From 2cb4fd123a8213875265a7b34ccd1b0cf7579a21 Mon Sep 17 00:00:00 2001
From: "advisory-database[bot]"
<45398580+advisory-database[bot]@users.noreply.github.com>
Date: Thu, 27 Mar 2025 18:32:19 +0000
Subject: [PATCH] Advisory Database Sync
---
.../GHSA-5pvr-hrvj-wq9p.json | 6 +-
.../GHSA-7r5f-jp39-68j3.json | 2 +-
.../GHSA-7wj8-hmjc-g8m9.json | 4 +-
.../GHSA-g4vw-65wg-8wxw.json | 2 +-
.../GHSA-hmx8-973g-mf9c.json | 4 +-
.../GHSA-rg9r-f32f-755r.json | 1 +
.../GHSA-w74v-6cvm-j42q.json | 4 +-
.../GHSA-42mf-5456-q6fw.json | 4 +-
.../GHSA-fpq7-2gc8-r9rx.json | 3 +-
.../GHSA-m8q6-hf5g-rg2m.json | 4 +-
.../GHSA-rf7c-46j8-p9fp.json | 4 +-
.../GHSA-3x6c-xfwc-qp7m.json | 15 +++--
.../GHSA-4qgw-8rww-mw2h.json | 4 +-
.../GHSA-5vw7-hf8v-5qgw.json | 4 +-
.../GHSA-94wh-fmx9-8mfh.json | 11 +++-
.../GHSA-9whp-6cg8-4p5h.json | 4 +-
.../GHSA-f279-w6jr-7xxj.json | 4 +-
.../GHSA-hc3f-33fv-495x.json | 15 +++--
.../GHSA-j63f-r65c-3x8x.json | 11 +++-
.../GHSA-p559-89wh-h48w.json | 4 +-
.../GHSA-vf74-j427-jc3g.json | 15 +++--
.../GHSA-x7hw-jwrw-qw78.json | 11 +++-
.../GHSA-3x3c-vqj6-m557.json | 11 +++-
.../GHSA-5656-3635-q384.json | 4 +-
.../GHSA-68j2-gxmg-qr7q.json | 15 +++--
.../GHSA-jhp9-93xh-vh3m.json | 4 +-
.../GHSA-v2xc-vg4h-28jp.json | 11 +++-
.../GHSA-x54g-mx9q-vc6g.json | 11 +++-
.../GHSA-79fj-qcrm-4368.json | 4 +-
.../GHSA-8vj3-86c4-xhm3.json | 11 +++-
.../GHSA-g8vg-m5vq-4hcq.json | 11 +++-
.../GHSA-gg2x-v7xp-pj7x.json | 4 +-
.../GHSA-pcm2-6vc4-fm2m.json | 11 +++-
.../GHSA-rmhw-r566-6398.json | 15 +++--
.../GHSA-vgpr-crmh-v58x.json | 11 +++-
.../GHSA-w3pf-5jqj-rj4q.json | 15 ++++-
.../GHSA-w682-79hv-gcr8.json | 11 +++-
.../GHSA-jq42-q6c8-f44h.json | 11 +++-
.../GHSA-736h-7p7r-vh9c.json | 4 +-
.../GHSA-cgrw-9q9p-34fj.json | 4 +-
.../GHSA-m28q-fx99-4vr5.json | 4 +-
.../GHSA-p9mv-wfx3-mx37.json | 11 +++-
.../GHSA-r54r-9gw2-2w5v.json | 4 +-
.../GHSA-rr22-7m4r-xf6r.json | 6 +-
.../GHSA-v5c5-m6wp-9rf7.json | 4 +-
.../GHSA-w3x2-w5xp-gm6x.json | 11 +++-
.../GHSA-3mjr-8v4p-9qf4.json | 4 +-
.../GHSA-8vrc-835p-5x34.json | 2 +-
.../GHSA-p838-f99j-pg58.json | 3 +-
.../GHSA-2g5f-4p47-mx3m.json | 41 +++++++++++++
.../GHSA-2g84-5882-fhcm.json | 33 ++++++++++
.../GHSA-2q9r-f82f-3g5x.json | 48 +++++++++++++++
.../GHSA-2x8g-m7hp-f3x8.json | 41 +++++++++++++
.../GHSA-34qc-h2vp-hq88.json | 60 +++++++++++++++++++
.../GHSA-37xv-f578-fgq6.json | 48 +++++++++++++++
.../GHSA-3cvm-96rv-2mw4.json | 33 ++++++++++
.../GHSA-3j53-j44c-wp43.json | 37 ++++++++++++
.../GHSA-3m27-46p7-w7mh.json | 41 +++++++++++++
.../GHSA-3vpw-mc3x-93rw.json | 36 +++++++++++
.../GHSA-443g-xxfv-37vx.json | 53 ++++++++++++++++
.../GHSA-47gf-fpw6-jjhw.json | 36 +++++++++++
.../GHSA-4997-qrqv-f5m7.json | 33 ++++++++++
.../GHSA-49f7-q2j4-qfwq.json | 36 +++++++++++
.../GHSA-4j5r-8cvm-p98h.json | 53 ++++++++++++++++
.../GHSA-4x8g-3q83-5465.json | 53 ++++++++++++++++
.../GHSA-4xh9-2qp4-9r3m.json | 3 +-
.../GHSA-54mv-r6h5-c8vf.json | 45 ++++++++++++++
.../GHSA-56r2-5qqm-ppfv.json | 36 +++++++++++
.../GHSA-57pw-gf47-fr76.json | 33 ++++++++++
.../GHSA-592q-r679-2jpc.json | 53 ++++++++++++++++
.../GHSA-5rg6-fchv-4f55.json | 29 +++++++++
.../GHSA-5w7q-3v7j-8q5q.json | 33 ++++++++++
.../GHSA-6gh5-4fvc-rw6c.json | 33 ++++++++++
.../GHSA-6rc5-mh5g-63wm.json | 33 ++++++++++
.../GHSA-6v4g-pv75-fm7f.json | 36 +++++++++++
.../GHSA-73pj-2jcm-q7xj.json | 33 ++++++++++
.../GHSA-75fp-4g7m-cr39.json | 33 ++++++++++
.../GHSA-76g9-mx4c-qm64.json | 37 ++++++++++++
.../GHSA-7fmf-h6vh-qp27.json | 41 +++++++++++++
.../GHSA-7hqh-xh4r-x7q4.json | 3 +-
.../GHSA-7m9p-x22p-v2hg.json | 37 ++++++++++++
.../GHSA-7mjx-q39g-f9qc.json | 33 ++++++++++
.../GHSA-7r4r-7wg2-96vj.json | 41 +++++++++++++
.../GHSA-7rcp-78xx-6fqm.json | 37 ++++++++++++
.../GHSA-8295-hcjh-5w9p.json | 41 +++++++++++++
.../GHSA-82wr-7889-862x.json | 37 ++++++++++++
.../GHSA-8378-x644-jppg.json | 33 ++++++++++
.../GHSA-83h3-pmwm-wj9j.json | 37 ++++++++++++
.../GHSA-88rq-q8gm-2chx.json | 33 ++++++++++
.../GHSA-8hf9-x5gr-j3rr.json | 29 +++++++++
.../GHSA-8qj8-x8gq-98wm.json | 37 ++++++++++++
.../GHSA-8qp4-g23m-7ww9.json | 36 +++++++++++
.../GHSA-92fq-22vv-8p4c.json | 36 +++++++++++
.../GHSA-9933-f4m5-7v96.json | 37 ++++++++++++
.../GHSA-9chp-g445-qxj3.json | 3 +-
.../GHSA-9h2w-crmf-mr2p.json | 41 +++++++++++++
.../GHSA-9w4w-6v5v-wh95.json | 45 ++++++++++++++
.../GHSA-c2p3-c9fp-43mx.json | 33 ++++++++++
.../GHSA-c2pc-4ww4-m54p.json | 49 +++++++++++++++
.../GHSA-c6c6-6xm6-jhp9.json | 53 ++++++++++++++++
.../GHSA-c7qr-fxvv-x4fh.json | 33 ++++++++++
.../GHSA-cc9v-j5mh-4rvx.json | 33 ++++++++++
.../GHSA-cg23-v479-px36.json | 33 ++++++++++
.../GHSA-cq6c-crmc-xmvp.json | 33 ++++++++++
.../GHSA-crf3-p565-96vh.json | 33 ++++++++++
.../GHSA-crqj-674f-vq27.json | 37 ++++++++++++
.../GHSA-cw78-q654-793w.json | 37 ++++++++++++
.../GHSA-cx4p-cv2h-hf45.json | 45 ++++++++++++++
.../GHSA-f436-rh44-wfp7.json | 49 +++++++++++++++
.../GHSA-f656-g9wf-2686.json | 45 ++++++++++++++
.../GHSA-f76f-mm36-mf6v.json | 53 ++++++++++++++++
.../GHSA-fhrv-4645-phmg.json | 36 +++++++++++
.../GHSA-fj6j-g6mj-6hf2.json | 33 ++++++++++
.../GHSA-fx88-897w-ccgj.json | 45 ++++++++++++++
.../GHSA-g5qc-p7w9-v26c.json | 53 ++++++++++++++++
.../GHSA-g7hp-hfwm-x3rp.json | 53 ++++++++++++++++
.../GHSA-gj95-rf37-g546.json | 15 +++--
.../GHSA-gmm6-5vw5-42h2.json | 29 +++++++++
.../GHSA-gqwp-f6mc-jxp2.json | 3 +-
.../GHSA-gqww-qgqj-92wg.json | 36 +++++++++++
.../GHSA-gr26-qx48-q4hh.json | 45 ++++++++++++++
.../GHSA-gr59-j2cc-29g3.json | 41 +++++++++++++
.../GHSA-gw27-9x3h-33gj.json | 15 +++--
.../GHSA-gw36-8q8h-w9xm.json | 53 ++++++++++++++++
.../GHSA-hcxq-v393-38jh.json | 49 +++++++++++++++
.../GHSA-hjff-56wf-4v5f.json | 45 ++++++++++++++
.../GHSA-hxj2-x4g6-rhf8.json | 41 +++++++++++++
.../GHSA-j94v-m9xh-gwvq.json | 52 ++++++++++++++++
.../GHSA-jhxv-jq7p-9qhc.json | 33 ++++++++++
.../GHSA-jph2-wv5j-5w33.json | 45 ++++++++++++++
.../GHSA-jw5w-h5c8-x699.json | 45 ++++++++++++++
.../GHSA-jw73-x24m-whqq.json | 37 ++++++++++++
.../GHSA-jwgp-qffh-vpgp.json | 33 ++++++++++
.../GHSA-m43r-r9j3-6gfp.json | 45 ++++++++++++++
.../GHSA-m76m-37m5-h9wj.json | 45 ++++++++++++++
.../GHSA-mh69-q9mq-74wg.json | 33 ++++++++++
.../GHSA-mp89-pxjh-mww8.json | 36 +++++++++++
.../GHSA-mq3c-v59w-hjf6.json | 33 ++++++++++
.../GHSA-mqh3-5x68-9v64.json | 49 +++++++++++++++
.../GHSA-mvjr-2pvh-8wqh.json | 37 ++++++++++++
.../GHSA-p2cv-98qj-r2qc.json | 33 ++++++++++
.../GHSA-p579-25jc-wxr5.json | 33 ++++++++++
.../GHSA-p7rv-2f34-8mwf.json | 60 +++++++++++++++++++
.../GHSA-pjg2-rfg9-hrh3.json | 49 +++++++++++++++
.../GHSA-pq67-2wwv-3xjx.json | 36 +++++++++++
.../GHSA-pqmw-jx87-8vxx.json | 37 ++++++++++++
.../GHSA-pwg3-m7h4-xjvm.json | 37 ++++++++++++
.../GHSA-qc5x-h4r4-86f3.json | 53 ++++++++++++++++
.../GHSA-qhg6-v8xh-pwh7.json | 53 ++++++++++++++++
.../GHSA-qv94-9c4f-29wh.json | 53 ++++++++++++++++
.../GHSA-qxq7-jc88-2fr4.json | 37 ++++++++++++
.../GHSA-r3gg-v2qj-wcmp.json | 53 ++++++++++++++++
.../GHSA-r956-xq9j-f5vj.json | 33 ++++++++++
.../GHSA-rfj2-m755-7qfc.json | 41 +++++++++++++
.../GHSA-v3mg-hw7c-8v25.json | 33 ++++++++++
.../GHSA-v743-mw8q-3h6g.json | 33 ++++++++++
.../GHSA-v7c9-p8hg-xgw5.json | 3 +-
.../GHSA-v985-xp9j-wxfh.json | 33 ++++++++++
.../GHSA-v9wm-8h4w-7wmw.json | 36 +++++++++++
.../GHSA-vgcw-mq7g-4h6g.json | 36 +++++++++++
.../GHSA-vjwm-w9rc-f4cc.json | 15 +++--
.../GHSA-vm8w-gf89-48f9.json | 44 ++++++++++++++
.../GHSA-vxj7-p6gh-99vg.json | 33 ++++++++++
.../GHSA-w6fx-qwwp-5r54.json | 33 ++++++++++
.../GHSA-w7fp-pj56-6xc6.json | 36 +++++++++++
.../GHSA-w9c3-ww8v-w4fv.json | 36 +++++++++++
.../GHSA-whcm-px77-62x7.json | 33 ++++++++++
.../GHSA-wpc3-48hj-vqgf.json | 33 ++++++++++
.../GHSA-wq32-8rp4-w2mc.json | 33 ++++++++++
.../GHSA-wq76-hwvv-4gwx.json | 52 ++++++++++++++++
.../GHSA-wqh7-68mq-r673.json | 60 +++++++++++++++++++
.../GHSA-wvmw-32m8-fcpg.json | 33 ++++++++++
.../GHSA-x444-83wh-35rx.json | 56 +++++++++++++++++
.../GHSA-x6ch-fhmp-9745.json | 45 ++++++++++++++
.../GHSA-x768-g2cv-hv4j.json | 53 ++++++++++++++++
.../GHSA-xhmw-hwm7-v657.json | 49 +++++++++++++++
.../GHSA-xpq9-hr2h-w5cj.json | 37 ++++++++++++
.../GHSA-xr6w-2qh5-hfqq.json | 33 ++++++++++
.../GHSA-xvxr-rrxw-rfp9.json | 53 ++++++++++++++++
179 files changed, 5224 insertions(+), 115 deletions(-)
create mode 100644 advisories/unreviewed/2025/03/GHSA-2g5f-4p47-mx3m/GHSA-2g5f-4p47-mx3m.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-2g84-5882-fhcm/GHSA-2g84-5882-fhcm.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-2q9r-f82f-3g5x/GHSA-2q9r-f82f-3g5x.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-2x8g-m7hp-f3x8/GHSA-2x8g-m7hp-f3x8.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-34qc-h2vp-hq88/GHSA-34qc-h2vp-hq88.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-37xv-f578-fgq6/GHSA-37xv-f578-fgq6.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-3cvm-96rv-2mw4/GHSA-3cvm-96rv-2mw4.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-3j53-j44c-wp43/GHSA-3j53-j44c-wp43.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-3m27-46p7-w7mh/GHSA-3m27-46p7-w7mh.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-3vpw-mc3x-93rw/GHSA-3vpw-mc3x-93rw.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-443g-xxfv-37vx/GHSA-443g-xxfv-37vx.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-47gf-fpw6-jjhw/GHSA-47gf-fpw6-jjhw.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-4997-qrqv-f5m7/GHSA-4997-qrqv-f5m7.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-49f7-q2j4-qfwq/GHSA-49f7-q2j4-qfwq.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-4j5r-8cvm-p98h/GHSA-4j5r-8cvm-p98h.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-4x8g-3q83-5465/GHSA-4x8g-3q83-5465.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-54mv-r6h5-c8vf/GHSA-54mv-r6h5-c8vf.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-56r2-5qqm-ppfv/GHSA-56r2-5qqm-ppfv.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-57pw-gf47-fr76/GHSA-57pw-gf47-fr76.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-592q-r679-2jpc/GHSA-592q-r679-2jpc.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-5rg6-fchv-4f55/GHSA-5rg6-fchv-4f55.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-5w7q-3v7j-8q5q/GHSA-5w7q-3v7j-8q5q.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-6gh5-4fvc-rw6c/GHSA-6gh5-4fvc-rw6c.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-6rc5-mh5g-63wm/GHSA-6rc5-mh5g-63wm.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-6v4g-pv75-fm7f/GHSA-6v4g-pv75-fm7f.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-73pj-2jcm-q7xj/GHSA-73pj-2jcm-q7xj.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-75fp-4g7m-cr39/GHSA-75fp-4g7m-cr39.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-76g9-mx4c-qm64/GHSA-76g9-mx4c-qm64.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-7fmf-h6vh-qp27/GHSA-7fmf-h6vh-qp27.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-7m9p-x22p-v2hg/GHSA-7m9p-x22p-v2hg.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-7mjx-q39g-f9qc/GHSA-7mjx-q39g-f9qc.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-7r4r-7wg2-96vj/GHSA-7r4r-7wg2-96vj.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-7rcp-78xx-6fqm/GHSA-7rcp-78xx-6fqm.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-8295-hcjh-5w9p/GHSA-8295-hcjh-5w9p.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-82wr-7889-862x/GHSA-82wr-7889-862x.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-8378-x644-jppg/GHSA-8378-x644-jppg.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-83h3-pmwm-wj9j/GHSA-83h3-pmwm-wj9j.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-88rq-q8gm-2chx/GHSA-88rq-q8gm-2chx.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-8hf9-x5gr-j3rr/GHSA-8hf9-x5gr-j3rr.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-8qj8-x8gq-98wm/GHSA-8qj8-x8gq-98wm.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-8qp4-g23m-7ww9/GHSA-8qp4-g23m-7ww9.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-92fq-22vv-8p4c/GHSA-92fq-22vv-8p4c.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-9933-f4m5-7v96/GHSA-9933-f4m5-7v96.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-9h2w-crmf-mr2p/GHSA-9h2w-crmf-mr2p.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-9w4w-6v5v-wh95/GHSA-9w4w-6v5v-wh95.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-c2p3-c9fp-43mx/GHSA-c2p3-c9fp-43mx.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-c2pc-4ww4-m54p/GHSA-c2pc-4ww4-m54p.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-c6c6-6xm6-jhp9/GHSA-c6c6-6xm6-jhp9.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-c7qr-fxvv-x4fh/GHSA-c7qr-fxvv-x4fh.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-cc9v-j5mh-4rvx/GHSA-cc9v-j5mh-4rvx.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-cg23-v479-px36/GHSA-cg23-v479-px36.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-cq6c-crmc-xmvp/GHSA-cq6c-crmc-xmvp.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-crf3-p565-96vh/GHSA-crf3-p565-96vh.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-crqj-674f-vq27/GHSA-crqj-674f-vq27.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-cw78-q654-793w/GHSA-cw78-q654-793w.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-cx4p-cv2h-hf45/GHSA-cx4p-cv2h-hf45.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-f436-rh44-wfp7/GHSA-f436-rh44-wfp7.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-f656-g9wf-2686/GHSA-f656-g9wf-2686.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-f76f-mm36-mf6v/GHSA-f76f-mm36-mf6v.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-fhrv-4645-phmg/GHSA-fhrv-4645-phmg.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-fj6j-g6mj-6hf2/GHSA-fj6j-g6mj-6hf2.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-fx88-897w-ccgj/GHSA-fx88-897w-ccgj.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-g5qc-p7w9-v26c/GHSA-g5qc-p7w9-v26c.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-g7hp-hfwm-x3rp/GHSA-g7hp-hfwm-x3rp.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-gmm6-5vw5-42h2/GHSA-gmm6-5vw5-42h2.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-gqww-qgqj-92wg/GHSA-gqww-qgqj-92wg.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-gr26-qx48-q4hh/GHSA-gr26-qx48-q4hh.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-gr59-j2cc-29g3/GHSA-gr59-j2cc-29g3.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-gw36-8q8h-w9xm/GHSA-gw36-8q8h-w9xm.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-hcxq-v393-38jh/GHSA-hcxq-v393-38jh.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-hjff-56wf-4v5f/GHSA-hjff-56wf-4v5f.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-hxj2-x4g6-rhf8/GHSA-hxj2-x4g6-rhf8.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-j94v-m9xh-gwvq/GHSA-j94v-m9xh-gwvq.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-jhxv-jq7p-9qhc/GHSA-jhxv-jq7p-9qhc.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-jph2-wv5j-5w33/GHSA-jph2-wv5j-5w33.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-jw5w-h5c8-x699/GHSA-jw5w-h5c8-x699.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-jw73-x24m-whqq/GHSA-jw73-x24m-whqq.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-jwgp-qffh-vpgp/GHSA-jwgp-qffh-vpgp.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-m43r-r9j3-6gfp/GHSA-m43r-r9j3-6gfp.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-m76m-37m5-h9wj/GHSA-m76m-37m5-h9wj.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-mh69-q9mq-74wg/GHSA-mh69-q9mq-74wg.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-mp89-pxjh-mww8/GHSA-mp89-pxjh-mww8.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-mq3c-v59w-hjf6/GHSA-mq3c-v59w-hjf6.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-mqh3-5x68-9v64/GHSA-mqh3-5x68-9v64.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-mvjr-2pvh-8wqh/GHSA-mvjr-2pvh-8wqh.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-p2cv-98qj-r2qc/GHSA-p2cv-98qj-r2qc.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-p579-25jc-wxr5/GHSA-p579-25jc-wxr5.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-p7rv-2f34-8mwf/GHSA-p7rv-2f34-8mwf.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-pjg2-rfg9-hrh3/GHSA-pjg2-rfg9-hrh3.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-pq67-2wwv-3xjx/GHSA-pq67-2wwv-3xjx.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-pqmw-jx87-8vxx/GHSA-pqmw-jx87-8vxx.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-pwg3-m7h4-xjvm/GHSA-pwg3-m7h4-xjvm.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-qc5x-h4r4-86f3/GHSA-qc5x-h4r4-86f3.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-qhg6-v8xh-pwh7/GHSA-qhg6-v8xh-pwh7.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-qv94-9c4f-29wh/GHSA-qv94-9c4f-29wh.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-qxq7-jc88-2fr4/GHSA-qxq7-jc88-2fr4.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-r3gg-v2qj-wcmp/GHSA-r3gg-v2qj-wcmp.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-r956-xq9j-f5vj/GHSA-r956-xq9j-f5vj.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-rfj2-m755-7qfc/GHSA-rfj2-m755-7qfc.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-v3mg-hw7c-8v25/GHSA-v3mg-hw7c-8v25.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-v743-mw8q-3h6g/GHSA-v743-mw8q-3h6g.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-v985-xp9j-wxfh/GHSA-v985-xp9j-wxfh.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-v9wm-8h4w-7wmw/GHSA-v9wm-8h4w-7wmw.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-vgcw-mq7g-4h6g/GHSA-vgcw-mq7g-4h6g.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-vm8w-gf89-48f9/GHSA-vm8w-gf89-48f9.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-vxj7-p6gh-99vg/GHSA-vxj7-p6gh-99vg.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-w6fx-qwwp-5r54/GHSA-w6fx-qwwp-5r54.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-w7fp-pj56-6xc6/GHSA-w7fp-pj56-6xc6.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-w9c3-ww8v-w4fv/GHSA-w9c3-ww8v-w4fv.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-whcm-px77-62x7/GHSA-whcm-px77-62x7.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-wpc3-48hj-vqgf/GHSA-wpc3-48hj-vqgf.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-wq32-8rp4-w2mc/GHSA-wq32-8rp4-w2mc.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-wq76-hwvv-4gwx/GHSA-wq76-hwvv-4gwx.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-wqh7-68mq-r673/GHSA-wqh7-68mq-r673.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-wvmw-32m8-fcpg/GHSA-wvmw-32m8-fcpg.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-x444-83wh-35rx/GHSA-x444-83wh-35rx.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-x6ch-fhmp-9745/GHSA-x6ch-fhmp-9745.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-x768-g2cv-hv4j/GHSA-x768-g2cv-hv4j.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-xhmw-hwm7-v657/GHSA-xhmw-hwm7-v657.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-xpq9-hr2h-w5cj/GHSA-xpq9-hr2h-w5cj.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-xr6w-2qh5-hfqq/GHSA-xr6w-2qh5-hfqq.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-xvxr-rrxw-rfp9/GHSA-xvxr-rrxw-rfp9.json
diff --git a/advisories/unreviewed/2022/05/GHSA-5pvr-hrvj-wq9p/GHSA-5pvr-hrvj-wq9p.json b/advisories/unreviewed/2022/05/GHSA-5pvr-hrvj-wq9p/GHSA-5pvr-hrvj-wq9p.json
index c98f4594482..6a462f734b5 100644
--- a/advisories/unreviewed/2022/05/GHSA-5pvr-hrvj-wq9p/GHSA-5pvr-hrvj-wq9p.json
+++ b/advisories/unreviewed/2022/05/GHSA-5pvr-hrvj-wq9p/GHSA-5pvr-hrvj-wq9p.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5pvr-hrvj-wq9p",
- "modified": "2022-05-02T00:02:26Z",
+ "modified": "2025-03-27T18:30:35Z",
"published": "2022-05-02T00:02:26Z",
"aliases": [
"CVE-2008-3652"
@@ -22,6 +22,10 @@
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2008-3652"
},
+ {
+ "type": "WEB",
+ "url": "https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=501026"
+ },
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=458846"
diff --git a/advisories/unreviewed/2023/02/GHSA-7r5f-jp39-68j3/GHSA-7r5f-jp39-68j3.json b/advisories/unreviewed/2023/02/GHSA-7r5f-jp39-68j3/GHSA-7r5f-jp39-68j3.json
index 4e1ba6dc7cf..2fbc3f43dbd 100644
--- a/advisories/unreviewed/2023/02/GHSA-7r5f-jp39-68j3/GHSA-7r5f-jp39-68j3.json
+++ b/advisories/unreviewed/2023/02/GHSA-7r5f-jp39-68j3/GHSA-7r5f-jp39-68j3.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7r5f-jp39-68j3",
- "modified": "2023-02-08T03:30:25Z",
+ "modified": "2025-03-27T18:30:36Z",
"published": "2023-02-01T03:30:29Z",
"aliases": [
"CVE-2022-47769"
diff --git a/advisories/unreviewed/2023/02/GHSA-7wj8-hmjc-g8m9/GHSA-7wj8-hmjc-g8m9.json b/advisories/unreviewed/2023/02/GHSA-7wj8-hmjc-g8m9/GHSA-7wj8-hmjc-g8m9.json
index 9c98beec442..5c8a6083514 100644
--- a/advisories/unreviewed/2023/02/GHSA-7wj8-hmjc-g8m9/GHSA-7wj8-hmjc-g8m9.json
+++ b/advisories/unreviewed/2023/02/GHSA-7wj8-hmjc-g8m9/GHSA-7wj8-hmjc-g8m9.json
@@ -25,7 +25,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-276"
+ ],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2023/02/GHSA-g4vw-65wg-8wxw/GHSA-g4vw-65wg-8wxw.json b/advisories/unreviewed/2023/02/GHSA-g4vw-65wg-8wxw/GHSA-g4vw-65wg-8wxw.json
index 478927132de..e10440db952 100644
--- a/advisories/unreviewed/2023/02/GHSA-g4vw-65wg-8wxw/GHSA-g4vw-65wg-8wxw.json
+++ b/advisories/unreviewed/2023/02/GHSA-g4vw-65wg-8wxw/GHSA-g4vw-65wg-8wxw.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g4vw-65wg-8wxw",
- "modified": "2023-02-08T00:30:34Z",
+ "modified": "2025-03-27T18:30:36Z",
"published": "2023-02-01T03:30:29Z",
"aliases": [
"CVE-2022-47770"
diff --git a/advisories/unreviewed/2023/02/GHSA-hmx8-973g-mf9c/GHSA-hmx8-973g-mf9c.json b/advisories/unreviewed/2023/02/GHSA-hmx8-973g-mf9c/GHSA-hmx8-973g-mf9c.json
index aaf8ffac537..58c57bff931 100644
--- a/advisories/unreviewed/2023/02/GHSA-hmx8-973g-mf9c/GHSA-hmx8-973g-mf9c.json
+++ b/advisories/unreviewed/2023/02/GHSA-hmx8-973g-mf9c/GHSA-hmx8-973g-mf9c.json
@@ -25,7 +25,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-276"
+ ],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2023/02/GHSA-rg9r-f32f-755r/GHSA-rg9r-f32f-755r.json b/advisories/unreviewed/2023/02/GHSA-rg9r-f32f-755r/GHSA-rg9r-f32f-755r.json
index 44db3aa2cdd..2766545bc88 100644
--- a/advisories/unreviewed/2023/02/GHSA-rg9r-f32f-755r/GHSA-rg9r-f32f-755r.json
+++ b/advisories/unreviewed/2023/02/GHSA-rg9r-f32f-755r/GHSA-rg9r-f32f-755r.json
@@ -26,6 +26,7 @@
],
"database_specific": {
"cwe_ids": [
+ "CWE-338",
"CWE-640"
],
"severity": "CRITICAL",
diff --git a/advisories/unreviewed/2023/02/GHSA-w74v-6cvm-j42q/GHSA-w74v-6cvm-j42q.json b/advisories/unreviewed/2023/02/GHSA-w74v-6cvm-j42q/GHSA-w74v-6cvm-j42q.json
index 6beebf4ee11..390c776f861 100644
--- a/advisories/unreviewed/2023/02/GHSA-w74v-6cvm-j42q/GHSA-w74v-6cvm-j42q.json
+++ b/advisories/unreviewed/2023/02/GHSA-w74v-6cvm-j42q/GHSA-w74v-6cvm-j42q.json
@@ -25,7 +25,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-94"
+ ],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/02/GHSA-42mf-5456-q6fw/GHSA-42mf-5456-q6fw.json b/advisories/unreviewed/2024/02/GHSA-42mf-5456-q6fw/GHSA-42mf-5456-q6fw.json
index f4981a3c45e..3ca7989fc3d 100644
--- a/advisories/unreviewed/2024/02/GHSA-42mf-5456-q6fw/GHSA-42mf-5456-q6fw.json
+++ b/advisories/unreviewed/2024/02/GHSA-42mf-5456-q6fw/GHSA-42mf-5456-q6fw.json
@@ -25,7 +25,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-284"
+ ],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/02/GHSA-fpq7-2gc8-r9rx/GHSA-fpq7-2gc8-r9rx.json b/advisories/unreviewed/2024/02/GHSA-fpq7-2gc8-r9rx/GHSA-fpq7-2gc8-r9rx.json
index ec997d3e250..7daf5f4b606 100644
--- a/advisories/unreviewed/2024/02/GHSA-fpq7-2gc8-r9rx/GHSA-fpq7-2gc8-r9rx.json
+++ b/advisories/unreviewed/2024/02/GHSA-fpq7-2gc8-r9rx/GHSA-fpq7-2gc8-r9rx.json
@@ -26,7 +26,8 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-233"
+ "CWE-233",
+ "CWE-94"
],
"severity": "CRITICAL",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/02/GHSA-m8q6-hf5g-rg2m/GHSA-m8q6-hf5g-rg2m.json b/advisories/unreviewed/2024/02/GHSA-m8q6-hf5g-rg2m/GHSA-m8q6-hf5g-rg2m.json
index ca43cdef43d..980caf2fb85 100644
--- a/advisories/unreviewed/2024/02/GHSA-m8q6-hf5g-rg2m/GHSA-m8q6-hf5g-rg2m.json
+++ b/advisories/unreviewed/2024/02/GHSA-m8q6-hf5g-rg2m/GHSA-m8q6-hf5g-rg2m.json
@@ -25,7 +25,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-400"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/02/GHSA-rf7c-46j8-p9fp/GHSA-rf7c-46j8-p9fp.json b/advisories/unreviewed/2024/02/GHSA-rf7c-46j8-p9fp/GHSA-rf7c-46j8-p9fp.json
index 92f8c1f25db..287e3de3535 100644
--- a/advisories/unreviewed/2024/02/GHSA-rf7c-46j8-p9fp/GHSA-rf7c-46j8-p9fp.json
+++ b/advisories/unreviewed/2024/02/GHSA-rf7c-46j8-p9fp/GHSA-rf7c-46j8-p9fp.json
@@ -25,7 +25,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-352"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/03/GHSA-3x6c-xfwc-qp7m/GHSA-3x6c-xfwc-qp7m.json b/advisories/unreviewed/2024/03/GHSA-3x6c-xfwc-qp7m/GHSA-3x6c-xfwc-qp7m.json
index 79a500c2963..14dd6e06062 100644
--- a/advisories/unreviewed/2024/03/GHSA-3x6c-xfwc-qp7m/GHSA-3x6c-xfwc-qp7m.json
+++ b/advisories/unreviewed/2024/03/GHSA-3x6c-xfwc-qp7m/GHSA-3x6c-xfwc-qp7m.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3x6c-xfwc-qp7m",
- "modified": "2024-04-05T18:30:33Z",
+ "modified": "2025-03-27T18:30:38Z",
"published": "2024-03-29T18:30:42Z",
"aliases": [
"CVE-2023-49234"
],
"details": "An XML external entity (XXE) vulnerability was found in Stilog Visual Planning 8. It allows an authenticated attacker to access local server files and exfiltrate data to an external server.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N"
+ }
+ ],
"affected": [],
"references": [
{
@@ -32,8 +37,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-611"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-29T17:15:11Z"
diff --git a/advisories/unreviewed/2024/03/GHSA-4qgw-8rww-mw2h/GHSA-4qgw-8rww-mw2h.json b/advisories/unreviewed/2024/03/GHSA-4qgw-8rww-mw2h/GHSA-4qgw-8rww-mw2h.json
index 5dfc3642e79..1525b9598e0 100644
--- a/advisories/unreviewed/2024/03/GHSA-4qgw-8rww-mw2h/GHSA-4qgw-8rww-mw2h.json
+++ b/advisories/unreviewed/2024/03/GHSA-4qgw-8rww-mw2h/GHSA-4qgw-8rww-mw2h.json
@@ -25,7 +25,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-285"
+ ],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/03/GHSA-5vw7-hf8v-5qgw/GHSA-5vw7-hf8v-5qgw.json b/advisories/unreviewed/2024/03/GHSA-5vw7-hf8v-5qgw/GHSA-5vw7-hf8v-5qgw.json
index f3f49315439..6423e20d6b6 100644
--- a/advisories/unreviewed/2024/03/GHSA-5vw7-hf8v-5qgw/GHSA-5vw7-hf8v-5qgw.json
+++ b/advisories/unreviewed/2024/03/GHSA-5vw7-hf8v-5qgw/GHSA-5vw7-hf8v-5qgw.json
@@ -37,7 +37,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-502"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/03/GHSA-94wh-fmx9-8mfh/GHSA-94wh-fmx9-8mfh.json b/advisories/unreviewed/2024/03/GHSA-94wh-fmx9-8mfh/GHSA-94wh-fmx9-8mfh.json
index cfc714696aa..a98fa116b6c 100644
--- a/advisories/unreviewed/2024/03/GHSA-94wh-fmx9-8mfh/GHSA-94wh-fmx9-8mfh.json
+++ b/advisories/unreviewed/2024/03/GHSA-94wh-fmx9-8mfh/GHSA-94wh-fmx9-8mfh.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-94wh-fmx9-8mfh",
- "modified": "2024-03-11T03:30:49Z",
+ "modified": "2025-03-27T18:30:38Z",
"published": "2024-03-11T03:30:49Z",
"aliases": [
"CVE-2024-28816"
],
"details": "Student Information Chatbot a0196ab allows SQL injection via the username to the login function in index.php.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N"
+ }
+ ],
"affected": [],
"references": [
{
@@ -23,7 +28,7 @@
"cwe_ids": [
"CWE-89"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-11T03:15:05Z"
diff --git a/advisories/unreviewed/2024/03/GHSA-9whp-6cg8-4p5h/GHSA-9whp-6cg8-4p5h.json b/advisories/unreviewed/2024/03/GHSA-9whp-6cg8-4p5h/GHSA-9whp-6cg8-4p5h.json
index 282842fd05d..c55605ccab8 100644
--- a/advisories/unreviewed/2024/03/GHSA-9whp-6cg8-4p5h/GHSA-9whp-6cg8-4p5h.json
+++ b/advisories/unreviewed/2024/03/GHSA-9whp-6cg8-4p5h/GHSA-9whp-6cg8-4p5h.json
@@ -49,7 +49,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-863"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/03/GHSA-f279-w6jr-7xxj/GHSA-f279-w6jr-7xxj.json b/advisories/unreviewed/2024/03/GHSA-f279-w6jr-7xxj/GHSA-f279-w6jr-7xxj.json
index 9992a85c9d7..3db6a78d4af 100644
--- a/advisories/unreviewed/2024/03/GHSA-f279-w6jr-7xxj/GHSA-f279-w6jr-7xxj.json
+++ b/advisories/unreviewed/2024/03/GHSA-f279-w6jr-7xxj/GHSA-f279-w6jr-7xxj.json
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f279-w6jr-7xxj",
- "modified": "2024-08-28T21:31:26Z",
+ "modified": "2025-03-27T18:30:38Z",
"published": "2024-03-04T12:31:09Z",
"aliases": [
"CVE-2023-6143"
],
- "details": "Use After Free vulnerability in Arm Ltd Midgard GPU Kernel Driver, Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to exploit a software race condition to perform improper memory processing operations. If the system’s memory is carefully prepared by the user and the system is under heavy load, then this in turn cause a use-after-free.This issue affects Midgard GPU Kernel Driver: from r13p0 through r32p0; Bifrost GPU Kernel Driver: from r1p0 through r18p0; Valhall GPU Kernel Driver: from r37p0 through r46p0; Arm 5th Gen GPU Architecture Kernel Driver: from r41p0 through r46p0.\n\n",
+ "details": "Use After Free vulnerability in Arm Ltd Midgard GPU Kernel Driver, Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to exploit a software race condition to perform improper memory processing operations. If the system’s memory is carefully prepared by the user and the system is under heavy load, then this in turn cause a use-after-free.This issue affects Midgard GPU Kernel Driver: from r13p0 through r32p0; Bifrost GPU Kernel Driver: from r1p0 through r18p0; Valhall GPU Kernel Driver: from r37p0 through r46p0; Arm 5th Gen GPU Architecture Kernel Driver: from r41p0 through r46p0.",
"severity": [
{
"type": "CVSS_V3",
diff --git a/advisories/unreviewed/2024/03/GHSA-hc3f-33fv-495x/GHSA-hc3f-33fv-495x.json b/advisories/unreviewed/2024/03/GHSA-hc3f-33fv-495x/GHSA-hc3f-33fv-495x.json
index 7f448ed9692..f510296c3b8 100644
--- a/advisories/unreviewed/2024/03/GHSA-hc3f-33fv-495x/GHSA-hc3f-33fv-495x.json
+++ b/advisories/unreviewed/2024/03/GHSA-hc3f-33fv-495x/GHSA-hc3f-33fv-495x.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hc3f-33fv-495x",
- "modified": "2024-03-03T09:30:37Z",
+ "modified": "2025-03-27T18:30:37Z",
"published": "2024-03-03T09:30:37Z",
"aliases": [
"CVE-2024-25844"
],
"details": "An issue was discovered in Common-Services \"So Flexibilite\" (soflexibilite) module for PrestaShop before version 4.1.26, allows remote attackers to escalate privileges and obtain sensitive information via debug file.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
+ }
+ ],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-280"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-03T08:15:08Z"
diff --git a/advisories/unreviewed/2024/03/GHSA-j63f-r65c-3x8x/GHSA-j63f-r65c-3x8x.json b/advisories/unreviewed/2024/03/GHSA-j63f-r65c-3x8x/GHSA-j63f-r65c-3x8x.json
index 997b510bee0..8cd5610b009 100644
--- a/advisories/unreviewed/2024/03/GHSA-j63f-r65c-3x8x/GHSA-j63f-r65c-3x8x.json
+++ b/advisories/unreviewed/2024/03/GHSA-j63f-r65c-3x8x/GHSA-j63f-r65c-3x8x.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j63f-r65c-3x8x",
- "modified": "2024-03-04T21:31:11Z",
+ "modified": "2025-03-27T18:30:38Z",
"published": "2024-03-04T21:31:11Z",
"aliases": [
"CVE-2024-1319"
],
"details": "The Events Tickets Plus WordPress plugin before 5.9.1 does not prevent users with at least the contributor role from leaking the attendees list on any post type regardless of status. (e.g. draft, private, pending review, password-protected, and trashed posts).",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
+ }
+ ],
"affected": [],
"references": [
{
@@ -21,7 +26,7 @@
],
"database_specific": {
"cwe_ids": [],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-04T21:15:07Z"
diff --git a/advisories/unreviewed/2024/03/GHSA-p559-89wh-h48w/GHSA-p559-89wh-h48w.json b/advisories/unreviewed/2024/03/GHSA-p559-89wh-h48w/GHSA-p559-89wh-h48w.json
index 4f57daeb80c..a2584f9e045 100644
--- a/advisories/unreviewed/2024/03/GHSA-p559-89wh-h48w/GHSA-p559-89wh-h48w.json
+++ b/advisories/unreviewed/2024/03/GHSA-p559-89wh-h48w/GHSA-p559-89wh-h48w.json
@@ -29,7 +29,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-497"
+ ],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/03/GHSA-vf74-j427-jc3g/GHSA-vf74-j427-jc3g.json b/advisories/unreviewed/2024/03/GHSA-vf74-j427-jc3g/GHSA-vf74-j427-jc3g.json
index 71986594dca..58988024734 100644
--- a/advisories/unreviewed/2024/03/GHSA-vf74-j427-jc3g/GHSA-vf74-j427-jc3g.json
+++ b/advisories/unreviewed/2024/03/GHSA-vf74-j427-jc3g/GHSA-vf74-j427-jc3g.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vf74-j427-jc3g",
- "modified": "2024-03-18T21:31:23Z",
+ "modified": "2025-03-27T18:30:38Z",
"published": "2024-03-18T21:31:23Z",
"aliases": [
"CVE-2024-0951"
],
"details": "The Advanced Social Feeds Widget & Shortcode WordPress plugin through 1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"
+ }
+ ],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-18T19:15:06Z"
diff --git a/advisories/unreviewed/2024/03/GHSA-x7hw-jwrw-qw78/GHSA-x7hw-jwrw-qw78.json b/advisories/unreviewed/2024/03/GHSA-x7hw-jwrw-qw78/GHSA-x7hw-jwrw-qw78.json
index d924dfaeade..27977cbb40b 100644
--- a/advisories/unreviewed/2024/03/GHSA-x7hw-jwrw-qw78/GHSA-x7hw-jwrw-qw78.json
+++ b/advisories/unreviewed/2024/03/GHSA-x7hw-jwrw-qw78/GHSA-x7hw-jwrw-qw78.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x7hw-jwrw-qw78",
- "modified": "2024-03-14T06:32:00Z",
+ "modified": "2025-03-27T18:30:38Z",
"published": "2024-03-14T06:32:00Z",
"aliases": [
"CVE-2024-22397"
],
"details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in the SonicOS SSLVPN portal allows a remote authenticated attacker as a firewall 'admin' user to store and execute arbitrary JavaScript code.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:L"
+ }
+ ],
"affected": [],
"references": [
{
@@ -23,7 +28,7 @@
"cwe_ids": [
"CWE-79"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-14T04:15:09Z"
diff --git a/advisories/unreviewed/2024/04/GHSA-3x3c-vqj6-m557/GHSA-3x3c-vqj6-m557.json b/advisories/unreviewed/2024/04/GHSA-3x3c-vqj6-m557/GHSA-3x3c-vqj6-m557.json
index d3dc4325238..9945fa21cd3 100644
--- a/advisories/unreviewed/2024/04/GHSA-3x3c-vqj6-m557/GHSA-3x3c-vqj6-m557.json
+++ b/advisories/unreviewed/2024/04/GHSA-3x3c-vqj6-m557/GHSA-3x3c-vqj6-m557.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3x3c-vqj6-m557",
- "modified": "2024-04-08T06:31:30Z",
+ "modified": "2025-03-27T18:30:39Z",
"published": "2024-04-08T06:31:30Z",
"aliases": [
"CVE-2024-1588"
],
"details": "The SendPress Newsletters WordPress plugin through 1.23.11.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -21,7 +26,7 @@
],
"database_specific": {
"cwe_ids": [],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-08T05:15:07Z"
diff --git a/advisories/unreviewed/2024/04/GHSA-5656-3635-q384/GHSA-5656-3635-q384.json b/advisories/unreviewed/2024/04/GHSA-5656-3635-q384/GHSA-5656-3635-q384.json
index f82079c8224..df23c65c65c 100644
--- a/advisories/unreviewed/2024/04/GHSA-5656-3635-q384/GHSA-5656-3635-q384.json
+++ b/advisories/unreviewed/2024/04/GHSA-5656-3635-q384/GHSA-5656-3635-q384.json
@@ -25,7 +25,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/04/GHSA-68j2-gxmg-qr7q/GHSA-68j2-gxmg-qr7q.json b/advisories/unreviewed/2024/04/GHSA-68j2-gxmg-qr7q/GHSA-68j2-gxmg-qr7q.json
index b5f2a4c8aff..c6f2d6a2a53 100644
--- a/advisories/unreviewed/2024/04/GHSA-68j2-gxmg-qr7q/GHSA-68j2-gxmg-qr7q.json
+++ b/advisories/unreviewed/2024/04/GHSA-68j2-gxmg-qr7q/GHSA-68j2-gxmg-qr7q.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-68j2-gxmg-qr7q",
- "modified": "2024-04-02T09:30:42Z",
+ "modified": "2025-03-27T18:30:39Z",
"published": "2024-04-02T09:30:42Z",
"aliases": [
"CVE-2024-31004"
],
"details": "An issue in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the Ap4StsdAtom.cpp,AP4_StsdAtom::AP4_StsdAtom,mp4fragment.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-94"
+ ],
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-02T08:16:10Z"
diff --git a/advisories/unreviewed/2024/04/GHSA-jhp9-93xh-vh3m/GHSA-jhp9-93xh-vh3m.json b/advisories/unreviewed/2024/04/GHSA-jhp9-93xh-vh3m/GHSA-jhp9-93xh-vh3m.json
index 8f5bbaac4aa..7909494fc7e 100644
--- a/advisories/unreviewed/2024/04/GHSA-jhp9-93xh-vh3m/GHSA-jhp9-93xh-vh3m.json
+++ b/advisories/unreviewed/2024/04/GHSA-jhp9-93xh-vh3m/GHSA-jhp9-93xh-vh3m.json
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jhp9-93xh-vh3m",
- "modified": "2024-07-03T18:36:00Z",
+ "modified": "2025-03-27T18:30:39Z",
"published": "2024-04-19T09:30:47Z",
"aliases": [
"CVE-2024-1065"
],
- "details": "Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to make improper GPU memory processing operations to gain access to already freed memory.This issue affects Bifrost GPU Kernel Driver: from r45p0 through r48p0; Valhall GPU Kernel Driver: from r45p0 through r48p0; Arm 5th Gen GPU Architecture Kernel Driver: from r45p0 through r48p0.\n\n",
+ "details": "Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to make improper GPU memory processing operations to gain access to already freed memory.This issue affects Bifrost GPU Kernel Driver: from r45p0 through r48p0; Valhall GPU Kernel Driver: from r45p0 through r48p0; Arm 5th Gen GPU Architecture Kernel Driver: from r45p0 through r48p0.",
"severity": [
{
"type": "CVSS_V3",
diff --git a/advisories/unreviewed/2024/04/GHSA-v2xc-vg4h-28jp/GHSA-v2xc-vg4h-28jp.json b/advisories/unreviewed/2024/04/GHSA-v2xc-vg4h-28jp/GHSA-v2xc-vg4h-28jp.json
index 2a5233e0ea7..ba2ab7ef9de 100644
--- a/advisories/unreviewed/2024/04/GHSA-v2xc-vg4h-28jp/GHSA-v2xc-vg4h-28jp.json
+++ b/advisories/unreviewed/2024/04/GHSA-v2xc-vg4h-28jp/GHSA-v2xc-vg4h-28jp.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v2xc-vg4h-28jp",
- "modified": "2024-04-24T06:30:31Z",
+ "modified": "2025-03-27T18:30:39Z",
"published": "2024-04-24T06:30:31Z",
"aliases": [
"CVE-2024-2972"
],
"details": "The Floating Chat Widget: Contact Chat Icons, WhatsApp, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button WordPress plugin before 3.1.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N"
+ }
+ ],
"affected": [],
"references": [
{
@@ -21,7 +26,7 @@
],
"database_specific": {
"cwe_ids": [],
- "severity": null,
+ "severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-24T05:15:47Z"
diff --git a/advisories/unreviewed/2024/04/GHSA-x54g-mx9q-vc6g/GHSA-x54g-mx9q-vc6g.json b/advisories/unreviewed/2024/04/GHSA-x54g-mx9q-vc6g/GHSA-x54g-mx9q-vc6g.json
index ed422754215..8990458449a 100644
--- a/advisories/unreviewed/2024/04/GHSA-x54g-mx9q-vc6g/GHSA-x54g-mx9q-vc6g.json
+++ b/advisories/unreviewed/2024/04/GHSA-x54g-mx9q-vc6g/GHSA-x54g-mx9q-vc6g.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x54g-mx9q-vc6g",
- "modified": "2024-04-30T21:30:32Z",
+ "modified": "2025-03-27T18:30:39Z",
"published": "2024-04-30T21:30:32Z",
"aliases": [
"CVE-2024-33332"
],
"details": "An issue discovered in SpringBlade 3.7.1 allows attackers to obtain sensitive information via crafted GET request to api/blade-system/tenant.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
+ }
+ ],
"affected": [],
"references": [
{
@@ -23,7 +28,7 @@
"cwe_ids": [
"CWE-89"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-30T20:15:08Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-79fj-qcrm-4368/GHSA-79fj-qcrm-4368.json b/advisories/unreviewed/2024/05/GHSA-79fj-qcrm-4368/GHSA-79fj-qcrm-4368.json
index 87824caa8e7..c4845f05f09 100644
--- a/advisories/unreviewed/2024/05/GHSA-79fj-qcrm-4368/GHSA-79fj-qcrm-4368.json
+++ b/advisories/unreviewed/2024/05/GHSA-79fj-qcrm-4368/GHSA-79fj-qcrm-4368.json
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-79fj-qcrm-4368",
- "modified": "2024-07-03T18:38:46Z",
+ "modified": "2025-03-27T18:30:39Z",
"published": "2024-05-03T15:30:54Z",
"aliases": [
"CVE-2024-1395"
],
- "details": "Use After Free vulnerability in Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to make improper GPU memory processing operations. If the system’s memory is carefully prepared by the user, then this in turn could give them access to already freed memory.\nThis issue affects Arm 5th Gen GPU Architecture Kernel Driver: from r41p0 through r47p0.\n\n",
+ "details": "Use After Free vulnerability in Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to make improper GPU memory processing operations. If the system’s memory is carefully prepared by the user, then this in turn could give them access to already freed memory.\nThis issue affects Arm 5th Gen GPU Architecture Kernel Driver: from r41p0 through r47p0.",
"severity": [
{
"type": "CVSS_V3",
diff --git a/advisories/unreviewed/2024/05/GHSA-8vj3-86c4-xhm3/GHSA-8vj3-86c4-xhm3.json b/advisories/unreviewed/2024/05/GHSA-8vj3-86c4-xhm3/GHSA-8vj3-86c4-xhm3.json
index 85bd993c363..3e3f5895db7 100644
--- a/advisories/unreviewed/2024/05/GHSA-8vj3-86c4-xhm3/GHSA-8vj3-86c4-xhm3.json
+++ b/advisories/unreviewed/2024/05/GHSA-8vj3-86c4-xhm3/GHSA-8vj3-86c4-xhm3.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8vj3-86c4-xhm3",
- "modified": "2024-05-17T06:31:16Z",
+ "modified": "2025-03-27T18:30:40Z",
"published": "2024-05-17T06:31:16Z",
"aliases": [
"CVE-2024-2744"
],
"details": "The NextGEN Gallery WordPress plugin before 3.59.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L"
+ }
+ ],
"affected": [],
"references": [
{
@@ -21,7 +26,7 @@
],
"database_specific": {
"cwe_ids": [],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-17T06:15:51Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-g8vg-m5vq-4hcq/GHSA-g8vg-m5vq-4hcq.json b/advisories/unreviewed/2024/05/GHSA-g8vg-m5vq-4hcq/GHSA-g8vg-m5vq-4hcq.json
index 97e345d5854..dae1038843d 100644
--- a/advisories/unreviewed/2024/05/GHSA-g8vg-m5vq-4hcq/GHSA-g8vg-m5vq-4hcq.json
+++ b/advisories/unreviewed/2024/05/GHSA-g8vg-m5vq-4hcq/GHSA-g8vg-m5vq-4hcq.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g8vg-m5vq-4hcq",
- "modified": "2024-05-16T06:30:51Z",
+ "modified": "2025-03-27T18:30:40Z",
"published": "2024-05-16T06:30:50Z",
"aliases": [
"CVE-2024-3642"
],
"details": "The Newsletter Popup WordPress plugin through 1.2 does not have CSRF check when deleting subscriber, which could allow attackers to make logged in admins perform such action via a CSRF attack",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:N"
+ }
+ ],
"affected": [],
"references": [
{
@@ -21,7 +26,7 @@
],
"database_specific": {
"cwe_ids": [],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-16T06:15:09Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-gg2x-v7xp-pj7x/GHSA-gg2x-v7xp-pj7x.json b/advisories/unreviewed/2024/05/GHSA-gg2x-v7xp-pj7x/GHSA-gg2x-v7xp-pj7x.json
index 4ecdf5061e7..8f19dbe0e0d 100644
--- a/advisories/unreviewed/2024/05/GHSA-gg2x-v7xp-pj7x/GHSA-gg2x-v7xp-pj7x.json
+++ b/advisories/unreviewed/2024/05/GHSA-gg2x-v7xp-pj7x/GHSA-gg2x-v7xp-pj7x.json
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gg2x-v7xp-pj7x",
- "modified": "2024-11-25T18:33:24Z",
+ "modified": "2025-03-27T18:30:39Z",
"published": "2024-05-03T15:30:54Z",
"aliases": [
"CVE-2023-6363"
],
- "details": "Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to make improper GPU memory processing operations. If the system’s memory is carefully prepared by the user, then this in turn could give them access to already freed memory.\nThis issue affects Valhall GPU Kernel Driver: from r41p0 through r47p0; Arm 5th Gen GPU Architecture Kernel Driver: from r41p0 through r47p0.\n\n",
+ "details": "Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to make improper GPU memory processing operations. If the system’s memory is carefully prepared by the user, then this in turn could give them access to already freed memory.\nThis issue affects Valhall GPU Kernel Driver: from r41p0 through r47p0; Arm 5th Gen GPU Architecture Kernel Driver: from r41p0 through r47p0.",
"severity": [
{
"type": "CVSS_V3",
diff --git a/advisories/unreviewed/2024/05/GHSA-pcm2-6vc4-fm2m/GHSA-pcm2-6vc4-fm2m.json b/advisories/unreviewed/2024/05/GHSA-pcm2-6vc4-fm2m/GHSA-pcm2-6vc4-fm2m.json
index a9e4822f115..a0cb94a0c1e 100644
--- a/advisories/unreviewed/2024/05/GHSA-pcm2-6vc4-fm2m/GHSA-pcm2-6vc4-fm2m.json
+++ b/advisories/unreviewed/2024/05/GHSA-pcm2-6vc4-fm2m/GHSA-pcm2-6vc4-fm2m.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pcm2-6vc4-fm2m",
- "modified": "2024-05-14T18:30:48Z",
+ "modified": "2025-03-27T18:30:39Z",
"published": "2024-05-14T18:30:48Z",
"aliases": [
"CVE-2024-33818"
],
"details": "Globitel KSA SpeechLog v8.1 was discovered to contain an Insecure Direct Object Reference (IDOR) via the userID parameter.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
+ }
+ ],
"affected": [],
"references": [
{
@@ -23,7 +28,7 @@
"cwe_ids": [
"CWE-639"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-14T15:38:07Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-rmhw-r566-6398/GHSA-rmhw-r566-6398.json b/advisories/unreviewed/2024/05/GHSA-rmhw-r566-6398/GHSA-rmhw-r566-6398.json
index 1e1d735727d..23450c048e3 100644
--- a/advisories/unreviewed/2024/05/GHSA-rmhw-r566-6398/GHSA-rmhw-r566-6398.json
+++ b/advisories/unreviewed/2024/05/GHSA-rmhw-r566-6398/GHSA-rmhw-r566-6398.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rmhw-r566-6398",
- "modified": "2024-05-14T18:30:51Z",
+ "modified": "2025-03-27T18:30:39Z",
"published": "2024-05-14T18:30:51Z",
"aliases": [
"CVE-2024-34749"
],
"details": "Phormer prior to version 3.35 contains a cross-site scripting vulnerability. If this vulnerability is exploited, a remote unauthenticated attacker may execute an arbitrary script on the web browser of the user.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
+ }
+ ],
"affected": [],
"references": [
{
@@ -32,8 +37,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-14T15:39:32Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-vgpr-crmh-v58x/GHSA-vgpr-crmh-v58x.json b/advisories/unreviewed/2024/05/GHSA-vgpr-crmh-v58x/GHSA-vgpr-crmh-v58x.json
index e9066c528d8..770ca9b9086 100644
--- a/advisories/unreviewed/2024/05/GHSA-vgpr-crmh-v58x/GHSA-vgpr-crmh-v58x.json
+++ b/advisories/unreviewed/2024/05/GHSA-vgpr-crmh-v58x/GHSA-vgpr-crmh-v58x.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vgpr-crmh-v58x",
- "modified": "2024-05-06T03:30:47Z",
+ "modified": "2025-03-27T18:30:39Z",
"published": "2024-05-06T03:30:47Z",
"aliases": [
"CVE-2024-20057"
],
"details": "In keyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08587881; Issue ID: ALPS08587881.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -23,7 +28,7 @@
"cwe_ids": [
"CWE-787"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-06T03:15:09Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-w3pf-5jqj-rj4q/GHSA-w3pf-5jqj-rj4q.json b/advisories/unreviewed/2024/05/GHSA-w3pf-5jqj-rj4q/GHSA-w3pf-5jqj-rj4q.json
index a07a8a7b065..644d0e98679 100644
--- a/advisories/unreviewed/2024/05/GHSA-w3pf-5jqj-rj4q/GHSA-w3pf-5jqj-rj4q.json
+++ b/advisories/unreviewed/2024/05/GHSA-w3pf-5jqj-rj4q/GHSA-w3pf-5jqj-rj4q.json
@@ -1,19 +1,28 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w3pf-5jqj-rj4q",
- "modified": "2024-05-15T18:30:35Z",
+ "modified": "2025-03-27T18:30:40Z",
"published": "2024-05-15T18:30:35Z",
"aliases": [
"CVE-2024-4622"
],
"details": "If misconfigured, alpitronic Hypercharger EV charging devices can expose a web interface \nprotected by authentication. If the default credentials are not changed,\n an attacker can use public knowledge to access the device as an \nadministrator.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V4",
+ "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
+ }
+ ],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4622"
},
+ {
+ "type": "WEB",
+ "url": "https://industrydecarbonization.com/news/insecure-password-allowed-administrative-access-to-electric-vehicle-chargers.html"
+ },
{
"type": "WEB",
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-130-02"
@@ -23,7 +32,7 @@
"cwe_ids": [
"CWE-1392"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-15T17:15:16Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-w682-79hv-gcr8/GHSA-w682-79hv-gcr8.json b/advisories/unreviewed/2024/05/GHSA-w682-79hv-gcr8/GHSA-w682-79hv-gcr8.json
index f2f95149670..3bbd5d03eea 100644
--- a/advisories/unreviewed/2024/05/GHSA-w682-79hv-gcr8/GHSA-w682-79hv-gcr8.json
+++ b/advisories/unreviewed/2024/05/GHSA-w682-79hv-gcr8/GHSA-w682-79hv-gcr8.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w682-79hv-gcr8",
- "modified": "2024-05-15T06:30:45Z",
+ "modified": "2025-03-27T18:30:40Z",
"published": "2024-05-15T06:30:44Z",
"aliases": [
"CVE-2024-3824"
],
"details": "The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not have CSRF check in place when resetting its settings, which could allow attackers to make a logged in admin reset them via a CSRF attack",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L"
+ }
+ ],
"affected": [],
"references": [
{
@@ -21,7 +26,7 @@
],
"database_specific": {
"cwe_ids": [],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-15T06:15:14Z"
diff --git a/advisories/unreviewed/2024/06/GHSA-jq42-q6c8-f44h/GHSA-jq42-q6c8-f44h.json b/advisories/unreviewed/2024/06/GHSA-jq42-q6c8-f44h/GHSA-jq42-q6c8-f44h.json
index 1e87fbb8ee1..593636127a0 100644
--- a/advisories/unreviewed/2024/06/GHSA-jq42-q6c8-f44h/GHSA-jq42-q6c8-f44h.json
+++ b/advisories/unreviewed/2024/06/GHSA-jq42-q6c8-f44h/GHSA-jq42-q6c8-f44h.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jq42-q6c8-f44h",
- "modified": "2024-06-13T21:30:55Z",
+ "modified": "2025-03-27T18:30:40Z",
"published": "2024-06-13T21:30:55Z",
"aliases": [
"CVE-2024-32924"
],
"details": "In DeregAcceptProcINT of cn_NrmmStateDeregInit.cpp, there is a possible denial of service due to a logic error in the code. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -21,7 +26,7 @@
],
"database_specific": {
"cwe_ids": [],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-13T21:15:56Z"
diff --git a/advisories/unreviewed/2024/07/GHSA-736h-7p7r-vh9c/GHSA-736h-7p7r-vh9c.json b/advisories/unreviewed/2024/07/GHSA-736h-7p7r-vh9c/GHSA-736h-7p7r-vh9c.json
index f61a88448ab..fba978cbcd9 100644
--- a/advisories/unreviewed/2024/07/GHSA-736h-7p7r-vh9c/GHSA-736h-7p7r-vh9c.json
+++ b/advisories/unreviewed/2024/07/GHSA-736h-7p7r-vh9c/GHSA-736h-7p7r-vh9c.json
@@ -25,7 +25,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-400"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/07/GHSA-cgrw-9q9p-34fj/GHSA-cgrw-9q9p-34fj.json b/advisories/unreviewed/2024/07/GHSA-cgrw-9q9p-34fj/GHSA-cgrw-9q9p-34fj.json
index fa5eaa7b015..faf521d0abc 100644
--- a/advisories/unreviewed/2024/07/GHSA-cgrw-9q9p-34fj/GHSA-cgrw-9q9p-34fj.json
+++ b/advisories/unreviewed/2024/07/GHSA-cgrw-9q9p-34fj/GHSA-cgrw-9q9p-34fj.json
@@ -25,7 +25,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-312"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/07/GHSA-m28q-fx99-4vr5/GHSA-m28q-fx99-4vr5.json b/advisories/unreviewed/2024/07/GHSA-m28q-fx99-4vr5/GHSA-m28q-fx99-4vr5.json
index f20ccfc4893..43723e50c29 100644
--- a/advisories/unreviewed/2024/07/GHSA-m28q-fx99-4vr5/GHSA-m28q-fx99-4vr5.json
+++ b/advisories/unreviewed/2024/07/GHSA-m28q-fx99-4vr5/GHSA-m28q-fx99-4vr5.json
@@ -29,7 +29,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-20"
+ ],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/07/GHSA-p9mv-wfx3-mx37/GHSA-p9mv-wfx3-mx37.json b/advisories/unreviewed/2024/07/GHSA-p9mv-wfx3-mx37/GHSA-p9mv-wfx3-mx37.json
index 18040429685..464914f2053 100644
--- a/advisories/unreviewed/2024/07/GHSA-p9mv-wfx3-mx37/GHSA-p9mv-wfx3-mx37.json
+++ b/advisories/unreviewed/2024/07/GHSA-p9mv-wfx3-mx37/GHSA-p9mv-wfx3-mx37.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p9mv-wfx3-mx37",
- "modified": "2024-07-13T06:32:41Z",
+ "modified": "2025-03-27T18:30:41Z",
"published": "2024-07-13T06:32:41Z",
"aliases": [
"CVE-2024-5627"
],
"details": "The Tournamatch WordPress plugin before 4.6.1 does not sanitise and escape some parameters, which could allow users with a role as low as subscriber to perform Cross-Site Scripting attacks.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
+ }
+ ],
"affected": [],
"references": [
{
@@ -21,7 +26,7 @@
],
"database_specific": {
"cwe_ids": [],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-13T06:15:05Z"
diff --git a/advisories/unreviewed/2024/07/GHSA-r54r-9gw2-2w5v/GHSA-r54r-9gw2-2w5v.json b/advisories/unreviewed/2024/07/GHSA-r54r-9gw2-2w5v/GHSA-r54r-9gw2-2w5v.json
index 2eda2c07c7c..ecbe9181cca 100644
--- a/advisories/unreviewed/2024/07/GHSA-r54r-9gw2-2w5v/GHSA-r54r-9gw2-2w5v.json
+++ b/advisories/unreviewed/2024/07/GHSA-r54r-9gw2-2w5v/GHSA-r54r-9gw2-2w5v.json
@@ -53,7 +53,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-284"
+ ],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/07/GHSA-rr22-7m4r-xf6r/GHSA-rr22-7m4r-xf6r.json b/advisories/unreviewed/2024/07/GHSA-rr22-7m4r-xf6r/GHSA-rr22-7m4r-xf6r.json
index 8baf1b88a33..849d1c122d3 100644
--- a/advisories/unreviewed/2024/07/GHSA-rr22-7m4r-xf6r/GHSA-rr22-7m4r-xf6r.json
+++ b/advisories/unreviewed/2024/07/GHSA-rr22-7m4r-xf6r/GHSA-rr22-7m4r-xf6r.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rr22-7m4r-xf6r",
- "modified": "2024-07-31T06:30:34Z",
+ "modified": "2025-03-27T18:30:42Z",
"published": "2024-07-31T06:30:34Z",
"aliases": [
"CVE-2024-39945"
@@ -25,7 +25,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-703"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/07/GHSA-v5c5-m6wp-9rf7/GHSA-v5c5-m6wp-9rf7.json b/advisories/unreviewed/2024/07/GHSA-v5c5-m6wp-9rf7/GHSA-v5c5-m6wp-9rf7.json
index 7b521252635..d39411b6a12 100644
--- a/advisories/unreviewed/2024/07/GHSA-v5c5-m6wp-9rf7/GHSA-v5c5-m6wp-9rf7.json
+++ b/advisories/unreviewed/2024/07/GHSA-v5c5-m6wp-9rf7/GHSA-v5c5-m6wp-9rf7.json
@@ -25,7 +25,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-400"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/07/GHSA-w3x2-w5xp-gm6x/GHSA-w3x2-w5xp-gm6x.json b/advisories/unreviewed/2024/07/GHSA-w3x2-w5xp-gm6x/GHSA-w3x2-w5xp-gm6x.json
index 54e8a79a214..f31fdf0baa2 100644
--- a/advisories/unreviewed/2024/07/GHSA-w3x2-w5xp-gm6x/GHSA-w3x2-w5xp-gm6x.json
+++ b/advisories/unreviewed/2024/07/GHSA-w3x2-w5xp-gm6x/GHSA-w3x2-w5xp-gm6x.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w3x2-w5xp-gm6x",
- "modified": "2024-07-19T15:31:47Z",
+ "modified": "2025-03-27T18:30:42Z",
"published": "2024-07-19T15:31:47Z",
"aliases": [
"CVE-2024-27489"
],
"details": "An issue in the DelFile() function of WMCMS v4.4 allows attackers to delete arbitrary files via a crafted POST request.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
+ }
+ ],
"affected": [],
"references": [
{
@@ -27,7 +32,7 @@
"cwe_ids": [
"CWE-473"
],
- "severity": null,
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-19T15:15:10Z"
diff --git a/advisories/unreviewed/2024/08/GHSA-3mjr-8v4p-9qf4/GHSA-3mjr-8v4p-9qf4.json b/advisories/unreviewed/2024/08/GHSA-3mjr-8v4p-9qf4/GHSA-3mjr-8v4p-9qf4.json
index 2c922250110..bf5c6da852e 100644
--- a/advisories/unreviewed/2024/08/GHSA-3mjr-8v4p-9qf4/GHSA-3mjr-8v4p-9qf4.json
+++ b/advisories/unreviewed/2024/08/GHSA-3mjr-8v4p-9qf4/GHSA-3mjr-8v4p-9qf4.json
@@ -25,7 +25,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-95"
+ ],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/12/GHSA-8vrc-835p-5x34/GHSA-8vrc-835p-5x34.json b/advisories/unreviewed/2024/12/GHSA-8vrc-835p-5x34/GHSA-8vrc-835p-5x34.json
index 761c9c2d4d7..47b9fdaadbb 100644
--- a/advisories/unreviewed/2024/12/GHSA-8vrc-835p-5x34/GHSA-8vrc-835p-5x34.json
+++ b/advisories/unreviewed/2024/12/GHSA-8vrc-835p-5x34/GHSA-8vrc-835p-5x34.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8vrc-835p-5x34",
- "modified": "2024-12-21T12:30:39Z",
+ "modified": "2025-03-27T18:30:45Z",
"published": "2024-12-21T12:30:39Z",
"aliases": [
"CVE-2024-10453"
diff --git a/advisories/unreviewed/2024/12/GHSA-p838-f99j-pg58/GHSA-p838-f99j-pg58.json b/advisories/unreviewed/2024/12/GHSA-p838-f99j-pg58/GHSA-p838-f99j-pg58.json
index cae5f251fe7..3ea9002c7aa 100644
--- a/advisories/unreviewed/2024/12/GHSA-p838-f99j-pg58/GHSA-p838-f99j-pg58.json
+++ b/advisories/unreviewed/2024/12/GHSA-p838-f99j-pg58/GHSA-p838-f99j-pg58.json
@@ -42,7 +42,8 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-74"
+ "CWE-74",
+ "CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2025/03/GHSA-2g5f-4p47-mx3m/GHSA-2g5f-4p47-mx3m.json b/advisories/unreviewed/2025/03/GHSA-2g5f-4p47-mx3m/GHSA-2g5f-4p47-mx3m.json
new file mode 100644
index 00000000000..05449de358d
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-2g5f-4p47-mx3m/GHSA-2g5f-4p47-mx3m.json
@@ -0,0 +1,41 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-2g5f-4p47-mx3m",
+ "modified": "2025-03-27T18:31:25Z",
+ "published": "2025-03-27T18:31:25Z",
+ "aliases": [
+ "CVE-2023-52929"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnvmem: core: fix cleanup after dev_set_name()\n\nIf dev_set_name() fails, we leak nvmem->wp_gpio as the cleanup does not\nput this. While a minimal fix for this would be to add the gpiod_put()\ncall, we can do better if we split device_register(), and use the\ntested nvmem_release() cleanup code by initialising the device early,\nand putting the device.\n\nThis results in a slightly larger fix, but results in clear code.\n\nNote: this patch depends on \"nvmem: core: initialise nvmem->id early\"\nand \"nvmem: core: remove nvmem_config wp_gpio\".\n\n[Srini: Fixed subject line and error code handing with wp_gpio while applying.]",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52929"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/23676ecd2eb377f7c24a6ff578b0f4c7135658b6"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/39708bc8da7858de0bed9b3a88b3beb1d1e0b443"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/560181d3ace61825f4ca9dd3481d6c0ee6709fa8"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/8f9c4b2a3b132bf6698e477aba6ee194b40c75f4"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:42Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-2g84-5882-fhcm/GHSA-2g84-5882-fhcm.json b/advisories/unreviewed/2025/03/GHSA-2g84-5882-fhcm/GHSA-2g84-5882-fhcm.json
new file mode 100644
index 00000000000..ae118f99057
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-2g84-5882-fhcm/GHSA-2g84-5882-fhcm.json
@@ -0,0 +1,33 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-2g84-5882-fhcm",
+ "modified": "2025-03-27T18:31:27Z",
+ "published": "2025-03-27T18:31:27Z",
+ "aliases": [
+ "CVE-2023-52994"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nacpi: Fix suspend with Xen PV\n\nCommit f1e525009493 (\"x86/boot: Skip realmode init code when running as\nXen PV guest\") missed one code path accessing real_mode_header, leading\nto dereferencing NULL when suspending the system under Xen:\n\n [ 348.284004] PM: suspend entry (deep)\n [ 348.289532] Filesystems sync: 0.005 seconds\n [ 348.291545] Freezing user space processes ... (elapsed 0.000 seconds) done.\n [ 348.292457] OOM killer disabled.\n [ 348.292462] Freezing remaining freezable tasks ... (elapsed 0.104 seconds) done.\n [ 348.396612] printk: Suspending console(s) (use no_console_suspend to debug)\n [ 348.749228] PM: suspend devices took 0.352 seconds\n [ 348.769713] ACPI: EC: interrupt blocked\n [ 348.816077] BUG: kernel NULL pointer dereference, address: 000000000000001c\n [ 348.816080] #PF: supervisor read access in kernel mode\n [ 348.816081] #PF: error_code(0x0000) - not-present page\n [ 348.816083] PGD 0 P4D 0\n [ 348.816086] Oops: 0000 [#1] PREEMPT SMP NOPTI\n [ 348.816089] CPU: 0 PID: 6764 Comm: systemd-sleep Not tainted 6.1.3-1.fc32.qubes.x86_64 #1\n [ 348.816092] Hardware name: Star Labs StarBook/StarBook, BIOS 8.01 07/03/2022\n [ 348.816093] RIP: e030:acpi_get_wakeup_address+0xc/0x20\n\nFix that by adding an optional acpi callback allowing to skip setting\nthe wakeup address, as in the Xen PV case this will be handled by the\nhypervisor anyway.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52994"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/b96903b7fc8c82ddfd92df4cdd83db3e567da0a5"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/fe0ba8c23f9a35b0307eb662f16dd3a75fcdae41"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:47Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-2q9r-f82f-3g5x/GHSA-2q9r-f82f-3g5x.json b/advisories/unreviewed/2025/03/GHSA-2q9r-f82f-3g5x/GHSA-2q9r-f82f-3g5x.json
new file mode 100644
index 00000000000..5c610ce23d3
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-2q9r-f82f-3g5x/GHSA-2q9r-f82f-3g5x.json
@@ -0,0 +1,48 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-2q9r-f82f-3g5x",
+ "modified": "2025-03-27T18:31:26Z",
+ "published": "2025-03-27T18:31:26Z",
+ "aliases": [
+ "CVE-2023-52983"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nblock, bfq: fix uaf for bfqq in bic_set_bfqq()\n\nAfter commit 64dc8c732f5c (\"block, bfq: fix possible uaf for 'bfqq->bic'\"),\nbic->bfqq will be accessed in bic_set_bfqq(), however, in some context\nbic->bfqq will be freed, and bic_set_bfqq() is called with the freed\nbic->bfqq.\n\nFix the problem by always freeing bfqq after bic_set_bfqq().",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52983"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/511c922c5bf6c8a166bea826e702336bc2424140"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/7f77f3dab5066a7c9da73d72d1eee895ff84a8d5"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/b600de2d7d3a16f9007fad1bdae82a3951a26af2"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/cb1876fc33af26d00efdd473311f1b664c77c44e"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:45Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-2x8g-m7hp-f3x8/GHSA-2x8g-m7hp-f3x8.json b/advisories/unreviewed/2025/03/GHSA-2x8g-m7hp-f3x8/GHSA-2x8g-m7hp-f3x8.json
new file mode 100644
index 00000000000..c5dd33e7c85
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-2x8g-m7hp-f3x8/GHSA-2x8g-m7hp-f3x8.json
@@ -0,0 +1,41 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-2x8g-m7hp-f3x8",
+ "modified": "2025-03-27T18:31:25Z",
+ "published": "2025-03-27T18:31:25Z",
+ "aliases": [
+ "CVE-2022-49761"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: always report error in run_one_delayed_ref()\n\nCurrently we have a btrfs_debug() for run_one_delayed_ref() failure, but\nif end users hit such problem, there will be no chance that\nbtrfs_debug() is enabled. This can lead to very little useful info for\ndebugging.\n\nThis patch will:\n\n- Add extra info for error reporting\n Including:\n * logical bytenr\n * num_bytes\n * type\n * action\n * ref_mod\n\n- Replace the btrfs_debug() with btrfs_err()\n\n- Move the error reporting into run_one_delayed_ref()\n This is to avoid use-after-free, the @node can be freed in the caller.\n\nThis error should only be triggered at most once.\n\nAs if run_one_delayed_ref() failed, we trigger the error message, then\ncausing the call chain to error out:\n\nbtrfs_run_delayed_refs()\n`- btrfs_run_delayed_refs()\n `- btrfs_run_delayed_refs_for_head()\n `- run_one_delayed_ref()\n\nAnd we will abort the current transaction in btrfs_run_delayed_refs().\nIf we have to run delayed refs for the abort transaction,\nrun_one_delayed_ref() will just cleanup the refs and do nothing, thus no\nnew error messages would be output.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49761"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/18bd1c9c02e64a3567f90c83c2c8b855531c8098"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/39f501d68ec1ed5cd5c66ac6ec2a7131c517bb92"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/853ffa1511b058c79a4c9bb1407b3b20ce311792"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/fdb4a70bb768d2a87890409597529ad81cb3de8a"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:41Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-34qc-h2vp-hq88/GHSA-34qc-h2vp-hq88.json b/advisories/unreviewed/2025/03/GHSA-34qc-h2vp-hq88/GHSA-34qc-h2vp-hq88.json
new file mode 100644
index 00000000000..5a12159bb64
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-34qc-h2vp-hq88/GHSA-34qc-h2vp-hq88.json
@@ -0,0 +1,60 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-34qc-h2vp-hq88",
+ "modified": "2025-03-27T18:31:26Z",
+ "published": "2025-03-27T18:31:26Z",
+ "aliases": [
+ "CVE-2023-52973"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nvc_screen: move load of struct vc_data pointer in vcs_read() to avoid UAF\n\nAfter a call to console_unlock() in vcs_read() the vc_data struct can be\nfreed by vc_deallocate(). Because of that, the struct vc_data pointer\nload must be done at the top of while loop in vcs_read() to avoid a UAF\nwhen vcs_size() is called.\n\nSyzkaller reported a UAF in vcs_size().\n\nBUG: KASAN: use-after-free in vcs_size (drivers/tty/vt/vc_screen.c:215)\nRead of size 4 at addr ffff8881137479a8 by task 4a005ed81e27e65/1537\n\nCPU: 0 PID: 1537 Comm: 4a005ed81e27e65 Not tainted 6.2.0-rc5 #1\nHardware name: Red Hat KVM, BIOS 1.15.0-2.module\nCall Trace:\n \n__asan_report_load4_noabort (mm/kasan/report_generic.c:350)\nvcs_size (drivers/tty/vt/vc_screen.c:215)\nvcs_read (drivers/tty/vt/vc_screen.c:415)\nvfs_read (fs/read_write.c:468 fs/read_write.c:450)\n...\n \n\nAllocated by task 1191:\n...\nkmalloc_trace (mm/slab_common.c:1069)\nvc_allocate (./include/linux/slab.h:580 ./include/linux/slab.h:720\n drivers/tty/vt/vt.c:1128 drivers/tty/vt/vt.c:1108)\ncon_install (drivers/tty/vt/vt.c:3383)\ntty_init_dev (drivers/tty/tty_io.c:1301 drivers/tty/tty_io.c:1413\n drivers/tty/tty_io.c:1390)\ntty_open (drivers/tty/tty_io.c:2080 drivers/tty/tty_io.c:2126)\nchrdev_open (fs/char_dev.c:415)\ndo_dentry_open (fs/open.c:883)\nvfs_open (fs/open.c:1014)\n...\n\nFreed by task 1548:\n...\nkfree (mm/slab_common.c:1021)\nvc_port_destruct (drivers/tty/vt/vt.c:1094)\ntty_port_destructor (drivers/tty/tty_port.c:296)\ntty_port_put (drivers/tty/tty_port.c:312)\nvt_disallocate_all (drivers/tty/vt/vt_ioctl.c:662 (discriminator 2))\nvt_ioctl (drivers/tty/vt/vt_ioctl.c:903)\ntty_ioctl (drivers/tty/tty_io.c:2776)\n...\n\nThe buggy address belongs to the object at ffff888113747800\n which belongs to the cache kmalloc-1k of size 1024\nThe buggy address is located 424 bytes inside of\n 1024-byte region [ffff888113747800, ffff888113747c00)\n\nThe buggy address belongs to the physical page:\npage:00000000b3fe6c7c refcount:1 mapcount:0 mapping:0000000000000000\n index:0x0 pfn:0x113740\nhead:00000000b3fe6c7c order:3 compound_mapcount:0 subpages_mapcount:0\n compound_pincount:0\nanon flags: 0x17ffffc0010200(slab|head|node=0|zone=2|lastcpupid=0x1fffff)\nraw: 0017ffffc0010200 ffff888100042dc0 0000000000000000 dead000000000001\nraw: 0000000000000000 0000000000100010 00000001ffffffff 0000000000000000\npage dumped because: kasan: bad access detected\n\nMemory state around the buggy address:\n ffff888113747880: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb\n ffff888113747900: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb\n> ffff888113747980: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb\n ^\n ffff888113747a00: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb\n ffff888113747a80: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb\n==================================================================\nDisabling lock debugging due to kernel taint",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52973"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/226fae124b2dac217ea5436060d623ff3385bc34"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/55515d7d8743b71b80bfe68e89eb9d92630626ab"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/6332f52f44b9776568bf3c0b714ddfb0bb175e78"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/8506f16aae9daf354e3732bcfd447e2a97f023df"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/af79ea9a2443016f64d8fd8d72020cc874f0e066"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/d0332cbf53dad06a22189cc341391237f4ea6d9f"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/fc9e27f3ba083534b8bbf72ab0f5c810ffdc7d18"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:44Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-37xv-f578-fgq6/GHSA-37xv-f578-fgq6.json b/advisories/unreviewed/2025/03/GHSA-37xv-f578-fgq6/GHSA-37xv-f578-fgq6.json
new file mode 100644
index 00000000000..5d741a2fc46
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-37xv-f578-fgq6/GHSA-37xv-f578-fgq6.json
@@ -0,0 +1,48 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-37xv-f578-fgq6",
+ "modified": "2025-03-27T18:31:29Z",
+ "published": "2025-03-27T18:31:28Z",
+ "aliases": [
+ "CVE-2023-53025"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nNFSD: fix use-after-free in nfsd4_ssc_setup_dul()\n\nIf signal_pending() returns true, schedule_timeout() will not be executed,\ncausing the waiting task to remain in the wait queue.\nFixed by adding a call to finish_wait(), which ensures that the waiting\ntask will always be removed from the wait queue.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-53025"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/0a27dcd5343026ac0cb168ee63304255372b7a36"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/32d5eb95f8f0e362e37c393310b13b9e95404560"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/6ac4c383c39f8f2f955f868d1ad9365c2363e80b"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/e6cf91b7b47ff82b624bdfe2fdcde32bb52e71dd"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:52Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-3cvm-96rv-2mw4/GHSA-3cvm-96rv-2mw4.json b/advisories/unreviewed/2025/03/GHSA-3cvm-96rv-2mw4/GHSA-3cvm-96rv-2mw4.json
new file mode 100644
index 00000000000..e8e1b9be042
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-3cvm-96rv-2mw4/GHSA-3cvm-96rv-2mw4.json
@@ -0,0 +1,33 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-3cvm-96rv-2mw4",
+ "modified": "2025-03-27T18:31:26Z",
+ "published": "2025-03-27T18:31:26Z",
+ "aliases": [
+ "CVE-2023-52982"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfscache: Use wait_on_bit() to wait for the freeing of relinquished volume\n\nThe freeing of relinquished volume will wake up the pending volume\nacquisition by using wake_up_bit(), however it is mismatched with\nwait_var_event() used in fscache_wait_on_volume_collision() and it will\nnever wake up the waiter in the wait-queue because these two functions\noperate on different wait-queues.\n\nAccording to the implementation in fscache_wait_on_volume_collision(),\nif the wake-up of pending acquisition is delayed longer than 20 seconds\n(e.g., due to the delay of on-demand fd closing), the first\nwait_var_event_timeout() will timeout and the following wait_var_event()\nwill hang forever as shown below:\n\n FS-Cache: Potential volume collision new=00000024 old=00000022\n ......\n INFO: task mount:1148 blocked for more than 122 seconds.\n Not tainted 6.1.0-rc6+ #1\n task:mount state:D stack:0 pid:1148 ppid:1\n Call Trace:\n \n __schedule+0x2f6/0xb80\n schedule+0x67/0xe0\n fscache_wait_on_volume_collision.cold+0x80/0x82\n __fscache_acquire_volume+0x40d/0x4e0\n erofs_fscache_register_volume+0x51/0xe0 [erofs]\n erofs_fscache_register_fs+0x19c/0x240 [erofs]\n erofs_fc_fill_super+0x746/0xaf0 [erofs]\n vfs_get_super+0x7d/0x100\n get_tree_nodev+0x16/0x20\n erofs_fc_get_tree+0x20/0x30 [erofs]\n vfs_get_tree+0x24/0xb0\n path_mount+0x2fa/0xa90\n do_mount+0x7c/0xa0\n __x64_sys_mount+0x8b/0xe0\n do_syscall_64+0x30/0x60\n entry_SYSCALL_64_after_hwframe+0x46/0xb0\n\nConsidering that wake_up_bit() is more selective, so fix it by using\nwait_on_bit() instead of wait_var_event() to wait for the freeing of\nrelinquished volume. In addition because waitqueue_active() is used in\nwake_up_bit() and clear_bit() doesn't imply any memory barrier, use\nclear_and_wake_up_bit() to add the missing memory barrier between\ncursor->flags and waitqueue_active().",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52982"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/3be069f42a7b79d3149194f21cdf24bf23864cac"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/8226e37d82f43657da34dd770e2b38f20242ada7"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:45Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-3j53-j44c-wp43/GHSA-3j53-j44c-wp43.json b/advisories/unreviewed/2025/03/GHSA-3j53-j44c-wp43/GHSA-3j53-j44c-wp43.json
new file mode 100644
index 00000000000..c8ffa61fc2d
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-3j53-j44c-wp43/GHSA-3j53-j44c-wp43.json
@@ -0,0 +1,37 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-3j53-j44c-wp43",
+ "modified": "2025-03-27T18:31:25Z",
+ "published": "2025-03-27T18:31:25Z",
+ "aliases": [
+ "CVE-2023-52936"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nkernel/irq/irqdomain.c: fix memory leak with using debugfs_lookup()\n\nWhen calling debugfs_lookup() the result must have dput() called on it,\notherwise the memory will leak over time. To make things simpler, just\ncall debugfs_lookup_and_remove() instead which handles all of the logic\nat once.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52936"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/066ecbf1a53eb0b92b10c8df7808666be6ea5681"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/cf1c917bf1c761a557b26410024e90057646c049"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/d83d7ed260283560700d4034a80baad46620481b"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:43Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-3m27-46p7-w7mh/GHSA-3m27-46p7-w7mh.json b/advisories/unreviewed/2025/03/GHSA-3m27-46p7-w7mh/GHSA-3m27-46p7-w7mh.json
new file mode 100644
index 00000000000..3090a9a891f
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-3m27-46p7-w7mh/GHSA-3m27-46p7-w7mh.json
@@ -0,0 +1,41 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-3m27-46p7-w7mh",
+ "modified": "2025-03-27T18:31:26Z",
+ "published": "2025-03-27T18:31:26Z",
+ "aliases": [
+ "CVE-2023-52986"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf, sockmap: Check for any of tcp_bpf_prots when cloning a listener\n\nA listening socket linked to a sockmap has its sk_prot overridden. It\npoints to one of the struct proto variants in tcp_bpf_prots. The variant\ndepends on the socket's family and which sockmap programs are attached.\n\nA child socket cloned from a TCP listener initially inherits their sk_prot.\nBut before cloning is finished, we restore the child's proto to the\nlistener's original non-tcp_bpf_prots one. This happens in\ntcp_create_openreq_child -> tcp_bpf_clone.\n\nToday, in tcp_bpf_clone we detect if the child's proto should be restored\nby checking only for the TCP_BPF_BASE proto variant. This is not\ncorrect. The sk_prot of listening socket linked to a sockmap can point to\nto any variant in tcp_bpf_prots.\n\nIf the listeners sk_prot happens to be not the TCP_BPF_BASE variant, then\nthe child socket unintentionally is left if the inherited sk_prot by\ntcp_bpf_clone.\n\nThis leads to issues like infinite recursion on close [1], because the\nchild state is otherwise not set up for use with tcp_bpf_prot operations.\n\nAdjust the check in tcp_bpf_clone to detect all of tcp_bpf_prots variants.\n\nNote that it wouldn't be sufficient to check the socket state when\noverriding the sk_prot in tcp_bpf_update_proto in order to always use the\nTCP_BPF_BASE variant for listening sockets. Since commit\nb8b8315e39ff (\"bpf, sockmap: Remove unhash handler for BPF sockmap usage\")\nit is possible for a socket to transition to TCP_LISTEN state while already\nlinked to a sockmap, e.g. connect() -> insert into map ->\nconnect(AF_UNSPEC) -> listen().\n\n[1]: https://lore.kernel.org/all/00000000000073b14905ef2e7401@google.com/",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52986"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/12b0ec7c6953e1602957926439e5297095d7d065"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/9bd6074e1872d22190a8da30e796cbf937d334f0"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/c681d7a4ed3d360de0574f4d6b7305a8de8dc54f"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/ddce1e091757d0259107c6c0c7262df201de2b66"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:45Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-3vpw-mc3x-93rw/GHSA-3vpw-mc3x-93rw.json b/advisories/unreviewed/2025/03/GHSA-3vpw-mc3x-93rw/GHSA-3vpw-mc3x-93rw.json
new file mode 100644
index 00000000000..ec44f323b9e
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-3vpw-mc3x-93rw/GHSA-3vpw-mc3x-93rw.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-3vpw-mc3x-93rw",
+ "modified": "2025-03-27T18:31:23Z",
+ "published": "2025-03-27T18:31:23Z",
+ "aliases": [
+ "CVE-2025-22629"
+ ],
+ "details": "Missing Authorization vulnerability in iNET iNET Webkit allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects iNET Webkit: from n/a through 1.2.2.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22629"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/inet-webkit/vulnerability/wordpress-inet-webkit-plugin-1-2-2-broken-access-control-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-862"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T16:15:28Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-443g-xxfv-37vx/GHSA-443g-xxfv-37vx.json b/advisories/unreviewed/2025/03/GHSA-443g-xxfv-37vx/GHSA-443g-xxfv-37vx.json
new file mode 100644
index 00000000000..87a1bf68321
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-443g-xxfv-37vx/GHSA-443g-xxfv-37vx.json
@@ -0,0 +1,53 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-443g-xxfv-37vx",
+ "modified": "2025-03-27T18:31:25Z",
+ "published": "2025-03-27T18:31:25Z",
+ "aliases": [
+ "CVE-2023-52932"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/swapfile: add cond_resched() in get_swap_pages()\n\nThe softlockup still occurs in get_swap_pages() under memory pressure. 64\nCPU cores, 64GB memory, and 28 zram devices, the disksize of each zram\ndevice is 50MB with same priority as si. Use the stress-ng tool to\nincrease memory pressure, causing the system to oom frequently.\n\nThe plist_for_each_entry_safe() loops in get_swap_pages() could reach tens\nof thousands of times to find available space (extreme case:\ncond_resched() is not called in scan_swap_map_slots()). Let's add\ncond_resched() into get_swap_pages() when failed to find available space\nto avoid softlockup.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52932"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/29f0349c5c76b627fe06b87d4b13fa03a6ce8e64"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/30187be29052bba9203b0ae2bdd815e0bc2faaab"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/387217b97e99699c34e6d95ce2b91b327fcd853e"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/49178d4d61e78aed8c837dfeea8a450700f196e2"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/5dbe1ebd56470d03b78fc31491a9e4d433106ef2"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/7717fc1a12f88701573f9ed897cc4f6699c661e3"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/d49c85a1913385eed46dd16a25ad0928253767f0"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:42Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-47gf-fpw6-jjhw/GHSA-47gf-fpw6-jjhw.json b/advisories/unreviewed/2025/03/GHSA-47gf-fpw6-jjhw/GHSA-47gf-fpw6-jjhw.json
new file mode 100644
index 00000000000..94ed22cc5cc
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-47gf-fpw6-jjhw/GHSA-47gf-fpw6-jjhw.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-47gf-fpw6-jjhw",
+ "modified": "2025-03-27T18:31:22Z",
+ "published": "2025-03-27T18:31:22Z",
+ "aliases": [
+ "CVE-2025-22278"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in yudleethemes Whitish Lite allows Stored XSS.This issue affects Whitish Lite: from n/a through 2.1.13.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22278"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/theme/whitish-lite/vulnerability/wordpress-whitish-lite-theme-2-1-13-stored-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T16:15:27Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-4997-qrqv-f5m7/GHSA-4997-qrqv-f5m7.json b/advisories/unreviewed/2025/03/GHSA-4997-qrqv-f5m7/GHSA-4997-qrqv-f5m7.json
new file mode 100644
index 00000000000..84413efc4db
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-4997-qrqv-f5m7/GHSA-4997-qrqv-f5m7.json
@@ -0,0 +1,33 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-4997-qrqv-f5m7",
+ "modified": "2025-03-27T18:31:28Z",
+ "published": "2025-03-27T18:31:28Z",
+ "aliases": [
+ "CVE-2023-53018"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_conn: Fix memory leaks\n\nWhen hci_cmd_sync_queue() failed in hci_le_terminate_big() or\nhci_le_big_terminate(), the memory pointed by variable d is not freed,\nwhich will cause memory leak. Add release process to error path.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-53018"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/3aa21311f36d8a2730c7ccef37235e951f23927b"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/f51a825b9f730a782aa768454906b4468e67b667"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:51Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-49f7-q2j4-qfwq/GHSA-49f7-q2j4-qfwq.json b/advisories/unreviewed/2025/03/GHSA-49f7-q2j4-qfwq/GHSA-49f7-q2j4-qfwq.json
new file mode 100644
index 00000000000..60d69576618
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-49f7-q2j4-qfwq/GHSA-49f7-q2j4-qfwq.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-49f7-q2j4-qfwq",
+ "modified": "2025-03-27T18:31:23Z",
+ "published": "2025-03-27T18:31:23Z",
+ "aliases": [
+ "CVE-2025-22638"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Acowebs Product Table For WooCommerce allows Stored XSS.This issue affects Product Table For WooCommerce: from n/a through 1.2.3.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22638"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/product-table-for-woocommerce/vulnerability/wordpress-product-table-for-woocommerce-plugin-1-2-3-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T16:15:28Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-4j5r-8cvm-p98h/GHSA-4j5r-8cvm-p98h.json b/advisories/unreviewed/2025/03/GHSA-4j5r-8cvm-p98h/GHSA-4j5r-8cvm-p98h.json
new file mode 100644
index 00000000000..cc840270ec9
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-4j5r-8cvm-p98h/GHSA-4j5r-8cvm-p98h.json
@@ -0,0 +1,53 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-4j5r-8cvm-p98h",
+ "modified": "2025-03-27T18:31:26Z",
+ "published": "2025-03-27T18:31:26Z",
+ "aliases": [
+ "CVE-2023-52988"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: hda/via: Avoid potential array out-of-bound in add_secret_dac_path()\n\nsnd_hda_get_connections() can return a negative error code.\nIt may lead to accessing 'conn' array at a negative index.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52988"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/1b9256c96220bcdba287eeeb90e7c910c77f8c46"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/2b557fa635e7487f638c0f030c305870839eeda2"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/437e50ef6290ac835d526d0e45f466a0aa69ba1b"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/6e1f586ddec48d71016b81acf68ba9f49ca54db8"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/b9cee506da2b7920b5ea02ccd8e78a907d0ee7aa"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/d6870f3800dbb212ae8433183ee82f566d067c6c"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/f011360ad234a07cb6fbcc720fff646a93a9f0d6"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:46Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-4x8g-3q83-5465/GHSA-4x8g-3q83-5465.json b/advisories/unreviewed/2025/03/GHSA-4x8g-3q83-5465/GHSA-4x8g-3q83-5465.json
new file mode 100644
index 00000000000..07f32bbd03d
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-4x8g-3q83-5465/GHSA-4x8g-3q83-5465.json
@@ -0,0 +1,53 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-4x8g-3q83-5465",
+ "modified": "2025-03-27T18:31:28Z",
+ "published": "2025-03-27T18:31:28Z",
+ "aliases": [
+ "CVE-2023-53019"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: mdio: validate parameter addr in mdiobus_get_phy()\n\nThe caller may pass any value as addr, what may result in an out-of-bounds\naccess to array mdio_map. One existing case is stmmac_init_phy() that\nmay pass -1 as addr. Therefore validate addr before using it.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-53019"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/1d80c259dfbadefa61b7ea334dfce5cb57f8c72f"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/4bc5f1f6bc94e695dfd912122af96e7115a0ddb8"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/7879626296e6ffd838ae0f2af1ab49ee46354973"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/867dbe784c5010a466f00a7d1467c1c5ea569c75"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/8a7b9560a3a8eb8724888c426e05926752f73aa0"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/ad67de330d83e8078372b52af18ffe8d39e26c85"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/c431a3d642593bbdb99e8a9e3eed608b730db6f8"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:51Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-4xh9-2qp4-9r3m/GHSA-4xh9-2qp4-9r3m.json b/advisories/unreviewed/2025/03/GHSA-4xh9-2qp4-9r3m/GHSA-4xh9-2qp4-9r3m.json
index 51096ed0e1e..8fa2be74a41 100644
--- a/advisories/unreviewed/2025/03/GHSA-4xh9-2qp4-9r3m/GHSA-4xh9-2qp4-9r3m.json
+++ b/advisories/unreviewed/2025/03/GHSA-4xh9-2qp4-9r3m/GHSA-4xh9-2qp4-9r3m.json
@@ -46,7 +46,8 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-74"
+ "CWE-74",
+ "CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2025/03/GHSA-54mv-r6h5-c8vf/GHSA-54mv-r6h5-c8vf.json b/advisories/unreviewed/2025/03/GHSA-54mv-r6h5-c8vf/GHSA-54mv-r6h5-c8vf.json
new file mode 100644
index 00000000000..88ac3f58744
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-54mv-r6h5-c8vf/GHSA-54mv-r6h5-c8vf.json
@@ -0,0 +1,45 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-54mv-r6h5-c8vf",
+ "modified": "2025-03-27T18:31:23Z",
+ "published": "2025-03-27T18:31:23Z",
+ "aliases": [
+ "CVE-2021-4454"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: j1939: fix errant WARN_ON_ONCE in j1939_session_deactivate\n\nThe conclusion \"j1939_session_deactivate() should be called with a\nsession ref-count of at least 2\" is incorrect. In some concurrent\nscenarios, j1939_session_deactivate can be called with the session\nref-count less than 2. But there is not any problem because it\nwill check the session active state before session putting in\nj1939_session_deactivate_locked().\n\nHere is the concurrent scenario of the problem reported by syzbot\nand my reproduction log.\n\n cpu0 cpu1\n j1939_xtp_rx_eoma\nj1939_xtp_rx_abort_one\n j1939_session_get_by_addr [kref == 2]\nj1939_session_get_by_addr [kref == 3]\nj1939_session_deactivate [kref == 2]\nj1939_session_put [kref == 1]\n\t\t\t\tj1939_session_completed\n\t\t\t\tj1939_session_deactivate\n\t\t\t\tWARN_ON_ONCE(kref < 2)\n\n=====================================================\nWARNING: CPU: 1 PID: 21 at net/can/j1939/transport.c:1088 j1939_session_deactivate+0x5f/0x70\nCPU: 1 PID: 21 Comm: ksoftirqd/1 Not tainted 5.14.0-rc7+ #32\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.13.0-1ubuntu1 04/01/2014\nRIP: 0010:j1939_session_deactivate+0x5f/0x70\nCall Trace:\n j1939_session_deactivate_activate_next+0x11/0x28\n j1939_xtp_rx_eoma+0x12a/0x180\n j1939_tp_recv+0x4a2/0x510\n j1939_can_recv+0x226/0x380\n can_rcv_filter+0xf8/0x220\n can_receive+0x102/0x220\n ? process_backlog+0xf0/0x2c0\n can_rcv+0x53/0xf0\n __netif_receive_skb_one_core+0x67/0x90\n ? process_backlog+0x97/0x2c0\n __netif_receive_skb+0x22/0x80",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-4454"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/1740a1e45eee65099a92fb502e1e67e63aad277d"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/6950df42a03c9ac9290503ced3f371199cb68fa9"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/9ab896775f98ff54b68512f345eed178bf961084"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/b6d44072117bba057d50f7a2f96e5d070c65926d"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/d0553680f94c49bbe0e39eb50d033ba563b4212d"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:35Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-56r2-5qqm-ppfv/GHSA-56r2-5qqm-ppfv.json b/advisories/unreviewed/2025/03/GHSA-56r2-5qqm-ppfv/GHSA-56r2-5qqm-ppfv.json
new file mode 100644
index 00000000000..538fb596e81
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-56r2-5qqm-ppfv/GHSA-56r2-5qqm-ppfv.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-56r2-5qqm-ppfv",
+ "modified": "2025-03-27T18:31:29Z",
+ "published": "2025-03-27T18:31:29Z",
+ "aliases": [
+ "CVE-2023-37405"
+ ],
+ "details": "IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.36 iFix1, 2.3.3.6 iFix2, 2.3.3.7, 2.3.3.7 iFix1, 2.3.4.0, and 2.3.4.1 stores sensitive data in memory, that could be obtained by an unauthorized user.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37405"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.ibm.com/support/pages/node/7229212"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-311"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T18:17:28Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-57pw-gf47-fr76/GHSA-57pw-gf47-fr76.json b/advisories/unreviewed/2025/03/GHSA-57pw-gf47-fr76/GHSA-57pw-gf47-fr76.json
new file mode 100644
index 00000000000..7f91f3bdf38
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-57pw-gf47-fr76/GHSA-57pw-gf47-fr76.json
@@ -0,0 +1,33 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-57pw-gf47-fr76",
+ "modified": "2025-03-27T18:31:24Z",
+ "published": "2025-03-27T18:31:24Z",
+ "aliases": [
+ "CVE-2022-49756"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nphy: usb: sunplus: Fix potential null-ptr-deref in sp_usb_phy_probe()\n\nsp_usb_phy_probe() will call platform_get_resource_byname() that may fail\nand return NULL. devm_ioremap() will use usbphy->moon4_res_mem->start as\ninput, which may causes null-ptr-deref. Check the ret value of\nplatform_get_resource_byname() to avoid the null-ptr-deref.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49756"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/17eee264ef386ef30a69dd70e36f29893b85c170"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/d838b5c99bcecd593b4710a93fce8fdbf122395b"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:40Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-592q-r679-2jpc/GHSA-592q-r679-2jpc.json b/advisories/unreviewed/2025/03/GHSA-592q-r679-2jpc/GHSA-592q-r679-2jpc.json
new file mode 100644
index 00000000000..2e511d0a343
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-592q-r679-2jpc/GHSA-592q-r679-2jpc.json
@@ -0,0 +1,53 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-592q-r679-2jpc",
+ "modified": "2025-03-27T18:31:26Z",
+ "published": "2025-03-27T18:31:26Z",
+ "aliases": [
+ "CVE-2023-52979"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsquashfs: harden sanity check in squashfs_read_xattr_id_table\n\nWhile mounting a corrupted filesystem, a signed integer '*xattr_ids' can\nbecome less than zero. This leads to the incorrect computation of 'len'\nand 'indexes' values which can cause null-ptr-deref in copy_bio_to_actor()\nor out-of-bounds accesses in the next sanity checks inside\nsquashfs_read_xattr_id_table().\n\nFound by Linux Verification Center (linuxtesting.org) with Syzkaller.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52979"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/29e774dcb27116c06b9c57b1f1f14a1623738989"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/72e544b1b28325fe78a4687b980871a7e4101f76"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/b30a74f83265c24d1d0842c6c3928cd2e775a3fb"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/b7398efe24a965cf3937b716c0b1011c201c5d6e"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/cf5d6612092408157db6bb500c70bf6d67c40fbc"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/db76fc535fbdfbf29fd0b93e49627537ad794c8c"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/de2785aa3448d1ee7be3ab47fd4a873025f1b3d7"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:45Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-5rg6-fchv-4f55/GHSA-5rg6-fchv-4f55.json b/advisories/unreviewed/2025/03/GHSA-5rg6-fchv-4f55/GHSA-5rg6-fchv-4f55.json
new file mode 100644
index 00000000000..3025a5f6c9c
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-5rg6-fchv-4f55/GHSA-5rg6-fchv-4f55.json
@@ -0,0 +1,29 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-5rg6-fchv-4f55",
+ "modified": "2025-03-27T18:31:23Z",
+ "published": "2025-03-27T18:31:23Z",
+ "aliases": [
+ "CVE-2025-28135"
+ ],
+ "details": "TOTOLINK A810R V4.1.2cu.5182_B20201026 was found to contain a buffer overflow vulnerability in downloadFile.cgi.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28135"
+ },
+ {
+ "type": "WEB",
+ "url": "https://sudsy-eyeliner-a59.notion.site/BufferOverflow-V4-1-2cu-5182_B20201026-19872b8cd95f80808902fac8449fee64"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T16:15:30Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-5w7q-3v7j-8q5q/GHSA-5w7q-3v7j-8q5q.json b/advisories/unreviewed/2025/03/GHSA-5w7q-3v7j-8q5q/GHSA-5w7q-3v7j-8q5q.json
new file mode 100644
index 00000000000..49bfb4f4ece
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-5w7q-3v7j-8q5q/GHSA-5w7q-3v7j-8q5q.json
@@ -0,0 +1,33 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-5w7q-3v7j-8q5q",
+ "modified": "2025-03-27T18:31:26Z",
+ "published": "2025-03-27T18:31:26Z",
+ "aliases": [
+ "CVE-2023-52942"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncgroup/cpuset: Fix wrong check in update_parent_subparts_cpumask()\n\nIt was found that the check to see if a partition could use up all\nthe cpus from the parent cpuset in update_parent_subparts_cpumask()\nwas incorrect. As a result, it is possible to leave parent with no\neffective cpu left even if there are tasks in the parent cpuset. This\ncan lead to system panic as reported in [1].\n\nFix this probem by updating the check to fail the enabling the partition\nif parent's effective_cpus is a subset of the child's cpus_allowed.\n\nAlso record the error code when an error happens in update_prstate()\nand add a test case where parent partition and child have the same cpu\nlist and parent has task. Enabling partition in the child will fail in\nthis case.\n\n[1] https://www.spinics.net/lists/cgroups/msg36254.html",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52942"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/a2ab7f2cf5ef8f0c6212a246e681d1fe358cec1f"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/e5ae8803847b80fe9d744a3174abe2b7bfed222a"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:44Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-6gh5-4fvc-rw6c/GHSA-6gh5-4fvc-rw6c.json b/advisories/unreviewed/2025/03/GHSA-6gh5-4fvc-rw6c/GHSA-6gh5-4fvc-rw6c.json
new file mode 100644
index 00000000000..00b59277aed
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-6gh5-4fvc-rw6c/GHSA-6gh5-4fvc-rw6c.json
@@ -0,0 +1,33 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-6gh5-4fvc-rw6c",
+ "modified": "2025-03-27T18:31:25Z",
+ "published": "2025-03-27T18:31:25Z",
+ "aliases": [
+ "CVE-2023-52938"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: typec: ucsi: Don't attempt to resume the ports before they exist\n\nThis will fix null pointer dereference that was caused by\nthe driver attempting to resume ports that were not yet\nregistered.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52938"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/f82060da749c611ed427523b6d1605d87338aac1"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/fdd11d7136fd070b3a74d6d8799d9eac28a57fc5"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:43Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-6rc5-mh5g-63wm/GHSA-6rc5-mh5g-63wm.json b/advisories/unreviewed/2025/03/GHSA-6rc5-mh5g-63wm/GHSA-6rc5-mh5g-63wm.json
new file mode 100644
index 00000000000..b9cc969b6b0
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-6rc5-mh5g-63wm/GHSA-6rc5-mh5g-63wm.json
@@ -0,0 +1,33 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-6rc5-mh5g-63wm",
+ "modified": "2025-03-27T18:31:25Z",
+ "published": "2025-03-27T18:31:25Z",
+ "aliases": [
+ "CVE-2023-52934"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/MADV_COLLAPSE: catch !none !huge !bad pmd lookups\n\nIn commit 34488399fa08 (\"mm/madvise: add file and shmem support to\nMADV_COLLAPSE\") we make the following change to find_pmd_or_thp_or_none():\n\n\t- if (!pmd_present(pmde))\n\t- return SCAN_PMD_NULL;\n\t+ if (pmd_none(pmde))\n\t+ return SCAN_PMD_NONE;\n\nThis was for-use by MADV_COLLAPSE file/shmem codepaths, where\nMADV_COLLAPSE might identify a pte-mapped hugepage, only to have\nkhugepaged race-in, free the pte table, and clear the pmd. Such codepaths\ninclude:\n\nA) If we find a suitably-aligned compound page of order HPAGE_PMD_ORDER\n already in the pagecache.\nB) In retract_page_tables(), if we fail to grab mmap_lock for the target\n mm/address.\n\nIn these cases, collapse_pte_mapped_thp() really does expect a none (not\njust !present) pmd, and we want to suitably identify that case separate\nfrom the case where no pmd is found, or it's a bad-pmd (of course, many\nthings could happen once we drop mmap_lock, and the pmd could plausibly\nundergo multiple transitions due to intervening fault, split, etc). \nRegardless, the code is prepared install a huge-pmd only when the existing\npmd entry is either a genuine pte-table-mapping-pmd, or the none-pmd.\n\nHowever, the commit introduces a logical hole; namely, that we've allowed\n!none- && !huge- && !bad-pmds to be classified as genuine\npte-table-mapping-pmds. One such example that could leak through are swap\nentries. The pmd values aren't checked again before use in\npte_offset_map_lock(), which is expecting nothing less than a genuine\npte-table-mapping-pmd.\n\nWe want to put back the !pmd_present() check (below the pmd_none() check),\nbut need to be careful to deal with subtleties in pmd transitions and\ntreatments by various arch.\n\nThe issue is that __split_huge_pmd_locked() temporarily clears the present\nbit (or otherwise marks the entry as invalid), but pmd_present() and\npmd_trans_huge() still need to return true while the pmd is in this\ntransitory state. For example, x86's pmd_present() also checks the\n_PAGE_PSE , riscv's version also checks the _PAGE_LEAF bit, and arm64 also\nchecks a PMD_PRESENT_INVALID bit.\n\nCovering all 4 cases for x86 (all checks done on the same pmd value):\n\n1) pmd_present() && pmd_trans_huge()\n All we actually know here is that the PSE bit is set. Either:\n a) We aren't racing with __split_huge_page(), and PRESENT or PROTNONE\n is set.\n => huge-pmd\n b) We are currently racing with __split_huge_page(). The danger here\n is that we proceed as-if we have a huge-pmd, but really we are\n looking at a pte-mapping-pmd. So, what is the risk of this\n danger?\n\n The only relevant path is:\n\n\tmadvise_collapse() -> collapse_pte_mapped_thp()\n\n Where we might just incorrectly report back \"success\", when really\n the memory isn't pmd-backed. This is fine, since split could\n happen immediately after (actually) successful madvise_collapse().\n So, it should be safe to just assume huge-pmd here.\n\n2) pmd_present() && !pmd_trans_huge()\n Either:\n a) PSE not set and either PRESENT or PROTNONE is.\n => pte-table-mapping pmd (or PROT_NONE)\n b) devmap. This routine can be called immediately after\n unlocking/locking mmap_lock -- or called with no locks held (see\n khugepaged_scan_mm_slot()), so previous VMA checks have since been\n invalidated.\n\n3) !pmd_present() && pmd_trans_huge()\n Not possible.\n\n4) !pmd_present() && !pmd_trans_huge()\n Neither PRESENT nor PROTNONE set\n => not present\n\nI've checked all archs that implement pmd_trans_huge() (arm64, riscv,\npowerpc, longarch, x86, mips, s390) and this logic roughly translates\n(though devmap treatment is unique to x86 and powerpc, and (3) doesn't\nnecessarily hold in general -- but that doesn't matter since\n!pmd_present() always takes failure path).\n\nAlso, add a comment above find_pmd_or_thp_or_none()\n---truncated---",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52934"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/96aaaf8666010a39430cecf8a65c7ce2908a030f"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/edb5d0cf5525357652aff6eacd9850b8ced07143"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:43Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-6v4g-pv75-fm7f/GHSA-6v4g-pv75-fm7f.json b/advisories/unreviewed/2025/03/GHSA-6v4g-pv75-fm7f/GHSA-6v4g-pv75-fm7f.json
new file mode 100644
index 00000000000..171b375a6d6
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-6v4g-pv75-fm7f/GHSA-6v4g-pv75-fm7f.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-6v4g-pv75-fm7f",
+ "modified": "2025-03-27T18:31:23Z",
+ "published": "2025-03-27T18:31:23Z",
+ "aliases": [
+ "CVE-2025-22496"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MarMar8x Notif Bell allows Stored XSS.This issue affects Notif Bell: from n/a through 0.9.8.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22496"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/notif-bell/vulnerability/wordpress-notif-bell-plugin-0-9-8-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T16:15:27Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-73pj-2jcm-q7xj/GHSA-73pj-2jcm-q7xj.json b/advisories/unreviewed/2025/03/GHSA-73pj-2jcm-q7xj/GHSA-73pj-2jcm-q7xj.json
new file mode 100644
index 00000000000..35985fd614c
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-73pj-2jcm-q7xj/GHSA-73pj-2jcm-q7xj.json
@@ -0,0 +1,33 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-73pj-2jcm-q7xj",
+ "modified": "2025-03-27T18:31:26Z",
+ "published": "2025-03-27T18:31:26Z",
+ "aliases": [
+ "CVE-2023-52981"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/i915: Fix request ref counting during error capture & debugfs dump\n\nWhen GuC support was added to error capture, the reference counting\naround the request object was broken. Fix it up.\n\nThe context based search manages the spinlocking around the search\ninternally. So it needs to grab the reference count internally as\nwell. The execlist only request based search relies on external\nlocking, so it needs an external reference count but within the\nspinlock not outside it.\n\nThe only other caller of the context based search is the code for\ndumping engine state to debugfs. That code wasn't previously getting\nan explicit reference at all as it does everything while holding the\nexeclist specific spinlock. So, that needs updaing as well as that\nspinlock doesn't help when using GuC submission. Rather than trying to\nconditionally get/put depending on submission model, just change it to\nalways do the get/put.\n\nv2: Explicitly document adding an extra blank line in some dense code\n(Andy Shevchenko). Fix multiple potential null pointer derefs in case\nof no request found (some spotted by Tvrtko, but there was more!).\nAlso fix a leaked request in case of !started and another in\n__guc_reset_context now that intel_context_find_active_request is\nactually reference counting the returned request.\nv3: Add a _get suffix to intel_context_find_active_request now that it\ngrabs a reference (Daniele).\nv4: Split the intel_guc_find_hung_context change to a separate patch\nand rename intel_context_find_active_request_get to\nintel_context_get_active_request (Tvrtko).\nv5: s/locking/reference counting/ in commit message (Tvrtko)\n\n(cherry picked from commit 3700e353781e27f1bc7222f51f2cc36cbeb9b4ec)",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52981"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/86d8ddc74124c3fdfc139f246ba6da15e45e86e3"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/9467397f417dd7b5d0db91452f0474e79716a527"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:45Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-75fp-4g7m-cr39/GHSA-75fp-4g7m-cr39.json b/advisories/unreviewed/2025/03/GHSA-75fp-4g7m-cr39/GHSA-75fp-4g7m-cr39.json
new file mode 100644
index 00000000000..d48c60f2e1f
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-75fp-4g7m-cr39/GHSA-75fp-4g7m-cr39.json
@@ -0,0 +1,33 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-75fp-4g7m-cr39",
+ "modified": "2025-03-27T18:31:24Z",
+ "published": "2025-03-27T18:31:24Z",
+ "aliases": [
+ "CVE-2022-49745"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfpga: m10bmc-sec: Fix probe rollback\n\nHandle probe error rollbacks properly to avoid leaks.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49745"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/60ce26d10e5850f33cc76fce52f5377045e75a15"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/74cff472d3d66db13b5ef64f40dfa42383f71ff7"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:39Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-76g9-mx4c-qm64/GHSA-76g9-mx4c-qm64.json b/advisories/unreviewed/2025/03/GHSA-76g9-mx4c-qm64/GHSA-76g9-mx4c-qm64.json
new file mode 100644
index 00000000000..dc2c8d1f088
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-76g9-mx4c-qm64/GHSA-76g9-mx4c-qm64.json
@@ -0,0 +1,37 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-76g9-mx4c-qm64",
+ "modified": "2025-03-27T18:31:27Z",
+ "published": "2025-03-27T18:31:27Z",
+ "aliases": [
+ "CVE-2023-52995"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nriscv/kprobe: Fix instruction simulation of JALR\n\nSet kprobe at 'jalr 1140(ra)' of vfs_write results in the following\ncrash:\n\n[ 32.092235] Unable to handle kernel access to user memory without uaccess routines at virtual address 00aaaaaad77b1170\n[ 32.093115] Oops [#1]\n[ 32.093251] Modules linked in:\n[ 32.093626] CPU: 0 PID: 135 Comm: ftracetest Not tainted 6.2.0-rc2-00013-gb0aa5e5df0cb-dirty #16\n[ 32.093985] Hardware name: riscv-virtio,qemu (DT)\n[ 32.094280] epc : ksys_read+0x88/0xd6\n[ 32.094855] ra : ksys_read+0xc0/0xd6\n[ 32.095016] epc : ffffffff801cda80 ra : ffffffff801cdab8 sp : ff20000000d7bdc0\n[ 32.095227] gp : ffffffff80f14000 tp : ff60000080f9cb40 t0 : ffffffff80f13e80\n[ 32.095500] t1 : ffffffff8000c29c t2 : ffffffff800dbc54 s0 : ff20000000d7be60\n[ 32.095716] s1 : 0000000000000000 a0 : ffffffff805a64ae a1 : ffffffff80a83708\n[ 32.095921] a2 : ffffffff80f160a0 a3 : 0000000000000000 a4 : f229b0afdb165300\n[ 32.096171] a5 : f229b0afdb165300 a6 : ffffffff80eeebd0 a7 : 00000000000003ff\n[ 32.096411] s2 : ff6000007ff76800 s3 : fffffffffffffff7 s4 : 00aaaaaad77b1170\n[ 32.096638] s5 : ffffffff80f160a0 s6 : ff6000007ff76800 s7 : 0000000000000030\n[ 32.096865] s8 : 00ffffffc3d97be0 s9 : 0000000000000007 s10: 00aaaaaad77c9410\n[ 32.097092] s11: 0000000000000000 t3 : ffffffff80f13e48 t4 : ffffffff8000c29c\n[ 32.097317] t5 : ffffffff8000c29c t6 : ffffffff800dbc54\n[ 32.097505] status: 0000000200000120 badaddr: 00aaaaaad77b1170 cause: 000000000000000d\n[ 32.098011] [] ksys_write+0x6c/0xd6\n[ 32.098222] [] sys_write+0x2a/0x38\n[ 32.098405] [] ret_from_syscall+0x0/0x2\n\nSince the rs1 and rd might be the same one, such as 'jalr 1140(ra)',\nhence it requires obtaining the target address from rs1 followed by\nupdating rd.\n\n[Palmer: Pick Guo's cleanup]",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52995"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/614471b7f7cd28a2c96ab9c90b37471c82258ffb"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/ca0254998be4d74cf6add70ccfab0d2dbd362a10"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/f4c8fc775fcbc9e9047b22671c55ca18f9a127d4"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:48Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-7fmf-h6vh-qp27/GHSA-7fmf-h6vh-qp27.json b/advisories/unreviewed/2025/03/GHSA-7fmf-h6vh-qp27/GHSA-7fmf-h6vh-qp27.json
new file mode 100644
index 00000000000..22ab05f6b7c
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-7fmf-h6vh-qp27/GHSA-7fmf-h6vh-qp27.json
@@ -0,0 +1,41 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-7fmf-h6vh-qp27",
+ "modified": "2025-03-27T18:31:28Z",
+ "published": "2025-03-27T18:31:28Z",
+ "aliases": [
+ "CVE-2023-53020"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nl2tp: close all race conditions in l2tp_tunnel_register()\n\nThe code in l2tp_tunnel_register() is racy in several ways:\n\n1. It modifies the tunnel socket _after_ publishing it.\n\n2. It calls setup_udp_tunnel_sock() on an existing socket without\n locking.\n\n3. It changes sock lock class on fly, which triggers many syzbot\n reports.\n\nThis patch amends all of them by moving socket initialization code\nbefore publishing and under sock lock. As suggested by Jakub, the\nl2tp lockdep class is not necessary as we can just switch to\nbh_lock_sock_nested().",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-53020"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/0b2c59720e65885a394a017d0cf9cab118914682"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/2d77e5c0ad79004b5ef901895437e9cce6dfcc7e"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/77e8ed776cdb1a24b2aab8fe7c6f1f154235e1ce"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/cef0845b6dcfa2f6c2c832e7f9622551456c741d"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:51Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-7hqh-xh4r-x7q4/GHSA-7hqh-xh4r-x7q4.json b/advisories/unreviewed/2025/03/GHSA-7hqh-xh4r-x7q4/GHSA-7hqh-xh4r-x7q4.json
index ed7ad0e8381..d32324d6e59 100644
--- a/advisories/unreviewed/2025/03/GHSA-7hqh-xh4r-x7q4/GHSA-7hqh-xh4r-x7q4.json
+++ b/advisories/unreviewed/2025/03/GHSA-7hqh-xh4r-x7q4/GHSA-7hqh-xh4r-x7q4.json
@@ -26,7 +26,8 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-121"
+ "CWE-121",
+ "CWE-787"
],
"severity": "HIGH",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2025/03/GHSA-7m9p-x22p-v2hg/GHSA-7m9p-x22p-v2hg.json b/advisories/unreviewed/2025/03/GHSA-7m9p-x22p-v2hg/GHSA-7m9p-x22p-v2hg.json
new file mode 100644
index 00000000000..f7d982a5ab6
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-7m9p-x22p-v2hg/GHSA-7m9p-x22p-v2hg.json
@@ -0,0 +1,37 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-7m9p-x22p-v2hg",
+ "modified": "2025-03-27T18:31:26Z",
+ "published": "2025-03-27T18:31:26Z",
+ "aliases": [
+ "CVE-2023-52978"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nriscv: kprobe: Fixup kernel panic when probing an illegal position\n\nThe kernel would panic when probed for an illegal position. eg:\n\n(CONFIG_RISCV_ISA_C=n)\n\necho 'p:hello kernel_clone+0x16 a0=%a0' >> kprobe_events\necho 1 > events/kprobes/hello/enable\ncat trace\n\nKernel panic - not syncing: stack-protector: Kernel stack\nis corrupted in: __do_sys_newfstatat+0xb8/0xb8\nCPU: 0 PID: 111 Comm: sh Not tainted\n6.2.0-rc1-00027-g2d398fe49a4d #490\nHardware name: riscv-virtio,qemu (DT)\nCall Trace:\n[] dump_backtrace+0x38/0x48\n[] show_stack+0x50/0x68\n[] dump_stack_lvl+0x60/0x84\n[] dump_stack+0x20/0x30\n[] panic+0x160/0x374\n[] generic_handle_arch_irq+0x0/0xa8\n[] sys_newstat+0x0/0x30\n[] sys_clone+0x20/0x30\n[] ret_from_syscall+0x0/0x4\n---[ end Kernel panic - not syncing: stack-protector:\nKernel stack is corrupted in: __do_sys_newfstatat+0xb8/0xb8 ]---\n\nThat is because the kprobe's ebreak instruction broke the kernel's\noriginal code. The user should guarantee the correction of the probe\nposition, but it couldn't make the kernel panic.\n\nThis patch adds arch_check_kprobe in arch_prepare_kprobe to prevent an\nillegal position (Such as the middle of an instruction).",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52978"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/04a73558209554da17f46490ec4faaaf1b2bab68"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/12316538b1d193064109ce1a28fc9bacd43950de"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/87f48c7ccc73afc78630530d9af51f458f58cab8"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:44Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-7mjx-q39g-f9qc/GHSA-7mjx-q39g-f9qc.json b/advisories/unreviewed/2025/03/GHSA-7mjx-q39g-f9qc/GHSA-7mjx-q39g-f9qc.json
new file mode 100644
index 00000000000..7a89d790cf8
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-7mjx-q39g-f9qc/GHSA-7mjx-q39g-f9qc.json
@@ -0,0 +1,33 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-7mjx-q39g-f9qc",
+ "modified": "2025-03-27T18:31:27Z",
+ "published": "2025-03-27T18:31:27Z",
+ "aliases": [
+ "CVE-2023-53004"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\novl: fix tmpfile leak\n\nMissed an error cleanup.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-53004"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/baabaa505563362b71f2637aedd7b807d270656c"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/caa0ea92503f8afa1941f6ac899e5c4e3f6ec8bb"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:49Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-7r4r-7wg2-96vj/GHSA-7r4r-7wg2-96vj.json b/advisories/unreviewed/2025/03/GHSA-7r4r-7wg2-96vj/GHSA-7r4r-7wg2-96vj.json
new file mode 100644
index 00000000000..5b95d3721d1
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-7r4r-7wg2-96vj/GHSA-7r4r-7wg2-96vj.json
@@ -0,0 +1,41 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-7r4r-7wg2-96vj",
+ "modified": "2025-03-27T18:31:26Z",
+ "published": "2025-03-27T18:31:26Z",
+ "aliases": [
+ "CVE-2023-52984"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: phy: dp83822: Fix null pointer access on DP83825/DP83826 devices\n\nThe probe() function is only used for the DP83822 PHY, leaving the\nprivate data pointer uninitialized for the smaller DP83825/26 models.\nWhile all uses of the private data structure are hidden in 82822 specific\ncallbacks, configuring the interrupt is shared across all models.\nThis causes a NULL pointer dereference on the smaller PHYs as it accesses\nthe private data unchecked. Verifying the pointer avoids that.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52984"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/2cd1e9c013ec56421c58921b1ddf1d2d53bd47fa"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/362a2f5531dc0e5b0b5b3e3a541000dbffa75461"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/422ae7d9c7221e8d4c8526d0f54106307d69d2dc"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/78901b10522cdf6badf24acf65a892637596bccc"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:45Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-7rcp-78xx-6fqm/GHSA-7rcp-78xx-6fqm.json b/advisories/unreviewed/2025/03/GHSA-7rcp-78xx-6fqm/GHSA-7rcp-78xx-6fqm.json
new file mode 100644
index 00000000000..4adf7fd9b9a
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-7rcp-78xx-6fqm/GHSA-7rcp-78xx-6fqm.json
@@ -0,0 +1,37 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-7rcp-78xx-6fqm",
+ "modified": "2025-03-27T18:31:28Z",
+ "published": "2025-03-27T18:31:28Z",
+ "aliases": [
+ "CVE-2023-53016"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: Fix possible deadlock in rfcomm_sk_state_change\n\nsyzbot reports a possible deadlock in rfcomm_sk_state_change [1].\nWhile rfcomm_sock_connect acquires the sk lock and waits for\nthe rfcomm lock, rfcomm_sock_release could have the rfcomm\nlock and hit a deadlock for acquiring the sk lock.\nHere's a simplified flow:\n\nrfcomm_sock_connect:\n lock_sock(sk)\n rfcomm_dlc_open:\n rfcomm_lock()\n\nrfcomm_sock_release:\n rfcomm_sock_shutdown:\n rfcomm_lock()\n __rfcomm_dlc_close:\n rfcomm_k_state_change:\n\t lock_sock(sk)\n\nThis patch drops the sk lock before calling rfcomm_dlc_open to\navoid the possible deadlock and holds sk's reference count to\nprevent use-after-free after rfcomm_dlc_open completes.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-53016"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/17511bd84871f4a6106cb335616e086880313f3f"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/1d80d57ffcb55488f0ec0b77928d4f82d16b6a90"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/98aec50ff7f60cc6f2d6a4396b475c547e58b04d"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:50Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-8295-hcjh-5w9p/GHSA-8295-hcjh-5w9p.json b/advisories/unreviewed/2025/03/GHSA-8295-hcjh-5w9p/GHSA-8295-hcjh-5w9p.json
new file mode 100644
index 00000000000..9810c3ce79c
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-8295-hcjh-5w9p/GHSA-8295-hcjh-5w9p.json
@@ -0,0 +1,41 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-8295-hcjh-5w9p",
+ "modified": "2025-03-27T18:31:25Z",
+ "published": "2025-03-27T18:31:25Z",
+ "aliases": [
+ "CVE-2023-52930"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/i915: Fix potential bit_17 double-free\n\nA userspace with multiple threads racing I915_GEM_SET_TILING to set the\ntiling to I915_TILING_NONE could trigger a double free of the bit_17\nbitmask. (Or conversely leak memory on the transition to tiled.) Move\nallocation/free'ing of the bitmask within the section protected by the\nobj lock.\n\n[tursulin: Correct fixes tag and added cc stable.]\n(cherry picked from commit 10e0cbaaf1104f449d695c80bcacf930dcd3c42e)",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52930"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/0769f997a7b6d5cb8336db0b4ec3d2d311b8097c"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/7057a8f126f14f14b040faecfa220fd27c6c2f85"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/b591abac78e25269b12e3d7170c99463f8c5cb02"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/e3ebc3e23bd9028a8a9a26cbc5985f99be445f65"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:42Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-82wr-7889-862x/GHSA-82wr-7889-862x.json b/advisories/unreviewed/2025/03/GHSA-82wr-7889-862x/GHSA-82wr-7889-862x.json
new file mode 100644
index 00000000000..9e440c3f5bc
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-82wr-7889-862x/GHSA-82wr-7889-862x.json
@@ -0,0 +1,37 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-82wr-7889-862x",
+ "modified": "2025-03-27T18:31:28Z",
+ "published": "2025-03-27T18:31:28Z",
+ "aliases": [
+ "CVE-2023-53013"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nptdma: pt_core_execute_cmd() should use spinlock\n\nThe interrupt handler (pt_core_irq_handler()) of the ptdma\ndriver can be called from interrupt context. The code flow\nin this function can lead down to pt_core_execute_cmd() which\nwill attempt to grab a mutex, which is not appropriate in\ninterrupt context and ultimately leads to a kernel panic.\nThe fix here changes this mutex to a spinlock, which has\nbeen verified to resolve the issue.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-53013"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/13ba563c2c8055ba8a637c9f70bb833b43cb4207"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/95e5fda3b5f9ed8239b145da3fa01e641cf5d53c"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/ed0d8f731e0bf1bb12a7a37698ac613db20e2794"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:50Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-8378-x644-jppg/GHSA-8378-x644-jppg.json b/advisories/unreviewed/2025/03/GHSA-8378-x644-jppg/GHSA-8378-x644-jppg.json
new file mode 100644
index 00000000000..4ebe8aa96e9
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-8378-x644-jppg/GHSA-8378-x644-jppg.json
@@ -0,0 +1,33 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-8378-x644-jppg",
+ "modified": "2025-03-27T18:31:28Z",
+ "published": "2025-03-27T18:31:28Z",
+ "aliases": [
+ "CVE-2023-53027"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nerofs: fix kvcalloc() misuse with __GFP_NOFAIL\n\nAs reported by syzbot [1], kvcalloc() cannot work with __GFP_NOFAIL.\nLet's use kcalloc() instead.\n\n[1] https://lore.kernel.org/r/0000000000007796bd05f1852ec2@google.com",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-53027"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/12724ba38992bd045e92a9a88a868a530f89d13e"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/7b28a8920844042ca9f44934d8f15d210ef42c75"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:52Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-83h3-pmwm-wj9j/GHSA-83h3-pmwm-wj9j.json b/advisories/unreviewed/2025/03/GHSA-83h3-pmwm-wj9j/GHSA-83h3-pmwm-wj9j.json
new file mode 100644
index 00000000000..ad0f7af4c18
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-83h3-pmwm-wj9j/GHSA-83h3-pmwm-wj9j.json
@@ -0,0 +1,37 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-83h3-pmwm-wj9j",
+ "modified": "2025-03-27T18:31:24Z",
+ "published": "2025-03-27T18:31:23Z",
+ "aliases": [
+ "CVE-2022-49743"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\novl: Use \"buf\" flexible array for memcpy() destination\n\nThe \"buf\" flexible array needs to be the memcpy() destination to avoid\nfalse positive run-time warning from the recent FORTIFY_SOURCE\nhardening:\n\n memcpy: detected field-spanning write (size 93) of single field \"&fh->fb\"\n at fs/overlayfs/export.c:799 (size 21)",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49743"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/07a96977b2f462337a9121302de64277b8747ab1"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/a77141a06367825d639ac51b04703d551163e36c"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/cf8aa9bf97cadf85745506c6a3e244b22c268d63"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:38Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-88rq-q8gm-2chx/GHSA-88rq-q8gm-2chx.json b/advisories/unreviewed/2025/03/GHSA-88rq-q8gm-2chx/GHSA-88rq-q8gm-2chx.json
new file mode 100644
index 00000000000..69414e2179c
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-88rq-q8gm-2chx/GHSA-88rq-q8gm-2chx.json
@@ -0,0 +1,33 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-88rq-q8gm-2chx",
+ "modified": "2025-03-27T18:31:24Z",
+ "published": "2025-03-27T18:31:23Z",
+ "aliases": [
+ "CVE-2022-49742"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: initialize locks earlier in f2fs_fill_super()\n\nsyzbot is reporting lockdep warning at f2fs_handle_error() [1], for\nspin_lock(&sbi->error_lock) is called before spin_lock_init() is called.\nFor safe locking in error handling, move initialization of locks (and\nobvious structures) in f2fs_fill_super() to immediately after memory\nallocation.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49742"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/92b4cf5b48955a4bdd15fe4e2067db8ebd87f04c"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/ddeff03bb33810fcf2f0c18e03d099cf0aacda62"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:38Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-8hf9-x5gr-j3rr/GHSA-8hf9-x5gr-j3rr.json b/advisories/unreviewed/2025/03/GHSA-8hf9-x5gr-j3rr/GHSA-8hf9-x5gr-j3rr.json
new file mode 100644
index 00000000000..3e14c597475
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-8hf9-x5gr-j3rr/GHSA-8hf9-x5gr-j3rr.json
@@ -0,0 +1,29 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-8hf9-x5gr-j3rr",
+ "modified": "2025-03-27T18:31:23Z",
+ "published": "2025-03-27T18:31:23Z",
+ "aliases": [
+ "CVE-2025-25686"
+ ],
+ "details": "semcms <=5.0 is vulnerable to SQL Injection in SEMCMS_Fuction.php.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25686"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/J1095/fkapfxx"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T16:15:29Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-8qj8-x8gq-98wm/GHSA-8qj8-x8gq-98wm.json b/advisories/unreviewed/2025/03/GHSA-8qj8-x8gq-98wm/GHSA-8qj8-x8gq-98wm.json
new file mode 100644
index 00000000000..55a70773c0d
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-8qj8-x8gq-98wm/GHSA-8qj8-x8gq-98wm.json
@@ -0,0 +1,37 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-8qj8-x8gq-98wm",
+ "modified": "2025-03-27T18:31:24Z",
+ "published": "2025-03-27T18:31:24Z",
+ "aliases": [
+ "CVE-2022-49752"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndevice property: fix of node refcount leak in fwnode_graph_get_next_endpoint()\n\nThe 'parent' returned by fwnode_graph_get_port_parent()\nwith refcount incremented when 'prev' is not NULL, it\nneeds be put when finish using it.\n\nBecause the parent is const, introduce a new variable to\nstore the returned fwnode, then put it before returning\nfrom fwnode_graph_get_next_endpoint().",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49752"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/39af728649b05e88a2b40e714feeee6451c3f18e"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/7701a4bd45c11f9a289d8f262fad05705a012339"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/e75485fc589ec729cc182aa9b41dfb6c15ae6f6e"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:40Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-8qp4-g23m-7ww9/GHSA-8qp4-g23m-7ww9.json b/advisories/unreviewed/2025/03/GHSA-8qp4-g23m-7ww9/GHSA-8qp4-g23m-7ww9.json
new file mode 100644
index 00000000000..7ff517c7810
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-8qp4-g23m-7ww9/GHSA-8qp4-g23m-7ww9.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-8qp4-g23m-7ww9",
+ "modified": "2025-03-27T18:31:23Z",
+ "published": "2025-03-27T18:31:23Z",
+ "aliases": [
+ "CVE-2025-22783"
+ ],
+ "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SEO Squirrly SEO Plugin by Squirrly SEO allows SQL Injection.This issue affects SEO Plugin by Squirrly SEO: from n/a through 12.4.03.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22783"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/squirrly-seo/vulnerability/wordpress-seo-plugin-by-squirrly-seo-plugin-12-4-03-sql-injection-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-89"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T16:15:29Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-92fq-22vv-8p4c/GHSA-92fq-22vv-8p4c.json b/advisories/unreviewed/2025/03/GHSA-92fq-22vv-8p4c/GHSA-92fq-22vv-8p4c.json
new file mode 100644
index 00000000000..ef89969a39f
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-92fq-22vv-8p4c/GHSA-92fq-22vv-8p4c.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-92fq-22vv-8p4c",
+ "modified": "2025-03-27T18:31:23Z",
+ "published": "2025-03-27T18:31:23Z",
+ "aliases": [
+ "CVE-2025-22634"
+ ],
+ "details": "Cross-Site Request Forgery (CSRF) vulnerability in MD Abu Jubayer Hossain Easy Booked – Appointment Booking and Scheduling Management System for WordPress allows Cross Site Request Forgery.This issue affects Easy Booked – Appointment Booking and Scheduling Management System for WordPress: from n/a through 2.4.5.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22634"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/easy-booked/vulnerability/wordpress-easy-booked-plugin-2-4-5-cross-site-request-forgery-csrf-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-352"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T16:15:28Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-9933-f4m5-7v96/GHSA-9933-f4m5-7v96.json b/advisories/unreviewed/2025/03/GHSA-9933-f4m5-7v96/GHSA-9933-f4m5-7v96.json
new file mode 100644
index 00000000000..cd12f866a75
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-9933-f4m5-7v96/GHSA-9933-f4m5-7v96.json
@@ -0,0 +1,37 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-9933-f4m5-7v96",
+ "modified": "2025-03-27T18:31:28Z",
+ "published": "2025-03-27T18:31:28Z",
+ "aliases": [
+ "CVE-2023-53022"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: enetc: avoid deadlock in enetc_tx_onestep_tstamp()\n\nThis lockdep splat says it better than I could:\n\n================================\nWARNING: inconsistent lock state\n6.2.0-rc2-07010-ga9b9500ffaac-dirty #967 Not tainted\n--------------------------------\ninconsistent {IN-SOFTIRQ-W} -> {SOFTIRQ-ON-W} usage.\nkworker/1:3/179 [HC0[0]:SC0[0]:HE1:SE1] takes:\nffff3ec4036ce098 (_xmit_ETHER#2){+.?.}-{3:3}, at: netif_freeze_queues+0x5c/0xc0\n{IN-SOFTIRQ-W} state was registered at:\n _raw_spin_lock+0x5c/0xc0\n sch_direct_xmit+0x148/0x37c\n __dev_queue_xmit+0x528/0x111c\n ip6_finish_output2+0x5ec/0xb7c\n ip6_finish_output+0x240/0x3f0\n ip6_output+0x78/0x360\n ndisc_send_skb+0x33c/0x85c\n ndisc_send_rs+0x54/0x12c\n addrconf_rs_timer+0x154/0x260\n call_timer_fn+0xb8/0x3a0\n __run_timers.part.0+0x214/0x26c\n run_timer_softirq+0x3c/0x74\n __do_softirq+0x14c/0x5d8\n ____do_softirq+0x10/0x20\n call_on_irq_stack+0x2c/0x5c\n do_softirq_own_stack+0x1c/0x30\n __irq_exit_rcu+0x168/0x1a0\n irq_exit_rcu+0x10/0x40\n el1_interrupt+0x38/0x64\nirq event stamp: 7825\nhardirqs last enabled at (7825): [] exit_to_kernel_mode+0x34/0x130\nhardirqs last disabled at (7823): [] __do_softirq+0x550/0x5d8\nsoftirqs last enabled at (7824): [] __do_softirq+0x46c/0x5d8\nsoftirqs last disabled at (7811): [] ____do_softirq+0x10/0x20\n\nother info that might help us debug this:\n Possible unsafe locking scenario:\n\n CPU0\n ----\n lock(_xmit_ETHER#2);\n \n lock(_xmit_ETHER#2);\n\n *** DEADLOCK ***\n\n3 locks held by kworker/1:3/179:\n #0: ffff3ec400004748 ((wq_completion)events){+.+.}-{0:0}, at: process_one_work+0x1f4/0x6c0\n #1: ffff80000a0bbdc8 ((work_completion)(&priv->tx_onestep_tstamp)){+.+.}-{0:0}, at: process_one_work+0x1f4/0x6c0\n #2: ffff3ec4036cd438 (&dev->tx_global_lock){+.+.}-{3:3}, at: netif_tx_lock+0x1c/0x34\n\nWorkqueue: events enetc_tx_onestep_tstamp\nCall trace:\n print_usage_bug.part.0+0x208/0x22c\n mark_lock+0x7f0/0x8b0\n __lock_acquire+0x7c4/0x1ce0\n lock_acquire.part.0+0xe0/0x220\n lock_acquire+0x68/0x84\n _raw_spin_lock+0x5c/0xc0\n netif_freeze_queues+0x5c/0xc0\n netif_tx_lock+0x24/0x34\n enetc_tx_onestep_tstamp+0x20/0x100\n process_one_work+0x28c/0x6c0\n worker_thread+0x74/0x450\n kthread+0x118/0x11c\n\nbut I'll say it anyway: the enetc_tx_onestep_tstamp() work item runs in\nprocess context, therefore with softirqs enabled (i.o.w., it can be\ninterrupted by a softirq). If we hold the netif_tx_lock() when there is\nan interrupt, and the NET_TX softirq then gets scheduled, this will take\nthe netif_tx_lock() a second time and deadlock the kernel.\n\nTo solve this, use netif_tx_lock_bh(), which blocks softirqs from\nrunning.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-53022"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/3c463721a73bdb57a913e0d3124677a3758886fc"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/8232e5a84d25a84a5cbda0f241a00793fb6eb608"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/e893dced1a18e77b1262f5c10169413f0ece0da7"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:51Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-9chp-g445-qxj3/GHSA-9chp-g445-qxj3.json b/advisories/unreviewed/2025/03/GHSA-9chp-g445-qxj3/GHSA-9chp-g445-qxj3.json
index beef0606104..93896082d8b 100644
--- a/advisories/unreviewed/2025/03/GHSA-9chp-g445-qxj3/GHSA-9chp-g445-qxj3.json
+++ b/advisories/unreviewed/2025/03/GHSA-9chp-g445-qxj3/GHSA-9chp-g445-qxj3.json
@@ -46,7 +46,8 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-74"
+ "CWE-74",
+ "CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2025/03/GHSA-9h2w-crmf-mr2p/GHSA-9h2w-crmf-mr2p.json b/advisories/unreviewed/2025/03/GHSA-9h2w-crmf-mr2p/GHSA-9h2w-crmf-mr2p.json
new file mode 100644
index 00000000000..e95d4764bdc
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-9h2w-crmf-mr2p/GHSA-9h2w-crmf-mr2p.json
@@ -0,0 +1,41 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-9h2w-crmf-mr2p",
+ "modified": "2025-03-27T18:31:26Z",
+ "published": "2025-03-27T18:31:26Z",
+ "aliases": [
+ "CVE-2023-52991"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: fix NULL pointer in skb_segment_list\n\nCommit 3a1296a38d0c (\"net: Support GRO/GSO fraglist chaining.\")\nintroduced UDP listifyed GRO. The segmentation relies on frag_list being\nuntouched when passing through the network stack. This assumption can be\nbroken sometimes, where frag_list itself gets pulled into linear area,\nleaving frag_list being NULL. When this happens it can trigger\nfollowing NULL pointer dereference, and panic the kernel. Reverse the\ntest condition should fix it.\n\n[19185.577801][ C1] BUG: kernel NULL pointer dereference, address:\n...\n[19185.663775][ C1] RIP: 0010:skb_segment_list+0x1cc/0x390\n...\n[19185.834644][ C1] Call Trace:\n[19185.841730][ C1] \n[19185.848563][ C1] __udp_gso_segment+0x33e/0x510\n[19185.857370][ C1] inet_gso_segment+0x15b/0x3e0\n[19185.866059][ C1] skb_mac_gso_segment+0x97/0x110\n[19185.874939][ C1] __skb_gso_segment+0xb2/0x160\n[19185.883646][ C1] udp_queue_rcv_skb+0xc3/0x1d0\n[19185.892319][ C1] udp_unicast_rcv_skb+0x75/0x90\n[19185.900979][ C1] ip_protocol_deliver_rcu+0xd2/0x200\n[19185.910003][ C1] ip_local_deliver_finish+0x44/0x60\n[19185.918757][ C1] __netif_receive_skb_one_core+0x8b/0xa0\n[19185.927834][ C1] process_backlog+0x88/0x130\n[19185.935840][ C1] __napi_poll+0x27/0x150\n[19185.943447][ C1] net_rx_action+0x27e/0x5f0\n[19185.951331][ C1] ? mlx5_cq_tasklet_cb+0x70/0x160 [mlx5_core]\n[19185.960848][ C1] __do_softirq+0xbc/0x25d\n[19185.968607][ C1] irq_exit_rcu+0x83/0xb0\n[19185.976247][ C1] common_interrupt+0x43/0xa0\n[19185.984235][ C1] asm_common_interrupt+0x22/0x40\n...\n[19186.094106][ C1] ",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52991"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/046de74f9af92ae9ffce75fa22a1795223f4fb54"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/6446369fb9f083ce032448c5047da08e298b22e6"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/876e8ca8366735a604bac86ff7e2732fc9d85d2d"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/888dad6f3e85e3b2f8389bd6478f181efc72534d"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:46Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-9w4w-6v5v-wh95/GHSA-9w4w-6v5v-wh95.json b/advisories/unreviewed/2025/03/GHSA-9w4w-6v5v-wh95/GHSA-9w4w-6v5v-wh95.json
new file mode 100644
index 00000000000..1ba9637e009
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-9w4w-6v5v-wh95/GHSA-9w4w-6v5v-wh95.json
@@ -0,0 +1,45 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-9w4w-6v5v-wh95",
+ "modified": "2025-03-27T18:31:27Z",
+ "published": "2025-03-27T18:31:27Z",
+ "aliases": [
+ "CVE-2023-53003"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nEDAC/qcom: Do not pass llcc_driv_data as edac_device_ctl_info's pvt_info\n\nThe memory for llcc_driv_data is allocated by the LLCC driver. But when\nit is passed as the private driver info to the EDAC core, it will get freed\nduring the qcom_edac driver release. So when the qcom_edac driver gets probed\nagain, it will try to use the freed data leading to the use-after-free bug.\n\nHence, do not pass llcc_driv_data as pvt_info but rather reference it\nusing the platform_data pointer in the qcom_edac driver.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-53003"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/66e10d5f399629ef7877304d9ba2b35d0474e7eb"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/6f0351d0c311951b8b3064db91e61841e85b2b96"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/76d9ebb7f0bc10fbc78b6d576751552edf743968"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/977c6ba624f24ae20cf0faee871257a39348d4a9"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/bff5243bd32661cf9ce66f6d9210fc8f89bda145"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:49Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-c2p3-c9fp-43mx/GHSA-c2p3-c9fp-43mx.json b/advisories/unreviewed/2025/03/GHSA-c2p3-c9fp-43mx/GHSA-c2p3-c9fp-43mx.json
new file mode 100644
index 00000000000..5da9ee150f0
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-c2p3-c9fp-43mx/GHSA-c2p3-c9fp-43mx.json
@@ -0,0 +1,33 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-c2p3-c9fp-43mx",
+ "modified": "2025-03-27T18:31:26Z",
+ "published": "2025-03-27T18:31:25Z",
+ "aliases": [
+ "CVE-2023-52940"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm: multi-gen LRU: fix crash during cgroup migration\n\nlru_gen_migrate_mm() assumes lru_gen_add_mm() runs prior to itself. This\nisn't true for the following scenario:\n\n CPU 1 CPU 2\n\n clone()\n cgroup_can_fork()\n cgroup_procs_write()\n cgroup_post_fork()\n task_lock()\n lru_gen_migrate_mm()\n task_unlock()\n task_lock()\n lru_gen_add_mm()\n task_unlock()\n\nAnd when the above happens, kernel crashes because of linked list\ncorruption (mm_struct->lru_gen.list).",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52940"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/04448022311cebd30969d3aebdde765f1258b360"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/de08eaa6156405f2e9369f06ba5afae0e4ab3b62"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:43Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-c2pc-4ww4-m54p/GHSA-c2pc-4ww4-m54p.json b/advisories/unreviewed/2025/03/GHSA-c2pc-4ww4-m54p/GHSA-c2pc-4ww4-m54p.json
new file mode 100644
index 00000000000..a8bae9c6a32
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-c2pc-4ww4-m54p/GHSA-c2pc-4ww4-m54p.json
@@ -0,0 +1,49 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-c2pc-4ww4-m54p",
+ "modified": "2025-03-27T18:31:24Z",
+ "published": "2025-03-27T18:31:24Z",
+ "aliases": [
+ "CVE-2022-49746"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: imx-sdma: Fix a possible memory leak in sdma_transfer_init\n\nIf the function sdma_load_context() fails, the sdma_desc will be\nfreed, but the allocated desc->bd is forgot to be freed.\n\nWe already met the sdma_load_context() failure case and the log as\nbelow:\n[ 450.699064] imx-sdma 30bd0000.dma-controller: Timeout waiting for CH0 ready\n...\n\nIn this case, the desc->bd will not be freed without this change.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49746"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/1417f59ac0b02130ee56c0c50794b9b257be3d17"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/43acd767bd90c5d4172ce7fee5d9007a9a08dea9"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/80ee99e52936b2c04cc37b17a14b2ae2f9d282ac"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/bd0050b7ffa87c7b260d563646af612f4112a778"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/ce4745a6b8016fae74c95dcd457d4ceef7d98af1"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/dbe634ce824329d8f14079c3e9f8f11670894bec"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:39Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-c6c6-6xm6-jhp9/GHSA-c6c6-6xm6-jhp9.json b/advisories/unreviewed/2025/03/GHSA-c6c6-6xm6-jhp9/GHSA-c6c6-6xm6-jhp9.json
new file mode 100644
index 00000000000..316791f70f9
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-c6c6-6xm6-jhp9/GHSA-c6c6-6xm6-jhp9.json
@@ -0,0 +1,53 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-c6c6-6xm6-jhp9",
+ "modified": "2025-03-27T18:31:25Z",
+ "published": "2025-03-27T18:31:24Z",
+ "aliases": [
+ "CVE-2022-49753"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: Fix double increment of client_count in dma_chan_get()\n\nThe first time dma_chan_get() is called for a channel the channel\nclient_count is incorrectly incremented twice for public channels,\nfirst in balance_ref_count(), and again prior to returning. This\nresults in an incorrect client count which will lead to the\nchannel resources not being freed when they should be. A simple\n test of repeated module load and unload of async_tx on a Dell\n Power Edge R7425 also shows this resulting in a kref underflow\n warning.\n\n[ 124.329662] async_tx: api initialized (async)\n[ 129.000627] async_tx: api initialized (async)\n[ 130.047839] ------------[ cut here ]------------\n[ 130.052472] refcount_t: underflow; use-after-free.\n[ 130.057279] WARNING: CPU: 3 PID: 19364 at lib/refcount.c:28\nrefcount_warn_saturate+0xba/0x110\n[ 130.065811] Modules linked in: async_tx(-) rfkill intel_rapl_msr\nintel_rapl_common amd64_edac edac_mce_amd ipmi_ssif kvm_amd dcdbas kvm\nmgag200 drm_shmem_helper acpi_ipmi irqbypass drm_kms_helper ipmi_si\nsyscopyarea sysfillrect rapl pcspkr ipmi_devintf sysimgblt fb_sys_fops\nk10temp i2c_piix4 ipmi_msghandler acpi_power_meter acpi_cpufreq vfat\nfat drm fuse xfs libcrc32c sd_mod t10_pi sg ahci crct10dif_pclmul\nlibahci crc32_pclmul crc32c_intel ghash_clmulni_intel igb megaraid_sas\ni40e libata i2c_algo_bit ccp sp5100_tco dca dm_mirror dm_region_hash\ndm_log dm_mod [last unloaded: async_tx]\n[ 130.117361] CPU: 3 PID: 19364 Comm: modprobe Kdump: loaded Not\ntainted 5.14.0-185.el9.x86_64 #1\n[ 130.126091] Hardware name: Dell Inc. PowerEdge R7425/02MJ3T, BIOS\n1.18.0 01/17/2022\n[ 130.133806] RIP: 0010:refcount_warn_saturate+0xba/0x110\n[ 130.139041] Code: 01 01 e8 6d bd 55 00 0f 0b e9 72 9d 8a 00 80 3d\n26 18 9c 01 00 75 85 48 c7 c7 f8 a3 03 9d c6 05 16 18 9c 01 01 e8 4a\nbd 55 00 <0f> 0b e9 4f 9d 8a 00 80 3d 01 18 9c 01 00 0f 85 5e ff ff ff\n48 c7\n[ 130.157807] RSP: 0018:ffffbf98898afe68 EFLAGS: 00010286\n[ 130.163036] RAX: 0000000000000000 RBX: ffff9da06028e598 RCX: 0000000000000000\n[ 130.170172] RDX: ffff9daf9de26480 RSI: ffff9daf9de198a0 RDI: ffff9daf9de198a0\n[ 130.177316] RBP: ffff9da7cddf3970 R08: 0000000000000000 R09: 00000000ffff7fff\n[ 130.184459] R10: ffffbf98898afd00 R11: ffffffff9d9e8c28 R12: ffff9da7cddf1970\n[ 130.191596] R13: 0000000000000000 R14: 0000000000000000 R15: 0000000000000000\n[ 130.198739] FS: 00007f646435c740(0000) GS:ffff9daf9de00000(0000)\nknlGS:0000000000000000\n[ 130.206832] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 130.212586] CR2: 00007f6463b214f0 CR3: 00000008ab98c000 CR4: 00000000003506e0\n[ 130.219729] Call Trace:\n[ 130.222192] \n[ 130.224305] dma_chan_put+0x10d/0x110\n[ 130.227988] dmaengine_put+0x7a/0xa0\n[ 130.231575] __do_sys_delete_module.constprop.0+0x178/0x280\n[ 130.237157] ? syscall_trace_enter.constprop.0+0x145/0x1d0\n[ 130.242652] do_syscall_64+0x5c/0x90\n[ 130.246240] ? exc_page_fault+0x62/0x150\n[ 130.250178] entry_SYSCALL_64_after_hwframe+0x63/0xcd\n[ 130.255243] RIP: 0033:0x7f6463a3f5ab\n[ 130.258830] Code: 73 01 c3 48 8b 0d 75 a8 1b 00 f7 d8 64 89 01 48\n83 c8 ff c3 66 2e 0f 1f 84 00 00 00 00 00 90 f3 0f 1e fa b8 b0 00 00\n00 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 8b 0d 45 a8 1b 00 f7 d8 64 89\n01 48\n[ 130.277591] RSP: 002b:00007fff22f972c8 EFLAGS: 00000206 ORIG_RAX:\n00000000000000b0\n[ 130.285164] RAX: ffffffffffffffda RBX: 000055b6786edd40 RCX: 00007f6463a3f5ab\n[ 130.292303] RDX: 0000000000000000 RSI: 0000000000000800 RDI: 000055b6786edda8\n[ 130.299443] RBP: 000055b6786edd40 R08: 0000000000000000 R09: 0000000000000000\n[ 130.306584] R10: 00007f6463b9eac0 R11: 0000000000000206 R12: 000055b6786edda8\n[ 130.313731] R13: 0000000000000000 R14: 000055b6786edda8 R15: 00007fff22f995f8\n[ 130.320875] \n[ 130.323081] ---[ end trace eff7156d56b5cf25 ]---\n\ncat /sys/class/dma/dma0chan*/in_use would get the wrong result.\n2\n2\n2\n\nTest-by: Jie Hai ",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49753"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/142d644fd2cc059ffa042fbfb68e766433ef3afd"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/18dd3b30d4c7e8440c63118c7a7b687372b9567f"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/1b409e14b4b7af034e0450f95c165b6c5c87dbc1"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/42ecd72f02cd657b00b559621e7ef7d2c4d3e5f1"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/71c601965532c38030133535f7cd93c1efa75af1"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/c6221afe573413fd2981e291f7df4a58283e0654"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/f3dc1b3b4750851a94212dba249703dd0e50bb20"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:40Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-c7qr-fxvv-x4fh/GHSA-c7qr-fxvv-x4fh.json b/advisories/unreviewed/2025/03/GHSA-c7qr-fxvv-x4fh/GHSA-c7qr-fxvv-x4fh.json
new file mode 100644
index 00000000000..61665e03642
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-c7qr-fxvv-x4fh/GHSA-c7qr-fxvv-x4fh.json
@@ -0,0 +1,33 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-c7qr-fxvv-x4fh",
+ "modified": "2025-03-27T18:31:27Z",
+ "published": "2025-03-27T18:31:27Z",
+ "aliases": [
+ "CVE-2023-52990"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ns390: workaround invalid gcc-11 out of bounds read warning\n\nGCC 11.1.0 and 11.2.0 generate a wrong warning when compiling the\nkernel e.g. with allmodconfig:\n\narch/s390/kernel/setup.c: In function ‘setup_lowcore_dat_on’:\n./include/linux/fortify-string.h:57:33: error: ‘__builtin_memcpy’ reading 128 bytes from a region of size 0 [-Werror=stringop-overread]\n...\narch/s390/kernel/setup.c:526:9: note: in expansion of macro ‘memcpy’\n 526 | memcpy(abs_lc->cregs_save_area, S390_lowcore.cregs_save_area,\n | ^~~~~~\n\nThis could be addressed by using absolute_pointer() with the\nS390_lowcore macro, but this is not a good idea since this generates\nworse code for performance critical paths.\n\nTherefore simply use a for loop to copy the array in question and get\nrid of the warning.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52990"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/1fc24f9da259b675c3cc74ad5aa92dac286543b3"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/41e1992665a2701fa025a8b76970c43b4148446f"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:46Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-cc9v-j5mh-4rvx/GHSA-cc9v-j5mh-4rvx.json b/advisories/unreviewed/2025/03/GHSA-cc9v-j5mh-4rvx/GHSA-cc9v-j5mh-4rvx.json
new file mode 100644
index 00000000000..95350168eb7
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-cc9v-j5mh-4rvx/GHSA-cc9v-j5mh-4rvx.json
@@ -0,0 +1,33 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-cc9v-j5mh-4rvx",
+ "modified": "2025-03-27T18:31:26Z",
+ "published": "2025-03-27T18:31:26Z",
+ "aliases": [
+ "CVE-2023-52985"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\narm64: dts: imx8mm-verdin: Do not power down eth-phy\n\nCurrently if suspending using either freeze or memory state, the fec\ndriver tries to power down the phy which leads to crash of the kernel\nand non-responsible kernel with the following call trace:\n\n[ 24.839889 ] Call trace:\n[ 24.839892 ] phy_error+0x18/0x60\n[ 24.839898 ] kszphy_handle_interrupt+0x6c/0x80\n[ 24.839903 ] phy_interrupt+0x20/0x2c\n[ 24.839909 ] irq_thread_fn+0x30/0xa0\n[ 24.839919 ] irq_thread+0x178/0x2c0\n[ 24.839925 ] kthread+0x154/0x160\n[ 24.839932 ] ret_from_fork+0x10/0x20\n\nSince there is currently no functionality in the phy subsystem to power\ndown phys let's just disable the feature of powering-down the ethernet\nphy.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52985"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/0bdd5a7b517f16fdffc444be6516c45788548d08"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/39c95d0c357d7ef76aea958c1bece6b24f9b2e7e"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:45Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-cg23-v479-px36/GHSA-cg23-v479-px36.json b/advisories/unreviewed/2025/03/GHSA-cg23-v479-px36/GHSA-cg23-v479-px36.json
new file mode 100644
index 00000000000..bb0cb57e6ff
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-cg23-v479-px36/GHSA-cg23-v479-px36.json
@@ -0,0 +1,33 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-cg23-v479-px36",
+ "modified": "2025-03-27T18:31:25Z",
+ "published": "2025-03-27T18:31:25Z",
+ "aliases": [
+ "CVE-2023-52937"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nHV: hv_balloon: fix memory leak with using debugfs_lookup()\n\nWhen calling debugfs_lookup() the result must have dput() called on it,\notherwise the memory will leak over time. To make things simpler, just\ncall debugfs_lookup_and_remove() instead which handles all of the logic\nat once.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52937"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/0b570a059cf42ad6e2eb632f47c23813d58d8303"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/6dfb0771429a63db8561d44147f2bb76f93e1c86"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:43Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-cq6c-crmc-xmvp/GHSA-cq6c-crmc-xmvp.json b/advisories/unreviewed/2025/03/GHSA-cq6c-crmc-xmvp/GHSA-cq6c-crmc-xmvp.json
new file mode 100644
index 00000000000..3613f3f85f5
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-cq6c-crmc-xmvp/GHSA-cq6c-crmc-xmvp.json
@@ -0,0 +1,33 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-cq6c-crmc-xmvp",
+ "modified": "2025-03-27T18:31:26Z",
+ "published": "2025-03-27T18:31:26Z",
+ "aliases": [
+ "CVE-2023-52980"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nblock: ublk: extending queue_size to fix overflow\n\nWhen validating drafted SPDK ublk target, in a case that\nassigning large queue depth to multiqueue ublk device,\nublk target would run into a weird incorrect state. During\nrounds of review and debug, An overflow bug was found\nin ublk driver.\n\nIn ublk_cmd.h, UBLK_MAX_QUEUE_DEPTH is 4096 which means\neach ublk queue depth can be set as large as 4096. But\nwhen setting qd for a ublk device,\nsizeof(struct ublk_queue) + depth * sizeof(struct ublk_io)\nwill be larger than 65535 if qd is larger than 2728.\nThen queue_size is overflowed, and ublk_get_queue()\nreferences a wrong pointer position. The wrong content of\nublk_queue elements will lead to out-of-bounds memory\naccess.\n\nExtend queue_size in ublk_device as \"unsigned int\".",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52980"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/29baef789c838bd5c02f50c88adbbc6b955aaf61"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/ee1e3fe4b4579f856997190a00ea4db0307b4332"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:45Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-crf3-p565-96vh/GHSA-crf3-p565-96vh.json b/advisories/unreviewed/2025/03/GHSA-crf3-p565-96vh/GHSA-crf3-p565-96vh.json
new file mode 100644
index 00000000000..a3e9b16d537
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-crf3-p565-96vh/GHSA-crf3-p565-96vh.json
@@ -0,0 +1,33 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-crf3-p565-96vh",
+ "modified": "2025-03-27T18:31:24Z",
+ "published": "2025-03-27T18:31:24Z",
+ "aliases": [
+ "CVE-2022-49744"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/uffd: fix pte marker when fork() without fork event\n\nPatch series \"mm: Fixes on pte markers\".\n\nPatch 1 resolves the syzkiller report from Pengfei.\n\nPatch 2 further harden pte markers when used with the recent swapin error\nmarkers. The major case is we should persist a swapin error marker after\nfork(), so child shouldn't read a corrupted page.\n\n\nThis patch (of 2):\n\nWhen fork(), dst_vma is not guaranteed to have VM_UFFD_WP even if src may\nhave it and has pte marker installed. The warning is improper along with\nthe comment. The right thing is to inherit the pte marker when needed, or\nkeep the dst pte empty.\n\nA vague guess is this happened by an accident when there's the prior patch\nto introduce src/dst vma into this helper during the uffd-wp feature got\ndeveloped and I probably messed up in the rebase, since if we replace\ndst_vma with src_vma the warning & comment it all makes sense too.\n\nHugetlb did exactly the right here (copy_hugetlb_page_range()). Fix the\ngeneral path.\n\nReproducer:\n\nhttps://github.com/xupengfe/syzkaller_logs/blob/main/221208_115556_copy_page_range/repro.c\n\nBugzilla report: https://bugzilla.kernel.org/show_bug.cgi?id=216808",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49744"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/2d11727655bf931776fb541f5862daf04bd5bf02"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/49d6d7fb631345b0f2957a7c4be24ad63903150f"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:39Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-crqj-674f-vq27/GHSA-crqj-674f-vq27.json b/advisories/unreviewed/2025/03/GHSA-crqj-674f-vq27/GHSA-crqj-674f-vq27.json
new file mode 100644
index 00000000000..e6d0919b3c3
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-crqj-674f-vq27/GHSA-crqj-674f-vq27.json
@@ -0,0 +1,37 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-crqj-674f-vq27",
+ "modified": "2025-03-27T18:31:24Z",
+ "published": "2025-03-27T18:31:24Z",
+ "aliases": [
+ "CVE-2022-49747"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nerofs/zmap.c: Fix incorrect offset calculation\n\nEffective offset to add to length was being incorrectly calculated,\nwhich resulted in iomap->length being set to 0, triggering a WARN_ON\nin iomap_iter_done().\n\nFix that, and describe it in comments.\n\nThis was reported as a crash by syzbot under an issue about a warning\nencountered in iomap_iter_done(), but unrelated to erofs.\n\nC reproducer: https://syzkaller.appspot.com/text?tag=ReproC&x=1037a6b2880000\nKernel config: https://syzkaller.appspot.com/text?tag=KernelConfig&x=e2021a61197ebe02\nDashboard link: https://syzkaller.appspot.com/bug?extid=a8e049cd3abd342936b6",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49747"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/2144859229c1e74f52d3ea067338d314a83a8afb"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/6acd87d50998ef0afafc441613aeaf5a8f5c9eff"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/9f31d8c889d9a4e47bfcc6c4537d0c9f89fe582c"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:39Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-cw78-q654-793w/GHSA-cw78-q654-793w.json b/advisories/unreviewed/2025/03/GHSA-cw78-q654-793w/GHSA-cw78-q654-793w.json
new file mode 100644
index 00000000000..245758aa454
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-cw78-q654-793w/GHSA-cw78-q654-793w.json
@@ -0,0 +1,37 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-cw78-q654-793w",
+ "modified": "2025-03-27T18:31:28Z",
+ "published": "2025-03-27T18:31:28Z",
+ "aliases": [
+ "CVE-2023-53030"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nocteontx2-pf: Avoid use of GFP_KERNEL in atomic context\n\nUsing GFP_KERNEL in preemption disable context, causing below warning\nwhen CONFIG_DEBUG_ATOMIC_SLEEP is enabled.\n\n[ 32.542271] BUG: sleeping function called from invalid context at include/linux/sched/mm.h:274\n[ 32.550883] in_atomic(): 1, irqs_disabled(): 0, non_block: 0, pid: 1, name: swapper/0\n[ 32.558707] preempt_count: 1, expected: 0\n[ 32.562710] RCU nest depth: 0, expected: 0\n[ 32.566800] CPU: 3 PID: 1 Comm: swapper/0 Tainted: G W 6.2.0-rc2-00269-gae9dcb91c606 #7\n[ 32.576188] Hardware name: Marvell CN106XX board (DT)\n[ 32.581232] Call trace:\n[ 32.583670] dump_backtrace.part.0+0xe0/0xf0\n[ 32.587937] show_stack+0x18/0x30\n[ 32.591245] dump_stack_lvl+0x68/0x84\n[ 32.594900] dump_stack+0x18/0x34\n[ 32.598206] __might_resched+0x12c/0x160\n[ 32.602122] __might_sleep+0x48/0xa0\n[ 32.605689] __kmem_cache_alloc_node+0x2b8/0x2e0\n[ 32.610301] __kmalloc+0x58/0x190\n[ 32.613610] otx2_sq_aura_pool_init+0x1a8/0x314\n[ 32.618134] otx2_open+0x1d4/0x9d0\n\nTo avoid use of GFP_ATOMIC for memory allocation, disable preemption\nafter all memory allocation is done.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-53030"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/1eb57b87f106c90cee6b2a56a10f2e29c7a25f3e"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/2827c4eb429db64befdca11362e2b1c5f524f6ba"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/87b93b678e95c7d93fe6a55b0e0fbda26d8c7760"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:52Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-cx4p-cv2h-hf45/GHSA-cx4p-cv2h-hf45.json b/advisories/unreviewed/2025/03/GHSA-cx4p-cv2h-hf45/GHSA-cx4p-cv2h-hf45.json
new file mode 100644
index 00000000000..f0416110f25
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-cx4p-cv2h-hf45/GHSA-cx4p-cv2h-hf45.json
@@ -0,0 +1,45 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-cx4p-cv2h-hf45",
+ "modified": "2025-03-27T18:31:24Z",
+ "published": "2025-03-27T18:31:24Z",
+ "aliases": [
+ "CVE-2022-49741"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: smscufx: fix error handling code in ufx_usb_probe\n\nThe current error handling code in ufx_usb_probe have many unmatching\nissues, e.g., missing ufx_free_usb_list, destroy_modedb label should\nonly include framebuffer_release, fb_dealloc_cmap only matches\nfb_alloc_cmap.\n\nMy local syzkaller reports a memory leak bug:\n\nmemory leak in ufx_usb_probe\n\nBUG: memory leak\nunreferenced object 0xffff88802f879580 (size 128):\n comm \"kworker/0:7\", pid 17416, jiffies 4295067474 (age 46.710s)\n hex dump (first 32 bytes):\n 80 21 7c 2e 80 88 ff ff 18 d0 d0 0c 80 88 ff ff .!|.............\n 00 d0 d0 0c 80 88 ff ff e0 ff ff ff 0f 00 00 00 ................\n backtrace:\n [] kmalloc_trace+0x20/0x90 mm/slab_common.c:1045\n [] kmalloc include/linux/slab.h:553 [inline]\n [] kzalloc include/linux/slab.h:689 [inline]\n [] ufx_alloc_urb_list drivers/video/fbdev/smscufx.c:1873 [inline]\n [] ufx_usb_probe+0x11c/0x15a0 drivers/video/fbdev/smscufx.c:1655\n [] usb_probe_interface+0x177/0x370 drivers/usb/core/driver.c:396\n [] call_driver_probe drivers/base/dd.c:560 [inline]\n [] really_probe+0x12d/0x390 drivers/base/dd.c:639\n [] __driver_probe_device+0xbf/0x140 drivers/base/dd.c:778\n [] driver_probe_device+0x2a/0x120 drivers/base/dd.c:808\n [] __device_attach_driver+0xf7/0x150 drivers/base/dd.c:936\n [] bus_for_each_drv+0xb7/0x100 drivers/base/bus.c:427\n [] __device_attach+0x105/0x2d0 drivers/base/dd.c:1008\n [] bus_probe_device+0xc6/0xe0 drivers/base/bus.c:487\n [] device_add+0x642/0xdc0 drivers/base/core.c:3517\n [] usb_set_configuration+0x8ef/0xb80 drivers/usb/core/message.c:2170\n [] usb_generic_driver_probe+0x8c/0xc0 drivers/usb/core/generic.c:238\n [] usb_probe_device+0x5c/0x140 drivers/usb/core/driver.c:293\n [] call_driver_probe drivers/base/dd.c:560 [inline]\n [] really_probe+0x12d/0x390 drivers/base/dd.c:639\n [] __driver_probe_device+0xbf/0x140 drivers/base/dd.c:778\n\nFix this bug by rewriting the error handling code in ufx_usb_probe.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49741"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/1b4c08844628dfc8d72d3f51b657f2a5e63b7b4b"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/3931014367ef31d26af65386a4ca496f50f0cfdf"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/3b3d3127f5b4291ae4caaf50f7b66089ad600480"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/64fa364ad3245508d393e16ed4886f92d7eb423c"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/b76449ee75e21acfe9fa4c653d8598f191ed7d68"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:38Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-f436-rh44-wfp7/GHSA-f436-rh44-wfp7.json b/advisories/unreviewed/2025/03/GHSA-f436-rh44-wfp7/GHSA-f436-rh44-wfp7.json
new file mode 100644
index 00000000000..582eb2467aa
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-f436-rh44-wfp7/GHSA-f436-rh44-wfp7.json
@@ -0,0 +1,49 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-f436-rh44-wfp7",
+ "modified": "2025-03-27T18:31:27Z",
+ "published": "2025-03-27T18:31:27Z",
+ "aliases": [
+ "CVE-2023-52997"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv4: prevent potential spectre v1 gadget in ip_metrics_convert()\n\nif (!type)\n\t\tcontinue;\n\tif (type > RTAX_MAX)\n\t\treturn -EINVAL;\n\t...\n\tmetrics[type - 1] = val;\n\n@type being used as an array index, we need to prevent\ncpu speculation or risk leaking kernel memory content.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52997"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/1d1d63b612801b3f0a39b7d4467cad0abd60e5c8"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/34c6142f0df9cd75cba5a7aa9df0960d2854b415"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/6850fe301d015a7d2012d1de8caf43dafb7cc2f6"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/746db9ec1e672eee13965625ddac0d97e16fa20c"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/d50e7348b44f1e046121ff5be01b7fb6978a1149"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/ef050cf5fb70d995a0d03244e25179b7c66a924a"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:48Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-f656-g9wf-2686/GHSA-f656-g9wf-2686.json b/advisories/unreviewed/2025/03/GHSA-f656-g9wf-2686/GHSA-f656-g9wf-2686.json
new file mode 100644
index 00000000000..43b01a4f339
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-f656-g9wf-2686/GHSA-f656-g9wf-2686.json
@@ -0,0 +1,45 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-f656-g9wf-2686",
+ "modified": "2025-03-27T18:31:27Z",
+ "published": "2025-03-27T18:31:27Z",
+ "aliases": [
+ "CVE-2023-52996"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv4: prevent potential spectre v1 gadget in fib_metrics_match()\n\nif (!type)\n continue;\n if (type > RTAX_MAX)\n return false;\n ...\n fi_val = fi->fib_metrics->metrics[type - 1];\n\n@type being used as an array index, we need to prevent\ncpu speculation or risk leaking kernel memory content.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52996"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/5e9398a26a92fc402d82ce1f97cc67d832527da0"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/7f9828fb1f688210e681268490576f0ca65c322a"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/8f0eb24f1a7a60ce635f0d757a46f1a37a4d467d"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/ca3cf947760de050d558293002ad3e7f4b8745d2"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/f9753ebd61be2d957b5504cbd3fd719674f05b7a"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:48Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-f76f-mm36-mf6v/GHSA-f76f-mm36-mf6v.json b/advisories/unreviewed/2025/03/GHSA-f76f-mm36-mf6v/GHSA-f76f-mm36-mf6v.json
new file mode 100644
index 00000000000..2057b7613dc
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-f76f-mm36-mf6v/GHSA-f76f-mm36-mf6v.json
@@ -0,0 +1,53 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-f76f-mm36-mf6v",
+ "modified": "2025-03-27T18:31:25Z",
+ "published": "2025-03-27T18:31:25Z",
+ "aliases": [
+ "CVE-2023-52933"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nSquashfs: fix handling and sanity checking of xattr_ids count\n\nA Sysbot [1] corrupted filesystem exposes two flaws in the handling and\nsanity checking of the xattr_ids count in the filesystem. Both of these\nflaws cause computation overflow due to incorrect typing.\n\nIn the corrupted filesystem the xattr_ids value is 4294967071, which\nstored in a signed variable becomes the negative number -225.\n\nFlaw 1 (64-bit systems only):\n\nThe signed integer xattr_ids variable causes sign extension.\n\nThis causes variable overflow in the SQUASHFS_XATTR_*(A) macros. The\nvariable is first multiplied by sizeof(struct squashfs_xattr_id) where the\ntype of the sizeof operator is \"unsigned long\".\n\nOn a 64-bit system this is 64-bits in size, and causes the negative number\nto be sign extended and widened to 64-bits and then become unsigned. This\nproduces the very large number 18446744073709548016 or 2^64 - 3600. This\nnumber when rounded up by SQUASHFS_METADATA_SIZE - 1 (8191 bytes) and\ndivided by SQUASHFS_METADATA_SIZE overflows and produces a length of 0\n(stored in len).\n\nFlaw 2 (32-bit systems only):\n\nOn a 32-bit system the integer variable is not widened by the unsigned\nlong type of the sizeof operator (32-bits), and the signedness of the\nvariable has no effect due it always being treated as unsigned.\n\nThe above corrupted xattr_ids value of 4294967071, when multiplied\noverflows and produces the number 4294963696 or 2^32 - 3400. This number\nwhen rounded up by SQUASHFS_METADATA_SIZE - 1 (8191 bytes) and divided by\nSQUASHFS_METADATA_SIZE overflows again and produces a length of 0.\n\nThe effect of the 0 length computation:\n\nIn conjunction with the corrupted xattr_ids field, the filesystem also has\na corrupted xattr_table_start value, where it matches the end of\nfilesystem value of 850.\n\nThis causes the following sanity check code to fail because the\nincorrectly computed len of 0 matches the incorrect size of the table\nreported by the superblock (0 bytes).\n\n len = SQUASHFS_XATTR_BLOCK_BYTES(*xattr_ids);\n indexes = SQUASHFS_XATTR_BLOCKS(*xattr_ids);\n\n /*\n * The computed size of the index table (len bytes) should exactly\n * match the table start and end points\n */\n start = table_start + sizeof(*id_table);\n end = msblk->bytes_used;\n\n if (len != (end - start))\n return ERR_PTR(-EINVAL);\n\nChanging the xattr_ids variable to be \"usigned int\" fixes the flaw on a\n64-bit system. This relies on the fact the computation is widened by the\nunsigned long type of the sizeof operator.\n\nCasting the variable to u64 in the above macro fixes this flaw on a 32-bit\nsystem.\n\nIt also means 64-bit systems do not implicitly rely on the type of the\nsizeof operator to widen the computation.\n\n[1] https://lore.kernel.org/lkml/000000000000cd44f005f1a0f17f@google.com/",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52933"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/1369322c1de52c7b9b988b95c9903110a4566778"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/5c4d4a83bf1a862d80c1efff1c6e3ce33b501e2e"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/7fe583c9bec10cd4b76231c51b37f3e4ca646e01"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/997bed0f3cde78a3e639d624985bf4a95cf767e6"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/a7da7d01ac5ce9b369a1ac70e1197999cc6c9686"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/b38c3e9e0adc01956cc3e5a52e4d3f92f79d88e2"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/f65c4bbbd682b0877b669828b4e033b8d5d0a2dc"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:43Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-fhrv-4645-phmg/GHSA-fhrv-4645-phmg.json b/advisories/unreviewed/2025/03/GHSA-fhrv-4645-phmg/GHSA-fhrv-4645-phmg.json
new file mode 100644
index 00000000000..60c89fb3bad
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-fhrv-4645-phmg/GHSA-fhrv-4645-phmg.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-fhrv-4645-phmg",
+ "modified": "2025-03-27T18:31:23Z",
+ "published": "2025-03-27T18:31:23Z",
+ "aliases": [
+ "CVE-2025-26909"
+ ],
+ "details": "Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in John Darrel Hide My WP Ghost allows PHP Local File Inclusion.This issue affects Hide My WP Ghost: from n/a through 5.4.01.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26909"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/hide-my-wp/vulnerability/wordpress-hide-my-wp-ghost-plugin-5-4-01-local-file-inclusion-to-rce-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-98"
+ ],
+ "severity": "CRITICAL",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T16:15:30Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-fj6j-g6mj-6hf2/GHSA-fj6j-g6mj-6hf2.json b/advisories/unreviewed/2025/03/GHSA-fj6j-g6mj-6hf2/GHSA-fj6j-g6mj-6hf2.json
new file mode 100644
index 00000000000..6e19c2dc3fb
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-fj6j-g6mj-6hf2/GHSA-fj6j-g6mj-6hf2.json
@@ -0,0 +1,33 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-fj6j-g6mj-6hf2",
+ "modified": "2025-03-27T18:31:25Z",
+ "published": "2025-03-27T18:31:25Z",
+ "aliases": [
+ "CVE-2023-52931"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/i915: Avoid potential vm use-after-free\n\nAdding the vm to the vm_xa table makes it visible to userspace, which\ncould try to race with us to close the vm. So we need to take our extra\nreference before putting it in the table.\n\n(cherry picked from commit 99343c46d4e2b34c285d3d5f68ff04274c2f9fb4)",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52931"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/41d419382ec7e257e54b7b6ff0d3623aafb1316d"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/764accc2c1b8fd1507be2e7f436c94cdce887a00"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:42Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-fx88-897w-ccgj/GHSA-fx88-897w-ccgj.json b/advisories/unreviewed/2025/03/GHSA-fx88-897w-ccgj/GHSA-fx88-897w-ccgj.json
new file mode 100644
index 00000000000..4f51910ab33
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-fx88-897w-ccgj/GHSA-fx88-897w-ccgj.json
@@ -0,0 +1,45 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-fx88-897w-ccgj",
+ "modified": "2025-03-27T18:31:26Z",
+ "published": "2025-03-27T18:31:26Z",
+ "aliases": [
+ "CVE-2023-52976"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nefi: fix potential NULL deref in efi_mem_reserve_persistent\n\nWhen iterating on a linked list, a result of memremap is dereferenced\nwithout checking it for NULL.\n\nThis patch adds a check that falls back on allocating a new page in\ncase memremap doesn't succeed.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.\n\n[ardb: return -ENOMEM instead of breaking out of the loop]",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52976"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/87d4ff18738fd71e7e3c10827c80257da6283697"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/966d47e1f27c45507c5df82b2a2157e5a4fd3909"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/a2e6a9ff89f13666a1c3ff7195612ab949ea9afc"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/d8fc0b5fb3e816a4a8684bcd3ed02cbef0fce23c"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/d92a25627bcdf264183670da73c9a60c0bac327e"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:44Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-g5qc-p7w9-v26c/GHSA-g5qc-p7w9-v26c.json b/advisories/unreviewed/2025/03/GHSA-g5qc-p7w9-v26c/GHSA-g5qc-p7w9-v26c.json
new file mode 100644
index 00000000000..c8fb7577c99
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-g5qc-p7w9-v26c/GHSA-g5qc-p7w9-v26c.json
@@ -0,0 +1,53 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-g5qc-p7w9-v26c",
+ "modified": "2025-03-27T18:31:29Z",
+ "published": "2025-03-27T18:31:29Z",
+ "aliases": [
+ "CVE-2023-53032"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: ipset: Fix overflow before widen in the bitmap_ip_create() function.\n\nWhen first_ip is 0, last_ip is 0xFFFFFFFF, and netmask is 31, the value of\nan arithmetic expression 2 << (netmask - mask_bits - 1) is subject\nto overflow due to a failure casting operands to a larger data type\nbefore performing the arithmetic.\n\nNote that it's harmless since the value will be checked at the next step.\n\nFound by InfoTeCS on behalf of Linux Verification Center\n(linuxtesting.org) with SVACE.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-53032"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/4e6a70fd840400e3a2e784a6673968a3eb2431c0"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/511cf17b2447fc41cfef8d71936e1fa53e395c1e"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/9ea4b476cea1b7d461d16dda25ca3c7e616e2d15"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/dfd834ccc1b88bbbab81b9046a3a539dd0c2d14f"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/e137d9bb26bd85ce07323a38e38ceb0b160db841"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/e88865876d47c790be0d5e23973499d75d034364"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/feefb33eefa166fc3e0fd17547b0bc0cb3baced9"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:52Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-g7hp-hfwm-x3rp/GHSA-g7hp-hfwm-x3rp.json b/advisories/unreviewed/2025/03/GHSA-g7hp-hfwm-x3rp/GHSA-g7hp-hfwm-x3rp.json
new file mode 100644
index 00000000000..9a074056e22
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-g7hp-hfwm-x3rp/GHSA-g7hp-hfwm-x3rp.json
@@ -0,0 +1,53 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-g7hp-hfwm-x3rp",
+ "modified": "2025-03-27T18:31:26Z",
+ "published": "2025-03-27T18:31:26Z",
+ "aliases": [
+ "CVE-2023-52993"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/i8259: Mark legacy PIC interrupts with IRQ_LEVEL\n\nBaoquan reported that after triggering a crash the subsequent crash-kernel\nfails to boot about half of the time. It triggers a NULL pointer\ndereference in the periodic tick code.\n\nThis happens because the legacy timer interrupt (IRQ0) is resent in\nsoftware which happens in soft interrupt (tasklet) context. In this context\nget_irq_regs() returns NULL which leads to the NULL pointer dereference.\n\nThe reason for the resend is a spurious APIC interrupt on the IRQ0 vector\nwhich is captured and leads to a resend when the legacy timer interrupt is\nenabled. This is wrong because the legacy PIC interrupts are level\ntriggered and therefore should never be resent in software, but nothing\never sets the IRQ_LEVEL flag on those interrupts, so the core code does not\nknow about their trigger type.\n\nEnsure that IRQ_LEVEL is set when the legacy PCI interrupts are set up.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52993"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/0b08201158f177aab469e356b4d6af24fdd118df"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/137f1b47da5f58805da42c1b7811e28c1e353f39"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/496975d1a2937f4baadf3d985991b13fc4fc4f27"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/5fa55950729d0762a787451dc52862c3f850f859"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/744fe9be9665227335539b7a77ece8d9ff62b6c0"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/8770cd9d7c14aa99c255a0d08186f0be953e1638"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/e284c273dbb4c1ed68d4204bff94d0b10e4a90f5"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:46Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-gj95-rf37-g546/GHSA-gj95-rf37-g546.json b/advisories/unreviewed/2025/03/GHSA-gj95-rf37-g546/GHSA-gj95-rf37-g546.json
index 4c89cdd9ff0..2a113caa020 100644
--- a/advisories/unreviewed/2025/03/GHSA-gj95-rf37-g546/GHSA-gj95-rf37-g546.json
+++ b/advisories/unreviewed/2025/03/GHSA-gj95-rf37-g546/GHSA-gj95-rf37-g546.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gj95-rf37-g546",
- "modified": "2025-03-25T21:31:33Z",
+ "modified": "2025-03-27T18:31:02Z",
"published": "2025-03-25T21:31:33Z",
"aliases": [
"CVE-2024-55029"
],
"details": "NASA Fprime v3.4.3 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
+ }
+ ],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-25T21:15:41Z"
diff --git a/advisories/unreviewed/2025/03/GHSA-gmm6-5vw5-42h2/GHSA-gmm6-5vw5-42h2.json b/advisories/unreviewed/2025/03/GHSA-gmm6-5vw5-42h2/GHSA-gmm6-5vw5-42h2.json
new file mode 100644
index 00000000000..0f174d9af95
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-gmm6-5vw5-42h2/GHSA-gmm6-5vw5-42h2.json
@@ -0,0 +1,29 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-gmm6-5vw5-42h2",
+ "modified": "2025-03-27T18:31:23Z",
+ "published": "2025-03-27T18:31:23Z",
+ "aliases": [
+ "CVE-2025-28138"
+ ],
+ "details": "TOTOLINK A800R V4.1.2cu.5137_B20200730 contains a remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28138"
+ },
+ {
+ "type": "WEB",
+ "url": "https://sudsy-eyeliner-a59.notion.site/RCE2-1ac72b8cd95f8055a76ee0ca262aac1a?pvs=4"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T16:15:30Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-gqwp-f6mc-jxp2/GHSA-gqwp-f6mc-jxp2.json b/advisories/unreviewed/2025/03/GHSA-gqwp-f6mc-jxp2/GHSA-gqwp-f6mc-jxp2.json
index 23ec4244802..4c067e87d1b 100644
--- a/advisories/unreviewed/2025/03/GHSA-gqwp-f6mc-jxp2/GHSA-gqwp-f6mc-jxp2.json
+++ b/advisories/unreviewed/2025/03/GHSA-gqwp-f6mc-jxp2/GHSA-gqwp-f6mc-jxp2.json
@@ -46,7 +46,8 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-74"
+ "CWE-74",
+ "CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2025/03/GHSA-gqww-qgqj-92wg/GHSA-gqww-qgqj-92wg.json b/advisories/unreviewed/2025/03/GHSA-gqww-qgqj-92wg/GHSA-gqww-qgqj-92wg.json
new file mode 100644
index 00000000000..b4652d5af4e
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-gqww-qgqj-92wg/GHSA-gqww-qgqj-92wg.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-gqww-qgqj-92wg",
+ "modified": "2025-03-27T18:31:23Z",
+ "published": "2025-03-27T18:31:23Z",
+ "aliases": [
+ "CVE-2025-22640"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Paytm Paytm Payment Donation allows Stored XSS.This issue affects Paytm Payment Donation: from n/a through 2.3.3.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22640"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/paytm-donation/vulnerability/wordpress-paytm-payment-donation-plugin-2-3-2-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T16:15:28Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-gr26-qx48-q4hh/GHSA-gr26-qx48-q4hh.json b/advisories/unreviewed/2025/03/GHSA-gr26-qx48-q4hh/GHSA-gr26-qx48-q4hh.json
new file mode 100644
index 00000000000..7d1725b4d19
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-gr26-qx48-q4hh/GHSA-gr26-qx48-q4hh.json
@@ -0,0 +1,45 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-gr26-qx48-q4hh",
+ "modified": "2025-03-27T18:31:29Z",
+ "published": "2025-03-27T18:31:28Z",
+ "aliases": [
+ "CVE-2023-53026"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/core: Fix ib block iterator counter overflow\n\nWhen registering a new DMA MR after selecting the best aligned page size\nfor it, we iterate over the given sglist to split each entry to smaller,\naligned to the selected page size, DMA blocks.\n\nIn given circumstances where the sg entry and page size fit certain\nsizes and the sg entry is not aligned to the selected page size, the\ntotal size of the aligned pages we need to cover the sg entry is >= 4GB.\nUnder this circumstances, while iterating page aligned blocks, the\ncounter responsible for counting how much we advanced from the start of\nthe sg entry is overflowed because its type is u32 and we pass 4GB in\nsize. This can lead to an infinite loop inside the iterator function\nbecause the overflow prevents the counter to be larger\nthan the size of the sg entry.\n\nFix the presented problem by changing the advancement condition to\neliminate overflow.\n\nBacktrace:\n[ 192.374329] efa_reg_user_mr_dmabuf\n[ 192.376783] efa_register_mr\n[ 192.382579] pgsz_bitmap 0xfffff000 rounddown 0x80000000\n[ 192.386423] pg_sz [0x80000000] umem_length[0xc0000000]\n[ 192.392657] start 0x0 length 0xc0000000 params.page_shift 31 params.page_num 3\n[ 192.399559] hp_cnt[3], pages_in_hp[524288]\n[ 192.403690] umem->sgt_append.sgt.nents[1]\n[ 192.407905] number entries: [1], pg_bit: [31]\n[ 192.411397] biter->__sg_nents [1] biter->__sg [0000000008b0c5d8]\n[ 192.415601] biter->__sg_advance [665837568] sg_dma_len[3221225472]\n[ 192.419823] biter->__sg_nents [1] biter->__sg [0000000008b0c5d8]\n[ 192.423976] biter->__sg_advance [2813321216] sg_dma_len[3221225472]\n[ 192.428243] biter->__sg_nents [1] biter->__sg [0000000008b0c5d8]\n[ 192.432397] biter->__sg_advance [665837568] sg_dma_len[3221225472]",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-53026"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/0afec5e9cea732cb47014655685a2a47fb180c31"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/362c9489720b31b6aa7491423ba65a4e98aa9838"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/43811d07ea64366af8ec9e168c558ec51440c39e"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/902063a9fea5f8252df392ade746bc9cfd07a5ae"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/d66c1d4178c219b6e7d7a6f714e3e3656faccc36"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:52Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-gr59-j2cc-29g3/GHSA-gr59-j2cc-29g3.json b/advisories/unreviewed/2025/03/GHSA-gr59-j2cc-29g3/GHSA-gr59-j2cc-29g3.json
new file mode 100644
index 00000000000..a4d8eebd36c
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-gr59-j2cc-29g3/GHSA-gr59-j2cc-29g3.json
@@ -0,0 +1,41 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-gr59-j2cc-29g3",
+ "modified": "2025-03-27T18:31:29Z",
+ "published": "2025-03-27T18:31:29Z",
+ "aliases": [
+ "CVE-2023-53028"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRevert \"wifi: mac80211: fix memory leak in ieee80211_if_add()\"\n\nThis reverts commit 13e5afd3d773c6fc6ca2b89027befaaaa1ea7293.\n\nieee80211_if_free() is already called from free_netdev(ndev)\nbecause ndev->priv_destructor == ieee80211_if_free\n\nsyzbot reported:\n\ngeneral protection fault, probably for non-canonical address 0xdffffc0000000004: 0000 [#1] PREEMPT SMP KASAN\nKASAN: null-ptr-deref in range [0x0000000000000020-0x0000000000000027]\nCPU: 0 PID: 10041 Comm: syz-executor.0 Not tainted 6.2.0-rc2-syzkaller-00388-g55b98837e37d #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/26/2022\nRIP: 0010:pcpu_get_page_chunk mm/percpu.c:262 [inline]\nRIP: 0010:pcpu_chunk_addr_search mm/percpu.c:1619 [inline]\nRIP: 0010:free_percpu mm/percpu.c:2271 [inline]\nRIP: 0010:free_percpu+0x186/0x10f0 mm/percpu.c:2254\nCode: 80 3c 02 00 0f 85 f5 0e 00 00 48 8b 3b 48 01 ef e8 cf b3 0b 00 48 ba 00 00 00 00 00 fc ff df 48 8d 78 20 48 89 f9 48 c1 e9 03 <80> 3c 11 00 0f 85 3b 0e 00 00 48 8b 58 20 48 b8 00 00 00 00 00 fc\nRSP: 0018:ffffc90004ba7068 EFLAGS: 00010002\nRAX: 0000000000000000 RBX: ffff88823ffe2b80 RCX: 0000000000000004\nRDX: dffffc0000000000 RSI: ffffffff81c1f4e7 RDI: 0000000000000020\nRBP: ffffe8fffe8fc220 R08: 0000000000000005 R09: 0000000000000000\nR10: 0000000000000000 R11: 1ffffffff2179ab2 R12: ffff8880b983d000\nR13: 0000000000000003 R14: 0000607f450fc220 R15: ffff88823ffe2988\nFS: 00007fcb349de700(0000) GS:ffff8880b9800000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000001b32220000 CR3: 000000004914f000 CR4: 00000000003506f0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nCall Trace:\n\nnetdev_run_todo+0x6bf/0x1100 net/core/dev.c:10352\nieee80211_register_hw+0x2663/0x4040 net/mac80211/main.c:1411\nmac80211_hwsim_new_radio+0x2537/0x4d80 drivers/net/wireless/mac80211_hwsim.c:4583\nhwsim_new_radio_nl+0xa09/0x10f0 drivers/net/wireless/mac80211_hwsim.c:5176\ngenl_family_rcv_msg_doit.isra.0+0x1e6/0x2d0 net/netlink/genetlink.c:968\ngenl_family_rcv_msg net/netlink/genetlink.c:1048 [inline]\ngenl_rcv_msg+0x4ff/0x7e0 net/netlink/genetlink.c:1065\nnetlink_rcv_skb+0x165/0x440 net/netlink/af_netlink.c:2564\ngenl_rcv+0x28/0x40 net/netlink/genetlink.c:1076\nnetlink_unicast_kernel net/netlink/af_netlink.c:1330 [inline]\nnetlink_unicast+0x547/0x7f0 net/netlink/af_netlink.c:1356\nnetlink_sendmsg+0x91b/0xe10 net/netlink/af_netlink.c:1932\nsock_sendmsg_nosec net/socket.c:714 [inline]\nsock_sendmsg+0xd3/0x120 net/socket.c:734\n____sys_sendmsg+0x712/0x8c0 net/socket.c:2476\n___sys_sendmsg+0x110/0x1b0 net/socket.c:2530\n__sys_sendmsg+0xf7/0x1c0 net/socket.c:2559\ndo_syscall_x64 arch/x86/entry/common.c:50 [inline]\ndo_syscall_64+0x39/0xb0 arch/x86/entry/common.c:80\nentry_SYSCALL_64_after_hwframe+0x63/0xcd",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-53028"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/71e5cd1018d345e649e63f74a56c1897f99db7e9"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/80f8a66dede0a4b4e9e846765a97809c6fe49ce5"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/982c8b1e95c088f5d8f65967ec25be66e961401c"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/effecd8d116d3d3a28b4f628e61bba8d318fdfcf"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:52Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-gw27-9x3h-33gj/GHSA-gw27-9x3h-33gj.json b/advisories/unreviewed/2025/03/GHSA-gw27-9x3h-33gj/GHSA-gw27-9x3h-33gj.json
index 23eff621fce..1fbaa2343b4 100644
--- a/advisories/unreviewed/2025/03/GHSA-gw27-9x3h-33gj/GHSA-gw27-9x3h-33gj.json
+++ b/advisories/unreviewed/2025/03/GHSA-gw27-9x3h-33gj/GHSA-gw27-9x3h-33gj.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gw27-9x3h-33gj",
- "modified": "2025-03-13T15:32:54Z",
+ "modified": "2025-03-27T18:30:45Z",
"published": "2025-03-06T18:31:11Z",
"aliases": [
"CVE-2024-58083"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: Explicitly verify target vCPU is online in kvm_get_vcpu()\n\nExplicitly verify the target vCPU is fully online _prior_ to clamping the\nindex in kvm_get_vcpu(). If the index is \"bad\", the nospec clamping will\ngenerate '0', i.e. KVM will return vCPU0 instead of NULL.\n\nIn practice, the bug is unlikely to cause problems, as it will only come\ninto play if userspace or the guest is buggy or misbehaving, e.g. KVM may\nsend interrupts to vCPU0 instead of dropping them on the floor.\n\nHowever, returning vCPU0 when it shouldn't exist per online_vcpus is\nproblematic now that KVM uses an xarray for the vCPUs array, as KVM needs\nto insert into the xarray before publishing the vCPU to userspace (see\ncommit c5b077549136 (\"KVM: Convert the kvm->vcpus array to a xarray\")),\ni.e. before vCPU creation is guaranteed to succeed.\n\nAs a result, incorrectly providing access to vCPU0 will trigger a\nuse-after-free if vCPU0 is dereferenced and kvm_vm_ioctl_create_vcpu()\nbails out of vCPU creation due to an error and frees vCPU0. Commit\nafb2acb2e3a3 (\"KVM: Fix vcpu_array[0] races\") papered over that issue, but\nin doing so introduced an unsolvable teardown conundrum. Preventing\naccesses to vCPU0 before it's fully online will allow reverting commit\nafb2acb2e3a3, without re-introducing the vcpu_array[0] UAF race.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -48,8 +53,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-06T17:15:21Z"
diff --git a/advisories/unreviewed/2025/03/GHSA-gw36-8q8h-w9xm/GHSA-gw36-8q8h-w9xm.json b/advisories/unreviewed/2025/03/GHSA-gw36-8q8h-w9xm/GHSA-gw36-8q8h-w9xm.json
new file mode 100644
index 00000000000..fb8fc800f9b
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-gw36-8q8h-w9xm/GHSA-gw36-8q8h-w9xm.json
@@ -0,0 +1,53 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-gw36-8q8h-w9xm",
+ "modified": "2025-03-27T18:31:24Z",
+ "published": "2025-03-27T18:31:24Z",
+ "aliases": [
+ "CVE-2022-49751"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nw1: fix WARNING after calling w1_process()\n\nI got the following WARNING message while removing driver(ds2482):\n\n------------[ cut here ]------------\ndo not call blocking ops when !TASK_RUNNING; state=1 set at [<000000002d50bfb6>] w1_process+0x9e/0x1d0 [wire]\nWARNING: CPU: 0 PID: 262 at kernel/sched/core.c:9817 __might_sleep+0x98/0xa0\nCPU: 0 PID: 262 Comm: w1_bus_master1 Tainted: G N 6.1.0-rc3+ #307\nRIP: 0010:__might_sleep+0x98/0xa0\nCall Trace:\n exit_signals+0x6c/0x550\n do_exit+0x2b4/0x17e0\n kthread_exit+0x52/0x60\n kthread+0x16d/0x1e0\n ret_from_fork+0x1f/0x30\n\nThe state of task is set to TASK_INTERRUPTIBLE in loop in w1_process(),\nset it to TASK_RUNNING when it breaks out of the loop to avoid the\nwarning.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49751"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/190b5c3bbd5df685bb1063bda048831d72b8f1d4"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/216f35db6ec6a667cd9db4838d657c1d2f4684da"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/276052159ba94d4d9f5b453fb4707d6798c6b845"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/36225a7c72e9e3e1ce4001b6ce72849f5c9a2d3b"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/89c62cee5d4d65ac75d99b5f986f7f94290e888f"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/bccd6df4c177b1ad766f16565ccc298653d027d0"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/cfc7462ff824ed6718ed0272ee9aae88e20d469a"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:39Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-hcxq-v393-38jh/GHSA-hcxq-v393-38jh.json b/advisories/unreviewed/2025/03/GHSA-hcxq-v393-38jh/GHSA-hcxq-v393-38jh.json
new file mode 100644
index 00000000000..70dee8607e4
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-hcxq-v393-38jh/GHSA-hcxq-v393-38jh.json
@@ -0,0 +1,49 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-hcxq-v393-38jh",
+ "modified": "2025-03-27T18:31:27Z",
+ "published": "2025-03-27T18:31:27Z",
+ "aliases": [
+ "CVE-2023-53005"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntrace_events_hist: add check for return value of 'create_hist_field'\n\nFunction 'create_hist_field' is called recursively at\ntrace_events_hist.c:1954 and can return NULL-value that's why we have\nto check it to avoid null pointer dereference.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-53005"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/31b2414abeaa6de0490e85164badc6dcb1bb8ec9"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/592ba7116fa620425725ff0972691f352ba3caf6"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/886aa449235f478e262bbd5dcdee6ed6bc202949"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/8b152e9150d07a885f95e1fd401fc81af202d9a4"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/b4e7e81b4fdfcf457daee6b7a61769f62198d840"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/d2d1ada58e7cc100b8d7d6b082d19321ba4a700a"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:49Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-hjff-56wf-4v5f/GHSA-hjff-56wf-4v5f.json b/advisories/unreviewed/2025/03/GHSA-hjff-56wf-4v5f/GHSA-hjff-56wf-4v5f.json
new file mode 100644
index 00000000000..9ed63c20b3f
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-hjff-56wf-4v5f/GHSA-hjff-56wf-4v5f.json
@@ -0,0 +1,45 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-hjff-56wf-4v5f",
+ "modified": "2025-03-27T18:31:24Z",
+ "published": "2025-03-27T18:31:24Z",
+ "aliases": [
+ "CVE-2022-49748"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nperf/x86/amd: fix potential integer overflow on shift of a int\n\nThe left shift of int 32 bit integer constant 1 is evaluated using 32 bit\narithmetic and then passed as a 64 bit function argument. In the case where\ni is 32 or more this can lead to an overflow. Avoid this by shifting\nusing the BIT_ULL macro instead.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49748"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/08245672cdc6505550d1a5020603b0a8d4a6dcc7"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/14cc13e433e1067557435b1adbf05608d7d47a93"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/a4d01fb87ece45d4164fd725890211ccf9a307a9"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/f84c9b72fb200633774704d8020f769c88a4b249"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/fbf7b0e4cef3b5470b610f14fb9faa5ee7f63954"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:39Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-hxj2-x4g6-rhf8/GHSA-hxj2-x4g6-rhf8.json b/advisories/unreviewed/2025/03/GHSA-hxj2-x4g6-rhf8/GHSA-hxj2-x4g6-rhf8.json
new file mode 100644
index 00000000000..ffbfa8b8d58
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-hxj2-x4g6-rhf8/GHSA-hxj2-x4g6-rhf8.json
@@ -0,0 +1,41 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-hxj2-x4g6-rhf8",
+ "modified": "2025-03-27T18:31:24Z",
+ "published": "2025-03-27T18:31:24Z",
+ "aliases": [
+ "CVE-2022-49749"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ni2c: designware: use casting of u64 in clock multiplication to avoid overflow\n\nIn functions i2c_dw_scl_lcnt() and i2c_dw_scl_hcnt() may have overflow\nby depending on the values of the given parameters including the ic_clk.\nFor example in our use case where ic_clk is larger than one million,\nmultiplication of ic_clk * 4700 will result in 32 bit overflow.\n\nAdd cast of u64 to the calculation to avoid multiplication overflow, and\nuse the corresponding define for divide.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49749"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/2f29d780bd691d20e89e5b35d5e6568607115e94"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/9f36aae9e80e79b7a6d62227eaa96935166be9fe"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/c8c37bc514514999e62a17e95160ed9ebf75ca8d"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/ed173f77fd28a3e4fffc13b3f28687b9eba61157"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:39Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-j94v-m9xh-gwvq/GHSA-j94v-m9xh-gwvq.json b/advisories/unreviewed/2025/03/GHSA-j94v-m9xh-gwvq/GHSA-j94v-m9xh-gwvq.json
new file mode 100644
index 00000000000..ab4f4f2ec0f
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-j94v-m9xh-gwvq/GHSA-j94v-m9xh-gwvq.json
@@ -0,0 +1,52 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-j94v-m9xh-gwvq",
+ "modified": "2025-03-27T18:31:28Z",
+ "published": "2025-03-27T18:31:28Z",
+ "aliases": [
+ "CVE-2023-53021"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: sch_taprio: fix possible use-after-free\n\nsyzbot reported a nasty crash [1] in net_tx_action() which\nmade little sense until we got a repro.\n\nThis repro installs a taprio qdisc, but providing an\ninvalid TCA_RATE attribute.\n\nqdisc_create() has to destroy the just initialized\ntaprio qdisc, and taprio_destroy() is called.\n\nHowever, the hrtimer used by taprio had already fired,\ntherefore advance_sched() called __netif_schedule().\n\nThen net_tx_action was trying to use a destroyed qdisc.\n\nWe can not undo the __netif_schedule(), so we must wait\nuntil one cpu serviced the qdisc before we can proceed.\n\nMany thanks to Alexander Potapenko for his help.\n\n[1]\nBUG: KMSAN: uninit-value in queued_spin_trylock include/asm-generic/qspinlock.h:94 [inline]\nBUG: KMSAN: uninit-value in do_raw_spin_trylock include/linux/spinlock.h:191 [inline]\nBUG: KMSAN: uninit-value in __raw_spin_trylock include/linux/spinlock_api_smp.h:89 [inline]\nBUG: KMSAN: uninit-value in _raw_spin_trylock+0x92/0xa0 kernel/locking/spinlock.c:138\n queued_spin_trylock include/asm-generic/qspinlock.h:94 [inline]\n do_raw_spin_trylock include/linux/spinlock.h:191 [inline]\n __raw_spin_trylock include/linux/spinlock_api_smp.h:89 [inline]\n _raw_spin_trylock+0x92/0xa0 kernel/locking/spinlock.c:138\n spin_trylock include/linux/spinlock.h:359 [inline]\n qdisc_run_begin include/net/sch_generic.h:187 [inline]\n qdisc_run+0xee/0x540 include/net/pkt_sched.h:125\n net_tx_action+0x77c/0x9a0 net/core/dev.c:5086\n __do_softirq+0x1cc/0x7fb kernel/softirq.c:571\n run_ksoftirqd+0x2c/0x50 kernel/softirq.c:934\n smpboot_thread_fn+0x554/0x9f0 kernel/smpboot.c:164\n kthread+0x31b/0x430 kernel/kthread.c:376\n ret_from_fork+0x1f/0x30\n\nUninit was created at:\n slab_post_alloc_hook mm/slab.h:732 [inline]\n slab_alloc_node mm/slub.c:3258 [inline]\n __kmalloc_node_track_caller+0x814/0x1250 mm/slub.c:4970\n kmalloc_reserve net/core/skbuff.c:358 [inline]\n __alloc_skb+0x346/0xcf0 net/core/skbuff.c:430\n alloc_skb include/linux/skbuff.h:1257 [inline]\n nlmsg_new include/net/netlink.h:953 [inline]\n netlink_ack+0x5f3/0x12b0 net/netlink/af_netlink.c:2436\n netlink_rcv_skb+0x55d/0x6c0 net/netlink/af_netlink.c:2507\n rtnetlink_rcv+0x30/0x40 net/core/rtnetlink.c:6108\n netlink_unicast_kernel net/netlink/af_netlink.c:1319 [inline]\n netlink_unicast+0xf3b/0x1270 net/netlink/af_netlink.c:1345\n netlink_sendmsg+0x1288/0x1440 net/netlink/af_netlink.c:1921\n sock_sendmsg_nosec net/socket.c:714 [inline]\n sock_sendmsg net/socket.c:734 [inline]\n ____sys_sendmsg+0xabc/0xe90 net/socket.c:2482\n ___sys_sendmsg+0x2a1/0x3f0 net/socket.c:2536\n __sys_sendmsg net/socket.c:2565 [inline]\n __do_sys_sendmsg net/socket.c:2574 [inline]\n __se_sys_sendmsg net/socket.c:2572 [inline]\n __x64_sys_sendmsg+0x367/0x540 net/socket.c:2572\n do_syscall_x64 arch/x86/entry/common.c:50 [inline]\n do_syscall_64+0x3d/0xb0 arch/x86/entry/common.c:80\n entry_SYSCALL_64_after_hwframe+0x63/0xcd\n\nCPU: 0 PID: 13 Comm: ksoftirqd/0 Not tainted 6.0.0-rc2-syzkaller-47461-gac3859c02d7f #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 07/22/2022",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-53021"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/1200388a0b1c3c6fda48d4d2143db8f7e4ef5348"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/3a415d59c1dbec9d772dbfab2d2520d98360caae"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/c53acbf2facfdfabdc6e6984a1a38f5d38b606a1"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/c60fe70078d6e515f424cb868d07e00411b27fbc"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/d3b2d2820a005e43855fa71b80c4a4b194201c60"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:51Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-jhxv-jq7p-9qhc/GHSA-jhxv-jq7p-9qhc.json b/advisories/unreviewed/2025/03/GHSA-jhxv-jq7p-9qhc/GHSA-jhxv-jq7p-9qhc.json
new file mode 100644
index 00000000000..7fc879621e3
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-jhxv-jq7p-9qhc/GHSA-jhxv-jq7p-9qhc.json
@@ -0,0 +1,33 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-jhxv-jq7p-9qhc",
+ "modified": "2025-03-27T18:31:24Z",
+ "published": "2025-03-27T18:31:24Z",
+ "aliases": [
+ "CVE-2022-49759"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nVMCI: Use threaded irqs instead of tasklets\n\nThe vmci_dispatch_dgs() tasklet function calls vmci_read_data()\nwhich uses wait_event() resulting in invalid sleep in an atomic\ncontext (and therefore potentially in a deadlock).\n\nUse threaded irqs to fix this issue and completely remove usage\nof tasklets.\n\n[ 20.264639] BUG: sleeping function called from invalid context at drivers/misc/vmw_vmci/vmci_guest.c:145\n[ 20.264643] in_atomic(): 1, irqs_disabled(): 0, non_block: 0, pid: 762, name: vmtoolsd\n[ 20.264645] preempt_count: 101, expected: 0\n[ 20.264646] RCU nest depth: 0, expected: 0\n[ 20.264647] 1 lock held by vmtoolsd/762:\n[ 20.264648] #0: ffff0000874ae440 (sk_lock-AF_VSOCK){+.+.}-{0:0}, at: vsock_connect+0x60/0x330 [vsock]\n[ 20.264658] Preemption disabled at:\n[ 20.264659] [] vmci_send_datagram+0x44/0xa0 [vmw_vmci]\n[ 20.264665] CPU: 0 PID: 762 Comm: vmtoolsd Not tainted 5.19.0-0.rc8.20220727git39c3c396f813.60.fc37.aarch64 #1\n[ 20.264667] Hardware name: VMware, Inc. VBSA/VBSA, BIOS VEFI 12/31/2020\n[ 20.264668] Call trace:\n[ 20.264669] dump_backtrace+0xc4/0x130\n[ 20.264672] show_stack+0x24/0x80\n[ 20.264673] dump_stack_lvl+0x88/0xb4\n[ 20.264676] dump_stack+0x18/0x34\n[ 20.264677] __might_resched+0x1a0/0x280\n[ 20.264679] __might_sleep+0x58/0x90\n[ 20.264681] vmci_read_data+0x74/0x120 [vmw_vmci]\n[ 20.264683] vmci_dispatch_dgs+0x64/0x204 [vmw_vmci]\n[ 20.264686] tasklet_action_common.constprop.0+0x13c/0x150\n[ 20.264688] tasklet_action+0x40/0x50\n[ 20.264689] __do_softirq+0x23c/0x6b4\n[ 20.264690] __irq_exit_rcu+0x104/0x214\n[ 20.264691] irq_exit_rcu+0x1c/0x50\n[ 20.264693] el1_interrupt+0x38/0x6c\n[ 20.264695] el1h_64_irq_handler+0x18/0x24\n[ 20.264696] el1h_64_irq+0x68/0x6c\n[ 20.264697] preempt_count_sub+0xa4/0xe0\n[ 20.264698] _raw_spin_unlock_irqrestore+0x64/0xb0\n[ 20.264701] vmci_send_datagram+0x7c/0xa0 [vmw_vmci]\n[ 20.264703] vmci_datagram_dispatch+0x84/0x100 [vmw_vmci]\n[ 20.264706] vmci_datagram_send+0x2c/0x40 [vmw_vmci]\n[ 20.264709] vmci_transport_send_control_pkt+0xb8/0x120 [vmw_vsock_vmci_transport]\n[ 20.264711] vmci_transport_connect+0x40/0x7c [vmw_vsock_vmci_transport]\n[ 20.264713] vsock_connect+0x278/0x330 [vsock]\n[ 20.264715] __sys_connect_file+0x8c/0xc0\n[ 20.264718] __sys_connect+0x84/0xb4\n[ 20.264720] __arm64_sys_connect+0x2c/0x3c\n[ 20.264721] invoke_syscall+0x78/0x100\n[ 20.264723] el0_svc_common.constprop.0+0x68/0x124\n[ 20.264724] do_el0_svc+0x38/0x4c\n[ 20.264725] el0_svc+0x60/0x180\n[ 20.264726] el0t_64_sync_handler+0x11c/0x150\n[ 20.264728] el0t_64_sync+0x190/0x194",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49759"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/3daed6345d5880464f46adab871d208e1baa2f3a"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/548ea9dd5e01b0ecf53d2563004c80abd636743d"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:41Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-jph2-wv5j-5w33/GHSA-jph2-wv5j-5w33.json b/advisories/unreviewed/2025/03/GHSA-jph2-wv5j-5w33/GHSA-jph2-wv5j-5w33.json
new file mode 100644
index 00000000000..d4f1c46cd51
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-jph2-wv5j-5w33/GHSA-jph2-wv5j-5w33.json
@@ -0,0 +1,45 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-jph2-wv5j-5w33",
+ "modified": "2025-03-27T18:31:29Z",
+ "published": "2025-03-27T18:31:29Z",
+ "aliases": [
+ "CVE-2023-53031"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\npowerpc/imc-pmu: Fix use of mutex in IRQs disabled section\n\nCurrent imc-pmu code triggers a WARNING with CONFIG_DEBUG_ATOMIC_SLEEP\nand CONFIG_PROVE_LOCKING enabled, while running a thread_imc event.\n\nCommand to trigger the warning:\n # perf stat -e thread_imc/CPM_CS_FROM_L4_MEM_X_DPTEG/ sleep 5\n\n Performance counter stats for 'sleep 5':\n\n 0 thread_imc/CPM_CS_FROM_L4_MEM_X_DPTEG/\n\n 5.002117947 seconds time elapsed\n\n 0.000131000 seconds user\n 0.001063000 seconds sys\n\nBelow is snippet of the warning in dmesg:\n\n BUG: sleeping function called from invalid context at kernel/locking/mutex.c:580\n in_atomic(): 1, irqs_disabled(): 1, non_block: 0, pid: 2869, name: perf-exec\n preempt_count: 2, expected: 0\n 4 locks held by perf-exec/2869:\n #0: c00000004325c540 (&sig->cred_guard_mutex){+.+.}-{3:3}, at: bprm_execve+0x64/0xa90\n #1: c00000004325c5d8 (&sig->exec_update_lock){++++}-{3:3}, at: begin_new_exec+0x460/0xef0\n #2: c0000003fa99d4e0 (&cpuctx_lock){-...}-{2:2}, at: perf_event_exec+0x290/0x510\n #3: c000000017ab8418 (&ctx->lock){....}-{2:2}, at: perf_event_exec+0x29c/0x510\n irq event stamp: 4806\n hardirqs last enabled at (4805): [] _raw_spin_unlock_irqrestore+0x94/0xd0\n hardirqs last disabled at (4806): [] perf_event_exec+0x394/0x510\n softirqs last enabled at (0): [] copy_process+0xc34/0x1ff0\n softirqs last disabled at (0): [<0000000000000000>] 0x0\n CPU: 36 PID: 2869 Comm: perf-exec Not tainted 6.2.0-rc2-00011-g1247637727f2 #61\n Hardware name: 8375-42A POWER9 0x4e1202 opal:v7.0-16-g9b85f7d961 PowerNV\n Call Trace:\n dump_stack_lvl+0x98/0xe0 (unreliable)\n __might_resched+0x2f8/0x310\n __mutex_lock+0x6c/0x13f0\n thread_imc_event_add+0xf4/0x1b0\n event_sched_in+0xe0/0x210\n merge_sched_in+0x1f0/0x600\n visit_groups_merge.isra.92.constprop.166+0x2bc/0x6c0\n ctx_flexible_sched_in+0xcc/0x140\n ctx_sched_in+0x20c/0x2a0\n ctx_resched+0x104/0x1c0\n perf_event_exec+0x340/0x510\n begin_new_exec+0x730/0xef0\n load_elf_binary+0x3f8/0x1e10\n ...\n do not call blocking ops when !TASK_RUNNING; state=2001 set at [<00000000fd63e7cf>] do_nanosleep+0x60/0x1a0\n WARNING: CPU: 36 PID: 2869 at kernel/sched/core.c:9912 __might_sleep+0x9c/0xb0\n CPU: 36 PID: 2869 Comm: sleep Tainted: G W 6.2.0-rc2-00011-g1247637727f2 #61\n Hardware name: 8375-42A POWER9 0x4e1202 opal:v7.0-16-g9b85f7d961 PowerNV\n NIP: c000000000194a1c LR: c000000000194a18 CTR: c000000000a78670\n REGS: c00000004d2134e0 TRAP: 0700 Tainted: G W (6.2.0-rc2-00011-g1247637727f2)\n MSR: 9000000000021033 CR: 48002824 XER: 00000000\n CFAR: c00000000013fb64 IRQMASK: 1\n\nThe above warning triggered because the current imc-pmu code uses mutex\nlock in interrupt disabled sections. The function mutex_lock()\ninternally calls __might_resched(), which will check if IRQs are\ndisabled and in case IRQs are disabled, it will trigger the warning.\n\nFix the issue by changing the mutex lock to spinlock.\n\n[mpe: Fix comments, trim oops in change log, add reported-by tags]",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-53031"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/424bcb570cb320d1d15238cd4c933522b90f78fa"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/76d588dddc459fefa1da96e0a081a397c5c8e216"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/8cbeb60320ac45a8240b561c8ef466b86c34dedc"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/a90d339f1f66be4a946769b565668e2bd0686dfa"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/d0c6d2a31026102d4738b47a610bed4401b9834f"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:52Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-jw5w-h5c8-x699/GHSA-jw5w-h5c8-x699.json b/advisories/unreviewed/2025/03/GHSA-jw5w-h5c8-x699/GHSA-jw5w-h5c8-x699.json
new file mode 100644
index 00000000000..9c7535888b4
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-jw5w-h5c8-x699/GHSA-jw5w-h5c8-x699.json
@@ -0,0 +1,45 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-jw5w-h5c8-x699",
+ "modified": "2025-03-27T18:31:27Z",
+ "published": "2025-03-27T18:31:27Z",
+ "aliases": [
+ "CVE-2023-53000"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetlink: prevent potential spectre v1 gadgets\n\nMost netlink attributes are parsed and validated from\n__nla_validate_parse() or validate_nla()\n\n u16 type = nla_type(nla);\n\n if (type == 0 || type > maxtype) {\n /* error or continue */\n }\n\n@type is then used as an array index and can be used\nas a Spectre v1 gadget.\n\narray_index_nospec() can be used to prevent leaking\ncontent of kernel memory to malicious users.\n\nThis should take care of vast majority of netlink uses,\nbut an audit is needed to take care of others where\nvalidation is not yet centralized in core netlink functions.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-53000"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/3e5082b1c66c7783fbcd79b5b178573230e528ff"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/41b74e95f297ac360ca7ed6bf200100717cb6c45"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/539ca5dcbc91134bbe2c45677811c31d8b030d2d"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/992e4ff7116a77968039277b5d6aaa535c2f2184"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/f0950402e8c76e7dcb08563f1b4e8000fbc62455"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:48Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-jw73-x24m-whqq/GHSA-jw73-x24m-whqq.json b/advisories/unreviewed/2025/03/GHSA-jw73-x24m-whqq/GHSA-jw73-x24m-whqq.json
new file mode 100644
index 00000000000..5a2a1780ba7
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-jw73-x24m-whqq/GHSA-jw73-x24m-whqq.json
@@ -0,0 +1,37 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-jw73-x24m-whqq",
+ "modified": "2025-03-27T18:31:28Z",
+ "published": "2025-03-27T18:31:28Z",
+ "aliases": [
+ "CVE-2023-53011"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: stmmac: enable all safety features by default\n\nIn the original implementation of dwmac5\ncommit 8bf993a5877e (\"net: stmmac: Add support for DWMAC5 and implement Safety Features\")\nall safety features were enabled by default.\n\nLater it seems some implementations didn't have support for all the\nfeatures, so in\ncommit 5ac712dcdfef (\"net: stmmac: enable platform specific safety features\")\nthe safety_feat_cfg structure was added to the callback and defined for\nsome platforms to selectively enable these safety features.\n\nThe problem is that only certain platforms were given that software\nsupport. If the automotive safety package bit is set in the hardware\nfeatures register the safety feature callback is called for the platform,\nand for platforms that didn't get a safety_feat_cfg defined this results\nin the following NULL pointer dereference:\n\n[ 7.933303] Call trace:\n[ 7.935812] dwmac5_safety_feat_config+0x20/0x170 [stmmac]\n[ 7.941455] __stmmac_open+0x16c/0x474 [stmmac]\n[ 7.946117] stmmac_open+0x38/0x70 [stmmac]\n[ 7.950414] __dev_open+0x100/0x1dc\n[ 7.954006] __dev_change_flags+0x18c/0x204\n[ 7.958297] dev_change_flags+0x24/0x6c\n[ 7.962237] do_setlink+0x2b8/0xfa4\n[ 7.965827] __rtnl_newlink+0x4ec/0x840\n[ 7.969766] rtnl_newlink+0x50/0x80\n[ 7.973353] rtnetlink_rcv_msg+0x12c/0x374\n[ 7.977557] netlink_rcv_skb+0x5c/0x130\n[ 7.981500] rtnetlink_rcv+0x18/0x2c\n[ 7.985172] netlink_unicast+0x2e8/0x340\n[ 7.989197] netlink_sendmsg+0x1a8/0x420\n[ 7.993222] ____sys_sendmsg+0x218/0x280\n[ 7.997249] ___sys_sendmsg+0xac/0x100\n[ 8.001103] __sys_sendmsg+0x84/0xe0\n[ 8.004776] __arm64_sys_sendmsg+0x24/0x30\n[ 8.008983] invoke_syscall+0x48/0x114\n[ 8.012840] el0_svc_common.constprop.0+0xcc/0xec\n[ 8.017665] do_el0_svc+0x38/0xb0\n[ 8.021071] el0_svc+0x2c/0x84\n[ 8.024212] el0t_64_sync_handler+0xf4/0x120\n[ 8.028598] el0t_64_sync+0x190/0x194\n\nGo back to the original behavior, if the automotive safety package\nis found to be supported in hardware enable all the features unless\nsafety_feat_cfg is passed in saying this particular platform only\nsupports a subset of the features.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-53011"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/120b8e527e07c65de7f2b9018dcd9d17e66f2427"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/aebf7e62708ba706ee7bf484c9023b15c214e92a"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/fdfc76a116b5e9d3e98e6c96fe83b42d011d21d4"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:50Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-jwgp-qffh-vpgp/GHSA-jwgp-qffh-vpgp.json b/advisories/unreviewed/2025/03/GHSA-jwgp-qffh-vpgp/GHSA-jwgp-qffh-vpgp.json
new file mode 100644
index 00000000000..a330fcecccc
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-jwgp-qffh-vpgp/GHSA-jwgp-qffh-vpgp.json
@@ -0,0 +1,33 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-jwgp-qffh-vpgp",
+ "modified": "2025-03-27T18:31:25Z",
+ "published": "2025-03-27T18:31:25Z",
+ "aliases": [
+ "CVE-2022-49760"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/hugetlb: fix PTE marker handling in hugetlb_change_protection()\n\nPatch series \"mm/hugetlb: uffd-wp fixes for hugetlb_change_protection()\".\n\nPlaying with virtio-mem and background snapshots (using uffd-wp) on\nhugetlb in QEMU, I managed to trigger a VM_BUG_ON(). Looking into the\ndetails, hugetlb_change_protection() seems to not handle uffd-wp correctly\nin all cases.\n\nPatch #1 fixes my test case. I don't have reproducers for patch #2, as it\nrequires running into migration entries.\n\nI did not yet check in detail yet if !hugetlb code requires similar care.\n\n\nThis patch (of 2):\n\nThere are two problematic cases when stumbling over a PTE marker in\nhugetlb_change_protection():\n\n(1) We protect an uffd-wp PTE marker a second time using uffd-wp: we will\n end up in the \"!huge_pte_none(pte)\" case and mess up the PTE marker.\n\n(2) We unprotect a uffd-wp PTE marker: we will similarly end up in the\n \"!huge_pte_none(pte)\" case even though we cleared the PTE, because\n the \"pte\" variable is stale. We'll mess up the PTE marker.\n\nFor example, if we later stumble over such a \"wrongly modified\" PTE marker,\nwe'll treat it like a present PTE that maps some garbage page.\n\nThis can, for example, be triggered by mapping a memfd backed by huge\npages, registering uffd-wp, uffd-wp'ing an unmapped page and (a)\nuffd-wp'ing it a second time; or (b) uffd-unprotecting it; or (c)\nunregistering uffd-wp. Then, ff we trigger fallocate(FALLOC_FL_PUNCH_HOLE)\non that file range, we will run into a VM_BUG_ON:\n\n[ 195.039560] page:00000000ba1f2987 refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x0\n[ 195.039565] flags: 0x7ffffc0001000(reserved|node=0|zone=0|lastcpupid=0x1fffff)\n[ 195.039568] raw: 0007ffffc0001000 ffffe742c0000008 ffffe742c0000008 0000000000000000\n[ 195.039569] raw: 0000000000000000 0000000000000000 00000001ffffffff 0000000000000000\n[ 195.039569] page dumped because: VM_BUG_ON_PAGE(compound && !PageHead(page))\n[ 195.039573] ------------[ cut here ]------------\n[ 195.039574] kernel BUG at mm/rmap.c:1346!\n[ 195.039579] invalid opcode: 0000 [#1] PREEMPT SMP NOPTI\n[ 195.039581] CPU: 7 PID: 4777 Comm: qemu-system-x86 Not tainted 6.0.12-200.fc36.x86_64 #1\n[ 195.039583] Hardware name: LENOVO 20WNS1F81N/20WNS1F81N, BIOS N35ET50W (1.50 ) 09/15/2022\n[ 195.039584] RIP: 0010:page_remove_rmap+0x45b/0x550\n[ 195.039588] Code: [...]\n[ 195.039589] RSP: 0018:ffffbc03c3633ba8 EFLAGS: 00010292\n[ 195.039591] RAX: 0000000000000040 RBX: ffffe742c0000000 RCX: 0000000000000000\n[ 195.039592] RDX: 0000000000000002 RSI: ffffffff8e7aac1a RDI: 00000000ffffffff\n[ 195.039592] RBP: 0000000000000001 R08: 0000000000000000 R09: ffffbc03c3633a08\n[ 195.039593] R10: 0000000000000003 R11: ffffffff8f146328 R12: ffff9b04c42754b0\n[ 195.039594] R13: ffffffff8fcc6328 R14: ffffbc03c3633c80 R15: ffff9b0484ab9100\n[ 195.039595] FS: 00007fc7aaf68640(0000) GS:ffff9b0bbf7c0000(0000) knlGS:0000000000000000\n[ 195.039596] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 195.039597] CR2: 000055d402c49110 CR3: 0000000159392003 CR4: 0000000000772ee0\n[ 195.039598] PKRU: 55555554\n[ 195.039599] Call Trace:\n[ 195.039600] \n[ 195.039602] __unmap_hugepage_range+0x33b/0x7d0\n[ 195.039605] unmap_hugepage_range+0x55/0x70\n[ 195.039608] hugetlb_vmdelete_list+0x77/0xa0\n[ 195.039611] hugetlbfs_fallocate+0x410/0x550\n[ 195.039612] ? _raw_spin_unlock_irqrestore+0x23/0x40\n[ 195.039616] vfs_fallocate+0x12e/0x360\n[ 195.039618] __x64_sys_fallocate+0x40/0x70\n[ 195.039620] do_syscall_64+0x58/0x80\n[ 195.039623] ? syscall_exit_to_user_mode+0x17/0x40\n[ 195.039624] ? do_syscall_64+0x67/0x80\n[ 195.039626] entry_SYSCALL_64_after_hwframe+0x63/0xcd\n[ 195.039628] RIP: 0033:0x7fc7b590651f\n[ 195.039653] Code: [...]\n[ 195.039654] RSP: 002b:00007fc7aaf66e70 EFLAGS: 00000293 ORIG_RAX: 000000000000011d\n[ 195.039655] RAX: ffffffffffffffda RBX: 0000558ef4b7f370 RCX: 00007fc7b590651f\n---truncated---",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49760"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/0e678153f5be7e6c8d28835f5a678618da4b7a9c"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/6062c992e912df1eedad52cf64efb3d48e8d35c5"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:41Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-m43r-r9j3-6gfp/GHSA-m43r-r9j3-6gfp.json b/advisories/unreviewed/2025/03/GHSA-m43r-r9j3-6gfp/GHSA-m43r-r9j3-6gfp.json
new file mode 100644
index 00000000000..441f44c269e
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-m43r-r9j3-6gfp/GHSA-m43r-r9j3-6gfp.json
@@ -0,0 +1,45 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-m43r-r9j3-6gfp",
+ "modified": "2025-03-27T18:31:26Z",
+ "published": "2025-03-27T18:31:26Z",
+ "aliases": [
+ "CVE-2023-52992"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Skip task with pid=1 in send_signal_common()\n\nThe following kernel panic can be triggered when a task with pid=1 attaches\na prog that attempts to send killing signal to itself, also see [1] for more\ndetails:\n\n Kernel panic - not syncing: Attempted to kill init! exitcode=0x0000000b\n CPU: 3 PID: 1 Comm: systemd Not tainted 6.1.0-09652-g59fe41b5255f #148\n Call Trace:\n \n __dump_stack lib/dump_stack.c:88 [inline]\n dump_stack_lvl+0x100/0x178 lib/dump_stack.c:106\n panic+0x2c4/0x60f kernel/panic.c:275\n do_exit.cold+0x63/0xe4 kernel/exit.c:789\n do_group_exit+0xd4/0x2a0 kernel/exit.c:950\n get_signal+0x2460/0x2600 kernel/signal.c:2858\n arch_do_signal_or_restart+0x78/0x5d0 arch/x86/kernel/signal.c:306\n exit_to_user_mode_loop kernel/entry/common.c:168 [inline]\n exit_to_user_mode_prepare+0x15f/0x250 kernel/entry/common.c:203\n __syscall_exit_to_user_mode_work kernel/entry/common.c:285 [inline]\n syscall_exit_to_user_mode+0x1d/0x50 kernel/entry/common.c:296\n do_syscall_64+0x44/0xb0 arch/x86/entry/common.c:86\n entry_SYSCALL_64_after_hwframe+0x63/0xcd\n\nSo skip task with pid=1 in bpf_send_signal_common() to avoid the panic.\n\n [1] https://lore.kernel.org/bpf/20221222043507.33037-1-sunhao.th@gmail.com",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52992"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/0dfef503133565fa0bcf3268d8eeb5b181191a65"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/1283a01b6e19d05f7ed49584ea653947245cd41e"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/4923160393b06a34759a11b17930d71e06f396f2"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/a1c0263f1eb4deee132e11e52ee6982435460d81"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/a3d81bc1eaef48e34dd0b9b48eefed9e02a06451"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:46Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-m76m-37m5-h9wj/GHSA-m76m-37m5-h9wj.json b/advisories/unreviewed/2025/03/GHSA-m76m-37m5-h9wj/GHSA-m76m-37m5-h9wj.json
new file mode 100644
index 00000000000..c4df1683d86
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-m76m-37m5-h9wj/GHSA-m76m-37m5-h9wj.json
@@ -0,0 +1,45 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-m76m-37m5-h9wj",
+ "modified": "2025-03-27T18:31:24Z",
+ "published": "2025-03-27T18:31:23Z",
+ "aliases": [
+ "CVE-2022-49740"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: brcmfmac: Check the count value of channel spec to prevent out-of-bounds reads\n\nThis patch fixes slab-out-of-bounds reads in brcmfmac that occur in\nbrcmf_construct_chaninfo() and brcmf_enable_bw40_2g() when the count\nvalue of channel specifications provided by the device is greater than\nthe length of 'list->element[]', decided by the size of the 'list'\nallocated with kzalloc(). The patch adds checks that make the functions\nfree the buffer and return -EINVAL if that is the case. Note that the\nnegative return is handled by the caller, brcmf_setup_wiphybands() or\nbrcmf_cfg80211_attach().\n\nFound by a modified version of syzkaller.\n\nCrash Report from brcmf_construct_chaninfo():\n==================================================================\nBUG: KASAN: slab-out-of-bounds in brcmf_setup_wiphybands+0x1238/0x1430\nRead of size 4 at addr ffff888115f24600 by task kworker/0:2/1896\n\nCPU: 0 PID: 1896 Comm: kworker/0:2 Tainted: G W O 5.14.0+ #132\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.12.1-0-ga5cab58e9a3f-prebuilt.qemu.org 04/01/2014\nWorkqueue: usb_hub_wq hub_event\nCall Trace:\n dump_stack_lvl+0x57/0x7d\n print_address_description.constprop.0.cold+0x93/0x334\n kasan_report.cold+0x83/0xdf\n brcmf_setup_wiphybands+0x1238/0x1430\n brcmf_cfg80211_attach+0x2118/0x3fd0\n brcmf_attach+0x389/0xd40\n brcmf_usb_probe+0x12de/0x1690\n usb_probe_interface+0x25f/0x710\n really_probe+0x1be/0xa90\n __driver_probe_device+0x2ab/0x460\n driver_probe_device+0x49/0x120\n __device_attach_driver+0x18a/0x250\n bus_for_each_drv+0x123/0x1a0\n __device_attach+0x207/0x330\n bus_probe_device+0x1a2/0x260\n device_add+0xa61/0x1ce0\n usb_set_configuration+0x984/0x1770\n usb_generic_driver_probe+0x69/0x90\n usb_probe_device+0x9c/0x220\n really_probe+0x1be/0xa90\n __driver_probe_device+0x2ab/0x460\n driver_probe_device+0x49/0x120\n __device_attach_driver+0x18a/0x250\n bus_for_each_drv+0x123/0x1a0\n __device_attach+0x207/0x330\n bus_probe_device+0x1a2/0x260\n device_add+0xa61/0x1ce0\n usb_new_device.cold+0x463/0xf66\n hub_event+0x10d5/0x3330\n process_one_work+0x873/0x13e0\n worker_thread+0x8b/0xd10\n kthread+0x379/0x450\n ret_from_fork+0x1f/0x30\n\nAllocated by task 1896:\n kasan_save_stack+0x1b/0x40\n __kasan_kmalloc+0x7c/0x90\n kmem_cache_alloc_trace+0x19e/0x330\n brcmf_setup_wiphybands+0x290/0x1430\n brcmf_cfg80211_attach+0x2118/0x3fd0\n brcmf_attach+0x389/0xd40\n brcmf_usb_probe+0x12de/0x1690\n usb_probe_interface+0x25f/0x710\n really_probe+0x1be/0xa90\n __driver_probe_device+0x2ab/0x460\n driver_probe_device+0x49/0x120\n __device_attach_driver+0x18a/0x250\n bus_for_each_drv+0x123/0x1a0\n __device_attach+0x207/0x330\n bus_probe_device+0x1a2/0x260\n device_add+0xa61/0x1ce0\n usb_set_configuration+0x984/0x1770\n usb_generic_driver_probe+0x69/0x90\n usb_probe_device+0x9c/0x220\n really_probe+0x1be/0xa90\n __driver_probe_device+0x2ab/0x460\n driver_probe_device+0x49/0x120\n __device_attach_driver+0x18a/0x250\n bus_for_each_drv+0x123/0x1a0\n __device_attach+0x207/0x330\n bus_probe_device+0x1a2/0x260\n device_add+0xa61/0x1ce0\n usb_new_device.cold+0x463/0xf66\n hub_event+0x10d5/0x3330\n process_one_work+0x873/0x13e0\n worker_thread+0x8b/0xd10\n kthread+0x379/0x450\n ret_from_fork+0x1f/0x30\n\nThe buggy address belongs to the object at ffff888115f24000\n which belongs to the cache kmalloc-2k of size 2048\nThe buggy address is located 1536 bytes inside of\n 2048-byte region [ffff888115f24000, ffff888115f24800)\n\nMemory state around the buggy address:\n ffff888115f24500: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\n ffff888115f24580: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\n>ffff888115f24600: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc\n ^\n ffff888115f24680: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc\n ffff888115f24700: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc\n==================================================================\n\nCrash Report from brcmf_enable_bw40_2g():\n==========\n---truncated---",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49740"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/4920ab131b2dbae7464b72bdcac465d070254209"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/9cf5e99c1ae1a85286a76c9a970202750538394c"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/b2e412879595821ff1b5545cbed5f108fba7f5b6"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/e4991910f15013db72f6ec0db7038ea67a57052e"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/f06de1bb6d61f0c18b0213bbc6298960037f9d42"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:38Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-mh69-q9mq-74wg/GHSA-mh69-q9mq-74wg.json b/advisories/unreviewed/2025/03/GHSA-mh69-q9mq-74wg/GHSA-mh69-q9mq-74wg.json
new file mode 100644
index 00000000000..9780cd55da7
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-mh69-q9mq-74wg/GHSA-mh69-q9mq-74wg.json
@@ -0,0 +1,33 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-mh69-q9mq-74wg",
+ "modified": "2025-03-27T18:31:26Z",
+ "published": "2025-03-27T18:31:25Z",
+ "aliases": [
+ "CVE-2023-52941"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: isotp: split tx timer into transmission and timeout\n\nThe timer for the transmission of isotp PDUs formerly had two functions:\n1. send two consecutive frames with a given time gap\n2. monitor the timeouts for flow control frames and the echo frames\n\nThis led to larger txstate checks and potentially to a problem discovered\nby syzbot which enabled the panic_on_warn feature while testing.\n\nThe former 'txtimer' function is split into 'txfrtimer' and 'txtimer'\nto handle the two above functionalities with separate timer callbacks.\n\nThe two simplified timers now run in one-shot mode and make the state\ntransitions (especially with isotp_rcv_echo) better understandable.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52941"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/4f027cba8216f42a18b544842efab134f8b1f9f4"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/cae4c9bc35f72af5d4a079bb9d9fd62c4088a411"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:44Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-mp89-pxjh-mww8/GHSA-mp89-pxjh-mww8.json b/advisories/unreviewed/2025/03/GHSA-mp89-pxjh-mww8/GHSA-mp89-pxjh-mww8.json
new file mode 100644
index 00000000000..2cc84caeeb4
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-mp89-pxjh-mww8/GHSA-mp89-pxjh-mww8.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-mp89-pxjh-mww8",
+ "modified": "2025-03-27T18:31:23Z",
+ "published": "2025-03-27T18:31:23Z",
+ "aliases": [
+ "CVE-2025-26762"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WooCommerce allows Stored XSS.This issue affects WooCommerce: from n/a through 9.7.0.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26762"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/woocommerce/vulnerability/wordpress-woocommerce-plugin-9-7-0-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T16:15:30Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-mq3c-v59w-hjf6/GHSA-mq3c-v59w-hjf6.json b/advisories/unreviewed/2025/03/GHSA-mq3c-v59w-hjf6/GHSA-mq3c-v59w-hjf6.json
new file mode 100644
index 00000000000..8943798618b
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-mq3c-v59w-hjf6/GHSA-mq3c-v59w-hjf6.json
@@ -0,0 +1,33 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-mq3c-v59w-hjf6",
+ "modified": "2025-03-27T18:31:27Z",
+ "published": "2025-03-27T18:31:27Z",
+ "aliases": [
+ "CVE-2023-53001"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/drm_vma_manager: Add drm_vma_node_allow_once()\n\nCurrently there is no easy way for a drm driver to safely check and allow\ndrm_vma_offset_node for a drm file just once. Allow drm drivers to call\nnon-refcounted version of drm_vma_node_allow() so that a driver doesn't\nneed to keep track of each drm_vma_node_allow() to call subsequent\ndrm_vma_node_revoke() to prevent memory leak.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-53001"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/67444f8ca31cdaf45e0b761241ad49b1ae04bcf9"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/899d3a3c19ac0e5da013ce34833dccb97d19b5e4"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:48Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-mqh3-5x68-9v64/GHSA-mqh3-5x68-9v64.json b/advisories/unreviewed/2025/03/GHSA-mqh3-5x68-9v64/GHSA-mqh3-5x68-9v64.json
new file mode 100644
index 00000000000..9e1a334e07e
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-mqh3-5x68-9v64/GHSA-mqh3-5x68-9v64.json
@@ -0,0 +1,49 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-mqh3-5x68-9v64",
+ "modified": "2025-03-27T18:31:28Z",
+ "published": "2025-03-27T18:31:28Z",
+ "aliases": [
+ "CVE-2023-53024"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix pointer-leak due to insufficient speculative store bypass mitigation\n\nTo mitigate Spectre v4, 2039f26f3aca (\"bpf: Fix leakage due to\ninsufficient speculative store bypass mitigation\") inserts lfence\ninstructions after 1) initializing a stack slot and 2) spilling a\npointer to the stack.\n\nHowever, this does not cover cases where a stack slot is first\ninitialized with a pointer (subject to sanitization) but then\noverwritten with a scalar (not subject to sanitization because\nthe slot was already initialized). In this case, the second write\nmay be subject to speculative store bypass (SSB) creating a\nspeculative pointer-as-scalar type confusion. This allows the\nprogram to subsequently leak the numerical pointer value using,\nfor example, a branch-based cache side channel.\n\nTo fix this, also sanitize scalars if they write a stack slot\nthat previously contained a pointer. Assuming that pointer-spills\nare only generated by LLVM on register-pressure, the performance\nimpact on most real-world BPF programs should be small.\n\nThe following unprivileged BPF bytecode drafts a minimal exploit\nand the mitigation:\n\n [...]\n // r6 = 0 or 1 (skalar, unknown user input)\n // r7 = accessible ptr for side channel\n // r10 = frame pointer (fp), to be leaked\n //\n r9 = r10 # fp alias to encourage ssb\n *(u64 *)(r9 - 8) = r10 // fp[-8] = ptr, to be leaked\n // lfence added here because of pointer spill to stack.\n //\n // Ommitted: Dummy bpf_ringbuf_output() here to train alias predictor\n // for no r9-r10 dependency.\n //\n *(u64 *)(r10 - 8) = r6 // fp[-8] = scalar, overwrites ptr\n // 2039f26f3aca: no lfence added because stack slot was not STACK_INVALID,\n // store may be subject to SSB\n //\n // fix: also add an lfence when the slot contained a ptr\n //\n r8 = *(u64 *)(r9 - 8)\n // r8 = architecturally a scalar, speculatively a ptr\n //\n // leak ptr using branch-based cache side channel:\n r8 &= 1 // choose bit to leak\n if r8 == 0 goto SLOW // no mispredict\n // architecturally dead code if input r6 is 0,\n // only executes speculatively iff ptr bit is 1\n r8 = *(u64 *)(r7 + 0) # encode bit in cache (0: slow, 1: fast)\nSLOW:\n [...]\n\nAfter running this, the program can time the access to *(r7 + 0) to\ndetermine whether the chosen pointer bit was 0 or 1. Repeat this 64\ntimes to recover the whole address on amd64.\n\nIn summary, sanitization can only be skipped if one scalar is\noverwritten with another scalar. Scalar-confusion due to speculative\nstore bypass can not lead to invalid accesses because the pointer\nbounds deducted during verification are enforced using branchless\nlogic. See 979d63d50c0c (\"bpf: prevent out of bounds speculation on\npointer arithmetic\") for details.\n\nDo not make the mitigation depend on !env->allow_{uninit_stack,ptr_leaks}\nbecause speculative leaks are likely unexpected if these were enabled.\nFor example, leaking the address to a protected log file may be acceptable\nwhile disabling the mitigation might unintentionally leak the address\ninto the cached-state of a map that is accessible to unprivileged\nprocesses.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-53024"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/01bdcc73dbe7be3ad4d4ee9a59b71e42f461a528"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/81b3374944d201872cfcf82730a7860f8e7c31dd"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/aae109414a57ab4164218f36e2e4a17f027fcaaa"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/b0c89ef025562161242a7c19b213bd6b272e93df"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/da75dec7c6617bddad418159ffebcb133f008262"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/e4f4db47794c9f474b184ee1418f42e6a07412b6"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:51Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-mvjr-2pvh-8wqh/GHSA-mvjr-2pvh-8wqh.json b/advisories/unreviewed/2025/03/GHSA-mvjr-2pvh-8wqh/GHSA-mvjr-2pvh-8wqh.json
new file mode 100644
index 00000000000..830fc117537
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-mvjr-2pvh-8wqh/GHSA-mvjr-2pvh-8wqh.json
@@ -0,0 +1,37 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-mvjr-2pvh-8wqh",
+ "modified": "2025-03-27T18:31:23Z",
+ "published": "2025-03-27T18:31:23Z",
+ "aliases": [
+ "CVE-2025-26265"
+ ],
+ "details": "A segmentation fault in openairinterface5g v2.1.0 allows attackers to cause a Denial of Service (DoS) via a crafted UE Context Modification response.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26265"
+ },
+ {
+ "type": "WEB",
+ "url": "https://anonymous.4open.science/r/Mobicom-ARCANE-36B7/README.md"
+ },
+ {
+ "type": "WEB",
+ "url": "https://gitlab.eurecom.fr/oai/openairinterface5g"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.sigmobile.org/mobicom/2025"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T16:15:30Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-p2cv-98qj-r2qc/GHSA-p2cv-98qj-r2qc.json b/advisories/unreviewed/2025/03/GHSA-p2cv-98qj-r2qc/GHSA-p2cv-98qj-r2qc.json
new file mode 100644
index 00000000000..dc47ee15077
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-p2cv-98qj-r2qc/GHSA-p2cv-98qj-r2qc.json
@@ -0,0 +1,33 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-p2cv-98qj-r2qc",
+ "modified": "2025-03-27T18:31:24Z",
+ "published": "2025-03-27T18:31:24Z",
+ "aliases": [
+ "CVE-2022-49754"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: Fix a buffer overflow in mgmt_mesh_add()\n\nSmatch Warning:\nnet/bluetooth/mgmt_util.c:375 mgmt_mesh_add() error: __memcpy()\n'mesh_tx->param' too small (48 vs 50)\n\nAnalysis:\n\n'mesh_tx->param' is array of size 48. This is the destination.\nu8 param[sizeof(struct mgmt_cp_mesh_send) + 29]; // 19 + 29 = 48.\n\nBut in the caller 'mesh_send' we reject only when len > 50.\nlen > (MGMT_MESH_SEND_SIZE + 31) // 19 + 31 = 50.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49754"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/2185e0fdbb2137f22a9dd9fcbf6481400d56299b"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/ed818fd8c531abf561b379995ee7cc4c68029464"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:40Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-p579-25jc-wxr5/GHSA-p579-25jc-wxr5.json b/advisories/unreviewed/2025/03/GHSA-p579-25jc-wxr5/GHSA-p579-25jc-wxr5.json
new file mode 100644
index 00000000000..2d34ab86227
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-p579-25jc-wxr5/GHSA-p579-25jc-wxr5.json
@@ -0,0 +1,33 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-p579-25jc-wxr5",
+ "modified": "2025-03-27T18:31:25Z",
+ "published": "2025-03-27T18:31:25Z",
+ "aliases": [
+ "CVE-2023-52939"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm: memcg: fix NULL pointer in mem_cgroup_track_foreign_dirty_slowpath()\n\nAs commit 18365225f044 (\"hwpoison, memcg: forcibly uncharge LRU pages\"),\nhwpoison will forcibly uncharg a LRU hwpoisoned page, the folio_memcg\ncould be NULl, then, mem_cgroup_track_foreign_dirty_slowpath() could\noccurs a NULL pointer dereference, let's do not record the foreign\nwritebacks for folio memcg is null in mem_cgroup_track_foreign_dirty() to\nfix it.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52939"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/ac86f547ca1002aec2ef66b9e64d03f45bbbfbb9"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/b79ba5953f6fdc5559389ad415620bffc24f024b"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:43Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-p7rv-2f34-8mwf/GHSA-p7rv-2f34-8mwf.json b/advisories/unreviewed/2025/03/GHSA-p7rv-2f34-8mwf/GHSA-p7rv-2f34-8mwf.json
new file mode 100644
index 00000000000..a74a324ad52
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-p7rv-2f34-8mwf/GHSA-p7rv-2f34-8mwf.json
@@ -0,0 +1,60 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-p7rv-2f34-8mwf",
+ "modified": "2025-03-27T18:31:28Z",
+ "published": "2025-03-27T18:31:28Z",
+ "aliases": [
+ "CVE-2023-53023"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: nfc: Fix use-after-free in local_cleanup()\n\nFix a use-after-free that occurs in kfree_skb() called from\nlocal_cleanup(). This could happen when killing nfc daemon (e.g. neard)\nafter detaching an nfc device.\nWhen detaching an nfc device, local_cleanup() called from\nnfc_llcp_unregister_device() frees local->rx_pending and decreases\nlocal->ref by kref_put() in nfc_llcp_local_put().\nIn the terminating process, nfc daemon releases all sockets and it leads\nto decreasing local->ref. After the last release of local->ref,\nlocal_cleanup() called from local_release() frees local->rx_pending\nagain, which leads to the bug.\n\nSetting local->rx_pending to NULL in local_cleanup() could prevent\nuse-after-free when local_cleanup() is called twice.\n\nFound by a modified version of syzkaller.\n\nBUG: KASAN: use-after-free in kfree_skb()\n\nCall Trace:\ndump_stack_lvl (lib/dump_stack.c:106)\nprint_address_description.constprop.0.cold (mm/kasan/report.c:306)\nkasan_check_range (mm/kasan/generic.c:189)\nkfree_skb (net/core/skbuff.c:955)\nlocal_cleanup (net/nfc/llcp_core.c:159)\nnfc_llcp_local_put.part.0 (net/nfc/llcp_core.c:172)\nnfc_llcp_local_put (net/nfc/llcp_core.c:181)\nllcp_sock_destruct (net/nfc/llcp_sock.c:959)\n__sk_destruct (net/core/sock.c:2133)\nsk_destruct (net/core/sock.c:2181)\n__sk_free (net/core/sock.c:2192)\nsk_free (net/core/sock.c:2203)\nllcp_sock_release (net/nfc/llcp_sock.c:646)\n__sock_release (net/socket.c:650)\nsock_close (net/socket.c:1365)\n__fput (fs/file_table.c:306)\ntask_work_run (kernel/task_work.c:179)\nptrace_notify (kernel/signal.c:2354)\nsyscall_exit_to_user_mode_prepare (kernel/entry/common.c:278)\nsyscall_exit_to_user_mode (kernel/entry/common.c:296)\ndo_syscall_64 (arch/x86/entry/common.c:86)\nentry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:106)\n\nAllocated by task 4719:\nkasan_save_stack (mm/kasan/common.c:45)\n__kasan_slab_alloc (mm/kasan/common.c:325)\nslab_post_alloc_hook (mm/slab.h:766)\nkmem_cache_alloc_node (mm/slub.c:3497)\n__alloc_skb (net/core/skbuff.c:552)\npn533_recv_response (drivers/nfc/pn533/usb.c:65)\n__usb_hcd_giveback_urb (drivers/usb/core/hcd.c:1671)\nusb_giveback_urb_bh (drivers/usb/core/hcd.c:1704)\ntasklet_action_common.isra.0 (kernel/softirq.c:797)\n__do_softirq (kernel/softirq.c:571)\n\nFreed by task 1901:\nkasan_save_stack (mm/kasan/common.c:45)\nkasan_set_track (mm/kasan/common.c:52)\nkasan_save_free_info (mm/kasan/genericdd.c:518)\n__kasan_slab_free (mm/kasan/common.c:236)\nkmem_cache_free (mm/slub.c:3809)\nkfree_skbmem (net/core/skbuff.c:874)\nkfree_skb (net/core/skbuff.c:931)\nlocal_cleanup (net/nfc/llcp_core.c:159)\nnfc_llcp_unregister_device (net/nfc/llcp_core.c:1617)\nnfc_unregister_device (net/nfc/core.c:1179)\npn53x_unregister_nfc (drivers/nfc/pn533/pn533.c:2846)\npn533_usb_disconnect (drivers/nfc/pn533/usb.c:579)\nusb_unbind_interface (drivers/usb/core/driver.c:458)\ndevice_release_driver_internal (drivers/base/dd.c:1279)\nbus_remove_device (drivers/base/bus.c:529)\ndevice_del (drivers/base/core.c:3665)\nusb_disable_device (drivers/usb/core/message.c:1420)\nusb_disconnect (drivers/usb/core.c:2261)\nhub_event (drivers/usb/core/hub.c:5833)\nprocess_one_work (arch/x86/include/asm/jump_label.h:27 include/linux/jump_label.h:212 include/trace/events/workqueue.h:108 kernel/workqueue.c:2281)\nworker_thread (include/linux/list.h:282 kernel/workqueue.c:2423)\nkthread (kernel/kthread.c:319)\nret_from_fork (arch/x86/entry/entry_64.S:301)",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-53023"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/4bb4db7f3187c6e3de6b229ffc87cdb30a2d22b6"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/54f7be61584b8ec4c6df405f479495b9397bae4a"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/7f129927feaf7c10b1c38bbce630172e9a08c834"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/a59cdbda3714e11aa3ab579132864c4c8c6d54f9"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/ad1baab3a5c03692d22ce446f38596a126377f6a"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/b09ae26f08aaf2d85f96ea7f90ddd3387f62216f"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/d3605282ec3502ec8847915eb2cf1f340493ff79"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:51Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-pjg2-rfg9-hrh3/GHSA-pjg2-rfg9-hrh3.json b/advisories/unreviewed/2025/03/GHSA-pjg2-rfg9-hrh3/GHSA-pjg2-rfg9-hrh3.json
new file mode 100644
index 00000000000..807f39fc216
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-pjg2-rfg9-hrh3/GHSA-pjg2-rfg9-hrh3.json
@@ -0,0 +1,49 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-pjg2-rfg9-hrh3",
+ "modified": "2025-03-27T18:31:27Z",
+ "published": "2025-03-27T18:31:27Z",
+ "aliases": [
+ "CVE-2023-53006"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncifs: Fix oops due to uncleared server->smbd_conn in reconnect\n\nIn smbd_destroy(), clear the server->smbd_conn pointer after freeing the\nsmbd_connection struct that it points to so that reconnection doesn't get\nconfused.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-53006"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/4b83bc6f87eedab4599b0123e572a422689444be"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/5109607a4ece7cd8536172bf7549eb4dce1f3576"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/91be54849d5392050f5b847b42bd5e6221551ac8"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/a9640c0b268405f2540e8203a545e930ea88bb7d"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/b7ab9161cf5ddc42a288edf9d1a61f3bdffe17c7"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/e037baee16e0b9ace7e730888fcae9cec11daff2"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:49Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-pq67-2wwv-3xjx/GHSA-pq67-2wwv-3xjx.json b/advisories/unreviewed/2025/03/GHSA-pq67-2wwv-3xjx/GHSA-pq67-2wwv-3xjx.json
new file mode 100644
index 00000000000..55d3571665b
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-pq67-2wwv-3xjx/GHSA-pq67-2wwv-3xjx.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-pq67-2wwv-3xjx",
+ "modified": "2025-03-27T18:31:28Z",
+ "published": "2025-03-27T18:31:28Z",
+ "aliases": [
+ "CVE-2024-12905"
+ ],
+ "details": "An Improper Link Resolution Before File Access (\"Link Following\") and Improper Limitation of a Pathname to a Restricted Directory (\"Path Traversal\"). This vulnerability occurs when extracting a maliciously crafted tar file, which can result in unauthorized file writes or overwrites outside the intended extraction directory. The issue is associated with index.js in the tar-fs package.\n\nThis issue affects tar-fs: from 0.0.0 before 1.16.4, from 2.0.0 before 2.1.2, from 3.0.0 before 3.0.8.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12905"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/mafintosh/tar-fs/commit/a1dd7e7c7f4b4a8bd2ab60f513baca573b44e2ed"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-22"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:53Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-pqmw-jx87-8vxx/GHSA-pqmw-jx87-8vxx.json b/advisories/unreviewed/2025/03/GHSA-pqmw-jx87-8vxx/GHSA-pqmw-jx87-8vxx.json
new file mode 100644
index 00000000000..ef1785ae349
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-pqmw-jx87-8vxx/GHSA-pqmw-jx87-8vxx.json
@@ -0,0 +1,37 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-pqmw-jx87-8vxx",
+ "modified": "2025-03-27T18:31:28Z",
+ "published": "2025-03-27T18:31:28Z",
+ "aliases": [
+ "CVE-2023-53012"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nthermal: core: call put_device() only after device_register() fails\n\nput_device() shouldn't be called before a prior call to\ndevice_register(). __thermal_cooling_device_register() doesn't follow\nthat properly and needs fixing. Also\nthermal_cooling_device_destroy_sysfs() is getting called unnecessarily\non few error paths.\n\nFix all this by placing the calls at the right place.\n\nBased on initial work done by Caleb Connolly.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-53012"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/2846a7412f6246fd5171f51011bf76dfebcec0ee"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/6c54b7bc8a31ce0f7cc7f8deef05067df414f1d8"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/a7d736cc3c6cb0d7498bbfb56515d414e35e9510"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:50Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-pwg3-m7h4-xjvm/GHSA-pwg3-m7h4-xjvm.json b/advisories/unreviewed/2025/03/GHSA-pwg3-m7h4-xjvm/GHSA-pwg3-m7h4-xjvm.json
new file mode 100644
index 00000000000..03879bcd87b
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-pwg3-m7h4-xjvm/GHSA-pwg3-m7h4-xjvm.json
@@ -0,0 +1,37 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-pwg3-m7h4-xjvm",
+ "modified": "2025-03-27T18:31:24Z",
+ "published": "2025-03-27T18:31:24Z",
+ "aliases": [
+ "CVE-2022-49758"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nreset: uniphier-glue: Fix possible null-ptr-deref\n\nIt will cause null-ptr-deref when resource_size(res) invoked,\nif platform_get_resource() returns NULL.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49758"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/3a2390c6777e3f6662980c6cfc25cafe9e4fef98"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/633bad3dc81ce2aa561f704ec091e49eb647bd0b"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/95de286200b2a046da01c4aeba02ae9220d68ca4"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:41Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-qc5x-h4r4-86f3/GHSA-qc5x-h4r4-86f3.json b/advisories/unreviewed/2025/03/GHSA-qc5x-h4r4-86f3/GHSA-qc5x-h4r4-86f3.json
new file mode 100644
index 00000000000..92692bb1970
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-qc5x-h4r4-86f3/GHSA-qc5x-h4r4-86f3.json
@@ -0,0 +1,53 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-qc5x-h4r4-86f3",
+ "modified": "2025-03-27T18:31:24Z",
+ "published": "2025-03-27T18:31:24Z",
+ "aliases": [
+ "CVE-2022-49755"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: f_fs: Prevent race during ffs_ep0_queue_wait\n\nWhile performing fast composition switch, there is a possibility that the\nprocess of ffs_ep0_write/ffs_ep0_read get into a race condition\ndue to ep0req being freed up from functionfs_unbind.\n\nConsider the scenario that the ffs_ep0_write calls the ffs_ep0_queue_wait\nby taking a lock &ffs->ev.waitq.lock. However, the functionfs_unbind isn't\nbounded so it can go ahead and mark the ep0req to NULL, and since there\nis no NULL check in ffs_ep0_queue_wait we will end up in use-after-free.\n\nFix this by making a serialized execution between the two functions using\na mutex_lock(ffs->mutex).",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49755"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/6a19da111057f69214b97c62fb0ac59023970850"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/6aee197b7fbcd61596a78b47d553f2f99111f217"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/6dd9ea05534f323668db94fcc2726c7a84547e78"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/a8d40942df074f4ebcb9bd3413596d92f323b064"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/ae8e136bcaae96163b5821984de1036efc9abb1a"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/e9036e951f93fb8d7b5e9d6e2c7f94a4da312ae4"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/facf353c9e8d7885b686d9a4b173d4e0af6441d2"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:40Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-qhg6-v8xh-pwh7/GHSA-qhg6-v8xh-pwh7.json b/advisories/unreviewed/2025/03/GHSA-qhg6-v8xh-pwh7/GHSA-qhg6-v8xh-pwh7.json
new file mode 100644
index 00000000000..2ad0eef651a
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-qhg6-v8xh-pwh7/GHSA-qhg6-v8xh-pwh7.json
@@ -0,0 +1,53 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-qhg6-v8xh-pwh7",
+ "modified": "2025-03-27T18:31:28Z",
+ "published": "2025-03-27T18:31:27Z",
+ "aliases": [
+ "CVE-2023-53007"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: Make sure trace_printk() can output as soon as it can be used\n\nCurrently trace_printk() can be used as soon as early_trace_init() is\ncalled from start_kernel(). But if a crash happens, and\n\"ftrace_dump_on_oops\" is set on the kernel command line, all you get will\nbe:\n\n [ 0.456075] -0 0dN.2. 347519us : Unknown type 6\n [ 0.456075] -0 0dN.2. 353141us : Unknown type 6\n [ 0.456075] -0 0dN.2. 358684us : Unknown type 6\n\nThis is because the trace_printk() event (type 6) hasn't been registered\nyet. That gets done via an early_initcall(), which may be early, but not\nearly enough.\n\nInstead of registering the trace_printk() event (and other ftrace events,\nwhich are not trace events) via an early_initcall(), have them registered at\nthe same time that trace_printk() can be used. This way, if there is a\ncrash before early_initcall(), then the trace_printk()s will actually be\nuseful.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-53007"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/198c83963f6335ca6d690cff067679560f2a3a22"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/3bb06eb6e9acf7c4a3e1b5bc87aed398ff8e2253"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/76b2390fdc80c0a8300e5da5b6b62d201b6fe9ce"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/b0af180514edea6c83dc9a299d9f383009c99f25"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/b94d7c7654356860dd7719120c7d15ba38b6162a"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/de3930a4883ddad2244efd6d349013294c62c75c"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/f97eb0ab066133483a65c93eb894748de2f6b598"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:49Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-qv94-9c4f-29wh/GHSA-qv94-9c4f-29wh.json b/advisories/unreviewed/2025/03/GHSA-qv94-9c4f-29wh/GHSA-qv94-9c4f-29wh.json
new file mode 100644
index 00000000000..feab90c7cab
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-qv94-9c4f-29wh/GHSA-qv94-9c4f-29wh.json
@@ -0,0 +1,53 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-qv94-9c4f-29wh",
+ "modified": "2025-03-27T18:31:26Z",
+ "published": "2025-03-27T18:31:26Z",
+ "aliases": [
+ "CVE-2023-52977"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: openvswitch: fix flow memory leak in ovs_flow_cmd_new\n\nSyzkaller reports a memory leak of new_flow in ovs_flow_cmd_new() as it is\nnot freed when an allocation of a key fails.\n\nBUG: memory leak\nunreferenced object 0xffff888116668000 (size 632):\n comm \"syz-executor231\", pid 1090, jiffies 4294844701 (age 18.871s)\n hex dump (first 32 bytes):\n 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n backtrace:\n [<00000000defa3494>] kmem_cache_zalloc include/linux/slab.h:654 [inline]\n [<00000000defa3494>] ovs_flow_alloc+0x19/0x180 net/openvswitch/flow_table.c:77\n [<00000000c67d8873>] ovs_flow_cmd_new+0x1de/0xd40 net/openvswitch/datapath.c:957\n [<0000000010a539a8>] genl_family_rcv_msg_doit+0x22d/0x330 net/netlink/genetlink.c:739\n [<00000000dff3302d>] genl_family_rcv_msg net/netlink/genetlink.c:783 [inline]\n [<00000000dff3302d>] genl_rcv_msg+0x328/0x590 net/netlink/genetlink.c:800\n [<000000000286dd87>] netlink_rcv_skb+0x153/0x430 net/netlink/af_netlink.c:2515\n [<0000000061fed410>] genl_rcv+0x24/0x40 net/netlink/genetlink.c:811\n [<000000009dc0f111>] netlink_unicast_kernel net/netlink/af_netlink.c:1313 [inline]\n [<000000009dc0f111>] netlink_unicast+0x545/0x7f0 net/netlink/af_netlink.c:1339\n [<000000004a5ee816>] netlink_sendmsg+0x8e7/0xde0 net/netlink/af_netlink.c:1934\n [<00000000482b476f>] sock_sendmsg_nosec net/socket.c:651 [inline]\n [<00000000482b476f>] sock_sendmsg+0x152/0x190 net/socket.c:671\n [<00000000698574ba>] ____sys_sendmsg+0x70a/0x870 net/socket.c:2356\n [<00000000d28d9e11>] ___sys_sendmsg+0xf3/0x170 net/socket.c:2410\n [<0000000083ba9120>] __sys_sendmsg+0xe5/0x1b0 net/socket.c:2439\n [<00000000c00628f8>] do_syscall_64+0x30/0x40 arch/x86/entry/common.c:46\n [<000000004abfdcf4>] entry_SYSCALL_64_after_hwframe+0x61/0xc6\n\nTo fix this the patch rearranges the goto labels to reflect the order of\nobject allocations and adds appropriate goto statements on the error\npaths.\n\nFound by Linux Verification Center (linuxtesting.org) with Syzkaller.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52977"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/0c598aed445eb45b0ee7ba405f7ece99ee349c30"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/1ac653cf886cdfc082708c82dc6ac6115cebd2ee"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/70154489f531587996f3e9d7cceeee65cff0001d"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/70d40674a549d498bd63d5432acf46205da1534b"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/af4e720bc00a2653f7b9df21755b9978b3d7f386"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/ed6c5e8caf55778500202775167e8ccdb1a030cb"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/f423c2efd51d7eb1d143c2be7eea233241d9bbbf"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:44Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-qxq7-jc88-2fr4/GHSA-qxq7-jc88-2fr4.json b/advisories/unreviewed/2025/03/GHSA-qxq7-jc88-2fr4/GHSA-qxq7-jc88-2fr4.json
new file mode 100644
index 00000000000..03225e6590d
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-qxq7-jc88-2fr4/GHSA-qxq7-jc88-2fr4.json
@@ -0,0 +1,37 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-qxq7-jc88-2fr4",
+ "modified": "2025-03-27T18:31:25Z",
+ "published": "2025-03-27T18:31:25Z",
+ "aliases": [
+ "CVE-2023-52928"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Skip invalid kfunc call in backtrack_insn\n\nThe verifier skips invalid kfunc call in check_kfunc_call(), which\nwould be captured in fixup_kfunc_call() if such insn is not eliminated\nby dead code elimination. However, this can lead to the following\nwarning in backtrack_insn(), also see [1]:\n\n ------------[ cut here ]------------\n verifier backtracking bug\n WARNING: CPU: 6 PID: 8646 at kernel/bpf/verifier.c:2756 backtrack_insn\n kernel/bpf/verifier.c:2756\n\t__mark_chain_precision kernel/bpf/verifier.c:3065\n\tmark_chain_precision kernel/bpf/verifier.c:3165\n\tadjust_reg_min_max_vals kernel/bpf/verifier.c:10715\n\tcheck_alu_op kernel/bpf/verifier.c:10928\n\tdo_check kernel/bpf/verifier.c:13821 [inline]\n\tdo_check_common kernel/bpf/verifier.c:16289\n [...]\n\nSo make backtracking conservative with this by returning ENOTSUPP.\n\n [1] https://lore.kernel.org/bpf/CACkBjsaXNceR8ZjkLG=dT3P=4A8SBsg0Z5h5PWLryF5=ghKq=g@mail.gmail.com/",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52928"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/6e2fac197de2c4c041bdd8982cffb104689113f1"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/74eec8266f37aff609db6a2f2b093e56a11c28c4"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/d3178e8a434b58678d99257c0387810a24042fb6"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:42Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-r3gg-v2qj-wcmp/GHSA-r3gg-v2qj-wcmp.json b/advisories/unreviewed/2025/03/GHSA-r3gg-v2qj-wcmp/GHSA-r3gg-v2qj-wcmp.json
new file mode 100644
index 00000000000..1fdc8e91929
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-r3gg-v2qj-wcmp/GHSA-r3gg-v2qj-wcmp.json
@@ -0,0 +1,53 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-r3gg-v2qj-wcmp",
+ "modified": "2025-03-27T18:31:28Z",
+ "published": "2025-03-27T18:31:28Z",
+ "aliases": [
+ "CVE-2023-53015"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: betop: check shape of output reports\n\nbetopff_init() only checks the total sum of the report counts for each\nreport field to be at least 4, but hid_betopff_play() expects 4 report\nfields.\nA device advertising an output report with one field and 4 report counts\nwould pass the check but crash the kernel with a NULL pointer dereference\nin hid_betopff_play().",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-53015"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/07bc32e53c7bd5c91472cc485231ef6274db9b76"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/1a2a47b85cab50a3c146731bfeaf2d860f5344ee"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/28fc6095da22dc88433d79578ae1c495ebe8ca43"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/3782c0d6edf658b71354a64d60aa7a296188fc90"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/7317326f685824c7c29bd80841fd18041af6bb73"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/d3065cc56221d1a5eda237e94eaf2a627b88ab79"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/dbab4dba400d6ea9a9697fbbd287adbf7db1dac4"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:50Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-r956-xq9j-f5vj/GHSA-r956-xq9j-f5vj.json b/advisories/unreviewed/2025/03/GHSA-r956-xq9j-f5vj/GHSA-r956-xq9j-f5vj.json
new file mode 100644
index 00000000000..7b3f5afbdd5
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-r956-xq9j-f5vj/GHSA-r956-xq9j-f5vj.json
@@ -0,0 +1,33 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-r956-xq9j-f5vj",
+ "modified": "2025-03-27T18:31:27Z",
+ "published": "2025-03-27T18:31:27Z",
+ "aliases": [
+ "CVE-2023-52998"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: fec: Use page_pool_put_full_page when freeing rx buffers\n\nThe page_pool_release_page was used when freeing rx buffers, and this\nfunction just unmaps the page (if mapped) and does not recycle the page.\nSo after hundreds of down/up the eth0, the system will out of memory.\nFor more details, please refer to the following reproduce steps and\nbug logs. To solve this issue and refer to the doc of page pool, the\npage_pool_put_full_page should be used to replace page_pool_release_page.\nBecause this API will try to recycle the page if the page refcnt equal to\n1. After testing 20000 times, the issue can not be reproduced anymore\n(about testing 391 times the issue will occur on i.MX8MN-EVK before).\n\nReproduce steps:\nCreate the test script and run the script. The script content is as\nfollows:\nLOOPS=20000\ni=1\nwhile [ $i -le $LOOPS ]\ndo\n echo \"TINFO:ENET $curface up and down test $i times\"\n org_macaddr=$(cat /sys/class/net/eth0/address)\n ifconfig eth0 down\n ifconfig eth0 hw ether $org_macaddr up\n i=$(expr $i + 1)\ndone\nsleep 5\nif cat /sys/class/net/eth0/operstate | grep 'up';then\n echo \"TEST PASS\"\nelse\n echo \"TEST FAIL\"\nfi\n\nBug detail logs:\nTINFO:ENET up and down test 391 times\n[ 850.471205] Qualcomm Atheros AR8031/AR8033 30be0000.ethernet-1:00: attached PHY driver (mii_bus:phy_addr=30be0000.ethernet-1:00, irq=POLL)\n[ 853.535318] IPv6: ADDRCONF(NETDEV_CHANGE): eth0: link becomes ready\n[ 853.541694] fec 30be0000.ethernet eth0: Link is Up - 1Gbps/Full - flow control rx/tx\n[ 870.590531] page_pool_release_retry() stalled pool shutdown 199 inflight 60 sec\n[ 931.006557] page_pool_release_retry() stalled pool shutdown 199 inflight 120 sec\nTINFO:ENET up and down test 392 times\n[ 991.426544] page_pool_release_retry() stalled pool shutdown 192 inflight 181 sec\n[ 1051.838531] page_pool_release_retry() stalled pool shutdown 170 inflight 241 sec\n[ 1093.751217] Qualcomm Atheros AR8031/AR8033 30be0000.ethernet-1:00: attached PHY driver (mii_bus:phy_addr=30be0000.ethernet-1:00, irq=POLL)\n[ 1096.446520] page_pool_release_retry() stalled pool shutdown 308 inflight 60 sec\n[ 1096.831245] fec 30be0000.ethernet eth0: Link is Up - 1Gbps/Full - flow control rx/tx\n[ 1096.839092] IPv6: ADDRCONF(NETDEV_CHANGE): eth0: link becomes ready\n[ 1112.254526] page_pool_release_retry() stalled pool shutdown 103 inflight 302 sec\n[ 1156.862533] page_pool_release_retry() stalled pool shutdown 308 inflight 120 sec\n[ 1172.674516] page_pool_release_retry() stalled pool shutdown 103 inflight 362 sec\n[ 1217.278532] page_pool_release_retry() stalled pool shutdown 308 inflight 181 sec\nTINFO:ENET up and down test 393 times\n[ 1233.086535] page_pool_release_retry() stalled pool shutdown 103 inflight 422 sec\n[ 1277.698513] page_pool_release_retry() stalled pool shutdown 308 inflight 241 sec\n[ 1293.502525] page_pool_release_retry() stalled pool shutdown 86 inflight 483 sec\n[ 1338.110518] page_pool_release_retry() stalled pool shutdown 308 inflight 302 sec\n[ 1353.918540] page_pool_release_retry() stalled pool shutdown 32 inflight 543 sec\n[ 1361.179205] Qualcomm Atheros AR8031/AR8033 30be0000.ethernet-1:00: attached PHY driver (mii_bus:phy_addr=30be0000.ethernet-1:00, irq=POLL)\n[ 1364.255298] fec 30be0000.ethernet eth0: Link is Up - 1Gbps/Full - flow control rx/tx\n[ 1364.263189] IPv6: ADDRCONF(NETDEV_CHANGE): eth0: link becomes ready\n[ 1371.998532] page_pool_release_retry() stalled pool shutdown 310 inflight 60 sec\n[ 1398.530542] page_pool_release_retry() stalled pool shutdown 308 inflight 362 sec\n[ 1414.334539] page_pool_release_retry() stalled pool shutdown 16 inflight 604 sec\n[ 1432.414520] page_pool_release_retry() stalled pool shutdown 310 inflight 120 sec\n[ 1458.942523] page_pool_release_retry() stalled pool shutdown 308 inflight 422 sec\n[ 1474.750521] page_pool_release_retry() stalled pool shutdown 16 inflight 664 sec\nTINFO:ENET up and down test 394 times\n[ 1492.8305\n---truncated---",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52998"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/554484a34e985a307756ee4794e60be31e3db2e5"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/e38553bdc377e3e7a6caa9dd9770d8b644d8dac3"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:48Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-rfj2-m755-7qfc/GHSA-rfj2-m755-7qfc.json b/advisories/unreviewed/2025/03/GHSA-rfj2-m755-7qfc/GHSA-rfj2-m755-7qfc.json
new file mode 100644
index 00000000000..fee7e289982
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-rfj2-m755-7qfc/GHSA-rfj2-m755-7qfc.json
@@ -0,0 +1,41 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-rfj2-m755-7qfc",
+ "modified": "2025-03-27T18:31:29Z",
+ "published": "2025-03-27T18:31:28Z",
+ "aliases": [
+ "CVE-2023-53033"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_payload: incorrect arithmetics when fetching VLAN header bits\n\nIf the offset + length goes over the ethernet + vlan header, then the\nlength is adjusted to copy the bytes that are within the boundaries of\nthe vlan_ethhdr scratchpad area. The remaining bytes beyond ethernet +\nvlan header are copied directly from the skbuff data area.\n\nFix incorrect arithmetic operator: subtract, not add, the size of the\nvlan header in case of double-tagged packets to adjust the length\naccordingly to address CVE-2023-0179.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-53033"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/550efeff989b041f3746118c0ddd863c39ddc1aa"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/696e1a48b1a1b01edad542a1ef293665864a4dd0"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/76ef74d4a379faa451003621a84e3498044e7aa3"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/a8acfe2c6fb99f9375a9325807a179cd8c32e6e3"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:53Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-v3mg-hw7c-8v25/GHSA-v3mg-hw7c-8v25.json b/advisories/unreviewed/2025/03/GHSA-v3mg-hw7c-8v25/GHSA-v3mg-hw7c-8v25.json
new file mode 100644
index 00000000000..95e5e5482dc
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-v3mg-hw7c-8v25/GHSA-v3mg-hw7c-8v25.json
@@ -0,0 +1,33 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-v3mg-hw7c-8v25",
+ "modified": "2025-03-27T18:31:28Z",
+ "published": "2025-03-27T18:31:28Z",
+ "aliases": [
+ "CVE-2023-53014"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: tegra: Fix memory leak in terminate_all()\n\nTerminate vdesc when terminating an ongoing transfer.\nThis will ensure that the vdesc is present in the desc_terminated list\nThe descriptor will be freed later in desc_free_list().\n\nThis fixes the memory leaks which can happen when terminating an\nongoing transfer.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-53014"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/567128076d554e41609c61b7d447089094ff72c5"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/a7a7ee6f5a019ad72852c001abbce50d35e992f2"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:50Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-v743-mw8q-3h6g/GHSA-v743-mw8q-3h6g.json b/advisories/unreviewed/2025/03/GHSA-v743-mw8q-3h6g/GHSA-v743-mw8q-3h6g.json
new file mode 100644
index 00000000000..482c627cb15
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-v743-mw8q-3h6g/GHSA-v743-mw8q-3h6g.json
@@ -0,0 +1,33 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-v743-mw8q-3h6g",
+ "modified": "2025-03-27T18:31:27Z",
+ "published": "2025-03-27T18:31:27Z",
+ "aliases": [
+ "CVE-2023-53010"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbnxt: Do not read past the end of test names\n\nTest names were being concatenated based on a offset beyond the end of\nthe first name, which tripped the buffer overflow detection logic:\n\n detected buffer overflow in strnlen\n [...]\n Call Trace:\n bnxt_ethtool_init.cold+0x18/0x18\n\nRefactor struct hwrm_selftest_qlist_output to use an actual array,\nand adjust the concatenation to use snprintf() rather than a series of\nstrncat() calls.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-53010"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/cefa85480ac99c0bef5a09daadb48d65fc28e279"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/d3e599c090fc6977331150c5f0a69ab8ce87da21"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:50Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-v7c9-p8hg-xgw5/GHSA-v7c9-p8hg-xgw5.json b/advisories/unreviewed/2025/03/GHSA-v7c9-p8hg-xgw5/GHSA-v7c9-p8hg-xgw5.json
index 6767857923f..a177ab1dbda 100644
--- a/advisories/unreviewed/2025/03/GHSA-v7c9-p8hg-xgw5/GHSA-v7c9-p8hg-xgw5.json
+++ b/advisories/unreviewed/2025/03/GHSA-v7c9-p8hg-xgw5/GHSA-v7c9-p8hg-xgw5.json
@@ -46,7 +46,8 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-74"
+ "CWE-74",
+ "CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2025/03/GHSA-v985-xp9j-wxfh/GHSA-v985-xp9j-wxfh.json b/advisories/unreviewed/2025/03/GHSA-v985-xp9j-wxfh/GHSA-v985-xp9j-wxfh.json
new file mode 100644
index 00000000000..b715c5b300c
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-v985-xp9j-wxfh/GHSA-v985-xp9j-wxfh.json
@@ -0,0 +1,33 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-v985-xp9j-wxfh",
+ "modified": "2025-03-27T18:31:24Z",
+ "published": "2025-03-27T18:31:24Z",
+ "aliases": [
+ "CVE-2022-49750"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncpufreq: CPPC: Add u64 casts to avoid overflowing\n\nThe fields of the _CPC object are unsigned 32-bits values.\nTo avoid overflows while using _CPC's values, add 'u64' casts.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49750"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/7d596bbc66a52ff2c7a83d7e0ee840cb07e2a045"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/f5f94b9c8b805d87ff185caf9779c3a4d07819e3"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:39Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-v9wm-8h4w-7wmw/GHSA-v9wm-8h4w-7wmw.json b/advisories/unreviewed/2025/03/GHSA-v9wm-8h4w-7wmw/GHSA-v9wm-8h4w-7wmw.json
new file mode 100644
index 00000000000..ae9f42a55ac
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-v9wm-8h4w-7wmw/GHSA-v9wm-8h4w-7wmw.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-v9wm-8h4w-7wmw",
+ "modified": "2025-03-27T18:31:23Z",
+ "published": "2025-03-27T18:31:23Z",
+ "aliases": [
+ "CVE-2025-22497"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in A.H.C. Waasdorp Simple Google Calendar Outlook Events Block Widget allows Stored XSS.This issue affects Simple Google Calendar Outlook Events Block Widget: from n/a through 2.5.0.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22497"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/simple-google-icalendar-widget/vulnerability/wordpress-simple-google-calendar-outlook-events-block-widget-plugin-2-6-0-cross-site-scripting-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T16:15:27Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-vgcw-mq7g-4h6g/GHSA-vgcw-mq7g-4h6g.json b/advisories/unreviewed/2025/03/GHSA-vgcw-mq7g-4h6g/GHSA-vgcw-mq7g-4h6g.json
new file mode 100644
index 00000000000..7ce25af4946
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-vgcw-mq7g-4h6g/GHSA-vgcw-mq7g-4h6g.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-vgcw-mq7g-4h6g",
+ "modified": "2025-03-27T18:31:23Z",
+ "published": "2025-03-27T18:31:23Z",
+ "aliases": [
+ "CVE-2025-22637"
+ ],
+ "details": "Cross-Site Request Forgery (CSRF) vulnerability in verkkovaraani Print PDF Generator and Publisher allows Cross Site Request Forgery.This issue affects Print PDF Generator and Publisher: from n/a through 1.2.0.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22637"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/nopeamedia/vulnerability/wordpress-print-pdf-generator-and-publisher-plugin-1-2-0-cross-site-request-forgery-csrf-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-352"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T16:15:28Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-vjwm-w9rc-f4cc/GHSA-vjwm-w9rc-f4cc.json b/advisories/unreviewed/2025/03/GHSA-vjwm-w9rc-f4cc/GHSA-vjwm-w9rc-f4cc.json
index 5d173e9337b..45aee8fddfa 100644
--- a/advisories/unreviewed/2025/03/GHSA-vjwm-w9rc-f4cc/GHSA-vjwm-w9rc-f4cc.json
+++ b/advisories/unreviewed/2025/03/GHSA-vjwm-w9rc-f4cc/GHSA-vjwm-w9rc-f4cc.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vjwm-w9rc-f4cc",
- "modified": "2025-03-27T15:31:12Z",
+ "modified": "2025-03-27T18:31:18Z",
"published": "2025-03-27T15:31:12Z",
"aliases": [
"CVE-2025-21887"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\novl: fix UAF in ovl_dentry_update_reval by moving dput() in ovl_link_up\n\nThe issue was caused by dput(upper) being called before\novl_dentry_update_reval(), while upper->d_flags was still\naccessed in ovl_dentry_remote().\n\nMove dput(upper) after its last use to prevent use-after-free.\n\nBUG: KASAN: slab-use-after-free in ovl_dentry_remote fs/overlayfs/util.c:162 [inline]\nBUG: KASAN: slab-use-after-free in ovl_dentry_update_reval+0xd2/0xf0 fs/overlayfs/util.c:167\n\nCall Trace:\n \n __dump_stack lib/dump_stack.c:88 [inline]\n dump_stack_lvl+0x116/0x1f0 lib/dump_stack.c:114\n print_address_description mm/kasan/report.c:377 [inline]\n print_report+0xc3/0x620 mm/kasan/report.c:488\n kasan_report+0xd9/0x110 mm/kasan/report.c:601\n ovl_dentry_remote fs/overlayfs/util.c:162 [inline]\n ovl_dentry_update_reval+0xd2/0xf0 fs/overlayfs/util.c:167\n ovl_link_up fs/overlayfs/copy_up.c:610 [inline]\n ovl_copy_up_one+0x2105/0x3490 fs/overlayfs/copy_up.c:1170\n ovl_copy_up_flags+0x18d/0x200 fs/overlayfs/copy_up.c:1223\n ovl_rename+0x39e/0x18c0 fs/overlayfs/dir.c:1136\n vfs_rename+0xf84/0x20a0 fs/namei.c:4893\n...\n ",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -40,8 +45,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-27T15:15:56Z"
diff --git a/advisories/unreviewed/2025/03/GHSA-vm8w-gf89-48f9/GHSA-vm8w-gf89-48f9.json b/advisories/unreviewed/2025/03/GHSA-vm8w-gf89-48f9/GHSA-vm8w-gf89-48f9.json
new file mode 100644
index 00000000000..0b1cf53d930
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-vm8w-gf89-48f9/GHSA-vm8w-gf89-48f9.json
@@ -0,0 +1,44 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-vm8w-gf89-48f9",
+ "modified": "2025-03-27T18:31:26Z",
+ "published": "2025-03-27T18:31:26Z",
+ "aliases": [
+ "CVE-2023-52975"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: iscsi_tcp: Fix UAF during logout when accessing the shost ipaddress\n\nBug report and analysis from Ding Hui.\n\nDuring iSCSI session logout, if another task accesses the shost ipaddress\nattr, we can get a KASAN UAF report like this:\n\n[ 276.942144] BUG: KASAN: use-after-free in _raw_spin_lock_bh+0x78/0xe0\n[ 276.942535] Write of size 4 at addr ffff8881053b45b8 by task cat/4088\n[ 276.943511] CPU: 2 PID: 4088 Comm: cat Tainted: G E 6.1.0-rc8+ #3\n[ 276.943997] Hardware name: VMware, Inc. VMware Virtual Platform/440BX Desktop Reference Platform, BIOS 6.00 11/12/2020\n[ 276.944470] Call Trace:\n[ 276.944943] \n[ 276.945397] dump_stack_lvl+0x34/0x48\n[ 276.945887] print_address_description.constprop.0+0x86/0x1e7\n[ 276.946421] print_report+0x36/0x4f\n[ 276.947358] kasan_report+0xad/0x130\n[ 276.948234] kasan_check_range+0x35/0x1c0\n[ 276.948674] _raw_spin_lock_bh+0x78/0xe0\n[ 276.949989] iscsi_sw_tcp_host_get_param+0xad/0x2e0 [iscsi_tcp]\n[ 276.951765] show_host_param_ISCSI_HOST_PARAM_IPADDRESS+0xe9/0x130 [scsi_transport_iscsi]\n[ 276.952185] dev_attr_show+0x3f/0x80\n[ 276.953005] sysfs_kf_seq_show+0x1fb/0x3e0\n[ 276.953401] seq_read_iter+0x402/0x1020\n[ 276.954260] vfs_read+0x532/0x7b0\n[ 276.955113] ksys_read+0xed/0x1c0\n[ 276.955952] do_syscall_64+0x38/0x90\n[ 276.956347] entry_SYSCALL_64_after_hwframe+0x63/0xcd\n[ 276.956769] RIP: 0033:0x7f5d3a679222\n[ 276.957161] Code: c0 e9 b2 fe ff ff 50 48 8d 3d 32 c0 0b 00 e8 a5 fe 01 00 0f 1f 44 00 00 f3 0f 1e fa 64 8b 04 25 18 00 00 00 85 c0 75 10 0f 05 <48> 3d 00 f0 ff ff 77 56 c3 0f 1f 44 00 00 48 83 ec 28 48 89 54 24\n[ 276.958009] RSP: 002b:00007ffc864d16a8 EFLAGS: 00000246 ORIG_RAX: 0000000000000000\n[ 276.958431] RAX: ffffffffffffffda RBX: 0000000000020000 RCX: 00007f5d3a679222\n[ 276.958857] RDX: 0000000000020000 RSI: 00007f5d3a4fe000 RDI: 0000000000000003\n[ 276.959281] RBP: 00007f5d3a4fe000 R08: 00000000ffffffff R09: 0000000000000000\n[ 276.959682] R10: 0000000000000022 R11: 0000000000000246 R12: 0000000000020000\n[ 276.960126] R13: 0000000000000003 R14: 0000000000000000 R15: 0000557a26dada58\n[ 276.960536] \n[ 276.961357] Allocated by task 2209:\n[ 276.961756] kasan_save_stack+0x1e/0x40\n[ 276.962170] kasan_set_track+0x21/0x30\n[ 276.962557] __kasan_kmalloc+0x7e/0x90\n[ 276.962923] __kmalloc+0x5b/0x140\n[ 276.963308] iscsi_alloc_session+0x28/0x840 [scsi_transport_iscsi]\n[ 276.963712] iscsi_session_setup+0xda/0xba0 [libiscsi]\n[ 276.964078] iscsi_sw_tcp_session_create+0x1fd/0x330 [iscsi_tcp]\n[ 276.964431] iscsi_if_create_session.isra.0+0x50/0x260 [scsi_transport_iscsi]\n[ 276.964793] iscsi_if_recv_msg+0xc5a/0x2660 [scsi_transport_iscsi]\n[ 276.965153] iscsi_if_rx+0x198/0x4b0 [scsi_transport_iscsi]\n[ 276.965546] netlink_unicast+0x4d5/0x7b0\n[ 276.965905] netlink_sendmsg+0x78d/0xc30\n[ 276.966236] sock_sendmsg+0xe5/0x120\n[ 276.966576] ____sys_sendmsg+0x5fe/0x860\n[ 276.966923] ___sys_sendmsg+0xe0/0x170\n[ 276.967300] __sys_sendmsg+0xc8/0x170\n[ 276.967666] do_syscall_64+0x38/0x90\n[ 276.968028] entry_SYSCALL_64_after_hwframe+0x63/0xcd\n[ 276.968773] Freed by task 2209:\n[ 276.969111] kasan_save_stack+0x1e/0x40\n[ 276.969449] kasan_set_track+0x21/0x30\n[ 276.969789] kasan_save_free_info+0x2a/0x50\n[ 276.970146] __kasan_slab_free+0x106/0x190\n[ 276.970470] __kmem_cache_free+0x133/0x270\n[ 276.970816] device_release+0x98/0x210\n[ 276.971145] kobject_cleanup+0x101/0x360\n[ 276.971462] iscsi_session_teardown+0x3fb/0x530 [libiscsi]\n[ 276.971775] iscsi_sw_tcp_session_destroy+0xd8/0x130 [iscsi_tcp]\n[ 276.972143] iscsi_if_recv_msg+0x1bf1/0x2660 [scsi_transport_iscsi]\n[ 276.972485] iscsi_if_rx+0x198/0x4b0 [scsi_transport_iscsi]\n[ 276.972808] netlink_unicast+0x4d5/0x7b0\n[ 276.973201] netlink_sendmsg+0x78d/0xc30\n[ 276.973544] sock_sendmsg+0xe5/0x120\n[ 276.973864] ____sys_sendmsg+0x5fe/0x860\n[ 276.974248] ___sys_\n---truncated---",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52975"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/17b738590b97fb3fc287289971d1519ff9b875a1"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/6f1d64b13097e85abda0f91b5638000afc5f9a06"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/8859687f5b242c0b057461df0a9ff51d5500783b"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:44Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-vxj7-p6gh-99vg/GHSA-vxj7-p6gh-99vg.json b/advisories/unreviewed/2025/03/GHSA-vxj7-p6gh-99vg/GHSA-vxj7-p6gh-99vg.json
new file mode 100644
index 00000000000..4c1d073db76
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-vxj7-p6gh-99vg/GHSA-vxj7-p6gh-99vg.json
@@ -0,0 +1,33 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-vxj7-p6gh-99vg",
+ "modified": "2025-03-27T18:31:27Z",
+ "published": "2025-03-27T18:31:27Z",
+ "aliases": [
+ "CVE-2023-53002"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/i915: Fix a memory leak with reused mmap_offset\n\ndrm_vma_node_allow() and drm_vma_node_revoke() should be called in\nbalanced pairs. We call drm_vma_node_allow() once per-file everytime a\nuser calls mmap_offset, but only call drm_vma_node_revoke once per-file\non each mmap_offset. As the mmap_offset is reused by the client, the\nper-file vm_count may remain non-zero and the rbtree leaked.\n\nCall drm_vma_node_allow_once() instead to prevent that memory leak.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-53002"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/0220e4fe178c3390eb0291cdb34912d66972db8a"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/0bdc4b4ba7206c452ee81c82fa66e39d0e1780fb"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:49Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-w6fx-qwwp-5r54/GHSA-w6fx-qwwp-5r54.json b/advisories/unreviewed/2025/03/GHSA-w6fx-qwwp-5r54/GHSA-w6fx-qwwp-5r54.json
new file mode 100644
index 00000000000..a5ee4c82a5f
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-w6fx-qwwp-5r54/GHSA-w6fx-qwwp-5r54.json
@@ -0,0 +1,33 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-w6fx-qwwp-5r54",
+ "modified": "2025-03-27T18:31:27Z",
+ "published": "2025-03-27T18:31:27Z",
+ "aliases": [
+ "CVE-2023-53009"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdkfd: Add sync after creating vram bo\n\nThere will be data corruption on vram allocated by svm\nif the initialization is not complete and application is\nwritting on the memory. Adding sync to wait for the\ninitialization completion is to resolve this issue.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-53009"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/92af2d3b57a1afdfdcafb1c6a07ffd89cf3e98fb"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/ba029e9991d9be90a28b6a0ceb25e9a6fb348829"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:49Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-w7fp-pj56-6xc6/GHSA-w7fp-pj56-6xc6.json b/advisories/unreviewed/2025/03/GHSA-w7fp-pj56-6xc6/GHSA-w7fp-pj56-6xc6.json
new file mode 100644
index 00000000000..75101edd132
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-w7fp-pj56-6xc6/GHSA-w7fp-pj56-6xc6.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-w7fp-pj56-6xc6",
+ "modified": "2025-03-27T18:31:29Z",
+ "published": "2025-03-27T18:31:29Z",
+ "aliases": [
+ "CVE-2023-38272"
+ ],
+ "details": "IBM Cloud Pak System 2.3.3.0, 2.3.3.3, 2.3.3.3 iFix1, 2.3.3.4, 2.3.3.5, 2.3.3.6, 2.3.36 iFix1, 2.3.3.6 iFix2, 2.3.3.7, 2.3.3.7 iFix1, 2.3.4.0, and 2.3.4.1 \n\ncould allow a user with access to the network to obtain sensitive information from CLI arguments.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38272"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.ibm.com/support/pages/node/7229212"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-300"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T18:17:29Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-w9c3-ww8v-w4fv/GHSA-w9c3-ww8v-w4fv.json b/advisories/unreviewed/2025/03/GHSA-w9c3-ww8v-w4fv/GHSA-w9c3-ww8v-w4fv.json
new file mode 100644
index 00000000000..a867302cd04
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-w9c3-ww8v-w4fv/GHSA-w9c3-ww8v-w4fv.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-w9c3-ww8v-w4fv",
+ "modified": "2025-03-27T18:31:23Z",
+ "published": "2025-03-27T18:31:23Z",
+ "aliases": [
+ "CVE-2025-22628"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Foliovision Filled In allows Stored XSS.This issue affects Filled In: from n/a through 1.9.2.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22628"
+ },
+ {
+ "type": "WEB",
+ "url": "https://patchstack.com/database/wordpress/plugin/filled-in/vulnerability/wordpress-filled-in-plugin-1-9-1-csrf-to-stored-xss-vulnerability?_s_id=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T16:15:28Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-whcm-px77-62x7/GHSA-whcm-px77-62x7.json b/advisories/unreviewed/2025/03/GHSA-whcm-px77-62x7/GHSA-whcm-px77-62x7.json
new file mode 100644
index 00000000000..375744a55e4
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-whcm-px77-62x7/GHSA-whcm-px77-62x7.json
@@ -0,0 +1,33 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-whcm-px77-62x7",
+ "modified": "2025-03-27T18:31:25Z",
+ "published": "2025-03-27T18:31:25Z",
+ "aliases": [
+ "CVE-2023-52935"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/khugepaged: fix ->anon_vma race\n\nIf an ->anon_vma is attached to the VMA, collapse_and_free_pmd() requires\nit to be locked.\n\nPage table traversal is allowed under any one of the mmap lock, the\nanon_vma lock (if the VMA is associated with an anon_vma), and the\nmapping lock (if the VMA is associated with a mapping); and so to be\nable to remove page tables, we must hold all three of them. \nretract_page_tables() bails out if an ->anon_vma is attached, but does\nthis check before holding the mmap lock (as the comment above the check\nexplains).\n\nIf we racily merged an existing ->anon_vma (shared with a child\nprocess) from a neighboring VMA, subsequent rmap traversals on pages\nbelonging to the child will be able to see the page tables that we are\nconcurrently removing while assuming that nothing else can access them.\n\nRepeat the ->anon_vma check once we hold the mmap lock to ensure that\nthere really is no concurrent page table access.\n\nHitting this bug causes a lockdep warning in collapse_and_free_pmd(),\nin the line \"lockdep_assert_held_write(&vma->anon_vma->root->rwsem)\". \nIt can also lead to use-after-free access.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52935"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/023f47a8250c6bdb4aebe744db4bf7f73414028b"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/acb08187b5a83cdb9ac4112fae9e18cf983b0128"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:43Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-wpc3-48hj-vqgf/GHSA-wpc3-48hj-vqgf.json b/advisories/unreviewed/2025/03/GHSA-wpc3-48hj-vqgf/GHSA-wpc3-48hj-vqgf.json
new file mode 100644
index 00000000000..69b83dc49c9
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-wpc3-48hj-vqgf/GHSA-wpc3-48hj-vqgf.json
@@ -0,0 +1,33 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-wpc3-48hj-vqgf",
+ "modified": "2025-03-27T18:31:27Z",
+ "published": "2025-03-27T18:31:27Z",
+ "aliases": [
+ "CVE-2023-53008"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncifs: fix potential memory leaks in session setup\n\nMake sure to free cifs_ses::auth_key.response before allocating it as\nwe might end up leaking memory in reconnect or mounting.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-53008"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/2fe58d977ee05da5bb89ef5dc4f5bf2dc15db46f"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/893d45394dbe4b5cbf3723c19e2ccc8b93a6ac9b"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:49Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-wq32-8rp4-w2mc/GHSA-wq32-8rp4-w2mc.json b/advisories/unreviewed/2025/03/GHSA-wq32-8rp4-w2mc/GHSA-wq32-8rp4-w2mc.json
new file mode 100644
index 00000000000..01c097e33c1
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-wq32-8rp4-w2mc/GHSA-wq32-8rp4-w2mc.json
@@ -0,0 +1,33 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-wq32-8rp4-w2mc",
+ "modified": "2025-03-27T18:31:23Z",
+ "published": "2025-03-27T18:31:23Z",
+ "aliases": [
+ "CVE-2025-29072"
+ ],
+ "details": "An integer overflow in Nethermind Juno before v.12.05 within the Sierra bytecode decompression logic within the \"cairo-lang-starknet-classes\" library could allow remote attackers to trigger an infinite loop (and high CPU usage) by submitting a malicious Declare v2/v3 transaction. This results in a denial-of-service condition for affected Starknet full-node implementations.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29072"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/NethermindEth/juno/commit/51074875941aa111c5dd2b41f2ec890a4a15b587"
+ },
+ {
+ "type": "WEB",
+ "url": "https://community.starknet.io/t/starknet-security-update-potential-full-node-vulnerability-recap/115314"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T16:15:30Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-wq76-hwvv-4gwx/GHSA-wq76-hwvv-4gwx.json b/advisories/unreviewed/2025/03/GHSA-wq76-hwvv-4gwx/GHSA-wq76-hwvv-4gwx.json
new file mode 100644
index 00000000000..f65d2c5bea8
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-wq76-hwvv-4gwx/GHSA-wq76-hwvv-4gwx.json
@@ -0,0 +1,52 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-wq76-hwvv-4gwx",
+ "modified": "2025-03-27T18:31:24Z",
+ "published": "2025-03-27T18:31:24Z",
+ "aliases": [
+ "CVE-2025-2855"
+ ],
+ "details": "A vulnerability, which was classified as problematic, has been found in elunez eladmin up to 2.7. Affected by this issue is the function checkFile of the file /api/deploy/upload. The manipulation of the argument servers leads to deserialization. The attack may be launched remotely.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L"
+ },
+ {
+ "type": "CVSS_V4",
+ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2855"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/elunez/eladmin/issues/873"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?ctiid.301502"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?id.301502"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?submit.522504"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-20"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T16:15:31Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-wqh7-68mq-r673/GHSA-wqh7-68mq-r673.json b/advisories/unreviewed/2025/03/GHSA-wqh7-68mq-r673/GHSA-wqh7-68mq-r673.json
new file mode 100644
index 00000000000..a879aad452e
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-wqh7-68mq-r673/GHSA-wqh7-68mq-r673.json
@@ -0,0 +1,60 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-wqh7-68mq-r673",
+ "modified": "2025-03-27T18:31:26Z",
+ "published": "2025-03-27T18:31:25Z",
+ "aliases": [
+ "CVE-2023-52974"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: iscsi_tcp: Fix UAF during login when accessing the shost ipaddress\n\nIf during iscsi_sw_tcp_session_create() iscsi_tcp_r2tpool_alloc() fails,\nuserspace could be accessing the host's ipaddress attr. If we then free the\nsession via iscsi_session_teardown() while userspace is still accessing the\nsession we will hit a use after free bug.\n\nSet the tcp_sw_host->session after we have completed session creation and\ncan no longer fail.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52974"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/0aaabdb900c7415caa2006ef580322f7eac5f6b6"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/496af9d3682ed4c28fb734342a09e6cc0c056ea4"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/61e43ebfd243bcbad11be26bd921723027b77441"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/6abd4698f4c8a78e7bbfc421205c060c199554a0"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/9758ffe1c07b86aefd7ca8e40d9a461293427ca0"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/d4d765f4761f9e3a2d62992f825aeee593bcb6b9"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/f484a794e4ee2a9ce61f52a78e810ac45f3fe3b3"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:44Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-wvmw-32m8-fcpg/GHSA-wvmw-32m8-fcpg.json b/advisories/unreviewed/2025/03/GHSA-wvmw-32m8-fcpg/GHSA-wvmw-32m8-fcpg.json
new file mode 100644
index 00000000000..cfc002b4266
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-wvmw-32m8-fcpg/GHSA-wvmw-32m8-fcpg.json
@@ -0,0 +1,33 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-wvmw-32m8-fcpg",
+ "modified": "2025-03-27T18:31:26Z",
+ "published": "2025-03-27T18:31:26Z",
+ "aliases": [
+ "CVE-2023-52987"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: SOF: ipc4-mtrace: prevent underflow in sof_ipc4_priority_mask_dfs_write()\n\nThe \"id\" comes from the user. Change the type to unsigned to prevent\nan array underflow.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52987"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/d52f34784e4e2f6e77671a9f104d8a69a3b5d24c"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/ea57680af47587397f5005d7758022441ed66d54"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:46Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-x444-83wh-35rx/GHSA-x444-83wh-35rx.json b/advisories/unreviewed/2025/03/GHSA-x444-83wh-35rx/GHSA-x444-83wh-35rx.json
new file mode 100644
index 00000000000..9acf4578c82
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-x444-83wh-35rx/GHSA-x444-83wh-35rx.json
@@ -0,0 +1,56 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-x444-83wh-35rx",
+ "modified": "2025-03-27T18:31:27Z",
+ "published": "2025-03-27T18:31:27Z",
+ "aliases": [
+ "CVE-2023-52999"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: fix UaF in netns ops registration error path\n\nIf net_assign_generic() fails, the current error path in ops_init() tries\nto clear the gen pointer slot. Anyway, in such error path, the gen pointer\nitself has not been modified yet, and the existing and accessed one is\nsmaller than the accessed index, causing an out-of-bounds error:\n\n BUG: KASAN: slab-out-of-bounds in ops_init+0x2de/0x320\n Write of size 8 at addr ffff888109124978 by task modprobe/1018\n\n CPU: 2 PID: 1018 Comm: modprobe Not tainted 6.2.0-rc2.mptcp_ae5ac65fbed5+ #1641\n Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.1-2.fc37 04/01/2014\n Call Trace:\n \n dump_stack_lvl+0x6a/0x9f\n print_address_description.constprop.0+0x86/0x2b5\n print_report+0x11b/0x1fb\n kasan_report+0x87/0xc0\n ops_init+0x2de/0x320\n register_pernet_operations+0x2e4/0x750\n register_pernet_subsys+0x24/0x40\n tcf_register_action+0x9f/0x560\n do_one_initcall+0xf9/0x570\n do_init_module+0x190/0x650\n load_module+0x1fa5/0x23c0\n __do_sys_finit_module+0x10d/0x1b0\n do_syscall_64+0x58/0x80\n entry_SYSCALL_64_after_hwframe+0x72/0xdc\n RIP: 0033:0x7f42518f778d\n Code: 00 c3 66 2e 0f 1f 84 00 00 00 00 00 90 f3 0f 1e fa 48 89 f8 48 89 f7 48\n 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff\n ff 73 01 c3 48 8b 0d cb 56 2c 00 f7 d8 64 89 01 48\n RSP: 002b:00007fff96869688 EFLAGS: 00000246 ORIG_RAX: 0000000000000139\n RAX: ffffffffffffffda RBX: 00005568ef7f7c90 RCX: 00007f42518f778d\n RDX: 0000000000000000 RSI: 00005568ef41d796 RDI: 0000000000000003\n RBP: 00005568ef41d796 R08: 0000000000000000 R09: 0000000000000000\n R10: 0000000000000003 R11: 0000000000000246 R12: 0000000000000000\n R13: 00005568ef7f7d30 R14: 0000000000040000 R15: 0000000000000000\n \n\nThis change addresses the issue by skipping the gen pointer\nde-reference in the mentioned error-path.\n\nFound by code inspection and verified with explicit error injection\non a kasan-enabled kernel.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52999"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/12075708f2e77ee6a9f8bb2cf512c38be3099794"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/66689a72ba73575e76d4f6a8748d3fa2690ec1c4"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/71ab9c3e2253619136c31c89dbb2c69305cc89b1"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/ad0dfe9bcf0d78e699c7efb64c90ed062dc48bea"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/d4c008f3b7f7d4ffd311eb2dae5e75b3cbddacd0"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/ddd49cbbd4c1ceb38032018b589b44208e54f55e"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:48Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-x6ch-fhmp-9745/GHSA-x6ch-fhmp-9745.json b/advisories/unreviewed/2025/03/GHSA-x6ch-fhmp-9745/GHSA-x6ch-fhmp-9745.json
new file mode 100644
index 00000000000..e346fe7b360
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-x6ch-fhmp-9745/GHSA-x6ch-fhmp-9745.json
@@ -0,0 +1,45 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-x6ch-fhmp-9745",
+ "modified": "2025-03-27T18:31:24Z",
+ "published": "2025-03-27T18:31:24Z",
+ "aliases": [
+ "CVE-2022-49738"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to do sanity check on i_extra_isize in is_alive()\n\nsyzbot found a f2fs bug:\n\nBUG: KASAN: slab-out-of-bounds in data_blkaddr fs/f2fs/f2fs.h:2891 [inline]\nBUG: KASAN: slab-out-of-bounds in is_alive fs/f2fs/gc.c:1117 [inline]\nBUG: KASAN: slab-out-of-bounds in gc_data_segment fs/f2fs/gc.c:1520 [inline]\nBUG: KASAN: slab-out-of-bounds in do_garbage_collect+0x386a/0x3df0 fs/f2fs/gc.c:1734\nRead of size 4 at addr ffff888076557568 by task kworker/u4:3/52\n\nCPU: 1 PID: 52 Comm: kworker/u4:3 Not tainted 6.1.0-rc4-syzkaller-00362-gfef7fd48922d #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/26/2022\nWorkqueue: writeback wb_workfn (flush-7:0)\nCall Trace:\n\n__dump_stack lib/dump_stack.c:88 [inline]\ndump_stack_lvl+0xcd/0x134 lib/dump_stack.c:106\nprint_address_description mm/kasan/report.c:284 [inline]\nprint_report+0x15e/0x45d mm/kasan/report.c:395\nkasan_report+0xbb/0x1f0 mm/kasan/report.c:495\ndata_blkaddr fs/f2fs/f2fs.h:2891 [inline]\nis_alive fs/f2fs/gc.c:1117 [inline]\ngc_data_segment fs/f2fs/gc.c:1520 [inline]\ndo_garbage_collect+0x386a/0x3df0 fs/f2fs/gc.c:1734\nf2fs_gc+0x88c/0x20a0 fs/f2fs/gc.c:1831\nf2fs_balance_fs+0x544/0x6b0 fs/f2fs/segment.c:410\nf2fs_write_inode+0x57e/0xe20 fs/f2fs/inode.c:753\nwrite_inode fs/fs-writeback.c:1440 [inline]\n__writeback_single_inode+0xcfc/0x1440 fs/fs-writeback.c:1652\nwriteback_sb_inodes+0x54d/0xf90 fs/fs-writeback.c:1870\nwb_writeback+0x2c5/0xd70 fs/fs-writeback.c:2044\nwb_do_writeback fs/fs-writeback.c:2187 [inline]\nwb_workfn+0x2dc/0x12f0 fs/fs-writeback.c:2227\nprocess_one_work+0x9bf/0x1710 kernel/workqueue.c:2289\nworker_thread+0x665/0x1080 kernel/workqueue.c:2436\nkthread+0x2e4/0x3a0 kernel/kthread.c:376\nret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:306\n\nThe root cause is that we forgot to do sanity check on .i_extra_isize\nin below path, result in accessing invalid address later, fix it.\n- gc_data_segment\n - is_alive\n - data_blkaddr\n - offset_in_addr",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49738"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/5b25035fb888cb2f78bf0b9c9f95b1dc54480d36"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/914e38f02a490dafd980ff0f39cccedc074deb29"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/97ccfffcc061e54ce87e4a51a40e2e9cb0b7076a"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/d3b7b4afd6b2c344eabf9cc26b8bfa903c164c7c"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/e5142a4935c1f15841d06047b8130078fc4d7b8f"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:38Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-x768-g2cv-hv4j/GHSA-x768-g2cv-hv4j.json b/advisories/unreviewed/2025/03/GHSA-x768-g2cv-hv4j/GHSA-x768-g2cv-hv4j.json
new file mode 100644
index 00000000000..5087bfbaaa4
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-x768-g2cv-hv4j/GHSA-x768-g2cv-hv4j.json
@@ -0,0 +1,53 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-x768-g2cv-hv4j",
+ "modified": "2025-03-27T18:31:27Z",
+ "published": "2025-03-27T18:31:27Z",
+ "aliases": [
+ "CVE-2023-52989"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfirewire: fix memory leak for payload of request subaction to IEC 61883-1 FCP region\n\nThis patch is fix for Linux kernel v2.6.33 or later.\n\nFor request subaction to IEC 61883-1 FCP region, Linux FireWire subsystem\nhave had an issue of use-after-free. The subsystem allows multiple\nuser space listeners to the region, while data of the payload was likely\nreleased before the listeners execute read(2) to access to it for copying\nto user space.\n\nThe issue was fixed by a commit 281e20323ab7 (\"firewire: core: fix\nuse-after-free regression in FCP handler\"). The object of payload is\nduplicated in kernel space for each listener. When the listener executes\nioctl(2) with FW_CDEV_IOC_SEND_RESPONSE request, the object is going to\nbe released.\n\nHowever, it causes memory leak since the commit relies on call of\nrelease_request() in drivers/firewire/core-cdev.c. Against the\nexpectation, the function is never called due to the design of\nrelease_client_resource(). The function delegates release task\nto caller when called with non-NULL fourth argument. The implementation\nof ioctl_send_response() is the case. It should release the object\nexplicitly.\n\nThis commit fixes the bug.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52989"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/356ff89acdbe6a66019154bc7eb2d300f5b15103"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/531390a243ef47448f8bad01c186c2787666bf4d"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/53785fd9b315583cf029e39f72b73d23704a2253"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/5f4543c9382ae2d5062f6aa4fecae0c9258d0b0e"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/b2cd3947d116bb9ba7ff097b5fc747a8956764db"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/c8bdc88216f09cb7387fedbdf613524367328616"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/d5a2dcee53fa6e6e2822f93cb3f1b0cd23163bee"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:46Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-xhmw-hwm7-v657/GHSA-xhmw-hwm7-v657.json b/advisories/unreviewed/2025/03/GHSA-xhmw-hwm7-v657/GHSA-xhmw-hwm7-v657.json
new file mode 100644
index 00000000000..2dc26654f03
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-xhmw-hwm7-v657/GHSA-xhmw-hwm7-v657.json
@@ -0,0 +1,49 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-xhmw-hwm7-v657",
+ "modified": "2025-03-27T18:31:24Z",
+ "published": "2025-03-27T18:31:23Z",
+ "aliases": [
+ "CVE-2022-49739"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ngfs2: Always check inode size of inline inodes\n\nCheck if the inode size of stuffed (inline) inodes is within the allowed\nrange when reading inodes from disk (gfs2_dinode_in()). This prevents\nus from on-disk corruption.\n\nThe two checks in stuffed_readpage() and gfs2_unstuffer_page() that just\ntruncate inline data to the maximum allowed size don't actually make\nsense, and they can be removed now as well.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49739"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/45df749f827c286adbc951f2a4865b67f0442ba9"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/46c9088cabd4d0469fdb61ac2a9c5003057fe94d"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/4d4cb76636134bf9a0c9c3432dae936f99954586"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/70376c7ff31221f1d21db5611d8209e677781d3a"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/7c414f6f06e9a3934901b6edc3177ae5a1e07094"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/d458a0984429c2d47e60254f5bc4119cbafe83a2"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:38Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-xpq9-hr2h-w5cj/GHSA-xpq9-hr2h-w5cj.json b/advisories/unreviewed/2025/03/GHSA-xpq9-hr2h-w5cj/GHSA-xpq9-hr2h-w5cj.json
new file mode 100644
index 00000000000..4d455ee33c6
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-xpq9-hr2h-w5cj/GHSA-xpq9-hr2h-w5cj.json
@@ -0,0 +1,37 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-xpq9-hr2h-w5cj",
+ "modified": "2025-03-27T18:31:29Z",
+ "published": "2025-03-27T18:31:29Z",
+ "aliases": [
+ "CVE-2023-53029"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nocteontx2-pf: Fix the use of GFP_KERNEL in atomic context on rt\n\nThe commit 4af1b64f80fb (\"octeontx2-pf: Fix lmtst ID used in aura\nfree\") uses the get/put_cpu() to protect the usage of percpu pointer\nin ->aura_freeptr() callback, but it also unnecessarily disable the\npreemption for the blockable memory allocation. The commit 87b93b678e95\n(\"octeontx2-pf: Avoid use of GFP_KERNEL in atomic context\") tried to\nfix these sleep inside atomic warnings. But it only fix the one for\nthe non-rt kernel. For the rt kernel, we still get the similar warnings\nlike below.\n BUG: sleeping function called from invalid context at kernel/locking/spinlock_rt.c:46\n in_atomic(): 1, irqs_disabled(): 0, non_block: 0, pid: 1, name: swapper/0\n preempt_count: 1, expected: 0\n RCU nest depth: 0, expected: 0\n 3 locks held by swapper/0/1:\n #0: ffff800009fc5fe8 (rtnl_mutex){+.+.}-{3:3}, at: rtnl_lock+0x24/0x30\n #1: ffff000100c276c0 (&mbox->lock){+.+.}-{3:3}, at: otx2_init_hw_resources+0x8c/0x3a4\n #2: ffffffbfef6537e0 (&cpu_rcache->lock){+.+.}-{2:2}, at: alloc_iova_fast+0x1ac/0x2ac\n Preemption disabled at:\n [] otx2_rq_aura_pool_init+0x14c/0x284\n CPU: 20 PID: 1 Comm: swapper/0 Tainted: G W 6.2.0-rc3-rt1-yocto-preempt-rt #1\n Hardware name: Marvell OcteonTX CN96XX board (DT)\n Call trace:\n dump_backtrace.part.0+0xe8/0xf4\n show_stack+0x20/0x30\n dump_stack_lvl+0x9c/0xd8\n dump_stack+0x18/0x34\n __might_resched+0x188/0x224\n rt_spin_lock+0x64/0x110\n alloc_iova_fast+0x1ac/0x2ac\n iommu_dma_alloc_iova+0xd4/0x110\n __iommu_dma_map+0x80/0x144\n iommu_dma_map_page+0xe8/0x260\n dma_map_page_attrs+0xb4/0xc0\n __otx2_alloc_rbuf+0x90/0x150\n otx2_rq_aura_pool_init+0x1c8/0x284\n otx2_init_hw_resources+0xe4/0x3a4\n otx2_open+0xf0/0x610\n __dev_open+0x104/0x224\n __dev_change_flags+0x1e4/0x274\n dev_change_flags+0x2c/0x7c\n ic_open_devs+0x124/0x2f8\n ip_auto_config+0x180/0x42c\n do_one_initcall+0x90/0x4dc\n do_basic_setup+0x10c/0x14c\n kernel_init_freeable+0x10c/0x13c\n kernel_init+0x2c/0x140\n ret_from_fork+0x10/0x20\n\nOf course, we can shuffle the get/put_cpu() to only wrap the invocation\nof ->aura_freeptr() as what commit 87b93b678e95 does. But there are only\ntwo ->aura_freeptr() callbacks, otx2_aura_freeptr() and\ncn10k_aura_freeptr(). There is no usage of perpcu variable in the\notx2_aura_freeptr() at all, so the get/put_cpu() seems redundant to it.\nWe can move the get/put_cpu() into the corresponding callback which\nreally has the percpu variable usage and avoid the sprinkling of\nget/put_cpu() in several places.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-53029"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/29e9c67bf3271067735c188e95cf3631ecd64d58"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/55ba18dc62deff5910c0fa64486dea1ff20832ff"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/659518e013d6bd562bb0f1d2d9f99d0ac54720e2"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:52Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-xr6w-2qh5-hfqq/GHSA-xr6w-2qh5-hfqq.json b/advisories/unreviewed/2025/03/GHSA-xr6w-2qh5-hfqq/GHSA-xr6w-2qh5-hfqq.json
new file mode 100644
index 00000000000..afb032052b4
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-xr6w-2qh5-hfqq/GHSA-xr6w-2qh5-hfqq.json
@@ -0,0 +1,33 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-xr6w-2qh5-hfqq",
+ "modified": "2025-03-27T18:31:28Z",
+ "published": "2025-03-27T18:31:28Z",
+ "aliases": [
+ "CVE-2023-53017"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_sync: fix memory leak in hci_update_adv_data()\n\nWhen hci_cmd_sync_queue() failed in hci_update_adv_data(), inst_ptr is\nnot freed, which will cause memory leak, convert to use ERR_PTR/PTR_ERR\nto pass the instance to callback so no memory needs to be allocated.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-53017"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/1ed8b37cbaf14574c779064ef1372af62e8ba6aa"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/8ac6043bd3e5b58d30f50737aedc2e58e8087ad5"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:51Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-xvxr-rrxw-rfp9/GHSA-xvxr-rrxw-rfp9.json b/advisories/unreviewed/2025/03/GHSA-xvxr-rrxw-rfp9/GHSA-xvxr-rrxw-rfp9.json
new file mode 100644
index 00000000000..49739c22d98
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-xvxr-rrxw-rfp9/GHSA-xvxr-rrxw-rfp9.json
@@ -0,0 +1,53 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-xvxr-rrxw-rfp9",
+ "modified": "2025-03-27T18:31:25Z",
+ "published": "2025-03-27T18:31:24Z",
+ "aliases": [
+ "CVE-2022-49757"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nEDAC/highbank: Fix memory leak in highbank_mc_probe()\n\nWhen devres_open_group() fails, it returns -ENOMEM without freeing memory\nallocated by edac_mc_alloc().\n\nCall edac_mc_free() on the error handling path to avoid a memory leak.\n\n [ bp: Massage commit message. ]",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49757"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/0db40e23b56d217eebd385bebb64057ef764b2c7"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/329fbd260352a7b9a83781d8b8bd96f95844a51f"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/8d23f5d25264beb223ee79cdb530b88c237719fc"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/b7863ef8a8f0fee96b4eb41211f4918c0e047253"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/caffa7fed1397d1395052272c93900176de86557"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/e7a293658c20a7945014570e1921bf7d25d68a36"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/f1b3e23ed8df87d779ee86ac37f379e79a24169a"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-27T17:15:40Z"
+ }
+}
\ No newline at end of file