From 3bda57a4b2cf91fa89b6425a9635db36cb3e3048 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 8 Aug 2024 15:33:27 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-82jv-mjpv-6mh8.json | 9 +++-- .../GHSA-2j66-vp53-phjj.json | 11 ++++-- .../GHSA-485m-923f-95wx.json | 3 +- .../GHSA-75c9-4w8r-55h3.json | 2 +- .../GHSA-97jv-xf89-qx5j.json | 1 + .../GHSA-f6rh-pgcv-pqrj.json | 2 +- .../GHSA-j65j-gpfr-72jv.json | 1 + .../GHSA-x6rq-p572-3385.json | 2 +- .../GHSA-26mh-xhv7-944g.json | 11 ++++-- .../GHSA-7j79-jvg5-vc33.json | 3 +- .../GHSA-9xpj-wgrg-m9r4.json | 3 +- .../GHSA-hg8f-ghpp-qpmq.json | 11 ++++-- .../GHSA-j378-rg6j-2ff4.json | 11 ++++-- .../GHSA-pqmv-6w3c-fgq2.json | 3 +- .../GHSA-q75j-p4r8-37x7.json | 11 ++++-- .../GHSA-q92f-2phr-4853.json | 11 ++++-- .../GHSA-r968-6g59-6626.json | 9 +++-- .../GHSA-w439-8pfm-9pjm.json | 3 +- .../GHSA-2pv9-pqcj-rmfm.json | 11 ++++-- .../GHSA-2rr5-68hg-rwmh.json | 9 +++-- .../GHSA-3c6g-7v4g-5xcm.json | 38 ++++++++++++++++++ .../GHSA-4rc5-7v2h-gq36.json | 9 +++-- .../GHSA-54w4-6j43-whvq.json | 11 ++++-- .../GHSA-557r-rm2w-qvrj.json | 11 ++++-- .../GHSA-5hgw-6w8f-3f58.json | 11 ++++-- .../GHSA-5jp3-wp5v-5363.json | 9 +++-- .../GHSA-5vqw-wppf-x433.json | 11 ++++-- .../GHSA-67jr-crfx-vm73.json | 9 +++-- .../GHSA-6p6f-gc59-4w3f.json | 11 ++++-- .../GHSA-762p-xx25-g6mq.json | 11 ++++-- .../GHSA-7j6j-8jww-jc3g.json | 9 +++-- .../GHSA-899c-qvc8-9hpp.json | 11 ++++-- .../GHSA-9hxq-vv35-9r5r.json | 9 +++-- .../GHSA-ccg8-wmfg-jr2m.json | 2 +- .../GHSA-cg4j-f388-m354.json | 11 ++++-- .../GHSA-cq28-4xvm-6h6g.json | 11 ++++-- .../GHSA-frq3-h54x-6725.json | 11 ++++-- .../GHSA-fxrf-h5v6-vcj7.json | 11 ++++-- .../GHSA-g474-4q7c-cx7q.json | 9 +++-- .../GHSA-g92r-8x2f-9v8m.json | 11 ++++-- .../GHSA-g9q3-4xq5-wqcj.json | 9 +++-- .../GHSA-ggh4-5hvc-554r.json | 11 ++++-- .../GHSA-hp2r-hjvj-mq3f.json | 9 +++-- .../GHSA-j9x3-2fgg-9qgj.json | 9 +++-- .../GHSA-jxv8-jmp2-87p8.json | 11 ++++-- .../GHSA-m475-c2qh-xg8v.json | 11 ++++-- .../GHSA-m4qj-p3wv-ph7c.json | 11 ++++-- .../GHSA-m5xv-fggp-4j5r.json | 38 ++++++++++++++++++ .../GHSA-mvr5-c43p-gf5m.json | 2 +- .../GHSA-pjph-5c8j-wm5g.json | 9 +++-- .../GHSA-qmvr-hqqr-gjg7.json | 9 +++-- .../GHSA-rx9p-j44h-69cp.json | 11 ++++-- .../GHSA-vfcg-vh6j-gg8j.json | 39 +++++++++++++++++++ .../GHSA-vfhx-cqwc-hf57.json | 11 ++++-- .../GHSA-wvp3-f576-fpv8.json | 11 ++++-- .../GHSA-x7x3-mj9c-m6x7.json | 9 +++-- .../GHSA-xg77-wrvc-q75c.json | 9 +++-- 57 files changed, 410 insertions(+), 162 deletions(-) create mode 100644 advisories/unreviewed/2024/08/GHSA-3c6g-7v4g-5xcm/GHSA-3c6g-7v4g-5xcm.json create mode 100644 advisories/unreviewed/2024/08/GHSA-m5xv-fggp-4j5r/GHSA-m5xv-fggp-4j5r.json create mode 100644 advisories/unreviewed/2024/08/GHSA-vfcg-vh6j-gg8j/GHSA-vfcg-vh6j-gg8j.json diff --git a/advisories/unreviewed/2022/04/GHSA-82jv-mjpv-6mh8/GHSA-82jv-mjpv-6mh8.json b/advisories/unreviewed/2022/04/GHSA-82jv-mjpv-6mh8/GHSA-82jv-mjpv-6mh8.json index 4f2dbfab666..822660f4593 100644 --- a/advisories/unreviewed/2022/04/GHSA-82jv-mjpv-6mh8/GHSA-82jv-mjpv-6mh8.json +++ b/advisories/unreviewed/2022/04/GHSA-82jv-mjpv-6mh8/GHSA-82jv-mjpv-6mh8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-82jv-mjpv-6mh8", - "modified": "2022-04-30T18:22:21Z", + "modified": "2024-08-08T15:31:26Z", "published": "2022-04-30T18:22:21Z", "aliases": [ "CVE-2002-2024" ], "details": "Horde IMP 2.2.7 allows remote attackers to obtain the full web root pathname via an HTTP request for (1) poppassd.php3, (2) login.php3?reason=chpass2, (3) spelling.php3, and (4) ldap.search.php3?ldap_serv=nonsense which leaks the information in error messages.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -33,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-219" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-2j66-vp53-phjj/GHSA-2j66-vp53-phjj.json b/advisories/unreviewed/2024/06/GHSA-2j66-vp53-phjj/GHSA-2j66-vp53-phjj.json index a5f3ed887b4..4d9af31e3a9 100644 --- a/advisories/unreviewed/2024/06/GHSA-2j66-vp53-phjj/GHSA-2j66-vp53-phjj.json +++ b/advisories/unreviewed/2024/06/GHSA-2j66-vp53-phjj/GHSA-2j66-vp53-phjj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2j66-vp53-phjj", - "modified": "2024-06-16T03:30:34Z", + "modified": "2024-08-08T15:31:26Z", "published": "2024-06-16T03:30:34Z", "aliases": [ "CVE-2024-38428" ], "details": "url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in which data that was supposed to be in the userinfo subcomponent is misinterpreted to be part of the host subcomponent.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-436" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-16T03:15:08Z" diff --git a/advisories/unreviewed/2024/06/GHSA-485m-923f-95wx/GHSA-485m-923f-95wx.json b/advisories/unreviewed/2024/06/GHSA-485m-923f-95wx/GHSA-485m-923f-95wx.json index 8d73f66e477..dfecd702126 100644 --- a/advisories/unreviewed/2024/06/GHSA-485m-923f-95wx/GHSA-485m-923f-95wx.json +++ b/advisories/unreviewed/2024/06/GHSA-485m-923f-95wx/GHSA-485m-923f-95wx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-485m-923f-95wx", - "modified": "2024-08-01T15:31:51Z", + "modified": "2024-08-08T15:31:27Z", "published": "2024-06-25T15:31:09Z", "aliases": [ "CVE-2024-37085" @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-287", "CWE-305" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/06/GHSA-75c9-4w8r-55h3/GHSA-75c9-4w8r-55h3.json b/advisories/unreviewed/2024/06/GHSA-75c9-4w8r-55h3/GHSA-75c9-4w8r-55h3.json index 7d7d6c6fc7b..e4192874398 100644 --- a/advisories/unreviewed/2024/06/GHSA-75c9-4w8r-55h3/GHSA-75c9-4w8r-55h3.json +++ b/advisories/unreviewed/2024/06/GHSA-75c9-4w8r-55h3/GHSA-75c9-4w8r-55h3.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-97jv-xf89-qx5j/GHSA-97jv-xf89-qx5j.json b/advisories/unreviewed/2024/06/GHSA-97jv-xf89-qx5j/GHSA-97jv-xf89-qx5j.json index 96c023c4645..e0c8e7c78f4 100644 --- a/advisories/unreviewed/2024/06/GHSA-97jv-xf89-qx5j/GHSA-97jv-xf89-qx5j.json +++ b/advisories/unreviewed/2024/06/GHSA-97jv-xf89-qx5j/GHSA-97jv-xf89-qx5j.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-269", "CWE-362" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/06/GHSA-f6rh-pgcv-pqrj/GHSA-f6rh-pgcv-pqrj.json b/advisories/unreviewed/2024/06/GHSA-f6rh-pgcv-pqrj/GHSA-f6rh-pgcv-pqrj.json index a4a48a39bf7..e7168fe8ec4 100644 --- a/advisories/unreviewed/2024/06/GHSA-f6rh-pgcv-pqrj/GHSA-f6rh-pgcv-pqrj.json +++ b/advisories/unreviewed/2024/06/GHSA-f6rh-pgcv-pqrj/GHSA-f6rh-pgcv-pqrj.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-862" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-j65j-gpfr-72jv/GHSA-j65j-gpfr-72jv.json b/advisories/unreviewed/2024/06/GHSA-j65j-gpfr-72jv/GHSA-j65j-gpfr-72jv.json index ca91eddd435..6df1aaea633 100644 --- a/advisories/unreviewed/2024/06/GHSA-j65j-gpfr-72jv/GHSA-j65j-gpfr-72jv.json +++ b/advisories/unreviewed/2024/06/GHSA-j65j-gpfr-72jv/GHSA-j65j-gpfr-72jv.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-269", "CWE-908" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/06/GHSA-x6rq-p572-3385/GHSA-x6rq-p572-3385.json b/advisories/unreviewed/2024/06/GHSA-x6rq-p572-3385/GHSA-x6rq-p572-3385.json index 34942ea317f..e03057f46df 100644 --- a/advisories/unreviewed/2024/06/GHSA-x6rq-p572-3385/GHSA-x6rq-p572-3385.json +++ b/advisories/unreviewed/2024/06/GHSA-x6rq-p572-3385/GHSA-x6rq-p572-3385.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-26mh-xhv7-944g/GHSA-26mh-xhv7-944g.json b/advisories/unreviewed/2024/07/GHSA-26mh-xhv7-944g/GHSA-26mh-xhv7-944g.json index 4174b59d036..dd59e42fa07 100644 --- a/advisories/unreviewed/2024/07/GHSA-26mh-xhv7-944g/GHSA-26mh-xhv7-944g.json +++ b/advisories/unreviewed/2024/07/GHSA-26mh-xhv7-944g/GHSA-26mh-xhv7-944g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-26mh-xhv7-944g", - "modified": "2024-07-30T21:31:28Z", + "modified": "2024-08-08T15:31:27Z", "published": "2024-07-30T21:31:28Z", "aliases": [ "CVE-2024-39012" ], "details": "ais-ltd strategyen v0.4.0 was discovered to contain a prototype pollution via the function mergeObjects. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-1321" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-30T20:15:04Z" diff --git a/advisories/unreviewed/2024/07/GHSA-7j79-jvg5-vc33/GHSA-7j79-jvg5-vc33.json b/advisories/unreviewed/2024/07/GHSA-7j79-jvg5-vc33/GHSA-7j79-jvg5-vc33.json index 9bfe0016e3d..36e2bfdb7d5 100644 --- a/advisories/unreviewed/2024/07/GHSA-7j79-jvg5-vc33/GHSA-7j79-jvg5-vc33.json +++ b/advisories/unreviewed/2024/07/GHSA-7j79-jvg5-vc33/GHSA-7j79-jvg5-vc33.json @@ -44,7 +44,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-259" + "CWE-259", + "CWE-798" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-9xpj-wgrg-m9r4/GHSA-9xpj-wgrg-m9r4.json b/advisories/unreviewed/2024/07/GHSA-9xpj-wgrg-m9r4/GHSA-9xpj-wgrg-m9r4.json index 02543a3f44a..8aeacba028e 100644 --- a/advisories/unreviewed/2024/07/GHSA-9xpj-wgrg-m9r4/GHSA-9xpj-wgrg-m9r4.json +++ b/advisories/unreviewed/2024/07/GHSA-9xpj-wgrg-m9r4/GHSA-9xpj-wgrg-m9r4.json @@ -44,7 +44,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-306" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-hg8f-ghpp-qpmq/GHSA-hg8f-ghpp-qpmq.json b/advisories/unreviewed/2024/07/GHSA-hg8f-ghpp-qpmq/GHSA-hg8f-ghpp-qpmq.json index 3993b829f0f..3669373db11 100644 --- a/advisories/unreviewed/2024/07/GHSA-hg8f-ghpp-qpmq/GHSA-hg8f-ghpp-qpmq.json +++ b/advisories/unreviewed/2024/07/GHSA-hg8f-ghpp-qpmq/GHSA-hg8f-ghpp-qpmq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hg8f-ghpp-qpmq", - "modified": "2024-07-10T21:30:38Z", + "modified": "2024-08-08T15:31:27Z", "published": "2024-07-10T21:30:38Z", "aliases": [ "CVE-2024-25077" ], "details": "An issue was discovered on Renesas SmartBond DA14691, DA14695, DA14697, and DA14699 devices. The Nonce used for on-the-fly decryption of flash images is stored in an unsigned header, allowing its value to be modified without invalidating the signature used for secureboot image verification. Because the encryption engine for on-the-fly decryption uses AES in CTR mode without authentication, an attacker-modified Nonce can result in execution of arbitrary code.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-94" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-10T20:15:03Z" diff --git a/advisories/unreviewed/2024/07/GHSA-j378-rg6j-2ff4/GHSA-j378-rg6j-2ff4.json b/advisories/unreviewed/2024/07/GHSA-j378-rg6j-2ff4/GHSA-j378-rg6j-2ff4.json index 7d61f925813..e763dcc4a4a 100644 --- a/advisories/unreviewed/2024/07/GHSA-j378-rg6j-2ff4/GHSA-j378-rg6j-2ff4.json +++ b/advisories/unreviewed/2024/07/GHSA-j378-rg6j-2ff4/GHSA-j378-rg6j-2ff4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j378-rg6j-2ff4", - "modified": "2024-07-30T09:32:03Z", + "modified": "2024-08-08T15:31:27Z", "published": "2024-07-30T09:32:03Z", "aliases": [ "CVE-2024-42153" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ni2c: pnx: Fix potential deadlock warning from del_timer_sync() call in isr\n\nWhen del_timer_sync() is called in an interrupt context it throws a warning\nbecause of potential deadlock. The timer is used only to exit from\nwait_for_completion() after a timeout so replacing the call with\nwait_for_completion_timeout() allows to remove the problematic timer and\nits related functions altogether.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-667" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-30T08:15:06Z" diff --git a/advisories/unreviewed/2024/07/GHSA-pqmv-6w3c-fgq2/GHSA-pqmv-6w3c-fgq2.json b/advisories/unreviewed/2024/07/GHSA-pqmv-6w3c-fgq2/GHSA-pqmv-6w3c-fgq2.json index e4d17ef5297..26f3ff61d37 100644 --- a/advisories/unreviewed/2024/07/GHSA-pqmv-6w3c-fgq2/GHSA-pqmv-6w3c-fgq2.json +++ b/advisories/unreviewed/2024/07/GHSA-pqmv-6w3c-fgq2/GHSA-pqmv-6w3c-fgq2.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-352" + "CWE-352", + "CWE-918" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-q75j-p4r8-37x7/GHSA-q75j-p4r8-37x7.json b/advisories/unreviewed/2024/07/GHSA-q75j-p4r8-37x7/GHSA-q75j-p4r8-37x7.json index 5c3ff730f3e..b409037d6a6 100644 --- a/advisories/unreviewed/2024/07/GHSA-q75j-p4r8-37x7/GHSA-q75j-p4r8-37x7.json +++ b/advisories/unreviewed/2024/07/GHSA-q75j-p4r8-37x7/GHSA-q75j-p4r8-37x7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q75j-p4r8-37x7", - "modified": "2024-07-30T09:32:03Z", + "modified": "2024-08-08T15:31:27Z", "published": "2024-07-30T09:32:03Z", "aliases": [ "CVE-2024-42154" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntcp_metrics: validate source addr length\n\nI don't see anything checking that TCP_METRICS_ATTR_SADDR_IPV4\nis at least 4 bytes long, and the policy doesn't have an entry\nfor this attribute at all (neither does it for IPv6 but v6 is\nmanually validated).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-754" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-30T08:15:06Z" diff --git a/advisories/unreviewed/2024/07/GHSA-q92f-2phr-4853/GHSA-q92f-2phr-4853.json b/advisories/unreviewed/2024/07/GHSA-q92f-2phr-4853/GHSA-q92f-2phr-4853.json index 6fc68eb187e..5cb2e45e999 100644 --- a/advisories/unreviewed/2024/07/GHSA-q92f-2phr-4853/GHSA-q92f-2phr-4853.json +++ b/advisories/unreviewed/2024/07/GHSA-q92f-2phr-4853/GHSA-q92f-2phr-4853.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q92f-2phr-4853", - "modified": "2024-07-06T00:31:06Z", + "modified": "2024-08-08T15:31:27Z", "published": "2024-07-06T00:31:06Z", "aliases": [ "CVE-2024-39182" ], "details": "An information disclosure vulnerability in ISPmanager v6.98.0 allows attackers to access sensitive details of the root user's session via an arbitrary command (ISP6-1779).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-05T23:15:10Z" diff --git a/advisories/unreviewed/2024/07/GHSA-r968-6g59-6626/GHSA-r968-6g59-6626.json b/advisories/unreviewed/2024/07/GHSA-r968-6g59-6626/GHSA-r968-6g59-6626.json index d56ccd6b002..128b4f3b569 100644 --- a/advisories/unreviewed/2024/07/GHSA-r968-6g59-6626/GHSA-r968-6g59-6626.json +++ b/advisories/unreviewed/2024/07/GHSA-r968-6g59-6626/GHSA-r968-6g59-6626.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r968-6g59-6626", - "modified": "2024-07-30T09:32:03Z", + "modified": "2024-08-08T15:31:27Z", "published": "2024-07-30T09:32:03Z", "aliases": [ "CVE-2024-42155" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ns390/pkey: Wipe copies of protected- and secure-keys\n\nAlthough the clear-key of neither protected- nor secure-keys is\naccessible, this key material should only be visible to the calling\nprocess. So wipe all copies of protected- or secure-keys from stack,\neven in case of an error.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-30T08:15:07Z" diff --git a/advisories/unreviewed/2024/07/GHSA-w439-8pfm-9pjm/GHSA-w439-8pfm-9pjm.json b/advisories/unreviewed/2024/07/GHSA-w439-8pfm-9pjm/GHSA-w439-8pfm-9pjm.json index 3705d475df0..d86aca5e274 100644 --- a/advisories/unreviewed/2024/07/GHSA-w439-8pfm-9pjm/GHSA-w439-8pfm-9pjm.json +++ b/advisories/unreviewed/2024/07/GHSA-w439-8pfm-9pjm/GHSA-w439-8pfm-9pjm.json @@ -44,7 +44,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-259" + "CWE-259", + "CWE-798" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-2pv9-pqcj-rmfm/GHSA-2pv9-pqcj-rmfm.json b/advisories/unreviewed/2024/08/GHSA-2pv9-pqcj-rmfm/GHSA-2pv9-pqcj-rmfm.json index eaf8f04de87..d4821a4cf2e 100644 --- a/advisories/unreviewed/2024/08/GHSA-2pv9-pqcj-rmfm/GHSA-2pv9-pqcj-rmfm.json +++ b/advisories/unreviewed/2024/08/GHSA-2pv9-pqcj-rmfm/GHSA-2pv9-pqcj-rmfm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2pv9-pqcj-rmfm", - "modified": "2024-08-07T18:30:42Z", + "modified": "2024-08-08T15:31:28Z", "published": "2024-08-07T18:30:42Z", "aliases": [ "CVE-2024-34480" ], "details": "SourceCodester Computer Laboratory Management System 1.0 allows admin/category/view_category.php id SQL Injection.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-07T16:15:44Z" diff --git a/advisories/unreviewed/2024/08/GHSA-2rr5-68hg-rwmh/GHSA-2rr5-68hg-rwmh.json b/advisories/unreviewed/2024/08/GHSA-2rr5-68hg-rwmh/GHSA-2rr5-68hg-rwmh.json index 84634361ff1..e140441b45d 100644 --- a/advisories/unreviewed/2024/08/GHSA-2rr5-68hg-rwmh/GHSA-2rr5-68hg-rwmh.json +++ b/advisories/unreviewed/2024/08/GHSA-2rr5-68hg-rwmh/GHSA-2rr5-68hg-rwmh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2rr5-68hg-rwmh", - "modified": "2024-08-07T18:30:43Z", + "modified": "2024-08-08T15:31:28Z", "published": "2024-08-07T18:30:43Z", "aliases": [ "CVE-2024-42233" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfilemap: replace pte_offset_map() with pte_offset_map_nolock()\n\nThe vmf->ptl in filemap_fault_recheck_pte_none() is still set from\nhandle_pte_fault(). But at the same time, we did a pte_unmap(vmf->pte). \nAfter a pte_unmap(vmf->pte) unmap and rcu_read_unlock(), the page table\nmay be racily changed and vmf->ptl maybe fails to protect the actual page\ntable. Fix this by replacing pte_offset_map() with\npte_offset_map_nolock().\n\nAs David said, the PTL pointer might be stale so if we continue to use\nit infilemap_fault_recheck_pte_none(), it might trigger UAF. Also, if\nthe PTL fails, the issue fixed by commit 58f327f2ce80 (\"filemap: avoid\nunnecessary major faults in filemap_fault()\") might reappear.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-07T16:15:46Z" diff --git a/advisories/unreviewed/2024/08/GHSA-3c6g-7v4g-5xcm/GHSA-3c6g-7v4g-5xcm.json b/advisories/unreviewed/2024/08/GHSA-3c6g-7v4g-5xcm/GHSA-3c6g-7v4g-5xcm.json new file mode 100644 index 00000000000..f72e965f88c --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-3c6g-7v4g-5xcm/GHSA-3c6g-7v4g-5xcm.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3c6g-7v4g-5xcm", + "modified": "2024-08-08T15:31:30Z", + "published": "2024-08-08T15:31:30Z", + "aliases": [ + "CVE-2024-7348" + ], + "details": "Time-of-check Time-of-use (TOCTOU) race condition in pg_dump in PostgreSQL allows an object creator to execute arbitrary SQL functions as the user running pg_dump, which is often a superuser. The attack involves replacing another relation type with a view or foreign table. The attack requires waiting for pg_dump to start, but winning the race condition is trivial if the attacker retains an open transaction. Versions before PostgreSQL 16.4, 15.8, 14.13, 13.16, and 12.20 are affected.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7348" + }, + { + "type": "WEB", + "url": "https://www.postgresql.org/support/security/CVE-2024-7348" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-367" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-08T13:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-4rc5-7v2h-gq36/GHSA-4rc5-7v2h-gq36.json b/advisories/unreviewed/2024/08/GHSA-4rc5-7v2h-gq36/GHSA-4rc5-7v2h-gq36.json index b0bcbdd8fd2..a1d57ca41e3 100644 --- a/advisories/unreviewed/2024/08/GHSA-4rc5-7v2h-gq36/GHSA-4rc5-7v2h-gq36.json +++ b/advisories/unreviewed/2024/08/GHSA-4rc5-7v2h-gq36/GHSA-4rc5-7v2h-gq36.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4rc5-7v2h-gq36", - "modified": "2024-08-08T00:31:44Z", + "modified": "2024-08-08T15:31:30Z", "published": "2024-08-08T00:31:44Z", "aliases": [ "CVE-2024-6890" ], "details": "Password reset tokens are generated using an insecure source of randomness. Attackers who know the username of the Journyx installation user can bruteforce the password reset and change the administrator password.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-321" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-07T23:15:41Z" diff --git a/advisories/unreviewed/2024/08/GHSA-54w4-6j43-whvq/GHSA-54w4-6j43-whvq.json b/advisories/unreviewed/2024/08/GHSA-54w4-6j43-whvq/GHSA-54w4-6j43-whvq.json index e399d42fd42..e75b58cdd20 100644 --- a/advisories/unreviewed/2024/08/GHSA-54w4-6j43-whvq/GHSA-54w4-6j43-whvq.json +++ b/advisories/unreviewed/2024/08/GHSA-54w4-6j43-whvq/GHSA-54w4-6j43-whvq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-54w4-6j43-whvq", - "modified": "2024-08-07T18:30:44Z", + "modified": "2024-08-08T15:31:29Z", "published": "2024-08-07T18:30:44Z", "aliases": [ "CVE-2024-41244" ], "details": "An Incorrect Access Control vulnerability was found in /smsa/view_class.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view CLASS details.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-07T17:15:51Z" diff --git a/advisories/unreviewed/2024/08/GHSA-557r-rm2w-qvrj/GHSA-557r-rm2w-qvrj.json b/advisories/unreviewed/2024/08/GHSA-557r-rm2w-qvrj/GHSA-557r-rm2w-qvrj.json index b9901df8cfc..3f6fec50b01 100644 --- a/advisories/unreviewed/2024/08/GHSA-557r-rm2w-qvrj/GHSA-557r-rm2w-qvrj.json +++ b/advisories/unreviewed/2024/08/GHSA-557r-rm2w-qvrj/GHSA-557r-rm2w-qvrj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-557r-rm2w-qvrj", - "modified": "2024-08-07T18:30:43Z", + "modified": "2024-08-08T15:31:29Z", "published": "2024-08-07T18:30:43Z", "aliases": [ "CVE-2024-42236" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: configfs: Prevent OOB read/write in usb_string_copy()\n\nUserspace provided string 's' could trivially have the length zero. Left\nunchecked this will firstly result in an OOB read in the form\n`if (str[0 - 1] == '\\n') followed closely by an OOB write in the form\n`str[0 - 1] = '\\0'`.\n\nThere is already a validating check to catch strings that are too long.\nLet's supply an additional check for invalid strings that are too short.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-07T16:15:46Z" diff --git a/advisories/unreviewed/2024/08/GHSA-5hgw-6w8f-3f58/GHSA-5hgw-6w8f-3f58.json b/advisories/unreviewed/2024/08/GHSA-5hgw-6w8f-3f58/GHSA-5hgw-6w8f-3f58.json index 0ea0382305e..df24d988dbd 100644 --- a/advisories/unreviewed/2024/08/GHSA-5hgw-6w8f-3f58/GHSA-5hgw-6w8f-3f58.json +++ b/advisories/unreviewed/2024/08/GHSA-5hgw-6w8f-3f58/GHSA-5hgw-6w8f-3f58.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5hgw-6w8f-3f58", - "modified": "2024-08-07T18:30:44Z", + "modified": "2024-08-08T15:31:29Z", "published": "2024-08-07T18:30:44Z", "aliases": [ "CVE-2024-41245" ], "details": "An Incorrect Access Control vulnerability was found in /smsa/view_teachers.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view TEACHER details.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-07T17:15:51Z" diff --git a/advisories/unreviewed/2024/08/GHSA-5jp3-wp5v-5363/GHSA-5jp3-wp5v-5363.json b/advisories/unreviewed/2024/08/GHSA-5jp3-wp5v-5363/GHSA-5jp3-wp5v-5363.json index 06dd2c8d65d..5eecdd707b2 100644 --- a/advisories/unreviewed/2024/08/GHSA-5jp3-wp5v-5363/GHSA-5jp3-wp5v-5363.json +++ b/advisories/unreviewed/2024/08/GHSA-5jp3-wp5v-5363/GHSA-5jp3-wp5v-5363.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5jp3-wp5v-5363", - "modified": "2024-08-08T00:31:44Z", + "modified": "2024-08-08T15:31:29Z", "published": "2024-08-08T00:31:44Z", "aliases": [ "CVE-2024-6706" ], "details": "Attackers can craft a malicious prompt that coerces the language model into executing arbitrary JavaScript in the context of the web page.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-07T23:15:41Z" diff --git a/advisories/unreviewed/2024/08/GHSA-5vqw-wppf-x433/GHSA-5vqw-wppf-x433.json b/advisories/unreviewed/2024/08/GHSA-5vqw-wppf-x433/GHSA-5vqw-wppf-x433.json index fd3e834bfc1..5550cc10be0 100644 --- a/advisories/unreviewed/2024/08/GHSA-5vqw-wppf-x433/GHSA-5vqw-wppf-x433.json +++ b/advisories/unreviewed/2024/08/GHSA-5vqw-wppf-x433/GHSA-5vqw-wppf-x433.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5vqw-wppf-x433", - "modified": "2024-08-07T18:30:43Z", + "modified": "2024-08-08T15:31:28Z", "published": "2024-08-07T18:30:43Z", "aliases": [ "CVE-2024-42232" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nlibceph: fix race between delayed_work() and ceph_monc_stop()\n\nThe way the delayed work is handled in ceph_monc_stop() is prone to\nraces with mon_fault() and possibly also finish_hunting(). Both of\nthese can requeue the delayed work which wouldn't be canceled by any of\nthe following code in case that happens after cancel_delayed_work_sync()\nruns -- __close_session() doesn't mess with the delayed work in order\nto avoid interfering with the hunting interval logic. This part was\nmissed in commit b5d91704f53e (\"libceph: behave in mon_fault() if\ncur_mon < 0\") and use-after-free can still ensue on monc and objects\nthat hang off of it, with monc->auth and monc->monmap being\nparticularly susceptible to quickly being reused.\n\nTo fix this:\n\n- clear monc->cur_mon and monc->hunting as part of closing the session\n in ceph_monc_stop()\n- bail from delayed_work() if monc->cur_mon is cleared, similar to how\n it's done in mon_fault() and finish_hunting() (based on monc->hunting)\n- call cancel_delayed_work_sync() after the session is closed", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-07T16:15:46Z" diff --git a/advisories/unreviewed/2024/08/GHSA-67jr-crfx-vm73/GHSA-67jr-crfx-vm73.json b/advisories/unreviewed/2024/08/GHSA-67jr-crfx-vm73/GHSA-67jr-crfx-vm73.json index ca130d9b82d..1bdbef2bb6b 100644 --- a/advisories/unreviewed/2024/08/GHSA-67jr-crfx-vm73/GHSA-67jr-crfx-vm73.json +++ b/advisories/unreviewed/2024/08/GHSA-67jr-crfx-vm73/GHSA-67jr-crfx-vm73.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-67jr-crfx-vm73", - "modified": "2024-08-08T00:31:44Z", + "modified": "2024-08-08T15:31:29Z", "published": "2024-08-08T00:31:44Z", "aliases": [ "CVE-2024-6707" ], "details": "Attacker controlled files can be uploaded to arbitrary locations on the web server's filesystem by abusing a path traversal vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-22" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-07T23:15:41Z" diff --git a/advisories/unreviewed/2024/08/GHSA-6p6f-gc59-4w3f/GHSA-6p6f-gc59-4w3f.json b/advisories/unreviewed/2024/08/GHSA-6p6f-gc59-4w3f/GHSA-6p6f-gc59-4w3f.json index 9ce422a28bc..ae78e7c834b 100644 --- a/advisories/unreviewed/2024/08/GHSA-6p6f-gc59-4w3f/GHSA-6p6f-gc59-4w3f.json +++ b/advisories/unreviewed/2024/08/GHSA-6p6f-gc59-4w3f/GHSA-6p6f-gc59-4w3f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6p6f-gc59-4w3f", - "modified": "2024-08-07T18:30:43Z", + "modified": "2024-08-08T15:31:28Z", "published": "2024-08-07T18:30:43Z", "aliases": [ "CVE-2024-42234" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm: fix crashes from deferred split racing folio migration\n\nEven on 6.10-rc6, I've been seeing elusive \"Bad page state\"s (often on\nflags when freeing, yet the flags shown are not bad: PG_locked had been\nset and cleared??), and VM_BUG_ON_PAGE(page_ref_count(page) == 0)s from\ndeferred_split_scan()'s folio_put(), and a variety of other BUG and WARN\nsymptoms implying double free by deferred split and large folio migration.\n\n6.7 commit 9bcef5973e31 (\"mm: memcg: fix split queue list crash when large\nfolio migration\") was right to fix the memcg-dependent locking broken in\n85ce2c517ade (\"memcontrol: only transfer the memcg data for migration\"),\nbut missed a subtlety of deferred_split_scan(): it moves folios to its own\nlocal list to work on them without split_queue_lock, during which time\nfolio->_deferred_list is not empty, but even the \"right\" lock does nothing\nto secure the folio and the list it is on.\n\nFortunately, deferred_split_scan() is careful to use folio_try_get(): so\nfolio_migrate_mapping() can avoid the race by folio_undo_large_rmappable()\nwhile the old folio's reference count is temporarily frozen to 0 - adding\nsuch a freeze in the !mapping case too (originally, folio lock and\nunmapping and no swap cache left an anon folio unreachable, so no freezing\nwas needed there: but the deferred split queue offers a way to reach it).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-415" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-07T16:15:46Z" diff --git a/advisories/unreviewed/2024/08/GHSA-762p-xx25-g6mq/GHSA-762p-xx25-g6mq.json b/advisories/unreviewed/2024/08/GHSA-762p-xx25-g6mq/GHSA-762p-xx25-g6mq.json index f99054966d3..8fde641ffdb 100644 --- a/advisories/unreviewed/2024/08/GHSA-762p-xx25-g6mq/GHSA-762p-xx25-g6mq.json +++ b/advisories/unreviewed/2024/08/GHSA-762p-xx25-g6mq/GHSA-762p-xx25-g6mq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-762p-xx25-g6mq", - "modified": "2024-08-07T18:30:44Z", + "modified": "2024-08-08T15:31:29Z", "published": "2024-08-07T18:30:44Z", "aliases": [ "CVE-2024-42245" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRevert \"sched/fair: Make sure to try to detach at least one movable task\"\n\nThis reverts commit b0defa7ae03ecf91b8bfd10ede430cff12fcbd06.\n\nb0defa7ae03ec changed the load balancing logic to ignore env.max_loop if\nall tasks examined to that point were pinned. The goal of the patch was\nto make it more likely to be able to detach a task buried in a long list\nof pinned tasks. However, this has the unfortunate side effect of\ncreating an O(n) iteration in detach_tasks(), as we now must fully\niterate every task on a cpu if all or most are pinned. Since this load\nbalance code is done with rq lock held, and often in softirq context, it\nis very easy to trigger hard lockups. We observed such hard lockups with\na user who affined O(10k) threads to a single cpu.\n\nWhen I discussed this with Vincent he initially suggested that we keep\nthe limit on the number of tasks to detach, but increase the number of\ntasks we can search. However, after some back and forth on the mailing\nlist, he recommended we instead revert the original patch, as it seems\nlikely no one was actually getting hit by the original issue.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-667" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-07T16:15:47Z" diff --git a/advisories/unreviewed/2024/08/GHSA-7j6j-8jww-jc3g/GHSA-7j6j-8jww-jc3g.json b/advisories/unreviewed/2024/08/GHSA-7j6j-8jww-jc3g/GHSA-7j6j-8jww-jc3g.json index d90758383db..1dcb4bf83c8 100644 --- a/advisories/unreviewed/2024/08/GHSA-7j6j-8jww-jc3g/GHSA-7j6j-8jww-jc3g.json +++ b/advisories/unreviewed/2024/08/GHSA-7j6j-8jww-jc3g/GHSA-7j6j-8jww-jc3g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7j6j-8jww-jc3g", - "modified": "2024-08-07T18:30:43Z", + "modified": "2024-08-08T15:31:29Z", "published": "2024-08-07T18:30:43Z", "aliases": [ "CVE-2024-42243" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/filemap: make MAX_PAGECACHE_ORDER acceptable to xarray\n\nPatch series \"mm/filemap: Limit page cache size to that supported by\nxarray\", v2.\n\nCurrently, xarray can't support arbitrary page cache size. More details\ncan be found from the WARN_ON() statement in xas_split_alloc(). In our\ntest whose code is attached below, we hit the WARN_ON() on ARM64 system\nwhere the base page size is 64KB and huge page size is 512MB. The issue\nwas reported long time ago and some discussions on it can be found here\n[1].\n\n[1] https://www.spinics.net/lists/linux-xfs/msg75404.html\n\nIn order to fix the issue, we need to adjust MAX_PAGECACHE_ORDER to one\nsupported by xarray and avoid PMD-sized page cache if needed. The code\nchanges are suggested by David Hildenbrand.\n\nPATCH[1] adjusts MAX_PAGECACHE_ORDER to that supported by xarray\nPATCH[2-3] avoids PMD-sized page cache in the synchronous readahead path\nPATCH[4] avoids PMD-sized page cache for shmem files if needed\n\nTest program\n============\n# cat test.c\n#define _GNU_SOURCE\n#include \n#include \n#include \n#include \n#include \n#include \n#include \n#include \n\n#define TEST_XFS_FILENAME\t\"/tmp/data\"\n#define TEST_SHMEM_FILENAME\t\"/dev/shm/data\"\n#define TEST_MEM_SIZE\t\t0x20000000\n\nint main(int argc, char **argv)\n{\n\tconst char *filename;\n\tint fd = 0;\n\tvoid *buf = (void *)-1, *p;\n\tint pgsize = getpagesize();\n\tint ret;\n\n\tif (pgsize != 0x10000) {\n\t\tfprintf(stderr, \"64KB base page size is required\\n\");\n\t\treturn -EPERM;\n\t}\n\n\tsystem(\"echo force > /sys/kernel/mm/transparent_hugepage/shmem_enabled\");\n\tsystem(\"rm -fr /tmp/data\");\n\tsystem(\"rm -fr /dev/shm/data\");\n\tsystem(\"echo 1 > /proc/sys/vm/drop_caches\");\n\n\t/* Open xfs or shmem file */\n\tfilename = TEST_XFS_FILENAME;\n\tif (argc > 1 && !strcmp(argv[1], \"shmem\"))\n\t\tfilename = TEST_SHMEM_FILENAME;\n\n\tfd = open(filename, O_CREAT | O_RDWR | O_TRUNC);\n\tif (fd < 0) {\n\t\tfprintf(stderr, \"Unable to open <%s>\\n\", filename);\n\t\treturn -EIO;\n\t}\n\n\t/* Extend file size */\n\tret = ftruncate(fd, TEST_MEM_SIZE);\n\tif (ret) {\n\t\tfprintf(stderr, \"Error %d to ftruncate()\\n\", ret);\n\t\tgoto cleanup;\n\t}\n\n\t/* Create VMA */\n\tbuf = mmap(NULL, TEST_MEM_SIZE,\n\t\t PROT_READ | PROT_WRITE, MAP_SHARED, fd, 0);\n\tif (buf == (void *)-1) {\n\t\tfprintf(stderr, \"Unable to mmap <%s>\\n\", filename);\n\t\tgoto cleanup;\n\t}\n\n\tfprintf(stdout, \"mapped buffer at 0x%p\\n\", buf);\n\tret = madvise(buf, TEST_MEM_SIZE, MADV_HUGEPAGE);\n if (ret) {\n\t\tfprintf(stderr, \"Unable to madvise(MADV_HUGEPAGE)\\n\");\n\t\tgoto cleanup;\n\t}\n\n\t/* Populate VMA */\n\tret = madvise(buf, TEST_MEM_SIZE, MADV_POPULATE_WRITE);\n\tif (ret) {\n\t\tfprintf(stderr, \"Error %d to madvise(MADV_POPULATE_WRITE)\\n\", ret);\n\t\tgoto cleanup;\n\t}\n\n\t/* Punch the file to enforce xarray split */\n\tret = fallocate(fd, FALLOC_FL_KEEP_SIZE | FALLOC_FL_PUNCH_HOLE,\n \t\tTEST_MEM_SIZE - pgsize, pgsize);\n\tif (ret)\n\t\tfprintf(stderr, \"Error %d to fallocate()\\n\", ret);\n\ncleanup:\n\tif (buf != (void *)-1)\n\t\tmunmap(buf, TEST_MEM_SIZE);\n\tif (fd > 0)\n\t\tclose(fd);\n\n\treturn 0;\n}\n\n# gcc test.c -o test\n# cat /proc/1/smaps | grep KernelPageSize | head -n 1\nKernelPageSize: 64 kB\n# ./test shmem\n :\n------------[ cut here ]------------\nWARNING: CPU: 17 PID: 5253 at lib/xarray.c:1025 xas_split_alloc+0xf8/0x128\nModules linked in: nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib \\\nnft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct \\\nnft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 \\\nip_set nf_tables rfkill nfnetlink vfat fat virtio_balloon \\\ndrm fuse xfs libcrc32c crct10dif_ce ghash_ce sha2_ce sha256_arm64 \\\nvirtio_net sha1_ce net_failover failover virtio_console virtio_blk \\\ndimlib virtio_mmio\nCPU: 17 PID: 5253 Comm: test Kdump: loaded Tainted: G W 6.10.0-rc5-gavin+ #12\nHardware name: QEMU KVM Virtual Machine, BIOS edk2-20240524-1.el9 05/24/2024\npstate: 83400005 (Nzcv daif +PAN -UAO +TC\n---truncated---", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-07T16:15:47Z" diff --git a/advisories/unreviewed/2024/08/GHSA-899c-qvc8-9hpp/GHSA-899c-qvc8-9hpp.json b/advisories/unreviewed/2024/08/GHSA-899c-qvc8-9hpp/GHSA-899c-qvc8-9hpp.json index 9d563f04829..54d55edda52 100644 --- a/advisories/unreviewed/2024/08/GHSA-899c-qvc8-9hpp/GHSA-899c-qvc8-9hpp.json +++ b/advisories/unreviewed/2024/08/GHSA-899c-qvc8-9hpp/GHSA-899c-qvc8-9hpp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-899c-qvc8-9hpp", - "modified": "2024-08-07T18:30:44Z", + "modified": "2024-08-08T15:31:29Z", "published": "2024-08-07T18:30:44Z", "aliases": [ "CVE-2024-42246" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet, sunrpc: Remap EPERM in case of connection failure in xs_tcp_setup_socket\n\nWhen using a BPF program on kernel_connect(), the call can return -EPERM. This\ncauses xs_tcp_setup_socket() to loop forever, filling up the syslog and causing\nthe kernel to potentially freeze up.\n\nNeil suggested:\n\n This will propagate -EPERM up into other layers which might not be ready\n to handle it. It might be safer to map EPERM to an error we would be more\n likely to expect from the network system - such as ECONNREFUSED or ENETDOWN.\n\nECONNREFUSED as error seems reasonable. For programs setting a different error\ncan be out of reach (see handling in 4fbac77d2d09) in particular on kernels\nwhich do not have f10d05966196 (\"bpf: Make BPF_PROG_RUN_ARRAY return -err\ninstead of allow boolean\"), thus given that it is better to simply remap for\nconsistent behavior. UDP does handle EPERM in xs_udp_send_request().", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-835" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-07T16:15:47Z" diff --git a/advisories/unreviewed/2024/08/GHSA-9hxq-vv35-9r5r/GHSA-9hxq-vv35-9r5r.json b/advisories/unreviewed/2024/08/GHSA-9hxq-vv35-9r5r/GHSA-9hxq-vv35-9r5r.json index e3c8dafb3e5..9eaa4ab0235 100644 --- a/advisories/unreviewed/2024/08/GHSA-9hxq-vv35-9r5r/GHSA-9hxq-vv35-9r5r.json +++ b/advisories/unreviewed/2024/08/GHSA-9hxq-vv35-9r5r/GHSA-9hxq-vv35-9r5r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9hxq-vv35-9r5r", - "modified": "2024-08-08T00:31:44Z", + "modified": "2024-08-08T15:31:30Z", "published": "2024-08-08T00:31:44Z", "aliases": [ "CVE-2024-6893" ], "details": "The \"soap_cgi.pyc\" API handler allows the XML body of SOAP requests to contain references to external entities. This allows an unauthenticated attacker to read local files, perform server-side request forgery, and overwhelm the web server resources.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-611" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-08T00:15:40Z" diff --git a/advisories/unreviewed/2024/08/GHSA-ccg8-wmfg-jr2m/GHSA-ccg8-wmfg-jr2m.json b/advisories/unreviewed/2024/08/GHSA-ccg8-wmfg-jr2m/GHSA-ccg8-wmfg-jr2m.json index 076a271fcd2..0912222a41d 100644 --- a/advisories/unreviewed/2024/08/GHSA-ccg8-wmfg-jr2m/GHSA-ccg8-wmfg-jr2m.json +++ b/advisories/unreviewed/2024/08/GHSA-ccg8-wmfg-jr2m/GHSA-ccg8-wmfg-jr2m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ccg8-wmfg-jr2m", - "modified": "2024-08-06T12:30:35Z", + "modified": "2024-08-08T15:31:27Z", "published": "2024-08-06T12:30:35Z", "aliases": [ "CVE-2024-33961" diff --git a/advisories/unreviewed/2024/08/GHSA-cg4j-f388-m354/GHSA-cg4j-f388-m354.json b/advisories/unreviewed/2024/08/GHSA-cg4j-f388-m354/GHSA-cg4j-f388-m354.json index 243f0416711..d5fb1419ed7 100644 --- a/advisories/unreviewed/2024/08/GHSA-cg4j-f388-m354/GHSA-cg4j-f388-m354.json +++ b/advisories/unreviewed/2024/08/GHSA-cg4j-f388-m354/GHSA-cg4j-f388-m354.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cg4j-f388-m354", - "modified": "2024-08-06T15:30:54Z", + "modified": "2024-08-08T15:31:28Z", "published": "2024-08-06T15:30:54Z", "aliases": [ "CVE-2024-41226" ], "details": "A CSV injection vulnerability in Automation Anywhere Automation 360 version 21094 allows attackers to execute arbitrary code via a crafted payload.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-1236" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-06T14:16:04Z" diff --git a/advisories/unreviewed/2024/08/GHSA-cq28-4xvm-6h6g/GHSA-cq28-4xvm-6h6g.json b/advisories/unreviewed/2024/08/GHSA-cq28-4xvm-6h6g/GHSA-cq28-4xvm-6h6g.json index 4603bc8edcd..55e73c8ade0 100644 --- a/advisories/unreviewed/2024/08/GHSA-cq28-4xvm-6h6g/GHSA-cq28-4xvm-6h6g.json +++ b/advisories/unreviewed/2024/08/GHSA-cq28-4xvm-6h6g/GHSA-cq28-4xvm-6h6g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cq28-4xvm-6h6g", - "modified": "2024-08-07T21:31:47Z", + "modified": "2024-08-08T15:31:29Z", "published": "2024-08-07T21:31:47Z", "aliases": [ "CVE-2024-41237" ], "details": "A SQL injection vulnerability in /smsa/teacher_login.php in Kashipara Responsive School Management System v1.0 allows an attacker to execute arbitrary SQL commands via the \"username\" parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-89" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-07T19:15:48Z" diff --git a/advisories/unreviewed/2024/08/GHSA-frq3-h54x-6725/GHSA-frq3-h54x-6725.json b/advisories/unreviewed/2024/08/GHSA-frq3-h54x-6725/GHSA-frq3-h54x-6725.json index 39acc4077e8..be8d6c7684c 100644 --- a/advisories/unreviewed/2024/08/GHSA-frq3-h54x-6725/GHSA-frq3-h54x-6725.json +++ b/advisories/unreviewed/2024/08/GHSA-frq3-h54x-6725/GHSA-frq3-h54x-6725.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-frq3-h54x-6725", - "modified": "2024-08-06T21:30:47Z", + "modified": "2024-08-08T15:31:28Z", "published": "2024-08-06T21:30:47Z", "aliases": [ "CVE-2024-42218" ], "details": "1Password 8 before 8.10.38 for macOS allows local attackers to exfiltrate vault items by bypassing macOS-specific security mechanisms.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-1289" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-06T21:16:03Z" diff --git a/advisories/unreviewed/2024/08/GHSA-fxrf-h5v6-vcj7/GHSA-fxrf-h5v6-vcj7.json b/advisories/unreviewed/2024/08/GHSA-fxrf-h5v6-vcj7/GHSA-fxrf-h5v6-vcj7.json index 631592c15ef..da95828ab35 100644 --- a/advisories/unreviewed/2024/08/GHSA-fxrf-h5v6-vcj7/GHSA-fxrf-h5v6-vcj7.json +++ b/advisories/unreviewed/2024/08/GHSA-fxrf-h5v6-vcj7/GHSA-fxrf-h5v6-vcj7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fxrf-h5v6-vcj7", - "modified": "2024-08-07T18:30:44Z", + "modified": "2024-08-08T15:31:29Z", "published": "2024-08-07T18:30:44Z", "aliases": [ "CVE-2024-41241" ], "details": "A Reflected Cross Site Scripting (XSS) vulnerability was found in \" /smsa/admin_login.php\" in Kashipara Responsive School Management System v3.2.0, which allows remote attackers to execute arbitrary code via \"error\" parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-07T18:15:37Z" diff --git a/advisories/unreviewed/2024/08/GHSA-g474-4q7c-cx7q/GHSA-g474-4q7c-cx7q.json b/advisories/unreviewed/2024/08/GHSA-g474-4q7c-cx7q/GHSA-g474-4q7c-cx7q.json index e6b56f0cd98..2fb18175f4c 100644 --- a/advisories/unreviewed/2024/08/GHSA-g474-4q7c-cx7q/GHSA-g474-4q7c-cx7q.json +++ b/advisories/unreviewed/2024/08/GHSA-g474-4q7c-cx7q/GHSA-g474-4q7c-cx7q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g474-4q7c-cx7q", - "modified": "2024-08-07T18:30:44Z", + "modified": "2024-08-08T15:31:29Z", "published": "2024-08-07T18:30:44Z", "aliases": [ "CVE-2024-41250" ], "details": "An Incorrect Access Control vulnerability was found in /smsa/view_students.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view STUDENT details.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-07T17:15:51Z" diff --git a/advisories/unreviewed/2024/08/GHSA-g92r-8x2f-9v8m/GHSA-g92r-8x2f-9v8m.json b/advisories/unreviewed/2024/08/GHSA-g92r-8x2f-9v8m/GHSA-g92r-8x2f-9v8m.json index 37892297454..d734a8c33dc 100644 --- a/advisories/unreviewed/2024/08/GHSA-g92r-8x2f-9v8m/GHSA-g92r-8x2f-9v8m.json +++ b/advisories/unreviewed/2024/08/GHSA-g92r-8x2f-9v8m/GHSA-g92r-8x2f-9v8m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g92r-8x2f-9v8m", - "modified": "2024-08-07T18:30:43Z", + "modified": "2024-08-08T15:31:29Z", "published": "2024-08-07T18:30:43Z", "aliases": [ "CVE-2024-42242" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmmc: sdhci: Fix max_seg_size for 64KiB PAGE_SIZE\n\nblk_queue_max_segment_size() ensured:\n\n\tif (max_size < PAGE_SIZE)\n\t\tmax_size = PAGE_SIZE;\n\nwhereas:\n\nblk_validate_limits() makes it an error:\n\n\tif (WARN_ON_ONCE(lim->max_segment_size < PAGE_SIZE))\n\t\treturn -EINVAL;\n\nThe change from one to the other, exposed sdhci which was setting maximum\nsegment size too low in some circumstances.\n\nFix the maximum segment size when it is too low.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-770" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-07T16:15:47Z" diff --git a/advisories/unreviewed/2024/08/GHSA-g9q3-4xq5-wqcj/GHSA-g9q3-4xq5-wqcj.json b/advisories/unreviewed/2024/08/GHSA-g9q3-4xq5-wqcj/GHSA-g9q3-4xq5-wqcj.json index 94ed66a5f8c..3193943b8d2 100644 --- a/advisories/unreviewed/2024/08/GHSA-g9q3-4xq5-wqcj/GHSA-g9q3-4xq5-wqcj.json +++ b/advisories/unreviewed/2024/08/GHSA-g9q3-4xq5-wqcj/GHSA-g9q3-4xq5-wqcj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g9q3-4xq5-wqcj", - "modified": "2024-08-07T18:30:44Z", + "modified": "2024-08-08T15:31:29Z", "published": "2024-08-07T18:30:44Z", "aliases": [ "CVE-2024-42244" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: serial: mos7840: fix crash on resume\n\nSince commit c49cfa917025 (\"USB: serial: use generic method if no\nalternative is provided in usb serial layer\"), USB serial core calls the\ngeneric resume implementation when the driver has not provided one.\n\nThis can trigger a crash on resume with mos7840 since support for\nmultiple read URBs was added back in 2011. Specifically, both port read\nURBs are now submitted on resume for open ports, but the context pointer\nof the second URB is left set to the core rather than mos7840 port\nstructure.\n\nFix this by implementing dedicated suspend and resume functions for\nmos7840.\n\nTested with Delock 87414 USB 2.0 to 4x serial adapter.\n\n[ johan: analyse crash and rewrite commit message; set busy flag on\n resume; drop bulk-in check; drop unnecessary usb_kill_urb() ]", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -47,7 +50,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-07T16:15:47Z" diff --git a/advisories/unreviewed/2024/08/GHSA-ggh4-5hvc-554r/GHSA-ggh4-5hvc-554r.json b/advisories/unreviewed/2024/08/GHSA-ggh4-5hvc-554r/GHSA-ggh4-5hvc-554r.json index ede99bbc10d..62e780fba16 100644 --- a/advisories/unreviewed/2024/08/GHSA-ggh4-5hvc-554r/GHSA-ggh4-5hvc-554r.json +++ b/advisories/unreviewed/2024/08/GHSA-ggh4-5hvc-554r/GHSA-ggh4-5hvc-554r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-ggh4-5hvc-554r", - "modified": "2024-08-07T18:30:43Z", + "modified": "2024-08-08T15:31:29Z", "published": "2024-08-07T18:30:43Z", "aliases": [ "CVE-2024-42239" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fail bpf_timer_cancel when callback is being cancelled\n\nGiven a schedule:\n\ntimer1 cb\t\t\ttimer2 cb\n\nbpf_timer_cancel(timer2);\tbpf_timer_cancel(timer1);\n\nBoth bpf_timer_cancel calls would wait for the other callback to finish\nexecuting, introducing a lockup.\n\nAdd an atomic_t count named 'cancelling' in bpf_hrtimer. This keeps\ntrack of all in-flight cancellation requests for a given BPF timer.\nWhenever cancelling a BPF timer, we must check if we have outstanding\ncancellation requests, and if so, we must fail the operation with an\nerror (-EDEADLK) since cancellation is synchronous and waits for the\ncallback to finish executing. This implies that we can enter a deadlock\nsituation involving two or more timer callbacks executing in parallel\nand attempting to cancel one another.\n\nNote that we avoid incrementing the cancelling counter for the target\ntimer (the one being cancelled) if bpf_timer_cancel is not invoked from\na callback, to avoid spurious errors. The whole point of detecting\ncur->cancelling and returning -EDEADLK is to not enter a busy wait loop\n(which may or may not lead to a lockup). This does not apply in case the\ncaller is in a non-callback context, the other side can continue to\ncancel as it sees fit without running into errors.\n\nBackground on prior attempts:\n\nEarlier versions of this patch used a bool 'cancelling' bit and used the\nfollowing pattern under timer->lock to publish cancellation status.\n\nlock(t->lock);\nt->cancelling = true;\nmb();\nif (cur->cancelling)\n\treturn -EDEADLK;\nunlock(t->lock);\nhrtimer_cancel(t->timer);\nt->cancelling = false;\n\nThe store outside the critical section could overwrite a parallel\nrequests t->cancelling assignment to true, to ensure the parallely\nexecuting callback observes its cancellation status.\n\nIt would be necessary to clear this cancelling bit once hrtimer_cancel\nis done, but lack of serialization introduced races. Another option was\nexplored where bpf_timer_start would clear the bit when (re)starting the\ntimer under timer->lock. This would ensure serialized access to the\ncancelling bit, but may allow it to be cleared before in-flight\nhrtimer_cancel has finished executing, such that lockups can occur\nagain.\n\nThus, we choose an atomic counter to keep track of all outstanding\ncancellation requests and use it to prevent lockups in case callbacks\nattempt to cancel each other while executing in parallel.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-667" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-07T16:15:46Z" diff --git a/advisories/unreviewed/2024/08/GHSA-hp2r-hjvj-mq3f/GHSA-hp2r-hjvj-mq3f.json b/advisories/unreviewed/2024/08/GHSA-hp2r-hjvj-mq3f/GHSA-hp2r-hjvj-mq3f.json index 4e2f19e3ce9..d4bcb144641 100644 --- a/advisories/unreviewed/2024/08/GHSA-hp2r-hjvj-mq3f/GHSA-hp2r-hjvj-mq3f.json +++ b/advisories/unreviewed/2024/08/GHSA-hp2r-hjvj-mq3f/GHSA-hp2r-hjvj-mq3f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hp2r-hjvj-mq3f", - "modified": "2024-08-08T00:31:44Z", + "modified": "2024-08-08T15:31:30Z", "published": "2024-08-08T00:31:44Z", "aliases": [ "CVE-2024-6891" ], "details": "Attackers with a valid username and password can exploit a python code injection vulnerability during the natural login flow.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-94" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-08T00:15:40Z" diff --git a/advisories/unreviewed/2024/08/GHSA-j9x3-2fgg-9qgj/GHSA-j9x3-2fgg-9qgj.json b/advisories/unreviewed/2024/08/GHSA-j9x3-2fgg-9qgj/GHSA-j9x3-2fgg-9qgj.json index d36573e2966..4589025158a 100644 --- a/advisories/unreviewed/2024/08/GHSA-j9x3-2fgg-9qgj/GHSA-j9x3-2fgg-9qgj.json +++ b/advisories/unreviewed/2024/08/GHSA-j9x3-2fgg-9qgj/GHSA-j9x3-2fgg-9qgj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j9x3-2fgg-9qgj", - "modified": "2024-08-07T18:30:42Z", + "modified": "2024-08-08T15:31:28Z", "published": "2024-08-07T18:30:42Z", "aliases": [ "CVE-2024-41251" ], "details": "An Incorrect Access Control vulnerability was found in /smsa/admin_teacher_register_approval.php and /smsa/admin_teacher_register_approval_submit.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view and approve Teacher registration.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-07T16:15:45Z" diff --git a/advisories/unreviewed/2024/08/GHSA-jxv8-jmp2-87p8/GHSA-jxv8-jmp2-87p8.json b/advisories/unreviewed/2024/08/GHSA-jxv8-jmp2-87p8/GHSA-jxv8-jmp2-87p8.json index 27c3f0b68e9..ebc35f6e611 100644 --- a/advisories/unreviewed/2024/08/GHSA-jxv8-jmp2-87p8/GHSA-jxv8-jmp2-87p8.json +++ b/advisories/unreviewed/2024/08/GHSA-jxv8-jmp2-87p8/GHSA-jxv8-jmp2-87p8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jxv8-jmp2-87p8", - "modified": "2024-08-07T18:30:43Z", + "modified": "2024-08-08T15:31:29Z", "published": "2024-08-07T18:30:43Z", "aliases": [ "CVE-2024-42240" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/bhi: Avoid warning in #DB handler due to BHI mitigation\n\nWhen BHI mitigation is enabled, if SYSENTER is invoked with the TF flag set\nthen entry_SYSENTER_compat() uses CLEAR_BRANCH_HISTORY and calls the\nclear_bhb_loop() before the TF flag is cleared. This causes the #DB handler\n(exc_debug_kernel()) to issue a warning because single-step is used outside the\nentry_SYSENTER_compat() function.\n\nTo address this issue, entry_SYSENTER_compat() should use CLEAR_BRANCH_HISTORY\nafter making sure the TF flag is cleared.\n\nThe problem can be reproduced with the following sequence:\n\n $ cat sysenter_step.c\n int main()\n { asm(\"pushf; pop %ax; bts $8,%ax; push %ax; popf; sysenter\"); }\n\n $ gcc -o sysenter_step sysenter_step.c\n\n $ ./sysenter_step\n Segmentation fault (core dumped)\n\nThe program is expected to crash, and the #DB handler will issue a warning.\n\nKernel log:\n\n WARNING: CPU: 27 PID: 7000 at arch/x86/kernel/traps.c:1009 exc_debug_kernel+0xd2/0x160\n ...\n RIP: 0010:exc_debug_kernel+0xd2/0x160\n ...\n Call Trace:\n <#DB>\n ? show_regs+0x68/0x80\n ? __warn+0x8c/0x140\n ? exc_debug_kernel+0xd2/0x160\n ? report_bug+0x175/0x1a0\n ? handle_bug+0x44/0x90\n ? exc_invalid_op+0x1c/0x70\n ? asm_exc_invalid_op+0x1f/0x30\n ? exc_debug_kernel+0xd2/0x160\n exc_debug+0x43/0x50\n asm_exc_debug+0x1e/0x40\n RIP: 0010:clear_bhb_loop+0x0/0xb0\n ...\n \n \n ? entry_SYSENTER_compat_after_hwframe+0x6e/0x8d\n \n\n [ bp: Massage commit message. ]", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-835" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-07T16:15:46Z" diff --git a/advisories/unreviewed/2024/08/GHSA-m475-c2qh-xg8v/GHSA-m475-c2qh-xg8v.json b/advisories/unreviewed/2024/08/GHSA-m475-c2qh-xg8v/GHSA-m475-c2qh-xg8v.json index 935489f7379..01b55f1a53e 100644 --- a/advisories/unreviewed/2024/08/GHSA-m475-c2qh-xg8v/GHSA-m475-c2qh-xg8v.json +++ b/advisories/unreviewed/2024/08/GHSA-m475-c2qh-xg8v/GHSA-m475-c2qh-xg8v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m475-c2qh-xg8v", - "modified": "2024-08-07T18:30:44Z", + "modified": "2024-08-08T15:31:29Z", "published": "2024-08-07T18:30:44Z", "aliases": [ "CVE-2024-42247" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwireguard: allowedips: avoid unaligned 64-bit memory accesses\n\nOn the parisc platform, the kernel issues kernel warnings because\nswap_endian() tries to load a 128-bit IPv6 address from an unaligned\nmemory location:\n\n Kernel: unaligned access to 0x55f4688c in wg_allowedips_insert_v6+0x2c/0x80 [wireguard] (iir 0xf3010df)\n Kernel: unaligned access to 0x55f46884 in wg_allowedips_insert_v6+0x38/0x80 [wireguard] (iir 0xf2010dc)\n\nAvoid such unaligned memory accesses by instead using the\nget_unaligned_be64() helper macro.\n\n[Jason: replace src[8] in original patch with src+8]", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-770" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-07T16:15:47Z" diff --git a/advisories/unreviewed/2024/08/GHSA-m4qj-p3wv-ph7c/GHSA-m4qj-p3wv-ph7c.json b/advisories/unreviewed/2024/08/GHSA-m4qj-p3wv-ph7c/GHSA-m4qj-p3wv-ph7c.json index 6921577db0f..3eb14c11ee4 100644 --- a/advisories/unreviewed/2024/08/GHSA-m4qj-p3wv-ph7c/GHSA-m4qj-p3wv-ph7c.json +++ b/advisories/unreviewed/2024/08/GHSA-m4qj-p3wv-ph7c/GHSA-m4qj-p3wv-ph7c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m4qj-p3wv-ph7c", - "modified": "2024-08-07T18:30:43Z", + "modified": "2024-08-08T15:31:29Z", "published": "2024-08-07T18:30:43Z", "aliases": [ "CVE-2024-42241" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/shmem: disable PMD-sized page cache if needed\n\nFor shmem files, it's possible that PMD-sized page cache can't be\nsupported by xarray. For example, 512MB page cache on ARM64 when the base\npage size is 64KB can't be supported by xarray. It leads to errors as the\nfollowing messages indicate when this sort of xarray entry is split.\n\nWARNING: CPU: 34 PID: 7578 at lib/xarray.c:1025 xas_split_alloc+0xf8/0x128\nModules linked in: binfmt_misc nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 \\\nnft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject \\\nnft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 \\\nip_set rfkill nf_tables nfnetlink vfat fat virtio_balloon drm fuse xfs \\\nlibcrc32c crct10dif_ce ghash_ce sha2_ce sha256_arm64 sha1_ce virtio_net \\\nnet_failover virtio_console virtio_blk failover dimlib virtio_mmio\nCPU: 34 PID: 7578 Comm: test Kdump: loaded Tainted: G W 6.10.0-rc5-gavin+ #9\nHardware name: QEMU KVM Virtual Machine, BIOS edk2-20240524-1.el9 05/24/2024\npstate: 83400005 (Nzcv daif +PAN -UAO +TCO +DIT -SSBS BTYPE=--)\npc : xas_split_alloc+0xf8/0x128\nlr : split_huge_page_to_list_to_order+0x1c4/0x720\nsp : ffff8000882af5f0\nx29: ffff8000882af5f0 x28: ffff8000882af650 x27: ffff8000882af768\nx26: 0000000000000cc0 x25: 000000000000000d x24: ffff00010625b858\nx23: ffff8000882af650 x22: ffffffdfc0900000 x21: 0000000000000000\nx20: 0000000000000000 x19: ffffffdfc0900000 x18: 0000000000000000\nx17: 0000000000000000 x16: 0000018000000000 x15: 52f8004000000000\nx14: 0000e00000000000 x13: 0000000000002000 x12: 0000000000000020\nx11: 52f8000000000000 x10: 52f8e1c0ffff6000 x9 : ffffbeb9619a681c\nx8 : 0000000000000003 x7 : 0000000000000000 x6 : ffff00010b02ddb0\nx5 : ffffbeb96395e378 x4 : 0000000000000000 x3 : 0000000000000cc0\nx2 : 000000000000000d x1 : 000000000000000c x0 : 0000000000000000\nCall trace:\n xas_split_alloc+0xf8/0x128\n split_huge_page_to_list_to_order+0x1c4/0x720\n truncate_inode_partial_folio+0xdc/0x160\n shmem_undo_range+0x2bc/0x6a8\n shmem_fallocate+0x134/0x430\n vfs_fallocate+0x124/0x2e8\n ksys_fallocate+0x4c/0xa0\n __arm64_sys_fallocate+0x24/0x38\n invoke_syscall.constprop.0+0x7c/0xd8\n do_el0_svc+0xb4/0xd0\n el0_svc+0x44/0x1d8\n el0t_64_sync_handler+0x134/0x150\n el0t_64_sync+0x17c/0x180\n\nFix it by disabling PMD-sized page cache when HPAGE_PMD_ORDER is larger\nthan MAX_PAGECACHE_ORDER. As Matthew Wilcox pointed, the page cache in a\nshmem file isn't represented by a multi-index entry and doesn't have this\nlimitation when the xarry entry is split until commit 6b24ca4a1a8d (\"mm:\nUse multi-index entries in the page cache\").", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-770" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-07T16:15:46Z" diff --git a/advisories/unreviewed/2024/08/GHSA-m5xv-fggp-4j5r/GHSA-m5xv-fggp-4j5r.json b/advisories/unreviewed/2024/08/GHSA-m5xv-fggp-4j5r/GHSA-m5xv-fggp-4j5r.json new file mode 100644 index 00000000000..731d7763b5c --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-m5xv-fggp-4j5r/GHSA-m5xv-fggp-4j5r.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m5xv-fggp-4j5r", + "modified": "2024-08-08T15:31:31Z", + "published": "2024-08-08T15:31:31Z", + "aliases": [ + "CVE-2024-7490" + ], + "details": "Improper Input Validation vulnerability in Microchip Techology Advanced Software Framework example DHCP server can cause remote code execution through a buffer overflow.\n This vulnerability is associated with program files tinydhcpserver.C and program routines lwip_dhcp_find_option.\n\nThis issue affects Advanced Software Framework: through 3.52.0.2574.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7490" + }, + { + "type": "WEB", + "url": "https://www.microchip.com/en-us/tools-resources/develop/libraries/advanced-software-framework" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-08T15:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-mvr5-c43p-gf5m/GHSA-mvr5-c43p-gf5m.json b/advisories/unreviewed/2024/08/GHSA-mvr5-c43p-gf5m/GHSA-mvr5-c43p-gf5m.json index 038a9ceedc0..b70ba2a7b47 100644 --- a/advisories/unreviewed/2024/08/GHSA-mvr5-c43p-gf5m/GHSA-mvr5-c43p-gf5m.json +++ b/advisories/unreviewed/2024/08/GHSA-mvr5-c43p-gf5m/GHSA-mvr5-c43p-gf5m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mvr5-c43p-gf5m", - "modified": "2024-08-06T12:30:35Z", + "modified": "2024-08-08T15:31:27Z", "published": "2024-08-06T12:30:35Z", "aliases": [ "CVE-2024-33962" diff --git a/advisories/unreviewed/2024/08/GHSA-pjph-5c8j-wm5g/GHSA-pjph-5c8j-wm5g.json b/advisories/unreviewed/2024/08/GHSA-pjph-5c8j-wm5g/GHSA-pjph-5c8j-wm5g.json index 4e16397b8f7..ce53829f140 100644 --- a/advisories/unreviewed/2024/08/GHSA-pjph-5c8j-wm5g/GHSA-pjph-5c8j-wm5g.json +++ b/advisories/unreviewed/2024/08/GHSA-pjph-5c8j-wm5g/GHSA-pjph-5c8j-wm5g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pjph-5c8j-wm5g", - "modified": "2024-08-07T18:30:44Z", + "modified": "2024-08-08T15:31:29Z", "published": "2024-08-07T18:30:44Z", "aliases": [ "CVE-2024-41243" ], "details": "An Incorrect Access Control vulnerability was found in /smsa/view_marks.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view MARKS details.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-07T17:15:51Z" diff --git a/advisories/unreviewed/2024/08/GHSA-qmvr-hqqr-gjg7/GHSA-qmvr-hqqr-gjg7.json b/advisories/unreviewed/2024/08/GHSA-qmvr-hqqr-gjg7/GHSA-qmvr-hqqr-gjg7.json index 09446ce26a8..166bf851c6f 100644 --- a/advisories/unreviewed/2024/08/GHSA-qmvr-hqqr-gjg7/GHSA-qmvr-hqqr-gjg7.json +++ b/advisories/unreviewed/2024/08/GHSA-qmvr-hqqr-gjg7/GHSA-qmvr-hqqr-gjg7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qmvr-hqqr-gjg7", - "modified": "2024-08-08T06:30:54Z", + "modified": "2024-08-08T15:31:30Z", "published": "2024-08-08T06:30:54Z", "aliases": [ "CVE-2024-6481" ], "details": "The Search & Filter Pro WordPress plugin before 2.5.18 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-08T06:15:40Z" diff --git a/advisories/unreviewed/2024/08/GHSA-rx9p-j44h-69cp/GHSA-rx9p-j44h-69cp.json b/advisories/unreviewed/2024/08/GHSA-rx9p-j44h-69cp/GHSA-rx9p-j44h-69cp.json index a8a17d5bb09..2d41b72f8b6 100644 --- a/advisories/unreviewed/2024/08/GHSA-rx9p-j44h-69cp/GHSA-rx9p-j44h-69cp.json +++ b/advisories/unreviewed/2024/08/GHSA-rx9p-j44h-69cp/GHSA-rx9p-j44h-69cp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rx9p-j44h-69cp", - "modified": "2024-08-07T18:30:43Z", + "modified": "2024-08-08T15:31:28Z", "published": "2024-08-07T18:30:43Z", "aliases": [ "CVE-2024-42235" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ns390/mm: Add NULL pointer check to crst_table_free() base_crst_free()\n\ncrst_table_free() used to work with NULL pointers before the conversion\nto ptdescs. Since crst_table_free() can be called with a NULL pointer\n(error handling in crst_table_upgrade() add an explicit check.\n\nAlso add the same check to base_crst_free() for consistency reasons.\n\nIn real life this should not happen, since order two GFP_KERNEL\nallocations will not fail, unless FAIL_PAGE_ALLOC is enabled and used.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-07T16:15:46Z" diff --git a/advisories/unreviewed/2024/08/GHSA-vfcg-vh6j-gg8j/GHSA-vfcg-vh6j-gg8j.json b/advisories/unreviewed/2024/08/GHSA-vfcg-vh6j-gg8j/GHSA-vfcg-vh6j-gg8j.json new file mode 100644 index 00000000000..5a7a7c4f638 --- /dev/null +++ b/advisories/unreviewed/2024/08/GHSA-vfcg-vh6j-gg8j/GHSA-vfcg-vh6j-gg8j.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vfcg-vh6j-gg8j", + "modified": "2024-08-08T15:31:31Z", + "published": "2024-08-08T15:31:30Z", + "aliases": [ + "CVE-2024-3659" + ], + "details": "Firmware in KAON AR2140 routers prior to version 4.2.16 is vulnerable to a shell command injection via sending a crafted request to one of the endpoints.\nIn order to exploit this vulnerability, one has to have access to the administrative portal of the router.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3659" + }, + { + "type": "WEB", + "url": "https://cert.pl/en/posts/2024/08/CVE-2024-3659" + }, + { + "type": "WEB", + "url": "https://cert.pl/posts/2024/08/CVE-2024-3659" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-08-08T13:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-vfhx-cqwc-hf57/GHSA-vfhx-cqwc-hf57.json b/advisories/unreviewed/2024/08/GHSA-vfhx-cqwc-hf57/GHSA-vfhx-cqwc-hf57.json index 18037c20e2a..fbcde4ad905 100644 --- a/advisories/unreviewed/2024/08/GHSA-vfhx-cqwc-hf57/GHSA-vfhx-cqwc-hf57.json +++ b/advisories/unreviewed/2024/08/GHSA-vfhx-cqwc-hf57/GHSA-vfhx-cqwc-hf57.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vfhx-cqwc-hf57", - "modified": "2024-08-07T18:30:43Z", + "modified": "2024-08-08T15:31:29Z", "published": "2024-08-07T18:30:43Z", "aliases": [ "CVE-2024-42238" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware: cs_dsp: Return error if block header overflows file\n\nReturn an error from cs_dsp_power_up() if a block header is longer\nthan the amount of data left in the file.\n\nThe previous code in cs_dsp_load() and cs_dsp_load_coeff() would loop\nwhile there was enough data left in the file for a valid region. This\nprotected against overrunning the end of the file data, but it didn't\nabort the file processing with an error.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-07T16:15:46Z" diff --git a/advisories/unreviewed/2024/08/GHSA-wvp3-f576-fpv8/GHSA-wvp3-f576-fpv8.json b/advisories/unreviewed/2024/08/GHSA-wvp3-f576-fpv8/GHSA-wvp3-f576-fpv8.json index ea7a51cf328..efd39c1fa91 100644 --- a/advisories/unreviewed/2024/08/GHSA-wvp3-f576-fpv8/GHSA-wvp3-f576-fpv8.json +++ b/advisories/unreviewed/2024/08/GHSA-wvp3-f576-fpv8/GHSA-wvp3-f576-fpv8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wvp3-f576-fpv8", - "modified": "2024-08-07T18:30:43Z", + "modified": "2024-08-08T15:31:29Z", "published": "2024-08-07T18:30:43Z", "aliases": [ "CVE-2024-42237" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware: cs_dsp: Validate payload length before processing block\n\nMove the payload length check in cs_dsp_load() and cs_dsp_coeff_load()\nto be done before the block is processed.\n\nThe check that the length of a block payload does not exceed the number\nof remaining bytes in the firwmware file buffer was being done near the\nend of the loop iteration. However, some code before that check used the\nlength field without validating it.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-834" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-07T16:15:46Z" diff --git a/advisories/unreviewed/2024/08/GHSA-x7x3-mj9c-m6x7/GHSA-x7x3-mj9c-m6x7.json b/advisories/unreviewed/2024/08/GHSA-x7x3-mj9c-m6x7/GHSA-x7x3-mj9c-m6x7.json index 36777155ad3..54b98d61ecc 100644 --- a/advisories/unreviewed/2024/08/GHSA-x7x3-mj9c-m6x7/GHSA-x7x3-mj9c-m6x7.json +++ b/advisories/unreviewed/2024/08/GHSA-x7x3-mj9c-m6x7/GHSA-x7x3-mj9c-m6x7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x7x3-mj9c-m6x7", - "modified": "2024-08-07T18:30:42Z", + "modified": "2024-08-08T15:31:28Z", "published": "2024-08-07T18:30:42Z", "aliases": [ "CVE-2024-41246" ], "details": "An Incorrect Access Control vulnerability was found in /smsa/admin_dashboard.php in Kashipara Responsive School Management System v3.2.0, which allows remote unauthenticated attackers to view administrator dashboard.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-284" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-07T16:15:45Z" diff --git a/advisories/unreviewed/2024/08/GHSA-xg77-wrvc-q75c/GHSA-xg77-wrvc-q75c.json b/advisories/unreviewed/2024/08/GHSA-xg77-wrvc-q75c/GHSA-xg77-wrvc-q75c.json index 3f2cdf785c1..237f48427b7 100644 --- a/advisories/unreviewed/2024/08/GHSA-xg77-wrvc-q75c/GHSA-xg77-wrvc-q75c.json +++ b/advisories/unreviewed/2024/08/GHSA-xg77-wrvc-q75c/GHSA-xg77-wrvc-q75c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xg77-wrvc-q75c", - "modified": "2024-08-07T18:30:42Z", + "modified": "2024-08-08T15:31:28Z", "published": "2024-08-07T18:30:42Z", "aliases": [ "CVE-2024-41309" ], "details": "An issue in the Hardware info module of IT Solutions Enjay CRM OS v1.0 allows attackers to escape the restricted terminal environment and gain root-level privileges on the underlying system.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-08-07T16:15:46Z"