From 3ac1b045c1c329d0ed1592f2da1f3f4ba9364d96 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 11 Apr 2025 15:34:38 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-2xm8-8q96-qxhc.json | 3 +- .../GHSA-6p47-w2hq-8j72.json | 2 +- .../GHSA-92fc-jgvr-56vr.json | 1 + .../GHSA-g9r7-hq6j-vv4r.json | 2 +- .../GHSA-5p7g-qx77-8f6h.json | 10 ++++- .../GHSA-g5vf-92m7-vh6w.json | 10 ++++- .../GHSA-v2hh-gf42-8pxh.json | 10 ++++- .../GHSA-5gx5-rcr5-mmg7.json | 2 +- .../GHSA-38f5-rx4x-f6j9.json | 8 +++- .../GHSA-h6cc-4vmm-cxpp.json | 6 ++- .../GHSA-vpfm-675m-rfm8.json | 8 +++- .../GHSA-4vrr-r4j5-6m68.json | 4 +- .../GHSA-5gvg-fggq-r6f6.json | 2 +- .../GHSA-938g-xvpf-6653.json | 2 +- .../GHSA-54v7-45g9-xcqh.json | 4 +- .../GHSA-cqm6-fcfw-pfm3.json | 4 +- .../GHSA-fjrj-vrrh-qjx6.json | 4 +- .../GHSA-h2c8-c64m-w4qp.json | 4 +- .../GHSA-36q8-mfw8-2m98.json | 4 +- .../GHSA-9g23-vp4v-xmvv.json | 2 +- .../GHSA-f3mv-cjr3-hr9j.json | 4 +- .../GHSA-qq52-2f2f-p65w.json | 2 +- .../GHSA-4hmh-pm5p-9j7j.json | 6 ++- .../GHSA-2j99-5q75-3f57.json | 18 +++++++- .../GHSA-8vh6-m67f-4h33.json | 15 +++++-- .../GHSA-5892-jw8m-4684.json | 45 +++++++++++++++++++ .../GHSA-5f2m-5gjf-8mqg.json | 15 +++++-- .../GHSA-5x97-hgxc-62pv.json | 33 ++++++++++++++ .../GHSA-64h7-7273-jw5g.json | 45 +++++++++++++++++++ .../GHSA-6g9c-7jcv-4g45.json | 15 +++++-- .../GHSA-73gg-qjfg-4g7x.json | 3 +- .../GHSA-7rrr-jvfx-w2gc.json | 40 +++++++++++++++++ .../GHSA-96jf-mvrm-934f.json | 3 +- .../GHSA-9v5v-qfv2-66qp.json | 45 +++++++++++++++++++ .../GHSA-c924-p67m-48hp.json | 15 +++++-- .../GHSA-cg4r-9g44-qvw4.json | 45 +++++++++++++++++++ .../GHSA-cmwf-4hcv-45rc.json | 29 ++++++++++++ .../GHSA-fc78-895f-8fh8.json | 29 ++++++++++++ .../GHSA-fgww-7769-w5pf.json | 36 +++++++++++++++ .../GHSA-h573-4qjm-8775.json | 40 +++++++++++++++++ .../GHSA-hf5w-7g55-wh36.json | 15 +++++-- .../GHSA-j8rw-3x8v-v327.json | 15 +++++-- .../GHSA-jq7g-h856-ccpg.json | 44 ++++++++++++++++++ .../GHSA-jxxv-c48x-753p.json | 15 +++++-- .../GHSA-m6p7-g6ff-wxw5.json | 33 ++++++++++++++ .../GHSA-p4qc-cp8p-44wh.json | 15 +++++-- .../GHSA-p79h-jcrm-6qrc.json | 15 +++++-- .../GHSA-pf4f-8wpm-5vh2.json | 15 +++++-- .../GHSA-pmvp-2f47-m6wx.json | 29 ++++++++++++ .../GHSA-qhr5-5m4q-73p8.json | 11 +++-- .../GHSA-rj34-pxf7-99v6.json | 29 ++++++++++++ .../GHSA-v2qv-44ch-jx7v.json | 15 +++++-- .../GHSA-v435-p7h6-v9pj.json | 29 ++++++++++++ .../GHSA-vcfm-2r3w-vjx5.json | 3 +- 54 files changed, 782 insertions(+), 76 deletions(-) create mode 100644 advisories/unreviewed/2025/04/GHSA-5892-jw8m-4684/GHSA-5892-jw8m-4684.json create mode 100644 advisories/unreviewed/2025/04/GHSA-5x97-hgxc-62pv/GHSA-5x97-hgxc-62pv.json create mode 100644 advisories/unreviewed/2025/04/GHSA-64h7-7273-jw5g/GHSA-64h7-7273-jw5g.json create mode 100644 advisories/unreviewed/2025/04/GHSA-7rrr-jvfx-w2gc/GHSA-7rrr-jvfx-w2gc.json create mode 100644 advisories/unreviewed/2025/04/GHSA-9v5v-qfv2-66qp/GHSA-9v5v-qfv2-66qp.json create mode 100644 advisories/unreviewed/2025/04/GHSA-cg4r-9g44-qvw4/GHSA-cg4r-9g44-qvw4.json create mode 100644 advisories/unreviewed/2025/04/GHSA-cmwf-4hcv-45rc/GHSA-cmwf-4hcv-45rc.json create mode 100644 advisories/unreviewed/2025/04/GHSA-fc78-895f-8fh8/GHSA-fc78-895f-8fh8.json create mode 100644 advisories/unreviewed/2025/04/GHSA-fgww-7769-w5pf/GHSA-fgww-7769-w5pf.json create mode 100644 advisories/unreviewed/2025/04/GHSA-h573-4qjm-8775/GHSA-h573-4qjm-8775.json create mode 100644 advisories/unreviewed/2025/04/GHSA-jq7g-h856-ccpg/GHSA-jq7g-h856-ccpg.json create mode 100644 advisories/unreviewed/2025/04/GHSA-m6p7-g6ff-wxw5/GHSA-m6p7-g6ff-wxw5.json create mode 100644 advisories/unreviewed/2025/04/GHSA-pmvp-2f47-m6wx/GHSA-pmvp-2f47-m6wx.json create mode 100644 advisories/unreviewed/2025/04/GHSA-rj34-pxf7-99v6/GHSA-rj34-pxf7-99v6.json create mode 100644 advisories/unreviewed/2025/04/GHSA-v435-p7h6-v9pj/GHSA-v435-p7h6-v9pj.json diff --git a/advisories/unreviewed/2022/09/GHSA-2xm8-8q96-qxhc/GHSA-2xm8-8q96-qxhc.json b/advisories/unreviewed/2022/09/GHSA-2xm8-8q96-qxhc/GHSA-2xm8-8q96-qxhc.json index 5928356f17b..d7ab97f3fdd 100644 --- a/advisories/unreviewed/2022/09/GHSA-2xm8-8q96-qxhc/GHSA-2xm8-8q96-qxhc.json +++ b/advisories/unreviewed/2022/09/GHSA-2xm8-8q96-qxhc/GHSA-2xm8-8q96-qxhc.json @@ -34,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/01/GHSA-6p47-w2hq-8j72/GHSA-6p47-w2hq-8j72.json b/advisories/unreviewed/2023/01/GHSA-6p47-w2hq-8j72/GHSA-6p47-w2hq-8j72.json index eaaf6ab2857..5f0ee0c7c2d 100644 --- a/advisories/unreviewed/2023/01/GHSA-6p47-w2hq-8j72/GHSA-6p47-w2hq-8j72.json +++ b/advisories/unreviewed/2023/01/GHSA-6p47-w2hq-8j72/GHSA-6p47-w2hq-8j72.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6p47-w2hq-8j72", - "modified": "2023-01-09T15:30:23Z", + "modified": "2025-04-11T15:32:12Z", "published": "2023-01-01T09:30:20Z", "aliases": [ "CVE-2022-40711" diff --git a/advisories/unreviewed/2023/01/GHSA-92fc-jgvr-56vr/GHSA-92fc-jgvr-56vr.json b/advisories/unreviewed/2023/01/GHSA-92fc-jgvr-56vr/GHSA-92fc-jgvr-56vr.json index 34d1d6b23f5..02570a149db 100644 --- a/advisories/unreviewed/2023/01/GHSA-92fc-jgvr-56vr/GHSA-92fc-jgvr-56vr.json +++ b/advisories/unreviewed/2023/01/GHSA-92fc-jgvr-56vr/GHSA-92fc-jgvr-56vr.json @@ -34,6 +34,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-668", "CWE-94" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2023/01/GHSA-g9r7-hq6j-vv4r/GHSA-g9r7-hq6j-vv4r.json b/advisories/unreviewed/2023/01/GHSA-g9r7-hq6j-vv4r/GHSA-g9r7-hq6j-vv4r.json index 460fbe760d9..ae7fd130c86 100644 --- a/advisories/unreviewed/2023/01/GHSA-g9r7-hq6j-vv4r/GHSA-g9r7-hq6j-vv4r.json +++ b/advisories/unreviewed/2023/01/GHSA-g9r7-hq6j-vv4r/GHSA-g9r7-hq6j-vv4r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g9r7-hq6j-vv4r", - "modified": "2023-01-09T18:30:33Z", + "modified": "2025-04-11T15:32:12Z", "published": "2023-01-01T09:30:20Z", "aliases": [ "CVE-2022-45027" diff --git a/advisories/unreviewed/2023/10/GHSA-5p7g-qx77-8f6h/GHSA-5p7g-qx77-8f6h.json b/advisories/unreviewed/2023/10/GHSA-5p7g-qx77-8f6h/GHSA-5p7g-qx77-8f6h.json index 57f88e32005..81bfdf81533 100644 --- a/advisories/unreviewed/2023/10/GHSA-5p7g-qx77-8f6h/GHSA-5p7g-qx77-8f6h.json +++ b/advisories/unreviewed/2023/10/GHSA-5p7g-qx77-8f6h/GHSA-5p7g-qx77-8f6h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5p7g-qx77-8f6h", - "modified": "2023-11-02T15:30:24Z", + "modified": "2025-04-11T15:32:14Z", "published": "2023-10-25T21:30:32Z", "aliases": [ "CVE-2023-41077" @@ -19,6 +19,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-41077" }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/109050" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/120950" + }, { "type": "WEB", "url": "https://support.apple.com/en-us/HT213985" diff --git a/advisories/unreviewed/2023/10/GHSA-g5vf-92m7-vh6w/GHSA-g5vf-92m7-vh6w.json b/advisories/unreviewed/2023/10/GHSA-g5vf-92m7-vh6w/GHSA-g5vf-92m7-vh6w.json index 7c4f05f3022..0fa9cf193fd 100644 --- a/advisories/unreviewed/2023/10/GHSA-g5vf-92m7-vh6w/GHSA-g5vf-92m7-vh6w.json +++ b/advisories/unreviewed/2023/10/GHSA-g5vf-92m7-vh6w/GHSA-g5vf-92m7-vh6w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g5vf-92m7-vh6w", - "modified": "2023-11-02T15:30:23Z", + "modified": "2025-04-11T15:32:14Z", "published": "2023-10-25T21:30:32Z", "aliases": [ "CVE-2023-40425" @@ -19,6 +19,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40425" }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/109055" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/120950" + }, { "type": "WEB", "url": "https://support.apple.com/en-us/HT213983" diff --git a/advisories/unreviewed/2024/01/GHSA-v2hh-gf42-8pxh/GHSA-v2hh-gf42-8pxh.json b/advisories/unreviewed/2024/01/GHSA-v2hh-gf42-8pxh/GHSA-v2hh-gf42-8pxh.json index 0d06f97ebfb..a68e07b28df 100644 --- a/advisories/unreviewed/2024/01/GHSA-v2hh-gf42-8pxh/GHSA-v2hh-gf42-8pxh.json +++ b/advisories/unreviewed/2024/01/GHSA-v2hh-gf42-8pxh/GHSA-v2hh-gf42-8pxh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v2hh-gf42-8pxh", - "modified": "2024-01-17T18:31:36Z", + "modified": "2025-04-11T15:32:15Z", "published": "2024-01-11T00:30:25Z", "aliases": [ "CVE-2023-40393" @@ -19,6 +19,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40393" }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/120949" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/120950" + }, { "type": "WEB", "url": "https://support.apple.com/en-us/HT213940" diff --git a/advisories/unreviewed/2024/03/GHSA-5gx5-rcr5-mmg7/GHSA-5gx5-rcr5-mmg7.json b/advisories/unreviewed/2024/03/GHSA-5gx5-rcr5-mmg7/GHSA-5gx5-rcr5-mmg7.json index 4d3f4cd6775..2d71c7196aa 100644 --- a/advisories/unreviewed/2024/03/GHSA-5gx5-rcr5-mmg7/GHSA-5gx5-rcr5-mmg7.json +++ b/advisories/unreviewed/2024/03/GHSA-5gx5-rcr5-mmg7/GHSA-5gx5-rcr5-mmg7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5gx5-rcr5-mmg7", - "modified": "2024-03-05T12:30:32Z", + "modified": "2025-04-11T15:32:15Z", "published": "2024-03-05T12:30:32Z", "aliases": [ "CVE-2023-45595" diff --git a/advisories/unreviewed/2024/04/GHSA-38f5-rx4x-f6j9/GHSA-38f5-rx4x-f6j9.json b/advisories/unreviewed/2024/04/GHSA-38f5-rx4x-f6j9/GHSA-38f5-rx4x-f6j9.json index 6a0c269314a..c290f949085 100644 --- a/advisories/unreviewed/2024/04/GHSA-38f5-rx4x-f6j9/GHSA-38f5-rx4x-f6j9.json +++ b/advisories/unreviewed/2024/04/GHSA-38f5-rx4x-f6j9/GHSA-38f5-rx4x-f6j9.json @@ -1,16 +1,20 @@ { "schema_version": "1.4.0", "id": "GHSA-38f5-rx4x-f6j9", - "modified": "2024-05-16T18:30:31Z", + "modified": "2025-04-11T15:32:17Z", "published": "2024-04-16T21:31:28Z", "aliases": [ "CVE-2024-30378" ], - "details": "A Use After Free vulnerability in command processing of Juniper Networks Junos OS on MX Series allows a local, authenticated attacker to cause the broadband edge service manager daemon (bbe-smgd) to crash upon execution of specific CLI commands, creating a Denial of Service (DoS) condition.  The process crashes and restarts automatically.\n\nWhen specific CLI commands are executed, the bbe-smgd daemon attempts to write into an area of memory (mgd socket) that was already closed, causing the process to crash.  This process manages and controls the configuration of broadband subscriber sessions and services.  While the process is unavailable, additional subscribers will not be able to connect to the device, causing a temporary Denial of Service condition.\n\nThis issue only occurs if Graceful Routing Engine Switchover (GRES) and Subscriber Management are enabled.\nThis issue affects Junos OS:\n\n\n * All versions before 20.4R3-S5, \n * from 21.1 before 21.1R3-S4, \n * from 21.2 before 21.2R3-S3, \n * from 21.3 before 21.3R3-S5, \n * from 21.4 before 21.4R3-S5, \n * from 22.1 before 22.1R3, \n * from 22.2 before 22.2R3, \n * from 22.3 before 22.3R2;\n\n\n\n\n\n\n\n\n\n", + "details": "A Use After Free vulnerability in command processing of Juniper Networks Junos OS on MX Series allows a local, authenticated attacker to cause the broadband edge service manager daemon (bbe-smgd) to crash upon execution of specific CLI commands, creating a Denial of Service (DoS) condition.  The process crashes and restarts automatically.\n\nWhen specific CLI commands are executed, the bbe-smgd daemon attempts to write into an area of memory (mgd socket) that was already closed, causing the process to crash.  This process manages and controls the configuration of broadband subscriber sessions and services.  While the process is unavailable, additional subscribers will not be able to connect to the device, causing a temporary Denial of Service condition.\n\nThis issue only occurs if Graceful Routing Engine Switchover (GRES) and Subscriber Management are enabled.\nThis issue affects Junos OS:\n\n\n * All versions before 20.4R3-S5, \n * from 21.1 before 21.1R3-S4, \n * from 21.2 before 21.2R3-S3, \n * from 21.3 before 21.3R3-S5, \n * from 21.4 before 21.4R3-S5, \n * from 22.1 before 22.1R3, \n * from 22.2 before 22.2R3, \n * from 22.3 before 22.3R2;", "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/04/GHSA-h6cc-4vmm-cxpp/GHSA-h6cc-4vmm-cxpp.json b/advisories/unreviewed/2024/04/GHSA-h6cc-4vmm-cxpp/GHSA-h6cc-4vmm-cxpp.json index 54e1a036714..6bbef43f174 100644 --- a/advisories/unreviewed/2024/04/GHSA-h6cc-4vmm-cxpp/GHSA-h6cc-4vmm-cxpp.json +++ b/advisories/unreviewed/2024/04/GHSA-h6cc-4vmm-cxpp/GHSA-h6cc-4vmm-cxpp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h6cc-4vmm-cxpp", - "modified": "2024-04-09T21:31:59Z", + "modified": "2025-04-11T15:32:16Z", "published": "2024-04-09T21:31:59Z", "aliases": [ "CVE-2024-2336" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-vpfm-675m-rfm8/GHSA-vpfm-675m-rfm8.json b/advisories/unreviewed/2024/04/GHSA-vpfm-675m-rfm8/GHSA-vpfm-675m-rfm8.json index 3837c5b8035..6045c5e14a7 100644 --- a/advisories/unreviewed/2024/04/GHSA-vpfm-675m-rfm8/GHSA-vpfm-675m-rfm8.json +++ b/advisories/unreviewed/2024/04/GHSA-vpfm-675m-rfm8/GHSA-vpfm-675m-rfm8.json @@ -1,16 +1,20 @@ { "schema_version": "1.4.0", "id": "GHSA-vpfm-675m-rfm8", - "modified": "2024-05-16T21:31:57Z", + "modified": "2025-04-11T15:32:17Z", "published": "2024-04-12T18:33:26Z", "aliases": [ "CVE-2024-30391" ], - "details": "A Missing Authentication for Critical Function vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series with SPC3, and SRX Series allows an unauthenticated network-based attacker to cause limited impact to the integrity or availability of the device.\n\nIf a device is configured with IPsec authentication algorithm hmac-sha-384 or hmac-sha-512, tunnels are established normally but for traffic traversing the tunnel no authentication information is sent with the encrypted data on egress, and no authentication information is expected on ingress. So if the peer is an unaffected device transit traffic is going to fail in both directions. If the peer is an also affected device transit traffic works, but without authentication, and configuration and CLI operational commands indicate authentication is performed.\nThis issue affects Junos OS:\n\nAll versions before 20.4R3-S7,\n\n21.1 versions before 21.1R3, \n\n21.2 versions before 21.2R2-S1, 21.2R3, \n\n21.3 versions before 21.3R1-S2, 21.3R2.\n\n\n", + "details": "A Missing Authentication for Critical Function vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on MX Series with SPC3, and SRX Series allows an unauthenticated network-based attacker to cause limited impact to the integrity or availability of the device.\n\nIf a device is configured with IPsec authentication algorithm hmac-sha-384 or hmac-sha-512, tunnels are established normally but for traffic traversing the tunnel no authentication information is sent with the encrypted data on egress, and no authentication information is expected on ingress. So if the peer is an unaffected device transit traffic is going to fail in both directions. If the peer is an also affected device transit traffic works, but without authentication, and configuration and CLI operational commands indicate authentication is performed.\nThis issue affects Junos OS:\n\nAll versions before 20.4R3-S7,\n\n21.1 versions before 21.1R3, \n\n21.2 versions before 21.2R2-S1, 21.2R3, \n\n21.3 versions before 21.3R1-S2, 21.3R2.", "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/06/GHSA-4vrr-r4j5-6m68/GHSA-4vrr-r4j5-6m68.json b/advisories/unreviewed/2024/06/GHSA-4vrr-r4j5-6m68/GHSA-4vrr-r4j5-6m68.json index 76b9e1c4559..879af35678c 100644 --- a/advisories/unreviewed/2024/06/GHSA-4vrr-r4j5-6m68/GHSA-4vrr-r4j5-6m68.json +++ b/advisories/unreviewed/2024/06/GHSA-4vrr-r4j5-6m68/GHSA-4vrr-r4j5-6m68.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-434" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-5gvg-fggq-r6f6/GHSA-5gvg-fggq-r6f6.json b/advisories/unreviewed/2024/07/GHSA-5gvg-fggq-r6f6/GHSA-5gvg-fggq-r6f6.json index f8542231b37..513370977b6 100644 --- a/advisories/unreviewed/2024/07/GHSA-5gvg-fggq-r6f6/GHSA-5gvg-fggq-r6f6.json +++ b/advisories/unreviewed/2024/07/GHSA-5gvg-fggq-r6f6/GHSA-5gvg-fggq-r6f6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5gvg-fggq-r6f6", - "modified": "2024-07-11T18:31:13Z", + "modified": "2025-04-11T15:32:22Z", "published": "2024-07-11T18:31:13Z", "aliases": [ "CVE-2024-39539" diff --git a/advisories/unreviewed/2024/07/GHSA-938g-xvpf-6653/GHSA-938g-xvpf-6653.json b/advisories/unreviewed/2024/07/GHSA-938g-xvpf-6653/GHSA-938g-xvpf-6653.json index 223d82d1275..043e855a689 100644 --- a/advisories/unreviewed/2024/07/GHSA-938g-xvpf-6653/GHSA-938g-xvpf-6653.json +++ b/advisories/unreviewed/2024/07/GHSA-938g-xvpf-6653/GHSA-938g-xvpf-6653.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-938g-xvpf-6653", - "modified": "2024-07-11T21:31:12Z", + "modified": "2025-04-11T15:32:22Z", "published": "2024-07-11T18:31:13Z", "aliases": [ "CVE-2024-39550" diff --git a/advisories/unreviewed/2024/08/GHSA-54v7-45g9-xcqh/GHSA-54v7-45g9-xcqh.json b/advisories/unreviewed/2024/08/GHSA-54v7-45g9-xcqh/GHSA-54v7-45g9-xcqh.json index 510ed455ba9..28bbedc78f5 100644 --- a/advisories/unreviewed/2024/08/GHSA-54v7-45g9-xcqh/GHSA-54v7-45g9-xcqh.json +++ b/advisories/unreviewed/2024/08/GHSA-54v7-45g9-xcqh/GHSA-54v7-45g9-xcqh.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/08/GHSA-cqm6-fcfw-pfm3/GHSA-cqm6-fcfw-pfm3.json b/advisories/unreviewed/2024/08/GHSA-cqm6-fcfw-pfm3/GHSA-cqm6-fcfw-pfm3.json index 34563186ecc..1a295978582 100644 --- a/advisories/unreviewed/2024/08/GHSA-cqm6-fcfw-pfm3/GHSA-cqm6-fcfw-pfm3.json +++ b/advisories/unreviewed/2024/08/GHSA-cqm6-fcfw-pfm3/GHSA-cqm6-fcfw-pfm3.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/08/GHSA-fjrj-vrrh-qjx6/GHSA-fjrj-vrrh-qjx6.json b/advisories/unreviewed/2024/08/GHSA-fjrj-vrrh-qjx6/GHSA-fjrj-vrrh-qjx6.json index a73d6185b22..677791de037 100644 --- a/advisories/unreviewed/2024/08/GHSA-fjrj-vrrh-qjx6/GHSA-fjrj-vrrh-qjx6.json +++ b/advisories/unreviewed/2024/08/GHSA-fjrj-vrrh-qjx6/GHSA-fjrj-vrrh-qjx6.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/09/GHSA-h2c8-c64m-w4qp/GHSA-h2c8-c64m-w4qp.json b/advisories/unreviewed/2024/09/GHSA-h2c8-c64m-w4qp/GHSA-h2c8-c64m-w4qp.json index 5b68c2b2fce..2b943717b61 100644 --- a/advisories/unreviewed/2024/09/GHSA-h2c8-c64m-w4qp/GHSA-h2c8-c64m-w4qp.json +++ b/advisories/unreviewed/2024/09/GHSA-h2c8-c64m-w4qp/GHSA-h2c8-c64m-w4qp.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/11/GHSA-36q8-mfw8-2m98/GHSA-36q8-mfw8-2m98.json b/advisories/unreviewed/2024/11/GHSA-36q8-mfw8-2m98/GHSA-36q8-mfw8-2m98.json index 79978d6ef89..9cc08d733af 100644 --- a/advisories/unreviewed/2024/11/GHSA-36q8-mfw8-2m98/GHSA-36q8-mfw8-2m98.json +++ b/advisories/unreviewed/2024/11/GHSA-36q8-mfw8-2m98/GHSA-36q8-mfw8-2m98.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/11/GHSA-9g23-vp4v-xmvv/GHSA-9g23-vp4v-xmvv.json b/advisories/unreviewed/2024/11/GHSA-9g23-vp4v-xmvv/GHSA-9g23-vp4v-xmvv.json index abbea118de6..2d0a78bf22e 100644 --- a/advisories/unreviewed/2024/11/GHSA-9g23-vp4v-xmvv/GHSA-9g23-vp4v-xmvv.json +++ b/advisories/unreviewed/2024/11/GHSA-9g23-vp4v-xmvv/GHSA-9g23-vp4v-xmvv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9g23-vp4v-xmvv", - "modified": "2024-11-28T18:38:36Z", + "modified": "2025-04-11T15:32:24Z", "published": "2024-11-28T18:38:36Z", "aliases": [ "CVE-2024-11203" diff --git a/advisories/unreviewed/2024/11/GHSA-f3mv-cjr3-hr9j/GHSA-f3mv-cjr3-hr9j.json b/advisories/unreviewed/2024/11/GHSA-f3mv-cjr3-hr9j/GHSA-f3mv-cjr3-hr9j.json index ad6571d5aed..4ebedb45ad5 100644 --- a/advisories/unreviewed/2024/11/GHSA-f3mv-cjr3-hr9j/GHSA-f3mv-cjr3-hr9j.json +++ b/advisories/unreviewed/2024/11/GHSA-f3mv-cjr3-hr9j/GHSA-f3mv-cjr3-hr9j.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/12/GHSA-qq52-2f2f-p65w/GHSA-qq52-2f2f-p65w.json b/advisories/unreviewed/2024/12/GHSA-qq52-2f2f-p65w/GHSA-qq52-2f2f-p65w.json index 1a08982bf72..4d7341c8389 100644 --- a/advisories/unreviewed/2024/12/GHSA-qq52-2f2f-p65w/GHSA-qq52-2f2f-p65w.json +++ b/advisories/unreviewed/2024/12/GHSA-qq52-2f2f-p65w/GHSA-qq52-2f2f-p65w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qq52-2f2f-p65w", - "modified": "2024-12-12T06:30:50Z", + "modified": "2025-04-11T15:32:25Z", "published": "2024-12-12T06:30:50Z", "aliases": [ "CVE-2024-11052" diff --git a/advisories/unreviewed/2025/02/GHSA-4hmh-pm5p-9j7j/GHSA-4hmh-pm5p-9j7j.json b/advisories/unreviewed/2025/02/GHSA-4hmh-pm5p-9j7j/GHSA-4hmh-pm5p-9j7j.json index 08c2ab49497..daf83f9824c 100644 --- a/advisories/unreviewed/2025/02/GHSA-4hmh-pm5p-9j7j/GHSA-4hmh-pm5p-9j7j.json +++ b/advisories/unreviewed/2025/02/GHSA-4hmh-pm5p-9j7j/GHSA-4hmh-pm5p-9j7j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4hmh-pm5p-9j7j", - "modified": "2025-02-12T03:31:14Z", + "modified": "2025-04-11T15:32:26Z", "published": "2025-02-12T03:31:14Z", "aliases": [ "CVE-2025-23359" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5616" + }, + { + "type": "WEB", + "url": "https://thehackernews.com/2025/04/incomplete-patch-in-nvidia-toolkit.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/03/GHSA-2j99-5q75-3f57/GHSA-2j99-5q75-3f57.json b/advisories/unreviewed/2025/03/GHSA-2j99-5q75-3f57/GHSA-2j99-5q75-3f57.json index f00e185efa6..29b6c2a7e8f 100644 --- a/advisories/unreviewed/2025/03/GHSA-2j99-5q75-3f57/GHSA-2j99-5q75-3f57.json +++ b/advisories/unreviewed/2025/03/GHSA-2j99-5q75-3f57/GHSA-2j99-5q75-3f57.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2j99-5q75-3f57", - "modified": "2025-03-20T15:30:31Z", + "modified": "2025-04-11T15:32:26Z", "published": "2025-03-11T18:32:19Z", "aliases": [ "CVE-2025-24201" @@ -35,6 +35,22 @@ "type": "WEB", "url": "https://support.apple.com/en-us/122285" }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122345" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122346" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122372" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/122376" + }, { "type": "WEB", "url": "http://seclists.org/fulldisclosure/2025/Mar/2" diff --git a/advisories/unreviewed/2025/03/GHSA-8vh6-m67f-4h33/GHSA-8vh6-m67f-4h33.json b/advisories/unreviewed/2025/03/GHSA-8vh6-m67f-4h33/GHSA-8vh6-m67f-4h33.json index fa1ec68257b..7f4291717a2 100644 --- a/advisories/unreviewed/2025/03/GHSA-8vh6-m67f-4h33/GHSA-8vh6-m67f-4h33.json +++ b/advisories/unreviewed/2025/03/GHSA-8vh6-m67f-4h33/GHSA-8vh6-m67f-4h33.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8vh6-m67f-4h33", - "modified": "2025-03-31T15:30:48Z", + "modified": "2025-04-11T15:32:26Z", "published": "2025-03-31T15:30:48Z", "aliases": [ "CVE-2025-30095" ], "details": "VyOS 1.3 through 1.5 or any Debian-based system using dropbear in combination with live-build has the same Dropbear private host keys across different installations. Thus, an attacker can conduct active man-in-the-middle attacks against SSH connections if Dropbear is enabled as the SSH daemon. I n VyOS, this is not the default configuration for the system SSH daemon, but is for the console service. To mitigate this, one can run \"rm -f /etc/dropbear/*key*\" and/or \"rm -f /etc/dropbear-initramfs/*key*\" and then dropbearkey -t rsa -s 4096 -f /etc/dropbear_rsa_host_key and reload the service or reboot the system before using Dropbear as the SSH daemon (this clears out all keys mistakenly built into the release image) or update to the latest version of VyOS 1.4 or 1.5. Note that this vulnerability is not unique to VyOS and may appear in any Debian-based Linux distribution that uses Dropbear in combination with live-build, which has a safeguard against this behavior in OpenSSH but no equivalent one for Dropbear.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-321" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T15:15:44Z" diff --git a/advisories/unreviewed/2025/04/GHSA-5892-jw8m-4684/GHSA-5892-jw8m-4684.json b/advisories/unreviewed/2025/04/GHSA-5892-jw8m-4684/GHSA-5892-jw8m-4684.json new file mode 100644 index 00000000000..dcc85b9945c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5892-jw8m-4684/GHSA-5892-jw8m-4684.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5892-jw8m-4684", + "modified": "2025-04-11T15:32:30Z", + "published": "2025-04-11T15:32:30Z", + "aliases": [ + "CVE-2023-42875" + ], + "details": "Processing web content may lead to arbitrary code execution. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14, watchOS 10, tvOS 17, Safari 17. The issue was addressed with improved memory handling.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-42875" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/120330" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/120947" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/120948" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/120949" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/120950" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-11T15:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5f2m-5gjf-8mqg/GHSA-5f2m-5gjf-8mqg.json b/advisories/unreviewed/2025/04/GHSA-5f2m-5gjf-8mqg/GHSA-5f2m-5gjf-8mqg.json index 410595e97e6..4df70ce0251 100644 --- a/advisories/unreviewed/2025/04/GHSA-5f2m-5gjf-8mqg/GHSA-5f2m-5gjf-8mqg.json +++ b/advisories/unreviewed/2025/04/GHSA-5f2m-5gjf-8mqg/GHSA-5f2m-5gjf-8mqg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5f2m-5gjf-8mqg", - "modified": "2025-04-01T18:30:51Z", + "modified": "2025-04-11T15:32:27Z", "published": "2025-04-01T18:30:51Z", "aliases": [ "CVE-2025-21923" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: hid-steam: Fix use-after-free when detaching device\n\nWhen a hid-steam device is removed it must clean up the client_hdev used for\nintercepting hidraw access. This can lead to scheduling deferred work to\nreattach the input device. Though the cleanup cancels the deferred work, this\nwas done before the client_hdev itself is cleaned up, so it gets rescheduled.\nThis patch fixes the ordering to make sure the deferred work is properly\ncanceled.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-01T16:15:23Z" diff --git a/advisories/unreviewed/2025/04/GHSA-5x97-hgxc-62pv/GHSA-5x97-hgxc-62pv.json b/advisories/unreviewed/2025/04/GHSA-5x97-hgxc-62pv/GHSA-5x97-hgxc-62pv.json new file mode 100644 index 00000000000..5c44930cf7c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5x97-hgxc-62pv/GHSA-5x97-hgxc-62pv.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5x97-hgxc-62pv", + "modified": "2025-04-11T15:32:30Z", + "published": "2025-04-11T15:32:30Z", + "aliases": [ + "CVE-2023-38614" + ], + "details": "A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to access sensitive user data.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38614" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/120949" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/120950" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-11T15:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-64h7-7273-jw5g/GHSA-64h7-7273-jw5g.json b/advisories/unreviewed/2025/04/GHSA-64h7-7273-jw5g/GHSA-64h7-7273-jw5g.json new file mode 100644 index 00000000000..96ed30ded4e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-64h7-7273-jw5g/GHSA-64h7-7273-jw5g.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-64h7-7273-jw5g", + "modified": "2025-04-11T15:32:30Z", + "published": "2025-04-11T15:32:30Z", + "aliases": [ + "CVE-2023-42969" + ], + "details": "An app may be able to break out of its sandbox. This issue is fixed in iOS 17 and iPadOS 17, iOS 16.7 and iPadOS 16.7, macOS Sonoma 14, macOS Ventura 13.6, macOS Monterey 12.7. The issue was addressed with improved handling of caches.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-42969" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/120328" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/120329" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/120337" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/120949" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/120950" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-11T15:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6g9c-7jcv-4g45/GHSA-6g9c-7jcv-4g45.json b/advisories/unreviewed/2025/04/GHSA-6g9c-7jcv-4g45/GHSA-6g9c-7jcv-4g45.json index dcfe99df7c0..2ecdef17863 100644 --- a/advisories/unreviewed/2025/04/GHSA-6g9c-7jcv-4g45/GHSA-6g9c-7jcv-4g45.json +++ b/advisories/unreviewed/2025/04/GHSA-6g9c-7jcv-4g45/GHSA-6g9c-7jcv-4g45.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6g9c-7jcv-4g45", - "modified": "2025-04-01T18:30:51Z", + "modified": "2025-04-11T15:32:27Z", "published": "2025-04-01T18:30:51Z", "aliases": [ "CVE-2025-21922" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nppp: Fix KMSAN uninit-value warning with bpf\n\nSyzbot caught an \"KMSAN: uninit-value\" warning [1], which is caused by the\nppp driver not initializing a 2-byte header when using socket filter.\n\nThe following code can generate a PPP filter BPF program:\n'''\nstruct bpf_program fp;\npcap_t *handle;\nhandle = pcap_open_dead(DLT_PPP_PPPD, 65535);\npcap_compile(handle, &fp, \"ip and outbound\", 0, 0);\nbpf_dump(&fp, 1);\n'''\nIts output is:\n'''\n(000) ldh [2]\n(001) jeq #0x21 jt 2 jf 5\n(002) ldb [0]\n(003) jeq #0x1 jt 4 jf 5\n(004) ret #65535\n(005) ret #0\n'''\nWen can find similar code at the following link:\nhttps://github.com/ppp-project/ppp/blob/master/pppd/options.c#L1680\nThe maintainer of this code repository is also the original maintainer\nof the ppp driver.\n\nAs you can see the BPF program skips 2 bytes of data and then reads the\n'Protocol' field to determine if it's an IP packet. Then it read the first\nbyte of the first 2 bytes to determine the direction.\n\nThe issue is that only the first byte indicating direction is initialized\nin current ppp driver code while the second byte is not initialized.\n\nFor normal BPF programs generated by libpcap, uninitialized data won't be\nused, so it's not a problem. However, for carefully crafted BPF programs,\nsuch as those generated by syzkaller [2], which start reading from offset\n0, the uninitialized data will be used and caught by KMSAN.\n\n[1] https://syzkaller.appspot.com/bug?extid=853242d9c9917165d791\n[2] https://syzkaller.appspot.com/text?tag=ReproC&x=11994913980000", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-908" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-01T16:15:22Z" diff --git a/advisories/unreviewed/2025/04/GHSA-73gg-qjfg-4g7x/GHSA-73gg-qjfg-4g7x.json b/advisories/unreviewed/2025/04/GHSA-73gg-qjfg-4g7x/GHSA-73gg-qjfg-4g7x.json index 31a230adec5..ed223e68ea7 100644 --- a/advisories/unreviewed/2025/04/GHSA-73gg-qjfg-4g7x/GHSA-73gg-qjfg-4g7x.json +++ b/advisories/unreviewed/2025/04/GHSA-73gg-qjfg-4g7x/GHSA-73gg-qjfg-4g7x.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-7rrr-jvfx-w2gc/GHSA-7rrr-jvfx-w2gc.json b/advisories/unreviewed/2025/04/GHSA-7rrr-jvfx-w2gc/GHSA-7rrr-jvfx-w2gc.json new file mode 100644 index 00000000000..84bf48583c9 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7rrr-jvfx-w2gc/GHSA-7rrr-jvfx-w2gc.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7rrr-jvfx-w2gc", + "modified": "2025-04-11T15:32:29Z", + "published": "2025-04-11T15:32:29Z", + "aliases": [ + "CVE-2025-3422" + ], + "details": "The The Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.1.1. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated attackers, with Subscriber-level access and above, to execute arbitrary shortcodes.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3422" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3268742" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/3db1d9a0-ea68-4979-a36d-864c649f7aca?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-11T13:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-96jf-mvrm-934f/GHSA-96jf-mvrm-934f.json b/advisories/unreviewed/2025/04/GHSA-96jf-mvrm-934f/GHSA-96jf-mvrm-934f.json index 204c97c83b7..b9cb3a24b21 100644 --- a/advisories/unreviewed/2025/04/GHSA-96jf-mvrm-934f/GHSA-96jf-mvrm-934f.json +++ b/advisories/unreviewed/2025/04/GHSA-96jf-mvrm-934f/GHSA-96jf-mvrm-934f.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-9v5v-qfv2-66qp/GHSA-9v5v-qfv2-66qp.json b/advisories/unreviewed/2025/04/GHSA-9v5v-qfv2-66qp/GHSA-9v5v-qfv2-66qp.json new file mode 100644 index 00000000000..6dcf86ddb82 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9v5v-qfv2-66qp/GHSA-9v5v-qfv2-66qp.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9v5v-qfv2-66qp", + "modified": "2025-04-11T15:32:30Z", + "published": "2025-04-11T15:32:30Z", + "aliases": [ + "CVE-2023-42970" + ], + "details": "A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14, watchOS 10, tvOS 17, Safari 17. Processing web content may lead to arbitrary code execution.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-42970" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/120330" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/120947" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/120948" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/120949" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/120950" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-11T15:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-c924-p67m-48hp/GHSA-c924-p67m-48hp.json b/advisories/unreviewed/2025/04/GHSA-c924-p67m-48hp/GHSA-c924-p67m-48hp.json index 68f89434cb7..a5474feb85c 100644 --- a/advisories/unreviewed/2025/04/GHSA-c924-p67m-48hp/GHSA-c924-p67m-48hp.json +++ b/advisories/unreviewed/2025/04/GHSA-c924-p67m-48hp/GHSA-c924-p67m-48hp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c924-p67m-48hp", - "modified": "2025-04-01T18:30:51Z", + "modified": "2025-04-11T15:32:27Z", "published": "2025-04-01T18:30:51Z", "aliases": [ "CVE-2025-21919" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsched/fair: Fix potential memory corruption in child_cfs_rq_on_list\n\nchild_cfs_rq_on_list attempts to convert a 'prev' pointer to a cfs_rq.\nThis 'prev' pointer can originate from struct rq's leaf_cfs_rq_list,\nmaking the conversion invalid and potentially leading to memory\ncorruption. Depending on the relative positions of leaf_cfs_rq_list and\nthe task group (tg) pointer within the struct, this can cause a memory\nfault or access garbage data.\n\nThe issue arises in list_add_leaf_cfs_rq, where both\ncfs_rq->leaf_cfs_rq_list and rq->leaf_cfs_rq_list are added to the same\nleaf list. Also, rq->tmp_alone_branch can be set to rq->leaf_cfs_rq_list.\n\nThis adds a check `if (prev == &rq->leaf_cfs_rq_list)` after the main\nconditional in child_cfs_rq_on_list. This ensures that the container_of\noperation will convert a correct cfs_rq struct.\n\nThis check is sufficient because only cfs_rqs on the same CPU are added\nto the list, so verifying the 'prev' pointer against the current rq's list\nhead is enough.\n\nFixes a potential memory corruption issue that due to current struct\nlayout might not be manifesting as a crash but could lead to unpredictable\nbehavior when the layout changes.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-01T16:15:22Z" diff --git a/advisories/unreviewed/2025/04/GHSA-cg4r-9g44-qvw4/GHSA-cg4r-9g44-qvw4.json b/advisories/unreviewed/2025/04/GHSA-cg4r-9g44-qvw4/GHSA-cg4r-9g44-qvw4.json new file mode 100644 index 00000000000..7f2a49c12f9 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-cg4r-9g44-qvw4/GHSA-cg4r-9g44-qvw4.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cg4r-9g44-qvw4", + "modified": "2025-04-11T15:32:30Z", + "published": "2025-04-11T15:32:30Z", + "aliases": [ + "CVE-2023-42961" + ], + "details": "A path handling issue was addressed with improved validation. This issue is fixed in iOS 17 and iPadOS 17, iOS 16.7 and iPadOS 16.7, macOS Sonoma 14, macOS Ventura 13.6, macOS Monterey 12.7. A sandboxed process may be able to circumvent sandbox restrictions.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-42961" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/120328" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/120329" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/120337" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/120949" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/120950" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-11T15:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-cmwf-4hcv-45rc/GHSA-cmwf-4hcv-45rc.json b/advisories/unreviewed/2025/04/GHSA-cmwf-4hcv-45rc/GHSA-cmwf-4hcv-45rc.json new file mode 100644 index 00000000000..a1d0e6e07d5 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-cmwf-4hcv-45rc/GHSA-cmwf-4hcv-45rc.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cmwf-4hcv-45rc", + "modified": "2025-04-11T15:32:31Z", + "published": "2025-04-11T15:32:31Z", + "aliases": [ + "CVE-2023-42973" + ], + "details": "Private Browsing tabs may be accessed without authentication. This issue is fixed in iOS 17 and iPadOS 17. The issue was addressed with improved UI.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-42973" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/120949" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-11T15:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fc78-895f-8fh8/GHSA-fc78-895f-8fh8.json b/advisories/unreviewed/2025/04/GHSA-fc78-895f-8fh8/GHSA-fc78-895f-8fh8.json new file mode 100644 index 00000000000..3f8018fc85a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fc78-895f-8fh8/GHSA-fc78-895f-8fh8.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fc78-895f-8fh8", + "modified": "2025-04-11T15:32:31Z", + "published": "2025-04-11T15:32:31Z", + "aliases": [ + "CVE-2023-42981" + ], + "details": "Processing a file may lead to a denial-of-service or potentially disclose memory contents. This issue is fixed in macOS 14. The issue was addressed with improved checks.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-42981" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/120950" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-11T15:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fgww-7769-w5pf/GHSA-fgww-7769-w5pf.json b/advisories/unreviewed/2025/04/GHSA-fgww-7769-w5pf/GHSA-fgww-7769-w5pf.json new file mode 100644 index 00000000000..086b2752fac --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fgww-7769-w5pf/GHSA-fgww-7769-w5pf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fgww-7769-w5pf", + "modified": "2025-04-11T15:32:29Z", + "published": "2025-04-11T15:32:28Z", + "aliases": [ + "CVE-2024-13861" + ], + "details": "A code injection vulnerability in the Debian package component of Taegis Endpoint Agent (Linux) versions older than 1.3.10 allows local users arbitrary code execution as root. Redhat-based systems using RPM packages are not affected.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13861" + }, + { + "type": "WEB", + "url": "https://www.sophos.com/en-us/security-advisories/sophos-sa-20250411-taegis-agent-lpe" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-732" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-11T13:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-h573-4qjm-8775/GHSA-h573-4qjm-8775.json b/advisories/unreviewed/2025/04/GHSA-h573-4qjm-8775/GHSA-h573-4qjm-8775.json new file mode 100644 index 00000000000..9375429aed7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-h573-4qjm-8775/GHSA-h573-4qjm-8775.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h573-4qjm-8775", + "modified": "2025-04-11T15:32:29Z", + "published": "2025-04-11T15:32:29Z", + "aliases": [ + "CVE-2025-3421" + ], + "details": "The Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'form_id' parameter in all versions up to, and including, 3.1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3421" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3268742" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/d55737a5-8aa5-4c26-bbb5-bbc5ea8be8d1?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-11T13:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hf5w-7g55-wh36/GHSA-hf5w-7g55-wh36.json b/advisories/unreviewed/2025/04/GHSA-hf5w-7g55-wh36/GHSA-hf5w-7g55-wh36.json index 865e92305d7..f0fc9052727 100644 --- a/advisories/unreviewed/2025/04/GHSA-hf5w-7g55-wh36/GHSA-hf5w-7g55-wh36.json +++ b/advisories/unreviewed/2025/04/GHSA-hf5w-7g55-wh36/GHSA-hf5w-7g55-wh36.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hf5w-7g55-wh36", - "modified": "2025-04-01T18:30:51Z", + "modified": "2025-04-11T15:32:27Z", "published": "2025-04-01T18:30:51Z", "aliases": [ "CVE-2025-21917" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: renesas_usbhs: Flush the notify_hotplug_work\n\nWhen performing continuous unbind/bind operations on the USB drivers\navailable on the Renesas RZ/G2L SoC, a kernel crash with the message\n\"Unable to handle kernel NULL pointer dereference at virtual address\"\nmay occur. This issue points to the usbhsc_notify_hotplug() function.\n\nFlush the delayed work to avoid its execution when driver resources are\nunavailable.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-01T16:15:22Z" diff --git a/advisories/unreviewed/2025/04/GHSA-j8rw-3x8v-v327/GHSA-j8rw-3x8v-v327.json b/advisories/unreviewed/2025/04/GHSA-j8rw-3x8v-v327/GHSA-j8rw-3x8v-v327.json index 88085e80681..40532d72aaa 100644 --- a/advisories/unreviewed/2025/04/GHSA-j8rw-3x8v-v327/GHSA-j8rw-3x8v-v327.json +++ b/advisories/unreviewed/2025/04/GHSA-j8rw-3x8v-v327/GHSA-j8rw-3x8v-v327.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-j8rw-3x8v-v327", - "modified": "2025-04-07T09:30:22Z", + "modified": "2025-04-11T15:32:27Z", "published": "2025-04-01T18:30:51Z", "aliases": [ "CVE-2025-21918" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: typec: ucsi: Fix NULL pointer access\n\nResources should be released only after all threads that utilize them\nhave been destroyed.\nThis commit ensures that resources are not released prematurely by waiting\nfor the associated workqueue to complete before deallocating them.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-01T16:15:22Z" diff --git a/advisories/unreviewed/2025/04/GHSA-jq7g-h856-ccpg/GHSA-jq7g-h856-ccpg.json b/advisories/unreviewed/2025/04/GHSA-jq7g-h856-ccpg/GHSA-jq7g-h856-ccpg.json new file mode 100644 index 00000000000..7314b54157b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jq7g-h856-ccpg/GHSA-jq7g-h856-ccpg.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jq7g-h856-ccpg", + "modified": "2025-04-11T15:32:29Z", + "published": "2025-04-11T15:32:29Z", + "aliases": [ + "CVE-2025-3439" + ], + "details": "The Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.1.1 via deserialization of untrusted input from the 'field_value' parameter. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3439" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/everest-forms/trunk/includes/admin/views/html-admin-page-entries-view.php#L147" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3268742" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/0e5617a2-5670-4d98-a36b-942f71634642?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-11T13:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-jxxv-c48x-753p/GHSA-jxxv-c48x-753p.json b/advisories/unreviewed/2025/04/GHSA-jxxv-c48x-753p/GHSA-jxxv-c48x-753p.json index d32e03cbddf..b84bdff2ffa 100644 --- a/advisories/unreviewed/2025/04/GHSA-jxxv-c48x-753p/GHSA-jxxv-c48x-753p.json +++ b/advisories/unreviewed/2025/04/GHSA-jxxv-c48x-753p/GHSA-jxxv-c48x-753p.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jxxv-c48x-753p", - "modified": "2025-04-01T18:30:53Z", + "modified": "2025-04-11T15:32:27Z", "published": "2025-04-01T18:30:52Z", "aliases": [ "CVE-2025-21948" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: appleir: Fix potential NULL dereference at raw event handle\n\nSyzkaller reports a NULL pointer dereference issue in input_event().\n\nBUG: KASAN: null-ptr-deref in instrument_atomic_read include/linux/instrumented.h:68 [inline]\nBUG: KASAN: null-ptr-deref in _test_bit include/asm-generic/bitops/instrumented-non-atomic.h:141 [inline]\nBUG: KASAN: null-ptr-deref in is_event_supported drivers/input/input.c:67 [inline]\nBUG: KASAN: null-ptr-deref in input_event+0x42/0xa0 drivers/input/input.c:395\nRead of size 8 at addr 0000000000000028 by task syz-executor199/2949\n\nCPU: 0 UID: 0 PID: 2949 Comm: syz-executor199 Not tainted 6.13.0-rc4-syzkaller-00076-gf097a36ef88d #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024\nCall Trace:\n \n __dump_stack lib/dump_stack.c:94 [inline]\n dump_stack_lvl+0x116/0x1f0 lib/dump_stack.c:120\n kasan_report+0xd9/0x110 mm/kasan/report.c:602\n check_region_inline mm/kasan/generic.c:183 [inline]\n kasan_check_range+0xef/0x1a0 mm/kasan/generic.c:189\n instrument_atomic_read include/linux/instrumented.h:68 [inline]\n _test_bit include/asm-generic/bitops/instrumented-non-atomic.h:141 [inline]\n is_event_supported drivers/input/input.c:67 [inline]\n input_event+0x42/0xa0 drivers/input/input.c:395\n input_report_key include/linux/input.h:439 [inline]\n key_down drivers/hid/hid-appleir.c:159 [inline]\n appleir_raw_event+0x3e5/0x5e0 drivers/hid/hid-appleir.c:232\n __hid_input_report.constprop.0+0x312/0x440 drivers/hid/hid-core.c:2111\n hid_ctrl+0x49f/0x550 drivers/hid/usbhid/hid-core.c:484\n __usb_hcd_giveback_urb+0x389/0x6e0 drivers/usb/core/hcd.c:1650\n usb_hcd_giveback_urb+0x396/0x450 drivers/usb/core/hcd.c:1734\n dummy_timer+0x17f7/0x3960 drivers/usb/gadget/udc/dummy_hcd.c:1993\n __run_hrtimer kernel/time/hrtimer.c:1739 [inline]\n __hrtimer_run_queues+0x20a/0xae0 kernel/time/hrtimer.c:1803\n hrtimer_run_softirq+0x17d/0x350 kernel/time/hrtimer.c:1820\n handle_softirqs+0x206/0x8d0 kernel/softirq.c:561\n __do_softirq kernel/softirq.c:595 [inline]\n invoke_softirq kernel/softirq.c:435 [inline]\n __irq_exit_rcu+0xfa/0x160 kernel/softirq.c:662\n irq_exit_rcu+0x9/0x30 kernel/softirq.c:678\n instr_sysvec_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1049 [inline]\n sysvec_apic_timer_interrupt+0x90/0xb0 arch/x86/kernel/apic/apic.c:1049\n \n \n asm_sysvec_apic_timer_interrupt+0x1a/0x20 arch/x86/include/asm/idtentry.h:702\n __mod_timer+0x8f6/0xdc0 kernel/time/timer.c:1185\n add_timer+0x62/0x90 kernel/time/timer.c:1295\n schedule_timeout+0x11f/0x280 kernel/time/sleep_timeout.c:98\n usbhid_wait_io+0x1c7/0x380 drivers/hid/usbhid/hid-core.c:645\n usbhid_init_reports+0x19f/0x390 drivers/hid/usbhid/hid-core.c:784\n hiddev_ioctl+0x1133/0x15b0 drivers/hid/usbhid/hiddev.c:794\n vfs_ioctl fs/ioctl.c:51 [inline]\n __do_sys_ioctl fs/ioctl.c:906 [inline]\n __se_sys_ioctl fs/ioctl.c:892 [inline]\n __x64_sys_ioctl+0x190/0x200 fs/ioctl.c:892\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xcd/0x250 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n \n\nThis happens due to the malformed report items sent by the emulated device\nwhich results in a report, that has no fields, being added to the report list.\nDue to this appleir_input_configured() is never called, hidinput_connect()\nfails which results in the HID_CLAIMED_INPUT flag is not being set. However,\nit does not make appleir_probe() fail and lets the event callback to be\ncalled without the associated input device.\n\nThus, add a check for the HID_CLAIMED_INPUT flag and leave the event hook\nearly if the driver didn't claim any input_dev for some reason. Moreover,\nsome other hid drivers accessing input_dev in their event callbacks do have\nsimilar checks, too.\n\nFound by Linux Verification Center (linuxtesting.org) with Syzkaller.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-01T16:15:25Z" diff --git a/advisories/unreviewed/2025/04/GHSA-m6p7-g6ff-wxw5/GHSA-m6p7-g6ff-wxw5.json b/advisories/unreviewed/2025/04/GHSA-m6p7-g6ff-wxw5/GHSA-m6p7-g6ff-wxw5.json new file mode 100644 index 00000000000..a6e7e7a28ba --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-m6p7-g6ff-wxw5/GHSA-m6p7-g6ff-wxw5.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m6p7-g6ff-wxw5", + "modified": "2025-04-11T15:32:31Z", + "published": "2025-04-11T15:32:31Z", + "aliases": [ + "CVE-2023-42977" + ], + "details": "A path handling issue was addressed with improved validation. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to break out of its sandbox.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-42977" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/120949" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/120950" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-11T15:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-p4qc-cp8p-44wh/GHSA-p4qc-cp8p-44wh.json b/advisories/unreviewed/2025/04/GHSA-p4qc-cp8p-44wh/GHSA-p4qc-cp8p-44wh.json index a2824c32342..287fac2f6a8 100644 --- a/advisories/unreviewed/2025/04/GHSA-p4qc-cp8p-44wh/GHSA-p4qc-cp8p-44wh.json +++ b/advisories/unreviewed/2025/04/GHSA-p4qc-cp8p-44wh/GHSA-p4qc-cp8p-44wh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p4qc-cp8p-44wh", - "modified": "2025-04-01T18:30:51Z", + "modified": "2025-04-11T15:32:27Z", "published": "2025-04-01T18:30:51Z", "aliases": [ "CVE-2025-21927" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnvme-tcp: fix potential memory corruption in nvme_tcp_recv_pdu()\n\nnvme_tcp_recv_pdu() doesn't check the validity of the header length.\nWhen header digests are enabled, a target might send a packet with an\ninvalid header length (e.g. 255), causing nvme_tcp_verify_hdgst()\nto access memory outside the allocated area and cause memory corruptions\nby overwriting it with the calculated digest.\n\nFix this by rejecting packets with an unexpected header length.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-01T16:15:23Z" diff --git a/advisories/unreviewed/2025/04/GHSA-p79h-jcrm-6qrc/GHSA-p79h-jcrm-6qrc.json b/advisories/unreviewed/2025/04/GHSA-p79h-jcrm-6qrc/GHSA-p79h-jcrm-6qrc.json index 161c2e698ca..34c4111d80f 100644 --- a/advisories/unreviewed/2025/04/GHSA-p79h-jcrm-6qrc/GHSA-p79h-jcrm-6qrc.json +++ b/advisories/unreviewed/2025/04/GHSA-p79h-jcrm-6qrc/GHSA-p79h-jcrm-6qrc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p79h-jcrm-6qrc", - "modified": "2025-04-01T18:30:51Z", + "modified": "2025-04-11T15:32:27Z", "published": "2025-04-01T18:30:51Z", "aliases": [ "CVE-2025-21920" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nvlan: enforce underlying device type\n\nCurrently, VLAN devices can be created on top of non-ethernet devices.\n\nBesides the fact that it doesn't make much sense, this also causes a\nbug which leaks the address of a kernel function to usermode.\n\nWhen creating a VLAN device, we initialize GARP (garp_init_applicant)\nand MRP (mrp_init_applicant) for the underlying device.\n\nAs part of the initialization process, we add the multicast address of\neach applicant to the underlying device, by calling dev_mc_add.\n\n__dev_mc_add uses dev->addr_len to determine the length of the new\nmulticast address.\n\nThis causes an out-of-bounds read if dev->addr_len is greater than 6,\nsince the multicast addresses provided by GARP and MRP are only 6\nbytes long.\n\nThis behaviour can be reproduced using the following commands:\n\nip tunnel add gretest mode ip6gre local ::1 remote ::2 dev lo\nip l set up dev gretest\nip link add link gretest name vlantest type vlan id 100\n\nThen, the following command will display the address of garp_pdu_rcv:\n\nip maddr show | grep 01:80:c2:00:00:21\n\nFix the bug by enforcing the type of the underlying device during VLAN\ndevice initialization.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-01T16:15:22Z" diff --git a/advisories/unreviewed/2025/04/GHSA-pf4f-8wpm-5vh2/GHSA-pf4f-8wpm-5vh2.json b/advisories/unreviewed/2025/04/GHSA-pf4f-8wpm-5vh2/GHSA-pf4f-8wpm-5vh2.json index b90ecbddd2e..a0f1bbd5c25 100644 --- a/advisories/unreviewed/2025/04/GHSA-pf4f-8wpm-5vh2/GHSA-pf4f-8wpm-5vh2.json +++ b/advisories/unreviewed/2025/04/GHSA-pf4f-8wpm-5vh2/GHSA-pf4f-8wpm-5vh2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pf4f-8wpm-5vh2", - "modified": "2025-04-01T18:30:53Z", + "modified": "2025-04-11T15:32:27Z", "published": "2025-04-01T18:30:52Z", "aliases": [ "CVE-2025-21951" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbus: mhi: host: pci_generic: Use pci_try_reset_function() to avoid deadlock\n\nThere are multiple places from where the recovery work gets scheduled\nasynchronously. Also, there are multiple places where the caller waits\nsynchronously for the recovery to be completed. One such place is during\nthe PM shutdown() callback.\n\nIf the device is not alive during recovery_work, it will try to reset the\ndevice using pci_reset_function(). This function internally will take the\ndevice_lock() first before resetting the device. By this time, if the lock\nhas already been acquired, then recovery_work will get stalled while\nwaiting for the lock. And if the lock was already acquired by the caller\nwhich waits for the recovery_work to be completed, it will lead to\ndeadlock.\n\nThis is what happened on the X1E80100 CRD device when the device died\nbefore shutdown() callback. Driver core calls the driver's shutdown()\ncallback while holding the device_lock() leading to deadlock.\n\nAnd this deadlock scenario can occur on other paths as well, like during\nthe PM suspend() callback, where the driver core would hold the\ndevice_lock() before calling driver's suspend() callback. And if the\nrecovery_work was already started, it could lead to deadlock. This is also\nobserved on the X1E80100 CRD.\n\nSo to fix both issues, use pci_try_reset_function() in recovery_work. This\nfunction first checks for the availability of the device_lock() before\ntrying to reset the device. If the lock is available, it will acquire it\nand reset the device. Otherwise, it will return -EAGAIN. If that happens,\nrecovery_work will fail with the error message \"Recovery failed\" as not\nmuch could be done.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-667" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-01T16:15:26Z" diff --git a/advisories/unreviewed/2025/04/GHSA-pmvp-2f47-m6wx/GHSA-pmvp-2f47-m6wx.json b/advisories/unreviewed/2025/04/GHSA-pmvp-2f47-m6wx/GHSA-pmvp-2f47-m6wx.json new file mode 100644 index 00000000000..4b0bc1db834 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-pmvp-2f47-m6wx/GHSA-pmvp-2f47-m6wx.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pmvp-2f47-m6wx", + "modified": "2025-04-11T15:32:30Z", + "published": "2025-04-11T15:32:30Z", + "aliases": [ + "CVE-2023-41076" + ], + "details": "An app may be able to elevate privileges. This issue is fixed in macOS 14. This issue was addressed by removing the vulnerable code.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-41076" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/120950" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-11T15:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qhr5-5m4q-73p8/GHSA-qhr5-5m4q-73p8.json b/advisories/unreviewed/2025/04/GHSA-qhr5-5m4q-73p8/GHSA-qhr5-5m4q-73p8.json index 91d0af596eb..c19e58a5fca 100644 --- a/advisories/unreviewed/2025/04/GHSA-qhr5-5m4q-73p8/GHSA-qhr5-5m4q-73p8.json +++ b/advisories/unreviewed/2025/04/GHSA-qhr5-5m4q-73p8/GHSA-qhr5-5m4q-73p8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qhr5-5m4q-73p8", - "modified": "2025-04-01T18:30:52Z", + "modified": "2025-04-11T15:32:27Z", "published": "2025-04-01T18:30:52Z", "aliases": [ "CVE-2025-21949" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nLoongArch: Set hugetlb mmap base address aligned with pmd size\n\nWith ltp test case \"testcases/bin/hugefork02\", there is a dmesg error\nreport message such as:\n\n kernel BUG at mm/hugetlb.c:5550!\n Oops - BUG[#1]:\n CPU: 0 UID: 0 PID: 1517 Comm: hugefork02 Not tainted 6.14.0-rc2+ #241\n Hardware name: QEMU QEMU Virtual Machine, BIOS unknown 2/2/2022\n pc 90000000004eaf1c ra 9000000000485538 tp 900000010edbc000 sp 900000010edbf940\n a0 900000010edbfb00 a1 9000000108d20280 a2 00007fffe9474000 a3 00007ffff3474000\n a4 0000000000000000 a5 0000000000000003 a6 00000000003cadd3 a7 0000000000000000\n t0 0000000001ffffff t1 0000000001474000 t2 900000010ecd7900 t3 00007fffe9474000\n t4 00007fffe9474000 t5 0000000000000040 t6 900000010edbfb00 t7 0000000000000001\n t8 0000000000000005 u0 90000000004849d0 s9 900000010edbfa00 s0 9000000108d20280\n s1 00007fffe9474000 s2 0000000002000000 s3 9000000108d20280 s4 9000000002b38b10\n s5 900000010edbfb00 s6 00007ffff3474000 s7 0000000000000406 s8 900000010edbfa08\n ra: 9000000000485538 unmap_vmas+0x130/0x218\n ERA: 90000000004eaf1c __unmap_hugepage_range+0x6f4/0x7d0\n PRMD: 00000004 (PPLV0 +PIE -PWE)\n EUEN: 00000007 (+FPE +SXE +ASXE -BTE)\n ECFG: 00071c1d (LIE=0,2-4,10-12 VS=7)\n ESTAT: 000c0000 [BRK] (IS= ECode=12 EsubCode=0)\n PRID: 0014c010 (Loongson-64bit, Loongson-3A5000)\n Process hugefork02 (pid: 1517, threadinfo=00000000a670eaf4, task=000000007a95fc64)\n Call Trace:\n [<90000000004eaf1c>] __unmap_hugepage_range+0x6f4/0x7d0\n [<9000000000485534>] unmap_vmas+0x12c/0x218\n [<9000000000494068>] exit_mmap+0xe0/0x308\n [<900000000025fdc4>] mmput+0x74/0x180\n [<900000000026a284>] do_exit+0x294/0x898\n [<900000000026aa30>] do_group_exit+0x30/0x98\n [<900000000027bed4>] get_signal+0x83c/0x868\n [<90000000002457b4>] arch_do_signal_or_restart+0x54/0xfa0\n [<90000000015795e8>] irqentry_exit_to_user_mode+0xb8/0x138\n [<90000000002572d0>] tlb_do_page_fault_1+0x114/0x1b4\n\nThe problem is that base address allocated from hugetlbfs is not aligned\nwith pmd size. Here add a checking for hugetlbfs and align base address\nwith pmd size. After this patch the test case \"testcases/bin/hugefork02\"\npasses to run.\n\nThis is similar to the commit 7f24cbc9c4d42db8a3c8484d1 (\"mm/mmap: teach\ngeneric_get_unmapped_area{_topdown} to handle hugetlb mappings\").", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -25,7 +30,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-01T16:15:26Z" diff --git a/advisories/unreviewed/2025/04/GHSA-rj34-pxf7-99v6/GHSA-rj34-pxf7-99v6.json b/advisories/unreviewed/2025/04/GHSA-rj34-pxf7-99v6/GHSA-rj34-pxf7-99v6.json new file mode 100644 index 00000000000..839a48355dd --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rj34-pxf7-99v6/GHSA-rj34-pxf7-99v6.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rj34-pxf7-99v6", + "modified": "2025-04-11T15:32:31Z", + "published": "2025-04-11T15:32:31Z", + "aliases": [ + "CVE-2023-42982" + ], + "details": "Processing a file may lead to a denial-of-service or potentially disclose memory contents. This issue is fixed in macOS 14. The issue was addressed with improved checks.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-42982" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/120950" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-11T15:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-v2qv-44ch-jx7v/GHSA-v2qv-44ch-jx7v.json b/advisories/unreviewed/2025/04/GHSA-v2qv-44ch-jx7v/GHSA-v2qv-44ch-jx7v.json index 372546c9311..05ce69043e8 100644 --- a/advisories/unreviewed/2025/04/GHSA-v2qv-44ch-jx7v/GHSA-v2qv-44ch-jx7v.json +++ b/advisories/unreviewed/2025/04/GHSA-v2qv-44ch-jx7v/GHSA-v2qv-44ch-jx7v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-v2qv-44ch-jx7v", - "modified": "2025-04-01T18:30:51Z", + "modified": "2025-04-11T15:32:27Z", "published": "2025-04-01T18:30:51Z", "aliases": [ "CVE-2025-21928" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: intel-ish-hid: Fix use-after-free issue in ishtp_hid_remove()\n\nThe system can experience a random crash a few minutes after the driver is\nremoved. This issue occurs due to improper handling of memory freeing in\nthe ishtp_hid_remove() function.\n\nThe function currently frees the `driver_data` directly within the loop\nthat destroys the HID devices, which can lead to accessing freed memory.\nSpecifically, `hid_destroy_device()` uses `driver_data` when it calls\n`hid_ishtp_set_feature()` to power off the sensor, so freeing\n`driver_data` beforehand can result in accessing invalid memory.\n\nThis patch resolves the issue by storing the `driver_data` in a temporary\nvariable before calling `hid_destroy_device()`, and then freeing the\n`driver_data` after the device is destroyed.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-01T16:15:23Z" diff --git a/advisories/unreviewed/2025/04/GHSA-v435-p7h6-v9pj/GHSA-v435-p7h6-v9pj.json b/advisories/unreviewed/2025/04/GHSA-v435-p7h6-v9pj/GHSA-v435-p7h6-v9pj.json new file mode 100644 index 00000000000..9eb9bf4fd1f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-v435-p7h6-v9pj/GHSA-v435-p7h6-v9pj.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v435-p7h6-v9pj", + "modified": "2025-04-11T15:32:31Z", + "published": "2025-04-11T15:32:31Z", + "aliases": [ + "CVE-2023-42983" + ], + "details": "Processing a file may lead to a denial-of-service or potentially disclose memory contents. This issue is fixed in macOS 14. The issue was addressed with improved checks.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-42983" + }, + { + "type": "WEB", + "url": "https://support.apple.com/en-us/120950" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-11T15:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vcfm-2r3w-vjx5/GHSA-vcfm-2r3w-vjx5.json b/advisories/unreviewed/2025/04/GHSA-vcfm-2r3w-vjx5/GHSA-vcfm-2r3w-vjx5.json index 0f941d354cc..261a3a81052 100644 --- a/advisories/unreviewed/2025/04/GHSA-vcfm-2r3w-vjx5/GHSA-vcfm-2r3w-vjx5.json +++ b/advisories/unreviewed/2025/04/GHSA-vcfm-2r3w-vjx5/GHSA-vcfm-2r3w-vjx5.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false,