diff --git a/advisories/unreviewed/2024/02/GHSA-fqcg-3mm9-jcr6/GHSA-fqcg-3mm9-jcr6.json b/advisories/unreviewed/2024/02/GHSA-fqcg-3mm9-jcr6/GHSA-fqcg-3mm9-jcr6.json index b79d615edfd..875cca41078 100644 --- a/advisories/unreviewed/2024/02/GHSA-fqcg-3mm9-jcr6/GHSA-fqcg-3mm9-jcr6.json +++ b/advisories/unreviewed/2024/02/GHSA-fqcg-3mm9-jcr6/GHSA-fqcg-3mm9-jcr6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fqcg-3mm9-jcr6", - "modified": "2024-02-29T03:33:13Z", + "modified": "2024-11-26T00:33:28Z", "published": "2024-02-29T03:33:13Z", "aliases": [ "CVE-2023-43769" ], "details": "An issue was discovered in Couchbase Server through 7.1.4 before 7.1.5 and before 7.2.1. There are Unauthenticated RMI Service Ports Exposed in Analytics.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-29T01:41:09Z" diff --git a/advisories/unreviewed/2024/06/GHSA-wcfw-xf28-g8pv/GHSA-wcfw-xf28-g8pv.json b/advisories/unreviewed/2024/06/GHSA-wcfw-xf28-g8pv/GHSA-wcfw-xf28-g8pv.json index bd95d18cfbe..f5734eb5ed4 100644 --- a/advisories/unreviewed/2024/06/GHSA-wcfw-xf28-g8pv/GHSA-wcfw-xf28-g8pv.json +++ b/advisories/unreviewed/2024/06/GHSA-wcfw-xf28-g8pv/GHSA-wcfw-xf28-g8pv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wcfw-xf28-g8pv", - "modified": "2024-06-13T21:30:52Z", + "modified": "2024-11-26T00:33:31Z", "published": "2024-06-13T21:30:52Z", "aliases": [ "CVE-2024-36589" ], "details": "An issue in Annonshop.app DecentralizeJustice/anonymousLocker commit 2b2b4 to ba9fd and DecentralizeJustice/anonBackend commit 57837 to cd815 was discovered to store credentials in plaintext.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-312" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-13T19:15:52Z" diff --git a/advisories/unreviewed/2024/10/GHSA-q8xm-x824-w6gf/GHSA-q8xm-x824-w6gf.json b/advisories/unreviewed/2024/10/GHSA-q8xm-x824-w6gf/GHSA-q8xm-x824-w6gf.json index b59898109bc..75f4fe0aead 100644 --- a/advisories/unreviewed/2024/10/GHSA-q8xm-x824-w6gf/GHSA-q8xm-x824-w6gf.json +++ b/advisories/unreviewed/2024/10/GHSA-q8xm-x824-w6gf/GHSA-q8xm-x824-w6gf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q8xm-x824-w6gf", - "modified": "2024-10-07T21:33:30Z", + "modified": "2024-11-26T00:33:31Z", "published": "2024-10-07T21:33:30Z", "aliases": [ "CVE-2024-45894" ], "details": "BlueCMS 1.6 suffers from Arbitrary File Deletion via the file_name parameter in an /admin/database.php?act=del request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-552" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-07T19:15:09Z" diff --git a/advisories/unreviewed/2024/11/GHSA-59xx-49pj-8gx8/GHSA-59xx-49pj-8gx8.json b/advisories/unreviewed/2024/11/GHSA-59xx-49pj-8gx8/GHSA-59xx-49pj-8gx8.json new file mode 100644 index 00000000000..25e457e696f --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-59xx-49pj-8gx8/GHSA-59xx-49pj-8gx8.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-59xx-49pj-8gx8", + "modified": "2024-11-26T00:33:31Z", + "published": "2024-11-26T00:33:31Z", + "aliases": [ + "CVE-2024-53102" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnvme: make keep-alive synchronous operation\n\nThe nvme keep-alive operation, which executes at a periodic interval,\ncould potentially sneak in while shutting down a fabric controller.\nThis may lead to a race between the fabric controller admin queue\ndestroy code path (invoked while shutting down controller) and hw/hctx\nqueue dispatcher called from the nvme keep-alive async request queuing\noperation. This race could lead to the kernel crash shown below:\n\nCall Trace:\n autoremove_wake_function+0x0/0xbc (unreliable)\n __blk_mq_sched_dispatch_requests+0x114/0x24c\n blk_mq_sched_dispatch_requests+0x44/0x84\n blk_mq_run_hw_queue+0x140/0x220\n nvme_keep_alive_work+0xc8/0x19c [nvme_core]\n process_one_work+0x200/0x4e0\n worker_thread+0x340/0x504\n kthread+0x138/0x140\n start_kernel_thread+0x14/0x18\n\nWhile shutting down fabric controller, if nvme keep-alive request sneaks\nin then it would be flushed off. The nvme_keep_alive_end_io function is\nthen invoked to handle the end of the keep-alive operation which\ndecrements the admin->q_usage_counter and assuming this is the last/only\nrequest in the admin queue then the admin->q_usage_counter becomes zero.\nIf that happens then blk-mq destroy queue operation (blk_mq_destroy_\nqueue()) which could be potentially running simultaneously on another\ncpu (as this is the controller shutdown code path) would forward\nprogress and deletes the admin queue. So, now from this point onward\nwe are not supposed to access the admin queue resources. However the\nissue here's that the nvme keep-alive thread running hw/hctx queue\ndispatch operation hasn't yet finished its work and so it could still\npotentially access the admin queue resource while the admin queue had\nbeen already deleted and that causes the above crash.\n\nThis fix helps avoid the observed crash by implementing keep-alive as a\nsynchronous operation so that we decrement admin->q_usage_counter only\nafter keep-alive command finished its execution and returns the command\nstatus back up to its caller (blk_execute_rq()). This would ensure that\nfabric shutdown code path doesn't destroy the fabric admin queue until\nkeep-alive request finished execution and also keep-alive thread is not\nrunning hw/hctx queue dispatch operation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53102" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1a1bcca5c9efd2c72c8d2fcbadf2d673cceb2ea7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/afa229465399f89d3af9d72ced865144c9748846" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ccc1d82dfaad0ad27d21139da22e57add73d2a5e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d06923670b5a5f609603d4a9fee4dec02d38de9c" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-25T22:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-hfmf-v8jm-fcm9/GHSA-hfmf-v8jm-fcm9.json b/advisories/unreviewed/2024/11/GHSA-hfmf-v8jm-fcm9/GHSA-hfmf-v8jm-fcm9.json new file mode 100644 index 00000000000..93a383e5108 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-hfmf-v8jm-fcm9/GHSA-hfmf-v8jm-fcm9.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hfmf-v8jm-fcm9", + "modified": "2024-11-26T00:33:31Z", + "published": "2024-11-26T00:33:31Z", + "aliases": [ + "CVE-2024-53597" + ], + "details": "masterstack_imgcap v0.0.1 was discovered to contain a SQL injection vulnerability via the endpoint /submit.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53597" + }, + { + "type": "WEB", + "url": "https://github.com/NoPurposeInLife/vulnerability_research/tree/main/CVE-2024-53597" + }, + { + "type": "WEB", + "url": "http://masterstackimgcap.com" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-25T22:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-j7rp-c5hp-xpqv/GHSA-j7rp-c5hp-xpqv.json b/advisories/unreviewed/2024/11/GHSA-j7rp-c5hp-xpqv/GHSA-j7rp-c5hp-xpqv.json new file mode 100644 index 00000000000..c064413f222 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-j7rp-c5hp-xpqv/GHSA-j7rp-c5hp-xpqv.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j7rp-c5hp-xpqv", + "modified": "2024-11-26T00:33:31Z", + "published": "2024-11-26T00:33:31Z", + "aliases": [ + "CVE-2024-53098" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe/ufence: Prefetch ufence addr to catch bogus address\n\naccess_ok() only checks for addr overflow so also try to read the addr\nto catch invalid addr sent from userspace.\n\n(cherry picked from commit 9408c4508483ffc60811e910a93d6425b8e63928)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53098" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5d623ffbae96b23f1fc43a3d5a267aabdb07583d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9c1813b3253480b30604c680026c7dc721ce86d1" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-25T22:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-jj65-jvhx-4h6p/GHSA-jj65-jvhx-4h6p.json b/advisories/unreviewed/2024/11/GHSA-jj65-jvhx-4h6p/GHSA-jj65-jvhx-4h6p.json new file mode 100644 index 00000000000..f142203f226 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-jj65-jvhx-4h6p/GHSA-jj65-jvhx-4h6p.json @@ -0,0 +1,63 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jj65-jvhx-4h6p", + "modified": "2024-11-26T00:33:31Z", + "published": "2024-11-26T00:33:31Z", + "aliases": [ + "CVE-2024-53101" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfs: Fix uninitialized value issue in from_kuid and from_kgid\n\nocfs2_setattr() uses attr->ia_mode, attr->ia_uid and attr->ia_gid in\na trace point even though ATTR_MODE, ATTR_UID and ATTR_GID aren't set.\n\nInitialize all fields of newattrs to avoid uninitialized variables, by\nchecking if ATTR_MODE, ATTR_UID, ATTR_GID are initialized, otherwise 0.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53101" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/15f34347481648a567db67fb473c23befb796af5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/17ecb40c5cc7755a321fb6148cba5797431ee5b8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1c28bca1256aecece6e94b26b85cd07e08b0dc90" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1cb5bfc5bfc651982b6203c224d49b7ddacf28bc" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5a72b0d3497b818d8f000c347a7c11801eb27bfc" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9db25c2b41c34963c3ccf473b08171f87670652e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a0c77e5e3dcbffc7c6080ccc89c037f0c86496cf" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b3e612bd8f64ce62e731e95f635e06a2efe3c80c" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-25T22:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-mh5g-qxxq-3x3p/GHSA-mh5g-qxxq-3x3p.json b/advisories/unreviewed/2024/11/GHSA-mh5g-qxxq-3x3p/GHSA-mh5g-qxxq-3x3p.json new file mode 100644 index 00000000000..0cb2473ddad --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-mh5g-qxxq-3x3p/GHSA-mh5g-qxxq-3x3p.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mh5g-qxxq-3x3p", + "modified": "2024-11-26T00:33:32Z", + "published": "2024-11-26T00:33:31Z", + "aliases": [ + "CVE-2024-53100" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnvme: tcp: avoid race between queue_lock lock and destroy\n\nCommit 76d54bf20cdc (\"nvme-tcp: don't access released socket during\nerror recovery\") added a mutex_lock() call for the queue->queue_lock\nin nvme_tcp_get_address(). However, the mutex_lock() races with\nmutex_destroy() in nvme_tcp_free_queue(), and causes the WARN below.\n\nDEBUG_LOCKS_WARN_ON(lock->magic != lock)\nWARNING: CPU: 3 PID: 34077 at kernel/locking/mutex.c:587 __mutex_lock+0xcf0/0x1220\nModules linked in: nvmet_tcp nvmet nvme_tcp nvme_fabrics iw_cm ib_cm ib_core pktcdvd nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 ip_set nf_tables qrtr sunrpc ppdev 9pnet_virtio 9pnet pcspkr netfs parport_pc parport e1000 i2c_piix4 i2c_smbus loop fuse nfnetlink zram bochs drm_vram_helper drm_ttm_helper ttm drm_kms_helper xfs drm sym53c8xx floppy nvme scsi_transport_spi nvme_core nvme_auth serio_raw ata_generic pata_acpi dm_multipath qemu_fw_cfg [last unloaded: ib_uverbs]\nCPU: 3 UID: 0 PID: 34077 Comm: udisksd Not tainted 6.11.0-rc7 #319\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-2.fc40 04/01/2014\nRIP: 0010:__mutex_lock+0xcf0/0x1220\nCode: 08 84 d2 0f 85 c8 04 00 00 8b 15 ef b6 c8 01 85 d2 0f 85 78 f4 ff ff 48 c7 c6 20 93 ee af 48 c7 c7 60 91 ee af e8 f0 a7 6d fd <0f> 0b e9 5e f4 ff ff 48 b8 00 00 00 00 00 fc ff df 4c 89 f2 48 c1\nRSP: 0018:ffff88811305f760 EFLAGS: 00010286\nRAX: 0000000000000000 RBX: ffff88812c652058 RCX: 0000000000000000\nRDX: 0000000000000000 RSI: 0000000000000004 RDI: 0000000000000001\nRBP: ffff88811305f8b0 R08: 0000000000000001 R09: ffffed1075c36341\nR10: ffff8883ae1b1a0b R11: 0000000000010498 R12: 0000000000000000\nR13: 0000000000000000 R14: dffffc0000000000 R15: ffff88812c652058\nFS: 00007f9713ae4980(0000) GS:ffff8883ae180000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007fcd78483c7c CR3: 0000000122c38000 CR4: 00000000000006f0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nCall Trace:\n \n ? __warn.cold+0x5b/0x1af\n ? __mutex_lock+0xcf0/0x1220\n ? report_bug+0x1ec/0x390\n ? handle_bug+0x3c/0x80\n ? exc_invalid_op+0x13/0x40\n ? asm_exc_invalid_op+0x16/0x20\n ? __mutex_lock+0xcf0/0x1220\n ? nvme_tcp_get_address+0xc2/0x1e0 [nvme_tcp]\n ? __pfx___mutex_lock+0x10/0x10\n ? __lock_acquire+0xd6a/0x59e0\n ? nvme_tcp_get_address+0xc2/0x1e0 [nvme_tcp]\n nvme_tcp_get_address+0xc2/0x1e0 [nvme_tcp]\n ? __pfx_nvme_tcp_get_address+0x10/0x10 [nvme_tcp]\n nvme_sysfs_show_address+0x81/0xc0 [nvme_core]\n dev_attr_show+0x42/0x80\n ? __asan_memset+0x1f/0x40\n sysfs_kf_seq_show+0x1f0/0x370\n seq_read_iter+0x2cb/0x1130\n ? rw_verify_area+0x3b1/0x590\n ? __mutex_lock+0x433/0x1220\n vfs_read+0x6a6/0xa20\n ? lockdep_hardirqs_on+0x78/0x100\n ? __pfx_vfs_read+0x10/0x10\n ksys_read+0xf7/0x1d0\n ? __pfx_ksys_read+0x10/0x10\n ? __x64_sys_openat+0x105/0x1d0\n do_syscall_64+0x93/0x180\n ? lockdep_hardirqs_on_prepare+0x16d/0x400\n ? do_syscall_64+0x9f/0x180\n ? lockdep_hardirqs_on+0x78/0x100\n ? do_syscall_64+0x9f/0x180\n ? __pfx_ksys_read+0x10/0x10\n ? lockdep_hardirqs_on_prepare+0x16d/0x400\n ? do_syscall_64+0x9f/0x180\n ? lockdep_hardirqs_on+0x78/0x100\n ? do_syscall_64+0x9f/0x180\n ? lockdep_hardirqs_on_prepare+0x16d/0x400\n ? do_syscall_64+0x9f/0x180\n ? lockdep_hardirqs_on+0x78/0x100\n ? do_syscall_64+0x9f/0x180\n ? lockdep_hardirqs_on_prepare+0x16d/0x400\n ? do_syscall_64+0x9f/0x180\n ? lockdep_hardirqs_on+0x78/0x100\n ? do_syscall_64+0x9f/0x180\n ? lockdep_hardirqs_on_prepare+0x16d/0x400\n ? do_syscall_64+0x9f/0x180\n ? lockdep_hardirqs_on+0x78/0x100\n ? do_syscall_64+0x9f/0x180\n ? do_syscall_64+0x9f/0x180\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\nRIP: 0033:0x7f9713f55cfa\nCode: 55 48 89 e5 48 83 ec 20 48 89 55 e8 48 89 75 f0 89 7d f8 e8 e8 74 f8 ff 48 8b 55 e8 48 8b 75 f0 4\n---truncated---", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53100" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4f946479b326a3cbb193f2b8368aed9269514c35" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/782373ba27660ba7d330208cf5509ece6feb4545" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/975cb1d2121511584695d0e47fdb90e6782da007" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e15cebc1b21856944b387f4abd03b66bd3d4f027" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-25T22:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-p8x9-vqx9-g5pw/GHSA-p8x9-vqx9-g5pw.json b/advisories/unreviewed/2024/11/GHSA-p8x9-vqx9-g5pw/GHSA-p8x9-vqx9-g5pw.json index 88debe370b4..fb0117b1a4c 100644 --- a/advisories/unreviewed/2024/11/GHSA-p8x9-vqx9-g5pw/GHSA-p8x9-vqx9-g5pw.json +++ b/advisories/unreviewed/2024/11/GHSA-p8x9-vqx9-g5pw/GHSA-p8x9-vqx9-g5pw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p8x9-vqx9-g5pw", - "modified": "2024-11-20T21:30:50Z", + "modified": "2024-11-26T00:33:31Z", "published": "2024-11-20T21:30:50Z", "aliases": [ "CVE-2024-48984" ], "details": "An issue was discovered in MBed OS 6.16.0. When parsing hci reports, the hci parsing software dynamically determines the length of a list of reports by reading a byte from an input stream. It then fetches the length of the first report, uses it to calculate the beginning of the second report, etc. In doing this, it tracks the largest report so it can later allocate a buffer that fits every individual report (but only one at a time). It does not, however, validate that these addresses are all contained within the buffer passed to hciEvtProcessLeExtAdvReport. It is then possible, though unlikely, that the buffer designated to hold the reports is allocated in such a way that one of these out-of-bounds length fields is contained within the new buffer. When the (n-1)th report is copied, it overwrites the length field of the nth report. This now corrupted length field is then used for a memcpy into the new buffer, which may lead to a buffer overflow.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-20T21:15:07Z" diff --git a/advisories/unreviewed/2024/11/GHSA-pg27-6936-jg2x/GHSA-pg27-6936-jg2x.json b/advisories/unreviewed/2024/11/GHSA-pg27-6936-jg2x/GHSA-pg27-6936-jg2x.json new file mode 100644 index 00000000000..259e5d493ad --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-pg27-6936-jg2x/GHSA-pg27-6936-jg2x.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pg27-6936-jg2x", + "modified": "2024-11-26T00:33:31Z", + "published": "2024-11-26T00:33:31Z", + "aliases": [ + "CVE-2024-53097" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm: krealloc: Fix MTE false alarm in __do_krealloc\n\nThis patch addresses an issue introduced by commit 1a83a716ec233 (\"mm:\nkrealloc: consider spare memory for __GFP_ZERO\") which causes MTE\n(Memory Tagging Extension) to falsely report a slab-out-of-bounds error.\n\nThe problem occurs when zeroing out spare memory in __do_krealloc. The\noriginal code only considered software-based KASAN and did not account\nfor MTE. It does not reset the KASAN tag before calling memset, leading\nto a mismatch between the pointer tag and the memory tag, resulting\nin a false positive.\n\nExample of the error:\n==================================================================\nswapper/0: BUG: KASAN: slab-out-of-bounds in __memset+0x84/0x188\nswapper/0: Write at addr f4ffff8005f0fdf0 by task swapper/0/1\nswapper/0: Pointer tag: [f4], memory tag: [fe]\nswapper/0:\nswapper/0: CPU: 4 UID: 0 PID: 1 Comm: swapper/0 Not tainted 6.12.\nswapper/0: Hardware name: MT6991(ENG) (DT)\nswapper/0: Call trace:\nswapper/0: dump_backtrace+0xfc/0x17c\nswapper/0: show_stack+0x18/0x28\nswapper/0: dump_stack_lvl+0x40/0xa0\nswapper/0: print_report+0x1b8/0x71c\nswapper/0: kasan_report+0xec/0x14c\nswapper/0: __do_kernel_fault+0x60/0x29c\nswapper/0: do_bad_area+0x30/0xdc\nswapper/0: do_tag_check_fault+0x20/0x34\nswapper/0: do_mem_abort+0x58/0x104\nswapper/0: el1_abort+0x3c/0x5c\nswapper/0: el1h_64_sync_handler+0x80/0xcc\nswapper/0: el1h_64_sync+0x68/0x6c\nswapper/0: __memset+0x84/0x188\nswapper/0: btf_populate_kfunc_set+0x280/0x3d8\nswapper/0: __register_btf_kfunc_id_set+0x43c/0x468\nswapper/0: register_btf_kfunc_id_set+0x48/0x60\nswapper/0: register_nf_nat_bpf+0x1c/0x40\nswapper/0: nf_nat_init+0xc0/0x128\nswapper/0: do_one_initcall+0x184/0x464\nswapper/0: do_initcall_level+0xdc/0x1b0\nswapper/0: do_initcalls+0x70/0xc0\nswapper/0: do_basic_setup+0x1c/0x28\nswapper/0: kernel_init_freeable+0x144/0x1b8\nswapper/0: kernel_init+0x20/0x1a8\nswapper/0: ret_from_fork+0x10/0x20\n==================================================================", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53097" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3dfb40da84f26dd35dd9bbaf626a2424565b8406" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/486aeb5f1855c75dd810c25036134961bd2a6722" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/704573851b51808b45dae2d62059d1d8189138a2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/71548fada7ee0eb50cc6ccda82dff010c745f92c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8ebee7565effdeae6085458f8f8463363120a871" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d02492863023431c31f85d570f718433c22b9311" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d43f1430d47c22a0727c05b6f156ed25fecdfeb4" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-25T22:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-pj8j-q75x-3c3f/GHSA-pj8j-q75x-3c3f.json b/advisories/unreviewed/2024/11/GHSA-pj8j-q75x-3c3f/GHSA-pj8j-q75x-3c3f.json new file mode 100644 index 00000000000..c90f4e1e547 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-pj8j-q75x-3c3f/GHSA-pj8j-q75x-3c3f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pj8j-q75x-3c3f", + "modified": "2024-11-26T00:33:31Z", + "published": "2024-11-26T00:33:31Z", + "aliases": [ + "CVE-2024-53333" + ], + "details": "TOTOLINK EX200 v4.0.3c.7646_B20201211 was found to contain a command insertion vulnerability in the setUssd function. This vulnerability allows an attacker to execute arbitrary commands via the \"ussd\" parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53333" + }, + { + "type": "WEB", + "url": "https://github.com/luckysmallbird/Totolink-EX200-Vulnerability-1/blob/main/README.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-21T18:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-pmfq-rg8w-w57m/GHSA-pmfq-rg8w-w57m.json b/advisories/unreviewed/2024/11/GHSA-pmfq-rg8w-w57m/GHSA-pmfq-rg8w-w57m.json new file mode 100644 index 00000000000..02eedab102a --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-pmfq-rg8w-w57m/GHSA-pmfq-rg8w-w57m.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pmfq-rg8w-w57m", + "modified": "2024-11-26T00:33:31Z", + "published": "2024-11-26T00:33:31Z", + "aliases": [ + "CVE-2024-53096" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm: resolve faulty mmap_region() error path behaviour\n\nThe mmap_region() function is somewhat terrifying, with spaghetti-like\ncontrol flow and numerous means by which issues can arise and incomplete\nstate, memory leaks and other unpleasantness can occur.\n\nA large amount of the complexity arises from trying to handle errors late\nin the process of mapping a VMA, which forms the basis of recently\nobserved issues with resource leaks and observable inconsistent state.\n\nTaking advantage of previous patches in this series we move a number of\nchecks earlier in the code, simplifying things by moving the core of the\nlogic into a static internal function __mmap_region().\n\nDoing this allows us to perform a number of checks up front before we do\nany real work, and allows us to unwind the writable unmap check\nunconditionally as required and to perform a CONFIG_DEBUG_VM_MAPLE_TREE\nvalidation unconditionally also.\n\nWe move a number of things here:\n\n1. We preallocate memory for the iterator before we call the file-backed\n memory hook, allowing us to exit early and avoid having to perform\n complicated and error-prone close/free logic. We carefully free\n iterator state on both success and error paths.\n\n2. The enclosing mmap_region() function handles the mapping_map_writable()\n logic early. Previously the logic had the mapping_map_writable() at the\n point of mapping a newly allocated file-backed VMA, and a matching\n mapping_unmap_writable() on success and error paths.\n\n We now do this unconditionally if this is a file-backed, shared writable\n mapping. If a driver changes the flags to eliminate VM_MAYWRITE, however\n doing so does not invalidate the seal check we just performed, and we in\n any case always decrement the counter in the wrapper.\n\n We perform a debug assert to ensure a driver does not attempt to do the\n opposite.\n\n3. We also move arch_validate_flags() up into the mmap_region()\n function. This is only relevant on arm64 and sparc64, and the check is\n only meaningful for SPARC with ADI enabled. We explicitly add a warning\n for this arch if a driver invalidates this check, though the code ought\n eventually to be fixed to eliminate the need for this.\n\nWith all of these measures in place, we no longer need to explicitly close\nthe VMA on error paths, as we place all checks which might fail prior to a\ncall to any driver mmap hook.\n\nThis eliminates an entire class of errors, makes the code easier to reason\nabout and more robust.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53096" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5de195060b2e251a835f622759550e6202167641" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-25T22:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-q84w-4cfg-vvhh/GHSA-q84w-4cfg-vvhh.json b/advisories/unreviewed/2024/11/GHSA-q84w-4cfg-vvhh/GHSA-q84w-4cfg-vvhh.json new file mode 100644 index 00000000000..012ecce6e14 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-q84w-4cfg-vvhh/GHSA-q84w-4cfg-vvhh.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q84w-4cfg-vvhh", + "modified": "2024-11-26T00:33:31Z", + "published": "2024-11-26T00:33:31Z", + "aliases": [ + "CVE-2024-53554" + ], + "details": "A Client-Side Template Injection (CSTI) vulnerability in the component /project/new/scrum of Taiga v 8.6.1 allows remote attackers to execute arbitrary code by injecting a malicious payload within the new project details.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53554" + }, + { + "type": "WEB", + "url": "https://drive.google.com/file/d/1v2MLZn4Ro9TCpw-KtksUACYFIzsbuTkL/view?usp=sharing" + }, + { + "type": "WEB", + "url": "https://gist.githubusercontent.com/Tommywarren/5ed67ab173ed60faeb791215d68e3fac/raw/352cb4259c0d41d70a206d108b5578c15824b2ff/CVE-2024-53554" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-25T22:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-v755-r9fp-w5gj/GHSA-v755-r9fp-w5gj.json b/advisories/unreviewed/2024/11/GHSA-v755-r9fp-w5gj/GHSA-v755-r9fp-w5gj.json new file mode 100644 index 00000000000..9b7579dca2c --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-v755-r9fp-w5gj/GHSA-v755-r9fp-w5gj.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v755-r9fp-w5gj", + "modified": "2024-11-26T00:33:32Z", + "published": "2024-11-26T00:33:31Z", + "aliases": [ + "CVE-2024-11673" + ], + "details": "A vulnerability, which was classified as problematic, has been found in 1000 Projects Bookstore Management System 1.0. This issue affects some unknown processing. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11673" + }, + { + "type": "WEB", + "url": "https://github.com/Hacker0xone/CVE/issues/16" + }, + { + "type": "WEB", + "url": "https://1000projects.org" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.286013" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.286013" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.448470" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-25T23:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-x6vf-7crv-fr5w/GHSA-x6vf-7crv-fr5w.json b/advisories/unreviewed/2024/11/GHSA-x6vf-7crv-fr5w/GHSA-x6vf-7crv-fr5w.json new file mode 100644 index 00000000000..8c76f95d7e3 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-x6vf-7crv-fr5w/GHSA-x6vf-7crv-fr5w.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x6vf-7crv-fr5w", + "modified": "2024-11-26T00:33:31Z", + "published": "2024-11-26T00:33:31Z", + "aliases": [ + "CVE-2024-11674" + ], + "details": "A vulnerability, which was classified as critical, was found in CodeAstro Hospital Management System 1.0. Affected is an unknown function of the file /backend/doc/his_doc_update-account.php. The manipulation of the argument doc_dpic leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11674" + }, + { + "type": "WEB", + "url": "https://codeastro.com" + }, + { + "type": "WEB", + "url": "https://github.com/EmilGallajov/zero-day/blob/main/codeastro_hms_rce.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.286014" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.286014" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.448705" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-26T00:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-xmv6-x39j-72gg/GHSA-xmv6-x39j-72gg.json b/advisories/unreviewed/2024/11/GHSA-xmv6-x39j-72gg/GHSA-xmv6-x39j-72gg.json new file mode 100644 index 00000000000..25632833167 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-xmv6-x39j-72gg/GHSA-xmv6-x39j-72gg.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xmv6-x39j-72gg", + "modified": "2024-11-26T00:33:31Z", + "published": "2024-11-26T00:33:31Z", + "aliases": [ + "CVE-2024-53099" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Check validity of link->type in bpf_link_show_fdinfo()\n\nIf a newly-added link type doesn't invoke BPF_LINK_TYPE(), accessing\nbpf_link_type_strs[link->type] may result in an out-of-bounds access.\n\nTo spot such missed invocations early in the future, checking the\nvalidity of link->type in bpf_link_show_fdinfo() and emitting a warning\nwhen such invocations are missed.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53099" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8421d4c8762bd022cb491f2f0f7019ef51b4f0a7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b3eb1b6a9f745d6941b345f0fae014dc8bb06d36" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d5092b0a1aaf35d77ebd8d33384d7930bec5cb5d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-25T22:15:16Z" + } +} \ No newline at end of file