diff --git a/advisories/unreviewed/2023/03/GHSA-2787-j4hr-mpvr/GHSA-2787-j4hr-mpvr.json b/advisories/unreviewed/2023/03/GHSA-2787-j4hr-mpvr/GHSA-2787-j4hr-mpvr.json
index e5239e6d2fe..bfdb343da1b 100644
--- a/advisories/unreviewed/2023/03/GHSA-2787-j4hr-mpvr/GHSA-2787-j4hr-mpvr.json
+++ b/advisories/unreviewed/2023/03/GHSA-2787-j4hr-mpvr/GHSA-2787-j4hr-mpvr.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2787-j4hr-mpvr",
- "modified": "2023-03-15T15:30:23Z",
+ "modified": "2025-02-27T21:31:49Z",
"published": "2023-03-10T15:30:42Z",
"aliases": [
"CVE-2022-48111"
diff --git a/advisories/unreviewed/2023/03/GHSA-9qm7-j7mp-35jq/GHSA-9qm7-j7mp-35jq.json b/advisories/unreviewed/2023/03/GHSA-9qm7-j7mp-35jq/GHSA-9qm7-j7mp-35jq.json
index 1f67ad47dbb..1106ad85883 100644
--- a/advisories/unreviewed/2023/03/GHSA-9qm7-j7mp-35jq/GHSA-9qm7-j7mp-35jq.json
+++ b/advisories/unreviewed/2023/03/GHSA-9qm7-j7mp-35jq/GHSA-9qm7-j7mp-35jq.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9qm7-j7mp-35jq",
- "modified": "2023-03-16T18:30:31Z",
+ "modified": "2025-02-27T21:31:49Z",
"published": "2023-03-13T12:30:17Z",
"aliases": [
"CVE-2023-25283"
diff --git a/advisories/unreviewed/2023/03/GHSA-c2r9-vh8c-wg3c/GHSA-c2r9-vh8c-wg3c.json b/advisories/unreviewed/2023/03/GHSA-c2r9-vh8c-wg3c/GHSA-c2r9-vh8c-wg3c.json
index e19f9fa79c1..7e6ed4457cb 100644
--- a/advisories/unreviewed/2023/03/GHSA-c2r9-vh8c-wg3c/GHSA-c2r9-vh8c-wg3c.json
+++ b/advisories/unreviewed/2023/03/GHSA-c2r9-vh8c-wg3c/GHSA-c2r9-vh8c-wg3c.json
@@ -25,7 +25,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-284"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2023/03/GHSA-cc55-g3cv-hx93/GHSA-cc55-g3cv-hx93.json b/advisories/unreviewed/2023/03/GHSA-cc55-g3cv-hx93/GHSA-cc55-g3cv-hx93.json
index f1cf71db926..53748c08922 100644
--- a/advisories/unreviewed/2023/03/GHSA-cc55-g3cv-hx93/GHSA-cc55-g3cv-hx93.json
+++ b/advisories/unreviewed/2023/03/GHSA-cc55-g3cv-hx93/GHSA-cc55-g3cv-hx93.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cc55-g3cv-hx93",
- "modified": "2023-03-16T18:30:28Z",
+ "modified": "2025-02-27T21:31:53Z",
"published": "2023-03-14T18:30:23Z",
"aliases": [
"CVE-2023-27069"
diff --git a/advisories/unreviewed/2023/03/GHSA-fg8g-w97j-ff9c/GHSA-fg8g-w97j-ff9c.json b/advisories/unreviewed/2023/03/GHSA-fg8g-w97j-ff9c/GHSA-fg8g-w97j-ff9c.json
index 36569eeab5b..ef424ae445f 100644
--- a/advisories/unreviewed/2023/03/GHSA-fg8g-w97j-ff9c/GHSA-fg8g-w97j-ff9c.json
+++ b/advisories/unreviewed/2023/03/GHSA-fg8g-w97j-ff9c/GHSA-fg8g-w97j-ff9c.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fg8g-w97j-ff9c",
- "modified": "2023-03-15T18:30:23Z",
+ "modified": "2025-02-27T21:31:49Z",
"published": "2023-03-10T18:30:22Z",
"aliases": [
"CVE-2023-26075"
@@ -27,6 +27,10 @@
"type": "WEB",
"url": "https://googleprojectzero.blogspot.com/2023/03/multiple-internet-to-baseband-remote-rce.html"
},
+ {
+ "type": "WEB",
+ "url": "https://project-zero.issues.chromium.org/issues/42451537"
+ },
{
"type": "WEB",
"url": "https://semiconductor.samsung.com/processor/mobile-processor"
diff --git a/advisories/unreviewed/2023/03/GHSA-frg3-hpqv-5jmr/GHSA-frg3-hpqv-5jmr.json b/advisories/unreviewed/2023/03/GHSA-frg3-hpqv-5jmr/GHSA-frg3-hpqv-5jmr.json
index 5e300ab49b4..1d4befa6f6b 100644
--- a/advisories/unreviewed/2023/03/GHSA-frg3-hpqv-5jmr/GHSA-frg3-hpqv-5jmr.json
+++ b/advisories/unreviewed/2023/03/GHSA-frg3-hpqv-5jmr/GHSA-frg3-hpqv-5jmr.json
@@ -25,7 +25,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-269"
+ ],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2023/03/GHSA-gjmx-fc7p-8h6w/GHSA-gjmx-fc7p-8h6w.json b/advisories/unreviewed/2023/03/GHSA-gjmx-fc7p-8h6w/GHSA-gjmx-fc7p-8h6w.json
index c7680cfc1f8..4582a845583 100644
--- a/advisories/unreviewed/2023/03/GHSA-gjmx-fc7p-8h6w/GHSA-gjmx-fc7p-8h6w.json
+++ b/advisories/unreviewed/2023/03/GHSA-gjmx-fc7p-8h6w/GHSA-gjmx-fc7p-8h6w.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gjmx-fc7p-8h6w",
- "modified": "2023-03-17T06:30:35Z",
+ "modified": "2025-02-27T21:31:51Z",
"published": "2023-03-14T15:30:16Z",
"aliases": [
"CVE-2023-27073"
diff --git a/advisories/unreviewed/2023/03/GHSA-q2xm-492x-5xjf/GHSA-q2xm-492x-5xjf.json b/advisories/unreviewed/2023/03/GHSA-q2xm-492x-5xjf/GHSA-q2xm-492x-5xjf.json
index 7451c7e154d..e489b637279 100644
--- a/advisories/unreviewed/2023/03/GHSA-q2xm-492x-5xjf/GHSA-q2xm-492x-5xjf.json
+++ b/advisories/unreviewed/2023/03/GHSA-q2xm-492x-5xjf/GHSA-q2xm-492x-5xjf.json
@@ -25,7 +25,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-427"
+ ],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/04/GHSA-gfm6-gxrr-6c2j/GHSA-gfm6-gxrr-6c2j.json b/advisories/unreviewed/2024/04/GHSA-gfm6-gxrr-6c2j/GHSA-gfm6-gxrr-6c2j.json
index ec7bed8c728..b6ee452d6bb 100644
--- a/advisories/unreviewed/2024/04/GHSA-gfm6-gxrr-6c2j/GHSA-gfm6-gxrr-6c2j.json
+++ b/advisories/unreviewed/2024/04/GHSA-gfm6-gxrr-6c2j/GHSA-gfm6-gxrr-6c2j.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gfm6-gxrr-6c2j",
- "modified": "2024-04-04T03:31:08Z",
+ "modified": "2025-02-27T21:31:56Z",
"published": "2024-04-04T03:31:08Z",
"aliases": [
"CVE-2024-2868"
@@ -33,7 +33,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-80"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/04/GHSA-vmh5-6rg4-ggmq/GHSA-vmh5-6rg4-ggmq.json b/advisories/unreviewed/2024/04/GHSA-vmh5-6rg4-ggmq/GHSA-vmh5-6rg4-ggmq.json
index 78bb859e619..6fe1b81dddf 100644
--- a/advisories/unreviewed/2024/04/GHSA-vmh5-6rg4-ggmq/GHSA-vmh5-6rg4-ggmq.json
+++ b/advisories/unreviewed/2024/04/GHSA-vmh5-6rg4-ggmq/GHSA-vmh5-6rg4-ggmq.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vmh5-6rg4-ggmq",
- "modified": "2024-10-31T15:30:57Z",
+ "modified": "2025-02-27T21:31:56Z",
"published": "2024-04-03T18:30:41Z",
"aliases": [
"CVE-2024-26735"
@@ -58,6 +58,10 @@
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2024/06/msg00020.html"
+ },
+ {
+ "type": "WEB",
+ "url": "https://security.netapp.com/advisory/ntap-20241101-0012"
}
],
"database_specific": {
diff --git a/advisories/unreviewed/2024/04/GHSA-xwrr-gvqm-j58v/GHSA-xwrr-gvqm-j58v.json b/advisories/unreviewed/2024/04/GHSA-xwrr-gvqm-j58v/GHSA-xwrr-gvqm-j58v.json
index 1dd650d2d0f..1e34e9a1c83 100644
--- a/advisories/unreviewed/2024/04/GHSA-xwrr-gvqm-j58v/GHSA-xwrr-gvqm-j58v.json
+++ b/advisories/unreviewed/2024/04/GHSA-xwrr-gvqm-j58v/GHSA-xwrr-gvqm-j58v.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xwrr-gvqm-j58v",
- "modified": "2024-04-05T21:32:43Z",
+ "modified": "2025-02-27T21:31:56Z",
"published": "2024-04-05T21:32:43Z",
"aliases": [
"CVE-2024-29741"
],
"details": "In pblS2mpuResume of s2mpu.c, there is a possible mitigation bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-269"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-04-05T20:15:08Z"
diff --git a/advisories/unreviewed/2024/10/GHSA-49vr-v9q4-q4ph/GHSA-49vr-v9q4-q4ph.json b/advisories/unreviewed/2024/10/GHSA-49vr-v9q4-q4ph/GHSA-49vr-v9q4-q4ph.json
index 51bc237032f..00d4c3d5a12 100644
--- a/advisories/unreviewed/2024/10/GHSA-49vr-v9q4-q4ph/GHSA-49vr-v9q4-q4ph.json
+++ b/advisories/unreviewed/2024/10/GHSA-49vr-v9q4-q4ph/GHSA-49vr-v9q4-q4ph.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-49vr-v9q4-q4ph",
- "modified": "2024-10-16T09:30:30Z",
+ "modified": "2025-02-27T21:31:59Z",
"published": "2024-10-16T09:30:30Z",
"aliases": [
"CVE-2020-36835"
@@ -34,7 +34,8 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-200"
+ "CWE-200",
+ "CWE-862"
],
"severity": "MODERATE",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/10/GHSA-mf2q-g3w5-qq7r/GHSA-mf2q-g3w5-qq7r.json b/advisories/unreviewed/2024/10/GHSA-mf2q-g3w5-qq7r/GHSA-mf2q-g3w5-qq7r.json
index 1664d4b116c..e6837d214d4 100644
--- a/advisories/unreviewed/2024/10/GHSA-mf2q-g3w5-qq7r/GHSA-mf2q-g3w5-qq7r.json
+++ b/advisories/unreviewed/2024/10/GHSA-mf2q-g3w5-qq7r/GHSA-mf2q-g3w5-qq7r.json
@@ -1,13 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mf2q-g3w5-qq7r",
- "modified": "2024-10-08T18:33:14Z",
+ "modified": "2025-02-27T21:31:58Z",
"published": "2024-10-08T18:33:14Z",
"aliases": [
"CVE-2024-8626"
],
"details": "Due to a memory leak, a denial-of-service vulnerability exists in the Rockwell Automation affected products. A malicious actor could exploit this vulnerability by performing multiple actions on certain web pages of the product causing the affected products to become fully unavailable and require a power cycle to recover.",
"severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
+ },
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
@@ -26,7 +30,8 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-400"
+ "CWE-400",
+ "CWE-401"
],
"severity": "HIGH",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/12/GHSA-vhgj-m2g2-6jfx/GHSA-vhgj-m2g2-6jfx.json b/advisories/unreviewed/2024/12/GHSA-vhgj-m2g2-6jfx/GHSA-vhgj-m2g2-6jfx.json
index 56e3d69e318..8d1b77db79c 100644
--- a/advisories/unreviewed/2024/12/GHSA-vhgj-m2g2-6jfx/GHSA-vhgj-m2g2-6jfx.json
+++ b/advisories/unreviewed/2024/12/GHSA-vhgj-m2g2-6jfx/GHSA-vhgj-m2g2-6jfx.json
@@ -42,7 +42,8 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-74"
+ "CWE-74",
+ "CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2025/01/GHSA-2p6v-g3wm-x2qp/GHSA-2p6v-g3wm-x2qp.json b/advisories/unreviewed/2025/01/GHSA-2p6v-g3wm-x2qp/GHSA-2p6v-g3wm-x2qp.json
index 11c9a2ea27d..eb13c3cbbfb 100644
--- a/advisories/unreviewed/2025/01/GHSA-2p6v-g3wm-x2qp/GHSA-2p6v-g3wm-x2qp.json
+++ b/advisories/unreviewed/2025/01/GHSA-2p6v-g3wm-x2qp/GHSA-2p6v-g3wm-x2qp.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2p6v-g3wm-x2qp",
- "modified": "2025-01-24T00:31:47Z",
+ "modified": "2025-02-27T21:32:01Z",
"published": "2025-01-24T00:31:47Z",
"aliases": [
"CVE-2024-53379"
],
"details": "Heap buffer overflow in the server site handshake implementation in Real Time Logic LLC's SharkSSL version (from 05/05/24) commit 64808a5e12c83b38f85c943dee0112e428dc2a43 allows a remote attacker to trigger a Denial-of-Service via a malformed Client-Hello message.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-120"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-23T23:15:07Z"
diff --git a/advisories/unreviewed/2025/02/GHSA-22qr-hr3v-pmr2/GHSA-22qr-hr3v-pmr2.json b/advisories/unreviewed/2025/02/GHSA-22qr-hr3v-pmr2/GHSA-22qr-hr3v-pmr2.json
new file mode 100644
index 00000000000..8ce29843633
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-22qr-hr3v-pmr2/GHSA-22qr-hr3v-pmr2.json
@@ -0,0 +1,33 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-22qr-hr3v-pmr2",
+ "modified": "2025-02-27T21:32:18Z",
+ "published": "2025-02-27T21:32:18Z",
+ "aliases": [
+ "CVE-2024-41338"
+ ],
+ "details": "A NULL pointer dereference in Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vigor 2862/2926 prior to v3.9.9.4, Vigor 2133/2762/2832 prior to v3.9.8, Vigor 2135/2765/2766 prior to v4.4.5.1, Vigor 2865/2866/2927 prior to v4.4.5.3, Vigor 2962/3910 prior to v4.3.2.7, Vigor 3912 prior to v4.3.5.2, and Vigor 2925 up to v3.9.6 allows attackers to cause a Denial of Service (DoS) via a crafted DHCP request.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41338"
+ },
+ {
+ "type": "WEB",
+ "url": "https://medium.com/faraday/advisory-multiple-vulnerabilities-affecting-draytek-routers-78a6cb8b3946"
+ },
+ {
+ "type": "WEB",
+ "url": "http://draytek.com"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-27T21:15:36Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-2c2p-jp6r-5757/GHSA-2c2p-jp6r-5757.json b/advisories/unreviewed/2025/02/GHSA-2c2p-jp6r-5757/GHSA-2c2p-jp6r-5757.json
new file mode 100644
index 00000000000..347f496b1b4
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-2c2p-jp6r-5757/GHSA-2c2p-jp6r-5757.json
@@ -0,0 +1,45 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-2c2p-jp6r-5757",
+ "modified": "2025-02-27T21:32:18Z",
+ "published": "2025-02-27T21:32:18Z",
+ "aliases": [
+ "CVE-2024-55160"
+ ],
+ "details": "GFast between v2 to v3.2 was discovered to contain a SQL injection vulnerability via the OrderBy parameter at /system/operLog/list.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55160"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/SuperDu1/CVE/issues/2"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/tiger1103/gfast/blob/os-v3.2/api/v1/system/sys_oper_log.go#L35"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/tiger1103/gfast/blob/os-v3.2/internal/app/system/logic/sysOperLog/sys_oper_log.go#L121"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/tiger1103/gfast/tree/os-v3.2"
+ },
+ {
+ "type": "WEB",
+ "url": "http://gfast.com"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-27T21:15:37Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-2jj4-33hw-m7m9/GHSA-2jj4-33hw-m7m9.json b/advisories/unreviewed/2025/02/GHSA-2jj4-33hw-m7m9/GHSA-2jj4-33hw-m7m9.json
new file mode 100644
index 00000000000..181fe4d384e
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-2jj4-33hw-m7m9/GHSA-2jj4-33hw-m7m9.json
@@ -0,0 +1,45 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-2jj4-33hw-m7m9",
+ "modified": "2025-02-27T21:32:17Z",
+ "published": "2025-02-27T21:32:17Z",
+ "aliases": [
+ "CVE-2025-21821"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: omap: use threaded IRQ for LCD DMA\n\nWhen using touchscreen and framebuffer, Nokia 770 crashes easily with:\n\n BUG: scheduling while atomic: irq/144-ads7846/82/0x00010000\n Modules linked in: usb_f_ecm g_ether usb_f_rndis u_ether libcomposite configfs omap_udc ohci_omap ohci_hcd\n CPU: 0 UID: 0 PID: 82 Comm: irq/144-ads7846 Not tainted 6.12.7-770 #2\n Hardware name: Nokia 770\n Call trace:\n unwind_backtrace from show_stack+0x10/0x14\n show_stack from dump_stack_lvl+0x54/0x5c\n dump_stack_lvl from __schedule_bug+0x50/0x70\n __schedule_bug from __schedule+0x4d4/0x5bc\n __schedule from schedule+0x34/0xa0\n schedule from schedule_preempt_disabled+0xc/0x10\n schedule_preempt_disabled from __mutex_lock.constprop.0+0x218/0x3b4\n __mutex_lock.constprop.0 from clk_prepare_lock+0x38/0xe4\n clk_prepare_lock from clk_set_rate+0x18/0x154\n clk_set_rate from sossi_read_data+0x4c/0x168\n sossi_read_data from hwa742_read_reg+0x5c/0x8c\n hwa742_read_reg from send_frame_handler+0xfc/0x300\n send_frame_handler from process_pending_requests+0x74/0xd0\n process_pending_requests from lcd_dma_irq_handler+0x50/0x74\n lcd_dma_irq_handler from __handle_irq_event_percpu+0x44/0x130\n __handle_irq_event_percpu from handle_irq_event+0x28/0x68\n handle_irq_event from handle_level_irq+0x9c/0x170\n handle_level_irq from generic_handle_domain_irq+0x2c/0x3c\n generic_handle_domain_irq from omap1_handle_irq+0x40/0x8c\n omap1_handle_irq from generic_handle_arch_irq+0x28/0x3c\n generic_handle_arch_irq from call_with_stack+0x1c/0x24\n call_with_stack from __irq_svc+0x94/0xa8\n Exception stack(0xc5255da0 to 0xc5255de8)\n 5da0: 00000001 c22fc620 00000000 00000000 c08384a8 c106fc00 00000000 c240c248\n 5dc0: c113a600 c3f6ec30 00000001 00000000 c22fc620 c5255df0 c22fc620 c0279a94\n 5de0: 60000013 ffffffff\n __irq_svc from clk_prepare_lock+0x4c/0xe4\n clk_prepare_lock from clk_get_rate+0x10/0x74\n clk_get_rate from uwire_setup_transfer+0x40/0x180\n uwire_setup_transfer from spi_bitbang_transfer_one+0x2c/0x9c\n spi_bitbang_transfer_one from spi_transfer_one_message+0x2d0/0x664\n spi_transfer_one_message from __spi_pump_transfer_message+0x29c/0x498\n __spi_pump_transfer_message from __spi_sync+0x1f8/0x2e8\n __spi_sync from spi_sync+0x24/0x40\n spi_sync from ads7846_halfd_read_state+0x5c/0x1c0\n ads7846_halfd_read_state from ads7846_irq+0x58/0x348\n ads7846_irq from irq_thread_fn+0x1c/0x78\n irq_thread_fn from irq_thread+0x120/0x228\n irq_thread from kthread+0xc8/0xe8\n kthread from ret_from_fork+0x14/0x28\n\nAs a quick fix, switch to a threaded IRQ which provides a stable system.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21821"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/7bbbd311dd503653a2cc86d9226740883051dc92"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/8392ea100f0b86c234c739c6662f39f0ccc0cefd"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/aa8e22cbedeb626f2a6bda0aea362353d627cd0a"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/e4b6b665df815b4841e71b72f06446884e8aad40"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/fb6a5edb60921887d7d10619fcdcbee9759552cb"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-27T20:16:04Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-37p3-cfcq-p2hp/GHSA-37p3-cfcq-p2hp.json b/advisories/unreviewed/2025/02/GHSA-37p3-cfcq-p2hp/GHSA-37p3-cfcq-p2hp.json
new file mode 100644
index 00000000000..7fdb586b769
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-37p3-cfcq-p2hp/GHSA-37p3-cfcq-p2hp.json
@@ -0,0 +1,37 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-37p3-cfcq-p2hp",
+ "modified": "2025-02-27T21:32:17Z",
+ "published": "2025-02-27T21:32:17Z",
+ "aliases": [
+ "CVE-2025-21815"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/compaction: fix UBSAN shift-out-of-bounds warning\n\nsyzkaller reported a UBSAN shift-out-of-bounds warning of (1UL << order)\nin isolate_freepages_block(). The bogus compound_order can be any value\nbecause it is union with flags. Add back the MAX_PAGE_ORDER check to fix\nthe warning.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21815"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/10b7d3eb535098ccd4c82a182a33655d8a0e5c88"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/4491159774d973a9e2e998d25d8fbb20fada6dfa"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/d1366e74342e75555af2648a2964deb2d5c92200"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-27T20:16:04Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-3f4p-8qj7-5fxp/GHSA-3f4p-8qj7-5fxp.json b/advisories/unreviewed/2025/02/GHSA-3f4p-8qj7-5fxp/GHSA-3f4p-8qj7-5fxp.json
new file mode 100644
index 00000000000..f2f0e254cf6
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-3f4p-8qj7-5fxp/GHSA-3f4p-8qj7-5fxp.json
@@ -0,0 +1,33 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-3f4p-8qj7-5fxp",
+ "modified": "2025-02-27T21:32:17Z",
+ "published": "2025-02-27T21:32:17Z",
+ "aliases": [
+ "CVE-2025-21817"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nblock: mark GFP_NOIO around sysfs ->store()\n\nsysfs ->store is called with queue freezed, meantime we have several\n->store() callbacks(update_nr_requests, wbt, scheduler) to allocate\nmemory with GFP_KERNEL which may run into direct reclaim code path,\nthen potential deadlock can be caused.\n\nFix the issue by marking NOIO around sysfs ->store()",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21817"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/2566ce907e5d5db8a039647208e029ce559baa31"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/7c0be4ead1f8f5f8be0803f347de0de81e3b8e1c"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-27T20:16:04Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-3g4q-gv3v-9pj2/GHSA-3g4q-gv3v-9pj2.json b/advisories/unreviewed/2025/02/GHSA-3g4q-gv3v-9pj2/GHSA-3g4q-gv3v-9pj2.json
index 2f87df55359..4dc6320332c 100644
--- a/advisories/unreviewed/2025/02/GHSA-3g4q-gv3v-9pj2/GHSA-3g4q-gv3v-9pj2.json
+++ b/advisories/unreviewed/2025/02/GHSA-3g4q-gv3v-9pj2/GHSA-3g4q-gv3v-9pj2.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3g4q-gv3v-9pj2",
- "modified": "2025-02-27T03:34:01Z",
+ "modified": "2025-02-27T21:32:15Z",
"published": "2025-02-27T03:34:01Z",
"aliases": [
"CVE-2025-21714"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/mlx5: Fix implicit ODP use after free\n\nPrevent double queueing of implicit ODP mr destroy work by using\n__xa_cmpxchg() to make sure this is the only time we are destroying this\nspecific mr.\n\nWithout this change, we could try to invalidate this mr twice, which in\nturn could result in queuing a MR work destroy twice, and eventually the\nsecond work could execute after the MR was freed due to the first work,\ncausing a user after free and trace below.\n\n refcount_t: underflow; use-after-free.\n WARNING: CPU: 2 PID: 12178 at lib/refcount.c:28 refcount_warn_saturate+0x12b/0x130\n Modules linked in: bonding ib_ipoib vfio_pci ip_gre geneve nf_tables ip6_gre gre ip6_tunnel tunnel6 ipip tunnel4 ib_umad rdma_ucm mlx5_vfio_pci vfio_pci_core vfio_iommu_type1 mlx5_ib vfio ib_uverbs mlx5_core iptable_raw openvswitch nsh rpcrdma ib_iser libiscsi scsi_transport_iscsi rdma_cm iw_cm ib_cm ib_core xt_conntrack xt_MASQUERADE nf_conntrack_netlink nfnetlink xt_addrtype iptable_nat nf_nat br_netfilter rpcsec_gss_krb5 auth_rpcgss oid_registry overlay zram zsmalloc fuse [last unloaded: ib_uverbs]\n CPU: 2 PID: 12178 Comm: kworker/u20:5 Not tainted 6.5.0-rc1_net_next_mlx5_58c644e #1\n Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014\n Workqueue: events_unbound free_implicit_child_mr_work [mlx5_ib]\n RIP: 0010:refcount_warn_saturate+0x12b/0x130\n Code: 48 c7 c7 38 95 2a 82 c6 05 bc c6 fe 00 01 e8 0c 66 aa ff 0f 0b 5b c3 48 c7 c7 e0 94 2a 82 c6 05 a7 c6 fe 00 01 e8 f5 65 aa ff <0f> 0b 5b c3 90 8b 07 3d 00 00 00 c0 74 12 83 f8 01 74 13 8d 50 ff\n RSP: 0018:ffff8881008e3e40 EFLAGS: 00010286\n RAX: 0000000000000000 RBX: 0000000000000000 RCX: 0000000000000027\n RDX: ffff88852c91b5c8 RSI: 0000000000000001 RDI: ffff88852c91b5c0\n RBP: ffff8881dacd4e00 R08: 00000000ffffffff R09: 0000000000000019\n R10: 000000000000072e R11: 0000000063666572 R12: ffff88812bfd9e00\n R13: ffff8881c792d200 R14: ffff88810011c005 R15: ffff8881002099c0\n FS: 0000000000000000(0000) GS:ffff88852c900000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 00007f5694b5e000 CR3: 00000001153f6003 CR4: 0000000000370ea0\n DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n Call Trace:\n \n ? refcount_warn_saturate+0x12b/0x130\n free_implicit_child_mr_work+0x180/0x1b0 [mlx5_ib]\n process_one_work+0x1cc/0x3c0\n worker_thread+0x218/0x3c0\n kthread+0xc6/0xf0\n ret_from_fork+0x1f/0x30\n ",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-27T02:15:15Z"
diff --git a/advisories/unreviewed/2025/02/GHSA-3j29-8r33-hfrc/GHSA-3j29-8r33-hfrc.json b/advisories/unreviewed/2025/02/GHSA-3j29-8r33-hfrc/GHSA-3j29-8r33-hfrc.json
new file mode 100644
index 00000000000..735671a0d27
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-3j29-8r33-hfrc/GHSA-3j29-8r33-hfrc.json
@@ -0,0 +1,48 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-3j29-8r33-hfrc",
+ "modified": "2025-02-27T21:32:11Z",
+ "published": "2025-02-27T21:32:11Z",
+ "aliases": [
+ "CVE-2022-49093"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nskbuff: fix coalescing for page_pool fragment recycling\n\nFix a use-after-free when using page_pool with page fragments. We\nencountered this problem during normal RX in the hns3 driver:\n\n(1) Initially we have three descriptors in the RX queue. The first one\n allocates PAGE1 through page_pool, and the other two allocate one\n half of PAGE2 each. Page references look like this:\n\n RX_BD1 _______ PAGE1\n RX_BD2 _______ PAGE2\n RX_BD3 _________/\n\n(2) Handle RX on the first descriptor. Allocate SKB1, eventually added\n to the receive queue by tcp_queue_rcv().\n\n(3) Handle RX on the second descriptor. Allocate SKB2 and pass it to\n netif_receive_skb():\n\n netif_receive_skb(SKB2)\n ip_rcv(SKB2)\n SKB3 = skb_clone(SKB2)\n\n SKB2 and SKB3 share a reference to PAGE2 through\n skb_shinfo()->dataref. The other ref to PAGE2 is still held by\n RX_BD3:\n\n SKB2 ---+- PAGE2\n SKB3 __/ /\n RX_BD3 _________/\n\n (3b) Now while handling TCP, coalesce SKB3 with SKB1:\n\n tcp_v4_rcv(SKB3)\n tcp_try_coalesce(to=SKB1, from=SKB3) // succeeds\n kfree_skb_partial(SKB3)\n skb_release_data(SKB3) // drops one dataref\n\n SKB1 _____ PAGE1\n \\____\n SKB2 _____ PAGE2\n /\n RX_BD3 _________/\n\n In skb_try_coalesce(), __skb_frag_ref() takes a page reference to\n PAGE2, where it should instead have increased the page_pool frag\n reference, pp_frag_count. Without coalescing, when releasing both\n SKB2 and SKB3, a single reference to PAGE2 would be dropped. Now\n when releasing SKB1 and SKB2, two references to PAGE2 will be\n dropped, resulting in underflow.\n\n (3c) Drop SKB2:\n\n af_packet_rcv(SKB2)\n consume_skb(SKB2)\n skb_release_data(SKB2) // drops second dataref\n page_pool_return_skb_page(PAGE2) // drops one pp_frag_count\n\n SKB1 _____ PAGE1\n \\____\n PAGE2\n /\n RX_BD3 _________/\n\n(4) Userspace calls recvmsg()\n Copies SKB1 and releases it. Since SKB3 was coalesced with SKB1, we\n release the SKB3 page as well:\n\n tcp_eat_recv_skb(SKB1)\n skb_release_data(SKB1)\n page_pool_return_skb_page(PAGE1)\n page_pool_return_skb_page(PAGE2) // drops second pp_frag_count\n\n(5) PAGE2 is freed, but the third RX descriptor was still using it!\n In our case this causes IOMMU faults, but it would silently corrupt\n memory if the IOMMU was disabled.\n\nChange the logic that checks whether pp_recycle SKBs can be coalesced.\nWe still reject differing pp_recycle between 'from' and 'to' SKBs, but\nin order to avoid the situation described above, we also reject\ncoalescing when both 'from' and 'to' are pp_recycled and 'from' is\ncloned.\n\nThe new logic allows coalescing a cloned pp_recycle SKB into a page\nrefcounted one, because in this case the release (4) will drop the right\nreference, the one taken by skb_try_coalesce().",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49093"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/1effe8ca4e34c34cdd9318436a4232dcb582ebf4"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/72bb856d16e883437023ff2ff77d0c498018728a"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/ba965e8605aee5387cecaa28fcf7ee9f61779a49"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/c4fa19615806a9a7e518c295b39175aa47a685ac"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-26T07:00:46Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-3pmf-5hr9-r9r6/GHSA-3pmf-5hr9-r9r6.json b/advisories/unreviewed/2025/02/GHSA-3pmf-5hr9-r9r6/GHSA-3pmf-5hr9-r9r6.json
new file mode 100644
index 00000000000..6b2036f1a73
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-3pmf-5hr9-r9r6/GHSA-3pmf-5hr9-r9r6.json
@@ -0,0 +1,33 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-3pmf-5hr9-r9r6",
+ "modified": "2025-02-27T21:32:17Z",
+ "published": "2025-02-27T21:32:17Z",
+ "aliases": [
+ "CVE-2024-41336"
+ ],
+ "details": "Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vigor 2862/2926 prior to v3.9.9.4, Vigor 2133/2762/2832 prior to v3.9.8, Vigor 2135/2765/2766 prior to v4.4.5.1, Vigor 2865/2866/2927 prior to v4.4.5.3, Vigor 2962/3910 prior to v4.3.2.7, Vigor 3912 prior to v4.3.5.2, and Vigor 2925 up to v3.9.6 were discovered to store passwords in plaintext.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41336"
+ },
+ {
+ "type": "WEB",
+ "url": "https://medium.com/faraday/advisory-multiple-vulnerabilities-affecting-draytek-routers-78a6cb8b3946"
+ },
+ {
+ "type": "WEB",
+ "url": "http://draytek.com"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-27T21:15:36Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-3r4m-vx24-mm6m/GHSA-3r4m-vx24-mm6m.json b/advisories/unreviewed/2025/02/GHSA-3r4m-vx24-mm6m/GHSA-3r4m-vx24-mm6m.json
new file mode 100644
index 00000000000..c511a8570db
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-3r4m-vx24-mm6m/GHSA-3r4m-vx24-mm6m.json
@@ -0,0 +1,48 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-3r4m-vx24-mm6m",
+ "modified": "2025-02-27T21:32:14Z",
+ "published": "2025-02-27T21:32:14Z",
+ "aliases": [
+ "CVE-2022-49470"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: btmtksdio: fix use-after-free at btmtksdio_recv_event\n\nWe should not access skb buffer data anymore after hci_recv_frame was\ncalled.\n\n[ 39.634809] BUG: KASAN: use-after-free in btmtksdio_recv_event+0x1b0\n[ 39.634855] Read of size 1 at addr ffffff80cf28a60d by task kworker\n[ 39.634962] Call trace:\n[ 39.634974] dump_backtrace+0x0/0x3b8\n[ 39.634999] show_stack+0x20/0x2c\n[ 39.635016] dump_stack_lvl+0x60/0x78\n[ 39.635040] print_address_description+0x70/0x2f0\n[ 39.635062] kasan_report+0x154/0x194\n[ 39.635079] __asan_report_load1_noabort+0x44/0x50\n[ 39.635099] btmtksdio_recv_event+0x1b0/0x1c4\n[ 39.635129] btmtksdio_txrx_work+0x6cc/0xac4\n[ 39.635157] process_one_work+0x560/0xc5c\n[ 39.635177] worker_thread+0x7ec/0xcc0\n[ 39.635195] kthread+0x2d0/0x3d0\n[ 39.635215] ret_from_fork+0x10/0x20\n[ 39.635247] Allocated by task 0:\n[ 39.635260] (stack is not available)\n[ 39.635281] Freed by task 2392:\n[ 39.635295] kasan_save_stack+0x38/0x68\n[ 39.635319] kasan_set_track+0x28/0x3c\n[ 39.635338] kasan_set_free_info+0x28/0x4c\n[ 39.635357] ____kasan_slab_free+0x104/0x150\n[ 39.635374] __kasan_slab_free+0x18/0x28\n[ 39.635391] slab_free_freelist_hook+0x114/0x248\n[ 39.635410] kfree+0xf8/0x2b4\n[ 39.635427] skb_free_head+0x58/0x98\n[ 39.635447] skb_release_data+0x2f4/0x410\n[ 39.635464] skb_release_all+0x50/0x60\n[ 39.635481] kfree_skb+0xc8/0x25c\n[ 39.635498] hci_event_packet+0x894/0xca4 [bluetooth]\n[ 39.635721] hci_rx_work+0x1c8/0x68c [bluetooth]\n[ 39.635925] process_one_work+0x560/0xc5c\n[ 39.635951] worker_thread+0x7ec/0xcc0\n[ 39.635970] kthread+0x2d0/0x3d0\n[ 39.635990] ret_from_fork+0x10/0x20\n[ 39.636021] The buggy address belongs to the object at ffffff80cf28a600\n which belongs to the cache kmalloc-512 of size 512\n[ 39.636039] The buggy address is located 13 bytes inside of\n 512-byte region [ffffff80cf28a600, ffffff80cf28a800)",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49470"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/01c6a899fa6be4f4cbf60c4f44f0f6691155415f"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/02ba31e09a26e8cd4582ac8e6163d80284997727"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/0fab6361c4ba17d1b43a991bef4238a3c1754d35"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/b3cec8a42fcd11d05313c724f27e01b1db77522c"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-26T07:01:23Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-3r6h-cmr9-36j6/GHSA-3r6h-cmr9-36j6.json b/advisories/unreviewed/2025/02/GHSA-3r6h-cmr9-36j6/GHSA-3r6h-cmr9-36j6.json
new file mode 100644
index 00000000000..ab501d44b79
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-3r6h-cmr9-36j6/GHSA-3r6h-cmr9-36j6.json
@@ -0,0 +1,45 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-3r6h-cmr9-36j6",
+ "modified": "2025-02-27T21:32:16Z",
+ "published": "2025-02-27T21:32:16Z",
+ "aliases": [
+ "CVE-2024-53944"
+ ],
+ "details": "An issue was discovered on Tuoshi/Dionlink LT15D 4G Wi-Fi devices through M7628NNxlSPv2xUI_v1.0.1802.10.08_P4 and LT21B devices through M7628xUSAxUIv2_v1.0.1481.15.02_P0. A unauthenticated remote attacker with network access can exploit a command injection vulnerability. The /goform/formJsonAjaxReq endpoint fails to sanitize shell metacharacters sent via JSON parameters, thus allowing attackers to execute arbitrary OS commands with root privileges.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53944"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/actuator/cve/blob/main/Tuoshi/CVE-2024-53944-Whitepaper.pdf"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/actuator/cve/blob/main/Tuoshi/CVE-2024-53944.txt"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/actuator/cve/blob/main/Tuoshi/Firmware-M7628NNxISPv2xUI_v1.0.1802.10.08_P4-Blind-CMD-Injection-unauth-WAN.gif"
+ },
+ {
+ "type": "WEB",
+ "url": "http://www.tuoshi.net/productview.asp?id=218"
+ },
+ {
+ "type": "WEB",
+ "url": "http://www.tuoshi.net/productview.asp?id=226"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-27T20:16:01Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-3vq2-wj5j-j897/GHSA-3vq2-wj5j-j897.json b/advisories/unreviewed/2025/02/GHSA-3vq2-wj5j-j897/GHSA-3vq2-wj5j-j897.json
new file mode 100644
index 00000000000..74b11ea74af
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-3vq2-wj5j-j897/GHSA-3vq2-wj5j-j897.json
@@ -0,0 +1,41 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-3vq2-wj5j-j897",
+ "modified": "2025-02-27T21:32:16Z",
+ "published": "2025-02-27T21:32:16Z",
+ "aliases": [
+ "CVE-2025-21803"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nLoongArch: Fix warnings during S3 suspend\n\nThe enable_gpe_wakeup() function calls acpi_enable_all_wakeup_gpes(),\nand the later one may call the preempt_schedule_common() function,\nresulting in a thread switch and causing the CPU to be in an interrupt\nenabled state after the enable_gpe_wakeup() function returns, leading\nto the warnings as follow.\n\n[ C0] WARNING: ... at kernel/time/timekeeping.c:845 ktime_get+0xbc/0xc8\n[ C0] ...\n[ C0] Call Trace:\n[ C0] [<90000000002243b4>] show_stack+0x64/0x188\n[ C0] [<900000000164673c>] dump_stack_lvl+0x60/0x88\n[ C0] [<90000000002687e4>] __warn+0x8c/0x148\n[ C0] [<90000000015e9978>] report_bug+0x1c0/0x2b0\n[ C0] [<90000000016478e4>] do_bp+0x204/0x3b8\n[ C0] [<90000000025b1924>] exception_handlers+0x1924/0x10000\n[ C0] [<9000000000343bbc>] ktime_get+0xbc/0xc8\n[ C0] [<9000000000354c08>] tick_sched_timer+0x30/0xb0\n[ C0] [<90000000003408e0>] __hrtimer_run_queues+0x160/0x378\n[ C0] [<9000000000341f14>] hrtimer_interrupt+0x144/0x388\n[ C0] [<9000000000228348>] constant_timer_interrupt+0x38/0x48\n[ C0] [<90000000002feba4>] __handle_irq_event_percpu+0x64/0x1e8\n[ C0] [<90000000002fed48>] handle_irq_event_percpu+0x20/0x80\n[ C0] [<9000000000306b9c>] handle_percpu_irq+0x5c/0x98\n[ C0] [<90000000002fd4a0>] generic_handle_domain_irq+0x30/0x48\n[ C0] [<9000000000d0c7b0>] handle_cpu_irq+0x70/0xa8\n[ C0] [<9000000001646b30>] handle_loongarch_irq+0x30/0x48\n[ C0] [<9000000001646bc8>] do_vint+0x80/0xe0\n[ C0] [<90000000002aea1c>] finish_task_switch.isra.0+0x8c/0x2a8\n[ C0] [<900000000164e34c>] __schedule+0x314/0xa48\n[ C0] [<900000000164ead8>] schedule+0x58/0xf0\n[ C0] [<9000000000294a2c>] worker_thread+0x224/0x498\n[ C0] [<900000000029d2f0>] kthread+0xf8/0x108\n[ C0] [<9000000000221f28>] ret_from_kernel_thread+0xc/0xa4\n[ C0]\n[ C0] ---[ end trace 0000000000000000 ]---\n\nThe root cause is acpi_enable_all_wakeup_gpes() uses a mutex to protect\nacpi_hw_enable_all_wakeup_gpes(), and acpi_ut_acquire_mutex() may cause\na thread switch. Since there is no longer concurrent execution during\nloongarch_acpi_suspend(), we can call acpi_hw_enable_all_wakeup_gpes()\ndirectly in enable_gpe_wakeup().\n\nThe solution is similar to commit 22db06337f590d01 (\"ACPI: sleep: Avoid\nbreaking S3 wakeup due to might_sleep()\").",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21803"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/194d26a5a43c26dc98a9b4e2c1d521dcb84dd1bf"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/26c0a2d93af55d30a46d5f45d3e9c42cde730168"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/8682a71a7f6de7c683f31b4334b04e19685a05f9"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/d49ab6857d98266010f3446c9c2063014db5b654"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-27T20:16:02Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-425c-353w-6mvg/GHSA-425c-353w-6mvg.json b/advisories/unreviewed/2025/02/GHSA-425c-353w-6mvg/GHSA-425c-353w-6mvg.json
new file mode 100644
index 00000000000..173c08e8dff
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-425c-353w-6mvg/GHSA-425c-353w-6mvg.json
@@ -0,0 +1,45 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-425c-353w-6mvg",
+ "modified": "2025-02-27T21:32:16Z",
+ "published": "2025-02-27T21:32:16Z",
+ "aliases": [
+ "CVE-2025-21802"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: hns3: fix oops when unload drivers paralleling\n\nWhen unload hclge driver, it tries to disable sriov first for each\nae_dev node from hnae3_ae_dev_list. If user unloads hns3 driver at\nthe time, because it removes all the ae_dev nodes, and it may cause\noops.\n\nBut we can't simply use hnae3_common_lock for this. Because in the\nprocess flow of pci_disable_sriov(), it will trigger the remove flow\nof VF, which will also take hnae3_common_lock.\n\nTo fixes it, introduce a new mutex to protect the unload process.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21802"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/82736bb83fb0221319c85c2e9917d0189cd84e1e"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/92e5995773774a3e70257e9c95ea03518268bea5"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/b5a8bc47aa0a4aa8bca5466dfa2d12dbb5b3cd0c"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/cafe9a27e22736d4a01b3933e36225f9857c7988"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/e876522659012ef2e73834a0b9f1cbe3f74d5fad"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-27T20:16:02Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-4fj4-ghwr-gjf7/GHSA-4fj4-ghwr-gjf7.json b/advisories/unreviewed/2025/02/GHSA-4fj4-ghwr-gjf7/GHSA-4fj4-ghwr-gjf7.json
new file mode 100644
index 00000000000..d7e0563cae1
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-4fj4-ghwr-gjf7/GHSA-4fj4-ghwr-gjf7.json
@@ -0,0 +1,37 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-4fj4-ghwr-gjf7",
+ "modified": "2025-02-27T21:32:16Z",
+ "published": "2025-02-27T21:32:16Z",
+ "aliases": [
+ "CVE-2025-21809"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nrxrpc, afs: Fix peer hash locking vs RCU callback\n\nIn its address list, afs now retains pointers to and refs on one or more\nrxrpc_peer objects. The address list is freed under RCU and at this time,\nit puts the refs on those peers.\n\nNow, when an rxrpc_peer object runs out of refs, it gets removed from the\npeer hash table and, for that, rxrpc has to take a spinlock. However, it\nis now being called from afs's RCU cleanup, which takes place in BH\ncontext - but it is just taking an ordinary spinlock.\n\nThe put may also be called from non-BH context, and so there exists the\npossibility of deadlock if the BH-based RCU cleanup happens whilst the hash\nspinlock is held. This led to the attached lockdep complaint.\n\nFix this by changing spinlocks of rxnet->peer_hash_lock back to\nBH-disabling locks.\n\n ================================\n WARNING: inconsistent lock state\n 6.13.0-rc5-build2+ #1223 Tainted: G E\n --------------------------------\n inconsistent {SOFTIRQ-ON-W} -> {IN-SOFTIRQ-W} usage.\n swapper/1/0 [HC0[0]:SC1[1]:HE1:SE0] takes:\n ffff88810babe228 (&rxnet->peer_hash_lock){+.?.}-{3:3}, at: rxrpc_put_peer+0xcb/0x180\n {SOFTIRQ-ON-W} state was registered at:\n mark_usage+0x164/0x180\n __lock_acquire+0x544/0x990\n lock_acquire.part.0+0x103/0x280\n _raw_spin_lock+0x2f/0x40\n rxrpc_peer_keepalive_worker+0x144/0x440\n process_one_work+0x486/0x7c0\n process_scheduled_works+0x73/0x90\n worker_thread+0x1c8/0x2a0\n kthread+0x19b/0x1b0\n ret_from_fork+0x24/0x40\n ret_from_fork_asm+0x1a/0x30\n irq event stamp: 972402\n hardirqs last enabled at (972402): [] _raw_spin_unlock_irqrestore+0x2e/0x50\n hardirqs last disabled at (972401): [] _raw_spin_lock_irqsave+0x18/0x60\n softirqs last enabled at (972300): [] handle_softirqs+0x3ee/0x430\n softirqs last disabled at (972313): [] __irq_exit_rcu+0x44/0x110\n\n other info that might help us debug this:\n Possible unsafe locking scenario:\n CPU0\n ----\n lock(&rxnet->peer_hash_lock);\n \n lock(&rxnet->peer_hash_lock);\n\n *** DEADLOCK ***\n 1 lock held by swapper/1/0:\n #0: ffffffff83576be0 (rcu_callback){....}-{0:0}, at: rcu_lock_acquire+0x7/0x30\n\n stack backtrace:\n CPU: 1 UID: 0 PID: 0 Comm: swapper/1 Tainted: G E 6.13.0-rc5-build2+ #1223\n Tainted: [E]=UNSIGNED_MODULE\n Hardware name: ASUS All Series/H97-PLUS, BIOS 2306 10/09/2014\n Call Trace:\n \n dump_stack_lvl+0x57/0x80\n print_usage_bug.part.0+0x227/0x240\n valid_state+0x53/0x70\n mark_lock_irq+0xa5/0x2f0\n mark_lock+0xf7/0x170\n mark_usage+0xe1/0x180\n __lock_acquire+0x544/0x990\n lock_acquire.part.0+0x103/0x280\n _raw_spin_lock+0x2f/0x40\n rxrpc_put_peer+0xcb/0x180\n afs_free_addrlist+0x46/0x90 [kafs]\n rcu_do_batch+0x2d2/0x640\n rcu_core+0x2f7/0x350\n handle_softirqs+0x1ee/0x430\n __irq_exit_rcu+0x44/0x110\n irq_exit_rcu+0xa/0x30\n sysvec_apic_timer_interrupt+0x7f/0xa0\n ",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21809"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/0e77dd41689637ac4e1b8fe0f27541f373640855"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/10ba5a3d57af20e494e0d979d1894260989235dd"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/79d458c13056559d49b5e41fbc4b6890e68cf65b"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-27T20:16:03Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-4v4x-mh67-4m6p/GHSA-4v4x-mh67-4m6p.json b/advisories/unreviewed/2025/02/GHSA-4v4x-mh67-4m6p/GHSA-4v4x-mh67-4m6p.json
new file mode 100644
index 00000000000..cc83ab307bc
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-4v4x-mh67-4m6p/GHSA-4v4x-mh67-4m6p.json
@@ -0,0 +1,48 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-4v4x-mh67-4m6p",
+ "modified": "2025-02-27T21:32:13Z",
+ "published": "2025-02-27T21:32:13Z",
+ "aliases": [
+ "CVE-2022-49377"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nblk-mq: don't touch ->tagset in blk_mq_get_sq_hctx\n\nblk_mq_run_hw_queues() could be run when there isn't queued request and\nafter queue is cleaned up, at that time tagset is freed, because tagset\nlifetime is covered by driver, and often freed after blk_cleanup_queue()\nreturns.\n\nSo don't touch ->tagset for figuring out current default hctx by the mapping\nbuilt in request queue, so use-after-free on tagset can be avoided. Meantime\nthis way should be fast than retrieving mapping from tagset.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49377"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/460aa288c5cd0544dcf933a2f0ad0e8c6d2d35ff"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/5d05426e2d5fd7df8afc866b78c36b37b00188b7"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/70fdd922c7bf8949f8df109cf2635dff64c90392"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/b140bac470b4f707cda59c7266214246238661df"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-26T07:01:14Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-54fp-2qhf-47h6/GHSA-54fp-2qhf-47h6.json b/advisories/unreviewed/2025/02/GHSA-54fp-2qhf-47h6/GHSA-54fp-2qhf-47h6.json
new file mode 100644
index 00000000000..c089429d79c
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-54fp-2qhf-47h6/GHSA-54fp-2qhf-47h6.json
@@ -0,0 +1,44 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-54fp-2qhf-47h6",
+ "modified": "2025-02-27T21:32:13Z",
+ "published": "2025-02-27T21:32:13Z",
+ "aliases": [
+ "CVE-2022-49168"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: do not clean up repair bio if submit fails\n\nThe submit helper will always run bio_endio() on the bio if it fails to\nsubmit, so cleaning up the bio just leads to a variety of use-after-free\nand NULL pointer dereference bugs because we race with the endio\nfunction that is cleaning up the bio. Instead just return BLK_STS_OK as\nthe repair function has to continue to process the rest of the pages,\nand the endio for the repair bio will do the appropriate cleanup for the\npage that it was given.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49168"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/8cbc3001a3264d998d6b6db3e23f935c158abd4d"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/d1cb11fb45ebbb1e7dfe5e9038b32ea72c184b14"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/e76c78c48902dae6fa612749f59162bca0a79e0b"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-26T07:00:53Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-579q-3q2m-34fw/GHSA-579q-3q2m-34fw.json b/advisories/unreviewed/2025/02/GHSA-579q-3q2m-34fw/GHSA-579q-3q2m-34fw.json
index f7df477e97a..5565eeeab7b 100644
--- a/advisories/unreviewed/2025/02/GHSA-579q-3q2m-34fw/GHSA-579q-3q2m-34fw.json
+++ b/advisories/unreviewed/2025/02/GHSA-579q-3q2m-34fw/GHSA-579q-3q2m-34fw.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-579q-3q2m-34fw",
- "modified": "2025-02-27T03:33:59Z",
+ "modified": "2025-02-27T21:32:15Z",
"published": "2025-02-27T03:33:59Z",
"aliases": [
"CVE-2024-57979"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\npps: Fix a use-after-free\n\nOn a board running ntpd and gpsd, I'm seeing a consistent use-after-free\nin sys_exit() from gpsd when rebooting:\n\n pps pps1: removed\n ------------[ cut here ]------------\n kobject: '(null)' (00000000db4bec24): is not initialized, yet kobject_put() is being called.\n WARNING: CPU: 2 PID: 440 at lib/kobject.c:734 kobject_put+0x120/0x150\n CPU: 2 UID: 299 PID: 440 Comm: gpsd Not tainted 6.11.0-rc6-00308-gb31c44928842 #1\n Hardware name: Raspberry Pi 4 Model B Rev 1.1 (DT)\n pstate: 60000005 (nZCv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n pc : kobject_put+0x120/0x150\n lr : kobject_put+0x120/0x150\n sp : ffffffc0803d3ae0\n x29: ffffffc0803d3ae0 x28: ffffff8042dc9738 x27: 0000000000000001\n x26: 0000000000000000 x25: ffffff8042dc9040 x24: ffffff8042dc9440\n x23: ffffff80402a4620 x22: ffffff8042ef4bd0 x21: ffffff80405cb600\n x20: 000000000008001b x19: ffffff8040b3b6e0 x18: 0000000000000000\n x17: 0000000000000000 x16: 0000000000000000 x15: 696e6920746f6e20\n x14: 7369203a29343263 x13: 205d303434542020 x12: 0000000000000000\n x11: 0000000000000000 x10: 0000000000000000 x9 : 0000000000000000\n x8 : 0000000000000000 x7 : 0000000000000000 x6 : 0000000000000000\n x5 : 0000000000000000 x4 : 0000000000000000 x3 : 0000000000000000\n x2 : 0000000000000000 x1 : 0000000000000000 x0 : 0000000000000000\n Call trace:\n kobject_put+0x120/0x150\n cdev_put+0x20/0x3c\n __fput+0x2c4/0x2d8\n ____fput+0x1c/0x38\n task_work_run+0x70/0xfc\n do_exit+0x2a0/0x924\n do_group_exit+0x34/0x90\n get_signal+0x7fc/0x8c0\n do_signal+0x128/0x13b4\n do_notify_resume+0xdc/0x160\n el0_svc+0xd4/0xf8\n el0t_64_sync_handler+0x140/0x14c\n el0t_64_sync+0x190/0x194\n ---[ end trace 0000000000000000 ]---\n\n...followed by more symptoms of corruption, with similar stacks:\n\n refcount_t: underflow; use-after-free.\n kernel BUG at lib/list_debug.c:62!\n Kernel panic - not syncing: Oops - BUG: Fatal exception\n\nThis happens because pps_device_destruct() frees the pps_device with the\nembedded cdev immediately after calling cdev_del(), but, as the comment\nabove cdev_del() notes, fops for previously opened cdevs are still\ncallable even after cdev_del() returns. I think this bug has always\nbeen there: I can't explain why it suddenly started happening every time\nI reboot this particular board.\n\nIn commit d953e0e837e6 (\"pps: Fix a use-after free bug when\nunregistering a source.\"), George Spelvin suggested removing the\nembedded cdev. That seems like the simplest way to fix this, so I've\nimplemented his suggestion, using __register_chrdev() with pps_idr\nbecoming the source of truth for which minor corresponds to which\ndevice.\n\nBut now that pps_idr defines userspace visibility instead of cdev_add(),\nwe need to be sure the pps->dev refcount can't reach zero while\nuserspace can still find it again. So, the idr_remove() call moves to\npps_unregister_cdev(), and pps_idr now holds a reference to pps->dev.\n\n pps_core: source serial1 got cdev (251:1)\n <...>\n pps pps1: removed\n pps_core: unregistering pps1\n pps_core: deallocating pps1",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -36,8 +41,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-27T02:15:11Z"
diff --git a/advisories/unreviewed/2025/02/GHSA-5828-2c94-235c/GHSA-5828-2c94-235c.json b/advisories/unreviewed/2025/02/GHSA-5828-2c94-235c/GHSA-5828-2c94-235c.json
index a01e75904b1..b0b606a9ab0 100644
--- a/advisories/unreviewed/2025/02/GHSA-5828-2c94-235c/GHSA-5828-2c94-235c.json
+++ b/advisories/unreviewed/2025/02/GHSA-5828-2c94-235c/GHSA-5828-2c94-235c.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5828-2c94-235c",
- "modified": "2025-02-27T03:34:05Z",
+ "modified": "2025-02-27T21:32:15Z",
"published": "2025-02-27T03:34:05Z",
"aliases": [
"CVE-2025-21756"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nvsock: Keep the binding until socket destruction\n\nPreserve sockets bindings; this includes both resulting from an explicit\nbind() and those implicitly bound through autobind during connect().\n\nPrevents socket unbinding during a transport reassignment, which fixes a\nuse-after-free:\n\n 1. vsock_create() (refcnt=1) calls vsock_insert_unbound() (refcnt=2)\n 2. transport->release() calls vsock_remove_bound() without checking if\n sk was bound and moved to bound list (refcnt=1)\n 3. vsock_bind() assumes sk is in unbound list and before\n __vsock_insert_bound(vsock_bound_sockets()) calls\n __vsock_remove_bound() which does:\n list_del_init(&vsk->bound_table); // nop\n sock_put(&vsk->sk); // refcnt=0\n\nBUG: KASAN: slab-use-after-free in __vsock_bind+0x62e/0x730\nRead of size 4 at addr ffff88816b46a74c by task a.out/2057\n dump_stack_lvl+0x68/0x90\n print_report+0x174/0x4f6\n kasan_report+0xb9/0x190\n __vsock_bind+0x62e/0x730\n vsock_bind+0x97/0xe0\n __sys_bind+0x154/0x1f0\n __x64_sys_bind+0x6e/0xb0\n do_syscall_64+0x93/0x1b0\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\nAllocated by task 2057:\n kasan_save_stack+0x1e/0x40\n kasan_save_track+0x10/0x30\n __kasan_slab_alloc+0x85/0x90\n kmem_cache_alloc_noprof+0x131/0x450\n sk_prot_alloc+0x5b/0x220\n sk_alloc+0x2c/0x870\n __vsock_create.constprop.0+0x2e/0xb60\n vsock_create+0xe4/0x420\n __sock_create+0x241/0x650\n __sys_socket+0xf2/0x1a0\n __x64_sys_socket+0x6e/0xb0\n do_syscall_64+0x93/0x1b0\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\nFreed by task 2057:\n kasan_save_stack+0x1e/0x40\n kasan_save_track+0x10/0x30\n kasan_save_free_info+0x37/0x60\n __kasan_slab_free+0x4b/0x70\n kmem_cache_free+0x1a1/0x590\n __sk_destruct+0x388/0x5a0\n __vsock_bind+0x5e1/0x730\n vsock_bind+0x97/0xe0\n __sys_bind+0x154/0x1f0\n __x64_sys_bind+0x6e/0xb0\n do_syscall_64+0x93/0x1b0\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\nrefcount_t: addition on 0; use-after-free.\nWARNING: CPU: 7 PID: 2057 at lib/refcount.c:25 refcount_warn_saturate+0xce/0x150\nRIP: 0010:refcount_warn_saturate+0xce/0x150\n __vsock_bind+0x66d/0x730\n vsock_bind+0x97/0xe0\n __sys_bind+0x154/0x1f0\n __x64_sys_bind+0x6e/0xb0\n do_syscall_64+0x93/0x1b0\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\nrefcount_t: underflow; use-after-free.\nWARNING: CPU: 7 PID: 2057 at lib/refcount.c:28 refcount_warn_saturate+0xee/0x150\nRIP: 0010:refcount_warn_saturate+0xee/0x150\n vsock_remove_bound+0x187/0x1e0\n __vsock_release+0x383/0x4a0\n vsock_release+0x90/0x120\n __sock_release+0xa3/0x250\n sock_close+0x14/0x20\n __fput+0x359/0xa80\n task_work_run+0x107/0x1d0\n do_exit+0x847/0x2560\n do_group_exit+0xb8/0x250\n __x64_sys_exit_group+0x3a/0x50\n x64_sys_call+0xfec/0x14f0\n do_syscall_64+0x93/0x1b0\n entry_SYSCALL_64_after_hwframe+0x76/0x7e",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -32,8 +37,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-27T03:15:16Z"
diff --git a/advisories/unreviewed/2025/02/GHSA-595v-ghj9-chj5/GHSA-595v-ghj9-chj5.json b/advisories/unreviewed/2025/02/GHSA-595v-ghj9-chj5/GHSA-595v-ghj9-chj5.json
index 4a56c47f15d..27ddafc37d9 100644
--- a/advisories/unreviewed/2025/02/GHSA-595v-ghj9-chj5/GHSA-595v-ghj9-chj5.json
+++ b/advisories/unreviewed/2025/02/GHSA-595v-ghj9-chj5/GHSA-595v-ghj9-chj5.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-595v-ghj9-chj5",
- "modified": "2025-02-27T03:34:04Z",
+ "modified": "2025-02-27T21:32:15Z",
"published": "2025-02-27T03:34:04Z",
"aliases": [
"CVE-2025-21753"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix use-after-free when attempting to join an aborted transaction\n\nWhen we are trying to join the current transaction and if it's aborted,\nwe read its 'aborted' field after unlocking fs_info->trans_lock and\nwithout holding any extra reference count on it. This means that a\nconcurrent task that is aborting the transaction may free the transaction\nbefore we read its 'aborted' field, leading to a use-after-free.\n\nFix this by reading the 'aborted' field while holding fs_info->trans_lock\nsince any freeing task must first acquire that lock and set\nfs_info->running_transaction to NULL before freeing the transaction.\n\nThis was reported by syzbot and Dmitry with the following stack traces\nfrom KASAN:\n\n ==================================================================\n BUG: KASAN: slab-use-after-free in join_transaction+0xd9b/0xda0 fs/btrfs/transaction.c:278\n Read of size 4 at addr ffff888011839024 by task kworker/u4:9/1128\n\n CPU: 0 UID: 0 PID: 1128 Comm: kworker/u4:9 Not tainted 6.13.0-rc7-syzkaller-00019-gc45323b7560e #0\n Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2~bpo12+1 04/01/2014\n Workqueue: events_unbound btrfs_async_reclaim_data_space\n Call Trace:\n \n __dump_stack lib/dump_stack.c:94 [inline]\n dump_stack_lvl+0x241/0x360 lib/dump_stack.c:120\n print_address_description mm/kasan/report.c:378 [inline]\n print_report+0x169/0x550 mm/kasan/report.c:489\n kasan_report+0x143/0x180 mm/kasan/report.c:602\n join_transaction+0xd9b/0xda0 fs/btrfs/transaction.c:278\n start_transaction+0xaf8/0x1670 fs/btrfs/transaction.c:697\n flush_space+0x448/0xcf0 fs/btrfs/space-info.c:803\n btrfs_async_reclaim_data_space+0x159/0x510 fs/btrfs/space-info.c:1321\n process_one_work kernel/workqueue.c:3236 [inline]\n process_scheduled_works+0xa66/0x1840 kernel/workqueue.c:3317\n worker_thread+0x870/0xd30 kernel/workqueue.c:3398\n kthread+0x2f0/0x390 kernel/kthread.c:389\n ret_from_fork+0x4b/0x80 arch/x86/kernel/process.c:147\n ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:244\n \n\n Allocated by task 5315:\n kasan_save_stack mm/kasan/common.c:47 [inline]\n kasan_save_track+0x3f/0x80 mm/kasan/common.c:68\n poison_kmalloc_redzone mm/kasan/common.c:377 [inline]\n __kasan_kmalloc+0x98/0xb0 mm/kasan/common.c:394\n kasan_kmalloc include/linux/kasan.h:260 [inline]\n __kmalloc_cache_noprof+0x243/0x390 mm/slub.c:4329\n kmalloc_noprof include/linux/slab.h:901 [inline]\n join_transaction+0x144/0xda0 fs/btrfs/transaction.c:308\n start_transaction+0xaf8/0x1670 fs/btrfs/transaction.c:697\n btrfs_create_common+0x1b2/0x2e0 fs/btrfs/inode.c:6572\n lookup_open fs/namei.c:3649 [inline]\n open_last_lookups fs/namei.c:3748 [inline]\n path_openat+0x1c03/0x3590 fs/namei.c:3984\n do_filp_open+0x27f/0x4e0 fs/namei.c:4014\n do_sys_openat2+0x13e/0x1d0 fs/open.c:1402\n do_sys_open fs/open.c:1417 [inline]\n __do_sys_creat fs/open.c:1495 [inline]\n __se_sys_creat fs/open.c:1489 [inline]\n __x64_sys_creat+0x123/0x170 fs/open.c:1489\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\n Freed by task 5336:\n kasan_save_stack mm/kasan/common.c:47 [inline]\n kasan_save_track+0x3f/0x80 mm/kasan/common.c:68\n kasan_save_free_info+0x40/0x50 mm/kasan/generic.c:582\n poison_slab_object mm/kasan/common.c:247 [inline]\n __kasan_slab_free+0x59/0x70 mm/kasan/common.c:264\n kasan_slab_free include/linux/kasan.h:233 [inline]\n slab_free_hook mm/slub.c:2353 [inline]\n slab_free mm/slub.c:4613 [inline]\n kfree+0x196/0x430 mm/slub.c:4761\n cleanup_transaction fs/btrfs/transaction.c:2063 [inline]\n btrfs_commit_transaction+0x2c97/0x3720 fs/btrfs/transaction.c:2598\n insert_balance_item+0x1284/0x20b0 fs/btrfs/volumes.c:3757\n btrfs_balance+0x992/\n---truncated---",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -36,8 +41,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-27T03:15:15Z"
diff --git a/advisories/unreviewed/2025/02/GHSA-5h7r-vm4m-qxq6/GHSA-5h7r-vm4m-qxq6.json b/advisories/unreviewed/2025/02/GHSA-5h7r-vm4m-qxq6/GHSA-5h7r-vm4m-qxq6.json
new file mode 100644
index 00000000000..8d974fbc396
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-5h7r-vm4m-qxq6/GHSA-5h7r-vm4m-qxq6.json
@@ -0,0 +1,45 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-5h7r-vm4m-qxq6",
+ "modified": "2025-02-27T21:32:17Z",
+ "published": "2025-02-27T21:32:17Z",
+ "aliases": [
+ "CVE-2025-21819"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRevert \"drm/amd/display: Use HW lock mgr for PSR1\"\n\nThis reverts commit\na2b5a9956269 (\"drm/amd/display: Use HW lock mgr for PSR1\")\n\nBecause it may cause system hang while connect with two edp panel.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21819"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/915697c2e69ac8d14dad498e6d6f43dbb7de3787"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/95c75578c420110c43791295985abb961d6dc033"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/a978864653e45d2671f99b09afcc1110e45d3dd9"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/dcc3f2c06d80da39eee742b51ddf0781affb260c"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/f245b400a223a71d6d5f4c72a2cb9b573a7fc2b6"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-27T20:16:04Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-5jx9-3p7f-55g3/GHSA-5jx9-3p7f-55g3.json b/advisories/unreviewed/2025/02/GHSA-5jx9-3p7f-55g3/GHSA-5jx9-3p7f-55g3.json
new file mode 100644
index 00000000000..db7b379f86b
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-5jx9-3p7f-55g3/GHSA-5jx9-3p7f-55g3.json
@@ -0,0 +1,33 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-5jx9-3p7f-55g3",
+ "modified": "2025-02-27T21:32:17Z",
+ "published": "2025-02-27T21:32:17Z",
+ "aliases": [
+ "CVE-2025-21822"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nptp: vmclock: Set driver data before its usage\n\nIf vmclock_ptp_register() fails during probing, vmclock_remove() is\ncalled to clean up the ptp clock and misc device.\nIt uses dev_get_drvdata() to access the vmclock state.\nHowever the driver data is not yet set at this point.\n\nAssign the driver data earlier.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21822"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/6dbd8b91a065d1d8001446a28e72cd140f9acef0"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/f7d07cd4f77d77f366c8ffbb8ba8b61f614e5fce"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-27T20:16:04Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-5qmp-w6rv-24wf/GHSA-5qmp-w6rv-24wf.json b/advisories/unreviewed/2025/02/GHSA-5qmp-w6rv-24wf/GHSA-5qmp-w6rv-24wf.json
new file mode 100644
index 00000000000..0669bf00c46
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-5qmp-w6rv-24wf/GHSA-5qmp-w6rv-24wf.json
@@ -0,0 +1,45 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-5qmp-w6rv-24wf",
+ "modified": "2025-02-27T21:32:17Z",
+ "published": "2025-02-27T21:32:17Z",
+ "aliases": [
+ "CVE-2025-21812"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nax25: rcu protect dev->ax25_ptr\n\nsyzbot found a lockdep issue [1].\n\nWe should remove ax25 RTNL dependency in ax25_setsockopt()\n\nThis should also fix a variety of possible UAF in ax25.\n\n[1]\n\nWARNING: possible circular locking dependency detected\n6.13.0-rc3-syzkaller-00762-g9268abe611b0 #0 Not tainted\n------------------------------------------------------\nsyz.5.1818/12806 is trying to acquire lock:\n ffffffff8fcb3988 (rtnl_mutex){+.+.}-{4:4}, at: ax25_setsockopt+0xa55/0xe90 net/ax25/af_ax25.c:680\n\nbut task is already holding lock:\n ffff8880617ac258 (sk_lock-AF_AX25){+.+.}-{0:0}, at: lock_sock include/net/sock.h:1618 [inline]\n ffff8880617ac258 (sk_lock-AF_AX25){+.+.}-{0:0}, at: ax25_setsockopt+0x209/0xe90 net/ax25/af_ax25.c:574\n\nwhich lock already depends on the new lock.\n\nthe existing dependency chain (in reverse order) is:\n\n-> #1 (sk_lock-AF_AX25){+.+.}-{0:0}:\n lock_acquire+0x1ed/0x550 kernel/locking/lockdep.c:5849\n lock_sock_nested+0x48/0x100 net/core/sock.c:3642\n lock_sock include/net/sock.h:1618 [inline]\n ax25_kill_by_device net/ax25/af_ax25.c:101 [inline]\n ax25_device_event+0x24d/0x580 net/ax25/af_ax25.c:146\n notifier_call_chain+0x1a5/0x3f0 kernel/notifier.c:85\n __dev_notify_flags+0x207/0x400\n dev_change_flags+0xf0/0x1a0 net/core/dev.c:9026\n dev_ifsioc+0x7c8/0xe70 net/core/dev_ioctl.c:563\n dev_ioctl+0x719/0x1340 net/core/dev_ioctl.c:820\n sock_do_ioctl+0x240/0x460 net/socket.c:1234\n sock_ioctl+0x626/0x8e0 net/socket.c:1339\n vfs_ioctl fs/ioctl.c:51 [inline]\n __do_sys_ioctl fs/ioctl.c:906 [inline]\n __se_sys_ioctl+0xf5/0x170 fs/ioctl.c:892\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\n-> #0 (rtnl_mutex){+.+.}-{4:4}:\n check_prev_add kernel/locking/lockdep.c:3161 [inline]\n check_prevs_add kernel/locking/lockdep.c:3280 [inline]\n validate_chain+0x18ef/0x5920 kernel/locking/lockdep.c:3904\n __lock_acquire+0x1397/0x2100 kernel/locking/lockdep.c:5226\n lock_acquire+0x1ed/0x550 kernel/locking/lockdep.c:5849\n __mutex_lock_common kernel/locking/mutex.c:585 [inline]\n __mutex_lock+0x1ac/0xee0 kernel/locking/mutex.c:735\n ax25_setsockopt+0xa55/0xe90 net/ax25/af_ax25.c:680\n do_sock_setsockopt+0x3af/0x720 net/socket.c:2324\n __sys_setsockopt net/socket.c:2349 [inline]\n __do_sys_setsockopt net/socket.c:2355 [inline]\n __se_sys_setsockopt net/socket.c:2352 [inline]\n __x64_sys_setsockopt+0x1ee/0x280 net/socket.c:2352\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nother info that might help us debug this:\n\n Possible unsafe locking scenario:\n\n CPU0 CPU1\n ---- ----\n lock(sk_lock-AF_AX25);\n lock(rtnl_mutex);\n lock(sk_lock-AF_AX25);\n lock(rtnl_mutex);\n\n *** DEADLOCK ***\n\n1 lock held by syz.5.1818/12806:\n #0: ffff8880617ac258 (sk_lock-AF_AX25){+.+.}-{0:0}, at: lock_sock include/net/sock.h:1618 [inline]\n #0: ffff8880617ac258 (sk_lock-AF_AX25){+.+.}-{0:0}, at: ax25_setsockopt+0x209/0xe90 net/ax25/af_ax25.c:574\n\nstack backtrace:\nCPU: 1 UID: 0 PID: 12806 Comm: syz.5.1818 Not tainted 6.13.0-rc3-syzkaller-00762-g9268abe611b0 #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024\nCall Trace:\n \n __dump_stack lib/dump_stack.c:94 [inline]\n dump_stack_lvl+0x241/0x360 lib/dump_stack.c:120\n print_circular_bug+0x13a/0x1b0 kernel/locking/lockdep.c:2074\n check_noncircular+0x36a/0x4a0 kernel/locking/lockdep.c:2206\n check_prev_add kernel/locking/lockdep.c:3161 [inline]\n check_prevs_add kernel/lockin\n---truncated---",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21812"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/2802ed4ced27ebd474828fc67ffd7d66f11e3605"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/7705d8a7f2c26c80973c81093db07c6022b2b30e"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/8937f5e38a218531dce2a89fae60e3adcc2311e1"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/95fc45d1dea8e1253f8ec58abc5befb71553d666"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/c2531db6de3c95551be58878f859c6a053b7eb2e"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-27T20:16:03Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-5r9q-cj6r-c6jj/GHSA-5r9q-cj6r-c6jj.json b/advisories/unreviewed/2025/02/GHSA-5r9q-cj6r-c6jj/GHSA-5r9q-cj6r-c6jj.json
new file mode 100644
index 00000000000..5336a57bda4
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-5r9q-cj6r-c6jj/GHSA-5r9q-cj6r-c6jj.json
@@ -0,0 +1,37 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-5r9q-cj6r-c6jj",
+ "modified": "2025-02-27T21:32:16Z",
+ "published": "2025-02-27T21:32:16Z",
+ "aliases": [
+ "CVE-2025-21800"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: HWS, fix definer's HWS_SET32 macro for negative offset\n\nWhen bit offset for HWS_SET32 macro is negative,\nUBSAN complains about the shift-out-of-bounds:\n\n UBSAN: shift-out-of-bounds in\n drivers/net/ethernet/mellanox/mlx5/core/steering/hws/definer.c:177:2\n shift exponent -8 is negative",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21800"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/69c676c0ded472713e6d1b3a456b3c4f52f66f0e"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/92cff996624c4757d5bbace3dfa3f1567ba94143"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/be482f1d10da781db9445d2753c1e3f1fd82babf"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-27T20:16:02Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-5rg8-h4cr-247f/GHSA-5rg8-h4cr-247f.json b/advisories/unreviewed/2025/02/GHSA-5rg8-h4cr-247f/GHSA-5rg8-h4cr-247f.json
new file mode 100644
index 00000000000..45857a629a1
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-5rg8-h4cr-247f/GHSA-5rg8-h4cr-247f.json
@@ -0,0 +1,37 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-5rg8-h4cr-247f",
+ "modified": "2025-02-27T21:32:16Z",
+ "published": "2025-02-27T21:32:16Z",
+ "aliases": [
+ "CVE-2025-21801"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ravb: Fix missing rtnl lock in suspend/resume path\n\nFix the suspend/resume path by ensuring the rtnl lock is held where\nrequired. Calls to ravb_open, ravb_close and wol operations must be\nperformed under the rtnl lock to prevent conflicts with ongoing ndo\noperations.\n\nWithout this fix, the following warning is triggered:\n[ 39.032969] =============================\n[ 39.032983] WARNING: suspicious RCU usage\n[ 39.033019] -----------------------------\n[ 39.033033] drivers/net/phy/phy_device.c:2004 suspicious\nrcu_dereference_protected() usage!\n...\n[ 39.033597] stack backtrace:\n[ 39.033613] CPU: 0 UID: 0 PID: 174 Comm: python3 Not tainted\n6.13.0-rc7-next-20250116-arm64-renesas-00002-g35245dfdc62c #7\n[ 39.033623] Hardware name: Renesas SMARC EVK version 2 based on\nr9a08g045s33 (DT)\n[ 39.033628] Call trace:\n[ 39.033633] show_stack+0x14/0x1c (C)\n[ 39.033652] dump_stack_lvl+0xb4/0xc4\n[ 39.033664] dump_stack+0x14/0x1c\n[ 39.033671] lockdep_rcu_suspicious+0x16c/0x22c\n[ 39.033682] phy_detach+0x160/0x190\n[ 39.033694] phy_disconnect+0x40/0x54\n[ 39.033703] ravb_close+0x6c/0x1cc\n[ 39.033714] ravb_suspend+0x48/0x120\n[ 39.033721] dpm_run_callback+0x4c/0x14c\n[ 39.033731] device_suspend+0x11c/0x4dc\n[ 39.033740] dpm_suspend+0xdc/0x214\n[ 39.033748] dpm_suspend_start+0x48/0x60\n[ 39.033758] suspend_devices_and_enter+0x124/0x574\n[ 39.033769] pm_suspend+0x1ac/0x274\n[ 39.033778] state_store+0x88/0x124\n[ 39.033788] kobj_attr_store+0x14/0x24\n[ 39.033798] sysfs_kf_write+0x48/0x6c\n[ 39.033808] kernfs_fop_write_iter+0x118/0x1a8\n[ 39.033817] vfs_write+0x27c/0x378\n[ 39.033825] ksys_write+0x64/0xf4\n[ 39.033833] __arm64_sys_write+0x18/0x20\n[ 39.033841] invoke_syscall+0x44/0x104\n[ 39.033852] el0_svc_common.constprop.0+0xb4/0xd4\n[ 39.033862] do_el0_svc+0x18/0x20\n[ 39.033870] el0_svc+0x3c/0xf0\n[ 39.033880] el0t_64_sync_handler+0xc0/0xc4\n[ 39.033888] el0t_64_sync+0x154/0x158\n[ 39.041274] ravb 11c30000.ethernet eth0: Link is Down",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21801"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/0296981941cf291edfbc318d3255a93439f368e4"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/2c2ebb2b49573e5f8726112ad06b1dffc3c9ea03"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/ad19522c007bb24ed874468f8baa1503c4662cf4"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-27T20:16:02Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-5wpf-jxv5-j2rg/GHSA-5wpf-jxv5-j2rg.json b/advisories/unreviewed/2025/02/GHSA-5wpf-jxv5-j2rg/GHSA-5wpf-jxv5-j2rg.json
new file mode 100644
index 00000000000..88a4871a9a0
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-5wpf-jxv5-j2rg/GHSA-5wpf-jxv5-j2rg.json
@@ -0,0 +1,68 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-5wpf-jxv5-j2rg",
+ "modified": "2025-02-27T21:32:12Z",
+ "published": "2025-02-27T21:32:12Z",
+ "aliases": [
+ "CVE-2022-49111"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: Fix use after free in hci_send_acl\n\nThis fixes the following trace caused by receiving\nHCI_EV_DISCONN_PHY_LINK_COMPLETE which does call hci_conn_del without\nfirst checking if conn->type is in fact AMP_LINK and in case it is\ndo properly cleanup upper layers with hci_disconn_cfm:\n\n ==================================================================\n BUG: KASAN: use-after-free in hci_send_acl+0xaba/0xc50\n Read of size 8 at addr ffff88800e404818 by task bluetoothd/142\n\n CPU: 0 PID: 142 Comm: bluetoothd Not tainted\n 5.17.0-rc5-00006-gda4022eeac1a #7\n Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS\n rel-1.14.0-0-g155821a1990b-prebuilt.qemu.org 04/01/2014\n Call Trace:\n \n dump_stack_lvl+0x45/0x59\n print_address_description.constprop.0+0x1f/0x150\n kasan_report.cold+0x7f/0x11b\n hci_send_acl+0xaba/0xc50\n l2cap_do_send+0x23f/0x3d0\n l2cap_chan_send+0xc06/0x2cc0\n l2cap_sock_sendmsg+0x201/0x2b0\n sock_sendmsg+0xdc/0x110\n sock_write_iter+0x20f/0x370\n do_iter_readv_writev+0x343/0x690\n do_iter_write+0x132/0x640\n vfs_writev+0x198/0x570\n do_writev+0x202/0x280\n do_syscall_64+0x38/0x90\n entry_SYSCALL_64_after_hwframe+0x44/0xae\n RSP: 002b:00007ffce8a099b8 EFLAGS: 00000246 ORIG_RAX: 0000000000000014\n Code: 0f 00 f7 d8 64 89 02 48 c7 c0 ff ff ff ff eb b8 0f 1f 00 f3\n 0f 1e fa 64 8b 04 25 18 00 00 00 85 c0 75 10 b8 14 00 00 00 0f 05\n <48> 3d 00 f0 ff ff 77 51 c3 48 83 ec 28 89 54 24 1c 48 89 74 24 10\n RDX: 0000000000000001 RSI: 00007ffce8a099e0 RDI: 0000000000000015\n RAX: ffffffffffffffda RBX: 00007ffce8a099e0 RCX: 00007f788fc3cf77\n R10: 00007ffce8af7080 R11: 0000000000000246 R12: 000055e4ccf75580\n RBP: 0000000000000015 R08: 0000000000000002 R09: 0000000000000001\n \n R13: 000055e4ccf754a0 R14: 000055e4ccf75cd0 R15: 000055e4ccf4a6b0\n\n Allocated by task 45:\n kasan_save_stack+0x1e/0x40\n __kasan_kmalloc+0x81/0xa0\n hci_chan_create+0x9a/0x2f0\n l2cap_conn_add.part.0+0x1a/0xdc0\n l2cap_connect_cfm+0x236/0x1000\n le_conn_complete_evt+0x15a7/0x1db0\n hci_le_conn_complete_evt+0x226/0x2c0\n hci_le_meta_evt+0x247/0x450\n hci_event_packet+0x61b/0xe90\n hci_rx_work+0x4d5/0xc50\n process_one_work+0x8fb/0x15a0\n worker_thread+0x576/0x1240\n kthread+0x29d/0x340\n ret_from_fork+0x1f/0x30\n\n Freed by task 45:\n kasan_save_stack+0x1e/0x40\n kasan_set_track+0x21/0x30\n kasan_set_free_info+0x20/0x30\n __kasan_slab_free+0xfb/0x130\n kfree+0xac/0x350\n hci_conn_cleanup+0x101/0x6a0\n hci_conn_del+0x27e/0x6c0\n hci_disconn_phylink_complete_evt+0xe0/0x120\n hci_event_packet+0x812/0xe90\n hci_rx_work+0x4d5/0xc50\n process_one_work+0x8fb/0x15a0\n worker_thread+0x576/0x1240\n kthread+0x29d/0x340\n ret_from_fork+0x1f/0x30\n\n The buggy address belongs to the object at ffff88800c0f0500\n The buggy address is located 24 bytes inside of\n which belongs to the cache kmalloc-128 of size 128\n The buggy address belongs to the page:\n 128-byte region [ffff88800c0f0500, ffff88800c0f0580)\n flags: 0x100000000000200(slab|node=0|zone=1)\n page:00000000fe45cd86 refcount:1 mapcount:0\n mapping:0000000000000000 index:0x0 pfn:0xc0f0\n raw: 0000000000000000 0000000080100010 00000001ffffffff\n 0000000000000000\n raw: 0100000000000200 ffffea00003a2c80 dead000000000004\n ffff8880078418c0\n page dumped because: kasan: bad access detected\n ffff88800c0f0400: 00 00 00 00 00 00 00 00 00 00 00 00 00 fc fc fc\n Memory state around the buggy address:\n >ffff88800c0f0500: fa fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb\n ffff88800c0f0480: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc\n ffff88800c0f0580: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc\n \n---truncated---",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49111"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/2cc803804ec9a296b3156855d6c8c4ca1c6b84be"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/3803d896ddd97c7c16689a5381c0960040727647"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/4da302b90b96c309987eb9b37c8547f939f042d2"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/643a6c26bd32e339d00ad97b8822b6db009e803c"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/684e505406abaeabe0058e9776f9210bf2747953"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/b3c2ea1fd444b3bb7b82bfd2c3a45418f85c2502"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/c41de54b0a963e59e4dd04c029a4a6d73f45ef9c"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/d404765dffdbd8dcd14758695d0c96c52fb2e624"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/f63d24baff787e13b723d86fe036f84bdbc35045"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-26T07:00:48Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-5wq4-958x-w5fq/GHSA-5wq4-958x-w5fq.json b/advisories/unreviewed/2025/02/GHSA-5wq4-958x-w5fq/GHSA-5wq4-958x-w5fq.json
new file mode 100644
index 00000000000..fd5c6e69441
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-5wq4-958x-w5fq/GHSA-5wq4-958x-w5fq.json
@@ -0,0 +1,64 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-5wq4-958x-w5fq",
+ "modified": "2025-02-27T21:32:15Z",
+ "published": "2025-02-27T21:32:14Z",
+ "aliases": [
+ "CVE-2022-49667"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: bonding: fix use-after-free after 802.3ad slave unbind\n\ncommit 0622cab0341c (\"bonding: fix 802.3ad aggregator reselection\"),\nresolve case, when there is several aggregation groups in the same bond.\nbond_3ad_unbind_slave will invalidate (clear) aggregator when\n__agg_active_ports return zero. So, ad_clear_agg can be executed even, when\nnum_of_ports!=0. Than bond_3ad_unbind_slave can be executed again for,\npreviously cleared aggregator. NOTE: at this time bond_3ad_unbind_slave\nwill not update slave ports list, because lag_ports==NULL. So, here we\ngot slave ports, pointing to freed aggregator memory.\n\nFix with checking actual number of ports in group (as was before\ncommit 0622cab0341c (\"bonding: fix 802.3ad aggregator reselection\") ),\nbefore ad_clear_agg().\n\nThe KASAN logs are as follows:\n\n[ 767.617392] ==================================================================\n[ 767.630776] BUG: KASAN: use-after-free in bond_3ad_state_machine_handler+0x13dc/0x1470\n[ 767.638764] Read of size 2 at addr ffff00011ba9d430 by task kworker/u8:7/767\n[ 767.647361] CPU: 3 PID: 767 Comm: kworker/u8:7 Tainted: G O 5.15.11 #15\n[ 767.655329] Hardware name: DNI AmazonGo1 A7040 board (DT)\n[ 767.660760] Workqueue: lacp_1 bond_3ad_state_machine_handler\n[ 767.666468] Call trace:\n[ 767.668930] dump_backtrace+0x0/0x2d0\n[ 767.672625] show_stack+0x24/0x30\n[ 767.675965] dump_stack_lvl+0x68/0x84\n[ 767.679659] print_address_description.constprop.0+0x74/0x2b8\n[ 767.685451] kasan_report+0x1f0/0x260\n[ 767.689148] __asan_load2+0x94/0xd0\n[ 767.692667] bond_3ad_state_machine_handler+0x13dc/0x1470",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49667"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/050133e1aa2cb49bb17be847d48a4431598ef562"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/2765749def4765c5052a4c66445cf4c96fcccdbc"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/63b2fe509f69b90168a75e04e14573dccf7984e6"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/893825289ba840afd86bfffcb6f7f363c73efff8"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/a853b7a3a9fd1d74a4ccdd9cd73512b7dace2f1e"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/b90ac60303063a43e17dd4aec159067599d255e6"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/ef0af7d08d26c5333ff4944a559279464edf6f15"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/f162f7c348fa2a5555bafdb5cc890b89b221e69c"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-26T07:01:41Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-6cpx-w2cg-qmgr/GHSA-6cpx-w2cg-qmgr.json b/advisories/unreviewed/2025/02/GHSA-6cpx-w2cg-qmgr/GHSA-6cpx-w2cg-qmgr.json
index ffbbb536c33..95e663b9f05 100644
--- a/advisories/unreviewed/2025/02/GHSA-6cpx-w2cg-qmgr/GHSA-6cpx-w2cg-qmgr.json
+++ b/advisories/unreviewed/2025/02/GHSA-6cpx-w2cg-qmgr/GHSA-6cpx-w2cg-qmgr.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6cpx-w2cg-qmgr",
- "modified": "2025-02-27T03:34:04Z",
+ "modified": "2025-02-27T21:32:15Z",
"published": "2025-02-27T03:34:04Z",
"aliases": [
"CVE-2025-21751"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: HWS, change error flow on matcher disconnect\n\nCurrently, when firmware failure occurs during matcher disconnect flow,\nthe error flow of the function reconnects the matcher back and returns\nan error, which continues running the calling function and eventually\nfrees the matcher that is being disconnected.\nThis leads to a case where we have a freed matcher on the matchers list,\nwhich in turn leads to use-after-free and eventual crash.\n\nThis patch fixes that by not trying to reconnect the matcher back when\nsome FW command fails during disconnect.\n\nNote that we're dealing here with FW error. We can't overcome this\nproblem. This might lead to bad steering state (e.g. wrong connection\nbetween matchers), and will also lead to resource leakage, as it is\nthe case with any other error handling during resource destruction.\n\nHowever, the goal here is to allow the driver to continue and not crash\nthe machine with use-after-free error.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-27T03:15:15Z"
diff --git a/advisories/unreviewed/2025/02/GHSA-6g66-96c8-x7cw/GHSA-6g66-96c8-x7cw.json b/advisories/unreviewed/2025/02/GHSA-6g66-96c8-x7cw/GHSA-6g66-96c8-x7cw.json
index e658ccdf49b..384bc35dc25 100644
--- a/advisories/unreviewed/2025/02/GHSA-6g66-96c8-x7cw/GHSA-6g66-96c8-x7cw.json
+++ b/advisories/unreviewed/2025/02/GHSA-6g66-96c8-x7cw/GHSA-6g66-96c8-x7cw.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6g66-96c8-x7cw",
- "modified": "2025-02-27T03:34:02Z",
+ "modified": "2025-02-27T21:32:15Z",
"published": "2025-02-27T03:34:02Z",
"aliases": [
"CVE-2025-21722"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: do not force clear folio if buffer is referenced\n\nPatch series \"nilfs2: protect busy buffer heads from being force-cleared\".\n\nThis series fixes the buffer head state inconsistency issues reported by\nsyzbot that occurs when the filesystem is corrupted and falls back to\nread-only, and the associated buffer head use-after-free issue.\n\n\nThis patch (of 2):\n\nSyzbot has reported that after nilfs2 detects filesystem corruption and\nfalls back to read-only, inconsistencies in the buffer state may occur.\n\nOne of the inconsistencies is that when nilfs2 calls mark_buffer_dirty()\nto set a data or metadata buffer as dirty, but it detects that the buffer\nis not in the uptodate state:\n\n WARNING: CPU: 0 PID: 6049 at fs/buffer.c:1177 mark_buffer_dirty+0x2e5/0x520\n fs/buffer.c:1177\n ...\n Call Trace:\n \n nilfs_palloc_commit_alloc_entry+0x4b/0x160 fs/nilfs2/alloc.c:598\n nilfs_ifile_create_inode+0x1dd/0x3a0 fs/nilfs2/ifile.c:73\n nilfs_new_inode+0x254/0x830 fs/nilfs2/inode.c:344\n nilfs_mkdir+0x10d/0x340 fs/nilfs2/namei.c:218\n vfs_mkdir+0x2f9/0x4f0 fs/namei.c:4257\n do_mkdirat+0x264/0x3a0 fs/namei.c:4280\n __do_sys_mkdirat fs/namei.c:4295 [inline]\n __se_sys_mkdirat fs/namei.c:4293 [inline]\n __x64_sys_mkdirat+0x87/0xa0 fs/namei.c:4293\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nThe other is when nilfs_btree_propagate(), which propagates the dirty\nstate to the ancestor nodes of a b-tree that point to a dirty buffer,\ndetects that the origin buffer is not dirty, even though it should be:\n\n WARNING: CPU: 0 PID: 5245 at fs/nilfs2/btree.c:2089\n nilfs_btree_propagate+0xc79/0xdf0 fs/nilfs2/btree.c:2089\n ...\n Call Trace:\n \n nilfs_bmap_propagate+0x75/0x120 fs/nilfs2/bmap.c:345\n nilfs_collect_file_data+0x4d/0xd0 fs/nilfs2/segment.c:587\n nilfs_segctor_apply_buffers+0x184/0x340 fs/nilfs2/segment.c:1006\n nilfs_segctor_scan_file+0x28c/0xa50 fs/nilfs2/segment.c:1045\n nilfs_segctor_collect_blocks fs/nilfs2/segment.c:1216 [inline]\n nilfs_segctor_collect fs/nilfs2/segment.c:1540 [inline]\n nilfs_segctor_do_construct+0x1c28/0x6b90 fs/nilfs2/segment.c:2115\n nilfs_segctor_construct+0x181/0x6b0 fs/nilfs2/segment.c:2479\n nilfs_segctor_thread_construct fs/nilfs2/segment.c:2587 [inline]\n nilfs_segctor_thread+0x69e/0xe80 fs/nilfs2/segment.c:2701\n kthread+0x2f0/0x390 kernel/kthread.c:389\n ret_from_fork+0x4b/0x80 arch/x86/kernel/process.c:147\n ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:244\n \n\nBoth of these issues are caused by the callbacks that handle the\npage/folio write requests, forcibly clear various states, including the\nworking state of the buffers they hold, at unexpected times when they\ndetect read-only fallback.\n\nFix these issues by checking if the buffer is referenced before clearing\nthe page/folio state, and skipping the clear if it is.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -32,8 +37,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-27T02:15:15Z"
diff --git a/advisories/unreviewed/2025/02/GHSA-72c2-78v3-v6cc/GHSA-72c2-78v3-v6cc.json b/advisories/unreviewed/2025/02/GHSA-72c2-78v3-v6cc/GHSA-72c2-78v3-v6cc.json
new file mode 100644
index 00000000000..57b75988ceb
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-72c2-78v3-v6cc/GHSA-72c2-78v3-v6cc.json
@@ -0,0 +1,64 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-72c2-78v3-v6cc",
+ "modified": "2025-02-27T21:32:15Z",
+ "published": "2025-02-27T21:32:14Z",
+ "aliases": [
+ "CVE-2022-49685"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\niio: trigger: sysfs: fix use-after-free on remove\n\nEnsure that the irq_work has completed before the trigger is freed.\n\n ==================================================================\n BUG: KASAN: use-after-free in irq_work_run_list\n Read of size 8 at addr 0000000064702248 by task python3/25\n\n Call Trace:\n irq_work_run_list\n irq_work_tick\n update_process_times\n tick_sched_handle\n tick_sched_timer\n __hrtimer_run_queues\n hrtimer_interrupt\n\n Allocated by task 25:\n kmem_cache_alloc_trace\n iio_sysfs_trig_add\n dev_attr_store\n sysfs_kf_write\n kernfs_fop_write_iter\n new_sync_write\n vfs_write\n ksys_write\n sys_write\n\n Freed by task 25:\n kfree\n iio_sysfs_trig_remove\n dev_attr_store\n sysfs_kf_write\n kernfs_fop_write_iter\n new_sync_write\n vfs_write\n ksys_write\n sys_write\n\n ==================================================================",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49685"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/31ff3309b47d98313c61b8301bf595820cc3cc33"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/4687c3f955240ca2a576bdc3f742d4d915b6272d"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/4ef1e521be610b720daeb7cf899fedc7db0274c4"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/5e39397d60dacc7f5d81d442c1c958eaaaf31128"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/78601726d4a59a291acc5a52da1d3a0a6831e4e8"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/b07a30a774b3c3e584a68dc91779c68ea2da4813"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/d6111e7bdb8ec27eb43d01c4cd4ff1620a75f7f2"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/fd5d8fb298a2866c337da635c79d63c3afabcaf7"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-26T07:01:43Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-7crf-mwwj-hvjp/GHSA-7crf-mwwj-hvjp.json b/advisories/unreviewed/2025/02/GHSA-7crf-mwwj-hvjp/GHSA-7crf-mwwj-hvjp.json
new file mode 100644
index 00000000000..1253ab4edcc
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-7crf-mwwj-hvjp/GHSA-7crf-mwwj-hvjp.json
@@ -0,0 +1,40 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-7crf-mwwj-hvjp",
+ "modified": "2025-02-27T21:32:16Z",
+ "published": "2025-02-27T21:32:16Z",
+ "aliases": [
+ "CVE-2025-0767"
+ ],
+ "details": "WP Activity Log 5.3.2 was found to be vulnerable. Unvalidated user input is used directly in an unserialize function in myapp/classes/Writers/class-csv-writer.php.",
+ "severity": [
+ {
+ "type": "CVSS_V4",
+ "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0767"
+ },
+ {
+ "type": "WEB",
+ "url": "https://co.wordpress.org/plugins/wp-security-audit-log"
+ },
+ {
+ "type": "WEB",
+ "url": "https://fluidattacks.com/advisories/skims-9"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-502"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-27T19:15:49Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-7fq4-85x5-74rc/GHSA-7fq4-85x5-74rc.json b/advisories/unreviewed/2025/02/GHSA-7fq4-85x5-74rc/GHSA-7fq4-85x5-74rc.json
new file mode 100644
index 00000000000..ebe96ae9157
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-7fq4-85x5-74rc/GHSA-7fq4-85x5-74rc.json
@@ -0,0 +1,48 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-7fq4-85x5-74rc",
+ "modified": "2025-02-27T21:32:09Z",
+ "published": "2025-02-27T21:32:09Z",
+ "aliases": [
+ "CVE-2021-47639"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: x86/mmu: Zap _all_ roots when unmapping gfn range in TDP MMU\n\nZap both valid and invalid roots when zapping/unmapping a gfn range, as\nKVM must ensure it holds no references to the freed page after returning\nfrom the unmap operation. Most notably, the TDP MMU doesn't zap invalid\nroots in mmu_notifier callbacks. This leads to use-after-free and other\nissues if the mmu_notifier runs to completion while an invalid root\nzapper yields as KVM fails to honor the requirement that there must be\n_no_ references to the page after the mmu_notifier returns.\n\nThe bug is most easily reproduced by hacking KVM to cause a collision\nbetween set_nx_huge_pages() and kvm_mmu_notifier_release(), but the bug\nexists between kvm_mmu_notifier_invalidate_range_start() and memslot\nupdates as well. Invalidating a root ensures pages aren't accessible by\nthe guest, and KVM won't read or write page data itself, but KVM will\ntrigger e.g. kvm_set_pfn_dirty() when zapping SPTEs, and thus completing\na zap of an invalid root _after_ the mmu_notifier returns is fatal.\n\n WARNING: CPU: 24 PID: 1496 at arch/x86/kvm/../../../virt/kvm/kvm_main.c:173 [kvm]\n RIP: 0010:kvm_is_zone_device_pfn+0x96/0xa0 [kvm]\n Call Trace:\n \n kvm_set_pfn_dirty+0xa8/0xe0 [kvm]\n __handle_changed_spte+0x2ab/0x5e0 [kvm]\n __handle_changed_spte+0x2ab/0x5e0 [kvm]\n __handle_changed_spte+0x2ab/0x5e0 [kvm]\n zap_gfn_range+0x1f3/0x310 [kvm]\n kvm_tdp_mmu_zap_invalidated_roots+0x50/0x90 [kvm]\n kvm_mmu_zap_all_fast+0x177/0x1a0 [kvm]\n set_nx_huge_pages+0xb4/0x190 [kvm]\n param_attr_store+0x70/0x100\n module_attr_store+0x19/0x30\n kernfs_fop_write_iter+0x119/0x1b0\n new_sync_write+0x11c/0x1b0\n vfs_write+0x1cc/0x270\n ksys_write+0x5f/0xe0\n do_syscall_64+0x38/0xc0\n entry_SYSCALL_64_after_hwframe+0x44/0xae\n ",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47639"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/0c8a8da182d4333d9bbb9131d765145568c847b2"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/8cf6f98ab1d16d5e607635a0c21c4231eb15367e"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/af47248407c0c5ae52a752af1ab5ce5b0db91502"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/d62007edf01f5c11f75d0f4b1e538fc52a5b1982"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-26T06:37:05Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-7vh4-856x-687c/GHSA-7vh4-856x-687c.json b/advisories/unreviewed/2025/02/GHSA-7vh4-856x-687c/GHSA-7vh4-856x-687c.json
new file mode 100644
index 00000000000..4630a594888
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-7vh4-856x-687c/GHSA-7vh4-856x-687c.json
@@ -0,0 +1,40 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-7vh4-856x-687c",
+ "modified": "2025-02-27T21:32:12Z",
+ "published": "2025-02-27T21:32:12Z",
+ "aliases": [
+ "CVE-2022-49127"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nref_tracker: implement use-after-free detection\n\nWhenever ref_tracker_dir_init() is called, mark the struct ref_tracker_dir\nas dead.\n\nTest the dead status from ref_tracker_alloc() and ref_tracker_free()\n\nThis should detect buggy dev_put()/dev_hold() happening too late\nin netdevice dismantle process.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49127"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/3743c9de303fa36c2e2ca2522ab280c52bcafbd2"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/e3ececfe668facd87d920b608349a32607060e66"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-26T07:00:50Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-82w6-hjxq-qjm2/GHSA-82w6-hjxq-qjm2.json b/advisories/unreviewed/2025/02/GHSA-82w6-hjxq-qjm2/GHSA-82w6-hjxq-qjm2.json
new file mode 100644
index 00000000000..c28b9a3af6e
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-82w6-hjxq-qjm2/GHSA-82w6-hjxq-qjm2.json
@@ -0,0 +1,37 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-82w6-hjxq-qjm2",
+ "modified": "2025-02-27T21:32:16Z",
+ "published": "2025-02-27T21:32:16Z",
+ "aliases": [
+ "CVE-2025-21798"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfirewire: test: Fix potential null dereference in firewire kunit test\n\nkunit_kzalloc() may return a NULL pointer, dereferencing it without\nNULL check may lead to NULL dereference.\nAdd a NULL check for test_state.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21798"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/352fafe97784e81a10a7c74bd508f71a19b53c2a"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/70fcb25472d90dd3b87cbee74b9eb68670b0c7b8"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/c6896bf4c611c3dd126f3e03685f2360a18b3d6f"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-27T20:16:02Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-84hr-q2hc-2m5c/GHSA-84hr-q2hc-2m5c.json b/advisories/unreviewed/2025/02/GHSA-84hr-q2hc-2m5c/GHSA-84hr-q2hc-2m5c.json
new file mode 100644
index 00000000000..669938b98d3
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-84hr-q2hc-2m5c/GHSA-84hr-q2hc-2m5c.json
@@ -0,0 +1,40 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-84hr-q2hc-2m5c",
+ "modified": "2025-02-27T21:32:14Z",
+ "published": "2025-02-27T21:32:14Z",
+ "aliases": [
+ "CVE-2022-49535"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: lpfc: Fix null pointer dereference after failing to issue FLOGI and PLOGI\n\nIf lpfc_issue_els_flogi() fails and returns non-zero status, the node\nreference count is decremented to trigger the release of the nodelist\nstructure. However, if there is a prior registration or dev-loss-evt work\npending, the node may be released prematurely. When dev-loss-evt\ncompletes, the released node is referenced causing a use-after-free null\npointer dereference.\n\nSimilarly, when processing non-zero ELS PLOGI completion status in\nlpfc_cmpl_els_plogi(), the ndlp flags are checked for a transport\nregistration before triggering node removal. If dev-loss-evt work is\npending, the node may be released prematurely and a subsequent call to\nlpfc_dev_loss_tmo_handler() results in a use after free ndlp dereference.\n\nAdd test for pending dev-loss before decrementing the node reference count\nfor FLOGI, PLOGI, PRLI, and ADISC handling.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49535"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/10663ebec0ad5c78493a0dd34c9ee4d73d7ca0df"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/577a942df3de2666f6947bdd3a5c9e8d30073424"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-26T07:01:29Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-87jq-rxj7-28vf/GHSA-87jq-rxj7-28vf.json b/advisories/unreviewed/2025/02/GHSA-87jq-rxj7-28vf/GHSA-87jq-rxj7-28vf.json
new file mode 100644
index 00000000000..18a50ebcd6a
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-87jq-rxj7-28vf/GHSA-87jq-rxj7-28vf.json
@@ -0,0 +1,52 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-87jq-rxj7-28vf",
+ "modified": "2025-02-27T21:32:10Z",
+ "published": "2025-02-27T21:32:10Z",
+ "aliases": [
+ "CVE-2022-49076"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/hfi1: Fix use-after-free bug for mm struct\n\nUnder certain conditions, such as MPI_Abort, the hfi1 cleanup code may\nrepresent the last reference held on the task mm.\nhfi1_mmu_rb_unregister() then drops the last reference and the mm is freed\nbefore the final use in hfi1_release_user_pages(). A new task may\nallocate the mm structure while it is still being used, resulting in\nproblems. One manifestation is corruption of the mmap_sem counter leading\nto a hang in down_write(). Another is corruption of an mm struct that is\nin use by another task.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49076"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/0b7186d657ee55e2cdefae498f07d5c1961e8023"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/2bbac98d0930e8161b1957dc0ec99de39ade1b3c"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/5a9a1b24ddb510715f8f621263938186579a965c"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/5f54364ff6cfcd14cddf5441c4a490bb28dd69f7"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/9ca11bd8222a612de0d2f54d050bfcf61ae2883f"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-26T07:00:44Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-8884-7rm9-mrx4/GHSA-8884-7rm9-mrx4.json b/advisories/unreviewed/2025/02/GHSA-8884-7rm9-mrx4/GHSA-8884-7rm9-mrx4.json
index 62b62d622bd..eeb751c329d 100644
--- a/advisories/unreviewed/2025/02/GHSA-8884-7rm9-mrx4/GHSA-8884-7rm9-mrx4.json
+++ b/advisories/unreviewed/2025/02/GHSA-8884-7rm9-mrx4/GHSA-8884-7rm9-mrx4.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8884-7rm9-mrx4",
- "modified": "2025-02-11T18:31:42Z",
+ "modified": "2025-02-27T21:32:07Z",
"published": "2025-02-11T18:31:42Z",
"aliases": [
"CVE-2025-24438"
diff --git a/advisories/unreviewed/2025/02/GHSA-8q79-fmf3-xh7r/GHSA-8q79-fmf3-xh7r.json b/advisories/unreviewed/2025/02/GHSA-8q79-fmf3-xh7r/GHSA-8q79-fmf3-xh7r.json
new file mode 100644
index 00000000000..05e9ce8e7df
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-8q79-fmf3-xh7r/GHSA-8q79-fmf3-xh7r.json
@@ -0,0 +1,56 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-8q79-fmf3-xh7r",
+ "modified": "2025-02-27T21:32:14Z",
+ "published": "2025-02-27T21:32:13Z",
+ "aliases": [
+ "CVE-2022-49413"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbfq: Update cgroup information before merging bio\n\nWhen the process is migrated to a different cgroup (or in case of\nwriteback just starts submitting bios associated with a different\ncgroup) bfq_merge_bio() can operate with stale cgroup information in\nbic. Thus the bio can be merged to a request from a different cgroup or\nit can result in merging of bfqqs for different cgroups or bfqqs of\nalready dead cgroups and causing possible use-after-free issues. Fix the\nproblem by updating cgroup information in bfq_merge_bio().",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49413"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/2a1077f17169a6059992a0bbdb330e0abad1e6d9"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/b06691af08b41dfd81052a3362514d9827b44bb1"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/d9165200c5627a2cf4408eefabdf0058bdf95e1a"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/da9f3025d595956410ceaab2bea01980d7775948"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/e8821f45612f2e6d9adb9c6ba0fb4184f57692aa"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/ea591cd4eb270393810e7be01feb8fde6a34fbbe"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-26T07:01:17Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-8w2r-337g-j83r/GHSA-8w2r-337g-j83r.json b/advisories/unreviewed/2025/02/GHSA-8w2r-337g-j83r/GHSA-8w2r-337g-j83r.json
new file mode 100644
index 00000000000..d778316f19b
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-8w2r-337g-j83r/GHSA-8w2r-337g-j83r.json
@@ -0,0 +1,45 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-8w2r-337g-j83r",
+ "modified": "2025-02-27T21:32:16Z",
+ "published": "2025-02-27T21:32:16Z",
+ "aliases": [
+ "CVE-2025-21804"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nPCI: rcar-ep: Fix incorrect variable used when calling devm_request_mem_region()\n\nThe rcar_pcie_parse_outbound_ranges() uses the devm_request_mem_region()\nmacro to request a needed resource. A string variable that lives on the\nstack is then used to store a dynamically computed resource name, which\nis then passed on as one of the macro arguments. This can lead to\nundefined behavior.\n\nDepending on the current contents of the memory, the manifestations of\nerrors may vary. One possible output may be as follows:\n\n $ cat /proc/iomem\n 30000000-37ffffff :\n 38000000-3fffffff :\n\nSometimes, garbage may appear after the colon.\n\nIn very rare cases, if no NULL-terminator is found in memory, the system\nmight crash because the string iterator will overrun which can lead to\naccess of unmapped memory above the stack.\n\nThus, fix this by replacing outbound_name with the name of the previously\nrequested resource. With the changes applied, the output will be as\nfollows:\n\n $ cat /proc/iomem\n 30000000-37ffffff : memory2\n 38000000-3fffffff : memory3\n\n[kwilczynski: commit log]",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21804"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/24576899c49509c0d533bcf569139f691d8f7af7"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/2c54b9fca1755e80a343ccfde0652dc5ea4744b2"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/2d2da5a4c1b4509f6f7e5a8db015cd420144beb4"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/44708208c2a4b828a57a2abe7799c9d3962e7eaa"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/9ff46b0bfeb6e0724a4ace015aa7a0b887cdb7c1"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-27T20:16:03Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-8w8c-pj2m-2g74/GHSA-8w8c-pj2m-2g74.json b/advisories/unreviewed/2025/02/GHSA-8w8c-pj2m-2g74/GHSA-8w8c-pj2m-2g74.json
index af9b07bde43..2c835debebf 100644
--- a/advisories/unreviewed/2025/02/GHSA-8w8c-pj2m-2g74/GHSA-8w8c-pj2m-2g74.json
+++ b/advisories/unreviewed/2025/02/GHSA-8w8c-pj2m-2g74/GHSA-8w8c-pj2m-2g74.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8w8c-pj2m-2g74",
- "modified": "2025-02-27T18:31:14Z",
+ "modified": "2025-02-27T21:32:15Z",
"published": "2025-02-27T18:31:14Z",
"aliases": [
"CVE-2025-25333"
],
"details": "An issue in IKEA CN iOS 4.13.0 allows attackers to access sensitive user information via supplying a crafted link.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
+ }
+ ],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-200"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-27T16:15:40Z"
diff --git a/advisories/unreviewed/2025/02/GHSA-92hm-vx54-jg8m/GHSA-92hm-vx54-jg8m.json b/advisories/unreviewed/2025/02/GHSA-92hm-vx54-jg8m/GHSA-92hm-vx54-jg8m.json
new file mode 100644
index 00000000000..7307eceef44
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-92hm-vx54-jg8m/GHSA-92hm-vx54-jg8m.json
@@ -0,0 +1,33 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-92hm-vx54-jg8m",
+ "modified": "2025-02-27T21:32:17Z",
+ "published": "2025-02-27T21:32:17Z",
+ "aliases": [
+ "CVE-2024-41334"
+ ],
+ "details": "Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vigor 2862/2926 prior to v3.9.9.4, Vigor 2133/2762/2832 prior to v3.9.8, Vigor 2135/2765/2766 prior to v4.4.5.1, Vigor 2865/2866/2927 prior to v4.4.5.3, Vigor 2962/3910 prior to v4.3.2.7, Vigor 3912 prior to v4.3.5.2, and Vigor 2925 up to v3.9.6 were discovered to not utilize certificate verification, allowing attackers to upload crafted APPE modules from non-official servers, leading to arbitrary code execution.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41334"
+ },
+ {
+ "type": "WEB",
+ "url": "https://medium.com/faraday/advisory-multiple-vulnerabilities-affecting-draytek-routers-78a6cb8b3946"
+ },
+ {
+ "type": "WEB",
+ "url": "http://draytek.com"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-27T21:15:36Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-95jr-p4jm-v55x/GHSA-95jr-p4jm-v55x.json b/advisories/unreviewed/2025/02/GHSA-95jr-p4jm-v55x/GHSA-95jr-p4jm-v55x.json
new file mode 100644
index 00000000000..93224f9845e
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-95jr-p4jm-v55x/GHSA-95jr-p4jm-v55x.json
@@ -0,0 +1,60 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-95jr-p4jm-v55x",
+ "modified": "2025-02-27T21:32:13Z",
+ "published": "2025-02-27T21:32:13Z",
+ "aliases": [
+ "CVE-2022-49176"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbfq: fix use-after-free in bfq_dispatch_request\n\nKASAN reports a use-after-free report when doing normal scsi-mq test\n\n[69832.239032] ==================================================================\n[69832.241810] BUG: KASAN: use-after-free in bfq_dispatch_request+0x1045/0x44b0\n[69832.243267] Read of size 8 at addr ffff88802622ba88 by task kworker/3:1H/155\n[69832.244656]\n[69832.245007] CPU: 3 PID: 155 Comm: kworker/3:1H Not tainted 5.10.0-10295-g576c6382529e #8\n[69832.246626] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.14.0-0-g155821a1990b-prebuilt.qemu.org 04/01/2014\n[69832.249069] Workqueue: kblockd blk_mq_run_work_fn\n[69832.250022] Call Trace:\n[69832.250541] dump_stack+0x9b/0xce\n[69832.251232] ? bfq_dispatch_request+0x1045/0x44b0\n[69832.252243] print_address_description.constprop.6+0x3e/0x60\n[69832.253381] ? __cpuidle_text_end+0x5/0x5\n[69832.254211] ? vprintk_func+0x6b/0x120\n[69832.254994] ? bfq_dispatch_request+0x1045/0x44b0\n[69832.255952] ? bfq_dispatch_request+0x1045/0x44b0\n[69832.256914] kasan_report.cold.9+0x22/0x3a\n[69832.257753] ? bfq_dispatch_request+0x1045/0x44b0\n[69832.258755] check_memory_region+0x1c1/0x1e0\n[69832.260248] bfq_dispatch_request+0x1045/0x44b0\n[69832.261181] ? bfq_bfqq_expire+0x2440/0x2440\n[69832.262032] ? blk_mq_delay_run_hw_queues+0xf9/0x170\n[69832.263022] __blk_mq_do_dispatch_sched+0x52f/0x830\n[69832.264011] ? blk_mq_sched_request_inserted+0x100/0x100\n[69832.265101] __blk_mq_sched_dispatch_requests+0x398/0x4f0\n[69832.266206] ? blk_mq_do_dispatch_ctx+0x570/0x570\n[69832.267147] ? __switch_to+0x5f4/0xee0\n[69832.267898] blk_mq_sched_dispatch_requests+0xdf/0x140\n[69832.268946] __blk_mq_run_hw_queue+0xc0/0x270\n[69832.269840] blk_mq_run_work_fn+0x51/0x60\n[69832.278170] process_one_work+0x6d4/0xfe0\n[69832.278984] worker_thread+0x91/0xc80\n[69832.279726] ? __kthread_parkme+0xb0/0x110\n[69832.280554] ? process_one_work+0xfe0/0xfe0\n[69832.281414] kthread+0x32d/0x3f0\n[69832.282082] ? kthread_park+0x170/0x170\n[69832.282849] ret_from_fork+0x1f/0x30\n[69832.283573]\n[69832.283886] Allocated by task 7725:\n[69832.284599] kasan_save_stack+0x19/0x40\n[69832.285385] __kasan_kmalloc.constprop.2+0xc1/0xd0\n[69832.286350] kmem_cache_alloc_node+0x13f/0x460\n[69832.287237] bfq_get_queue+0x3d4/0x1140\n[69832.287993] bfq_get_bfqq_handle_split+0x103/0x510\n[69832.289015] bfq_init_rq+0x337/0x2d50\n[69832.289749] bfq_insert_requests+0x304/0x4e10\n[69832.290634] blk_mq_sched_insert_requests+0x13e/0x390\n[69832.291629] blk_mq_flush_plug_list+0x4b4/0x760\n[69832.292538] blk_flush_plug_list+0x2c5/0x480\n[69832.293392] io_schedule_prepare+0xb2/0xd0\n[69832.294209] io_schedule_timeout+0x13/0x80\n[69832.295014] wait_for_common_io.constprop.1+0x13c/0x270\n[69832.296137] submit_bio_wait+0x103/0x1a0\n[69832.296932] blkdev_issue_discard+0xe6/0x160\n[69832.297794] blk_ioctl_discard+0x219/0x290\n[69832.298614] blkdev_common_ioctl+0x50a/0x1750\n[69832.304715] blkdev_ioctl+0x470/0x600\n[69832.305474] block_ioctl+0xde/0x120\n[69832.306232] vfs_ioctl+0x6c/0xc0\n[69832.306877] __se_sys_ioctl+0x90/0xa0\n[69832.307629] do_syscall_64+0x2d/0x40\n[69832.308362] entry_SYSCALL_64_after_hwframe+0x44/0xa9\n[69832.309382]\n[69832.309701] Freed by task 155:\n[69832.310328] kasan_save_stack+0x19/0x40\n[69832.311121] kasan_set_track+0x1c/0x30\n[69832.311868] kasan_set_free_info+0x1b/0x30\n[69832.312699] __kasan_slab_free+0x111/0x160\n[69832.313524] kmem_cache_free+0x94/0x460\n[69832.314367] bfq_put_queue+0x582/0x940\n[69832.315112] __bfq_bfqd_reset_in_service+0x166/0x1d0\n[69832.317275] bfq_bfqq_expire+0xb27/0x2440\n[69832.318084] bfq_dispatch_request+0x697/0x44b0\n[69832.318991] __blk_mq_do_dispatch_sched+0x52f/0x830\n[69832.319984] __blk_mq_sched_dispatch_requests+0x398/0x4f0\n[69832.321087] blk_mq_sched_dispatch_requests+0xdf/0x140\n[69832.322225] __blk_mq_run_hw_queue+0xc0/0x270\n[69832.323114] blk_mq_run_work_fn+0x51/0x6\n---truncated---",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49176"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/080665e2c3cbfc68359b9a348a3546ed9b908e7a"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/40b4ba0030e0b02cbacd424ebb9f4c8b0976c786"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/5117c9ff4c2ebae0f5c2c262d42a25a8fbc086e6"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/5687958bf18f84384d809f521210d0f5deed03b0"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/74e610b5ee0d95e751280567100509eb11517efa"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/ab552fcb17cc9e4afe0e4ac4df95fc7b30e8490a"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/df6e00b1a53c57dca82c63b5ecbcad5452231bc7"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-26T07:00:54Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-9925-237c-wgf7/GHSA-9925-237c-wgf7.json b/advisories/unreviewed/2025/02/GHSA-9925-237c-wgf7/GHSA-9925-237c-wgf7.json
new file mode 100644
index 00000000000..ccb8911cbca
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-9925-237c-wgf7/GHSA-9925-237c-wgf7.json
@@ -0,0 +1,68 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-9925-237c-wgf7",
+ "modified": "2025-02-27T21:32:14Z",
+ "published": "2025-02-27T21:32:14Z",
+ "aliases": [
+ "CVE-2022-49493"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: rt5645: Fix errorenous cleanup order\n\nThere is a logic error when removing rt5645 device as the function\nrt5645_i2c_remove() first cancel the &rt5645->jack_detect_work and\ndelete the &rt5645->btn_check_timer latter. However, since the timer\nhandler rt5645_btn_check_callback() will re-queue the jack_detect_work,\nthis cleanup order is buggy.\n\nThat is, once the del_timer_sync in rt5645_i2c_remove is concurrently\nrun with the rt5645_btn_check_callback, the canceled jack_detect_work\nwill be rescheduled again, leading to possible use-after-free.\n\nThis patch fix the issue by placing the del_timer_sync function before\nthe cancel_delayed_work_sync.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49493"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/061a6159cea583f1155f67d1915917a6b9282662"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/0941150100173d4eaf3fe08ff4b16740e7c3026f"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/1a5a3dfd9f172dcb115072f0aea5e27d3083c20e"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/236d29c5857f02e0a53fdf15d3dce1536c4322ce"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/2def44d3aec59e38d2701c568d65540783f90f2f"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/453f0920ffc1a28e28ddb9c3cd5562472b2895b0"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/7d801e807536a9a9c2146c5f4a5836f154517ed3"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/88c09e4812d72c3153afc8e5a45ecac2d0eae3ff"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/abe7554da62cb489712a54de69ef5665c250e564"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-26T07:01:25Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-9hgg-vxph-4hw9/GHSA-9hgg-vxph-4hw9.json b/advisories/unreviewed/2025/02/GHSA-9hgg-vxph-4hw9/GHSA-9hgg-vxph-4hw9.json
new file mode 100644
index 00000000000..6eae9f7eadc
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-9hgg-vxph-4hw9/GHSA-9hgg-vxph-4hw9.json
@@ -0,0 +1,48 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-9hgg-vxph-4hw9",
+ "modified": "2025-02-27T21:32:15Z",
+ "published": "2025-02-27T21:32:14Z",
+ "aliases": [
+ "CVE-2022-49696"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: fix use-after-free Read in tipc_named_reinit\n\nsyzbot found the following issue on:\n==================================================================\nBUG: KASAN: use-after-free in tipc_named_reinit+0x94f/0x9b0\nnet/tipc/name_distr.c:413\nRead of size 8 at addr ffff88805299a000 by task kworker/1:9/23764\n\nCPU: 1 PID: 23764 Comm: kworker/1:9 Not tainted\n5.18.0-rc4-syzkaller-00878-g17d49e6e8012 #0\nHardware name: Google Compute Engine/Google Compute Engine,\nBIOS Google 01/01/2011\nWorkqueue: events tipc_net_finalize_work\nCall Trace:\n \n __dump_stack lib/dump_stack.c:88 [inline]\n dump_stack_lvl+0xcd/0x134 lib/dump_stack.c:106\n print_address_description.constprop.0.cold+0xeb/0x495\nmm/kasan/report.c:313\n print_report mm/kasan/report.c:429 [inline]\n kasan_report.cold+0xf4/0x1c6 mm/kasan/report.c:491\n tipc_named_reinit+0x94f/0x9b0 net/tipc/name_distr.c:413\n tipc_net_finalize+0x234/0x3d0 net/tipc/net.c:138\n process_one_work+0x996/0x1610 kernel/workqueue.c:2289\n worker_thread+0x665/0x1080 kernel/workqueue.c:2436\n kthread+0x2e9/0x3a0 kernel/kthread.c:376\n ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:298\n \n[...]\n==================================================================\n\nIn the commit\nd966ddcc3821 (\"tipc: fix a deadlock when flushing scheduled work\"),\nthe cancel_work_sync() function just to make sure ONLY the work\ntipc_net_finalize_work() is executing/pending on any CPU completed before\ntipc namespace is destroyed through tipc_exit_net(). But this function\nis not guaranteed the work is the last queued. So, the destroyed instance\nmay be accessed in the work which will try to enqueue later.\n\nIn order to completely fix, we re-order the calling of cancel_work_sync()\nto make sure the work tipc_net_finalize_work() was last queued and it\nmust be completed by calling cancel_work_sync().",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49696"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/361c5521c1e49843b710f455cae3c0a50b714323"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/8b246ddd394d7d9640816611693b0096b998e27a"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/911600bf5a5e84bfda4d33ee32acc75ecf6159f0"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/cd7789e659e84f137631dc1f5ec8d794f2700e6c"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-26T07:01:44Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-9hrg-vg64-94qj/GHSA-9hrg-vg64-94qj.json b/advisories/unreviewed/2025/02/GHSA-9hrg-vg64-94qj/GHSA-9hrg-vg64-94qj.json
new file mode 100644
index 00000000000..90801612818
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-9hrg-vg64-94qj/GHSA-9hrg-vg64-94qj.json
@@ -0,0 +1,40 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-9hrg-vg64-94qj",
+ "modified": "2025-02-27T21:32:10Z",
+ "published": "2025-02-27T21:32:10Z",
+ "aliases": [
+ "CVE-2022-49063"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nice: arfs: fix use-after-free when freeing @rx_cpu_rmap\n\nThe CI testing bots triggered the following splat:\n\n[ 718.203054] BUG: KASAN: use-after-free in free_irq_cpu_rmap+0x53/0x80\n[ 718.206349] Read of size 4 at addr ffff8881bd127e00 by task sh/20834\n[ 718.212852] CPU: 28 PID: 20834 Comm: sh Kdump: loaded Tainted: G S W IOE 5.17.0-rc8_nextqueue-devqueue-02643-g23f3121aca93 #1\n[ 718.219695] Hardware name: Intel Corporation S2600WFT/S2600WFT, BIOS SE5C620.86B.02.01.0012.070720200218 07/07/2020\n[ 718.223418] Call Trace:\n[ 718.227139]\n[ 718.230783] dump_stack_lvl+0x33/0x42\n[ 718.234431] print_address_description.constprop.9+0x21/0x170\n[ 718.238177] ? free_irq_cpu_rmap+0x53/0x80\n[ 718.241885] ? free_irq_cpu_rmap+0x53/0x80\n[ 718.245539] kasan_report.cold.18+0x7f/0x11b\n[ 718.249197] ? free_irq_cpu_rmap+0x53/0x80\n[ 718.252852] free_irq_cpu_rmap+0x53/0x80\n[ 718.256471] ice_free_cpu_rx_rmap.part.11+0x37/0x50 [ice]\n[ 718.260174] ice_remove_arfs+0x5f/0x70 [ice]\n[ 718.263810] ice_rebuild_arfs+0x3b/0x70 [ice]\n[ 718.267419] ice_rebuild+0x39c/0xb60 [ice]\n[ 718.270974] ? asm_sysvec_apic_timer_interrupt+0x12/0x20\n[ 718.274472] ? ice_init_phy_user_cfg+0x360/0x360 [ice]\n[ 718.278033] ? delay_tsc+0x4a/0xb0\n[ 718.281513] ? preempt_count_sub+0x14/0xc0\n[ 718.284984] ? delay_tsc+0x8f/0xb0\n[ 718.288463] ice_do_reset+0x92/0xf0 [ice]\n[ 718.292014] ice_pci_err_resume+0x91/0xf0 [ice]\n[ 718.295561] pci_reset_function+0x53/0x80\n<...>\n[ 718.393035] Allocated by task 690:\n[ 718.433497] Freed by task 20834:\n[ 718.495688] Last potentially related work creation:\n[ 718.568966] The buggy address belongs to the object at ffff8881bd127e00\n which belongs to the cache kmalloc-96 of size 96\n[ 718.574085] The buggy address is located 0 bytes inside of\n 96-byte region [ffff8881bd127e00, ffff8881bd127e60)\n[ 718.579265] The buggy address belongs to the page:\n[ 718.598905] Memory state around the buggy address:\n[ 718.601809] ffff8881bd127d00: fa fb fb fb fb fb fb fb fb fb fb fb fc fc fc fc\n[ 718.604796] ffff8881bd127d80: 00 00 00 00 00 00 00 00 00 00 fc fc fc fc fc fc\n[ 718.607794] >ffff8881bd127e00: fa fb fb fb fb fb fb fb fb fb fb fb fc fc fc fc\n[ 718.610811] ^\n[ 718.613819] ffff8881bd127e80: 00 00 00 00 00 00 00 00 00 00 00 00 fc fc fc fc\n[ 718.617107] ffff8881bd127f00: fa fb fb fb fb fb fb fb fb fb fb fb fc fc fc fc\n\nThis is due to that free_irq_cpu_rmap() is always being called\n*after* (devm_)free_irq() and thus it tries to work with IRQ descs\nalready freed. For example, on device reset the driver frees the\nrmap right before allocating a new one (the splat above).\nMake rmap creation and freeing function symmetrical with\n{request,free}_irq() calls i.e. do that on ifup/ifdown instead\nof device probe/remove/resume. These operations can be performed\nindependently from the actual device aRFS configuration.\nAlso, make sure ice_vsi_free_irq() clears IRQ affinity notifiers\nonly when aRFS is disabled -- otherwise, CPU rmap sets and clears\nits own and they must not be touched manually.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49063"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/d08d2fb6d99d82da1c63aba5c0d1c6f237e150f3"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/d7442f512b71fc63a99c8a801422dde4fbbf9f93"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-26T07:00:43Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-9rg5-7j22-7fqw/GHSA-9rg5-7j22-7fqw.json b/advisories/unreviewed/2025/02/GHSA-9rg5-7j22-7fqw/GHSA-9rg5-7j22-7fqw.json
new file mode 100644
index 00000000000..8b6434cbcee
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-9rg5-7j22-7fqw/GHSA-9rg5-7j22-7fqw.json
@@ -0,0 +1,48 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-9rg5-7j22-7fqw",
+ "modified": "2025-02-27T21:32:09Z",
+ "published": "2025-02-27T21:32:09Z",
+ "aliases": [
+ "CVE-2021-47653"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: davinci: vpif: fix use-after-free on driver unbind\n\nThe driver allocates and registers two platform device structures during\nprobe, but the devices were never deregistered on driver unbind.\n\nThis results in a use-after-free on driver unbind as the device\nstructures were allocated using devres and would be freed by driver\ncore when remove() returns.\n\nFix this by adding the missing deregistration calls to the remove()\ncallback and failing probe on registration errors.\n\nNote that the platform device structures must be freed using a proper\nrelease callback to avoid leaking associated resources like device\nnames.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47653"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/43acb728bbc40169d2e2425e84a80068270974be"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/6512c3c39cb6b573b791ce45365818a38b76afbe"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/9ffc602e14d7b9f7e7cb2f67e18dfef9ef8af676"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/b5a3bb7f6f164eb6ee74ef4898dcd019b2063448"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-26T06:37:07Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-cp43-x3rr-gwcc/GHSA-cp43-x3rr-gwcc.json b/advisories/unreviewed/2025/02/GHSA-cp43-x3rr-gwcc/GHSA-cp43-x3rr-gwcc.json
new file mode 100644
index 00000000000..b9664be2a79
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-cp43-x3rr-gwcc/GHSA-cp43-x3rr-gwcc.json
@@ -0,0 +1,33 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-cp43-x3rr-gwcc",
+ "modified": "2025-02-27T21:32:16Z",
+ "published": "2025-02-27T21:32:16Z",
+ "aliases": [
+ "CVE-2025-21807"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nblock: fix queue freeze vs limits lock order in sysfs store methods\n\nqueue_attr_store() always freezes a device queue before calling the\nattribute store operation. For attributes that control queue limits, the\nstore operation will also lock the queue limits with a call to\nqueue_limits_start_update(). However, some drivers (e.g. SCSI sd) may\nneed to issue commands to a device to obtain limit values from the\nhardware with the queue limits locked. This creates a potential ABBA\ndeadlock situation if a user attempts to modify a limit (thus freezing\nthe device queue) while the device driver starts a revalidation of the\ndevice queue limits.\n\nAvoid such deadlock by not freezing the queue before calling the\n->store_limit() method in struct queue_sysfs_entry and instead use the\nqueue_limits_commit_update_frozen helper to freeze the queue after taking\nthe limits lock.\n\nThis also removes taking the sysfs lock for the store_limit method as\nit doesn't protect anything here, but creates even more nesting.\nHopefully it will go away from the actual sysfs methods entirely soon.\n\n(commit log adapted from a similar patch from Damien Le Moal)",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21807"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/8985da5481562e96b95e94ed8e5cc9b6565eb82b"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/c99f66e4084a62a2cc401c4704a84328aeddc9ec"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-27T20:16:03Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-cpr3-4f88-q3jq/GHSA-cpr3-4f88-q3jq.json b/advisories/unreviewed/2025/02/GHSA-cpr3-4f88-q3jq/GHSA-cpr3-4f88-q3jq.json
new file mode 100644
index 00000000000..d5cbaaabbe0
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-cpr3-4f88-q3jq/GHSA-cpr3-4f88-q3jq.json
@@ -0,0 +1,33 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-cpr3-4f88-q3jq",
+ "modified": "2025-02-27T21:32:18Z",
+ "published": "2025-02-27T21:32:18Z",
+ "aliases": [
+ "CVE-2024-41339"
+ ],
+ "details": "An issue in the CGI endpoint used to upload configurations in Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vigor 2862/2926 prior to v3.9.9.4, Vigor 2133/2762/2832 prior to v3.9.8, Vigor 2135/2765/2766 prior to v4.4.5.1, Vigor 2865/2866/2927 prior to v4.4.5.3, Vigor 2962/3910 prior to v4.3.2.7, Vigor 3912 prior to v4.3.5.2, and Vigor 2925 up to v3.9.6 allows attackers to upload a crafted kernel module, allowing for arbitrary code execution.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41339"
+ },
+ {
+ "type": "WEB",
+ "url": "https://medium.com/faraday/advisory-multiple-vulnerabilities-affecting-draytek-routers-78a6cb8b3946"
+ },
+ {
+ "type": "WEB",
+ "url": "http://draytek.com"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-27T21:15:36Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-cq4r-9fv8-53r2/GHSA-cq4r-9fv8-53r2.json b/advisories/unreviewed/2025/02/GHSA-cq4r-9fv8-53r2/GHSA-cq4r-9fv8-53r2.json
new file mode 100644
index 00000000000..a7eea4f01fc
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-cq4r-9fv8-53r2/GHSA-cq4r-9fv8-53r2.json
@@ -0,0 +1,45 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-cq4r-9fv8-53r2",
+ "modified": "2025-02-27T21:32:17Z",
+ "published": "2025-02-27T21:32:17Z",
+ "aliases": [
+ "CVE-2025-21823"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: Drop unmanaged ELP metric worker\n\nThe ELP worker needs to calculate new metric values for all neighbors\n\"reachable\" over an interface. Some of the used metric sources require\nlocks which might need to sleep. This sleep is incompatible with the RCU\nlist iterator used for the recorded neighbors. The initial approach to work\naround of this problem was to queue another work item per neighbor and then\nrun this in a new context.\n\nEven when this solved the RCU vs might_sleep() conflict, it has a major\nproblems: Nothing was stopping the work item in case it is not needed\nanymore - for example because one of the related interfaces was removed or\nthe batman-adv module was unloaded - resulting in potential invalid memory\naccesses.\n\nDirectly canceling the metric worker also has various problems:\n\n* cancel_work_sync for a to-be-deactivated interface is called with\n rtnl_lock held. But the code in the ELP metric worker also tries to use\n rtnl_lock() - which will never return in this case. This also means that\n cancel_work_sync would never return because it is waiting for the worker\n to finish.\n* iterating over the neighbor list for the to-be-deactivated interface is\n currently done using the RCU specific methods. Which means that it is\n possible to miss items when iterating over it without the associated\n spinlock - a behaviour which is acceptable for a periodic metric check\n but not for a cleanup routine (which must \"stop\" all still running\n workers)\n\nThe better approch is to get rid of the per interface neighbor metric\nworker and handle everything in the interface worker. The original problems\nare solved by:\n\n* creating a list of neighbors which require new metric information inside\n the RCU protected context, gathering the metric according to the new list\n outside the RCU protected context\n* only use rcu_trylock inside metric gathering code to avoid a deadlock\n when the cancel_delayed_work_sync is called in the interface removal code\n (which is called with the rtnl_lock held)",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21823"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/0fdc3c166ac17b26014313fa2b93696354511b24"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/781a06fd265a8151f7601122d9c2e985663828ff"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/8c8ecc98f5c65947b0070a24bac11e12e47cc65d"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/a7aa2317285806640c844acd4cd2cd768e395264"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/af264c2a9adc37f4bdf88ca7f3affa15d8c7de9e"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-27T20:16:04Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-cx6c-r38j-fxp8/GHSA-cx6c-r38j-fxp8.json b/advisories/unreviewed/2025/02/GHSA-cx6c-r38j-fxp8/GHSA-cx6c-r38j-fxp8.json
new file mode 100644
index 00000000000..7fb151658c0
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-cx6c-r38j-fxp8/GHSA-cx6c-r38j-fxp8.json
@@ -0,0 +1,48 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-cx6c-r38j-fxp8",
+ "modified": "2025-02-27T21:32:14Z",
+ "published": "2025-02-27T21:32:14Z",
+ "aliases": [
+ "CVE-2022-49501"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusbnet: Run unregister_netdev() before unbind() again\n\nCommit 2c9d6c2b871d (\"usbnet: run unbind() before unregister_netdev()\")\nsought to fix a use-after-free on disconnect of USB Ethernet adapters.\n\nIt turns out that a different fix is necessary to address the issue:\nhttps://lore.kernel.org/netdev/18b3541e5372bc9b9fc733d422f4e698c089077c.1650177997.git.lukas@wunner.de/\n\nSo the commit was not necessary.\n\nThe commit made binding and unbinding of USB Ethernet asymmetrical:\nBefore, usbnet_probe() first invoked the ->bind() callback and then\nregister_netdev(). usbnet_disconnect() mirrored that by first invoking\nunregister_netdev() and then ->unbind().\n\nSince the commit, the order in usbnet_disconnect() is reversed and no\nlonger mirrors usbnet_probe().\n\nOne consequence is that a PHY disconnected (and stopped) in ->unbind()\nis afterwards stopped once more by unregister_netdev() as it closes the\nnetdev before unregistering. That necessitates a contortion in ->stop()\nbecause the PHY may only be stopped if it hasn't already been\ndisconnected.\n\nReverting the commit allows making the call to phy_stop() unconditional\nin ->stop().",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49501"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/6d5deb242874d924beccf7eb3cef04c1c3b0da79"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/969a1b3ea3cb7d58a16fe12fd1b04bfc0ea40509"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/d1408f6b4dd78fb1b9e26bcf64477984e5f85409"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/fbda837107f9bd4ec658d2aa88c6856dba606f06"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-26T07:01:26Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-f7q5-fwf8-r5q4/GHSA-f7q5-fwf8-r5q4.json b/advisories/unreviewed/2025/02/GHSA-f7q5-fwf8-r5q4/GHSA-f7q5-fwf8-r5q4.json
new file mode 100644
index 00000000000..076e3025b2b
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-f7q5-fwf8-r5q4/GHSA-f7q5-fwf8-r5q4.json
@@ -0,0 +1,45 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-f7q5-fwf8-r5q4",
+ "modified": "2025-02-27T21:32:17Z",
+ "published": "2025-02-27T21:32:17Z",
+ "aliases": [
+ "CVE-2025-21818"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/xen: fix xen_hypercall_hvm() to not clobber %rbx\n\nxen_hypercall_hvm(), which is used when running as a Xen PVH guest at\nmost only once during early boot, is clobbering %rbx. Depending on\nwhether the caller relies on %rbx to be preserved across the call or\nnot, this clobbering might result in an early crash of the system.\n\nThis can be avoided by using an already saved register instead of %rbx.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21818"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/23f6f420cd727d641f95478fcf3bbbee41e4e5d6"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/242f7584da3ad041a9db809d33d27a8be8eccc29"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/4890a0858c09d96f3234a8f94663de80a7201bc4"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/522d726824cc570e0b6bf0b3af4d5a826f1b17c5"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/98a5cfd2320966f40fe049a9855f8787f0126825"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-27T20:16:04Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-fhjf-w34g-fcvp/GHSA-fhjf-w34g-fcvp.json b/advisories/unreviewed/2025/02/GHSA-fhjf-w34g-fcvp/GHSA-fhjf-w34g-fcvp.json
new file mode 100644
index 00000000000..42a2b023b58
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-fhjf-w34g-fcvp/GHSA-fhjf-w34g-fcvp.json
@@ -0,0 +1,45 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-fhjf-w34g-fcvp",
+ "modified": "2025-02-27T21:32:16Z",
+ "published": "2025-02-27T21:32:16Z",
+ "aliases": [
+ "CVE-2024-58034"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmemory: tegra20-emc: fix an OF node reference bug in tegra_emc_find_node_by_ram_code()\n\nAs of_find_node_by_name() release the reference of the argument device\nnode, tegra_emc_find_node_by_ram_code() releases some device nodes while\nstill in use, resulting in possible UAFs. According to the bindings and\nthe in-tree DTS files, the \"emc-tables\" node is always device's child\nnode with the property \"nvidia,use-ram-code\", and the \"lpddr2\" node is a\nchild of the \"emc-tables\" node. Thus utilize the\nfor_each_child_of_node() macro and of_get_child_by_name() instead of\nof_find_node_by_name() to simplify the code.\n\nThis bug was found by an experimental verification tool that I am\ndeveloping.\n\n[krzysztof: applied v1, adjust the commit msg to incorporate v2 parts]",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-58034"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/3b02273446e23961d910b50cc12528faec649fb2"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/755e44538c190c31de9090d8e8821d228fcfd416"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/b9784e5cde1f9fb83661a70e580e381ae1264d12"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/c144423cb07e4e227a8572d5742ca2b36ada770d"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/e9d07e91de140679eeaf275f47ad154467cb9e05"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-27T20:16:02Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-fhw6-3mj5-w9gv/GHSA-fhw6-3mj5-w9gv.json b/advisories/unreviewed/2025/02/GHSA-fhw6-3mj5-w9gv/GHSA-fhw6-3mj5-w9gv.json
index 9956f25e0da..5d3f6618958 100644
--- a/advisories/unreviewed/2025/02/GHSA-fhw6-3mj5-w9gv/GHSA-fhw6-3mj5-w9gv.json
+++ b/advisories/unreviewed/2025/02/GHSA-fhw6-3mj5-w9gv/GHSA-fhw6-3mj5-w9gv.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fhw6-3mj5-w9gv",
- "modified": "2025-02-11T18:31:41Z",
+ "modified": "2025-02-27T21:32:01Z",
"published": "2025-02-11T18:31:41Z",
"aliases": [
"CVE-2025-24414"
diff --git a/advisories/unreviewed/2025/02/GHSA-frc7-r8x5-7jq8/GHSA-frc7-r8x5-7jq8.json b/advisories/unreviewed/2025/02/GHSA-frc7-r8x5-7jq8/GHSA-frc7-r8x5-7jq8.json
new file mode 100644
index 00000000000..6463906a51e
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-frc7-r8x5-7jq8/GHSA-frc7-r8x5-7jq8.json
@@ -0,0 +1,48 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-frc7-r8x5-7jq8",
+ "modified": "2025-02-27T21:32:11Z",
+ "published": "2025-02-27T21:32:11Z",
+ "aliases": [
+ "CVE-2022-49082"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: mpt3sas: Fix use after free in _scsih_expander_node_remove()\n\nThe function mpt3sas_transport_port_remove() called in\n_scsih_expander_node_remove() frees the port field of the sas_expander\nstructure, leading to the following use-after-free splat from KASAN when\nthe ioc_info() call following that function is executed (e.g. when doing\nrmmod of the driver module):\n\n[ 3479.371167] ==================================================================\n[ 3479.378496] BUG: KASAN: use-after-free in _scsih_expander_node_remove+0x710/0x750 [mpt3sas]\n[ 3479.386936] Read of size 1 at addr ffff8881c037691c by task rmmod/1531\n[ 3479.393524]\n[ 3479.395035] CPU: 18 PID: 1531 Comm: rmmod Not tainted 5.17.0-rc8+ #1436\n[ 3479.401712] Hardware name: Supermicro Super Server/H12SSL-NT, BIOS 2.1 06/02/2021\n[ 3479.409263] Call Trace:\n[ 3479.411743] \n[ 3479.413875] dump_stack_lvl+0x45/0x59\n[ 3479.417582] print_address_description.constprop.0+0x1f/0x120\n[ 3479.423389] ? _scsih_expander_node_remove+0x710/0x750 [mpt3sas]\n[ 3479.429469] kasan_report.cold+0x83/0xdf\n[ 3479.433438] ? _scsih_expander_node_remove+0x710/0x750 [mpt3sas]\n[ 3479.439514] _scsih_expander_node_remove+0x710/0x750 [mpt3sas]\n[ 3479.445411] ? _raw_spin_unlock_irqrestore+0x2d/0x40\n[ 3479.452032] scsih_remove+0x525/0xc90 [mpt3sas]\n[ 3479.458212] ? mpt3sas_expander_remove+0x1d0/0x1d0 [mpt3sas]\n[ 3479.465529] ? down_write+0xde/0x150\n[ 3479.470746] ? up_write+0x14d/0x460\n[ 3479.475840] ? kernfs_find_ns+0x137/0x310\n[ 3479.481438] pci_device_remove+0x65/0x110\n[ 3479.487013] __device_release_driver+0x316/0x680\n[ 3479.493180] driver_detach+0x1ec/0x2d0\n[ 3479.498499] bus_remove_driver+0xe7/0x2d0\n[ 3479.504081] pci_unregister_driver+0x26/0x250\n[ 3479.510033] _mpt3sas_exit+0x2b/0x6cf [mpt3sas]\n[ 3479.516144] __x64_sys_delete_module+0x2fd/0x510\n[ 3479.522315] ? free_module+0xaa0/0xaa0\n[ 3479.527593] ? __cond_resched+0x1c/0x90\n[ 3479.532951] ? lockdep_hardirqs_on_prepare+0x273/0x3e0\n[ 3479.539607] ? syscall_enter_from_user_mode+0x21/0x70\n[ 3479.546161] ? trace_hardirqs_on+0x1c/0x110\n[ 3479.551828] do_syscall_64+0x35/0x80\n[ 3479.556884] entry_SYSCALL_64_after_hwframe+0x44/0xae\n[ 3479.563402] RIP: 0033:0x7f1fc482483b\n...\n[ 3479.943087] ==================================================================\n\nFix this by introducing the local variable port_id to store the port ID\nvalue before executing mpt3sas_transport_port_remove(). This local variable\nis then used in the call to ioc_info() instead of dereferencing the freed\nport structure.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49082"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/17d66b1c92bcb41e72271ec60069d3684aaa1c9c"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/1bb8a7fc64d63ec818e367e1b37676ea2ef2d20c"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/25c1353dca74ad7cf3fd7ce258fe7c957a147d5e"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/87d663d40801dffc99a5ad3b0188ad3e2b4d1557"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-26T07:00:45Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-fv97-qmwg-89pj/GHSA-fv97-qmwg-89pj.json b/advisories/unreviewed/2025/02/GHSA-fv97-qmwg-89pj/GHSA-fv97-qmwg-89pj.json
new file mode 100644
index 00000000000..bb328a78d95
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-fv97-qmwg-89pj/GHSA-fv97-qmwg-89pj.json
@@ -0,0 +1,64 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-fv97-qmwg-89pj",
+ "modified": "2025-02-27T21:32:15Z",
+ "published": "2025-02-27T21:32:14Z",
+ "aliases": [
+ "CVE-2022-49626"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsfc: fix use after free when disabling sriov\n\nUse after free is detected by kfence when disabling sriov. What was read\nafter being freed was vf->pci_dev: it was freed from pci_disable_sriov\nand later read in efx_ef10_sriov_free_vf_vports, called from\nefx_ef10_sriov_free_vf_vswitching.\n\nSet the pointer to NULL at release time to not trying to read it later.\n\nReproducer and dmesg log (note that kfence doesn't detect it every time):\n$ echo 1 > /sys/class/net/enp65s0f0np0/device/sriov_numvfs\n$ echo 0 > /sys/class/net/enp65s0f0np0/device/sriov_numvfs\n\n BUG: KFENCE: use-after-free read in efx_ef10_sriov_free_vf_vswitching+0x82/0x170 [sfc]\n\n Use-after-free read at 0x00000000ff3c1ba5 (in kfence-#224):\n efx_ef10_sriov_free_vf_vswitching+0x82/0x170 [sfc]\n efx_ef10_pci_sriov_disable+0x38/0x70 [sfc]\n efx_pci_sriov_configure+0x24/0x40 [sfc]\n sriov_numvfs_store+0xfe/0x140\n kernfs_fop_write_iter+0x11c/0x1b0\n new_sync_write+0x11f/0x1b0\n vfs_write+0x1eb/0x280\n ksys_write+0x5f/0xe0\n do_syscall_64+0x5c/0x80\n entry_SYSCALL_64_after_hwframe+0x44/0xae\n\n kfence-#224: 0x00000000edb8ef95-0x00000000671f5ce1, size=2792, cache=kmalloc-4k\n\n allocated by task 6771 on cpu 10 at 3137.860196s:\n pci_alloc_dev+0x21/0x60\n pci_iov_add_virtfn+0x2a2/0x320\n sriov_enable+0x212/0x3e0\n efx_ef10_sriov_configure+0x67/0x80 [sfc]\n efx_pci_sriov_configure+0x24/0x40 [sfc]\n sriov_numvfs_store+0xba/0x140\n kernfs_fop_write_iter+0x11c/0x1b0\n new_sync_write+0x11f/0x1b0\n vfs_write+0x1eb/0x280\n ksys_write+0x5f/0xe0\n do_syscall_64+0x5c/0x80\n entry_SYSCALL_64_after_hwframe+0x44/0xae\n\n freed by task 6771 on cpu 12 at 3170.991309s:\n device_release+0x34/0x90\n kobject_cleanup+0x3a/0x130\n pci_iov_remove_virtfn+0xd9/0x120\n sriov_disable+0x30/0xe0\n efx_ef10_pci_sriov_disable+0x57/0x70 [sfc]\n efx_pci_sriov_configure+0x24/0x40 [sfc]\n sriov_numvfs_store+0xfe/0x140\n kernfs_fop_write_iter+0x11c/0x1b0\n new_sync_write+0x11f/0x1b0\n vfs_write+0x1eb/0x280\n ksys_write+0x5f/0xe0\n do_syscall_64+0x5c/0x80\n entry_SYSCALL_64_after_hwframe+0x44/0xae",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49626"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/3199e34912d84cdfb8a93a984c5ae5c73fb13e84"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/58d93e9d160c0de6d867c7eb4c2206671a351eb1"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/9c854ae512b89229aeee93849e9bd4c115b37909"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/bcad880865bfb421885364b1f0c7351280fe2b97"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/c2240500817b3b4b996cdf2a461a3a5679f49b94"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/c9e75bb22a26e391f189f5a5133dd63dcb57fdaa"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/e435c4aeeaa073091f7f3b7735af2ef5c97d63f2"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/ebe41da5d47ac0fff877e57bd14c54dccf168827"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-26T07:01:37Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-fwpw-c8x9-xmmr/GHSA-fwpw-c8x9-xmmr.json b/advisories/unreviewed/2025/02/GHSA-fwpw-c8x9-xmmr/GHSA-fwpw-c8x9-xmmr.json
new file mode 100644
index 00000000000..50e1508bb82
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-fwpw-c8x9-xmmr/GHSA-fwpw-c8x9-xmmr.json
@@ -0,0 +1,33 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-fwpw-c8x9-xmmr",
+ "modified": "2025-02-27T21:32:16Z",
+ "published": "2025-02-27T21:32:16Z",
+ "aliases": [
+ "CVE-2024-58022"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmailbox: th1520: Fix a NULL vs IS_ERR() bug\n\nThe devm_ioremap() function doesn't return error pointers, it returns\nNULL. Update the error checking to match.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-58022"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/d0f98e14c010bcf27898b635a54c1994ac4110a8"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/ecbde88e544ff016fa08bbf2156dc431bb123e9b"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-27T20:16:02Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-g3j6-9753-8mp2/GHSA-g3j6-9753-8mp2.json b/advisories/unreviewed/2025/02/GHSA-g3j6-9753-8mp2/GHSA-g3j6-9753-8mp2.json
index 26ab3da1c17..fac65da43c5 100644
--- a/advisories/unreviewed/2025/02/GHSA-g3j6-9753-8mp2/GHSA-g3j6-9753-8mp2.json
+++ b/advisories/unreviewed/2025/02/GHSA-g3j6-9753-8mp2/GHSA-g3j6-9753-8mp2.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g3j6-9753-8mp2",
- "modified": "2025-02-11T18:31:41Z",
+ "modified": "2025-02-27T21:32:02Z",
"published": "2025-02-11T18:31:41Z",
"aliases": [
"CVE-2025-24417"
diff --git a/advisories/unreviewed/2025/02/GHSA-gc27-rvvm-q77r/GHSA-gc27-rvvm-q77r.json b/advisories/unreviewed/2025/02/GHSA-gc27-rvvm-q77r/GHSA-gc27-rvvm-q77r.json
index 6f6e5733787..b14e4db1e93 100644
--- a/advisories/unreviewed/2025/02/GHSA-gc27-rvvm-q77r/GHSA-gc27-rvvm-q77r.json
+++ b/advisories/unreviewed/2025/02/GHSA-gc27-rvvm-q77r/GHSA-gc27-rvvm-q77r.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gc27-rvvm-q77r",
- "modified": "2025-02-11T18:31:42Z",
+ "modified": "2025-02-27T21:32:02Z",
"published": "2025-02-11T18:31:41Z",
"aliases": [
"CVE-2025-24415"
diff --git a/advisories/unreviewed/2025/02/GHSA-gc4f-hpr3-xwmc/GHSA-gc4f-hpr3-xwmc.json b/advisories/unreviewed/2025/02/GHSA-gc4f-hpr3-xwmc/GHSA-gc4f-hpr3-xwmc.json
new file mode 100644
index 00000000000..d34ed6ed9ab
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-gc4f-hpr3-xwmc/GHSA-gc4f-hpr3-xwmc.json
@@ -0,0 +1,64 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-gc4f-hpr3-xwmc",
+ "modified": "2025-02-27T21:32:13Z",
+ "published": "2025-02-27T21:32:13Z",
+ "aliases": [
+ "CVE-2022-49287"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntpm: fix reference counting for struct tpm_chip\n\nThe following sequence of operations results in a refcount warning:\n\n1. Open device /dev/tpmrm.\n2. Remove module tpm_tis_spi.\n3. Write a TPM command to the file descriptor opened at step 1.\n\n------------[ cut here ]------------\nWARNING: CPU: 3 PID: 1161 at lib/refcount.c:25 kobject_get+0xa0/0xa4\nrefcount_t: addition on 0; use-after-free.\nModules linked in: tpm_tis_spi tpm_tis_core tpm mdio_bcm_unimac brcmfmac\nsha256_generic libsha256 sha256_arm hci_uart btbcm bluetooth cfg80211 vc4\nbrcmutil ecdh_generic ecc snd_soc_core crc32_arm_ce libaes\nraspberrypi_hwmon ac97_bus snd_pcm_dmaengine bcm2711_thermal snd_pcm\nsnd_timer genet snd phy_generic soundcore [last unloaded: spi_bcm2835]\nCPU: 3 PID: 1161 Comm: hold_open Not tainted 5.10.0ls-main-dirty #2\nHardware name: BCM2711\n[] (unwind_backtrace) from [] (show_stack+0x10/0x14)\n[] (show_stack) from [] (dump_stack+0xc4/0xd8)\n[] (dump_stack) from [] (__warn+0x104/0x108)\n[] (__warn) from [] (warn_slowpath_fmt+0x74/0xb8)\n[] (warn_slowpath_fmt) from [] (kobject_get+0xa0/0xa4)\n[] (kobject_get) from [] (tpm_try_get_ops+0x14/0x54 [tpm])\n[] (tpm_try_get_ops [tpm]) from [] (tpm_common_write+0x38/0x60 [tpm])\n[] (tpm_common_write [tpm]) from [] (vfs_write+0xc4/0x3c0)\n[] (vfs_write) from [] (ksys_write+0x58/0xcc)\n[] (ksys_write) from [] (ret_fast_syscall+0x0/0x4c)\nException stack(0xc226bfa8 to 0xc226bff0)\nbfa0: 00000000 000105b4 00000003 beafe664 00000014 00000000\nbfc0: 00000000 000105b4 000103f8 00000004 00000000 00000000 b6f9c000 beafe684\nbfe0: 0000006c beafe648 0001056c b6eb6944\n---[ end trace d4b8409def9b8b1f ]---\n\nThe reason for this warning is the attempt to get the chip->dev reference\nin tpm_common_write() although the reference counter is already zero.\n\nSince commit 8979b02aaf1d (\"tpm: Fix reference count to main device\") the\nextra reference used to prevent a premature zero counter is never taken,\nbecause the required TPM_CHIP_FLAG_TPM2 flag is never set.\n\nFix this by moving the TPM 2 character device handling from\ntpm_chip_alloc() to tpm_add_char_device() which is called at a later point\nin time when the flag has been set in case of TPM2.\n\nCommit fdc915f7f719 (\"tpm: expose spaces via a device link /dev/tpmrm\")\nalready introduced function tpm_devs_release() to release the extra\nreference but did not implement the required put on chip->devs that results\nin the call of this function.\n\nFix this by putting chip->devs in tpm_chip_unregister().\n\nFinally move the new implementation for the TPM 2 handling into a new\nfunction to avoid multiple checks for the TPM_CHIP_FLAG_TPM2 flag in the\ngood case and error cases.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49287"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/290e05f346d1829e849662c97e42d5ad984f5258"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/2f928c0d5c02dbab49e8c19d98725c822f6fc409"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/473a66f99cb8173c14138c5a5c69bfad04e8f9ac"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/662893b4f6bd466ff9e1cd454c44c26d32d554fe"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/6e7baf84149fb43950631415de231b3a41915aa3"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/7e0438f83dc769465ee663bb5dcf8cc154940712"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/a27ed2f3695baf15f9b34d2d7a1f9fc105539a81"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/cb64bd038beacb4331fe464a36c8b5481e8f51e2"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-26T07:01:05Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-gfvc-29p2-2qqj/GHSA-gfvc-29p2-2qqj.json b/advisories/unreviewed/2025/02/GHSA-gfvc-29p2-2qqj/GHSA-gfvc-29p2-2qqj.json
new file mode 100644
index 00000000000..d59bf2cc9a8
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-gfvc-29p2-2qqj/GHSA-gfvc-29p2-2qqj.json
@@ -0,0 +1,68 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-gfvc-29p2-2qqj",
+ "modified": "2025-02-27T21:32:14Z",
+ "published": "2025-02-27T21:32:14Z",
+ "aliases": [
+ "CVE-2022-49474"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: fix dangling sco_conn and use-after-free in sco_sock_timeout\n\nConnecting the same socket twice consecutively in sco_sock_connect()\ncould lead to a race condition where two sco_conn objects are created\nbut only one is associated with the socket. If the socket is closed\nbefore the SCO connection is established, the timer associated with the\ndangling sco_conn object won't be canceled. As the sock object is being\nfreed, the use-after-free problem happens when the timer callback\nfunction sco_sock_timeout() accesses the socket. Here's the call trace:\n\ndump_stack+0x107/0x163\n? refcount_inc+0x1c/\nprint_address_description.constprop.0+0x1c/0x47e\n? refcount_inc+0x1c/0x7b\nkasan_report+0x13a/0x173\n? refcount_inc+0x1c/0x7b\ncheck_memory_region+0x132/0x139\nrefcount_inc+0x1c/0x7b\nsco_sock_timeout+0xb2/0x1ba\nprocess_one_work+0x739/0xbd1\n? cancel_delayed_work+0x13f/0x13f\n? __raw_spin_lock_init+0xf0/0xf0\n? to_kthread+0x59/0x85\nworker_thread+0x593/0x70e\nkthread+0x346/0x35a\n? drain_workqueue+0x31a/0x31a\n? kthread_bind+0x4b/0x4b\nret_from_fork+0x1f/0x30",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49474"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/36c644c63bfcaee2d3a426f45e89a9cd09799318"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/390d82733a953c1fabf3de9c9618091a7a9c90a6"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/537f619dea4e3fa8ed1f8f938abffe3615794bcc"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/65d347cb39e2e6bd0c2a745ad7c928998ebb0162"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/6f55fac0af3531cf60d11369454c41f5fc81ab3f"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/7aa1e7d15f8a5b65f67bacb100d8fc033b21efa2"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/7d61dbd7311ab978d8ddac1749a758de4de00374"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/99df16007f4bbf9abfc3478cb17d10f0d7f8906e"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/9de3dc09e56f8deacd2bdbf4cecb71e11a312405"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-26T07:01:23Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-gh8v-hvqf-g2jx/GHSA-gh8v-hvqf-g2jx.json b/advisories/unreviewed/2025/02/GHSA-gh8v-hvqf-g2jx/GHSA-gh8v-hvqf-g2jx.json
new file mode 100644
index 00000000000..e1cb460a078
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-gh8v-hvqf-g2jx/GHSA-gh8v-hvqf-g2jx.json
@@ -0,0 +1,41 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-gh8v-hvqf-g2jx",
+ "modified": "2025-02-27T21:32:17Z",
+ "published": "2025-02-27T21:32:16Z",
+ "aliases": [
+ "CVE-2025-21808"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: xdp: Disallow attaching device-bound programs in generic mode\n\nDevice-bound programs are used to support RX metadata kfuncs. These\nkfuncs are driver-specific and rely on the driver context to read the\nmetadata. This means they can't work in generic XDP mode. However, there\nis no check to disallow such programs from being attached in generic\nmode, in which case the metadata kfuncs will be called in an invalid\ncontext, leading to crashes.\n\nFix this by adding a check to disallow attaching device-bound programs\nin generic mode.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21808"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/3595599fa8360bb3c7afa7ee50c810b4a64106ea"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/557707906dd3e34b8a8c265f664d19f95799937e"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/5a9eae683d6c36e8a7aa31e5eb8b369e41aa66e1"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/b1bc4a35a04cbeb85b6ef5911ec015baa424989f"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-27T20:16:03Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-gjxp-46rq-wg4q/GHSA-gjxp-46rq-wg4q.json b/advisories/unreviewed/2025/02/GHSA-gjxp-46rq-wg4q/GHSA-gjxp-46rq-wg4q.json
index 55cc0eb3bc5..e20c36eff45 100644
--- a/advisories/unreviewed/2025/02/GHSA-gjxp-46rq-wg4q/GHSA-gjxp-46rq-wg4q.json
+++ b/advisories/unreviewed/2025/02/GHSA-gjxp-46rq-wg4q/GHSA-gjxp-46rq-wg4q.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gjxp-46rq-wg4q",
- "modified": "2025-02-11T18:31:41Z",
+ "modified": "2025-02-27T21:32:01Z",
"published": "2025-02-11T18:31:41Z",
"aliases": [
"CVE-2025-24410"
diff --git a/advisories/unreviewed/2025/02/GHSA-gpg5-528w-fhh8/GHSA-gpg5-528w-fhh8.json b/advisories/unreviewed/2025/02/GHSA-gpg5-528w-fhh8/GHSA-gpg5-528w-fhh8.json
new file mode 100644
index 00000000000..933fba78eba
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-gpg5-528w-fhh8/GHSA-gpg5-528w-fhh8.json
@@ -0,0 +1,45 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-gpg5-528w-fhh8",
+ "modified": "2025-02-27T21:32:16Z",
+ "published": "2025-02-27T21:32:16Z",
+ "aliases": [
+ "CVE-2025-21799"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ethernet: ti: am65-cpsw: fix freeing IRQ in am65_cpsw_nuss_remove_tx_chns()\n\nWhen getting the IRQ we use k3_udma_glue_tx_get_irq() which returns\nnegative error value on error. So not NULL check is not sufficient\nto deteremine if IRQ is valid. Check that IRQ is greater then zero\nto ensure it is valid.\n\nThere is no issue at probe time but at runtime user can invoke\n.set_channels which results in the following call chain.\nam65_cpsw_set_channels()\n am65_cpsw_nuss_update_tx_rx_chns()\n am65_cpsw_nuss_remove_tx_chns()\n am65_cpsw_nuss_init_tx_chns()\n\nAt this point if am65_cpsw_nuss_init_tx_chns() fails due to\nk3_udma_glue_tx_get_irq() then tx_chn->irq will be set to a\nnegative value.\n\nThen, at subsequent .set_channels with higher channel count we\nwill attempt to free an invalid IRQ in am65_cpsw_nuss_remove_tx_chns()\nleading to a kernel warning.\n\nThe issue is present in the original commit that introduced this driver,\nalthough there, am65_cpsw_nuss_update_tx_rx_chns() existed as\nam65_cpsw_nuss_update_tx_chns().",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21799"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/4395a44acb15850e492dd1de9ec4b6479d96bc80"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/8448c87b3af68bebca21e3136913f7f77e363515"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/88fd5db8c0073bd91d18391feb5741aeb0a2b475"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/8aae91ae1c65782a169ec070e023d4d269e5d6e6"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/aea5cca681d268f794fa2385f9ec26a5cce025cd"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-27T20:16:02Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-gvx3-72r6-pv8h/GHSA-gvx3-72r6-pv8h.json b/advisories/unreviewed/2025/02/GHSA-gvx3-72r6-pv8h/GHSA-gvx3-72r6-pv8h.json
new file mode 100644
index 00000000000..8bada13ad9e
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-gvx3-72r6-pv8h/GHSA-gvx3-72r6-pv8h.json
@@ -0,0 +1,44 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-gvx3-72r6-pv8h",
+ "modified": "2025-02-27T21:32:13Z",
+ "published": "2025-02-27T21:32:13Z",
+ "aliases": [
+ "CVE-2022-49359"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/panfrost: Job should reference MMU not file_priv\n\nFor a while now it's been allowed for a MMU context to outlive it's\ncorresponding panfrost_priv, however the job structure still references\npanfrost_priv to get hold of the MMU context. If panfrost_priv has been\nfreed this is a use-after-free which I've been able to trigger resulting\nin a splat.\n\nTo fix this, drop the reference to panfrost_priv in the job structure\nand add a direct reference to the MMU structure which is what's actually\nneeded.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49359"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/472dd7ea5e19a1aeabf1711ddc756777e05ee7c2"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/6e516faf04317db2c46cbec4e3b78b4653a5b109"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/8c8e8cc91a6ffc79865108279a74fd57d9070a17"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-26T07:01:12Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-hg55-7j9j-f4rq/GHSA-hg55-7j9j-f4rq.json b/advisories/unreviewed/2025/02/GHSA-hg55-7j9j-f4rq/GHSA-hg55-7j9j-f4rq.json
new file mode 100644
index 00000000000..521ec04b155
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-hg55-7j9j-f4rq/GHSA-hg55-7j9j-f4rq.json
@@ -0,0 +1,37 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-hg55-7j9j-f4rq",
+ "modified": "2025-02-27T21:32:16Z",
+ "published": "2025-02-27T21:32:16Z",
+ "aliases": [
+ "CVE-2025-21805"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/rtrs: Add missing deinit() call\n\nA warning is triggered when repeatedly connecting and disconnecting the\nrnbd:\n list_add corruption. prev->next should be next (ffff88800b13e480), but was ffff88801ecd1338. (prev=ffff88801ecd1340).\n WARNING: CPU: 1 PID: 36562 at lib/list_debug.c:32 __list_add_valid_or_report+0x7f/0xa0\n Workqueue: ib_cm cm_work_handler [ib_cm]\n RIP: 0010:__list_add_valid_or_report+0x7f/0xa0\n ? __list_add_valid_or_report+0x7f/0xa0\n ib_register_event_handler+0x65/0x93 [ib_core]\n rtrs_srv_ib_dev_init+0x29/0x30 [rtrs_server]\n rtrs_ib_dev_find_or_add+0x124/0x1d0 [rtrs_core]\n __alloc_path+0x46c/0x680 [rtrs_server]\n ? rtrs_rdma_connect+0xa6/0x2d0 [rtrs_server]\n ? rcu_is_watching+0xd/0x40\n ? __mutex_lock+0x312/0xcf0\n ? get_or_create_srv+0xad/0x310 [rtrs_server]\n ? rtrs_rdma_connect+0xa6/0x2d0 [rtrs_server]\n rtrs_rdma_connect+0x23c/0x2d0 [rtrs_server]\n ? __lock_release+0x1b1/0x2d0\n cma_cm_event_handler+0x4a/0x1a0 [rdma_cm]\n cma_ib_req_handler+0x3a0/0x7e0 [rdma_cm]\n cm_process_work+0x28/0x1a0 [ib_cm]\n ? _raw_spin_unlock_irq+0x2f/0x50\n cm_req_handler+0x618/0xa60 [ib_cm]\n cm_work_handler+0x71/0x520 [ib_cm]\n\nCommit 667db86bcbe8 (\"RDMA/rtrs: Register ib event handler\") introduced a\nnew element .deinit but never used it at all. Fix it by invoking the\n`deinit()` to appropriately unregister the IB event handler.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21805"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/1af2c769032b6b334cd2a867d7d8c7cbbc527b2d"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/5a79cc9bc961fafe90787f86e8f53ba6fad8d63b"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/81468c4058a62e84e475433b83b3edc613294f5e"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-27T20:16:03Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-hh3r-c2qq-5xgv/GHSA-hh3r-c2qq-5xgv.json b/advisories/unreviewed/2025/02/GHSA-hh3r-c2qq-5xgv/GHSA-hh3r-c2qq-5xgv.json
new file mode 100644
index 00000000000..0b662c6786b
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-hh3r-c2qq-5xgv/GHSA-hh3r-c2qq-5xgv.json
@@ -0,0 +1,48 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-hh3r-c2qq-5xgv",
+ "modified": "2025-02-27T21:32:14Z",
+ "published": "2025-02-27T21:32:14Z",
+ "aliases": [
+ "CVE-2022-49419"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nvideo: fbdev: vesafb: Fix a use-after-free due early fb_info cleanup\n\nCommit b3c9a924aab6 (\"fbdev: vesafb: Cleanup fb_info in .fb_destroy rather\nthan .remove\") fixed a use-after-free error due the vesafb driver freeing\nthe fb_info in the .remove handler instead of doing it in .fb_destroy.\n\nThis can happen if the .fb_destroy callback is executed after the .remove\ncallback, since the former tries to access a pointer freed by the latter.\n\nBut that change didn't take into account that another possible scenario is\nthat .fb_destroy is called before the .remove callback. For example, if no\nprocess has the fbdev chardev opened by the time the driver is removed.\n\nIf that's the case, fb_info will be freed when unregister_framebuffer() is\ncalled, making the fb_info pointer accessed in vesafb_remove() after that\nto no longer be valid.\n\nTo prevent that, move the expression containing the info->par to happen\nbefore the unregister_framebuffer() function call.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49419"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/0fac5f8fb1bc2fc4f8714bf5e743c9cc3f547c63"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/acde4003efc16480375543638484d8f13f2e99a3"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/d260cad015945d1f4bb9b028a096f648506106a2"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/f605f5558ecc175ec70016a3c15f007cb6386531"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-26T07:01:18Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-hr8j-x4gj-pqf8/GHSA-hr8j-x4gj-pqf8.json b/advisories/unreviewed/2025/02/GHSA-hr8j-x4gj-pqf8/GHSA-hr8j-x4gj-pqf8.json
new file mode 100644
index 00000000000..22ed1c73e1a
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-hr8j-x4gj-pqf8/GHSA-hr8j-x4gj-pqf8.json
@@ -0,0 +1,48 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-hr8j-x4gj-pqf8",
+ "modified": "2025-02-27T21:32:13Z",
+ "published": "2025-02-27T21:32:13Z",
+ "aliases": [
+ "CVE-2022-49270"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndm: fix use-after-free in dm_cleanup_zoned_dev()\n\ndm_cleanup_zoned_dev() uses queue, so it must be called\nbefore blk_cleanup_disk() starts its killing:\n\nblk_cleanup_disk->blk_cleanup_queue()->kobject_put()->blk_release_queue()->\n->...RCU...->blk_free_queue_rcu()->kmem_cache_free()\n\nOtherwise, RCU callback may be executed first and\ndm_cleanup_zoned_dev() will touch free'd memory:\n\n BUG: KASAN: use-after-free in dm_cleanup_zoned_dev+0x33/0xd0\n Read of size 8 at addr ffff88805ac6e430 by task dmsetup/681\n\n CPU: 4 PID: 681 Comm: dmsetup Not tainted 5.17.0-rc2+ #6\n Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.14.0-2 04/01/2014\n Call Trace:\n \n dump_stack_lvl+0x57/0x7d\n print_address_description.constprop.0+0x1f/0x150\n ? dm_cleanup_zoned_dev+0x33/0xd0\n kasan_report.cold+0x7f/0x11b\n ? dm_cleanup_zoned_dev+0x33/0xd0\n dm_cleanup_zoned_dev+0x33/0xd0\n __dm_destroy+0x26a/0x400\n ? dm_blk_ioctl+0x230/0x230\n ? up_write+0xd8/0x270\n dev_remove+0x156/0x1d0\n ctl_ioctl+0x269/0x530\n ? table_clear+0x140/0x140\n ? lock_release+0xb2/0x750\n ? remove_all+0x40/0x40\n ? rcu_read_lock_sched_held+0x12/0x70\n ? lock_downgrade+0x3c0/0x3c0\n ? rcu_read_lock_sched_held+0x12/0x70\n dm_ctl_ioctl+0xa/0x10\n __x64_sys_ioctl+0xb9/0xf0\n do_syscall_64+0x3b/0x90\n entry_SYSCALL_64_after_hwframe+0x44/0xae\n RIP: 0033:0x7fb6dfa95c27",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49270"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/0987f00a76a17aa7213da492c00ed9e5a6210c73"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/43a043aed964659bc69ef81f266912b73c80d837"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/588b7f5df0cb64f281290c7672470c006abe7160"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/fdfe414ca28ddfd562c233fb27385cf820de03e8"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-26T07:01:03Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-j2gc-738w-q744/GHSA-j2gc-738w-q744.json b/advisories/unreviewed/2025/02/GHSA-j2gc-738w-q744/GHSA-j2gc-738w-q744.json
new file mode 100644
index 00000000000..2ba5814d2be
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-j2gc-738w-q744/GHSA-j2gc-738w-q744.json
@@ -0,0 +1,45 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-j2gc-738w-q744",
+ "modified": "2025-02-27T21:32:17Z",
+ "published": "2025-02-27T21:32:17Z",
+ "aliases": [
+ "CVE-2025-21811"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: protect access to buffers with no active references\n\nnilfs_lookup_dirty_data_buffers(), which iterates through the buffers\nattached to dirty data folios/pages, accesses the attached buffers without\nlocking the folios/pages.\n\nFor data cache, nilfs_clear_folio_dirty() may be called asynchronously\nwhen the file system degenerates to read only, so\nnilfs_lookup_dirty_data_buffers() still has the potential to cause use\nafter free issues when buffers lose the protection of their dirty state\nmidway due to this asynchronous clearing and are unintentionally freed by\ntry_to_free_buffers().\n\nEliminate this race issue by adjusting the lock section in this function.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21811"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/367a9bffabe08c04f6d725032cce3d891b2b9e1a"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/4b08d23d7d1917bef4fbee8ad81372f49b006656"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/58c27fa7a610b6e8d44e6220e7dbddfbaccaf439"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/8e1b9201c9a24638cf09c6e1c9f224157328010b"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/c437dfac9f7a5a46ac2a5e6d6acd3059e9f68188"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-27T20:16:03Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-j4hc-7ppm-rrh4/GHSA-j4hc-7ppm-rrh4.json b/advisories/unreviewed/2025/02/GHSA-j4hc-7ppm-rrh4/GHSA-j4hc-7ppm-rrh4.json
new file mode 100644
index 00000000000..40a8cf4bf21
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-j4hc-7ppm-rrh4/GHSA-j4hc-7ppm-rrh4.json
@@ -0,0 +1,64 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-j4hc-7ppm-rrh4",
+ "modified": "2025-02-27T21:32:09Z",
+ "published": "2025-02-27T21:32:09Z",
+ "aliases": [
+ "CVE-2021-47634"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nubi: Fix race condition between ctrl_cdev_ioctl and ubi_cdev_ioctl\n\nHulk Robot reported a KASAN report about use-after-free:\n ==================================================================\n BUG: KASAN: use-after-free in __list_del_entry_valid+0x13d/0x160\n Read of size 8 at addr ffff888035e37d98 by task ubiattach/1385\n [...]\n Call Trace:\n klist_dec_and_del+0xa7/0x4a0\n klist_put+0xc7/0x1a0\n device_del+0x4d4/0xed0\n cdev_device_del+0x1a/0x80\n ubi_attach_mtd_dev+0x2951/0x34b0 [ubi]\n ctrl_cdev_ioctl+0x286/0x2f0 [ubi]\n\n Allocated by task 1414:\n device_add+0x60a/0x18b0\n cdev_device_add+0x103/0x170\n ubi_create_volume+0x1118/0x1a10 [ubi]\n ubi_cdev_ioctl+0xb7f/0x1ba0 [ubi]\n\n Freed by task 1385:\n cdev_device_del+0x1a/0x80\n ubi_remove_volume+0x438/0x6c0 [ubi]\n ubi_cdev_ioctl+0xbf4/0x1ba0 [ubi]\n [...]\n ==================================================================\n\nThe lock held by ctrl_cdev_ioctl is ubi_devices_mutex, but the lock held\nby ubi_cdev_ioctl is ubi->device_mutex. Therefore, the two locks can be\nconcurrent.\n\nctrl_cdev_ioctl contains two operations: ubi_attach and ubi_detach.\nubi_detach is bug-free because it uses reference counting to prevent\nconcurrency. However, uif_init and uif_close in ubi_attach may race with\nubi_cdev_ioctl.\n\nuif_init will race with ubi_cdev_ioctl as in the following stack.\n cpu1 cpu2 cpu3\n_______________________|________________________|______________________\nctrl_cdev_ioctl\n ubi_attach_mtd_dev\n uif_init\n ubi_cdev_ioctl\n ubi_create_volume\n cdev_device_add\n ubi_add_volume\n // sysfs exist\n kill_volumes\n ubi_cdev_ioctl\n ubi_remove_volume\n cdev_device_del\n // first free\n ubi_free_volume\n cdev_del\n // double free\n cdev_device_del\n\nAnd uif_close will race with ubi_cdev_ioctl as in the following stack.\n cpu1 cpu2 cpu3\n_______________________|________________________|______________________\nctrl_cdev_ioctl\n ubi_attach_mtd_dev\n uif_init\n ubi_cdev_ioctl\n ubi_create_volume\n cdev_device_add\n ubi_debugfs_init_dev\n //error goto out_uif;\n uif_close\n kill_volumes\n ubi_cdev_ioctl\n ubi_remove_volume\n cdev_device_del\n // first free\n ubi_free_volume\n // double free\n\nThe cause of this problem is that commit 714fb87e8bc0 make device\n\"available\" before it becomes accessible via sysfs. Therefore, we\nroll back the modification. We will fix the race condition between\nubi device creation and udev by removing ubi_get_device in\nvol_attribute_show and dev_attribute_show.This avoids accessing\nuninitialized ubi_devices[ubi_num].\n\nubi_get_device is used to prevent devices from being deleted during\nsysfs execution. However, now kernfs ensures that devices will not\nbe deleted before all reference counting are released.\nThe key process is shown in the following stack.\n\ndevice_del\n device_remove_attrs\n device_remove_groups\n sysfs_remove_groups\n sysfs_remove_group\n remove_files\n kernfs_remove_by_name\n kernfs_remove_by_name_ns\n __kernfs_remove\n kernfs_drain",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47634"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/1a3f1cf87054833242fcd0218de0481cf855f888"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/3cbf0e392f173ba0ce425968c8374a6aa3e90f2e"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/432b057f8e847ae5a2306515606f8d2defaca178"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/5f9e9c223e48c264241d2f34d0bfc29e5fcb5c1b"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/a8ecee49259f8f78d91ddb329ab2be7e6fd01974"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/c32fe764191b8ae8b128588beb96e3718d9179d8"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/d727fd32cbd1abf3465f607021bc9c746f17b5a8"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/f149b1bd213820363731aa119e5011ca892a2aac"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-26T06:37:05Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-jc9r-g3mj-xmwh/GHSA-jc9r-g3mj-xmwh.json b/advisories/unreviewed/2025/02/GHSA-jc9r-g3mj-xmwh/GHSA-jc9r-g3mj-xmwh.json
new file mode 100644
index 00000000000..4c4468ddbe1
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-jc9r-g3mj-xmwh/GHSA-jc9r-g3mj-xmwh.json
@@ -0,0 +1,40 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-jc9r-g3mj-xmwh",
+ "modified": "2025-02-27T21:32:14Z",
+ "published": "2025-02-27T21:32:14Z",
+ "aliases": [
+ "CVE-2022-49651"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsrcu: Tighten cleanup_srcu_struct() GP checks\n\nCurrently, cleanup_srcu_struct() checks for a grace period in progress,\nbut it does not check for a grace period that has not yet started but\nwhich might start at any time. Such a situation could result in a\nuse-after-free bug, so this commit adds a check for a grace period that\nis needed but not yet started to cleanup_srcu_struct().",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49651"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/8ed00760203d8018bee042fbfe8e076579be2c2b"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/e997dda6502eefbc1032d6b0da7b353c53344b07"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-26T07:01:40Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-jfr9-726h-gv8r/GHSA-jfr9-726h-gv8r.json b/advisories/unreviewed/2025/02/GHSA-jfr9-726h-gv8r/GHSA-jfr9-726h-gv8r.json
index cf9b3af1601..564adf06903 100644
--- a/advisories/unreviewed/2025/02/GHSA-jfr9-726h-gv8r/GHSA-jfr9-726h-gv8r.json
+++ b/advisories/unreviewed/2025/02/GHSA-jfr9-726h-gv8r/GHSA-jfr9-726h-gv8r.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jfr9-726h-gv8r",
- "modified": "2025-02-27T03:34:06Z",
+ "modified": "2025-02-27T21:32:15Z",
"published": "2025-02-27T03:34:06Z",
"aliases": [
"CVE-2025-21786"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nworkqueue: Put the pwq after detaching the rescuer from the pool\n\nThe commit 68f83057b913(\"workqueue: Reap workers via kthread_stop() and\nremove detach_completion\") adds code to reap the normal workers but\nmistakenly does not handle the rescuer and also removes the code waiting\nfor the rescuer in put_unbound_pool(), which caused a use-after-free bug\nreported by Cheung Wall.\n\nTo avoid the use-after-free bug, the pool’s reference must be held until\nthe detachment is complete. Therefore, move the code that puts the pwq\nafter detaching the rescuer from the pool.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-27T03:15:19Z"
diff --git a/advisories/unreviewed/2025/02/GHSA-jgc9-w6v9-w8rc/GHSA-jgc9-w6v9-w8rc.json b/advisories/unreviewed/2025/02/GHSA-jgc9-w6v9-w8rc/GHSA-jgc9-w6v9-w8rc.json
new file mode 100644
index 00000000000..6b72b8b9b83
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-jgc9-w6v9-w8rc/GHSA-jgc9-w6v9-w8rc.json
@@ -0,0 +1,44 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-jgc9-w6v9-w8rc",
+ "modified": "2025-02-27T21:32:14Z",
+ "published": "2025-02-27T21:32:14Z",
+ "aliases": [
+ "CVE-2022-49479"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmt76: fix tx status related use-after-free race on station removal\n\nThere is a small race window where ongoing tx activity can lead to a skb\ngetting added to the status tracking idr after that idr has already been\ncleaned up, which will keep the wcid linked in the status poll list.\nFix this by only adding status skbs if the wcid pointer is still assigned\nin dev->wcid, which gets cleared early by mt76_sta_pre_rcu_remove",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49479"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/ddd426d72aca4054045a9bd3b80a4ce1d398f11f"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/ef7f9f894cfd0b2e471206409a529af4a26ddd55"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/fcfe1b5e162bf473c1d47760962cec8523c00466"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-26T07:01:24Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-jh7f-g4j5-2f7h/GHSA-jh7f-g4j5-2f7h.json b/advisories/unreviewed/2025/02/GHSA-jh7f-g4j5-2f7h/GHSA-jh7f-g4j5-2f7h.json
new file mode 100644
index 00000000000..b0c529e3c3c
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-jh7f-g4j5-2f7h/GHSA-jh7f-g4j5-2f7h.json
@@ -0,0 +1,33 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-jh7f-g4j5-2f7h",
+ "modified": "2025-02-27T21:32:16Z",
+ "published": "2025-02-27T21:32:16Z",
+ "aliases": [
+ "CVE-2024-54957"
+ ],
+ "details": "Nagios XI 2024R1.2.2 is vulnerable to an open redirect flaw on the Tools page, exploitable by users with read-only permissions. This vulnerability allows an attacker to craft a malicious link that redirects users to an arbitrary external URL without their consent.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54957"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/Sharpe-nl/CVEs/tree/main/CVE-2024-54957"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.nagios.com/products/security"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-27T20:16:01Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-jqwh-9m3g-v933/GHSA-jqwh-9m3g-v933.json b/advisories/unreviewed/2025/02/GHSA-jqwh-9m3g-v933/GHSA-jqwh-9m3g-v933.json
new file mode 100644
index 00000000000..20388cda1cf
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-jqwh-9m3g-v933/GHSA-jqwh-9m3g-v933.json
@@ -0,0 +1,33 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-jqwh-9m3g-v933",
+ "modified": "2025-02-27T21:32:18Z",
+ "published": "2025-02-27T21:32:18Z",
+ "aliases": [
+ "CVE-2024-51139"
+ ],
+ "details": "Buffer Overflow vulnerability in Vigor2620/LTE200 3.9.8.9 and earlier and Vigor2860/2925 3.9.8 and earlier and Vigor2862/2926 3.9.9.5 and earlier and Vigor2133/2762/2832 3.9.9 and earlier and Vigor165/166 4.2.7 and earlier and Vigor2135/2765/2766 4.4.5.1 and earlier and Vigor2865/2866/2927 4.4.5.3 and earlier and Vigor2962/3910 4.3.2.8/4.4.3.1 and earlier and Vigor3912 4.3.6.1 and earlier allows a remote attacker to execute arbitrary code via the CGI parser's handling of the \"Content-Length\" header of HTTP POST requests.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51139"
+ },
+ {
+ "type": "WEB",
+ "url": "https://medium.com/faraday/advisory-multiple-vulnerabilities-affecting-draytek-routers-78a6cb8b3946"
+ },
+ {
+ "type": "WEB",
+ "url": "http://draytek.com"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-27T21:15:37Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-m4rg-mpp2-97px/GHSA-m4rg-mpp2-97px.json b/advisories/unreviewed/2025/02/GHSA-m4rg-mpp2-97px/GHSA-m4rg-mpp2-97px.json
index 14f739051d0..d6757b4ff12 100644
--- a/advisories/unreviewed/2025/02/GHSA-m4rg-mpp2-97px/GHSA-m4rg-mpp2-97px.json
+++ b/advisories/unreviewed/2025/02/GHSA-m4rg-mpp2-97px/GHSA-m4rg-mpp2-97px.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m4rg-mpp2-97px",
- "modified": "2025-02-11T18:31:41Z",
+ "modified": "2025-02-27T21:32:01Z",
"published": "2025-02-11T18:31:41Z",
"aliases": [
"CVE-2025-24412"
diff --git a/advisories/unreviewed/2025/02/GHSA-mffp-559q-rchq/GHSA-mffp-559q-rchq.json b/advisories/unreviewed/2025/02/GHSA-mffp-559q-rchq/GHSA-mffp-559q-rchq.json
new file mode 100644
index 00000000000..53df9aca5b0
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-mffp-559q-rchq/GHSA-mffp-559q-rchq.json
@@ -0,0 +1,37 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-mffp-559q-rchq",
+ "modified": "2025-02-27T21:32:16Z",
+ "published": "2025-02-27T21:32:16Z",
+ "aliases": [
+ "CVE-2024-58042"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nrhashtable: Fix potential deadlock by moving schedule_work outside lock\n\nMove the hash table growth check and work scheduling outside the\nrht lock to prevent a possible circular locking dependency.\n\nThe original implementation could trigger a lockdep warning due to\na potential deadlock scenario involving nested locks between\nrhashtable bucket, rq lock, and dsq lock. By relocating the\ngrowth check and work scheduling after releasing the rth lock, we break\nthis potential deadlock chain.\n\nThis change expands the flexibility of rhashtable by removing\nrestrictive locking that previously limited its use in scheduler\nand workqueue contexts.\n\nImport to say that this calls rht_grow_above_75(), which reads from\nstruct rhashtable without holding the lock, if this is a problem, we can\nmove the check to the lock, and schedule the workqueue after the lock.\n\n\nModified so that atomic_inc is also moved outside of the bucket\nlock along with the growth above 75% check.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-58042"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/ced8ce3c83a7150c5f5d371a8c332d7bc7f9b66d"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/e1d3422c95f003eba241c176adfe593c33e8a8f6"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/eb2e58484b838fb4e777ee9721bb9e20e6ca971d"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-27T20:16:02Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-mgc5-hg3f-6h7v/GHSA-mgc5-hg3f-6h7v.json b/advisories/unreviewed/2025/02/GHSA-mgc5-hg3f-6h7v/GHSA-mgc5-hg3f-6h7v.json
new file mode 100644
index 00000000000..769d0aba712
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-mgc5-hg3f-6h7v/GHSA-mgc5-hg3f-6h7v.json
@@ -0,0 +1,33 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-mgc5-hg3f-6h7v",
+ "modified": "2025-02-27T21:32:18Z",
+ "published": "2025-02-27T21:32:18Z",
+ "aliases": [
+ "CVE-2024-51138"
+ ],
+ "details": "Vigor165/166 4.2.7 and earlier; Vigor2620/LTE200 3.9.8.9 and earlier; Vigor2860/2925 3.9.8 and earlier; Vigor2862/2926 3.9.9.5 and earlier; Vigor2133/2762/2832 3.9.9 and earlier; Vigor2135/2765/2766 4.4.5. and earlier; Vigor2865/2866/2927 4.4.5.3 and earlier; Vigor2962 4.3.2.8 and earlier; Vigor3912 4.3.6.1 and earlier; Vigor3910 4.4.3.1 and earlier a stack-based buffer overflow vulnerability has been identified in the URL parsing functionality of the TR069 STUN server. This flaw occurs due to insufficient bounds checking on the amount of URL parameters, allowing an attacker to exploit the overflow by sending a maliciously crafted request. Consequently, a remote attacker can execute arbitrary code with elevated privileges.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51138"
+ },
+ {
+ "type": "WEB",
+ "url": "https://medium.com/faraday/advisory-multiple-vulnerabilities-affecting-draytek-routers-78a6cb8b3946"
+ },
+ {
+ "type": "WEB",
+ "url": "http://draytek.com"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-27T21:15:37Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-mm87-rrqx-94cr/GHSA-mm87-rrqx-94cr.json b/advisories/unreviewed/2025/02/GHSA-mm87-rrqx-94cr/GHSA-mm87-rrqx-94cr.json
index 2c52c7f9b63..52245ece889 100644
--- a/advisories/unreviewed/2025/02/GHSA-mm87-rrqx-94cr/GHSA-mm87-rrqx-94cr.json
+++ b/advisories/unreviewed/2025/02/GHSA-mm87-rrqx-94cr/GHSA-mm87-rrqx-94cr.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mm87-rrqx-94cr",
- "modified": "2025-02-11T18:31:42Z",
+ "modified": "2025-02-27T21:32:06Z",
"published": "2025-02-11T18:31:42Z",
"aliases": [
"CVE-2025-24428"
diff --git a/advisories/unreviewed/2025/02/GHSA-mpc5-232j-wwmm/GHSA-mpc5-232j-wwmm.json b/advisories/unreviewed/2025/02/GHSA-mpc5-232j-wwmm/GHSA-mpc5-232j-wwmm.json
new file mode 100644
index 00000000000..bcc7ea1d982
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-mpc5-232j-wwmm/GHSA-mpc5-232j-wwmm.json
@@ -0,0 +1,48 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-mpc5-232j-wwmm",
+ "modified": "2025-02-27T21:32:14Z",
+ "published": "2025-02-27T21:32:14Z",
+ "aliases": [
+ "CVE-2022-49426"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\niommu/arm-smmu-v3-sva: Fix mm use-after-free\n\nWe currently call arm64_mm_context_put() without holding a reference to\nthe mm, which can result in use-after-free. Call mmgrab()/mmdrop() to\nensure the mm only gets freed after we unpinned the ASID.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49426"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/9aa215450888cf29af0c479e14a712dc6b0c506c"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/cbd23144f7662b00bcde32a938c4a4057e476d68"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/e3cbbdbff8a4db5d053c53fd71be62ccccdb52b0"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/fc90f13ea0dcd960e5002d204fa55cec4e0db2fa"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-26T07:01:19Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-mq5p-7q76-276p/GHSA-mq5p-7q76-276p.json b/advisories/unreviewed/2025/02/GHSA-mq5p-7q76-276p/GHSA-mq5p-7q76-276p.json
new file mode 100644
index 00000000000..56696942b97
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-mq5p-7q76-276p/GHSA-mq5p-7q76-276p.json
@@ -0,0 +1,45 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-mq5p-7q76-276p",
+ "modified": "2025-02-27T21:32:16Z",
+ "published": "2025-02-27T21:32:16Z",
+ "aliases": [
+ "CVE-2025-21806"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: let net.core.dev_weight always be non-zero\n\nThe following problem was encountered during stability test:\n\n(NULL net_device): NAPI poll function process_backlog+0x0/0x530 \\\n\treturned 1, exceeding its budget of 0.\n------------[ cut here ]------------\nlist_add double add: new=ffff88905f746f48, prev=ffff88905f746f48, \\\n\tnext=ffff88905f746e40.\nWARNING: CPU: 18 PID: 5462 at lib/list_debug.c:35 \\\n\t__list_add_valid_or_report+0xf3/0x130\nCPU: 18 UID: 0 PID: 5462 Comm: ping Kdump: loaded Not tainted 6.13.0-rc7+\nRIP: 0010:__list_add_valid_or_report+0xf3/0x130\nCall Trace:\n? __warn+0xcd/0x250\n? __list_add_valid_or_report+0xf3/0x130\nenqueue_to_backlog+0x923/0x1070\nnetif_rx_internal+0x92/0x2b0\n__netif_rx+0x15/0x170\nloopback_xmit+0x2ef/0x450\ndev_hard_start_xmit+0x103/0x490\n__dev_queue_xmit+0xeac/0x1950\nip_finish_output2+0x6cc/0x1620\nip_output+0x161/0x270\nip_push_pending_frames+0x155/0x1a0\nraw_sendmsg+0xe13/0x1550\n__sys_sendto+0x3bf/0x4e0\n__x64_sys_sendto+0xdc/0x1b0\ndo_syscall_64+0x5b/0x170\nentry_SYSCALL_64_after_hwframe+0x76/0x7e\n\nThe reproduction command is as follows:\n sysctl -w net.core.dev_weight=0\n ping 127.0.0.1\n\nThis is because when the napi's weight is set to 0, process_backlog() may\nreturn 0 and clear the NAPI_STATE_SCHED bit of napi->state, causing this\nnapi to be re-polled in net_rx_action() until __do_softirq() times out.\nSince the NAPI_STATE_SCHED bit has been cleared, napi_schedule_rps() can\nbe retriggered in enqueue_to_backlog(), causing this issue.\n\nMaking the napi's weight always non-zero solves this problem.\n\nTriggering this issue requires system-wide admin (setting is\nnot namespaced).",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21806"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/1489824e5226a26841c70639ebd2d1aed390764b"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/33e2168788f8fb5cb8bd4f36cb1ef37d1d34dada"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/5860abbf15eeb61838b5e32e721ba67b0aa84450"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/6ce38b5a6a49e65bad163162a54cb3f104c40b48"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/d1f9f79fa2af8e3b45cffdeef66e05833480148a"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-27T20:16:03Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-mxqw-697j-9cv7/GHSA-mxqw-697j-9cv7.json b/advisories/unreviewed/2025/02/GHSA-mxqw-697j-9cv7/GHSA-mxqw-697j-9cv7.json
index 8f9b0ca75fa..3f9602ebfb1 100644
--- a/advisories/unreviewed/2025/02/GHSA-mxqw-697j-9cv7/GHSA-mxqw-697j-9cv7.json
+++ b/advisories/unreviewed/2025/02/GHSA-mxqw-697j-9cv7/GHSA-mxqw-697j-9cv7.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mxqw-697j-9cv7",
- "modified": "2025-02-27T03:34:04Z",
+ "modified": "2025-02-27T21:32:15Z",
"published": "2025-02-27T03:34:04Z",
"aliases": [
"CVE-2025-21739"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: ufs: core: Fix use-after free in init error and remove paths\n\ndevm_blk_crypto_profile_init() registers a cleanup handler to run when\nthe associated (platform-) device is being released. For UFS, the\ncrypto private data and pointers are stored as part of the ufs_hba's\ndata structure 'struct ufs_hba::crypto_profile'. This structure is\nallocated as part of the underlying ufshcd and therefore Scsi_host\nallocation.\n\nDuring driver release or during error handling in ufshcd_pltfrm_init(),\nthis structure is released as part of ufshcd_dealloc_host() before the\n(platform-) device associated with the crypto call above is released.\nOnce this device is released, the crypto cleanup code will run, using\nthe just-released 'struct ufs_hba::crypto_profile'. This causes a\nuse-after-free situation:\n\n Call trace:\n kfree+0x60/0x2d8 (P)\n kvfree+0x44/0x60\n blk_crypto_profile_destroy_callback+0x28/0x70\n devm_action_release+0x1c/0x30\n release_nodes+0x6c/0x108\n devres_release_all+0x98/0x100\n device_unbind_cleanup+0x20/0x70\n really_probe+0x218/0x2d0\n\nIn other words, the initialisation code flow is:\n\n platform-device probe\n ufshcd_pltfrm_init()\n ufshcd_alloc_host()\n scsi_host_alloc()\n allocation of struct ufs_hba\n creation of scsi-host devices\n devm_blk_crypto_profile_init()\n devm registration of cleanup handler using platform-device\n\nand during error handling of ufshcd_pltfrm_init() or during driver\nremoval:\n\n ufshcd_dealloc_host()\n scsi_host_put()\n put_device(scsi-host)\n release of struct ufs_hba\n put_device(platform-device)\n crypto cleanup handler\n\nTo fix this use-after free, change ufshcd_alloc_host() to register a\ndevres action to automatically cleanup the underlying SCSI device on\nufshcd destruction, without requiring explicit calls to\nufshcd_dealloc_host(). This way:\n\n * the crypto profile and all other ufs_hba-owned resources are\n destroyed before SCSI (as they've been registered after)\n * a memleak is plugged in tc-dwc-g210-pci.c remove() as a\n side-effect\n * EXPORT_SYMBOL_GPL(ufshcd_dealloc_host) can be removed fully as\n it's not needed anymore\n * no future drivers using ufshcd_alloc_host() could ever forget\n adding the cleanup",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-27T03:15:14Z"
diff --git a/advisories/unreviewed/2025/02/GHSA-p247-4v6m-f77m/GHSA-p247-4v6m-f77m.json b/advisories/unreviewed/2025/02/GHSA-p247-4v6m-f77m/GHSA-p247-4v6m-f77m.json
new file mode 100644
index 00000000000..dfdd3cea254
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-p247-4v6m-f77m/GHSA-p247-4v6m-f77m.json
@@ -0,0 +1,64 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-p247-4v6m-f77m",
+ "modified": "2025-02-27T21:32:15Z",
+ "published": "2025-02-27T21:32:15Z",
+ "aliases": [
+ "CVE-2022-49700"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/slub: add missing TID updates on slab deactivation\n\nThe fastpath in slab_alloc_node() assumes that c->slab is stable as long as\nthe TID stays the same. However, two places in __slab_alloc() currently\ndon't update the TID when deactivating the CPU slab.\n\nIf multiple operations race the right way, this could lead to an object\ngetting lost; or, in an even more unlikely situation, it could even lead to\nan object being freed onto the wrong slab's freelist, messing up the\n`inuse` counter and eventually causing a page to be freed to the page\nallocator while it still contains slab objects.\n\n(I haven't actually tested these cases though, this is just based on\nlooking at the code. Writing testcases for this stuff seems like it'd be\na pain...)\n\nThe race leading to state inconsistency is (all operations on the same CPU\nand kmem_cache):\n\n - task A: begin do_slab_free():\n - read TID\n - read pcpu freelist (==NULL)\n - check `slab == c->slab` (true)\n - [PREEMPT A->B]\n - task B: begin slab_alloc_node():\n - fastpath fails (`c->freelist` is NULL)\n - enter __slab_alloc()\n - slub_get_cpu_ptr() (disables preemption)\n - enter ___slab_alloc()\n - take local_lock_irqsave()\n - read c->freelist as NULL\n - get_freelist() returns NULL\n - write `c->slab = NULL`\n - drop local_unlock_irqrestore()\n - goto new_slab\n - slub_percpu_partial() is NULL\n - get_partial() returns NULL\n - slub_put_cpu_ptr() (enables preemption)\n - [PREEMPT B->A]\n - task A: finish do_slab_free():\n - this_cpu_cmpxchg_double() succeeds()\n - [CORRUPT STATE: c->slab==NULL, c->freelist!=NULL]\n\nFrom there, the object on c->freelist will get lost if task B is allowed to\ncontinue from here: It will proceed to the retry_load_slab label,\nset c->slab, then jump to load_freelist, which clobbers c->freelist.\n\nBut if we instead continue as follows, we get worse corruption:\n\n - task A: run __slab_free() on object from other struct slab:\n - CPU_PARTIAL_FREE case (slab was on no list, is now on pcpu partial)\n - task A: run slab_alloc_node() with NUMA node constraint:\n - fastpath fails (c->slab is NULL)\n - call __slab_alloc()\n - slub_get_cpu_ptr() (disables preemption)\n - enter ___slab_alloc()\n - c->slab is NULL: goto new_slab\n - slub_percpu_partial() is non-NULL\n - set c->slab to slub_percpu_partial(c)\n - [CORRUPT STATE: c->slab points to slab-1, c->freelist has objects\n from slab-2]\n - goto redo\n - node_match() fails\n - goto deactivate_slab\n - existing c->freelist is passed into deactivate_slab()\n - inuse count of slab-1 is decremented to account for object from\n slab-2\n\nAt this point, the inuse count of slab-1 is 1 lower than it should be.\nThis means that if we free all allocated objects in slab-1 except for one,\nSLUB will think that slab-1 is completely unused, and may free its page,\nleading to use-after-free.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49700"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/0515cc9b6b24877f59b222ade704bfaa42caa2a6"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/197e257da473c725dfe47759c3ee02f2398d8ea5"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/308c6d0e1f200fd26c71270c6e6bfcf0fc6ff082"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/6c32496964da0dc230cea763a0e934b2e02dabd5"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/d6a597450e686d4c6388bd3cdcb17224b4dae7f0"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/e2b2f0e2e34d71ae6c2a1114fd3c525930e84bc7"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/e7e3e90d671078455a3a08189f89d85b3da2de9e"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/eeaa345e128515135ccb864c04482180c08e3259"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-26T07:01:44Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-p7wm-885p-3rmg/GHSA-p7wm-885p-3rmg.json b/advisories/unreviewed/2025/02/GHSA-p7wm-885p-3rmg/GHSA-p7wm-885p-3rmg.json
new file mode 100644
index 00000000000..852c6987c56
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-p7wm-885p-3rmg/GHSA-p7wm-885p-3rmg.json
@@ -0,0 +1,41 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-p7wm-885p-3rmg",
+ "modified": "2025-02-27T21:32:17Z",
+ "published": "2025-02-27T21:32:17Z",
+ "aliases": [
+ "CVE-2025-21810"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndriver core: class: Fix wild pointer dereferences in API class_dev_iter_next()\n\nThere are a potential wild pointer dereferences issue regarding APIs\nclass_dev_iter_(init|next|exit)(), as explained by below typical usage:\n\n// All members of @iter are wild pointers.\nstruct class_dev_iter iter;\n\n// class_dev_iter_init(@iter, @class, ...) checks parameter @class for\n// potential class_to_subsys() error, and it returns void type and does\n// not initialize its output parameter @iter, so caller can not detect\n// the error and continues to invoke class_dev_iter_next(@iter) even if\n// @iter still contains wild pointers.\nclass_dev_iter_init(&iter, ...);\n\n// Dereference these wild pointers in @iter here once suffer the error.\nwhile (dev = class_dev_iter_next(&iter)) { ... };\n\n// Also dereference these wild pointers here.\nclass_dev_iter_exit(&iter);\n\nActually, all callers of these APIs have such usage pattern in kernel tree.\nFix by:\n- Initialize output parameter @iter by memset() in class_dev_iter_init()\n and give callers prompt by pr_crit() for the error.\n- Check if @iter is valid in class_dev_iter_next().",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21810"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/1614e75d1a1b63db6421c7a4bf37004720c7376c"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/5c504e9767b947cf7d4e29b811c0c8b3c53242b7"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/e128f82f7006991c99a58114f70ef61e937b1ac1"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/f4b9bc823b0cfdebfed479c0e87d6939c7562e87"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-27T20:16:03Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-p9mp-976m-mcf6/GHSA-p9mp-976m-mcf6.json b/advisories/unreviewed/2025/02/GHSA-p9mp-976m-mcf6/GHSA-p9mp-976m-mcf6.json
new file mode 100644
index 00000000000..329426688d5
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-p9mp-976m-mcf6/GHSA-p9mp-976m-mcf6.json
@@ -0,0 +1,40 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-p9mp-976m-mcf6",
+ "modified": "2025-02-27T21:32:16Z",
+ "published": "2025-02-27T21:32:16Z",
+ "aliases": [
+ "CVE-2025-22624"
+ ],
+ "details": "FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry and Carousel 2.4.29 was found to be vulnerable. The web application dynamically generates web content without validating the source of the potentially untrusted data in myapp/extensions/albums/admin/class-meta boxes.php.",
+ "severity": [
+ {
+ "type": "CVSS_V4",
+ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22624"
+ },
+ {
+ "type": "WEB",
+ "url": "https://fluidattacks.com/advisories/skims-10"
+ },
+ {
+ "type": "WEB",
+ "url": "https://wordpress.org/plugins/foogallery"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-27T19:15:50Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-pc9x-vqhx-p2xg/GHSA-pc9x-vqhx-p2xg.json b/advisories/unreviewed/2025/02/GHSA-pc9x-vqhx-p2xg/GHSA-pc9x-vqhx-p2xg.json
index ca28196e195..9989b03d7b4 100644
--- a/advisories/unreviewed/2025/02/GHSA-pc9x-vqhx-p2xg/GHSA-pc9x-vqhx-p2xg.json
+++ b/advisories/unreviewed/2025/02/GHSA-pc9x-vqhx-p2xg/GHSA-pc9x-vqhx-p2xg.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pc9x-vqhx-p2xg",
- "modified": "2025-02-27T03:34:02Z",
+ "modified": "2025-02-27T21:32:15Z",
"published": "2025-02-27T03:34:02Z",
"aliases": [
"CVE-2025-21729"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: rtw89: fix race between cancel_hw_scan and hw_scan completion\n\nThe rtwdev->scanning flag isn't protected by mutex originally, so\ncancel_hw_scan can pass the condition, but suddenly hw_scan completion\nunset the flag and calls ieee80211_scan_completed() that will free\nlocal->hw_scan_req. Then, cancel_hw_scan raises null-ptr-deref and\nuse-after-free. Fix it by moving the check condition to where\nprotected by mutex.\n\n KASAN: null-ptr-deref in range [0x0000000000000088-0x000000000000008f]\n CPU: 2 PID: 6922 Comm: kworker/2:2 Tainted: G OE\n Hardware name: LENOVO 2356AD1/2356AD1, BIOS G7ETB6WW (2.76 ) 09/10/2019\n Workqueue: events cfg80211_conn_work [cfg80211]\n RIP: 0010:rtw89_fw_h2c_scan_offload_be+0xc33/0x13c3 [rtw89_core]\n Code: 00 45 89 6c 24 1c 0f 85 23 01 00 00 48 8b 85 20 ff ff ff 48 8d\n RSP: 0018:ffff88811fd9f068 EFLAGS: 00010206\n RAX: dffffc0000000000 RBX: ffff88811fd9f258 RCX: 0000000000000001\n RDX: 0000000000000011 RSI: 0000000000000001 RDI: 0000000000000089\n RBP: ffff88811fd9f170 R08: 0000000000000000 R09: 0000000000000000\n R10: ffff88811fd9f108 R11: 0000000000000000 R12: ffff88810e47f960\n R13: 0000000000000000 R14: 000000000000ffff R15: 0000000000000000\n FS: 0000000000000000(0000) GS:ffff8881d6f00000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 00007531dfca55b0 CR3: 00000001be296004 CR4: 00000000001706e0\n Call Trace:\n \n ? show_regs+0x61/0x73\n ? __die_body+0x20/0x73\n ? die_addr+0x4f/0x7b\n ? exc_general_protection+0x191/0x1db\n ? asm_exc_general_protection+0x27/0x30\n ? rtw89_fw_h2c_scan_offload_be+0xc33/0x13c3 [rtw89_core]\n ? rtw89_fw_h2c_scan_offload_be+0x458/0x13c3 [rtw89_core]\n ? __pfx_rtw89_fw_h2c_scan_offload_be+0x10/0x10 [rtw89_core]\n ? do_raw_spin_lock+0x75/0xdb\n ? __pfx_do_raw_spin_lock+0x10/0x10\n rtw89_hw_scan_offload+0xb5e/0xbf7 [rtw89_core]\n ? _raw_spin_unlock+0xe/0x24\n ? __mutex_lock.constprop.0+0x40c/0x471\n ? __pfx_rtw89_hw_scan_offload+0x10/0x10 [rtw89_core]\n ? __mutex_lock_slowpath+0x13/0x1f\n ? mutex_lock+0xa2/0xdc\n ? __pfx_mutex_lock+0x10/0x10\n rtw89_hw_scan_abort+0x58/0xb7 [rtw89_core]\n rtw89_ops_cancel_hw_scan+0x120/0x13b [rtw89_core]\n ieee80211_scan_cancel+0x468/0x4d0 [mac80211]\n ieee80211_prep_connection+0x858/0x899 [mac80211]\n ieee80211_mgd_auth+0xbea/0xdde [mac80211]\n ? __pfx_ieee80211_mgd_auth+0x10/0x10 [mac80211]\n ? cfg80211_find_elem+0x15/0x29 [cfg80211]\n ? is_bss+0x1b7/0x1d7 [cfg80211]\n ieee80211_auth+0x18/0x27 [mac80211]\n cfg80211_mlme_auth+0x3bb/0x3e7 [cfg80211]\n cfg80211_conn_do_work+0x410/0xb81 [cfg80211]\n ? __pfx_cfg80211_conn_do_work+0x10/0x10 [cfg80211]\n ? __kasan_check_read+0x11/0x1f\n ? psi_group_change+0x8bc/0x944\n ? __kasan_check_write+0x14/0x22\n ? mutex_lock+0x8e/0xdc\n ? __pfx_mutex_lock+0x10/0x10\n ? __pfx___radix_tree_lookup+0x10/0x10\n cfg80211_conn_work+0x245/0x34d [cfg80211]\n ? __pfx_cfg80211_conn_work+0x10/0x10 [cfg80211]\n ? update_cfs_rq_load_avg+0x3bc/0x3d7\n ? sched_clock_noinstr+0x9/0x1a\n ? sched_clock+0x10/0x24\n ? sched_clock_cpu+0x7e/0x42e\n ? newidle_balance+0x796/0x937\n ? __pfx_sched_clock_cpu+0x10/0x10\n ? __pfx_newidle_balance+0x10/0x10\n ? __kasan_check_read+0x11/0x1f\n ? psi_group_change+0x8bc/0x944\n ? _raw_spin_unlock+0xe/0x24\n ? raw_spin_rq_unlock+0x47/0x54\n ? raw_spin_rq_unlock_irq+0x9/0x1f\n ? finish_task_switch.isra.0+0x347/0x586\n ? __schedule+0x27bf/0x2892\n ? mutex_unlock+0x80/0xd0\n ? do_raw_spin_lock+0x75/0xdb\n ? __pfx___schedule+0x10/0x10\n process_scheduled_works+0x58c/0x821\n worker_thread+0x4c7/0x586\n ? __kasan_check_read+0x11/0x1f\n kthread+0x285/0x294\n ? __pfx_worker_thread+0x10/0x10\n ? __pfx_kthread+0x10/0x10\n ret_from_fork+0x29/0x6f\n ? __pfx_kthread+0x10/0x10\n ret_from_fork_asm+0x1b/0x30\n ",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-27T02:15:16Z"
diff --git a/advisories/unreviewed/2025/02/GHSA-pgjm-rqqp-m93m/GHSA-pgjm-rqqp-m93m.json b/advisories/unreviewed/2025/02/GHSA-pgjm-rqqp-m93m/GHSA-pgjm-rqqp-m93m.json
new file mode 100644
index 00000000000..4b20da3ad24
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-pgjm-rqqp-m93m/GHSA-pgjm-rqqp-m93m.json
@@ -0,0 +1,45 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-pgjm-rqqp-m93m",
+ "modified": "2025-02-27T21:32:17Z",
+ "published": "2025-02-27T21:32:17Z",
+ "aliases": [
+ "CVE-2025-21820"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntty: xilinx_uartps: split sysrq handling\n\nlockdep detects the following circular locking dependency:\n\nCPU 0 CPU 1\n========================== ============================\ncdns_uart_isr() printk()\n uart_port_lock(port) console_lock()\n\t\t\t cdns_uart_console_write()\n if (!port->sysrq)\n uart_port_lock(port)\n uart_handle_break()\n port->sysrq = ...\n uart_handle_sysrq_char()\n printk()\n console_lock()\n\nThe fixed commit attempts to avoid this situation by only taking the\nport lock in cdns_uart_console_write if port->sysrq unset. However, if\n(as shown above) cdns_uart_console_write runs before port->sysrq is set,\nthen it will try to take the port lock anyway. This may result in a\ndeadlock.\n\nFix this by splitting sysrq handling into two parts. We use the prepare\nhelper under the port lock and defer handling until we release the lock.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21820"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/4410dba9807a17a93f649a9f5870ceaf30a675a3"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/8ea0e7b3d7b8f2f0fc9db491ff22a0abe120801c"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/9b88a7c4584ba67267a051069b8abe44fc9595b2"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/b06f388994500297bb91be60ffaf6825ecfd2afe"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/de5bd24197bd9ee37ec1e379a3d882bbd15c5065"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-27T20:16:04Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-pp5m-frf4-qc3r/GHSA-pp5m-frf4-qc3r.json b/advisories/unreviewed/2025/02/GHSA-pp5m-frf4-qc3r/GHSA-pp5m-frf4-qc3r.json
new file mode 100644
index 00000000000..b14a6e2d624
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-pp5m-frf4-qc3r/GHSA-pp5m-frf4-qc3r.json
@@ -0,0 +1,33 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-pp5m-frf4-qc3r",
+ "modified": "2025-02-27T21:32:17Z",
+ "published": "2025-02-27T21:32:17Z",
+ "aliases": [
+ "CVE-2024-41335"
+ ],
+ "details": "Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vigor 2862/2926 prior to v3.9.9.4, Vigor 2133/2762/2832 prior to v3.9.8, Vigor 2135/2765/2766 prior to v4.4.5.1, Vigor 2865/2866/2927 prior to v4.4.5.3, Vigor 2962/3910 prior to v4.3.2.7, Vigor 3912 prior to v4.3.5.2, and Vigor 2925 up to v3.9.6 were discovered to utilize insecure versions of the functions strcmp and memcmp, allowing attackers to possibly obtain sensitive information via timing attacks.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41335"
+ },
+ {
+ "type": "WEB",
+ "url": "https://medium.com/faraday/advisory-multiple-vulnerabilities-affecting-draytek-routers-78a6cb8b3946"
+ },
+ {
+ "type": "WEB",
+ "url": "http://draytek.com"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-27T21:15:36Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-prh5-fm3v-6477/GHSA-prh5-fm3v-6477.json b/advisories/unreviewed/2025/02/GHSA-prh5-fm3v-6477/GHSA-prh5-fm3v-6477.json
new file mode 100644
index 00000000000..6e14aec6d93
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-prh5-fm3v-6477/GHSA-prh5-fm3v-6477.json
@@ -0,0 +1,29 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-prh5-fm3v-6477",
+ "modified": "2025-02-27T21:32:16Z",
+ "published": "2025-02-27T21:32:16Z",
+ "aliases": [
+ "CVE-2024-53408"
+ ],
+ "details": "AVE System Web Client v2.1.131.13992 was discovered to contain a cross-site scripting (XSS) vulnerability.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53408"
+ },
+ {
+ "type": "WEB",
+ "url": "https://cosmosofcyberspace.github.io/ave-system-cve.html"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-27T20:16:01Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-q2r6-4p8p-594q/GHSA-q2r6-4p8p-594q.json b/advisories/unreviewed/2025/02/GHSA-q2r6-4p8p-594q/GHSA-q2r6-4p8p-594q.json
new file mode 100644
index 00000000000..ae04ad91953
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-q2r6-4p8p-594q/GHSA-q2r6-4p8p-594q.json
@@ -0,0 +1,64 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-q2r6-4p8p-594q",
+ "modified": "2025-02-27T21:32:14Z",
+ "published": "2025-02-27T21:32:14Z",
+ "aliases": [
+ "CVE-2022-49524"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: pci: cx23885: Fix the error handling in cx23885_initdev()\n\nWhen the driver fails to call the dma_set_mask(), the driver will get\nthe following splat:\n\n[ 55.853884] BUG: KASAN: use-after-free in __process_removed_driver+0x3c/0x240\n[ 55.854486] Read of size 8 at addr ffff88810de60408 by task modprobe/590\n[ 55.856822] Call Trace:\n[ 55.860327] __process_removed_driver+0x3c/0x240\n[ 55.861347] bus_for_each_dev+0x102/0x160\n[ 55.861681] i2c_del_driver+0x2f/0x50\n\nThis is because the driver has initialized the i2c related resources\nin cx23885_dev_setup() but not released them in error handling, fix this\nbug by modifying the error path that jumps after failing to call the\ndma_set_mask().",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49524"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/453514a874c78df1e7804e6e3aaa60c8d8deb6a8"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/6041d1a0365baa729b6adfb6ed5386d9388018db"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/7b9978e1c94e569d65a0e7e719abb9340f5db4a0"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/86bd6a579c6c60547706cabf299cd2c9feab3332"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/98106f100f50c487469903b9cf6d966785fc9cc3"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/ca17e7a532d1a55466cc007b3f4d319541a27493"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/e8123311cf06d7dae71e8c5fe78e0510d20cd30b"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/fa636e9ee4442215cd9a2e079cd5a8e1fe0cb8ba"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-26T07:01:28Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-q7gv-q8jp-4pmj/GHSA-q7gv-q8jp-4pmj.json b/advisories/unreviewed/2025/02/GHSA-q7gv-q8jp-4pmj/GHSA-q7gv-q8jp-4pmj.json
new file mode 100644
index 00000000000..982de4618aa
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-q7gv-q8jp-4pmj/GHSA-q7gv-q8jp-4pmj.json
@@ -0,0 +1,44 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-q7gv-q8jp-4pmj",
+ "modified": "2025-02-27T21:32:14Z",
+ "published": "2025-02-27T21:32:14Z",
+ "aliases": [
+ "CVE-2022-49464"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nerofs: fix buffer copy overflow of ztailpacking feature\n\nI got some KASAN report as below:\n\n[ 46.959738] ==================================================================\n[ 46.960430] BUG: KASAN: use-after-free in z_erofs_shifted_transform+0x2bd/0x370\n[ 46.960430] Read of size 4074 at addr ffff8880300c2f8e by task fssum/188\n...\n[ 46.960430] Call Trace:\n[ 46.960430] \n[ 46.960430] dump_stack_lvl+0x41/0x5e\n[ 46.960430] print_report.cold+0xb2/0x6b7\n[ 46.960430] ? z_erofs_shifted_transform+0x2bd/0x370\n[ 46.960430] kasan_report+0x8a/0x140\n[ 46.960430] ? z_erofs_shifted_transform+0x2bd/0x370\n[ 46.960430] kasan_check_range+0x14d/0x1d0\n[ 46.960430] memcpy+0x20/0x60\n[ 46.960430] z_erofs_shifted_transform+0x2bd/0x370\n[ 46.960430] z_erofs_decompress_pcluster+0xaae/0x1080\n\nThe root cause is that the tail pcluster won't be a complete filesystem\nblock anymore. So if ztailpacking is used, the second part of an\nuncompressed tail pcluster may not be ``rq->pageofs_out``.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49464"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/4d53a625f29074e7b8236c2c0e0922edb7608df9"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/6b59e1907f58cf877c563dcf013159eb9f994b64"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/dcbe6803fffd387f72b48c2373b5f5ed12a5804b"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-26T07:01:22Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-qp82-v3h4-hw29/GHSA-qp82-v3h4-hw29.json b/advisories/unreviewed/2025/02/GHSA-qp82-v3h4-hw29/GHSA-qp82-v3h4-hw29.json
new file mode 100644
index 00000000000..be7dae9c103
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-qp82-v3h4-hw29/GHSA-qp82-v3h4-hw29.json
@@ -0,0 +1,48 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-qp82-v3h4-hw29",
+ "modified": "2025-02-27T21:32:13Z",
+ "published": "2025-02-27T21:32:13Z",
+ "aliases": [
+ "CVE-2022-49362"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nNFSD: Fix potential use-after-free in nfsd_file_put()\n\nnfsd_file_put_noref() can free @nf, so don't dereference @nf\nimmediately upon return from nfsd_file_put_noref().",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49362"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/261eabe19cb28e4a8587a4442d257b543d7c2d57"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/333dcc94ebf53f79f3dc0e7a7c16700bc7ff7e57"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/ada1757b259f353cade47037ee0a0249b4cddad3"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/b6c71c66b0ad8f2b59d9bc08c7a5079b110bec01"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-26T07:01:12Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-qq39-f366-wjqw/GHSA-qq39-f366-wjqw.json b/advisories/unreviewed/2025/02/GHSA-qq39-f366-wjqw/GHSA-qq39-f366-wjqw.json
new file mode 100644
index 00000000000..cd67c562913
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-qq39-f366-wjqw/GHSA-qq39-f366-wjqw.json
@@ -0,0 +1,68 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-qq39-f366-wjqw",
+ "modified": "2025-02-27T21:32:14Z",
+ "published": "2025-02-27T21:32:13Z",
+ "aliases": [
+ "CVE-2022-49416"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: fix use-after-free in chanctx code\n\nIn ieee80211_vif_use_reserved_context(), when we have an\nold context and the new context's replace_state is set to\nIEEE80211_CHANCTX_REPLACE_NONE, we free the old context\nin ieee80211_vif_use_reserved_reassign(). Therefore, we\ncannot check the old_ctx anymore, so we should set it to\nNULL after this point.\n\nHowever, since the new_ctx replace state is clearly not\nIEEE80211_CHANCTX_REPLACES_OTHER, we're not going to do\nanything else in this function and can just return to\navoid accessing the freed old_ctx.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49416"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/265bec4779a38b65e86a25120370f200822dfa76"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/2965c4cdf7ad9ce0796fac5e57debb9519ea721e"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/4ba81e794f0fad6234f644c2da1ae14d5b95e1c4"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/4f05a9e15edcdf5b97e0d86ab6ecd5f187289f6c"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/6118bbdf69f4718b02d26bbcf2e497eb66004331"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/82c8e7bbdd06c7ed58e22450cc5b37f33a25bb2c"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/88cc8f963febe192d6ded9df7217f92f380b449a"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/9f1e5cc85ad77e52f54049a94db0407445ae2a34"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/b79110f2bf6022e60e590d2e094728a8eec3e79e"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-26T07:01:18Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-qwcq-8262-9j44/GHSA-qwcq-8262-9j44.json b/advisories/unreviewed/2025/02/GHSA-qwcq-8262-9j44/GHSA-qwcq-8262-9j44.json
new file mode 100644
index 00000000000..137f564bfb8
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-qwcq-8262-9j44/GHSA-qwcq-8262-9j44.json
@@ -0,0 +1,68 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-qwcq-8262-9j44",
+ "modified": "2025-02-27T21:32:13Z",
+ "published": "2025-02-27T21:32:13Z",
+ "aliases": [
+ "CVE-2022-49349"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\next4: fix use-after-free in ext4_rename_dir_prepare\n\nWe got issue as follows:\nEXT4-fs (loop0): mounted filesystem without journal. Opts: ,errors=continue\next4_get_first_dir_block: bh->b_data=0xffff88810bee6000 len=34478\next4_get_first_dir_block: *parent_de=0xffff88810beee6ae bh->b_data=0xffff88810bee6000\next4_rename_dir_prepare: [1] parent_de=0xffff88810beee6ae\n==================================================================\nBUG: KASAN: use-after-free in ext4_rename_dir_prepare+0x152/0x220\nRead of size 4 at addr ffff88810beee6ae by task rep/1895\n\nCPU: 13 PID: 1895 Comm: rep Not tainted 5.10.0+ #241\nCall Trace:\n dump_stack+0xbe/0xf9\n print_address_description.constprop.0+0x1e/0x220\n kasan_report.cold+0x37/0x7f\n ext4_rename_dir_prepare+0x152/0x220\n ext4_rename+0xf44/0x1ad0\n ext4_rename2+0x11c/0x170\n vfs_rename+0xa84/0x1440\n do_renameat2+0x683/0x8f0\n __x64_sys_renameat+0x53/0x60\n do_syscall_64+0x33/0x40\n entry_SYSCALL_64_after_hwframe+0x44/0xa9\nRIP: 0033:0x7f45a6fc41c9\nRSP: 002b:00007ffc5a470218 EFLAGS: 00000246 ORIG_RAX: 0000000000000108\nRAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007f45a6fc41c9\nRDX: 0000000000000005 RSI: 0000000020000180 RDI: 0000000000000005\nRBP: 00007ffc5a470240 R08: 00007ffc5a470160 R09: 0000000020000080\nR10: 00000000200001c0 R11: 0000000000000246 R12: 0000000000400bb0\nR13: 00007ffc5a470320 R14: 0000000000000000 R15: 0000000000000000\n\nThe buggy address belongs to the page:\npage:00000000440015ce refcount:0 mapcount:0 mapping:0000000000000000 index:0x1 pfn:0x10beee\nflags: 0x200000000000000()\nraw: 0200000000000000 ffffea00043ff4c8 ffffea0004325608 0000000000000000\nraw: 0000000000000001 0000000000000000 00000000ffffffff 0000000000000000\npage dumped because: kasan: bad access detected\n\nMemory state around the buggy address:\n ffff88810beee580: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff\n ffff88810beee600: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff\n>ffff88810beee680: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff\n ^\n ffff88810beee700: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff\n ffff88810beee780: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff\n==================================================================\nDisabling lock debugging due to kernel taint\next4_rename_dir_prepare: [2] parent_de->inode=3537895424\next4_rename_dir_prepare: [3] dir=0xffff888124170140\next4_rename_dir_prepare: [4] ino=2\next4_rename_dir_prepare: ent->dir->i_ino=2 parent=-757071872\n\nReason is first directory entry which 'rec_len' is 34478, then will get illegal\nparent entry. Now, we do not check directory entry after read directory block\nin 'ext4_get_first_dir_block'.\nTo solve this issue, check directory entry in 'ext4_get_first_dir_block'.\n\n[ Trigger an ext4_error() instead of just warning if the directory is\n missing a '.' or '..' entry. Also make sure we return an error code\n if the file system is corrupted. -TYT ]",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49349"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/0be698ecbe4471fcad80e81ec6a05001421041b3"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/0ff38b99fa075ddd246487a28cb9af049f4ceef1"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/10801095224de0d0ab06ae60698680c1f883a3ae"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/1a3a15bf6f9963d755270cbdb282863b84839195"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/364380c00912bed9b5d99eb485018360b0ecf64f"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/4a2bea60cf7ff957b3eda0b17750d483876a02fa"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/97f802a652a749422dede32071d29a53cf4bd034"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/dd887f83ea54aea5b780a84527e23ab95f777fed"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/eaecf7ebfd5dd09038a80b14be46b844f54cfc5c"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-26T07:01:11Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-r26p-qcvf-g5c5/GHSA-r26p-qcvf-g5c5.json b/advisories/unreviewed/2025/02/GHSA-r26p-qcvf-g5c5/GHSA-r26p-qcvf-g5c5.json
new file mode 100644
index 00000000000..f47cf7ea006
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-r26p-qcvf-g5c5/GHSA-r26p-qcvf-g5c5.json
@@ -0,0 +1,56 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-r26p-qcvf-g5c5",
+ "modified": "2025-02-27T21:32:13Z",
+ "published": "2025-02-27T21:32:13Z",
+ "aliases": [
+ "CVE-2022-49412"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbfq: Avoid merging queues with different parents\n\nIt can happen that the parent of a bfqq changes between the moment we\ndecide two queues are worth to merge (and set bic->stable_merge_bfqq)\nand the moment bfq_setup_merge() is called. This can happen e.g. because\nthe process submitted IO for a different cgroup and thus bfqq got\nreparented. It can even happen that the bfqq we are merging with has\nparent cgroup that is already offline and going to be destroyed in which\ncase the merge can lead to use-after-free issues such as:\n\nBUG: KASAN: use-after-free in __bfq_deactivate_entity+0x9cb/0xa50\nRead of size 8 at addr ffff88800693c0c0 by task runc:[2:INIT]/10544\n\nCPU: 0 PID: 10544 Comm: runc:[2:INIT] Tainted: G E 5.15.2-0.g5fb85fd-default #1 openSUSE Tumbleweed (unreleased) f1f3b891c72369aebecd2e43e4641a6358867c70\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.14.0-0-g155821a-rebuilt.opensuse.org 04/01/2014\nCall Trace:\n \n dump_stack_lvl+0x46/0x5a\n print_address_description.constprop.0+0x1f/0x140\n ? __bfq_deactivate_entity+0x9cb/0xa50\n kasan_report.cold+0x7f/0x11b\n ? __bfq_deactivate_entity+0x9cb/0xa50\n __bfq_deactivate_entity+0x9cb/0xa50\n ? update_curr+0x32f/0x5d0\n bfq_deactivate_entity+0xa0/0x1d0\n bfq_del_bfqq_busy+0x28a/0x420\n ? resched_curr+0x116/0x1d0\n ? bfq_requeue_bfqq+0x70/0x70\n ? check_preempt_wakeup+0x52b/0xbc0\n __bfq_bfqq_expire+0x1a2/0x270\n bfq_bfqq_expire+0xd16/0x2160\n ? try_to_wake_up+0x4ee/0x1260\n ? bfq_end_wr_async_queues+0xe0/0xe0\n ? _raw_write_unlock_bh+0x60/0x60\n ? _raw_spin_lock_irq+0x81/0xe0\n bfq_idle_slice_timer+0x109/0x280\n ? bfq_dispatch_request+0x4870/0x4870\n __hrtimer_run_queues+0x37d/0x700\n ? enqueue_hrtimer+0x1b0/0x1b0\n ? kvm_clock_get_cycles+0xd/0x10\n ? ktime_get_update_offsets_now+0x6f/0x280\n hrtimer_interrupt+0x2c8/0x740\n\nFix the problem by checking that the parent of the two bfqqs we are\nmerging in bfq_setup_merge() is the same.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49412"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/5ee21edaed09e6b25f2c007b3f326752bc89bacf"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/7d172b9dc913e161d8ff88770eea01701ff553de"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/8abc8763b11c35e03cc91d59fd0cd28d39f88ca9"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/97be7d13fbd4001eeab49b1be6399f23a8c66160"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/a16c65cca7d2c7ff965fdd3adc8df2156529caf1"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/c1cee4ab36acef271be9101590756ed0c0c374d9"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-26T07:01:17Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-r426-g4w9-x3q5/GHSA-r426-g4w9-x3q5.json b/advisories/unreviewed/2025/02/GHSA-r426-g4w9-x3q5/GHSA-r426-g4w9-x3q5.json
new file mode 100644
index 00000000000..ae7ec954185
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-r426-g4w9-x3q5/GHSA-r426-g4w9-x3q5.json
@@ -0,0 +1,48 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-r426-g4w9-x3q5",
+ "modified": "2025-02-27T21:32:13Z",
+ "published": "2025-02-27T21:32:13Z",
+ "aliases": [
+ "CVE-2022-49129"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmt76: mt7921: fix crash when startup fails.\n\nIf the nic fails to start, it is possible that the\nreset_work has already been scheduled. Ensure the\nwork item is canceled so we do not have use-after-free\ncrash in case cleanup is called before the work item\nis executed.\n\nThis fixes crash on my x86_64 apu2 when mt7921k radio\nfails to work. Radio still fails, but OS does not\ncrash.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49129"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/38fbe806645090c07aa97171f20fc62c3d7d3a98"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/827e7799c61b978fbc2cc9dac66cb62401b2b3f0"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/ac1260b661c2ef0d0a56680cdb5672b931b7be8f"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/c1a5e6002ec441a3b9fb4d048b4b49ae93409a46"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-26T07:00:50Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-r8xf-h4x7-4grp/GHSA-r8xf-h4x7-4grp.json b/advisories/unreviewed/2025/02/GHSA-r8xf-h4x7-4grp/GHSA-r8xf-h4x7-4grp.json
new file mode 100644
index 00000000000..69761675105
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-r8xf-h4x7-4grp/GHSA-r8xf-h4x7-4grp.json
@@ -0,0 +1,33 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-r8xf-h4x7-4grp",
+ "modified": "2025-02-27T21:32:18Z",
+ "published": "2025-02-27T21:32:18Z",
+ "aliases": [
+ "CVE-2024-41340"
+ ],
+ "details": "An issue in Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vigor 2862/2926 prior to v3.9.9.4, Vigor 2133/2762/2832 prior to v3.9.8, Vigor 2135/2765/2766 prior to v4.4.5.1, Vigor 2865/2866/2927 prior to v4.4.5.3, Vigor 2962/3910 prior to v4.3.2.7, Vigor 3912 prior to v4.3.5.2, and Vigor 2925 up to v3.9.6 allows attackers to upload crafted APP Enforcement modules, leading to arbitrary code execution.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41340"
+ },
+ {
+ "type": "WEB",
+ "url": "https://medium.com/faraday/advisory-multiple-vulnerabilities-affecting-draytek-routers-78a6cb8b3946"
+ },
+ {
+ "type": "WEB",
+ "url": "http://draytek.com"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-27T21:15:36Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-rjjw-g6hw-7pc9/GHSA-rjjw-g6hw-7pc9.json b/advisories/unreviewed/2025/02/GHSA-rjjw-g6hw-7pc9/GHSA-rjjw-g6hw-7pc9.json
index 79b72db54b8..e908ef5374d 100644
--- a/advisories/unreviewed/2025/02/GHSA-rjjw-g6hw-7pc9/GHSA-rjjw-g6hw-7pc9.json
+++ b/advisories/unreviewed/2025/02/GHSA-rjjw-g6hw-7pc9/GHSA-rjjw-g6hw-7pc9.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rjjw-g6hw-7pc9",
- "modified": "2025-02-11T18:31:42Z",
+ "modified": "2025-02-27T21:32:02Z",
"published": "2025-02-11T18:31:41Z",
"aliases": [
"CVE-2025-24416"
diff --git a/advisories/unreviewed/2025/02/GHSA-rp2m-6293-6r8v/GHSA-rp2m-6293-6r8v.json b/advisories/unreviewed/2025/02/GHSA-rp2m-6293-6r8v/GHSA-rp2m-6293-6r8v.json
new file mode 100644
index 00000000000..00a90a8417e
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-rp2m-6293-6r8v/GHSA-rp2m-6293-6r8v.json
@@ -0,0 +1,37 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-rp2m-6293-6r8v",
+ "modified": "2025-02-27T21:32:17Z",
+ "published": "2025-02-27T21:32:17Z",
+ "aliases": [
+ "CVE-2025-21816"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nhrtimers: Force migrate away hrtimers queued after CPUHP_AP_HRTIMERS_DYING\n\nhrtimers are migrated away from the dying CPU to any online target at\nthe CPUHP_AP_HRTIMERS_DYING stage in order not to delay bandwidth timers\nhandling tasks involved in the CPU hotplug forward progress.\n\nHowever wakeups can still be performed by the outgoing CPU after\nCPUHP_AP_HRTIMERS_DYING. Those can result again in bandwidth timers being\narmed. Depending on several considerations (crystal ball power management\nbased election, earliest timer already enqueued, timer migration enabled or\nnot), the target may eventually be the current CPU even if offline. If that\nhappens, the timer is eventually ignored.\n\nThe most notable example is RCU which had to deal with each and every of\nthose wake-ups by deferring them to an online CPU, along with related\nworkarounds:\n\n_ e787644caf76 (rcu: Defer RCU kthreads wakeup when CPU is dying)\n_ 9139f93209d1 (rcu/nocb: Fix RT throttling hrtimer armed from offline CPU)\n_ f7345ccc62a4 (rcu/nocb: Fix rcuog wake-up from offline softirq)\n\nThe problem isn't confined to RCU though as the stop machine kthread\n(which runs CPUHP_AP_HRTIMERS_DYING) reports its completion at the end\nof its work through cpu_stop_signal_done() and performs a wake up that\neventually arms the deadline server timer:\n\n WARNING: CPU: 94 PID: 588 at kernel/time/hrtimer.c:1086 hrtimer_start_range_ns+0x289/0x2d0\n CPU: 94 UID: 0 PID: 588 Comm: migration/94 Not tainted\n Stopper: multi_cpu_stop+0x0/0x120 <- stop_machine_cpuslocked+0x66/0xc0\n RIP: 0010:hrtimer_start_range_ns+0x289/0x2d0\n Call Trace:\n \n start_dl_timer\n enqueue_dl_entity\n dl_server_start\n enqueue_task_fair\n enqueue_task\n ttwu_do_activate\n try_to_wake_up\n complete\n cpu_stopper_thread\n\nInstead of providing yet another bandaid to work around the situation, fix\nit in the hrtimers infrastructure instead: always migrate away a timer to\nan online target whenever it is enqueued from an offline CPU.\n\nThis will also allow to revert all the above RCU disgraceful hacks.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21816"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/2aecec58e9040ce3d2694707889f9914a2374955"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/53dac345395c0d2493cbc2f4c85fe38aef5b63f5"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/e456a88bddae4030ba962447bb84be6669f2a0c1"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-27T20:16:04Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-rpw2-9h57-v827/GHSA-rpw2-9h57-v827.json b/advisories/unreviewed/2025/02/GHSA-rpw2-9h57-v827/GHSA-rpw2-9h57-v827.json
new file mode 100644
index 00000000000..489ccd3dbc9
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-rpw2-9h57-v827/GHSA-rpw2-9h57-v827.json
@@ -0,0 +1,44 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-rpw2-9h57-v827",
+ "modified": "2025-02-27T21:32:15Z",
+ "published": "2025-02-27T21:32:15Z",
+ "aliases": [
+ "CVE-2022-49730"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: lpfc: Resolve NULL ptr dereference after an ELS LOGO is aborted\n\nA use-after-free crash can occur after an ELS LOGO is aborted.\n\nSpecifically, a nodelist structure is freed and then\nndlp->vport->cfg_log_verbose is dereferenced in lpfc_nlp_get() when the\ndiscovery state machine is mistakenly called a second time with\nNLP_EVT_DEVICE_RM argument.\n\nRework lpfc_cmpl_els_logo() to prevent the duplicate calls to release a\nnodelist structure.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49730"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/5e83869e29448958f8ae2c6911f350318f75e4fc"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/b1b3440f437b75fb2a9b0cfe58df461e40eca474"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/eea34ce23dc3a595695856dc73bb132a9c5a2902"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-26T07:01:48Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-v93h-9m65-mhx5/GHSA-v93h-9m65-mhx5.json b/advisories/unreviewed/2025/02/GHSA-v93h-9m65-mhx5/GHSA-v93h-9m65-mhx5.json
new file mode 100644
index 00000000000..a31b1f30915
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-v93h-9m65-mhx5/GHSA-v93h-9m65-mhx5.json
@@ -0,0 +1,48 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-v93h-9m65-mhx5",
+ "modified": "2025-02-27T21:32:13Z",
+ "published": "2025-02-27T21:32:13Z",
+ "aliases": [
+ "CVE-2022-49328"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmt76: fix use-after-free by removing a non-RCU wcid pointer\n\nFixes an issue caught by KASAN about use-after-free in mt76_txq_schedule\nby protecting mtxq->wcid with rcu_lock between mt76_txq_schedule and\nsta_info_[alloc, free].\n\n[18853.876689] ==================================================================\n[18853.876751] BUG: KASAN: use-after-free in mt76_txq_schedule+0x204/0xaf8 [mt76]\n[18853.876773] Read of size 8 at addr ffffffaf989a2138 by task mt76-tx phy0/883\n[18853.876786]\n[18853.876810] CPU: 5 PID: 883 Comm: mt76-tx phy0 Not tainted 5.10.100-fix-510-56778d365941-kasan #5 0b01fbbcf41a530f52043508fec2e31a4215\n\n[18853.876840] Call trace:\n[18853.876861] dump_backtrace+0x0/0x3ec\n[18853.876878] show_stack+0x20/0x2c\n[18853.876899] dump_stack+0x11c/0x1ac\n[18853.876918] print_address_description+0x74/0x514\n[18853.876934] kasan_report+0x134/0x174\n[18853.876948] __asan_report_load8_noabort+0x44/0x50\n[18853.876976] mt76_txq_schedule+0x204/0xaf8 [mt76 074e03e4640e97fe7405ee1fab547b81c4fa45d2]\n[18853.877002] mt76_txq_schedule_all+0x2c/0x48 [mt76 074e03e4640e97fe7405ee1fab547b81c4fa45d2]\n[18853.877030] mt7921_tx_worker+0xa0/0x1cc [mt7921_common f0875ebac9d7b4754e1010549e7db50fbd90a047]\n[18853.877054] __mt76_worker_fn+0x190/0x22c [mt76 074e03e4640e97fe7405ee1fab547b81c4fa45d2]\n[18853.877071] kthread+0x2f8/0x3b8\n[18853.877087] ret_from_fork+0x10/0x30\n[18853.877098]\n[18853.877112] Allocated by task 941:\n[18853.877131] kasan_save_stack+0x38/0x68\n[18853.877147] __kasan_kmalloc+0xd4/0xfc\n[18853.877163] kasan_kmalloc+0x10/0x1c\n[18853.877177] __kmalloc+0x264/0x3c4\n[18853.877294] sta_info_alloc+0x460/0xf88 [mac80211]\n[18853.877410] ieee80211_prep_connection+0x204/0x1ee0 [mac80211]\n[18853.877523] ieee80211_mgd_auth+0x6c4/0xa4c [mac80211]\n[18853.877635] ieee80211_auth+0x20/0x2c [mac80211]\n[18853.877733] rdev_auth+0x7c/0x438 [cfg80211]\n[18853.877826] cfg80211_mlme_auth+0x26c/0x390 [cfg80211]\n[18853.877919] nl80211_authenticate+0x6d4/0x904 [cfg80211]\n[18853.877938] genl_rcv_msg+0x748/0x93c\n[18853.877954] netlink_rcv_skb+0x160/0x2a8\n[18853.877969] genl_rcv+0x3c/0x54\n[18853.877985] netlink_unicast_kernel+0x104/0x1ec\n[18853.877999] netlink_unicast+0x178/0x268\n[18853.878015] netlink_sendmsg+0x3cc/0x5f0\n[18853.878030] sock_sendmsg+0xb4/0xd8\n[18853.878043] ____sys_sendmsg+0x2f8/0x53c\n[18853.878058] ___sys_sendmsg+0xe8/0x150\n[18853.878071] __sys_sendmsg+0xc4/0x1f4\n[18853.878087] __arm64_compat_sys_sendmsg+0x88/0x9c\n[18853.878101] el0_svc_common+0x1b4/0x390\n[18853.878115] do_el0_svc_compat+0x8c/0xdc\n[18853.878131] el0_svc_compat+0x10/0x1c\n[18853.878146] el0_sync_compat_handler+0xa8/0xcc\n[18853.878161] el0_sync_compat+0x188/0x1c0\n[18853.878171]\n[18853.878183] Freed by task 10927:\n[18853.878200] kasan_save_stack+0x38/0x68\n[18853.878215] kasan_set_track+0x28/0x3c\n[18853.878228] kasan_set_free_info+0x24/0x48\n[18853.878244] __kasan_slab_free+0x11c/0x154\n[18853.878259] kasan_slab_free+0x14/0x24\n[18853.878273] slab_free_freelist_hook+0xac/0x1b0\n[18853.878287] kfree+0x104/0x390\n[18853.878402] sta_info_free+0x198/0x210 [mac80211]\n[18853.878515] __sta_info_destroy_part2+0x230/0x2d4 [mac80211]\n[18853.878628] __sta_info_flush+0x300/0x37c [mac80211]\n[18853.878740] ieee80211_set_disassoc+0x2cc/0xa7c [mac80211]\n[18853.878851] ieee80211_mgd_deauth+0x4a4/0x10a0 [mac80211]\n[18853.878962] ieee80211_deauth+0x20/0x2c [mac80211]\n[18853.879057] rdev_deauth+0x7c/0x438 [cfg80211]\n[18853.879150] cfg80211_mlme_deauth+0x274/0x414 [cfg80211]\n[18853.879243] cfg80211_mlme_down+0xe4/0x118 [cfg80211]\n[18853.879335] cfg80211_disconnect+0x218/0x2d8 [cfg80211]\n[18853.879427] __cfg80211_leave+0x17c/0x240 [cfg80211]\n[18853.879519] cfg80211_leave+0x3c/0x58 [cfg80211]\n[18853.879611] wiphy_suspend+0xdc/0x200 [cfg80211]\n[18853.879628] dpm_run_callback+0x58/0x408\n[18853.879642] __device_suspend+0x4cc/0x864\n[18853.879658] async_suspend+0x34/0xf4\n[18\n---truncated---",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49328"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/4448327b41738dbfcda680eb4935ff835568f468"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/51fb1278aa57ae0fc54adaa786e1965362bed4fb"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/d5f77f1dbb59feae81f88e44551e8e1d8a802d9a"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/e55bcdd0bf34a8b10d45ce80ebb3164c5292a17d"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-26T07:01:09Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-v9wv-g6fx-53c4/GHSA-v9wv-g6fx-53c4.json b/advisories/unreviewed/2025/02/GHSA-v9wv-g6fx-53c4/GHSA-v9wv-g6fx-53c4.json
new file mode 100644
index 00000000000..1a70812003a
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-v9wv-g6fx-53c4/GHSA-v9wv-g6fx-53c4.json
@@ -0,0 +1,44 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-v9wv-g6fx-53c4",
+ "modified": "2025-02-27T21:32:15Z",
+ "published": "2025-02-27T21:32:15Z",
+ "aliases": [
+ "CVE-2022-49711"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbus: fsl-mc-bus: fix KASAN use-after-free in fsl_mc_bus_remove()\n\nIn fsl_mc_bus_remove(), mc->root_mc_bus_dev->mc_io is passed to\nfsl_destroy_mc_io(). However, mc->root_mc_bus_dev is already freed in\nfsl_mc_device_remove(). Then reference to mc->root_mc_bus_dev->mc_io\ntriggers KASAN use-after-free. To avoid the use-after-free, keep the\nreference to mc->root_mc_bus_dev->mc_io in a local variable and pass to\nfsl_destroy_mc_io().\n\nThis patch needs rework to apply to kernels older than v5.15.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49711"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/161b68b0a728377aaa10a8e14c70e7734f3c9ff7"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/928ea98252ad75118950941683893cf904541da9"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/ccd1751092341ac120a961835211f9f2e3735963"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-26T07:01:46Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-vcgf-2jcf-5569/GHSA-vcgf-2jcf-5569.json b/advisories/unreviewed/2025/02/GHSA-vcgf-2jcf-5569/GHSA-vcgf-2jcf-5569.json
new file mode 100644
index 00000000000..04f86f046d3
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-vcgf-2jcf-5569/GHSA-vcgf-2jcf-5569.json
@@ -0,0 +1,48 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-vcgf-2jcf-5569",
+ "modified": "2025-02-27T21:32:15Z",
+ "published": "2025-02-27T21:32:15Z",
+ "aliases": [
+ "CVE-2022-49695"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nigb: fix a use-after-free issue in igb_clean_tx_ring\n\nFix the following use-after-free bug in igb_clean_tx_ring routine when\nthe NIC is running in XDP mode. The issue can be triggered redirecting\ntraffic into the igb NIC and then closing the device while the traffic\nis flowing.\n\n[ 73.322719] CPU: 1 PID: 487 Comm: xdp_redirect Not tainted 5.18.3-apu2 #9\n[ 73.330639] Hardware name: PC Engines APU2/APU2, BIOS 4.0.7 02/28/2017\n[ 73.337434] RIP: 0010:refcount_warn_saturate+0xa7/0xf0\n[ 73.362283] RSP: 0018:ffffc9000081f798 EFLAGS: 00010282\n[ 73.367761] RAX: 0000000000000000 RBX: ffffc90000420f80 RCX: 0000000000000000\n[ 73.375200] RDX: ffff88811ad22d00 RSI: ffff88811ad171e0 RDI: ffff88811ad171e0\n[ 73.382590] RBP: 0000000000000900 R08: ffffffff82298f28 R09: 0000000000000058\n[ 73.390008] R10: 0000000000000219 R11: ffffffff82280f40 R12: 0000000000000090\n[ 73.397356] R13: ffff888102343a40 R14: ffff88810359e0e4 R15: 0000000000000000\n[ 73.404806] FS: 00007ff38d31d740(0000) GS:ffff88811ad00000(0000) knlGS:0000000000000000\n[ 73.413129] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 73.419096] CR2: 000055cff35f13f8 CR3: 0000000106391000 CR4: 00000000000406e0\n[ 73.426565] Call Trace:\n[ 73.429087] \n[ 73.431314] igb_clean_tx_ring+0x43/0x140 [igb]\n[ 73.436002] igb_down+0x1d7/0x220 [igb]\n[ 73.439974] __igb_close+0x3c/0x120 [igb]\n[ 73.444118] igb_xdp+0x10c/0x150 [igb]\n[ 73.447983] ? igb_pci_sriov_configure+0x70/0x70 [igb]\n[ 73.453362] dev_xdp_install+0xda/0x110\n[ 73.457371] dev_xdp_attach+0x1da/0x550\n[ 73.461369] do_setlink+0xfd0/0x10f0\n[ 73.465166] ? __nla_validate_parse+0x89/0xc70\n[ 73.469714] rtnl_setlink+0x11a/0x1e0\n[ 73.473547] rtnetlink_rcv_msg+0x145/0x3d0\n[ 73.477709] ? rtnl_calcit.isra.0+0x130/0x130\n[ 73.482258] netlink_rcv_skb+0x8d/0x110\n[ 73.486229] netlink_unicast+0x230/0x340\n[ 73.490317] netlink_sendmsg+0x215/0x470\n[ 73.494395] __sys_sendto+0x179/0x190\n[ 73.498268] ? move_addr_to_user+0x37/0x70\n[ 73.502547] ? __sys_getsockname+0x84/0xe0\n[ 73.506853] ? netlink_setsockopt+0x1c1/0x4a0\n[ 73.511349] ? __sys_setsockopt+0xc8/0x1d0\n[ 73.515636] __x64_sys_sendto+0x20/0x30\n[ 73.519603] do_syscall_64+0x3b/0x80\n[ 73.523399] entry_SYSCALL_64_after_hwframe+0x44/0xae\n[ 73.528712] RIP: 0033:0x7ff38d41f20c\n[ 73.551866] RSP: 002b:00007fff3b945a68 EFLAGS: 00000246 ORIG_RAX: 000000000000002c\n[ 73.559640] RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007ff38d41f20c\n[ 73.567066] RDX: 0000000000000034 RSI: 00007fff3b945b30 RDI: 0000000000000003\n[ 73.574457] RBP: 0000000000000003 R08: 0000000000000000 R09: 0000000000000000\n[ 73.581852] R10: 0000000000000000 R11: 0000000000000246 R12: 00007fff3b945ab0\n[ 73.589179] R13: 0000000000000000 R14: 0000000000000003 R15: 00007fff3b945b30\n[ 73.596545] \n[ 73.598842] ---[ end trace 0000000000000000 ]---",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49695"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/2af944210dc23d43d8208dafac4df7be7e3c168b"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/3f6a57ee8544ec3982f8a3cbcbf4aea7d47eb9ec"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/68a0ed06dcd5d3ea732d011c0b83d66e4791f521"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/c12a2c9b1b460ed72e6b3c33aac1ef51b0329b66"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-26T07:01:44Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-vhw3-82w5-42p7/GHSA-vhw3-82w5-42p7.json b/advisories/unreviewed/2025/02/GHSA-vhw3-82w5-42p7/GHSA-vhw3-82w5-42p7.json
new file mode 100644
index 00000000000..f0cc7207780
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-vhw3-82w5-42p7/GHSA-vhw3-82w5-42p7.json
@@ -0,0 +1,60 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-vhw3-82w5-42p7",
+ "modified": "2025-02-27T21:32:11Z",
+ "published": "2025-02-27T21:32:11Z",
+ "aliases": [
+ "CVE-2022-49087"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nrxrpc: fix a race in rxrpc_exit_net()\n\nCurrent code can lead to the following race:\n\nCPU0 CPU1\n\nrxrpc_exit_net()\n rxrpc_peer_keepalive_worker()\n if (rxnet->live)\n\n rxnet->live = false;\n del_timer_sync(&rxnet->peer_keepalive_timer);\n\n timer_reduce(&rxnet->peer_keepalive_timer, jiffies + delay);\n\n cancel_work_sync(&rxnet->peer_keepalive_work);\n\nrxrpc_exit_net() exits while peer_keepalive_timer is still armed,\nleading to use-after-free.\n\nsyzbot report was:\n\nODEBUG: free active (active state 0) object type: timer_list hint: rxrpc_peer_keepalive_timeout+0x0/0xb0\nWARNING: CPU: 0 PID: 3660 at lib/debugobjects.c:505 debug_print_object+0x16e/0x250 lib/debugobjects.c:505\nModules linked in:\nCPU: 0 PID: 3660 Comm: kworker/u4:6 Not tainted 5.17.0-syzkaller-13993-g88e6c0207623 #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011\nWorkqueue: netns cleanup_net\nRIP: 0010:debug_print_object+0x16e/0x250 lib/debugobjects.c:505\nCode: ff df 48 89 fa 48 c1 ea 03 80 3c 02 00 0f 85 af 00 00 00 48 8b 14 dd 00 1c 26 8a 4c 89 ee 48 c7 c7 00 10 26 8a e8 b1 e7 28 05 <0f> 0b 83 05 15 eb c5 09 01 48 83 c4 18 5b 5d 41 5c 41 5d 41 5e c3\nRSP: 0018:ffffc9000353fb00 EFLAGS: 00010082\nRAX: 0000000000000000 RBX: 0000000000000003 RCX: 0000000000000000\nRDX: ffff888029196140 RSI: ffffffff815efad8 RDI: fffff520006a7f52\nRBP: 0000000000000001 R08: 0000000000000000 R09: 0000000000000000\nR10: ffffffff815ea4ae R11: 0000000000000000 R12: ffffffff89ce23e0\nR13: ffffffff8a2614e0 R14: ffffffff816628c0 R15: dffffc0000000000\nFS: 0000000000000000(0000) GS:ffff8880b9c00000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007fe1f2908924 CR3: 0000000043720000 CR4: 00000000003506f0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nCall Trace:\n \n __debug_check_no_obj_freed lib/debugobjects.c:992 [inline]\n debug_check_no_obj_freed+0x301/0x420 lib/debugobjects.c:1023\n kfree+0xd6/0x310 mm/slab.c:3809\n ops_free_list.part.0+0x119/0x370 net/core/net_namespace.c:176\n ops_free_list net/core/net_namespace.c:174 [inline]\n cleanup_net+0x591/0xb00 net/core/net_namespace.c:598\n process_one_work+0x996/0x1610 kernel/workqueue.c:2289\n worker_thread+0x665/0x1080 kernel/workqueue.c:2436\n kthread+0x2e9/0x3a0 kernel/kthread.c:376\n ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:298\n ",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49087"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/08ff0e74fab517dbc44e11b8bc683dd4ecc65950"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/1946014ca3b19be9e485e780e862c375c6f98bad"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/41024a40f6c793abbb916a857f18fb009f07464c"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/571d8e1d154ca18f08dcb72b69318d36e10010a0"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/7ee84d29f22de6f6c63fad6c54690517659862f1"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/864297ee30727ae6233f80296b7fc91442620b05"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/cd8aef1f30d1215648e4e6686cfb422004851429"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-26T07:00:46Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-vjv2-ppj4-v42p/GHSA-vjv2-ppj4-v42p.json b/advisories/unreviewed/2025/02/GHSA-vjv2-ppj4-v42p/GHSA-vjv2-ppj4-v42p.json
new file mode 100644
index 00000000000..727f9ba9214
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-vjv2-ppj4-v42p/GHSA-vjv2-ppj4-v42p.json
@@ -0,0 +1,48 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-vjv2-ppj4-v42p",
+ "modified": "2025-02-27T21:32:13Z",
+ "published": "2025-02-27T21:32:13Z",
+ "aliases": [
+ "CVE-2022-49223"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncxl/port: Hold port reference until decoder release\n\nKASAN + DEBUG_KOBJECT_RELEASE reports a potential use-after-free in\ncxl_decoder_release() where it goes to reference its parent, a cxl_port,\nto free its id back to port->decoder_ida.\n\n BUG: KASAN: use-after-free in to_cxl_port+0x18/0x90 [cxl_core]\n Read of size 8 at addr ffff888119270908 by task kworker/35:2/379\n\n CPU: 35 PID: 379 Comm: kworker/35:2 Tainted: G OE 5.17.0-rc2+ #198\n Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 0.0.0 02/06/2015\n Workqueue: events kobject_delayed_cleanup\n Call Trace:\n \n dump_stack_lvl+0x59/0x73\n print_address_description.constprop.0+0x1f/0x150\n ? to_cxl_port+0x18/0x90 [cxl_core]\n kasan_report.cold+0x83/0xdf\n ? to_cxl_port+0x18/0x90 [cxl_core]\n to_cxl_port+0x18/0x90 [cxl_core]\n cxl_decoder_release+0x2a/0x60 [cxl_core]\n device_release+0x5f/0x100\n kobject_cleanup+0x80/0x1c0\n\nThe device core only guarantees parent lifetime until all children are\nunregistered. If a child needs a parent to complete its ->release()\ncallback that child needs to hold a reference to extend the lifetime of\nthe parent.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49223"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/49f2dab77a5e1354f5da6ccdc9346a8212697be2"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/518bb96367123062b48b0a9842f2864249b565f6"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/74be98774dfbc5b8b795db726bd772e735d2edd4"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/b0022ca445d5fc4d0c89d15dcd0f855977b22c1d"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-26T07:00:59Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-wfxg-v3j4-7qmj/GHSA-wfxg-v3j4-7qmj.json b/advisories/unreviewed/2025/02/GHSA-wfxg-v3j4-7qmj/GHSA-wfxg-v3j4-7qmj.json
new file mode 100644
index 00000000000..17b3c3d4de7
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-wfxg-v3j4-7qmj/GHSA-wfxg-v3j4-7qmj.json
@@ -0,0 +1,41 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-wfxg-v3j4-7qmj",
+ "modified": "2025-02-27T21:32:17Z",
+ "published": "2025-02-27T21:32:17Z",
+ "aliases": [
+ "CVE-2025-22952"
+ ],
+ "details": "elestio memos v0.23.0 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of user-supplied URLs, which can be exploited to perform SSRF attacks.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22952"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/usememos/memos/issues/4413"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/usememos/memos/pull/4428"
+ },
+ {
+ "type": "WEB",
+ "url": "https://elest.io/open-source/memos"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/usememos/memos"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-27T20:16:04Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-wqgg-8638-f2vf/GHSA-wqgg-8638-f2vf.json b/advisories/unreviewed/2025/02/GHSA-wqgg-8638-f2vf/GHSA-wqgg-8638-f2vf.json
index 35680fb0e23..9f4baacf520 100644
--- a/advisories/unreviewed/2025/02/GHSA-wqgg-8638-f2vf/GHSA-wqgg-8638-f2vf.json
+++ b/advisories/unreviewed/2025/02/GHSA-wqgg-8638-f2vf/GHSA-wqgg-8638-f2vf.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wqgg-8638-f2vf",
- "modified": "2025-02-27T03:34:06Z",
+ "modified": "2025-02-27T21:32:15Z",
"published": "2025-02-27T03:34:06Z",
"aliases": [
"CVE-2025-21797"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: corsair-void: Add missing delayed work cancel for headset status\n\nThe cancel_delayed_work_sync() call was missed, causing a use-after-free\nin corsair_void_remove().",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-27T03:15:20Z"
diff --git a/advisories/unreviewed/2025/02/GHSA-x3qg-8v4m-cfv7/GHSA-x3qg-8v4m-cfv7.json b/advisories/unreviewed/2025/02/GHSA-x3qg-8v4m-cfv7/GHSA-x3qg-8v4m-cfv7.json
new file mode 100644
index 00000000000..6282b2cf7e3
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-x3qg-8v4m-cfv7/GHSA-x3qg-8v4m-cfv7.json
@@ -0,0 +1,60 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-x3qg-8v4m-cfv7",
+ "modified": "2025-02-27T21:32:15Z",
+ "published": "2025-02-27T21:32:14Z",
+ "aliases": [
+ "CVE-2022-49647"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncgroup: Use separate src/dst nodes when preloading css_sets for migration\n\nEach cset (css_set) is pinned by its tasks. When we're moving tasks around\nacross csets for a migration, we need to hold the source and destination\ncsets to ensure that they don't go away while we're moving tasks about. This\nis done by linking cset->mg_preload_node on either the\nmgctx->preloaded_src_csets or mgctx->preloaded_dst_csets list. Using the\nsame cset->mg_preload_node for both the src and dst lists was deemed okay as\na cset can't be both the source and destination at the same time.\n\nUnfortunately, this overloading becomes problematic when multiple tasks are\ninvolved in a migration and some of them are identity noop migrations while\nothers are actually moving across cgroups. For example, this can happen with\nthe following sequence on cgroup1:\n\n #1> mkdir -p /sys/fs/cgroup/misc/a/b\n #2> echo $$ > /sys/fs/cgroup/misc/a/cgroup.procs\n #3> RUN_A_COMMAND_WHICH_CREATES_MULTIPLE_THREADS &\n #4> PID=$!\n #5> echo $PID > /sys/fs/cgroup/misc/a/b/tasks\n #6> echo $PID > /sys/fs/cgroup/misc/a/cgroup.procs\n\nthe process including the group leader back into a. In this final migration,\nnon-leader threads would be doing identity migration while the group leader\nis doing an actual one.\n\nAfter #3, let's say the whole process was in cset A, and that after #4, the\nleader moves to cset B. Then, during #6, the following happens:\n\n 1. cgroup_migrate_add_src() is called on B for the leader.\n\n 2. cgroup_migrate_add_src() is called on A for the other threads.\n\n 3. cgroup_migrate_prepare_dst() is called. It scans the src list.\n\n 4. It notices that B wants to migrate to A, so it tries to A to the dst\n list but realizes that its ->mg_preload_node is already busy.\n\n 5. and then it notices A wants to migrate to A as it's an identity\n migration, it culls it by list_del_init()'ing its ->mg_preload_node and\n putting references accordingly.\n\n 6. The rest of migration takes place with B on the src list but nothing on\n the dst list.\n\nThis means that A isn't held while migration is in progress. If all tasks\nleave A before the migration finishes and the incoming task pins it, the\ncset will be destroyed leading to use-after-free.\n\nThis is caused by overloading cset->mg_preload_node for both src and dst\npreload lists. We wanted to exclude the cset from the src list but ended up\ninadvertently excluding it from the dst list too.\n\nThis patch fixes the issue by separating out cset->mg_preload_node into\n->mg_src_preload_node and ->mg_dst_preload_node, so that the src and dst\npreloadings don't interfere with each other.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49647"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/05f7658210d1d331e8dd4cb6e7bbbe3df5f5ac27"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/07fd5b6cdf3cc30bfde8fe0f644771688be04447"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/0e41774b564befa6d271e8d5086bf870d617a4e6"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/54aee4e5ce8c21555286a6333e46c1713880cf93"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/7657e3958535d101a24ab4400f9b8062b9107cc4"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/ad44e05f3e016bdcb1ad25af35ade5b5f41ccd68"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/cec2bbdcc14fbaa6b95ee15a7c423b05d97038be"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-26T07:01:39Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-x45r-q45r-hq9w/GHSA-x45r-q45r-hq9w.json b/advisories/unreviewed/2025/02/GHSA-x45r-q45r-hq9w/GHSA-x45r-q45r-hq9w.json
new file mode 100644
index 00000000000..daa863853f0
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-x45r-q45r-hq9w/GHSA-x45r-q45r-hq9w.json
@@ -0,0 +1,37 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-x45r-q45r-hq9w",
+ "modified": "2025-02-27T21:32:17Z",
+ "published": "2025-02-27T21:32:17Z",
+ "aliases": [
+ "CVE-2025-21824"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ngpu: host1x: Fix a use of uninitialized mutex\n\ncommit c8347f915e67 (\"gpu: host1x: Fix boot regression for Tegra\")\ncaused a use of uninitialized mutex leading to below warning when\nCONFIG_DEBUG_MUTEXES and CONFIG_DEBUG_LOCK_ALLOC are enabled.\n\n[ 41.662843] ------------[ cut here ]------------\n[ 41.663012] DEBUG_LOCKS_WARN_ON(lock->magic != lock)\n[ 41.663035] WARNING: CPU: 4 PID: 794 at kernel/locking/mutex.c:587 __mutex_lock+0x670/0x878\n[ 41.663458] Modules linked in: rtw88_8822c(+) bluetooth(+) rtw88_pci rtw88_core mac80211 aquantia libarc4 crc_itu_t cfg80211 tegra194_cpufreq dwmac_tegra(+) arm_dsu_pmu stmmac_platform stmmac pcs_xpcs rfkill at24 host1x(+) tegra_bpmp_thermal ramoops reed_solomon fuse loop nfnetlink xfs mmc_block rpmb_core ucsi_ccg ina3221 crct10dif_ce xhci_tegra ghash_ce lm90 sha2_ce sha256_arm64 sha1_ce sdhci_tegra pwm_fan sdhci_pltfm sdhci gpio_keys rtc_tegra cqhci mmc_core phy_tegra_xusb i2c_tegra tegra186_gpc_dma i2c_tegra_bpmp spi_tegra114 dm_mirror dm_region_hash dm_log dm_mod\n[ 41.665078] CPU: 4 UID: 0 PID: 794 Comm: (udev-worker) Not tainted 6.11.0-29.31_1538613708.el10.aarch64+debug #1\n[ 41.665838] Hardware name: NVIDIA NVIDIA Jetson AGX Orin Developer Kit/Jetson, BIOS 36.3.0-gcid-35594366 02/26/2024\n[ 41.672555] pstate: 60400009 (nZCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n[ 41.679636] pc : __mutex_lock+0x670/0x878\n[ 41.683834] lr : __mutex_lock+0x670/0x878\n[ 41.688035] sp : ffff800084b77090\n[ 41.691446] x29: ffff800084b77160 x28: ffffdd4bebf7b000 x27: ffffdd4be96b1000\n[ 41.698799] x26: 1fffe0002308361c x25: 1ffff0001096ee18 x24: 0000000000000000\n[ 41.706149] x23: 0000000000000000 x22: 0000000000000002 x21: ffffdd4be6e3c7a0\n[ 41.713500] x20: ffff800084b770f0 x19: ffff00011841b1e8 x18: 0000000000000000\n[ 41.720675] x17: 0000000000000000 x16: 0000000000000000 x15: 0720072007200720\n[ 41.728023] x14: 0000000000000000 x13: 0000000000000001 x12: ffff6001a96eaab3\n[ 41.735375] x11: 1fffe001a96eaab2 x10: ffff6001a96eaab2 x9 : ffffdd4be4838bbc\n[ 41.742723] x8 : 00009ffe5691554e x7 : ffff000d4b755593 x6 : 0000000000000001\n[ 41.749985] x5 : ffff000d4b755590 x4 : 1fffe0001d88f001 x3 : dfff800000000000\n[ 41.756988] x2 : 0000000000000000 x1 : 0000000000000000 x0 : ffff0000ec478000\n[ 41.764251] Call trace:\n[ 41.766695] __mutex_lock+0x670/0x878\n[ 41.770373] mutex_lock_nested+0x2c/0x40\n[ 41.774134] host1x_intr_start+0x54/0xf8 [host1x]\n[ 41.778863] host1x_runtime_resume+0x150/0x228 [host1x]\n[ 41.783935] pm_generic_runtime_resume+0x84/0xc8\n[ 41.788485] __rpm_callback+0xa0/0x478\n[ 41.792422] rpm_callback+0x15c/0x1a8\n[ 41.795922] rpm_resume+0x698/0xc08\n[ 41.799597] __pm_runtime_resume+0xa8/0x140\n[ 41.803621] host1x_probe+0x810/0xbc0 [host1x]\n[ 41.807909] platform_probe+0xcc/0x1a8\n[ 41.811845] really_probe+0x188/0x800\n[ 41.815347] __driver_probe_device+0x164/0x360\n[ 41.819810] driver_probe_device+0x64/0x1a8\n[ 41.823834] __driver_attach+0x180/0x490\n[ 41.827773] bus_for_each_dev+0x104/0x1a0\n[ 41.831797] driver_attach+0x44/0x68\n[ 41.835296] bus_add_driver+0x23c/0x4e8\n[ 41.839235] driver_register+0x15c/0x3a8\n[ 41.843170] __platform_register_drivers+0xa4/0x208\n[ 41.848159] tegra_host1x_init+0x4c/0xff8 [host1x]\n[ 41.853147] do_one_initcall+0xd4/0x380\n[ 41.856997] do_init_module+0x1dc/0x698\n[ 41.860758] load_module+0xc70/0x1300\n[ 41.864435] __do_sys_init_module+0x1a8/0x1d0\n[ 41.868721] __arm64_sys_init_module+0x74/0xb0\n[ 41.873183] invoke_syscall.constprop.0+0xdc/0x1e8\n[ 41.877997] do_el0_svc+0x154/0x1d0\n[ 41.881671] el0_svc+0x54/0x140\n[ 41.884820] el0t_64_sync_handler+0x120/0x130\n[ 41.889285] el0t_64_sync+0x1a4/0x1a8\n[ 41.892960] irq event stamp: 69737\n[ 41.896370] hardirqs last enabled at (69737): [] _raw_spin_unlock_irqrestore+0x44/0xe8\n[ 41.905739] hardirqs last disabled at (69736):\n---truncated---",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21824"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/02458fbfaa0170aabf8506f7d4ed054f02414251"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/127e91638ddcd02b80de92fec2240609a9f90426"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/396d8e5136b4476672bc15b83ba312486bb4bf76"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-27T20:16:04Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-xf4c-frc6-wrrh/GHSA-xf4c-frc6-wrrh.json b/advisories/unreviewed/2025/02/GHSA-xf4c-frc6-wrrh/GHSA-xf4c-frc6-wrrh.json
new file mode 100644
index 00000000000..60e7ec3dcbd
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-xf4c-frc6-wrrh/GHSA-xf4c-frc6-wrrh.json
@@ -0,0 +1,40 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-xf4c-frc6-wrrh",
+ "modified": "2025-02-27T21:32:14Z",
+ "published": "2025-02-27T21:32:14Z",
+ "aliases": [
+ "CVE-2022-49622"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: avoid skb access on nf_stolen\n\nWhen verdict is NF_STOLEN, the skb might have been freed.\n\nWhen tracing is enabled, this can result in a use-after-free:\n1. access to skb->nf_trace\n2. access to skb->mark\n3. computation of trace id\n4. dump of packet payload\n\nTo avoid 1, keep a cached copy of skb->nf_trace in the\ntrace state struct.\nRefresh this copy whenever verdict is != STOLEN.\n\nAvoid 2 by skipping skb->mark access if verdict is STOLEN.\n\n3 is avoided by precomputing the trace id.\n\nOnly dump the packet when verdict is not \"STOLEN\".",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49622"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/0016d5d46d7440729a3132f61a8da3bf7f84e2ba"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/e34b9ed96ce3b06c79bf884009b16961ca478f87"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-26T07:01:37Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-xjrx-58mf-555f/GHSA-xjrx-58mf-555f.json b/advisories/unreviewed/2025/02/GHSA-xjrx-58mf-555f/GHSA-xjrx-58mf-555f.json
new file mode 100644
index 00000000000..f24b6bcab8f
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-xjrx-58mf-555f/GHSA-xjrx-58mf-555f.json
@@ -0,0 +1,37 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-xjrx-58mf-555f",
+ "modified": "2025-02-27T21:32:17Z",
+ "published": "2025-02-27T21:32:16Z",
+ "aliases": [
+ "CVE-2025-21813"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntimers/migration: Fix off-by-one root mis-connection\n\nBefore attaching a new root to the old root, the children counter of the\nnew root is checked to verify that only the upcoming CPU's top group have\nbeen connected to it. However since the recently added commit b729cc1ec21a\n(\"timers/migration: Fix another race between hotplug and idle entry/exit\")\nthis check is not valid anymore because the old root is pre-accounted\nas a child to the new root. Therefore after connecting the upcoming\nCPU's top group to the new root, the children count to be expected must\nbe 2 and not 1 anymore.\n\nThis omission results in the old root to not be connected to the new\nroot. Then eventually the system may run with more than one top level,\nwhich defeats the purpose of a single idle migrator.\n\nAlso the old root is pre-accounted but not connected upon the new root\ncreation. But it can be connected to the new root later on. Therefore\nthe old root may be accounted twice to the new root. The propagation of\nsuch overcommit can end up creating a double final top-level root with a\ngroupmask incorrectly initialized. Although harmless given that the final\ntop level roots will never have a parent to walk up to, this oddity\nopportunistically reported the core issue:\n\n WARNING: CPU: 8 PID: 0 at kernel/time/timer_migration.c:543 tmigr_requires_handle_remote\n CPU: 8 UID: 0 PID: 0 Comm: swapper/8\n RIP: 0010:tmigr_requires_handle_remote\n Call Trace:\n \n ? tmigr_requires_handle_remote\n ? hrtimer_run_queues\n update_process_times\n tick_periodic\n tick_handle_periodic\n __sysvec_apic_timer_interrupt\n sysvec_apic_timer_interrupt\n \n\nFix the problem by taking the old root into account in the children count\nof the new root so the connection is not omitted.\n\nAlso warn when more than one top level group exists to better detect\nsimilar issues in the future.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21813"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/6f449d8fa1808a7f9ee644866bbc079285dbefdd"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/868c9037df626b3c245ee26a290a03ae1f9f58d3"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/c6dd70e5b465a2b77c7a7c3d868736d302e29aec"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-27T20:16:03Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-xp9j-268q-p7q6/GHSA-xp9j-268q-p7q6.json b/advisories/unreviewed/2025/02/GHSA-xp9j-268q-p7q6/GHSA-xp9j-268q-p7q6.json
new file mode 100644
index 00000000000..fcbb9b87159
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-xp9j-268q-p7q6/GHSA-xp9j-268q-p7q6.json
@@ -0,0 +1,44 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-xp9j-268q-p7q6",
+ "modified": "2025-02-27T21:32:14Z",
+ "published": "2025-02-27T21:32:14Z",
+ "aliases": [
+ "CVE-2022-49465"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nblk-throttle: Set BIO_THROTTLED when bio has been throttled\n\n1.In current process, all bio will set the BIO_THROTTLED flag\nafter __blk_throtl_bio().\n\n2.If bio needs to be throttled, it will start the timer and\nstop submit bio directly. Bio will submit in\nblk_throtl_dispatch_work_fn() when the timer expires.But in\nthe current process, if bio is throttled. The BIO_THROTTLED\nwill be set to bio after timer start. If the bio has been\ncompleted, it may cause use-after-free blow.\n\nBUG: KASAN: use-after-free in blk_throtl_bio+0x12f0/0x2c70\nRead of size 2 at addr ffff88801b8902d4 by task fio/26380\n\n dump_stack+0x9b/0xce\n print_address_description.constprop.6+0x3e/0x60\n kasan_report.cold.9+0x22/0x3a\n blk_throtl_bio+0x12f0/0x2c70\n submit_bio_checks+0x701/0x1550\n submit_bio_noacct+0x83/0xc80\n submit_bio+0xa7/0x330\n mpage_readahead+0x380/0x500\n read_pages+0x1c1/0xbf0\n page_cache_ra_unbounded+0x471/0x6f0\n do_page_cache_ra+0xda/0x110\n ondemand_readahead+0x442/0xae0\n page_cache_async_ra+0x210/0x300\n generic_file_buffered_read+0x4d9/0x2130\n generic_file_read_iter+0x315/0x490\n blkdev_read_iter+0x113/0x1b0\n aio_read+0x2ad/0x450\n io_submit_one+0xc8e/0x1d60\n __se_sys_io_submit+0x125/0x350\n do_syscall_64+0x2d/0x40\n entry_SYSCALL_64_after_hwframe+0x44/0xa9\n\nAllocated by task 26380:\n kasan_save_stack+0x19/0x40\n __kasan_kmalloc.constprop.2+0xc1/0xd0\n kmem_cache_alloc+0x146/0x440\n mempool_alloc+0x125/0x2f0\n bio_alloc_bioset+0x353/0x590\n mpage_alloc+0x3b/0x240\n do_mpage_readpage+0xddf/0x1ef0\n mpage_readahead+0x264/0x500\n read_pages+0x1c1/0xbf0\n page_cache_ra_unbounded+0x471/0x6f0\n do_page_cache_ra+0xda/0x110\n ondemand_readahead+0x442/0xae0\n page_cache_async_ra+0x210/0x300\n generic_file_buffered_read+0x4d9/0x2130\n generic_file_read_iter+0x315/0x490\n blkdev_read_iter+0x113/0x1b0\n aio_read+0x2ad/0x450\n io_submit_one+0xc8e/0x1d60\n __se_sys_io_submit+0x125/0x350\n do_syscall_64+0x2d/0x40\n entry_SYSCALL_64_after_hwframe+0x44/0xa9\n\nFreed by task 0:\n kasan_save_stack+0x19/0x40\n kasan_set_track+0x1c/0x30\n kasan_set_free_info+0x1b/0x30\n __kasan_slab_free+0x111/0x160\n kmem_cache_free+0x94/0x460\n mempool_free+0xd6/0x320\n bio_free+0xe0/0x130\n bio_put+0xab/0xe0\n bio_endio+0x3a6/0x5d0\n blk_update_request+0x590/0x1370\n scsi_end_request+0x7d/0x400\n scsi_io_completion+0x1aa/0xe50\n scsi_softirq_done+0x11b/0x240\n blk_mq_complete_request+0xd4/0x120\n scsi_mq_done+0xf0/0x200\n virtscsi_vq_done+0xbc/0x150\n vring_interrupt+0x179/0x390\n __handle_irq_event_percpu+0xf7/0x490\n handle_irq_event_percpu+0x7b/0x160\n handle_irq_event+0xcc/0x170\n handle_edge_irq+0x215/0xb20\n common_interrupt+0x60/0x120\n asm_common_interrupt+0x1e/0x40\n\nFix this by move BIO_THROTTLED set into the queue_lock.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49465"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/0cfc8a0fb07cde61915e4a77c4794c47de3114a4"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/5a011f889b4832aa80c2a872a5aade5c48d2756f"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/935fa666534d7b7185e8c6b0191cd06281be4290"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-26T07:01:22Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-xqq8-xc8f-f7c4/GHSA-xqq8-xc8f-f7c4.json b/advisories/unreviewed/2025/02/GHSA-xqq8-xc8f-f7c4/GHSA-xqq8-xc8f-f7c4.json
new file mode 100644
index 00000000000..25312b4aef7
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-xqq8-xc8f-f7c4/GHSA-xqq8-xc8f-f7c4.json
@@ -0,0 +1,40 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-xqq8-xc8f-f7c4",
+ "modified": "2025-02-27T21:32:13Z",
+ "published": "2025-02-27T21:32:13Z",
+ "aliases": [
+ "CVE-2022-49238"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nath11k: free peer for station when disconnect from AP for QCA6390/WCN6855\n\nCommit b4a0f54156ac (\"ath11k: move peer delete after vdev stop of station\nfor QCA6390 and WCN6855\") is to fix firmware crash by changing the WMI\ncommand sequence, but actually skip all the peer delete operation, then\nit lead commit 58595c9874c6 (\"ath11k: Fixing dangling pointer issue upon\npeer delete failure\") not take effect, and then happened a use-after-free\nwarning from KASAN. because the peer->sta is not set to NULL and then used\nlater.\n\nChange to only skip the WMI_PEER_DELETE_CMDID for QCA6390/WCN6855.\n\nlog of user-after-free:\n\n[ 534.888665] BUG: KASAN: use-after-free in ath11k_dp_rx_update_peer_stats+0x912/0xc10 [ath11k]\n[ 534.888696] Read of size 8 at addr ffff8881396bb1b8 by task rtcwake/2860\n\n[ 534.888705] CPU: 4 PID: 2860 Comm: rtcwake Kdump: loaded Tainted: G W 5.15.0-wt-ath+ #523\n[ 534.888712] Hardware name: Intel(R) Client Systems NUC8i7HVK/NUC8i7HVB, BIOS HNKBLi70.86A.0067.2021.0528.1339 05/28/2021\n[ 534.888716] Call Trace:\n[ 534.888720] \n[ 534.888726] dump_stack_lvl+0x57/0x7d\n[ 534.888736] print_address_description.constprop.0+0x1f/0x170\n[ 534.888745] ? ath11k_dp_rx_update_peer_stats+0x912/0xc10 [ath11k]\n[ 534.888771] kasan_report.cold+0x83/0xdf\n[ 534.888783] ? ath11k_dp_rx_update_peer_stats+0x912/0xc10 [ath11k]\n[ 534.888810] ath11k_dp_rx_update_peer_stats+0x912/0xc10 [ath11k]\n[ 534.888840] ath11k_dp_rx_process_mon_status+0x529/0xa70 [ath11k]\n[ 534.888874] ? ath11k_dp_rx_mon_status_bufs_replenish+0x3f0/0x3f0 [ath11k]\n[ 534.888897] ? check_prev_add+0x20f0/0x20f0\n[ 534.888922] ? __lock_acquire+0xb72/0x1870\n[ 534.888937] ? find_held_lock+0x33/0x110\n[ 534.888954] ath11k_dp_rx_process_mon_rings+0x297/0x520 [ath11k]\n[ 534.888981] ? rcu_read_unlock+0x40/0x40\n[ 534.888990] ? ath11k_dp_rx_pdev_alloc+0xd90/0xd90 [ath11k]\n[ 534.889026] ath11k_dp_service_mon_ring+0x67/0xe0 [ath11k]\n[ 534.889053] ? ath11k_dp_rx_process_mon_rings+0x520/0x520 [ath11k]\n[ 534.889075] call_timer_fn+0x167/0x4a0\n[ 534.889084] ? add_timer_on+0x3b0/0x3b0\n[ 534.889103] ? lockdep_hardirqs_on_prepare.part.0+0x18c/0x370\n[ 534.889117] __run_timers.part.0+0x539/0x8b0\n[ 534.889123] ? ath11k_dp_rx_process_mon_rings+0x520/0x520 [ath11k]\n[ 534.889157] ? call_timer_fn+0x4a0/0x4a0\n[ 534.889164] ? mark_lock_irq+0x1c30/0x1c30\n[ 534.889173] ? clockevents_program_event+0xdd/0x280\n[ 534.889189] ? mark_held_locks+0xa5/0xe0\n[ 534.889203] run_timer_softirq+0x97/0x180\n[ 534.889213] __do_softirq+0x276/0x86a\n[ 534.889230] __irq_exit_rcu+0x11c/0x180\n[ 534.889238] irq_exit_rcu+0x5/0x20\n[ 534.889244] sysvec_apic_timer_interrupt+0x8e/0xc0\n[ 534.889251] \n[ 534.889254] \n[ 534.889259] asm_sysvec_apic_timer_interrupt+0x12/0x20\n[ 534.889265] RIP: 0010:_raw_spin_unlock_irqrestore+0x38/0x70\n[ 534.889271] Code: 74 24 10 e8 ea c2 bf fd 48 89 ef e8 12 53 c0 fd 81 e3 00 02 00 00 75 25 9c 58 f6 c4 02 75 2d 48 85 db 74 01 fb bf 01 00 00 00 13 a7 b5 fd 65 8b 05 cc d9 9c 5e 85 c0 74 0a 5b 5d c3 e8 a0 ee\n[ 534.889276] RSP: 0018:ffffc90002e5f880 EFLAGS: 00000206\n[ 534.889284] RAX: 0000000000000006 RBX: 0000000000000200 RCX: ffffffff9f256f10\n[ 534.889289] RDX: 0000000000000000 RSI: ffffffffa1c6e420 RDI: 0000000000000001\n[ 534.889293] RBP: ffff8881095e6200 R08: 0000000000000001 R09: ffffffffa40d2b8f\n[ 534.889298] R10: fffffbfff481a571 R11: 0000000000000001 R12: ffff8881095e6e68\n[ 534.889302] R13: ffffc90002e5f908 R14: 0000000000000246 R15: 0000000000000000\n[ 534.889316] ? mark_lock+0xd0/0x14a0\n[ 534.889332] klist_next+0x1d4/0x450\n[ 534.889340] ? dpm_wait_for_subordinate+0x2d0/0x2d0\n[ 534.889350] device_for_each_child+0xa8/0x140\n[ 534.889360] ? device_remove_class_symlinks+0x1b0/0x1b0\n[ 534.889370] ? __lock_release+0x4bd/0x9f0\n[ 534.889378] ? dpm_suspend+0x26b/0x3f0\n[ 534.889390] dpm_wait_for_subordinate+\n---truncated---",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49238"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/212ad7cb7d7592669c067125949e0a8e31ce6a0b"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/400705c50bbf184794c885d1efad7fe9ccf1471a"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-26T07:01:00Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/02/GHSA-xwgx-8v72-4j5j/GHSA-xwgx-8v72-4j5j.json b/advisories/unreviewed/2025/02/GHSA-xwgx-8v72-4j5j/GHSA-xwgx-8v72-4j5j.json
index 68982bbb733..8e8f8cd6214 100644
--- a/advisories/unreviewed/2025/02/GHSA-xwgx-8v72-4j5j/GHSA-xwgx-8v72-4j5j.json
+++ b/advisories/unreviewed/2025/02/GHSA-xwgx-8v72-4j5j/GHSA-xwgx-8v72-4j5j.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xwgx-8v72-4j5j",
- "modified": "2025-02-11T18:31:42Z",
+ "modified": "2025-02-27T21:32:01Z",
"published": "2025-02-11T18:31:41Z",
"aliases": [
"CVE-2025-24413"
diff --git a/advisories/unreviewed/2025/02/GHSA-xxp9-gm8j-w4c9/GHSA-xxp9-gm8j-w4c9.json b/advisories/unreviewed/2025/02/GHSA-xxp9-gm8j-w4c9/GHSA-xxp9-gm8j-w4c9.json
new file mode 100644
index 00000000000..8448e7f33c3
--- /dev/null
+++ b/advisories/unreviewed/2025/02/GHSA-xxp9-gm8j-w4c9/GHSA-xxp9-gm8j-w4c9.json
@@ -0,0 +1,45 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-xxp9-gm8j-w4c9",
+ "modified": "2025-02-27T21:32:17Z",
+ "published": "2025-02-27T21:32:17Z",
+ "aliases": [
+ "CVE-2025-21814"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nptp: Ensure info->enable callback is always set\n\nThe ioctl and sysfs handlers unconditionally call the ->enable callback.\nNot all drivers implement that callback, leading to NULL dereferences.\nExample of affected drivers: ptp_s390.c, ptp_vclock.c and ptp_mock.c.\n\nInstead use a dummy callback if no better was specified by the driver.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21814"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/5d1041c76de656f9f8d5a192218039a9acf9bd00"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/755caf4ee1c615ee5717862e427124370f46b1f3"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/81846070cba17125a866e8023c01d3465b153339"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/8441aea46445252df5d2eed6deb6d5246fc24002"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/fd53aa40e65f518453115b6f56183b0c201db26b"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-02-27T20:16:03Z"
+ }
+}
\ No newline at end of file