From 41840c22bf64bf8d273186eab26c6526566c1d01 Mon Sep 17 00:00:00 2001
From: "advisory-database[bot]"
<45398580+advisory-database[bot]@users.noreply.github.com>
Date: Thu, 6 Mar 2025 15:36:19 +0000
Subject: [PATCH] Advisory Database Sync
---
.../GHSA-c3gq-qcr6-5vj9.json | 4 +-
.../GHSA-62m2-jvfw-mjgv.json | 7 +--
.../GHSA-2h72-wjmg-q2hg.json | 15 +++++-
.../GHSA-gj62-r5fm-pg3q.json | 4 +-
.../GHSA-8369-88r2-v5v6.json | 4 +-
.../GHSA-3hw4-pvhh-9qcq.json | 15 ++++--
.../GHSA-3p2v-4qj8-6w5f.json | 15 ++++--
.../GHSA-45rj-9f26-3gf5.json | 15 ++++--
.../GHSA-7wx4-4999-cgfj.json | 15 ++++--
.../GHSA-c352-9339-wrc2.json | 15 ++++--
.../GHSA-frc8-7f65-3g5r.json | 15 ++++--
.../GHSA-p4g6-hq7c-h438.json | 15 ++++--
.../GHSA-qfp7-gc56-5hcj.json | 6 ++-
.../GHSA-rwr5-hmxr-6v8j.json | 15 ++++--
.../GHSA-w7qp-vgwj-6g7r.json | 6 ++-
.../GHSA-r8c3-h27x-qrpx.json | 15 ++++--
.../GHSA-x592-qqvv-rpr2.json | 15 ++++--
.../GHSA-88vm-fw2c-f253.json | 15 ++++--
.../GHSA-c6gv-gfxc-vrwh.json | 15 ++++--
.../GHSA-ghhh-5r4g-5v2c.json | 15 ++++--
.../GHSA-j2gx-qfwv-h2pp.json | 15 ++++--
.../GHSA-pfhx-g36q-294h.json | 4 +-
.../GHSA-vjq5-pfrc-9vjr.json | 15 ++++--
.../GHSA-w7f6-93r9-8m94.json | 15 ++++--
.../GHSA-6cxx-x253-9xcq.json | 15 ++++--
.../GHSA-64p7-wm49-vgg4.json | 15 ++++--
.../GHSA-gxj3-vh7p-4j4h.json | 15 ++++--
.../GHSA-j2r5-qpjf-gcfc.json | 15 ++++--
.../GHSA-q9f3-jcg6-9j2x.json | 15 ++++--
.../GHSA-wm3v-h2q8-5pg6.json | 15 ++++--
.../GHSA-3xqw-4m9h-8f2c.json | 3 +-
.../GHSA-5r5h-j8r7-pr7g.json | 3 +-
.../GHSA-5r5h-v4j5-xvwv.json | 3 +-
.../GHSA-p389-5xc8-8rj5.json | 3 +-
.../GHSA-pmj8-x3xv-95rq.json | 3 +-
.../GHSA-wm69-gq95-wfj3.json | 3 +-
.../GHSA-6hq3-frr2-vjp4.json | 15 ++++--
.../GHSA-7ch8-4hvj-r54q.json | 2 +-
.../GHSA-8929-x24h-jv8r.json | 2 +-
.../GHSA-8fx2-6c45-vg8j.json | 3 +-
.../GHSA-c7vr-vpm2-822g.json | 1 +
.../GHSA-j992-gmv8-p6vw.json | 11 ++--
.../GHSA-jcx5-2hxr-pwq4.json | 15 ++++--
.../GHSA-qc22-v4cr-4rv7.json | 15 ++++--
.../GHSA-qwgw-jf68-fjmq.json | 2 +-
.../GHSA-rg7g-5842-62w5.json | 2 +-
.../GHSA-xgjf-869w-4cgj.json | 15 ++++--
.../GHSA-2cg5-9vjw-w6vg.json | 40 ++++++++++++++
.../GHSA-2q7g-85wh-78fq.json | 29 +++++++++++
.../GHSA-4gjv-fwgw-f3qc.json | 15 ++++--
.../GHSA-55g6-rmp8-f2fq.json | 29 +++++++++++
.../GHSA-c346-qq93-pfrw.json | 29 +++++++++++
.../GHSA-c36c-4j2q-pp23.json | 52 +++++++++++++++++++
.../GHSA-cg3h-9f75-2rjp.json | 15 ++++--
.../GHSA-cg48-xw7q-cpc8.json | 3 +-
.../GHSA-cxm9-pc6x-88r5.json | 2 +-
.../GHSA-g274-9873-jcxx.json | 2 +-
.../GHSA-j3gx-p9r2-3cwr.json | 15 ++++--
.../GHSA-mcv4-fgfj-mggf.json | 40 ++++++++++++++
.../GHSA-p67q-hj2w-25v7.json | 15 ++++--
.../GHSA-qjcx-8429-2j74.json | 15 ++++--
.../GHSA-qvrp-9f8q-f2v4.json | 52 +++++++++++++++++++
.../GHSA-rvp8-xxf9-v75q.json | 36 +++++++++++++
.../GHSA-v4ww-8j7m-x2h2.json | 36 +++++++++++++
.../GHSA-vw7g-g3g7-v6rm.json | 40 ++++++++++++++
.../GHSA-w896-hhvv-gm4g.json | 36 +++++++++++++
.../GHSA-x5m3-m392-xf85.json | 29 +++++++++++
.../GHSA-xm5p-cw89-f4rg.json | 40 ++++++++++++++
68 files changed, 898 insertions(+), 153 deletions(-)
create mode 100644 advisories/unreviewed/2025/03/GHSA-2cg5-9vjw-w6vg/GHSA-2cg5-9vjw-w6vg.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-2q7g-85wh-78fq/GHSA-2q7g-85wh-78fq.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-55g6-rmp8-f2fq/GHSA-55g6-rmp8-f2fq.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-c346-qq93-pfrw/GHSA-c346-qq93-pfrw.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-c36c-4j2q-pp23/GHSA-c36c-4j2q-pp23.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-mcv4-fgfj-mggf/GHSA-mcv4-fgfj-mggf.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-qvrp-9f8q-f2v4/GHSA-qvrp-9f8q-f2v4.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-rvp8-xxf9-v75q/GHSA-rvp8-xxf9-v75q.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-v4ww-8j7m-x2h2/GHSA-v4ww-8j7m-x2h2.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-vw7g-g3g7-v6rm/GHSA-vw7g-g3g7-v6rm.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-w896-hhvv-gm4g/GHSA-w896-hhvv-gm4g.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-x5m3-m392-xf85/GHSA-x5m3-m392-xf85.json
create mode 100644 advisories/unreviewed/2025/03/GHSA-xm5p-cw89-f4rg/GHSA-xm5p-cw89-f4rg.json
diff --git a/advisories/unreviewed/2023/03/GHSA-c3gq-qcr6-5vj9/GHSA-c3gq-qcr6-5vj9.json b/advisories/unreviewed/2023/03/GHSA-c3gq-qcr6-5vj9/GHSA-c3gq-qcr6-5vj9.json
index 48ae1ee6ce9..a2e4530a6ad 100644
--- a/advisories/unreviewed/2023/03/GHSA-c3gq-qcr6-5vj9/GHSA-c3gq-qcr6-5vj9.json
+++ b/advisories/unreviewed/2023/03/GHSA-c3gq-qcr6-5vj9/GHSA-c3gq-qcr6-5vj9.json
@@ -25,7 +25,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-200"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2023/07/GHSA-62m2-jvfw-mjgv/GHSA-62m2-jvfw-mjgv.json b/advisories/unreviewed/2023/07/GHSA-62m2-jvfw-mjgv/GHSA-62m2-jvfw-mjgv.json
index cd9dfaa1f97..df8e9e29617 100644
--- a/advisories/unreviewed/2023/07/GHSA-62m2-jvfw-mjgv/GHSA-62m2-jvfw-mjgv.json
+++ b/advisories/unreviewed/2023/07/GHSA-62m2-jvfw-mjgv/GHSA-62m2-jvfw-mjgv.json
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-62m2-jvfw-mjgv",
- "modified": "2024-04-04T06:17:27Z",
+ "modified": "2025-03-06T15:34:35Z",
"published": "2023-07-20T00:30:24Z",
"aliases": [
"CVE-2023-37362"
],
- "details": "\n\n\nWeintek Weincloud v0.13.6\n\n \n\ncould allow an attacker to abuse the registration functionality to login with testing credentials to the official website.\n\n\n\n\n\n",
+ "details": "Weintek Weincloud v0.13.6\n\n \n\ncould allow an attacker to abuse the registration functionality to login with testing credentials to the official website.",
"severity": [
{
"type": "CVSS_V3",
@@ -26,7 +26,8 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-287"
+ "CWE-287",
+ "CWE-522"
],
"severity": "HIGH",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2023/09/GHSA-2h72-wjmg-q2hg/GHSA-2h72-wjmg-q2hg.json b/advisories/unreviewed/2023/09/GHSA-2h72-wjmg-q2hg/GHSA-2h72-wjmg-q2hg.json
index ca18a26b6f7..f570b715c46 100644
--- a/advisories/unreviewed/2023/09/GHSA-2h72-wjmg-q2hg/GHSA-2h72-wjmg-q2hg.json
+++ b/advisories/unreviewed/2023/09/GHSA-2h72-wjmg-q2hg/GHSA-2h72-wjmg-q2hg.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2h72-wjmg-q2hg",
- "modified": "2023-09-29T18:30:22Z",
+ "modified": "2025-03-06T15:34:35Z",
"published": "2023-09-29T18:30:22Z",
"aliases": [
"CVE-2023-5269"
@@ -11,6 +11,10 @@
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
+ },
+ {
+ "type": "CVSS_V4",
+ "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
@@ -30,10 +34,19 @@
{
"type": "WEB",
"url": "https://vuldb.com/?id.240882"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?submit.212108"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.sourcecodester.com"
}
],
"database_specific": {
"cwe_ids": [
+ "CWE-74",
"CWE-89"
],
"severity": "MODERATE",
diff --git a/advisories/unreviewed/2024/03/GHSA-gj62-r5fm-pg3q/GHSA-gj62-r5fm-pg3q.json b/advisories/unreviewed/2024/03/GHSA-gj62-r5fm-pg3q/GHSA-gj62-r5fm-pg3q.json
index bcdf09a5cf1..77a4b3c1d60 100644
--- a/advisories/unreviewed/2024/03/GHSA-gj62-r5fm-pg3q/GHSA-gj62-r5fm-pg3q.json
+++ b/advisories/unreviewed/2024/03/GHSA-gj62-r5fm-pg3q/GHSA-gj62-r5fm-pg3q.json
@@ -33,7 +33,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/04/GHSA-8369-88r2-v5v6/GHSA-8369-88r2-v5v6.json b/advisories/unreviewed/2024/04/GHSA-8369-88r2-v5v6/GHSA-8369-88r2-v5v6.json
index c9dc15d569a..c82fc5bd18e 100644
--- a/advisories/unreviewed/2024/04/GHSA-8369-88r2-v5v6/GHSA-8369-88r2-v5v6.json
+++ b/advisories/unreviewed/2024/04/GHSA-8369-88r2-v5v6/GHSA-8369-88r2-v5v6.json
@@ -29,7 +29,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/05/GHSA-3hw4-pvhh-9qcq/GHSA-3hw4-pvhh-9qcq.json b/advisories/unreviewed/2024/05/GHSA-3hw4-pvhh-9qcq/GHSA-3hw4-pvhh-9qcq.json
index 01738548f4a..400843ca20a 100644
--- a/advisories/unreviewed/2024/05/GHSA-3hw4-pvhh-9qcq/GHSA-3hw4-pvhh-9qcq.json
+++ b/advisories/unreviewed/2024/05/GHSA-3hw4-pvhh-9qcq/GHSA-3hw4-pvhh-9qcq.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3hw4-pvhh-9qcq",
- "modified": "2024-05-21T15:31:43Z",
+ "modified": "2025-03-06T15:34:35Z",
"published": "2024-05-21T15:31:43Z",
"aliases": [
"CVE-2021-47346"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncoresight: tmc-etf: Fix global-out-of-bounds in tmc_update_etf_buffer()\n\ncommit 6f755e85c332 (\"coresight: Add helper for inserting synchronization\npackets\") removed trailing '\\0' from barrier_pkt array and updated the\ncall sites like etb_update_buffer() to have proper checks for barrier_pkt\nsize before read but missed updating tmc_update_etf_buffer() which still\nreads barrier_pkt past the array size resulting in KASAN out-of-bounds\nbug. Fix this by adding a check for barrier_pkt size before accessing\nlike it is done in etb_update_buffer().\n\n BUG: KASAN: global-out-of-bounds in tmc_update_etf_buffer+0x4b8/0x698\n Read of size 4 at addr ffffffd05b7d1030 by task perf/2629\n\n Call trace:\n dump_backtrace+0x0/0x27c\n show_stack+0x20/0x2c\n dump_stack+0x11c/0x188\n print_address_description+0x3c/0x4a4\n __kasan_report+0x140/0x164\n kasan_report+0x10/0x18\n __asan_report_load4_noabort+0x1c/0x24\n tmc_update_etf_buffer+0x4b8/0x698\n etm_event_stop+0x248/0x2d8\n etm_event_del+0x20/0x2c\n event_sched_out+0x214/0x6f0\n group_sched_out+0xd0/0x270\n ctx_sched_out+0x2ec/0x518\n __perf_event_task_sched_out+0x4fc/0xe6c\n __schedule+0x1094/0x16a0\n preempt_schedule_irq+0x88/0x170\n arm64_preempt_schedule_irq+0xf0/0x18c\n el1_irq+0xe8/0x180\n perf_event_exec+0x4d8/0x56c\n setup_new_exec+0x204/0x400\n load_elf_binary+0x72c/0x18c0\n search_binary_handler+0x13c/0x420\n load_script+0x500/0x6c4\n search_binary_handler+0x13c/0x420\n exec_binprm+0x118/0x654\n __do_execve_file+0x77c/0xba4\n __arm64_compat_sys_execve+0x98/0xac\n el0_svc_common+0x1f8/0x5e0\n el0_svc_compat_handler+0x84/0xb0\n el0_svc_compat+0x10/0x50\n\n The buggy address belongs to the variable:\n barrier_pkt+0x10/0x40\n\n Memory state around the buggy address:\n ffffffd05b7d0f00: fa fa fa fa 04 fa fa fa fa fa fa fa 00 00 00 00\n ffffffd05b7d0f80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\n >ffffffd05b7d1000: 00 00 00 00 00 00 fa fa fa fa fa fa 00 00 00 03\n ^\n ffffffd05b7d1080: fa fa fa fa 00 02 fa fa fa fa fa fa 03 fa fa fa\n ffffffd05b7d1100: fa fa fa fa 00 00 00 00 05 fa fa fa fa fa fa fa\n ==================================================================",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -40,8 +45,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-125"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-21T15:15:21Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-3p2v-4qj8-6w5f/GHSA-3p2v-4qj8-6w5f.json b/advisories/unreviewed/2024/05/GHSA-3p2v-4qj8-6w5f/GHSA-3p2v-4qj8-6w5f.json
index 5168c5bfddb..867e8c57f6a 100644
--- a/advisories/unreviewed/2024/05/GHSA-3p2v-4qj8-6w5f/GHSA-3p2v-4qj8-6w5f.json
+++ b/advisories/unreviewed/2024/05/GHSA-3p2v-4qj8-6w5f/GHSA-3p2v-4qj8-6w5f.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3p2v-4qj8-6w5f",
- "modified": "2024-05-21T15:31:43Z",
+ "modified": "2025-03-06T15:34:35Z",
"published": "2024-05-21T15:31:43Z",
"aliases": [
"CVE-2021-47339"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: v4l2-core: explicitly clear ioctl input data\n\nAs seen from a recent syzbot bug report, mistakes in the compat ioctl\nimplementation can lead to uninitialized kernel stack data getting used\nas input for driver ioctl handlers.\n\nThe reported bug is now fixed, but it's possible that other related\nbugs are still present or get added in the future. As the drivers need\nto check user input already, the possible impact is fairly low, but it\nmight still cause an information leak.\n\nTo be on the safe side, always clear the entire ioctl buffer before\ncalling the conversion handler functions that are meant to initialize\nthem.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-908"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-21T15:15:20Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-45rj-9f26-3gf5/GHSA-45rj-9f26-3gf5.json b/advisories/unreviewed/2024/05/GHSA-45rj-9f26-3gf5/GHSA-45rj-9f26-3gf5.json
index d4e624a717d..fdf92025f21 100644
--- a/advisories/unreviewed/2024/05/GHSA-45rj-9f26-3gf5/GHSA-45rj-9f26-3gf5.json
+++ b/advisories/unreviewed/2024/05/GHSA-45rj-9f26-3gf5/GHSA-45rj-9f26-3gf5.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-45rj-9f26-3gf5",
- "modified": "2024-08-29T18:31:34Z",
+ "modified": "2025-03-06T15:34:35Z",
"published": "2024-05-19T12:30:39Z",
"aliases": [
"CVE-2024-35937"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: cfg80211: check A-MSDU format more carefully\n\nIf it looks like there's another subframe in the A-MSDU\nbut the header isn't fully there, we can end up reading\ndata out of bounds, only to discard later. Make this a\nbit more careful and check if the subframe header can\neven be present.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -32,8 +37,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-125"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-19T11:15:49Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-7wx4-4999-cgfj/GHSA-7wx4-4999-cgfj.json b/advisories/unreviewed/2024/05/GHSA-7wx4-4999-cgfj/GHSA-7wx4-4999-cgfj.json
index 19f7c424388..0621d13c85c 100644
--- a/advisories/unreviewed/2024/05/GHSA-7wx4-4999-cgfj/GHSA-7wx4-4999-cgfj.json
+++ b/advisories/unreviewed/2024/05/GHSA-7wx4-4999-cgfj/GHSA-7wx4-4999-cgfj.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7wx4-4999-cgfj",
- "modified": "2024-05-21T18:31:21Z",
+ "modified": "2025-03-06T15:34:35Z",
"published": "2024-05-21T18:31:21Z",
"aliases": [
"CVE-2023-52805"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\njfs: fix array-index-out-of-bounds in diAlloc\n\nCurrently there is not check against the agno of the iag while\nallocating new inodes to avoid fragmentation problem. Added the check\nwhich is required.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -52,8 +57,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-129"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-21T16:15:18Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-c352-9339-wrc2/GHSA-c352-9339-wrc2.json b/advisories/unreviewed/2024/05/GHSA-c352-9339-wrc2/GHSA-c352-9339-wrc2.json
index 9fa90d3639e..f984e2b271f 100644
--- a/advisories/unreviewed/2024/05/GHSA-c352-9339-wrc2/GHSA-c352-9339-wrc2.json
+++ b/advisories/unreviewed/2024/05/GHSA-c352-9339-wrc2/GHSA-c352-9339-wrc2.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c352-9339-wrc2",
- "modified": "2024-05-21T18:31:21Z",
+ "modified": "2025-03-06T15:34:35Z",
"published": "2024-05-21T18:31:21Z",
"aliases": [
"CVE-2023-52799"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\njfs: fix array-index-out-of-bounds in dbFindLeaf\n\nCurrently while searching for dmtree_t for sufficient free blocks there\nis an array out of bounds while getting element in tp->dm_stree. To add\nthe required check for out of bound we first need to determine the type\nof dmtree. Thus added an extra parameter to dbFindLeaf so that the type\nof tree can be determined and the required check can be applied.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -52,8 +57,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-129"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-21T16:15:18Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-frc8-7f65-3g5r/GHSA-frc8-7f65-3g5r.json b/advisories/unreviewed/2024/05/GHSA-frc8-7f65-3g5r/GHSA-frc8-7f65-3g5r.json
index e51d0af085a..8b5a619ba7d 100644
--- a/advisories/unreviewed/2024/05/GHSA-frc8-7f65-3g5r/GHSA-frc8-7f65-3g5r.json
+++ b/advisories/unreviewed/2024/05/GHSA-frc8-7f65-3g5r/GHSA-frc8-7f65-3g5r.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-frc8-7f65-3g5r",
- "modified": "2024-05-21T18:31:21Z",
+ "modified": "2025-03-06T15:34:35Z",
"published": "2024-05-21T18:31:21Z",
"aliases": [
"CVE-2023-52794"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nthermal: intel: powerclamp: fix mismatch in get function for max_idle\n\nKASAN reported this\n\n [ 444.853098] BUG: KASAN: global-out-of-bounds in param_get_int+0x77/0x90\n [ 444.853111] Read of size 4 at addr ffffffffc16c9220 by task cat/2105\n ...\n [ 444.853442] The buggy address belongs to the variable:\n [ 444.853443] max_idle+0x0/0xffffffffffffcde0 [intel_powerclamp]\n\nThere is a mismatch between the param_get_int and the definition of\nmax_idle. Replacing param_get_int with param_get_byte resolves this\nissue.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-125"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-21T16:15:18Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-p4g6-hq7c-h438/GHSA-p4g6-hq7c-h438.json b/advisories/unreviewed/2024/05/GHSA-p4g6-hq7c-h438/GHSA-p4g6-hq7c-h438.json
index 71502ad591d..48340b6db35 100644
--- a/advisories/unreviewed/2024/05/GHSA-p4g6-hq7c-h438/GHSA-p4g6-hq7c-h438.json
+++ b/advisories/unreviewed/2024/05/GHSA-p4g6-hq7c-h438/GHSA-p4g6-hq7c-h438.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p4g6-hq7c-h438",
- "modified": "2024-05-21T18:31:20Z",
+ "modified": "2025-03-06T15:34:35Z",
"published": "2024-05-21T18:31:19Z",
"aliases": [
"CVE-2023-52745"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nIB/IPoIB: Fix legacy IPoIB due to wrong number of queues\n\nThe cited commit creates child PKEY interfaces over netlink will\nmultiple tx and rx queues, but some devices doesn't support more than 1\ntx and 1 rx queues. This causes to a crash when traffic is sent over the\nPKEY interface due to the parent having a single queue but the child\nhaving multiple queues.\n\nThis patch fixes the number of queues to 1 for legacy IPoIB at the\nearliest possible point in time.\n\nBUG: kernel NULL pointer dereference, address: 000000000000036b\nPGD 0 P4D 0\nOops: 0000 [#1] SMP\nCPU: 4 PID: 209665 Comm: python3 Not tainted 6.1.0_for_upstream_min_debug_2022_12_12_17_02 #1\nHardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014\nRIP: 0010:kmem_cache_alloc+0xcb/0x450\nCode: ce 7e 49 8b 50 08 49 83 78 10 00 4d 8b 28 0f 84 cb 02 00 00 4d 85 ed 0f 84 c2 02 00 00 41 8b 44 24 28 48 8d 4a\n01 49 8b 3c 24 <49> 8b 5c 05 00 4c 89 e8 65 48 0f c7 0f 0f 94 c0 84 c0 74 b8 41 8b\nRSP: 0018:ffff88822acbbab8 EFLAGS: 00010202\nRAX: 0000000000000070 RBX: ffff8881c28e3e00 RCX: 00000000064f8dae\nRDX: 00000000064f8dad RSI: 0000000000000a20 RDI: 0000000000030d00\nRBP: 0000000000000a20 R08: ffff8882f5d30d00 R09: ffff888104032f40\nR10: ffff88810fade828 R11: 736f6d6570736575 R12: ffff88810081c000\nR13: 00000000000002fb R14: ffffffff817fc865 R15: 0000000000000000\nFS: 00007f9324ff9700(0000) GS:ffff8882f5d00000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 000000000000036b CR3: 00000001125af004 CR4: 0000000000370ea0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nCall Trace:\n \n skb_clone+0x55/0xd0\n ip6_finish_output2+0x3fe/0x690\n ip6_finish_output+0xfa/0x310\n ip6_send_skb+0x1e/0x60\n udp_v6_send_skb+0x1e5/0x420\n udpv6_sendmsg+0xb3c/0xe60\n ? ip_mc_finish_output+0x180/0x180\n ? __switch_to_asm+0x3a/0x60\n ? __switch_to_asm+0x34/0x60\n sock_sendmsg+0x33/0x40\n __sys_sendto+0x103/0x160\n ? _copy_to_user+0x21/0x30\n ? kvm_clock_get_cycles+0xd/0x10\n ? ktime_get_ts64+0x49/0xe0\n __x64_sys_sendto+0x25/0x30\n do_syscall_64+0x3d/0x90\n entry_SYSCALL_64_after_hwframe+0x46/0xb0\nRIP: 0033:0x7f9374f1ed14\nCode: 42 41 f8 ff 44 8b 4c 24 2c 4c 8b 44 24 20 89 c5 44 8b 54 24 28 48 8b 54 24 18 b8 2c 00 00 00 48 8b 74 24 10 8b\n7c 24 08 0f 05 <48> 3d 00 f0 ff ff 77 34 89 ef 48 89 44 24 08 e8 68 41 f8 ff 48 8b\nRSP: 002b:00007f9324ff7bd0 EFLAGS: 00000293 ORIG_RAX: 000000000000002c\nRAX: ffffffffffffffda RBX: 00007f9324ff7cc8 RCX: 00007f9374f1ed14\nRDX: 00000000000002fb RSI: 00007f93000052f0 RDI: 0000000000000030\nRBP: 0000000000000000 R08: 00007f9324ff7d40 R09: 000000000000001c\nR10: 0000000000000000 R11: 0000000000000293 R12: 0000000000000000\nR13: 000000012a05f200 R14: 0000000000000001 R15: 00007f9374d57bdc\n ",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -36,8 +41,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-476"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-21T16:15:14Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-qfp7-gc56-5hcj/GHSA-qfp7-gc56-5hcj.json b/advisories/unreviewed/2024/05/GHSA-qfp7-gc56-5hcj/GHSA-qfp7-gc56-5hcj.json
index 9bb37488add..e7ac0a5a15c 100644
--- a/advisories/unreviewed/2024/05/GHSA-qfp7-gc56-5hcj/GHSA-qfp7-gc56-5hcj.json
+++ b/advisories/unreviewed/2024/05/GHSA-qfp7-gc56-5hcj/GHSA-qfp7-gc56-5hcj.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qfp7-gc56-5hcj",
- "modified": "2024-05-31T09:31:29Z",
+ "modified": "2025-03-06T15:34:36Z",
"published": "2024-05-31T09:31:29Z",
"aliases": [
"CVE-2024-5427"
@@ -37,7 +37,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/05/GHSA-rwr5-hmxr-6v8j/GHSA-rwr5-hmxr-6v8j.json b/advisories/unreviewed/2024/05/GHSA-rwr5-hmxr-6v8j/GHSA-rwr5-hmxr-6v8j.json
index d60a9a84d01..a7231a8255c 100644
--- a/advisories/unreviewed/2024/05/GHSA-rwr5-hmxr-6v8j/GHSA-rwr5-hmxr-6v8j.json
+++ b/advisories/unreviewed/2024/05/GHSA-rwr5-hmxr-6v8j/GHSA-rwr5-hmxr-6v8j.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rwr5-hmxr-6v8j",
- "modified": "2024-05-21T18:31:21Z",
+ "modified": "2025-03-06T15:34:35Z",
"published": "2024-05-21T18:31:21Z",
"aliases": [
"CVE-2023-52807"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: hns3: fix out-of-bounds access may occur when coalesce info is read via debugfs\n\nThe hns3 driver define an array of string to show the coalesce\ninfo, but if the kernel adds a new mode or a new state,\nout-of-bounds access may occur when coalesce info is read via\ndebugfs, this patch fix the problem.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -32,8 +37,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-129"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-21T16:15:19Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-w7qp-vgwj-6g7r/GHSA-w7qp-vgwj-6g7r.json b/advisories/unreviewed/2024/05/GHSA-w7qp-vgwj-6g7r/GHSA-w7qp-vgwj-6g7r.json
index ee818a2de92..5c70623d5c6 100644
--- a/advisories/unreviewed/2024/05/GHSA-w7qp-vgwj-6g7r/GHSA-w7qp-vgwj-6g7r.json
+++ b/advisories/unreviewed/2024/05/GHSA-w7qp-vgwj-6g7r/GHSA-w7qp-vgwj-6g7r.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w7qp-vgwj-6g7r",
- "modified": "2024-06-03T18:55:31Z",
+ "modified": "2025-03-06T15:34:35Z",
"published": "2024-05-23T03:30:40Z",
"aliases": [
"CVE-2024-1855"
@@ -33,7 +33,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-918"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/06/GHSA-r8c3-h27x-qrpx/GHSA-r8c3-h27x-qrpx.json b/advisories/unreviewed/2024/06/GHSA-r8c3-h27x-qrpx/GHSA-r8c3-h27x-qrpx.json
index ed73a7ca11d..24606dbc0c8 100644
--- a/advisories/unreviewed/2024/06/GHSA-r8c3-h27x-qrpx/GHSA-r8c3-h27x-qrpx.json
+++ b/advisories/unreviewed/2024/06/GHSA-r8c3-h27x-qrpx/GHSA-r8c3-h27x-qrpx.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r8c3-h27x-qrpx",
- "modified": "2024-06-19T15:30:54Z",
+ "modified": "2025-03-06T15:34:36Z",
"published": "2024-06-19T15:30:54Z",
"aliases": [
"CVE-2024-38606"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: qat - validate slices count returned by FW\n\nThe function adf_send_admin_tl_start() enables the telemetry (TL)\nfeature on a QAT device by sending the ICP_QAT_FW_TL_START message to\nthe firmware. This triggers the FW to start writing TL data to a DMA\nbuffer in memory and returns an array containing the number of\naccelerators of each type (slices) supported by this HW.\nThe pointer to this array is stored in the adf_tl_hw_data data\nstructure called slice_cnt.\n\nThe array slice_cnt is then used in the function tl_print_dev_data()\nto report in debugfs only statistics about the supported accelerators.\nAn incorrect value of the elements in slice_cnt might lead to an out\nof bounds memory read.\nAt the moment, there isn't an implementation of FW that returns a wrong\nvalue, but for robustness validate the slice count array returned by FW.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-125"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-19T14:15:20Z"
diff --git a/advisories/unreviewed/2024/06/GHSA-x592-qqvv-rpr2/GHSA-x592-qqvv-rpr2.json b/advisories/unreviewed/2024/06/GHSA-x592-qqvv-rpr2/GHSA-x592-qqvv-rpr2.json
index 19bad7a321d..5620248a7b8 100644
--- a/advisories/unreviewed/2024/06/GHSA-x592-qqvv-rpr2/GHSA-x592-qqvv-rpr2.json
+++ b/advisories/unreviewed/2024/06/GHSA-x592-qqvv-rpr2/GHSA-x592-qqvv-rpr2.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x592-qqvv-rpr2",
- "modified": "2024-06-19T15:30:53Z",
+ "modified": "2025-03-06T15:34:36Z",
"published": "2024-06-19T15:30:53Z",
"aliases": [
"CVE-2024-38556"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: Add a timeout to acquire the command queue semaphore\n\nPrevent forced completion handling on an entry that has not yet been\nassigned an index, causing an out of bounds access on idx = -22.\nInstead of waiting indefinitely for the sem, blocking flow now waits for\nindex to be allocated or a sem acquisition timeout before beginning the\ntimer for FW completion.\n\nKernel log example:\nmlx5_core 0000:06:00.0: wait_func_handle_exec_timeout:1128:(pid 185911): cmd[-22]: CREATE_UCTX(0xa04) No done completion",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -36,8 +41,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-129"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-06-19T14:15:15Z"
diff --git a/advisories/unreviewed/2024/07/GHSA-88vm-fw2c-f253/GHSA-88vm-fw2c-f253.json b/advisories/unreviewed/2024/07/GHSA-88vm-fw2c-f253/GHSA-88vm-fw2c-f253.json
index f31fccc9735..e9497d95b07 100644
--- a/advisories/unreviewed/2024/07/GHSA-88vm-fw2c-f253/GHSA-88vm-fw2c-f253.json
+++ b/advisories/unreviewed/2024/07/GHSA-88vm-fw2c-f253/GHSA-88vm-fw2c-f253.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-88vm-fw2c-f253",
- "modified": "2024-07-12T15:31:28Z",
+ "modified": "2025-03-06T15:34:37Z",
"published": "2024-07-12T15:31:28Z",
"aliases": [
"CVE-2024-40926"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/nouveau: don't attempt to schedule hpd_work on headless cards\n\nIf the card doesn't have display hardware, hpd_work and hpd_lock are\nleft uninitialized which causes BUG when attempting to schedule hpd_work\non runtime PM resume.\n\nFix it by adding headless flag to DRM and skip any hpd if it's set.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-908"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-12T13:15:15Z"
diff --git a/advisories/unreviewed/2024/07/GHSA-c6gv-gfxc-vrwh/GHSA-c6gv-gfxc-vrwh.json b/advisories/unreviewed/2024/07/GHSA-c6gv-gfxc-vrwh/GHSA-c6gv-gfxc-vrwh.json
index da2bfa3d6d7..f81ec82c2d1 100644
--- a/advisories/unreviewed/2024/07/GHSA-c6gv-gfxc-vrwh/GHSA-c6gv-gfxc-vrwh.json
+++ b/advisories/unreviewed/2024/07/GHSA-c6gv-gfxc-vrwh/GHSA-c6gv-gfxc-vrwh.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c6gv-gfxc-vrwh",
- "modified": "2024-07-12T15:31:28Z",
+ "modified": "2025-03-06T15:34:37Z",
"published": "2024-07-12T15:31:28Z",
"aliases": [
"CVE-2024-40931"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: ensure snd_una is properly initialized on connect\n\nThis is strictly related to commit fb7a0d334894 (\"mptcp: ensure snd_nxt\nis properly initialized on connect\"). It turns out that syzkaller can\ntrigger the retransmit after fallback and before processing any other\nincoming packet - so that snd_una is still left uninitialized.\n\nAddress the issue explicitly initializing snd_una together with snd_nxt\nand write_seq.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -40,8 +45,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-908"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-12T13:15:15Z"
diff --git a/advisories/unreviewed/2024/07/GHSA-ghhh-5r4g-5v2c/GHSA-ghhh-5r4g-5v2c.json b/advisories/unreviewed/2024/07/GHSA-ghhh-5r4g-5v2c/GHSA-ghhh-5r4g-5v2c.json
index 49221713f9f..1d974af6df1 100644
--- a/advisories/unreviewed/2024/07/GHSA-ghhh-5r4g-5v2c/GHSA-ghhh-5r4g-5v2c.json
+++ b/advisories/unreviewed/2024/07/GHSA-ghhh-5r4g-5v2c/GHSA-ghhh-5r4g-5v2c.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-ghhh-5r4g-5v2c",
- "modified": "2024-07-12T15:31:26Z",
+ "modified": "2025-03-06T15:34:37Z",
"published": "2024-07-12T15:31:26Z",
"aliases": [
"CVE-2024-39507"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: hns3: fix kernel crash problem in concurrent scenario\n\nWhen link status change, the nic driver need to notify the roce\ndriver to handle this event, but at this time, the roce driver\nmay uninit, then cause kernel crash.\n\nTo fix the problem, when link status change, need to check\nwhether the roce registered, and when uninit, need to wait link\nupdate finish.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -36,8 +41,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-908"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-12T13:15:13Z"
diff --git a/advisories/unreviewed/2024/07/GHSA-j2gx-qfwv-h2pp/GHSA-j2gx-qfwv-h2pp.json b/advisories/unreviewed/2024/07/GHSA-j2gx-qfwv-h2pp/GHSA-j2gx-qfwv-h2pp.json
index 6315e92067d..bb218afe3b4 100644
--- a/advisories/unreviewed/2024/07/GHSA-j2gx-qfwv-h2pp/GHSA-j2gx-qfwv-h2pp.json
+++ b/advisories/unreviewed/2024/07/GHSA-j2gx-qfwv-h2pp/GHSA-j2gx-qfwv-h2pp.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j2gx-qfwv-h2pp",
- "modified": "2024-07-12T15:31:29Z",
+ "modified": "2025-03-06T15:34:37Z",
"published": "2024-07-12T15:31:29Z",
"aliases": [
"CVE-2024-40984"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nACPICA: Revert \"ACPICA: avoid Info: mapping multiple BARs. Your kernel is fine.\"\n\nUndo the modifications made in commit d410ee5109a1 (\"ACPICA: avoid\n\"Info: mapping multiple BARs. Your kernel is fine.\"\"). The initial\npurpose of this commit was to stop memory mappings for operation\nregions from overlapping page boundaries, as it can trigger warnings\nif different page attributes are present.\n\nHowever, it was found that when this situation arises, mapping\ncontinues until the boundary's end, but there is still an attempt to\nread/write the entire length of the map, leading to a NULL pointer\ndeference. For example, if a four-byte mapping request is made but\nonly one byte is mapped because it hits the current page boundary's\nend, a four-byte read/write attempt is still made, resulting in a NULL\npointer deference.\n\nInstead, map the entire length, as the ACPI specification does not\nmandate that it must be within the same page boundary. It is\npermissible for it to be mapped across different regions.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -48,8 +53,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-476"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-12T13:15:19Z"
diff --git a/advisories/unreviewed/2024/07/GHSA-pfhx-g36q-294h/GHSA-pfhx-g36q-294h.json b/advisories/unreviewed/2024/07/GHSA-pfhx-g36q-294h/GHSA-pfhx-g36q-294h.json
index f7fb93a793f..ab87c53adb4 100644
--- a/advisories/unreviewed/2024/07/GHSA-pfhx-g36q-294h/GHSA-pfhx-g36q-294h.json
+++ b/advisories/unreviewed/2024/07/GHSA-pfhx-g36q-294h/GHSA-pfhx-g36q-294h.json
@@ -65,7 +65,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/07/GHSA-vjq5-pfrc-9vjr/GHSA-vjq5-pfrc-9vjr.json b/advisories/unreviewed/2024/07/GHSA-vjq5-pfrc-9vjr/GHSA-vjq5-pfrc-9vjr.json
index 9e233493605..2392533efac 100644
--- a/advisories/unreviewed/2024/07/GHSA-vjq5-pfrc-9vjr/GHSA-vjq5-pfrc-9vjr.json
+++ b/advisories/unreviewed/2024/07/GHSA-vjq5-pfrc-9vjr/GHSA-vjq5-pfrc-9vjr.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vjq5-pfrc-9vjr",
- "modified": "2024-07-16T12:30:40Z",
+ "modified": "2025-03-06T15:34:37Z",
"published": "2024-07-16T12:30:40Z",
"aliases": [
"CVE-2022-48805"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: usb: ax88179_178a: Fix out-of-bounds accesses in RX fixup\n\nax88179_rx_fixup() contains several out-of-bounds accesses that can be\ntriggered by a malicious (or defective) USB device, in particular:\n\n - The metadata array (hdr_off..hdr_off+2*pkt_cnt) can be out of bounds,\n causing OOB reads and (on big-endian systems) OOB endianness flips.\n - A packet can overlap the metadata array, causing a later OOB\n endianness flip to corrupt data used by a cloned SKB that has already\n been handed off into the network stack.\n - A packet SKB can be constructed whose tail is far beyond its end,\n causing out-of-bounds heap data to be considered part of the SKB's\n data.\n\nI have tested that this can be used by a malicious USB device to send a\nbogus ICMPv6 Echo Request and receive an ICMPv6 Echo Reply in response\nthat contains random kernel heap data.\nIt's probably also possible to get OOB writes from this on a\nlittle-endian system somehow - maybe by triggering skb_cow() via IP\noptions processing -, but I haven't tested that.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -48,8 +53,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-125"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-16T12:15:04Z"
diff --git a/advisories/unreviewed/2024/07/GHSA-w7f6-93r9-8m94/GHSA-w7f6-93r9-8m94.json b/advisories/unreviewed/2024/07/GHSA-w7f6-93r9-8m94/GHSA-w7f6-93r9-8m94.json
index e4d039e9100..b5bde454d27 100644
--- a/advisories/unreviewed/2024/07/GHSA-w7f6-93r9-8m94/GHSA-w7f6-93r9-8m94.json
+++ b/advisories/unreviewed/2024/07/GHSA-w7f6-93r9-8m94/GHSA-w7f6-93r9-8m94.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w7f6-93r9-8m94",
- "modified": "2024-07-29T15:30:39Z",
+ "modified": "2025-03-06T15:34:37Z",
"published": "2024-07-29T15:30:39Z",
"aliases": [
"CVE-2024-41028"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86: toshiba_acpi: Fix array out-of-bounds access\n\nIn order to use toshiba_dmi_quirks[] together with the standard DMI\nmatching functions, it must be terminated by a empty entry.\n\nSince this entry is missing, an array out-of-bounds access occurs\nevery time the quirk list is processed.\n\nFix this by adding the terminating empty entry.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -32,8 +37,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-129"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-29T15:15:11Z"
diff --git a/advisories/unreviewed/2024/08/GHSA-6cxx-x253-9xcq/GHSA-6cxx-x253-9xcq.json b/advisories/unreviewed/2024/08/GHSA-6cxx-x253-9xcq/GHSA-6cxx-x253-9xcq.json
index 74cad89ae5d..9738011c7f9 100644
--- a/advisories/unreviewed/2024/08/GHSA-6cxx-x253-9xcq/GHSA-6cxx-x253-9xcq.json
+++ b/advisories/unreviewed/2024/08/GHSA-6cxx-x253-9xcq/GHSA-6cxx-x253-9xcq.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6cxx-x253-9xcq",
- "modified": "2024-08-17T09:30:24Z",
+ "modified": "2025-03-06T15:34:37Z",
"published": "2024-08-17T09:30:24Z",
"aliases": [
"CVE-2024-42264"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/v3d: Prevent out of bounds access in performance query extensions\n\nCheck that the number of perfmons userspace is passing in the copy and\nreset extensions is not greater than the internal kernel storage where\nthe ids will be copied into.\n\n(cherry picked from commit f32b5128d2c440368b5bf3a7a356823e235caabb)",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-125"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-17T09:15:07Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-64p7-wm49-vgg4/GHSA-64p7-wm49-vgg4.json b/advisories/unreviewed/2024/12/GHSA-64p7-wm49-vgg4/GHSA-64p7-wm49-vgg4.json
index fc48a34c1c3..8f89121f0f4 100644
--- a/advisories/unreviewed/2024/12/GHSA-64p7-wm49-vgg4/GHSA-64p7-wm49-vgg4.json
+++ b/advisories/unreviewed/2024/12/GHSA-64p7-wm49-vgg4/GHSA-64p7-wm49-vgg4.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-64p7-wm49-vgg4",
- "modified": "2024-12-27T15:31:53Z",
+ "modified": "2025-03-06T15:34:38Z",
"published": "2024-12-27T15:31:53Z",
"aliases": [
"CVE-2024-56548"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nhfsplus: don't query the device logical block size multiple times\n\nDevices block sizes may change. One of these cases is a loop device by\nusing ioctl LOOP_SET_BLOCK_SIZE.\n\nWhile this may cause other issues like IO being rejected, in the case of\nhfsplus, it will allocate a block by using that size and potentially write\nout-of-bounds when hfsplus_read_wrapper calls hfsplus_submit_bio and the\nlatter function reads a different io_size.\n\nUsing a new min_io_size initally set to sb_min_blocksize works for the\npurposes of the original fix, since it will be set to the max between\nHFSPLUS_SECTOR_SIZE and the first seen logical block size. We still use the\nmax between HFSPLUS_SECTOR_SIZE and min_io_size in case the latter is not\ninitialized.\n\nTested by mounting an hfsplus filesystem with loop block sizes 512, 1024\nand 4096.\n\nThe produced KASAN report before the fix looks like this:\n\n[ 419.944641] ==================================================================\n[ 419.945655] BUG: KASAN: slab-use-after-free in hfsplus_read_wrapper+0x659/0xa0a\n[ 419.946703] Read of size 2 at addr ffff88800721fc00 by task repro/10678\n[ 419.947612]\n[ 419.947846] CPU: 0 UID: 0 PID: 10678 Comm: repro Not tainted 6.12.0-rc5-00008-gdf56e0f2f3ca #84\n[ 419.949007] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.15.0-1 04/01/2014\n[ 419.950035] Call Trace:\n[ 419.950384] \n[ 419.950676] dump_stack_lvl+0x57/0x78\n[ 419.951212] ? hfsplus_read_wrapper+0x659/0xa0a\n[ 419.951830] print_report+0x14c/0x49e\n[ 419.952361] ? __virt_addr_valid+0x267/0x278\n[ 419.952979] ? kmem_cache_debug_flags+0xc/0x1d\n[ 419.953561] ? hfsplus_read_wrapper+0x659/0xa0a\n[ 419.954231] kasan_report+0x89/0xb0\n[ 419.954748] ? hfsplus_read_wrapper+0x659/0xa0a\n[ 419.955367] hfsplus_read_wrapper+0x659/0xa0a\n[ 419.955948] ? __pfx_hfsplus_read_wrapper+0x10/0x10\n[ 419.956618] ? do_raw_spin_unlock+0x59/0x1a9\n[ 419.957214] ? _raw_spin_unlock+0x1a/0x2e\n[ 419.957772] hfsplus_fill_super+0x348/0x1590\n[ 419.958355] ? hlock_class+0x4c/0x109\n[ 419.958867] ? __pfx_hfsplus_fill_super+0x10/0x10\n[ 419.959499] ? __pfx_string+0x10/0x10\n[ 419.960006] ? lock_acquire+0x3e2/0x454\n[ 419.960532] ? bdev_name.constprop.0+0xce/0x243\n[ 419.961129] ? __pfx_bdev_name.constprop.0+0x10/0x10\n[ 419.961799] ? pointer+0x3f0/0x62f\n[ 419.962277] ? __pfx_pointer+0x10/0x10\n[ 419.962761] ? vsnprintf+0x6c4/0xfba\n[ 419.963178] ? __pfx_vsnprintf+0x10/0x10\n[ 419.963621] ? setup_bdev_super+0x376/0x3b3\n[ 419.964029] ? snprintf+0x9d/0xd2\n[ 419.964344] ? __pfx_snprintf+0x10/0x10\n[ 419.964675] ? lock_acquired+0x45c/0x5e9\n[ 419.965016] ? set_blocksize+0x139/0x1c1\n[ 419.965381] ? sb_set_blocksize+0x6d/0xae\n[ 419.965742] ? __pfx_hfsplus_fill_super+0x10/0x10\n[ 419.966179] mount_bdev+0x12f/0x1bf\n[ 419.966512] ? __pfx_mount_bdev+0x10/0x10\n[ 419.966886] ? vfs_parse_fs_string+0xce/0x111\n[ 419.967293] ? __pfx_vfs_parse_fs_string+0x10/0x10\n[ 419.967702] ? __pfx_hfsplus_mount+0x10/0x10\n[ 419.968073] legacy_get_tree+0x104/0x178\n[ 419.968414] vfs_get_tree+0x86/0x296\n[ 419.968751] path_mount+0xba3/0xd0b\n[ 419.969157] ? __pfx_path_mount+0x10/0x10\n[ 419.969594] ? kmem_cache_free+0x1e2/0x260\n[ 419.970311] do_mount+0x99/0xe0\n[ 419.970630] ? __pfx_do_mount+0x10/0x10\n[ 419.971008] __do_sys_mount+0x199/0x1c9\n[ 419.971397] do_syscall_64+0xd0/0x135\n[ 419.971761] entry_SYSCALL_64_after_hwframe+0x76/0x7e\n[ 419.972233] RIP: 0033:0x7c3cb812972e\n[ 419.972564] Code: 48 8b 0d f5 46 0d 00 f7 d8 64 89 01 48 83 c8 ff c3 66 2e 0f 1f 84 00 00 00 00 00 90 f3 0f 1e fa 49 89 ca b8 a5 00 00 00 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 8b 0d c2 46 0d 00 f7 d8 64 89 01 48\n[ 419.974371] RSP: 002b:00007ffe30632548 EFLAGS: 00000286 ORIG_RAX: 00000000000000a5\n[ 419.975048] RAX: ffffffffffffffda RBX: 00007ffe306328d8 RCX: 00007c3cb812972e\n[ 419.975701] RDX: 0000000020000000 RSI: 0000000020000c80 RDI:\n---truncated---",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -52,8 +57,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-787"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-27T14:15:34Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-gxj3-vh7p-4j4h/GHSA-gxj3-vh7p-4j4h.json b/advisories/unreviewed/2024/12/GHSA-gxj3-vh7p-4j4h/GHSA-gxj3-vh7p-4j4h.json
index 38148a0fa07..491210111bf 100644
--- a/advisories/unreviewed/2024/12/GHSA-gxj3-vh7p-4j4h/GHSA-gxj3-vh7p-4j4h.json
+++ b/advisories/unreviewed/2024/12/GHSA-gxj3-vh7p-4j4h/GHSA-gxj3-vh7p-4j4h.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gxj3-vh7p-4j4h",
- "modified": "2024-12-24T12:30:43Z",
+ "modified": "2025-03-06T15:34:38Z",
"published": "2024-12-24T12:30:43Z",
"aliases": [
"CVE-2024-53162"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: qat/qat_4xxx - fix off by one in uof_get_name()\n\nThe fw_objs[] array has \"num_objs\" elements so the > needs to be >= to\nprevent an out of bounds read.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -32,8 +37,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-125"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-24T12:15:24Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-j2r5-qpjf-gcfc/GHSA-j2r5-qpjf-gcfc.json b/advisories/unreviewed/2024/12/GHSA-j2r5-qpjf-gcfc/GHSA-j2r5-qpjf-gcfc.json
index 77f6c7579a9..69194facbde 100644
--- a/advisories/unreviewed/2024/12/GHSA-j2r5-qpjf-gcfc/GHSA-j2r5-qpjf-gcfc.json
+++ b/advisories/unreviewed/2024/12/GHSA-j2r5-qpjf-gcfc/GHSA-j2r5-qpjf-gcfc.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j2r5-qpjf-gcfc",
- "modified": "2024-12-27T15:31:52Z",
+ "modified": "2025-03-06T15:34:38Z",
"published": "2024-12-27T15:31:52Z",
"aliases": [
"CVE-2024-53209"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbnxt_en: Fix receive ring space parameters when XDP is active\n\nThe MTU setting at the time an XDP multi-buffer is attached\ndetermines whether the aggregation ring will be used and the\nrx_skb_func handler. This is done in bnxt_set_rx_skb_mode().\n\nIf the MTU is later changed, the aggregation ring setting may need\nto be changed and it may become out-of-sync with the settings\ninitially done in bnxt_set_rx_skb_mode(). This may result in\nrandom memory corruption and crashes as the HW may DMA data larger\nthan the allocated buffer size, such as:\n\nBUG: kernel NULL pointer dereference, address: 00000000000003c0\nPGD 0 P4D 0\nOops: 0000 [#1] PREEMPT SMP NOPTI\nCPU: 17 PID: 0 Comm: swapper/17 Kdump: loaded Tainted: G S OE 6.1.0-226bf9805506 #1\nHardware name: Wiwynn Delta Lake PVT BZA.02601.0150/Delta Lake-Class1, BIOS F0E_3A12 08/26/2021\nRIP: 0010:bnxt_rx_pkt+0xe97/0x1ae0 [bnxt_en]\nCode: 8b 95 70 ff ff ff 4c 8b 9d 48 ff ff ff 66 41 89 87 b4 00 00 00 e9 0b f7 ff ff 0f b7 43 0a 49 8b 95 a8 04 00 00 25 ff 0f 00 00 <0f> b7 14 42 48 c1 e2 06 49 03 95 a0 04 00 00 0f b6 42 33f\nRSP: 0018:ffffa19f40cc0d18 EFLAGS: 00010202\nRAX: 00000000000001e0 RBX: ffff8e2c805c6100 RCX: 00000000000007ff\nRDX: 0000000000000000 RSI: ffff8e2c271ab990 RDI: ffff8e2c84f12380\nRBP: ffffa19f40cc0e48 R08: 000000000001000d R09: 974ea2fcddfa4cbf\nR10: 0000000000000000 R11: ffffa19f40cc0ff8 R12: ffff8e2c94b58980\nR13: ffff8e2c952d6600 R14: 0000000000000016 R15: ffff8e2c271ab990\nFS: 0000000000000000(0000) GS:ffff8e3b3f840000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00000000000003c0 CR3: 0000000e8580a004 CR4: 00000000007706e0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nPKRU: 55555554\nCall Trace:\n \n __bnxt_poll_work+0x1c2/0x3e0 [bnxt_en]\n\nTo address the issue, we now call bnxt_set_rx_skb_mode() within\nbnxt_change_mtu() to properly set the AGG rings configuration and\nupdate rx_skb_func based on the new MTU value.\nAdditionally, BNXT_FLAG_NO_AGG_RINGS is cleared at the beginning of\nbnxt_set_rx_skb_mode() to make sure it gets set or cleared based on\nthe current MTU.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-476"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-27T14:15:28Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-q9f3-jcg6-9j2x/GHSA-q9f3-jcg6-9j2x.json b/advisories/unreviewed/2024/12/GHSA-q9f3-jcg6-9j2x/GHSA-q9f3-jcg6-9j2x.json
index 823dc1ee7a3..87fc80d6ff2 100644
--- a/advisories/unreviewed/2024/12/GHSA-q9f3-jcg6-9j2x/GHSA-q9f3-jcg6-9j2x.json
+++ b/advisories/unreviewed/2024/12/GHSA-q9f3-jcg6-9j2x/GHSA-q9f3-jcg6-9j2x.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q9f3-jcg6-9j2x",
- "modified": "2024-12-27T15:31:53Z",
+ "modified": "2025-03-06T15:34:39Z",
"published": "2024-12-27T15:31:53Z",
"aliases": [
"CVE-2024-56555"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbinder: fix OOB in binder_add_freeze_work()\n\nIn binder_add_freeze_work() we iterate over the proc->nodes with the\nproc->inner_lock held. However, this lock is temporarily dropped to\nacquire the node->lock first (lock nesting order). This can race with\nbinder_deferred_release() which removes the nodes from the proc->nodes\nrbtree and adds them into binder_dead_nodes list. This leads to a broken\niteration in binder_add_freeze_work() as rb_next() will use data from\nbinder_dead_nodes, triggering an out-of-bounds access:\n\n ==================================================================\n BUG: KASAN: global-out-of-bounds in rb_next+0xfc/0x124\n Read of size 8 at addr ffffcb84285f7170 by task freeze/660\n\n CPU: 8 UID: 0 PID: 660 Comm: freeze Not tainted 6.11.0-07343-ga727812a8d45 #18\n Hardware name: linux,dummy-virt (DT)\n Call trace:\n rb_next+0xfc/0x124\n binder_add_freeze_work+0x344/0x534\n binder_ioctl+0x1e70/0x25ac\n __arm64_sys_ioctl+0x124/0x190\n\n The buggy address belongs to the variable:\n binder_dead_nodes+0x10/0x40\n [...]\n ==================================================================\n\nThis is possible because proc->nodes (rbtree) and binder_dead_nodes\n(list) share entries in binder_node through a union:\n\n\tstruct binder_node {\n\t[...]\n\t\tunion {\n\t\t\tstruct rb_node rb_node;\n\t\t\tstruct hlist_node dead_node;\n\t\t};\n\nFix the race by checking that the proc is still alive. If not, simply\nbreak out of the iteration.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-125"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-27T15:15:14Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-wm3v-h2q8-5pg6/GHSA-wm3v-h2q8-5pg6.json b/advisories/unreviewed/2024/12/GHSA-wm3v-h2q8-5pg6/GHSA-wm3v-h2q8-5pg6.json
index b00ef3076c0..a8979ff5479 100644
--- a/advisories/unreviewed/2024/12/GHSA-wm3v-h2q8-5pg6/GHSA-wm3v-h2q8-5pg6.json
+++ b/advisories/unreviewed/2024/12/GHSA-wm3v-h2q8-5pg6/GHSA-wm3v-h2q8-5pg6.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wm3v-h2q8-5pg6",
- "modified": "2024-12-24T12:30:43Z",
+ "modified": "2025-03-06T15:34:38Z",
"published": "2024-12-24T12:30:43Z",
"aliases": [
"CVE-2024-53163"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: qat/qat_420xx - fix off by one in uof_get_name()\n\nThis is called from uof_get_name_420xx() where \"num_objs\" is the\nARRAY_SIZE() of fw_objs[]. The > needs to be >= to prevent an out of\nbounds access.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-193"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-24T12:15:24Z"
diff --git a/advisories/unreviewed/2025/01/GHSA-3xqw-4m9h-8f2c/GHSA-3xqw-4m9h-8f2c.json b/advisories/unreviewed/2025/01/GHSA-3xqw-4m9h-8f2c/GHSA-3xqw-4m9h-8f2c.json
index baa25b27446..3b2709815f6 100644
--- a/advisories/unreviewed/2025/01/GHSA-3xqw-4m9h-8f2c/GHSA-3xqw-4m9h-8f2c.json
+++ b/advisories/unreviewed/2025/01/GHSA-3xqw-4m9h-8f2c/GHSA-3xqw-4m9h-8f2c.json
@@ -26,7 +26,8 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-120"
+ "CWE-120",
+ "CWE-787"
],
"severity": "CRITICAL",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2025/01/GHSA-5r5h-j8r7-pr7g/GHSA-5r5h-j8r7-pr7g.json b/advisories/unreviewed/2025/01/GHSA-5r5h-j8r7-pr7g/GHSA-5r5h-j8r7-pr7g.json
index d466a632f7b..2f7857470f4 100644
--- a/advisories/unreviewed/2025/01/GHSA-5r5h-j8r7-pr7g/GHSA-5r5h-j8r7-pr7g.json
+++ b/advisories/unreviewed/2025/01/GHSA-5r5h-j8r7-pr7g/GHSA-5r5h-j8r7-pr7g.json
@@ -46,7 +46,8 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-119"
+ "CWE-119",
+ "CWE-787"
],
"severity": "HIGH",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2025/01/GHSA-5r5h-v4j5-xvwv/GHSA-5r5h-v4j5-xvwv.json b/advisories/unreviewed/2025/01/GHSA-5r5h-v4j5-xvwv/GHSA-5r5h-v4j5-xvwv.json
index aa8abde66f8..1f5f9eda7d5 100644
--- a/advisories/unreviewed/2025/01/GHSA-5r5h-v4j5-xvwv/GHSA-5r5h-v4j5-xvwv.json
+++ b/advisories/unreviewed/2025/01/GHSA-5r5h-v4j5-xvwv/GHSA-5r5h-v4j5-xvwv.json
@@ -26,7 +26,8 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-120"
+ "CWE-120",
+ "CWE-787"
],
"severity": "CRITICAL",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2025/01/GHSA-p389-5xc8-8rj5/GHSA-p389-5xc8-8rj5.json b/advisories/unreviewed/2025/01/GHSA-p389-5xc8-8rj5/GHSA-p389-5xc8-8rj5.json
index 72fa2f748f3..4709ae93f87 100644
--- a/advisories/unreviewed/2025/01/GHSA-p389-5xc8-8rj5/GHSA-p389-5xc8-8rj5.json
+++ b/advisories/unreviewed/2025/01/GHSA-p389-5xc8-8rj5/GHSA-p389-5xc8-8rj5.json
@@ -26,7 +26,8 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-120"
+ "CWE-120",
+ "CWE-787"
],
"severity": "CRITICAL",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2025/01/GHSA-pmj8-x3xv-95rq/GHSA-pmj8-x3xv-95rq.json b/advisories/unreviewed/2025/01/GHSA-pmj8-x3xv-95rq/GHSA-pmj8-x3xv-95rq.json
index 6cb47d3b076..a487bb57665 100644
--- a/advisories/unreviewed/2025/01/GHSA-pmj8-x3xv-95rq/GHSA-pmj8-x3xv-95rq.json
+++ b/advisories/unreviewed/2025/01/GHSA-pmj8-x3xv-95rq/GHSA-pmj8-x3xv-95rq.json
@@ -26,7 +26,8 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-120"
+ "CWE-120",
+ "CWE-787"
],
"severity": "CRITICAL",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2025/01/GHSA-wm69-gq95-wfj3/GHSA-wm69-gq95-wfj3.json b/advisories/unreviewed/2025/01/GHSA-wm69-gq95-wfj3/GHSA-wm69-gq95-wfj3.json
index 9806d2150f6..3764da141a9 100644
--- a/advisories/unreviewed/2025/01/GHSA-wm69-gq95-wfj3/GHSA-wm69-gq95-wfj3.json
+++ b/advisories/unreviewed/2025/01/GHSA-wm69-gq95-wfj3/GHSA-wm69-gq95-wfj3.json
@@ -46,7 +46,8 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-119"
+ "CWE-119",
+ "CWE-787"
],
"severity": "HIGH",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2025/02/GHSA-6hq3-frr2-vjp4/GHSA-6hq3-frr2-vjp4.json b/advisories/unreviewed/2025/02/GHSA-6hq3-frr2-vjp4/GHSA-6hq3-frr2-vjp4.json
index 1d7d6a57775..c89a9d0bcb9 100644
--- a/advisories/unreviewed/2025/02/GHSA-6hq3-frr2-vjp4/GHSA-6hq3-frr2-vjp4.json
+++ b/advisories/unreviewed/2025/02/GHSA-6hq3-frr2-vjp4/GHSA-6hq3-frr2-vjp4.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6hq3-frr2-vjp4",
- "modified": "2025-02-27T03:34:03Z",
+ "modified": "2025-03-06T15:34:42Z",
"published": "2025-02-27T03:34:03Z",
"aliases": [
"CVE-2024-58010"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbinfmt_flat: Fix integer overflow bug on 32 bit systems\n\nMost of these sizes and counts are capped at 256MB so the math doesn't\nresult in an integer overflow. The \"relocs\" count needs to be checked\nas well. Otherwise on 32bit systems the calculation of \"full_data\"\ncould be wrong.\n\n\tfull_data = data_len + relocs * sizeof(unsigned long);",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -36,8 +41,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-190"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-27T03:15:11Z"
diff --git a/advisories/unreviewed/2025/02/GHSA-7ch8-4hvj-r54q/GHSA-7ch8-4hvj-r54q.json b/advisories/unreviewed/2025/02/GHSA-7ch8-4hvj-r54q/GHSA-7ch8-4hvj-r54q.json
index 961c5f8214c..230d710a548 100644
--- a/advisories/unreviewed/2025/02/GHSA-7ch8-4hvj-r54q/GHSA-7ch8-4hvj-r54q.json
+++ b/advisories/unreviewed/2025/02/GHSA-7ch8-4hvj-r54q/GHSA-7ch8-4hvj-r54q.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7ch8-4hvj-r54q",
- "modified": "2025-02-19T09:33:29Z",
+ "modified": "2025-03-06T15:34:41Z",
"published": "2025-02-19T09:33:29Z",
"aliases": [
"CVE-2024-13736"
diff --git a/advisories/unreviewed/2025/02/GHSA-8929-x24h-jv8r/GHSA-8929-x24h-jv8r.json b/advisories/unreviewed/2025/02/GHSA-8929-x24h-jv8r/GHSA-8929-x24h-jv8r.json
index 25ee53b9d00..577e39a3e0e 100644
--- a/advisories/unreviewed/2025/02/GHSA-8929-x24h-jv8r/GHSA-8929-x24h-jv8r.json
+++ b/advisories/unreviewed/2025/02/GHSA-8929-x24h-jv8r/GHSA-8929-x24h-jv8r.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8929-x24h-jv8r",
- "modified": "2025-02-28T12:32:26Z",
+ "modified": "2025-03-06T15:34:43Z",
"published": "2025-02-28T12:32:26Z",
"aliases": [
"CVE-2024-10860"
diff --git a/advisories/unreviewed/2025/02/GHSA-8fx2-6c45-vg8j/GHSA-8fx2-6c45-vg8j.json b/advisories/unreviewed/2025/02/GHSA-8fx2-6c45-vg8j/GHSA-8fx2-6c45-vg8j.json
index 6e4c54206bd..323c39114a2 100644
--- a/advisories/unreviewed/2025/02/GHSA-8fx2-6c45-vg8j/GHSA-8fx2-6c45-vg8j.json
+++ b/advisories/unreviewed/2025/02/GHSA-8fx2-6c45-vg8j/GHSA-8fx2-6c45-vg8j.json
@@ -30,7 +30,8 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-284"
+ "CWE-284",
+ "CWE-639"
],
"severity": "MODERATE",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2025/02/GHSA-c7vr-vpm2-822g/GHSA-c7vr-vpm2-822g.json b/advisories/unreviewed/2025/02/GHSA-c7vr-vpm2-822g/GHSA-c7vr-vpm2-822g.json
index e9c65421e1d..b413c4a51fb 100644
--- a/advisories/unreviewed/2025/02/GHSA-c7vr-vpm2-822g/GHSA-c7vr-vpm2-822g.json
+++ b/advisories/unreviewed/2025/02/GHSA-c7vr-vpm2-822g/GHSA-c7vr-vpm2-822g.json
@@ -30,6 +30,7 @@
],
"database_specific": {
"cwe_ids": [
+ "CWE-639",
"CWE-862"
],
"severity": "MODERATE",
diff --git a/advisories/unreviewed/2025/02/GHSA-j992-gmv8-p6vw/GHSA-j992-gmv8-p6vw.json b/advisories/unreviewed/2025/02/GHSA-j992-gmv8-p6vw/GHSA-j992-gmv8-p6vw.json
index bdfd8bf1afd..962b7a468a9 100644
--- a/advisories/unreviewed/2025/02/GHSA-j992-gmv8-p6vw/GHSA-j992-gmv8-p6vw.json
+++ b/advisories/unreviewed/2025/02/GHSA-j992-gmv8-p6vw/GHSA-j992-gmv8-p6vw.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j992-gmv8-p6vw",
- "modified": "2025-02-27T03:34:03Z",
+ "modified": "2025-03-06T15:34:42Z",
"published": "2025-02-27T03:34:03Z",
"aliases": [
"CVE-2024-58005"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntpm: Change to kvalloc() in eventlog/acpi.c\n\nThe following failure was reported on HPE ProLiant D320:\n\n[ 10.693310][ T1] tpm_tis STM0925:00: 2.0 TPM (device-id 0x3, rev-id 0)\n[ 10.848132][ T1] ------------[ cut here ]------------\n[ 10.853559][ T1] WARNING: CPU: 59 PID: 1 at mm/page_alloc.c:4727 __alloc_pages_noprof+0x2ca/0x330\n[ 10.862827][ T1] Modules linked in:\n[ 10.866671][ T1] CPU: 59 UID: 0 PID: 1 Comm: swapper/0 Not tainted 6.12.0-lp155.2.g52785e2-default #1 openSUSE Tumbleweed (unreleased) 588cd98293a7c9eba9013378d807364c088c9375\n[ 10.882741][ T1] Hardware name: HPE ProLiant DL320 Gen12/ProLiant DL320 Gen12, BIOS 1.20 10/28/2024\n[ 10.892170][ T1] RIP: 0010:__alloc_pages_noprof+0x2ca/0x330\n[ 10.898103][ T1] Code: 24 08 e9 4a fe ff ff e8 34 36 fa ff e9 88 fe ff ff 83 fe 0a 0f 86 b3 fd ff ff 80 3d 01 e7 ce 01 00 75 09 c6 05 f8 e6 ce 01 01 <0f> 0b 45 31 ff e9 e5 fe ff ff f7 c2 00 00 08 00 75 42 89 d9 80 e1\n[ 10.917750][ T1] RSP: 0000:ffffb7cf40077980 EFLAGS: 00010246\n[ 10.923777][ T1] RAX: 0000000000000000 RBX: 0000000000040cc0 RCX: 0000000000000000\n[ 10.931727][ T1] RDX: 0000000000000000 RSI: 000000000000000c RDI: 0000000000040cc0\n\nThe above transcript shows that ACPI pointed a 16 MiB buffer for the log\nevents because RSI maps to the 'order' parameter of __alloc_pages_noprof().\nAddress the bug by moving from devm_kmalloc() to devm_add_action() and\nkvmalloc() and devm_add_action().",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -33,7 +38,7 @@
],
"database_specific": {
"cwe_ids": [],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-27T03:15:11Z"
diff --git a/advisories/unreviewed/2025/02/GHSA-jcx5-2hxr-pwq4/GHSA-jcx5-2hxr-pwq4.json b/advisories/unreviewed/2025/02/GHSA-jcx5-2hxr-pwq4/GHSA-jcx5-2hxr-pwq4.json
index dfeb7618999..8c8377703a6 100644
--- a/advisories/unreviewed/2025/02/GHSA-jcx5-2hxr-pwq4/GHSA-jcx5-2hxr-pwq4.json
+++ b/advisories/unreviewed/2025/02/GHSA-jcx5-2hxr-pwq4/GHSA-jcx5-2hxr-pwq4.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jcx5-2hxr-pwq4",
- "modified": "2025-02-27T03:34:03Z",
+ "modified": "2025-03-06T15:34:42Z",
"published": "2025-02-27T03:34:03Z",
"aliases": [
"CVE-2024-58011"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86: int3472: Check for adev == NULL\n\nNot all devices have an ACPI companion fwnode, so adev might be NULL. This\ncan e.g. (theoretically) happen when a user manually binds one of\nthe int3472 drivers to another i2c/platform device through sysfs.\n\nAdd a check for adev not being set and return -ENODEV in that case to\navoid a possible NULL pointer deref in skl_int3472_get_acpi_buffer().",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -36,8 +41,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-476"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-27T03:15:12Z"
diff --git a/advisories/unreviewed/2025/02/GHSA-qc22-v4cr-4rv7/GHSA-qc22-v4cr-4rv7.json b/advisories/unreviewed/2025/02/GHSA-qc22-v4cr-4rv7/GHSA-qc22-v4cr-4rv7.json
index 98ffb24e968..a3928038484 100644
--- a/advisories/unreviewed/2025/02/GHSA-qc22-v4cr-4rv7/GHSA-qc22-v4cr-4rv7.json
+++ b/advisories/unreviewed/2025/02/GHSA-qc22-v4cr-4rv7/GHSA-qc22-v4cr-4rv7.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qc22-v4cr-4rv7",
- "modified": "2025-02-27T15:31:51Z",
+ "modified": "2025-03-06T15:34:42Z",
"published": "2025-02-27T03:34:02Z",
"aliases": [
"CVE-2024-58002"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: uvcvideo: Remove dangling pointers\n\nWhen an async control is written, we copy a pointer to the file handle\nthat started the operation. That pointer will be used when the device is\ndone. Which could be anytime in the future.\n\nIf the user closes that file descriptor, its structure will be freed,\nand there will be one dangling pointer per pending async control, that\nthe driver will try to use.\n\nClean all the dangling pointers during release().\n\nTo avoid adding a performance penalty in the most common case (no async\noperation), a counter has been introduced with some logic to make sure\nthat it is properly handled.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -32,8 +37,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-27T03:15:11Z"
diff --git a/advisories/unreviewed/2025/02/GHSA-qwgw-jf68-fjmq/GHSA-qwgw-jf68-fjmq.json b/advisories/unreviewed/2025/02/GHSA-qwgw-jf68-fjmq/GHSA-qwgw-jf68-fjmq.json
index 0de88177179..006394139f6 100644
--- a/advisories/unreviewed/2025/02/GHSA-qwgw-jf68-fjmq/GHSA-qwgw-jf68-fjmq.json
+++ b/advisories/unreviewed/2025/02/GHSA-qwgw-jf68-fjmq/GHSA-qwgw-jf68-fjmq.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qwgw-jf68-fjmq",
- "modified": "2025-02-28T15:31:02Z",
+ "modified": "2025-03-06T15:34:43Z",
"published": "2025-02-28T15:31:02Z",
"aliases": [
"CVE-2025-1319"
diff --git a/advisories/unreviewed/2025/02/GHSA-rg7g-5842-62w5/GHSA-rg7g-5842-62w5.json b/advisories/unreviewed/2025/02/GHSA-rg7g-5842-62w5/GHSA-rg7g-5842-62w5.json
index be4a1516b50..13abd219eae 100644
--- a/advisories/unreviewed/2025/02/GHSA-rg7g-5842-62w5/GHSA-rg7g-5842-62w5.json
+++ b/advisories/unreviewed/2025/02/GHSA-rg7g-5842-62w5/GHSA-rg7g-5842-62w5.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rg7g-5842-62w5",
- "modified": "2025-02-22T06:30:33Z",
+ "modified": "2025-03-06T15:34:41Z",
"published": "2025-02-22T06:30:33Z",
"aliases": [
"CVE-2024-12038"
diff --git a/advisories/unreviewed/2025/02/GHSA-xgjf-869w-4cgj/GHSA-xgjf-869w-4cgj.json b/advisories/unreviewed/2025/02/GHSA-xgjf-869w-4cgj/GHSA-xgjf-869w-4cgj.json
index 18aa0aaf21c..249878cf231 100644
--- a/advisories/unreviewed/2025/02/GHSA-xgjf-869w-4cgj/GHSA-xgjf-869w-4cgj.json
+++ b/advisories/unreviewed/2025/02/GHSA-xgjf-869w-4cgj/GHSA-xgjf-869w-4cgj.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xgjf-869w-4cgj",
- "modified": "2025-02-27T03:34:03Z",
+ "modified": "2025-03-06T15:34:42Z",
"published": "2025-02-27T03:34:02Z",
"aliases": [
"CVE-2024-57834"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: vidtv: Fix a null-ptr-deref in vidtv_mux_stop_thread\n\nsyzbot report a null-ptr-deref in vidtv_mux_stop_thread. [1]\n\nIf dvb->mux is not initialized successfully by vidtv_mux_init() in the\nvidtv_start_streaming(), it will trigger null pointer dereference about mux\nin vidtv_mux_stop_thread().\n\nAdjust the timing of streaming initialization and check it before\nstopping it.\n\n[1]\nKASAN: null-ptr-deref in range [0x0000000000000128-0x000000000000012f]\nCPU: 0 UID: 0 PID: 5842 Comm: syz-executor248 Not tainted 6.13.0-rc4-syzkaller-00012-g9b2ffa6148b1 #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024\nRIP: 0010:vidtv_mux_stop_thread+0x26/0x80 drivers/media/test-drivers/vidtv/vidtv_mux.c:471\nCode: 90 90 90 90 66 0f 1f 00 55 53 48 89 fb e8 82 2e c8 f9 48 8d bb 28 01 00 00 48 b8 00 00 00 00 00 fc ff df 48 89 fa 48 c1 ea 03 <0f> b6 04 02 84 c0 74 02 7e 3b 0f b6 ab 28 01 00 00 31 ff 89 ee e8\nRSP: 0018:ffffc90003f2faa8 EFLAGS: 00010202\nRAX: dffffc0000000000 RBX: 0000000000000000 RCX: ffffffff87cfb125\nRDX: 0000000000000025 RSI: ffffffff87d120ce RDI: 0000000000000128\nRBP: ffff888029b8d220 R08: 0000000000000005 R09: 0000000000000000\nR10: 0000000000000000 R11: 0000000000000003 R12: ffff888029b8d188\nR13: ffffffff8f590aa0 R14: ffffc9000581c5c8 R15: ffff888029a17710\nFS: 00007f7eef5156c0(0000) GS:ffff8880b8600000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007f7eef5e635c CR3: 0000000076ca6000 CR4: 00000000003526f0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nCall Trace:\n \n vidtv_stop_streaming drivers/media/test-drivers/vidtv/vidtv_bridge.c:209 [inline]\n vidtv_stop_feed+0x151/0x250 drivers/media/test-drivers/vidtv/vidtv_bridge.c:252\n dmx_section_feed_stop_filtering+0x90/0x160 drivers/media/dvb-core/dvb_demux.c:1000\n dvb_dmxdev_feed_stop.isra.0+0x1ee/0x270 drivers/media/dvb-core/dmxdev.c:486\n dvb_dmxdev_filter_stop+0x22a/0x3a0 drivers/media/dvb-core/dmxdev.c:559\n dvb_dmxdev_filter_free drivers/media/dvb-core/dmxdev.c:840 [inline]\n dvb_demux_release+0x92/0x550 drivers/media/dvb-core/dmxdev.c:1246\n __fput+0x3f8/0xb60 fs/file_table.c:450\n task_work_run+0x14e/0x250 kernel/task_work.c:239\n get_signal+0x1d3/0x2610 kernel/signal.c:2790\n arch_do_signal_or_restart+0x90/0x7e0 arch/x86/kernel/signal.c:337\n exit_to_user_mode_loop kernel/entry/common.c:111 [inline]\n exit_to_user_mode_prepare include/linux/entry-common.h:329 [inline]\n __syscall_exit_to_user_mode_work kernel/entry/common.c:207 [inline]\n syscall_exit_to_user_mode+0x150/0x2a0 kernel/entry/common.c:218\n do_syscall_64+0xda/0x250 arch/x86/entry/common.c:89\n entry_SYSCALL_64_after_hwframe+0x77/0x7f",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -36,8 +41,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-476"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-27T03:15:10Z"
diff --git a/advisories/unreviewed/2025/03/GHSA-2cg5-9vjw-w6vg/GHSA-2cg5-9vjw-w6vg.json b/advisories/unreviewed/2025/03/GHSA-2cg5-9vjw-w6vg/GHSA-2cg5-9vjw-w6vg.json
new file mode 100644
index 00000000000..69f8b20fb76
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-2cg5-9vjw-w6vg/GHSA-2cg5-9vjw-w6vg.json
@@ -0,0 +1,40 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-2cg5-9vjw-w6vg",
+ "modified": "2025-03-06T15:34:46Z",
+ "published": "2025-03-06T15:34:46Z",
+ "aliases": [
+ "CVE-2025-2045"
+ ],
+ "details": "Improper authorization in GitLab EE affecting all versions from 17.7 prior to 17.7.6, 17.8 prior to 17.8.4, 17.9 prior to 17.9.1 allow users with limited permissions to access to potentially sensitive project analytics data.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2045"
+ },
+ {
+ "type": "WEB",
+ "url": "https://hackerone.com/reports/2921111"
+ },
+ {
+ "type": "WEB",
+ "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/512050"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-863"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-06T13:15:12Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-2q7g-85wh-78fq/GHSA-2q7g-85wh-78fq.json b/advisories/unreviewed/2025/03/GHSA-2q7g-85wh-78fq/GHSA-2q7g-85wh-78fq.json
new file mode 100644
index 00000000000..361b81cc44e
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-2q7g-85wh-78fq/GHSA-2q7g-85wh-78fq.json
@@ -0,0 +1,29 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-2q7g-85wh-78fq",
+ "modified": "2025-03-06T15:34:47Z",
+ "published": "2025-03-06T15:34:47Z",
+ "aliases": [
+ "CVE-2024-42844"
+ ],
+ "details": "A SQL Injection vulnerability has been identified in EPICOR Prophet 21 (P21) up to 23.2.5232. This vulnerability allows authenticated remote attackers to execute arbitrary SQL commands through unsanitized user input fields to obtain unauthorized information",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42844"
+ },
+ {
+ "type": "WEB",
+ "url": "https://gist.github.com/getHecked/dc4ae46526d181d3deb17092815b9bec"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-06T15:15:15Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-4gjv-fwgw-f3qc/GHSA-4gjv-fwgw-f3qc.json b/advisories/unreviewed/2025/03/GHSA-4gjv-fwgw-f3qc/GHSA-4gjv-fwgw-f3qc.json
index abe031a2e73..a00a9e6c6bd 100644
--- a/advisories/unreviewed/2025/03/GHSA-4gjv-fwgw-f3qc/GHSA-4gjv-fwgw-f3qc.json
+++ b/advisories/unreviewed/2025/03/GHSA-4gjv-fwgw-f3qc/GHSA-4gjv-fwgw-f3qc.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4gjv-fwgw-f3qc",
- "modified": "2025-03-05T21:32:12Z",
+ "modified": "2025-03-06T15:34:46Z",
"published": "2025-03-05T21:32:12Z",
"aliases": [
"CVE-2024-48246"
],
"details": "Vehicle Management System 1.0 contains a Stored Cross-Site Scripting (XSS) vulnerability in the \"Name\" parameter of /vehicle-management/booking.php.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
+ }
+ ],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-05T19:15:37Z"
diff --git a/advisories/unreviewed/2025/03/GHSA-55g6-rmp8-f2fq/GHSA-55g6-rmp8-f2fq.json b/advisories/unreviewed/2025/03/GHSA-55g6-rmp8-f2fq/GHSA-55g6-rmp8-f2fq.json
new file mode 100644
index 00000000000..b91aeb00396
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-55g6-rmp8-f2fq/GHSA-55g6-rmp8-f2fq.json
@@ -0,0 +1,29 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-55g6-rmp8-f2fq",
+ "modified": "2025-03-06T15:34:47Z",
+ "published": "2025-03-06T15:34:47Z",
+ "aliases": [
+ "CVE-2025-25451"
+ ],
+ "details": "An issue in TAAGSOLUTIONS GmbH MyTaag v.2024-11-24 and before allows a physically proximate attacker to escalate privileges via the \"2fa_authorized\" Local Storage key",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25451"
+ },
+ {
+ "type": "WEB",
+ "url": "https://piuswalter.de/blog/2fa-bypass-and-deactivation-attack-in-mytaag"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-06T15:15:17Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-c346-qq93-pfrw/GHSA-c346-qq93-pfrw.json b/advisories/unreviewed/2025/03/GHSA-c346-qq93-pfrw/GHSA-c346-qq93-pfrw.json
new file mode 100644
index 00000000000..f1753f5c7dd
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-c346-qq93-pfrw/GHSA-c346-qq93-pfrw.json
@@ -0,0 +1,29 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-c346-qq93-pfrw",
+ "modified": "2025-03-06T15:34:47Z",
+ "published": "2025-03-06T15:34:47Z",
+ "aliases": [
+ "CVE-2025-25450"
+ ],
+ "details": "An issue in TAAGSOLUTIONS GmbH MyTaag v.2024-11-24 and before allows a remote attacker to escalate privileges via the deactivation of the activated second factor to the /session endpoint",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25450"
+ },
+ {
+ "type": "WEB",
+ "url": "https://piuswalter.de/blog/2fa-bypass-and-deactivation-attack-in-mytaag"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-06T15:15:17Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-c36c-4j2q-pp23/GHSA-c36c-4j2q-pp23.json b/advisories/unreviewed/2025/03/GHSA-c36c-4j2q-pp23/GHSA-c36c-4j2q-pp23.json
new file mode 100644
index 00000000000..87c22dc18f5
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-c36c-4j2q-pp23/GHSA-c36c-4j2q-pp23.json
@@ -0,0 +1,52 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-c36c-4j2q-pp23",
+ "modified": "2025-03-06T15:34:48Z",
+ "published": "2025-03-06T15:34:47Z",
+ "aliases": [
+ "CVE-2025-2030"
+ ],
+ "details": "A vulnerability was found in Seeyon Zhiyuan Interconnect FE Collaborative Office Platform up to 20250224. It has been rated as critical. Affected by this issue is some unknown functionality of the file /security/addUser.jsp. The manipulation of the argument groupId leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
+ },
+ {
+ "type": "CVSS_V4",
+ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2030"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/CloudRoam7/CVE/blob/main/CVE_1.md"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?ctiid.298772"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?id.298772"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?submit.505638"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-74"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-06T15:15:18Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-cg3h-9f75-2rjp/GHSA-cg3h-9f75-2rjp.json b/advisories/unreviewed/2025/03/GHSA-cg3h-9f75-2rjp/GHSA-cg3h-9f75-2rjp.json
index 2c71712ed2b..f39711f2c35 100644
--- a/advisories/unreviewed/2025/03/GHSA-cg3h-9f75-2rjp/GHSA-cg3h-9f75-2rjp.json
+++ b/advisories/unreviewed/2025/03/GHSA-cg3h-9f75-2rjp/GHSA-cg3h-9f75-2rjp.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cg3h-9f75-2rjp",
- "modified": "2025-03-05T21:32:13Z",
+ "modified": "2025-03-06T15:34:46Z",
"published": "2025-03-05T21:32:13Z",
"aliases": [
"CVE-2025-25632"
],
"details": "Tenda AC15 v15.03.05.19 is vulnerable to Command Injection via the handler function in /goform/telnet.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-77"
+ ],
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-05T21:15:19Z"
diff --git a/advisories/unreviewed/2025/03/GHSA-cg48-xw7q-cpc8/GHSA-cg48-xw7q-cpc8.json b/advisories/unreviewed/2025/03/GHSA-cg48-xw7q-cpc8/GHSA-cg48-xw7q-cpc8.json
index 4c585e8fa59..451f446b3d3 100644
--- a/advisories/unreviewed/2025/03/GHSA-cg48-xw7q-cpc8/GHSA-cg48-xw7q-cpc8.json
+++ b/advisories/unreviewed/2025/03/GHSA-cg48-xw7q-cpc8/GHSA-cg48-xw7q-cpc8.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cg48-xw7q-cpc8",
- "modified": "2025-03-03T21:31:00Z",
+ "modified": "2025-03-06T15:34:45Z",
"published": "2025-03-03T21:31:00Z",
"aliases": [
"CVE-2024-51961"
@@ -26,6 +26,7 @@
],
"database_specific": {
"cwe_ids": [
+ "CWE-610",
"CWE-73"
],
"severity": "HIGH",
diff --git a/advisories/unreviewed/2025/03/GHSA-cxm9-pc6x-88r5/GHSA-cxm9-pc6x-88r5.json b/advisories/unreviewed/2025/03/GHSA-cxm9-pc6x-88r5/GHSA-cxm9-pc6x-88r5.json
index 023a279778f..5c9cd820c1d 100644
--- a/advisories/unreviewed/2025/03/GHSA-cxm9-pc6x-88r5/GHSA-cxm9-pc6x-88r5.json
+++ b/advisories/unreviewed/2025/03/GHSA-cxm9-pc6x-88r5/GHSA-cxm9-pc6x-88r5.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cxm9-pc6x-88r5",
- "modified": "2025-03-03T21:31:00Z",
+ "modified": "2025-03-06T15:34:45Z",
"published": "2025-03-03T21:31:00Z",
"aliases": [
"CVE-2024-51954"
diff --git a/advisories/unreviewed/2025/03/GHSA-g274-9873-jcxx/GHSA-g274-9873-jcxx.json b/advisories/unreviewed/2025/03/GHSA-g274-9873-jcxx/GHSA-g274-9873-jcxx.json
index cf631f2059a..6d33d196e66 100644
--- a/advisories/unreviewed/2025/03/GHSA-g274-9873-jcxx/GHSA-g274-9873-jcxx.json
+++ b/advisories/unreviewed/2025/03/GHSA-g274-9873-jcxx/GHSA-g274-9873-jcxx.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g274-9873-jcxx",
- "modified": "2025-03-03T21:31:00Z",
+ "modified": "2025-03-06T15:34:45Z",
"published": "2025-03-03T21:31:00Z",
"aliases": [
"CVE-2024-51962"
diff --git a/advisories/unreviewed/2025/03/GHSA-j3gx-p9r2-3cwr/GHSA-j3gx-p9r2-3cwr.json b/advisories/unreviewed/2025/03/GHSA-j3gx-p9r2-3cwr/GHSA-j3gx-p9r2-3cwr.json
index 07a9eae7ef3..a3b6a7d45fe 100644
--- a/advisories/unreviewed/2025/03/GHSA-j3gx-p9r2-3cwr/GHSA-j3gx-p9r2-3cwr.json
+++ b/advisories/unreviewed/2025/03/GHSA-j3gx-p9r2-3cwr/GHSA-j3gx-p9r2-3cwr.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j3gx-p9r2-3cwr",
- "modified": "2025-03-05T21:32:12Z",
+ "modified": "2025-03-06T15:34:46Z",
"published": "2025-03-05T21:32:12Z",
"aliases": [
"CVE-2024-51144"
],
"details": "Cross Site Request Forgery (CSRF) vulnerability exists in the 'pvmsg.php?action=add_message', pvmsg.php?action=confirm_delete , and ajax.server.php?page=user&action=flip_follow endpoints in Ampache <= 6.6.0.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-352"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-05T20:16:05Z"
diff --git a/advisories/unreviewed/2025/03/GHSA-mcv4-fgfj-mggf/GHSA-mcv4-fgfj-mggf.json b/advisories/unreviewed/2025/03/GHSA-mcv4-fgfj-mggf/GHSA-mcv4-fgfj-mggf.json
new file mode 100644
index 00000000000..42b5177f1d1
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-mcv4-fgfj-mggf/GHSA-mcv4-fgfj-mggf.json
@@ -0,0 +1,40 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-mcv4-fgfj-mggf",
+ "modified": "2025-03-06T15:34:46Z",
+ "published": "2025-03-06T15:34:46Z",
+ "aliases": [
+ "CVE-2024-13892"
+ ],
+ "details": "Smartwares cameras CIP-37210AT and C724IP, as well as others which share the same firmware in versions up to 3.3.0, are vulnerable to command injection. \nDuring the initialization process, a user has to use a mobile app to provide devices with Access Point credentials. This input is not properly sanitized, what allows for command injection.\nThe vendor has not replied to reports, so the patching status remains unknown. Newer firmware versions might be vulnerable as well.",
+ "severity": [
+ {
+ "type": "CVSS_V4",
+ "score": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13892"
+ },
+ {
+ "type": "WEB",
+ "url": "https://cert.pl/en/posts/2025/03/CVE-2024-13892"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.smartwares.eu/en-gb/smartwares-cip-37210at-indoor-wi-fi-camera-cip--37210at"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-77"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-06T14:15:35Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-p67q-hj2w-25v7/GHSA-p67q-hj2w-25v7.json b/advisories/unreviewed/2025/03/GHSA-p67q-hj2w-25v7/GHSA-p67q-hj2w-25v7.json
index 8c9488144fe..c1406cf8a84 100644
--- a/advisories/unreviewed/2025/03/GHSA-p67q-hj2w-25v7/GHSA-p67q-hj2w-25v7.json
+++ b/advisories/unreviewed/2025/03/GHSA-p67q-hj2w-25v7/GHSA-p67q-hj2w-25v7.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p67q-hj2w-25v7",
- "modified": "2025-03-05T21:32:13Z",
+ "modified": "2025-03-06T15:34:45Z",
"published": "2025-03-05T21:32:13Z",
"aliases": [
"CVE-2024-31525"
],
"details": "Peppermint Ticket Management 0.4.6 is vulnerable to Incorrect Access Control. A regular registered user is able to elevate his privileges to admin and gain complete access to the system as the authorization mechanism is not validated on the server side and only on the client side. This can result, for example, in creating a new admin user in the system which enables persistent access for the attacker as an administrator.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-306"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-05T19:15:37Z"
diff --git a/advisories/unreviewed/2025/03/GHSA-qjcx-8429-2j74/GHSA-qjcx-8429-2j74.json b/advisories/unreviewed/2025/03/GHSA-qjcx-8429-2j74/GHSA-qjcx-8429-2j74.json
index 5298ea4b89e..99348c3f384 100644
--- a/advisories/unreviewed/2025/03/GHSA-qjcx-8429-2j74/GHSA-qjcx-8429-2j74.json
+++ b/advisories/unreviewed/2025/03/GHSA-qjcx-8429-2j74/GHSA-qjcx-8429-2j74.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qjcx-8429-2j74",
- "modified": "2025-03-06T06:30:53Z",
+ "modified": "2025-03-06T15:34:46Z",
"published": "2025-03-06T06:30:53Z",
"aliases": [
"CVE-2024-13868"
],
"details": "The URL Shortener | Conversion Tracking | AB Testing | WooCommerce WordPress plugin through 9.0.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
+ }
+ ],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-06T06:15:34Z"
diff --git a/advisories/unreviewed/2025/03/GHSA-qvrp-9f8q-f2v4/GHSA-qvrp-9f8q-f2v4.json b/advisories/unreviewed/2025/03/GHSA-qvrp-9f8q-f2v4/GHSA-qvrp-9f8q-f2v4.json
new file mode 100644
index 00000000000..52bb17b507c
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-qvrp-9f8q-f2v4/GHSA-qvrp-9f8q-f2v4.json
@@ -0,0 +1,52 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-qvrp-9f8q-f2v4",
+ "modified": "2025-03-06T15:34:47Z",
+ "published": "2025-03-06T15:34:47Z",
+ "aliases": [
+ "CVE-2025-2029"
+ ],
+ "details": "A vulnerability was found in MicroDicom DICOM Viewer 2025.1 Build 3321. It has been classified as critical. Affected is an unknown function of the file mDicom.exe. The manipulation leads to memory corruption. The attack needs to be approached locally. It is recommended to upgrade the affected component. The vendor quickly confirmed the existence of the vulnerability and fixed it in the latest beta.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
+ },
+ {
+ "type": "CVSS_V4",
+ "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2029"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?ctiid.298770"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?id.298770"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?submit.506579"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.microdicom.com/beta.html"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-119"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-06T15:15:17Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-rvp8-xxf9-v75q/GHSA-rvp8-xxf9-v75q.json b/advisories/unreviewed/2025/03/GHSA-rvp8-xxf9-v75q/GHSA-rvp8-xxf9-v75q.json
new file mode 100644
index 00000000000..725bc8c920c
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-rvp8-xxf9-v75q/GHSA-rvp8-xxf9-v75q.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-rvp8-xxf9-v75q",
+ "modified": "2025-03-06T15:34:47Z",
+ "published": "2025-03-06T15:34:47Z",
+ "aliases": [
+ "CVE-2024-12146"
+ ],
+ "details": "Improper Validation of Syntactic Correctness of Input vulnerability in Finder Fire Safety Finder ERP/CRM (New System) allows SQL Injection.This issue affects Finder ERP/CRM (New System): before 18.12.2024.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12146"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.usom.gov.tr/bildirim/tr-25-0060"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-1286"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-06T15:15:15Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-v4ww-8j7m-x2h2/GHSA-v4ww-8j7m-x2h2.json b/advisories/unreviewed/2025/03/GHSA-v4ww-8j7m-x2h2/GHSA-v4ww-8j7m-x2h2.json
new file mode 100644
index 00000000000..00bf0ef6c4d
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-v4ww-8j7m-x2h2/GHSA-v4ww-8j7m-x2h2.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-v4ww-8j7m-x2h2",
+ "modified": "2025-03-06T15:34:46Z",
+ "published": "2025-03-06T15:34:46Z",
+ "aliases": [
+ "CVE-2024-12144"
+ ],
+ "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Finder Fire Safety Finder ERP/CRM (Old System) allows SQL Injection.This issue affects Finder ERP/CRM (Old System): before 18.12.2024.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12144"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.usom.gov.tr/bildirim/tr-25-0060"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-89"
+ ],
+ "severity": "CRITICAL",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-06T14:15:35Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-vw7g-g3g7-v6rm/GHSA-vw7g-g3g7-v6rm.json b/advisories/unreviewed/2025/03/GHSA-vw7g-g3g7-v6rm/GHSA-vw7g-g3g7-v6rm.json
new file mode 100644
index 00000000000..045a94b7133
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-vw7g-g3g7-v6rm/GHSA-vw7g-g3g7-v6rm.json
@@ -0,0 +1,40 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-vw7g-g3g7-v6rm",
+ "modified": "2025-03-06T15:34:47Z",
+ "published": "2025-03-06T15:34:47Z",
+ "aliases": [
+ "CVE-2024-13894"
+ ],
+ "details": "Smartwares cameras CIP-37210AT and C724IP, as well as others which share the same firmware in versions up to 3.3.0, are vulnerable to path traversal. \nWhen an affected device is connected to a mobile app, it opens a port 10000 enabling a user to download pictures shot at specific moments by providing paths to the files. However, the directories to which a user has access are not limited, allowing for path traversal attacks and downloading sensitive information.\nThe vendor has not replied to reports, so the patching status remains unknown. Newer firmware versions might be vulnerable as well.",
+ "severity": [
+ {
+ "type": "CVSS_V4",
+ "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13894"
+ },
+ {
+ "type": "WEB",
+ "url": "https://cert.pl/en/posts/2025/03/CVE-2024-13892"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.smartwares.eu/en-gb/smartwares-cip-37210at-indoor-wi-fi-camera-cip--37210at"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-22"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-06T14:15:35Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-w896-hhvv-gm4g/GHSA-w896-hhvv-gm4g.json b/advisories/unreviewed/2025/03/GHSA-w896-hhvv-gm4g/GHSA-w896-hhvv-gm4g.json
new file mode 100644
index 00000000000..2cd57cccd69
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-w896-hhvv-gm4g/GHSA-w896-hhvv-gm4g.json
@@ -0,0 +1,36 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-w896-hhvv-gm4g",
+ "modified": "2025-03-06T15:34:47Z",
+ "published": "2025-03-06T15:34:47Z",
+ "aliases": [
+ "CVE-2025-0877"
+ ],
+ "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in AtaksAPP Reservation Management System allows Cross-Site Scripting (XSS).This issue affects Reservation Management System: before 4.2.3.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0877"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.usom.gov.tr/bildirim/tr-25-0059"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-06T14:15:36Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-x5m3-m392-xf85/GHSA-x5m3-m392-xf85.json b/advisories/unreviewed/2025/03/GHSA-x5m3-m392-xf85/GHSA-x5m3-m392-xf85.json
new file mode 100644
index 00000000000..a418fe25916
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-x5m3-m392-xf85/GHSA-x5m3-m392-xf85.json
@@ -0,0 +1,29 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-x5m3-m392-xf85",
+ "modified": "2025-03-06T15:34:47Z",
+ "published": "2025-03-06T15:34:47Z",
+ "aliases": [
+ "CVE-2025-25452"
+ ],
+ "details": "An issue in TAAGSOLUTIONS GmbH MyTaag v.2024-11-24 and before allows a remote attacker to escalate privileges via the \"/user\" endpoint",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25452"
+ },
+ {
+ "type": "WEB",
+ "url": "https://piuswalter.de/blog/2fa-bypass-and-deactivation-attack-in-mytaag"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-06T15:15:17Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/03/GHSA-xm5p-cw89-f4rg/GHSA-xm5p-cw89-f4rg.json b/advisories/unreviewed/2025/03/GHSA-xm5p-cw89-f4rg/GHSA-xm5p-cw89-f4rg.json
new file mode 100644
index 00000000000..a1f0aa3ea35
--- /dev/null
+++ b/advisories/unreviewed/2025/03/GHSA-xm5p-cw89-f4rg/GHSA-xm5p-cw89-f4rg.json
@@ -0,0 +1,40 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-xm5p-cw89-f4rg",
+ "modified": "2025-03-06T15:34:46Z",
+ "published": "2025-03-06T15:34:46Z",
+ "aliases": [
+ "CVE-2024-13893"
+ ],
+ "details": "Smartwares cameras CIP-37210AT and C724IP, as well as others which share the same firmware in versions up to 3.3.0, might share same credentials for telnet service. Hash of the password can be retrieved through physical access to SPI connected memory.\nFor the telnet service to be enabled, the inserted SD card needs to have a folder with a specific name created. \nTwo products were tested, but since the vendor has not replied to reports, patching status remains unknown, as well as groups of devices and firmware ranges in which the same password is shared.\n Newer firmware versions might be vulnerable as well.",
+ "severity": [
+ {
+ "type": "CVSS_V4",
+ "score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13893"
+ },
+ {
+ "type": "WEB",
+ "url": "https://cert.pl/en/posts/2025/03/CVE-2024-13892"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.smartwares.eu/en-gb/smartwares-cip-37210at-indoor-wi-fi-camera-cip--37210at"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-1392"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-03-06T14:15:35Z"
+ }
+}
\ No newline at end of file