From 3ac21ef5cd40fc7a690c41d9f8e4618a30ed539e Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 11 Dec 2024 21:33:08 +0000 Subject: [PATCH] Publish Advisories GHSA-2v5g-8cvx-qmfq GHSA-f58x-r563-jp48 GHSA-xhg2-hhrv-v2x2 GHSA-58qx-pwx2-gqm9 GHSA-6fr7-h9mh-45f3 GHSA-86gj-xr8h-wjf6 GHSA-88mc-pcqg-4446 GHSA-8x6v-8q4g-xh9f GHSA-96gv-mmp8-mqx5 GHSA-c7fm-gwfm-q8c7 GHSA-f679-5wx9-qfmm GHSA-fvhh-6wh3-m386 GHSA-gh2q-9gh5-p9fx GHSA-gwx2-9h8p-phf8 GHSA-q56w-m7h5-j43f GHSA-rgw8-cw3p-qv66 GHSA-vr58-5gj9-563m GHSA-w78w-44c5-7mwx GHSA-x34g-xjxv-fc48 --- .../GHSA-2v5g-8cvx-qmfq/GHSA-2v5g-8cvx-qmfq.json | 2 +- .../GHSA-f58x-r563-jp48/GHSA-f58x-r563-jp48.json | 3 ++- .../GHSA-xhg2-hhrv-v2x2/GHSA-xhg2-hhrv-v2x2.json | 3 ++- .../GHSA-58qx-pwx2-gqm9/GHSA-58qx-pwx2-gqm9.json | 15 +++++++++++---- .../GHSA-6fr7-h9mh-45f3/GHSA-6fr7-h9mh-45f3.json | 15 +++++++++++---- .../GHSA-86gj-xr8h-wjf6/GHSA-86gj-xr8h-wjf6.json | 11 ++++++++--- .../GHSA-88mc-pcqg-4446/GHSA-88mc-pcqg-4446.json | 15 +++++++++++---- .../GHSA-8x6v-8q4g-xh9f/GHSA-8x6v-8q4g-xh9f.json | 15 +++++++++++---- .../GHSA-96gv-mmp8-mqx5/GHSA-96gv-mmp8-mqx5.json | 15 +++++++++++---- .../GHSA-c7fm-gwfm-q8c7/GHSA-c7fm-gwfm-q8c7.json | 15 +++++++++++---- .../GHSA-f679-5wx9-qfmm/GHSA-f679-5wx9-qfmm.json | 15 +++++++++++---- .../GHSA-fvhh-6wh3-m386/GHSA-fvhh-6wh3-m386.json | 15 +++++++++++---- .../GHSA-gh2q-9gh5-p9fx/GHSA-gh2q-9gh5-p9fx.json | 11 ++++++++--- .../GHSA-gwx2-9h8p-phf8/GHSA-gwx2-9h8p-phf8.json | 15 +++++++++++---- .../GHSA-q56w-m7h5-j43f/GHSA-q56w-m7h5-j43f.json | 15 +++++++++++---- .../GHSA-rgw8-cw3p-qv66/GHSA-rgw8-cw3p-qv66.json | 11 ++++++++--- .../GHSA-vr58-5gj9-563m/GHSA-vr58-5gj9-563m.json | 11 ++++++++--- .../GHSA-w78w-44c5-7mwx/GHSA-w78w-44c5-7mwx.json | 11 ++++++++--- .../GHSA-x34g-xjxv-fc48/GHSA-x34g-xjxv-fc48.json | 15 +++++++++++---- 19 files changed, 166 insertions(+), 62 deletions(-) diff --git a/advisories/unreviewed/2024/02/GHSA-2v5g-8cvx-qmfq/GHSA-2v5g-8cvx-qmfq.json b/advisories/unreviewed/2024/02/GHSA-2v5g-8cvx-qmfq/GHSA-2v5g-8cvx-qmfq.json index cb8a8f16c1b..f780f232488 100644 --- a/advisories/unreviewed/2024/02/GHSA-2v5g-8cvx-qmfq/GHSA-2v5g-8cvx-qmfq.json +++ b/advisories/unreviewed/2024/02/GHSA-2v5g-8cvx-qmfq/GHSA-2v5g-8cvx-qmfq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2v5g-8cvx-qmfq", - "modified": "2024-02-16T21:31:31Z", + "modified": "2024-12-11T21:31:56Z", "published": "2024-02-16T21:31:31Z", "aliases": [ "CVE-2024-21915" diff --git a/advisories/unreviewed/2024/06/GHSA-f58x-r563-jp48/GHSA-f58x-r563-jp48.json b/advisories/unreviewed/2024/06/GHSA-f58x-r563-jp48/GHSA-f58x-r563-jp48.json index 199670eacc9..2750d4612df 100644 --- a/advisories/unreviewed/2024/06/GHSA-f58x-r563-jp48/GHSA-f58x-r563-jp48.json +++ b/advisories/unreviewed/2024/06/GHSA-f58x-r563-jp48/GHSA-f58x-r563-jp48.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-xhg2-hhrv-v2x2/GHSA-xhg2-hhrv-v2x2.json b/advisories/unreviewed/2024/11/GHSA-xhg2-hhrv-v2x2/GHSA-xhg2-hhrv-v2x2.json index 16674d47b54..d407fb777ef 100644 --- a/advisories/unreviewed/2024/11/GHSA-xhg2-hhrv-v2x2/GHSA-xhg2-hhrv-v2x2.json +++ b/advisories/unreviewed/2024/11/GHSA-xhg2-hhrv-v2x2/GHSA-xhg2-hhrv-v2x2.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-58qx-pwx2-gqm9/GHSA-58qx-pwx2-gqm9.json b/advisories/unreviewed/2024/12/GHSA-58qx-pwx2-gqm9/GHSA-58qx-pwx2-gqm9.json index c83e053a095..42b6c79ecfd 100644 --- a/advisories/unreviewed/2024/12/GHSA-58qx-pwx2-gqm9/GHSA-58qx-pwx2-gqm9.json +++ b/advisories/unreviewed/2024/12/GHSA-58qx-pwx2-gqm9/GHSA-58qx-pwx2-gqm9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-58qx-pwx2-gqm9", - "modified": "2024-12-02T15:31:39Z", + "modified": "2024-12-11T21:31:57Z", "published": "2024-12-02T15:31:39Z", "aliases": [ "CVE-2024-53123" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: error out earlier on disconnect\n\nEric reported a division by zero splat in the MPTCP protocol:\n\nOops: divide error: 0000 [#1] PREEMPT SMP KASAN PTI\nCPU: 1 UID: 0 PID: 6094 Comm: syz-executor317 Not tainted\n6.12.0-rc5-syzkaller-00291-g05b92660cdfe #0\nHardware name: Google Google Compute Engine/Google Compute Engine,\nBIOS Google 09/13/2024\nRIP: 0010:__tcp_select_window+0x5b4/0x1310 net/ipv4/tcp_output.c:3163\nCode: f6 44 01 e3 89 df e8 9b 75 09 f8 44 39 f3 0f 8d 11 ff ff ff e8\n0d 74 09 f8 45 89 f4 e9 04 ff ff ff e8 00 74 09 f8 44 89 f0 99 7c\n24 14 41 29 d6 45 89 f4 e9 ec fe ff ff e8 e8 73 09 f8 48 89\nRSP: 0018:ffffc900041f7930 EFLAGS: 00010293\nRAX: 0000000000017e67 RBX: 0000000000017e67 RCX: ffffffff8983314b\nRDX: 0000000000000000 RSI: ffffffff898331b0 RDI: 0000000000000004\nRBP: 00000000005d6000 R08: 0000000000000004 R09: 0000000000017e67\nR10: 0000000000003e80 R11: 0000000000000000 R12: 0000000000003e80\nR13: ffff888031d9b440 R14: 0000000000017e67 R15: 00000000002eb000\nFS: 00007feb5d7f16c0(0000) GS:ffff8880b8700000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007feb5d8adbb8 CR3: 0000000074e4c000 CR4: 00000000003526f0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nCall Trace:\n\n__tcp_cleanup_rbuf+0x3e7/0x4b0 net/ipv4/tcp.c:1493\nmptcp_rcv_space_adjust net/mptcp/protocol.c:2085 [inline]\nmptcp_recvmsg+0x2156/0x2600 net/mptcp/protocol.c:2289\ninet_recvmsg+0x469/0x6a0 net/ipv4/af_inet.c:885\nsock_recvmsg_nosec net/socket.c:1051 [inline]\nsock_recvmsg+0x1b2/0x250 net/socket.c:1073\n__sys_recvfrom+0x1a5/0x2e0 net/socket.c:2265\n__do_sys_recvfrom net/socket.c:2283 [inline]\n__se_sys_recvfrom net/socket.c:2279 [inline]\n__x64_sys_recvfrom+0xe0/0x1c0 net/socket.c:2279\ndo_syscall_x64 arch/x86/entry/common.c:52 [inline]\ndo_syscall_64+0xcd/0x250 arch/x86/entry/common.c:83\nentry_SYSCALL_64_after_hwframe+0x77/0x7f\nRIP: 0033:0x7feb5d857559\nCode: 28 00 00 00 75 05 48 83 c4 28 c3 e8 51 18 00 00 90 48 89 f8 48\n89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d\n01 f0 ff ff 73 01 c3 48 c7 c1 b0 ff ff ff f7 d8 64 89 01 48\nRSP: 002b:00007feb5d7f1208 EFLAGS: 00000246 ORIG_RAX: 000000000000002d\nRAX: ffffffffffffffda RBX: 00007feb5d8e1318 RCX: 00007feb5d857559\nRDX: 000000800000000e RSI: 0000000000000000 RDI: 0000000000000003\nRBP: 00007feb5d8e1310 R08: 0000000000000000 R09: ffffffff81000000\nR10: 0000000000000100 R11: 0000000000000246 R12: 00007feb5d8e131c\nR13: 00007feb5d8ae074 R14: 000000800000000e R15: 00000000fffffdef\n\nand provided a nice reproducer.\n\nThe root cause is the current bad handling of racing disconnect.\nAfter the blamed commit below, sk_wait_data() can return (with\nerror) with the underlying socket disconnected and a zero rcv_mss.\n\nCatch the error and return without performing any additional\noperations on the current socket.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-362" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-02T14:15:13Z" diff --git a/advisories/unreviewed/2024/12/GHSA-6fr7-h9mh-45f3/GHSA-6fr7-h9mh-45f3.json b/advisories/unreviewed/2024/12/GHSA-6fr7-h9mh-45f3/GHSA-6fr7-h9mh-45f3.json index c98cd65a3ee..011a4516636 100644 --- a/advisories/unreviewed/2024/12/GHSA-6fr7-h9mh-45f3/GHSA-6fr7-h9mh-45f3.json +++ b/advisories/unreviewed/2024/12/GHSA-6fr7-h9mh-45f3/GHSA-6fr7-h9mh-45f3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6fr7-h9mh-45f3", - "modified": "2024-12-02T15:31:39Z", + "modified": "2024-12-11T21:31:57Z", "published": "2024-12-02T15:31:39Z", "aliases": [ "CVE-2024-53115" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/vmwgfx: avoid null_ptr_deref in vmw_framebuffer_surface_create_handle\n\nThe 'vmw_user_object_buffer' function may return NULL with incorrect\ninputs. To avoid possible null pointer dereference, add a check whether\nthe 'bo' is NULL in the vmw_framebuffer_surface_create_handle.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-02T14:15:12Z" diff --git a/advisories/unreviewed/2024/12/GHSA-86gj-xr8h-wjf6/GHSA-86gj-xr8h-wjf6.json b/advisories/unreviewed/2024/12/GHSA-86gj-xr8h-wjf6/GHSA-86gj-xr8h-wjf6.json index b9b29bbb061..211fa02c280 100644 --- a/advisories/unreviewed/2024/12/GHSA-86gj-xr8h-wjf6/GHSA-86gj-xr8h-wjf6.json +++ b/advisories/unreviewed/2024/12/GHSA-86gj-xr8h-wjf6/GHSA-86gj-xr8h-wjf6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-86gj-xr8h-wjf6", - "modified": "2024-12-02T15:31:39Z", + "modified": "2024-12-11T21:31:57Z", "published": "2024-12-02T15:31:39Z", "aliases": [ "CVE-2024-53109" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnommu: pass NULL argument to vma_iter_prealloc()\n\nWhen deleting a vma entry from a maple tree, it has to pass NULL to\nvma_iter_prealloc() in order to calculate internal state of the tree, but\nit passed a wrong argument. As a result, nommu kernels crashed upon\naccessing a vma iterator, such as acct_collect() reading the size of vma\nentries after do_munmap().\n\nThis commit fixes this issue by passing a right argument to the\npreallocation call.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -29,7 +34,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-02T14:15:11Z" diff --git a/advisories/unreviewed/2024/12/GHSA-88mc-pcqg-4446/GHSA-88mc-pcqg-4446.json b/advisories/unreviewed/2024/12/GHSA-88mc-pcqg-4446/GHSA-88mc-pcqg-4446.json index e7b51aed29b..c88bf0c7e18 100644 --- a/advisories/unreviewed/2024/12/GHSA-88mc-pcqg-4446/GHSA-88mc-pcqg-4446.json +++ b/advisories/unreviewed/2024/12/GHSA-88mc-pcqg-4446/GHSA-88mc-pcqg-4446.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-88mc-pcqg-4446", - "modified": "2024-12-02T15:31:39Z", + "modified": "2024-12-11T21:31:57Z", "published": "2024-12-02T15:31:39Z", "aliases": [ "CVE-2024-53117" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nvirtio/vsock: Improve MSG_ZEROCOPY error handling\n\nAdd a missing kfree_skb() to prevent memory leaks.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-02T14:15:12Z" diff --git a/advisories/unreviewed/2024/12/GHSA-8x6v-8q4g-xh9f/GHSA-8x6v-8q4g-xh9f.json b/advisories/unreviewed/2024/12/GHSA-8x6v-8q4g-xh9f/GHSA-8x6v-8q4g-xh9f.json index 5149595d6e1..fc69061ee25 100644 --- a/advisories/unreviewed/2024/12/GHSA-8x6v-8q4g-xh9f/GHSA-8x6v-8q4g-xh9f.json +++ b/advisories/unreviewed/2024/12/GHSA-8x6v-8q4g-xh9f/GHSA-8x6v-8q4g-xh9f.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8x6v-8q4g-xh9f", - "modified": "2024-12-02T15:31:39Z", + "modified": "2024-12-11T21:31:57Z", "published": "2024-12-02T15:31:39Z", "aliases": [ "CVE-2024-53113" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm: fix NULL pointer dereference in alloc_pages_bulk_noprof\n\nWe triggered a NULL pointer dereference for ac.preferred_zoneref->zone in\nalloc_pages_bulk_noprof() when the task is migrated between cpusets.\n\nWhen cpuset is enabled, in prepare_alloc_pages(), ac->nodemask may be\n¤t->mems_allowed. when first_zones_zonelist() is called to find\npreferred_zoneref, the ac->nodemask may be modified concurrently if the\ntask is migrated between different cpusets. Assuming we have 2 NUMA Node,\nwhen traversing Node1 in ac->zonelist, the nodemask is 2, and when\ntraversing Node2 in ac->zonelist, the nodemask is 1. As a result, the\nac->preferred_zoneref points to NULL zone.\n\nIn alloc_pages_bulk_noprof(), for_each_zone_zonelist_nodemask() finds a\nallowable zone and calls zonelist_node_idx(ac.preferred_zoneref), leading\nto NULL pointer dereference.\n\n__alloc_pages_noprof() fixes this issue by checking NULL pointer in commit\nea57485af8f4 (\"mm, page_alloc: fix check for NULL preferred_zone\") and\ncommit df76cee6bbeb (\"mm, page_alloc: remove redundant checks from alloc\nfastpath\").\n\nTo fix it, check NULL pointer for preferred_zoneref->zone.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-02T14:15:12Z" diff --git a/advisories/unreviewed/2024/12/GHSA-96gv-mmp8-mqx5/GHSA-96gv-mmp8-mqx5.json b/advisories/unreviewed/2024/12/GHSA-96gv-mmp8-mqx5/GHSA-96gv-mmp8-mqx5.json index 8bc9457781a..91ebacc8a17 100644 --- a/advisories/unreviewed/2024/12/GHSA-96gv-mmp8-mqx5/GHSA-96gv-mmp8-mqx5.json +++ b/advisories/unreviewed/2024/12/GHSA-96gv-mmp8-mqx5/GHSA-96gv-mmp8-mqx5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-96gv-mmp8-mqx5", - "modified": "2024-12-02T15:31:39Z", + "modified": "2024-12-11T21:31:57Z", "published": "2024-12-02T15:31:39Z", "aliases": [ "CVE-2024-53119" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nvirtio/vsock: Fix accept_queue memory leak\n\nAs the final stages of socket destruction may be delayed, it is possible\nthat virtio_transport_recv_listen() will be called after the accept_queue\nhas been flushed, but before the SOCK_DONE flag has been set. As a result,\nsockets enqueued after the flush would remain unremoved, leading to a\nmemory leak.\n\nvsock_release\n __vsock_release\n lock\n virtio_transport_release\n virtio_transport_close\n schedule_delayed_work(close_work)\n sk_shutdown = SHUTDOWN_MASK\n(!) flush accept_queue\n release\n virtio_transport_recv_pkt\n vsock_find_bound_socket\n lock\n if flag(SOCK_DONE) return\n virtio_transport_recv_listen\n child = vsock_create_connected\n (!) vsock_enqueue_accept(child)\n release\nclose_work\n lock\n virtio_transport_do_close\n set_flag(SOCK_DONE)\n virtio_transport_remove_sock\n vsock_remove_sock\n vsock_remove_bound\n release\n\nIntroduce a sk_shutdown check to disallow vsock_enqueue_accept() during\nsocket destruction.\n\nunreferenced object 0xffff888109e3f800 (size 2040):\n comm \"kworker/5:2\", pid 371, jiffies 4294940105\n hex dump (first 32 bytes):\n 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n 28 00 0b 40 00 00 00 00 00 00 00 00 00 00 00 00 (..@............\n backtrace (crc 9e5f4e84):\n [] kmem_cache_alloc_noprof+0x2c1/0x360\n [] sk_prot_alloc+0x30/0x120\n [] sk_alloc+0x2c/0x4b0\n [] __vsock_create.constprop.0+0x2a/0x310\n [] virtio_transport_recv_pkt+0x4dc/0x9a0\n [] vsock_loopback_work+0xfd/0x140\n [] process_one_work+0x20c/0x570\n [] worker_thread+0x1bf/0x3a0\n [] kthread+0xdd/0x110\n [] ret_from_fork+0x2d/0x50\n [] ret_from_fork_asm+0x1a/0x30", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-02T14:15:12Z" diff --git a/advisories/unreviewed/2024/12/GHSA-c7fm-gwfm-q8c7/GHSA-c7fm-gwfm-q8c7.json b/advisories/unreviewed/2024/12/GHSA-c7fm-gwfm-q8c7/GHSA-c7fm-gwfm-q8c7.json index af27b0d77a1..14c7e39d0b6 100644 --- a/advisories/unreviewed/2024/12/GHSA-c7fm-gwfm-q8c7/GHSA-c7fm-gwfm-q8c7.json +++ b/advisories/unreviewed/2024/12/GHSA-c7fm-gwfm-q8c7/GHSA-c7fm-gwfm-q8c7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c7fm-gwfm-q8c7", - "modified": "2024-12-02T15:31:39Z", + "modified": "2024-12-11T21:31:57Z", "published": "2024-12-02T15:31:39Z", "aliases": [ "CVE-2024-53124" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: fix data-races around sk->sk_forward_alloc\n\nSyzkaller reported this warning:\n ------------[ cut here ]------------\n WARNING: CPU: 0 PID: 16 at net/ipv4/af_inet.c:156 inet_sock_destruct+0x1c5/0x1e0\n Modules linked in:\n CPU: 0 UID: 0 PID: 16 Comm: ksoftirqd/0 Not tainted 6.12.0-rc5 #26\n Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014\n RIP: 0010:inet_sock_destruct+0x1c5/0x1e0\n Code: 24 12 4c 89 e2 5b 48 c7 c7 98 ec bb 82 41 5c e9 d1 18 17 ff 4c 89 e6 5b 48 c7 c7 d0 ec bb 82 41 5c e9 bf 18 17 ff 0f 0b eb 83 <0f> 0b eb 97 0f 0b eb 87 0f 0b e9 68 ff ff ff 66 66 2e 0f 1f 84 00\n RSP: 0018:ffffc9000008bd90 EFLAGS: 00010206\n RAX: 0000000000000300 RBX: ffff88810b172a90 RCX: 0000000000000007\n RDX: 0000000000000002 RSI: 0000000000000300 RDI: ffff88810b172a00\n RBP: ffff88810b172a00 R08: ffff888104273c00 R09: 0000000000100007\n R10: 0000000000020000 R11: 0000000000000006 R12: ffff88810b172a00\n R13: 0000000000000004 R14: 0000000000000000 R15: ffff888237c31f78\n FS: 0000000000000000(0000) GS:ffff888237c00000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 00007ffc63fecac8 CR3: 000000000342e000 CR4: 00000000000006f0\n DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n Call Trace:\n \n ? __warn+0x88/0x130\n ? inet_sock_destruct+0x1c5/0x1e0\n ? report_bug+0x18e/0x1a0\n ? handle_bug+0x53/0x90\n ? exc_invalid_op+0x18/0x70\n ? asm_exc_invalid_op+0x1a/0x20\n ? inet_sock_destruct+0x1c5/0x1e0\n __sk_destruct+0x2a/0x200\n rcu_do_batch+0x1aa/0x530\n ? rcu_do_batch+0x13b/0x530\n rcu_core+0x159/0x2f0\n handle_softirqs+0xd3/0x2b0\n ? __pfx_smpboot_thread_fn+0x10/0x10\n run_ksoftirqd+0x25/0x30\n smpboot_thread_fn+0xdd/0x1d0\n kthread+0xd3/0x100\n ? __pfx_kthread+0x10/0x10\n ret_from_fork+0x34/0x50\n ? __pfx_kthread+0x10/0x10\n ret_from_fork_asm+0x1a/0x30\n \n ---[ end trace 0000000000000000 ]---\n\nIts possible that two threads call tcp_v6_do_rcv()/sk_forward_alloc_add()\nconcurrently when sk->sk_state == TCP_LISTEN with sk->sk_lock unlocked,\nwhich triggers a data-race around sk->sk_forward_alloc:\ntcp_v6_rcv\n tcp_v6_do_rcv\n skb_clone_and_charge_r\n sk_rmem_schedule\n __sk_mem_schedule\n sk_forward_alloc_add()\n skb_set_owner_r\n sk_mem_charge\n sk_forward_alloc_add()\n __kfree_skb\n skb_release_all\n skb_release_head_state\n sock_rfree\n sk_mem_uncharge\n sk_forward_alloc_add()\n sk_mem_reclaim\n // set local var reclaimable\n __sk_mem_reclaim\n sk_forward_alloc_add()\n\nIn this syzkaller testcase, two threads call\ntcp_v6_do_rcv() with skb->truesize=768, the sk_forward_alloc changes like\nthis:\n (cpu 1) | (cpu 2) | sk_forward_alloc\n ... | ... | 0\n __sk_mem_schedule() | | +4096 = 4096\n | __sk_mem_schedule() | +4096 = 8192\n sk_mem_charge() | | -768 = 7424\n | sk_mem_charge() | -768 = 6656\n ... | ... |\n sk_mem_uncharge() | | +768 = 7424\n reclaimable=7424 | |\n | sk_mem_uncharge() | +768 = 8192\n | reclaimable=8192 |\n __sk_mem_reclaim() | | -4096 = 4096\n | __sk_mem_reclaim() | -8192 = -4096 != 0\n\nThe skb_clone_and_charge_r() should not be called in tcp_v6_do_rcv() when\nsk->sk_state is TCP_LISTEN, it happens later in tcp_v6_syn_recv_sock().\nFix the same issue in dccp_v6_do_rcv().", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-362" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-02T14:15:13Z" diff --git a/advisories/unreviewed/2024/12/GHSA-f679-5wx9-qfmm/GHSA-f679-5wx9-qfmm.json b/advisories/unreviewed/2024/12/GHSA-f679-5wx9-qfmm/GHSA-f679-5wx9-qfmm.json index 6aaa26254f4..74170f77d5a 100644 --- a/advisories/unreviewed/2024/12/GHSA-f679-5wx9-qfmm/GHSA-f679-5wx9-qfmm.json +++ b/advisories/unreviewed/2024/12/GHSA-f679-5wx9-qfmm/GHSA-f679-5wx9-qfmm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-f679-5wx9-qfmm", - "modified": "2024-12-02T15:31:39Z", + "modified": "2024-12-11T21:31:57Z", "published": "2024-12-02T15:31:39Z", "aliases": [ "CVE-2024-53118" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nvsock: Fix sk_error_queue memory leak\n\nKernel queues MSG_ZEROCOPY completion notifications on the error queue.\nWhere they remain, until explicitly recv()ed. To prevent memory leaks,\nclean up the queue when the socket is destroyed.\n\nunreferenced object 0xffff8881028beb00 (size 224):\n comm \"vsock_test\", pid 1218, jiffies 4294694897\n hex dump (first 32 bytes):\n 90 b0 21 17 81 88 ff ff 90 b0 21 17 81 88 ff ff ..!.......!.....\n 00 00 00 00 00 00 00 00 00 b0 21 17 81 88 ff ff ..........!.....\n backtrace (crc 6c7031ca):\n [] kmem_cache_alloc_node_noprof+0x2f7/0x370\n [] __alloc_skb+0x132/0x180\n [] sock_omalloc+0x4b/0x80\n [] msg_zerocopy_realloc+0x9e/0x240\n [] virtio_transport_send_pkt_info+0x412/0x4c0\n [] virtio_transport_stream_enqueue+0x43/0x50\n [] vsock_connectible_sendmsg+0x373/0x450\n [] ____sys_sendmsg+0x365/0x3a0\n [] ___sys_sendmsg+0x84/0xd0\n [] __sys_sendmsg+0x47/0x80\n [] do_syscall_64+0x93/0x180\n [] entry_SYSCALL_64_after_hwframe+0x76/0x7e", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-02T14:15:12Z" diff --git a/advisories/unreviewed/2024/12/GHSA-fvhh-6wh3-m386/GHSA-fvhh-6wh3-m386.json b/advisories/unreviewed/2024/12/GHSA-fvhh-6wh3-m386/GHSA-fvhh-6wh3-m386.json index de2ad5db1ea..a1eb3190a0a 100644 --- a/advisories/unreviewed/2024/12/GHSA-fvhh-6wh3-m386/GHSA-fvhh-6wh3-m386.json +++ b/advisories/unreviewed/2024/12/GHSA-fvhh-6wh3-m386/GHSA-fvhh-6wh3-m386.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fvhh-6wh3-m386", - "modified": "2024-12-02T15:31:39Z", + "modified": "2024-12-11T21:31:57Z", "published": "2024-12-02T15:31:39Z", "aliases": [ "CVE-2024-53120" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: CT: Fix null-ptr-deref in add rule err flow\n\nIn error flow of mlx5_tc_ct_entry_add_rule(), in case ct_rule_add()\ncallback returns error, zone_rule->attr is used uninitiated. Fix it to\nuse attr which has the needed pointer value.\n\nKernel log:\n BUG: kernel NULL pointer dereference, address: 0000000000000110\n RIP: 0010:mlx5_tc_ct_entry_add_rule+0x2b1/0x2f0 [mlx5_core]\n…\n Call Trace:\n \n ? __die+0x20/0x70\n ? page_fault_oops+0x150/0x3e0\n ? exc_page_fault+0x74/0x140\n ? asm_exc_page_fault+0x22/0x30\n ? mlx5_tc_ct_entry_add_rule+0x2b1/0x2f0 [mlx5_core]\n ? mlx5_tc_ct_entry_add_rule+0x1d5/0x2f0 [mlx5_core]\n mlx5_tc_ct_block_flow_offload+0xc6a/0xf90 [mlx5_core]\n ? nf_flow_offload_tuple+0xd8/0x190 [nf_flow_table]\n nf_flow_offload_tuple+0xd8/0x190 [nf_flow_table]\n flow_offload_work_handler+0x142/0x320 [nf_flow_table]\n ? finish_task_switch.isra.0+0x15b/0x2b0\n process_one_work+0x16c/0x320\n worker_thread+0x28c/0x3a0\n ? __pfx_worker_thread+0x10/0x10\n kthread+0xb8/0xf0\n ? __pfx_kthread+0x10/0x10\n ret_from_fork+0x2d/0x50\n ? __pfx_kthread+0x10/0x10\n ret_from_fork_asm+0x1a/0x30\n ", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-02T14:15:12Z" diff --git a/advisories/unreviewed/2024/12/GHSA-gh2q-9gh5-p9fx/GHSA-gh2q-9gh5-p9fx.json b/advisories/unreviewed/2024/12/GHSA-gh2q-9gh5-p9fx/GHSA-gh2q-9gh5-p9fx.json index 788f0b8ea0a..60b21eb61a1 100644 --- a/advisories/unreviewed/2024/12/GHSA-gh2q-9gh5-p9fx/GHSA-gh2q-9gh5-p9fx.json +++ b/advisories/unreviewed/2024/12/GHSA-gh2q-9gh5-p9fx/GHSA-gh2q-9gh5-p9fx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gh2q-9gh5-p9fx", - "modified": "2024-12-05T12:31:26Z", + "modified": "2024-12-11T21:31:57Z", "published": "2024-12-02T15:31:39Z", "aliases": [ "CVE-2024-53112" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: uncache inode which has failed entering the group\n\nSyzbot has reported the following BUG:\n\nkernel BUG at fs/ocfs2/uptodate.c:509!\n...\nCall Trace:\n \n ? __die_body+0x5f/0xb0\n ? die+0x9e/0xc0\n ? do_trap+0x15a/0x3a0\n ? ocfs2_set_new_buffer_uptodate+0x145/0x160\n ? do_error_trap+0x1dc/0x2c0\n ? ocfs2_set_new_buffer_uptodate+0x145/0x160\n ? __pfx_do_error_trap+0x10/0x10\n ? handle_invalid_op+0x34/0x40\n ? ocfs2_set_new_buffer_uptodate+0x145/0x160\n ? exc_invalid_op+0x38/0x50\n ? asm_exc_invalid_op+0x1a/0x20\n ? ocfs2_set_new_buffer_uptodate+0x2e/0x160\n ? ocfs2_set_new_buffer_uptodate+0x144/0x160\n ? ocfs2_set_new_buffer_uptodate+0x145/0x160\n ocfs2_group_add+0x39f/0x15a0\n ? __pfx_ocfs2_group_add+0x10/0x10\n ? __pfx_lock_acquire+0x10/0x10\n ? mnt_get_write_access+0x68/0x2b0\n ? __pfx_lock_release+0x10/0x10\n ? rcu_read_lock_any_held+0xb7/0x160\n ? __pfx_rcu_read_lock_any_held+0x10/0x10\n ? smack_log+0x123/0x540\n ? mnt_get_write_access+0x68/0x2b0\n ? mnt_get_write_access+0x68/0x2b0\n ? mnt_get_write_access+0x226/0x2b0\n ocfs2_ioctl+0x65e/0x7d0\n ? __pfx_ocfs2_ioctl+0x10/0x10\n ? smack_file_ioctl+0x29e/0x3a0\n ? __pfx_smack_file_ioctl+0x10/0x10\n ? lockdep_hardirqs_on_prepare+0x43d/0x780\n ? __pfx_lockdep_hardirqs_on_prepare+0x10/0x10\n ? __pfx_ocfs2_ioctl+0x10/0x10\n __se_sys_ioctl+0xfb/0x170\n do_syscall_64+0xf3/0x230\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n...\n \n\nWhen 'ioctl(OCFS2_IOC_GROUP_ADD, ...)' has failed for the particular\ninode in 'ocfs2_verify_group_and_input()', corresponding buffer head\nremains cached and subsequent call to the same 'ioctl()' for the same\ninode issues the BUG() in 'ocfs2_set_new_buffer_uptodate()' (trying\nto cache the same buffer head of that inode). Fix this by uncaching\nthe buffer head with 'ocfs2_remove_from_cache()' on error path in\n'ocfs2_group_add()'.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -37,7 +42,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-02T14:15:11Z" diff --git a/advisories/unreviewed/2024/12/GHSA-gwx2-9h8p-phf8/GHSA-gwx2-9h8p-phf8.json b/advisories/unreviewed/2024/12/GHSA-gwx2-9h8p-phf8/GHSA-gwx2-9h8p-phf8.json index c9803d353b4..24006afe152 100644 --- a/advisories/unreviewed/2024/12/GHSA-gwx2-9h8p-phf8/GHSA-gwx2-9h8p-phf8.json +++ b/advisories/unreviewed/2024/12/GHSA-gwx2-9h8p-phf8/GHSA-gwx2-9h8p-phf8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gwx2-9h8p-phf8", - "modified": "2024-12-02T15:31:39Z", + "modified": "2024-12-11T21:31:57Z", "published": "2024-12-02T15:31:39Z", "aliases": [ "CVE-2024-53121" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: fs, lock FTE when checking if active\n\nThe referenced commits introduced a two-step process for deleting FTEs:\n\n- Lock the FTE, delete it from hardware, set the hardware deletion function\n to NULL and unlock the FTE.\n- Lock the parent flow group, delete the software copy of the FTE, and\n remove it from the xarray.\n\nHowever, this approach encounters a race condition if a rule with the same\nmatch value is added simultaneously. In this scenario, fs_core may set the\nhardware deletion function to NULL prematurely, causing a panic during\nsubsequent rule deletions.\n\nTo prevent this, ensure the active flag of the FTE is checked under a lock,\nwhich will prevent the fs_core layer from attaching a new steering rule to\nan FTE that is in the process of deletion.\n\n[ 438.967589] MOSHE: 2496 mlx5_del_flow_rules del_hw_func\n[ 438.968205] ------------[ cut here ]------------\n[ 438.968654] refcount_t: decrement hit 0; leaking memory.\n[ 438.969249] WARNING: CPU: 0 PID: 8957 at lib/refcount.c:31 refcount_warn_saturate+0xfb/0x110\n[ 438.970054] Modules linked in: act_mirred cls_flower act_gact sch_ingress openvswitch nsh mlx5_vdpa vringh vhost_iotlb vdpa mlx5_ib mlx5_core xt_conntrack xt_MASQUERADE nf_conntrack_netlink nfnetlink xt_addrtype iptable_nat nf_nat br_netfilter rpcsec_gss_krb5 auth_rpcgss oid_registry overlay rpcrdma rdma_ucm ib_iser libiscsi scsi_transport_iscsi ib_umad rdma_cm ib_ipoib iw_cm ib_cm ib_uverbs ib_core zram zsmalloc fuse [last unloaded: cls_flower]\n[ 438.973288] CPU: 0 UID: 0 PID: 8957 Comm: tc Not tainted 6.12.0-rc1+ #8\n[ 438.973888] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014\n[ 438.974874] RIP: 0010:refcount_warn_saturate+0xfb/0x110\n[ 438.975363] Code: 40 66 3b 82 c6 05 16 e9 4d 01 01 e8 1f 7c a0 ff 0f 0b c3 cc cc cc cc 48 c7 c7 10 66 3b 82 c6 05 fd e8 4d 01 01 e8 05 7c a0 ff <0f> 0b c3 cc cc cc cc 66 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 00 90\n[ 438.976947] RSP: 0018:ffff888124a53610 EFLAGS: 00010286\n[ 438.977446] RAX: 0000000000000000 RBX: ffff888119d56de0 RCX: 0000000000000000\n[ 438.978090] RDX: ffff88852c828700 RSI: ffff88852c81b3c0 RDI: ffff88852c81b3c0\n[ 438.978721] RBP: ffff888120fa0e88 R08: 0000000000000000 R09: ffff888124a534b0\n[ 438.979353] R10: 0000000000000001 R11: 0000000000000001 R12: ffff888119d56de0\n[ 438.979979] R13: ffff888120fa0ec0 R14: ffff888120fa0ee8 R15: ffff888119d56de0\n[ 438.980607] FS: 00007fe6dcc0f800(0000) GS:ffff88852c800000(0000) knlGS:0000000000000000\n[ 438.983984] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 438.984544] CR2: 00000000004275e0 CR3: 0000000186982001 CR4: 0000000000372eb0\n[ 438.985205] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n[ 438.985842] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n[ 438.986507] Call Trace:\n[ 438.986799] \n[ 438.987070] ? __warn+0x7d/0x110\n[ 438.987426] ? refcount_warn_saturate+0xfb/0x110\n[ 438.987877] ? report_bug+0x17d/0x190\n[ 438.988261] ? prb_read_valid+0x17/0x20\n[ 438.988659] ? handle_bug+0x53/0x90\n[ 438.989054] ? exc_invalid_op+0x14/0x70\n[ 438.989458] ? asm_exc_invalid_op+0x16/0x20\n[ 438.989883] ? refcount_warn_saturate+0xfb/0x110\n[ 438.990348] mlx5_del_flow_rules+0x2f7/0x340 [mlx5_core]\n[ 438.990932] __mlx5_eswitch_del_rule+0x49/0x170 [mlx5_core]\n[ 438.991519] ? mlx5_lag_is_sriov+0x3c/0x50 [mlx5_core]\n[ 438.992054] ? xas_load+0x9/0xb0\n[ 438.992407] mlx5e_tc_rule_unoffload+0x45/0xe0 [mlx5_core]\n[ 438.993037] mlx5e_tc_del_fdb_flow+0x2a6/0x2e0 [mlx5_core]\n[ 438.993623] mlx5e_flow_put+0x29/0x60 [mlx5_core]\n[ 438.994161] mlx5e_delete_flower+0x261/0x390 [mlx5_core]\n[ 438.994728] tc_setup_cb_destroy+0xb9/0x190\n[ 438.995150] fl_hw_destroy_filter+0x94/0xc0 [cls_flower]\n[ 438.995650] fl_change+0x11a4/0x13c0 [cls_flower]\n[ 438.996105] tc_new_tfilter+0x347/0xbc0\n[ 438.996503] ? __\n---truncated---", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-362" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-02T14:15:12Z" diff --git a/advisories/unreviewed/2024/12/GHSA-q56w-m7h5-j43f/GHSA-q56w-m7h5-j43f.json b/advisories/unreviewed/2024/12/GHSA-q56w-m7h5-j43f/GHSA-q56w-m7h5-j43f.json index 3e506cd8ef3..7deaa3c1619 100644 --- a/advisories/unreviewed/2024/12/GHSA-q56w-m7h5-j43f/GHSA-q56w-m7h5-j43f.json +++ b/advisories/unreviewed/2024/12/GHSA-q56w-m7h5-j43f/GHSA-q56w-m7h5-j43f.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-q56w-m7h5-j43f", - "modified": "2024-12-02T15:31:39Z", + "modified": "2024-12-11T21:31:57Z", "published": "2024-12-02T15:31:39Z", "aliases": [ "CVE-2024-53111" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/mremap: fix address wraparound in move_page_tables()\n\nOn 32-bit platforms, it is possible for the expression `len + old_addr <\nold_end` to be false-positive if `len + old_addr` wraps around. \n`old_addr` is the cursor in the old range up to which page table entries\nhave been moved; so if the operation succeeded, `old_addr` is the *end* of\nthe old region, and adding `len` to it can wrap.\n\nThe overflow causes mremap() to mistakenly believe that PTEs have been\ncopied; the consequence is that mremap() bails out, but doesn't move the\nPTEs back before the new VMA is unmapped, causing anonymous pages in the\nregion to be lost. So basically if userspace tries to mremap() a\nprivate-anon region and hits this bug, mremap() will return an error and\nthe private-anon region's contents appear to have been zeroed.\n\nThe idea of this check is that `old_end - len` is the original start\naddress, and writing the check that way also makes it easier to read; so\nfix the check by rearranging the comparison accordingly.\n\n(An alternate fix would be to refactor this function by introducing an\n\"orig_old_start\" variable or such.)\n\n\nTested in a VM with a 32-bit X86 kernel; without the patch:\n\n```\nuser@horn:~/big_mremap$ cat test.c\n#define _GNU_SOURCE\n#include \n#include \n#include \n#include \n\n#define ADDR1 ((void*)0x60000000)\n#define ADDR2 ((void*)0x10000000)\n#define SIZE 0x50000000uL\n\nint main(void) {\n unsigned char *p1 = mmap(ADDR1, SIZE, PROT_READ|PROT_WRITE,\n MAP_ANONYMOUS|MAP_PRIVATE|MAP_FIXED_NOREPLACE, -1, 0);\n if (p1 == MAP_FAILED)\n err(1, \"mmap 1\");\n unsigned char *p2 = mmap(ADDR2, SIZE, PROT_NONE,\n MAP_ANONYMOUS|MAP_PRIVATE|MAP_FIXED_NOREPLACE, -1, 0);\n if (p2 == MAP_FAILED)\n err(1, \"mmap 2\");\n *p1 = 0x41;\n printf(\"first char is 0x%02hhx\\n\", *p1);\n unsigned char *p3 = mremap(p1, SIZE, SIZE,\n MREMAP_MAYMOVE|MREMAP_FIXED, p2);\n if (p3 == MAP_FAILED) {\n printf(\"mremap() failed; first char is 0x%02hhx\\n\", *p1);\n } else {\n printf(\"mremap() succeeded; first char is 0x%02hhx\\n\", *p3);\n }\n}\nuser@horn:~/big_mremap$ gcc -static -o test test.c\nuser@horn:~/big_mremap$ setarch -R ./test\nfirst char is 0x41\nmremap() failed; first char is 0x00\n```\n\nWith the patch:\n\n```\nuser@horn:~/big_mremap$ setarch -R ./test\nfirst char is 0x41\nmremap() succeeded; first char is 0x41\n```", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-190" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-02T14:15:11Z" diff --git a/advisories/unreviewed/2024/12/GHSA-rgw8-cw3p-qv66/GHSA-rgw8-cw3p-qv66.json b/advisories/unreviewed/2024/12/GHSA-rgw8-cw3p-qv66/GHSA-rgw8-cw3p-qv66.json index a4817b362a6..21b7200ddd0 100644 --- a/advisories/unreviewed/2024/12/GHSA-rgw8-cw3p-qv66/GHSA-rgw8-cw3p-qv66.json +++ b/advisories/unreviewed/2024/12/GHSA-rgw8-cw3p-qv66/GHSA-rgw8-cw3p-qv66.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rgw8-cw3p-qv66", - "modified": "2024-12-02T15:31:39Z", + "modified": "2024-12-11T21:31:57Z", "published": "2024-12-02T15:31:39Z", "aliases": [ "CVE-2024-53114" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/CPU/AMD: Clear virtualized VMLOAD/VMSAVE on Zen4 client\n\nA number of Zen4 client SoCs advertise the ability to use virtualized\nVMLOAD/VMSAVE, but using these instructions is reported to be a cause\nof a random host reboot.\n\nThese instructions aren't intended to be advertised on Zen4 client\nso clear the capability.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -25,7 +30,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-02T14:15:12Z" diff --git a/advisories/unreviewed/2024/12/GHSA-vr58-5gj9-563m/GHSA-vr58-5gj9-563m.json b/advisories/unreviewed/2024/12/GHSA-vr58-5gj9-563m/GHSA-vr58-5gj9-563m.json index 454aec6d4a6..dc5ce2102fb 100644 --- a/advisories/unreviewed/2024/12/GHSA-vr58-5gj9-563m/GHSA-vr58-5gj9-563m.json +++ b/advisories/unreviewed/2024/12/GHSA-vr58-5gj9-563m/GHSA-vr58-5gj9-563m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vr58-5gj9-563m", - "modified": "2024-12-02T15:31:39Z", + "modified": "2024-12-11T21:31:57Z", "published": "2024-12-02T15:31:39Z", "aliases": [ "CVE-2024-53116" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/panthor: Fix handling of partial GPU mapping of BOs\n\nThis commit fixes the bug in the handling of partial mapping of the\nbuffer objects to the GPU, which caused kernel warnings.\n\nPanthor didn't correctly handle the case where the partial mapping\nspanned multiple scatterlists and the mapping offset didn't point\nto the 1st page of starting scatterlist. The offset variable was\nnot cleared after reaching the starting scatterlist.\n\nFollowing warning messages were seen.\nWARNING: CPU: 1 PID: 650 at drivers/iommu/io-pgtable-arm.c:659 __arm_lpae_unmap+0x254/0x5a0\n\npc : __arm_lpae_unmap+0x254/0x5a0\nlr : __arm_lpae_unmap+0x2cc/0x5a0\n\nCall trace:\n __arm_lpae_unmap+0x254/0x5a0\n __arm_lpae_unmap+0x108/0x5a0\n __arm_lpae_unmap+0x108/0x5a0\n __arm_lpae_unmap+0x108/0x5a0\n arm_lpae_unmap_pages+0x80/0xa0\n panthor_vm_unmap_pages+0xac/0x1c8 [panthor]\n panthor_gpuva_sm_step_unmap+0x4c/0xc8 [panthor]\n op_unmap_cb.isra.23.constprop.30+0x54/0x80\n __drm_gpuvm_sm_unmap+0x184/0x1c8\n drm_gpuvm_sm_unmap+0x40/0x60\n panthor_vm_exec_op+0xa8/0x120 [panthor]\n panthor_vm_bind_exec_sync_op+0xc4/0xe8 [panthor]\n panthor_ioctl_vm_bind+0x10c/0x170 [panthor]\n drm_ioctl_kernel+0xbc/0x138\n drm_ioctl+0x210/0x4b0\n __arm64_sys_ioctl+0xb0/0xf8\n invoke_syscall+0x4c/0x110\n el0_svc_common.constprop.1+0x98/0xf8\n do_el0_svc+0x24/0x38\n el0_svc+0x34/0xc8\n el0t_64_sync_handler+0xa0/0xc8\n el0t_64_sync+0x174/0x178\n\npanthor : [drm] drm_WARN_ON(unmapped_sz != pgsize * pgcount)\nWARNING: CPU: 1 PID: 650 at drivers/gpu/drm/panthor/panthor_mmu.c:922 panthor_vm_unmap_pages+0x124/0x1c8 [panthor]\n\npc : panthor_vm_unmap_pages+0x124/0x1c8 [panthor]\nlr : panthor_vm_unmap_pages+0x124/0x1c8 [panthor]\n\npanthor : [drm] *ERROR* failed to unmap range ffffa388f000-ffffa3890000 (requested range ffffa388c000-ffffa3890000)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -25,7 +30,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-02T14:15:12Z" diff --git a/advisories/unreviewed/2024/12/GHSA-w78w-44c5-7mwx/GHSA-w78w-44c5-7mwx.json b/advisories/unreviewed/2024/12/GHSA-w78w-44c5-7mwx/GHSA-w78w-44c5-7mwx.json index 4f3ab7ad814..6e5e2f08aef 100644 --- a/advisories/unreviewed/2024/12/GHSA-w78w-44c5-7mwx/GHSA-w78w-44c5-7mwx.json +++ b/advisories/unreviewed/2024/12/GHSA-w78w-44c5-7mwx/GHSA-w78w-44c5-7mwx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-w78w-44c5-7mwx", - "modified": "2024-12-02T15:31:39Z", + "modified": "2024-12-11T21:31:57Z", "published": "2024-12-02T15:31:39Z", "aliases": [ "CVE-2024-53110" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nvp_vdpa: fix id_table array not null terminated error\n\nAllocate one extra virtio_device_id as null terminator, otherwise\nvdpa_mgmtdev_get_classes() may iterate multiple times and visit\nundefined memory.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -33,7 +38,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-02T14:15:11Z" diff --git a/advisories/unreviewed/2024/12/GHSA-x34g-xjxv-fc48/GHSA-x34g-xjxv-fc48.json b/advisories/unreviewed/2024/12/GHSA-x34g-xjxv-fc48/GHSA-x34g-xjxv-fc48.json index 2fff0ed3b99..ebdc55d080d 100644 --- a/advisories/unreviewed/2024/12/GHSA-x34g-xjxv-fc48/GHSA-x34g-xjxv-fc48.json +++ b/advisories/unreviewed/2024/12/GHSA-x34g-xjxv-fc48/GHSA-x34g-xjxv-fc48.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x34g-xjxv-fc48", - "modified": "2024-12-02T15:31:39Z", + "modified": "2024-12-11T21:31:57Z", "published": "2024-12-02T15:31:39Z", "aliases": [ "CVE-2024-53122" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: cope racing subflow creation in mptcp_rcv_space_adjust\n\nAdditional active subflows - i.e. created by the in kernel path\nmanager - are included into the subflow list before starting the\n3whs.\n\nA racing recvmsg() spooling data received on an already established\nsubflow would unconditionally call tcp_cleanup_rbuf() on all the\ncurrent subflows, potentially hitting a divide by zero error on\nthe newly created ones.\n\nExplicitly check that the subflow is in a suitable state before\ninvoking tcp_cleanup_rbuf().", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-362" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-02T14:15:13Z"