From 34d751bb93a3704f0e72f2b25a0d2368d9b46e5c Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 3 Feb 2025 12:32:04 +0000 Subject: [PATCH] Publish Advisories GHSA-wwr4-cj7g-985f GHSA-qfc2-wxrw-h7h2 GHSA-x2mw-9w7g-6qh6 --- .../GHSA-wwr4-cj7g-985f.json | 6 +++- .../GHSA-qfc2-wxrw-h7h2.json | 31 +++++++++++++++++++ .../GHSA-x2mw-9w7g-6qh6.json | 31 +++++++++++++++++++ 3 files changed, 67 insertions(+), 1 deletion(-) create mode 100644 advisories/unreviewed/2025/02/GHSA-qfc2-wxrw-h7h2/GHSA-qfc2-wxrw-h7h2.json create mode 100644 advisories/unreviewed/2025/02/GHSA-x2mw-9w7g-6qh6/GHSA-x2mw-9w7g-6qh6.json diff --git a/advisories/unreviewed/2025/01/GHSA-wwr4-cj7g-985f/GHSA-wwr4-cj7g-985f.json b/advisories/unreviewed/2025/01/GHSA-wwr4-cj7g-985f/GHSA-wwr4-cj7g-985f.json index 866155a1493..2499b1220c2 100644 --- a/advisories/unreviewed/2025/01/GHSA-wwr4-cj7g-985f/GHSA-wwr4-cj7g-985f.json +++ b/advisories/unreviewed/2025/01/GHSA-wwr4-cj7g-985f/GHSA-wwr4-cj7g-985f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wwr4-cj7g-985f", - "modified": "2025-01-17T00:30:48Z", + "modified": "2025-02-03T12:30:59Z", "published": "2025-01-15T06:30:49Z", "aliases": [ "CVE-2025-23013" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23013" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2025/02/msg00001.html" + }, { "type": "WEB", "url": "https://www.yubico.com/support/security-advisories/ysa-2025-01" diff --git a/advisories/unreviewed/2025/02/GHSA-qfc2-wxrw-h7h2/GHSA-qfc2-wxrw-h7h2.json b/advisories/unreviewed/2025/02/GHSA-qfc2-wxrw-h7h2/GHSA-qfc2-wxrw-h7h2.json new file mode 100644 index 00000000000..c6def246da4 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-qfc2-wxrw-h7h2/GHSA-qfc2-wxrw-h7h2.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qfc2-wxrw-h7h2", + "modified": "2025-02-03T12:31:00Z", + "published": "2025-02-03T12:31:00Z", + "aliases": [ + "CVE-2025-0015" + ], + "details": "Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user process to make improper GPU processing operations to gain access to already freed memory.This issue affects Valhall GPU Kernel Driver: from r48p0 through r49p1, from r50p0 through r52p0; Arm 5th Gen GPU Architecture Kernel Driver: from r48p0 through r49p1, from r50p0 through r52p0.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0015" + }, + { + "type": "WEB", + "url": "https://developer.arm.com/Arm%20Security%20Center/Mali%20GPU%20Driver%20Vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-03T11:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-x2mw-9w7g-6qh6/GHSA-x2mw-9w7g-6qh6.json b/advisories/unreviewed/2025/02/GHSA-x2mw-9w7g-6qh6/GHSA-x2mw-9w7g-6qh6.json new file mode 100644 index 00000000000..cbaf6a4a036 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-x2mw-9w7g-6qh6/GHSA-x2mw-9w7g-6qh6.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x2mw-9w7g-6qh6", + "modified": "2025-02-03T12:31:00Z", + "published": "2025-02-03T12:31:00Z", + "aliases": [ + "CVE-2024-6790" + ], + "details": "Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a non-privileged user process to make valid GPU memory processing operations, including via WebGL or WebGPU, to cause the whole system to become unresponsive.This issue affects Bifrost GPU Kernel Driver: r44p1, from r46p0 through r49p0, from r50p0 through r51p0; Valhall GPU Kernel Driver: r44p1, from r46p0 through r49p0, from r50p0 through r51p0; Arm 5th Gen GPU Architecture Kernel Driver: r44p1, from r46p0 through r49p0, from r50p0 through r51p0.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6790" + }, + { + "type": "WEB", + "url": "https://developer.arm.com/Arm%20Security%20Center/Mali%20GPU%20Driver%20Vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-835" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-03T11:15:09Z" + } +} \ No newline at end of file