Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2024-09-06 15:34:42 +00:00
parent 21be351a6a
commit 33caebca3b
47 changed files with 595 additions and 100 deletions
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-537m-c5h3-whvr",
"modified": "2022-05-24T17:49:18Z",
"modified": "2024-09-06T15:32:54Z",
"published": "2022-05-24T17:49:18Z",
"aliases": [
"CVE-2020-24918"
],
"details": "A buffer overflow in the RTSP service of the Ambarella Oryx RTSP Server 2020-01-07 allows an unauthenticated attacker to send a crafted RTSP request, with a long digest authentication header, to execute arbitrary code in parse_authentication_header() in libamprotocol-rtsp.so.1 in rtsp_svc (or cause a crash). This allows remote takeover of a Furbo Dog Camera, for example.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -18,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2020-24918"
},
{
"type": "WEB",
"url": "https://github.com/Ambarella-Inc/amba-cve-info/tree/main/cve-2020-24918"
},
{
"type": "WEB",
"url": "https://somersetrecon.squarespace.com/blog/2021/hacking-the-furbo-part-1"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-23qj-5qgc-98rc",
"modified": "2023-11-13T21:30:56Z",
"modified": "2024-09-06T15:32:54Z",
"published": "2023-11-03T06:36:30Z",
"aliases": [
"CVE-2023-46817"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4cc6-f2xj-w7jx",
"modified": "2023-11-13T15:30:20Z",
"modified": "2024-09-06T15:32:54Z",
"published": "2023-11-03T06:36:29Z",
"aliases": [
"CVE-2023-31102"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-55hr-9g5v-p4pg",
"modified": "2023-11-13T18:30:58Z",
"modified": "2024-09-06T15:32:54Z",
"published": "2023-11-03T18:30:23Z",
"aliases": [
"CVE-2023-46404"
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-94"
],
"severity": "CRITICAL",
"github_reviewed": false,
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-94"
],
"severity": "CRITICAL",
"github_reviewed": false,
@@ -32,7 +32,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-200"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hm7g-wj92-rj6w",
"modified": "2023-11-09T21:30:37Z",
"modified": "2024-09-06T15:32:54Z",
"published": "2023-11-03T00:30:26Z",
"aliases": [
"CVE-2023-46958"
@@ -36,7 +36,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-94"
],
"severity": "CRITICAL",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p7gf-g75v-jjv5",
"modified": "2023-11-13T18:30:58Z",
"modified": "2024-09-06T15:32:54Z",
"published": "2023-11-03T06:36:29Z",
"aliases": [
"CVE-2023-34259"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-ffqq-vj92-hpx8",
"modified": "2024-02-12T06:30:33Z",
"modified": "2024-09-06T15:32:55Z",
"published": "2024-02-12T06:30:33Z",
"aliases": [
"CVE-2024-25744"
],
"details": "In the Linux kernel before 6.6.7, an untrusted VMM can trigger int80 syscall handling at any given point. This is related to arch/x86/coco/tdx/tdx.c and arch/x86/mm/mem_encrypt_amd.c.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
}
],
"affected": [
@@ -31,7 +34,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-12T05:15:07Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gpjf-f4mx-92px",
"modified": "2024-02-12T03:30:24Z",
"modified": "2024-09-06T15:32:55Z",
"published": "2024-02-12T03:30:24Z",
"aliases": [
"CVE-2024-25741"
],
"details": "printer_write in drivers/usb/gadget/function/f_printer.c in the Linux kernel through 6.7.4 does not properly call usb_ep_queue, which might allow attackers to cause a denial of service or have unspecified other impact.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-12T03:15:32Z"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fv42-492h-89pj",
"modified": "2024-09-04T12:30:36Z",
"modified": "2024-09-06T15:32:55Z",
"published": "2024-07-18T09:30:50Z",
"aliases": [
"CVE-2024-41011"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdkfd: don't allow mapping the MMIO HDP page with large pages\n\nWe don't get the right offset in that case. The GPU has\nan unused 4K area of the register BAR space into which you can\nremap registers. We remap the HDP flush registers into this\nspace to allow userspace (CPU or GPU) to flush the HDP when it\nupdates VRAM. However, on systems with >4K pages, we end up\nexposing PAGE_SIZE of MMIO space.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -49,9 +52,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-682"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-18T07:15:02Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-26rc-mj52-pcf5",
"modified": "2024-08-28T12:30:33Z",
"modified": "2024-09-06T15:32:56Z",
"published": "2024-08-28T12:30:33Z",
"aliases": [
"CVE-2024-6449"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3j3g-6r9w-9pc8",
"modified": "2024-08-21T09:31:31Z",
"modified": "2024-09-06T15:32:56Z",
"published": "2024-08-21T09:31:31Z",
"aliases": [
"CVE-2022-48872"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmisc: fastrpc: Fix use-after-free race condition for maps\n\nIt is possible that in between calling fastrpc_map_get() until\nmap->fl->lock is taken in fastrpc_free_map(), another thread can call\nfastrpc_map_lookup() and get a reference to a map that is about to be\ndeleted.\n\nRewrite fastrpc_map_get() to only increase the reference count of a map\nif it's non-zero. Propagate this to callers so they can know if a map is\nabout to be deleted.\n\nFixes this warning:\nrefcount_t: addition on 0; use-after-free.\nWARNING: CPU: 5 PID: 10100 at lib/refcount.c:25 refcount_warn_saturate\n...\nCall trace:\n refcount_warn_saturate\n [fastrpc_map_get inlined]\n [fastrpc_map_lookup inlined]\n fastrpc_map_create\n fastrpc_internal_invoke\n fastrpc_device_ioctl\n __arm64_sys_ioctl\n invoke_syscall",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -41,9 +44,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-416"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-21T07:15:04Z"
File diff suppressed because one or more lines are too long
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5hgq-f2qx-82g9",
"modified": "2024-08-21T09:31:31Z",
"modified": "2024-09-06T15:32:56Z",
"published": "2024-08-21T09:31:31Z",
"aliases": [
"CVE-2022-48870"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntty: fix possible null-ptr-defer in spk_ttyio_release\n\nRun the following tests on the qemu platform:\n\nsyzkaller:~# modprobe speakup_audptr\n input: Speakup as /devices/virtual/input/input4\n initialized device: /dev/synth, node (MAJOR 10, MINOR 125)\n speakup 3.1.6: initialized\n synth name on entry is: (null)\n synth probe\n\nspk_ttyio_initialise_ldisc failed because tty_kopen_exclusive returned\nfailed (errno -16), then remove the module, we will get a null-ptr-defer\nproblem, as follow:\n\nsyzkaller:~# modprobe -r speakup_audptr\n releasing synth audptr\n BUG: kernel NULL pointer dereference, address: 0000000000000080\n #PF: supervisor write access in kernel mode\n #PF: error_code(0x0002) - not-present page\n PGD 0 P4D 0\n Oops: 0002 [#1] PREEMPT SMP PTI\n CPU: 2 PID: 204 Comm: modprobe Not tainted 6.1.0-rc6-dirty #1\n RIP: 0010:mutex_lock+0x14/0x30\n Call Trace:\n <TASK>\n spk_ttyio_release+0x19/0x70 [speakup]\n synth_release.part.6+0xac/0xc0 [speakup]\n synth_remove+0x56/0x60 [speakup]\n __x64_sys_delete_module+0x156/0x250\n ? fpregs_assert_state_consistent+0x1d/0x50\n do_syscall_64+0x37/0x90\n entry_SYSCALL_64_after_hwframe+0x63/0xcd\n </TASK>\n Modules linked in: speakup_audptr(-) speakup\n Dumping ftrace buffer:\n\nin_synth->dev was not initialized during modprobe, so we add check\nfor in_synth->dev to fix this bug.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
@@ -33,9 +36,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-476"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-21T07:15:04Z"
@@ -28,7 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-601"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7fhg-f25c-34r6",
"modified": "2024-08-21T09:31:32Z",
"modified": "2024-09-06T15:32:56Z",
"published": "2024-08-21T09:31:32Z",
"aliases": [
"CVE-2022-48890"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: storvsc: Fix swiotlb bounce buffer leak in confidential VM\n\nstorvsc_queuecommand() maps the scatter/gather list using scsi_dma_map(),\nwhich in a confidential VM allocates swiotlb bounce buffers. If the I/O\nsubmission fails in storvsc_do_io(), the I/O is typically retried by higher\nlevel code, but the bounce buffer memory is never freed. The mostly like\ncause of I/O submission failure is a full VMBus channel ring buffer, which\nis not uncommon under high I/O loads. Eventually enough bounce buffer\nmemory leaks that the confidential VM can't do any I/O. The same problem\ncan arise in a non-confidential VM with kernel boot parameter\nswiotlb=force.\n\nFix this by doing scsi_dma_unmap() in the case of an I/O submission\nerror, which frees the bounce buffer memory.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
@@ -29,9 +32,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-401"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-21T07:15:05Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9c47-7pjp-gr57",
"modified": "2024-08-28T12:30:33Z",
"modified": "2024-09-06T15:32:56Z",
"published": "2024-08-28T12:30:33Z",
"aliases": [
"CVE-2024-6450"
@@ -36,6 +36,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-494",
"CWE-94"
],
"severity": "CRITICAL",
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cchp-c7c7-jf58",
"modified": "2024-08-07T21:31:48Z",
"modified": "2024-09-06T15:32:55Z",
"published": "2024-08-07T21:31:48Z",
"aliases": [
"CVE-2024-41912"
],
"details": "A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The firmware flaw does not properly implement access controls.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -27,7 +30,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-07T20:15:50Z"

Some files were not shown because too many files have changed in this diff Show More