From 2c26608333d08302b2d8cb96638ceb13833d910e Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 30 Jul 2024 21:33:01 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-pv98-48f2-5vjr.json | 6 +- .../GHSA-22g4-7m96-g7pp.json | 51 ++++++++++++++++ .../GHSA-26mh-xhv7-944g.json | 35 +++++++++++ .../GHSA-273f-pp2q-7h53.json | 54 +++++++++++++++++ .../GHSA-27rx-w643-mrjg.json | 11 ++-- .../GHSA-28mc-g557-92m7.json | 35 +++++++++++ .../GHSA-3ghx-8gmm-9rg3.json | 39 ++++++++++++ .../GHSA-3wqv-582c-6cpc.json | 38 ++++++++++++ .../GHSA-45f8-hpxx-pqmq.json | 11 ++-- .../GHSA-45vr-76fp-gmwx.json | 39 ++++++++++++ .../GHSA-47v5-cr23-pw2c.json | 11 ++-- .../GHSA-4fx6-x999-g2xc.json | 9 ++- .../GHSA-4hjh-qjjx-6vx4.json | 11 ++-- .../GHSA-4qj9-whm7-4cr2.json | 2 +- .../GHSA-5h8j-93h4-mm7v.json | 11 ++-- .../GHSA-64jr-8qg8-gh2j.json | 4 +- .../GHSA-6764-gfvg-wvf4.json | 9 ++- .../GHSA-68vf-xmgr-pxm6.json | 11 ++-- .../GHSA-6xvq-4crp-429f.json | 11 ++-- .../GHSA-7wph-5wjx-7rgv.json | 11 ++-- .../GHSA-8cw4-xx6j-52ph.json | 2 +- .../GHSA-8vxj-86v6-ppgq.json | 51 ++++++++++++++++ .../GHSA-93xv-w432-6pgp.json | 38 ++++++++++++ .../GHSA-9qp4-rw2q-rx7r.json | 11 ++-- .../GHSA-c3g7-jwpr-vrhq.json | 11 ++-- .../GHSA-c4hf-x9gr-w5f8.json | 11 ++-- .../GHSA-cfqx-qcxx-3hwg.json | 9 ++- .../GHSA-f2w3-phmv-5298.json | 11 ++-- .../GHSA-f53v-x4rw-42rf.json | 11 ++-- .../GHSA-fgq5-vx4r-rg7c.json | 35 +++++++++++ .../GHSA-gxw4-wqj9-7x83.json | 35 +++++++++++ .../GHSA-h4gx-rc62-wcvc.json | 55 +++++++++++++++++ .../GHSA-hm79-2wxc-w993.json | 55 +++++++++++++++++ .../GHSA-hmvx-mw63-jvg7.json | 11 ++-- .../GHSA-hwc3-9p27-c4j6.json | 9 ++- .../GHSA-hx5h-3r35-f985.json | 2 +- .../GHSA-j2f8-8cqp-fv4p.json | 46 +++++++++++++++ .../GHSA-jg37-q3vp-38x3.json | 11 ++-- .../GHSA-m5g2-rqpc-h5hr.json | 9 ++- .../GHSA-mhjg-j5hq-m4p7.json | 11 ++-- .../GHSA-mj9h-qp8g-g746.json | 35 +++++++++++ .../GHSA-mjjp-275q-ww9c.json | 38 ++++++++++++ .../GHSA-p649-hp44-fr85.json | 11 ++-- .../GHSA-qf7q-7m3q-4gg2.json | 9 ++- .../GHSA-qvjc-6j6m-p7gx.json | 11 ++-- .../GHSA-rxwh-225r-76q6.json | 11 ++-- .../GHSA-v7qg-qfrr-c59x.json | 35 +++++++++++ .../GHSA-vmmw-2v5h-4hf6.json | 11 ++-- .../GHSA-wrxx-pv2p-6gjj.json | 59 +++++++++++++++++++ .../GHSA-x8rh-6x6w-x2xg.json | 11 ++-- .../GHSA-x93q-6p46-2qqf.json | 39 ++++++++++++ 51 files changed, 1005 insertions(+), 108 deletions(-) create mode 100644 advisories/unreviewed/2024/07/GHSA-22g4-7m96-g7pp/GHSA-22g4-7m96-g7pp.json create mode 100644 advisories/unreviewed/2024/07/GHSA-26mh-xhv7-944g/GHSA-26mh-xhv7-944g.json create mode 100644 advisories/unreviewed/2024/07/GHSA-273f-pp2q-7h53/GHSA-273f-pp2q-7h53.json create mode 100644 advisories/unreviewed/2024/07/GHSA-28mc-g557-92m7/GHSA-28mc-g557-92m7.json create mode 100644 advisories/unreviewed/2024/07/GHSA-3ghx-8gmm-9rg3/GHSA-3ghx-8gmm-9rg3.json create mode 100644 advisories/unreviewed/2024/07/GHSA-3wqv-582c-6cpc/GHSA-3wqv-582c-6cpc.json create mode 100644 advisories/unreviewed/2024/07/GHSA-45vr-76fp-gmwx/GHSA-45vr-76fp-gmwx.json create mode 100644 advisories/unreviewed/2024/07/GHSA-8vxj-86v6-ppgq/GHSA-8vxj-86v6-ppgq.json create mode 100644 advisories/unreviewed/2024/07/GHSA-93xv-w432-6pgp/GHSA-93xv-w432-6pgp.json create mode 100644 advisories/unreviewed/2024/07/GHSA-fgq5-vx4r-rg7c/GHSA-fgq5-vx4r-rg7c.json create mode 100644 advisories/unreviewed/2024/07/GHSA-gxw4-wqj9-7x83/GHSA-gxw4-wqj9-7x83.json create mode 100644 advisories/unreviewed/2024/07/GHSA-h4gx-rc62-wcvc/GHSA-h4gx-rc62-wcvc.json create mode 100644 advisories/unreviewed/2024/07/GHSA-hm79-2wxc-w993/GHSA-hm79-2wxc-w993.json create mode 100644 advisories/unreviewed/2024/07/GHSA-j2f8-8cqp-fv4p/GHSA-j2f8-8cqp-fv4p.json create mode 100644 advisories/unreviewed/2024/07/GHSA-mj9h-qp8g-g746/GHSA-mj9h-qp8g-g746.json create mode 100644 advisories/unreviewed/2024/07/GHSA-mjjp-275q-ww9c/GHSA-mjjp-275q-ww9c.json create mode 100644 advisories/unreviewed/2024/07/GHSA-v7qg-qfrr-c59x/GHSA-v7qg-qfrr-c59x.json create mode 100644 advisories/unreviewed/2024/07/GHSA-wrxx-pv2p-6gjj/GHSA-wrxx-pv2p-6gjj.json create mode 100644 advisories/unreviewed/2024/07/GHSA-x93q-6p46-2qqf/GHSA-x93q-6p46-2qqf.json diff --git a/advisories/unreviewed/2024/03/GHSA-pv98-48f2-5vjr/GHSA-pv98-48f2-5vjr.json b/advisories/unreviewed/2024/03/GHSA-pv98-48f2-5vjr/GHSA-pv98-48f2-5vjr.json index a8cccf6f5a1..b0548afb69d 100644 --- a/advisories/unreviewed/2024/03/GHSA-pv98-48f2-5vjr/GHSA-pv98-48f2-5vjr.json +++ b/advisories/unreviewed/2024/03/GHSA-pv98-48f2-5vjr/GHSA-pv98-48f2-5vjr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pv98-48f2-5vjr", - "modified": "2024-07-29T09:36:13Z", + "modified": "2024-07-30T21:31:25Z", "published": "2024-03-03T00:30:32Z", "aliases": [ "CVE-2024-26621" @@ -117,6 +117,10 @@ { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2024/07/29/2" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/07/30/2" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/07/GHSA-22g4-7m96-g7pp/GHSA-22g4-7m96-g7pp.json b/advisories/unreviewed/2024/07/GHSA-22g4-7m96-g7pp/GHSA-22g4-7m96-g7pp.json new file mode 100644 index 00000000000..a19ce2d19bc --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-22g4-7m96-g7pp/GHSA-22g4-7m96-g7pp.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-22g4-7m96-g7pp", + "modified": "2024-07-30T21:31:27Z", + "published": "2024-07-30T21:31:27Z", + "aliases": [ + "CVE-2024-41437" + ], + "details": "A heap buffer overflow in the function cp_unfilter() (/vendor/cute_png.h) of hicolor v0.5.0 allows attackers to cause a Denial of Service (DoS) via a crafted PNG file.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41437" + }, + { + "type": "WEB", + "url": "https://github.com/Helson-S/FuzzyTesting/blob/master/hicolor/heapof-r1-cp_unfilter-cute_png-1019c11/poc/sample6.png" + }, + { + "type": "WEB", + "url": "https://github.com/Helson-S/FuzzyTesting/blob/master/hicolor/heapof-r1-cp_unfilter-cute_png-1019c11/vulDescription.assets/image-20240530183857985.png" + }, + { + "type": "WEB", + "url": "https://github.com/Helson-S/FuzzyTesting/blob/master/hicolor/heapof-r1-cp_unfilter-cute_png-1019c11/vulDescription.md" + }, + { + "type": "WEB", + "url": "https://github.com/Helson-S/FuzzyTesting/tree/master/hicolor/heapof-r1-cp_unfilter-cute_png-1019c11" + }, + { + "type": "WEB", + "url": "https://github.com/Helson-S/FuzzyTesting/tree/master/hicolor/heapof-r1-cp_unfilter-cute_png-1019c11/poc" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-30T19:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-26mh-xhv7-944g/GHSA-26mh-xhv7-944g.json b/advisories/unreviewed/2024/07/GHSA-26mh-xhv7-944g/GHSA-26mh-xhv7-944g.json new file mode 100644 index 00000000000..4174b59d036 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-26mh-xhv7-944g/GHSA-26mh-xhv7-944g.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-26mh-xhv7-944g", + "modified": "2024-07-30T21:31:28Z", + "published": "2024-07-30T21:31:28Z", + "aliases": [ + "CVE-2024-39012" + ], + "details": "ais-ltd strategyen v0.4.0 was discovered to contain a prototype pollution via the function mergeObjects. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39012" + }, + { + "type": "WEB", + "url": "https://gist.github.com/mestrtee/acfbd724a4b73bfb5d030575b653453c" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-30T20:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-273f-pp2q-7h53/GHSA-273f-pp2q-7h53.json b/advisories/unreviewed/2024/07/GHSA-273f-pp2q-7h53/GHSA-273f-pp2q-7h53.json new file mode 100644 index 00000000000..283844430c7 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-273f-pp2q-7h53/GHSA-273f-pp2q-7h53.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-273f-pp2q-7h53", + "modified": "2024-07-30T21:31:29Z", + "published": "2024-07-30T21:31:29Z", + "aliases": [ + "CVE-2024-7273" + ], + "details": "A vulnerability classified as critical was found in itsourcecode Alton Management System 1.0. This vulnerability affects unknown code of the file search.php. The manipulation of the argument rcode leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-273142 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7273" + }, + { + "type": "WEB", + "url": "https://github.com/DeepMountains/Mirage/blob/main/CVE8-1.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.273142" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.273142" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.381089" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-30T21:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-27rx-w643-mrjg/GHSA-27rx-w643-mrjg.json b/advisories/unreviewed/2024/07/GHSA-27rx-w643-mrjg/GHSA-27rx-w643-mrjg.json index c469aed85ef..c60e39d2912 100644 --- a/advisories/unreviewed/2024/07/GHSA-27rx-w643-mrjg/GHSA-27rx-w643-mrjg.json +++ b/advisories/unreviewed/2024/07/GHSA-27rx-w643-mrjg/GHSA-27rx-w643-mrjg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-27rx-w643-mrjg", - "modified": "2024-07-30T09:32:04Z", + "modified": "2024-07-30T21:31:27Z", "published": "2024-07-30T09:32:04Z", "aliases": [ "CVE-2024-42225" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: replace skb_put with skb_put_zero\n\nAvoid potentially reusing uninitialized data", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-908" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-30T08:15:07Z" diff --git a/advisories/unreviewed/2024/07/GHSA-28mc-g557-92m7/GHSA-28mc-g557-92m7.json b/advisories/unreviewed/2024/07/GHSA-28mc-g557-92m7/GHSA-28mc-g557-92m7.json new file mode 100644 index 00000000000..f37397cc964 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-28mc-g557-92m7/GHSA-28mc-g557-92m7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-28mc-g557-92m7", + "modified": "2024-07-30T21:31:28Z", + "published": "2024-07-30T21:31:28Z", + "aliases": [ + "CVE-2024-38986" + ], + "details": "Prototype Pollution in 75lb deep-merge 1.1.1 allows attackers to execute arbitrary code or cause a Denial of Service (DoS) and cause other impacts via merge methods of lodash to merge objects.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38986" + }, + { + "type": "WEB", + "url": "https://gist.github.com/mestrtee/b20c3aee8bea16e1863933778da6e4cb" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-30T20:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-3ghx-8gmm-9rg3/GHSA-3ghx-8gmm-9rg3.json b/advisories/unreviewed/2024/07/GHSA-3ghx-8gmm-9rg3/GHSA-3ghx-8gmm-9rg3.json new file mode 100644 index 00000000000..fcf5862397d --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-3ghx-8gmm-9rg3/GHSA-3ghx-8gmm-9rg3.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3ghx-8gmm-9rg3", + "modified": "2024-07-30T21:31:29Z", + "published": "2024-07-30T21:31:29Z", + "aliases": [ + "CVE-2024-41611" + ], + "details": "In D-Link DIR-860L REVA FIRMWARE PATCH 1.10..B04, the Telnet service contains hardcoded credentials, enabling attackers to log in remotely to the Telnet service and perform arbitrary commands.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41611" + }, + { + "type": "WEB", + "url": "https://github.com/Nop3z/CVE/blob/main/dlink/dir-820/Dlink-860L-hardcoded-vulnerability.md" + }, + { + "type": "WEB", + "url": "https://www.dlink.com/en/security-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-30T20:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-3wqv-582c-6cpc/GHSA-3wqv-582c-6cpc.json b/advisories/unreviewed/2024/07/GHSA-3wqv-582c-6cpc/GHSA-3wqv-582c-6cpc.json new file mode 100644 index 00000000000..f5b608f4664 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-3wqv-582c-6cpc/GHSA-3wqv-582c-6cpc.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3wqv-582c-6cpc", + "modified": "2024-07-30T21:31:27Z", + "published": "2024-07-30T21:31:27Z", + "aliases": [ + "CVE-2024-3930" + ], + "details": "In versions of Akana API Platform prior to 2024.1.0 a flaw resulting in XML External Entity (XXE) was discovered.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3930" + }, + { + "type": "WEB", + "url": "https://portal.perforce.com/s/detail/a91PA000001SUKLYA4" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-611" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-30T19:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-45f8-hpxx-pqmq/GHSA-45f8-hpxx-pqmq.json b/advisories/unreviewed/2024/07/GHSA-45f8-hpxx-pqmq/GHSA-45f8-hpxx-pqmq.json index bdae1cde11d..fa8e74c972b 100644 --- a/advisories/unreviewed/2024/07/GHSA-45f8-hpxx-pqmq/GHSA-45f8-hpxx-pqmq.json +++ b/advisories/unreviewed/2024/07/GHSA-45f8-hpxx-pqmq/GHSA-45f8-hpxx-pqmq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-45f8-hpxx-pqmq", - "modified": "2024-07-29T18:30:39Z", + "modified": "2024-07-30T21:31:26Z", "published": "2024-07-29T18:30:39Z", "aliases": [ "CVE-2024-42066" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe: Fix potential integer overflow in page size calculation\n\nExplicitly cast tbo->page_alignment to u64 before bit-shifting to\nprevent overflow when assigning to min_page_size.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-190" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T16:15:06Z" diff --git a/advisories/unreviewed/2024/07/GHSA-45vr-76fp-gmwx/GHSA-45vr-76fp-gmwx.json b/advisories/unreviewed/2024/07/GHSA-45vr-76fp-gmwx/GHSA-45vr-76fp-gmwx.json new file mode 100644 index 00000000000..a540b027506 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-45vr-76fp-gmwx/GHSA-45vr-76fp-gmwx.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-45vr-76fp-gmwx", + "modified": "2024-07-30T21:31:28Z", + "published": "2024-07-30T21:31:28Z", + "aliases": [ + "CVE-2024-36572" + ], + "details": "Prototype pollution in allpro form-manager 0.7.4 allows attackers to run arbitrary code and cause other impacts via the functions setDefaults, mergeBranch, and Object.setObjectValue.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36572" + }, + { + "type": "WEB", + "url": "https://github.com/allpro/form-manager/issues/1" + }, + { + "type": "WEB", + "url": "https://gist.github.com/mestrtee/1771ab4fba733ca898b6e2463dc6ed19" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-30T20:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-47v5-cr23-pw2c/GHSA-47v5-cr23-pw2c.json b/advisories/unreviewed/2024/07/GHSA-47v5-cr23-pw2c/GHSA-47v5-cr23-pw2c.json index e31a8530ee6..9104dc85b94 100644 --- a/advisories/unreviewed/2024/07/GHSA-47v5-cr23-pw2c/GHSA-47v5-cr23-pw2c.json +++ b/advisories/unreviewed/2024/07/GHSA-47v5-cr23-pw2c/GHSA-47v5-cr23-pw2c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-47v5-cr23-pw2c", - "modified": "2024-07-29T18:30:39Z", + "modified": "2024-07-30T21:31:26Z", "published": "2024-07-29T18:30:39Z", "aliases": [ "CVE-2024-42069" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: mana: Fix possible double free in error handling path\n\nWhen auxiliary_device_add() returns error and then calls\nauxiliary_device_uninit(), callback function adev_release\ncalls kfree(madev). We shouldn't call kfree(madev) again\nin the error handling path. Set 'madev' to NULL.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T16:15:06Z" diff --git a/advisories/unreviewed/2024/07/GHSA-4fx6-x999-g2xc/GHSA-4fx6-x999-g2xc.json b/advisories/unreviewed/2024/07/GHSA-4fx6-x999-g2xc/GHSA-4fx6-x999-g2xc.json index fd4f709f082..78aea79648a 100644 --- a/advisories/unreviewed/2024/07/GHSA-4fx6-x999-g2xc/GHSA-4fx6-x999-g2xc.json +++ b/advisories/unreviewed/2024/07/GHSA-4fx6-x999-g2xc/GHSA-4fx6-x999-g2xc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4fx6-x999-g2xc", - "modified": "2024-07-29T18:30:39Z", + "modified": "2024-07-30T21:31:25Z", "published": "2024-07-29T18:30:39Z", "aliases": [ "CVE-2024-42064" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Skip pipe if the pipe idx not set properly\n\n[why]\nDriver crashes when pipe idx not set properly\n\n[how]\nAdd code to skip the pipe that idx not set properly", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T16:15:06Z" diff --git a/advisories/unreviewed/2024/07/GHSA-4hjh-qjjx-6vx4/GHSA-4hjh-qjjx-6vx4.json b/advisories/unreviewed/2024/07/GHSA-4hjh-qjjx-6vx4/GHSA-4hjh-qjjx-6vx4.json index 1c3b7e5cb5d..d25c3536b0f 100644 --- a/advisories/unreviewed/2024/07/GHSA-4hjh-qjjx-6vx4/GHSA-4hjh-qjjx-6vx4.json +++ b/advisories/unreviewed/2024/07/GHSA-4hjh-qjjx-6vx4/GHSA-4hjh-qjjx-6vx4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4hjh-qjjx-6vx4", - "modified": "2024-07-29T18:30:40Z", + "modified": "2024-07-30T21:31:27Z", "published": "2024-07-29T18:30:40Z", "aliases": [ "CVE-2024-42083" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nionic: fix kernel panic due to multi-buffer handling\n\nCurrently, the ionic_run_xdp() doesn't handle multi-buffer packets\nproperly for XDP_TX and XDP_REDIRECT.\nWhen a jumbo frame is received, the ionic_run_xdp() first makes xdp\nframe with all necessary pages in the rx descriptor.\nAnd if the action is either XDP_TX or XDP_REDIRECT, it should unmap\ndma-mapping and reset page pointer to NULL for all pages, not only the\nfirst page.\nBut it doesn't for SG pages. So, SG pages unexpectedly will be reused.\nIt eventually causes kernel panic.\n\nOops: general protection fault, probably for non-canonical address 0x504f4e4dbebc64ff: 0000 [#1] PREEMPT SMP NOPTI\nCPU: 3 PID: 0 Comm: swapper/3 Not tainted 6.10.0-rc3+ #25\nRIP: 0010:xdp_return_frame+0x42/0x90\nCode: 01 75 12 5b 4c 89 e6 5d 31 c9 41 5c 31 d2 41 5d e9 73 fd ff ff 44 8b 6b 20 0f b7 43 0a 49 81 ed 68 01 00 00 49 29 c5 49 01 fd <41> 80 7d0\nRSP: 0018:ffff99d00122ce08 EFLAGS: 00010202\nRAX: 0000000000005453 RBX: ffff8d325f904000 RCX: 0000000000000001\nRDX: 00000000670e1000 RSI: 000000011f90d000 RDI: 504f4e4d4c4b4a49\nRBP: ffff99d003907740 R08: 0000000000000000 R09: 0000000000000000\nR10: 000000011f90d000 R11: 0000000000000000 R12: ffff8d325f904010\nR13: 504f4e4dbebc64fd R14: ffff8d3242b070c8 R15: ffff99d0039077c0\nFS: 0000000000000000(0000) GS:ffff8d399f780000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007f41f6c85e38 CR3: 000000037ac30000 CR4: 00000000007506f0\nPKRU: 55555554\nCall Trace:\n \n ? die_addr+0x33/0x90\n ? exc_general_protection+0x251/0x2f0\n ? asm_exc_general_protection+0x22/0x30\n ? xdp_return_frame+0x42/0x90\n ionic_tx_clean+0x211/0x280 [ionic 15881354510e6a9c655c59c54812b319ed2cd015]\n ionic_tx_cq_service+0xd3/0x210 [ionic 15881354510e6a9c655c59c54812b319ed2cd015]\n ionic_txrx_napi+0x41/0x1b0 [ionic 15881354510e6a9c655c59c54812b319ed2cd015]\n __napi_poll.constprop.0+0x29/0x1b0\n net_rx_action+0x2c4/0x350\n handle_softirqs+0xf4/0x320\n irq_exit_rcu+0x78/0xa0\n common_interrupt+0x77/0x90", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T16:15:07Z" diff --git a/advisories/unreviewed/2024/07/GHSA-4qj9-whm7-4cr2/GHSA-4qj9-whm7-4cr2.json b/advisories/unreviewed/2024/07/GHSA-4qj9-whm7-4cr2/GHSA-4qj9-whm7-4cr2.json index 8605cbc7db3..d88e8b2a47a 100644 --- a/advisories/unreviewed/2024/07/GHSA-4qj9-whm7-4cr2/GHSA-4qj9-whm7-4cr2.json +++ b/advisories/unreviewed/2024/07/GHSA-4qj9-whm7-4cr2/GHSA-4qj9-whm7-4cr2.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-5h8j-93h4-mm7v/GHSA-5h8j-93h4-mm7v.json b/advisories/unreviewed/2024/07/GHSA-5h8j-93h4-mm7v/GHSA-5h8j-93h4-mm7v.json index ca9ded42c8d..10d4f1a1e2f 100644 --- a/advisories/unreviewed/2024/07/GHSA-5h8j-93h4-mm7v/GHSA-5h8j-93h4-mm7v.json +++ b/advisories/unreviewed/2024/07/GHSA-5h8j-93h4-mm7v/GHSA-5h8j-93h4-mm7v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5h8j-93h4-mm7v", - "modified": "2024-07-29T18:30:40Z", + "modified": "2024-07-30T21:31:26Z", "published": "2024-07-29T18:30:40Z", "aliases": [ "CVE-2024-42070" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: fully validate NFT_DATA_VALUE on store to data registers\n\nregister store validation for NFT_DATA_VALUE is conditional, however,\nthe datatype is always either NFT_DATA_VALUE or NFT_DATA_VERDICT. This\nonly requires a new helper function to infer the register type from the\nset datatype so this conditional check can be removed. Otherwise,\npointer to chain object can be leaked through the registers.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-401" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T16:15:06Z" diff --git a/advisories/unreviewed/2024/07/GHSA-64jr-8qg8-gh2j/GHSA-64jr-8qg8-gh2j.json b/advisories/unreviewed/2024/07/GHSA-64jr-8qg8-gh2j/GHSA-64jr-8qg8-gh2j.json index 3fc377bf895..5244d0e6a1b 100644 --- a/advisories/unreviewed/2024/07/GHSA-64jr-8qg8-gh2j/GHSA-64jr-8qg8-gh2j.json +++ b/advisories/unreviewed/2024/07/GHSA-64jr-8qg8-gh2j/GHSA-64jr-8qg8-gh2j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-64jr-8qg8-gh2j", - "modified": "2024-07-10T09:30:41Z", + "modified": "2024-07-30T21:31:25Z", "published": "2024-07-10T09:30:41Z", "aliases": [ "CVE-2024-5664" @@ -40,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-6764-gfvg-wvf4/GHSA-6764-gfvg-wvf4.json b/advisories/unreviewed/2024/07/GHSA-6764-gfvg-wvf4/GHSA-6764-gfvg-wvf4.json index 92337fcc823..da2c817c4af 100644 --- a/advisories/unreviewed/2024/07/GHSA-6764-gfvg-wvf4/GHSA-6764-gfvg-wvf4.json +++ b/advisories/unreviewed/2024/07/GHSA-6764-gfvg-wvf4/GHSA-6764-gfvg-wvf4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6764-gfvg-wvf4", - "modified": "2024-07-30T09:32:04Z", + "modified": "2024-07-30T21:31:27Z", "published": "2024-07-30T09:32:04Z", "aliases": [ "CVE-2024-42227" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Fix overlapping copy within dml_core_mode_programming\n\n[WHY]\n&mode_lib->mp.Watermark and &locals->Watermark are\nthe same address. memcpy may lead to unexpected behavior.\n\n[HOW]\nmemmove should be used.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-30T08:15:07Z" diff --git a/advisories/unreviewed/2024/07/GHSA-68vf-xmgr-pxm6/GHSA-68vf-xmgr-pxm6.json b/advisories/unreviewed/2024/07/GHSA-68vf-xmgr-pxm6/GHSA-68vf-xmgr-pxm6.json index a60915579ed..fee14f6518e 100644 --- a/advisories/unreviewed/2024/07/GHSA-68vf-xmgr-pxm6/GHSA-68vf-xmgr-pxm6.json +++ b/advisories/unreviewed/2024/07/GHSA-68vf-xmgr-pxm6/GHSA-68vf-xmgr-pxm6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-68vf-xmgr-pxm6", - "modified": "2024-07-29T18:30:40Z", + "modified": "2024-07-30T21:31:26Z", "published": "2024-07-29T18:30:40Z", "aliases": [ "CVE-2024-42076" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: can: j1939: Initialize unused data in j1939_send_one()\n\nsyzbot reported kernel-infoleak in raw_recvmsg() [1]. j1939_send_one()\ncreates full frame including unused data, but it doesn't initialize\nit. This causes the kernel-infoleak issue. Fix this by initializing\nunused data.\n\n[1]\nBUG: KMSAN: kernel-infoleak in instrument_copy_to_user include/linux/instrumented.h:114 [inline]\nBUG: KMSAN: kernel-infoleak in copy_to_user_iter lib/iov_iter.c:24 [inline]\nBUG: KMSAN: kernel-infoleak in iterate_ubuf include/linux/iov_iter.h:29 [inline]\nBUG: KMSAN: kernel-infoleak in iterate_and_advance2 include/linux/iov_iter.h:245 [inline]\nBUG: KMSAN: kernel-infoleak in iterate_and_advance include/linux/iov_iter.h:271 [inline]\nBUG: KMSAN: kernel-infoleak in _copy_to_iter+0x366/0x2520 lib/iov_iter.c:185\n instrument_copy_to_user include/linux/instrumented.h:114 [inline]\n copy_to_user_iter lib/iov_iter.c:24 [inline]\n iterate_ubuf include/linux/iov_iter.h:29 [inline]\n iterate_and_advance2 include/linux/iov_iter.h:245 [inline]\n iterate_and_advance include/linux/iov_iter.h:271 [inline]\n _copy_to_iter+0x366/0x2520 lib/iov_iter.c:185\n copy_to_iter include/linux/uio.h:196 [inline]\n memcpy_to_msg include/linux/skbuff.h:4113 [inline]\n raw_recvmsg+0x2b8/0x9e0 net/can/raw.c:1008\n sock_recvmsg_nosec net/socket.c:1046 [inline]\n sock_recvmsg+0x2c4/0x340 net/socket.c:1068\n ____sys_recvmsg+0x18a/0x620 net/socket.c:2803\n ___sys_recvmsg+0x223/0x840 net/socket.c:2845\n do_recvmmsg+0x4fc/0xfd0 net/socket.c:2939\n __sys_recvmmsg net/socket.c:3018 [inline]\n __do_sys_recvmmsg net/socket.c:3041 [inline]\n __se_sys_recvmmsg net/socket.c:3034 [inline]\n __x64_sys_recvmmsg+0x397/0x490 net/socket.c:3034\n x64_sys_call+0xf6c/0x3b50 arch/x86/include/generated/asm/syscalls_64.h:300\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xcf/0x1e0 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nUninit was created at:\n slab_post_alloc_hook mm/slub.c:3804 [inline]\n slab_alloc_node mm/slub.c:3845 [inline]\n kmem_cache_alloc_node+0x613/0xc50 mm/slub.c:3888\n kmalloc_reserve+0x13d/0x4a0 net/core/skbuff.c:577\n __alloc_skb+0x35b/0x7a0 net/core/skbuff.c:668\n alloc_skb include/linux/skbuff.h:1313 [inline]\n alloc_skb_with_frags+0xc8/0xbf0 net/core/skbuff.c:6504\n sock_alloc_send_pskb+0xa81/0xbf0 net/core/sock.c:2795\n sock_alloc_send_skb include/net/sock.h:1842 [inline]\n j1939_sk_alloc_skb net/can/j1939/socket.c:878 [inline]\n j1939_sk_send_loop net/can/j1939/socket.c:1142 [inline]\n j1939_sk_sendmsg+0xc0a/0x2730 net/can/j1939/socket.c:1277\n sock_sendmsg_nosec net/socket.c:730 [inline]\n __sock_sendmsg+0x30f/0x380 net/socket.c:745\n ____sys_sendmsg+0x877/0xb60 net/socket.c:2584\n ___sys_sendmsg+0x28d/0x3c0 net/socket.c:2638\n __sys_sendmsg net/socket.c:2667 [inline]\n __do_sys_sendmsg net/socket.c:2676 [inline]\n __se_sys_sendmsg net/socket.c:2674 [inline]\n __x64_sys_sendmsg+0x307/0x4a0 net/socket.c:2674\n x64_sys_call+0xc4b/0x3b50 arch/x86/include/generated/asm/syscalls_64.h:47\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xcf/0x1e0 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nBytes 12-15 of 16 are uninitialized\nMemory access of size 16 starts at ffff888120969690\nData copied to user address 00000000200017c0\n\nCPU: 1 PID: 5050 Comm: syz-executor198 Not tainted 6.9.0-rc5-syzkaller-00031-g71b1543c83d6 #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 03/27/2024", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -49,9 +52,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-908" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T16:15:06Z" diff --git a/advisories/unreviewed/2024/07/GHSA-6xvq-4crp-429f/GHSA-6xvq-4crp-429f.json b/advisories/unreviewed/2024/07/GHSA-6xvq-4crp-429f/GHSA-6xvq-4crp-429f.json index 4c57a198c71..b72bef70be1 100644 --- a/advisories/unreviewed/2024/07/GHSA-6xvq-4crp-429f/GHSA-6xvq-4crp-429f.json +++ b/advisories/unreviewed/2024/07/GHSA-6xvq-4crp-429f/GHSA-6xvq-4crp-429f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6xvq-4crp-429f", - "modified": "2024-07-29T18:30:40Z", + "modified": "2024-07-30T21:31:26Z", "published": "2024-07-29T18:30:40Z", "aliases": [ "CVE-2024-42081" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe/xe_devcoredump: Check NULL before assignments\n\nAssign 'xe_devcoredump_snapshot *' and 'xe_device *' only if\n'coredump' is not NULL.\n\nv2\n- Fix commit messages.\n\nv3\n- Define variables before code.(Ashutosh/Jose)\n\nv4\n- Drop return check for coredump_to_xe. (Jose/Rodrigo)\n\nv5\n- Modify misleading commit message. (Matt)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T16:15:07Z" diff --git a/advisories/unreviewed/2024/07/GHSA-7wph-5wjx-7rgv/GHSA-7wph-5wjx-7rgv.json b/advisories/unreviewed/2024/07/GHSA-7wph-5wjx-7rgv/GHSA-7wph-5wjx-7rgv.json index ffbf5fce382..5cd78e09ba6 100644 --- a/advisories/unreviewed/2024/07/GHSA-7wph-5wjx-7rgv/GHSA-7wph-5wjx-7rgv.json +++ b/advisories/unreviewed/2024/07/GHSA-7wph-5wjx-7rgv/GHSA-7wph-5wjx-7rgv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7wph-5wjx-7rgv", - "modified": "2024-07-29T18:30:40Z", + "modified": "2024-07-30T21:31:26Z", "published": "2024-07-29T18:30:40Z", "aliases": [ "CVE-2024-42079" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ngfs2: Fix NULL pointer dereference in gfs2_log_flush\n\nIn gfs2_jindex_free(), set sdp->sd_jdesc to NULL under the log flush\nlock to provide exclusion against gfs2_log_flush().\n\nIn gfs2_log_flush(), check if sdp->sd_jdesc is non-NULL before\ndereferencing it. Otherwise, we could run into a NULL pointer\ndereference when outstanding glock work races with an unmount\n(glock_work_func -> run_queue -> do_xmote -> inode_go_sync ->\ngfs2_log_flush).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T16:15:07Z" diff --git a/advisories/unreviewed/2024/07/GHSA-8cw4-xx6j-52ph/GHSA-8cw4-xx6j-52ph.json b/advisories/unreviewed/2024/07/GHSA-8cw4-xx6j-52ph/GHSA-8cw4-xx6j-52ph.json index 45f7857bb26..b3e9773feca 100644 --- a/advisories/unreviewed/2024/07/GHSA-8cw4-xx6j-52ph/GHSA-8cw4-xx6j-52ph.json +++ b/advisories/unreviewed/2024/07/GHSA-8cw4-xx6j-52ph/GHSA-8cw4-xx6j-52ph.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-8vxj-86v6-ppgq/GHSA-8vxj-86v6-ppgq.json b/advisories/unreviewed/2024/07/GHSA-8vxj-86v6-ppgq/GHSA-8vxj-86v6-ppgq.json new file mode 100644 index 00000000000..f756649c716 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-8vxj-86v6-ppgq/GHSA-8vxj-86v6-ppgq.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8vxj-86v6-ppgq", + "modified": "2024-07-30T21:31:28Z", + "published": "2024-07-30T21:31:28Z", + "aliases": [ + "CVE-2024-41440" + ], + "details": "A heap buffer overflow in the function png_quantize() of hicolor v0.5.0 allows attackers to cause a Denial of Service (DoS) via a crafted PNG file.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41440" + }, + { + "type": "WEB", + "url": "https://github.com/Helson-S/FuzzyTesting/blob/master/hicolor/heapof-w1-png_quantize-cli-220c32" + }, + { + "type": "WEB", + "url": "https://github.com/Helson-S/FuzzyTesting/blob/master/hicolor/heapof-w1-png_quantize-cli-220c32/poc" + }, + { + "type": "WEB", + "url": "https://github.com/Helson-S/FuzzyTesting/blob/master/hicolor/heapof-w1-png_quantize-cli-220c32/poc/sample18.png" + }, + { + "type": "WEB", + "url": "https://github.com/Helson-S/FuzzyTesting/blob/master/hicolor/heapof-w1-png_quantize-cli-220c32/vulDescription.assets/image-20240530225208577.png" + }, + { + "type": "WEB", + "url": "https://github.com/Helson-S/FuzzyTesting/blob/master/hicolor/heapof-w1-png_quantize-cli-220c32/vulDescription.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-30T19:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-93xv-w432-6pgp/GHSA-93xv-w432-6pgp.json b/advisories/unreviewed/2024/07/GHSA-93xv-w432-6pgp/GHSA-93xv-w432-6pgp.json new file mode 100644 index 00000000000..bb902dc1855 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-93xv-w432-6pgp/GHSA-93xv-w432-6pgp.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-93xv-w432-6pgp", + "modified": "2024-07-30T21:31:27Z", + "published": "2024-07-30T21:31:27Z", + "aliases": [ + "CVE-2024-5249" + ], + "details": "In versions of Akana API Platform prior to 2024.1.0, SAML tokens can be replayed.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5249" + }, + { + "type": "WEB", + "url": "https://portal.perforce.com/s/detail/a91PA000001SUH7YAO" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-294" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-30T19:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-9qp4-rw2q-rx7r/GHSA-9qp4-rw2q-rx7r.json b/advisories/unreviewed/2024/07/GHSA-9qp4-rw2q-rx7r/GHSA-9qp4-rw2q-rx7r.json index 25365dff7c6..34ca0f26711 100644 --- a/advisories/unreviewed/2024/07/GHSA-9qp4-rw2q-rx7r/GHSA-9qp4-rw2q-rx7r.json +++ b/advisories/unreviewed/2024/07/GHSA-9qp4-rw2q-rx7r/GHSA-9qp4-rw2q-rx7r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9qp4-rw2q-rx7r", - "modified": "2024-07-29T18:30:39Z", + "modified": "2024-07-30T21:31:26Z", "published": "2024-07-29T18:30:39Z", "aliases": [ "CVE-2024-42068" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Take return from set_memory_ro() into account with bpf_prog_lock_ro()\n\nset_memory_ro() can fail, leaving memory unprotected.\n\nCheck its return and take it into account as an error.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-252" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T16:15:06Z" diff --git a/advisories/unreviewed/2024/07/GHSA-c3g7-jwpr-vrhq/GHSA-c3g7-jwpr-vrhq.json b/advisories/unreviewed/2024/07/GHSA-c3g7-jwpr-vrhq/GHSA-c3g7-jwpr-vrhq.json index 31c4e0d4676..03b2b8238d6 100644 --- a/advisories/unreviewed/2024/07/GHSA-c3g7-jwpr-vrhq/GHSA-c3g7-jwpr-vrhq.json +++ b/advisories/unreviewed/2024/07/GHSA-c3g7-jwpr-vrhq/GHSA-c3g7-jwpr-vrhq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c3g7-jwpr-vrhq", - "modified": "2024-07-29T18:30:40Z", + "modified": "2024-07-30T21:31:26Z", "published": "2024-07-29T18:30:40Z", "aliases": [ "CVE-2024-42073" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmlxsw: spectrum_buffers: Fix memory corruptions on Spectrum-4 systems\n\nThe following two shared buffer operations make use of the Shared Buffer\nStatus Register (SBSR):\n\n # devlink sb occupancy snapshot pci/0000:01:00.0\n # devlink sb occupancy clearmax pci/0000:01:00.0\n\nThe register has two masks of 256 bits to denote on which ingress /\negress ports the register should operate on. Spectrum-4 has more than\n256 ports, so the register was extended by cited commit with a new\n'port_page' field.\n\nHowever, when filling the register's payload, the driver specifies the\nports as absolute numbers and not relative to the first port of the port\npage, resulting in memory corruptions [1].\n\nFix by specifying the ports relative to the first port of the port page.\n\n[1]\nBUG: KASAN: slab-use-after-free in mlxsw_sp_sb_occ_snapshot+0xb6d/0xbc0\nRead of size 1 at addr ffff8881068cb00f by task devlink/1566\n[...]\nCall Trace:\n \n dump_stack_lvl+0xc6/0x120\n print_report+0xce/0x670\n kasan_report+0xd7/0x110\n mlxsw_sp_sb_occ_snapshot+0xb6d/0xbc0\n mlxsw_devlink_sb_occ_snapshot+0x75/0xb0\n devlink_nl_sb_occ_snapshot_doit+0x1f9/0x2a0\n genl_family_rcv_msg_doit+0x20c/0x300\n genl_rcv_msg+0x567/0x800\n netlink_rcv_skb+0x170/0x450\n genl_rcv+0x2d/0x40\n netlink_unicast+0x547/0x830\n netlink_sendmsg+0x8d4/0xdb0\n __sys_sendto+0x49b/0x510\n __x64_sys_sendto+0xe5/0x1c0\n do_syscall_64+0xc1/0x1d0\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n[...]\nAllocated by task 1:\n kasan_save_stack+0x33/0x60\n kasan_save_track+0x14/0x30\n __kasan_kmalloc+0x8f/0xa0\n copy_verifier_state+0xbc2/0xfb0\n do_check_common+0x2c51/0xc7e0\n bpf_check+0x5107/0x9960\n bpf_prog_load+0xf0e/0x2690\n __sys_bpf+0x1a61/0x49d0\n __x64_sys_bpf+0x7d/0xc0\n do_syscall_64+0xc1/0x1d0\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nFreed by task 1:\n kasan_save_stack+0x33/0x60\n kasan_save_track+0x14/0x30\n kasan_save_free_info+0x3b/0x60\n poison_slab_object+0x109/0x170\n __kasan_slab_free+0x14/0x30\n kfree+0xca/0x2b0\n free_verifier_state+0xce/0x270\n do_check_common+0x4828/0xc7e0\n bpf_check+0x5107/0x9960\n bpf_prog_load+0xf0e/0x2690\n __sys_bpf+0x1a61/0x49d0\n __x64_sys_bpf+0x7d/0xc0\n do_syscall_64+0xc1/0x1d0\n entry_SYSCALL_64_after_hwframe+0x77/0x7f", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T16:15:06Z" diff --git a/advisories/unreviewed/2024/07/GHSA-c4hf-x9gr-w5f8/GHSA-c4hf-x9gr-w5f8.json b/advisories/unreviewed/2024/07/GHSA-c4hf-x9gr-w5f8/GHSA-c4hf-x9gr-w5f8.json index 7a64c95576c..99492c87c24 100644 --- a/advisories/unreviewed/2024/07/GHSA-c4hf-x9gr-w5f8/GHSA-c4hf-x9gr-w5f8.json +++ b/advisories/unreviewed/2024/07/GHSA-c4hf-x9gr-w5f8/GHSA-c4hf-x9gr-w5f8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c4hf-x9gr-w5f8", - "modified": "2024-07-30T09:32:04Z", + "modified": "2024-07-30T21:31:27Z", "published": "2024-07-30T09:32:04Z", "aliases": [ "CVE-2024-42226" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: xhci: prevent potential failure in handle_tx_event() for Transfer events without TRB\n\nSome transfer events don't always point to a TRB, and consequently don't\nhave a endpoint ring. In these cases, function handle_tx_event() should\nnot proceed, because if 'ep->skip' is set, the pointer to the endpoint\nring is used.\n\nTo prevent a potential failure and make the code logical, return after\nchecking the completion code for a Transfer event without TRBs.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-30T08:15:07Z" diff --git a/advisories/unreviewed/2024/07/GHSA-cfqx-qcxx-3hwg/GHSA-cfqx-qcxx-3hwg.json b/advisories/unreviewed/2024/07/GHSA-cfqx-qcxx-3hwg/GHSA-cfqx-qcxx-3hwg.json index 629d643f5f7..b7a48e1b2f4 100644 --- a/advisories/unreviewed/2024/07/GHSA-cfqx-qcxx-3hwg/GHSA-cfqx-qcxx-3hwg.json +++ b/advisories/unreviewed/2024/07/GHSA-cfqx-qcxx-3hwg/GHSA-cfqx-qcxx-3hwg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cfqx-qcxx-3hwg", - "modified": "2024-07-29T18:30:40Z", + "modified": "2024-07-30T21:31:26Z", "published": "2024-07-29T18:30:40Z", "aliases": [ "CVE-2024-42077" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: fix DIO failure due to insufficient transaction credits\n\nThe code in ocfs2_dio_end_io_write() estimates number of necessary\ntransaction credits using ocfs2_calc_extend_credits(). This however does\nnot take into account that the IO could be arbitrarily large and can\ncontain arbitrary number of extents.\n\nExtent tree manipulations do often extend the current transaction but not\nin all of the cases. For example if we have only single block extents in\nthe tree, ocfs2_mark_extent_written() will end up calling\nocfs2_replace_extent_rec() all the time and we will never extend the\ncurrent transaction and eventually exhaust all the transaction credits if\nthe IO contains many single block extents. Once that happens a\nWARN_ON(jbd2_handle_buffer_credits(handle) <= 0) is triggered in\njbd2_journal_dirty_metadata() and subsequently OCFS2 aborts in response to\nthis error. This was actually triggered by one of our customers on a\nheavily fragmented OCFS2 filesystem.\n\nTo fix the issue make sure the transaction always has enough credits for\none extent insert before each call of ocfs2_mark_extent_written().\n\nHeming Zhao said:\n\n------\nPANIC: \"Kernel panic - not syncing: OCFS2: (device dm-1): panic forced after error\"\n\nPID: xxx TASK: xxxx CPU: 5 COMMAND: \"SubmitThread-CA\"\n #0 machine_kexec at ffffffff8c069932\n #1 __crash_kexec at ffffffff8c1338fa\n #2 panic at ffffffff8c1d69b9\n #3 ocfs2_handle_error at ffffffffc0c86c0c [ocfs2]\n #4 __ocfs2_abort at ffffffffc0c88387 [ocfs2]\n #5 ocfs2_journal_dirty at ffffffffc0c51e98 [ocfs2]\n #6 ocfs2_split_extent at ffffffffc0c27ea3 [ocfs2]\n #7 ocfs2_change_extent_flag at ffffffffc0c28053 [ocfs2]\n #8 ocfs2_mark_extent_written at ffffffffc0c28347 [ocfs2]\n #9 ocfs2_dio_end_io_write at ffffffffc0c2bef9 [ocfs2]\n#10 ocfs2_dio_end_io at ffffffffc0c2c0f5 [ocfs2]\n#11 dio_complete at ffffffff8c2b9fa7\n#12 do_blockdev_direct_IO at ffffffff8c2bc09f\n#13 ocfs2_direct_IO at ffffffffc0c2b653 [ocfs2]\n#14 generic_file_direct_write at ffffffff8c1dcf14\n#15 __generic_file_write_iter at ffffffff8c1dd07b\n#16 ocfs2_file_write_iter at ffffffffc0c49f1f [ocfs2]\n#17 aio_write at ffffffff8c2cc72e\n#18 kmem_cache_alloc at ffffffff8c248dde\n#19 do_io_submit at ffffffff8c2ccada\n#20 do_syscall_64 at ffffffff8c004984\n#21 entry_SYSCALL_64_after_hwframe at ffffffff8c8000ba", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -47,7 +50,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T16:15:07Z" diff --git a/advisories/unreviewed/2024/07/GHSA-f2w3-phmv-5298/GHSA-f2w3-phmv-5298.json b/advisories/unreviewed/2024/07/GHSA-f2w3-phmv-5298/GHSA-f2w3-phmv-5298.json index dd14af84a29..21ca89ddeb7 100644 --- a/advisories/unreviewed/2024/07/GHSA-f2w3-phmv-5298/GHSA-f2w3-phmv-5298.json +++ b/advisories/unreviewed/2024/07/GHSA-f2w3-phmv-5298/GHSA-f2w3-phmv-5298.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f2w3-phmv-5298", - "modified": "2024-07-29T18:30:40Z", + "modified": "2024-07-30T21:31:26Z", "published": "2024-07-29T18:30:40Z", "aliases": [ "CVE-2024-42075" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix remap of arena.\n\nThe bpf arena logic didn't account for mremap operation. Add a refcnt for\nmultiple mmap events to prevent use-after-free in arena_vm_close.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T16:15:06Z" diff --git a/advisories/unreviewed/2024/07/GHSA-f53v-x4rw-42rf/GHSA-f53v-x4rw-42rf.json b/advisories/unreviewed/2024/07/GHSA-f53v-x4rw-42rf/GHSA-f53v-x4rw-42rf.json index de59200e00e..c5d7f1c0917 100644 --- a/advisories/unreviewed/2024/07/GHSA-f53v-x4rw-42rf/GHSA-f53v-x4rw-42rf.json +++ b/advisories/unreviewed/2024/07/GHSA-f53v-x4rw-42rf/GHSA-f53v-x4rw-42rf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f53v-x4rw-42rf", - "modified": "2024-07-29T18:30:40Z", + "modified": "2024-07-30T21:31:26Z", "published": "2024-07-29T18:30:40Z", "aliases": [ "CVE-2024-42074" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: amd: acp: add a null check for chip_pdev structure\n\nWhen acp platform device creation is skipped, chip->chip_pdev value will\nremain NULL. Add NULL check for chip->chip_pdev structure in\nsnd_acp_resume() function to avoid null pointer dereference.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T16:15:06Z" diff --git a/advisories/unreviewed/2024/07/GHSA-fgq5-vx4r-rg7c/GHSA-fgq5-vx4r-rg7c.json b/advisories/unreviewed/2024/07/GHSA-fgq5-vx4r-rg7c/GHSA-fgq5-vx4r-rg7c.json new file mode 100644 index 00000000000..f827312dc91 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-fgq5-vx4r-rg7c/GHSA-fgq5-vx4r-rg7c.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fgq5-vx4r-rg7c", + "modified": "2024-07-30T21:31:29Z", + "published": "2024-07-30T21:31:29Z", + "aliases": [ + "CVE-2024-38983" + ], + "details": "Prototype Pollution in alykoshin mini-deep-assign v0.0.8 allows an attacker to execute arbitrary code or cause a Denial of Service (DoS) and cause other impacts via the _assign() method at (/lib/index.js:91)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38983" + }, + { + "type": "WEB", + "url": "https://gist.github.com/mestrtee/f82d0c3a8fe3a125f06425caef5d22ed" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-30T21:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-gxw4-wqj9-7x83/GHSA-gxw4-wqj9-7x83.json b/advisories/unreviewed/2024/07/GHSA-gxw4-wqj9-7x83/GHSA-gxw4-wqj9-7x83.json new file mode 100644 index 00000000000..935b87e1bbf --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-gxw4-wqj9-7x83/GHSA-gxw4-wqj9-7x83.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gxw4-wqj9-7x83", + "modified": "2024-07-30T21:31:29Z", + "published": "2024-07-30T21:31:29Z", + "aliases": [ + "CVE-2024-39011" + ], + "details": "Prototype Pollution in chargeover redoc v2.0.9-rc.69 allows attackers to execute arbitrary code or cause a Denial of Service (DoS) and cause other impacts via the function mergeObjects.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39011" + }, + { + "type": "WEB", + "url": "https://gist.github.com/mestrtee/693ef1c8b0a5ff1ae19f253381711f3e" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-30T20:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-h4gx-rc62-wcvc/GHSA-h4gx-rc62-wcvc.json b/advisories/unreviewed/2024/07/GHSA-h4gx-rc62-wcvc/GHSA-h4gx-rc62-wcvc.json new file mode 100644 index 00000000000..2a676386f53 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-h4gx-rc62-wcvc/GHSA-h4gx-rc62-wcvc.json @@ -0,0 +1,55 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h4gx-rc62-wcvc", + "modified": "2024-07-30T21:31:27Z", + "published": "2024-07-30T21:31:27Z", + "aliases": [ + "CVE-2024-41439" + ], + "details": "A heap buffer overflow in the function cp_block() (/vendor/cute_png.h) of hicolor v0.5.0 allows attackers to cause a Denial of Service (DoS) via a crafted PNG file.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41439" + }, + { + "type": "WEB", + "url": "https://github.com/Helson-S/FuzzyTesting/blob/master/hicolor/heapof-w98-cp_block-5c0-cute_png-642c5" + }, + { + "type": "WEB", + "url": "https://github.com/Helson-S/FuzzyTesting/blob/master/hicolor/heapof-w98-cp_block-5c0-cute_png-642c5/poc" + }, + { + "type": "WEB", + "url": "https://github.com/Helson-S/FuzzyTesting/blob/master/hicolor/heapof-w98-cp_block-5c0-cute_png-642c5/poc/sample13.png" + }, + { + "type": "WEB", + "url": "https://github.com/Helson-S/FuzzyTesting/blob/master/hicolor/heapof-w98-cp_block-5c0-cute_png-642c5/vulDescription.assets/image-20240530192505615.png" + }, + { + "type": "WEB", + "url": "https://github.com/Helson-S/FuzzyTesting/blob/master/hicolor/heapof-w98-cp_block-5c0-cute_png-642c5/vulDescription.assets/image-20240531002753478.png" + }, + { + "type": "WEB", + "url": "https://github.com/Helson-S/FuzzyTesting/blob/master/hicolor/heapof-w98-cp_block-5c0-cute_png-642c5/vulDescription.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-30T19:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-hm79-2wxc-w993/GHSA-hm79-2wxc-w993.json b/advisories/unreviewed/2024/07/GHSA-hm79-2wxc-w993/GHSA-hm79-2wxc-w993.json new file mode 100644 index 00000000000..66fa3e372a2 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-hm79-2wxc-w993/GHSA-hm79-2wxc-w993.json @@ -0,0 +1,55 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hm79-2wxc-w993", + "modified": "2024-07-30T21:31:28Z", + "published": "2024-07-30T21:31:27Z", + "aliases": [ + "CVE-2024-41443" + ], + "details": "A stack overflow in the function cp_dynamic() (/vendor/cute_png.h) of hicolor v0.5.0 allows attackers to cause a Denial of Service (DoS) via a crafted PNG file.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41443" + }, + { + "type": "WEB", + "url": "https://github.com/Helson-S/FuzzyTesting/blob/master/hicolor/stkof-w133-cp_dynamic-cute_png-603" + }, + { + "type": "WEB", + "url": "https://github.com/Helson-S/FuzzyTesting/blob/master/hicolor/stkof-w133-cp_dynamic-cute_png-603/poc" + }, + { + "type": "WEB", + "url": "https://github.com/Helson-S/FuzzyTesting/blob/master/hicolor/stkof-w133-cp_dynamic-cute_png-603/poc/sample16.png" + }, + { + "type": "WEB", + "url": "https://github.com/Helson-S/FuzzyTesting/blob/master/hicolor/stkof-w133-cp_dynamic-cute_png-603/vulDescription.assets/image-20240530223831738.png" + }, + { + "type": "WEB", + "url": "https://github.com/Helson-S/FuzzyTesting/blob/master/hicolor/stkof-w133-cp_dynamic-cute_png-603/vulDescription.assets/image-20240530223921086.png" + }, + { + "type": "WEB", + "url": "https://github.com/Helson-S/FuzzyTesting/blob/master/hicolor/stkof-w133-cp_dynamic-cute_png-603/vulDescription.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-30T19:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-hmvx-mw63-jvg7/GHSA-hmvx-mw63-jvg7.json b/advisories/unreviewed/2024/07/GHSA-hmvx-mw63-jvg7/GHSA-hmvx-mw63-jvg7.json index b19e52bc414..c159726ccef 100644 --- a/advisories/unreviewed/2024/07/GHSA-hmvx-mw63-jvg7/GHSA-hmvx-mw63-jvg7.json +++ b/advisories/unreviewed/2024/07/GHSA-hmvx-mw63-jvg7/GHSA-hmvx-mw63-jvg7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hmvx-mw63-jvg7", - "modified": "2024-07-30T09:32:04Z", + "modified": "2024-07-30T21:31:27Z", "published": "2024-07-30T09:32:04Z", "aliases": [ "CVE-2024-42231" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: zoned: fix calc_available_free_space() for zoned mode\n\ncalc_available_free_space() returns the total size of metadata (or\nsystem) block groups, which can be allocated from unallocated disk\nspace. The logic is wrong on zoned mode in two places.\n\nFirst, the calculation of data_chunk_size is wrong. We always allocate\none zone as one chunk, and no partial allocation of a zone. So, we\nshould use zone_size (= data_sinfo->chunk_size) as it is.\n\nSecond, the result \"avail\" may not be zone aligned. Since we always\nallocate one zone as one chunk on zoned mode, returning non-zone size\naligned bytes will result in less pressure on the async metadata reclaim\nprocess.\n\nThis is serious for the nearly full state with a large zone size device.\nAllowing over-commit too much will result in less async reclaim work and\nend up in ENOSPC. We can align down to the zone size to avoid that.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-682" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-30T08:15:08Z" diff --git a/advisories/unreviewed/2024/07/GHSA-hwc3-9p27-c4j6/GHSA-hwc3-9p27-c4j6.json b/advisories/unreviewed/2024/07/GHSA-hwc3-9p27-c4j6/GHSA-hwc3-9p27-c4j6.json index 1808f874bee..f977ec55bef 100644 --- a/advisories/unreviewed/2024/07/GHSA-hwc3-9p27-c4j6/GHSA-hwc3-9p27-c4j6.json +++ b/advisories/unreviewed/2024/07/GHSA-hwc3-9p27-c4j6/GHSA-hwc3-9p27-c4j6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hwc3-9p27-c4j6", - "modified": "2024-07-29T18:30:40Z", + "modified": "2024-07-30T21:31:26Z", "published": "2024-07-29T18:30:40Z", "aliases": [ "CVE-2024-42072" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix may_goto with negative offset.\n\nZac's syzbot crafted a bpf prog that exposed two bugs in may_goto.\nThe 1st bug is the way may_goto is patched. When offset is negative\nit should be patched differently.\nThe 2nd bug is in the verifier:\nwhen current state may_goto_depth is equal to visited state may_goto_depth\nit means there is an actual infinite loop. It's not correct to prune\nexploration of the program at this point.\nNote, that this check doesn't limit the program to only one may_goto insn,\nsince 2nd and any further may_goto will increment may_goto_depth only\nin the queued state pushed for future exploration. The current state\nwill have may_goto_depth == 0 regardless of number of may_goto insns\nand the verifier has to explore the program until bpf_exit.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T16:15:06Z" diff --git a/advisories/unreviewed/2024/07/GHSA-hx5h-3r35-f985/GHSA-hx5h-3r35-f985.json b/advisories/unreviewed/2024/07/GHSA-hx5h-3r35-f985/GHSA-hx5h-3r35-f985.json index 04d38f17ee9..d7dfeb54001 100644 --- a/advisories/unreviewed/2024/07/GHSA-hx5h-3r35-f985/GHSA-hx5h-3r35-f985.json +++ b/advisories/unreviewed/2024/07/GHSA-hx5h-3r35-f985/GHSA-hx5h-3r35-f985.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-j2f8-8cqp-fv4p/GHSA-j2f8-8cqp-fv4p.json b/advisories/unreviewed/2024/07/GHSA-j2f8-8cqp-fv4p/GHSA-j2f8-8cqp-fv4p.json new file mode 100644 index 00000000000..636c2221f57 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-j2f8-8cqp-fv4p/GHSA-j2f8-8cqp-fv4p.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j2f8-8cqp-fv4p", + "modified": "2024-07-30T21:31:29Z", + "published": "2024-07-30T21:31:29Z", + "aliases": [ + "CVE-2024-5901" + ], + "details": "The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Grid widget in all versions up to, and including, 1.62.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5901" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/so-widgets-bundle/tags/1.62.0/widgets/image-grid/image-grid.php#L282" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/so-widgets-bundle/tags/1.62.0/widgets/image-grid/tpl/default.php#L28" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/0045c5a4-0807-4e89-8639-0802e54ce6ab?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-30T21:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-jg37-q3vp-38x3/GHSA-jg37-q3vp-38x3.json b/advisories/unreviewed/2024/07/GHSA-jg37-q3vp-38x3/GHSA-jg37-q3vp-38x3.json index 0e198b4e9d7..fe182b02cee 100644 --- a/advisories/unreviewed/2024/07/GHSA-jg37-q3vp-38x3/GHSA-jg37-q3vp-38x3.json +++ b/advisories/unreviewed/2024/07/GHSA-jg37-q3vp-38x3/GHSA-jg37-q3vp-38x3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jg37-q3vp-38x3", - "modified": "2024-07-29T18:30:40Z", + "modified": "2024-07-30T21:31:26Z", "published": "2024-07-29T18:30:40Z", "aliases": [ "CVE-2024-42078" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: initialise nfsd_info.mutex early.\n\nnfsd_info.mutex can be dereferenced by svc_pool_stats_start()\nimmediately after the new netns is created. Currently this can\ntrigger an oops.\n\nMove the initialisation earlier before it can possibly be dereferenced.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-665" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T16:15:07Z" diff --git a/advisories/unreviewed/2024/07/GHSA-m5g2-rqpc-h5hr/GHSA-m5g2-rqpc-h5hr.json b/advisories/unreviewed/2024/07/GHSA-m5g2-rqpc-h5hr/GHSA-m5g2-rqpc-h5hr.json index fb26fd0fc05..ac31c319431 100644 --- a/advisories/unreviewed/2024/07/GHSA-m5g2-rqpc-h5hr/GHSA-m5g2-rqpc-h5hr.json +++ b/advisories/unreviewed/2024/07/GHSA-m5g2-rqpc-h5hr/GHSA-m5g2-rqpc-h5hr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m5g2-rqpc-h5hr", - "modified": "2024-07-30T09:32:04Z", + "modified": "2024-07-30T21:31:27Z", "published": "2024-07-30T09:32:04Z", "aliases": [ "CVE-2024-42229" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: aead,cipher - zeroize key buffer after use\n\nI.G 9.7.B for FIPS 140-3 specifies that variables temporarily holding\ncryptographic information should be zeroized once they are no longer\nneeded. Accomplish this by using kfree_sensitive for buffers that\npreviously held the private key.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -47,7 +50,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-30T08:15:08Z" diff --git a/advisories/unreviewed/2024/07/GHSA-mhjg-j5hq-m4p7/GHSA-mhjg-j5hq-m4p7.json b/advisories/unreviewed/2024/07/GHSA-mhjg-j5hq-m4p7/GHSA-mhjg-j5hq-m4p7.json index 1ef99544a39..066b1c8eae8 100644 --- a/advisories/unreviewed/2024/07/GHSA-mhjg-j5hq-m4p7/GHSA-mhjg-j5hq-m4p7.json +++ b/advisories/unreviewed/2024/07/GHSA-mhjg-j5hq-m4p7/GHSA-mhjg-j5hq-m4p7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mhjg-j5hq-m4p7", - "modified": "2024-07-30T09:32:04Z", + "modified": "2024-07-30T21:31:27Z", "published": "2024-07-30T09:32:04Z", "aliases": [ "CVE-2024-42228" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: Using uninitialized value *size when calling amdgpu_vce_cs_reloc\n\nInitialize the size before calling amdgpu_vce_cs_reloc, such as case 0x03000001.\nV2: To really improve the handling we would actually\n need to have a separate value of 0xffffffff.(Christian)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-908" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-30T08:15:07Z" diff --git a/advisories/unreviewed/2024/07/GHSA-mj9h-qp8g-g746/GHSA-mj9h-qp8g-g746.json b/advisories/unreviewed/2024/07/GHSA-mj9h-qp8g-g746/GHSA-mj9h-qp8g-g746.json new file mode 100644 index 00000000000..c18dd9abe89 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-mj9h-qp8g-g746/GHSA-mj9h-qp8g-g746.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mj9h-qp8g-g746", + "modified": "2024-07-30T21:31:28Z", + "published": "2024-07-30T21:31:28Z", + "aliases": [ + "CVE-2024-39010" + ], + "details": "chase-moskal snapstate v0.0.9 was discovered to contain a prototype pollution via the function attemptNestedProperty. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39010" + }, + { + "type": "WEB", + "url": "https://gist.github.com/mestrtee/af7a746df91ab5e944bd7a186816c262" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-30T20:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-mjjp-275q-ww9c/GHSA-mjjp-275q-ww9c.json b/advisories/unreviewed/2024/07/GHSA-mjjp-275q-ww9c/GHSA-mjjp-275q-ww9c.json new file mode 100644 index 00000000000..7bf58b21847 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-mjjp-275q-ww9c/GHSA-mjjp-275q-ww9c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mjjp-275q-ww9c", + "modified": "2024-07-30T21:31:27Z", + "published": "2024-07-30T21:31:27Z", + "aliases": [ + "CVE-2024-5250" + ], + "details": "In versions of Akana API Platform prior to 2024.1.0 overly verbose errors can be found in SAML integrations", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5250" + }, + { + "type": "WEB", + "url": "https://portal.perforce.com/s/detail/a91PA000001SUIjYAO" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-209" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-30T19:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-p649-hp44-fr85/GHSA-p649-hp44-fr85.json b/advisories/unreviewed/2024/07/GHSA-p649-hp44-fr85/GHSA-p649-hp44-fr85.json index c8c49dc4d47..1f8750eec27 100644 --- a/advisories/unreviewed/2024/07/GHSA-p649-hp44-fr85/GHSA-p649-hp44-fr85.json +++ b/advisories/unreviewed/2024/07/GHSA-p649-hp44-fr85/GHSA-p649-hp44-fr85.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p649-hp44-fr85", - "modified": "2024-07-29T18:30:40Z", + "modified": "2024-07-30T21:31:26Z", "published": "2024-07-29T18:30:40Z", "aliases": [ "CVE-2024-42082" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nxdp: Remove WARN() from __xdp_reg_mem_model()\n\nsyzkaller reports a warning in __xdp_reg_mem_model().\n\nThe warning occurs only if __mem_id_init_hash_table() returns an error. It\nreturns the error in two cases:\n\n 1. memory allocation fails;\n 2. rhashtable_init() fails when some fields of rhashtable_params\n struct are not initialized properly.\n\nThe second case cannot happen since there is a static const rhashtable_params\nstruct with valid fields. So, warning is only triggered when there is a\nproblem with memory allocation.\n\nThus, there is no sense in using WARN() to handle this error and it can be\nsafely removed.\n\nWARNING: CPU: 0 PID: 5065 at net/core/xdp.c:299 __xdp_reg_mem_model+0x2d9/0x650 net/core/xdp.c:299\n\nCPU: 0 PID: 5065 Comm: syz-executor883 Not tainted 6.8.0-syzkaller-05271-gf99c5f563c17 #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 03/27/2024\nRIP: 0010:__xdp_reg_mem_model+0x2d9/0x650 net/core/xdp.c:299\n\nCall Trace:\n xdp_reg_mem_model+0x22/0x40 net/core/xdp.c:344\n xdp_test_run_setup net/bpf/test_run.c:188 [inline]\n bpf_test_run_xdp_live+0x365/0x1e90 net/bpf/test_run.c:377\n bpf_prog_test_run_xdp+0x813/0x11b0 net/bpf/test_run.c:1267\n bpf_prog_test_run+0x33a/0x3b0 kernel/bpf/syscall.c:4240\n __sys_bpf+0x48d/0x810 kernel/bpf/syscall.c:5649\n __do_sys_bpf kernel/bpf/syscall.c:5738 [inline]\n __se_sys_bpf kernel/bpf/syscall.c:5736 [inline]\n __x64_sys_bpf+0x7c/0x90 kernel/bpf/syscall.c:5736\n do_syscall_64+0xfb/0x240\n entry_SYSCALL_64_after_hwframe+0x6d/0x75\n\nFound by Linux Verification Center (linuxtesting.org) with syzkaller.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-770" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T16:15:07Z" diff --git a/advisories/unreviewed/2024/07/GHSA-qf7q-7m3q-4gg2/GHSA-qf7q-7m3q-4gg2.json b/advisories/unreviewed/2024/07/GHSA-qf7q-7m3q-4gg2/GHSA-qf7q-7m3q-4gg2.json index 0f64e4812a2..f5c2b4f7bc2 100644 --- a/advisories/unreviewed/2024/07/GHSA-qf7q-7m3q-4gg2/GHSA-qf7q-7m3q-4gg2.json +++ b/advisories/unreviewed/2024/07/GHSA-qf7q-7m3q-4gg2/GHSA-qf7q-7m3q-4gg2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qf7q-7m3q-4gg2", - "modified": "2024-07-30T09:32:04Z", + "modified": "2024-07-30T21:31:27Z", "published": "2024-07-30T09:32:04Z", "aliases": [ "CVE-2024-42230" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\npowerpc/pseries: Fix scv instruction crash with kexec\n\nkexec on pseries disables AIL (reloc_on_exc), required for scv\ninstruction support, before other CPUs have been shut down. This means\nthey can execute scv instructions after AIL is disabled, which causes an\ninterrupt at an unexpected entry location that crashes the kernel.\n\nChange the kexec sequence to disable AIL after other CPUs have been\nbrought down.\n\nAs a refresher, the real-mode scv interrupt vector is 0x17000, and the\nfixed-location head code probably couldn't easily deal with implementing\nsuch high addresses so it was just decided not to support that interrupt\nat all.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-30T08:15:08Z" diff --git a/advisories/unreviewed/2024/07/GHSA-qvjc-6j6m-p7gx/GHSA-qvjc-6j6m-p7gx.json b/advisories/unreviewed/2024/07/GHSA-qvjc-6j6m-p7gx/GHSA-qvjc-6j6m-p7gx.json index 5d722bc213c..1a1ccc73169 100644 --- a/advisories/unreviewed/2024/07/GHSA-qvjc-6j6m-p7gx/GHSA-qvjc-6j6m-p7gx.json +++ b/advisories/unreviewed/2024/07/GHSA-qvjc-6j6m-p7gx/GHSA-qvjc-6j6m-p7gx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qvjc-6j6m-p7gx", - "modified": "2024-07-29T18:30:39Z", + "modified": "2024-07-30T21:31:25Z", "published": "2024-07-29T18:30:39Z", "aliases": [ "CVE-2024-42065" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe: Add a NULL check in xe_ttm_stolen_mgr_init\n\nAdd an explicit check to ensure that the mgr is not NULL.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T16:15:06Z" diff --git a/advisories/unreviewed/2024/07/GHSA-rxwh-225r-76q6/GHSA-rxwh-225r-76q6.json b/advisories/unreviewed/2024/07/GHSA-rxwh-225r-76q6/GHSA-rxwh-225r-76q6.json index 0a8b72d9dd5..f23deb20091 100644 --- a/advisories/unreviewed/2024/07/GHSA-rxwh-225r-76q6/GHSA-rxwh-225r-76q6.json +++ b/advisories/unreviewed/2024/07/GHSA-rxwh-225r-76q6/GHSA-rxwh-225r-76q6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rxwh-225r-76q6", - "modified": "2024-07-29T18:30:40Z", + "modified": "2024-07-30T21:31:26Z", "published": "2024-07-29T18:30:40Z", "aliases": [ "CVE-2024-42071" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nionic: use dev_consume_skb_any outside of napi\n\nIf we're not in a NAPI softirq context, we need to be careful\nabout how we call napi_consume_skb(), specifically we need to\ncall it with budget==0 to signal to it that we're not in a\nsafe context.\n\nThis was found while running some configuration stress testing\nof traffic and a change queue config loop running, and this\ncurious note popped out:\n\n[ 4371.402645] BUG: using smp_processor_id() in preemptible [00000000] code: ethtool/20545\n[ 4371.402897] caller is napi_skb_cache_put+0x16/0x80\n[ 4371.403120] CPU: 25 PID: 20545 Comm: ethtool Kdump: loaded Tainted: G OE 6.10.0-rc3-netnext+ #8\n[ 4371.403302] Hardware name: HPE ProLiant DL360 Gen10/ProLiant DL360 Gen10, BIOS U32 01/23/2021\n[ 4371.403460] Call Trace:\n[ 4371.403613] \n[ 4371.403758] dump_stack_lvl+0x4f/0x70\n[ 4371.403904] check_preemption_disabled+0xc1/0xe0\n[ 4371.404051] napi_skb_cache_put+0x16/0x80\n[ 4371.404199] ionic_tx_clean+0x18a/0x240 [ionic]\n[ 4371.404354] ionic_tx_cq_service+0xc4/0x200 [ionic]\n[ 4371.404505] ionic_tx_flush+0x15/0x70 [ionic]\n[ 4371.404653] ? ionic_lif_qcq_deinit.isra.23+0x5b/0x70 [ionic]\n[ 4371.404805] ionic_txrx_deinit+0x71/0x190 [ionic]\n[ 4371.404956] ionic_reconfigure_queues+0x5f5/0xff0 [ionic]\n[ 4371.405111] ionic_set_ringparam+0x2e8/0x3e0 [ionic]\n[ 4371.405265] ethnl_set_rings+0x1f1/0x300\n[ 4371.405418] ethnl_default_set_doit+0xbb/0x160\n[ 4371.405571] genl_family_rcv_msg_doit+0xff/0x130\n\t[...]\n\nI found that ionic_tx_clean() calls napi_consume_skb() which calls\nnapi_skb_cache_put(), but before that last call is the note\n /* Zero budget indicate non-NAPI context called us, like netpoll */\nand\n DEBUG_NET_WARN_ON_ONCE(!in_softirq());\n\nThose are pretty big hints that we're doing it wrong. We can pass a\ncontext hint down through the calls to let ionic_tx_clean() know what\nwe're doing so it can call napi_consume_skb() correctly.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-834" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T16:15:06Z" diff --git a/advisories/unreviewed/2024/07/GHSA-v7qg-qfrr-c59x/GHSA-v7qg-qfrr-c59x.json b/advisories/unreviewed/2024/07/GHSA-v7qg-qfrr-c59x/GHSA-v7qg-qfrr-c59x.json new file mode 100644 index 00000000000..53db5cab00a --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-v7qg-qfrr-c59x/GHSA-v7qg-qfrr-c59x.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v7qg-qfrr-c59x", + "modified": "2024-07-30T21:31:28Z", + "published": "2024-07-30T21:31:28Z", + "aliases": [ + "CVE-2024-38984" + ], + "details": "Prototype Pollution in lukebond json-override 0.2.0 allows attackers to to execute arbitrary code or cause a Denial of Service (DoS) via the __proto__ property.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38984" + }, + { + "type": "WEB", + "url": "https://gist.github.com/mestrtee/97a9a7d73fc8b38fcf01322239dd5fb1" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-30T20:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-vmmw-2v5h-4hf6/GHSA-vmmw-2v5h-4hf6.json b/advisories/unreviewed/2024/07/GHSA-vmmw-2v5h-4hf6/GHSA-vmmw-2v5h-4hf6.json index 9f8ae3e12e1..d7999ae6814 100644 --- a/advisories/unreviewed/2024/07/GHSA-vmmw-2v5h-4hf6/GHSA-vmmw-2v5h-4hf6.json +++ b/advisories/unreviewed/2024/07/GHSA-vmmw-2v5h-4hf6/GHSA-vmmw-2v5h-4hf6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vmmw-2v5h-4hf6", - "modified": "2024-07-29T18:30:40Z", + "modified": "2024-07-30T21:31:26Z", "published": "2024-07-29T18:30:40Z", "aliases": [ "CVE-2024-42080" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/restrack: Fix potential invalid address access\n\nstruct rdma_restrack_entry's kern_name was set to KBUILD_MODNAME\nin ib_create_cq(), while if the module exited but forgot del this\nrdma_restrack_entry, it would cause a invalid address access in\nrdma_restrack_clean() when print the owner of this rdma_restrack_entry.\n\nThese code is used to help find one forgotten PD release in one of the\nULPs. But it is not needed anymore, so delete them.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T16:15:07Z" diff --git a/advisories/unreviewed/2024/07/GHSA-wrxx-pv2p-6gjj/GHSA-wrxx-pv2p-6gjj.json b/advisories/unreviewed/2024/07/GHSA-wrxx-pv2p-6gjj/GHSA-wrxx-pv2p-6gjj.json new file mode 100644 index 00000000000..898d4fefd7d --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-wrxx-pv2p-6gjj/GHSA-wrxx-pv2p-6gjj.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wrxx-pv2p-6gjj", + "modified": "2024-07-30T21:31:27Z", + "published": "2024-07-30T21:31:27Z", + "aliases": [ + "CVE-2024-41438" + ], + "details": "A heap buffer overflow in the function cp_stored() (/vendor/cute_png.h) of hicolor v0.5.0 allows attackers to cause a Denial of Service (DoS) via a crafted PNG file.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41438" + }, + { + "type": "WEB", + "url": "https://github.com/Helson-S/FuzzyTesting/blob/master/hicolor/heapof-r65280-cp_stored-cute_png-543c2" + }, + { + "type": "WEB", + "url": "https://github.com/Helson-S/FuzzyTesting/blob/master/hicolor/heapof-r65280-cp_stored-cute_png-543c2/vulDescription.assets/image-20240530184723547.png" + }, + { + "type": "WEB", + "url": "https://github.com/Helson-S/FuzzyTesting/blob/master/hicolor/heapof-r65280-cp_stored-cute_png-543c2/vulDescription.assets/image-20240530184848743.png" + }, + { + "type": "WEB", + "url": "https://github.com/Helson-S/FuzzyTesting/blob/master/hicolor/heapof-r65280-cp_stored-cute_png-543c2/vulDescription.assets/image-20240530185015780.png" + }, + { + "type": "WEB", + "url": "https://github.com/Helson-S/FuzzyTesting/blob/master/hicolor/heapof-r65280-cp_stored-cute_png-543c2/vulDescription.md" + }, + { + "type": "WEB", + "url": "https://github.com/Helson-S/FuzzyTesting/tree/master/hicolor/heapof-r65280-cp_stored-cute_png-543c2/poc" + }, + { + "type": "WEB", + "url": "https://github.com/Helson-S/FuzzyTesting/tree/master/hicolor/heapof-r65280-cp_stored-cute_png-543c2/poc/sample10.png" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-30T19:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-x8rh-6x6w-x2xg/GHSA-x8rh-6x6w-x2xg.json b/advisories/unreviewed/2024/07/GHSA-x8rh-6x6w-x2xg/GHSA-x8rh-6x6w-x2xg.json index 5cf285283bf..1eb17efd02e 100644 --- a/advisories/unreviewed/2024/07/GHSA-x8rh-6x6w-x2xg/GHSA-x8rh-6x6w-x2xg.json +++ b/advisories/unreviewed/2024/07/GHSA-x8rh-6x6w-x2xg/GHSA-x8rh-6x6w-x2xg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x8rh-6x6w-x2xg", - "modified": "2024-07-29T18:30:39Z", + "modified": "2024-07-30T21:31:25Z", "published": "2024-07-29T18:30:39Z", "aliases": [ "CVE-2024-42067" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Take return from set_memory_rox() into account with bpf_jit_binary_lock_ro()\n\nset_memory_rox() can fail, leaving memory unprotected.\n\nCheck return and bail out when bpf_jit_binary_lock_ro() returns\nan error.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-252" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-29T16:15:06Z" diff --git a/advisories/unreviewed/2024/07/GHSA-x93q-6p46-2qqf/GHSA-x93q-6p46-2qqf.json b/advisories/unreviewed/2024/07/GHSA-x93q-6p46-2qqf/GHSA-x93q-6p46-2qqf.json new file mode 100644 index 00000000000..5a59fca631d --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-x93q-6p46-2qqf/GHSA-x93q-6p46-2qqf.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x93q-6p46-2qqf", + "modified": "2024-07-30T21:31:29Z", + "published": "2024-07-30T21:31:29Z", + "aliases": [ + "CVE-2024-41610" + ], + "details": "D-Link DIR-820LW REVB FIRMWARE PATCH 2.03.B01_TC contains hardcoded credentials in the Telnet service, enabling attackers to log in remotely to the Telnet service and perform arbitrary commands.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41610" + }, + { + "type": "WEB", + "url": "https://github.com/Nop3z/CVE/blob/main/dlink/dir-820/Dlink-820LW-hardcoded-vulnerability.md" + }, + { + "type": "WEB", + "url": "https://www.dlink.com/en/security-bulletin" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-30T20:15:04Z" + } +} \ No newline at end of file