulnerability affecting Meeting Management in ENOVIA Change Manager from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0830" + }, + { + "type": "WEB", + "url": "https://www.3ds.com/vulnerability/advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T14:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-mwxh-v66f-wcq5/GHSA-mwxh-v66f-wcq5.json b/advisories/unreviewed/2025/03/GHSA-mwxh-v66f-wcq5/GHSA-mwxh-v66f-wcq5.json new file mode 100644 index 00000000000..baaa857a1a6 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-mwxh-v66f-wcq5/GHSA-mwxh-v66f-wcq5.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mwxh-v66f-wcq5", + "modified": "2025-03-17T15:31:50Z", + "published": "2025-03-17T15:31:50Z", + "aliases": [ + "CVE-2025-25621" + ], + "details": "Unifiedtransform 2.0 is vulnerable to Incorrect Access Control, which allows teachers to take attendance of fellow teachers. This affected endpoint is /courses/teacher/index?teacher_id=2&semester_id=1.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25621" + }, + { + "type": "WEB", + "url": "https://github.com/armaansidana2003/CVE-2025-25621" + }, + { + "type": "WEB", + "url": "https://github.com/changeweb/Unifiedtransform" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T15:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-p53g-v548-5w7v/GHSA-p53g-v548-5w7v.json b/advisories/unreviewed/2025/03/GHSA-p53g-v548-5w7v/GHSA-p53g-v548-5w7v.json new file mode 100644 index 00000000000..9182f3c42e0 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-p53g-v548-5w7v/GHSA-p53g-v548-5w7v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p53g-v548-5w7v", + "modified": "2025-03-17T15:31:48Z", + "published": "2025-03-17T15:31:48Z", + "aliases": [ + "CVE-2024-9055" + ], + "details": "The DPA countermeasures on Silicon Labs' Series 2 devices are not reseeded periodically as they should be. This may allow an attacker to eventually extract secret keys through a DPA attack.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9055" + }, + { + "type": "WEB", + "url": "https://community.silabs.com/069Vm00000LJMlfIAH" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-331" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T14:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-ph9c-99wp-5w5f/GHSA-ph9c-99wp-5w5f.json b/advisories/unreviewed/2025/03/GHSA-ph9c-99wp-5w5f/GHSA-ph9c-99wp-5w5f.json new file mode 100644 index 00000000000..89dd5380d50 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-ph9c-99wp-5w5f/GHSA-ph9c-99wp-5w5f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ph9c-99wp-5w5f", + "modified": "2025-03-17T15:31:49Z", + "published": "2025-03-17T15:31:49Z", + "aliases": [ + "CVE-2025-0598" + ], + "details": "A stored Cross-site Scripting (XSS) vulnerability affecting Relations in ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0598" + }, + { + "type": "WEB", + "url": "https://www.3ds.com/vulnerability/advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T14:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-q62g-355r-cfg2/GHSA-q62g-355r-cfg2.json b/advisories/unreviewed/2025/03/GHSA-q62g-355r-cfg2/GHSA-q62g-355r-cfg2.json new file mode 100644 index 00000000000..c3cb0070d71 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-q62g-355r-cfg2/GHSA-q62g-355r-cfg2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q62g-355r-cfg2", + "modified": "2025-03-17T15:31:49Z", + "published": "2025-03-17T15:31:49Z", + "aliases": [ + "CVE-2025-0827" + ], + "details": "A stored Cross-site Scripting (XSS) vulnerability affecting 3DPlay in 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0827" + }, + { + "type": "WEB", + "url": "https://www.3ds.com/vulnerability/advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T14:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-qcqx-4h2x-x43j/GHSA-qcqx-4h2x-x43j.json b/advisories/unreviewed/2025/03/GHSA-qcqx-4h2x-x43j/GHSA-qcqx-4h2x-x43j.json new file mode 100644 index 00000000000..a0b8a643c30 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-qcqx-4h2x-x43j/GHSA-qcqx-4h2x-x43j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qcqx-4h2x-x43j", + "modified": "2025-03-17T15:31:48Z", + "published": "2025-03-17T15:31:48Z", + "aliases": [ + "CVE-2024-54027" + ], + "details": "A Use of Hard-coded Cryptographic Key vulnerability [CWE-321] in FortiSandbox version 4.4.6 and below, version 4.2.7 and below, version 4.0.5 and below, version 3.2.4 and below, version 3.1.5 and below, version 3.0.7 to 3.0.5 may allow a privileged attacker with super-admin profile and CLI access to read sensitive data via CLI.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54027" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-327" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-321" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T14:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-qh8m-89j4-42jf/GHSA-qh8m-89j4-42jf.json b/advisories/unreviewed/2025/03/GHSA-qh8m-89j4-42jf/GHSA-qh8m-89j4-42jf.json new file mode 100644 index 00000000000..c2a37938bc8 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-qh8m-89j4-42jf/GHSA-qh8m-89j4-42jf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qh8m-89j4-42jf", + "modified": "2025-03-17T15:31:48Z", + "published": "2025-03-17T15:31:48Z", + "aliases": [ + "CVE-2020-29010" + ], + "details": "An exposure of sensitive information to an unauthorized actor vulnerability in FortiOS version 6.2.4 and below, version 6.0.10 and belowmay allow remote authenticated actors to read the SSL VPN events log entries of users in other VDOMs by executing \"get vpn ssl monitor\" from the CLI. The sensitive data includes usernames, user groups, and IP address.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-29010" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-20-103" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T14:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-qqcj-9cvv-63xg/GHSA-qqcj-9cvv-63xg.json b/advisories/unreviewed/2025/03/GHSA-qqcj-9cvv-63xg/GHSA-qqcj-9cvv-63xg.json new file mode 100644 index 00000000000..b0d306d88c6 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-qqcj-9cvv-63xg/GHSA-qqcj-9cvv-63xg.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qqcj-9cvv-63xg", + "modified": "2025-03-17T15:31:48Z", + "published": "2025-03-17T15:31:48Z", + "aliases": [ + "CVE-2025-2378" + ], + "details": "A vulnerability was found in PHPGurukul Medical Card Generation System 1.0. It has been classified as critical. This affects an unknown part of the file /download-medical-cards.php. The manipulation of the argument searchdata leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2378" + }, + { + "type": "WEB", + "url": "https://github.com/chenyihao-cyber/CVE/issues/4" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.299877" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.299877" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.515822" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T13:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-r4vm-xmvg-644h/GHSA-r4vm-xmvg-644h.json b/advisories/unreviewed/2025/03/GHSA-r4vm-xmvg-644h/GHSA-r4vm-xmvg-644h.json new file mode 100644 index 00000000000..bc839d493bb --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-r4vm-xmvg-644h/GHSA-r4vm-xmvg-644h.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r4vm-xmvg-644h", + "modified": "2025-03-17T15:31:50Z", + "published": "2025-03-17T15:31:50Z", + "aliases": [ + "CVE-2025-26127" + ], + "details": "A stored cross-site scripting (XSS) vulnerability in the Send for Approval function of FileCloud v23.241.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26127" + }, + { + "type": "WEB", + "url": "https://github.com/pentesttoolscom/vulnerability-research/tree/master/CVE-2025-26127" + }, + { + "type": "WEB", + "url": "https://www.filecloud.com/supportdocs/fcdoc/latest/server/release-notes/filecloud-version-23-241-release-notes/minor-filecloud-release-23-241-3" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T15:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-rg2v-4c8w-w4r4/GHSA-rg2v-4c8w-w4r4.json b/advisories/unreviewed/2025/03/GHSA-rg2v-4c8w-w4r4/GHSA-rg2v-4c8w-w4r4.json new file mode 100644 index 00000000000..ccd153c1541 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-rg2v-4c8w-w4r4/GHSA-rg2v-4c8w-w4r4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rg2v-4c8w-w4r4", + "modified": "2025-03-17T15:31:49Z", + "published": "2025-03-17T15:31:49Z", + "aliases": [ + "CVE-2025-0826" + ], + "details": "A stored Cross-site Scripting (XSS) vulnerability affecting 3D Navigate in ENOVIA Collaborative Industry Innovator from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0826" + }, + { + "type": "WEB", + "url": "https://www.3ds.com/vulnerability/advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T14:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-w2mf-wgp6-w934/GHSA-w2mf-wgp6-w934.json b/advisories/unreviewed/2025/03/GHSA-w2mf-wgp6-w934/GHSA-w2mf-wgp6-w934.json new file mode 100644 index 00000000000..cf3e51d3935 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-w2mf-wgp6-w934/GHSA-w2mf-wgp6-w934.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w2mf-wgp6-w934", + "modified": "2025-03-17T15:31:50Z", + "published": "2025-03-17T15:31:50Z", + "aliases": [ + "CVE-2025-2379" + ], + "details": "A vulnerability was found in PHPGurukul Apartment Visitors Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /create-pass.php. The manipulation of the argument visname leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2379" + }, + { + "type": "WEB", + "url": "https://github.com/aionman/cve/issues/2" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.299878" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.299878" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.515872" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T14:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-w97p-2hwc-7qx6/GHSA-w97p-2hwc-7qx6.json b/advisories/unreviewed/2025/03/GHSA-w97p-2hwc-7qx6/GHSA-w97p-2hwc-7qx6.json new file mode 100644 index 00000000000..ea273cf5de8 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-w97p-2hwc-7qx6/GHSA-w97p-2hwc-7qx6.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w97p-2hwc-7qx6", + "modified": "2025-03-17T15:31:50Z", + "published": "2025-03-17T15:31:50Z", + "aliases": [ + "CVE-2025-1774" + ], + "details": "Incorrect string encoding vulnerability in NASK - PIB BotSense allows injection of an additional field separator character or value in the content of some fields of the generated event. A field with additional field separator characters or values can be included in the \"extraData\" field.This issue affects BotSense in versions before 2.8.0.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1774" + }, + { + "type": "WEB", + "url": "https://cert.pl/en/posts/2025/03/CVE-2025-1774" + }, + { + "type": "WEB", + "url": "https://cert.pl/posts/2025/03/CVE-2025-1774" + }, + { + "type": "WEB", + "url": "https://nask.pl/instytut/dla-biznesu/botsense" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-142" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T15:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-wc4q-pc87-7ch2/GHSA-wc4q-pc87-7ch2.json b/advisories/unreviewed/2025/03/GHSA-wc4q-pc87-7ch2/GHSA-wc4q-pc87-7ch2.json new file mode 100644 index 00000000000..4ffc2575fbb --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-wc4q-pc87-7ch2/GHSA-wc4q-pc87-7ch2.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wc4q-pc87-7ch2", + "modified": "2025-03-17T15:31:50Z", + "published": "2025-03-17T15:31:50Z", + "aliases": [ + "CVE-2025-2381" + ], + "details": "A vulnerability classified as critical has been found in PHPGurukul Curfew e-Pass Management System 1.0. Affected is an unknown function of the file /admin/search-pass.php. The manipulation of the argument searchdata leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2381" + }, + { + "type": "WEB", + "url": "https://github.com/aionman/cve/issues/4" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.299880" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.299880" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.515896" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T15:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-xmvv-w44w-j8wx/GHSA-xmvv-w44w-j8wx.json b/advisories/unreviewed/2025/03/GHSA-xmvv-w44w-j8wx/GHSA-xmvv-w44w-j8wx.json new file mode 100644 index 00000000000..ea501d1bf00 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-xmvv-w44w-j8wx/GHSA-xmvv-w44w-j8wx.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xmvv-w44w-j8wx", + "modified": "2025-03-17T15:31:50Z", + "published": "2025-03-17T15:31:50Z", + "aliases": [ + "CVE-2025-1398" + ], + "details": "Mattermost Desktop App versions <=5.10.0 explicitly declared unnecessary macOS entitlements which allows an attacker with remote access to bypass Transparency, Consent, and Control (TCC) via code injection.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1398" + }, + { + "type": "WEB", + "url": "https://mattermost.com/security-updates" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-426" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T15:15:43Z" + } +} \ No newline at end of file