From 429b01635b09ace636b980a03adffbfa16752ad4 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 7 Jan 2025 21:31:56 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-2xm8-8q96-qxhc.json | 10 ++++- .../GHSA-5jhv-q32v-v4q2.json | 10 ++++- .../GHSA-c2gj-fphg-qv3q.json | 10 ++++- .../GHSA-g2pv-jwfp-hm99.json | 10 ++++- .../GHSA-jj96-j367-3jx7.json | 10 ++++- .../GHSA-ppmm-vg73-p2w2.json | 11 +++++- .../GHSA-pq38-mrwr-77j3.json | 10 ++++- .../GHSA-q3jf-w4ph-7r73.json | 10 ++++- .../GHSA-wjh5-2jj8-8xpj.json | 10 ++++- .../GHSA-5gqw-x43v-hg43.json | 1 + .../GHSA-6pxx-9rr9-j7h4.json | 1 + .../GHSA-77vj-9qxr-p2qf.json | 1 + .../GHSA-g23p-v3rc-vq74.json | 1 + .../GHSA-hr98-7gw3-84v4.json | 1 + .../GHSA-m786-rxff-x32m.json | 1 + .../GHSA-pg3q-6wmp-whpx.json | 1 + .../GHSA-g78x-643m-9qmf.json | 4 +- .../GHSA-hrgc-qp5r-xq3p.json | 4 +- .../GHSA-jc2w-6rjp-h443.json | 4 +- .../GHSA-48ww-vppq-9c8v.json | 15 ++++++-- .../GHSA-9rrq-f95g-4wmq.json | 15 ++++++-- .../GHSA-gxqp-64jf-hj53.json | 15 ++++++-- .../GHSA-pqmh-qr2r-5wwj.json | 15 ++++++-- .../GHSA-q5p6-rx6m-vx4m.json | 1 + .../GHSA-3vhh-8wwm-whvg.json | 15 ++++++-- .../GHSA-5qq4-q34c-9875.json | 4 +- .../GHSA-78j7-xmw6-68gr.json | 15 ++++++-- .../GHSA-97mp-32j5-q87r.json | 15 ++++++-- .../GHSA-98m4-jppc-qq3m.json | 15 ++++++-- .../GHSA-f6g6-gf5g-h3f3.json | 15 ++++++-- .../GHSA-fg2w-r2w5-mgjw.json | 15 ++++++-- .../GHSA-m5hg-cjq4-86mq.json | 15 ++++++-- .../GHSA-pgm2-2p72-h4hg.json | 15 ++++++-- .../GHSA-pjwq-hg2p-9vw7.json | 15 ++++++-- .../GHSA-vhpg-m2r9-345p.json | 15 ++++++-- .../GHSA-wfcg-p9mh-53w7.json | 15 ++++++-- .../GHSA-x723-q7ww-gm79.json | 4 +- .../GHSA-24vw-fq64-647q.json | 15 ++++++-- .../GHSA-263c-689v-jcfh.json | 3 +- .../GHSA-28j2-gr4p-p982.json | 15 ++++++-- .../GHSA-2m7m-jhx5-8crh.json | 1 + .../GHSA-2xxj-gwfx-rr2c.json | 15 ++++++-- .../GHSA-fh33-v9vq-826f.json | 15 ++++++-- .../GHSA-mcp9-hfjj-cpp5.json | 1 + .../GHSA-rrxx-mf3x-75gw.json | 4 +- .../GHSA-x6jr-wrhc-h2x2.json | 1 + .../GHSA-xwj2-c9hw-p6p6.json | 15 ++++++-- .../GHSA-gr2q-rxqg-mrrq.json | 2 +- .../GHSA-8x2h-c9mx-cx2j.json | 3 +- .../GHSA-42wq-32p9-mf48.json | 15 ++++++-- .../GHSA-pqw3-898v-hg67.json | 15 ++++++-- .../GHSA-23fx-r767-q5g7.json | 37 +++++++++++++++++++ .../GHSA-3695-47qv-rc3x.json | 4 +- .../GHSA-39fw-qmf8-vr6v.json | 15 ++++++-- .../GHSA-3wcp-pwj7-fwmf.json | 4 +- .../GHSA-3wv8-q6g7-7frh.json | 33 +++++++++++++++++ .../GHSA-533j-w77v-fmxv.json | 15 ++++++-- .../GHSA-7x7r-gpvw-q53f.json | 33 +++++++++++++++++ .../GHSA-8rg4-cvw3-v3c2.json | 15 ++++++-- .../GHSA-9w8w-fgjg-w972.json | 33 +++++++++++++++++ .../GHSA-c2qq-pcr6-27vg.json | 15 ++++++-- .../GHSA-frx6-qwhw-g358.json | 15 ++++++-- .../GHSA-fv2q-p9cw-m9w5.json | 33 +++++++++++++++++ .../GHSA-g968-64xh-hq2x.json | 15 ++++++-- .../GHSA-hg4v-r4m7-xj5j.json | 15 ++++++-- .../GHSA-j2pc-4j53-q3ww.json | 36 ++++++++++++++++++ .../GHSA-qjmp-rfrj-7cv5.json | 37 +++++++++++++++++++ .../GHSA-r253-3wvv-8j5p.json | 15 ++++++-- .../GHSA-vh28-f7wh-hg42.json | 37 +++++++++++++++++++ .../GHSA-vrcp-29m9-49c3.json | 15 ++++++-- .../GHSA-vw24-gw6x-f64v.json | 15 ++++++-- .../GHSA-w3jp-95q8-wv48.json | 37 +++++++++++++++++++ .../GHSA-w3wc-83g3-v333.json | 33 +++++++++++++++++ 73 files changed, 823 insertions(+), 148 deletions(-) create mode 100644 advisories/unreviewed/2025/01/GHSA-23fx-r767-q5g7/GHSA-23fx-r767-q5g7.json create mode 100644 advisories/unreviewed/2025/01/GHSA-3wv8-q6g7-7frh/GHSA-3wv8-q6g7-7frh.json create mode 100644 advisories/unreviewed/2025/01/GHSA-7x7r-gpvw-q53f/GHSA-7x7r-gpvw-q53f.json create mode 100644 advisories/unreviewed/2025/01/GHSA-9w8w-fgjg-w972/GHSA-9w8w-fgjg-w972.json create mode 100644 advisories/unreviewed/2025/01/GHSA-fv2q-p9cw-m9w5/GHSA-fv2q-p9cw-m9w5.json create mode 100644 advisories/unreviewed/2025/01/GHSA-j2pc-4j53-q3ww/GHSA-j2pc-4j53-q3ww.json create mode 100644 advisories/unreviewed/2025/01/GHSA-qjmp-rfrj-7cv5/GHSA-qjmp-rfrj-7cv5.json create mode 100644 advisories/unreviewed/2025/01/GHSA-vh28-f7wh-hg42/GHSA-vh28-f7wh-hg42.json create mode 100644 advisories/unreviewed/2025/01/GHSA-w3jp-95q8-wv48/GHSA-w3jp-95q8-wv48.json create mode 100644 advisories/unreviewed/2025/01/GHSA-w3wc-83g3-v333/GHSA-w3wc-83g3-v333.json diff --git a/advisories/unreviewed/2022/09/GHSA-2xm8-8q96-qxhc/GHSA-2xm8-8q96-qxhc.json b/advisories/unreviewed/2022/09/GHSA-2xm8-8q96-qxhc/GHSA-2xm8-8q96-qxhc.json index d2c74b212ef..5928356f17b 100644 --- a/advisories/unreviewed/2022/09/GHSA-2xm8-8q96-qxhc/GHSA-2xm8-8q96-qxhc.json +++ b/advisories/unreviewed/2022/09/GHSA-2xm8-8q96-qxhc/GHSA-2xm8-8q96-qxhc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2xm8-8q96-qxhc", - "modified": "2022-09-18T00:00:30Z", + "modified": "2025-01-07T21:30:53Z", "published": "2022-09-16T00:00:38Z", "aliases": [ "CVE-2022-40660" @@ -19,6 +19,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-40660" }, + { + "type": "WEB", + "url": "https://www.software-dl.microscope.healthcare.nikon.com/vuln/index.html" + }, + { + "type": "WEB", + "url": "https://www.software-dl.microscope.healthcare.nikon.com/vuln/pdf/Vulnerabilities_on_NIS-Elements_Freeware_and_L_en_240917_02.pdf" + }, { "type": "WEB", "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1216" diff --git a/advisories/unreviewed/2022/09/GHSA-5jhv-q32v-v4q2/GHSA-5jhv-q32v-v4q2.json b/advisories/unreviewed/2022/09/GHSA-5jhv-q32v-v4q2/GHSA-5jhv-q32v-v4q2.json index 7216fee195d..85177b088da 100644 --- a/advisories/unreviewed/2022/09/GHSA-5jhv-q32v-v4q2/GHSA-5jhv-q32v-v4q2.json +++ b/advisories/unreviewed/2022/09/GHSA-5jhv-q32v-v4q2/GHSA-5jhv-q32v-v4q2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5jhv-q32v-v4q2", - "modified": "2022-09-18T00:00:30Z", + "modified": "2025-01-07T21:30:53Z", "published": "2022-09-16T00:00:38Z", "aliases": [ "CVE-2022-40659" @@ -19,6 +19,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-40659" }, + { + "type": "WEB", + "url": "https://www.software-dl.microscope.healthcare.nikon.com/vuln/index.html" + }, + { + "type": "WEB", + "url": "https://www.software-dl.microscope.healthcare.nikon.com/vuln/pdf/Vulnerabilities_on_NIS-Elements_Freeware_and_L_en_240917_02.pdf" + }, { "type": "WEB", "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1215" diff --git a/advisories/unreviewed/2022/09/GHSA-c2gj-fphg-qv3q/GHSA-c2gj-fphg-qv3q.json b/advisories/unreviewed/2022/09/GHSA-c2gj-fphg-qv3q/GHSA-c2gj-fphg-qv3q.json index 6c8467db357..b07e3609385 100644 --- a/advisories/unreviewed/2022/09/GHSA-c2gj-fphg-qv3q/GHSA-c2gj-fphg-qv3q.json +++ b/advisories/unreviewed/2022/09/GHSA-c2gj-fphg-qv3q/GHSA-c2gj-fphg-qv3q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c2gj-fphg-qv3q", - "modified": "2022-09-18T00:00:31Z", + "modified": "2025-01-07T21:30:53Z", "published": "2022-09-16T00:00:38Z", "aliases": [ "CVE-2022-40658" @@ -19,6 +19,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-40658" }, + { + "type": "WEB", + "url": "https://www.software-dl.microscope.healthcare.nikon.com/vuln/index.html" + }, + { + "type": "WEB", + "url": "https://www.software-dl.microscope.healthcare.nikon.com/vuln/pdf/Vulnerabilities_on_NIS-Elements_Freeware_and_L_en_240917_02.pdf" + }, { "type": "WEB", "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1214" diff --git a/advisories/unreviewed/2022/09/GHSA-g2pv-jwfp-hm99/GHSA-g2pv-jwfp-hm99.json b/advisories/unreviewed/2022/09/GHSA-g2pv-jwfp-hm99/GHSA-g2pv-jwfp-hm99.json index fb28ae8b0f0..b77bd467a57 100644 --- a/advisories/unreviewed/2022/09/GHSA-g2pv-jwfp-hm99/GHSA-g2pv-jwfp-hm99.json +++ b/advisories/unreviewed/2022/09/GHSA-g2pv-jwfp-hm99/GHSA-g2pv-jwfp-hm99.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g2pv-jwfp-hm99", - "modified": "2022-09-18T00:00:31Z", + "modified": "2025-01-07T21:30:53Z", "published": "2022-09-16T00:00:38Z", "aliases": [ "CVE-2022-40657" @@ -19,6 +19,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-40657" }, + { + "type": "WEB", + "url": "https://www.software-dl.microscope.healthcare.nikon.com/vuln/index.html" + }, + { + "type": "WEB", + "url": "https://www.software-dl.microscope.healthcare.nikon.com/vuln/pdf/Vulnerabilities_on_NIS-Elements_Freeware_and_L_en_240917_02.pdf" + }, { "type": "WEB", "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1213" diff --git a/advisories/unreviewed/2022/09/GHSA-jj96-j367-3jx7/GHSA-jj96-j367-3jx7.json b/advisories/unreviewed/2022/09/GHSA-jj96-j367-3jx7/GHSA-jj96-j367-3jx7.json index 9474383ed92..4626f143db8 100644 --- a/advisories/unreviewed/2022/09/GHSA-jj96-j367-3jx7/GHSA-jj96-j367-3jx7.json +++ b/advisories/unreviewed/2022/09/GHSA-jj96-j367-3jx7/GHSA-jj96-j367-3jx7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jj96-j367-3jx7", - "modified": "2022-09-18T00:00:31Z", + "modified": "2025-01-07T21:30:53Z", "published": "2022-09-16T00:00:38Z", "aliases": [ "CVE-2022-40661" @@ -19,6 +19,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-40661" }, + { + "type": "WEB", + "url": "https://www.software-dl.microscope.healthcare.nikon.com/vuln/index.html" + }, + { + "type": "WEB", + "url": "https://www.software-dl.microscope.healthcare.nikon.com/vuln/pdf/Vulnerabilities_on_NIS-Elements_Freeware_and_L_en_240917_02.pdf" + }, { "type": "WEB", "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1217" diff --git a/advisories/unreviewed/2022/09/GHSA-ppmm-vg73-p2w2/GHSA-ppmm-vg73-p2w2.json b/advisories/unreviewed/2022/09/GHSA-ppmm-vg73-p2w2/GHSA-ppmm-vg73-p2w2.json index e87725dd25d..045a543bb47 100644 --- a/advisories/unreviewed/2022/09/GHSA-ppmm-vg73-p2w2/GHSA-ppmm-vg73-p2w2.json +++ b/advisories/unreviewed/2022/09/GHSA-ppmm-vg73-p2w2/GHSA-ppmm-vg73-p2w2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ppmm-vg73-p2w2", - "modified": "2022-09-18T00:00:31Z", + "modified": "2025-01-07T21:30:52Z", "published": "2022-09-16T00:00:38Z", "aliases": [ "CVE-2022-40655" @@ -19,6 +19,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-40655" }, + { + "type": "WEB", + "url": "https://www.software-dl.microscope.healthcare.nikon.com/vuln/index.html" + }, + { + "type": "WEB", + "url": "https://www.software-dl.microscope.healthcare.nikon.com/vuln/pdf/Vulnerabilities_on_NIS-Elements_Freeware_and_L_en_240917_02.pdf" + }, { "type": "WEB", "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1211" @@ -26,6 +34,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-122", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/09/GHSA-pq38-mrwr-77j3/GHSA-pq38-mrwr-77j3.json b/advisories/unreviewed/2022/09/GHSA-pq38-mrwr-77j3/GHSA-pq38-mrwr-77j3.json index 02c35e0cb6c..cd5e2997085 100644 --- a/advisories/unreviewed/2022/09/GHSA-pq38-mrwr-77j3/GHSA-pq38-mrwr-77j3.json +++ b/advisories/unreviewed/2022/09/GHSA-pq38-mrwr-77j3/GHSA-pq38-mrwr-77j3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pq38-mrwr-77j3", - "modified": "2022-09-18T00:00:31Z", + "modified": "2025-01-07T21:30:52Z", "published": "2022-09-16T00:00:37Z", "aliases": [ "CVE-2022-40656" @@ -19,6 +19,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-40656" }, + { + "type": "WEB", + "url": "https://www.software-dl.microscope.healthcare.nikon.com/vuln/index.html" + }, + { + "type": "WEB", + "url": "https://www.software-dl.microscope.healthcare.nikon.com/vuln/pdf/Vulnerabilities_on_NIS-Elements_Freeware_and_L_en_240917_02.pdf" + }, { "type": "WEB", "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1212" diff --git a/advisories/unreviewed/2022/09/GHSA-q3jf-w4ph-7r73/GHSA-q3jf-w4ph-7r73.json b/advisories/unreviewed/2022/09/GHSA-q3jf-w4ph-7r73/GHSA-q3jf-w4ph-7r73.json index 299008df88a..c831466d5ee 100644 --- a/advisories/unreviewed/2022/09/GHSA-q3jf-w4ph-7r73/GHSA-q3jf-w4ph-7r73.json +++ b/advisories/unreviewed/2022/09/GHSA-q3jf-w4ph-7r73/GHSA-q3jf-w4ph-7r73.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q3jf-w4ph-7r73", - "modified": "2022-09-18T00:00:31Z", + "modified": "2025-01-07T21:30:53Z", "published": "2022-09-16T00:00:38Z", "aliases": [ "CVE-2022-40662" @@ -19,6 +19,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-40662" }, + { + "type": "WEB", + "url": "https://www.software-dl.microscope.healthcare.nikon.com/vuln/index.html" + }, + { + "type": "WEB", + "url": "https://www.software-dl.microscope.healthcare.nikon.com/vuln/pdf/Vulnerabilities_on_NIS-Elements_Freeware_and_L_en_240917_02.pdf" + }, { "type": "WEB", "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1218" diff --git a/advisories/unreviewed/2022/09/GHSA-wjh5-2jj8-8xpj/GHSA-wjh5-2jj8-8xpj.json b/advisories/unreviewed/2022/09/GHSA-wjh5-2jj8-8xpj/GHSA-wjh5-2jj8-8xpj.json index ef487723d2d..7a9c72db324 100644 --- a/advisories/unreviewed/2022/09/GHSA-wjh5-2jj8-8xpj/GHSA-wjh5-2jj8-8xpj.json +++ b/advisories/unreviewed/2022/09/GHSA-wjh5-2jj8-8xpj/GHSA-wjh5-2jj8-8xpj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wjh5-2jj8-8xpj", - "modified": "2022-09-18T00:00:31Z", + "modified": "2025-01-07T21:30:53Z", "published": "2022-09-16T00:00:38Z", "aliases": [ "CVE-2022-40663" @@ -19,6 +19,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-40663" }, + { + "type": "WEB", + "url": "https://www.software-dl.microscope.healthcare.nikon.com/vuln/index.html" + }, + { + "type": "WEB", + "url": "https://www.software-dl.microscope.healthcare.nikon.com/vuln/pdf/Vulnerabilities_on_NIS-Elements_Freeware_and_L_en_240917_02.pdf" + }, { "type": "WEB", "url": "https://www.zerodayinitiative.com/advisories/ZDI-22-1219" diff --git a/advisories/unreviewed/2023/06/GHSA-5gqw-x43v-hg43/GHSA-5gqw-x43v-hg43.json b/advisories/unreviewed/2023/06/GHSA-5gqw-x43v-hg43/GHSA-5gqw-x43v-hg43.json index 20189907ea6..d82a487c378 100644 --- a/advisories/unreviewed/2023/06/GHSA-5gqw-x43v-hg43/GHSA-5gqw-x43v-hg43.json +++ b/advisories/unreviewed/2023/06/GHSA-5gqw-x43v-hg43/GHSA-5gqw-x43v-hg43.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-770", "CWE-862" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2023/06/GHSA-6pxx-9rr9-j7h4/GHSA-6pxx-9rr9-j7h4.json b/advisories/unreviewed/2023/06/GHSA-6pxx-9rr9-j7h4/GHSA-6pxx-9rr9-j7h4.json index 224e0ee82f3..bc80b0c18f1 100644 --- a/advisories/unreviewed/2023/06/GHSA-6pxx-9rr9-j7h4/GHSA-6pxx-9rr9-j7h4.json +++ b/advisories/unreviewed/2023/06/GHSA-6pxx-9rr9-j7h4/GHSA-6pxx-9rr9-j7h4.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-476", "CWE-862" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2023/06/GHSA-77vj-9qxr-p2qf/GHSA-77vj-9qxr-p2qf.json b/advisories/unreviewed/2023/06/GHSA-77vj-9qxr-p2qf/GHSA-77vj-9qxr-p2qf.json index 457ecf6e6c7..d5d81e01074 100644 --- a/advisories/unreviewed/2023/06/GHSA-77vj-9qxr-p2qf/GHSA-77vj-9qxr-p2qf.json +++ b/advisories/unreviewed/2023/06/GHSA-77vj-9qxr-p2qf/GHSA-77vj-9qxr-p2qf.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-476", "CWE-862" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2023/06/GHSA-g23p-v3rc-vq74/GHSA-g23p-v3rc-vq74.json b/advisories/unreviewed/2023/06/GHSA-g23p-v3rc-vq74/GHSA-g23p-v3rc-vq74.json index 98f149e6f0b..ed53c2c249b 100644 --- a/advisories/unreviewed/2023/06/GHSA-g23p-v3rc-vq74/GHSA-g23p-v3rc-vq74.json +++ b/advisories/unreviewed/2023/06/GHSA-g23p-v3rc-vq74/GHSA-g23p-v3rc-vq74.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-120", "CWE-787" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2023/06/GHSA-hr98-7gw3-84v4/GHSA-hr98-7gw3-84v4.json b/advisories/unreviewed/2023/06/GHSA-hr98-7gw3-84v4/GHSA-hr98-7gw3-84v4.json index d2280e922f9..f59ef8db520 100644 --- a/advisories/unreviewed/2023/06/GHSA-hr98-7gw3-84v4/GHSA-hr98-7gw3-84v4.json +++ b/advisories/unreviewed/2023/06/GHSA-hr98-7gw3-84v4/GHSA-hr98-7gw3-84v4.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-476", "CWE-862" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2023/06/GHSA-m786-rxff-x32m/GHSA-m786-rxff-x32m.json b/advisories/unreviewed/2023/06/GHSA-m786-rxff-x32m/GHSA-m786-rxff-x32m.json index 4db281d4843..864578885ef 100644 --- a/advisories/unreviewed/2023/06/GHSA-m786-rxff-x32m/GHSA-m786-rxff-x32m.json +++ b/advisories/unreviewed/2023/06/GHSA-m786-rxff-x32m/GHSA-m786-rxff-x32m.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-476", "CWE-862" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2023/06/GHSA-pg3q-6wmp-whpx/GHSA-pg3q-6wmp-whpx.json b/advisories/unreviewed/2023/06/GHSA-pg3q-6wmp-whpx/GHSA-pg3q-6wmp-whpx.json index 8de26fe28a8..f4700abbe18 100644 --- a/advisories/unreviewed/2023/06/GHSA-pg3q-6wmp-whpx/GHSA-pg3q-6wmp-whpx.json +++ b/advisories/unreviewed/2023/06/GHSA-pg3q-6wmp-whpx/GHSA-pg3q-6wmp-whpx.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-770", "CWE-862" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2023/11/GHSA-g78x-643m-9qmf/GHSA-g78x-643m-9qmf.json b/advisories/unreviewed/2023/11/GHSA-g78x-643m-9qmf/GHSA-g78x-643m-9qmf.json index 7784c728753..349498ff390 100644 --- a/advisories/unreviewed/2023/11/GHSA-g78x-643m-9qmf/GHSA-g78x-643m-9qmf.json +++ b/advisories/unreviewed/2023/11/GHSA-g78x-643m-9qmf/GHSA-g78x-643m-9qmf.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-276" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/11/GHSA-hrgc-qp5r-xq3p/GHSA-hrgc-qp5r-xq3p.json b/advisories/unreviewed/2023/11/GHSA-hrgc-qp5r-xq3p/GHSA-hrgc-qp5r-xq3p.json index 29ccb04dc57..6f8cf63bab4 100644 --- a/advisories/unreviewed/2023/11/GHSA-hrgc-qp5r-xq3p/GHSA-hrgc-qp5r-xq3p.json +++ b/advisories/unreviewed/2023/11/GHSA-hrgc-qp5r-xq3p/GHSA-hrgc-qp5r-xq3p.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-770" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/11/GHSA-jc2w-6rjp-h443/GHSA-jc2w-6rjp-h443.json b/advisories/unreviewed/2023/11/GHSA-jc2w-6rjp-h443/GHSA-jc2w-6rjp-h443.json index 37f91ab3ee4..7dce62bcf46 100644 --- a/advisories/unreviewed/2023/11/GHSA-jc2w-6rjp-h443/GHSA-jc2w-6rjp-h443.json +++ b/advisories/unreviewed/2023/11/GHSA-jc2w-6rjp-h443/GHSA-jc2w-6rjp-h443.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-276" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-48ww-vppq-9c8v/GHSA-48ww-vppq-9c8v.json b/advisories/unreviewed/2024/03/GHSA-48ww-vppq-9c8v/GHSA-48ww-vppq-9c8v.json index 8888205b921..0a70439cc33 100644 --- a/advisories/unreviewed/2024/03/GHSA-48ww-vppq-9c8v/GHSA-48ww-vppq-9c8v.json +++ b/advisories/unreviewed/2024/03/GHSA-48ww-vppq-9c8v/GHSA-48ww-vppq-9c8v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-48ww-vppq-9c8v", - "modified": "2024-03-04T21:31:11Z", + "modified": "2025-01-07T21:30:54Z", "published": "2024-03-04T21:31:11Z", "aliases": [ "CVE-2021-47108" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/mediatek: hdmi: Perform NULL pointer check for mtk_hdmi_conf\n\nIn commit 41ca9caaae0b\n(\"drm/mediatek: hdmi: Add check for CEA modes only\") a check\nfor CEA modes was added to function mtk_hdmi_bridge_mode_valid()\nin order to address possible issues on MT8167;\nmoreover, with commit c91026a938c2\n(\"drm/mediatek: hdmi: Add optional limit on maximal HDMI mode clock\")\nanother similar check was introduced.\n\nUnfortunately though, at the time of writing, MT8173 does not provide\nany mtk_hdmi_conf structure and this is crashing the kernel with NULL\npointer upon entering mtk_hdmi_bridge_mode_valid(), which happens as\nsoon as a HDMI cable gets plugged in.\n\nTo fix this regression, add a NULL pointer check for hdmi->conf in the\nsaid function, restoring HDMI functionality and avoiding NULL pointer\nkernel panics.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-04T19:15:18Z" diff --git a/advisories/unreviewed/2024/03/GHSA-9rrq-f95g-4wmq/GHSA-9rrq-f95g-4wmq.json b/advisories/unreviewed/2024/03/GHSA-9rrq-f95g-4wmq/GHSA-9rrq-f95g-4wmq.json index fed7f5f7f0b..561f8f14e68 100644 --- a/advisories/unreviewed/2024/03/GHSA-9rrq-f95g-4wmq/GHSA-9rrq-f95g-4wmq.json +++ b/advisories/unreviewed/2024/03/GHSA-9rrq-f95g-4wmq/GHSA-9rrq-f95g-4wmq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9rrq-f95g-4wmq", - "modified": "2024-06-27T15:30:38Z", + "modified": "2025-01-07T21:30:54Z", "published": "2024-03-06T09:30:29Z", "aliases": [ "CVE-2024-26625" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nllc: call sock_orphan() at release time\n\nsyzbot reported an interesting trace [1] caused by a stale sk->sk_wq\npointer in a closed llc socket.\n\nIn commit ff7b11aa481f (\"net: socket: set sock->sk to NULL after\ncalling proto_ops::release()\") Eric Biggers hinted that some protocols\nare missing a sock_orphan(), we need to perform a full audit.\n\nIn net-next, I plan to clear sock->sk from sock_orphan() and\namend Eric patch to add a warning.\n\n[1]\n BUG: KASAN: slab-use-after-free in list_empty include/linux/list.h:373 [inline]\n BUG: KASAN: slab-use-after-free in waitqueue_active include/linux/wait.h:127 [inline]\n BUG: KASAN: slab-use-after-free in sock_def_write_space_wfree net/core/sock.c:3384 [inline]\n BUG: KASAN: slab-use-after-free in sock_wfree+0x9a8/0x9d0 net/core/sock.c:2468\nRead of size 8 at addr ffff88802f4fc880 by task ksoftirqd/1/27\n\nCPU: 1 PID: 27 Comm: ksoftirqd/1 Not tainted 6.8.0-rc1-syzkaller-00049-g6098d87eaf31 #0\nHardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.2-debian-1.16.2-1 04/01/2014\nCall Trace:\n \n __dump_stack lib/dump_stack.c:88 [inline]\n dump_stack_lvl+0xd9/0x1b0 lib/dump_stack.c:106\n print_address_description mm/kasan/report.c:377 [inline]\n print_report+0xc4/0x620 mm/kasan/report.c:488\n kasan_report+0xda/0x110 mm/kasan/report.c:601\n list_empty include/linux/list.h:373 [inline]\n waitqueue_active include/linux/wait.h:127 [inline]\n sock_def_write_space_wfree net/core/sock.c:3384 [inline]\n sock_wfree+0x9a8/0x9d0 net/core/sock.c:2468\n skb_release_head_state+0xa3/0x2b0 net/core/skbuff.c:1080\n skb_release_all net/core/skbuff.c:1092 [inline]\n napi_consume_skb+0x119/0x2b0 net/core/skbuff.c:1404\n e1000_unmap_and_free_tx_resource+0x144/0x200 drivers/net/ethernet/intel/e1000/e1000_main.c:1970\n e1000_clean_tx_irq drivers/net/ethernet/intel/e1000/e1000_main.c:3860 [inline]\n e1000_clean+0x4a1/0x26e0 drivers/net/ethernet/intel/e1000/e1000_main.c:3801\n __napi_poll.constprop.0+0xb4/0x540 net/core/dev.c:6576\n napi_poll net/core/dev.c:6645 [inline]\n net_rx_action+0x956/0xe90 net/core/dev.c:6778\n __do_softirq+0x21a/0x8de kernel/softirq.c:553\n run_ksoftirqd kernel/softirq.c:921 [inline]\n run_ksoftirqd+0x31/0x60 kernel/softirq.c:913\n smpboot_thread_fn+0x660/0xa10 kernel/smpboot.c:164\n kthread+0x2c6/0x3a0 kernel/kthread.c:388\n ret_from_fork+0x45/0x80 arch/x86/kernel/process.c:147\n ret_from_fork_asm+0x11/0x20 arch/x86/entry/entry_64.S:242\n \n\nAllocated by task 5167:\n kasan_save_stack+0x33/0x50 mm/kasan/common.c:47\n kasan_save_track+0x14/0x30 mm/kasan/common.c:68\n unpoison_slab_object mm/kasan/common.c:314 [inline]\n __kasan_slab_alloc+0x81/0x90 mm/kasan/common.c:340\n kasan_slab_alloc include/linux/kasan.h:201 [inline]\n slab_post_alloc_hook mm/slub.c:3813 [inline]\n slab_alloc_node mm/slub.c:3860 [inline]\n kmem_cache_alloc_lru+0x142/0x6f0 mm/slub.c:3879\n alloc_inode_sb include/linux/fs.h:3019 [inline]\n sock_alloc_inode+0x25/0x1c0 net/socket.c:308\n alloc_inode+0x5d/0x220 fs/inode.c:260\n new_inode_pseudo+0x16/0x80 fs/inode.c:1005\n sock_alloc+0x40/0x270 net/socket.c:634\n __sock_create+0xbc/0x800 net/socket.c:1535\n sock_create net/socket.c:1622 [inline]\n __sys_socket_create net/socket.c:1659 [inline]\n __sys_socket+0x14c/0x260 net/socket.c:1706\n __do_sys_socket net/socket.c:1720 [inline]\n __se_sys_socket net/socket.c:1718 [inline]\n __x64_sys_socket+0x72/0xb0 net/socket.c:1718\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xd3/0x250 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x63/0x6b\n\nFreed by task 0:\n kasan_save_stack+0x33/0x50 mm/kasan/common.c:47\n kasan_save_track+0x14/0x30 mm/kasan/common.c:68\n kasan_save_free_info+0x3f/0x60 mm/kasan/generic.c:640\n poison_slab_object mm/kasan/common.c:241 [inline]\n __kasan_slab_free+0x121/0x1b0 mm/kasan/common.c:257\n kasan_slab_free include/linux/kasan.h:184 [inline]\n slab_free_hook mm/slub.c:2121 [inlin\n---truncated---", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -56,8 +61,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-06T07:15:12Z" diff --git a/advisories/unreviewed/2024/03/GHSA-gxqp-64jf-hj53/GHSA-gxqp-64jf-hj53.json b/advisories/unreviewed/2024/03/GHSA-gxqp-64jf-hj53/GHSA-gxqp-64jf-hj53.json index 46ea6fdb63d..84bdc317baf 100644 --- a/advisories/unreviewed/2024/03/GHSA-gxqp-64jf-hj53/GHSA-gxqp-64jf-hj53.json +++ b/advisories/unreviewed/2024/03/GHSA-gxqp-64jf-hj53/GHSA-gxqp-64jf-hj53.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gxqp-64jf-hj53", - "modified": "2024-03-26T18:32:07Z", + "modified": "2025-01-07T21:30:54Z", "published": "2024-03-26T18:32:07Z", "aliases": [ "CVE-2024-26647" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Fix late derefrence 'dsc' check in 'link_set_dsc_pps_packet()'\n\nIn link_set_dsc_pps_packet(), 'struct display_stream_compressor *dsc'\nwas dereferenced in a DC_LOGGER_INIT(dsc->ctx->logger); before the 'dsc'\nNULL pointer check.\n\nFixes the below:\ndrivers/gpu/drm/amd/amdgpu/../display/dc/link/link_dpms.c:905 link_set_dsc_pps_packet() warn: variable dereferenced before check 'dsc' (see line 903)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-26T18:15:10Z" diff --git a/advisories/unreviewed/2024/03/GHSA-pqmh-qr2r-5wwj/GHSA-pqmh-qr2r-5wwj.json b/advisories/unreviewed/2024/03/GHSA-pqmh-qr2r-5wwj/GHSA-pqmh-qr2r-5wwj.json index e69e7d2ce17..a975c0380bb 100644 --- a/advisories/unreviewed/2024/03/GHSA-pqmh-qr2r-5wwj/GHSA-pqmh-qr2r-5wwj.json +++ b/advisories/unreviewed/2024/03/GHSA-pqmh-qr2r-5wwj/GHSA-pqmh-qr2r-5wwj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pqmh-qr2r-5wwj", - "modified": "2024-03-04T18:30:38Z", + "modified": "2025-01-07T21:30:54Z", "published": "2024-03-04T18:30:38Z", "aliases": [ "CVE-2021-47095" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nipmi: ssif: initialize ssif_info->client early\n\nDuring probe ssif_info->client is dereferenced in error path. However,\nit is set when some of the error checking has already been done. This\ncauses following kernel crash if an error path is taken:\n\n[ 30.645593][ T674] ipmi_ssif 0-000e: ipmi_ssif: Not probing, Interface already present\n[ 30.657616][ T674] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000088\n...\n[ 30.657723][ T674] pc : __dev_printk+0x28/0xa0\n[ 30.657732][ T674] lr : _dev_err+0x7c/0xa0\n...\n[ 30.657772][ T674] Call trace:\n[ 30.657775][ T674] __dev_printk+0x28/0xa0\n[ 30.657778][ T674] _dev_err+0x7c/0xa0\n[ 30.657781][ T674] ssif_probe+0x548/0x900 [ipmi_ssif 62ce4b08badc1458fd896206d9ef69a3c31f3d3e]\n[ 30.657791][ T674] i2c_device_probe+0x37c/0x3c0\n...\n\nInitialize ssif_info->client before any error path can be taken. Clear\ni2c_client data in the error path to prevent the dangling pointer from\nleaking.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-04T18:15:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-q5p6-rx6m-vx4m/GHSA-q5p6-rx6m-vx4m.json b/advisories/unreviewed/2024/03/GHSA-q5p6-rx6m-vx4m/GHSA-q5p6-rx6m-vx4m.json index 278c2420e98..5d938472bad 100644 --- a/advisories/unreviewed/2024/03/GHSA-q5p6-rx6m-vx4m/GHSA-q5p6-rx6m-vx4m.json +++ b/advisories/unreviewed/2024/03/GHSA-q5p6-rx6m-vx4m/GHSA-q5p6-rx6m-vx4m.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-203", "CWE-204" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/04/GHSA-3vhh-8wwm-whvg/GHSA-3vhh-8wwm-whvg.json b/advisories/unreviewed/2024/04/GHSA-3vhh-8wwm-whvg/GHSA-3vhh-8wwm-whvg.json index 0afd4f0c8c5..6f1815856fa 100644 --- a/advisories/unreviewed/2024/04/GHSA-3vhh-8wwm-whvg/GHSA-3vhh-8wwm-whvg.json +++ b/advisories/unreviewed/2024/04/GHSA-3vhh-8wwm-whvg/GHSA-3vhh-8wwm-whvg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3vhh-8wwm-whvg", - "modified": "2024-04-03T18:30:41Z", + "modified": "2025-01-07T21:30:54Z", "published": "2024-04-03T18:30:41Z", "aliases": [ "CVE-2023-52641" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfs/ntfs3: Add NULL ptr dereference checking at the end of attr_allocate_frame()\n\nIt is preferable to exit through the out: label because\ninternal debugging functions are located there.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T17:15:47Z" diff --git a/advisories/unreviewed/2024/04/GHSA-5qq4-q34c-9875/GHSA-5qq4-q34c-9875.json b/advisories/unreviewed/2024/04/GHSA-5qq4-q34c-9875/GHSA-5qq4-q34c-9875.json index e59bbe318a1..8d7fb4bbc81 100644 --- a/advisories/unreviewed/2024/04/GHSA-5qq4-q34c-9875/GHSA-5qq4-q34c-9875.json +++ b/advisories/unreviewed/2024/04/GHSA-5qq4-q34c-9875/GHSA-5qq4-q34c-9875.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-78j7-xmw6-68gr/GHSA-78j7-xmw6-68gr.json b/advisories/unreviewed/2024/04/GHSA-78j7-xmw6-68gr/GHSA-78j7-xmw6-68gr.json index e98e245eac5..dfa752825ee 100644 --- a/advisories/unreviewed/2024/04/GHSA-78j7-xmw6-68gr/GHSA-78j7-xmw6-68gr.json +++ b/advisories/unreviewed/2024/04/GHSA-78j7-xmw6-68gr/GHSA-78j7-xmw6-68gr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-78j7-xmw6-68gr", - "modified": "2024-04-03T15:30:43Z", + "modified": "2025-01-07T21:30:54Z", "published": "2024-04-03T15:30:43Z", "aliases": [ "CVE-2024-26716" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: core: Prevent null pointer dereference in update_port_device_state\n\nCurrently, the function update_port_device_state gets the usb_hub from\nudev->parent by calling usb_hub_to_struct_hub.\nHowever, in case the actconfig or the maxchild is 0, the usb_hub would\nbe NULL and upon further accessing to get port_dev would result in null\npointer dereference.\n\nFix this by introducing an if check after the usb_hub is populated.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T15:15:53Z" diff --git a/advisories/unreviewed/2024/04/GHSA-97mp-32j5-q87r/GHSA-97mp-32j5-q87r.json b/advisories/unreviewed/2024/04/GHSA-97mp-32j5-q87r/GHSA-97mp-32j5-q87r.json index b5f0cb1fbab..57b32aee64c 100644 --- a/advisories/unreviewed/2024/04/GHSA-97mp-32j5-q87r/GHSA-97mp-32j5-q87r.json +++ b/advisories/unreviewed/2024/04/GHSA-97mp-32j5-q87r/GHSA-97mp-32j5-q87r.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-97mp-32j5-q87r", - "modified": "2024-04-03T15:30:43Z", + "modified": "2025-01-07T21:30:54Z", "published": "2024-04-03T15:30:43Z", "aliases": [ "CVE-2024-26715" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: dwc3: gadget: Fix NULL pointer dereference in dwc3_gadget_suspend\n\nIn current scenario if Plug-out and Plug-In performed continuously\nthere could be a chance while checking for dwc->gadget_driver in\ndwc3_gadget_suspend, a NULL pointer dereference may occur.\n\nCall Stack:\n\n\tCPU1: CPU2:\n\tgadget_unbind_driver dwc3_suspend_common\n\tdwc3_gadget_stop dwc3_gadget_suspend\n dwc3_disconnect_gadget\n\nCPU1 basically clears the variable and CPU2 checks the variable.\nConsider CPU1 is running and right before gadget_driver is cleared\nand in parallel CPU2 executes dwc3_gadget_suspend where it finds\ndwc->gadget_driver which is not NULL and resumes execution and then\nCPU1 completes execution. CPU2 executes dwc3_disconnect_gadget where\nit checks dwc->gadget_driver is already NULL because of which the\nNULL pointer deference occur.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T15:15:53Z" diff --git a/advisories/unreviewed/2024/04/GHSA-98m4-jppc-qq3m/GHSA-98m4-jppc-qq3m.json b/advisories/unreviewed/2024/04/GHSA-98m4-jppc-qq3m/GHSA-98m4-jppc-qq3m.json index 5c56aa18b80..d8a7491e9fb 100644 --- a/advisories/unreviewed/2024/04/GHSA-98m4-jppc-qq3m/GHSA-98m4-jppc-qq3m.json +++ b/advisories/unreviewed/2024/04/GHSA-98m4-jppc-qq3m/GHSA-98m4-jppc-qq3m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-98m4-jppc-qq3m", - "modified": "2024-06-27T15:30:38Z", + "modified": "2025-01-07T21:30:54Z", "published": "2024-04-03T18:30:42Z", "aliases": [ "CVE-2024-26754" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ngtp: fix use-after-free and null-ptr-deref in gtp_genl_dump_pdp()\n\nThe gtp_net_ops pernet operations structure for the subsystem must be\nregistered before registering the generic netlink family.\n\nSyzkaller hit 'general protection fault in gtp_genl_dump_pdp' bug:\n\ngeneral protection fault, probably for non-canonical address\n0xdffffc0000000002: 0000 [#1] PREEMPT SMP KASAN NOPTI\nKASAN: null-ptr-deref in range [0x0000000000000010-0x0000000000000017]\nCPU: 1 PID: 5826 Comm: gtp Not tainted 6.8.0-rc3-std-def-alt1 #1\nHardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.0-alt1 04/01/2014\nRIP: 0010:gtp_genl_dump_pdp+0x1be/0x800 [gtp]\nCode: c6 89 c6 e8 64 e9 86 df 58 45 85 f6 0f 85 4e 04 00 00 e8 c5 ee 86\n df 48 8b 54 24 18 48 b8 00 00 00 00 00 fc ff df 48 c1 ea 03 <80>\n 3c 02 00 0f 85 de 05 00 00 48 8b 44 24 18 4c 8b 30 4c 39 f0 74\nRSP: 0018:ffff888014107220 EFLAGS: 00010202\nRAX: dffffc0000000000 RBX: 0000000000000000 RCX: 0000000000000000\nRDX: 0000000000000002 RSI: 0000000000000000 RDI: 0000000000000000\nRBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000000000\nR10: 0000000000000000 R11: 0000000000000000 R12: 0000000000000000\nR13: ffff88800fcda588 R14: 0000000000000001 R15: 0000000000000000\nFS: 00007f1be4eb05c0(0000) GS:ffff88806ce80000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007f1be4e766cf CR3: 000000000c33e000 CR4: 0000000000750ef0\nPKRU: 55555554\nCall Trace:\n \n ? show_regs+0x90/0xa0\n ? die_addr+0x50/0xd0\n ? exc_general_protection+0x148/0x220\n ? asm_exc_general_protection+0x22/0x30\n ? gtp_genl_dump_pdp+0x1be/0x800 [gtp]\n ? __alloc_skb+0x1dd/0x350\n ? __pfx___alloc_skb+0x10/0x10\n genl_dumpit+0x11d/0x230\n netlink_dump+0x5b9/0xce0\n ? lockdep_hardirqs_on_prepare+0x253/0x430\n ? __pfx_netlink_dump+0x10/0x10\n ? kasan_save_track+0x10/0x40\n ? __kasan_kmalloc+0x9b/0xa0\n ? genl_start+0x675/0x970\n __netlink_dump_start+0x6fc/0x9f0\n genl_family_rcv_msg_dumpit+0x1bb/0x2d0\n ? __pfx_genl_family_rcv_msg_dumpit+0x10/0x10\n ? genl_op_from_small+0x2a/0x440\n ? cap_capable+0x1d0/0x240\n ? __pfx_genl_start+0x10/0x10\n ? __pfx_genl_dumpit+0x10/0x10\n ? __pfx_genl_done+0x10/0x10\n ? security_capable+0x9d/0xe0", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -56,8 +61,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T17:15:52Z" diff --git a/advisories/unreviewed/2024/04/GHSA-f6g6-gf5g-h3f3/GHSA-f6g6-gf5g-h3f3.json b/advisories/unreviewed/2024/04/GHSA-f6g6-gf5g-h3f3/GHSA-f6g6-gf5g-h3f3.json index fe2fb5fddd5..8809acc82b7 100644 --- a/advisories/unreviewed/2024/04/GHSA-f6g6-gf5g-h3f3/GHSA-f6g6-gf5g-h3f3.json +++ b/advisories/unreviewed/2024/04/GHSA-f6g6-gf5g-h3f3/GHSA-f6g6-gf5g-h3f3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-f6g6-gf5g-h3f3", - "modified": "2024-04-03T15:30:43Z", + "modified": "2025-01-07T21:30:54Z", "published": "2024-04-03T15:30:43Z", "aliases": [ "CVE-2024-26700" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Fix MST Null Ptr for RV\n\nThe change try to fix below error specific to RV platform:\n\nBUG: kernel NULL pointer dereference, address: 0000000000000008\nPGD 0 P4D 0\nOops: 0000 [#1] PREEMPT SMP NOPTI\nCPU: 4 PID: 917 Comm: sway Not tainted 6.3.9-arch1-1 #1 124dc55df4f5272ccb409f39ef4872fc2b3376a2\nHardware name: LENOVO 20NKS01Y00/20NKS01Y00, BIOS R12ET61W(1.31 ) 07/28/2022\nRIP: 0010:drm_dp_atomic_find_time_slots+0x5e/0x260 [drm_display_helper]\nCode: 01 00 00 48 8b 85 60 05 00 00 48 63 80 88 00 00 00 3b 43 28 0f 8d 2e 01 00 00 48 8b 53 30 48 8d 04 80 48 8d 04 c2 48 8b 40 18 <48> 8>\nRSP: 0018:ffff960cc2df77d8 EFLAGS: 00010293\nRAX: 0000000000000000 RBX: ffff8afb87e81280 RCX: 0000000000000224\nRDX: ffff8afb9ee37c00 RSI: ffff8afb8da1a578 RDI: ffff8afb87e81280\nRBP: ffff8afb83d67000 R08: 0000000000000001 R09: ffff8afb9652f850\nR10: ffff960cc2df7908 R11: 0000000000000002 R12: 0000000000000000\nR13: ffff8afb8d7688a0 R14: ffff8afb8da1a578 R15: 0000000000000224\nFS: 00007f4dac35ce00(0000) GS:ffff8afe30b00000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000000000000008 CR3: 000000010ddc6000 CR4: 00000000003506e0\nCall Trace:\n \n ? __die+0x23/0x70\n ? page_fault_oops+0x171/0x4e0\n ? plist_add+0xbe/0x100\n ? exc_page_fault+0x7c/0x180\n ? asm_exc_page_fault+0x26/0x30\n ? drm_dp_atomic_find_time_slots+0x5e/0x260 [drm_display_helper 0e67723696438d8e02b741593dd50d80b44c2026]\n ? drm_dp_atomic_find_time_slots+0x28/0x260 [drm_display_helper 0e67723696438d8e02b741593dd50d80b44c2026]\n compute_mst_dsc_configs_for_link+0x2ff/0xa40 [amdgpu 62e600d2a75e9158e1cd0a243bdc8e6da040c054]\n ? fill_plane_buffer_attributes+0x419/0x510 [amdgpu 62e600d2a75e9158e1cd0a243bdc8e6da040c054]\n compute_mst_dsc_configs_for_state+0x1e1/0x250 [amdgpu 62e600d2a75e9158e1cd0a243bdc8e6da040c054]\n amdgpu_dm_atomic_check+0xecd/0x1190 [amdgpu 62e600d2a75e9158e1cd0a243bdc8e6da040c054]\n drm_atomic_check_only+0x5c5/0xa40\n drm_mode_atomic_ioctl+0x76e/0xbc0\n ? _copy_to_user+0x25/0x30\n ? drm_ioctl+0x296/0x4b0\n ? __pfx_drm_mode_atomic_ioctl+0x10/0x10\n drm_ioctl_kernel+0xcd/0x170\n drm_ioctl+0x26d/0x4b0\n ? __pfx_drm_mode_atomic_ioctl+0x10/0x10\n amdgpu_drm_ioctl+0x4e/0x90 [amdgpu 62e600d2a75e9158e1cd0a243bdc8e6da040c054]\n __x64_sys_ioctl+0x94/0xd0\n do_syscall_64+0x60/0x90\n ? do_syscall_64+0x6c/0x90\n entry_SYSCALL_64_after_hwframe+0x72/0xdc\nRIP: 0033:0x7f4dad17f76f\nCode: 00 48 89 44 24 18 31 c0 48 8d 44 24 60 c7 04 24 10 00 00 00 48 89 44 24 08 48 8d 44 24 20 48 89 44 24 10 b8 10 00 00 00 0f 05 <89> c>\nRSP: 002b:00007ffd9ae859f0 EFLAGS: 00000246 ORIG_RAX: 0000000000000010\nRAX: ffffffffffffffda RBX: 000055e255a55900 RCX: 00007f4dad17f76f\nRDX: 00007ffd9ae85a90 RSI: 00000000c03864bc RDI: 000000000000000b\nRBP: 00007ffd9ae85a90 R08: 0000000000000003 R09: 0000000000000003\nR10: 0000000000000000 R11: 0000000000000246 R12: 00000000c03864bc\nR13: 000000000000000b R14: 000055e255a7fc60 R15: 000055e255a01eb0\n \nModules linked in: rfcomm snd_seq_dummy snd_hrtimer snd_seq snd_seq_device ccm cmac algif_hash algif_skcipher af_alg joydev mousedev bnep >\n typec libphy k10temp ipmi_msghandler roles i2c_scmi acpi_cpufreq mac_hid nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_mas>\nCR2: 0000000000000008\n---[ end trace 0000000000000000 ]---\nRIP: 0010:drm_dp_atomic_find_time_slots+0x5e/0x260 [drm_display_helper]\nCode: 01 00 00 48 8b 85 60 05 00 00 48 63 80 88 00 00 00 3b 43 28 0f 8d 2e 01 00 00 48 8b 53 30 48 8d 04 80 48 8d 04 c2 48 8b 40 18 <48> 8>\nRSP: 0018:ffff960cc2df77d8 EFLAGS: 00010293\nRAX: 0000000000000000 RBX: ffff8afb87e81280 RCX: 0000000000000224\nRDX: ffff8afb9ee37c00 RSI: ffff8afb8da1a578 RDI: ffff8afb87e81280\nRBP: ffff8afb83d67000 R08: 0000000000000001 R09: ffff8afb9652f850\nR10: ffff960cc2df7908 R11: 0000000000000002 R12: 0000000000000000\nR13: ffff8afb8d7688a0 R14: ffff8afb8da1a578 R15: 0000000000000224\nFS: 00007f4dac35ce00(0000) GS:ffff8afe30b00000(0000\n---truncated---", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T15:15:53Z" diff --git a/advisories/unreviewed/2024/04/GHSA-fg2w-r2w5-mgjw/GHSA-fg2w-r2w5-mgjw.json b/advisories/unreviewed/2024/04/GHSA-fg2w-r2w5-mgjw/GHSA-fg2w-r2w5-mgjw.json index c20a6a9ad0f..310fffe1887 100644 --- a/advisories/unreviewed/2024/04/GHSA-fg2w-r2w5-mgjw/GHSA-fg2w-r2w5-mgjw.json +++ b/advisories/unreviewed/2024/04/GHSA-fg2w-r2w5-mgjw/GHSA-fg2w-r2w5-mgjw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fg2w-r2w5-mgjw", - "modified": "2024-04-03T15:30:43Z", + "modified": "2025-01-07T21:30:54Z", "published": "2024-04-03T15:30:43Z", "aliases": [ "CVE-2024-26717" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: i2c-hid-of: fix NULL-deref on failed power up\n\nA while back the I2C HID implementation was split in an ACPI and OF\npart, but the new OF driver never initialises the client pointer which\nis dereferenced on power-up failures.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T15:15:53Z" diff --git a/advisories/unreviewed/2024/04/GHSA-m5hg-cjq4-86mq/GHSA-m5hg-cjq4-86mq.json b/advisories/unreviewed/2024/04/GHSA-m5hg-cjq4-86mq/GHSA-m5hg-cjq4-86mq.json index 4d6753bf7e6..33ed863e783 100644 --- a/advisories/unreviewed/2024/04/GHSA-m5hg-cjq4-86mq/GHSA-m5hg-cjq4-86mq.json +++ b/advisories/unreviewed/2024/04/GHSA-m5hg-cjq4-86mq/GHSA-m5hg-cjq4-86mq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-m5hg-cjq4-86mq", - "modified": "2024-04-03T18:30:42Z", + "modified": "2025-01-07T21:30:54Z", "published": "2024-04-03T18:30:42Z", "aliases": [ "CVE-2024-26738" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\npowerpc/pseries/iommu: DLPAR add doesn't completely initialize pci_controller\n\nWhen a PCI device is dynamically added, the kernel oopses with a NULL\npointer dereference:\n\n BUG: Kernel NULL pointer dereference on read at 0x00000030\n Faulting instruction address: 0xc0000000006bbe5c\n Oops: Kernel access of bad area, sig: 11 [#1]\n LE PAGE_SIZE=64K MMU=Radix SMP NR_CPUS=2048 NUMA pSeries\n Modules linked in: rpadlpar_io rpaphp rpcsec_gss_krb5 auth_rpcgss nfsv4 dns_resolver nfs lockd grace fscache netfs xsk_diag bonding nft_compat nf_tables nfnetlink rfkill binfmt_misc dm_multipath rpcrdma sunrpc rdma_ucm ib_srpt ib_isert iscsi_target_mod target_core_mod ib_umad ib_iser libiscsi scsi_transport_iscsi ib_ipoib rdma_cm iw_cm ib_cm mlx5_ib ib_uverbs ib_core pseries_rng drm drm_panel_orientation_quirks xfs libcrc32c mlx5_core mlxfw sd_mod t10_pi sg tls ibmvscsi ibmveth scsi_transport_srp vmx_crypto pseries_wdt psample dm_mirror dm_region_hash dm_log dm_mod fuse\n CPU: 17 PID: 2685 Comm: drmgr Not tainted 6.7.0-203405+ #66\n Hardware name: IBM,9080-HEX POWER10 (raw) 0x800200 0xf000006 of:IBM,FW1060.00 (NH1060_008) hv:phyp pSeries\n NIP: c0000000006bbe5c LR: c000000000a13e68 CTR: c0000000000579f8\n REGS: c00000009924f240 TRAP: 0300 Not tainted (6.7.0-203405+)\n MSR: 8000000000009033 CR: 24002220 XER: 20040006\n CFAR: c000000000a13e64 DAR: 0000000000000030 DSISR: 40000000 IRQMASK: 0\n ...\n NIP sysfs_add_link_to_group+0x34/0x94\n LR iommu_device_link+0x5c/0x118\n Call Trace:\n iommu_init_device+0x26c/0x318 (unreliable)\n iommu_device_link+0x5c/0x118\n iommu_init_device+0xa8/0x318\n iommu_probe_device+0xc0/0x134\n iommu_bus_notifier+0x44/0x104\n notifier_call_chain+0xb8/0x19c\n blocking_notifier_call_chain+0x64/0x98\n bus_notify+0x50/0x7c\n device_add+0x640/0x918\n pci_device_add+0x23c/0x298\n of_create_pci_dev+0x400/0x884\n of_scan_pci_dev+0x124/0x1b0\n __of_scan_bus+0x78/0x18c\n pcibios_scan_phb+0x2a4/0x3b0\n init_phb_dynamic+0xb8/0x110\n dlpar_add_slot+0x170/0x3b8 [rpadlpar_io]\n add_slot_store.part.0+0xb4/0x130 [rpadlpar_io]\n kobj_attr_store+0x2c/0x48\n sysfs_kf_write+0x64/0x78\n kernfs_fop_write_iter+0x1b0/0x290\n vfs_write+0x350/0x4a0\n ksys_write+0x84/0x140\n system_call_exception+0x124/0x330\n system_call_vectored_common+0x15c/0x2ec\n\nCommit a940904443e4 (\"powerpc/iommu: Add iommu_ops to report capabilities\nand allow blocking domains\") broke DLPAR add of PCI devices.\n\nThe above added iommu_device structure to pci_controller. During\nsystem boot, PCI devices are discovered and this newly added iommu_device\nstructure is initialized by a call to iommu_device_register().\n\nDuring DLPAR add of a PCI device, a new pci_controller structure is\nallocated but there are no calls made to iommu_device_register()\ninterface.\n\nFix is to register the iommu device during DLPAR add as well.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T17:15:51Z" diff --git a/advisories/unreviewed/2024/04/GHSA-pgm2-2p72-h4hg/GHSA-pgm2-2p72-h4hg.json b/advisories/unreviewed/2024/04/GHSA-pgm2-2p72-h4hg/GHSA-pgm2-2p72-h4hg.json index 71f5cbbfab1..07d04fbb071 100644 --- a/advisories/unreviewed/2024/04/GHSA-pgm2-2p72-h4hg/GHSA-pgm2-2p72-h4hg.json +++ b/advisories/unreviewed/2024/04/GHSA-pgm2-2p72-h4hg/GHSA-pgm2-2p72-h4hg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pgm2-2p72-h4hg", - "modified": "2024-04-03T18:30:41Z", + "modified": "2025-01-07T21:30:54Z", "published": "2024-04-03T18:30:41Z", "aliases": [ "CVE-2024-26728" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: fix null-pointer dereference on edid reading\n\nUse i2c adapter when there isn't aux_mode in dc_link to fix a\nnull-pointer derefence that happens when running\nigt@kms_force_connector_basic in a system with DCN2.1 and HDMI connector\ndetected as below:\n\n[ +0.178146] BUG: kernel NULL pointer dereference, address: 00000000000004c0\n[ +0.000010] #PF: supervisor read access in kernel mode\n[ +0.000005] #PF: error_code(0x0000) - not-present page\n[ +0.000004] PGD 0 P4D 0\n[ +0.000006] Oops: 0000 [#1] PREEMPT SMP NOPTI\n[ +0.000006] CPU: 15 PID: 2368 Comm: kms_force_conne Not tainted 6.5.0-asdn+ #152\n[ +0.000005] Hardware name: HP HP ENVY x360 Convertible 13-ay1xxx/8929, BIOS F.01 07/14/2021\n[ +0.000004] RIP: 0010:i2c_transfer+0xd/0x100\n[ +0.000011] Code: ea fc ff ff 66 0f 1f 84 00 00 00 00 00 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 f3 0f 1e fa 0f 1f 44 00 00 41 54 55 53 <48> 8b 47 10 48 89 fb 48 83 38 00 0f 84 b3 00 00 00 83 3d 2f 80 16\n[ +0.000004] RSP: 0018:ffff9c4f89c0fad0 EFLAGS: 00010246\n[ +0.000005] RAX: 0000000000000000 RBX: 0000000000000005 RCX: 0000000000000080\n[ +0.000003] RDX: 0000000000000002 RSI: ffff9c4f89c0fb20 RDI: 00000000000004b0\n[ +0.000003] RBP: ffff9c4f89c0fb80 R08: 0000000000000080 R09: ffff8d8e0b15b980\n[ +0.000003] R10: 00000000000380e0 R11: 0000000000000000 R12: 0000000000000080\n[ +0.000002] R13: 0000000000000002 R14: ffff9c4f89c0fb0e R15: ffff9c4f89c0fb0f\n[ +0.000004] FS: 00007f9ad2176c40(0000) GS:ffff8d90fe9c0000(0000) knlGS:0000000000000000\n[ +0.000003] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ +0.000004] CR2: 00000000000004c0 CR3: 0000000121bc4000 CR4: 0000000000750ee0\n[ +0.000003] PKRU: 55555554\n[ +0.000003] Call Trace:\n[ +0.000006] \n[ +0.000006] ? __die+0x23/0x70\n[ +0.000011] ? page_fault_oops+0x17d/0x4c0\n[ +0.000008] ? preempt_count_add+0x6e/0xa0\n[ +0.000008] ? srso_alias_return_thunk+0x5/0x7f\n[ +0.000011] ? exc_page_fault+0x7f/0x180\n[ +0.000009] ? asm_exc_page_fault+0x26/0x30\n[ +0.000013] ? i2c_transfer+0xd/0x100\n[ +0.000010] drm_do_probe_ddc_edid+0xc2/0x140 [drm]\n[ +0.000067] ? srso_alias_return_thunk+0x5/0x7f\n[ +0.000006] ? _drm_do_get_edid+0x97/0x3c0 [drm]\n[ +0.000043] ? __pfx_drm_do_probe_ddc_edid+0x10/0x10 [drm]\n[ +0.000042] edid_block_read+0x3b/0xd0 [drm]\n[ +0.000043] _drm_do_get_edid+0xb6/0x3c0 [drm]\n[ +0.000041] ? __pfx_drm_do_probe_ddc_edid+0x10/0x10 [drm]\n[ +0.000043] drm_edid_read_custom+0x37/0xd0 [drm]\n[ +0.000044] amdgpu_dm_connector_mode_valid+0x129/0x1d0 [amdgpu]\n[ +0.000153] drm_connector_mode_valid+0x3b/0x60 [drm_kms_helper]\n[ +0.000000] __drm_helper_update_and_validate+0xfe/0x3c0 [drm_kms_helper]\n[ +0.000000] ? amdgpu_dm_connector_get_modes+0xb6/0x520 [amdgpu]\n[ +0.000000] ? srso_alias_return_thunk+0x5/0x7f\n[ +0.000000] drm_helper_probe_single_connector_modes+0x2ab/0x540 [drm_kms_helper]\n[ +0.000000] status_store+0xb2/0x1f0 [drm]\n[ +0.000000] kernfs_fop_write_iter+0x136/0x1d0\n[ +0.000000] vfs_write+0x24d/0x440\n[ +0.000000] ksys_write+0x6f/0xf0\n[ +0.000000] do_syscall_64+0x60/0xc0\n[ +0.000000] ? srso_alias_return_thunk+0x5/0x7f\n[ +0.000000] ? syscall_exit_to_user_mode+0x2b/0x40\n[ +0.000000] ? srso_alias_return_thunk+0x5/0x7f\n[ +0.000000] ? do_syscall_64+0x6c/0xc0\n[ +0.000000] ? do_syscall_64+0x6c/0xc0\n[ +0.000000] entry_SYSCALL_64_after_hwframe+0x6e/0xd8\n[ +0.000000] RIP: 0033:0x7f9ad46b4b00\n[ +0.000000] Code: 40 00 48 8b 15 19 b3 0d 00 f7 d8 64 89 02 48 c7 c0 ff ff ff ff eb b7 0f 1f 00 80 3d e1 3a 0e 00 00 74 17 b8 01 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 58 c3 0f 1f 80 00 00 00 00 48 83 ec 28 48 89\n[ +0.000000] RSP: 002b:00007ffcbd3bd6d8 EFLAGS: 00000202 ORIG_RAX: 0000000000000001\n[ +0.000000] RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007f9ad46b4b00\n[ +0.000000] RDX: 0000000000000002 RSI: 00007f9ad48a7417 RDI: 0000000000000009\n[ +0.000000] RBP: 0000000000000002 R08\n---truncated---", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T17:15:50Z" diff --git a/advisories/unreviewed/2024/04/GHSA-pjwq-hg2p-9vw7/GHSA-pjwq-hg2p-9vw7.json b/advisories/unreviewed/2024/04/GHSA-pjwq-hg2p-9vw7/GHSA-pjwq-hg2p-9vw7.json index 608985afac3..0324896ab48 100644 --- a/advisories/unreviewed/2024/04/GHSA-pjwq-hg2p-9vw7/GHSA-pjwq-hg2p-9vw7.json +++ b/advisories/unreviewed/2024/04/GHSA-pjwq-hg2p-9vw7/GHSA-pjwq-hg2p-9vw7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pjwq-hg2p-9vw7", - "modified": "2024-04-03T18:30:41Z", + "modified": "2025-01-07T21:30:54Z", "published": "2024-04-03T18:30:41Z", "aliases": [ "CVE-2024-26729" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Fix potential null pointer dereference in dc_dmub_srv\n\nFixes potential null pointer dereference warnings in the\ndc_dmub_srv_cmd_list_queue_execute() and dc_dmub_srv_is_hw_pwr_up()\nfunctions.\n\nIn both functions, the 'dc_dmub_srv' variable was being dereferenced\nbefore it was checked for null. This could lead to a null pointer\ndereference if 'dc_dmub_srv' is null. The fix is to check if\n'dc_dmub_srv' is null before dereferencing it.\n\nThus moving the null checks for 'dc_dmub_srv' to the beginning of the\nfunctions to ensure that 'dc_dmub_srv' is not null when it is\ndereferenced.\n\nFound by smatch & thus fixing the below:\ndrivers/gpu/drm/amd/amdgpu/../display/dc/dc_dmub_srv.c:133 dc_dmub_srv_cmd_list_queue_execute() warn: variable dereferenced before check 'dc_dmub_srv' (see line 128)\ndrivers/gpu/drm/amd/amdgpu/../display/dc/dc_dmub_srv.c:1167 dc_dmub_srv_is_hw_pwr_up() warn: variable dereferenced before check 'dc_dmub_srv' (see line 1164)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T17:15:50Z" diff --git a/advisories/unreviewed/2024/04/GHSA-vhpg-m2r9-345p/GHSA-vhpg-m2r9-345p.json b/advisories/unreviewed/2024/04/GHSA-vhpg-m2r9-345p/GHSA-vhpg-m2r9-345p.json index 95c2a64f8d4..b19a457542f 100644 --- a/advisories/unreviewed/2024/04/GHSA-vhpg-m2r9-345p/GHSA-vhpg-m2r9-345p.json +++ b/advisories/unreviewed/2024/04/GHSA-vhpg-m2r9-345p/GHSA-vhpg-m2r9-345p.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vhpg-m2r9-345p", - "modified": "2024-04-03T15:30:42Z", + "modified": "2025-01-07T21:30:54Z", "published": "2024-04-03T15:30:42Z", "aliases": [ "CVE-2024-26694" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: iwlwifi: fix double-free bug\n\nThe storage for the TLV PC register data wasn't done like all\nthe other storage in the drv->fw area, which is cleared at the\nend of deallocation. Therefore, the freeing must also be done\ndifferently, explicitly NULL'ing it out after the free, since\notherwise there's a nasty double-free bug here if a file fails\nto load after this has been parsed, and we get another free\nlater (e.g. because no other file exists.) Fix that by adding\nthe missing NULL assignment.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-415" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T15:15:52Z" diff --git a/advisories/unreviewed/2024/04/GHSA-wfcg-p9mh-53w7/GHSA-wfcg-p9mh-53w7.json b/advisories/unreviewed/2024/04/GHSA-wfcg-p9mh-53w7/GHSA-wfcg-p9mh-53w7.json index b962898141d..9e87bddec78 100644 --- a/advisories/unreviewed/2024/04/GHSA-wfcg-p9mh-53w7/GHSA-wfcg-p9mh-53w7.json +++ b/advisories/unreviewed/2024/04/GHSA-wfcg-p9mh-53w7/GHSA-wfcg-p9mh-53w7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wfcg-p9mh-53w7", - "modified": "2024-06-26T00:31:36Z", + "modified": "2025-01-07T21:30:54Z", "published": "2024-04-03T15:30:42Z", "aliases": [ "CVE-2024-26688" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfs,hugetlb: fix NULL pointer dereference in hugetlbs_fill_super\n\nWhen configuring a hugetlb filesystem via the fsconfig() syscall, there is\na possible NULL dereference in hugetlbfs_fill_super() caused by assigning\nNULL to ctx->hstate in hugetlbfs_parse_param() when the requested pagesize\nis non valid.\n\nE.g: Taking the following steps:\n\n fd = fsopen(\"hugetlbfs\", FSOPEN_CLOEXEC);\n fsconfig(fd, FSCONFIG_SET_STRING, \"pagesize\", \"1024\", 0);\n fsconfig(fd, FSCONFIG_CMD_CREATE, NULL, NULL, 0);\n\nGiven that the requested \"pagesize\" is invalid, ctxt->hstate will be replaced\nwith NULL, losing its previous value, and we will print an error:\n\n ...\n ...\n case Opt_pagesize:\n ps = memparse(param->string, &rest);\n ctx->hstate = h;\n if (!ctx->hstate) {\n pr_err(\"Unsupported page size %lu MB\\n\", ps / SZ_1M);\n return -EINVAL;\n }\n return 0;\n ...\n ...\n\nThis is a problem because later on, we will dereference ctxt->hstate in\nhugetlbfs_fill_super()\n\n ...\n ...\n sb->s_blocksize = huge_page_size(ctx->hstate);\n ...\n ...\n\nCausing below Oops.\n\nFix this by replacing cxt->hstate value only when then pagesize is known\nto be valid.\n\n kernel: hugetlbfs: Unsupported page size 0 MB\n kernel: BUG: kernel NULL pointer dereference, address: 0000000000000028\n kernel: #PF: supervisor read access in kernel mode\n kernel: #PF: error_code(0x0000) - not-present page\n kernel: PGD 800000010f66c067 P4D 800000010f66c067 PUD 1b22f8067 PMD 0\n kernel: Oops: 0000 [#1] PREEMPT SMP PTI\n kernel: CPU: 4 PID: 5659 Comm: syscall Tainted: G E 6.8.0-rc2-default+ #22 5a47c3fef76212addcc6eb71344aabc35190ae8f\n kernel: Hardware name: Intel Corp. GROVEPORT/GROVEPORT, BIOS GVPRCRB1.86B.0016.D04.1705030402 05/03/2017\n kernel: RIP: 0010:hugetlbfs_fill_super+0xb4/0x1a0\n kernel: Code: 48 8b 3b e8 3e c6 ed ff 48 85 c0 48 89 45 20 0f 84 d6 00 00 00 48 b8 ff ff ff ff ff ff ff 7f 4c 89 e7 49 89 44 24 20 48 8b 03 <8b> 48 28 b8 00 10 00 00 48 d3 e0 49 89 44 24 18 48 8b 03 8b 40 28\n kernel: RSP: 0018:ffffbe9960fcbd48 EFLAGS: 00010246\n kernel: RAX: 0000000000000000 RBX: ffff9af5272ae780 RCX: 0000000000372004\n kernel: RDX: ffffffffffffffff RSI: ffffffffffffffff RDI: ffff9af555e9b000\n kernel: RBP: ffff9af52ee66b00 R08: 0000000000000040 R09: 0000000000370004\n kernel: R10: ffffbe9960fcbd48 R11: 0000000000000040 R12: ffff9af555e9b000\n kernel: R13: ffffffffa66b86c0 R14: ffff9af507d2f400 R15: ffff9af507d2f400\n kernel: FS: 00007ffbc0ba4740(0000) GS:ffff9b0bd7000000(0000) knlGS:0000000000000000\n kernel: CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n kernel: CR2: 0000000000000028 CR3: 00000001b1ee0000 CR4: 00000000001506f0\n kernel: Call Trace:\n kernel: \n kernel: ? __die_body+0x1a/0x60\n kernel: ? page_fault_oops+0x16f/0x4a0\n kernel: ? search_bpf_extables+0x65/0x70\n kernel: ? fixup_exception+0x22/0x310\n kernel: ? exc_page_fault+0x69/0x150\n kernel: ? asm_exc_page_fault+0x22/0x30\n kernel: ? __pfx_hugetlbfs_fill_super+0x10/0x10\n kernel: ? hugetlbfs_fill_super+0xb4/0x1a0\n kernel: ? hugetlbfs_fill_super+0x28/0x1a0\n kernel: ? __pfx_hugetlbfs_fill_super+0x10/0x10\n kernel: vfs_get_super+0x40/0xa0\n kernel: ? __pfx_bpf_lsm_capable+0x10/0x10\n kernel: vfs_get_tree+0x25/0xd0\n kernel: vfs_cmd_create+0x64/0xe0\n kernel: __x64_sys_fsconfig+0x395/0x410\n kernel: do_syscall_64+0x80/0x160\n kernel: ? syscall_exit_to_user_mode+0x82/0x240\n kernel: ? do_syscall_64+0x8d/0x160\n kernel: ? syscall_exit_to_user_mode+0x82/0x240\n kernel: ? do_syscall_64+0x8d/0x160\n kernel: ? exc_page_fault+0x69/0x150\n kernel: entry_SYSCALL_64_after_hwframe+0x6e/0x76\n kernel: RIP: 0033:0x7ffbc0cb87c9\n kernel: Code: 00 90 90 90 90 90 90 90 90 90 90 90 90 90 90 66 90 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 8b 0d 97 96 0d 00 f7 d8 64 89 01 48\n kernel: RSP: 002b:00007ffc29d2f388 EFLAGS: 00000206 ORIG_RAX: 00000000000001af\n kernel: RAX: fffffffffff\n---truncated---", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T15:15:52Z" diff --git a/advisories/unreviewed/2024/04/GHSA-x723-q7ww-gm79/GHSA-x723-q7ww-gm79.json b/advisories/unreviewed/2024/04/GHSA-x723-q7ww-gm79/GHSA-x723-q7ww-gm79.json index 43a2922153c..034913538e8 100644 --- a/advisories/unreviewed/2024/04/GHSA-x723-q7ww-gm79/GHSA-x723-q7ww-gm79.json +++ b/advisories/unreviewed/2024/04/GHSA-x723-q7ww-gm79/GHSA-x723-q7ww-gm79.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-24vw-fq64-647q/GHSA-24vw-fq64-647q.json b/advisories/unreviewed/2024/05/GHSA-24vw-fq64-647q/GHSA-24vw-fq64-647q.json index 5d122b9c77a..b8725f32119 100644 --- a/advisories/unreviewed/2024/05/GHSA-24vw-fq64-647q/GHSA-24vw-fq64-647q.json +++ b/advisories/unreviewed/2024/05/GHSA-24vw-fq64-647q/GHSA-24vw-fq64-647q.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-24vw-fq64-647q", - "modified": "2024-05-22T09:31:44Z", + "modified": "2025-01-07T21:30:54Z", "published": "2024-05-22T09:31:44Z", "aliases": [ "CVE-2021-47438" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: Fix memory leak in mlx5_core_destroy_cq() error path\n\nPrior to this patch in case mlx5_core_destroy_cq() failed it returns\nwithout completing all destroy operations and that leads to memory leak.\nInstead, complete the destroy flow before return error.\n\nAlso move mlx5_debug_cq_remove() to the beginning of mlx5_core_destroy_cq()\nto be symmetrical with mlx5_core_create_cq().\n\nkmemleak complains on:\n\nunreferenced object 0xc000000038625100 (size 64):\n comm \"ethtool\", pid 28301, jiffies 4298062946 (age 785.380s)\n hex dump (first 32 bytes):\n 60 01 48 94 00 00 00 c0 b8 05 34 c3 00 00 00 c0 `.H.......4.....\n 02 00 00 00 00 00 00 00 00 db 7d c1 00 00 00 c0 ..........}.....\n backtrace:\n [<000000009e8643cb>] add_res_tree+0xd0/0x270 [mlx5_core]\n [<00000000e7cb8e6c>] mlx5_debug_cq_add+0x5c/0xc0 [mlx5_core]\n [<000000002a12918f>] mlx5_core_create_cq+0x1d0/0x2d0 [mlx5_core]\n [<00000000cef0a696>] mlx5e_create_cq+0x210/0x3f0 [mlx5_core]\n [<000000009c642c26>] mlx5e_open_cq+0xb4/0x130 [mlx5_core]\n [<0000000058dfa578>] mlx5e_ptp_open+0x7f4/0xe10 [mlx5_core]\n [<0000000081839561>] mlx5e_open_channels+0x9cc/0x13e0 [mlx5_core]\n [<0000000009cf05d4>] mlx5e_switch_priv_channels+0xa4/0x230\n[mlx5_core]\n [<0000000042bbedd8>] mlx5e_safe_switch_params+0x14c/0x300\n[mlx5_core]\n [<0000000004bc9db8>] set_pflag_tx_port_ts+0x9c/0x160 [mlx5_core]\n [<00000000a0553443>] mlx5e_set_priv_flags+0xd0/0x1b0 [mlx5_core]\n [<00000000a8f3d84b>] ethnl_set_privflags+0x234/0x2d0\n [<00000000fd27f27c>] genl_family_rcv_msg_doit+0x108/0x1d0\n [<00000000f495e2bb>] genl_family_rcv_msg+0xe4/0x1f0\n [<00000000646c5c2c>] genl_rcv_msg+0x78/0x120\n [<00000000d53e384e>] netlink_rcv_skb+0x74/0x1a0", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-22T07:15:09Z" diff --git a/advisories/unreviewed/2024/05/GHSA-263c-689v-jcfh/GHSA-263c-689v-jcfh.json b/advisories/unreviewed/2024/05/GHSA-263c-689v-jcfh/GHSA-263c-689v-jcfh.json index a1aba7c374c..488b4ee1434 100644 --- a/advisories/unreviewed/2024/05/GHSA-263c-689v-jcfh/GHSA-263c-689v-jcfh.json +++ b/advisories/unreviewed/2024/05/GHSA-263c-689v-jcfh/GHSA-263c-689v-jcfh.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-324" + "CWE-324", + "CWE-672" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-28j2-gr4p-p982/GHSA-28j2-gr4p-p982.json b/advisories/unreviewed/2024/05/GHSA-28j2-gr4p-p982/GHSA-28j2-gr4p-p982.json index 25bae49bd42..dbbb08ddbbc 100644 --- a/advisories/unreviewed/2024/05/GHSA-28j2-gr4p-p982/GHSA-28j2-gr4p-p982.json +++ b/advisories/unreviewed/2024/05/GHSA-28j2-gr4p-p982/GHSA-28j2-gr4p-p982.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-28j2-gr4p-p982", - "modified": "2024-05-22T09:31:45Z", + "modified": "2025-01-07T21:30:54Z", "published": "2024-05-22T09:31:45Z", "aliases": [ "CVE-2021-47473" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: qla2xxx: Fix a memory leak in an error path of qla2x00_process_els()\n\nCommit 8c0eb596baa5 (\"[SCSI] qla2xxx: Fix a memory leak in an error path of\nqla2x00_process_els()\"), intended to change:\n\n bsg_job->request->msgcode == FC_BSG_HST_ELS_NOLOGIN\n\n\n bsg_job->request->msgcode != FC_BSG_RPT_ELS\n\nbut changed it to:\n\n bsg_job->request->msgcode == FC_BSG_RPT_ELS\n\ninstead.\n\nChange the == to a != to avoid leaking the fcport structure or freeing\nunallocated memory.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-22T07:15:12Z" diff --git a/advisories/unreviewed/2024/05/GHSA-2m7m-jhx5-8crh/GHSA-2m7m-jhx5-8crh.json b/advisories/unreviewed/2024/05/GHSA-2m7m-jhx5-8crh/GHSA-2m7m-jhx5-8crh.json index c64235700e6..9a76ba09d51 100644 --- a/advisories/unreviewed/2024/05/GHSA-2m7m-jhx5-8crh/GHSA-2m7m-jhx5-8crh.json +++ b/advisories/unreviewed/2024/05/GHSA-2m7m-jhx5-8crh/GHSA-2m7m-jhx5-8crh.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-203", "CWE-204" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/05/GHSA-2xxj-gwfx-rr2c/GHSA-2xxj-gwfx-rr2c.json b/advisories/unreviewed/2024/05/GHSA-2xxj-gwfx-rr2c/GHSA-2xxj-gwfx-rr2c.json index 48cc2ef4083..ee60fd3e99d 100644 --- a/advisories/unreviewed/2024/05/GHSA-2xxj-gwfx-rr2c/GHSA-2xxj-gwfx-rr2c.json +++ b/advisories/unreviewed/2024/05/GHSA-2xxj-gwfx-rr2c/GHSA-2xxj-gwfx-rr2c.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2xxj-gwfx-rr2c", - "modified": "2024-06-27T12:30:46Z", + "modified": "2025-01-07T21:30:54Z", "published": "2024-05-17T15:31:12Z", "aliases": [ "CVE-2023-52698" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncalipso: fix memory leak in netlbl_calipso_add_pass()\n\nIf IPv6 support is disabled at boot (ipv6.disable=1),\nthe calipso_init() -> netlbl_calipso_ops_register() function isn't called,\nand the netlbl_calipso_ops_get() function always returns NULL.\nIn this case, the netlbl_calipso_add_pass() function allocates memory\nfor the doi_def variable but doesn't free it with the calipso_doi_free().\n\nBUG: memory leak\nunreferenced object 0xffff888011d68180 (size 64):\n comm \"syz-executor.1\", pid 10746, jiffies 4295410986 (age 17.928s)\n hex dump (first 32 bytes):\n 00 00 00 00 02 00 00 00 00 00 00 00 00 00 00 00 ................\n 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n backtrace:\n [<...>] kmalloc include/linux/slab.h:552 [inline]\n [<...>] netlbl_calipso_add_pass net/netlabel/netlabel_calipso.c:76 [inline]\n [<...>] netlbl_calipso_add+0x22e/0x4f0 net/netlabel/netlabel_calipso.c:111\n [<...>] genl_family_rcv_msg_doit+0x22f/0x330 net/netlink/genetlink.c:739\n [<...>] genl_family_rcv_msg net/netlink/genetlink.c:783 [inline]\n [<...>] genl_rcv_msg+0x341/0x5a0 net/netlink/genetlink.c:800\n [<...>] netlink_rcv_skb+0x14d/0x440 net/netlink/af_netlink.c:2515\n [<...>] genl_rcv+0x29/0x40 net/netlink/genetlink.c:811\n [<...>] netlink_unicast_kernel net/netlink/af_netlink.c:1313 [inline]\n [<...>] netlink_unicast+0x54b/0x800 net/netlink/af_netlink.c:1339\n [<...>] netlink_sendmsg+0x90a/0xdf0 net/netlink/af_netlink.c:1934\n [<...>] sock_sendmsg_nosec net/socket.c:651 [inline]\n [<...>] sock_sendmsg+0x157/0x190 net/socket.c:671\n [<...>] ____sys_sendmsg+0x712/0x870 net/socket.c:2342\n [<...>] ___sys_sendmsg+0xf8/0x170 net/socket.c:2396\n [<...>] __sys_sendmsg+0xea/0x1b0 net/socket.c:2429\n [<...>] do_syscall_64+0x30/0x40 arch/x86/entry/common.c:46\n [<...>] entry_SYSCALL_64_after_hwframe+0x61/0xc6\n\nFound by InfoTeCS on behalf of Linux Verification Center\n(linuxtesting.org) with Syzkaller\n\n[PM: merged via the LSM tree at Jakub Kicinski request]", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -56,8 +61,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-17T15:15:20Z" diff --git a/advisories/unreviewed/2024/05/GHSA-fh33-v9vq-826f/GHSA-fh33-v9vq-826f.json b/advisories/unreviewed/2024/05/GHSA-fh33-v9vq-826f/GHSA-fh33-v9vq-826f.json index 2680032c9a3..ddb732bb464 100644 --- a/advisories/unreviewed/2024/05/GHSA-fh33-v9vq-826f/GHSA-fh33-v9vq-826f.json +++ b/advisories/unreviewed/2024/05/GHSA-fh33-v9vq-826f/GHSA-fh33-v9vq-826f.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fh33-v9vq-826f", - "modified": "2024-05-22T09:31:45Z", + "modified": "2025-01-07T21:30:54Z", "published": "2024-05-22T09:31:45Z", "aliases": [ "CVE-2021-47442" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nNFC: digital: fix possible memory leak in digital_in_send_sdd_req()\n\n'skb' is allocated in digital_in_send_sdd_req(), but not free when\ndigital_in_send_cmd() failed, which will cause memory leak. Fix it\nby freeing 'skb' if digital_in_send_cmd() return failed.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-22T07:15:09Z" diff --git a/advisories/unreviewed/2024/05/GHSA-mcp9-hfjj-cpp5/GHSA-mcp9-hfjj-cpp5.json b/advisories/unreviewed/2024/05/GHSA-mcp9-hfjj-cpp5/GHSA-mcp9-hfjj-cpp5.json index 0427f33167e..8ca901aa6c4 100644 --- a/advisories/unreviewed/2024/05/GHSA-mcp9-hfjj-cpp5/GHSA-mcp9-hfjj-cpp5.json +++ b/advisories/unreviewed/2024/05/GHSA-mcp9-hfjj-cpp5/GHSA-mcp9-hfjj-cpp5.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-116", "CWE-117" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/05/GHSA-rrxx-mf3x-75gw/GHSA-rrxx-mf3x-75gw.json b/advisories/unreviewed/2024/05/GHSA-rrxx-mf3x-75gw/GHSA-rrxx-mf3x-75gw.json index 4a8997ca988..243c7199e8b 100644 --- a/advisories/unreviewed/2024/05/GHSA-rrxx-mf3x-75gw/GHSA-rrxx-mf3x-75gw.json +++ b/advisories/unreviewed/2024/05/GHSA-rrxx-mf3x-75gw/GHSA-rrxx-mf3x-75gw.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-x6jr-wrhc-h2x2/GHSA-x6jr-wrhc-h2x2.json b/advisories/unreviewed/2024/05/GHSA-x6jr-wrhc-h2x2/GHSA-x6jr-wrhc-h2x2.json index c08327056d8..78efd288aae 100644 --- a/advisories/unreviewed/2024/05/GHSA-x6jr-wrhc-h2x2/GHSA-x6jr-wrhc-h2x2.json +++ b/advisories/unreviewed/2024/05/GHSA-x6jr-wrhc-h2x2/GHSA-x6jr-wrhc-h2x2.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-290", "CWE-350" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/05/GHSA-xwj2-c9hw-p6p6/GHSA-xwj2-c9hw-p6p6.json b/advisories/unreviewed/2024/05/GHSA-xwj2-c9hw-p6p6/GHSA-xwj2-c9hw-p6p6.json index dc36781125c..f88b9e65864 100644 --- a/advisories/unreviewed/2024/05/GHSA-xwj2-c9hw-p6p6/GHSA-xwj2-c9hw-p6p6.json +++ b/advisories/unreviewed/2024/05/GHSA-xwj2-c9hw-p6p6/GHSA-xwj2-c9hw-p6p6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xwj2-c9hw-p6p6", - "modified": "2024-05-22T09:31:46Z", + "modified": "2025-01-07T21:30:54Z", "published": "2024-05-22T09:31:45Z", "aliases": [ "CVE-2021-47466" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm, slub: fix potential memoryleak in kmem_cache_open()\n\nIn error path, the random_seq of slub cache might be leaked. Fix this\nby using __kmem_cache_release() to release all the relevant resources.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-22T07:15:11Z" diff --git a/advisories/unreviewed/2024/07/GHSA-gr2q-rxqg-mrrq/GHSA-gr2q-rxqg-mrrq.json b/advisories/unreviewed/2024/07/GHSA-gr2q-rxqg-mrrq/GHSA-gr2q-rxqg-mrrq.json index e3c7c659661..1a383f9729b 100644 --- a/advisories/unreviewed/2024/07/GHSA-gr2q-rxqg-mrrq/GHSA-gr2q-rxqg-mrrq.json +++ b/advisories/unreviewed/2024/07/GHSA-gr2q-rxqg-mrrq/GHSA-gr2q-rxqg-mrrq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gr2q-rxqg-mrrq", - "modified": "2024-07-11T18:31:13Z", + "modified": "2025-01-07T21:30:54Z", "published": "2024-07-11T18:31:13Z", "aliases": [ "CVE-2024-39532" diff --git a/advisories/unreviewed/2024/09/GHSA-8x2h-c9mx-cx2j/GHSA-8x2h-c9mx-cx2j.json b/advisories/unreviewed/2024/09/GHSA-8x2h-c9mx-cx2j/GHSA-8x2h-c9mx-cx2j.json index 2c7a35d80f7..494a66a8407 100644 --- a/advisories/unreviewed/2024/09/GHSA-8x2h-c9mx-cx2j/GHSA-8x2h-c9mx-cx2j.json +++ b/advisories/unreviewed/2024/09/GHSA-8x2h-c9mx-cx2j/GHSA-8x2h-c9mx-cx2j.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-256" + "CWE-256", + "CWE-522" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-42wq-32p9-mf48/GHSA-42wq-32p9-mf48.json b/advisories/unreviewed/2024/12/GHSA-42wq-32p9-mf48/GHSA-42wq-32p9-mf48.json index 83407f26f60..793c5eb71fb 100644 --- a/advisories/unreviewed/2024/12/GHSA-42wq-32p9-mf48/GHSA-42wq-32p9-mf48.json +++ b/advisories/unreviewed/2024/12/GHSA-42wq-32p9-mf48/GHSA-42wq-32p9-mf48.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-42wq-32p9-mf48", - "modified": "2024-12-29T12:30:40Z", + "modified": "2025-01-07T21:30:55Z", "published": "2024-12-29T12:30:40Z", "aliases": [ "CVE-2024-56739" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nrtc: check if __rtc_read_time was successful in rtc_timer_do_work()\n\nIf the __rtc_read_time call fails,, the struct rtc_time tm; may contain\nuninitialized data, or an illegal date/time read from the RTC hardware.\n\nWhen calling rtc_tm_to_ktime later, the result may be a very large value\n(possibly KTIME_MAX). If there are periodic timers in rtc->timerqueue,\nthey will continually expire, may causing kernel softlockup.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -52,8 +57,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-908" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-29T12:15:07Z" diff --git a/advisories/unreviewed/2024/12/GHSA-pqw3-898v-hg67/GHSA-pqw3-898v-hg67.json b/advisories/unreviewed/2024/12/GHSA-pqw3-898v-hg67/GHSA-pqw3-898v-hg67.json index 6ffdb2fbca8..34f9f22f029 100644 --- a/advisories/unreviewed/2024/12/GHSA-pqw3-898v-hg67/GHSA-pqw3-898v-hg67.json +++ b/advisories/unreviewed/2024/12/GHSA-pqw3-898v-hg67/GHSA-pqw3-898v-hg67.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pqw3-898v-hg67", - "modified": "2024-12-29T12:30:40Z", + "modified": "2025-01-07T21:30:55Z", "published": "2024-12-29T12:30:40Z", "aliases": [ "CVE-2024-56730" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/9p/usbg: fix handling of the failed kzalloc() memory allocation\n\nOn the linux-next, next-20241108 vanilla kernel, the coccinelle tool gave the\nfollowing error report:\n\n./net/9p/trans_usbg.c:912:5-11: ERROR: allocation function on line 911 returns\nNULL not ERR_PTR on failure\n\nkzalloc() failure is fixed to handle the NULL return case on the memory exhaustion.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-29T12:15:07Z" diff --git a/advisories/unreviewed/2025/01/GHSA-23fx-r767-q5g7/GHSA-23fx-r767-q5g7.json b/advisories/unreviewed/2025/01/GHSA-23fx-r767-q5g7/GHSA-23fx-r767-q5g7.json new file mode 100644 index 00000000000..30ecbca71a8 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-23fx-r767-q5g7/GHSA-23fx-r767-q5g7.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-23fx-r767-q5g7", + "modified": "2025-01-07T21:30:55Z", + "published": "2025-01-07T21:30:55Z", + "aliases": [ + "CVE-2022-45186" + ], + "details": "An issue was discovered in SuiteCRM 7.12.7. Authenticated users can recover an arbitrary field of a database.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45186" + }, + { + "type": "WEB", + "url": "https://docs.suitecrm.com/admin/releases/7.12.x" + }, + { + "type": "WEB", + "url": "https://github.com/Orange-Cyberdefense/CVE-repository" + }, + { + "type": "WEB", + "url": "https://github.com/Orange-Cyberdefense/CVE-repository/blob/master/PoCs/poc_SuiteCRM.py" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T20:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-3695-47qv-rc3x/GHSA-3695-47qv-rc3x.json b/advisories/unreviewed/2025/01/GHSA-3695-47qv-rc3x/GHSA-3695-47qv-rc3x.json index 77e3ba0e396..19a923617db 100644 --- a/advisories/unreviewed/2025/01/GHSA-3695-47qv-rc3x/GHSA-3695-47qv-rc3x.json +++ b/advisories/unreviewed/2025/01/GHSA-3695-47qv-rc3x/GHSA-3695-47qv-rc3x.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-77" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-39fw-qmf8-vr6v/GHSA-39fw-qmf8-vr6v.json b/advisories/unreviewed/2025/01/GHSA-39fw-qmf8-vr6v/GHSA-39fw-qmf8-vr6v.json index 3a2a4dc4476..66903f75562 100644 --- a/advisories/unreviewed/2025/01/GHSA-39fw-qmf8-vr6v/GHSA-39fw-qmf8-vr6v.json +++ b/advisories/unreviewed/2025/01/GHSA-39fw-qmf8-vr6v/GHSA-39fw-qmf8-vr6v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-39fw-qmf8-vr6v", - "modified": "2025-01-07T18:30:52Z", + "modified": "2025-01-07T21:30:55Z", "published": "2025-01-07T18:30:52Z", "aliases": [ "CVE-2024-55555" ], "details": "Invoice Ninja before 5.10.43 allows remote code execution from a pre-authenticated route when an attacker knows the APP_KEY. This is exacerbated by .env files, available from the product's repository, that have default APP_KEY values. The route/{hash} route defined in the invoiceninja/routes/client.php file can be accessed without authentication. The parameter {hash} is passed to the function decrypt that expects a Laravel ciphered value containing a serialized object. (Furthermore, Laravel contains several gadget chains usable to trigger remote command execution from arbitrary deserialization.) Therefore, an attacker in possession of the APP_KEY is able to fully control a string passed to an unserialize function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-07T17:15:30Z" diff --git a/advisories/unreviewed/2025/01/GHSA-3wcp-pwj7-fwmf/GHSA-3wcp-pwj7-fwmf.json b/advisories/unreviewed/2025/01/GHSA-3wcp-pwj7-fwmf/GHSA-3wcp-pwj7-fwmf.json index b18086ad832..41a5a9ffe9d 100644 --- a/advisories/unreviewed/2025/01/GHSA-3wcp-pwj7-fwmf/GHSA-3wcp-pwj7-fwmf.json +++ b/advisories/unreviewed/2025/01/GHSA-3wcp-pwj7-fwmf/GHSA-3wcp-pwj7-fwmf.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-77" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-3wv8-q6g7-7frh/GHSA-3wv8-q6g7-7frh.json b/advisories/unreviewed/2025/01/GHSA-3wv8-q6g7-7frh/GHSA-3wv8-q6g7-7frh.json new file mode 100644 index 00000000000..3c56aed1090 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-3wv8-q6g7-7frh/GHSA-3wv8-q6g7-7frh.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3wv8-q6g7-7frh", + "modified": "2025-01-07T21:30:55Z", + "published": "2025-01-07T21:30:55Z", + "aliases": [ + "CVE-2022-41572" + ], + "details": "An issue was discovered in EyesOfNetwork (EON) through 5.3.11. Privilege escalation can be accomplished on the server because nmap can be run as root. The attacker achieves total control over the server.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-41572" + }, + { + "type": "WEB", + "url": "https://github.com/EyesOfNetworkCommunity/eonweb/issues/120" + }, + { + "type": "WEB", + "url": "https://github.com/Orange-Cyberdefense/CVE-repository" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T20:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-533j-w77v-fmxv/GHSA-533j-w77v-fmxv.json b/advisories/unreviewed/2025/01/GHSA-533j-w77v-fmxv/GHSA-533j-w77v-fmxv.json index 5d74a3a9dc1..fe17e8b7804 100644 --- a/advisories/unreviewed/2025/01/GHSA-533j-w77v-fmxv/GHSA-533j-w77v-fmxv.json +++ b/advisories/unreviewed/2025/01/GHSA-533j-w77v-fmxv/GHSA-533j-w77v-fmxv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-533j-w77v-fmxv", - "modified": "2025-01-06T18:31:04Z", + "modified": "2025-01-07T21:30:55Z", "published": "2025-01-06T18:31:04Z", "aliases": [ "CVE-2024-54880" ], "details": "SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user to register accounts in bulk.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-281" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-06T18:15:22Z" diff --git a/advisories/unreviewed/2025/01/GHSA-7x7r-gpvw-q53f/GHSA-7x7r-gpvw-q53f.json b/advisories/unreviewed/2025/01/GHSA-7x7r-gpvw-q53f/GHSA-7x7r-gpvw-q53f.json new file mode 100644 index 00000000000..3c610996ff4 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-7x7r-gpvw-q53f/GHSA-7x7r-gpvw-q53f.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7x7r-gpvw-q53f", + "modified": "2025-01-07T21:30:55Z", + "published": "2025-01-07T21:30:55Z", + "aliases": [ + "CVE-2024-55218" + ], + "details": "IceWarp Server 10.2.1 is vulnerable to Cross Site Scripting (XSS) via the meta parameter.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55218" + }, + { + "type": "WEB", + "url": "https://resources.s4e.io/blog/icewarp-server-10-2-1-reflected-xss-vulnerability-cve-2024-55218" + }, + { + "type": "WEB", + "url": "https://www.icewarp.com" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T20:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-8rg4-cvw3-v3c2/GHSA-8rg4-cvw3-v3c2.json b/advisories/unreviewed/2025/01/GHSA-8rg4-cvw3-v3c2/GHSA-8rg4-cvw3-v3c2.json index 4f36f7992a1..d27640d663e 100644 --- a/advisories/unreviewed/2025/01/GHSA-8rg4-cvw3-v3c2/GHSA-8rg4-cvw3-v3c2.json +++ b/advisories/unreviewed/2025/01/GHSA-8rg4-cvw3-v3c2/GHSA-8rg4-cvw3-v3c2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8rg4-cvw3-v3c2", - "modified": "2025-01-07T18:30:49Z", + "modified": "2025-01-07T21:30:55Z", "published": "2025-01-07T18:30:49Z", "aliases": [ "CVE-2024-46242" ], "details": "An issue in the validate_email function in CTFd/utils/validators/__init__.py of CTFd 3.7.3 allows attackers to cause a Regular expression Denial of Service (ReDoS) via supplying a crafted string as e-mail address during registration.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-1333" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-07T16:15:33Z" diff --git a/advisories/unreviewed/2025/01/GHSA-9w8w-fgjg-w972/GHSA-9w8w-fgjg-w972.json b/advisories/unreviewed/2025/01/GHSA-9w8w-fgjg-w972/GHSA-9w8w-fgjg-w972.json new file mode 100644 index 00000000000..3989c96388b --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9w8w-fgjg-w972/GHSA-9w8w-fgjg-w972.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9w8w-fgjg-w972", + "modified": "2025-01-07T21:30:55Z", + "published": "2025-01-07T21:30:55Z", + "aliases": [ + "CVE-2024-54819" + ], + "details": "I, Librarian before and including 5.11.1 is vulnerable to Server-Side Request Forgery (SSRF) due to improper input validation in classes/security/validation.php", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54819" + }, + { + "type": "WEB", + "url": "https://github.com/mkucej/i-librarian-free/commit/ed36f6f258392fa2ec72f9820661ded75d91accc" + }, + { + "type": "WEB", + "url": "https://github.com/partywavesec/CVE-2024-55557" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T20:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-c2qq-pcr6-27vg/GHSA-c2qq-pcr6-27vg.json b/advisories/unreviewed/2025/01/GHSA-c2qq-pcr6-27vg/GHSA-c2qq-pcr6-27vg.json index 8ecc0b1bef7..499d9842bb9 100644 --- a/advisories/unreviewed/2025/01/GHSA-c2qq-pcr6-27vg/GHSA-c2qq-pcr6-27vg.json +++ b/advisories/unreviewed/2025/01/GHSA-c2qq-pcr6-27vg/GHSA-c2qq-pcr6-27vg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c2qq-pcr6-27vg", - "modified": "2025-01-07T18:30:52Z", + "modified": "2025-01-07T21:30:55Z", "published": "2025-01-07T18:30:52Z", "aliases": [ "CVE-2024-55410" ], "details": "An issue in the 690b33e1-0462-4e84-9bea-c7552b45432a.sys component of Asus GPU Tweak II Program Driver v1.0.0.0 allows attackers to perform arbitrary read and write actions via supplying crafted IOCTL requests.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-07T18:15:20Z" diff --git a/advisories/unreviewed/2025/01/GHSA-frx6-qwhw-g358/GHSA-frx6-qwhw-g358.json b/advisories/unreviewed/2025/01/GHSA-frx6-qwhw-g358/GHSA-frx6-qwhw-g358.json index 39a98226f4b..c5e5b5ea796 100644 --- a/advisories/unreviewed/2025/01/GHSA-frx6-qwhw-g358/GHSA-frx6-qwhw-g358.json +++ b/advisories/unreviewed/2025/01/GHSA-frx6-qwhw-g358/GHSA-frx6-qwhw-g358.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-frx6-qwhw-g358", - "modified": "2025-01-07T18:30:49Z", + "modified": "2025-01-07T21:30:55Z", "published": "2025-01-07T18:30:49Z", "aliases": [ "CVE-2024-46602" ], "details": "An issue was discovered in Elspec G5 digital fault recorder version 1.2.1.12 and earlier. An XML External Entity (XXE) vulnerability may allow an attacker to cause a Denial of Service (DoS) via a crafted XML payload.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-611" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-07T16:15:34Z" diff --git a/advisories/unreviewed/2025/01/GHSA-fv2q-p9cw-m9w5/GHSA-fv2q-p9cw-m9w5.json b/advisories/unreviewed/2025/01/GHSA-fv2q-p9cw-m9w5/GHSA-fv2q-p9cw-m9w5.json new file mode 100644 index 00000000000..7b817afebe5 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-fv2q-p9cw-m9w5/GHSA-fv2q-p9cw-m9w5.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fv2q-p9cw-m9w5", + "modified": "2025-01-07T21:30:55Z", + "published": "2025-01-07T21:30:55Z", + "aliases": [ + "CVE-2024-35532" + ], + "details": "An XML External Entity (XXE) injection vulnerability in Intersec Geosafe-ea 2022.12, 2022.13, and 2022.14 allows attackers to perform arbitrary file reading under the privileges of the running process, make SSRF requests, or cause a Denial of Service (DoS) via unspecified vectors.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35532" + }, + { + "type": "WEB", + "url": "https://github.com/post-cyberlabs/CVE-Advisory/blob/main/CVE-2024-35532.pdf" + }, + { + "type": "WEB", + "url": "https://intersec.com/public-safety" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T20:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-g968-64xh-hq2x/GHSA-g968-64xh-hq2x.json b/advisories/unreviewed/2025/01/GHSA-g968-64xh-hq2x/GHSA-g968-64xh-hq2x.json index e8fbfcf2cbc..520c56776da 100644 --- a/advisories/unreviewed/2025/01/GHSA-g968-64xh-hq2x/GHSA-g968-64xh-hq2x.json +++ b/advisories/unreviewed/2025/01/GHSA-g968-64xh-hq2x/GHSA-g968-64xh-hq2x.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-g968-64xh-hq2x", - "modified": "2025-01-07T18:30:52Z", + "modified": "2025-01-07T21:30:55Z", "published": "2025-01-07T18:30:52Z", "aliases": [ "CVE-2024-44450" ], "details": "Multiple functions are vulnerable to Authorization Bypass in AIMS eCrew. The issue was fixed in version JUN23 #190.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-639" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-07T18:15:18Z" diff --git a/advisories/unreviewed/2025/01/GHSA-hg4v-r4m7-xj5j/GHSA-hg4v-r4m7-xj5j.json b/advisories/unreviewed/2025/01/GHSA-hg4v-r4m7-xj5j/GHSA-hg4v-r4m7-xj5j.json index ebc859c0181..f0065ef4193 100644 --- a/advisories/unreviewed/2025/01/GHSA-hg4v-r4m7-xj5j/GHSA-hg4v-r4m7-xj5j.json +++ b/advisories/unreviewed/2025/01/GHSA-hg4v-r4m7-xj5j/GHSA-hg4v-r4m7-xj5j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hg4v-r4m7-xj5j", - "modified": "2025-01-07T18:30:49Z", + "modified": "2025-01-07T21:30:55Z", "published": "2025-01-07T18:30:49Z", "aliases": [ "CVE-2024-46603" ], "details": "An XML External Entity (XXE) vulnerability in Elspec Engineering G5 Digital Fault Recorder Firmware v1.2.1.12 allows attackers to cause a Denial of Service (DoS) via a crafted XML payload.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-611" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-07T16:15:34Z" diff --git a/advisories/unreviewed/2025/01/GHSA-j2pc-4j53-q3ww/GHSA-j2pc-4j53-q3ww.json b/advisories/unreviewed/2025/01/GHSA-j2pc-4j53-q3ww/GHSA-j2pc-4j53-q3ww.json new file mode 100644 index 00000000000..be667a7d45e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-j2pc-4j53-q3ww/GHSA-j2pc-4j53-q3ww.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j2pc-4j53-q3ww", + "modified": "2025-01-07T21:30:55Z", + "published": "2025-01-07T21:30:55Z", + "aliases": [ + "CVE-2025-0218" + ], + "details": "When batch jobs are executed by pgAgent, a script is created in a temporary directory and then executed. In versions of pgAgent prior to 4.2.3, an insufficiently seeded random number generator is used when generating the directory name, leading to the possibility for a local attacker to pre-create the directory and thus prevent pgAgent from executing jobs, disrupting scheduled tasks.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0218" + }, + { + "type": "WEB", + "url": "https://github.com/pgadmin-org/pgagent/commit/1ecd193a2be3a3dc9e98f369495e1a792e6d508c" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-340" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T20:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-qjmp-rfrj-7cv5/GHSA-qjmp-rfrj-7cv5.json b/advisories/unreviewed/2025/01/GHSA-qjmp-rfrj-7cv5/GHSA-qjmp-rfrj-7cv5.json new file mode 100644 index 00000000000..5d86efe6cfb --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-qjmp-rfrj-7cv5/GHSA-qjmp-rfrj-7cv5.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qjmp-rfrj-7cv5", + "modified": "2025-01-07T21:30:55Z", + "published": "2025-01-07T21:30:55Z", + "aliases": [ + "CVE-2022-45185" + ], + "details": "An issue was discovered in SuiteCRM 7.12.7. Authenticated users can use CRM functions to upload malicious files. Then, deserialization can be used to achieve code execution.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45185" + }, + { + "type": "WEB", + "url": "https://docs.suitecrm.com/admin/releases/7.12.x" + }, + { + "type": "WEB", + "url": "https://github.com/Orange-Cyberdefense/CVE-repository" + }, + { + "type": "WEB", + "url": "https://github.com/Orange-Cyberdefense/CVE-repository/blob/master/PoCs/poc_SuiteCRM.py" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T20:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-r253-3wvv-8j5p/GHSA-r253-3wvv-8j5p.json b/advisories/unreviewed/2025/01/GHSA-r253-3wvv-8j5p/GHSA-r253-3wvv-8j5p.json index 3e68dc1f131..c50d4f1668a 100644 --- a/advisories/unreviewed/2025/01/GHSA-r253-3wvv-8j5p/GHSA-r253-3wvv-8j5p.json +++ b/advisories/unreviewed/2025/01/GHSA-r253-3wvv-8j5p/GHSA-r253-3wvv-8j5p.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-r253-3wvv-8j5p", - "modified": "2025-01-07T18:30:49Z", + "modified": "2025-01-07T21:30:55Z", "published": "2025-01-07T18:30:49Z", "aliases": [ "CVE-2024-48245" ], "details": "Vehicle Management System 1.0 is vulnerable to SQL Injection. A guest user can exploit vulnerable POST parameters in various administrative actions, such as booking a vehicle or confirming a booking. The affected parameters include \"Booking ID\", \"Action Name\", and \"Payment Confirmation ID\", which are present in /newvehicle.php and /newdriver.php.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-07T16:15:34Z" diff --git a/advisories/unreviewed/2025/01/GHSA-vh28-f7wh-hg42/GHSA-vh28-f7wh-hg42.json b/advisories/unreviewed/2025/01/GHSA-vh28-f7wh-hg42/GHSA-vh28-f7wh-hg42.json new file mode 100644 index 00000000000..7731011a670 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-vh28-f7wh-hg42/GHSA-vh28-f7wh-hg42.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vh28-f7wh-hg42", + "modified": "2025-01-07T21:30:55Z", + "published": "2025-01-07T21:30:55Z", + "aliases": [ + "CVE-2022-41573" + ], + "details": "An issue was discovered in Ovidentia 8.3. The file upload feature does not prevent the uploading of executable files. A user can upload a .png file containing PHP code and then rename it to have the .php extension. It will then be accessible at an images/common/ URI for remote code execution.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-41573" + }, + { + "type": "WEB", + "url": "https://bitbucket.org/cantico/ovidentia/branches" + }, + { + "type": "WEB", + "url": "https://github.com/Orange-Cyberdefense/CVE-repository" + }, + { + "type": "WEB", + "url": "https://github.com/Orange-Cyberdefense/CVE-repository/blob/master/PoCs/poc_CVE-2022-41573.txt" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T20:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-vrcp-29m9-49c3/GHSA-vrcp-29m9-49c3.json b/advisories/unreviewed/2025/01/GHSA-vrcp-29m9-49c3/GHSA-vrcp-29m9-49c3.json index 05d7dcf420d..df0b774aecf 100644 --- a/advisories/unreviewed/2025/01/GHSA-vrcp-29m9-49c3/GHSA-vrcp-29m9-49c3.json +++ b/advisories/unreviewed/2025/01/GHSA-vrcp-29m9-49c3/GHSA-vrcp-29m9-49c3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vrcp-29m9-49c3", - "modified": "2025-01-07T18:30:49Z", + "modified": "2025-01-07T21:30:55Z", "published": "2025-01-07T18:30:49Z", "aliases": [ "CVE-2024-53345" ], "details": "An authenticated arbitrary file upload vulnerability in Car Rental Management System v1.0 to v1.3 allows attackers to execute arbitrary code via uploading a crafted file.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-434" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-07T16:15:35Z" diff --git a/advisories/unreviewed/2025/01/GHSA-vw24-gw6x-f64v/GHSA-vw24-gw6x-f64v.json b/advisories/unreviewed/2025/01/GHSA-vw24-gw6x-f64v/GHSA-vw24-gw6x-f64v.json index cc283a394f8..d79745f5ffe 100644 --- a/advisories/unreviewed/2025/01/GHSA-vw24-gw6x-f64v/GHSA-vw24-gw6x-f64v.json +++ b/advisories/unreviewed/2025/01/GHSA-vw24-gw6x-f64v/GHSA-vw24-gw6x-f64v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vw24-gw6x-f64v", - "modified": "2025-01-06T18:31:04Z", + "modified": "2025-01-07T21:30:55Z", "published": "2025-01-06T18:31:04Z", "aliases": [ "CVE-2024-54879" ], "details": "SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user to recharge members indefinitely.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-281" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-06T18:15:21Z" diff --git a/advisories/unreviewed/2025/01/GHSA-w3jp-95q8-wv48/GHSA-w3jp-95q8-wv48.json b/advisories/unreviewed/2025/01/GHSA-w3jp-95q8-wv48/GHSA-w3jp-95q8-wv48.json new file mode 100644 index 00000000000..20886e5bf14 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-w3jp-95q8-wv48/GHSA-w3jp-95q8-wv48.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w3jp-95q8-wv48", + "modified": "2025-01-07T21:30:55Z", + "published": "2025-01-07T21:30:55Z", + "aliases": [ + "CVE-2024-53522" + ], + "details": "Bangkok Medical Software HOSxP XE v4.64.11.3 was discovered to contain a hardcoded IDEA Key-IV pair in the HOSxPXE4.exe and HOS-WIN32.INI components. This allows attackers to access sensitive information.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53522" + }, + { + "type": "WEB", + "url": "https://www.safecloud.co.th/researches/blog/CVE-2024-53522" + }, + { + "type": "WEB", + "url": "http://bangkok.com" + }, + { + "type": "WEB", + "url": "http://hosxp.com" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T20:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-w3wc-83g3-v333/GHSA-w3wc-83g3-v333.json b/advisories/unreviewed/2025/01/GHSA-w3wc-83g3-v333/GHSA-w3wc-83g3-v333.json new file mode 100644 index 00000000000..ab6f16b0fec --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-w3wc-83g3-v333/GHSA-w3wc-83g3-v333.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w3wc-83g3-v333", + "modified": "2025-01-07T21:30:55Z", + "published": "2025-01-07T21:30:55Z", + "aliases": [ + "CVE-2024-40427" + ], + "details": "Stack Buffer Overflow in PX4-Autopilot v1.14.3, which allows attackers to execute commands to exploit this vulnerability and cause the program to refuse to execute", + "severity": [], + "affected": [], + "references": [ + { + "type": "WEB", + "url": "https://github.com/PX4/PX4-Autopilot/security/advisories/GHSA-55wq-2hgm-75m4" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40427" + }, + { + "type": "WEB", + "url": "https://github.com/PX4/PX4-Autopilot/commit/e03e0261a1a0c82f545e66a1e3795956c886db71" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-07T19:15:32Z" + } +} \ No newline at end of file