diff --git a/advisories/unreviewed/2022/05/GHSA-537m-c5h3-whvr/GHSA-537m-c5h3-whvr.json b/advisories/unreviewed/2022/05/GHSA-537m-c5h3-whvr/GHSA-537m-c5h3-whvr.json index c37e34e8a19..b2c700366b0 100644 --- a/advisories/unreviewed/2022/05/GHSA-537m-c5h3-whvr/GHSA-537m-c5h3-whvr.json +++ b/advisories/unreviewed/2022/05/GHSA-537m-c5h3-whvr/GHSA-537m-c5h3-whvr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-537m-c5h3-whvr", - "modified": "2022-05-24T17:49:18Z", + "modified": "2024-09-06T15:32:54Z", "published": "2022-05-24T17:49:18Z", "aliases": [ "CVE-2020-24918" ], "details": "A buffer overflow in the RTSP service of the Ambarella Oryx RTSP Server 2020-01-07 allows an unauthenticated attacker to send a crafted RTSP request, with a long digest authentication header, to execute arbitrary code in parse_authentication_header() in libamprotocol-rtsp.so.1 in rtsp_svc (or cause a crash). This allows remote takeover of a Furbo Dog Camera, for example.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -18,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-24918" }, + { + "type": "WEB", + "url": "https://github.com/Ambarella-Inc/amba-cve-info/tree/main/cve-2020-24918" + }, { "type": "WEB", "url": "https://somersetrecon.squarespace.com/blog/2021/hacking-the-furbo-part-1" diff --git a/advisories/unreviewed/2023/11/GHSA-23qj-5qgc-98rc/GHSA-23qj-5qgc-98rc.json b/advisories/unreviewed/2023/11/GHSA-23qj-5qgc-98rc/GHSA-23qj-5qgc-98rc.json index b3b19afd900..52ab79fb230 100644 --- a/advisories/unreviewed/2023/11/GHSA-23qj-5qgc-98rc/GHSA-23qj-5qgc-98rc.json +++ b/advisories/unreviewed/2023/11/GHSA-23qj-5qgc-98rc/GHSA-23qj-5qgc-98rc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-23qj-5qgc-98rc", - "modified": "2023-11-13T21:30:56Z", + "modified": "2024-09-06T15:32:54Z", "published": "2023-11-03T06:36:30Z", "aliases": [ "CVE-2023-46817" diff --git a/advisories/unreviewed/2023/11/GHSA-4cc6-f2xj-w7jx/GHSA-4cc6-f2xj-w7jx.json b/advisories/unreviewed/2023/11/GHSA-4cc6-f2xj-w7jx/GHSA-4cc6-f2xj-w7jx.json index 38645331b8b..da9e7c5dc76 100644 --- a/advisories/unreviewed/2023/11/GHSA-4cc6-f2xj-w7jx/GHSA-4cc6-f2xj-w7jx.json +++ b/advisories/unreviewed/2023/11/GHSA-4cc6-f2xj-w7jx/GHSA-4cc6-f2xj-w7jx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4cc6-f2xj-w7jx", - "modified": "2023-11-13T15:30:20Z", + "modified": "2024-09-06T15:32:54Z", "published": "2023-11-03T06:36:29Z", "aliases": [ "CVE-2023-31102" diff --git a/advisories/unreviewed/2023/11/GHSA-55hr-9g5v-p4pg/GHSA-55hr-9g5v-p4pg.json b/advisories/unreviewed/2023/11/GHSA-55hr-9g5v-p4pg/GHSA-55hr-9g5v-p4pg.json index 581a19d90e4..afa9a2f7663 100644 --- a/advisories/unreviewed/2023/11/GHSA-55hr-9g5v-p4pg/GHSA-55hr-9g5v-p4pg.json +++ b/advisories/unreviewed/2023/11/GHSA-55hr-9g5v-p4pg/GHSA-55hr-9g5v-p4pg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-55hr-9g5v-p4pg", - "modified": "2023-11-13T18:30:58Z", + "modified": "2024-09-06T15:32:54Z", "published": "2023-11-03T18:30:23Z", "aliases": [ "CVE-2023-46404" @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/11/GHSA-95p4-xmxw-7258/GHSA-95p4-xmxw-7258.json b/advisories/unreviewed/2023/11/GHSA-95p4-xmxw-7258/GHSA-95p4-xmxw-7258.json index 12a3d1e4809..419f1a358b3 100644 --- a/advisories/unreviewed/2023/11/GHSA-95p4-xmxw-7258/GHSA-95p4-xmxw-7258.json +++ b/advisories/unreviewed/2023/11/GHSA-95p4-xmxw-7258/GHSA-95p4-xmxw-7258.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/11/GHSA-9xrr-x36v-8929/GHSA-9xrr-x36v-8929.json b/advisories/unreviewed/2023/11/GHSA-9xrr-x36v-8929/GHSA-9xrr-x36v-8929.json index 85daab86d9b..6d378e22b2c 100644 --- a/advisories/unreviewed/2023/11/GHSA-9xrr-x36v-8929/GHSA-9xrr-x36v-8929.json +++ b/advisories/unreviewed/2023/11/GHSA-9xrr-x36v-8929/GHSA-9xrr-x36v-8929.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/11/GHSA-hm7g-wj92-rj6w/GHSA-hm7g-wj92-rj6w.json b/advisories/unreviewed/2023/11/GHSA-hm7g-wj92-rj6w/GHSA-hm7g-wj92-rj6w.json index efbf2ac7c8b..e26c84c6b45 100644 --- a/advisories/unreviewed/2023/11/GHSA-hm7g-wj92-rj6w/GHSA-hm7g-wj92-rj6w.json +++ b/advisories/unreviewed/2023/11/GHSA-hm7g-wj92-rj6w/GHSA-hm7g-wj92-rj6w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hm7g-wj92-rj6w", - "modified": "2023-11-09T21:30:37Z", + "modified": "2024-09-06T15:32:54Z", "published": "2023-11-03T00:30:26Z", "aliases": [ "CVE-2023-46958" @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/11/GHSA-p7gf-g75v-jjv5/GHSA-p7gf-g75v-jjv5.json b/advisories/unreviewed/2023/11/GHSA-p7gf-g75v-jjv5/GHSA-p7gf-g75v-jjv5.json index 6d59f738fd6..6996dc7dba4 100644 --- a/advisories/unreviewed/2023/11/GHSA-p7gf-g75v-jjv5/GHSA-p7gf-g75v-jjv5.json +++ b/advisories/unreviewed/2023/11/GHSA-p7gf-g75v-jjv5/GHSA-p7gf-g75v-jjv5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p7gf-g75v-jjv5", - "modified": "2023-11-13T18:30:58Z", + "modified": "2024-09-06T15:32:54Z", "published": "2023-11-03T06:36:29Z", "aliases": [ "CVE-2023-34259" diff --git a/advisories/unreviewed/2024/02/GHSA-ffqq-vj92-hpx8/GHSA-ffqq-vj92-hpx8.json b/advisories/unreviewed/2024/02/GHSA-ffqq-vj92-hpx8/GHSA-ffqq-vj92-hpx8.json index fc357b07d41..963c4cf6568 100644 --- a/advisories/unreviewed/2024/02/GHSA-ffqq-vj92-hpx8/GHSA-ffqq-vj92-hpx8.json +++ b/advisories/unreviewed/2024/02/GHSA-ffqq-vj92-hpx8/GHSA-ffqq-vj92-hpx8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-ffqq-vj92-hpx8", - "modified": "2024-02-12T06:30:33Z", + "modified": "2024-09-06T15:32:55Z", "published": "2024-02-12T06:30:33Z", "aliases": [ "CVE-2024-25744" ], "details": "In the Linux kernel before 6.6.7, an untrusted VMM can trigger int80 syscall handling at any given point. This is related to arch/x86/coco/tdx/tdx.c and arch/x86/mm/mem_encrypt_amd.c.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-12T05:15:07Z" diff --git a/advisories/unreviewed/2024/02/GHSA-gpjf-f4mx-92px/GHSA-gpjf-f4mx-92px.json b/advisories/unreviewed/2024/02/GHSA-gpjf-f4mx-92px/GHSA-gpjf-f4mx-92px.json index 6873406fbb9..d0bfaa3461c 100644 --- a/advisories/unreviewed/2024/02/GHSA-gpjf-f4mx-92px/GHSA-gpjf-f4mx-92px.json +++ b/advisories/unreviewed/2024/02/GHSA-gpjf-f4mx-92px/GHSA-gpjf-f4mx-92px.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gpjf-f4mx-92px", - "modified": "2024-02-12T03:30:24Z", + "modified": "2024-09-06T15:32:55Z", "published": "2024-02-12T03:30:24Z", "aliases": [ "CVE-2024-25741" ], "details": "printer_write in drivers/usb/gadget/function/f_printer.c in the Linux kernel through 6.7.4 does not properly call usb_ep_queue, which might allow attackers to cause a denial of service or have unspecified other impact.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-12T03:15:32Z" diff --git a/advisories/unreviewed/2024/07/GHSA-fv42-492h-89pj/GHSA-fv42-492h-89pj.json b/advisories/unreviewed/2024/07/GHSA-fv42-492h-89pj/GHSA-fv42-492h-89pj.json index 69248f74dcb..d3e257683a4 100644 --- a/advisories/unreviewed/2024/07/GHSA-fv42-492h-89pj/GHSA-fv42-492h-89pj.json +++ b/advisories/unreviewed/2024/07/GHSA-fv42-492h-89pj/GHSA-fv42-492h-89pj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fv42-492h-89pj", - "modified": "2024-09-04T12:30:36Z", + "modified": "2024-09-06T15:32:55Z", "published": "2024-07-18T09:30:50Z", "aliases": [ "CVE-2024-41011" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdkfd: don't allow mapping the MMIO HDP page with large pages\n\nWe don't get the right offset in that case. The GPU has\nan unused 4K area of the register BAR space into which you can\nremap registers. We remap the HDP flush registers into this\nspace to allow userspace (CPU or GPU) to flush the HDP when it\nupdates VRAM. However, on systems with >4K pages, we end up\nexposing PAGE_SIZE of MMIO space.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -49,9 +52,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-682" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-18T07:15:02Z" diff --git a/advisories/unreviewed/2024/08/GHSA-26rc-mj52-pcf5/GHSA-26rc-mj52-pcf5.json b/advisories/unreviewed/2024/08/GHSA-26rc-mj52-pcf5/GHSA-26rc-mj52-pcf5.json index f810e102eba..de3509912ca 100644 --- a/advisories/unreviewed/2024/08/GHSA-26rc-mj52-pcf5/GHSA-26rc-mj52-pcf5.json +++ b/advisories/unreviewed/2024/08/GHSA-26rc-mj52-pcf5/GHSA-26rc-mj52-pcf5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-26rc-mj52-pcf5", - "modified": "2024-08-28T12:30:33Z", + "modified": "2024-09-06T15:32:56Z", "published": "2024-08-28T12:30:33Z", "aliases": [ "CVE-2024-6449" diff --git a/advisories/unreviewed/2024/08/GHSA-3j3g-6r9w-9pc8/GHSA-3j3g-6r9w-9pc8.json b/advisories/unreviewed/2024/08/GHSA-3j3g-6r9w-9pc8/GHSA-3j3g-6r9w-9pc8.json index 69c494563d5..f63c5acc1b3 100644 --- a/advisories/unreviewed/2024/08/GHSA-3j3g-6r9w-9pc8/GHSA-3j3g-6r9w-9pc8.json +++ b/advisories/unreviewed/2024/08/GHSA-3j3g-6r9w-9pc8/GHSA-3j3g-6r9w-9pc8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3j3g-6r9w-9pc8", - "modified": "2024-08-21T09:31:31Z", + "modified": "2024-09-06T15:32:56Z", "published": "2024-08-21T09:31:31Z", "aliases": [ "CVE-2022-48872" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmisc: fastrpc: Fix use-after-free race condition for maps\n\nIt is possible that in between calling fastrpc_map_get() until\nmap->fl->lock is taken in fastrpc_free_map(), another thread can call\nfastrpc_map_lookup() and get a reference to a map that is about to be\ndeleted.\n\nRewrite fastrpc_map_get() to only increase the reference count of a map\nif it's non-zero. Propagate this to callers so they can know if a map is\nabout to be deleted.\n\nFixes this warning:\nrefcount_t: addition on 0; use-after-free.\nWARNING: CPU: 5 PID: 10100 at lib/refcount.c:25 refcount_warn_saturate\n...\nCall trace:\n refcount_warn_saturate\n [fastrpc_map_get inlined]\n [fastrpc_map_lookup inlined]\n fastrpc_map_create\n fastrpc_internal_invoke\n fastrpc_device_ioctl\n __arm64_sys_ioctl\n invoke_syscall", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-21T07:15:04Z" diff --git a/advisories/unreviewed/2024/08/GHSA-4765-gch7-m8cw/GHSA-4765-gch7-m8cw.json b/advisories/unreviewed/2024/08/GHSA-4765-gch7-m8cw/GHSA-4765-gch7-m8cw.json index 8d3fb81bd73..c1e1b463eab 100644 --- a/advisories/unreviewed/2024/08/GHSA-4765-gch7-m8cw/GHSA-4765-gch7-m8cw.json +++ b/advisories/unreviewed/2024/08/GHSA-4765-gch7-m8cw/GHSA-4765-gch7-m8cw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4765-gch7-m8cw", - "modified": "2024-08-08T09:30:37Z", + "modified": "2024-09-06T15:32:55Z", "published": "2024-08-08T09:30:37Z", "aliases": [ "CVE-2024-42252" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nclosures: Change BUG_ON() to WARN_ON()\n\nIf a BUG_ON() can be hit in the wild, it shouldn't be a BUG_ON()\n\nFor reference, this has popped up once in the CI, and we'll need more\ninfo to debug it:\n\n03240 ------------[ cut here ]------------\n03240 kernel BUG at lib/closure.c:21!\n03240 kernel BUG at lib/closure.c:21!\n03240 Internal error: Oops - BUG: 00000000f2000800 [#1] SMP\n03240 Modules linked in:\n03240 CPU: 15 PID: 40534 Comm: kworker/u80:1 Not tainted 6.10.0-rc4-ktest-ga56da69799bd #25570\n03240 Hardware name: linux,dummy-virt (DT)\n03240 Workqueue: btree_update btree_interior_update_work\n03240 pstate: 00001005 (nzcv daif -PAN -UAO -TCO -DIT +SSBS BTYPE=--)\n03240 pc : closure_put+0x224/0x2a0\n03240 lr : closure_put+0x24/0x2a0\n03240 sp : ffff0000d12071c0\n03240 x29: ffff0000d12071c0 x28: dfff800000000000 x27: ffff0000d1207360\n03240 x26: 0000000000000040 x25: 0000000000000040 x24: 0000000000000040\n03240 x23: ffff0000c1f20180 x22: 0000000000000000 x21: ffff0000c1f20168\n03240 x20: 0000000040000000 x19: ffff0000c1f20140 x18: 0000000000000001\n03240 x17: 0000000000003aa0 x16: 0000000000003ad0 x15: 1fffe0001c326974\n03240 x14: 0000000000000a1e x13: 0000000000000000 x12: 1fffe000183e402d\n03240 x11: ffff6000183e402d x10: dfff800000000000 x9 : ffff6000183e402e\n03240 x8 : 0000000000000001 x7 : 00009fffe7c1bfd3 x6 : ffff0000c1f2016b\n03240 x5 : ffff0000c1f20168 x4 : ffff6000183e402e x3 : ffff800081391954\n03240 x2 : 0000000000000001 x1 : 0000000000000000 x0 : 00000000a8000000\n03240 Call trace:\n03240 closure_put+0x224/0x2a0\n03240 bch2_check_for_deadlock+0x910/0x1028\n03240 bch2_six_check_for_deadlock+0x1c/0x30\n03240 six_lock_slowpath.isra.0+0x29c/0xed0\n03240 six_lock_ip_waiter+0xa8/0xf8\n03240 __bch2_btree_node_lock_write+0x14c/0x298\n03240 bch2_trans_lock_write+0x6d4/0xb10\n03240 __bch2_trans_commit+0x135c/0x5520\n03240 btree_interior_update_work+0x1248/0x1c10\n03240 process_scheduled_works+0x53c/0xd90\n03240 worker_thread+0x370/0x8c8\n03240 kthread+0x258/0x2e8\n03240 ret_from_fork+0x10/0x20\n03240 Code: aa1303e0 d63f0020 a94363f7 17ffff8c (d4210000)\n03240 ---[ end trace 0000000000000000 ]---\n03240 Kernel panic - not syncing: Oops - BUG: Fatal exception\n03240 SMP: stopping secondary CPUs\n03241 SMP: failed to stop secondary CPUs 13,15\n03241 Kernel Offset: disabled\n03241 CPU features: 0x00,00000003,80000008,4240500b\n03241 Memory Limit: none\n03241 ---[ end Kernel panic - not syncing: Oops - BUG: Fatal exception ]---\n03246 ========= FAILED TIMEOUT copygc_torture_no_checksum in 7200s", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-617" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-08T09:15:08Z" diff --git a/advisories/unreviewed/2024/08/GHSA-5hgq-f2qx-82g9/GHSA-5hgq-f2qx-82g9.json b/advisories/unreviewed/2024/08/GHSA-5hgq-f2qx-82g9/GHSA-5hgq-f2qx-82g9.json index 341db35fd28..02091d80b4b 100644 --- a/advisories/unreviewed/2024/08/GHSA-5hgq-f2qx-82g9/GHSA-5hgq-f2qx-82g9.json +++ b/advisories/unreviewed/2024/08/GHSA-5hgq-f2qx-82g9/GHSA-5hgq-f2qx-82g9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5hgq-f2qx-82g9", - "modified": "2024-08-21T09:31:31Z", + "modified": "2024-09-06T15:32:56Z", "published": "2024-08-21T09:31:31Z", "aliases": [ "CVE-2022-48870" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntty: fix possible null-ptr-defer in spk_ttyio_release\n\nRun the following tests on the qemu platform:\n\nsyzkaller:~# modprobe speakup_audptr\n input: Speakup as /devices/virtual/input/input4\n initialized device: /dev/synth, node (MAJOR 10, MINOR 125)\n speakup 3.1.6: initialized\n synth name on entry is: (null)\n synth probe\n\nspk_ttyio_initialise_ldisc failed because tty_kopen_exclusive returned\nfailed (errno -16), then remove the module, we will get a null-ptr-defer\nproblem, as follow:\n\nsyzkaller:~# modprobe -r speakup_audptr\n releasing synth audptr\n BUG: kernel NULL pointer dereference, address: 0000000000000080\n #PF: supervisor write access in kernel mode\n #PF: error_code(0x0002) - not-present page\n PGD 0 P4D 0\n Oops: 0002 [#1] PREEMPT SMP PTI\n CPU: 2 PID: 204 Comm: modprobe Not tainted 6.1.0-rc6-dirty #1\n RIP: 0010:mutex_lock+0x14/0x30\n Call Trace:\n \n spk_ttyio_release+0x19/0x70 [speakup]\n synth_release.part.6+0xac/0xc0 [speakup]\n synth_remove+0x56/0x60 [speakup]\n __x64_sys_delete_module+0x156/0x250\n ? fpregs_assert_state_consistent+0x1d/0x50\n do_syscall_64+0x37/0x90\n entry_SYSCALL_64_after_hwframe+0x63/0xcd\n \n Modules linked in: speakup_audptr(-) speakup\n Dumping ftrace buffer:\n\nin_synth->dev was not initialized during modprobe, so we add check\nfor in_synth->dev to fix this bug.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-21T07:15:04Z" diff --git a/advisories/unreviewed/2024/08/GHSA-62gh-q5g8-jv59/GHSA-62gh-q5g8-jv59.json b/advisories/unreviewed/2024/08/GHSA-62gh-q5g8-jv59/GHSA-62gh-q5g8-jv59.json index 617930b07b3..77b8ca988b7 100644 --- a/advisories/unreviewed/2024/08/GHSA-62gh-q5g8-jv59/GHSA-62gh-q5g8-jv59.json +++ b/advisories/unreviewed/2024/08/GHSA-62gh-q5g8-jv59/GHSA-62gh-q5g8-jv59.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-601" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-7fhg-f25c-34r6/GHSA-7fhg-f25c-34r6.json b/advisories/unreviewed/2024/08/GHSA-7fhg-f25c-34r6/GHSA-7fhg-f25c-34r6.json index 58169924b97..6486a122533 100644 --- a/advisories/unreviewed/2024/08/GHSA-7fhg-f25c-34r6/GHSA-7fhg-f25c-34r6.json +++ b/advisories/unreviewed/2024/08/GHSA-7fhg-f25c-34r6/GHSA-7fhg-f25c-34r6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7fhg-f25c-34r6", - "modified": "2024-08-21T09:31:32Z", + "modified": "2024-09-06T15:32:56Z", "published": "2024-08-21T09:31:32Z", "aliases": [ "CVE-2022-48890" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: storvsc: Fix swiotlb bounce buffer leak in confidential VM\n\nstorvsc_queuecommand() maps the scatter/gather list using scsi_dma_map(),\nwhich in a confidential VM allocates swiotlb bounce buffers. If the I/O\nsubmission fails in storvsc_do_io(), the I/O is typically retried by higher\nlevel code, but the bounce buffer memory is never freed. The mostly like\ncause of I/O submission failure is a full VMBus channel ring buffer, which\nis not uncommon under high I/O loads. Eventually enough bounce buffer\nmemory leaks that the confidential VM can't do any I/O. The same problem\ncan arise in a non-confidential VM with kernel boot parameter\nswiotlb=force.\n\nFix this by doing scsi_dma_unmap() in the case of an I/O submission\nerror, which frees the bounce buffer memory.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-401" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-21T07:15:05Z" diff --git a/advisories/unreviewed/2024/08/GHSA-9c47-7pjp-gr57/GHSA-9c47-7pjp-gr57.json b/advisories/unreviewed/2024/08/GHSA-9c47-7pjp-gr57/GHSA-9c47-7pjp-gr57.json index 10da4737f15..ad65c1083e7 100644 --- a/advisories/unreviewed/2024/08/GHSA-9c47-7pjp-gr57/GHSA-9c47-7pjp-gr57.json +++ b/advisories/unreviewed/2024/08/GHSA-9c47-7pjp-gr57/GHSA-9c47-7pjp-gr57.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9c47-7pjp-gr57", - "modified": "2024-08-28T12:30:33Z", + "modified": "2024-09-06T15:32:56Z", "published": "2024-08-28T12:30:33Z", "aliases": [ "CVE-2024-6450" diff --git a/advisories/unreviewed/2024/08/GHSA-9mmm-86g7-vp9g/GHSA-9mmm-86g7-vp9g.json b/advisories/unreviewed/2024/08/GHSA-9mmm-86g7-vp9g/GHSA-9mmm-86g7-vp9g.json index 0af9b85f384..576bb7f4ca8 100644 --- a/advisories/unreviewed/2024/08/GHSA-9mmm-86g7-vp9g/GHSA-9mmm-86g7-vp9g.json +++ b/advisories/unreviewed/2024/08/GHSA-9mmm-86g7-vp9g/GHSA-9mmm-86g7-vp9g.json @@ -36,6 +36,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-494", "CWE-94" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2024/08/GHSA-cchp-c7c7-jf58/GHSA-cchp-c7c7-jf58.json b/advisories/unreviewed/2024/08/GHSA-cchp-c7c7-jf58/GHSA-cchp-c7c7-jf58.json index 114c9829863..6926248f1ba 100644 --- a/advisories/unreviewed/2024/08/GHSA-cchp-c7c7-jf58/GHSA-cchp-c7c7-jf58.json +++ b/advisories/unreviewed/2024/08/GHSA-cchp-c7c7-jf58/GHSA-cchp-c7c7-jf58.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cchp-c7c7-jf58", - "modified": "2024-08-07T21:31:48Z", + "modified": "2024-09-06T15:32:55Z", "published": "2024-08-07T21:31:48Z", "aliases": [ "CVE-2024-41912" ], "details": "A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The firmware flaw does not properly implement access controls.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-07T20:15:50Z" diff --git a/advisories/unreviewed/2024/08/GHSA-cfrr-p6rw-prf5/GHSA-cfrr-p6rw-prf5.json b/advisories/unreviewed/2024/08/GHSA-cfrr-p6rw-prf5/GHSA-cfrr-p6rw-prf5.json index 42c70a83b48..5354a2ec8d7 100644 --- a/advisories/unreviewed/2024/08/GHSA-cfrr-p6rw-prf5/GHSA-cfrr-p6rw-prf5.json +++ b/advisories/unreviewed/2024/08/GHSA-cfrr-p6rw-prf5/GHSA-cfrr-p6rw-prf5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cfrr-p6rw-prf5", - "modified": "2024-08-21T09:31:31Z", + "modified": "2024-09-06T15:32:56Z", "published": "2024-08-21T09:31:31Z", "aliases": [ "CVE-2022-48867" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: idxd: Prevent use after free on completion memory\n\nOn driver unload any pending descriptors are flushed at the\ntime the interrupt is freed:\nidxd_dmaengine_drv_remove() ->\n\tdrv_disable_wq() ->\n\t\tidxd_wq_free_irq() ->\n\t\t\tidxd_flush_pending_descs().\n\nIf there are any descriptors present that need to be flushed this\nflow triggers a \"not present\" page fault as below:\n\n BUG: unable to handle page fault for address: ff391c97c70c9040\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\n\nThe address that triggers the fault is the address of the\ndescriptor that was freed moments earlier via:\ndrv_disable_wq()->idxd_wq_free_resources()\n\nFix the use after free by freeing the descriptors after any possible\nusage. This is done after idxd_wq_reset() to ensure that the memory\nremains accessible during possible completion writes by the device.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-21T07:15:03Z" diff --git a/advisories/unreviewed/2024/08/GHSA-cvqf-8622-79m2/GHSA-cvqf-8622-79m2.json b/advisories/unreviewed/2024/08/GHSA-cvqf-8622-79m2/GHSA-cvqf-8622-79m2.json index 0a113434731..a5a277016c8 100644 --- a/advisories/unreviewed/2024/08/GHSA-cvqf-8622-79m2/GHSA-cvqf-8622-79m2.json +++ b/advisories/unreviewed/2024/08/GHSA-cvqf-8622-79m2/GHSA-cvqf-8622-79m2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cvqf-8622-79m2", - "modified": "2024-08-21T09:31:31Z", + "modified": "2024-09-06T15:32:56Z", "published": "2024-08-21T09:31:31Z", "aliases": [ "CVE-2022-48869" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: gadgetfs: Fix race between mounting and unmounting\n\nThe syzbot fuzzer and Gerald Lee have identified a use-after-free bug\nin the gadgetfs driver, involving processes concurrently mounting and\nunmounting the gadgetfs filesystem. In particular, gadgetfs_fill_super()\ncan race with gadgetfs_kill_sb(), causing the latter to deallocate\nthe_device while the former is using it. The output from KASAN says,\nin part:\n\nBUG: KASAN: use-after-free in instrument_atomic_read_write include/linux/instrumented.h:102 [inline]\nBUG: KASAN: use-after-free in atomic_fetch_sub_release include/linux/atomic/atomic-instrumented.h:176 [inline]\nBUG: KASAN: use-after-free in __refcount_sub_and_test include/linux/refcount.h:272 [inline]\nBUG: KASAN: use-after-free in __refcount_dec_and_test include/linux/refcount.h:315 [inline]\nBUG: KASAN: use-after-free in refcount_dec_and_test include/linux/refcount.h:333 [inline]\nBUG: KASAN: use-after-free in put_dev drivers/usb/gadget/legacy/inode.c:159 [inline]\nBUG: KASAN: use-after-free in gadgetfs_kill_sb+0x33/0x100 drivers/usb/gadget/legacy/inode.c:2086\nWrite of size 4 at addr ffff8880276d7840 by task syz-executor126/18689\n\nCPU: 0 PID: 18689 Comm: syz-executor126 Not tainted 6.1.0-syzkaller #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/26/2022\nCall Trace:\n \n...\n atomic_fetch_sub_release include/linux/atomic/atomic-instrumented.h:176 [inline]\n __refcount_sub_and_test include/linux/refcount.h:272 [inline]\n __refcount_dec_and_test include/linux/refcount.h:315 [inline]\n refcount_dec_and_test include/linux/refcount.h:333 [inline]\n put_dev drivers/usb/gadget/legacy/inode.c:159 [inline]\n gadgetfs_kill_sb+0x33/0x100 drivers/usb/gadget/legacy/inode.c:2086\n deactivate_locked_super+0xa7/0xf0 fs/super.c:332\n vfs_get_super fs/super.c:1190 [inline]\n get_tree_single+0xd0/0x160 fs/super.c:1207\n vfs_get_tree+0x88/0x270 fs/super.c:1531\n vfs_fsconfig_locked fs/fsopen.c:232 [inline]\n\nThe simplest solution is to ensure that gadgetfs_fill_super() and\ngadgetfs_kill_sb() are serialized by making them both acquire a new\nmutex.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-21T07:15:04Z" diff --git a/advisories/unreviewed/2024/08/GHSA-gr3w-p7mm-8pcq/GHSA-gr3w-p7mm-8pcq.json b/advisories/unreviewed/2024/08/GHSA-gr3w-p7mm-8pcq/GHSA-gr3w-p7mm-8pcq.json index c19f65d8246..6ebb6cd3eac 100644 --- a/advisories/unreviewed/2024/08/GHSA-gr3w-p7mm-8pcq/GHSA-gr3w-p7mm-8pcq.json +++ b/advisories/unreviewed/2024/08/GHSA-gr3w-p7mm-8pcq/GHSA-gr3w-p7mm-8pcq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gr3w-p7mm-8pcq", - "modified": "2024-08-08T09:30:37Z", + "modified": "2024-09-06T15:32:55Z", "published": "2024-08-08T09:30:37Z", "aliases": [ "CVE-2024-42253" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ngpio: pca953x: fix pca953x_irq_bus_sync_unlock race\n\nEnsure that `i2c_lock' is held when setting interrupt latch and mask in\npca953x_irq_bus_sync_unlock() in order to avoid races.\n\nThe other (non-probe) call site pca953x_gpio_set_multiple() ensures the\nlock is held before calling pca953x_write_regs().\n\nThe problem occurred when a request raced against irq_bus_sync_unlock()\napproximately once per thousand reboots on an i.MX8MP based system.\n\n * Normal case\n\n 0-0022: write register AI|3a {03,02,00,00,01} Input latch P0\n 0-0022: write register AI|49 {fc,fd,ff,ff,fe} Interrupt mask P0\n 0-0022: write register AI|08 {ff,00,00,00,00} Output P3\n 0-0022: write register AI|12 {fc,00,00,00,00} Config P3\n\n * Race case\n\n 0-0022: write register AI|08 {ff,00,00,00,00} Output P3\n 0-0022: write register AI|08 {03,02,00,00,01} *** Wrong register ***\n 0-0022: write register AI|12 {fc,00,00,00,00} Config P3\n 0-0022: write register AI|49 {fc,fd,ff,ff,fe} Interrupt mask P0", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-667" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-08T09:15:08Z" diff --git a/advisories/unreviewed/2024/08/GHSA-hq8p-jq83-pjp2/GHSA-hq8p-jq83-pjp2.json b/advisories/unreviewed/2024/08/GHSA-hq8p-jq83-pjp2/GHSA-hq8p-jq83-pjp2.json index 26629e60b86..3da35951355 100644 --- a/advisories/unreviewed/2024/08/GHSA-hq8p-jq83-pjp2/GHSA-hq8p-jq83-pjp2.json +++ b/advisories/unreviewed/2024/08/GHSA-hq8p-jq83-pjp2/GHSA-hq8p-jq83-pjp2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hq8p-jq83-pjp2", - "modified": "2024-08-21T09:31:31Z", + "modified": "2024-09-06T15:32:56Z", "published": "2024-08-21T09:31:31Z", "aliases": [ "CVE-2022-48871" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntty: serial: qcom-geni-serial: fix slab-out-of-bounds on RX FIFO buffer\n\nDriver's probe allocates memory for RX FIFO (port->rx_fifo) based on\ndefault RX FIFO depth, e.g. 16. Later during serial startup the\nqcom_geni_serial_port_setup() updates the RX FIFO depth\n(port->rx_fifo_depth) to match real device capabilities, e.g. to 32.\n\nThe RX UART handle code will read \"port->rx_fifo_depth\" number of words\ninto \"port->rx_fifo\" buffer, thus exceeding the bounds. This can be\nobserved in certain configurations with Qualcomm Bluetooth HCI UART\ndevice and KASAN:\n\n Bluetooth: hci0: QCA Product ID :0x00000010\n Bluetooth: hci0: QCA SOC Version :0x400a0200\n Bluetooth: hci0: QCA ROM Version :0x00000200\n Bluetooth: hci0: QCA Patch Version:0x00000d2b\n Bluetooth: hci0: QCA controller version 0x02000200\n Bluetooth: hci0: QCA Downloading qca/htbtfw20.tlv\n bluetooth hci0: Direct firmware load for qca/htbtfw20.tlv failed with error -2\n Bluetooth: hci0: QCA Failed to request file: qca/htbtfw20.tlv (-2)\n Bluetooth: hci0: QCA Failed to download patch (-2)\n ==================================================================\n BUG: KASAN: slab-out-of-bounds in handle_rx_uart+0xa8/0x18c\n Write of size 4 at addr ffff279347d578c0 by task swapper/0/0\n\n CPU: 0 PID: 0 Comm: swapper/0 Not tainted 6.1.0-rt5-00350-gb2450b7e00be-dirty #26\n Hardware name: Qualcomm Technologies, Inc. Robotics RB5 (DT)\n Call trace:\n dump_backtrace.part.0+0xe0/0xf0\n show_stack+0x18/0x40\n dump_stack_lvl+0x8c/0xb8\n print_report+0x188/0x488\n kasan_report+0xb4/0x100\n __asan_store4+0x80/0xa4\n handle_rx_uart+0xa8/0x18c\n qcom_geni_serial_handle_rx+0x84/0x9c\n qcom_geni_serial_isr+0x24c/0x760\n __handle_irq_event_percpu+0x108/0x500\n handle_irq_event+0x6c/0x110\n handle_fasteoi_irq+0x138/0x2cc\n generic_handle_domain_irq+0x48/0x64\n\nIf the RX FIFO depth changes after probe, be sure to resize the buffer.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-21T07:15:04Z" diff --git a/advisories/unreviewed/2024/08/GHSA-j2cv-6c69-ccm5/GHSA-j2cv-6c69-ccm5.json b/advisories/unreviewed/2024/08/GHSA-j2cv-6c69-ccm5/GHSA-j2cv-6c69-ccm5.json index cf5f6bc0073..3046975eaeb 100644 --- a/advisories/unreviewed/2024/08/GHSA-j2cv-6c69-ccm5/GHSA-j2cv-6c69-ccm5.json +++ b/advisories/unreviewed/2024/08/GHSA-j2cv-6c69-ccm5/GHSA-j2cv-6c69-ccm5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j2cv-6c69-ccm5", - "modified": "2024-08-21T09:31:31Z", + "modified": "2024-09-06T15:32:56Z", "published": "2024-08-21T09:31:31Z", "aliases": [ "CVE-2022-48873" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmisc: fastrpc: Don't remove map on creater_process and device_release\n\nDo not remove the map from the list on error path in\nfastrpc_init_create_process, instead call fastrpc_map_put, to avoid\nuse-after-free. Do not remove it on fastrpc_device_release either,\ncall fastrpc_map_put instead.\n\nThe fastrpc_free_map is the only proper place to remove the map.\nThis is called only after the reference count is 0.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-21T07:15:04Z" diff --git a/advisories/unreviewed/2024/08/GHSA-j5gm-gf6p-7hpm/GHSA-j5gm-gf6p-7hpm.json b/advisories/unreviewed/2024/08/GHSA-j5gm-gf6p-7hpm/GHSA-j5gm-gf6p-7hpm.json index f599563b1a0..665166764ab 100644 --- a/advisories/unreviewed/2024/08/GHSA-j5gm-gf6p-7hpm/GHSA-j5gm-gf6p-7hpm.json +++ b/advisories/unreviewed/2024/08/GHSA-j5gm-gf6p-7hpm/GHSA-j5gm-gf6p-7hpm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j5gm-gf6p-7hpm", - "modified": "2024-08-08T09:30:37Z", + "modified": "2024-09-06T15:32:56Z", "published": "2024-08-08T09:30:37Z", "aliases": [ "CVE-2024-42255" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntpm: Use auth only after NULL check in tpm_buf_check_hmac_response()\n\nDereference auth after NULL check in tpm_buf_check_hmac_response().\nOtherwise, unless tpm2_sessions_init() was called, a call can cause NULL\ndereference, when TCG_TPM2_HMAC is enabled.\n\n[jarkko: adjusted the commit message.]", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-08T09:15:08Z" diff --git a/advisories/unreviewed/2024/08/GHSA-jrcf-gr4j-p9gp/GHSA-jrcf-gr4j-p9gp.json b/advisories/unreviewed/2024/08/GHSA-jrcf-gr4j-p9gp/GHSA-jrcf-gr4j-p9gp.json index 25440ba5685..3643bdb7c89 100644 --- a/advisories/unreviewed/2024/08/GHSA-jrcf-gr4j-p9gp/GHSA-jrcf-gr4j-p9gp.json +++ b/advisories/unreviewed/2024/08/GHSA-jrcf-gr4j-p9gp/GHSA-jrcf-gr4j-p9gp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jrcf-gr4j-p9gp", - "modified": "2024-08-08T09:30:37Z", + "modified": "2024-09-06T15:32:56Z", "published": "2024-08-08T09:30:37Z", "aliases": [ "CVE-2024-42256" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncifs: Fix server re-repick on subrequest retry\n\nWhen a subrequest is marked for needing retry, netfs will call\ncifs_prepare_write() which will make cifs repick the server for the op\nbefore renegotiating credits; it then calls cifs_issue_write() which\ninvokes smb2_async_writev() - which re-repicks the server.\n\nIf a different server is then selected, this causes the increment of\nserver->in_flight to happen against one record and the decrement to happen\nagainst another, leading to misaccounting.\n\nFix this by just removing the repick code in smb2_async_writev(). As this\nis only called from netfslib-driven code, cifs_prepare_write() should\nalways have been called first, and so server should never be NULL and the\npreparatory step is repeated in the event that we do a retry.\n\nThe problem manifests as a warning looking something like:\n\n WARNING: CPU: 4 PID: 72896 at fs/smb/client/smb2ops.c:97 smb2_add_credits+0x3f0/0x9e0 [cifs]\n ...\n RIP: 0010:smb2_add_credits+0x3f0/0x9e0 [cifs]\n ...\n smb2_writev_callback+0x334/0x560 [cifs]\n cifs_demultiplex_thread+0x77a/0x11b0 [cifs]\n kthread+0x187/0x1d0\n ret_from_fork+0x34/0x60\n ret_from_fork_asm+0x1a/0x30\n\nWhich may be triggered by a number of different xfstests running against an\nAzure server in multichannel mode. generic/249 seems the most repeatable,\nbut generic/215, generic/249 and generic/308 may also show it.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-08T09:15:08Z" diff --git a/advisories/unreviewed/2024/08/GHSA-p744-9p3j-x3vr/GHSA-p744-9p3j-x3vr.json b/advisories/unreviewed/2024/08/GHSA-p744-9p3j-x3vr/GHSA-p744-9p3j-x3vr.json index 36309171fcf..d5479c87cd4 100644 --- a/advisories/unreviewed/2024/08/GHSA-p744-9p3j-x3vr/GHSA-p744-9p3j-x3vr.json +++ b/advisories/unreviewed/2024/08/GHSA-p744-9p3j-x3vr/GHSA-p744-9p3j-x3vr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p744-9p3j-x3vr", - "modified": "2024-08-08T09:30:37Z", + "modified": "2024-09-06T15:32:55Z", "published": "2024-08-08T09:30:37Z", "aliases": [ "CVE-2024-42251" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm: page_ref: remove folio_try_get_rcu()\n\nThe below bug was reported on a non-SMP kernel:\n\n[ 275.267158][ T4335] ------------[ cut here ]------------\n[ 275.267949][ T4335] kernel BUG at include/linux/page_ref.h:275!\n[ 275.268526][ T4335] invalid opcode: 0000 [#1] KASAN PTI\n[ 275.269001][ T4335] CPU: 0 PID: 4335 Comm: trinity-c3 Not tainted 6.7.0-rc4-00061-gefa7df3e3bb5 #1\n[ 275.269787][ T4335] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.2-debian-1.16.2-1 04/01/2014\n[ 275.270679][ T4335] RIP: 0010:try_get_folio (include/linux/page_ref.h:275 (discriminator 3) mm/gup.c:79 (discriminator 3))\n[ 275.272813][ T4335] RSP: 0018:ffffc90005dcf650 EFLAGS: 00010202\n[ 275.273346][ T4335] RAX: 0000000000000246 RBX: ffffea00066e0000 RCX: 0000000000000000\n[ 275.274032][ T4335] RDX: fffff94000cdc007 RSI: 0000000000000004 RDI: ffffea00066e0034\n[ 275.274719][ T4335] RBP: ffffea00066e0000 R08: 0000000000000000 R09: fffff94000cdc006\n[ 275.275404][ T4335] R10: ffffea00066e0037 R11: 0000000000000000 R12: 0000000000000136\n[ 275.276106][ T4335] R13: ffffea00066e0034 R14: dffffc0000000000 R15: ffffea00066e0008\n[ 275.276790][ T4335] FS: 00007fa2f9b61740(0000) GS:ffffffff89d0d000(0000) knlGS:0000000000000000\n[ 275.277570][ T4335] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 275.278143][ T4335] CR2: 00007fa2f6c00000 CR3: 0000000134b04000 CR4: 00000000000406f0\n[ 275.278833][ T4335] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n[ 275.279521][ T4335] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n[ 275.280201][ T4335] Call Trace:\n[ 275.280499][ T4335] \n[ 275.280751][ T4335] ? die (arch/x86/kernel/dumpstack.c:421 arch/x86/kernel/dumpstack.c:434 arch/x86/kernel/dumpstack.c:447)\n[ 275.281087][ T4335] ? do_trap (arch/x86/kernel/traps.c:112 arch/x86/kernel/traps.c:153)\n[ 275.281463][ T4335] ? try_get_folio (include/linux/page_ref.h:275 (discriminator 3) mm/gup.c:79 (discriminator 3))\n[ 275.281884][ T4335] ? try_get_folio (include/linux/page_ref.h:275 (discriminator 3) mm/gup.c:79 (discriminator 3))\n[ 275.282300][ T4335] ? do_error_trap (arch/x86/kernel/traps.c:174)\n[ 275.282711][ T4335] ? try_get_folio (include/linux/page_ref.h:275 (discriminator 3) mm/gup.c:79 (discriminator 3))\n[ 275.283129][ T4335] ? handle_invalid_op (arch/x86/kernel/traps.c:212)\n[ 275.283561][ T4335] ? try_get_folio (include/linux/page_ref.h:275 (discriminator 3) mm/gup.c:79 (discriminator 3))\n[ 275.283990][ T4335] ? exc_invalid_op (arch/x86/kernel/traps.c:264)\n[ 275.284415][ T4335] ? asm_exc_invalid_op (arch/x86/include/asm/idtentry.h:568)\n[ 275.284859][ T4335] ? try_get_folio (include/linux/page_ref.h:275 (discriminator 3) mm/gup.c:79 (discriminator 3))\n[ 275.285278][ T4335] try_grab_folio (mm/gup.c:148)\n[ 275.285684][ T4335] __get_user_pages (mm/gup.c:1297 (discriminator 1))\n[ 275.286111][ T4335] ? __pfx___get_user_pages (mm/gup.c:1188)\n[ 275.286579][ T4335] ? __pfx_validate_chain (kernel/locking/lockdep.c:3825)\n[ 275.287034][ T4335] ? mark_lock (kernel/locking/lockdep.c:4656 (discriminator 1))\n[ 275.287416][ T4335] __gup_longterm_locked (mm/gup.c:1509 mm/gup.c:2209)\n[ 275.288192][ T4335] ? __pfx___gup_longterm_locked (mm/gup.c:2204)\n[ 275.288697][ T4335] ? __pfx_lock_acquire (kernel/locking/lockdep.c:5722)\n[ 275.289135][ T4335] ? __pfx___might_resched (kernel/sched/core.c:10106)\n[ 275.289595][ T4335] pin_user_pages_remote (mm/gup.c:3350)\n[ 275.290041][ T4335] ? __pfx_pin_user_pages_remote (mm/gup.c:3350)\n[ 275.290545][ T4335] ? find_held_lock (kernel/locking/lockdep.c:5244 (discriminator 1))\n[ 275.290961][ T4335] ? mm_access (kernel/fork.c:1573)\n[ 275.291353][ T4335] process_vm_rw_single_vec+0x142/0x360\n[ 275.291900][ T4335] ? __pfx_process_vm_rw_single_vec+0x10/0x10\n[ 275.292471][ T4335] ? mm_access (kernel/fork.c:1573)\n[ 275.292859][ T4335] process_vm_rw_core+0x272/0x4e0\n[ 275.293384][ T4335] ? hlock_class (a\n---truncated---", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-617" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-08T09:15:08Z" diff --git a/advisories/unreviewed/2024/08/GHSA-p8rw-v5c5-234r/GHSA-p8rw-v5c5-234r.json b/advisories/unreviewed/2024/08/GHSA-p8rw-v5c5-234r/GHSA-p8rw-v5c5-234r.json index ab3acc5751b..771222df5ac 100644 --- a/advisories/unreviewed/2024/08/GHSA-p8rw-v5c5-234r/GHSA-p8rw-v5c5-234r.json +++ b/advisories/unreviewed/2024/08/GHSA-p8rw-v5c5-234r/GHSA-p8rw-v5c5-234r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p8rw-v5c5-234r", - "modified": "2024-08-21T09:31:32Z", + "modified": "2024-09-06T15:32:56Z", "published": "2024-08-21T09:31:32Z", "aliases": [ "CVE-2022-48886" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nice: Add check for kzalloc\n\nAdd the check for the return value of kzalloc in order to avoid\nNULL pointer dereference.\nMoreover, use the goto-label to share the clean code.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-21T07:15:05Z" diff --git a/advisories/unreviewed/2024/08/GHSA-pj8g-xgcw-9p63/GHSA-pj8g-xgcw-9p63.json b/advisories/unreviewed/2024/08/GHSA-pj8g-xgcw-9p63/GHSA-pj8g-xgcw-9p63.json index 1b4d561b307..6dcbfdc34f3 100644 --- a/advisories/unreviewed/2024/08/GHSA-pj8g-xgcw-9p63/GHSA-pj8g-xgcw-9p63.json +++ b/advisories/unreviewed/2024/08/GHSA-pj8g-xgcw-9p63/GHSA-pj8g-xgcw-9p63.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pj8g-xgcw-9p63", - "modified": "2024-08-08T09:30:37Z", + "modified": "2024-09-06T15:32:55Z", "published": "2024-08-08T09:30:37Z", "aliases": [ "CVE-2024-42254" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nio_uring: fix error pbuf checking\n\nSyz reports a problem, which boils down to NULL vs IS_ERR inconsistent\nerror handling in io_alloc_pbuf_ring().\n\nKASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]\nRIP: 0010:__io_remove_buffers+0xac/0x700 io_uring/kbuf.c:341\nCall Trace:\n \n io_put_bl io_uring/kbuf.c:378 [inline]\n io_destroy_buffers+0x14e/0x490 io_uring/kbuf.c:392\n io_ring_ctx_free+0xa00/0x1070 io_uring/io_uring.c:2613\n io_ring_exit_work+0x80f/0x8a0 io_uring/io_uring.c:2844\n process_one_work kernel/workqueue.c:3231 [inline]\n process_scheduled_works+0xa2c/0x1830 kernel/workqueue.c:3312\n worker_thread+0x86d/0xd40 kernel/workqueue.c:3390\n kthread+0x2f0/0x390 kernel/kthread.c:389\n ret_from_fork+0x4b/0x80 arch/x86/kernel/process.c:147\n ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:244", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-08T09:15:08Z" diff --git a/advisories/unreviewed/2024/08/GHSA-rc9q-9gjh-f3q6/GHSA-rc9q-9gjh-f3q6.json b/advisories/unreviewed/2024/08/GHSA-rc9q-9gjh-f3q6/GHSA-rc9q-9gjh-f3q6.json index 8108d48a2af..8b30f50e7ca 100644 --- a/advisories/unreviewed/2024/08/GHSA-rc9q-9gjh-f3q6/GHSA-rc9q-9gjh-f3q6.json +++ b/advisories/unreviewed/2024/08/GHSA-rc9q-9gjh-f3q6/GHSA-rc9q-9gjh-f3q6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rc9q-9gjh-f3q6", - "modified": "2024-08-21T09:31:31Z", + "modified": "2024-09-06T15:32:56Z", "published": "2024-08-21T09:31:31Z", "aliases": [ "CVE-2022-48885" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nice: Fix potential memory leak in ice_gnss_tty_write()\n\nThe ice_gnss_tty_write() return directly if the write_buf alloc failed,\nleaking the cmd_buf.\n\nFix by free cmd_buf if write_buf alloc failed.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-401" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-21T07:15:05Z" diff --git a/advisories/unreviewed/2024/08/GHSA-rfpq-wmg2-4ww7/GHSA-rfpq-wmg2-4ww7.json b/advisories/unreviewed/2024/08/GHSA-rfpq-wmg2-4ww7/GHSA-rfpq-wmg2-4ww7.json index d56ddaf4eaf..516d2314e5a 100644 --- a/advisories/unreviewed/2024/08/GHSA-rfpq-wmg2-4ww7/GHSA-rfpq-wmg2-4ww7.json +++ b/advisories/unreviewed/2024/08/GHSA-rfpq-wmg2-4ww7/GHSA-rfpq-wmg2-4ww7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rfpq-wmg2-4ww7", - "modified": "2024-08-21T09:31:31Z", + "modified": "2024-09-06T15:32:56Z", "published": "2024-08-21T09:31:31Z", "aliases": [ "CVE-2022-48889" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: Intel: sof-nau8825: fix module alias overflow\n\nThe maximum name length for a platform_device_id entry is 20 characters\nincluding the trailing NUL byte. The sof_nau8825.c file exceeds that,\nwhich causes an obscure error message:\n\nsound/soc/intel/boards/snd-soc-sof_nau8825.mod.c:35:45: error: illegal character encoding in string literal [-Werror,-Winvalid-source-encoding]\nMODULE_ALIAS(\"platform:adl_max98373_nau8825\");\n ^~~~\ninclude/linux/module.h:168:49: note: expanded from macro 'MODULE_ALIAS'\n ^~~~~~\ninclude/linux/module.h:165:56: note: expanded from macro 'MODULE_INFO'\n ^~~~\ninclude/linux/moduleparam.h:26:47: note: expanded from macro '__MODULE_INFO'\n = __MODULE_INFO_PREFIX __stringify(tag) \"=\" info\n\nI could not figure out how to make the module handling robust enough\nto handle this better, but as a quick fix, using slightly shorter\nnames that are still unique avoids the build issue.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-131" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-21T07:15:05Z" diff --git a/advisories/unreviewed/2024/08/GHSA-w8v8-pp27-rwcg/GHSA-w8v8-pp27-rwcg.json b/advisories/unreviewed/2024/08/GHSA-w8v8-pp27-rwcg/GHSA-w8v8-pp27-rwcg.json index 0b3992d35da..15777c6040e 100644 --- a/advisories/unreviewed/2024/08/GHSA-w8v8-pp27-rwcg/GHSA-w8v8-pp27-rwcg.json +++ b/advisories/unreviewed/2024/08/GHSA-w8v8-pp27-rwcg/GHSA-w8v8-pp27-rwcg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w8v8-pp27-rwcg", - "modified": "2024-08-21T09:31:32Z", + "modified": "2024-09-06T15:32:56Z", "published": "2024-08-21T09:31:31Z", "aliases": [ "CVE-2022-48887" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/vmwgfx: Remove rcu locks from user resources\n\nUser resource lookups used rcu to avoid two extra atomics. Unfortunately\nthe rcu paths were buggy and it was easy to make the driver crash by\nsubmitting command buffers from two different threads. Because the\nlookups never show up in performance profiles replace them with a\nregular spin lock which fixes the races in accesses to those shared\nresources.\n\nFixes kernel oops'es in IGT's vmwgfx execution_buffer stress test and\nseen crashes with apps using shared resources.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-21T07:15:05Z" diff --git a/advisories/unreviewed/2024/08/GHSA-xc8j-8q2q-h32f/GHSA-xc8j-8q2q-h32f.json b/advisories/unreviewed/2024/08/GHSA-xc8j-8q2q-h32f/GHSA-xc8j-8q2q-h32f.json index dc136670133..fddf35dd9dd 100644 --- a/advisories/unreviewed/2024/08/GHSA-xc8j-8q2q-h32f/GHSA-xc8j-8q2q-h32f.json +++ b/advisories/unreviewed/2024/08/GHSA-xc8j-8q2q-h32f/GHSA-xc8j-8q2q-h32f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xc8j-8q2q-h32f", - "modified": "2024-08-08T09:30:37Z", + "modified": "2024-09-06T15:32:56Z", "published": "2024-08-08T09:30:37Z", "aliases": [ "CVE-2024-42257" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\next4: use memtostr_pad() for s_volume_name\n\nAs with the other strings in struct ext4_super_block, s_volume_name is\nnot NUL terminated. The other strings were marked in commit 072ebb3bffe6\n(\"ext4: add nonstring annotations to ext4.h\"). Using strscpy() isn't\nthe right replacement for strncpy(); it should use memtostr_pad()\ninstead.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-08T09:15:08Z" diff --git a/advisories/unreviewed/2024/09/GHSA-36pg-hxf8-378v/GHSA-36pg-hxf8-378v.json b/advisories/unreviewed/2024/09/GHSA-36pg-hxf8-378v/GHSA-36pg-hxf8-378v.json new file mode 100644 index 00000000000..5497b764f30 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-36pg-hxf8-378v/GHSA-36pg-hxf8-378v.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-36pg-hxf8-378v", + "modified": "2024-09-06T15:32:59Z", + "published": "2024-09-06T15:32:59Z", + "aliases": [ + "CVE-2024-7599" + ], + "details": "The Advanced Sermons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘sermon_video_embed’ parameter in all versions up to, and including, 3.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7599" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/advanced-sermons/trunk/admin/meta/sermon-details.php#L396" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/advanced-sermons/trunk/include/templates/sections/video-template.php#L124" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/advanced-sermons/trunk/include/templates/sections/video-template.php#L18" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3147283" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/41859e1c-1ae0-49f1-82d3-5af3c15994ef?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-06T14:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-3rx7-fmcf-hpgr/GHSA-3rx7-fmcf-hpgr.json b/advisories/unreviewed/2024/09/GHSA-3rx7-fmcf-hpgr/GHSA-3rx7-fmcf-hpgr.json new file mode 100644 index 00000000000..53d228f0a95 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-3rx7-fmcf-hpgr/GHSA-3rx7-fmcf-hpgr.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3rx7-fmcf-hpgr", + "modified": "2024-09-06T15:32:59Z", + "published": "2024-09-06T15:32:59Z", + "aliases": [ + "CVE-2024-6445" + ], + "details": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in DataFlowX Technology DataDiodeX allows Path Traversal.This issue affects DataDiodeX: before v3.5.0.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6445" + }, + { + "type": "WEB", + "url": "https://www.usom.gov.tr/bildirim/tr-24-1409" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-06T14:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-5q69-34vj-qhx4/GHSA-5q69-34vj-qhx4.json b/advisories/unreviewed/2024/09/GHSA-5q69-34vj-qhx4/GHSA-5q69-34vj-qhx4.json index 4a52eb88fde..56edc1a2ed9 100644 --- a/advisories/unreviewed/2024/09/GHSA-5q69-34vj-qhx4/GHSA-5q69-34vj-qhx4.json +++ b/advisories/unreviewed/2024/09/GHSA-5q69-34vj-qhx4/GHSA-5q69-34vj-qhx4.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-436", "CWE-650" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/09/GHSA-8m2f-286x-6p4c/GHSA-8m2f-286x-6p4c.json b/advisories/unreviewed/2024/09/GHSA-8m2f-286x-6p4c/GHSA-8m2f-286x-6p4c.json new file mode 100644 index 00000000000..dff62030d99 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-8m2f-286x-6p4c/GHSA-8m2f-286x-6p4c.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8m2f-286x-6p4c", + "modified": "2024-09-06T15:32:59Z", + "published": "2024-09-06T15:32:59Z", + "aliases": [ + "CVE-2024-7622" + ], + "details": "The Revision Manager TMC plugin for WordPress is vulnerable to unauthorized arbitrary email sending due to a missing capability check on the _a_ajaxQuickEmailTestCallback() function in all versions up to, and including, 2.8.19. This makes it possible for authenticated attackers, with subscriber-level access and above, to send emails with arbitrary content to any individual through the vulnerable web server.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7622" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/revision-manager-tmc/trunk/src/Components/Notifications.php#L357" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3147298" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/2c8a6ff9-6aa8-4e0f-b058-759561a55508?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-06T14:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-94pj-f953-73h5/GHSA-94pj-f953-73h5.json b/advisories/unreviewed/2024/09/GHSA-94pj-f953-73h5/GHSA-94pj-f953-73h5.json new file mode 100644 index 00000000000..b77707ca16a --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-94pj-f953-73h5/GHSA-94pj-f953-73h5.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-94pj-f953-73h5", + "modified": "2024-09-06T15:32:59Z", + "published": "2024-09-06T15:32:59Z", + "aliases": [ + "CVE-2024-7611" + ], + "details": "The Enter Addons – Ultimate Template Builder for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' attribute of the Events Card widget in all versions up to, and including, 2.1.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7611" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/enteraddons/trunk/widgets/events_card/traits/Templates_Components.php#L25" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/f7580145-03da-4aff-b804-39125e7daad1?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-06T14:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-cc7f-7qrj-r4v2/GHSA-cc7f-7qrj-r4v2.json b/advisories/unreviewed/2024/09/GHSA-cc7f-7qrj-r4v2/GHSA-cc7f-7qrj-r4v2.json new file mode 100644 index 00000000000..88baf4312c7 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-cc7f-7qrj-r4v2/GHSA-cc7f-7qrj-r4v2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cc7f-7qrj-r4v2", + "modified": "2024-09-06T15:32:58Z", + "published": "2024-09-06T15:32:58Z", + "aliases": [ + "CVE-2024-1744" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ariva Computer Accord ORS allows Retrieve Embedded Sensitive Data.This issue affects Accord ORS: before 7.3.2.1.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1744" + }, + { + "type": "WEB", + "url": "https://www.usom.gov.tr/bildirim/tr-24-1408" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-06T13:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-fx63-vgj4-88r8/GHSA-fx63-vgj4-88r8.json b/advisories/unreviewed/2024/09/GHSA-fx63-vgj4-88r8/GHSA-fx63-vgj4-88r8.json new file mode 100644 index 00000000000..6ed9eacedc0 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-fx63-vgj4-88r8/GHSA-fx63-vgj4-88r8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fx63-vgj4-88r8", + "modified": "2024-09-06T15:32:59Z", + "published": "2024-09-06T15:32:59Z", + "aliases": [ + "CVE-2024-25584" + ], + "details": "Dovecot accepts dot LF DOT LF symbol as end of DATA command. RFC requires that it should always be CR LF DOT CR LF. This causes Dovecot to convert single mail with LF DOT LF in middle, into two emails when relaying to SMTP. Dovecot will split mail with LF DOT LF into two mails. Upgrade to latest released version. No publicly available exploits are known.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25584" + }, + { + "type": "WEB", + "url": "https://documentation.open-xchange.com/dovecot/security/advisories/csaf/2024/oxdc-adv-2024-0001.json" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-345" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-06T15:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-h2c8-c64m-w4qp/GHSA-h2c8-c64m-w4qp.json b/advisories/unreviewed/2024/09/GHSA-h2c8-c64m-w4qp/GHSA-h2c8-c64m-w4qp.json index df6bfeeca01..8ba9f76e8c5 100644 --- a/advisories/unreviewed/2024/09/GHSA-h2c8-c64m-w4qp/GHSA-h2c8-c64m-w4qp.json +++ b/advisories/unreviewed/2024/09/GHSA-h2c8-c64m-w4qp/GHSA-h2c8-c64m-w4qp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h2c8-c64m-w4qp", - "modified": "2024-09-06T06:31:41Z", + "modified": "2024-09-06T15:32:58Z", "published": "2024-09-06T06:31:41Z", "aliases": [ "CVE-2024-6792" ], "details": "The WP ULike WordPress plugin before 4.7.2.1 does not properly sanitize user display names when rendering on a public page.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-09-06T06:15:02Z" diff --git a/advisories/unreviewed/2024/09/GHSA-m899-p55c-35f9/GHSA-m899-p55c-35f9.json b/advisories/unreviewed/2024/09/GHSA-m899-p55c-35f9/GHSA-m899-p55c-35f9.json new file mode 100644 index 00000000000..4d8b6c65eec --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-m899-p55c-35f9/GHSA-m899-p55c-35f9.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m899-p55c-35f9", + "modified": "2024-09-06T15:32:58Z", + "published": "2024-09-06T15:32:58Z", + "aliases": [ + "CVE-2024-44739" + ], + "details": "Sourcecodester Simple Forum Website v1.0 has a SQL injection vulnerability in /php-sqlite-forum/?page=manage_user&id=.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44739" + }, + { + "type": "WEB", + "url": "https://github.com/zach341/Cve_report/blob/main/simple-forum-website/SQLi-1.md" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-06T13:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-q5h4-2jhc-x7wp/GHSA-q5h4-2jhc-x7wp.json b/advisories/unreviewed/2024/09/GHSA-q5h4-2jhc-x7wp/GHSA-q5h4-2jhc-x7wp.json index 901c2bde959..1fc52f4e5f3 100644 --- a/advisories/unreviewed/2024/09/GHSA-q5h4-2jhc-x7wp/GHSA-q5h4-2jhc-x7wp.json +++ b/advisories/unreviewed/2024/09/GHSA-q5h4-2jhc-x7wp/GHSA-q5h4-2jhc-x7wp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q5h4-2jhc-x7wp", - "modified": "2024-09-04T03:30:45Z", + "modified": "2024-09-06T15:32:57Z", "published": "2024-09-04T03:30:45Z", "aliases": [ "CVE-2024-8298" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8298" }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2024/9" + }, { "type": "WEB", "url": "https://https://consumer.huawei.com/en/support/bulletin/2024/9" diff --git a/advisories/unreviewed/2024/09/GHSA-qcf5-7mv4-v635/GHSA-qcf5-7mv4-v635.json b/advisories/unreviewed/2024/09/GHSA-qcf5-7mv4-v635/GHSA-qcf5-7mv4-v635.json new file mode 100644 index 00000000000..247863bf05b --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-qcf5-7mv4-v635/GHSA-qcf5-7mv4-v635.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qcf5-7mv4-v635", + "modified": "2024-09-06T15:32:59Z", + "published": "2024-09-06T15:32:59Z", + "aliases": [ + "CVE-2024-7493" + ], + "details": "The WPCOM Member plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.5.2.1. This is due to the plugin allowing arbitrary data to be passed to wp_insert_user() during registration. This makes it possible for unauthenticated attackers to update their role to that of an administrator during registration.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7493" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wpcom-member/tags/1.5.2/includes/form-validation.php#L267" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/ec7f3e0c-a07c-4082-9b6b-12d0fbe0fdc8?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-06T14:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-vxpg-8v7f-78w3/GHSA-vxpg-8v7f-78w3.json b/advisories/unreviewed/2024/09/GHSA-vxpg-8v7f-78w3/GHSA-vxpg-8v7f-78w3.json new file mode 100644 index 00000000000..06928614634 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-vxpg-8v7f-78w3/GHSA-vxpg-8v7f-78w3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vxpg-8v7f-78w3", + "modified": "2024-09-06T15:32:59Z", + "published": "2024-09-06T15:32:59Z", + "aliases": [ + "CVE-2024-44837" + ], + "details": "A cross-site scripting (XSS) vulnerability in the component \\bean\\Manager.java of Drug v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the user parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-44837" + }, + { + "type": "WEB", + "url": "https://kaput-raptorex-7c1.notion.site/drug-1-0-DOM-based-cross-site-scripting-fae620f769304f67a7488a961d048672" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-06T14:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-ww5m-q9hx-hcf2/GHSA-ww5m-q9hx-hcf2.json b/advisories/unreviewed/2024/09/GHSA-ww5m-q9hx-hcf2/GHSA-ww5m-q9hx-hcf2.json new file mode 100644 index 00000000000..cfb79174c66 --- /dev/null +++ b/advisories/unreviewed/2024/09/GHSA-ww5m-q9hx-hcf2/GHSA-ww5m-q9hx-hcf2.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ww5m-q9hx-hcf2", + "modified": "2024-09-06T15:32:59Z", + "published": "2024-09-06T15:32:59Z", + "aliases": [ + "CVE-2024-8428" + ], + "details": "The ForumWP – Forum & Discussion Board Plugin plugin for WordPress is vulnerable to Privilege Escalation via Insecure Direct Object Reference in all versions up to, and including, 2.0.2 via the submit_form_handler due to missing validation on the 'user_id' user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to change the email address of administrative user accounts which can then be leveraged to reset the administrative users password and gain access to their account.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8428" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/forumwp/trunk/includes/frontend/class-actions-listener.php#L179" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/b5818587-0a52-4734-8f75-263b4ab5020e?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-09-06T14:15:13Z" + } +} \ No newline at end of file