From 55f42f5d8594e43930f39ccd61902c36622e5b0b Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 27 Feb 2025 18:32:23 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-phg3-gv66-q38x.json | 6 +- .../GHSA-427h-98c5-gq24.json | 4 +- .../GHSA-6x3m-hh2g-4gwp.json | 4 +- .../GHSA-j9xq-95fc-pqv2.json | 4 +- .../GHSA-rqpf-mw6m-jx7p.json | 2 +- .../GHSA-v3fg-qxxf-34w3.json | 6 +- .../GHSA-3rqr-p9xj-863f.json | 4 +- .../GHSA-567q-hq5r-pw43.json | 4 +- .../GHSA-24vg-8cmx-c7xr.json | 4 +- .../GHSA-48jr-p93f-pwq8.json | 15 ++-- .../GHSA-m9px-xr79-8fvc.json | 11 ++- .../GHSA-6r8w-jhg7-gpr9.json | 4 +- .../GHSA-96hm-xqc5-vqv9.json | 4 +- .../GHSA-g5vh-4wvj-vgc9.json | 6 +- .../GHSA-pfc9-pj4x-5f23.json | 4 +- .../GHSA-26m5-cv5f-4mwg.json | 2 +- .../GHSA-4xvm-58x2-m87c.json | 5 +- .../GHSA-78pr-m5p7-52qj.json | 2 +- .../GHSA-7jf8-hmr2-f4xc.json | 2 +- .../GHSA-8297-wvjg-5vxg.json | 2 +- .../GHSA-8r6w-mfx6-6726.json | 2 +- .../GHSA-99ww-c378-6m65.json | 5 +- .../GHSA-9w62-9ghr-p98m.json | 2 +- .../GHSA-c3m5-p52q-pvhf.json | 3 +- .../GHSA-p4vp-3hqc-mfgr.json | 2 +- .../GHSA-px35-m227-24jv.json | 2 +- .../GHSA-r8wg-fm7g-x3vf.json | 2 +- .../GHSA-rff8-7ph7-xchr.json | 3 +- .../GHSA-rgc4-v4cj-59q2.json | 2 +- .../GHSA-w8wv-xphh-4948.json | 2 +- .../GHSA-wq8m-87w7-34w5.json | 5 +- .../GHSA-xj26-gx3h-x793.json | 2 +- .../GHSA-25hc-2p68-qc2g.json | 40 +++++++++++ .../GHSA-2qfv-5w3v-jvfv.json | 15 ++-- .../GHSA-3q7x-q7fm-whrm.json | 36 ++++++++++ .../GHSA-3vhc-4mgh-2vvp.json | 15 ++-- .../GHSA-422g-php3-xrv4.json | 64 +++++++++++++++++ .../GHSA-45c3-pwch-8qg9.json | 64 +++++++++++++++++ .../GHSA-4gxw-5w55-6f5h.json | 15 ++-- .../GHSA-4mx7-h455-mwxv.json | 68 +++++++++++++++++++ .../GHSA-5f34-xwxq-mm2x.json | 40 +++++++++++ .../GHSA-5mhv-g6m4-pmp4.json | 56 +++++++++++++++ .../GHSA-5mwf-pvj7-8qj6.json | 29 ++++++++ .../GHSA-65hc-mhvg-x697.json | 29 ++++++++ .../GHSA-75q5-6x22-qjpw.json | 52 ++++++++++++++ .../GHSA-798h-hm78-q979.json | 15 ++-- .../GHSA-87qr-3hp3-x583.json | 64 +++++++++++++++++ .../GHSA-8gcm-9r6g-8j3f.json | 64 +++++++++++++++++ .../GHSA-8qgg-vj9j-hh4r.json | 60 ++++++++++++++++ .../GHSA-8w8c-pj2m-2g74.json | 29 ++++++++ .../GHSA-94p4-4m9q-5m8x.json | 15 ++-- .../GHSA-97f5-6j52-rp35.json | 40 +++++++++++ .../GHSA-cmvg-6vcw-642h.json | 15 ++-- .../GHSA-f5w3-73h4-jpcm.json | 40 +++++++++++ .../GHSA-f6m2-43g4-75fj.json | 36 ++++++++++ .../GHSA-fr54-2qgg-4whr.json | 52 ++++++++++++++ .../GHSA-g48q-f43r-rjjg.json | 40 +++++++++++ .../GHSA-gcjr-rx2g-5wh3.json | 4 +- .../GHSA-gq6q-2ffm-3vc2.json | 29 ++++++++ .../GHSA-gr74-v59q-3p8g.json | 29 ++++++++ .../GHSA-gw7x-m5vf-fw73.json | 56 +++++++++++++++ .../GHSA-hgrx-p3hg-cw72.json | 15 ++-- .../GHSA-hpv4-mq4h-frcq.json | 52 ++++++++++++++ .../GHSA-j8mq-pfgm-36r2.json | 15 ++-- .../GHSA-jc5w-m29h-g88w.json | 15 ++-- .../GHSA-jh3f-g934-rw77.json | 56 +++++++++++++++ .../GHSA-m2x9-jx4p-g5c8.json | 29 ++++++++ .../GHSA-m3vm-45hm-666q.json | 48 +++++++++++++ .../GHSA-m4c7-j6q4-hc9j.json | 52 ++++++++++++++ .../GHSA-m645-2c8g-gg4p.json | 68 +++++++++++++++++++ .../GHSA-p967-4mgh-r94w.json | 64 +++++++++++++++++ .../GHSA-ppc4-h225-m9r2.json | 29 ++++++++ .../GHSA-pvj3-f5v8-hgxh.json | 15 ++-- .../GHSA-q6cq-g5qv-hwc8.json | 15 ++-- .../GHSA-r42x-vw8p-w99g.json | 60 ++++++++++++++++ .../GHSA-v53m-h2x7-3m5p.json | 52 ++++++++++++++ .../GHSA-v68h-2qqv-28r8.json | 29 ++++++++ .../GHSA-vcqr-h4qj-jv8g.json | 68 +++++++++++++++++++ .../GHSA-vr2w-w74g-r822.json | 15 ++-- .../GHSA-w66w-gg7v-xc4c.json | 29 ++++++++ .../GHSA-w9jf-hmj5-fp54.json | 44 ++++++++++++ .../GHSA-wm97-xp23-f4x4.json | 15 ++-- .../GHSA-wqcr-wj43-4gg7.json | 15 ++-- .../GHSA-wvmf-xh97-gmfr.json | 15 ++-- 84 files changed, 1948 insertions(+), 105 deletions(-) create mode 100644 advisories/unreviewed/2025/02/GHSA-25hc-2p68-qc2g/GHSA-25hc-2p68-qc2g.json create mode 100644 advisories/unreviewed/2025/02/GHSA-3q7x-q7fm-whrm/GHSA-3q7x-q7fm-whrm.json create mode 100644 advisories/unreviewed/2025/02/GHSA-422g-php3-xrv4/GHSA-422g-php3-xrv4.json create mode 100644 advisories/unreviewed/2025/02/GHSA-45c3-pwch-8qg9/GHSA-45c3-pwch-8qg9.json create mode 100644 advisories/unreviewed/2025/02/GHSA-4mx7-h455-mwxv/GHSA-4mx7-h455-mwxv.json create mode 100644 advisories/unreviewed/2025/02/GHSA-5f34-xwxq-mm2x/GHSA-5f34-xwxq-mm2x.json create mode 100644 advisories/unreviewed/2025/02/GHSA-5mhv-g6m4-pmp4/GHSA-5mhv-g6m4-pmp4.json create mode 100644 advisories/unreviewed/2025/02/GHSA-5mwf-pvj7-8qj6/GHSA-5mwf-pvj7-8qj6.json create mode 100644 advisories/unreviewed/2025/02/GHSA-65hc-mhvg-x697/GHSA-65hc-mhvg-x697.json create mode 100644 advisories/unreviewed/2025/02/GHSA-75q5-6x22-qjpw/GHSA-75q5-6x22-qjpw.json create mode 100644 advisories/unreviewed/2025/02/GHSA-87qr-3hp3-x583/GHSA-87qr-3hp3-x583.json create mode 100644 advisories/unreviewed/2025/02/GHSA-8gcm-9r6g-8j3f/GHSA-8gcm-9r6g-8j3f.json create mode 100644 advisories/unreviewed/2025/02/GHSA-8qgg-vj9j-hh4r/GHSA-8qgg-vj9j-hh4r.json create mode 100644 advisories/unreviewed/2025/02/GHSA-8w8c-pj2m-2g74/GHSA-8w8c-pj2m-2g74.json create mode 100644 advisories/unreviewed/2025/02/GHSA-97f5-6j52-rp35/GHSA-97f5-6j52-rp35.json create mode 100644 advisories/unreviewed/2025/02/GHSA-f5w3-73h4-jpcm/GHSA-f5w3-73h4-jpcm.json create mode 100644 advisories/unreviewed/2025/02/GHSA-f6m2-43g4-75fj/GHSA-f6m2-43g4-75fj.json create mode 100644 advisories/unreviewed/2025/02/GHSA-fr54-2qgg-4whr/GHSA-fr54-2qgg-4whr.json create mode 100644 advisories/unreviewed/2025/02/GHSA-g48q-f43r-rjjg/GHSA-g48q-f43r-rjjg.json create mode 100644 advisories/unreviewed/2025/02/GHSA-gq6q-2ffm-3vc2/GHSA-gq6q-2ffm-3vc2.json create mode 100644 advisories/unreviewed/2025/02/GHSA-gr74-v59q-3p8g/GHSA-gr74-v59q-3p8g.json create mode 100644 advisories/unreviewed/2025/02/GHSA-gw7x-m5vf-fw73/GHSA-gw7x-m5vf-fw73.json create mode 100644 advisories/unreviewed/2025/02/GHSA-hpv4-mq4h-frcq/GHSA-hpv4-mq4h-frcq.json create mode 100644 advisories/unreviewed/2025/02/GHSA-jh3f-g934-rw77/GHSA-jh3f-g934-rw77.json create mode 100644 advisories/unreviewed/2025/02/GHSA-m2x9-jx4p-g5c8/GHSA-m2x9-jx4p-g5c8.json create mode 100644 advisories/unreviewed/2025/02/GHSA-m3vm-45hm-666q/GHSA-m3vm-45hm-666q.json create mode 100644 advisories/unreviewed/2025/02/GHSA-m4c7-j6q4-hc9j/GHSA-m4c7-j6q4-hc9j.json create mode 100644 advisories/unreviewed/2025/02/GHSA-m645-2c8g-gg4p/GHSA-m645-2c8g-gg4p.json create mode 100644 advisories/unreviewed/2025/02/GHSA-p967-4mgh-r94w/GHSA-p967-4mgh-r94w.json create mode 100644 advisories/unreviewed/2025/02/GHSA-ppc4-h225-m9r2/GHSA-ppc4-h225-m9r2.json create mode 100644 advisories/unreviewed/2025/02/GHSA-r42x-vw8p-w99g/GHSA-r42x-vw8p-w99g.json create mode 100644 advisories/unreviewed/2025/02/GHSA-v53m-h2x7-3m5p/GHSA-v53m-h2x7-3m5p.json create mode 100644 advisories/unreviewed/2025/02/GHSA-v68h-2qqv-28r8/GHSA-v68h-2qqv-28r8.json create mode 100644 advisories/unreviewed/2025/02/GHSA-vcqr-h4qj-jv8g/GHSA-vcqr-h4qj-jv8g.json create mode 100644 advisories/unreviewed/2025/02/GHSA-w66w-gg7v-xc4c/GHSA-w66w-gg7v-xc4c.json create mode 100644 advisories/unreviewed/2025/02/GHSA-w9jf-hmj5-fp54/GHSA-w9jf-hmj5-fp54.json diff --git a/advisories/github-reviewed/2025/02/GHSA-phg3-gv66-q38x/GHSA-phg3-gv66-q38x.json b/advisories/github-reviewed/2025/02/GHSA-phg3-gv66-q38x/GHSA-phg3-gv66-q38x.json index eabd814d987..897866aec09 100644 --- a/advisories/github-reviewed/2025/02/GHSA-phg3-gv66-q38x/GHSA-phg3-gv66-q38x.json +++ b/advisories/github-reviewed/2025/02/GHSA-phg3-gv66-q38x/GHSA-phg3-gv66-q38x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-phg3-gv66-q38x", - "modified": "2025-02-27T15:31:50Z", + "modified": "2025-02-27T18:31:07Z", "published": "2025-02-13T15:31:25Z", "aliases": [ "CVE-2025-1247" @@ -67,6 +67,10 @@ "type": "WEB", "url": "https://github.com/quarkusio/quarkus/commit/02ff9ed45c3928edf2a0f8b906543606fed7cd53" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:1884" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:1885" diff --git a/advisories/unreviewed/2023/03/GHSA-427h-98c5-gq24/GHSA-427h-98c5-gq24.json b/advisories/unreviewed/2023/03/GHSA-427h-98c5-gq24/GHSA-427h-98c5-gq24.json index e4ec2325240..617f422bb04 100644 --- a/advisories/unreviewed/2023/03/GHSA-427h-98c5-gq24/GHSA-427h-98c5-gq24.json +++ b/advisories/unreviewed/2023/03/GHSA-427h-98c5-gq24/GHSA-427h-98c5-gq24.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-306" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/03/GHSA-6x3m-hh2g-4gwp/GHSA-6x3m-hh2g-4gwp.json b/advisories/unreviewed/2023/03/GHSA-6x3m-hh2g-4gwp/GHSA-6x3m-hh2g-4gwp.json index 1a1451aa4f8..8d507bac7bd 100644 --- a/advisories/unreviewed/2023/03/GHSA-6x3m-hh2g-4gwp/GHSA-6x3m-hh2g-4gwp.json +++ b/advisories/unreviewed/2023/03/GHSA-6x3m-hh2g-4gwp/GHSA-6x3m-hh2g-4gwp.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-266" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/03/GHSA-j9xq-95fc-pqv2/GHSA-j9xq-95fc-pqv2.json b/advisories/unreviewed/2023/03/GHSA-j9xq-95fc-pqv2/GHSA-j9xq-95fc-pqv2.json index c0c48310365..5a810e284c3 100644 --- a/advisories/unreviewed/2023/03/GHSA-j9xq-95fc-pqv2/GHSA-j9xq-95fc-pqv2.json +++ b/advisories/unreviewed/2023/03/GHSA-j9xq-95fc-pqv2/GHSA-j9xq-95fc-pqv2.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-427" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/03/GHSA-rqpf-mw6m-jx7p/GHSA-rqpf-mw6m-jx7p.json b/advisories/unreviewed/2023/03/GHSA-rqpf-mw6m-jx7p/GHSA-rqpf-mw6m-jx7p.json index fe08e6b4116..7bb488dcfc7 100644 --- a/advisories/unreviewed/2023/03/GHSA-rqpf-mw6m-jx7p/GHSA-rqpf-mw6m-jx7p.json +++ b/advisories/unreviewed/2023/03/GHSA-rqpf-mw6m-jx7p/GHSA-rqpf-mw6m-jx7p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rqpf-mw6m-jx7p", - "modified": "2023-03-24T15:30:21Z", + "modified": "2025-02-27T18:30:52Z", "published": "2023-03-19T03:30:25Z", "aliases": [ "CVE-2022-48424" diff --git a/advisories/unreviewed/2023/03/GHSA-v3fg-qxxf-34w3/GHSA-v3fg-qxxf-34w3.json b/advisories/unreviewed/2023/03/GHSA-v3fg-qxxf-34w3/GHSA-v3fg-qxxf-34w3.json index bd8b92b8265..4a02c7c453f 100644 --- a/advisories/unreviewed/2023/03/GHSA-v3fg-qxxf-34w3/GHSA-v3fg-qxxf-34w3.json +++ b/advisories/unreviewed/2023/03/GHSA-v3fg-qxxf-34w3/GHSA-v3fg-qxxf-34w3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v3fg-qxxf-34w3", - "modified": "2023-03-24T15:30:21Z", + "modified": "2025-02-27T18:30:52Z", "published": "2023-03-19T03:30:25Z", "aliases": [ "CVE-2022-48423" @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-3rqr-p9xj-863f/GHSA-3rqr-p9xj-863f.json b/advisories/unreviewed/2024/03/GHSA-3rqr-p9xj-863f/GHSA-3rqr-p9xj-863f.json index a486461ed40..98df875c884 100644 --- a/advisories/unreviewed/2024/03/GHSA-3rqr-p9xj-863f/GHSA-3rqr-p9xj-863f.json +++ b/advisories/unreviewed/2024/03/GHSA-3rqr-p9xj-863f/GHSA-3rqr-p9xj-863f.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-3rqr-p9xj-863f", - "modified": "2024-03-11T18:31:07Z", + "modified": "2025-02-27T18:30:53Z", "published": "2024-03-11T18:31:07Z", "aliases": [ "CVE-2024-23610" ], - "details": "An out of bounds write due to a missing bounds check in LabVIEW may result in remote code execution. Successful exploitation requires an attacker to provide a user with a specially crafted VI. This vulnerability affects LabVIEW 2024 Q1 and prior versions.\n\n\n", + "details": "An out of bounds write due to a missing bounds check in LabVIEW may result in remote code execution. Successful exploitation requires an attacker to provide a user with a specially crafted VI. This vulnerability affects LabVIEW 2024 Q1 and prior versions.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/03/GHSA-567q-hq5r-pw43/GHSA-567q-hq5r-pw43.json b/advisories/unreviewed/2024/03/GHSA-567q-hq5r-pw43/GHSA-567q-hq5r-pw43.json index 0cdea024c28..1923759ca0b 100644 --- a/advisories/unreviewed/2024/03/GHSA-567q-hq5r-pw43/GHSA-567q-hq5r-pw43.json +++ b/advisories/unreviewed/2024/03/GHSA-567q-hq5r-pw43/GHSA-567q-hq5r-pw43.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-567q-hq5r-pw43", - "modified": "2024-03-11T18:31:07Z", + "modified": "2025-02-27T18:30:53Z", "published": "2024-03-11T18:31:07Z", "aliases": [ "CVE-2024-23611" ], - "details": "An out of bounds write due to a missing bounds check in LabVIEW may result in remote code execution. Successful exploitation requires an attacker to provide a user with a specially crafted VI. This vulnerability affects LabVIEW 2024 Q1 and prior versions.\n\n", + "details": "An out of bounds write due to a missing bounds check in LabVIEW may result in remote code execution. Successful exploitation requires an attacker to provide a user with a specially crafted VI. This vulnerability affects LabVIEW 2024 Q1 and prior versions.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-24vg-8cmx-c7xr/GHSA-24vg-8cmx-c7xr.json b/advisories/unreviewed/2024/04/GHSA-24vg-8cmx-c7xr/GHSA-24vg-8cmx-c7xr.json index c5daaab4244..1f33b275801 100644 --- a/advisories/unreviewed/2024/04/GHSA-24vg-8cmx-c7xr/GHSA-24vg-8cmx-c7xr.json +++ b/advisories/unreviewed/2024/04/GHSA-24vg-8cmx-c7xr/GHSA-24vg-8cmx-c7xr.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-94" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-48jr-p93f-pwq8/GHSA-48jr-p93f-pwq8.json b/advisories/unreviewed/2024/04/GHSA-48jr-p93f-pwq8/GHSA-48jr-p93f-pwq8.json index 3aa7f06887a..328c12dd2ba 100644 --- a/advisories/unreviewed/2024/04/GHSA-48jr-p93f-pwq8/GHSA-48jr-p93f-pwq8.json +++ b/advisories/unreviewed/2024/04/GHSA-48jr-p93f-pwq8/GHSA-48jr-p93f-pwq8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-48jr-p93f-pwq8", - "modified": "2024-04-02T21:30:28Z", + "modified": "2025-02-27T18:30:53Z", "published": "2024-04-02T21:30:28Z", "aliases": [ "CVE-2024-27604" ], "details": "Alldata V0.4.6 is vulnerable to Command execution vulnerability. System commands can be deserialized.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-02T21:15:46Z" diff --git a/advisories/unreviewed/2024/04/GHSA-m9px-xr79-8fvc/GHSA-m9px-xr79-8fvc.json b/advisories/unreviewed/2024/04/GHSA-m9px-xr79-8fvc/GHSA-m9px-xr79-8fvc.json index b09a44c2bb6..5ef1ffda435 100644 --- a/advisories/unreviewed/2024/04/GHSA-m9px-xr79-8fvc/GHSA-m9px-xr79-8fvc.json +++ b/advisories/unreviewed/2024/04/GHSA-m9px-xr79-8fvc/GHSA-m9px-xr79-8fvc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-m9px-xr79-8fvc", - "modified": "2024-04-02T21:30:29Z", + "modified": "2025-02-27T18:30:54Z", "published": "2024-04-02T21:30:29Z", "aliases": [ "CVE-2024-27605" ], "details": "Alldata V0.4.6 is vulnerable to Insecure Permissions. Using users (test) can query information about the users in the system.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-02T21:15:46Z" diff --git a/advisories/unreviewed/2024/05/GHSA-6r8w-jhg7-gpr9/GHSA-6r8w-jhg7-gpr9.json b/advisories/unreviewed/2024/05/GHSA-6r8w-jhg7-gpr9/GHSA-6r8w-jhg7-gpr9.json index bcd2eeb7e8e..54608792be2 100644 --- a/advisories/unreviewed/2024/05/GHSA-6r8w-jhg7-gpr9/GHSA-6r8w-jhg7-gpr9.json +++ b/advisories/unreviewed/2024/05/GHSA-6r8w-jhg7-gpr9/GHSA-6r8w-jhg7-gpr9.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-96hm-xqc5-vqv9/GHSA-96hm-xqc5-vqv9.json b/advisories/unreviewed/2024/05/GHSA-96hm-xqc5-vqv9/GHSA-96hm-xqc5-vqv9.json index 5c00103aed5..531659a621b 100644 --- a/advisories/unreviewed/2024/05/GHSA-96hm-xqc5-vqv9/GHSA-96hm-xqc5-vqv9.json +++ b/advisories/unreviewed/2024/05/GHSA-96hm-xqc5-vqv9/GHSA-96hm-xqc5-vqv9.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-g5vh-4wvj-vgc9/GHSA-g5vh-4wvj-vgc9.json b/advisories/unreviewed/2024/05/GHSA-g5vh-4wvj-vgc9/GHSA-g5vh-4wvj-vgc9.json index a9c640a5683..ebb71482eec 100644 --- a/advisories/unreviewed/2024/05/GHSA-g5vh-4wvj-vgc9/GHSA-g5vh-4wvj-vgc9.json +++ b/advisories/unreviewed/2024/05/GHSA-g5vh-4wvj-vgc9/GHSA-g5vh-4wvj-vgc9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g5vh-4wvj-vgc9", - "modified": "2024-05-02T18:30:53Z", + "modified": "2025-02-27T18:30:56Z", "published": "2024-05-02T18:30:53Z", "aliases": [ "CVE-2024-2765" @@ -41,7 +41,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-pfc9-pj4x-5f23/GHSA-pfc9-pj4x-5f23.json b/advisories/unreviewed/2024/05/GHSA-pfc9-pj4x-5f23/GHSA-pfc9-pj4x-5f23.json index 617ae72b7e8..8f3d4b6e1b8 100644 --- a/advisories/unreviewed/2024/05/GHSA-pfc9-pj4x-5f23/GHSA-pfc9-pj4x-5f23.json +++ b/advisories/unreviewed/2024/05/GHSA-pfc9-pj4x-5f23/GHSA-pfc9-pj4x-5f23.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-94" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/12/GHSA-26m5-cv5f-4mwg/GHSA-26m5-cv5f-4mwg.json b/advisories/unreviewed/2024/12/GHSA-26m5-cv5f-4mwg/GHSA-26m5-cv5f-4mwg.json index 23bd3f68b6e..4989dbe496c 100644 --- a/advisories/unreviewed/2024/12/GHSA-26m5-cv5f-4mwg/GHSA-26m5-cv5f-4mwg.json +++ b/advisories/unreviewed/2024/12/GHSA-26m5-cv5f-4mwg/GHSA-26m5-cv5f-4mwg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-26m5-cv5f-4mwg", - "modified": "2024-12-05T15:31:02Z", + "modified": "2025-02-27T18:31:06Z", "published": "2024-12-05T15:31:02Z", "aliases": [ "CVE-2024-6516" diff --git a/advisories/unreviewed/2024/12/GHSA-4xvm-58x2-m87c/GHSA-4xvm-58x2-m87c.json b/advisories/unreviewed/2024/12/GHSA-4xvm-58x2-m87c/GHSA-4xvm-58x2-m87c.json index 7e1e4446fca..e8cd1119bd3 100644 --- a/advisories/unreviewed/2024/12/GHSA-4xvm-58x2-m87c/GHSA-4xvm-58x2-m87c.json +++ b/advisories/unreviewed/2024/12/GHSA-4xvm-58x2-m87c/GHSA-4xvm-58x2-m87c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4xvm-58x2-m87c", - "modified": "2024-12-05T15:31:02Z", + "modified": "2025-02-27T18:31:05Z", "published": "2024-12-05T15:31:02Z", "aliases": [ "CVE-2024-51551" @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-1287" + "CWE-1287", + "CWE-798" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-78pr-m5p7-52qj/GHSA-78pr-m5p7-52qj.json b/advisories/unreviewed/2024/12/GHSA-78pr-m5p7-52qj/GHSA-78pr-m5p7-52qj.json index 3dc6af0f865..b3a10818cab 100644 --- a/advisories/unreviewed/2024/12/GHSA-78pr-m5p7-52qj/GHSA-78pr-m5p7-52qj.json +++ b/advisories/unreviewed/2024/12/GHSA-78pr-m5p7-52qj/GHSA-78pr-m5p7-52qj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-78pr-m5p7-52qj", - "modified": "2024-12-05T15:31:02Z", + "modified": "2025-02-27T18:31:05Z", "published": "2024-12-05T15:31:02Z", "aliases": [ "CVE-2024-51550" diff --git a/advisories/unreviewed/2024/12/GHSA-7jf8-hmr2-f4xc/GHSA-7jf8-hmr2-f4xc.json b/advisories/unreviewed/2024/12/GHSA-7jf8-hmr2-f4xc/GHSA-7jf8-hmr2-f4xc.json index a2c1145556c..68ce7a2d4b1 100644 --- a/advisories/unreviewed/2024/12/GHSA-7jf8-hmr2-f4xc/GHSA-7jf8-hmr2-f4xc.json +++ b/advisories/unreviewed/2024/12/GHSA-7jf8-hmr2-f4xc/GHSA-7jf8-hmr2-f4xc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7jf8-hmr2-f4xc", - "modified": "2024-12-05T15:31:02Z", + "modified": "2025-02-27T18:31:02Z", "published": "2024-12-05T15:31:02Z", "aliases": [ "CVE-2024-51541" diff --git a/advisories/unreviewed/2024/12/GHSA-8297-wvjg-5vxg/GHSA-8297-wvjg-5vxg.json b/advisories/unreviewed/2024/12/GHSA-8297-wvjg-5vxg/GHSA-8297-wvjg-5vxg.json index dbc99279e4a..bd124b149a0 100644 --- a/advisories/unreviewed/2024/12/GHSA-8297-wvjg-5vxg/GHSA-8297-wvjg-5vxg.json +++ b/advisories/unreviewed/2024/12/GHSA-8297-wvjg-5vxg/GHSA-8297-wvjg-5vxg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8297-wvjg-5vxg", - "modified": "2024-12-05T15:31:01Z", + "modified": "2025-02-27T18:31:00Z", "published": "2024-12-05T15:31:01Z", "aliases": [ "CVE-2024-48845" diff --git a/advisories/unreviewed/2024/12/GHSA-8r6w-mfx6-6726/GHSA-8r6w-mfx6-6726.json b/advisories/unreviewed/2024/12/GHSA-8r6w-mfx6-6726/GHSA-8r6w-mfx6-6726.json index 32818e3b6ed..e215aa19935 100644 --- a/advisories/unreviewed/2024/12/GHSA-8r6w-mfx6-6726/GHSA-8r6w-mfx6-6726.json +++ b/advisories/unreviewed/2024/12/GHSA-8r6w-mfx6-6726/GHSA-8r6w-mfx6-6726.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8r6w-mfx6-6726", - "modified": "2024-12-05T15:31:01Z", + "modified": "2025-02-27T18:31:00Z", "published": "2024-12-05T15:31:01Z", "aliases": [ "CVE-2024-48844" diff --git a/advisories/unreviewed/2024/12/GHSA-99ww-c378-6m65/GHSA-99ww-c378-6m65.json b/advisories/unreviewed/2024/12/GHSA-99ww-c378-6m65/GHSA-99ww-c378-6m65.json index 851d463219a..45902498fe5 100644 --- a/advisories/unreviewed/2024/12/GHSA-99ww-c378-6m65/GHSA-99ww-c378-6m65.json +++ b/advisories/unreviewed/2024/12/GHSA-99ww-c378-6m65/GHSA-99ww-c378-6m65.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-99ww-c378-6m65", - "modified": "2024-12-05T15:31:02Z", + "modified": "2025-02-27T18:31:03Z", "published": "2024-12-05T15:31:02Z", "aliases": [ "CVE-2024-51546" @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-1287" + "CWE-1287", + "CWE-522" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-9w62-9ghr-p98m/GHSA-9w62-9ghr-p98m.json b/advisories/unreviewed/2024/12/GHSA-9w62-9ghr-p98m/GHSA-9w62-9ghr-p98m.json index 926d4a8d36b..407c03bf145 100644 --- a/advisories/unreviewed/2024/12/GHSA-9w62-9ghr-p98m/GHSA-9w62-9ghr-p98m.json +++ b/advisories/unreviewed/2024/12/GHSA-9w62-9ghr-p98m/GHSA-9w62-9ghr-p98m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9w62-9ghr-p98m", - "modified": "2024-12-05T15:31:02Z", + "modified": "2025-02-27T18:31:03Z", "published": "2024-12-05T15:31:02Z", "aliases": [ "CVE-2024-51548" diff --git a/advisories/unreviewed/2024/12/GHSA-c3m5-p52q-pvhf/GHSA-c3m5-p52q-pvhf.json b/advisories/unreviewed/2024/12/GHSA-c3m5-p52q-pvhf/GHSA-c3m5-p52q-pvhf.json index 6d89274c906..2d8f2dffb10 100644 --- a/advisories/unreviewed/2024/12/GHSA-c3m5-p52q-pvhf/GHSA-c3m5-p52q-pvhf.json +++ b/advisories/unreviewed/2024/12/GHSA-c3m5-p52q-pvhf/GHSA-c3m5-p52q-pvhf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c3m5-p52q-pvhf", - "modified": "2024-12-05T15:31:02Z", + "modified": "2025-02-27T18:31:04Z", "published": "2024-12-05T15:31:02Z", "aliases": [ "CVE-2024-51549" @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-36" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2024/12/GHSA-p4vp-3hqc-mfgr/GHSA-p4vp-3hqc-mfgr.json b/advisories/unreviewed/2024/12/GHSA-p4vp-3hqc-mfgr/GHSA-p4vp-3hqc-mfgr.json index 830787f47c5..5d0b01ccee3 100644 --- a/advisories/unreviewed/2024/12/GHSA-p4vp-3hqc-mfgr/GHSA-p4vp-3hqc-mfgr.json +++ b/advisories/unreviewed/2024/12/GHSA-p4vp-3hqc-mfgr/GHSA-p4vp-3hqc-mfgr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p4vp-3hqc-mfgr", - "modified": "2024-12-05T15:31:02Z", + "modified": "2025-02-27T18:31:02Z", "published": "2024-12-05T15:31:02Z", "aliases": [ "CVE-2024-51543" diff --git a/advisories/unreviewed/2024/12/GHSA-px35-m227-24jv/GHSA-px35-m227-24jv.json b/advisories/unreviewed/2024/12/GHSA-px35-m227-24jv/GHSA-px35-m227-24jv.json index 96684ec4cd9..4385190cdca 100644 --- a/advisories/unreviewed/2024/12/GHSA-px35-m227-24jv/GHSA-px35-m227-24jv.json +++ b/advisories/unreviewed/2024/12/GHSA-px35-m227-24jv/GHSA-px35-m227-24jv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-px35-m227-24jv", - "modified": "2024-12-05T15:31:02Z", + "modified": "2025-02-27T18:31:03Z", "published": "2024-12-05T15:31:02Z", "aliases": [ "CVE-2024-51545" diff --git a/advisories/unreviewed/2024/12/GHSA-r8wg-fm7g-x3vf/GHSA-r8wg-fm7g-x3vf.json b/advisories/unreviewed/2024/12/GHSA-r8wg-fm7g-x3vf/GHSA-r8wg-fm7g-x3vf.json index ccafac1ae59..54a67fb0e53 100644 --- a/advisories/unreviewed/2024/12/GHSA-r8wg-fm7g-x3vf/GHSA-r8wg-fm7g-x3vf.json +++ b/advisories/unreviewed/2024/12/GHSA-r8wg-fm7g-x3vf/GHSA-r8wg-fm7g-x3vf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r8wg-fm7g-x3vf", - "modified": "2024-12-05T15:31:01Z", + "modified": "2025-02-27T18:30:59Z", "published": "2024-12-05T15:31:01Z", "aliases": [ "CVE-2024-48840" diff --git a/advisories/unreviewed/2024/12/GHSA-rff8-7ph7-xchr/GHSA-rff8-7ph7-xchr.json b/advisories/unreviewed/2024/12/GHSA-rff8-7ph7-xchr/GHSA-rff8-7ph7-xchr.json index e20896e03aa..a9d72dc2586 100644 --- a/advisories/unreviewed/2024/12/GHSA-rff8-7ph7-xchr/GHSA-rff8-7ph7-xchr.json +++ b/advisories/unreviewed/2024/12/GHSA-rff8-7ph7-xchr/GHSA-rff8-7ph7-xchr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rff8-7ph7-xchr", - "modified": "2024-12-05T15:31:01Z", + "modified": "2025-02-27T18:31:02Z", "published": "2024-12-05T15:31:01Z", "aliases": [ "CVE-2024-48847" @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-327", "CWE-328" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/12/GHSA-rgc4-v4cj-59q2/GHSA-rgc4-v4cj-59q2.json b/advisories/unreviewed/2024/12/GHSA-rgc4-v4cj-59q2/GHSA-rgc4-v4cj-59q2.json index 11de10da493..67eefe6b3c0 100644 --- a/advisories/unreviewed/2024/12/GHSA-rgc4-v4cj-59q2/GHSA-rgc4-v4cj-59q2.json +++ b/advisories/unreviewed/2024/12/GHSA-rgc4-v4cj-59q2/GHSA-rgc4-v4cj-59q2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rgc4-v4cj-59q2", - "modified": "2024-12-05T15:31:01Z", + "modified": "2025-02-27T18:31:01Z", "published": "2024-12-05T15:31:01Z", "aliases": [ "CVE-2024-48846" diff --git a/advisories/unreviewed/2024/12/GHSA-w8wv-xphh-4948/GHSA-w8wv-xphh-4948.json b/advisories/unreviewed/2024/12/GHSA-w8wv-xphh-4948/GHSA-w8wv-xphh-4948.json index 21a18ce05dc..5bcfacbd08d 100644 --- a/advisories/unreviewed/2024/12/GHSA-w8wv-xphh-4948/GHSA-w8wv-xphh-4948.json +++ b/advisories/unreviewed/2024/12/GHSA-w8wv-xphh-4948/GHSA-w8wv-xphh-4948.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w8wv-xphh-4948", - "modified": "2024-12-05T15:31:02Z", + "modified": "2025-02-27T18:31:06Z", "published": "2024-12-05T15:31:02Z", "aliases": [ "CVE-2024-6515" diff --git a/advisories/unreviewed/2024/12/GHSA-wq8m-87w7-34w5/GHSA-wq8m-87w7-34w5.json b/advisories/unreviewed/2024/12/GHSA-wq8m-87w7-34w5/GHSA-wq8m-87w7-34w5.json index 4fbbefb35b3..b3454887754 100644 --- a/advisories/unreviewed/2024/12/GHSA-wq8m-87w7-34w5/GHSA-wq8m-87w7-34w5.json +++ b/advisories/unreviewed/2024/12/GHSA-wq8m-87w7-34w5/GHSA-wq8m-87w7-34w5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wq8m-87w7-34w5", - "modified": "2024-12-05T15:31:01Z", + "modified": "2025-02-27T18:31:00Z", "published": "2024-12-05T15:31:01Z", "aliases": [ "CVE-2024-48843" @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-770" + "CWE-770", + "CWE-89" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-xj26-gx3h-x793/GHSA-xj26-gx3h-x793.json b/advisories/unreviewed/2024/12/GHSA-xj26-gx3h-x793/GHSA-xj26-gx3h-x793.json index 9cc4f05ccf8..379233a3061 100644 --- a/advisories/unreviewed/2024/12/GHSA-xj26-gx3h-x793/GHSA-xj26-gx3h-x793.json +++ b/advisories/unreviewed/2024/12/GHSA-xj26-gx3h-x793/GHSA-xj26-gx3h-x793.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xj26-gx3h-x793", - "modified": "2024-12-05T15:31:02Z", + "modified": "2025-02-27T18:31:06Z", "published": "2024-12-05T15:31:02Z", "aliases": [ "CVE-2024-51554" diff --git a/advisories/unreviewed/2025/02/GHSA-25hc-2p68-qc2g/GHSA-25hc-2p68-qc2g.json b/advisories/unreviewed/2025/02/GHSA-25hc-2p68-qc2g/GHSA-25hc-2p68-qc2g.json new file mode 100644 index 00000000000..dbaaaaafc3b --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-25hc-2p68-qc2g/GHSA-25hc-2p68-qc2g.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-25hc-2p68-qc2g", + "modified": "2025-02-27T18:31:12Z", + "published": "2025-02-27T18:31:12Z", + "aliases": [ + "CVE-2025-1755" + ], + "details": "MongoDB Compass may be susceptible to local privilege escalation under certain conditions potentially enabling unauthorized actions on a user's system with elevated privileges, when a crafted file is stored in C:\\node_modules\\. This issue affects MongoDB Compass prior to 1.42.1", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1755" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:1755.html" + }, + { + "type": "WEB", + "url": "https://jira.mongodb.org/browse/COMPASS-9058" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-426" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-27T16:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-2qfv-5w3v-jvfv/GHSA-2qfv-5w3v-jvfv.json b/advisories/unreviewed/2025/02/GHSA-2qfv-5w3v-jvfv/GHSA-2qfv-5w3v-jvfv.json index daa0cfedcb4..d1ca495067d 100644 --- a/advisories/unreviewed/2025/02/GHSA-2qfv-5w3v-jvfv/GHSA-2qfv-5w3v-jvfv.json +++ b/advisories/unreviewed/2025/02/GHSA-2qfv-5w3v-jvfv/GHSA-2qfv-5w3v-jvfv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2qfv-5w3v-jvfv", - "modified": "2025-02-27T03:34:02Z", + "modified": "2025-02-27T18:31:10Z", "published": "2025-02-27T03:34:02Z", "aliases": [ "CVE-2025-21731" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnbd: don't allow reconnect after disconnect\n\nFollowing process can cause nbd_config UAF:\n\n1) grab nbd_config temporarily;\n\n2) nbd_genl_disconnect() flush all recv_work() and release the\ninitial reference:\n\n nbd_genl_disconnect\n nbd_disconnect_and_put\n nbd_disconnect\n flush_workqueue(nbd->recv_workq)\n if (test_and_clear_bit(NBD_RT_HAS_CONFIG_REF, ...))\n nbd_config_put\n -> due to step 1), reference is still not zero\n\n3) nbd_genl_reconfigure() queue recv_work() again;\n\n nbd_genl_reconfigure\n config = nbd_get_config_unlocked(nbd)\n if (!config)\n -> succeed\n if (!test_bit(NBD_RT_BOUND, ...))\n -> succeed\n nbd_reconnect_socket\n queue_work(nbd->recv_workq, &args->work)\n\n4) step 1) release the reference;\n\n5) Finially, recv_work() will trigger UAF:\n\n recv_work\n nbd_config_put(nbd)\n -> nbd_config is freed\n atomic_dec(&config->recv_threads)\n -> UAF\n\nFix the problem by clearing NBD_RT_BOUND in nbd_genl_disconnect(), so\nthat nbd_genl_reconfigure() will fail.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-27T02:15:16Z" diff --git a/advisories/unreviewed/2025/02/GHSA-3q7x-q7fm-whrm/GHSA-3q7x-q7fm-whrm.json b/advisories/unreviewed/2025/02/GHSA-3q7x-q7fm-whrm/GHSA-3q7x-q7fm-whrm.json new file mode 100644 index 00000000000..56594f1a876 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-3q7x-q7fm-whrm/GHSA-3q7x-q7fm-whrm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3q7x-q7fm-whrm", + "modified": "2025-02-27T18:31:12Z", + "published": "2025-02-27T18:31:12Z", + "aliases": [ + "CVE-2025-0914" + ], + "details": "An improper access control issue in the VQL shell feature in Velociraptor Versions < 0.73.4 allowed authenticated users to execute the execve() plugin in deployments where this was explicitly forbidden by configuring the prevent_execve flag in the configuration file. This setting is not usually recommended and is uncommonly used, so this issue will only affect users who do set it. This issue is fixed in release 0.73.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0914" + }, + { + "type": "WEB", + "url": "https://docs.velociraptor.app/announcements/advisories/cve-2025-0914" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-281" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-27T16:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-3vhc-4mgh-2vvp/GHSA-3vhc-4mgh-2vvp.json b/advisories/unreviewed/2025/02/GHSA-3vhc-4mgh-2vvp/GHSA-3vhc-4mgh-2vvp.json index 5377ef27b79..36a03c4bb0c 100644 --- a/advisories/unreviewed/2025/02/GHSA-3vhc-4mgh-2vvp/GHSA-3vhc-4mgh-2vvp.json +++ b/advisories/unreviewed/2025/02/GHSA-3vhc-4mgh-2vvp/GHSA-3vhc-4mgh-2vvp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3vhc-4mgh-2vvp", - "modified": "2025-02-27T03:34:05Z", + "modified": "2025-02-27T18:31:11Z", "published": "2025-02-27T03:34:05Z", "aliases": [ "CVE-2025-21762" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\narp: use RCU protection in arp_xmit()\n\narp_xmit() can be called without RTNL or RCU protection.\n\nUse RCU protection to avoid potential UAF.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-27T03:15:16Z" diff --git a/advisories/unreviewed/2025/02/GHSA-422g-php3-xrv4/GHSA-422g-php3-xrv4.json b/advisories/unreviewed/2025/02/GHSA-422g-php3-xrv4/GHSA-422g-php3-xrv4.json new file mode 100644 index 00000000000..72dbab1b8fd --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-422g-php3-xrv4/GHSA-422g-php3-xrv4.json @@ -0,0 +1,64 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-422g-php3-xrv4", + "modified": "2025-02-27T18:31:08Z", + "published": "2025-02-27T18:31:08Z", + "aliases": [ + "CVE-2022-49388" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nubi: ubi_create_volume: Fix use-after-free when volume creation failed\n\nThere is an use-after-free problem for 'eba_tbl' in ubi_create_volume()'s\nerror handling path:\n\n ubi_eba_replace_table(vol, eba_tbl)\n vol->eba_tbl = tbl\nout_mapping:\n ubi_eba_destroy_table(eba_tbl) // Free 'eba_tbl'\nout_unlock:\n put_device(&vol->dev)\n vol_release\n kfree(tbl->entries)\t // UAF\n\nFix it by removing redundant 'eba_tbl' releasing.\nFetch a reproducer in [Link].", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49388" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1174ab8ba36a48025b68b5ff1085000b1e510217" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/25ff1e3a1351c0d936dd1ac2f9e58231ea1510c9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5ff2514e4fb55dcf3d88294686040ca73ea0c1a2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6d8d3f68cbecfd31925796f0fb668eb21ab06734" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8302620aeb940f386817321d272b12411ae7d39f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8c03a1c21d72210f81cb369cc528e3fde4b45411" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/abb67043060f2bf4c03d7c3debb9ae980e2b6db3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e27ecf325e51abd06aaefba57a6322a46fa4178b" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-45c3-pwch-8qg9/GHSA-45c3-pwch-8qg9.json b/advisories/unreviewed/2025/02/GHSA-45c3-pwch-8qg9/GHSA-45c3-pwch-8qg9.json new file mode 100644 index 00000000000..61ea25a3f5f --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-45c3-pwch-8qg9/GHSA-45c3-pwch-8qg9.json @@ -0,0 +1,64 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-45c3-pwch-8qg9", + "modified": "2025-02-27T18:31:08Z", + "published": "2025-02-27T18:31:08Z", + "aliases": [ + "CVE-2022-49291" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: pcm: Fix races among concurrent hw_params and hw_free calls\n\nCurrently we have neither proper check nor protection against the\nconcurrent calls of PCM hw_params and hw_free ioctls, which may result\nin a UAF. Since the existing PCM stream lock can't be used for\nprotecting the whole ioctl operations, we need a new mutex to protect\nthose racy calls.\n\nThis patch introduced a new mutex, runtime->buffer_mutex, and applies\nit to both hw_params and hw_free ioctl code paths. Along with it, the\nboth functions are slightly modified (the mmap_count check is moved\ninto the state-check block) for code simplicity.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49291" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0090c13cbbdffd7da079ac56f80373a9a1be0bf8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0f6947f5f5208f6ebd4d76a82a4757e2839a23f8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1bbf82d9f961414d6c76a08f7f843ea068e0ab7b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/33061d0fba51d2bf70a2ef9645f703c33fe8e438" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/92ee3c60ec9fe64404dc035e7c41277d74aa26cb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9cb6c40a6ebe4a0cfc9d6a181958211682cffea9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a42aa926843acca96c0dfbde2e835b8137f2f092" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fbeb492694ce0441053de57699e1e2b7bc148a69" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-4gxw-5w55-6f5h/GHSA-4gxw-5w55-6f5h.json b/advisories/unreviewed/2025/02/GHSA-4gxw-5w55-6f5h/GHSA-4gxw-5w55-6f5h.json index 4ef453db94f..8209fa2f97b 100644 --- a/advisories/unreviewed/2025/02/GHSA-4gxw-5w55-6f5h/GHSA-4gxw-5w55-6f5h.json +++ b/advisories/unreviewed/2025/02/GHSA-4gxw-5w55-6f5h/GHSA-4gxw-5w55-6f5h.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4gxw-5w55-6f5h", - "modified": "2025-02-27T03:34:02Z", + "modified": "2025-02-27T18:31:09Z", "published": "2025-02-27T03:34:02Z", "aliases": [ "CVE-2025-21726" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\npadata: avoid UAF for reorder_work\n\nAlthough the previous patch can avoid ps and ps UAF for _do_serial, it\ncan not avoid potential UAF issue for reorder_work. This issue can\nhappen just as below:\n\ncrypto_request\t\t\tcrypto_request\t\tcrypto_del_alg\npadata_do_serial\n ...\n padata_reorder\n // processes all remaining\n // requests then breaks\n while (1) {\n if (!padata)\n break;\n ...\n }\n\n\t\t\t\tpadata_do_serial\n\t\t\t\t // new request added\n\t\t\t\t list_add\n // sees the new request\n queue_work(reorder_work)\n\t\t\t\t padata_reorder\n\t\t\t\t queue_work_on(squeue->work)\n...\n\n\t\t\t\t\n\t\t\t\tpadata_serial_worker\n\t\t\t\t// completes new request,\n\t\t\t\t// no more outstanding\n\t\t\t\t// requests\n\n\t\t\t\t\t\t\tcrypto_del_alg\n\t\t\t\t\t\t\t // free pd\n\n\ninvoke_padata_reorder\n // UAF of pd\n\nTo avoid UAF for 'reorder_work', get 'pd' ref before put 'reorder_work'\ninto the 'serial_wq' and put 'pd' ref until the 'serial_wq' finish.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-27T02:15:16Z" diff --git a/advisories/unreviewed/2025/02/GHSA-4mx7-h455-mwxv/GHSA-4mx7-h455-mwxv.json b/advisories/unreviewed/2025/02/GHSA-4mx7-h455-mwxv/GHSA-4mx7-h455-mwxv.json new file mode 100644 index 00000000000..ce3487e0981 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-4mx7-h455-mwxv/GHSA-4mx7-h455-mwxv.json @@ -0,0 +1,68 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4mx7-h455-mwxv", + "modified": "2025-02-27T18:31:07Z", + "published": "2025-02-27T18:31:07Z", + "aliases": [ + "CVE-2021-47656" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\njffs2: fix use-after-free in jffs2_clear_xattr_subsystem\n\nWhen we mount a jffs2 image, assume that the first few blocks of\nthe image are normal and contain at least one xattr-related inode,\nbut the next block is abnormal. As a result, an error is returned\nin jffs2_scan_eraseblock(). jffs2_clear_xattr_subsystem() is then\ncalled in jffs2_build_filesystem() and then again in\njffs2_do_fill_super().\n\nFinally we can observe the following report:\n ==================================================================\n BUG: KASAN: use-after-free in jffs2_clear_xattr_subsystem+0x95/0x6ac\n Read of size 8 at addr ffff8881243384e0 by task mount/719\n\n Call Trace:\n dump_stack+0x115/0x16b\n jffs2_clear_xattr_subsystem+0x95/0x6ac\n jffs2_do_fill_super+0x84f/0xc30\n jffs2_fill_super+0x2ea/0x4c0\n mtd_get_sb+0x254/0x400\n mtd_get_sb_by_nr+0x4f/0xd0\n get_tree_mtd+0x498/0x840\n jffs2_get_tree+0x25/0x30\n vfs_get_tree+0x8d/0x2e0\n path_mount+0x50f/0x1e50\n do_mount+0x107/0x130\n __se_sys_mount+0x1c5/0x2f0\n __x64_sys_mount+0xc7/0x160\n do_syscall_64+0x45/0x70\n entry_SYSCALL_64_after_hwframe+0x44/0xa9\n\n Allocated by task 719:\n kasan_save_stack+0x23/0x60\n __kasan_kmalloc.constprop.0+0x10b/0x120\n kasan_slab_alloc+0x12/0x20\n kmem_cache_alloc+0x1c0/0x870\n jffs2_alloc_xattr_ref+0x2f/0xa0\n jffs2_scan_medium.cold+0x3713/0x4794\n jffs2_do_mount_fs.cold+0xa7/0x2253\n jffs2_do_fill_super+0x383/0xc30\n jffs2_fill_super+0x2ea/0x4c0\n [...]\n\n Freed by task 719:\n kmem_cache_free+0xcc/0x7b0\n jffs2_free_xattr_ref+0x78/0x98\n jffs2_clear_xattr_subsystem+0xa1/0x6ac\n jffs2_do_mount_fs.cold+0x5e6/0x2253\n jffs2_do_fill_super+0x383/0xc30\n jffs2_fill_super+0x2ea/0x4c0\n [...]\n\n The buggy address belongs to the object at ffff8881243384b8\n which belongs to the cache jffs2_xattr_ref of size 48\n The buggy address is located 40 bytes inside of\n 48-byte region [ffff8881243384b8, ffff8881243384e8)\n [...]\n ==================================================================\n\nThe triggering of the BUG is shown in the following stack:\n-----------------------------------------------------------\njffs2_fill_super\n jffs2_do_fill_super\n jffs2_do_mount_fs\n jffs2_build_filesystem\n jffs2_scan_medium\n jffs2_scan_eraseblock <--- ERROR\n jffs2_clear_xattr_subsystem <--- free\n jffs2_clear_xattr_subsystem <--- free again\n-----------------------------------------------------------\n\nAn error is returned in jffs2_do_mount_fs(). If the error is returned\nby jffs2_sum_init(), the jffs2_clear_xattr_subsystem() does not need to\nbe executed. If the error is returned by jffs2_build_filesystem(), the\njffs2_clear_xattr_subsystem() also does not need to be executed again.\nSo move jffs2_clear_xattr_subsystem() from 'out_inohash' to 'out_root'\nto fix this UAF problem.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47656" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/22327bd7988f21de3a53c1373f3b81542bfe1f44" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/30bf7244acf32f19cb722c39f7bc1c2a9f300422" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3bd2454162ec6bbb5503233c804fce6e4b6dcec5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4c7c44ee1650677fbe89d86edbad9497b7679b5c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7a75740206af5f17e9f3efa384211cba70213da1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7bb7428dd73991bf4b3a7a61b493ca50046c2b13" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8c0f024f29e055840a5a89fe23b96ae3f921afed" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9150cb625b46f68d524f4cfd491f1aafc23e10a9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c3b07c875fa8f906f932976460fd14798596f101" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T06:37:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-5f34-xwxq-mm2x/GHSA-5f34-xwxq-mm2x.json b/advisories/unreviewed/2025/02/GHSA-5f34-xwxq-mm2x/GHSA-5f34-xwxq-mm2x.json new file mode 100644 index 00000000000..740e79bd411 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-5f34-xwxq-mm2x/GHSA-5f34-xwxq-mm2x.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5f34-xwxq-mm2x", + "modified": "2025-02-27T18:31:07Z", + "published": "2025-02-27T18:31:07Z", + "aliases": [ + "CVE-2022-49047" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nep93xx: clock: Fix UAF in ep93xx_clk_register_gate()\n\narch/arm/mach-ep93xx/clock.c:154:2: warning: Use of memory after it is freed [clang-analyzer-unix.Malloc]\narch/arm/mach-ep93xx/clock.c:151:2: note: Taking true branch\nif (IS_ERR(clk))\n^\narch/arm/mach-ep93xx/clock.c:152:3: note: Memory is released\nkfree(psc);\n^~~~~~~~~~\narch/arm/mach-ep93xx/clock.c:154:2: note: Use of memory after it is freed\nreturn &psc->hw;\n^ ~~~~~~~~", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49047" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0f12166872da46c6b57ba2f1314bbf310b3bf017" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3b68b08885217abd9c57ff9b3bb3eb173eee02a9" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:00:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-5mhv-g6m4-pmp4/GHSA-5mhv-g6m4-pmp4.json b/advisories/unreviewed/2025/02/GHSA-5mhv-g6m4-pmp4/GHSA-5mhv-g6m4-pmp4.json new file mode 100644 index 00000000000..d981bfb58a4 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-5mhv-g6m4-pmp4/GHSA-5mhv-g6m4-pmp4.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5mhv-g6m4-pmp4", + "modified": "2025-02-27T18:31:09Z", + "published": "2025-02-27T18:31:08Z", + "aliases": [ + "CVE-2022-49385" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndriver: base: fix UAF when driver_attach failed\n\nWhen driver_attach(drv); failed, the driver_private will be freed.\nBut it has been added to the bus, which caused a UAF.\n\nTo fix it, we need to delete it from the bus when failed.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49385" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/310862e574001a97ad02272bac0fd13f75f42a27" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5389101257828d1913d713d9a40acbe14f5961df" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5d709f58c743166fe1c6914b9de0ae8868600d9b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/823f24f2e329babd0330200d0b74882516fe57f4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c059665c84feab46b7173d3a1bf36c2fb7f9df86" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cdf1a683a01583bca4b618dd16223cbd6e462e21" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-5mwf-pvj7-8qj6/GHSA-5mwf-pvj7-8qj6.json b/advisories/unreviewed/2025/02/GHSA-5mwf-pvj7-8qj6/GHSA-5mwf-pvj7-8qj6.json new file mode 100644 index 00000000000..737f3a98906 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-5mwf-pvj7-8qj6/GHSA-5mwf-pvj7-8qj6.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5mwf-pvj7-8qj6", + "modified": "2025-02-27T18:31:14Z", + "published": "2025-02-27T18:31:14Z", + "aliases": [ + "CVE-2025-25331" + ], + "details": "An issue in Beitatong Technology LianJia iOS 9.83.50 allows attackers to access sensitive user information via supplying a crafted link.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25331" + }, + { + "type": "WEB", + "url": "https://github.com/ZhouZiyi1/Vuls/blob/main/250116-LianJia/250116-LianJia.pdf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-27T16:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-65hc-mhvg-x697/GHSA-65hc-mhvg-x697.json b/advisories/unreviewed/2025/02/GHSA-65hc-mhvg-x697/GHSA-65hc-mhvg-x697.json new file mode 100644 index 00000000000..a5b31a1994e --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-65hc-mhvg-x697/GHSA-65hc-mhvg-x697.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-65hc-mhvg-x697", + "modified": "2025-02-27T18:31:14Z", + "published": "2025-02-27T18:31:14Z", + "aliases": [ + "CVE-2025-25330" + ], + "details": "An issue in Boohee Technology Boohee Health iOS 13.0.13 allows attackers to access sensitive user information via supplying a crafted link.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25330" + }, + { + "type": "WEB", + "url": "https://github.com/ZhouZiyi1/Vuls/blob/main/250116-BooheeHealth/250116-BooheeHealth.pdf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-27T16:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-75q5-6x22-qjpw/GHSA-75q5-6x22-qjpw.json b/advisories/unreviewed/2025/02/GHSA-75q5-6x22-qjpw/GHSA-75q5-6x22-qjpw.json new file mode 100644 index 00000000000..ce7d63a307d --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-75q5-6x22-qjpw/GHSA-75q5-6x22-qjpw.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-75q5-6x22-qjpw", + "modified": "2025-02-27T18:31:08Z", + "published": "2025-02-27T18:31:08Z", + "aliases": [ + "CVE-2022-49258" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: ccree - Fix use after free in cc_cipher_exit()\n\nkfree_sensitive(ctx_p->user.key) will free the ctx_p->user.key. But\nctx_p->user.key is still used in the next line, which will lead to a\nuse after free.\n\nWe can call kfree_sensitive() after dev_dbg() to avoid the uaf.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49258" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/25c358efee5153dfd240d4e0d3169d5bebe9cacd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/335bf1fc74f775a8255257aa3e33763f2257b676" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3d950c34074ed74d2713c3856ba01264523289e6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c93017c8d5ebf55a4e453ac7c84cc84cf92ab570" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cffb5382bd8d3cf21b874ab5b84bf7618932286b" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-798h-hm78-q979/GHSA-798h-hm78-q979.json b/advisories/unreviewed/2025/02/GHSA-798h-hm78-q979/GHSA-798h-hm78-q979.json index cf598d6ae18..eacb5afc889 100644 --- a/advisories/unreviewed/2025/02/GHSA-798h-hm78-q979/GHSA-798h-hm78-q979.json +++ b/advisories/unreviewed/2025/02/GHSA-798h-hm78-q979/GHSA-798h-hm78-q979.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-798h-hm78-q979", - "modified": "2025-02-27T03:34:05Z", + "modified": "2025-02-27T18:31:11Z", "published": "2025-02-27T03:34:05Z", "aliases": [ "CVE-2025-21763" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nneighbour: use RCU protection in __neigh_notify()\n\n__neigh_notify() can be called without RTNL or RCU protection.\n\nUse RCU protection to avoid potential UAF.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-27T03:15:16Z" diff --git a/advisories/unreviewed/2025/02/GHSA-87qr-3hp3-x583/GHSA-87qr-3hp3-x583.json b/advisories/unreviewed/2025/02/GHSA-87qr-3hp3-x583/GHSA-87qr-3hp3-x583.json new file mode 100644 index 00000000000..f3f420be5ca --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-87qr-3hp3-x583/GHSA-87qr-3hp3-x583.json @@ -0,0 +1,64 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-87qr-3hp3-x583", + "modified": "2025-02-27T18:31:08Z", + "published": "2025-02-27T18:31:08Z", + "aliases": [ + "CVE-2022-49288" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: pcm: Fix races among concurrent prealloc proc writes\n\nWe have no protection against concurrent PCM buffer preallocation\nchanges via proc files, and it may potentially lead to UAF or some\nweird problem. This patch applies the PCM open_mutex to the proc\nwrite operation for avoiding the racy proc writes and the PCM stream\nopen (and further operations).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49288" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/37b12c16beb6f6c1c3c678c1aacbc46525c250f7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/51fce708ab8986a9879ee5da946a2cc120f1036d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5ed8f8e3c4e59d0396b9ccf2e639711e24295bb6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/69534c48ba8ce552ce383b3dfdb271ffe51820c3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a21d2f323b5a978dedf9ff1d50f101f85e39b3f2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b560d670c87d7d40b3cf6949246fa4c7aa65a00a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e14dca613e0a6ddc2bf6e360f16936a9f865205b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e7786c445bb67a9a6e64f66ebd6b7215b153ff7d" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-8gcm-9r6g-8j3f/GHSA-8gcm-9r6g-8j3f.json b/advisories/unreviewed/2025/02/GHSA-8gcm-9r6g-8j3f/GHSA-8gcm-9r6g-8j3f.json new file mode 100644 index 00000000000..e082e501e29 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-8gcm-9r6g-8j3f/GHSA-8gcm-9r6g-8j3f.json @@ -0,0 +1,64 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8gcm-9r6g-8j3f", + "modified": "2025-02-27T18:31:12Z", + "published": "2025-02-27T18:31:12Z", + "aliases": [ + "CVE-2025-1741" + ], + "details": "A vulnerability classified as problematic was found in b1gMail up to 7.4.1-pl1. Affected by this vulnerability is an unknown functionality of the file src/admin/users.php of the component Admin Page. The manipulation of the argument query/q leads to deserialization. The attack can be launched remotely. Upgrading to version 7.4.1-pl2 is able to address this issue. The identifier of the patch is 4816c8b748f6a5b965c8994e2cf10861bf6e68aa. It is recommended to upgrade the affected component. The vendor acted highly professional and even fixed this issue in the discontinued commercial edition as b1gMail 7.4.0-pl3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1741" + }, + { + "type": "WEB", + "url": "https://github.com/b1gMail-OSS/b1gMail/commit/4816c8b748f6a5b965c8994e2cf10861bf6e68aa" + }, + { + "type": "WEB", + "url": "https://gist.github.com/mcdruid/cb0b848c12fd6a6bc0c1b3357b983d30" + }, + { + "type": "WEB", + "url": "https://github.com/b1gMail-OSS/b1gMail/releases/tag/7.4.1-pl2" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.297829" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.297829" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.505838" + }, + { + "type": "WEB", + "url": "https://www.b1gmail.eu/forum/thread/217-security-update-to-b1gmail-7-4-1-released" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-27T16:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-8qgg-vj9j-hh4r/GHSA-8qgg-vj9j-hh4r.json b/advisories/unreviewed/2025/02/GHSA-8qgg-vj9j-hh4r/GHSA-8qgg-vj9j-hh4r.json new file mode 100644 index 00000000000..d91f6cc81c5 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-8qgg-vj9j-hh4r/GHSA-8qgg-vj9j-hh4r.json @@ -0,0 +1,60 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8qgg-vj9j-hh4r", + "modified": "2025-02-27T18:31:07Z", + "published": "2025-02-27T18:31:07Z", + "aliases": [ + "CVE-2021-47646" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRevert \"Revert \"block, bfq: honor already-setup queue merges\"\"\n\nA crash [1] happened to be triggered in conjunction with commit\n2d52c58b9c9b (\"block, bfq: honor already-setup queue merges\"). The\nlatter was then reverted by commit ebc69e897e17 (\"Revert \"block, bfq:\nhonor already-setup queue merges\"\"). Yet, the reverted commit was not\nthe one introducing the bug. In fact, it actually triggered a UAF\nintroduced by a different commit, and now fixed by commit d29bd41428cf\n(\"block, bfq: reset last_bfqq_created on group change\").\n\nSo, there is no point in keeping commit 2d52c58b9c9b (\"block, bfq:\nhonor already-setup queue merges\") out. This commit restores it.\n\n[1] https://bugzilla.kernel.org/show_bug.cgi?id=214503", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47646" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/15729ff8143f8135b03988a100a19e66d7cb7ecd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4083925bd6dc89216d156474a8076feec904e607" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/65d8a737452e88f251fe5d925371de6d606df613" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/931aff627469a75c77b9fd3823146d0575afffd6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/abc2129e646af7b43025d90a071f83043f1ae76c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cc051f497eac9d8a0d816cd4bffa3415f2724871" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f990f0985eda59d4f29fc83fcf300c92b1225d39" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T06:37:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-8w8c-pj2m-2g74/GHSA-8w8c-pj2m-2g74.json b/advisories/unreviewed/2025/02/GHSA-8w8c-pj2m-2g74/GHSA-8w8c-pj2m-2g74.json new file mode 100644 index 00000000000..af9b07bde43 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-8w8c-pj2m-2g74/GHSA-8w8c-pj2m-2g74.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8w8c-pj2m-2g74", + "modified": "2025-02-27T18:31:14Z", + "published": "2025-02-27T18:31:14Z", + "aliases": [ + "CVE-2025-25333" + ], + "details": "An issue in IKEA CN iOS 4.13.0 allows attackers to access sensitive user information via supplying a crafted link.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25333" + }, + { + "type": "WEB", + "url": "https://github.com/ZhouZiyi1/Vuls/blob/main/250116-IKEACN/250116-IKEACN.pdf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-27T16:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-94p4-4m9q-5m8x/GHSA-94p4-4m9q-5m8x.json b/advisories/unreviewed/2025/02/GHSA-94p4-4m9q-5m8x/GHSA-94p4-4m9q-5m8x.json index 5d072d91d30..3dcc6868f38 100644 --- a/advisories/unreviewed/2025/02/GHSA-94p4-4m9q-5m8x/GHSA-94p4-4m9q-5m8x.json +++ b/advisories/unreviewed/2025/02/GHSA-94p4-4m9q-5m8x/GHSA-94p4-4m9q-5m8x.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-94p4-4m9q-5m8x", - "modified": "2025-02-27T03:34:02Z", + "modified": "2025-02-27T18:31:10Z", "published": "2025-02-27T03:34:02Z", "aliases": [ "CVE-2024-49570" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe/tracing: Fix a potential TP_printk UAF\n\nThe commit\nafd2627f727b (\"tracing: Check \"%s\" dereference via the field and not the TP_printk format\")\nexposes potential UAFs in the xe_bo_move trace event.\n\nFix those by avoiding dereferencing the\nxe_mem_type_to_name[] array at TP_printk time.\n\nSince some code refactoring has taken place, explicit backporting may\nbe needed for kernels older than 6.10.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-27T03:15:10Z" diff --git a/advisories/unreviewed/2025/02/GHSA-97f5-6j52-rp35/GHSA-97f5-6j52-rp35.json b/advisories/unreviewed/2025/02/GHSA-97f5-6j52-rp35/GHSA-97f5-6j52-rp35.json new file mode 100644 index 00000000000..cfec65e5b1b --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-97f5-6j52-rp35/GHSA-97f5-6j52-rp35.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-97f5-6j52-rp35", + "modified": "2025-02-27T18:31:09Z", + "published": "2025-02-27T18:31:09Z", + "aliases": [ + "CVE-2022-49669" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: fix race on unaccepted mptcp sockets\n\nWhen the listener socket owning the relevant request is closed,\nit frees the unaccepted subflows and that causes later deletion\nof the paired MPTCP sockets.\n\nThe mptcp socket's worker can run in the time interval between such delete\noperations. When that happens, any access to msk->first will cause an UaF\naccess, as the subflow cleanup did not cleared such field in the mptcp\nsocket.\n\nAddress the issue explicitly traversing the listener socket accept\nqueue at close time and performing the needed cleanup on the pending\nmsk.\n\nNote that the locking is a bit tricky, as we need to acquire the msk\nsocket lock, while still owning the subflow socket one.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49669" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6aeed9045071f2252ff4e98fc13d1e304f33e5b0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a8a3e95c74e48c2c9b07b81fafda9122993f2e12" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-cmvg-6vcw-642h/GHSA-cmvg-6vcw-642h.json b/advisories/unreviewed/2025/02/GHSA-cmvg-6vcw-642h/GHSA-cmvg-6vcw-642h.json index 6cfece13bd8..a799ba2e857 100644 --- a/advisories/unreviewed/2025/02/GHSA-cmvg-6vcw-642h/GHSA-cmvg-6vcw-642h.json +++ b/advisories/unreviewed/2025/02/GHSA-cmvg-6vcw-642h/GHSA-cmvg-6vcw-642h.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cmvg-6vcw-642h", - "modified": "2025-02-27T03:34:02Z", + "modified": "2025-02-27T18:31:09Z", "published": "2025-02-27T03:34:01Z", "aliases": [ "CVE-2025-21715" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: davicom: fix UAF in dm9000_drv_remove\n\ndm is netdev private data and it cannot be\nused after free_netdev() call. Using dm after free_netdev()\ncan cause UAF bug. Fix it by moving free_netdev() at the end of the\nfunction.\n\nThis is similar to the issue fixed in commit\nad297cd2db89 (\"net: qcom/emac: fix UAF in emac_remove\").\n\nThis bug is detected by our static analysis tool.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-27T02:15:15Z" diff --git a/advisories/unreviewed/2025/02/GHSA-f5w3-73h4-jpcm/GHSA-f5w3-73h4-jpcm.json b/advisories/unreviewed/2025/02/GHSA-f5w3-73h4-jpcm/GHSA-f5w3-73h4-jpcm.json new file mode 100644 index 00000000000..51436bd61d0 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-f5w3-73h4-jpcm/GHSA-f5w3-73h4-jpcm.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f5w3-73h4-jpcm", + "modified": "2025-02-27T18:31:13Z", + "published": "2025-02-27T18:31:13Z", + "aliases": [ + "CVE-2025-1756" + ], + "details": "mongosh may be susceptible to local privilege escalation under certain conditions potentially enabling unauthorized actions on a user's system with elevated privilege, when a crafted file is stored in C:\\node_modules\\. This issue affects mongosh prior to 2.3.0", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1756" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:1756" + }, + { + "type": "WEB", + "url": "https://jira.mongodb.org/browse/MONGOSH-2028" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-426" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-27T16:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-f6m2-43g4-75fj/GHSA-f6m2-43g4-75fj.json b/advisories/unreviewed/2025/02/GHSA-f6m2-43g4-75fj/GHSA-f6m2-43g4-75fj.json new file mode 100644 index 00000000000..f94183fdf25 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-f6m2-43g4-75fj/GHSA-f6m2-43g4-75fj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f6m2-43g4-75fj", + "modified": "2025-02-27T18:31:14Z", + "published": "2025-02-27T18:31:14Z", + "aliases": [ + "CVE-2025-23687" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in simonhunter Woo Store Mode allows Reflected XSS. This issue affects Woo Store Mode: from n/a through 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23687" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/woo-store-mode/vulnerability/wordpress-woo-store-mode-plugin-1-0-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-27T17:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-fr54-2qgg-4whr/GHSA-fr54-2qgg-4whr.json b/advisories/unreviewed/2025/02/GHSA-fr54-2qgg-4whr/GHSA-fr54-2qgg-4whr.json new file mode 100644 index 00000000000..250b58f8a53 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-fr54-2qgg-4whr/GHSA-fr54-2qgg-4whr.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fr54-2qgg-4whr", + "modified": "2025-02-27T18:31:14Z", + "published": "2025-02-27T18:31:14Z", + "aliases": [ + "CVE-2024-9285" + ], + "details": "A vulnerability was found in Tu Yafeng Via Browser up to 5.9.0 on Android. It has been rated as problematic. This issue affects some unknown processing of the component Javascript Bridge. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9285" + }, + { + "type": "WEB", + "url": "https://modzero.com/en/advisories/mz-25-01-via-browser" + }, + { + "type": "WEB", + "url": "https://modzero.com/static/MZ-25-01_modzero_uXSS-in-Via-Browser.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.297863" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.297863" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-27T17:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-g48q-f43r-rjjg/GHSA-g48q-f43r-rjjg.json b/advisories/unreviewed/2025/02/GHSA-g48q-f43r-rjjg/GHSA-g48q-f43r-rjjg.json new file mode 100644 index 00000000000..2f2310c394a --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-g48q-f43r-rjjg/GHSA-g48q-f43r-rjjg.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g48q-f43r-rjjg", + "modified": "2025-02-27T18:31:08Z", + "published": "2025-02-27T18:31:08Z", + "aliases": [ + "CVE-2022-49136" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_sync: Fix queuing commands when HCI_UNREGISTER is set\n\nhci_cmd_sync_queue shall return an error if HCI_UNREGISTER flag has\nbeen set as that means hci_unregister_dev has been called so it will\nlikely cause a uaf after the timeout as the hdev will be freed.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49136" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0b94f2651f56b9e4aa5f012b0d7eb57308c773cf" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1c69ef84a808676cceb69210addf5df45b741323" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:00:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-gcjr-rx2g-5wh3/GHSA-gcjr-rx2g-5wh3.json b/advisories/unreviewed/2025/02/GHSA-gcjr-rx2g-5wh3/GHSA-gcjr-rx2g-5wh3.json index ad55beb47ee..caaaf39400d 100644 --- a/advisories/unreviewed/2025/02/GHSA-gcjr-rx2g-5wh3/GHSA-gcjr-rx2g-5wh3.json +++ b/advisories/unreviewed/2025/02/GHSA-gcjr-rx2g-5wh3/GHSA-gcjr-rx2g-5wh3.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-269" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-gq6q-2ffm-3vc2/GHSA-gq6q-2ffm-3vc2.json b/advisories/unreviewed/2025/02/GHSA-gq6q-2ffm-3vc2/GHSA-gq6q-2ffm-3vc2.json new file mode 100644 index 00000000000..76b3f09f62b --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-gq6q-2ffm-3vc2/GHSA-gq6q-2ffm-3vc2.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gq6q-2ffm-3vc2", + "modified": "2025-02-27T18:31:13Z", + "published": "2025-02-27T18:31:13Z", + "aliases": [ + "CVE-2025-25323" + ], + "details": "An issue in Qianjin Network Information Technology (Shanghai) Co., Ltd 51Job iOS 14.22.0 allows attackers to access sensitive user information via supplying a crafted link.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25323" + }, + { + "type": "WEB", + "url": "https://github.com/ZhouZiyi1/Vuls/blob/main/250111-51Job/250111-51Job.pdf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-27T16:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-gr74-v59q-3p8g/GHSA-gr74-v59q-3p8g.json b/advisories/unreviewed/2025/02/GHSA-gr74-v59q-3p8g/GHSA-gr74-v59q-3p8g.json new file mode 100644 index 00000000000..d27523e48af --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-gr74-v59q-3p8g/GHSA-gr74-v59q-3p8g.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gr74-v59q-3p8g", + "modified": "2025-02-27T18:31:13Z", + "published": "2025-02-27T18:31:13Z", + "aliases": [ + "CVE-2025-25324" + ], + "details": "An issue in Shandong Provincial Big Data Center AiShanDong iOS 5.0.0 allows attackers to access sensitive user information via supplying a crafted link.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25324" + }, + { + "type": "WEB", + "url": "https://github.com/ZhouZiyi1/Vuls/blob/main/250111-AiShanDong/250111-AiShanDong.pdf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-27T16:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-gw7x-m5vf-fw73/GHSA-gw7x-m5vf-fw73.json b/advisories/unreviewed/2025/02/GHSA-gw7x-m5vf-fw73/GHSA-gw7x-m5vf-fw73.json new file mode 100644 index 00000000000..016faaddbef --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-gw7x-m5vf-fw73/GHSA-gw7x-m5vf-fw73.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gw7x-m5vf-fw73", + "modified": "2025-02-27T18:31:08Z", + "published": "2025-02-27T18:31:08Z", + "aliases": [ + "CVE-2022-49179" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nblock, bfq: don't move oom_bfqq\n\nOur test report a UAF:\n\n[ 2073.019181] ==================================================================\n[ 2073.019188] BUG: KASAN: use-after-free in __bfq_put_async_bfqq+0xa0/0x168\n[ 2073.019191] Write of size 8 at addr ffff8000ccf64128 by task rmmod/72584\n[ 2073.019192]\n[ 2073.019196] CPU: 0 PID: 72584 Comm: rmmod Kdump: loaded Not tainted 4.19.90-yk #5\n[ 2073.019198] Hardware name: QEMU KVM Virtual Machine, BIOS 0.0.0 02/06/2015\n[ 2073.019200] Call trace:\n[ 2073.019203] dump_backtrace+0x0/0x310\n[ 2073.019206] show_stack+0x28/0x38\n[ 2073.019210] dump_stack+0xec/0x15c\n[ 2073.019216] print_address_description+0x68/0x2d0\n[ 2073.019220] kasan_report+0x238/0x2f0\n[ 2073.019224] __asan_store8+0x88/0xb0\n[ 2073.019229] __bfq_put_async_bfqq+0xa0/0x168\n[ 2073.019233] bfq_put_async_queues+0xbc/0x208\n[ 2073.019236] bfq_pd_offline+0x178/0x238\n[ 2073.019240] blkcg_deactivate_policy+0x1f0/0x420\n[ 2073.019244] bfq_exit_queue+0x128/0x178\n[ 2073.019249] blk_mq_exit_sched+0x12c/0x160\n[ 2073.019252] elevator_exit+0xc8/0xd0\n[ 2073.019256] blk_exit_queue+0x50/0x88\n[ 2073.019259] blk_cleanup_queue+0x228/0x3d8\n[ 2073.019267] null_del_dev+0xfc/0x1e0 [null_blk]\n[ 2073.019274] null_exit+0x90/0x114 [null_blk]\n[ 2073.019278] __arm64_sys_delete_module+0x358/0x5a0\n[ 2073.019282] el0_svc_common+0xc8/0x320\n[ 2073.019287] el0_svc_handler+0xf8/0x160\n[ 2073.019290] el0_svc+0x10/0x218\n[ 2073.019291]\n[ 2073.019294] Allocated by task 14163:\n[ 2073.019301] kasan_kmalloc+0xe0/0x190\n[ 2073.019305] kmem_cache_alloc_node_trace+0x1cc/0x418\n[ 2073.019308] bfq_pd_alloc+0x54/0x118\n[ 2073.019313] blkcg_activate_policy+0x250/0x460\n[ 2073.019317] bfq_create_group_hierarchy+0x38/0x110\n[ 2073.019321] bfq_init_queue+0x6d0/0x948\n[ 2073.019325] blk_mq_init_sched+0x1d8/0x390\n[ 2073.019330] elevator_switch_mq+0x88/0x170\n[ 2073.019334] elevator_switch+0x140/0x270\n[ 2073.019338] elv_iosched_store+0x1a4/0x2a0\n[ 2073.019342] queue_attr_store+0x90/0xe0\n[ 2073.019348] sysfs_kf_write+0xa8/0xe8\n[ 2073.019351] kernfs_fop_write+0x1f8/0x378\n[ 2073.019359] __vfs_write+0xe0/0x360\n[ 2073.019363] vfs_write+0xf0/0x270\n[ 2073.019367] ksys_write+0xdc/0x1b8\n[ 2073.019371] __arm64_sys_write+0x50/0x60\n[ 2073.019375] el0_svc_common+0xc8/0x320\n[ 2073.019380] el0_svc_handler+0xf8/0x160\n[ 2073.019383] el0_svc+0x10/0x218\n[ 2073.019385]\n[ 2073.019387] Freed by task 72584:\n[ 2073.019391] __kasan_slab_free+0x120/0x228\n[ 2073.019394] kasan_slab_free+0x10/0x18\n[ 2073.019397] kfree+0x94/0x368\n[ 2073.019400] bfqg_put+0x64/0xb0\n[ 2073.019404] bfqg_and_blkg_put+0x90/0xb0\n[ 2073.019408] bfq_put_queue+0x220/0x228\n[ 2073.019413] __bfq_put_async_bfqq+0x98/0x168\n[ 2073.019416] bfq_put_async_queues+0xbc/0x208\n[ 2073.019420] bfq_pd_offline+0x178/0x238\n[ 2073.019424] blkcg_deactivate_policy+0x1f0/0x420\n[ 2073.019429] bfq_exit_queue+0x128/0x178\n[ 2073.019433] blk_mq_exit_sched+0x12c/0x160\n[ 2073.019437] elevator_exit+0xc8/0xd0\n[ 2073.019440] blk_exit_queue+0x50/0x88\n[ 2073.019443] blk_cleanup_queue+0x228/0x3d8\n[ 2073.019451] null_del_dev+0xfc/0x1e0 [null_blk]\n[ 2073.019459] null_exit+0x90/0x114 [null_blk]\n[ 2073.019462] __arm64_sys_delete_module+0x358/0x5a0\n[ 2073.019467] el0_svc_common+0xc8/0x320\n[ 2073.019471] el0_svc_handler+0xf8/0x160\n[ 2073.019474] el0_svc+0x10/0x218\n[ 2073.019475]\n[ 2073.019479] The buggy address belongs to the object at ffff8000ccf63f00\n which belongs to the cache kmalloc-1024 of size 1024\n[ 2073.019484] The buggy address is located 552 bytes inside of\n 1024-byte region [ffff8000ccf63f00, ffff8000ccf64300)\n[ 2073.019486] The buggy address belongs to the page:\n[ 2073.019492] page:ffff7e000333d800 count:1 mapcount:0 mapping:ffff8000c0003a00 index:0x0 compound_mapcount: 0\n[ 2073.020123] flags: 0x7ffff0000008100(slab|head)\n[ 2073.020403] raw: 07ffff0000008100 ffff7e0003334c08 ffff7e00001f5a08 ffff8000c0003a00\n[ 2073.020409] ra\n---truncated---", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49179" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7507ead1e9d42957c2340f2c4a0e9d00034e3366" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8410f70977734f21b8ed45c37e925d311dfda2e7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/87fdfe8589d43e471dffb4c60f75eeb6f37afc4c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8f34dea99cd7761156a146a5258a67d045d862f7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c01fced8d38fbccc82787065229578006f28e020" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c4f5a678add58a8a0e7ee5e038496b376ea6d205" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:00:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-hgrx-p3hg-cw72/GHSA-hgrx-p3hg-cw72.json b/advisories/unreviewed/2025/02/GHSA-hgrx-p3hg-cw72/GHSA-hgrx-p3hg-cw72.json index 531bd684d3d..3048bdde370 100644 --- a/advisories/unreviewed/2025/02/GHSA-hgrx-p3hg-cw72/GHSA-hgrx-p3hg-cw72.json +++ b/advisories/unreviewed/2025/02/GHSA-hgrx-p3hg-cw72/GHSA-hgrx-p3hg-cw72.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hgrx-p3hg-cw72", - "modified": "2025-02-27T03:34:07Z", + "modified": "2025-02-27T18:31:12Z", "published": "2025-02-27T03:34:07Z", "aliases": [ "CVE-2025-21796" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: clear acl_access/acl_default after releasing them\n\nIf getting acl_default fails, acl_access and acl_default will be released\nsimultaneously. However, acl_access will still retain a pointer pointing\nto the released posix_acl, which will trigger a WARNING in\nnfs3svc_release_getacl like this:\n\n------------[ cut here ]------------\nrefcount_t: underflow; use-after-free.\nWARNING: CPU: 26 PID: 3199 at lib/refcount.c:28\nrefcount_warn_saturate+0xb5/0x170\nModules linked in:\nCPU: 26 UID: 0 PID: 3199 Comm: nfsd Not tainted\n6.12.0-rc6-00079-g04ae226af01f-dirty #8\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS\n1.16.1-2.fc37 04/01/2014\nRIP: 0010:refcount_warn_saturate+0xb5/0x170\nCode: cc cc 0f b6 1d b3 20 a5 03 80 fb 01 0f 87 65 48 d8 00 83 e3 01 75\ne4 48 c7 c7 c0 3b 9b 85 c6 05 97 20 a5 03 01 e8 fb 3e 30 ff <0f> 0b eb\ncd 0f b6 1d 8a3\nRSP: 0018:ffffc90008637cd8 EFLAGS: 00010282\nRAX: 0000000000000000 RBX: 0000000000000000 RCX: ffffffff83904fde\nRDX: dffffc0000000000 RSI: 0000000000000008 RDI: ffff88871ed36380\nRBP: ffff888158beeb40 R08: 0000000000000001 R09: fffff520010c6f56\nR10: ffffc90008637ab7 R11: 0000000000000001 R12: 0000000000000001\nR13: ffff888140e77400 R14: ffff888140e77408 R15: ffffffff858b42c0\nFS: 0000000000000000(0000) GS:ffff88871ed00000(0000)\nknlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000562384d32158 CR3: 000000055cc6a000 CR4: 00000000000006f0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nCall Trace:\n \n ? refcount_warn_saturate+0xb5/0x170\n ? __warn+0xa5/0x140\n ? refcount_warn_saturate+0xb5/0x170\n ? report_bug+0x1b1/0x1e0\n ? handle_bug+0x53/0xa0\n ? exc_invalid_op+0x17/0x40\n ? asm_exc_invalid_op+0x1a/0x20\n ? tick_nohz_tick_stopped+0x1e/0x40\n ? refcount_warn_saturate+0xb5/0x170\n ? refcount_warn_saturate+0xb5/0x170\n nfs3svc_release_getacl+0xc9/0xe0\n svc_process_common+0x5db/0xb60\n ? __pfx_svc_process_common+0x10/0x10\n ? __rcu_read_unlock+0x69/0xa0\n ? __pfx_nfsd_dispatch+0x10/0x10\n ? svc_xprt_received+0xa1/0x120\n ? xdr_init_decode+0x11d/0x190\n svc_process+0x2a7/0x330\n svc_handle_xprt+0x69d/0x940\n svc_recv+0x180/0x2d0\n nfsd+0x168/0x200\n ? __pfx_nfsd+0x10/0x10\n kthread+0x1a2/0x1e0\n ? kthread+0xf4/0x1e0\n ? __pfx_kthread+0x10/0x10\n ret_from_fork+0x34/0x60\n ? __pfx_kthread+0x10/0x10\n ret_from_fork_asm+0x1a/0x30\n \nKernel panic - not syncing: kernel: panic_on_warn set ...\n\nClear acl_access/acl_default after posix_acl_release is called to prevent\nUAF from being triggered.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-27T03:15:20Z" diff --git a/advisories/unreviewed/2025/02/GHSA-hpv4-mq4h-frcq/GHSA-hpv4-mq4h-frcq.json b/advisories/unreviewed/2025/02/GHSA-hpv4-mq4h-frcq/GHSA-hpv4-mq4h-frcq.json new file mode 100644 index 00000000000..589f3ad1e52 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-hpv4-mq4h-frcq/GHSA-hpv4-mq4h-frcq.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hpv4-mq4h-frcq", + "modified": "2025-02-27T18:31:14Z", + "published": "2025-02-27T18:31:14Z", + "aliases": [ + "CVE-2025-1745" + ], + "details": "A vulnerability has been found in LinZhaoguan pb-cms 2.0 and classified as problematic. This vulnerability affects unknown code of the component Logout. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1745" + }, + { + "type": "WEB", + "url": "https://gitee.com/LinZhaoguan/pb-cms/issues/IBMM8V" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.297832" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.297832" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.502342" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-27T18:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-j8mq-pfgm-36r2/GHSA-j8mq-pfgm-36r2.json b/advisories/unreviewed/2025/02/GHSA-j8mq-pfgm-36r2/GHSA-j8mq-pfgm-36r2.json index 8b05e30b037..52d38bcaccb 100644 --- a/advisories/unreviewed/2025/02/GHSA-j8mq-pfgm-36r2/GHSA-j8mq-pfgm-36r2.json +++ b/advisories/unreviewed/2025/02/GHSA-j8mq-pfgm-36r2/GHSA-j8mq-pfgm-36r2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-j8mq-pfgm-36r2", - "modified": "2025-02-27T03:34:05Z", + "modified": "2025-02-27T18:31:11Z", "published": "2025-02-27T03:34:05Z", "aliases": [ "CVE-2025-21764" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nndisc: use RCU protection in ndisc_alloc_skb()\n\nndisc_alloc_skb() can be called without RTNL or RCU being held.\n\nAdd RCU protection to avoid possible UAF.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-27T03:15:17Z" diff --git a/advisories/unreviewed/2025/02/GHSA-jc5w-m29h-g88w/GHSA-jc5w-m29h-g88w.json b/advisories/unreviewed/2025/02/GHSA-jc5w-m29h-g88w/GHSA-jc5w-m29h-g88w.json index ac8d7a758c5..f2c1c46e8d5 100644 --- a/advisories/unreviewed/2025/02/GHSA-jc5w-m29h-g88w/GHSA-jc5w-m29h-g88w.json +++ b/advisories/unreviewed/2025/02/GHSA-jc5w-m29h-g88w/GHSA-jc5w-m29h-g88w.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jc5w-m29h-g88w", - "modified": "2025-02-27T03:34:02Z", + "modified": "2025-02-27T18:31:10Z", "published": "2025-02-27T03:34:02Z", "aliases": [ "CVE-2024-54458" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: ufs: bsg: Set bsg_queue to NULL after removal\n\nCurrently, this does not cause any issues, but I believe it is necessary to\nset bsg_queue to NULL after removing it to prevent potential use-after-free\n(UAF) access.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-27T03:15:10Z" diff --git a/advisories/unreviewed/2025/02/GHSA-jh3f-g934-rw77/GHSA-jh3f-g934-rw77.json b/advisories/unreviewed/2025/02/GHSA-jh3f-g934-rw77/GHSA-jh3f-g934-rw77.json new file mode 100644 index 00000000000..6fd821d3458 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-jh3f-g934-rw77/GHSA-jh3f-g934-rw77.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jh3f-g934-rw77", + "modified": "2025-02-27T18:31:08Z", + "published": "2025-02-27T18:31:08Z", + "aliases": [ + "CVE-2022-49078" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nlz4: fix LZ4_decompress_safe_partial read out of bound\n\nWhen partialDecoding, it is EOF if we've either filled the output buffer\nor can't proceed with reading an offset for following match.\n\nIn some extreme corner cases when compressed data is suitably corrupted,\nUAF will occur. As reported by KASAN [1], LZ4_decompress_safe_partial\nmay lead to read out of bound problem during decoding. lz4 upstream has\nfixed it [2] and this issue has been disscussed here [3] before.\n\ncurrent decompression routine was ported from lz4 v1.8.3, bumping\nlib/lz4 to v1.9.+ is certainly a huge work to be done later, so, we'd\nbetter fix it first.\n\n[1] https://lore.kernel.org/all/000000000000830d1205cf7f0477@google.com/\n[2] https://github.com/lz4/lz4/commit/c5d6f8a8be3927c0bec91bcc58667a6cfad244ad#\n[3] https://lore.kernel.org/all/CC666AE8-4CA4-4951-B6FB-A2EFDE3AC03B@fb.com/", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49078" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/467d5e200ab4486b744fe1776154a43d1aa22d4b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6adc01a7aa37445dafe8846faa0610a86029b253" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/73953dfa9d50e5c9fe98ee13fd1d3427aa12a0a3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9fb8bc6cfc58773ce95414e11c9ccc8fc6ac4927" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e64dbe97c05c769525cbca099ddbd22485630235" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/eafc0a02391b7b36617b36c97c4b5d6832cf5e24" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:00:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-m2x9-jx4p-g5c8/GHSA-m2x9-jx4p-g5c8.json b/advisories/unreviewed/2025/02/GHSA-m2x9-jx4p-g5c8/GHSA-m2x9-jx4p-g5c8.json new file mode 100644 index 00000000000..d54f74bfa0a --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-m2x9-jx4p-g5c8/GHSA-m2x9-jx4p-g5c8.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m2x9-jx4p-g5c8", + "modified": "2025-02-27T18:31:14Z", + "published": "2025-02-27T18:31:14Z", + "aliases": [ + "CVE-2025-25334" + ], + "details": "An issue in Suning Commerce Group Suning EMall iOS 9.5.198 allows attackers to access sensitive user information via supplying a crafted link.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25334" + }, + { + "type": "WEB", + "url": "https://github.com/ZhouZiyi1/Vuls/blob/main/250116-SuningEMall/250116-SuningEMall.pdf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-27T16:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-m3vm-45hm-666q/GHSA-m3vm-45hm-666q.json b/advisories/unreviewed/2025/02/GHSA-m3vm-45hm-666q/GHSA-m3vm-45hm-666q.json new file mode 100644 index 00000000000..0fd688d5a63 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-m3vm-45hm-666q/GHSA-m3vm-45hm-666q.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m3vm-45hm-666q", + "modified": "2025-02-27T18:31:08Z", + "published": "2025-02-27T18:31:08Z", + "aliases": [ + "CVE-2022-49236" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix UAF due to race between btf_try_get_module and load_module\n\nWhile working on code to populate kfunc BTF ID sets for module BTF from\nits initcall, I noticed that by the time the initcall is invoked, the\nmodule BTF can already be seen by userspace (and the BPF verifier). The\nexisting btf_try_get_module calls try_module_get which only fails if\nmod->state == MODULE_STATE_GOING, i.e. it can increment module reference\nwhen module initcall is happening in parallel.\n\nCurrently, BTF parsing happens from MODULE_STATE_COMING notifier\ncallback. At this point, the module initcalls have not been invoked.\nThe notifier callback parses and prepares the module BTF, allocates an\nID, which publishes it to userspace, and then adds it to the btf_modules\nlist allowing the kernel to invoke btf_try_get_module for the BTF.\n\nHowever, at this point, the module has not been fully initialized (i.e.\nits initcalls have not finished). The code in module.c can still fail\nand free the module, without caring for other users. However, nothing\nstops btf_try_get_module from succeeding between the state transition\nfrom MODULE_STATE_COMING to MODULE_STATE_LIVE.\n\nThis leads to a use-after-free issue when BPF program loads\nsuccessfully in the state transition, load_module's do_init_module call\nfails and frees the module, and BPF program fd on close calls module_put\nfor the freed module. Future patch has test case to verify we don't\nregress in this area in future.\n\nThere are multiple points after prepare_coming_module (in load_module)\nwhere failure can occur and module loading can return error. We\nillustrate and test for the race using the last point where it can\npractically occur (in module __init function).\n\nAn illustration of the race:\n\nCPU 0 CPU 1\n\t\t\t load_module\n\t\t\t notifier_call(MODULE_STATE_COMING)\n\t\t\t btf_parse_module\n\t\t\t btf_alloc_id\t// Published to userspace\n\t\t\t list_add(&btf_mod->list, btf_modules)\n\t\t\t mod->init(...)\n...\t\t\t\t^\nbpf_check\t\t |\ncheck_pseudo_btf_id |\n btf_try_get_module |\n returns true | ...\n... | module __init in progress\nreturn prog_fd | ...\n... V\n\t\t\t if (ret < 0)\n\t\t\t free_module(mod)\n\t\t\t ...\nclose(prog_fd)\n ...\n bpf_prog_free_deferred\n module_put(used_btf.mod) // use-after-free\n\nWe fix this issue by setting a flag BTF_MODULE_F_LIVE, from the notifier\ncallback when MODULE_STATE_LIVE state is reached for the module, so that\nwe return NULL from btf_try_get_module for modules that are not fully\nformed. Since try_module_get already checks that module is not in\nMODULE_STATE_GOING state, and that is the only transition a live module\ncan make before being removed from btf_modules list, this is enough to\nclose the race and prevent the bug.\n\nA later selftest patch crafts the race condition artifically to verify\nthat it has been fixed, and that verifier fails to load program (with\nENXIO).\n\nLastly, a couple of comments:\n\n 1. Even if this race didn't exist, it seems more appropriate to only\n access resources (ksyms and kfuncs) of a fully formed module which\n has been initialized completely.\n\n 2. This patch was born out of need for synchronization against module\n initcall for the next patch, so it is needed for correctness even\n without the aforementioned race condition. The BTF resources\n initialized by module initcall are set up once and then only looked\n up, so just waiting until the initcall has finished ensures correct\n behavior.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49236" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0481baa2318cb1ab13277715da6cdbb657807b3f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/18688de203b47e5d8d9d0953385bf30b5949324f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/51b82141fffa454abf937a8ff0b8af89e4fd0c8f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d7fccf264b1a785525b366a5b7f8113c756187ad" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-m4c7-j6q4-hc9j/GHSA-m4c7-j6q4-hc9j.json b/advisories/unreviewed/2025/02/GHSA-m4c7-j6q4-hc9j/GHSA-m4c7-j6q4-hc9j.json new file mode 100644 index 00000000000..2202fce423c --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-m4c7-j6q4-hc9j/GHSA-m4c7-j6q4-hc9j.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m4c7-j6q4-hc9j", + "modified": "2025-02-27T18:31:14Z", + "published": "2025-02-27T18:31:14Z", + "aliases": [ + "CVE-2025-1742" + ], + "details": "A vulnerability, which was classified as problematic, has been found in pihome-shc PiHome 2.0. Affected by this issue is some unknown functionality of the file /home.php. The manipulation of the argument page_name leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1742" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.297830" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.297830" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.502501" + }, + { + "type": "WEB", + "url": "https://www.singto.io/pocsforexploits/pihomehvac_xss_home.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-27T17:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-m645-2c8g-gg4p/GHSA-m645-2c8g-gg4p.json b/advisories/unreviewed/2025/02/GHSA-m645-2c8g-gg4p/GHSA-m645-2c8g-gg4p.json new file mode 100644 index 00000000000..c7db42935f5 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-m645-2c8g-gg4p/GHSA-m645-2c8g-gg4p.json @@ -0,0 +1,68 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m645-2c8g-gg4p", + "modified": "2025-02-27T18:31:09Z", + "published": "2025-02-27T18:31:09Z", + "aliases": [ + "CVE-2022-49505" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nNFC: NULL out the dev->rfkill to prevent UAF\n\nCommit 3e3b5dfcd16a (\"NFC: reorder the logic in nfc_{un,}register_device\")\nassumes the device_is_registered() in function nfc_dev_up() will help\nto check when the rfkill is unregistered. However, this check only\ntake effect when device_del(&dev->dev) is done in nfc_unregister_device().\nHence, the rfkill object is still possible be dereferenced.\n\nThe crash trace in latest kernel (5.18-rc2):\n\n[ 68.760105] ==================================================================\n[ 68.760330] BUG: KASAN: use-after-free in __lock_acquire+0x3ec1/0x6750\n[ 68.760756] Read of size 8 at addr ffff888009c93018 by task fuzz/313\n[ 68.760756]\n[ 68.760756] CPU: 0 PID: 313 Comm: fuzz Not tainted 5.18.0-rc2 #4\n[ 68.760756] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.14.0-0-g155821a1990b-prebuilt.qemu.org 04/01/2014\n[ 68.760756] Call Trace:\n[ 68.760756] \n[ 68.760756] dump_stack_lvl+0x57/0x7d\n[ 68.760756] print_report.cold+0x5e/0x5db\n[ 68.760756] ? __lock_acquire+0x3ec1/0x6750\n[ 68.760756] kasan_report+0xbe/0x1c0\n[ 68.760756] ? __lock_acquire+0x3ec1/0x6750\n[ 68.760756] __lock_acquire+0x3ec1/0x6750\n[ 68.760756] ? lockdep_hardirqs_on_prepare+0x410/0x410\n[ 68.760756] ? register_lock_class+0x18d0/0x18d0\n[ 68.760756] lock_acquire+0x1ac/0x4f0\n[ 68.760756] ? rfkill_blocked+0xe/0x60\n[ 68.760756] ? lockdep_hardirqs_on_prepare+0x410/0x410\n[ 68.760756] ? mutex_lock_io_nested+0x12c0/0x12c0\n[ 68.760756] ? nla_get_range_signed+0x540/0x540\n[ 68.760756] ? _raw_spin_lock_irqsave+0x4e/0x50\n[ 68.760756] _raw_spin_lock_irqsave+0x39/0x50\n[ 68.760756] ? rfkill_blocked+0xe/0x60\n[ 68.760756] rfkill_blocked+0xe/0x60\n[ 68.760756] nfc_dev_up+0x84/0x260\n[ 68.760756] nfc_genl_dev_up+0x90/0xe0\n[ 68.760756] genl_family_rcv_msg_doit+0x1f4/0x2f0\n[ 68.760756] ? genl_family_rcv_msg_attrs_parse.constprop.0+0x230/0x230\n[ 68.760756] ? security_capable+0x51/0x90\n[ 68.760756] genl_rcv_msg+0x280/0x500\n[ 68.760756] ? genl_get_cmd+0x3c0/0x3c0\n[ 68.760756] ? lock_acquire+0x1ac/0x4f0\n[ 68.760756] ? nfc_genl_dev_down+0xe0/0xe0\n[ 68.760756] ? lockdep_hardirqs_on_prepare+0x410/0x410\n[ 68.760756] netlink_rcv_skb+0x11b/0x340\n[ 68.760756] ? genl_get_cmd+0x3c0/0x3c0\n[ 68.760756] ? netlink_ack+0x9c0/0x9c0\n[ 68.760756] ? netlink_deliver_tap+0x136/0xb00\n[ 68.760756] genl_rcv+0x1f/0x30\n[ 68.760756] netlink_unicast+0x430/0x710\n[ 68.760756] ? memset+0x20/0x40\n[ 68.760756] ? netlink_attachskb+0x740/0x740\n[ 68.760756] ? __build_skb_around+0x1f4/0x2a0\n[ 68.760756] netlink_sendmsg+0x75d/0xc00\n[ 68.760756] ? netlink_unicast+0x710/0x710\n[ 68.760756] ? netlink_unicast+0x710/0x710\n[ 68.760756] sock_sendmsg+0xdf/0x110\n[ 68.760756] __sys_sendto+0x19e/0x270\n[ 68.760756] ? __ia32_sys_getpeername+0xa0/0xa0\n[ 68.760756] ? fd_install+0x178/0x4c0\n[ 68.760756] ? fd_install+0x195/0x4c0\n[ 68.760756] ? kernel_fpu_begin_mask+0x1c0/0x1c0\n[ 68.760756] __x64_sys_sendto+0xd8/0x1b0\n[ 68.760756] ? lockdep_hardirqs_on+0xbf/0x130\n[ 68.760756] ? syscall_enter_from_user_mode+0x1d/0x50\n[ 68.760756] do_syscall_64+0x3b/0x90\n[ 68.760756] entry_SYSCALL_64_after_hwframe+0x44/0xae\n[ 68.760756] RIP: 0033:0x7f67fb50e6b3\n...\n[ 68.760756] RSP: 002b:00007f67fa91fe90 EFLAGS: 00000293 ORIG_RAX: 000000000000002c\n[ 68.760756] RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007f67fb50e6b3\n[ 68.760756] RDX: 000000000000001c RSI: 0000559354603090 RDI: 0000000000000003\n[ 68.760756] RBP: 00007f67fa91ff00 R08: 00007f67fa91fedc R09: 000000000000000c\n[ 68.760756] R10: 0000000000000000 R11: 0000000000000293 R12: 00007ffe824d496e\n[ 68.760756] R13: 00007ffe824d496f R14: 00007f67fa120000 R15: 0000000000000003\n\n[ 68.760756] \n[ 68.760756]\n[ 68.760756] Allocated by task 279:\n[ 68.760756] kasan_save_stack+0x1e/0x40\n[\n---truncated---", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49505" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1632be63862f183cd5cf1cc094e698e6ec005dfd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1b0e81416a24d6e9b8c2341e22e8bf48f8b8bfc9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2a1b5110c95e4d49c8c3906270dfcde680a5a7be" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4a68938f43b7c2663e4c90bb9bbe29ac8b9a42a0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4f5d71930f41be78557f9714393179025baacd65" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6abfaca8711803d0d7cc8c0fac1070a88509d463" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a8e03bcad52dc9afabf650fdbad84f739cec9efa" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f81270125b50532624400063281e6611ecd61ddf" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fbf9c4c714d3cdeb98b6a18e4d057f931cad1d81" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-p967-4mgh-r94w/GHSA-p967-4mgh-r94w.json b/advisories/unreviewed/2025/02/GHSA-p967-4mgh-r94w/GHSA-p967-4mgh-r94w.json new file mode 100644 index 00000000000..a79d0717edb --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-p967-4mgh-r94w/GHSA-p967-4mgh-r94w.json @@ -0,0 +1,64 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p967-4mgh-r94w", + "modified": "2025-02-27T18:31:08Z", + "published": "2025-02-27T18:31:08Z", + "aliases": [ + "CVE-2022-49059" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: nci: add flush_workqueue to prevent uaf\n\nOur detector found a concurrent use-after-free bug when detaching an\nNCI device. The main reason for this bug is the unexpected scheduling\nbetween the used delayed mechanism (timer and workqueue).\n\nThe race can be demonstrated below:\n\nThread-1 Thread-2\n | nci_dev_up()\n | nci_open_device()\n | __nci_request(nci_reset_req)\n | nci_send_cmd\n | queue_work(cmd_work)\nnci_unregister_device() |\n nci_close_device() | ...\n del_timer_sync(cmd_timer)[1] |\n... | Worker\nnci_free_device() | nci_cmd_work()\n kfree(ndev)[3] | mod_timer(cmd_timer)[2]\n\nIn short, the cleanup routine thought that the cmd_timer has already\nbeen detached by [1] but the mod_timer can re-attach the timer [2], even\nit is already released [3], resulting in UAF.\n\nThis UAF is easy to trigger, crash trace by POC is like below\n\n[ 66.703713] ==================================================================\n[ 66.703974] BUG: KASAN: use-after-free in enqueue_timer+0x448/0x490\n[ 66.703974] Write of size 8 at addr ffff888009fb7058 by task kworker/u4:1/33\n[ 66.703974]\n[ 66.703974] CPU: 1 PID: 33 Comm: kworker/u4:1 Not tainted 5.18.0-rc2 #5\n[ 66.703974] Workqueue: nfc2_nci_cmd_wq nci_cmd_work\n[ 66.703974] Call Trace:\n[ 66.703974] \n[ 66.703974] dump_stack_lvl+0x57/0x7d\n[ 66.703974] print_report.cold+0x5e/0x5db\n[ 66.703974] ? enqueue_timer+0x448/0x490\n[ 66.703974] kasan_report+0xbe/0x1c0\n[ 66.703974] ? enqueue_timer+0x448/0x490\n[ 66.703974] enqueue_timer+0x448/0x490\n[ 66.703974] __mod_timer+0x5e6/0xb80\n[ 66.703974] ? mark_held_locks+0x9e/0xe0\n[ 66.703974] ? try_to_del_timer_sync+0xf0/0xf0\n[ 66.703974] ? lockdep_hardirqs_on_prepare+0x17b/0x410\n[ 66.703974] ? queue_work_on+0x61/0x80\n[ 66.703974] ? lockdep_hardirqs_on+0xbf/0x130\n[ 66.703974] process_one_work+0x8bb/0x1510\n[ 66.703974] ? lockdep_hardirqs_on_prepare+0x410/0x410\n[ 66.703974] ? pwq_dec_nr_in_flight+0x230/0x230\n[ 66.703974] ? rwlock_bug.part.0+0x90/0x90\n[ 66.703974] ? _raw_spin_lock_irq+0x41/0x50\n[ 66.703974] worker_thread+0x575/0x1190\n[ 66.703974] ? process_one_work+0x1510/0x1510\n[ 66.703974] kthread+0x2a0/0x340\n[ 66.703974] ? kthread_complete_and_exit+0x20/0x20\n[ 66.703974] ret_from_fork+0x22/0x30\n[ 66.703974] \n[ 66.703974]\n[ 66.703974] Allocated by task 267:\n[ 66.703974] kasan_save_stack+0x1e/0x40\n[ 66.703974] __kasan_kmalloc+0x81/0xa0\n[ 66.703974] nci_allocate_device+0xd3/0x390\n[ 66.703974] nfcmrvl_nci_register_dev+0x183/0x2c0\n[ 66.703974] nfcmrvl_nci_uart_open+0xf2/0x1dd\n[ 66.703974] nci_uart_tty_ioctl+0x2c3/0x4a0\n[ 66.703974] tty_ioctl+0x764/0x1310\n[ 66.703974] __x64_sys_ioctl+0x122/0x190\n[ 66.703974] do_syscall_64+0x3b/0x90\n[ 66.703974] entry_SYSCALL_64_after_hwframe+0x44/0xae\n[ 66.703974]\n[ 66.703974] Freed by task 406:\n[ 66.703974] kasan_save_stack+0x1e/0x40\n[ 66.703974] kasan_set_track+0x21/0x30\n[ 66.703974] kasan_set_free_info+0x20/0x30\n[ 66.703974] __kasan_slab_free+0x108/0x170\n[ 66.703974] kfree+0xb0/0x330\n[ 66.703974] nfcmrvl_nci_unregister_dev+0x90/0xd0\n[ 66.703974] nci_uart_tty_close+0xdf/0x180\n[ 66.703974] tty_ldisc_kill+0x73/0x110\n[ 66.703974] tty_ldisc_hangup+0x281/0x5b0\n[ 66.703974] __tty_hangup.part.0+0x431/0x890\n[ 66.703974] tty_release+0x3a8/0xc80\n[ 66.703974] __fput+0x1f0/0x8c0\n[ 66.703974] task_work_run+0xc9/0x170\n[ 66.703974] exit_to_user_mode_prepare+0x194/0x1a0\n[ 66.703974] syscall_exit_to_user_mode+0x19/0x50\n[ 66.703974] do_syscall_64+0x48/0x90\n[ 66.703974] entry_SYSCALL_64_after_hwframe+0x44/0x\n---truncated---", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49059" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1a1748d0dd0f0a98535c6baeef671c8722107639" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5c63ad2b0a267a524c12c88acb1ba9c2d109a801" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/67677050cecbe0edfdd81cd508415e9636ba7c65" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7d3232214ca4ea8f7d18df264c3b254aa8089d7f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9d243aff5f7e6b04e907c617426bbdf26e996ac8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9ded5ae40f4fe37fcc28f36d76bf45df20be5432" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/edd4600120641e1714e30112e69a548cfb68e067" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ef27324e2cb7bb24542d6cb2571740eefe6b00dc" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:00:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-ppc4-h225-m9r2/GHSA-ppc4-h225-m9r2.json b/advisories/unreviewed/2025/02/GHSA-ppc4-h225-m9r2/GHSA-ppc4-h225-m9r2.json new file mode 100644 index 00000000000..35f65c2206e --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-ppc4-h225-m9r2/GHSA-ppc4-h225-m9r2.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ppc4-h225-m9r2", + "modified": "2025-02-27T18:31:13Z", + "published": "2025-02-27T18:31:13Z", + "aliases": [ + "CVE-2025-25325" + ], + "details": "An issue in Yibin Fengguan Network Technology Co., Ltd YuPao DirectHire iOS 8.8.0 allows attackers to access sensitive user information via supplying a crafted link.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25325" + }, + { + "type": "WEB", + "url": "https://github.com/ZhouZiyi1/Vuls/blob/main/250112-YuPaoDirectHire/250112-YuPaoDirectHire.pdf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-27T16:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-pvj3-f5v8-hgxh/GHSA-pvj3-f5v8-hgxh.json b/advisories/unreviewed/2025/02/GHSA-pvj3-f5v8-hgxh/GHSA-pvj3-f5v8-hgxh.json index 0ee24a8af96..83d16c20e42 100644 --- a/advisories/unreviewed/2025/02/GHSA-pvj3-f5v8-hgxh/GHSA-pvj3-f5v8-hgxh.json +++ b/advisories/unreviewed/2025/02/GHSA-pvj3-f5v8-hgxh/GHSA-pvj3-f5v8-hgxh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pvj3-f5v8-hgxh", - "modified": "2025-02-27T03:34:05Z", + "modified": "2025-02-27T18:31:10Z", "published": "2025-02-27T03:34:05Z", "aliases": [ "CVE-2025-21759" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: mcast: extend RCU protection in igmp6_send()\n\nigmp6_send() can be called without RTNL or RCU being held.\n\nExtend RCU protection so that we can safely fetch the net pointer\nand avoid a potential UAF.\n\nNote that we no longer can use sock_alloc_send_skb() because\nipv6.igmp_sk uses GFP_KERNEL allocations which can sleep.\n\nInstead use alloc_skb() and charge the net->ipv6.igmp_sk\nsocket under RCU protection.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-27T03:15:16Z" diff --git a/advisories/unreviewed/2025/02/GHSA-q6cq-g5qv-hwc8/GHSA-q6cq-g5qv-hwc8.json b/advisories/unreviewed/2025/02/GHSA-q6cq-g5qv-hwc8/GHSA-q6cq-g5qv-hwc8.json index 3cbbfa17f43..2afeed08787 100644 --- a/advisories/unreviewed/2025/02/GHSA-q6cq-g5qv-hwc8/GHSA-q6cq-g5qv-hwc8.json +++ b/advisories/unreviewed/2025/02/GHSA-q6cq-g5qv-hwc8/GHSA-q6cq-g5qv-hwc8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-q6cq-g5qv-hwc8", - "modified": "2025-02-27T03:34:05Z", + "modified": "2025-02-27T18:31:11Z", "published": "2025-02-27T03:34:05Z", "aliases": [ "CVE-2025-21761" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nopenvswitch: use RCU protection in ovs_vport_cmd_fill_info()\n\novs_vport_cmd_fill_info() can be called without RTNL or RCU.\n\nUse RCU protection and dev_net_rcu() to avoid potential UAF.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-27T03:15:16Z" diff --git a/advisories/unreviewed/2025/02/GHSA-r42x-vw8p-w99g/GHSA-r42x-vw8p-w99g.json b/advisories/unreviewed/2025/02/GHSA-r42x-vw8p-w99g/GHSA-r42x-vw8p-w99g.json new file mode 100644 index 00000000000..6411b2dc692 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-r42x-vw8p-w99g/GHSA-r42x-vw8p-w99g.json @@ -0,0 +1,60 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r42x-vw8p-w99g", + "modified": "2025-02-27T18:31:08Z", + "published": "2025-02-27T18:31:08Z", + "aliases": [ + "CVE-2022-49053" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: target: tcmu: Fix possible page UAF\n\ntcmu_try_get_data_page() looks up pages under cmdr_lock, but it does not\ntake refcount properly and just returns page pointer. When\ntcmu_try_get_data_page() returns, the returned page may have been freed by\ntcmu_blocks_release().\n\nWe need to get_page() under cmdr_lock to avoid concurrent\ntcmu_blocks_release().", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49053" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a6968f7a367f128d120447360734344d5a3d5336" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a9564d84ed9f6ee71017d062d0d2182154294a4b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/aec36b98a1bbaa84bfd8299a306e4c12314af626" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b7f3b5d70c834f49f7d87a2f2ed1c6284d9a0322" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d7c5d79e50be6e06b669141e3db1f977a0dd4e8e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e3e0e067d5b34e4a68e3cc55f8eebc413f56f8ed" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fb7a5115422fbd6a4d505e8844f1ef5529f10489" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:00:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-v53m-h2x7-3m5p/GHSA-v53m-h2x7-3m5p.json b/advisories/unreviewed/2025/02/GHSA-v53m-h2x7-3m5p/GHSA-v53m-h2x7-3m5p.json new file mode 100644 index 00000000000..91bf0fc3d86 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-v53m-h2x7-3m5p/GHSA-v53m-h2x7-3m5p.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v53m-h2x7-3m5p", + "modified": "2025-02-27T18:31:14Z", + "published": "2025-02-27T18:31:14Z", + "aliases": [ + "CVE-2025-1743" + ], + "details": "A vulnerability, which was classified as critical, was found in zyx0814 Pichome 2.1.0. This affects an unknown part of the file /index.php?mod=textviewer. The manipulation of the argument src leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1743" + }, + { + "type": "WEB", + "url": "https://github.com/sheratan4/cve/issues/4" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.297831" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.297831" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.502168" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-27T18:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-v68h-2qqv-28r8/GHSA-v68h-2qqv-28r8.json b/advisories/unreviewed/2025/02/GHSA-v68h-2qqv-28r8/GHSA-v68h-2qqv-28r8.json new file mode 100644 index 00000000000..eb0a2b238fc --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-v68h-2qqv-28r8/GHSA-v68h-2qqv-28r8.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v68h-2qqv-28r8", + "modified": "2025-02-27T18:31:13Z", + "published": "2025-02-27T18:31:13Z", + "aliases": [ + "CVE-2025-25326" + ], + "details": "An issue in Merchants Union Consumer Finance Company Limited Merchants Union Finance iOS 6.19.0 allows attackers to access sensitive user information via supplying a crafted link.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25326" + }, + { + "type": "WEB", + "url": "https://github.com/ZhouZiyi1/Vuls/blob/main/250115-MerchantsUnionFinance/250115-MerchantsUnionFinance.pdf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-27T16:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-vcqr-h4qj-jv8g/GHSA-vcqr-h4qj-jv8g.json b/advisories/unreviewed/2025/02/GHSA-vcqr-h4qj-jv8g/GHSA-vcqr-h4qj-jv8g.json new file mode 100644 index 00000000000..f6c36e9fa01 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-vcqr-h4qj-jv8g/GHSA-vcqr-h4qj-jv8g.json @@ -0,0 +1,68 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vcqr-h4qj-jv8g", + "modified": "2025-02-27T18:31:08Z", + "published": "2025-02-27T18:31:08Z", + "aliases": [ + "CVE-2022-49085" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrbd: Fix five use after free bugs in get_initial_state\n\nIn get_initial_state, it calls notify_initial_state_done(skb,..) if\ncb->args[5]==1. If genlmsg_put() failed in notify_initial_state_done(),\nthe skb will be freed by nlmsg_free(skb).\nThen get_initial_state will goto out and the freed skb will be used by\nreturn value skb->len, which is a uaf bug.\n\nWhat's worse, the same problem goes even further: skb can also be\nfreed in the notify_*_state_change -> notify_*_state calls below.\nThus 4 additional uaf bugs happened.\n\nMy patch lets the problem callee functions: notify_initial_state_done\nand notify_*_state_change return an error code if errors happen.\nSo that the error codes could be propagated and the uaf bugs can be avoid.\n\nv2 reports a compilation warning. This v3 fixed this warning and built\nsuccessfully in my local environment with no additional warnings.\nv2: https://lore.kernel.org/patchwork/patch/1435218/", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49085" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0489700bfeb1e53eb2039c2291c67e71b0b40103" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/188fe6b26765edbad4055611c0f788b6870f4024" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/226e993c39405292781bfcf4b039a8db56aab362" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/594205b4936771a250f9d141e7e0fff21c3dd2d9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a972c768723359ec995579902473028fe3cd64b1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/aadb22ba2f656581b2f733deb3a467c48cc618f6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b6a4055036eed1f5e239ce3d8b0db1ce38bba447" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/dcf6be17b5c53b741898d2223b23e66d682de300" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/de63e74da2333b4068bb79983e632db730fea97e" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:00:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-vr2w-w74g-r822/GHSA-vr2w-w74g-r822.json b/advisories/unreviewed/2025/02/GHSA-vr2w-w74g-r822/GHSA-vr2w-w74g-r822.json index 2b270569baf..fd9fc8b6c72 100644 --- a/advisories/unreviewed/2025/02/GHSA-vr2w-w74g-r822/GHSA-vr2w-w74g-r822.json +++ b/advisories/unreviewed/2025/02/GHSA-vr2w-w74g-r822/GHSA-vr2w-w74g-r822.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vr2w-w74g-r822", - "modified": "2025-02-27T03:34:06Z", + "modified": "2025-02-27T18:31:11Z", "published": "2025-02-27T03:34:06Z", "aliases": [ "CVE-2025-21791" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nvrf: use RCU protection in l3mdev_l3_out()\n\nl3mdev_l3_out() can be called without RCU being held:\n\nraw_sendmsg()\n ip_push_pending_frames()\n ip_send_skb()\n ip_local_out()\n __ip_local_out()\n l3mdev_ip_out()\n\nAdd rcu_read_lock() / rcu_read_unlock() pair to avoid\na potential UAF.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-27T03:15:19Z" diff --git a/advisories/unreviewed/2025/02/GHSA-w66w-gg7v-xc4c/GHSA-w66w-gg7v-xc4c.json b/advisories/unreviewed/2025/02/GHSA-w66w-gg7v-xc4c/GHSA-w66w-gg7v-xc4c.json new file mode 100644 index 00000000000..26e4823dbf2 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-w66w-gg7v-xc4c/GHSA-w66w-gg7v-xc4c.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w66w-gg7v-xc4c", + "modified": "2025-02-27T18:31:14Z", + "published": "2025-02-27T18:31:14Z", + "aliases": [ + "CVE-2025-25329" + ], + "details": "An issue in Tencent Technology (Beijing) Company Limited Tencent MicroVision iOS 8.137.0 allows attackers to access sensitive user information via supplying a crafted link.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25329" + }, + { + "type": "WEB", + "url": "https://github.com/ZhouZiyi1/Vuls/blob/main/250116-TencentMicroVision/250116-TencentMicroVision.pdf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-27T17:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-w9jf-hmj5-fp54/GHSA-w9jf-hmj5-fp54.json b/advisories/unreviewed/2025/02/GHSA-w9jf-hmj5-fp54/GHSA-w9jf-hmj5-fp54.json new file mode 100644 index 00000000000..3f46dc7ca27 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-w9jf-hmj5-fp54/GHSA-w9jf-hmj5-fp54.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w9jf-hmj5-fp54", + "modified": "2025-02-27T18:31:08Z", + "published": "2025-02-27T18:31:08Z", + "aliases": [ + "CVE-2022-49390" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmacsec: fix UAF bug for real_dev\n\nCreate a new macsec device but not get reference to real_dev. That can\nnot ensure that real_dev is freed after macsec. That will trigger the\nUAF bug for real_dev as following:\n\n==================================================================\nBUG: KASAN: use-after-free in macsec_get_iflink+0x5f/0x70 drivers/net/macsec.c:3662\nCall Trace:\n ...\n macsec_get_iflink+0x5f/0x70 drivers/net/macsec.c:3662\n dev_get_iflink+0x73/0xe0 net/core/dev.c:637\n default_operstate net/core/link_watch.c:42 [inline]\n rfc2863_policy+0x233/0x2d0 net/core/link_watch.c:54\n linkwatch_do_dev+0x2a/0x150 net/core/link_watch.c:161\n\nAllocated by task 22209:\n ...\n alloc_netdev_mqs+0x98/0x1100 net/core/dev.c:10549\n rtnl_create_link+0x9d7/0xc00 net/core/rtnetlink.c:3235\n veth_newlink+0x20e/0xa90 drivers/net/veth.c:1748\n\nFreed by task 8:\n ...\n kfree+0xd6/0x4d0 mm/slub.c:4552\n kvfree+0x42/0x50 mm/util.c:615\n device_release+0x9f/0x240 drivers/base/core.c:2229\n kobject_cleanup lib/kobject.c:673 [inline]\n kobject_release lib/kobject.c:704 [inline]\n kref_put include/linux/kref.h:65 [inline]\n kobject_put+0x1c8/0x540 lib/kobject.c:721\n netdev_run_todo+0x72e/0x10b0 net/core/dev.c:10327\n\nAfter commit faab39f63c1f (\"net: allow out-of-order netdev unregistration\")\nand commit e5f80fcf869a (\"ipv6: give an IPv6 dev to blackhole_netdev\"), we\ncan add dev_hold_track() in macsec_dev_init() and dev_put_track() in\nmacsec_free_netdev() to fix the problem.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49390" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/196a888ca6571deb344468e1d7138e3273206335" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/78933cbc143b82d02330e00900d2fd08f2682f4e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d130282179aa6051449ac8f8df1115769998a665" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-wm97-xp23-f4x4/GHSA-wm97-xp23-f4x4.json b/advisories/unreviewed/2025/02/GHSA-wm97-xp23-f4x4/GHSA-wm97-xp23-f4x4.json index e52c446b314..df89cd724ff 100644 --- a/advisories/unreviewed/2025/02/GHSA-wm97-xp23-f4x4/GHSA-wm97-xp23-f4x4.json +++ b/advisories/unreviewed/2025/02/GHSA-wm97-xp23-f4x4/GHSA-wm97-xp23-f4x4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wm97-xp23-f4x4", - "modified": "2025-02-27T03:34:05Z", + "modified": "2025-02-27T18:31:10Z", "published": "2025-02-27T03:34:05Z", "aliases": [ "CVE-2025-21760" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nndisc: extend RCU protection in ndisc_send_skb()\n\nndisc_send_skb() can be called without RTNL or RCU held.\n\nAcquire rcu_read_lock() earlier, so that we can use dev_net_rcu()\nand avoid a potential UAF.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-27T03:15:16Z" diff --git a/advisories/unreviewed/2025/02/GHSA-wqcr-wj43-4gg7/GHSA-wqcr-wj43-4gg7.json b/advisories/unreviewed/2025/02/GHSA-wqcr-wj43-4gg7/GHSA-wqcr-wj43-4gg7.json index 0e0600e4058..914550e93ef 100644 --- a/advisories/unreviewed/2025/02/GHSA-wqcr-wj43-4gg7/GHSA-wqcr-wj43-4gg7.json +++ b/advisories/unreviewed/2025/02/GHSA-wqcr-wj43-4gg7/GHSA-wqcr-wj43-4gg7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wqcr-wj43-4gg7", - "modified": "2025-02-27T03:33:59Z", + "modified": "2025-02-27T18:31:09Z", "published": "2025-02-27T03:33:59Z", "aliases": [ "CVE-2024-57984" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ni3c: dw: Fix use-after-free in dw_i3c_master driver due to race condition\n\nIn dw_i3c_common_probe, &master->hj_work is bound with\ndw_i3c_hj_work. And dw_i3c_master_irq_handler can call\ndw_i3c_master_irq_handle_ibis function to start the work.\n\nIf we remove the module which will call dw_i3c_common_remove to\nmake cleanup, it will free master->base through i3c_master_unregister\nwhile the work mentioned above will be used. The sequence of operations\nthat may lead to a UAF bug is as follows:\n\nCPU0 CPU1\n\n | dw_i3c_hj_work\ndw_i3c_common_remove |\ni3c_master_unregister(&master->base) |\ndevice_unregister(&master->dev) |\ndevice_release |\n//free master->base |\n | i3c_master_do_daa(&master->base)\n | //use master->base\n\nFix it by ensuring that the work is canceled before proceeding with\nthe cleanup in dw_i3c_common_remove.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-27T02:15:11Z" diff --git a/advisories/unreviewed/2025/02/GHSA-wvmf-xh97-gmfr/GHSA-wvmf-xh97-gmfr.json b/advisories/unreviewed/2025/02/GHSA-wvmf-xh97-gmfr/GHSA-wvmf-xh97-gmfr.json index 6a626ff5227..cc9a96c594d 100644 --- a/advisories/unreviewed/2025/02/GHSA-wvmf-xh97-gmfr/GHSA-wvmf-xh97-gmfr.json +++ b/advisories/unreviewed/2025/02/GHSA-wvmf-xh97-gmfr/GHSA-wvmf-xh97-gmfr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wvmf-xh97-gmfr", - "modified": "2025-02-27T03:34:02Z", + "modified": "2025-02-27T18:31:09Z", "published": "2025-02-27T03:34:02Z", "aliases": [ "CVE-2025-21727" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\npadata: fix UAF in padata_reorder\n\nA bug was found when run ltp test:\n\nBUG: KASAN: slab-use-after-free in padata_find_next+0x29/0x1a0\nRead of size 4 at addr ffff88bbfe003524 by task kworker/u113:2/3039206\n\nCPU: 0 PID: 3039206 Comm: kworker/u113:2 Kdump: loaded Not tainted 6.6.0+\nWorkqueue: pdecrypt_parallel padata_parallel_worker\nCall Trace:\n\ndump_stack_lvl+0x32/0x50\nprint_address_description.constprop.0+0x6b/0x3d0\nprint_report+0xdd/0x2c0\nkasan_report+0xa5/0xd0\npadata_find_next+0x29/0x1a0\npadata_reorder+0x131/0x220\npadata_parallel_worker+0x3d/0xc0\nprocess_one_work+0x2ec/0x5a0\n\nIf 'mdelay(10)' is added before calling 'padata_find_next' in the\n'padata_reorder' function, this issue could be reproduced easily with\nltp test (pcrypt_aead01).\n\nThis can be explained as bellow:\n\npcrypt_aead_encrypt\n...\npadata_do_parallel\nrefcount_inc(&pd->refcnt); // add refcnt\n...\npadata_do_serial\npadata_reorder // pd\nwhile (1) {\npadata_find_next(pd, true); // using pd\nqueue_work_on\n...\npadata_serial_worker\t\t\t\tcrypto_del_alg\npadata_put_pd_cnt // sub refcnt\n\t\t\t\t\t\tpadata_free_shell\n\t\t\t\t\t\tpadata_put_pd(ps->pd);\n\t\t\t\t\t\t// pd is freed\n// loop again, but pd is freed\n// call padata_find_next, UAF\n}\n\nIn the padata_reorder function, when it loops in 'while', if the alg is\ndeleted, the refcnt may be decreased to 0 before entering\n'padata_find_next', which leads to UAF.\n\nAs mentioned in [1], do_serial is supposed to be called with BHs disabled\nand always happen under RCU protection, to address this issue, add\nsynchronize_rcu() in 'padata_free_shell' wait for all _do_serial calls\nto finish.\n\n[1] https://lore.kernel.org/all/20221028160401.cccypv4euxikusiq@parnassus.localdomain/\n[2] https://lore.kernel.org/linux-kernel/jfjz5d7zwbytztackem7ibzalm5lnxldi2eofeiczqmqs2m7o6@fq426cwnjtkm/", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-27T02:15:16Z"