From 2e3f63c319f732709c6c1cfdfb58023426e57c99 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Sat, 30 Nov 2024 03:33:30 +0000 Subject: [PATCH] Publish Advisories GHSA-2m53-6p59-jfh3 GHSA-cv39-r3v5-92vv --- .../GHSA-2m53-6p59-jfh3.json | 31 +++++++++++++++++++ .../GHSA-cv39-r3v5-92vv.json | 31 +++++++++++++++++++ 2 files changed, 62 insertions(+) create mode 100644 advisories/unreviewed/2024/11/GHSA-2m53-6p59-jfh3/GHSA-2m53-6p59-jfh3.json create mode 100644 advisories/unreviewed/2024/11/GHSA-cv39-r3v5-92vv/GHSA-cv39-r3v5-92vv.json diff --git a/advisories/unreviewed/2024/11/GHSA-2m53-6p59-jfh3/GHSA-2m53-6p59-jfh3.json b/advisories/unreviewed/2024/11/GHSA-2m53-6p59-jfh3/GHSA-2m53-6p59-jfh3.json new file mode 100644 index 00000000000..9432061b03e --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-2m53-6p59-jfh3/GHSA-2m53-6p59-jfh3.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2m53-6p59-jfh3", + "modified": "2024-11-30T03:32:09Z", + "published": "2024-11-30T03:32:09Z", + "aliases": [ + "CVE-2024-43702" + ], + "details": "Software installed and run as a non-privileged user may conduct improper GPU system calls to allow unprivileged access to arbitrary physical memory page.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43702" + }, + { + "type": "WEB", + "url": "https://www.imaginationtech.com/gpu-driver-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-280" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-30T03:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-cv39-r3v5-92vv/GHSA-cv39-r3v5-92vv.json b/advisories/unreviewed/2024/11/GHSA-cv39-r3v5-92vv/GHSA-cv39-r3v5-92vv.json new file mode 100644 index 00000000000..a09125edd29 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-cv39-r3v5-92vv/GHSA-cv39-r3v5-92vv.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cv39-r3v5-92vv", + "modified": "2024-11-30T03:32:09Z", + "published": "2024-11-30T03:32:09Z", + "aliases": [ + "CVE-2024-43703" + ], + "details": "Software installed and run as a non-privileged user may conduct improper GPU system calls to achieve unauthorised reads and writes of physical memory from the GPU HW.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43703" + }, + { + "type": "WEB", + "url": "https://www.imaginationtech.com/gpu-driver-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-30T03:15:14Z" + } +} \ No newline at end of file