diff --git a/advisories/unreviewed/2024/02/GHSA-7x96-4hxq-29v4/GHSA-7x96-4hxq-29v4.json b/advisories/unreviewed/2024/02/GHSA-7x96-4hxq-29v4/GHSA-7x96-4hxq-29v4.json index 34aeea3be97..6e09cd3c461 100644 --- a/advisories/unreviewed/2024/02/GHSA-7x96-4hxq-29v4/GHSA-7x96-4hxq-29v4.json +++ b/advisories/unreviewed/2024/02/GHSA-7x96-4hxq-29v4/GHSA-7x96-4hxq-29v4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7x96-4hxq-29v4", - "modified": "2024-02-16T00:30:28Z", + "modified": "2024-10-31T15:30:55Z", "published": "2024-02-16T00:30:28Z", "aliases": [ "CVE-2023-40112" ], "details": "In ippSetValueTag of ipp.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure of past print jobs or other print-related information, with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-15T23:15:08Z" diff --git a/advisories/unreviewed/2024/03/GHSA-7359-w9jh-qr2r/GHSA-7359-w9jh-qr2r.json b/advisories/unreviewed/2024/03/GHSA-7359-w9jh-qr2r/GHSA-7359-w9jh-qr2r.json index d7ad85b50d3..d0d14e763b0 100644 --- a/advisories/unreviewed/2024/03/GHSA-7359-w9jh-qr2r/GHSA-7359-w9jh-qr2r.json +++ b/advisories/unreviewed/2024/03/GHSA-7359-w9jh-qr2r/GHSA-7359-w9jh-qr2r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7359-w9jh-qr2r", - "modified": "2024-03-21T15:31:55Z", + "modified": "2024-10-31T15:30:57Z", "published": "2024-03-21T15:31:55Z", "aliases": [ "CVE-2024-2465" ], "details": "Open redirection vulnerability in CDeX application allows to redirect users to arbitrary websites via a specially crafted URL.This issue affects CDeX application versions through 5.7.1.\n\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ "CWE-601" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-21T15:16:54Z" diff --git a/advisories/unreviewed/2024/03/GHSA-97gj-q9fx-vc88/GHSA-97gj-q9fx-vc88.json b/advisories/unreviewed/2024/03/GHSA-97gj-q9fx-vc88/GHSA-97gj-q9fx-vc88.json index 95e897c2cd9..1395e033e5d 100644 --- a/advisories/unreviewed/2024/03/GHSA-97gj-q9fx-vc88/GHSA-97gj-q9fx-vc88.json +++ b/advisories/unreviewed/2024/03/GHSA-97gj-q9fx-vc88/GHSA-97gj-q9fx-vc88.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-97gj-q9fx-vc88", - "modified": "2024-03-04T18:30:38Z", + "modified": "2024-10-31T15:30:57Z", "published": "2024-03-04T18:30:37Z", "aliases": [ "CVE-2021-47089" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nkfence: fix memory leak when cat kfence objects\n\nHulk robot reported a kmemleak problem:\n\n unreferenced object 0xffff93d1d8cc02e8 (size 248):\n comm \"cat\", pid 23327, jiffies 4624670141 (age 495992.217s)\n hex dump (first 32 bytes):\n 00 40 85 19 d4 93 ff ff 00 10 00 00 00 00 00 00 .@..............\n 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n backtrace:\n seq_open+0x2a/0x80\n full_proxy_open+0x167/0x1e0\n do_dentry_open+0x1e1/0x3a0\n path_openat+0x961/0xa20\n do_filp_open+0xae/0x120\n do_sys_openat2+0x216/0x2f0\n do_sys_open+0x57/0x80\n do_syscall_64+0x33/0x40\n entry_SYSCALL_64_after_hwframe+0x44/0xa9\n unreferenced object 0xffff93d419854000 (size 4096):\n comm \"cat\", pid 23327, jiffies 4624670141 (age 495992.217s)\n hex dump (first 32 bytes):\n 6b 66 65 6e 63 65 2d 23 32 35 30 3a 20 30 78 30 kfence-#250: 0x0\n 30 30 30 30 30 30 30 37 35 34 62 64 61 31 32 2d 0000000754bda12-\n backtrace:\n seq_read_iter+0x313/0x440\n seq_read+0x14b/0x1a0\n full_proxy_read+0x56/0x80\n vfs_read+0xa5/0x1b0\n ksys_read+0xa0/0xf0\n do_syscall_64+0x33/0x40\n entry_SYSCALL_64_after_hwframe+0x44/0xa9\n\nI find that we can easily reproduce this problem with the following\ncommands:\n\n\tcat /sys/kernel/debug/kfence/objects\n\techo scan > /sys/kernel/debug/kmemleak\n\tcat /sys/kernel/debug/kmemleak\n\nThe leaked memory is allocated in the stack below:\n\n do_syscall_64\n do_sys_open\n do_dentry_open\n full_proxy_open\n seq_open ---> alloc seq_file\n vfs_read\n full_proxy_read\n seq_read\n seq_read_iter\n traverse ---> alloc seq_buf\n\nAnd it should have been released in the following process:\n\n do_syscall_64\n syscall_exit_to_user_mode\n exit_to_user_mode_prepare\n task_work_run\n ____fput\n __fput\n full_proxy_release ---> free here\n\nHowever, the release function corresponding to file_operations is not\nimplemented in kfence. As a result, a memory leak occurs. Therefore,\nthe solution to this problem is to implement the corresponding release\nfunction.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-04T18:15:07Z" diff --git a/advisories/unreviewed/2024/04/GHSA-8qv9-vpw9-7q8x/GHSA-8qv9-vpw9-7q8x.json b/advisories/unreviewed/2024/04/GHSA-8qv9-vpw9-7q8x/GHSA-8qv9-vpw9-7q8x.json index fed34f2037d..962e4d462f0 100644 --- a/advisories/unreviewed/2024/04/GHSA-8qv9-vpw9-7q8x/GHSA-8qv9-vpw9-7q8x.json +++ b/advisories/unreviewed/2024/04/GHSA-8qv9-vpw9-7q8x/GHSA-8qv9-vpw9-7q8x.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-fjfc-48h7-67x9/GHSA-fjfc-48h7-67x9.json b/advisories/unreviewed/2024/04/GHSA-fjfc-48h7-67x9/GHSA-fjfc-48h7-67x9.json index daa04430aa8..2ec0cc21bbf 100644 --- a/advisories/unreviewed/2024/04/GHSA-fjfc-48h7-67x9/GHSA-fjfc-48h7-67x9.json +++ b/advisories/unreviewed/2024/04/GHSA-fjfc-48h7-67x9/GHSA-fjfc-48h7-67x9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fjfc-48h7-67x9", - "modified": "2024-04-03T09:30:33Z", + "modified": "2024-10-31T15:30:57Z", "published": "2024-04-03T09:30:33Z", "aliases": [ "CVE-2024-29734" ], "details": "Uncontrolled search path element issue exists in SonicDICOM Media Viewer 2.3.2 and earlier, which may lead to insecurely loading Dynamic Link Libraries. As a result, arbitrary code may be executed with the privileges of the running application.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-427" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T08:15:49Z" diff --git a/advisories/unreviewed/2024/04/GHSA-h345-j35x-7hc5/GHSA-h345-j35x-7hc5.json b/advisories/unreviewed/2024/04/GHSA-h345-j35x-7hc5/GHSA-h345-j35x-7hc5.json index 279a06eb5cb..ac9c1828598 100644 --- a/advisories/unreviewed/2024/04/GHSA-h345-j35x-7hc5/GHSA-h345-j35x-7hc5.json +++ b/advisories/unreviewed/2024/04/GHSA-h345-j35x-7hc5/GHSA-h345-j35x-7hc5.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-vmh5-6rg4-ggmq/GHSA-vmh5-6rg4-ggmq.json b/advisories/unreviewed/2024/04/GHSA-vmh5-6rg4-ggmq/GHSA-vmh5-6rg4-ggmq.json index a1d9b7497c1..92efda19a3e 100644 --- a/advisories/unreviewed/2024/04/GHSA-vmh5-6rg4-ggmq/GHSA-vmh5-6rg4-ggmq.json +++ b/advisories/unreviewed/2024/04/GHSA-vmh5-6rg4-ggmq/GHSA-vmh5-6rg4-ggmq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vmh5-6rg4-ggmq", - "modified": "2024-06-27T12:30:44Z", + "modified": "2024-10-31T15:30:57Z", "published": "2024-04-03T18:30:41Z", "aliases": [ "CVE-2024-26735" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: sr: fix possible use-after-free and null-ptr-deref\n\nThe pernet operations structure for the subsystem must be registered\nbefore registering the generic netlink family.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -61,9 +64,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T17:15:51Z" diff --git a/advisories/unreviewed/2024/05/GHSA-5f9p-9995-r2rv/GHSA-5f9p-9995-r2rv.json b/advisories/unreviewed/2024/05/GHSA-5f9p-9995-r2rv/GHSA-5f9p-9995-r2rv.json index cf06197d6a1..a8373c44ce4 100644 --- a/advisories/unreviewed/2024/05/GHSA-5f9p-9995-r2rv/GHSA-5f9p-9995-r2rv.json +++ b/advisories/unreviewed/2024/05/GHSA-5f9p-9995-r2rv/GHSA-5f9p-9995-r2rv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5f9p-9995-r2rv", - "modified": "2024-05-19T12:30:38Z", + "modified": "2024-10-31T15:30:58Z", "published": "2024-05-19T12:30:38Z", "aliases": [ "CVE-2024-35919" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: mediatek: vcodec: adding lock to protect encoder context list\n\nAdd a lock for the ctx_list, to avoid accessing a NULL pointer\nwithin the 'vpu_enc_ipi_handler' function when the ctx_list has\nbeen deleted due to an unexpected behavior on the SCP IP block.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-19T11:15:48Z" diff --git a/advisories/unreviewed/2024/05/GHSA-8cj3-cf5p-99vq/GHSA-8cj3-cf5p-99vq.json b/advisories/unreviewed/2024/05/GHSA-8cj3-cf5p-99vq/GHSA-8cj3-cf5p-99vq.json index f1448888c16..1a38007ba42 100644 --- a/advisories/unreviewed/2024/05/GHSA-8cj3-cf5p-99vq/GHSA-8cj3-cf5p-99vq.json +++ b/advisories/unreviewed/2024/05/GHSA-8cj3-cf5p-99vq/GHSA-8cj3-cf5p-99vq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8cj3-cf5p-99vq", - "modified": "2024-05-14T15:32:53Z", + "modified": "2024-10-31T15:30:58Z", "published": "2024-05-14T15:32:53Z", "aliases": [ "CVE-2024-28276" ], "details": "Sourcecodester School Task Manager 1.0 is vulnerable to Cross Site Scripting (XSS) via add-task.php?task_name=.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:14:18Z" diff --git a/advisories/unreviewed/2024/06/GHSA-34pw-x3jp-c8x5/GHSA-34pw-x3jp-c8x5.json b/advisories/unreviewed/2024/06/GHSA-34pw-x3jp-c8x5/GHSA-34pw-x3jp-c8x5.json index 06edd9bb272..59c780b171d 100644 --- a/advisories/unreviewed/2024/06/GHSA-34pw-x3jp-c8x5/GHSA-34pw-x3jp-c8x5.json +++ b/advisories/unreviewed/2024/06/GHSA-34pw-x3jp-c8x5/GHSA-34pw-x3jp-c8x5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-34pw-x3jp-c8x5", - "modified": "2024-06-19T15:30:55Z", + "modified": "2024-10-31T15:30:58Z", "published": "2024-06-19T15:30:55Z", "aliases": [ "CVE-2021-47594" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: never allow the PM to close a listener subflow\n\nCurrently, when deleting an endpoint the netlink PM treverses\nall the local MPTCP sockets, regardless of their status.\n\nIf an MPTCP listener socket is bound to the IP matching the\ndelete endpoint, the listener TCP socket will be closed.\nThat is unexpected, the PM should only affect data subflows.\n\nAdditionally, syzbot was able to trigger a NULL ptr dereference\ndue to the above:\n\ngeneral protection fault, probably for non-canonical address 0xdffffc0000000003: 0000 [#1] PREEMPT SMP KASAN\nKASAN: null-ptr-deref in range [0x0000000000000018-0x000000000000001f]\nCPU: 1 PID: 6550 Comm: syz-executor122 Not tainted 5.16.0-rc4-syzkaller #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011\nRIP: 0010:__lock_acquire+0xd7d/0x54a0 kernel/locking/lockdep.c:4897\nCode: 0f 0e 41 be 01 00 00 00 0f 86 c8 00 00 00 89 05 69 cc 0f 0e e9 bd 00 00 00 48 b8 00 00 00 00 00 fc ff df 48 89 da 48 c1 ea 03 <80> 3c 02 00 0f 85 f3 2f 00 00 48 81 3b 20 75 17 8f 0f 84 52 f3 ff\nRSP: 0018:ffffc90001f2f818 EFLAGS: 00010016\nRAX: dffffc0000000000 RBX: 0000000000000018 RCX: 0000000000000000\nRDX: 0000000000000003 RSI: 0000000000000000 RDI: 0000000000000001\nRBP: 0000000000000000 R08: 0000000000000001 R09: 0000000000000001\nR10: 0000000000000000 R11: 000000000000000a R12: 0000000000000000\nR13: ffff88801b98d700 R14: 0000000000000000 R15: 0000000000000001\nFS: 00007f177cd3d700(0000) GS:ffff8880b9d00000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007f177cd1b268 CR3: 000000001dd55000 CR4: 0000000000350ee0\nCall Trace:\n \n lock_acquire kernel/locking/lockdep.c:5637 [inline]\n lock_acquire+0x1ab/0x510 kernel/locking/lockdep.c:5602\n __raw_spin_lock_irqsave include/linux/spinlock_api_smp.h:110 [inline]\n _raw_spin_lock_irqsave+0x39/0x50 kernel/locking/spinlock.c:162\n finish_wait+0xc0/0x270 kernel/sched/wait.c:400\n inet_csk_wait_for_connect net/ipv4/inet_connection_sock.c:464 [inline]\n inet_csk_accept+0x7de/0x9d0 net/ipv4/inet_connection_sock.c:497\n mptcp_accept+0xe5/0x500 net/mptcp/protocol.c:2865\n inet_accept+0xe4/0x7b0 net/ipv4/af_inet.c:739\n mptcp_stream_accept+0x2e7/0x10e0 net/mptcp/protocol.c:3345\n do_accept+0x382/0x510 net/socket.c:1773\n __sys_accept4_file+0x7e/0xe0 net/socket.c:1816\n __sys_accept4+0xb0/0x100 net/socket.c:1846\n __do_sys_accept net/socket.c:1864 [inline]\n __se_sys_accept net/socket.c:1861 [inline]\n __x64_sys_accept+0x71/0xb0 net/socket.c:1861\n do_syscall_x64 arch/x86/entry/common.c:50 [inline]\n do_syscall_64+0x35/0xb0 arch/x86/entry/common.c:80\n entry_SYSCALL_64_after_hwframe+0x44/0xae\nRIP: 0033:0x7f177cd8b8e9\nCode: 28 00 00 00 75 05 48 83 c4 28 c3 e8 b1 14 00 00 90 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b8 ff ff ff f7 d8 64 89 01 48\nRSP: 002b:00007f177cd3d308 EFLAGS: 00000246 ORIG_RAX: 000000000000002b\nRAX: ffffffffffffffda RBX: 00007f177ce13408 RCX: 00007f177cd8b8e9\nRDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000003\nRBP: 00007f177ce13400 R08: 0000000000000000 R09: 0000000000000000\nR10: 0000000000000000 R11: 0000000000000246 R12: 00007f177ce1340c\nR13: 00007f177cde1004 R14: 6d705f706374706d R15: 0000000000022000\n \n\nFix the issue explicitly skipping MPTCP socket in TCP_LISTEN\nstatus.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-19T15:15:53Z" diff --git a/advisories/unreviewed/2024/06/GHSA-4gc8-p5p2-ww5g/GHSA-4gc8-p5p2-ww5g.json b/advisories/unreviewed/2024/06/GHSA-4gc8-p5p2-ww5g/GHSA-4gc8-p5p2-ww5g.json index 107edcf8715..432331ee4d4 100644 --- a/advisories/unreviewed/2024/06/GHSA-4gc8-p5p2-ww5g/GHSA-4gc8-p5p2-ww5g.json +++ b/advisories/unreviewed/2024/06/GHSA-4gc8-p5p2-ww5g/GHSA-4gc8-p5p2-ww5g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4gc8-p5p2-ww5g", - "modified": "2024-06-25T15:31:09Z", + "modified": "2024-10-31T15:30:58Z", "published": "2024-06-25T15:31:09Z", "aliases": [ "CVE-2024-37087" @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-732" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-4h2m-3c33-9fw3/GHSA-4h2m-3c33-9fw3.json b/advisories/unreviewed/2024/06/GHSA-4h2m-3c33-9fw3/GHSA-4h2m-3c33-9fw3.json index c38f6d32ab0..47d6d807522 100644 --- a/advisories/unreviewed/2024/06/GHSA-4h2m-3c33-9fw3/GHSA-4h2m-3c33-9fw3.json +++ b/advisories/unreviewed/2024/06/GHSA-4h2m-3c33-9fw3/GHSA-4h2m-3c33-9fw3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4h2m-3c33-9fw3", - "modified": "2024-06-19T15:30:55Z", + "modified": "2024-10-31T15:30:58Z", "published": "2024-06-19T15:30:55Z", "aliases": [ "CVE-2021-47605" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nvduse: fix memory corruption in vduse_dev_ioctl()\n\nThe \"config.offset\" comes from the user. There needs to a check to\nprevent it being out of bounds. The \"config.offset\" and\n\"dev->config_size\" variables are both type u32. So if the offset if\nout of bounds then the \"dev->config_size - config.offset\" subtraction\nresults in a very high u32 value. The out of bounds offset can result\nin memory corruption.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-19T15:15:55Z" diff --git a/advisories/unreviewed/2024/06/GHSA-7jvp-hvfw-w5mc/GHSA-7jvp-hvfw-w5mc.json b/advisories/unreviewed/2024/06/GHSA-7jvp-hvfw-w5mc/GHSA-7jvp-hvfw-w5mc.json index 445eb7fcd13..e0b601cd53f 100644 --- a/advisories/unreviewed/2024/06/GHSA-7jvp-hvfw-w5mc/GHSA-7jvp-hvfw-w5mc.json +++ b/advisories/unreviewed/2024/06/GHSA-7jvp-hvfw-w5mc/GHSA-7jvp-hvfw-w5mc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7jvp-hvfw-w5mc", - "modified": "2024-06-19T15:30:55Z", + "modified": "2024-10-31T15:30:58Z", "published": "2024-06-19T15:30:55Z", "aliases": [ "CVE-2021-47595" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: sch_ets: don't remove idle classes from the round-robin list\n\nShuang reported that the following script:\n\n 1) tc qdisc add dev ddd0 handle 10: parent 1: ets bands 8 strict 4 priomap 7 7 7 7 7 7 7 7 7 7 7 7 7 7 7 7\n 2) mausezahn ddd0 -A 10.10.10.1 -B 10.10.10.2 -c 0 -a own -b 00:c1:a0:c1:a0:00 -t udp &\n 3) tc qdisc change dev ddd0 handle 10: ets bands 4 strict 2 quanta 2500 2500 priomap 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3 3\n\ncrashes systematically when line 2) is commented:\n\n list_del corruption, ffff8e028404bd30->next is LIST_POISON1 (dead000000000100)\n ------------[ cut here ]------------\n kernel BUG at lib/list_debug.c:47!\n invalid opcode: 0000 [#1] PREEMPT SMP NOPTI\n CPU: 0 PID: 954 Comm: tc Not tainted 5.16.0-rc4+ #478\n Hardware name: Red Hat KVM, BIOS 1.11.1-4.module+el8.1.0+4066+0f1aadab 04/01/2014\n RIP: 0010:__list_del_entry_valid.cold.1+0x12/0x47\n Code: fe ff 0f 0b 48 89 c1 4c 89 c6 48 c7 c7 08 42 1b 87 e8 1d c5 fe ff 0f 0b 48 89 fe 48 89 c2 48 c7 c7 98 42 1b 87 e8 09 c5 fe ff <0f> 0b 48 c7 c7 48 43 1b 87 e8 fb c4 fe ff 0f 0b 48 89 f2 48 89 fe\n RSP: 0018:ffffae46807a3888 EFLAGS: 00010246\n RAX: 000000000000004e RBX: 0000000000000007 RCX: 0000000000000202\n RDX: 0000000000000000 RSI: ffffffff871ac536 RDI: 00000000ffffffff\n RBP: ffffae46807a3a10 R08: 0000000000000000 R09: c0000000ffff7fff\n R10: 0000000000000001 R11: ffffae46807a36a8 R12: ffff8e028404b800\n R13: ffff8e028404bd30 R14: dead000000000100 R15: ffff8e02fafa2400\n FS: 00007efdc92e4480(0000) GS:ffff8e02fb600000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 0000000000682f48 CR3: 00000001058be000 CR4: 0000000000350ef0\n Call Trace:\n \n ets_qdisc_change+0x58b/0xa70 [sch_ets]\n tc_modify_qdisc+0x323/0x880\n rtnetlink_rcv_msg+0x169/0x4a0\n netlink_rcv_skb+0x50/0x100\n netlink_unicast+0x1a5/0x280\n netlink_sendmsg+0x257/0x4d0\n sock_sendmsg+0x5b/0x60\n ____sys_sendmsg+0x1f2/0x260\n ___sys_sendmsg+0x7c/0xc0\n __sys_sendmsg+0x57/0xa0\n do_syscall_64+0x3a/0x80\n entry_SYSCALL_64_after_hwframe+0x44/0xae\n RIP: 0033:0x7efdc8031338\n Code: 89 02 48 c7 c0 ff ff ff ff eb b5 0f 1f 80 00 00 00 00 f3 0f 1e fa 48 8d 05 25 43 2c 00 8b 00 85 c0 75 17 b8 2e 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 58 c3 0f 1f 80 00 00 00 00 41 54 41 89 d4 55\n RSP: 002b:00007ffdf1ce9828 EFLAGS: 00000246 ORIG_RAX: 000000000000002e\n RAX: ffffffffffffffda RBX: 0000000061b37a97 RCX: 00007efdc8031338\n RDX: 0000000000000000 RSI: 00007ffdf1ce9890 RDI: 0000000000000003\n RBP: 0000000000000000 R08: 0000000000000001 R09: 000000000078a940\n R10: 000000000000000c R11: 0000000000000246 R12: 0000000000000001\n R13: 0000000000688880 R14: 0000000000000000 R15: 0000000000000000\n \n Modules linked in: sch_ets sch_tbf dummy rfkill iTCO_wdt iTCO_vendor_support intel_rapl_msr intel_rapl_common joydev pcspkr i2c_i801 virtio_balloon i2c_smbus lpc_ich ip_tables xfs libcrc32c crct10dif_pclmul crc32_pclmul crc32c_intel serio_raw ghash_clmulni_intel ahci libahci libata virtio_blk virtio_console virtio_net net_failover failover sunrpc dm_mirror dm_region_hash dm_log dm_mod [last unloaded: sch_ets]\n ---[ end trace f35878d1912655c2 ]---\n RIP: 0010:__list_del_entry_valid.cold.1+0x12/0x47\n Code: fe ff 0f 0b 48 89 c1 4c 89 c6 48 c7 c7 08 42 1b 87 e8 1d c5 fe ff 0f 0b 48 89 fe 48 89 c2 48 c7 c7 98 42 1b 87 e8 09 c5 fe ff <0f> 0b 48 c7 c7 48 43 1b 87 e8 fb c4 fe ff 0f 0b 48 89 f2 48 89 fe\n RSP: 0018:ffffae46807a3888 EFLAGS: 00010246\n RAX: 000000000000004e RBX: 0000000000000007 RCX: 0000000000000202\n RDX: 0000000000000000 RSI: ffffffff871ac536 RDI: 00000000ffffffff\n RBP: ffffae46807a3a10 R08: 0000000000000000 R09: c0000000ffff7fff\n R10: 0000000000000001 R11: ffffae46807a36a8 R12: ffff8e028404b800\n R13: ffff8e028404bd30 R14: dead000000000100 R15: ffff8e02fafa2400\n FS: 00007efdc92e4480(0000) GS:ffff8e02fb600000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 000000000\n---truncated---", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-19T15:15:54Z" diff --git a/advisories/unreviewed/2024/06/GHSA-fp67-w4xm-4hj6/GHSA-fp67-w4xm-4hj6.json b/advisories/unreviewed/2024/06/GHSA-fp67-w4xm-4hj6/GHSA-fp67-w4xm-4hj6.json index f00049d4327..227222f8aa3 100644 --- a/advisories/unreviewed/2024/06/GHSA-fp67-w4xm-4hj6/GHSA-fp67-w4xm-4hj6.json +++ b/advisories/unreviewed/2024/06/GHSA-fp67-w4xm-4hj6/GHSA-fp67-w4xm-4hj6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fp67-w4xm-4hj6", - "modified": "2024-06-19T15:30:55Z", + "modified": "2024-10-31T15:30:58Z", "published": "2024-06-19T15:30:55Z", "aliases": [ "CVE-2021-47607" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix kernel address leakage in atomic cmpxchg's r0 aux reg\n\nThe implementation of BPF_CMPXCHG on a high level has the following parameters:\n\n .-[old-val] .-[new-val]\n BPF_R0 = cmpxchg{32,64}(DST_REG + insn->off, BPF_R0, SRC_REG)\n `-[mem-loc] `-[old-val]\n\nGiven a BPF insn can only have two registers (dst, src), the R0 is fixed and\nused as an auxilliary register for input (old value) as well as output (returning\nold value from memory location). While the verifier performs a number of safety\nchecks, it misses to reject unprivileged programs where R0 contains a pointer as\nold value.\n\nThrough brute-forcing it takes about ~16sec on my machine to leak a kernel pointer\nwith BPF_CMPXCHG. The PoC is basically probing for kernel addresses by storing the\nguessed address into the map slot as a scalar, and using the map value pointer as\nR0 while SRC_REG has a canary value to detect a matching address.\n\nFix it by checking R0 for pointers, and reject if that's the case for unprivileged\nprograms.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-19T15:15:55Z" diff --git a/advisories/unreviewed/2024/06/GHSA-g68j-9rxj-c36w/GHSA-g68j-9rxj-c36w.json b/advisories/unreviewed/2024/06/GHSA-g68j-9rxj-c36w/GHSA-g68j-9rxj-c36w.json index 5ed26585677..eabdba39a8a 100644 --- a/advisories/unreviewed/2024/06/GHSA-g68j-9rxj-c36w/GHSA-g68j-9rxj-c36w.json +++ b/advisories/unreviewed/2024/06/GHSA-g68j-9rxj-c36w/GHSA-g68j-9rxj-c36w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g68j-9rxj-c36w", - "modified": "2024-06-19T15:30:55Z", + "modified": "2024-10-31T15:30:58Z", "published": "2024-06-19T15:30:55Z", "aliases": [ "CVE-2021-47602" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmac80211: track only QoS data frames for admission control\n\nFor admission control, obviously all of that only works for\nQoS data frames, otherwise we cannot even access the QoS\nfield in the header.\n\nSyzbot reported (see below) an uninitialized value here due\nto a status of a non-QoS nullfunc packet, which isn't even\nlong enough to contain the QoS header.\n\nFix this to only do anything for QoS data packets.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-824" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-19T15:15:54Z" diff --git a/advisories/unreviewed/2024/06/GHSA-qh5p-hc8x-v67x/GHSA-qh5p-hc8x-v67x.json b/advisories/unreviewed/2024/06/GHSA-qh5p-hc8x-v67x/GHSA-qh5p-hc8x-v67x.json index ddcb70409ad..a318caa20dd 100644 --- a/advisories/unreviewed/2024/06/GHSA-qh5p-hc8x-v67x/GHSA-qh5p-hc8x-v67x.json +++ b/advisories/unreviewed/2024/06/GHSA-qh5p-hc8x-v67x/GHSA-qh5p-hc8x-v67x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qh5p-hc8x-v67x", - "modified": "2024-06-19T15:30:55Z", + "modified": "2024-10-31T15:30:58Z", "published": "2024-06-19T15:30:55Z", "aliases": [ "CVE-2021-47606" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: netlink: af_netlink: Prevent empty skb by adding a check on len.\n\nAdding a check on len parameter to avoid empty skb. This prevents a\ndivision error in netem_enqueue function which is caused when skb->len=0\nand skb->data_len=0 in the randomized corruption step as shown below.\n\nskb->data[prandom_u32() % skb_headlen(skb)] ^= 1<<(prandom_u32() % 8);\n\nCrash Report:\n[ 343.170349] netdevsim netdevsim0 netdevsim3: set [1, 0] type 2 family\n0 port 6081 - 0\n[ 343.216110] netem: version 1.3\n[ 343.235841] divide error: 0000 [#1] PREEMPT SMP KASAN NOPTI\n[ 343.236680] CPU: 3 PID: 4288 Comm: reproducer Not tainted 5.16.0-rc1+\n[ 343.237569] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996),\nBIOS 1.11.0-2.el7 04/01/2014\n[ 343.238707] RIP: 0010:netem_enqueue+0x1590/0x33c0 [sch_netem]\n[ 343.239499] Code: 89 85 58 ff ff ff e8 5f 5d e9 d3 48 8b b5 48 ff ff\nff 8b 8d 50 ff ff ff 8b 85 58 ff ff ff 48 8b bd 70 ff ff ff 31 d2 2b 4f\n74 f1 48 b8 00 00 00 00 00 fc ff df 49 01 d5 4c 89 e9 48 c1 e9 03\n[ 343.241883] RSP: 0018:ffff88800bcd7368 EFLAGS: 00010246\n[ 343.242589] RAX: 00000000ba7c0a9c RBX: 0000000000000001 RCX:\n0000000000000000\n[ 343.243542] RDX: 0000000000000000 RSI: ffff88800f8edb10 RDI:\nffff88800f8eda40\n[ 343.244474] RBP: ffff88800bcd7458 R08: 0000000000000000 R09:\nffffffff94fb8445\n[ 343.245403] R10: ffffffff94fb8336 R11: ffffffff94fb8445 R12:\n0000000000000000\n[ 343.246355] R13: ffff88800a5a7000 R14: ffff88800a5b5800 R15:\n0000000000000020\n[ 343.247291] FS: 00007fdde2bd7700(0000) GS:ffff888109780000(0000)\nknlGS:0000000000000000\n[ 343.248350] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 343.249120] CR2: 00000000200000c0 CR3: 000000000ef4c000 CR4:\n00000000000006e0\n[ 343.250076] Call Trace:\n[ 343.250423] \n[ 343.250713] ? memcpy+0x4d/0x60\n[ 343.251162] ? netem_init+0xa0/0xa0 [sch_netem]\n[ 343.251795] ? __sanitizer_cov_trace_pc+0x21/0x60\n[ 343.252443] netem_enqueue+0xe28/0x33c0 [sch_netem]\n[ 343.253102] ? stack_trace_save+0x87/0xb0\n[ 343.253655] ? filter_irq_stacks+0xb0/0xb0\n[ 343.254220] ? netem_init+0xa0/0xa0 [sch_netem]\n[ 343.254837] ? __kasan_check_write+0x14/0x20\n[ 343.255418] ? _raw_spin_lock+0x88/0xd6\n[ 343.255953] dev_qdisc_enqueue+0x50/0x180\n[ 343.256508] __dev_queue_xmit+0x1a7e/0x3090\n[ 343.257083] ? netdev_core_pick_tx+0x300/0x300\n[ 343.257690] ? check_kcov_mode+0x10/0x40\n[ 343.258219] ? _raw_spin_unlock_irqrestore+0x29/0x40\n[ 343.258899] ? __kasan_init_slab_obj+0x24/0x30\n[ 343.259529] ? setup_object.isra.71+0x23/0x90\n[ 343.260121] ? new_slab+0x26e/0x4b0\n[ 343.260609] ? kasan_poison+0x3a/0x50\n[ 343.261118] ? kasan_unpoison+0x28/0x50\n[ 343.261637] ? __kasan_slab_alloc+0x71/0x90\n[ 343.262214] ? memcpy+0x4d/0x60\n[ 343.262674] ? write_comp_data+0x2f/0x90\n[ 343.263209] ? __kasan_check_write+0x14/0x20\n[ 343.263802] ? __skb_clone+0x5d6/0x840\n[ 343.264329] ? __sanitizer_cov_trace_pc+0x21/0x60\n[ 343.264958] dev_queue_xmit+0x1c/0x20\n[ 343.265470] netlink_deliver_tap+0x652/0x9c0\n[ 343.266067] netlink_unicast+0x5a0/0x7f0\n[ 343.266608] ? netlink_attachskb+0x860/0x860\n[ 343.267183] ? __sanitizer_cov_trace_pc+0x21/0x60\n[ 343.267820] ? write_comp_data+0x2f/0x90\n[ 343.268367] netlink_sendmsg+0x922/0xe80\n[ 343.268899] ? netlink_unicast+0x7f0/0x7f0\n[ 343.269472] ? __sanitizer_cov_trace_pc+0x21/0x60\n[ 343.270099] ? write_comp_data+0x2f/0x90\n[ 343.270644] ? netlink_unicast+0x7f0/0x7f0\n[ 343.271210] sock_sendmsg+0x155/0x190\n[ 343.271721] ____sys_sendmsg+0x75f/0x8f0\n[ 343.272262] ? kernel_sendmsg+0x60/0x60\n[ 343.272788] ? write_comp_data+0x2f/0x90\n[ 343.273332] ? write_comp_data+0x2f/0x90\n[ 343.273869] ___sys_sendmsg+0x10f/0x190\n[ 343.274405] ? sendmsg_copy_msghdr+0x80/0x80\n[ 343.274984] ? slab_post_alloc_hook+0x70/0x230\n[ 343.275597] ? futex_wait_setup+0x240/0x240\n[ 343.276175] ? security_file_alloc+0x3e/0x170\n[ 343.276779] ? write_comp_d\n---truncated---", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-369" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-19T15:15:55Z" diff --git a/advisories/unreviewed/2024/06/GHSA-v7fm-vjvq-9fg6/GHSA-v7fm-vjvq-9fg6.json b/advisories/unreviewed/2024/06/GHSA-v7fm-vjvq-9fg6/GHSA-v7fm-vjvq-9fg6.json index 3295e23ee28..1eb731f348d 100644 --- a/advisories/unreviewed/2024/06/GHSA-v7fm-vjvq-9fg6/GHSA-v7fm-vjvq-9fg6.json +++ b/advisories/unreviewed/2024/06/GHSA-v7fm-vjvq-9fg6/GHSA-v7fm-vjvq-9fg6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v7fm-vjvq-9fg6", - "modified": "2024-06-19T15:30:55Z", + "modified": "2024-10-31T15:30:58Z", "published": "2024-06-19T15:30:55Z", "aliases": [ "CVE-2021-47608" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix kernel address leakage in atomic fetch\n\nThe change in commit 37086bfdc737 (\"bpf: Propagate stack bounds to registers\nin atomics w/ BPF_FETCH\") around check_mem_access() handling is buggy since\nthis would allow for unprivileged users to leak kernel pointers. For example,\nan atomic fetch/and with -1 on a stack destination which holds a spilled\npointer will migrate the spilled register type into a scalar, which can then\nbe exported out of the program (since scalar != pointer) by dumping it into\na map value.\n\nThe original implementation of XADD was preventing this situation by using\na double call to check_mem_access() one with BPF_READ and a subsequent one\nwith BPF_WRITE, in both cases passing -1 as a placeholder value instead of\nregister as per XADD semantics since it didn't contain a value fetch. The\nBPF_READ also included a check in check_stack_read_fixed_off() which rejects\nthe program if the stack slot is of __is_pointer_value() if dst_regno < 0.\nThe latter is to distinguish whether we're dealing with a regular stack spill/\nfill or some arithmetical operation which is disallowed on non-scalars, see\nalso 6e7e63cbb023 (\"bpf: Forbid XADD on spilled pointers for unprivileged\nusers\") for more context on check_mem_access() and its handling of placeholder\nvalue -1.\n\nOne minimally intrusive option to fix the leak is for the BPF_FETCH case to\ninitially check the BPF_READ case via check_mem_access() with -1 as register,\nfollowed by the actual load case with non-negative load_reg to propagate\nstack bounds to registers.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-19T15:15:55Z" diff --git a/advisories/unreviewed/2024/06/GHSA-v8rf-qj3w-fq5c/GHSA-v8rf-qj3w-fq5c.json b/advisories/unreviewed/2024/06/GHSA-v8rf-qj3w-fq5c/GHSA-v8rf-qj3w-fq5c.json index cc899ad5f73..8b0d037f460 100644 --- a/advisories/unreviewed/2024/06/GHSA-v8rf-qj3w-fq5c/GHSA-v8rf-qj3w-fq5c.json +++ b/advisories/unreviewed/2024/06/GHSA-v8rf-qj3w-fq5c/GHSA-v8rf-qj3w-fq5c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v8rf-qj3w-fq5c", - "modified": "2024-06-19T15:30:55Z", + "modified": "2024-10-31T15:30:58Z", "published": "2024-06-19T15:30:55Z", "aliases": [ "CVE-2021-47599" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: use latest_dev in btrfs_show_devname\n\nThe test case btrfs/238 reports the warning below:\n\n WARNING: CPU: 3 PID: 481 at fs/btrfs/super.c:2509 btrfs_show_devname+0x104/0x1e8 [btrfs]\n CPU: 2 PID: 1 Comm: systemd Tainted: G W O 5.14.0-rc1-custom #72\n Hardware name: QEMU QEMU Virtual Machine, BIOS 0.0.0 02/06/2015\n Call trace:\n btrfs_show_devname+0x108/0x1b4 [btrfs]\n show_mountinfo+0x234/0x2c4\n m_show+0x28/0x34\n seq_read_iter+0x12c/0x3c4\n vfs_read+0x29c/0x2c8\n ksys_read+0x80/0xec\n __arm64_sys_read+0x28/0x34\n invoke_syscall+0x50/0xf8\n do_el0_svc+0x88/0x138\n el0_svc+0x2c/0x8c\n el0t_64_sync_handler+0x84/0xe4\n el0t_64_sync+0x198/0x19c\n\nReason:\nWhile btrfs_prepare_sprout() moves the fs_devices::devices into\nfs_devices::seed_list, the btrfs_show_devname() searches for the devices\nand found none, leading to the warning as in above.\n\nFix:\nlatest_dev is updated according to the changes to the device list.\nThat means we could use the latest_dev->name to show the device name in\n/proc/self/mounts, the pointer will be always valid as it's assigned\nbefore the device is deleted from the list in remove or replace.\nThe RCU protection is sufficient as the device structure is freed after\nsynchronization.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-362" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-19T15:15:54Z" diff --git a/advisories/unreviewed/2024/06/GHSA-xfpp-3cjf-2x3v/GHSA-xfpp-3cjf-2x3v.json b/advisories/unreviewed/2024/06/GHSA-xfpp-3cjf-2x3v/GHSA-xfpp-3cjf-2x3v.json index b4aefbef05b..69d0d8445d9 100644 --- a/advisories/unreviewed/2024/06/GHSA-xfpp-3cjf-2x3v/GHSA-xfpp-3cjf-2x3v.json +++ b/advisories/unreviewed/2024/06/GHSA-xfpp-3cjf-2x3v/GHSA-xfpp-3cjf-2x3v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xfpp-3cjf-2x3v", - "modified": "2024-06-19T15:30:55Z", + "modified": "2024-10-31T15:30:58Z", "published": "2024-06-19T15:30:55Z", "aliases": [ "CVE-2021-47603" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\naudit: improve robustness of the audit queue handling\n\nIf the audit daemon were ever to get stuck in a stopped state the\nkernel's kauditd_thread() could get blocked attempting to send audit\nrecords to the userspace audit daemon. With the kernel thread\nblocked it is possible that the audit queue could grow unbounded as\ncertain audit record generating events must be exempt from the queue\nlimits else the system enter a deadlock state.\n\nThis patch resolves this problem by lowering the kernel thread's\nsocket sending timeout from MAX_SCHEDULE_TIMEOUT to HZ/10 and tweaks\nthe kauditd_send_queue() function to better manage the various audit\nqueues when connection problems occur between the kernel and the\naudit daemon. With this patch, the backlog may temporarily grow\nbeyond the defined limits when the audit daemon is stopped and the\nsystem is under heavy audit pressure, but kauditd_thread() will\ncontinue to make progress and drain the queues as it would for other\nconnection problems. For example, with the audit daemon put into a\nstopped state and the system configured to audit every syscall it\nwas still possible to shutdown the system without a kernel panic,\ndeadlock, etc.; granted, the system was slow to shutdown but that is\nto be expected given the extreme pressure of recording every syscall.\n\nThe timeout value of HZ/10 was chosen primarily through\nexperimentation and this developer's \"gut feeling\". There is likely\nno one perfect value, but as this scenario is limited in scope (root\nprivileges would be needed to send SIGSTOP to the audit daemon), it\nis likely not worth exposing this as a tunable at present. This can\nalways be done at a later date if it proves necessary.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-667" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-19T15:15:54Z" diff --git a/advisories/unreviewed/2024/07/GHSA-fhff-r739-p363/GHSA-fhff-r739-p363.json b/advisories/unreviewed/2024/07/GHSA-fhff-r739-p363/GHSA-fhff-r739-p363.json index 9b76e4561ba..f2fa56ee8a8 100644 --- a/advisories/unreviewed/2024/07/GHSA-fhff-r739-p363/GHSA-fhff-r739-p363.json +++ b/advisories/unreviewed/2024/07/GHSA-fhff-r739-p363/GHSA-fhff-r739-p363.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-6744-v55g-mhwj/GHSA-6744-v55g-mhwj.json b/advisories/unreviewed/2024/08/GHSA-6744-v55g-mhwj/GHSA-6744-v55g-mhwj.json index 4bd355702b7..cbb47789a08 100644 --- a/advisories/unreviewed/2024/08/GHSA-6744-v55g-mhwj/GHSA-6744-v55g-mhwj.json +++ b/advisories/unreviewed/2024/08/GHSA-6744-v55g-mhwj/GHSA-6744-v55g-mhwj.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-427" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-682f-6p39-r4r2/GHSA-682f-6p39-r4r2.json b/advisories/unreviewed/2024/08/GHSA-682f-6p39-r4r2/GHSA-682f-6p39-r4r2.json index fadcb661051..8c3eb04784f 100644 --- a/advisories/unreviewed/2024/08/GHSA-682f-6p39-r4r2/GHSA-682f-6p39-r4r2.json +++ b/advisories/unreviewed/2024/08/GHSA-682f-6p39-r4r2/GHSA-682f-6p39-r4r2.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-266" + "CWE-266", + "CWE-863" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-xqmq-3744-539p/GHSA-xqmq-3744-539p.json b/advisories/unreviewed/2024/08/GHSA-xqmq-3744-539p/GHSA-xqmq-3744-539p.json index 7c790ce0ecb..0bfb763737c 100644 --- a/advisories/unreviewed/2024/08/GHSA-xqmq-3744-539p/GHSA-xqmq-3744-539p.json +++ b/advisories/unreviewed/2024/08/GHSA-xqmq-3744-539p/GHSA-xqmq-3744-539p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xqmq-3744-539p", - "modified": "2024-08-13T18:31:15Z", + "modified": "2024-10-31T15:30:58Z", "published": "2024-08-13T18:31:15Z", "aliases": [ "CVE-2021-46746" @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-3c3q-vw42-rfc2/GHSA-3c3q-vw42-rfc2.json b/advisories/unreviewed/2024/10/GHSA-3c3q-vw42-rfc2/GHSA-3c3q-vw42-rfc2.json index 81a39e06870..ff667c2428a 100644 --- a/advisories/unreviewed/2024/10/GHSA-3c3q-vw42-rfc2/GHSA-3c3q-vw42-rfc2.json +++ b/advisories/unreviewed/2024/10/GHSA-3c3q-vw42-rfc2/GHSA-3c3q-vw42-rfc2.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-288" + "CWE-288", + "CWE-306" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-56m6-4mhw-h3g5/GHSA-56m6-4mhw-h3g5.json b/advisories/unreviewed/2024/10/GHSA-56m6-4mhw-h3g5/GHSA-56m6-4mhw-h3g5.json new file mode 100644 index 00000000000..552345687e6 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-56m6-4mhw-h3g5/GHSA-56m6-4mhw-h3g5.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-56m6-4mhw-h3g5", + "modified": "2024-10-31T15:30:59Z", + "published": "2024-10-31T15:30:59Z", + "aliases": [ + "CVE-2024-42835" + ], + "details": "langflow v1.0.12 was discovered to contain a remote code execution (RCE) vulnerability via the PythonCodeTool component.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42835" + }, + { + "type": "WEB", + "url": "https://github.com/langflow-ai/langflow/issues/2908" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-31T14:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-6m34-xwq2-mrch/GHSA-6m34-xwq2-mrch.json b/advisories/unreviewed/2024/10/GHSA-6m34-xwq2-mrch/GHSA-6m34-xwq2-mrch.json index c68f6d85b63..d5da1331fb3 100644 --- a/advisories/unreviewed/2024/10/GHSA-6m34-xwq2-mrch/GHSA-6m34-xwq2-mrch.json +++ b/advisories/unreviewed/2024/10/GHSA-6m34-xwq2-mrch/GHSA-6m34-xwq2-mrch.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6m34-xwq2-mrch", - "modified": "2024-10-21T21:30:52Z", + "modified": "2024-10-31T15:30:58Z", "published": "2024-10-21T21:30:52Z", "aliases": [ "CVE-2022-48999" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv4: Handle attempt to delete multipath route when fib_info contains an nh reference\n\nGwangun Jung reported a slab-out-of-bounds access in fib_nh_match:\n fib_nh_match+0xf98/0x1130 linux-6.0-rc7/net/ipv4/fib_semantics.c:961\n fib_table_delete+0x5f3/0xa40 linux-6.0-rc7/net/ipv4/fib_trie.c:1753\n inet_rtm_delroute+0x2b3/0x380 linux-6.0-rc7/net/ipv4/fib_frontend.c:874\n\nSeparate nexthop objects are mutually exclusive with the legacy\nmultipath spec. Fix fib_nh_match to return if the config for the\nto be deleted route contains a multipath spec while the fib_info\nis using a nexthop object.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T20:15:11Z" diff --git a/advisories/unreviewed/2024/10/GHSA-77hv-rqc3-4gm6/GHSA-77hv-rqc3-4gm6.json b/advisories/unreviewed/2024/10/GHSA-77hv-rqc3-4gm6/GHSA-77hv-rqc3-4gm6.json index c2cdb2cb59a..457b5dd4626 100644 --- a/advisories/unreviewed/2024/10/GHSA-77hv-rqc3-4gm6/GHSA-77hv-rqc3-4gm6.json +++ b/advisories/unreviewed/2024/10/GHSA-77hv-rqc3-4gm6/GHSA-77hv-rqc3-4gm6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-77hv-rqc3-4gm6", - "modified": "2024-10-29T15:32:02Z", + "modified": "2024-10-31T15:30:58Z", "published": "2024-10-29T15:32:02Z", "aliases": [ "CVE-2024-10459" ], "details": "An attacker could have caused a use-after-free when accessibility was enabled, leading to a potentially exploitable crash. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Firefox ESR < 115.17, Thunderbird < 128.4, and Thunderbird < 132.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-29T13:15:03Z" diff --git a/advisories/unreviewed/2024/10/GHSA-87x3-r6f2-m885/GHSA-87x3-r6f2-m885.json b/advisories/unreviewed/2024/10/GHSA-87x3-r6f2-m885/GHSA-87x3-r6f2-m885.json index 42523f66f3c..dfe416e8197 100644 --- a/advisories/unreviewed/2024/10/GHSA-87x3-r6f2-m885/GHSA-87x3-r6f2-m885.json +++ b/advisories/unreviewed/2024/10/GHSA-87x3-r6f2-m885/GHSA-87x3-r6f2-m885.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-87x3-r6f2-m885", - "modified": "2024-10-29T15:32:02Z", + "modified": "2024-10-31T15:30:58Z", "published": "2024-10-29T15:32:02Z", "aliases": [ "CVE-2024-10458" ], "details": "A permission leak could have occurred from a trusted site to an untrusted site via `embed` or `object` elements. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Firefox ESR < 115.17, Thunderbird < 128.4, and Thunderbird < 132.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -47,7 +50,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-29T13:15:03Z" diff --git a/advisories/unreviewed/2024/10/GHSA-8rm2-54v5-9c84/GHSA-8rm2-54v5-9c84.json b/advisories/unreviewed/2024/10/GHSA-8rm2-54v5-9c84/GHSA-8rm2-54v5-9c84.json index 98540995a5c..64b68860adb 100644 --- a/advisories/unreviewed/2024/10/GHSA-8rm2-54v5-9c84/GHSA-8rm2-54v5-9c84.json +++ b/advisories/unreviewed/2024/10/GHSA-8rm2-54v5-9c84/GHSA-8rm2-54v5-9c84.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8rm2-54v5-9c84", - "modified": "2024-10-24T00:33:36Z", + "modified": "2024-10-31T15:30:58Z", "published": "2024-10-24T00:33:36Z", "aliases": [ "CVE-2024-48213" ], "details": "RockOA v2.6.5 is vulnerable to Directory Traversal in webmain/system/beifen/beifenAction.php.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-23T22:15:02Z" diff --git a/advisories/unreviewed/2024/10/GHSA-8vcm-p6g6-xjqp/GHSA-8vcm-p6g6-xjqp.json b/advisories/unreviewed/2024/10/GHSA-8vcm-p6g6-xjqp/GHSA-8vcm-p6g6-xjqp.json index cf53bd8e03f..f86db96ac7e 100644 --- a/advisories/unreviewed/2024/10/GHSA-8vcm-p6g6-xjqp/GHSA-8vcm-p6g6-xjqp.json +++ b/advisories/unreviewed/2024/10/GHSA-8vcm-p6g6-xjqp/GHSA-8vcm-p6g6-xjqp.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-305" + "CWE-305", + "CWE-862" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-8x2w-53h6-vwx3/GHSA-8x2w-53h6-vwx3.json b/advisories/unreviewed/2024/10/GHSA-8x2w-53h6-vwx3/GHSA-8x2w-53h6-vwx3.json index 7c1aa657bac..26b186e0132 100644 --- a/advisories/unreviewed/2024/10/GHSA-8x2w-53h6-vwx3/GHSA-8x2w-53h6-vwx3.json +++ b/advisories/unreviewed/2024/10/GHSA-8x2w-53h6-vwx3/GHSA-8x2w-53h6-vwx3.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-362" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-945q-vj74-93vc/GHSA-945q-vj74-93vc.json b/advisories/unreviewed/2024/10/GHSA-945q-vj74-93vc/GHSA-945q-vj74-93vc.json index eeb7699bb6d..2181e6473be 100644 --- a/advisories/unreviewed/2024/10/GHSA-945q-vj74-93vc/GHSA-945q-vj74-93vc.json +++ b/advisories/unreviewed/2024/10/GHSA-945q-vj74-93vc/GHSA-945q-vj74-93vc.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-922" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-c5xj-vg6h-cc3w/GHSA-c5xj-vg6h-cc3w.json b/advisories/unreviewed/2024/10/GHSA-c5xj-vg6h-cc3w/GHSA-c5xj-vg6h-cc3w.json index 47be651bb34..bdc58614484 100644 --- a/advisories/unreviewed/2024/10/GHSA-c5xj-vg6h-cc3w/GHSA-c5xj-vg6h-cc3w.json +++ b/advisories/unreviewed/2024/10/GHSA-c5xj-vg6h-cc3w/GHSA-c5xj-vg6h-cc3w.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-203" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-ffc7-h8x5-mm7h/GHSA-ffc7-h8x5-mm7h.json b/advisories/unreviewed/2024/10/GHSA-ffc7-h8x5-mm7h/GHSA-ffc7-h8x5-mm7h.json new file mode 100644 index 00000000000..d138b3a038e --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-ffc7-h8x5-mm7h/GHSA-ffc7-h8x5-mm7h.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ffc7-h8x5-mm7h", + "modified": "2024-10-31T15:30:59Z", + "published": "2024-10-31T15:30:59Z", + "aliases": [ + "CVE-2024-8553" + ], + "details": "A vulnerability was found in Foreman's loader macros introduced with report templates. These macros may allow an authenticated user with permissions to view and create templates to read any field from Foreman's database. By using specific strings in the loader macros, users can bypass permissions and access sensitive information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8553" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-8553" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2312524" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-31T15:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-fjvg-5x2f-67rq/GHSA-fjvg-5x2f-67rq.json b/advisories/unreviewed/2024/10/GHSA-fjvg-5x2f-67rq/GHSA-fjvg-5x2f-67rq.json index a4114920c51..81fccc499dc 100644 --- a/advisories/unreviewed/2024/10/GHSA-fjvg-5x2f-67rq/GHSA-fjvg-5x2f-67rq.json +++ b/advisories/unreviewed/2024/10/GHSA-fjvg-5x2f-67rq/GHSA-fjvg-5x2f-67rq.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-203" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-h72j-469c-c787/GHSA-h72j-469c-c787.json b/advisories/unreviewed/2024/10/GHSA-h72j-469c-c787/GHSA-h72j-469c-c787.json index 417e05cb6d1..226ebdf3845 100644 --- a/advisories/unreviewed/2024/10/GHSA-h72j-469c-c787/GHSA-h72j-469c-c787.json +++ b/advisories/unreviewed/2024/10/GHSA-h72j-469c-c787/GHSA-h72j-469c-c787.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h72j-469c-c787", - "modified": "2024-10-21T18:30:59Z", + "modified": "2024-10-31T15:30:58Z", "published": "2024-10-21T18:30:59Z", "aliases": [ "CVE-2024-49980" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nvrf: revert \"vrf: Remove unnecessary RCU-bh critical section\"\n\nThis reverts commit 504fc6f4f7f681d2a03aa5f68aad549d90eab853.\n\ndev_queue_xmit_nit is expected to be called with BH disabled.\n__dev_queue_xmit has the following:\n\n /* Disable soft irqs for various locks below. Also\n * stops preemption for RCU.\n */\n rcu_read_lock_bh();\n\nVRF must follow this invariant. The referenced commit removed this\nprotection. Which triggered a lockdep warning:\n\n\t================================\n\tWARNING: inconsistent lock state\n\t6.11.0 #1 Tainted: G W\n\t--------------------------------\n\tinconsistent {IN-SOFTIRQ-W} -> {SOFTIRQ-ON-W} usage.\n\tbtserver/134819 [HC0[0]:SC0[0]:HE1:SE1] takes:\n\tffff8882da30c118 (rlock-AF_PACKET){+.?.}-{2:2}, at: tpacket_rcv+0x863/0x3b30\n\t{IN-SOFTIRQ-W} state was registered at:\n\t lock_acquire+0x19a/0x4f0\n\t _raw_spin_lock+0x27/0x40\n\t packet_rcv+0xa33/0x1320\n\t __netif_receive_skb_core.constprop.0+0xcb0/0x3a90\n\t __netif_receive_skb_list_core+0x2c9/0x890\n\t netif_receive_skb_list_internal+0x610/0xcc0\n [...]\n\n\tother info that might help us debug this:\n\t Possible unsafe locking scenario:\n\n\t CPU0\n\t ----\n\t lock(rlock-AF_PACKET);\n\t \n\t lock(rlock-AF_PACKET);\n\n\t *** DEADLOCK ***\n\n\tCall Trace:\n\t \n\t dump_stack_lvl+0x73/0xa0\n\t mark_lock+0x102e/0x16b0\n\t __lock_acquire+0x9ae/0x6170\n\t lock_acquire+0x19a/0x4f0\n\t _raw_spin_lock+0x27/0x40\n\t tpacket_rcv+0x863/0x3b30\n\t dev_queue_xmit_nit+0x709/0xa40\n\t vrf_finish_direct+0x26e/0x340 [vrf]\n\t vrf_l3_out+0x5f4/0xe80 [vrf]\n\t __ip_local_out+0x51e/0x7a0\n [...]", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-667" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T18:15:18Z" diff --git a/advisories/unreviewed/2024/10/GHSA-j4rf-24v6-vq7x/GHSA-j4rf-24v6-vq7x.json b/advisories/unreviewed/2024/10/GHSA-j4rf-24v6-vq7x/GHSA-j4rf-24v6-vq7x.json index 20b3d2b78eb..ab0c7bc09c0 100644 --- a/advisories/unreviewed/2024/10/GHSA-j4rf-24v6-vq7x/GHSA-j4rf-24v6-vq7x.json +++ b/advisories/unreviewed/2024/10/GHSA-j4rf-24v6-vq7x/GHSA-j4rf-24v6-vq7x.json @@ -29,7 +29,8 @@ "database_specific": { "cwe_ids": [ "CWE-257", - "CWE-522" + "CWE-522", + "CWE-922" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-j9pm-88v7-rvp8/GHSA-j9pm-88v7-rvp8.json b/advisories/unreviewed/2024/10/GHSA-j9pm-88v7-rvp8/GHSA-j9pm-88v7-rvp8.json index 9453c05a28b..33f0b4c2c26 100644 --- a/advisories/unreviewed/2024/10/GHSA-j9pm-88v7-rvp8/GHSA-j9pm-88v7-rvp8.json +++ b/advisories/unreviewed/2024/10/GHSA-j9pm-88v7-rvp8/GHSA-j9pm-88v7-rvp8.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-203" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-jgmx-4v96-mgr5/GHSA-jgmx-4v96-mgr5.json b/advisories/unreviewed/2024/10/GHSA-jgmx-4v96-mgr5/GHSA-jgmx-4v96-mgr5.json index 32620b758e5..3e5eb1ba030 100644 --- a/advisories/unreviewed/2024/10/GHSA-jgmx-4v96-mgr5/GHSA-jgmx-4v96-mgr5.json +++ b/advisories/unreviewed/2024/10/GHSA-jgmx-4v96-mgr5/GHSA-jgmx-4v96-mgr5.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-362" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-jv24-5j5x-m8w6/GHSA-jv24-5j5x-m8w6.json b/advisories/unreviewed/2024/10/GHSA-jv24-5j5x-m8w6/GHSA-jv24-5j5x-m8w6.json index a62e8efcb19..1dd7c42a9e4 100644 --- a/advisories/unreviewed/2024/10/GHSA-jv24-5j5x-m8w6/GHSA-jv24-5j5x-m8w6.json +++ b/advisories/unreviewed/2024/10/GHSA-jv24-5j5x-m8w6/GHSA-jv24-5j5x-m8w6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jv24-5j5x-m8w6", - "modified": "2024-10-29T15:32:03Z", + "modified": "2024-10-31T15:30:58Z", "published": "2024-10-29T15:32:03Z", "aliases": [ "CVE-2024-10460" ], "details": "The origin of an external protocol handler prompt could have been obscured using a data: URL within an `iframe`. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -43,7 +46,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-29T13:15:03Z" diff --git a/advisories/unreviewed/2024/10/GHSA-jwgw-4h9p-rxx6/GHSA-jwgw-4h9p-rxx6.json b/advisories/unreviewed/2024/10/GHSA-jwgw-4h9p-rxx6/GHSA-jwgw-4h9p-rxx6.json new file mode 100644 index 00000000000..2fff5f3230e --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-jwgw-4h9p-rxx6/GHSA-jwgw-4h9p-rxx6.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jwgw-4h9p-rxx6", + "modified": "2024-10-31T15:30:59Z", + "published": "2024-10-31T15:30:59Z", + "aliases": [ + "CVE-2024-51254" + ], + "details": "DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the sign_cacertificate function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51254" + }, + { + "type": "WEB", + "url": "https://github.com/fu37kola/cve/blob/main/DrayTek/Vigor3900/1.5.1.3/DrayTek_Vigor_3900_1.5.1.3.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-31T14:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-mrpf-hrph-4gm4/GHSA-mrpf-hrph-4gm4.json b/advisories/unreviewed/2024/10/GHSA-mrpf-hrph-4gm4/GHSA-mrpf-hrph-4gm4.json index 11e65b08c40..841d8402a9b 100644 --- a/advisories/unreviewed/2024/10/GHSA-mrpf-hrph-4gm4/GHSA-mrpf-hrph-4gm4.json +++ b/advisories/unreviewed/2024/10/GHSA-mrpf-hrph-4gm4/GHSA-mrpf-hrph-4gm4.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-269" + "CWE-269", + "CWE-639" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-mwrg-g727-8qpv/GHSA-mwrg-g727-8qpv.json b/advisories/unreviewed/2024/10/GHSA-mwrg-g727-8qpv/GHSA-mwrg-g727-8qpv.json index 5937971455a..8ca73b82836 100644 --- a/advisories/unreviewed/2024/10/GHSA-mwrg-g727-8qpv/GHSA-mwrg-g727-8qpv.json +++ b/advisories/unreviewed/2024/10/GHSA-mwrg-g727-8qpv/GHSA-mwrg-g727-8qpv.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-203" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-mxvr-rwhq-rpw8/GHSA-mxvr-rwhq-rpw8.json b/advisories/unreviewed/2024/10/GHSA-mxvr-rwhq-rpw8/GHSA-mxvr-rwhq-rpw8.json new file mode 100644 index 00000000000..d3e57b444ac --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-mxvr-rwhq-rpw8/GHSA-mxvr-rwhq-rpw8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mxvr-rwhq-rpw8", + "modified": "2024-10-31T15:30:59Z", + "published": "2024-10-31T15:30:59Z", + "aliases": [ + "CVE-2024-10454" + ], + "details": "Clickjacking vulnerability in Clibo Manager v1.1.9.12 in the '/public/login' directory, a login panel. This vulnerability occurs due to the absence of an X-Frame-Options server-side header. An attacker could overlay a transparent iframe to perform click hijacking on victims.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10454" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/clickjacking-vulnerability-clibo-manager" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1021" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-31T13:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-p7rx-j8x8-2j2p/GHSA-p7rx-j8x8-2j2p.json b/advisories/unreviewed/2024/10/GHSA-p7rx-j8x8-2j2p/GHSA-p7rx-j8x8-2j2p.json index 8fff6345971..45fc54d1664 100644 --- a/advisories/unreviewed/2024/10/GHSA-p7rx-j8x8-2j2p/GHSA-p7rx-j8x8-2j2p.json +++ b/advisories/unreviewed/2024/10/GHSA-p7rx-j8x8-2j2p/GHSA-p7rx-j8x8-2j2p.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-79", "CWE-80" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/10/GHSA-q6cx-8jm9-6wv4/GHSA-q6cx-8jm9-6wv4.json b/advisories/unreviewed/2024/10/GHSA-q6cx-8jm9-6wv4/GHSA-q6cx-8jm9-6wv4.json index 5c85f727d3b..421e89eb1de 100644 --- a/advisories/unreviewed/2024/10/GHSA-q6cx-8jm9-6wv4/GHSA-q6cx-8jm9-6wv4.json +++ b/advisories/unreviewed/2024/10/GHSA-q6cx-8jm9-6wv4/GHSA-q6cx-8jm9-6wv4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q6cx-8jm9-6wv4", - "modified": "2024-10-21T21:30:52Z", + "modified": "2024-10-31T15:30:58Z", "published": "2024-10-21T21:30:52Z", "aliases": [ "CVE-2022-49000" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\niommu/vt-d: Fix PCI device refcount leak in has_external_pci()\n\nfor_each_pci_dev() is implemented by pci_get_device(). The comment of\npci_get_device() says that it will increase the reference count for the\nreturned pci_dev and also decrease the reference count for the input\npci_dev @from if it is not NULL.\n\nIf we break for_each_pci_dev() loop with pdev not NULL, we need to call\npci_dev_put() to decrease the reference count. Add the missing\npci_dev_put() before 'return true' to avoid reference count leak.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-21T20:15:11Z" diff --git a/advisories/unreviewed/2024/10/GHSA-qrjg-cmwm-3465/GHSA-qrjg-cmwm-3465.json b/advisories/unreviewed/2024/10/GHSA-qrjg-cmwm-3465/GHSA-qrjg-cmwm-3465.json index e0db987a7cc..b93469fe674 100644 --- a/advisories/unreviewed/2024/10/GHSA-qrjg-cmwm-3465/GHSA-qrjg-cmwm-3465.json +++ b/advisories/unreviewed/2024/10/GHSA-qrjg-cmwm-3465/GHSA-qrjg-cmwm-3465.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-829", "CWE-98" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/10/GHSA-v4vg-xp9f-3jx2/GHSA-v4vg-xp9f-3jx2.json b/advisories/unreviewed/2024/10/GHSA-v4vg-xp9f-3jx2/GHSA-v4vg-xp9f-3jx2.json new file mode 100644 index 00000000000..099d908da9d --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-v4vg-xp9f-3jx2/GHSA-v4vg-xp9f-3jx2.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v4vg-xp9f-3jx2", + "modified": "2024-10-31T15:30:59Z", + "published": "2024-10-31T15:30:59Z", + "aliases": [ + "CVE-2024-51259" + ], + "details": "DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the setup_cacertificate function.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51259" + }, + { + "type": "WEB", + "url": "https://github.com/fu37kola/cve/blob/main/DrayTek/Vigor3900/1.5.1.3/DrayTek_Vigor_3900_1.5.1.3.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-31T14:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-vhqv-fr8v-3cwq/GHSA-vhqv-fr8v-3cwq.json b/advisories/unreviewed/2024/10/GHSA-vhqv-fr8v-3cwq/GHSA-vhqv-fr8v-3cwq.json index c060dd297d2..2ea009dd07e 100644 --- a/advisories/unreviewed/2024/10/GHSA-vhqv-fr8v-3cwq/GHSA-vhqv-fr8v-3cwq.json +++ b/advisories/unreviewed/2024/10/GHSA-vhqv-fr8v-3cwq/GHSA-vhqv-fr8v-3cwq.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-203" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-w5cm-m7c3-4jj4/GHSA-w5cm-m7c3-4jj4.json b/advisories/unreviewed/2024/10/GHSA-w5cm-m7c3-4jj4/GHSA-w5cm-m7c3-4jj4.json index 0433023ee87..e10be7704cb 100644 --- a/advisories/unreviewed/2024/10/GHSA-w5cm-m7c3-4jj4/GHSA-w5cm-m7c3-4jj4.json +++ b/advisories/unreviewed/2024/10/GHSA-w5cm-m7c3-4jj4/GHSA-w5cm-m7c3-4jj4.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-250" + "CWE-250", + "CWE-863" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-w672-pp4p-44p3/GHSA-w672-pp4p-44p3.json b/advisories/unreviewed/2024/10/GHSA-w672-pp4p-44p3/GHSA-w672-pp4p-44p3.json new file mode 100644 index 00000000000..196856553fd --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-w672-pp4p-44p3/GHSA-w672-pp4p-44p3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w672-pp4p-44p3", + "modified": "2024-10-31T15:30:59Z", + "published": "2024-10-31T15:30:59Z", + "aliases": [ + "CVE-2024-8934" + ], + "details": "A local user with administrative access rights can enter specialy crafted values for settings at the user interface (UI) of the TwinCAT Package Manager which then causes arbitrary OS commands to be executed.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8934" + }, + { + "type": "WEB", + "url": "https://cert.vde.com/en/advisories/VDE-2024-064" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-31T13:15:15Z" + } +} \ No newline at end of file