From 52dcf7f75e3cacea178a37ff1e1f564ca725df6b Mon Sep 17 00:00:00 2001
From: "advisory-database[bot]"
<45398580+advisory-database[bot]@users.noreply.github.com>
Date: Thu, 16 Jan 2025 18:32:36 +0000
Subject: [PATCH] Advisory Database Sync
---
.../GHSA-42w8-jq8g-mg7m.json | 9 ++++-
.../GHSA-9q6c-grq3-7prg.json | 2 +-
.../GHSA-h49m-hqr5-72m9.json | 9 ++++-
.../GHSA-pv3p-47qr-3pw4.json | 9 ++++-
.../GHSA-965f-g96x-3w5j.json | 4 +-
.../GHSA-x79h-5263-4x77.json | 4 +-
.../GHSA-3x46-c2g7-344x.json | 15 +++++--
.../GHSA-9g2q-6jw7-cqfm.json | 4 +-
.../GHSA-p7f2-66rr-gm45.json | 6 ++-
.../GHSA-2g8r-g5wp-xcxp.json | 11 +++--
.../GHSA-3f3q-cv7c-w6c7.json | 15 +++++--
.../GHSA-3hhr-965v-pj8r.json | 11 +++--
.../GHSA-3mhq-jqrv-fc88.json | 15 +++++--
.../GHSA-484w-f535-whcj.json | 15 +++++--
.../GHSA-5c2q-g9wc-9gf6.json | 2 +-
.../GHSA-94pf-4p5q-jc3r.json | 11 +++--
.../GHSA-gxjr-v6fw-49mr.json | 2 +-
.../GHSA-j56h-xwg2-4wc2.json | 11 +++--
.../GHSA-mjrq-f967-qfp4.json | 11 +++--
.../GHSA-pv98-48f2-5vjr.json | 11 +++--
.../GHSA-qp87-27q4-8526.json | 15 +++++--
.../GHSA-r296-33w8-272g.json | 15 +++++--
.../GHSA-vhp7-fvvc-gp4m.json | 11 +++--
.../GHSA-vjpg-wm6m-cjg7.json | 2 +-
.../GHSA-9pw9-3858-mcgc.json | 3 +-
.../GHSA-fc6q-xmrf-7jx4.json | 2 +-
.../GHSA-p7hw-w67j-562v.json | 2 +-
.../GHSA-qp9g-95jm-jwfj.json | 15 +++++--
.../GHSA-vvc7-qvmv-vpjw.json | 15 +++++--
.../GHSA-x4qv-v3fh-v8rj.json | 11 +++--
.../GHSA-xv8c-x88j-w3qj.json | 15 +++++--
.../GHSA-562v-pvgc-xrg8.json | 15 +++++--
.../GHSA-56q7-cvh5-mq2r.json | 15 +++++--
.../GHSA-6gmm-x3pr-vhmf.json | 15 +++++--
.../GHSA-7822-7h76-h235.json | 15 +++++--
.../GHSA-7w8v-gc2j-m9c7.json | 15 +++++--
.../GHSA-8fcf-qpcm-frcf.json | 11 +++--
.../GHSA-cpf2-vjq3-4h5q.json | 15 +++++--
.../GHSA-cwp6-92gh-h7h8.json | 15 +++++--
.../GHSA-fghf-x6v5-95fg.json | 15 +++++--
.../GHSA-g4vc-rr66-6355.json | 15 +++++--
.../GHSA-hc7h-3x34-frvv.json | 15 +++++--
.../GHSA-m75c-j939-x6c2.json | 15 +++++--
.../GHSA-p6p2-g83c-783v.json | 15 +++++--
.../GHSA-pq66-h8qj-7xg9.json | 15 +++++--
.../GHSA-q2w6-3cqh-h6qq.json | 15 +++++--
.../GHSA-wrw9-rpg8-p3wx.json | 15 +++++--
.../GHSA-xq66-2344-jv36.json | 15 +++++--
.../GHSA-26h2-xpj3-3r9v.json | 29 ++++++++++++++
.../GHSA-28h2-465h-q5v7.json | 15 +++++--
.../GHSA-363m-f7wv-qpfm.json | 15 +++++--
.../GHSA-3wg7-r7q5-r2jf.json | 29 ++++++++++++++
.../GHSA-3wjr-3jc2-hr84.json | 29 ++++++++++++++
.../GHSA-488w-xmwq-qcpr.json | 29 ++++++++++++++
.../GHSA-4mfx-6h3r-r7mp.json | 29 ++++++++++++++
.../GHSA-4vwx-53cp-qmh4.json | 15 +++++--
.../GHSA-6q3r-g9gc-ggv9.json | 15 +++++--
.../GHSA-72qv-wqcg-m38g.json | 15 +++++--
.../GHSA-778q-j98c-h63p.json | 36 +++++++++++++++++
.../GHSA-85mx-pqv6-r46j.json | 15 +++++--
.../GHSA-86hg-8qx9-pcjm.json | 15 +++++--
.../GHSA-89gw-cghg-xxj8.json | 15 +++++--
.../GHSA-89vg-q56w-837m.json | 19 +++++++--
.../GHSA-8w9w-hrff-vhqw.json | 15 +++++--
.../GHSA-9j24-7gq4-23wc.json | 15 +++++--
.../GHSA-c6cm-6jvv-fff6.json | 29 ++++++++++++++
.../GHSA-c93c-mp49-pjr9.json | 29 ++++++++++++++
.../GHSA-ccv9-w5j7-qfjr.json | 15 +++++--
.../GHSA-fhcf-5gx2-w6p5.json | 36 +++++++++++++++++
.../GHSA-fw54-qxpm-m379.json | 29 ++++++++++++++
.../GHSA-fx2w-48wv-h9qv.json | 15 +++++--
.../GHSA-g244-x9gp-5m7r.json | 29 ++++++++++++++
.../GHSA-gf42-x7c4-vmr8.json | 15 +++++--
.../GHSA-h394-xchv-jh49.json | 15 +++++--
.../GHSA-h79v-x5rx-hc8c.json | 29 ++++++++++++++
.../GHSA-hpr9-7q5c-v2vc.json | 15 +++++--
.../GHSA-hqhr-2wm6-h7fv.json | 29 ++++++++++++++
.../GHSA-j3j3-25qq-c2c9.json | 15 +++++--
.../GHSA-mmx8-rpcx-mqx8.json | 15 +++++--
.../GHSA-mqpq-866q-4xr5.json | 15 +++++--
.../GHSA-pmh4-6w4w-36pv.json | 15 +++++--
.../GHSA-ppm9-gj8r-ccqm.json | 15 +++++--
.../GHSA-pv2j-88c7-fj84.json | 29 ++++++++++++++
.../GHSA-q3m9-569q-p862.json | 25 ++++++++++++
.../GHSA-q4p3-fg3r-g43m.json | 15 +++++--
.../GHSA-rj29-6cmj-c5hg.json | 15 +++++--
.../GHSA-vc42-8hvr-72r6.json | 29 ++++++++++++++
.../GHSA-vfh4-5f9p-v75j.json | 15 +++++--
.../GHSA-vp3p-57c4-r559.json | 36 +++++++++++++++++
.../GHSA-wmrr-4g25-jxww.json | 15 +++++--
.../GHSA-wp9g-p59f-6fmw.json | 15 +++++--
.../GHSA-wqjm-248p-mph4.json | 15 +++++--
.../GHSA-wrjx-c64x-6339.json | 40 +++++++++++++++++++
.../GHSA-wrvx-8w4q-9p22.json | 29 ++++++++++++++
.../GHSA-wrxp-6gw7-g9fx.json | 11 +++--
.../GHSA-ww6f-v2xc-h7qp.json | 15 +++++--
.../GHSA-ww84-gxq7-g6hv.json | 15 +++++--
.../GHSA-xmr9-3j8w-v8gw.json | 29 ++++++++++++++
98 files changed, 1328 insertions(+), 264 deletions(-)
create mode 100644 advisories/unreviewed/2025/01/GHSA-26h2-xpj3-3r9v/GHSA-26h2-xpj3-3r9v.json
create mode 100644 advisories/unreviewed/2025/01/GHSA-3wg7-r7q5-r2jf/GHSA-3wg7-r7q5-r2jf.json
create mode 100644 advisories/unreviewed/2025/01/GHSA-3wjr-3jc2-hr84/GHSA-3wjr-3jc2-hr84.json
create mode 100644 advisories/unreviewed/2025/01/GHSA-488w-xmwq-qcpr/GHSA-488w-xmwq-qcpr.json
create mode 100644 advisories/unreviewed/2025/01/GHSA-4mfx-6h3r-r7mp/GHSA-4mfx-6h3r-r7mp.json
create mode 100644 advisories/unreviewed/2025/01/GHSA-778q-j98c-h63p/GHSA-778q-j98c-h63p.json
create mode 100644 advisories/unreviewed/2025/01/GHSA-c6cm-6jvv-fff6/GHSA-c6cm-6jvv-fff6.json
create mode 100644 advisories/unreviewed/2025/01/GHSA-c93c-mp49-pjr9/GHSA-c93c-mp49-pjr9.json
create mode 100644 advisories/unreviewed/2025/01/GHSA-fhcf-5gx2-w6p5/GHSA-fhcf-5gx2-w6p5.json
create mode 100644 advisories/unreviewed/2025/01/GHSA-fw54-qxpm-m379/GHSA-fw54-qxpm-m379.json
create mode 100644 advisories/unreviewed/2025/01/GHSA-g244-x9gp-5m7r/GHSA-g244-x9gp-5m7r.json
create mode 100644 advisories/unreviewed/2025/01/GHSA-h79v-x5rx-hc8c/GHSA-h79v-x5rx-hc8c.json
create mode 100644 advisories/unreviewed/2025/01/GHSA-hqhr-2wm6-h7fv/GHSA-hqhr-2wm6-h7fv.json
create mode 100644 advisories/unreviewed/2025/01/GHSA-pv2j-88c7-fj84/GHSA-pv2j-88c7-fj84.json
create mode 100644 advisories/unreviewed/2025/01/GHSA-q3m9-569q-p862/GHSA-q3m9-569q-p862.json
create mode 100644 advisories/unreviewed/2025/01/GHSA-vc42-8hvr-72r6/GHSA-vc42-8hvr-72r6.json
create mode 100644 advisories/unreviewed/2025/01/GHSA-vp3p-57c4-r559/GHSA-vp3p-57c4-r559.json
create mode 100644 advisories/unreviewed/2025/01/GHSA-wrjx-c64x-6339/GHSA-wrjx-c64x-6339.json
create mode 100644 advisories/unreviewed/2025/01/GHSA-wrvx-8w4q-9p22/GHSA-wrvx-8w4q-9p22.json
create mode 100644 advisories/unreviewed/2025/01/GHSA-xmr9-3j8w-v8gw/GHSA-xmr9-3j8w-v8gw.json
diff --git a/advisories/unreviewed/2022/04/GHSA-42w8-jq8g-mg7m/GHSA-42w8-jq8g-mg7m.json b/advisories/unreviewed/2022/04/GHSA-42w8-jq8g-mg7m/GHSA-42w8-jq8g-mg7m.json
index 4a48b5ecb2a..6ffa0e2c157 100644
--- a/advisories/unreviewed/2022/04/GHSA-42w8-jq8g-mg7m/GHSA-42w8-jq8g-mg7m.json
+++ b/advisories/unreviewed/2022/04/GHSA-42w8-jq8g-mg7m/GHSA-42w8-jq8g-mg7m.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-42w8-jq8g-mg7m",
- "modified": "2022-04-30T18:16:30Z",
+ "modified": "2025-01-16T18:30:54Z",
"published": "2022-04-30T18:16:30Z",
"aliases": [
"CVE-2001-0667"
],
"details": "Internet Explorer 6 and earlier, when used with the Telnet client in Services for Unix (SFU) 2.0, allows remote attackers to execute commands by spawning Telnet with a log file option on the command line and writing arbitrary code into an executable file which is later executed, aka a new variant of the Telnet Invocation vulnerability as described in CVE-2001-0150.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
+ }
+ ],
"affected": [],
"references": [
{
diff --git a/advisories/unreviewed/2022/04/GHSA-9q6c-grq3-7prg/GHSA-9q6c-grq3-7prg.json b/advisories/unreviewed/2022/04/GHSA-9q6c-grq3-7prg/GHSA-9q6c-grq3-7prg.json
index a78b06f29ca..68bc0945583 100644
--- a/advisories/unreviewed/2022/04/GHSA-9q6c-grq3-7prg/GHSA-9q6c-grq3-7prg.json
+++ b/advisories/unreviewed/2022/04/GHSA-9q6c-grq3-7prg/GHSA-9q6c-grq3-7prg.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9q6c-grq3-7prg",
- "modified": "2024-02-02T15:30:26Z",
+ "modified": "2025-01-16T18:30:56Z",
"published": "2022-04-29T02:58:17Z",
"aliases": [
"CVE-2004-0747"
diff --git a/advisories/unreviewed/2022/05/GHSA-h49m-hqr5-72m9/GHSA-h49m-hqr5-72m9.json b/advisories/unreviewed/2022/05/GHSA-h49m-hqr5-72m9/GHSA-h49m-hqr5-72m9.json
index efed81e6eb0..3447b55a70f 100644
--- a/advisories/unreviewed/2022/05/GHSA-h49m-hqr5-72m9/GHSA-h49m-hqr5-72m9.json
+++ b/advisories/unreviewed/2022/05/GHSA-h49m-hqr5-72m9/GHSA-h49m-hqr5-72m9.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h49m-hqr5-72m9",
- "modified": "2022-05-01T01:48:49Z",
+ "modified": "2025-01-16T18:30:55Z",
"published": "2022-05-01T01:48:49Z",
"aliases": [
"CVE-2005-0369"
],
"details": "Armagetron 0.2.6.0 and earlier and Armagetron Advanced 0.2.7.0 earlier allows remote attackers to cause a denial of service (application crash) via a packet with a large (1) descriptor ID or (2) claim_id, which exceeds the boundaries of an array.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
+ }
+ ],
"affected": [],
"references": [
{
diff --git a/advisories/unreviewed/2022/05/GHSA-pv3p-47qr-3pw4/GHSA-pv3p-47qr-3pw4.json b/advisories/unreviewed/2022/05/GHSA-pv3p-47qr-3pw4/GHSA-pv3p-47qr-3pw4.json
index 8a97ed6e6db..1e0688b884b 100644
--- a/advisories/unreviewed/2022/05/GHSA-pv3p-47qr-3pw4/GHSA-pv3p-47qr-3pw4.json
+++ b/advisories/unreviewed/2022/05/GHSA-pv3p-47qr-3pw4/GHSA-pv3p-47qr-3pw4.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pv3p-47qr-3pw4",
- "modified": "2022-05-01T01:48:02Z",
+ "modified": "2025-01-16T18:30:55Z",
"published": "2022-05-01T01:48:02Z",
"aliases": [
"CVE-2005-0254"
],
"details": "BibORB 1.3.2, and possibly earlier versions, does not properly enforce a restriction for uploading only PDF and PS files, which allows remote attackers to upload arbitrary files that are presented to other users with PDF or PS icons, which may trick some users into downloading and executing those files.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"
+ }
+ ],
"affected": [],
"references": [
{
diff --git a/advisories/unreviewed/2023/05/GHSA-965f-g96x-3w5j/GHSA-965f-g96x-3w5j.json b/advisories/unreviewed/2023/05/GHSA-965f-g96x-3w5j/GHSA-965f-g96x-3w5j.json
index eece2a17c9f..8c7bfba81e3 100644
--- a/advisories/unreviewed/2023/05/GHSA-965f-g96x-3w5j/GHSA-965f-g96x-3w5j.json
+++ b/advisories/unreviewed/2023/05/GHSA-965f-g96x-3w5j/GHSA-965f-g96x-3w5j.json
@@ -25,7 +25,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-362"
+ ],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2023/05/GHSA-x79h-5263-4x77/GHSA-x79h-5263-4x77.json b/advisories/unreviewed/2023/05/GHSA-x79h-5263-4x77/GHSA-x79h-5263-4x77.json
index 0c5fb1d1cad..1d16750db6d 100644
--- a/advisories/unreviewed/2023/05/GHSA-x79h-5263-4x77/GHSA-x79h-5263-4x77.json
+++ b/advisories/unreviewed/2023/05/GHSA-x79h-5263-4x77/GHSA-x79h-5263-4x77.json
@@ -25,7 +25,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-306"
+ ],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/02/GHSA-3x46-c2g7-344x/GHSA-3x46-c2g7-344x.json b/advisories/unreviewed/2024/02/GHSA-3x46-c2g7-344x/GHSA-3x46-c2g7-344x.json
index 4915938140f..6258939de07 100644
--- a/advisories/unreviewed/2024/02/GHSA-3x46-c2g7-344x/GHSA-3x46-c2g7-344x.json
+++ b/advisories/unreviewed/2024/02/GHSA-3x46-c2g7-344x/GHSA-3x46-c2g7-344x.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3x46-c2g7-344x",
- "modified": "2024-02-29T03:33:18Z",
+ "modified": "2025-01-16T18:30:56Z",
"published": "2024-02-29T03:33:18Z",
"aliases": [
"CVE-2024-25832"
],
"details": "F-logic DataCube3 v1.0 is vulnerable to unrestricted file upload, which could allow an authenticated malicious actor to upload a file of dangerous type by manipulating the filename extension.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-434"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-29T01:44:16Z"
diff --git a/advisories/unreviewed/2024/02/GHSA-9g2q-6jw7-cqfm/GHSA-9g2q-6jw7-cqfm.json b/advisories/unreviewed/2024/02/GHSA-9g2q-6jw7-cqfm/GHSA-9g2q-6jw7-cqfm.json
index 78e8e9e55ef..624e0c13689 100644
--- a/advisories/unreviewed/2024/02/GHSA-9g2q-6jw7-cqfm/GHSA-9g2q-6jw7-cqfm.json
+++ b/advisories/unreviewed/2024/02/GHSA-9g2q-6jw7-cqfm/GHSA-9g2q-6jw7-cqfm.json
@@ -29,7 +29,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-918"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/02/GHSA-p7f2-66rr-gm45/GHSA-p7f2-66rr-gm45.json b/advisories/unreviewed/2024/02/GHSA-p7f2-66rr-gm45/GHSA-p7f2-66rr-gm45.json
index 62a0126883f..35ad5d17865 100644
--- a/advisories/unreviewed/2024/02/GHSA-p7f2-66rr-gm45/GHSA-p7f2-66rr-gm45.json
+++ b/advisories/unreviewed/2024/02/GHSA-p7f2-66rr-gm45/GHSA-p7f2-66rr-gm45.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p7f2-66rr-gm45",
- "modified": "2024-02-29T06:30:33Z",
+ "modified": "2025-01-16T18:30:56Z",
"published": "2024-02-29T06:30:33Z",
"aliases": [
"CVE-2024-1977"
@@ -29,7 +29,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/03/GHSA-2g8r-g5wp-xcxp/GHSA-2g8r-g5wp-xcxp.json b/advisories/unreviewed/2024/03/GHSA-2g8r-g5wp-xcxp/GHSA-2g8r-g5wp-xcxp.json
index a01616f3c68..bd5687503c8 100644
--- a/advisories/unreviewed/2024/03/GHSA-2g8r-g5wp-xcxp/GHSA-2g8r-g5wp-xcxp.json
+++ b/advisories/unreviewed/2024/03/GHSA-2g8r-g5wp-xcxp/GHSA-2g8r-g5wp-xcxp.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2g8r-g5wp-xcxp",
- "modified": "2024-03-03T00:30:32Z",
+ "modified": "2025-01-16T18:30:57Z",
"published": "2024-03-03T00:30:32Z",
"aliases": [
"CVE-2023-52582"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfs: Only call folio_start_fscache() one time for each folio\n\nIf a network filesystem using netfs implements a clamp_length()\nfunction, it can set subrequest lengths smaller than a page size.\n\nWhen we loop through the folios in netfs_rreq_unlock_folios() to\nset any folios to be written back, we need to make sure we only\ncall folio_start_fscache() once for each folio.\n\nOtherwise, this simple testcase:\n\n mount -o fsc,rsize=1024,wsize=1024 127.0.0.1:/export /mnt/nfs\n dd if=/dev/zero of=/mnt/nfs/file.bin bs=4096 count=1\n 1+0 records in\n 1+0 records out\n 4096 bytes (4.1 kB, 4.0 KiB) copied, 0.0126359 s, 324 kB/s\n echo 3 > /proc/sys/vm/drop_caches\n cat /mnt/nfs/file.bin > /dev/null\n\nwill trigger an oops similar to the following:\n\n page dumped because: VM_BUG_ON_FOLIO(folio_test_private_2(folio))\n ------------[ cut here ]------------\n kernel BUG at include/linux/netfs.h:44!\n ...\n CPU: 5 PID: 134 Comm: kworker/u16:5 Kdump: loaded Not tainted 6.4.0-rc5\n ...\n RIP: 0010:netfs_rreq_unlock_folios+0x68e/0x730 [netfs]\n ...\n Call Trace:\n netfs_rreq_assess+0x497/0x660 [netfs]\n netfs_subreq_terminated+0x32b/0x610 [netfs]\n nfs_netfs_read_completion+0x14e/0x1a0 [nfs]\n nfs_read_completion+0x2f9/0x330 [nfs]\n rpc_free_task+0x72/0xa0 [sunrpc]\n rpc_async_release+0x46/0x70 [sunrpc]\n process_one_work+0x3bd/0x710\n worker_thread+0x89/0x610\n kthread+0x181/0x1c0\n ret_from_fork+0x29/0x50",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -29,7 +34,7 @@
],
"database_specific": {
"cwe_ids": [],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-02T22:15:49Z"
diff --git a/advisories/unreviewed/2024/03/GHSA-3f3q-cv7c-w6c7/GHSA-3f3q-cv7c-w6c7.json b/advisories/unreviewed/2024/03/GHSA-3f3q-cv7c-w6c7/GHSA-3f3q-cv7c-w6c7.json
index 8c51cc28545..fb1d1302e71 100644
--- a/advisories/unreviewed/2024/03/GHSA-3f3q-cv7c-w6c7/GHSA-3f3q-cv7c-w6c7.json
+++ b/advisories/unreviewed/2024/03/GHSA-3f3q-cv7c-w6c7/GHSA-3f3q-cv7c-w6c7.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3f3q-cv7c-w6c7",
- "modified": "2024-03-04T18:30:37Z",
+ "modified": "2025-01-16T18:30:57Z",
"published": "2024-03-04T18:30:37Z",
"aliases": [
"CVE-2021-47088"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/damon/dbgfs: protect targets destructions with kdamond_lock\n\nDAMON debugfs interface iterates current monitoring targets in\n'dbgfs_target_ids_read()' while holding the corresponding\n'kdamond_lock'. However, it also destructs the monitoring targets in\n'dbgfs_before_terminate()' without holding the lock. This can result in\na use_after_free bug. This commit avoids the race by protecting the\ndestruction with the corresponding 'kdamond_lock'.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-04T18:15:07Z"
diff --git a/advisories/unreviewed/2024/03/GHSA-3hhr-965v-pj8r/GHSA-3hhr-965v-pj8r.json b/advisories/unreviewed/2024/03/GHSA-3hhr-965v-pj8r/GHSA-3hhr-965v-pj8r.json
index b9dd0e57544..8f5182447dd 100644
--- a/advisories/unreviewed/2024/03/GHSA-3hhr-965v-pj8r/GHSA-3hhr-965v-pj8r.json
+++ b/advisories/unreviewed/2024/03/GHSA-3hhr-965v-pj8r/GHSA-3hhr-965v-pj8r.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3hhr-965v-pj8r",
- "modified": "2024-03-04T18:30:37Z",
+ "modified": "2025-01-16T18:30:57Z",
"published": "2024-03-04T18:30:37Z",
"aliases": [
"CVE-2021-47086"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nphonet/pep: refuse to enable an unbound pipe\n\nThis ioctl() implicitly assumed that the socket was already bound to\na valid local socket name, i.e. Phonet object. If the socket was not\nbound, two separate problems would occur:\n\n1) We'd send an pipe enablement request with an invalid source object.\n2) Later socket calls could BUG on the socket unexpectedly being\n connected yet not bound to a valid object.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -49,7 +54,7 @@
],
"database_specific": {
"cwe_ids": [],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-04T18:15:07Z"
diff --git a/advisories/unreviewed/2024/03/GHSA-3mhq-jqrv-fc88/GHSA-3mhq-jqrv-fc88.json b/advisories/unreviewed/2024/03/GHSA-3mhq-jqrv-fc88/GHSA-3mhq-jqrv-fc88.json
index 588a8fec26f..c3e06f524af 100644
--- a/advisories/unreviewed/2024/03/GHSA-3mhq-jqrv-fc88/GHSA-3mhq-jqrv-fc88.json
+++ b/advisories/unreviewed/2024/03/GHSA-3mhq-jqrv-fc88/GHSA-3mhq-jqrv-fc88.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3mhq-jqrv-fc88",
- "modified": "2024-03-04T18:30:37Z",
+ "modified": "2025-01-16T18:30:57Z",
"published": "2024-03-04T18:30:37Z",
"aliases": [
"CVE-2021-47087"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntee: optee: Fix incorrect page free bug\n\nPointer to the allocated pages (struct page *page) has already\nprogressed towards the end of allocation. It is incorrect to perform\n__free_pages(page, order) using this pointer as we would free any\narbitrary pages. Fix this by stop modifying the page pointer.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -32,8 +37,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-763"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-04T18:15:07Z"
diff --git a/advisories/unreviewed/2024/03/GHSA-484w-f535-whcj/GHSA-484w-f535-whcj.json b/advisories/unreviewed/2024/03/GHSA-484w-f535-whcj/GHSA-484w-f535-whcj.json
index 202fb00d8fc..02e335362bb 100644
--- a/advisories/unreviewed/2024/03/GHSA-484w-f535-whcj/GHSA-484w-f535-whcj.json
+++ b/advisories/unreviewed/2024/03/GHSA-484w-f535-whcj/GHSA-484w-f535-whcj.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-484w-f535-whcj",
- "modified": "2024-03-03T00:30:32Z",
+ "modified": "2025-01-16T18:30:57Z",
"published": "2024-03-03T00:30:32Z",
"aliases": [
"CVE-2023-52569"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: remove BUG() after failure to insert delayed dir index item\n\nInstead of calling BUG() when we fail to insert a delayed dir index item\ninto the delayed node's tree, we can just release all the resources we\nhave allocated/acquired before and return the error to the caller. This is\nfine because all existing call chains undo anything they have done before\ncalling btrfs_insert_delayed_dir_index() or BUG_ON (when creating pending\nsnapshots in the transaction commit path).\n\nSo remove the BUG() call and do proper error handling.\n\nThis relates to a syzbot report linked below, but does not fix it because\nit only prevents hitting a BUG(), it does not fix the issue where somehow\nwe attempt to use twice the same index number for different index items.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-617"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-02T22:15:49Z"
diff --git a/advisories/unreviewed/2024/03/GHSA-5c2q-g9wc-9gf6/GHSA-5c2q-g9wc-9gf6.json b/advisories/unreviewed/2024/03/GHSA-5c2q-g9wc-9gf6/GHSA-5c2q-g9wc-9gf6.json
index 65fd4e6c0ff..f8c099357fb 100644
--- a/advisories/unreviewed/2024/03/GHSA-5c2q-g9wc-9gf6/GHSA-5c2q-g9wc-9gf6.json
+++ b/advisories/unreviewed/2024/03/GHSA-5c2q-g9wc-9gf6/GHSA-5c2q-g9wc-9gf6.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5c2q-g9wc-9gf6",
- "modified": "2024-03-20T15:32:57Z",
+ "modified": "2025-01-16T18:30:57Z",
"published": "2024-03-20T15:32:57Z",
"aliases": [
"CVE-2024-1801"
diff --git a/advisories/unreviewed/2024/03/GHSA-94pf-4p5q-jc3r/GHSA-94pf-4p5q-jc3r.json b/advisories/unreviewed/2024/03/GHSA-94pf-4p5q-jc3r/GHSA-94pf-4p5q-jc3r.json
index 0d133e614fe..2841c19a211 100644
--- a/advisories/unreviewed/2024/03/GHSA-94pf-4p5q-jc3r/GHSA-94pf-4p5q-jc3r.json
+++ b/advisories/unreviewed/2024/03/GHSA-94pf-4p5q-jc3r/GHSA-94pf-4p5q-jc3r.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-94pf-4p5q-jc3r",
- "modified": "2024-03-03T00:30:32Z",
+ "modified": "2025-01-16T18:30:57Z",
"published": "2024-03-03T00:30:32Z",
"aliases": [
"CVE-2023-52559"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\niommu/vt-d: Avoid memory allocation in iommu_suspend()\n\nThe iommu_suspend() syscore suspend callback is invoked with IRQ disabled.\nAllocating memory with the GFP_KERNEL flag may re-enable IRQs during\nthe suspend callback, which can cause intermittent suspend/hibernation\nproblems with the following kernel traces:\n\nCalling iommu_suspend+0x0/0x1d0\n------------[ cut here ]------------\nWARNING: CPU: 0 PID: 15 at kernel/time/timekeeping.c:868 ktime_get+0x9b/0xb0\n...\nCPU: 0 PID: 15 Comm: rcu_preempt Tainted: G U E 6.3-intel #r1\nRIP: 0010:ktime_get+0x9b/0xb0\n...\nCall Trace:\n \n tick_sched_timer+0x22/0x90\n ? __pfx_tick_sched_timer+0x10/0x10\n __hrtimer_run_queues+0x111/0x2b0\n hrtimer_interrupt+0xfa/0x230\n __sysvec_apic_timer_interrupt+0x63/0x140\n sysvec_apic_timer_interrupt+0x7b/0xa0\n \n \n asm_sysvec_apic_timer_interrupt+0x1f/0x30\n...\n------------[ cut here ]------------\nInterrupts enabled after iommu_suspend+0x0/0x1d0\nWARNING: CPU: 0 PID: 27420 at drivers/base/syscore.c:68 syscore_suspend+0x147/0x270\nCPU: 0 PID: 27420 Comm: rtcwake Tainted: G U W E 6.3-intel #r1\nRIP: 0010:syscore_suspend+0x147/0x270\n...\nCall Trace:\n \n hibernation_snapshot+0x25b/0x670\n hibernate+0xcd/0x390\n state_store+0xcf/0xe0\n kobj_attr_store+0x13/0x30\n sysfs_kf_write+0x3f/0x50\n kernfs_fop_write_iter+0x128/0x200\n vfs_write+0x1fd/0x3c0\n ksys_write+0x6f/0xf0\n __x64_sys_write+0x1d/0x30\n do_syscall_64+0x3b/0x90\n entry_SYSCALL_64_after_hwframe+0x72/0xdc\n\nGiven that only 4 words memory is needed, avoid the memory allocation in\niommu_suspend().",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -33,7 +38,7 @@
],
"database_specific": {
"cwe_ids": [],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-02T22:15:48Z"
diff --git a/advisories/unreviewed/2024/03/GHSA-gxjr-v6fw-49mr/GHSA-gxjr-v6fw-49mr.json b/advisories/unreviewed/2024/03/GHSA-gxjr-v6fw-49mr/GHSA-gxjr-v6fw-49mr.json
index 0af7497546e..9a5761032cd 100644
--- a/advisories/unreviewed/2024/03/GHSA-gxjr-v6fw-49mr/GHSA-gxjr-v6fw-49mr.json
+++ b/advisories/unreviewed/2024/03/GHSA-gxjr-v6fw-49mr/GHSA-gxjr-v6fw-49mr.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gxjr-v6fw-49mr",
- "modified": "2024-03-20T15:32:57Z",
+ "modified": "2025-01-16T18:30:57Z",
"published": "2024-03-20T15:32:57Z",
"aliases": [
"CVE-2024-1800"
diff --git a/advisories/unreviewed/2024/03/GHSA-j56h-xwg2-4wc2/GHSA-j56h-xwg2-4wc2.json b/advisories/unreviewed/2024/03/GHSA-j56h-xwg2-4wc2/GHSA-j56h-xwg2-4wc2.json
index 149f8204d34..66529d6c21e 100644
--- a/advisories/unreviewed/2024/03/GHSA-j56h-xwg2-4wc2/GHSA-j56h-xwg2-4wc2.json
+++ b/advisories/unreviewed/2024/03/GHSA-j56h-xwg2-4wc2/GHSA-j56h-xwg2-4wc2.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j56h-xwg2-4wc2",
- "modified": "2024-03-03T00:30:32Z",
+ "modified": "2025-01-16T18:30:57Z",
"published": "2024-03-03T00:30:32Z",
"aliases": [
"CVE-2023-52562"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/slab_common: fix slab_caches list corruption after kmem_cache_destroy()\n\nAfter the commit in Fixes:, if a module that created a slab cache does not\nrelease all of its allocated objects before destroying the cache (at rmmod\ntime), we might end up releasing the kmem_cache object without removing it\nfrom the slab_caches list thus corrupting the list as kmem_cache_destroy()\nignores the return value from shutdown_cache(), which in turn never removes\nthe kmem_cache object from slabs_list in case __kmem_cache_shutdown() fails\nto release all of the cache's slabs.\n\nThis is easily observable on a kernel built with CONFIG_DEBUG_LIST=y\nas after that ill release the system will immediately trip on list_add,\nor list_del, assertions similar to the one shown below as soon as another\nkmem_cache gets created, or destroyed:\n\n [ 1041.213632] list_del corruption. next->prev should be ffff89f596fb5768, but was 52f1e5016aeee75d. (next=ffff89f595a1b268)\n [ 1041.219165] ------------[ cut here ]------------\n [ 1041.221517] kernel BUG at lib/list_debug.c:62!\n [ 1041.223452] invalid opcode: 0000 [#1] PREEMPT SMP PTI\n [ 1041.225408] CPU: 2 PID: 1852 Comm: rmmod Kdump: loaded Tainted: G B W OE 6.5.0 #15\n [ 1041.228244] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS edk2-20230524-3.fc37 05/24/2023\n [ 1041.231212] RIP: 0010:__list_del_entry_valid+0xae/0xb0\n\nAnother quick way to trigger this issue, in a kernel with CONFIG_SLUB=y,\nis to set slub_debug to poison the released objects and then just run\ncat /proc/slabinfo after removing the module that leaks slab objects,\nin which case the kernel will panic:\n\n [ 50.954843] general protection fault, probably for non-canonical address 0xa56b6b6b6b6b6b8b: 0000 [#1] PREEMPT SMP PTI\n [ 50.961545] CPU: 2 PID: 1495 Comm: cat Kdump: loaded Tainted: G B W OE 6.5.0 #15\n [ 50.966808] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS edk2-20230524-3.fc37 05/24/2023\n [ 50.972663] RIP: 0010:get_slabinfo+0x42/0xf0\n\nThis patch fixes this issue by properly checking shutdown_cache()'s\nreturn value before taking the kmem_cache_release() branch.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -29,7 +34,7 @@
],
"database_specific": {
"cwe_ids": [],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-02T22:15:48Z"
diff --git a/advisories/unreviewed/2024/03/GHSA-mjrq-f967-qfp4/GHSA-mjrq-f967-qfp4.json b/advisories/unreviewed/2024/03/GHSA-mjrq-f967-qfp4/GHSA-mjrq-f967-qfp4.json
index 4d32abd269e..18dfaf6115d 100644
--- a/advisories/unreviewed/2024/03/GHSA-mjrq-f967-qfp4/GHSA-mjrq-f967-qfp4.json
+++ b/advisories/unreviewed/2024/03/GHSA-mjrq-f967-qfp4/GHSA-mjrq-f967-qfp4.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mjrq-f967-qfp4",
- "modified": "2024-03-03T00:30:32Z",
+ "modified": "2025-01-16T18:30:57Z",
"published": "2024-03-03T00:30:32Z",
"aliases": [
"CVE-2023-52580"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/core: Fix ETH_P_1588 flow dissector\n\nWhen a PTP ethernet raw frame with a size of more than 256 bytes followed\nby a 0xff pattern is sent to __skb_flow_dissect, nhoff value calculation\nis wrong. For example: hdr->message_length takes the wrong value (0xffff)\nand it does not replicate real header length. In this case, 'nhoff' value\nwas overridden and the PTP header was badly dissected. This leads to a\nkernel crash.\n\nnet/core: flow_dissector\nnet/core flow dissector nhoff = 0x0000000e\nnet/core flow dissector hdr->message_length = 0x0000ffff\nnet/core flow dissector nhoff = 0x0001000d (u16 overflow)\n...\nskb linear: 00000000: 00 a0 c9 00 00 00 00 a0 c9 00 00 00 88\nskb frag: 00000000: f7 ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff\n\nUsing the size of the ptp_header struct will allow the corrected\ncalculation of the nhoff value.\n\nnet/core flow dissector nhoff = 0x0000000e\nnet/core flow dissector nhoff = 0x00000030 (sizeof ptp_header)\n...\nskb linear: 00000000: 00 a0 c9 00 00 00 00 a0 c9 00 00 00 88 f7 ff ff\nskb linear: 00000010: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff\nskb linear: 00000020: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff\nskb frag: 00000000: ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff\n\nKernel trace:\n[ 74.984279] ------------[ cut here ]------------\n[ 74.989471] kernel BUG at include/linux/skbuff.h:2440!\n[ 74.995237] invalid opcode: 0000 [#1] PREEMPT SMP NOPTI\n[ 75.001098] CPU: 4 PID: 0 Comm: swapper/4 Tainted: G U 5.15.85-intel-ese-standard-lts #1\n[ 75.011629] Hardware name: Intel Corporation A-Island (CPU:AlderLake)/A-Island (ID:06), BIOS SB_ADLP.01.01.00.01.03.008.D-6A9D9E73-dirty Mar 30 2023\n[ 75.026507] RIP: 0010:eth_type_trans+0xd0/0x130\n[ 75.031594] Code: 03 88 47 78 eb c7 8b 47 68 2b 47 6c 48 8b 97 c0 00 00 00 83 f8 01 7e 1b 48 85 d2 74 06 66 83 3a ff 74 09 b8 00 04 00 00 eb ab <0f> 0b b8 00 01 00 00 eb a2 48 85 ff 74 eb 48 8d 54 24 06 31 f6 b9\n[ 75.052612] RSP: 0018:ffff9948c0228de0 EFLAGS: 00010297\n[ 75.058473] RAX: 00000000000003f2 RBX: ffff8e47047dc300 RCX: 0000000000001003\n[ 75.066462] RDX: ffff8e4e8c9ea040 RSI: ffff8e4704e0a000 RDI: ffff8e47047dc300\n[ 75.074458] RBP: ffff8e4704e2acc0 R08: 00000000000003f3 R09: 0000000000000800\n[ 75.082466] R10: 000000000000000d R11: ffff9948c0228dec R12: ffff8e4715e4e010\n[ 75.090461] R13: ffff9948c0545018 R14: 0000000000000001 R15: 0000000000000800\n[ 75.098464] FS: 0000000000000000(0000) GS:ffff8e4e8fb00000(0000) knlGS:0000000000000000\n[ 75.107530] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 75.113982] CR2: 00007f5eb35934a0 CR3: 0000000150e0a002 CR4: 0000000000770ee0\n[ 75.121980] PKRU: 55555554\n[ 75.125035] Call Trace:\n[ 75.127792] \n[ 75.130063] ? eth_get_headlen+0xa4/0xc0\n[ 75.134472] igc_process_skb_fields+0xcd/0x150\n[ 75.139461] igc_poll+0xc80/0x17b0\n[ 75.143272] __napi_poll+0x27/0x170\n[ 75.147192] net_rx_action+0x234/0x280\n[ 75.151409] __do_softirq+0xef/0x2f4\n[ 75.155424] irq_exit_rcu+0xc7/0x110\n[ 75.159432] common_interrupt+0xb8/0xd0\n[ 75.163748] \n[ 75.166112] \n[ 75.168473] asm_common_interrupt+0x22/0x40\n[ 75.173175] RIP: 0010:cpuidle_enter_state+0xe2/0x350\n[ 75.178749] Code: 85 c0 0f 8f 04 02 00 00 31 ff e8 39 6c 67 ff 45 84 ff 74 12 9c 58 f6 c4 02 0f 85 50 02 00 00 31 ff e8 52 b0 6d ff fb 45 85 f6 <0f> 88 b1 00 00 00 49 63 ce 4c 2b 2c 24 48 89 c8 48 6b d1 68 48 c1\n[ 75.199757] RSP: 0018:ffff9948c013bea8 EFLAGS: 00000202\n[ 75.205614] RAX: ffff8e4e8fb00000 RBX: ffffb948bfd23900 RCX: 000000000000001f\n[ 75.213619] RDX: 0000000000000004 RSI: ffffffff94206161 RDI: ffffffff94212e20\n[ 75.221620] RBP: 0000000000000004 R08: 000000117568973a R09: 0000000000000001\n[ 75.229622] R10: 000000000000afc8 R11: ffff8e4e8fb29ce4 R12: ffffffff945ae980\n[ 75.237628] R13: 000000117568973a R14: 0000000000000004 R15: 0000000000000000\n[ 75.245635] ? \n---truncated---",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -33,7 +38,7 @@
],
"database_specific": {
"cwe_ids": [],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-02T22:15:49Z"
diff --git a/advisories/unreviewed/2024/03/GHSA-pv98-48f2-5vjr/GHSA-pv98-48f2-5vjr.json b/advisories/unreviewed/2024/03/GHSA-pv98-48f2-5vjr/GHSA-pv98-48f2-5vjr.json
index 6f73dcb66cb..1bc69d84fe1 100644
--- a/advisories/unreviewed/2024/03/GHSA-pv98-48f2-5vjr/GHSA-pv98-48f2-5vjr.json
+++ b/advisories/unreviewed/2024/03/GHSA-pv98-48f2-5vjr/GHSA-pv98-48f2-5vjr.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pv98-48f2-5vjr",
- "modified": "2024-08-14T15:31:11Z",
+ "modified": "2025-01-16T18:30:57Z",
"published": "2024-03-03T00:30:32Z",
"aliases": [
"CVE-2024-26621"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm: huge_memory: don't force huge page alignment on 32 bit\n\ncommit efa7df3e3bb5 (\"mm: align larger anonymous mappings on THP\nboundaries\") caused two issues [1] [2] reported on 32 bit system or compat\nuserspace.\n\nIt doesn't make too much sense to force huge page alignment on 32 bit\nsystem due to the constrained virtual address space.\n\n[1] https://lore.kernel.org/linux-mm/d0a136a0-4a31-46bc-adf4-2db109a61672@kernel.org/\n[2] https://lore.kernel.org/linux-mm/CAJuCfpHXLdQy1a2B6xN2d7quTYwg2OoZseYPZTRpU0eHHKD-sQ@mail.gmail.com/",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -125,7 +130,7 @@
],
"database_specific": {
"cwe_ids": [],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-02T22:15:50Z"
diff --git a/advisories/unreviewed/2024/03/GHSA-qp87-27q4-8526/GHSA-qp87-27q4-8526.json b/advisories/unreviewed/2024/03/GHSA-qp87-27q4-8526/GHSA-qp87-27q4-8526.json
index cc523e9b176..3238c493511 100644
--- a/advisories/unreviewed/2024/03/GHSA-qp87-27q4-8526/GHSA-qp87-27q4-8526.json
+++ b/advisories/unreviewed/2024/03/GHSA-qp87-27q4-8526/GHSA-qp87-27q4-8526.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qp87-27q4-8526",
- "modified": "2024-03-13T18:31:36Z",
+ "modified": "2025-01-16T18:30:57Z",
"published": "2024-03-13T18:31:36Z",
"aliases": [
"CVE-2024-2403"
],
"details": "\nImproper cleanup in temporary file handling component in Devolutions Remote Desktop Manager 2024.1.12 and\nearlier on Windows allows an attacker that compromised a user endpoint, under specific circumstances, to access sensitive information via residual files in the temporary directory.\n\n",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
+ }
+ ],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-459"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-13T18:15:07Z"
diff --git a/advisories/unreviewed/2024/03/GHSA-r296-33w8-272g/GHSA-r296-33w8-272g.json b/advisories/unreviewed/2024/03/GHSA-r296-33w8-272g/GHSA-r296-33w8-272g.json
index 10124b6a63e..cdd37201d7c 100644
--- a/advisories/unreviewed/2024/03/GHSA-r296-33w8-272g/GHSA-r296-33w8-272g.json
+++ b/advisories/unreviewed/2024/03/GHSA-r296-33w8-272g/GHSA-r296-33w8-272g.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r296-33w8-272g",
- "modified": "2024-03-04T18:30:36Z",
+ "modified": "2025-01-16T18:30:57Z",
"published": "2024-03-04T18:30:36Z",
"aliases": [
"CVE-2021-47083"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\npinctrl: mediatek: fix global-out-of-bounds issue\n\nWhen eint virtual eint number is greater than gpio number,\nit maybe produce 'desc[eint_n]' size globle-out-of-bounds issue.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -32,8 +37,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-125"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-04T18:15:07Z"
diff --git a/advisories/unreviewed/2024/03/GHSA-vhp7-fvvc-gp4m/GHSA-vhp7-fvvc-gp4m.json b/advisories/unreviewed/2024/03/GHSA-vhp7-fvvc-gp4m/GHSA-vhp7-fvvc-gp4m.json
index 8b2a3eeaf07..4f3b60df427 100644
--- a/advisories/unreviewed/2024/03/GHSA-vhp7-fvvc-gp4m/GHSA-vhp7-fvvc-gp4m.json
+++ b/advisories/unreviewed/2024/03/GHSA-vhp7-fvvc-gp4m/GHSA-vhp7-fvvc-gp4m.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vhp7-fvvc-gp4m",
- "modified": "2024-03-03T00:30:32Z",
+ "modified": "2025-01-16T18:30:57Z",
"published": "2024-03-03T00:30:32Z",
"aliases": [
"CVE-2023-52532"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: mana: Fix TX CQE error handling\n\nFor an unknown TX CQE error type (probably from a newer hardware),\nstill free the SKB, update the queue tail, etc., otherwise the\naccounting will be wrong.\n\nAlso, TX errors can be triggered by injecting corrupted packets, so\nreplace the WARN_ONCE to ratelimited error logging.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -29,7 +34,7 @@
],
"database_specific": {
"cwe_ids": [],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-03-02T22:15:48Z"
diff --git a/advisories/unreviewed/2024/03/GHSA-vjpg-wm6m-cjg7/GHSA-vjpg-wm6m-cjg7.json b/advisories/unreviewed/2024/03/GHSA-vjpg-wm6m-cjg7/GHSA-vjpg-wm6m-cjg7.json
index c49a463bfce..6b7cdc6e2ee 100644
--- a/advisories/unreviewed/2024/03/GHSA-vjpg-wm6m-cjg7/GHSA-vjpg-wm6m-cjg7.json
+++ b/advisories/unreviewed/2024/03/GHSA-vjpg-wm6m-cjg7/GHSA-vjpg-wm6m-cjg7.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vjpg-wm6m-cjg7",
- "modified": "2024-03-20T15:32:57Z",
+ "modified": "2025-01-16T18:30:57Z",
"published": "2024-03-20T15:32:57Z",
"aliases": [
"CVE-2024-1856"
diff --git a/advisories/unreviewed/2024/04/GHSA-9pw9-3858-mcgc/GHSA-9pw9-3858-mcgc.json b/advisories/unreviewed/2024/04/GHSA-9pw9-3858-mcgc/GHSA-9pw9-3858-mcgc.json
index cbdcac0fee7..3dd8333c45d 100644
--- a/advisories/unreviewed/2024/04/GHSA-9pw9-3858-mcgc/GHSA-9pw9-3858-mcgc.json
+++ b/advisories/unreviewed/2024/04/GHSA-9pw9-3858-mcgc/GHSA-9pw9-3858-mcgc.json
@@ -26,7 +26,8 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-197"
+ "CWE-197",
+ "CWE-295"
],
"severity": "HIGH",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/05/GHSA-fc6q-xmrf-7jx4/GHSA-fc6q-xmrf-7jx4.json b/advisories/unreviewed/2024/05/GHSA-fc6q-xmrf-7jx4/GHSA-fc6q-xmrf-7jx4.json
index 1db2791f977..62cd99a7ad3 100644
--- a/advisories/unreviewed/2024/05/GHSA-fc6q-xmrf-7jx4/GHSA-fc6q-xmrf-7jx4.json
+++ b/advisories/unreviewed/2024/05/GHSA-fc6q-xmrf-7jx4/GHSA-fc6q-xmrf-7jx4.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fc6q-xmrf-7jx4",
- "modified": "2024-05-15T18:30:35Z",
+ "modified": "2025-01-16T18:30:58Z",
"published": "2024-05-15T18:30:35Z",
"aliases": [
"CVE-2024-4202"
diff --git a/advisories/unreviewed/2024/05/GHSA-p7hw-w67j-562v/GHSA-p7hw-w67j-562v.json b/advisories/unreviewed/2024/05/GHSA-p7hw-w67j-562v/GHSA-p7hw-w67j-562v.json
index 9eedd7b6120..9d207e4d079 100644
--- a/advisories/unreviewed/2024/05/GHSA-p7hw-w67j-562v/GHSA-p7hw-w67j-562v.json
+++ b/advisories/unreviewed/2024/05/GHSA-p7hw-w67j-562v/GHSA-p7hw-w67j-562v.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p7hw-w67j-562v",
- "modified": "2024-05-15T18:30:35Z",
+ "modified": "2025-01-16T18:30:58Z",
"published": "2024-05-15T18:30:35Z",
"aliases": [
"CVE-2024-4200"
diff --git a/advisories/unreviewed/2024/05/GHSA-qp9g-95jm-jwfj/GHSA-qp9g-95jm-jwfj.json b/advisories/unreviewed/2024/05/GHSA-qp9g-95jm-jwfj/GHSA-qp9g-95jm-jwfj.json
index 71436d7a43a..a179654e05a 100644
--- a/advisories/unreviewed/2024/05/GHSA-qp9g-95jm-jwfj/GHSA-qp9g-95jm-jwfj.json
+++ b/advisories/unreviewed/2024/05/GHSA-qp9g-95jm-jwfj/GHSA-qp9g-95jm-jwfj.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qp9g-95jm-jwfj",
- "modified": "2024-05-20T12:30:29Z",
+ "modified": "2025-01-16T18:30:58Z",
"published": "2024-05-20T12:30:29Z",
"aliases": [
"CVE-2024-35985"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsched/eevdf: Prevent vlag from going out of bounds in reweight_eevdf()\n\nIt was possible to have pick_eevdf() return NULL, which then causes a\nNULL-deref. This turned out to be due to entity_eligible() returning\nfalsely negative because of a s64 multiplcation overflow.\n\nSpecifically, reweight_eevdf() computes the vlag without considering\nthe limit placed upon vlag as update_entity_lag() does, and then the\nscaling multiplication (remember that weight is 20bit fixed point) can\noverflow. This then leads to the new vruntime being weird which then\ncauses the above entity_eligible() to go side-ways and claim nothing\nis eligible.\n\nThus limit the range of vlag accordingly.\n\nAll this was quite rare, but fatal when it does happen.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-476"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-20T10:15:12Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-vvc7-qvmv-vpjw/GHSA-vvc7-qvmv-vpjw.json b/advisories/unreviewed/2024/05/GHSA-vvc7-qvmv-vpjw/GHSA-vvc7-qvmv-vpjw.json
index 493ef15144d..549db723551 100644
--- a/advisories/unreviewed/2024/05/GHSA-vvc7-qvmv-vpjw/GHSA-vvc7-qvmv-vpjw.json
+++ b/advisories/unreviewed/2024/05/GHSA-vvc7-qvmv-vpjw/GHSA-vvc7-qvmv-vpjw.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vvc7-qvmv-vpjw",
- "modified": "2024-05-20T12:30:29Z",
+ "modified": "2025-01-16T18:30:58Z",
"published": "2024-05-20T12:30:29Z",
"aliases": [
"CVE-2024-35981"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nvirtio_net: Do not send RSS key if it is not supported\n\nThere is a bug when setting the RSS options in virtio_net that can break\nthe whole machine, getting the kernel into an infinite loop.\n\nRunning the following command in any QEMU virtual machine with virtionet\nwill reproduce this problem:\n\n # ethtool -X eth0 hfunc toeplitz\n\nThis is how the problem happens:\n\n1) ethtool_set_rxfh() calls virtnet_set_rxfh()\n\n2) virtnet_set_rxfh() calls virtnet_commit_rss_command()\n\n3) virtnet_commit_rss_command() populates 4 entries for the rss\nscatter-gather\n\n4) Since the command above does not have a key, then the last\nscatter-gatter entry will be zeroed, since rss_key_size == 0.\nsg_buf_size = vi->rss_key_size;\n\n5) This buffer is passed to qemu, but qemu is not happy with a buffer\nwith zero length, and do the following in virtqueue_map_desc() (QEMU\nfunction):\n\n if (!sz) {\n virtio_error(vdev, \"virtio: zero sized buffers are not allowed\");\n\n6) virtio_error() (also QEMU function) set the device as broken\n\n vdev->broken = true;\n\n7) Qemu bails out, and do not repond this crazy kernel.\n\n8) The kernel is waiting for the response to come back (function\nvirtnet_send_command())\n\n9) The kernel is waiting doing the following :\n\n while (!virtqueue_get_buf(vi->cvq, &tmp) &&\n\t !virtqueue_is_broken(vi->cvq))\n\t cpu_relax();\n\n10) None of the following functions above is true, thus, the kernel\nloops here forever. Keeping in mind that virtqueue_is_broken() does\nnot look at the qemu `vdev->broken`, so, it never realizes that the\nvitio is broken at QEMU side.\n\nFix it by not sending RSS commands if the feature is not available in\nthe device.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -32,8 +37,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-835"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-20T10:15:12Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-x4qv-v3fh-v8rj/GHSA-x4qv-v3fh-v8rj.json b/advisories/unreviewed/2024/05/GHSA-x4qv-v3fh-v8rj/GHSA-x4qv-v3fh-v8rj.json
index eb379ce3d70..1177dea6042 100644
--- a/advisories/unreviewed/2024/05/GHSA-x4qv-v3fh-v8rj/GHSA-x4qv-v3fh-v8rj.json
+++ b/advisories/unreviewed/2024/05/GHSA-x4qv-v3fh-v8rj/GHSA-x4qv-v3fh-v8rj.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x4qv-v3fh-v8rj",
- "modified": "2024-06-26T00:31:43Z",
+ "modified": "2025-01-16T18:30:58Z",
"published": "2024-05-20T12:30:29Z",
"aliases": [
"CVE-2024-35983"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbounds: Use the right number of bits for power-of-two CONFIG_NR_CPUS\n\nbits_per() rounds up to the next power of two when passed a power of\ntwo. This causes crashes on some machines and configurations.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -49,7 +54,7 @@
],
"database_specific": {
"cwe_ids": [],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-20T10:15:12Z"
diff --git a/advisories/unreviewed/2024/05/GHSA-xv8c-x88j-w3qj/GHSA-xv8c-x88j-w3qj.json b/advisories/unreviewed/2024/05/GHSA-xv8c-x88j-w3qj/GHSA-xv8c-x88j-w3qj.json
index c6c34d98aa5..4a8ab4d60bb 100644
--- a/advisories/unreviewed/2024/05/GHSA-xv8c-x88j-w3qj/GHSA-xv8c-x88j-w3qj.json
+++ b/advisories/unreviewed/2024/05/GHSA-xv8c-x88j-w3qj/GHSA-xv8c-x88j-w3qj.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xv8c-x88j-w3qj",
- "modified": "2024-05-20T12:30:29Z",
+ "modified": "2025-01-16T18:30:58Z",
"published": "2024-05-20T12:30:29Z",
"aliases": [
"CVE-2024-35980"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\narm64: tlb: Fix TLBI RANGE operand\n\nKVM/arm64 relies on TLBI RANGE feature to flush TLBs when the dirty\npages are collected by VMM and the page table entries become write\nprotected during live migration. Unfortunately, the operand passed\nto the TLBI RANGE instruction isn't correctly sorted out due to the\ncommit 117940aa6e5f (\"KVM: arm64: Define kvm_tlb_flush_vmid_range()\").\nIt leads to crash on the destination VM after live migration because\nTLBs aren't flushed completely and some of the dirty pages are missed.\n\nFor example, I have a VM where 8GB memory is assigned, starting from\n0x40000000 (1GB). Note that the host has 4KB as the base page size.\nIn the middile of migration, kvm_tlb_flush_vmid_range() is executed\nto flush TLBs. It passes MAX_TLBI_RANGE_PAGES as the argument to\n__kvm_tlb_flush_vmid_range() and __flush_s2_tlb_range_op(). SCALE#3\nand NUM#31, corresponding to MAX_TLBI_RANGE_PAGES, isn't supported\nby __TLBI_RANGE_NUM(). In this specific case, -1 has been returned\nfrom __TLBI_RANGE_NUM() for SCALE#3/2/1/0 and rejected by the loop\nin the __flush_tlb_range_op() until the variable @scale underflows\nand becomes -9, 0xffff708000040000 is set as the operand. The operand\nis wrong since it's sorted out by __TLBI_VADDR_RANGE() according to\ninvalid @scale and @num.\n\nFix it by extending __TLBI_RANGE_NUM() to support the combination of\nSCALE#3 and NUM#31. With the changes, [-1 31] instead of [-1 30] can\nbe returned from the macro, meaning the TLBs for 0x200000 pages in the\nabove example can be flushed in one shoot with SCALE#3 and NUM#31. The\nmacro TLBI_RANGE_MASK is dropped since no one uses it any more. The\ncomments are also adjusted accordingly.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-191"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-20T10:15:12Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-562v-pvgc-xrg8/GHSA-562v-pvgc-xrg8.json b/advisories/unreviewed/2024/12/GHSA-562v-pvgc-xrg8/GHSA-562v-pvgc-xrg8.json
index 338d0892eb0..66af02eb057 100644
--- a/advisories/unreviewed/2024/12/GHSA-562v-pvgc-xrg8/GHSA-562v-pvgc-xrg8.json
+++ b/advisories/unreviewed/2024/12/GHSA-562v-pvgc-xrg8/GHSA-562v-pvgc-xrg8.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-562v-pvgc-xrg8",
- "modified": "2024-12-27T15:31:53Z",
+ "modified": "2025-01-16T18:30:58Z",
"published": "2024-12-27T15:31:53Z",
"aliases": [
"CVE-2024-56551"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: fix usage slab after free\n\n[ +0.000021] BUG: KASAN: slab-use-after-free in drm_sched_entity_flush+0x6cb/0x7a0 [gpu_sched]\n[ +0.000027] Read of size 8 at addr ffff8881b8605f88 by task amd_pci_unplug/2147\n\n[ +0.000023] CPU: 6 PID: 2147 Comm: amd_pci_unplug Not tainted 6.10.0+ #1\n[ +0.000016] Hardware name: ASUS System Product Name/ROG STRIX B550-F GAMING (WI-FI), BIOS 1401 12/03/2020\n[ +0.000016] Call Trace:\n[ +0.000008] \n[ +0.000009] dump_stack_lvl+0x76/0xa0\n[ +0.000017] print_report+0xce/0x5f0\n[ +0.000017] ? drm_sched_entity_flush+0x6cb/0x7a0 [gpu_sched]\n[ +0.000019] ? srso_return_thunk+0x5/0x5f\n[ +0.000015] ? kasan_complete_mode_report_info+0x72/0x200\n[ +0.000016] ? drm_sched_entity_flush+0x6cb/0x7a0 [gpu_sched]\n[ +0.000019] kasan_report+0xbe/0x110\n[ +0.000015] ? drm_sched_entity_flush+0x6cb/0x7a0 [gpu_sched]\n[ +0.000023] __asan_report_load8_noabort+0x14/0x30\n[ +0.000014] drm_sched_entity_flush+0x6cb/0x7a0 [gpu_sched]\n[ +0.000020] ? srso_return_thunk+0x5/0x5f\n[ +0.000013] ? __kasan_check_write+0x14/0x30\n[ +0.000016] ? __pfx_drm_sched_entity_flush+0x10/0x10 [gpu_sched]\n[ +0.000020] ? srso_return_thunk+0x5/0x5f\n[ +0.000013] ? __kasan_check_write+0x14/0x30\n[ +0.000013] ? srso_return_thunk+0x5/0x5f\n[ +0.000013] ? enable_work+0x124/0x220\n[ +0.000015] ? __pfx_enable_work+0x10/0x10\n[ +0.000013] ? srso_return_thunk+0x5/0x5f\n[ +0.000014] ? free_large_kmalloc+0x85/0xf0\n[ +0.000016] drm_sched_entity_destroy+0x18/0x30 [gpu_sched]\n[ +0.000020] amdgpu_vce_sw_fini+0x55/0x170 [amdgpu]\n[ +0.000735] ? __kasan_check_read+0x11/0x20\n[ +0.000016] vce_v4_0_sw_fini+0x80/0x110 [amdgpu]\n[ +0.000726] amdgpu_device_fini_sw+0x331/0xfc0 [amdgpu]\n[ +0.000679] ? mutex_unlock+0x80/0xe0\n[ +0.000017] ? __pfx_amdgpu_device_fini_sw+0x10/0x10 [amdgpu]\n[ +0.000662] ? srso_return_thunk+0x5/0x5f\n[ +0.000014] ? __kasan_check_write+0x14/0x30\n[ +0.000013] ? srso_return_thunk+0x5/0x5f\n[ +0.000013] ? mutex_unlock+0x80/0xe0\n[ +0.000016] amdgpu_driver_release_kms+0x16/0x80 [amdgpu]\n[ +0.000663] drm_minor_release+0xc9/0x140 [drm]\n[ +0.000081] drm_release+0x1fd/0x390 [drm]\n[ +0.000082] __fput+0x36c/0xad0\n[ +0.000018] __fput_sync+0x3c/0x50\n[ +0.000014] __x64_sys_close+0x7d/0xe0\n[ +0.000014] x64_sys_call+0x1bc6/0x2680\n[ +0.000014] do_syscall_64+0x70/0x130\n[ +0.000014] ? srso_return_thunk+0x5/0x5f\n[ +0.000014] ? irqentry_exit_to_user_mode+0x60/0x190\n[ +0.000015] ? srso_return_thunk+0x5/0x5f\n[ +0.000014] ? irqentry_exit+0x43/0x50\n[ +0.000012] ? srso_return_thunk+0x5/0x5f\n[ +0.000013] ? exc_page_fault+0x7c/0x110\n[ +0.000015] entry_SYSCALL_64_after_hwframe+0x76/0x7e\n[ +0.000014] RIP: 0033:0x7ffff7b14f67\n[ +0.000013] Code: ff e8 0d 16 02 00 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 00 f3 0f 1e fa 64 8b 04 25 18 00 00 00 85 c0 75 10 b8 03 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 41 c3 48 83 ec 18 89 7c 24 0c e8 73 ba f7 ff\n[ +0.000026] RSP: 002b:00007fffffffe378 EFLAGS: 00000246 ORIG_RAX: 0000000000000003\n[ +0.000019] RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007ffff7b14f67\n[ +0.000014] RDX: 0000000000000000 RSI: 00007ffff7f6f47a RDI: 0000000000000003\n[ +0.000014] RBP: 00007fffffffe3a0 R08: 0000555555569890 R09: 0000000000000000\n[ +0.000014] R10: 0000000000000000 R11: 0000000000000246 R12: 00007fffffffe5c8\n[ +0.000013] R13: 00005555555552a9 R14: 0000555555557d48 R15: 00007ffff7ffd040\n[ +0.000020] \n\n[ +0.000016] Allocated by task 383 on cpu 7 at 26.880319s:\n[ +0.000014] kasan_save_stack+0x28/0x60\n[ +0.000008] kasan_save_track+0x18/0x70\n[ +0.000007] kasan_save_alloc_info+0x38/0x60\n[ +0.000007] __kasan_kmalloc+0xc1/0xd0\n[ +0.000007] kmalloc_trace_noprof+0x180/0x380\n[ +0.000007] drm_sched_init+0x411/0xec0 [gpu_sched]\n[ +0.000012] amdgpu_device_init+0x695f/0xa610 [amdgpu]\n[ +0.000658] amdgpu_driver_load_kms+0x1a/0x120 [amdgpu]\n[ +0.000662] amdgpu_pci_p\n---truncated---",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-27T15:15:13Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-56q7-cvh5-mq2r/GHSA-56q7-cvh5-mq2r.json b/advisories/unreviewed/2024/12/GHSA-56q7-cvh5-mq2r/GHSA-56q7-cvh5-mq2r.json
index 72853ccaa8d..24cf4ae23ce 100644
--- a/advisories/unreviewed/2024/12/GHSA-56q7-cvh5-mq2r/GHSA-56q7-cvh5-mq2r.json
+++ b/advisories/unreviewed/2024/12/GHSA-56q7-cvh5-mq2r/GHSA-56q7-cvh5-mq2r.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-56q7-cvh5-mq2r",
- "modified": "2024-12-27T15:31:54Z",
+ "modified": "2025-01-16T18:30:58Z",
"published": "2024-12-27T15:31:54Z",
"aliases": [
"CVE-2024-56595"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\njfs: add a check to prevent array-index-out-of-bounds in dbAdjTree\n\nWhen the value of lp is 0 at the beginning of the for loop, it will\nbecome negative in the next assignment and we should bail out.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -44,8 +49,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-129"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-27T15:15:18Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-6gmm-x3pr-vhmf/GHSA-6gmm-x3pr-vhmf.json b/advisories/unreviewed/2024/12/GHSA-6gmm-x3pr-vhmf/GHSA-6gmm-x3pr-vhmf.json
index d3cad61ca8a..55ab1535a9c 100644
--- a/advisories/unreviewed/2024/12/GHSA-6gmm-x3pr-vhmf/GHSA-6gmm-x3pr-vhmf.json
+++ b/advisories/unreviewed/2024/12/GHSA-6gmm-x3pr-vhmf/GHSA-6gmm-x3pr-vhmf.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6gmm-x3pr-vhmf",
- "modified": "2024-12-27T15:31:50Z",
+ "modified": "2025-01-16T18:30:58Z",
"published": "2024-12-27T15:31:50Z",
"aliases": [
"CVE-2024-53166"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nblock, bfq: fix bfqq uaf in bfq_limit_depth()\n\nSet new allocated bfqq to bic or remove freed bfqq from bic are both\nprotected by bfqd->lock, however bfq_limit_depth() is deferencing bfqq\nfrom bic without the lock, this can lead to UAF if the io_context is\nshared by multiple tasks.\n\nFor example, test bfq with io_uring can trigger following UAF in v6.6:\n\n==================================================================\nBUG: KASAN: slab-use-after-free in bfqq_group+0x15/0x50\n\nCall Trace:\n \n dump_stack_lvl+0x47/0x80\n print_address_description.constprop.0+0x66/0x300\n print_report+0x3e/0x70\n kasan_report+0xb4/0xf0\n bfqq_group+0x15/0x50\n bfqq_request_over_limit+0x130/0x9a0\n bfq_limit_depth+0x1b5/0x480\n __blk_mq_alloc_requests+0x2b5/0xa00\n blk_mq_get_new_requests+0x11d/0x1d0\n blk_mq_submit_bio+0x286/0xb00\n submit_bio_noacct_nocheck+0x331/0x400\n __block_write_full_folio+0x3d0/0x640\n writepage_cb+0x3b/0xc0\n write_cache_pages+0x254/0x6c0\n write_cache_pages+0x254/0x6c0\n do_writepages+0x192/0x310\n filemap_fdatawrite_wbc+0x95/0xc0\n __filemap_fdatawrite_range+0x99/0xd0\n filemap_write_and_wait_range.part.0+0x4d/0xa0\n blkdev_read_iter+0xef/0x1e0\n io_read+0x1b6/0x8a0\n io_issue_sqe+0x87/0x300\n io_wq_submit_work+0xeb/0x390\n io_worker_handle_work+0x24d/0x550\n io_wq_worker+0x27f/0x6c0\n ret_from_fork_asm+0x1b/0x30\n \n\nAllocated by task 808602:\n kasan_save_stack+0x1e/0x40\n kasan_set_track+0x21/0x30\n __kasan_slab_alloc+0x83/0x90\n kmem_cache_alloc_node+0x1b1/0x6d0\n bfq_get_queue+0x138/0xfa0\n bfq_get_bfqq_handle_split+0xe3/0x2c0\n bfq_init_rq+0x196/0xbb0\n bfq_insert_request.isra.0+0xb5/0x480\n bfq_insert_requests+0x156/0x180\n blk_mq_insert_request+0x15d/0x440\n blk_mq_submit_bio+0x8a4/0xb00\n submit_bio_noacct_nocheck+0x331/0x400\n __blkdev_direct_IO_async+0x2dd/0x330\n blkdev_write_iter+0x39a/0x450\n io_write+0x22a/0x840\n io_issue_sqe+0x87/0x300\n io_wq_submit_work+0xeb/0x390\n io_worker_handle_work+0x24d/0x550\n io_wq_worker+0x27f/0x6c0\n ret_from_fork+0x2d/0x50\n ret_from_fork_asm+0x1b/0x30\n\nFreed by task 808589:\n kasan_save_stack+0x1e/0x40\n kasan_set_track+0x21/0x30\n kasan_save_free_info+0x27/0x40\n __kasan_slab_free+0x126/0x1b0\n kmem_cache_free+0x10c/0x750\n bfq_put_queue+0x2dd/0x770\n __bfq_insert_request.isra.0+0x155/0x7a0\n bfq_insert_request.isra.0+0x122/0x480\n bfq_insert_requests+0x156/0x180\n blk_mq_dispatch_plug_list+0x528/0x7e0\n blk_mq_flush_plug_list.part.0+0xe5/0x590\n __blk_flush_plug+0x3b/0x90\n blk_finish_plug+0x40/0x60\n do_writepages+0x19d/0x310\n filemap_fdatawrite_wbc+0x95/0xc0\n __filemap_fdatawrite_range+0x99/0xd0\n filemap_write_and_wait_range.part.0+0x4d/0xa0\n blkdev_read_iter+0xef/0x1e0\n io_read+0x1b6/0x8a0\n io_issue_sqe+0x87/0x300\n io_wq_submit_work+0xeb/0x390\n io_worker_handle_work+0x24d/0x550\n io_wq_worker+0x27f/0x6c0\n ret_from_fork+0x2d/0x50\n ret_from_fork_asm+0x1b/0x30\n\nFix the problem by protecting bic_to_bfqq() with bfqd->lock.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -32,8 +37,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-27T14:15:23Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-7822-7h76-h235/GHSA-7822-7h76-h235.json b/advisories/unreviewed/2024/12/GHSA-7822-7h76-h235/GHSA-7822-7h76-h235.json
index d442a8de511..c191818d562 100644
--- a/advisories/unreviewed/2024/12/GHSA-7822-7h76-h235/GHSA-7822-7h76-h235.json
+++ b/advisories/unreviewed/2024/12/GHSA-7822-7h76-h235/GHSA-7822-7h76-h235.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7822-7h76-h235",
- "modified": "2025-01-09T18:32:13Z",
+ "modified": "2025-01-16T18:30:59Z",
"published": "2024-12-27T15:31:55Z",
"aliases": [
"CVE-2024-56627"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix Out-of-Bounds Read in ksmbd_vfs_stream_read\n\nAn offset from client could be a negative value, It could lead\nto an out-of-bounds read from the stream_buf.\nNote that this issue is coming when setting\n'vfs objects = streams_xattr parameter' in ksmbd.conf.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -36,8 +41,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-125"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-27T15:15:22Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-7w8v-gc2j-m9c7/GHSA-7w8v-gc2j-m9c7.json b/advisories/unreviewed/2024/12/GHSA-7w8v-gc2j-m9c7/GHSA-7w8v-gc2j-m9c7.json
index 5e239f2d668..0c6fae2f1c4 100644
--- a/advisories/unreviewed/2024/12/GHSA-7w8v-gc2j-m9c7/GHSA-7w8v-gc2j-m9c7.json
+++ b/advisories/unreviewed/2024/12/GHSA-7w8v-gc2j-m9c7/GHSA-7w8v-gc2j-m9c7.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7w8v-gc2j-m9c7",
- "modified": "2024-12-27T15:31:54Z",
+ "modified": "2025-01-16T18:30:58Z",
"published": "2024-12-27T15:31:54Z",
"aliases": [
"CVE-2024-56598"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\njfs: array-index-out-of-bounds fix in dtReadFirst\n\nThe value of stbl can be sometimes out of bounds due\nto a bad filesystem. Added a check with appopriate return\nof error code in that case.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -44,8 +49,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-129"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-27T15:15:19Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-8fcf-qpcm-frcf/GHSA-8fcf-qpcm-frcf.json b/advisories/unreviewed/2024/12/GHSA-8fcf-qpcm-frcf/GHSA-8fcf-qpcm-frcf.json
index ecc6d37b17c..73011c11ba5 100644
--- a/advisories/unreviewed/2024/12/GHSA-8fcf-qpcm-frcf/GHSA-8fcf-qpcm-frcf.json
+++ b/advisories/unreviewed/2024/12/GHSA-8fcf-qpcm-frcf/GHSA-8fcf-qpcm-frcf.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8fcf-qpcm-frcf",
- "modified": "2024-12-27T15:31:55Z",
+ "modified": "2025-01-16T18:30:59Z",
"published": "2024-12-27T15:31:55Z",
"aliases": [
"CVE-2024-56618"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\npmdomain: imx: gpcv2: Adjust delay after power up handshake\n\nThe udelay(5) is not enough, sometimes below kernel panic\nstill be triggered:\n\n[ 4.012973] Kernel panic - not syncing: Asynchronous SError Interrupt\n[ 4.012976] CPU: 2 UID: 0 PID: 186 Comm: (udev-worker) Not tainted 6.12.0-rc2-0.0.0-devel-00004-g8b1b79e88956 #1\n[ 4.012982] Hardware name: Toradex Verdin iMX8M Plus WB on Dahlia Board (DT)\n[ 4.012985] Call trace:\n[...]\n[ 4.013029] arm64_serror_panic+0x64/0x70\n[ 4.013034] do_serror+0x3c/0x70\n[ 4.013039] el1h_64_error_handler+0x30/0x54\n[ 4.013046] el1h_64_error+0x64/0x68\n[ 4.013050] clk_imx8mp_audiomix_runtime_resume+0x38/0x48\n[ 4.013059] __genpd_runtime_resume+0x30/0x80\n[ 4.013066] genpd_runtime_resume+0x114/0x29c\n[ 4.013073] __rpm_callback+0x48/0x1e0\n[ 4.013079] rpm_callback+0x68/0x80\n[ 4.013084] rpm_resume+0x3bc/0x6a0\n[ 4.013089] __pm_runtime_resume+0x50/0x9c\n[ 4.013095] pm_runtime_get_suppliers+0x60/0x8c\n[ 4.013101] __driver_probe_device+0x4c/0x14c\n[ 4.013108] driver_probe_device+0x3c/0x120\n[ 4.013114] __driver_attach+0xc4/0x200\n[ 4.013119] bus_for_each_dev+0x7c/0xe0\n[ 4.013125] driver_attach+0x24/0x30\n[ 4.013130] bus_add_driver+0x110/0x240\n[ 4.013135] driver_register+0x68/0x124\n[ 4.013142] __platform_driver_register+0x24/0x30\n[ 4.013149] sdma_driver_init+0x20/0x1000 [imx_sdma]\n[ 4.013163] do_one_initcall+0x60/0x1e0\n[ 4.013168] do_init_module+0x5c/0x21c\n[ 4.013175] load_module+0x1a98/0x205c\n[ 4.013181] init_module_from_file+0x88/0xd4\n[ 4.013187] __arm64_sys_finit_module+0x258/0x350\n[ 4.013194] invoke_syscall.constprop.0+0x50/0xe0\n[ 4.013202] do_el0_svc+0xa8/0xe0\n[ 4.013208] el0_svc+0x3c/0x140\n[ 4.013215] el0t_64_sync_handler+0x120/0x12c\n[ 4.013222] el0t_64_sync+0x190/0x194\n[ 4.013228] SMP: stopping secondary CPUs\n\nThe correct way is to wait handshake, but it needs BUS clock of\nBLK-CTL be enabled, which is in separate driver. So delay is the\nonly option here. The udelay(10) is a data got by experiment.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -25,7 +30,7 @@
],
"database_specific": {
"cwe_ids": [],
- "severity": null,
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-27T15:15:21Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-cpf2-vjq3-4h5q/GHSA-cpf2-vjq3-4h5q.json b/advisories/unreviewed/2024/12/GHSA-cpf2-vjq3-4h5q/GHSA-cpf2-vjq3-4h5q.json
index aa06fb2edbc..28f31410846 100644
--- a/advisories/unreviewed/2024/12/GHSA-cpf2-vjq3-4h5q/GHSA-cpf2-vjq3-4h5q.json
+++ b/advisories/unreviewed/2024/12/GHSA-cpf2-vjq3-4h5q/GHSA-cpf2-vjq3-4h5q.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cpf2-vjq3-4h5q",
- "modified": "2024-12-27T15:31:51Z",
+ "modified": "2025-01-16T18:30:58Z",
"published": "2024-12-27T15:31:51Z",
"aliases": [
"CVE-2024-53187"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nio_uring: check for overflows in io_pin_pages\n\nWARNING: CPU: 0 PID: 5834 at io_uring/memmap.c:144 io_pin_pages+0x149/0x180 io_uring/memmap.c:144\nCPU: 0 UID: 0 PID: 5834 Comm: syz-executor825 Not tainted 6.12.0-next-20241118-syzkaller #0\nCall Trace:\n \n __io_uaddr_map+0xfb/0x2d0 io_uring/memmap.c:183\n io_rings_map io_uring/io_uring.c:2611 [inline]\n io_allocate_scq_urings+0x1c0/0x650 io_uring/io_uring.c:3470\n io_uring_create+0x5b5/0xc00 io_uring/io_uring.c:3692\n io_uring_setup io_uring/io_uring.c:3781 [inline]\n ...\n \n\nio_pin_pages()'s uaddr parameter came directly from the user and can be\ngarbage. Don't just add size to it as it can overflow.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-190"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-27T14:15:26Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-cwp6-92gh-h7h8/GHSA-cwp6-92gh-h7h8.json b/advisories/unreviewed/2024/12/GHSA-cwp6-92gh-h7h8/GHSA-cwp6-92gh-h7h8.json
index 4e440e2de60..28acbf67168 100644
--- a/advisories/unreviewed/2024/12/GHSA-cwp6-92gh-h7h8/GHSA-cwp6-92gh-h7h8.json
+++ b/advisories/unreviewed/2024/12/GHSA-cwp6-92gh-h7h8/GHSA-cwp6-92gh-h7h8.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cwp6-92gh-h7h8",
- "modified": "2024-12-27T15:31:52Z",
+ "modified": "2025-01-16T18:30:58Z",
"published": "2024-12-27T15:31:52Z",
"aliases": [
"CVE-2024-53228"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nriscv: kvm: Fix out-of-bounds array access\n\nIn kvm_riscv_vcpu_sbi_init() the entry->ext_idx can contain an\nout-of-bound index. This is used as a special marker for the base\nextensions, that cannot be disabled. However, when traversing the\nextensions, that special marker is not checked prior indexing the\narray.\n\nAdd an out-of-bounds check to the function.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-129"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-27T14:15:31Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-fghf-x6v5-95fg/GHSA-fghf-x6v5-95fg.json b/advisories/unreviewed/2024/12/GHSA-fghf-x6v5-95fg/GHSA-fghf-x6v5-95fg.json
index 7e90284de20..9d243fbdff2 100644
--- a/advisories/unreviewed/2024/12/GHSA-fghf-x6v5-95fg/GHSA-fghf-x6v5-95fg.json
+++ b/advisories/unreviewed/2024/12/GHSA-fghf-x6v5-95fg/GHSA-fghf-x6v5-95fg.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fghf-x6v5-95fg",
- "modified": "2024-12-27T15:31:51Z",
+ "modified": "2025-01-16T18:30:58Z",
"published": "2024-12-27T15:31:51Z",
"aliases": [
"CVE-2024-53208"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: MGMT: Fix slab-use-after-free Read in set_powered_sync\n\nThis fixes the following crash:\n\n==================================================================\nBUG: KASAN: slab-use-after-free in set_powered_sync+0x3a/0xc0 net/bluetooth/mgmt.c:1353\nRead of size 8 at addr ffff888029b4dd18 by task kworker/u9:0/54\n\nCPU: 1 UID: 0 PID: 54 Comm: kworker/u9:0 Not tainted 6.11.0-rc6-syzkaller-01155-gf723224742fc #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 08/06/2024\nWorkqueue: hci0 hci_cmd_sync_work\nCall Trace:\n \n __dump_stack lib/dump_stack.c:93 [inline]\n dump_stack_lvl+0x241/0x360 lib/dump_stack.c:119\n print_address_description mm/kasan/report.c:377 [inline]\n print_report+0x169/0x550 mm/kasan/report.c:488\nq kasan_report+0x143/0x180 mm/kasan/report.c:601\n set_powered_sync+0x3a/0xc0 net/bluetooth/mgmt.c:1353\n hci_cmd_sync_work+0x22b/0x400 net/bluetooth/hci_sync.c:328\n process_one_work kernel/workqueue.c:3231 [inline]\n process_scheduled_works+0xa2c/0x1830 kernel/workqueue.c:3312\n worker_thread+0x86d/0xd10 kernel/workqueue.c:3389\n kthread+0x2f0/0x390 kernel/kthread.c:389\n ret_from_fork+0x4b/0x80 arch/x86/kernel/process.c:147\n ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:244\n \n\nAllocated by task 5247:\n kasan_save_stack mm/kasan/common.c:47 [inline]\n kasan_save_track+0x3f/0x80 mm/kasan/common.c:68\n poison_kmalloc_redzone mm/kasan/common.c:370 [inline]\n __kasan_kmalloc+0x98/0xb0 mm/kasan/common.c:387\n kasan_kmalloc include/linux/kasan.h:211 [inline]\n __kmalloc_cache_noprof+0x19c/0x2c0 mm/slub.c:4193\n kmalloc_noprof include/linux/slab.h:681 [inline]\n kzalloc_noprof include/linux/slab.h:807 [inline]\n mgmt_pending_new+0x65/0x250 net/bluetooth/mgmt_util.c:269\n mgmt_pending_add+0x36/0x120 net/bluetooth/mgmt_util.c:296\n set_powered+0x3cd/0x5e0 net/bluetooth/mgmt.c:1394\n hci_mgmt_cmd+0xc47/0x11d0 net/bluetooth/hci_sock.c:1712\n hci_sock_sendmsg+0x7b8/0x11c0 net/bluetooth/hci_sock.c:1832\n sock_sendmsg_nosec net/socket.c:730 [inline]\n __sock_sendmsg+0x221/0x270 net/socket.c:745\n sock_write_iter+0x2dd/0x400 net/socket.c:1160\n new_sync_write fs/read_write.c:497 [inline]\n vfs_write+0xa72/0xc90 fs/read_write.c:590\n ksys_write+0x1a0/0x2c0 fs/read_write.c:643\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nFreed by task 5246:\n kasan_save_stack mm/kasan/common.c:47 [inline]\n kasan_save_track+0x3f/0x80 mm/kasan/common.c:68\n kasan_save_free_info+0x40/0x50 mm/kasan/generic.c:579\n poison_slab_object+0xe0/0x150 mm/kasan/common.c:240\n __kasan_slab_free+0x37/0x60 mm/kasan/common.c:256\n kasan_slab_free include/linux/kasan.h:184 [inline]\n slab_free_hook mm/slub.c:2256 [inline]\n slab_free mm/slub.c:4477 [inline]\n kfree+0x149/0x360 mm/slub.c:4598\n settings_rsp+0x2bc/0x390 net/bluetooth/mgmt.c:1443\n mgmt_pending_foreach+0xd1/0x130 net/bluetooth/mgmt_util.c:259\n __mgmt_power_off+0x112/0x420 net/bluetooth/mgmt.c:9455\n hci_dev_close_sync+0x665/0x11a0 net/bluetooth/hci_sync.c:5191\n hci_dev_do_close net/bluetooth/hci_core.c:483 [inline]\n hci_dev_close+0x112/0x210 net/bluetooth/hci_core.c:508\n sock_do_ioctl+0x158/0x460 net/socket.c:1222\n sock_ioctl+0x629/0x8e0 net/socket.c:1341\n vfs_ioctl fs/ioctl.c:51 [inline]\n __do_sys_ioctl fs/ioctl.c:907 [inline]\n __se_sys_ioctl+0xfc/0x170 fs/ioctl.c:893\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83gv\n entry_SYSCALL_64_after_hwframe+0x77/0x7f",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -36,8 +41,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-27T14:15:28Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-g4vc-rr66-6355/GHSA-g4vc-rr66-6355.json b/advisories/unreviewed/2024/12/GHSA-g4vc-rr66-6355/GHSA-g4vc-rr66-6355.json
index 9f21d82d16a..e94e28474c7 100644
--- a/advisories/unreviewed/2024/12/GHSA-g4vc-rr66-6355/GHSA-g4vc-rr66-6355.json
+++ b/advisories/unreviewed/2024/12/GHSA-g4vc-rr66-6355/GHSA-g4vc-rr66-6355.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g4vc-rr66-6355",
- "modified": "2025-01-09T18:32:13Z",
+ "modified": "2025-01-16T18:30:59Z",
"published": "2024-12-27T15:31:55Z",
"aliases": [
"CVE-2024-56626"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix Out-of-Bounds Write in ksmbd_vfs_stream_write\n\nAn offset from client could be a negative value, It could allows\nto write data outside the bounds of the allocated buffer.\nNote that this issue is coming when setting\n'vfs objects = streams_xattr parameter' in ksmbd.conf.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -36,8 +41,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-787"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-27T15:15:22Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-hc7h-3x34-frvv/GHSA-hc7h-3x34-frvv.json b/advisories/unreviewed/2024/12/GHSA-hc7h-3x34-frvv/GHSA-hc7h-3x34-frvv.json
index 578bc21fe3e..d392f50b32c 100644
--- a/advisories/unreviewed/2024/12/GHSA-hc7h-3x34-frvv/GHSA-hc7h-3x34-frvv.json
+++ b/advisories/unreviewed/2024/12/GHSA-hc7h-3x34-frvv/GHSA-hc7h-3x34-frvv.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hc7h-3x34-frvv",
- "modified": "2024-12-28T12:30:47Z",
+ "modified": "2025-01-16T18:30:59Z",
"published": "2024-12-28T12:30:47Z",
"aliases": [
"CVE-2024-56692"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to do sanity check on node blkaddr in truncate_node()\n\nsyzbot reports a f2fs bug as below:\n\n------------[ cut here ]------------\nkernel BUG at fs/f2fs/segment.c:2534!\nRIP: 0010:f2fs_invalidate_blocks+0x35f/0x370 fs/f2fs/segment.c:2534\nCall Trace:\n truncate_node+0x1ae/0x8c0 fs/f2fs/node.c:909\n f2fs_remove_inode_page+0x5c2/0x870 fs/f2fs/node.c:1288\n f2fs_evict_inode+0x879/0x15c0 fs/f2fs/inode.c:856\n evict+0x4e8/0x9b0 fs/inode.c:723\n f2fs_handle_failed_inode+0x271/0x2e0 fs/f2fs/inode.c:986\n f2fs_create+0x357/0x530 fs/f2fs/namei.c:394\n lookup_open fs/namei.c:3595 [inline]\n open_last_lookups fs/namei.c:3694 [inline]\n path_openat+0x1c03/0x3590 fs/namei.c:3930\n do_filp_open+0x235/0x490 fs/namei.c:3960\n do_sys_openat2+0x13e/0x1d0 fs/open.c:1415\n do_sys_open fs/open.c:1430 [inline]\n __do_sys_openat fs/open.c:1446 [inline]\n __se_sys_openat fs/open.c:1441 [inline]\n __x64_sys_openat+0x247/0x2a0 fs/open.c:1441\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\nRIP: 0010:f2fs_invalidate_blocks+0x35f/0x370 fs/f2fs/segment.c:2534\n\nThe root cause is: on a fuzzed image, blkaddr in nat entry may be\ncorrupted, then it will cause system panic when using it in\nf2fs_invalidate_blocks(), to avoid this, let's add sanity check on\nnat blkaddr in truncate_node().",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -32,8 +37,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-754"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-28T10:15:14Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-m75c-j939-x6c2/GHSA-m75c-j939-x6c2.json b/advisories/unreviewed/2024/12/GHSA-m75c-j939-x6c2/GHSA-m75c-j939-x6c2.json
index a19b57128a6..e374b5a2b34 100644
--- a/advisories/unreviewed/2024/12/GHSA-m75c-j939-x6c2/GHSA-m75c-j939-x6c2.json
+++ b/advisories/unreviewed/2024/12/GHSA-m75c-j939-x6c2/GHSA-m75c-j939-x6c2.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m75c-j939-x6c2",
- "modified": "2024-12-27T15:31:51Z",
+ "modified": "2025-01-16T18:30:58Z",
"published": "2024-12-27T15:31:50Z",
"aliases": [
"CVE-2024-53180"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: pcm: Add sanity NULL check for the default mmap fault handler\n\nA driver might allow the mmap access before initializing its\nruntime->dma_area properly. Add a proper NULL check before passing to\nvirt_to_page() for avoiding a panic.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -40,8 +45,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-476"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-27T14:15:25Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-p6p2-g83c-783v/GHSA-p6p2-g83c-783v.json b/advisories/unreviewed/2024/12/GHSA-p6p2-g83c-783v/GHSA-p6p2-g83c-783v.json
index d12eb907264..72df461b04f 100644
--- a/advisories/unreviewed/2024/12/GHSA-p6p2-g83c-783v/GHSA-p6p2-g83c-783v.json
+++ b/advisories/unreviewed/2024/12/GHSA-p6p2-g83c-783v/GHSA-p6p2-g83c-783v.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p6p2-g83c-783v",
- "modified": "2024-12-27T15:31:54Z",
+ "modified": "2025-01-16T18:30:58Z",
"published": "2024-12-27T15:31:54Z",
"aliases": [
"CVE-2024-56596"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\njfs: fix array-index-out-of-bounds in jfs_readdir\n\nThe stbl might contain some invalid values. Added a check to\nreturn error code in that case.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -44,8 +49,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-129"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-27T15:15:18Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-pq66-h8qj-7xg9/GHSA-pq66-h8qj-7xg9.json b/advisories/unreviewed/2024/12/GHSA-pq66-h8qj-7xg9/GHSA-pq66-h8qj-7xg9.json
index d4fcd2fbabf..0e33b375142 100644
--- a/advisories/unreviewed/2024/12/GHSA-pq66-h8qj-7xg9/GHSA-pq66-h8qj-7xg9.json
+++ b/advisories/unreviewed/2024/12/GHSA-pq66-h8qj-7xg9/GHSA-pq66-h8qj-7xg9.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pq66-h8qj-7xg9",
- "modified": "2024-12-27T15:31:55Z",
+ "modified": "2025-01-16T18:30:59Z",
"published": "2024-12-27T15:31:55Z",
"aliases": [
"CVE-2024-56617"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncacheinfo: Allocate memory during CPU hotplug if not done from the primary CPU\n\nCommit\n\n 5944ce092b97 (\"arch_topology: Build cacheinfo from primary CPU\")\n\nadds functionality that architectures can use to optionally allocate and\nbuild cacheinfo early during boot. Commit\n\n 6539cffa9495 (\"cacheinfo: Add arch specific early level initializer\")\n\nlets secondary CPUs correct (and reallocate memory) cacheinfo data if\nneeded.\n\nIf the early build functionality is not used and cacheinfo does not need\ncorrection, memory for cacheinfo is never allocated. x86 does not use\nthe early build functionality. Consequently, during the cacheinfo CPU\nhotplug callback, last_level_cache_is_valid() attempts to dereference\na NULL pointer:\n\n BUG: kernel NULL pointer dereference, address: 0000000000000100\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not present page\n PGD 0 P4D 0\n Oops: 0000 [#1] PREEPMT SMP NOPTI\n CPU: 0 PID 19 Comm: cpuhp/0 Not tainted 6.4.0-rc2 #1\n RIP: 0010: last_level_cache_is_valid+0x95/0xe0a\n\nAllocate memory for cacheinfo during the cacheinfo CPU hotplug callback\nif not done earlier.\n\nMoreover, before determining the validity of the last-level cache info,\nensure that it has been allocated. Simply checking for non-zero\ncache_leaves() is not sufficient, as some architectures (e.g., Intel\nprocessors) have non-zero cache_leaves() before allocation.\n\nDereferencing NULL cacheinfo can occur in update_per_cpu_data_slice_size().\nThis function iterates over all online CPUs. However, a CPU may have come\nonline recently, but its cacheinfo may not have been allocated yet.\n\nWhile here, remove an unnecessary indentation in allocate_cache_info().\n\n [ bp: Massage. ]",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-476"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-27T15:15:21Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-q2w6-3cqh-h6qq/GHSA-q2w6-3cqh-h6qq.json b/advisories/unreviewed/2024/12/GHSA-q2w6-3cqh-h6qq/GHSA-q2w6-3cqh-h6qq.json
index c30eb48b672..0f118e599c0 100644
--- a/advisories/unreviewed/2024/12/GHSA-q2w6-3cqh-h6qq/GHSA-q2w6-3cqh-h6qq.json
+++ b/advisories/unreviewed/2024/12/GHSA-q2w6-3cqh-h6qq/GHSA-q2w6-3cqh-h6qq.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q2w6-3cqh-h6qq",
- "modified": "2024-12-27T15:31:51Z",
+ "modified": "2025-01-16T18:30:58Z",
"published": "2024-12-27T15:31:51Z",
"aliases": [
"CVE-2024-53203"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: typec: fix potential array underflow in ucsi_ccg_sync_control()\n\nThe \"command\" variable can be controlled by the user via debugfs. The\nworry is that if con_index is zero then \"&uc->ucsi->connector[con_index\n- 1]\" would be an array underflow.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-129"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-27T14:15:28Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-wrw9-rpg8-p3wx/GHSA-wrw9-rpg8-p3wx.json b/advisories/unreviewed/2024/12/GHSA-wrw9-rpg8-p3wx/GHSA-wrw9-rpg8-p3wx.json
index e07a8fd3951..5e9c19f93bc 100644
--- a/advisories/unreviewed/2024/12/GHSA-wrw9-rpg8-p3wx/GHSA-wrw9-rpg8-p3wx.json
+++ b/advisories/unreviewed/2024/12/GHSA-wrw9-rpg8-p3wx/GHSA-wrw9-rpg8-p3wx.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wrw9-rpg8-p3wx",
- "modified": "2024-12-27T15:31:55Z",
+ "modified": "2025-01-16T18:30:58Z",
"published": "2024-12-27T15:31:55Z",
"aliases": [
"CVE-2024-56615"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: fix OOB devmap writes when deleting elements\n\nJordy reported issue against XSKMAP which also applies to DEVMAP - the\nindex used for accessing map entry, due to being a signed integer,\ncauses the OOB writes. Fix is simple as changing the type from int to\nu32, however, when compared to XSKMAP case, one more thing needs to be\naddressed.\n\nWhen map is released from system via dev_map_free(), we iterate through\nall of the entries and an iterator variable is also an int, which\nimplies OOB accesses. Again, change it to be u32.\n\nExample splat below:\n\n[ 160.724676] BUG: unable to handle page fault for address: ffffc8fc2c001000\n[ 160.731662] #PF: supervisor read access in kernel mode\n[ 160.736876] #PF: error_code(0x0000) - not-present page\n[ 160.742095] PGD 0 P4D 0\n[ 160.744678] Oops: Oops: 0000 [#1] PREEMPT SMP\n[ 160.749106] CPU: 1 UID: 0 PID: 520 Comm: kworker/u145:12 Not tainted 6.12.0-rc1+ #487\n[ 160.757050] Hardware name: Intel Corporation S2600WFT/S2600WFT, BIOS SE5C620.86B.02.01.0008.031920191559 03/19/2019\n[ 160.767642] Workqueue: events_unbound bpf_map_free_deferred\n[ 160.773308] RIP: 0010:dev_map_free+0x77/0x170\n[ 160.777735] Code: 00 e8 fd 91 ed ff e8 b8 73 ed ff 41 83 7d 18 19 74 6e 41 8b 45 24 49 8b bd f8 00 00 00 31 db 85 c0 74 48 48 63 c3 48 8d 04 c7 <48> 8b 28 48 85 ed 74 30 48 8b 7d 18 48 85 ff 74 05 e8 b3 52 fa ff\n[ 160.796777] RSP: 0018:ffffc9000ee1fe38 EFLAGS: 00010202\n[ 160.802086] RAX: ffffc8fc2c001000 RBX: 0000000080000000 RCX: 0000000000000024\n[ 160.809331] RDX: 0000000000000000 RSI: 0000000000000024 RDI: ffffc9002c001000\n[ 160.816576] RBP: 0000000000000000 R08: 0000000000000023 R09: 0000000000000001\n[ 160.823823] R10: 0000000000000001 R11: 00000000000ee6b2 R12: dead000000000122\n[ 160.831066] R13: ffff88810c928e00 R14: ffff8881002df405 R15: 0000000000000000\n[ 160.838310] FS: 0000000000000000(0000) GS:ffff8897e0c40000(0000) knlGS:0000000000000000\n[ 160.846528] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 160.852357] CR2: ffffc8fc2c001000 CR3: 0000000005c32006 CR4: 00000000007726f0\n[ 160.859604] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n[ 160.866847] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n[ 160.874092] PKRU: 55555554\n[ 160.876847] Call Trace:\n[ 160.879338] \n[ 160.881477] ? __die+0x20/0x60\n[ 160.884586] ? page_fault_oops+0x15a/0x450\n[ 160.888746] ? search_extable+0x22/0x30\n[ 160.892647] ? search_bpf_extables+0x5f/0x80\n[ 160.896988] ? exc_page_fault+0xa9/0x140\n[ 160.900973] ? asm_exc_page_fault+0x22/0x30\n[ 160.905232] ? dev_map_free+0x77/0x170\n[ 160.909043] ? dev_map_free+0x58/0x170\n[ 160.912857] bpf_map_free_deferred+0x51/0x90\n[ 160.917196] process_one_work+0x142/0x370\n[ 160.921272] worker_thread+0x29e/0x3b0\n[ 160.925082] ? rescuer_thread+0x4b0/0x4b0\n[ 160.929157] kthread+0xd4/0x110\n[ 160.932355] ? kthread_park+0x80/0x80\n[ 160.936079] ret_from_fork+0x2d/0x50\n[ 160.943396] ? kthread_park+0x80/0x80\n[ 160.950803] ret_from_fork_asm+0x11/0x20\n[ 160.958482] ",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -44,8 +49,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-787"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-27T15:15:21Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-xq66-2344-jv36/GHSA-xq66-2344-jv36.json b/advisories/unreviewed/2024/12/GHSA-xq66-2344-jv36/GHSA-xq66-2344-jv36.json
index 905fc638d13..3506a5d095f 100644
--- a/advisories/unreviewed/2024/12/GHSA-xq66-2344-jv36/GHSA-xq66-2344-jv36.json
+++ b/advisories/unreviewed/2024/12/GHSA-xq66-2344-jv36/GHSA-xq66-2344-jv36.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xq66-2344-jv36",
- "modified": "2024-12-27T15:31:50Z",
+ "modified": "2025-01-16T18:30:58Z",
"published": "2024-12-27T15:31:50Z",
"aliases": [
"CVE-2024-53170"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nblock: fix uaf for flush rq while iterating tags\n\nblk_mq_clear_flush_rq_mapping() is not called during scsi probe, by\nchecking blk_queue_init_done(). However, QUEUE_FLAG_INIT_DONE is cleared\nin del_gendisk by commit aec89dc5d421 (\"block: keep q_usage_counter in\natomic mode after del_gendisk\"), hence for disk like scsi, following\nblk_mq_destroy_queue() will not clear flush rq from tags->rqs[] as well,\ncause following uaf that is found by our syzkaller for v6.6:\n\n==================================================================\nBUG: KASAN: slab-use-after-free in blk_mq_find_and_get_req+0x16e/0x1a0 block/blk-mq-tag.c:261\nRead of size 4 at addr ffff88811c969c20 by task kworker/1:2H/224909\n\nCPU: 1 PID: 224909 Comm: kworker/1:2H Not tainted 6.6.0-ga836a5060850 #32\nWorkqueue: kblockd blk_mq_timeout_work\nCall Trace:\n\n__dump_stack lib/dump_stack.c:88 [inline]\ndump_stack_lvl+0x91/0xf0 lib/dump_stack.c:106\nprint_address_description.constprop.0+0x66/0x300 mm/kasan/report.c:364\nprint_report+0x3e/0x70 mm/kasan/report.c:475\nkasan_report+0xb8/0xf0 mm/kasan/report.c:588\nblk_mq_find_and_get_req+0x16e/0x1a0 block/blk-mq-tag.c:261\nbt_iter block/blk-mq-tag.c:288 [inline]\n__sbitmap_for_each_set include/linux/sbitmap.h:295 [inline]\nsbitmap_for_each_set include/linux/sbitmap.h:316 [inline]\nbt_for_each+0x455/0x790 block/blk-mq-tag.c:325\nblk_mq_queue_tag_busy_iter+0x320/0x740 block/blk-mq-tag.c:534\nblk_mq_timeout_work+0x1a3/0x7b0 block/blk-mq.c:1673\nprocess_one_work+0x7c4/0x1450 kernel/workqueue.c:2631\nprocess_scheduled_works kernel/workqueue.c:2704 [inline]\nworker_thread+0x804/0xe40 kernel/workqueue.c:2785\nkthread+0x346/0x450 kernel/kthread.c:388\nret_from_fork+0x4d/0x80 arch/x86/kernel/process.c:147\nret_from_fork_asm+0x1b/0x30 arch/x86/entry/entry_64.S:293\n\nAllocated by task 942:\nkasan_save_stack+0x22/0x50 mm/kasan/common.c:45\nkasan_set_track+0x25/0x30 mm/kasan/common.c:52\n____kasan_kmalloc mm/kasan/common.c:374 [inline]\n__kasan_kmalloc mm/kasan/common.c:383 [inline]\n__kasan_kmalloc+0xaa/0xb0 mm/kasan/common.c:380\nkasan_kmalloc include/linux/kasan.h:198 [inline]\n__do_kmalloc_node mm/slab_common.c:1007 [inline]\n__kmalloc_node+0x69/0x170 mm/slab_common.c:1014\nkmalloc_node include/linux/slab.h:620 [inline]\nkzalloc_node include/linux/slab.h:732 [inline]\nblk_alloc_flush_queue+0x144/0x2f0 block/blk-flush.c:499\nblk_mq_alloc_hctx+0x601/0x940 block/blk-mq.c:3788\nblk_mq_alloc_and_init_hctx+0x27f/0x330 block/blk-mq.c:4261\nblk_mq_realloc_hw_ctxs+0x488/0x5e0 block/blk-mq.c:4294\nblk_mq_init_allocated_queue+0x188/0x860 block/blk-mq.c:4350\nblk_mq_init_queue_data block/blk-mq.c:4166 [inline]\nblk_mq_init_queue+0x8d/0x100 block/blk-mq.c:4176\nscsi_alloc_sdev+0x843/0xd50 drivers/scsi/scsi_scan.c:335\nscsi_probe_and_add_lun+0x77c/0xde0 drivers/scsi/scsi_scan.c:1189\n__scsi_scan_target+0x1fc/0x5a0 drivers/scsi/scsi_scan.c:1727\nscsi_scan_channel drivers/scsi/scsi_scan.c:1815 [inline]\nscsi_scan_channel+0x14b/0x1e0 drivers/scsi/scsi_scan.c:1791\nscsi_scan_host_selected+0x2fe/0x400 drivers/scsi/scsi_scan.c:1844\nscsi_scan+0x3a0/0x3f0 drivers/scsi/scsi_sysfs.c:151\nstore_scan+0x2a/0x60 drivers/scsi/scsi_sysfs.c:191\ndev_attr_store+0x5c/0x90 drivers/base/core.c:2388\nsysfs_kf_write+0x11c/0x170 fs/sysfs/file.c:136\nkernfs_fop_write_iter+0x3fc/0x610 fs/kernfs/file.c:338\ncall_write_iter include/linux/fs.h:2083 [inline]\nnew_sync_write+0x1b4/0x2d0 fs/read_write.c:493\nvfs_write+0x76c/0xb00 fs/read_write.c:586\nksys_write+0x127/0x250 fs/read_write.c:639\ndo_syscall_x64 arch/x86/entry/common.c:51 [inline]\ndo_syscall_64+0x70/0x120 arch/x86/entry/common.c:81\nentry_SYSCALL_64_after_hwframe+0x78/0xe2\n\nFreed by task 244687:\nkasan_save_stack+0x22/0x50 mm/kasan/common.c:45\nkasan_set_track+0x25/0x30 mm/kasan/common.c:52\nkasan_save_free_info+0x2b/0x50 mm/kasan/generic.c:522\n____kasan_slab_free mm/kasan/common.c:236 [inline]\n__kasan_slab_free+0x12a/0x1b0 mm/kasan/common.c:244\nkasan_slab_free include/linux/kasan.h:164 [in\n---truncated---",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-27T14:15:24Z"
diff --git a/advisories/unreviewed/2025/01/GHSA-26h2-xpj3-3r9v/GHSA-26h2-xpj3-3r9v.json b/advisories/unreviewed/2025/01/GHSA-26h2-xpj3-3r9v/GHSA-26h2-xpj3-3r9v.json
new file mode 100644
index 00000000000..5a7932c8924
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-26h2-xpj3-3r9v/GHSA-26h2-xpj3-3r9v.json
@@ -0,0 +1,29 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-26h2-xpj3-3r9v",
+ "modified": "2025-01-16T18:31:00Z",
+ "published": "2025-01-16T18:31:00Z",
+ "aliases": [
+ "CVE-2024-57161"
+ ],
+ "details": "07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net:80/oa/OaWorkReport/edit.html",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57161"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/1091101/yang.xian/tree/main/8/readme.md"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-16T16:15:32Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-28h2-465h-q5v7/GHSA-28h2-465h-q5v7.json b/advisories/unreviewed/2025/01/GHSA-28h2-465h-q5v7/GHSA-28h2-465h-q5v7.json
index f14d070f144..c8525dad93c 100644
--- a/advisories/unreviewed/2025/01/GHSA-28h2-465h-q5v7/GHSA-28h2-465h-q5v7.json
+++ b/advisories/unreviewed/2025/01/GHSA-28h2-465h-q5v7/GHSA-28h2-465h-q5v7.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-28h2-465h-q5v7",
- "modified": "2025-01-11T15:30:28Z",
+ "modified": "2025-01-16T18:30:59Z",
"published": "2025-01-11T15:30:28Z",
"aliases": [
"CVE-2024-53689"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nblock: Fix potential deadlock while freezing queue and acquiring sysfs_lock\n\nFor storing a value to a queue attribute, the queue_attr_store function\nfirst freezes the queue (->q_usage_counter(io)) and then acquire\n->sysfs_lock. This seems not correct as the usual ordering should be to\nacquire ->sysfs_lock before freezing the queue. This incorrect ordering\ncauses the following lockdep splat which we are able to reproduce always\nsimply by accessing /sys/kernel/debug file using ls command:\n\n[ 57.597146] WARNING: possible circular locking dependency detected\n[ 57.597154] 6.12.0-10553-gb86545e02e8c #20 Tainted: G W\n[ 57.597162] ------------------------------------------------------\n[ 57.597168] ls/4605 is trying to acquire lock:\n[ 57.597176] c00000003eb56710 (&mm->mmap_lock){++++}-{4:4}, at: __might_fault+0x58/0xc0\n[ 57.597200]\n but task is already holding lock:\n[ 57.597207] c0000018e27c6810 (&sb->s_type->i_mutex_key#3){++++}-{4:4}, at: iterate_dir+0x94/0x1d4\n[ 57.597226]\n which lock already depends on the new lock.\n\n[ 57.597233]\n the existing dependency chain (in reverse order) is:\n[ 57.597241]\n -> #5 (&sb->s_type->i_mutex_key#3){++++}-{4:4}:\n[ 57.597255] down_write+0x6c/0x18c\n[ 57.597264] start_creating+0xb4/0x24c\n[ 57.597274] debugfs_create_dir+0x2c/0x1e8\n[ 57.597283] blk_register_queue+0xec/0x294\n[ 57.597292] add_disk_fwnode+0x2e4/0x548\n[ 57.597302] brd_alloc+0x2c8/0x338\n[ 57.597309] brd_init+0x100/0x178\n[ 57.597317] do_one_initcall+0x88/0x3e4\n[ 57.597326] kernel_init_freeable+0x3cc/0x6e0\n[ 57.597334] kernel_init+0x34/0x1cc\n[ 57.597342] ret_from_kernel_user_thread+0x14/0x1c\n[ 57.597350]\n -> #4 (&q->debugfs_mutex){+.+.}-{4:4}:\n[ 57.597362] __mutex_lock+0xfc/0x12a0\n[ 57.597370] blk_register_queue+0xd4/0x294\n[ 57.597379] add_disk_fwnode+0x2e4/0x548\n[ 57.597388] brd_alloc+0x2c8/0x338\n[ 57.597395] brd_init+0x100/0x178\n[ 57.597402] do_one_initcall+0x88/0x3e4\n[ 57.597410] kernel_init_freeable+0x3cc/0x6e0\n[ 57.597418] kernel_init+0x34/0x1cc\n[ 57.597426] ret_from_kernel_user_thread+0x14/0x1c\n[ 57.597434]\n -> #3 (&q->sysfs_lock){+.+.}-{4:4}:\n[ 57.597446] __mutex_lock+0xfc/0x12a0\n[ 57.597454] queue_attr_store+0x9c/0x110\n[ 57.597462] sysfs_kf_write+0x70/0xb0\n[ 57.597471] kernfs_fop_write_iter+0x1b0/0x2ac\n[ 57.597480] vfs_write+0x3dc/0x6e8\n[ 57.597488] ksys_write+0x84/0x140\n[ 57.597495] system_call_exception+0x130/0x360\n[ 57.597504] system_call_common+0x160/0x2c4\n[ 57.597516]\n -> #2 (&q->q_usage_counter(io)#21){++++}-{0:0}:\n[ 57.597530] __submit_bio+0x5ec/0x828\n[ 57.597538] submit_bio_noacct_nocheck+0x1e4/0x4f0\n[ 57.597547] iomap_readahead+0x2a0/0x448\n[ 57.597556] xfs_vm_readahead+0x28/0x3c\n[ 57.597564] read_pages+0x88/0x41c\n[ 57.597571] page_cache_ra_unbounded+0x1ac/0x2d8\n[ 57.597580] filemap_get_pages+0x188/0x984\n[ 57.597588] filemap_read+0x13c/0x4bc\n[ 57.597596] xfs_file_buffered_read+0x88/0x17c\n[ 57.597605] xfs_file_read_iter+0xac/0x158\n[ 57.597614] vfs_read+0x2d4/0x3b4\n[ 57.597622] ksys_read+0x84/0x144\n[ 57.597629] system_call_exception+0x130/0x360\n[ 57.597637] system_call_common+0x160/0x2c4\n[ 57.597647]\n -> #1 (mapping.invalidate_lock#2){++++}-{4:4}:\n[ 57.597661] down_read+0x6c/0x220\n[ 57.597669] filemap_fault+0x870/0x100c\n[ 57.597677] xfs_filemap_fault+0xc4/0x18c\n[ 57.597684] __do_fault+0x64/0x164\n[ 57.597693] __handle_mm_fault+0x1274/0x1dac\n[ 57.597702] handle_mm_fault+0x248/0x48\n---truncated---",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-667"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-11T13:15:26Z"
diff --git a/advisories/unreviewed/2025/01/GHSA-363m-f7wv-qpfm/GHSA-363m-f7wv-qpfm.json b/advisories/unreviewed/2025/01/GHSA-363m-f7wv-qpfm/GHSA-363m-f7wv-qpfm.json
index 831311778ce..f4c5b5ab715 100644
--- a/advisories/unreviewed/2025/01/GHSA-363m-f7wv-qpfm/GHSA-363m-f7wv-qpfm.json
+++ b/advisories/unreviewed/2025/01/GHSA-363m-f7wv-qpfm/GHSA-363m-f7wv-qpfm.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-363m-f7wv-qpfm",
- "modified": "2025-01-15T00:30:42Z",
+ "modified": "2025-01-16T18:30:59Z",
"published": "2025-01-15T00:30:42Z",
"aliases": [
"CVE-2024-54730"
],
"details": "Flatnotes lock){+.+.}-{3:3},\n at: iso_conn_big_sync+0x73/0x260 [bluetooth]\n[ 561.670405]\n but task is already holding lock:\n[ 561.670407] ffff88815af58258 (sk_lock-AF_BLUETOOTH){+.+.}-{0:0},\n at: iso_sock_recvmsg+0xbf/0x500 [bluetooth]\n[ 561.670450]\n which lock already depends on the new lock.\n\n[ 561.670452]\n the existing dependency chain (in reverse order) is:\n[ 561.670453]\n -> #2 (sk_lock-AF_BLUETOOTH){+.+.}-{0:0}:\n[ 561.670458] lock_acquire+0x7c/0xc0\n[ 561.670463] lock_sock_nested+0x3b/0xf0\n[ 561.670467] bt_accept_dequeue+0x1a5/0x4d0 [bluetooth]\n[ 561.670510] iso_sock_accept+0x271/0x830 [bluetooth]\n[ 561.670547] do_accept+0x3dd/0x610\n[ 561.670550] __sys_accept4+0xd8/0x170\n[ 561.670553] __x64_sys_accept+0x74/0xc0\n[ 561.670556] x64_sys_call+0x17d6/0x25f0\n[ 561.670559] do_syscall_64+0x87/0x150\n[ 561.670563] entry_SYSCALL_64_after_hwframe+0x76/0x7e\n[ 561.670567]\n -> #1 (sk_lock-AF_BLUETOOTH-BTPROTO_ISO){+.+.}-{0:0}:\n[ 561.670571] lock_acquire+0x7c/0xc0\n[ 561.670574] lock_sock_nested+0x3b/0xf0\n[ 561.670577] iso_sock_listen+0x2de/0xf30 [bluetooth]\n[ 561.670617] __sys_listen_socket+0xef/0x130\n[ 561.670620] __x64_sys_listen+0xe1/0x190\n[ 561.670623] x64_sys_call+0x2517/0x25f0\n[ 561.670626] do_syscall_64+0x87/0x150\n[ 561.670629] entry_SYSCALL_64_after_hwframe+0x76/0x7e\n[ 561.670632]\n -> #0 (&hdev->lock){+.+.}-{3:3}:\n[ 561.670636] __lock_acquire+0x32ad/0x6ab0\n[ 561.670639] lock_acquire.part.0+0x118/0x360\n[ 561.670642] lock_acquire+0x7c/0xc0\n[ 561.670644] __mutex_lock+0x18d/0x12f0\n[ 561.670647] mutex_lock_nested+0x1b/0x30\n[ 561.670651] iso_conn_big_sync+0x73/0x260 [bluetooth]\n[ 561.670687] iso_sock_recvmsg+0x3e9/0x500 [bluetooth]\n[ 561.670722] sock_recvmsg+0x1d5/0x240\n[ 561.670725] sock_read_iter+0x27d/0x470\n[ 561.670727] vfs_read+0x9a0/0xd30\n[ 561.670731] ksys_read+0x1a8/0x250\n[ 561.670733] __x64_sys_read+0x72/0xc0\n[ 561.670736] x64_sys_call+0x1b12/0x25f0\n[ 561.670738] do_syscall_64+0x87/0x150\n[ 561.670741] entry_SYSCALL_64_after_hwframe+0x76/0x7e\n[ 561.670744]\n other info that might help us debug this:\n\n[ 561.670745] Chain exists of:\n&hdev->lock --> sk_lock-AF_BLUETOOTH-BTPROTO_ISO --> sk_lock-AF_BLUETOOTH\n\n[ 561.670751] Possible unsafe locking scenario:\n\n[ 561.670753] CPU0 CPU1\n[ 561.670754] ---- ----\n[ 561.670756] lock(sk_lock-AF_BLUETOOTH);\n[ 561.670758] lock(sk_lock\n AF_BLUETOOTH-BTPROTO_ISO);\n[ 561.670761] lock(sk_lock-AF_BLUETOOTH);\n[ 561.670764] lock(&hdev->lock);\n[ 561.670767]\n *** DEADLOCK ***",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-667"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-11T13:15:26Z"
diff --git a/advisories/unreviewed/2025/01/GHSA-xmr9-3j8w-v8gw/GHSA-xmr9-3j8w-v8gw.json b/advisories/unreviewed/2025/01/GHSA-xmr9-3j8w-v8gw/GHSA-xmr9-3j8w-v8gw.json
new file mode 100644
index 00000000000..b705e8ae13b
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-xmr9-3j8w-v8gw/GHSA-xmr9-3j8w-v8gw.json
@@ -0,0 +1,29 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-xmr9-3j8w-v8gw",
+ "modified": "2025-01-16T18:31:00Z",
+ "published": "2025-01-16T18:31:00Z",
+ "aliases": [
+ "CVE-2024-57771"
+ ],
+ "details": "A cross-site scripting (XSS) vulnerability in the common/getEditPage?view interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57771"
+ },
+ {
+ "type": "WEB",
+ "url": "https://gitee.com/r1bbit/JFinalOA/issues/IBHUPO"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-16T18:15:26Z"
+ }
+}
\ No newline at end of file