From 63ede572cb17f56a4f9ded5967961ad5d424a155 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 8 Jan 2025 18:32:35 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-ffmc-4rrr-xm85.json | 3 +- .../GHSA-wf52-5wvv-68vv.json | 2 +- .../GHSA-gp56-58fv-r42c.json | 6 ++- .../GHSA-r526-pvv3-w6p8.json | 6 ++- .../GHSA-5fx7-qfg5-mpmc.json | 15 ++++-- .../GHSA-92wm-282g-vw3w.json | 15 ++++-- .../GHSA-94mv-98xv-9mqq.json | 15 ++++-- .../GHSA-98fc-82jh-j626.json | 11 ++-- .../GHSA-c4q6-cxg2-pxc8.json | 15 ++++-- .../GHSA-c4xm-6jcf-xfq6.json | 15 ++++-- .../GHSA-gc58-f6gq-w9xv.json | 11 ++-- .../GHSA-h3qj-j9m5-8ffr.json | 11 ++-- .../GHSA-hmgx-rfwx-3mvq.json | 11 ++-- .../GHSA-jfx3-f7mg-7cp3.json | 11 ++-- .../GHSA-jvv7-jhh3-m96v.json | 11 ++-- .../GHSA-m99h-2hm4-q649.json | 11 ++-- .../GHSA-mvm9-g6f5-rfmr.json | 11 ++-- .../GHSA-p768-cw2x-34vr.json | 11 ++-- .../GHSA-pvcm-vr92-9wx7.json | 15 ++++-- .../GHSA-q466-f768-77v8.json | 15 ++++-- .../GHSA-rcvc-x6h8-mpp2.json | 15 ++++-- .../GHSA-45hm-gg77-pjg9.json | 4 +- .../GHSA-4h58-gcmv-6qjq.json | 6 ++- .../GHSA-58qv-qvf3-f8mp.json | 15 ++++-- .../GHSA-c33g-4mp4-9vx4.json | 6 ++- .../GHSA-c6h8-8xgj-56vw.json | 4 +- .../GHSA-fv2v-wvxg-x978.json | 6 ++- .../GHSA-hjp2-wg69-g55x.json | 4 +- .../GHSA-pcgx-35gv-6fvj.json | 6 ++- .../GHSA-r345-j492-57q4.json | 1 + .../GHSA-vxwm-wx7w-rvwj.json | 6 ++- .../GHSA-2jc9-36w4-pmqw.json | 3 +- .../GHSA-2mcw-fg5h-w8g7.json | 4 +- .../GHSA-2q2v-8vjq-r8m5.json | 6 ++- .../GHSA-4qwp-4p88-ww2v.json | 6 ++- .../GHSA-4ww3-585w-6p9r.json | 1 + .../GHSA-53gv-p4jm-h5xv.json | 4 +- .../GHSA-5mgw-pvjq-2c2v.json | 6 ++- .../GHSA-73p8-jp88-9jjm.json | 1 + .../GHSA-7jq6-7f95-hv67.json | 4 +- .../GHSA-86p8-qv4v-vv9r.json | 1 + .../GHSA-8g89-49x9-pqr8.json | 1 + .../GHSA-cw34-gw9h-rxc6.json | 1 + .../GHSA-cwxc-rm5r-crmq.json | 4 +- .../GHSA-f3x6-c3gw-gv5x.json | 4 +- .../GHSA-jjch-qg3j-855w.json | 1 + .../GHSA-pcjj-9wx4-9phh.json | 4 +- .../GHSA-qr85-xmff-4wqh.json | 4 +- .../GHSA-r8v8-787r-c5p4.json | 4 +- .../GHSA-rjmx-4pf7-6fpx.json | 3 +- .../GHSA-rvh5-mpf7-h5hf.json | 1 + .../GHSA-mhcv-2f7w-4c7r.json | 3 +- .../GHSA-qj72-6765-vjx4.json | 1 + .../GHSA-2rhh-63xh-7gv7.json | 4 +- .../GHSA-hcq4-pvmg-m2gp.json | 1 + .../GHSA-x3xf-ggm9-v393.json | 4 +- .../GHSA-2c9f-4h7m-wqr9.json | 15 ++++-- .../GHSA-3h64-ff22-jvm6.json | 15 ++++-- .../GHSA-3px9-r72j-9hxj.json | 15 ++++-- .../GHSA-5xcw-9q32-27qc.json | 15 ++++-- .../GHSA-6779-v6gp-jmxv.json | 15 ++++-- .../GHSA-68cq-j9f2-ggv4.json | 15 ++++-- .../GHSA-84gj-7736-4xgg.json | 15 ++++-- .../GHSA-89vj-8q5m-mj67.json | 15 ++++-- .../GHSA-9pg7-c56m-xqjx.json | 15 ++++-- .../GHSA-f225-f9rp-hg69.json | 15 ++++-- .../GHSA-g3c8-2g4x-qq2h.json | 15 ++++-- .../GHSA-gh74-96w4-8m3h.json | 15 ++++-- .../GHSA-gw7x-jcrq-44c3.json | 15 ++++-- .../GHSA-h345-5w6p-mhwf.json | 15 ++++-- .../GHSA-hm4v-3pg5-6f5c.json | 15 ++++-- .../GHSA-j53q-3928-9255.json | 15 ++++-- .../GHSA-m39v-c9r9-vmwh.json | 15 ++++-- .../GHSA-q94m-6jg9-pcmh.json | 15 ++++-- .../GHSA-qqv2-5qvx-v346.json | 15 ++++-- .../GHSA-qrq9-5x8v-ghpv.json | 15 ++++-- .../GHSA-v859-83xr-7x5w.json | 15 ++++-- .../GHSA-v9jf-g2rr-85c3.json | 15 ++++-- .../GHSA-vww8-w2qw-qhfg.json | 15 ++++-- .../GHSA-23fx-r767-q5g7.json | 11 ++-- .../GHSA-2776-h8x3-vrr7.json | 15 ++++-- .../GHSA-27cc-fvv7-2rh9.json | 37 +++++++++++++ .../GHSA-2g52-qw8q-wfr9.json | 11 ++-- .../GHSA-43hc-8q23-h42p.json | 15 ++++-- .../GHSA-4g5v-5q43-rwpj.json | 49 +++++++++++++++++ .../GHSA-4rjf-m3j3-4xh4.json | 29 ++++++++++ .../GHSA-56h9-9qx5-f7gf.json | 36 +++++++++++++ .../GHSA-5c45-mgcf-3hhj.json | 36 +++++++++++++ .../GHSA-5grh-jq56-9254.json | 15 ++++-- .../GHSA-5gvr-6wv7-hpcv.json | 11 ++-- .../GHSA-5hp7-929x-xgf8.json | 11 ++-- .../GHSA-68r8-f4jc-vc2p.json | 15 ++++-- .../GHSA-6prq-q63r-xqhp.json | 15 ++++-- .../GHSA-79x5-rf42-8f32.json | 40 ++++++++++++++ .../GHSA-7x89-2c7c-8xjf.json | 40 ++++++++++++++ .../GHSA-87rx-3vxp-6r9f.json | 52 ++++++++++++++++++ .../GHSA-89r5-96wf-852f.json | 15 ++++-- .../GHSA-928f-3rxq-5jvp.json | 11 ++-- .../GHSA-93c4-8fxm-4wq3.json | 45 ++++++++++++++++ .../GHSA-95w3-8433-6jf6.json | 53 +++++++++++++++++++ .../GHSA-9vgr-6gpq-2rj5.json | 41 ++++++++++++++ .../GHSA-cjgq-5qmw-rcj6.json | 48 +++++++++++++++++ .../GHSA-f3xq-g93v-w8cv.json | 15 ++++-- .../GHSA-f4vg-m386-rcvq.json | 33 ++++++++++++ .../GHSA-h4qv-2mm7-9gwm.json | 41 ++++++++++++++ .../GHSA-hwmv-fpmh-92pc.json | 40 ++++++++++++++ .../GHSA-j3fj-gjrj-c97q.json | 33 ++++++++++++ .../GHSA-jcv7-vfq5-hj4c.json | 15 ++++-- .../GHSA-jwc2-hj9w-9cff.json | 40 ++++++++++++++ .../GHSA-m6c8-mv97-5jcm.json | 45 ++++++++++++++++ .../GHSA-m7p9-xw5x-w2c4.json | 53 +++++++++++++++++++ .../GHSA-p48v-w2c7-4756.json | 29 ++++++++++ .../GHSA-p4q7-g7ff-823j.json | 15 ++++-- .../GHSA-p52h-3642-m4x3.json | 11 ++-- .../GHSA-phcc-6pmp-qw9v.json | 15 ++++-- .../GHSA-phf7-cpqm-749x.json | 45 ++++++++++++++++ .../GHSA-pj5p-wjjg-q3w5.json | 15 ++++-- .../GHSA-pm49-6j2c-6857.json | 33 ++++++++++++ .../GHSA-pxgr-mfpf-3qxj.json | 11 ++-- .../GHSA-q9q4-8gjg-4w35.json | 40 ++++++++++++++ .../GHSA-qjmp-rfrj-7cv5.json | 15 ++++-- .../GHSA-qw28-p6qx-vj78.json | 15 ++++-- .../GHSA-r7gg-4xq2-48h9.json | 15 ++++-- .../GHSA-rpgv-42mm-c94j.json | 15 ++++-- .../GHSA-v6jm-7r7p-9979.json | 53 +++++++++++++++++++ .../GHSA-v6xw-pf6j-mpfg.json | 33 ++++++++++++ .../GHSA-w3jp-95q8-wv48.json | 15 ++++-- .../GHSA-w4pw-p565-4p8w.json | 45 ++++++++++++++++ .../GHSA-w5c9-x85v-xrxm.json | 33 ++++++++++++ .../GHSA-w993-3vv8-hxp8.json | 33 ++++++++++++ .../GHSA-x99c-gp84-c52f.json | 53 +++++++++++++++++++ .../GHSA-x9pj-5qm2-7p6v.json | 45 ++++++++++++++++ .../GHSA-xwpw-pxrm-39pm.json | 11 ++-- 133 files changed, 1995 insertions(+), 281 deletions(-) create mode 100644 advisories/unreviewed/2025/01/GHSA-27cc-fvv7-2rh9/GHSA-27cc-fvv7-2rh9.json create mode 100644 advisories/unreviewed/2025/01/GHSA-4g5v-5q43-rwpj/GHSA-4g5v-5q43-rwpj.json create mode 100644 advisories/unreviewed/2025/01/GHSA-4rjf-m3j3-4xh4/GHSA-4rjf-m3j3-4xh4.json create mode 100644 advisories/unreviewed/2025/01/GHSA-56h9-9qx5-f7gf/GHSA-56h9-9qx5-f7gf.json create mode 100644 advisories/unreviewed/2025/01/GHSA-5c45-mgcf-3hhj/GHSA-5c45-mgcf-3hhj.json create mode 100644 advisories/unreviewed/2025/01/GHSA-79x5-rf42-8f32/GHSA-79x5-rf42-8f32.json create mode 100644 advisories/unreviewed/2025/01/GHSA-7x89-2c7c-8xjf/GHSA-7x89-2c7c-8xjf.json create mode 100644 advisories/unreviewed/2025/01/GHSA-87rx-3vxp-6r9f/GHSA-87rx-3vxp-6r9f.json create mode 100644 advisories/unreviewed/2025/01/GHSA-93c4-8fxm-4wq3/GHSA-93c4-8fxm-4wq3.json create mode 100644 advisories/unreviewed/2025/01/GHSA-95w3-8433-6jf6/GHSA-95w3-8433-6jf6.json create mode 100644 advisories/unreviewed/2025/01/GHSA-9vgr-6gpq-2rj5/GHSA-9vgr-6gpq-2rj5.json create mode 100644 advisories/unreviewed/2025/01/GHSA-cjgq-5qmw-rcj6/GHSA-cjgq-5qmw-rcj6.json create mode 100644 advisories/unreviewed/2025/01/GHSA-f4vg-m386-rcvq/GHSA-f4vg-m386-rcvq.json create mode 100644 advisories/unreviewed/2025/01/GHSA-h4qv-2mm7-9gwm/GHSA-h4qv-2mm7-9gwm.json create mode 100644 advisories/unreviewed/2025/01/GHSA-hwmv-fpmh-92pc/GHSA-hwmv-fpmh-92pc.json create mode 100644 advisories/unreviewed/2025/01/GHSA-j3fj-gjrj-c97q/GHSA-j3fj-gjrj-c97q.json create mode 100644 advisories/unreviewed/2025/01/GHSA-jwc2-hj9w-9cff/GHSA-jwc2-hj9w-9cff.json create mode 100644 advisories/unreviewed/2025/01/GHSA-m6c8-mv97-5jcm/GHSA-m6c8-mv97-5jcm.json create mode 100644 advisories/unreviewed/2025/01/GHSA-m7p9-xw5x-w2c4/GHSA-m7p9-xw5x-w2c4.json create mode 100644 advisories/unreviewed/2025/01/GHSA-p48v-w2c7-4756/GHSA-p48v-w2c7-4756.json create mode 100644 advisories/unreviewed/2025/01/GHSA-phf7-cpqm-749x/GHSA-phf7-cpqm-749x.json create mode 100644 advisories/unreviewed/2025/01/GHSA-pm49-6j2c-6857/GHSA-pm49-6j2c-6857.json create mode 100644 advisories/unreviewed/2025/01/GHSA-q9q4-8gjg-4w35/GHSA-q9q4-8gjg-4w35.json create mode 100644 advisories/unreviewed/2025/01/GHSA-v6jm-7r7p-9979/GHSA-v6jm-7r7p-9979.json create mode 100644 advisories/unreviewed/2025/01/GHSA-v6xw-pf6j-mpfg/GHSA-v6xw-pf6j-mpfg.json create mode 100644 advisories/unreviewed/2025/01/GHSA-w4pw-p565-4p8w/GHSA-w4pw-p565-4p8w.json create mode 100644 advisories/unreviewed/2025/01/GHSA-w5c9-x85v-xrxm/GHSA-w5c9-x85v-xrxm.json create mode 100644 advisories/unreviewed/2025/01/GHSA-w993-3vv8-hxp8/GHSA-w993-3vv8-hxp8.json create mode 100644 advisories/unreviewed/2025/01/GHSA-x99c-gp84-c52f/GHSA-x99c-gp84-c52f.json create mode 100644 advisories/unreviewed/2025/01/GHSA-x9pj-5qm2-7p6v/GHSA-x9pj-5qm2-7p6v.json diff --git a/advisories/unreviewed/2023/06/GHSA-ffmc-4rrr-xm85/GHSA-ffmc-4rrr-xm85.json b/advisories/unreviewed/2023/06/GHSA-ffmc-4rrr-xm85/GHSA-ffmc-4rrr-xm85.json index 47474e9657e..f662cf3b9f8 100644 --- a/advisories/unreviewed/2023/06/GHSA-ffmc-4rrr-xm85/GHSA-ffmc-4rrr-xm85.json +++ b/advisories/unreviewed/2023/06/GHSA-ffmc-4rrr-xm85/GHSA-ffmc-4rrr-xm85.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-269" + "CWE-269", + "CWE-863" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/06/GHSA-wf52-5wvv-68vv/GHSA-wf52-5wvv-68vv.json b/advisories/unreviewed/2023/06/GHSA-wf52-5wvv-68vv/GHSA-wf52-5wvv-68vv.json index 002110b8d7b..d1f9f90cde7 100644 --- a/advisories/unreviewed/2023/06/GHSA-wf52-5wvv-68vv/GHSA-wf52-5wvv-68vv.json +++ b/advisories/unreviewed/2023/06/GHSA-wf52-5wvv-68vv/GHSA-wf52-5wvv-68vv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wf52-5wvv-68vv", - "modified": "2023-11-25T12:30:22Z", + "modified": "2025-01-08T18:30:40Z", "published": "2023-06-07T21:30:18Z", "aliases": [ "CVE-2023-33864" diff --git a/advisories/unreviewed/2023/11/GHSA-gp56-58fv-r42c/GHSA-gp56-58fv-r42c.json b/advisories/unreviewed/2023/11/GHSA-gp56-58fv-r42c/GHSA-gp56-58fv-r42c.json index e2f3e476b66..e97c652a1b7 100644 --- a/advisories/unreviewed/2023/11/GHSA-gp56-58fv-r42c/GHSA-gp56-58fv-r42c.json +++ b/advisories/unreviewed/2023/11/GHSA-gp56-58fv-r42c/GHSA-gp56-58fv-r42c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gp56-58fv-r42c", - "modified": "2023-11-18T00:30:17Z", + "modified": "2025-01-08T18:30:40Z", "published": "2023-11-14T06:30:19Z", "aliases": [ "CVE-2023-43902" @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-276" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/11/GHSA-r526-pvv3-w6p8/GHSA-r526-pvv3-w6p8.json b/advisories/unreviewed/2023/11/GHSA-r526-pvv3-w6p8/GHSA-r526-pvv3-w6p8.json index 004312ab1fd..9c6ca1843d9 100644 --- a/advisories/unreviewed/2023/11/GHSA-r526-pvv3-w6p8/GHSA-r526-pvv3-w6p8.json +++ b/advisories/unreviewed/2023/11/GHSA-r526-pvv3-w6p8/GHSA-r526-pvv3-w6p8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r526-pvv3-w6p8", - "modified": "2023-11-18T00:30:17Z", + "modified": "2025-01-08T18:30:40Z", "published": "2023-11-14T06:30:19Z", "aliases": [ "CVE-2023-45878" @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-5fx7-qfg5-mpmc/GHSA-5fx7-qfg5-mpmc.json b/advisories/unreviewed/2024/02/GHSA-5fx7-qfg5-mpmc/GHSA-5fx7-qfg5-mpmc.json index 21b49ceec0c..01a58f9233f 100644 --- a/advisories/unreviewed/2024/02/GHSA-5fx7-qfg5-mpmc/GHSA-5fx7-qfg5-mpmc.json +++ b/advisories/unreviewed/2024/02/GHSA-5fx7-qfg5-mpmc/GHSA-5fx7-qfg5-mpmc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5fx7-qfg5-mpmc", - "modified": "2024-02-27T21:31:27Z", + "modified": "2025-01-08T18:30:40Z", "published": "2024-02-27T21:31:27Z", "aliases": [ "CVE-2021-46972" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\novl: fix leaked dentry\n\nSince commit 6815f479ca90 (\"ovl: use only uppermetacopy state in\novl_lookup()\"), overlayfs doesn't put temporary dentry when there is a\nmetacopy error, which leads to dentry leaks when shutting down the related\nsuperblock:\n\n overlayfs: refusing to follow metacopy origin for (/file0)\n ...\n BUG: Dentry (____ptrval____){i=3f33,n=file3} still in use (1) [unmount of overlay overlay]\n ...\n WARNING: CPU: 1 PID: 432 at umount_check.cold+0x107/0x14d\n CPU: 1 PID: 432 Comm: unmount-overlay Not tainted 5.12.0-rc5 #1\n ...\n RIP: 0010:umount_check.cold+0x107/0x14d\n ...\n Call Trace:\n d_walk+0x28c/0x950\n ? dentry_lru_isolate+0x2b0/0x2b0\n ? __kasan_slab_free+0x12/0x20\n do_one_tree+0x33/0x60\n shrink_dcache_for_umount+0x78/0x1d0\n generic_shutdown_super+0x70/0x440\n kill_anon_super+0x3e/0x70\n deactivate_locked_super+0xc4/0x160\n deactivate_super+0xfa/0x140\n cleanup_mnt+0x22e/0x370\n __cleanup_mnt+0x1a/0x30\n task_work_run+0x139/0x210\n do_exit+0xb0c/0x2820\n ? __kasan_check_read+0x1d/0x30\n ? find_held_lock+0x35/0x160\n ? lock_release+0x1b6/0x660\n ? mm_update_next_owner+0xa20/0xa20\n ? reacquire_held_locks+0x3f0/0x3f0\n ? __sanitizer_cov_trace_const_cmp4+0x22/0x30\n do_group_exit+0x135/0x380\n __do_sys_exit_group.isra.0+0x20/0x20\n __x64_sys_exit_group+0x3c/0x50\n do_syscall_64+0x45/0x70\n entry_SYSCALL_64_after_hwframe+0x44/0xae\n ...\n VFS: Busy inodes after unmount of overlay. Self-destruct in 5 seconds. Have a nice day...\n\nThis fix has been tested with a syzkaller reproducer.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-27T19:04:07Z" diff --git a/advisories/unreviewed/2024/02/GHSA-92wm-282g-vw3w/GHSA-92wm-282g-vw3w.json b/advisories/unreviewed/2024/02/GHSA-92wm-282g-vw3w/GHSA-92wm-282g-vw3w.json index 2c944836c41..820cc025afc 100644 --- a/advisories/unreviewed/2024/02/GHSA-92wm-282g-vw3w/GHSA-92wm-282g-vw3w.json +++ b/advisories/unreviewed/2024/02/GHSA-92wm-282g-vw3w/GHSA-92wm-282g-vw3w.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-92wm-282g-vw3w", - "modified": "2024-02-28T09:30:37Z", + "modified": "2025-01-08T18:30:41Z", "published": "2024-02-28T09:30:37Z", "aliases": [ "CVE-2021-47007" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix panic during f2fs_resize_fs()\n\nf2fs_resize_fs() hangs in below callstack with testcase:\n- mkfs 16GB image & mount image\n- dd 8GB fileA\n- dd 8GB fileB\n- sync\n- rm fileA\n- sync\n- resize filesystem to 8GB\n\nkernel BUG at segment.c:2484!\nCall Trace:\n allocate_segment_by_default+0x92/0xf0 [f2fs]\n f2fs_allocate_data_block+0x44b/0x7e0 [f2fs]\n do_write_page+0x5a/0x110 [f2fs]\n f2fs_outplace_write_data+0x55/0x100 [f2fs]\n f2fs_do_write_data_page+0x392/0x850 [f2fs]\n move_data_page+0x233/0x320 [f2fs]\n do_garbage_collect+0x14d9/0x1660 [f2fs]\n free_segment_range+0x1f7/0x310 [f2fs]\n f2fs_resize_fs+0x118/0x330 [f2fs]\n __f2fs_ioctl+0x487/0x3680 [f2fs]\n __x64_sys_ioctl+0x8e/0xd0\n do_syscall_64+0x33/0x80\n entry_SYSCALL_64_after_hwframe+0x44/0xa9\n\nThe root cause is we forgot to check that whether we have enough space\nin resized filesystem to store all valid blocks in before-resizing\nfilesystem, then allocator will run out-of-space during block migration\nin free_segment_range().", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-754" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-28T09:15:38Z" diff --git a/advisories/unreviewed/2024/02/GHSA-94mv-98xv-9mqq/GHSA-94mv-98xv-9mqq.json b/advisories/unreviewed/2024/02/GHSA-94mv-98xv-9mqq/GHSA-94mv-98xv-9mqq.json index de52138661d..3a102c5d5ba 100644 --- a/advisories/unreviewed/2024/02/GHSA-94mv-98xv-9mqq/GHSA-94mv-98xv-9mqq.json +++ b/advisories/unreviewed/2024/02/GHSA-94mv-98xv-9mqq/GHSA-94mv-98xv-9mqq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-94mv-98xv-9mqq", - "modified": "2024-02-28T09:30:37Z", + "modified": "2025-01-08T18:30:41Z", "published": "2024-02-28T09:30:37Z", "aliases": [ "CVE-2021-47014" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: act_ct: fix wild memory access when clearing fragments\n\nwhile testing re-assembly/re-fragmentation using act_ct, it's possible to\nobserve a crash like the following one:\n\n KASAN: maybe wild-memory-access in range [0x0001000000000448-0x000100000000044f]\n CPU: 50 PID: 0 Comm: swapper/50 Tainted: G S 5.12.0-rc7+ #424\n Hardware name: Dell Inc. PowerEdge R730/072T6D, BIOS 2.4.3 01/17/2017\n RIP: 0010:inet_frag_rbtree_purge+0x50/0xc0\n Code: 00 fc ff df 48 89 c3 31 ed 48 89 df e8 a9 7a 38 ff 4c 89 fe 48 89 df 49 89 c6 e8 5b 3a 38 ff 48 8d 7b 40 48 89 f8 48 c1 e8 03 <42> 80 3c 20 00 75 59 48 8d bb d0 00 00 00 4c 8b 6b 40 48 89 f8 48\n RSP: 0018:ffff888c31449db8 EFLAGS: 00010203\n RAX: 0000200000000089 RBX: 000100000000040e RCX: ffffffff989eb960\n RDX: 0000000000000140 RSI: ffffffff97cfb977 RDI: 000100000000044e\n RBP: 0000000000000900 R08: 0000000000000000 R09: ffffed1186289350\n R10: 0000000000000003 R11: ffffed1186289350 R12: dffffc0000000000\n R13: 000100000000040e R14: 0000000000000000 R15: ffff888155e02160\n FS: 0000000000000000(0000) GS:ffff888c31440000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 00005600cb70a5b8 CR3: 0000000a2c014005 CR4: 00000000003706e0\n DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n Call Trace:\n \n inet_frag_destroy+0xa9/0x150\n call_timer_fn+0x2d/0x180\n run_timer_softirq+0x4fe/0xe70\n __do_softirq+0x197/0x5a0\n irq_exit_rcu+0x1de/0x200\n sysvec_apic_timer_interrupt+0x6b/0x80\n \n\nwhen act_ct temporarily stores an IP fragment, restoring the skb qdisc cb\nresults in putting random data in FRAG_CB(), and this causes those \"wild\"\nmemory accesses later, when the rbtree is purged. Never overwrite the skb\ncb in case tcf_ct_handle_fragments() returns -EINPROGRESS.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-754" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-28T09:15:38Z" diff --git a/advisories/unreviewed/2024/02/GHSA-98fc-82jh-j626/GHSA-98fc-82jh-j626.json b/advisories/unreviewed/2024/02/GHSA-98fc-82jh-j626/GHSA-98fc-82jh-j626.json index 1cdf7ac1844..73d80917731 100644 --- a/advisories/unreviewed/2024/02/GHSA-98fc-82jh-j626/GHSA-98fc-82jh-j626.json +++ b/advisories/unreviewed/2024/02/GHSA-98fc-82jh-j626/GHSA-98fc-82jh-j626.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-98fc-82jh-j626", - "modified": "2024-02-28T09:30:37Z", + "modified": "2025-01-08T18:30:41Z", "published": "2024-02-28T09:30:37Z", "aliases": [ "CVE-2021-47004" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to avoid touching checkpointed data in get_victim()\n\nIn CP disabling mode, there are two issues when using LFS or SSR | AT_SSR\nmode to select victim:\n\n1. LFS is set to find source section during GC, the victim should have\nno checkpointed data, since after GC, section could not be set free for\nreuse.\n\nPreviously, we only check valid chpt blocks in current segment rather\nthan section, fix it.\n\n2. SSR | AT_SSR are set to find target segment for writes which can be\nfully filled by checkpointed and newly written blocks, we should never\nselect such segment, otherwise it can cause panic or data corruption\nduring allocation, potential case is described as below:\n\n a) target segment has 'n' (n < 512) ckpt valid blocks\n b) GC migrates 'n' valid blocks to other segment (segment is still\n in dirty list)\n c) GC migrates '512 - n' blocks to target segment (segment has 'n'\n cp_vblocks and '512 - n' vblocks)\n d) If GC selects target segment via {AT,}SSR allocator, however there\n is no free space in targe segment.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -33,7 +38,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-28T09:15:38Z" diff --git a/advisories/unreviewed/2024/02/GHSA-c4q6-cxg2-pxc8/GHSA-c4q6-cxg2-pxc8.json b/advisories/unreviewed/2024/02/GHSA-c4q6-cxg2-pxc8/GHSA-c4q6-cxg2-pxc8.json index dff94ad1647..b71b8f993ff 100644 --- a/advisories/unreviewed/2024/02/GHSA-c4q6-cxg2-pxc8/GHSA-c4q6-cxg2-pxc8.json +++ b/advisories/unreviewed/2024/02/GHSA-c4q6-cxg2-pxc8/GHSA-c4q6-cxg2-pxc8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c4q6-cxg2-pxc8", - "modified": "2024-02-27T21:31:27Z", + "modified": "2025-01-08T18:30:40Z", "published": "2024-02-27T21:31:27Z", "aliases": [ "CVE-2021-46969" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbus: mhi: core: Fix invalid error returning in mhi_queue\n\nmhi_queue returns an error when the doorbell is not accessible in\nthe current state. This can happen when the device is in non M0\nstate, like M3, and needs to be waken-up prior ringing the DB. This\ncase is managed earlier by triggering an asynchronous M3 exit via\ncontroller resume/suspend callbacks, that in turn will cause M0\ntransition and DB update.\n\nSo, since it's not an error but just delaying of doorbell update, there\nis no reason to return an error.\n\nThis also fixes a use after free error for skb case, indeed a caller\nqueuing skb will try to free the skb if the queueing fails, but in\nthat case queueing has been done.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-27T19:04:07Z" diff --git a/advisories/unreviewed/2024/02/GHSA-c4xm-6jcf-xfq6/GHSA-c4xm-6jcf-xfq6.json b/advisories/unreviewed/2024/02/GHSA-c4xm-6jcf-xfq6/GHSA-c4xm-6jcf-xfq6.json index 30b99876a00..f7744f23d67 100644 --- a/advisories/unreviewed/2024/02/GHSA-c4xm-6jcf-xfq6/GHSA-c4xm-6jcf-xfq6.json +++ b/advisories/unreviewed/2024/02/GHSA-c4xm-6jcf-xfq6/GHSA-c4xm-6jcf-xfq6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c4xm-6jcf-xfq6", - "modified": "2024-02-28T09:30:37Z", + "modified": "2025-01-08T18:30:40Z", "published": "2024-02-28T09:30:37Z", "aliases": [ "CVE-2021-46999" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: do asoc update earlier in sctp_sf_do_dupcook_a\n\nThere's a panic that occurs in a few of envs, the call trace is as below:\n\n [] general protection fault, ... 0x29acd70f1000a: 0000 [#1] SMP PTI\n [] RIP: 0010:sctp_ulpevent_notify_peer_addr_change+0x4b/0x1fa [sctp]\n [] sctp_assoc_control_transport+0x1b9/0x210 [sctp]\n [] sctp_do_8_2_transport_strike.isra.16+0x15c/0x220 [sctp]\n [] sctp_cmd_interpreter.isra.21+0x1231/0x1a10 [sctp]\n [] sctp_do_sm+0xc3/0x2a0 [sctp]\n [] sctp_generate_timeout_event+0x81/0xf0 [sctp]\n\nThis is caused by a transport use-after-free issue. When processing a\nduplicate COOKIE-ECHO chunk in sctp_sf_do_dupcook_a(), both COOKIE-ACK\nand SHUTDOWN chunks are allocated with the transort from the new asoc.\nHowever, later in the sideeffect machine, the old asoc is used to send\nthem out and old asoc's shutdown_last_sent_to is set to the transport\nthat SHUTDOWN chunk attached to in sctp_cmd_setup_t2(), which actually\nbelongs to the new asoc. After the new_asoc is freed and the old asoc\nT2 timeout, the old asoc's shutdown_last_sent_to that is already freed\nwould be accessed in sctp_sf_t2_timer_expire().\n\nThanks Alexander and Jere for helping dig into this issue.\n\nTo fix it, this patch is to do the asoc update first, then allocate\nthe COOKIE-ACK and SHUTDOWN chunks with the 'updated' old asoc. This\nwould make more sense, as a chunk from an asoc shouldn't be sent out\nwith another asoc. We had fixed quite a few issues caused by this.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-28T09:15:38Z" diff --git a/advisories/unreviewed/2024/02/GHSA-gc58-f6gq-w9xv/GHSA-gc58-f6gq-w9xv.json b/advisories/unreviewed/2024/02/GHSA-gc58-f6gq-w9xv/GHSA-gc58-f6gq-w9xv.json index 03fb5b060e0..58423451e27 100644 --- a/advisories/unreviewed/2024/02/GHSA-gc58-f6gq-w9xv/GHSA-gc58-f6gq-w9xv.json +++ b/advisories/unreviewed/2024/02/GHSA-gc58-f6gq-w9xv/GHSA-gc58-f6gq-w9xv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gc58-f6gq-w9xv", - "modified": "2024-02-28T09:30:38Z", + "modified": "2025-01-08T18:30:41Z", "published": "2024-02-28T09:30:38Z", "aliases": [ "CVE-2021-47019" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmt76: mt7921: fix possible invalid register access\n\nDisable the interrupt and synchronze for the pending irq handlers to ensure\nthe irq tasklet is not being scheduled after the suspend to avoid the\npossible invalid register access acts when the host pcie controller is\nsuspended.\n\n[17932.910534] mt7921e 0000:01:00.0: pci_pm_suspend+0x0/0x22c returned 0 after 21375 usecs\n[17932.910590] pcieport 0000:00:00.0: calling pci_pm_suspend+0x0/0x22c @ 18565, parent: pci0000:00\n[17932.910602] pcieport 0000:00:00.0: pci_pm_suspend+0x0/0x22c returned 0 after 8 usecs\n[17932.910671] mtk-pcie 11230000.pcie: calling platform_pm_suspend+0x0/0x60 @ 22783, parent: soc\n[17932.910674] mtk-pcie 11230000.pcie: platform_pm_suspend+0x0/0x60 returned 0 after 0 usecs\n\n...\n\n17933.615352] x1 : 00000000000d4200 x0 : ffffff8269ca2300\n[17933.620666] Call trace:\n[17933.623127] mt76_mmio_rr+0x28/0xf0 [mt76]\n[17933.627234] mt7921_rr+0x38/0x44 [mt7921e]\n[17933.631339] mt7921_irq_tasklet+0x54/0x1d8 [mt7921e]\n[17933.636309] tasklet_action_common+0x12c/0x16c\n[17933.640754] tasklet_action+0x24/0x2c\n[17933.644418] __do_softirq+0x16c/0x344\n[17933.648082] irq_exit+0xa8/0xac\n[17933.651224] scheduler_ipi+0xd4/0x148\n[17933.654890] handle_IPI+0x164/0x2d4\n[17933.658379] gic_handle_irq+0x140/0x178\n[17933.662216] el1_irq+0xb8/0x180\n[17933.665361] cpuidle_enter_state+0xf8/0x204\n[17933.669544] cpuidle_enter+0x38/0x4c\n[17933.673122] do_idle+0x1a4/0x2a8\n[17933.676352] cpu_startup_entry+0x24/0x28\n[17933.680276] rest_init+0xd4/0xe0\n[17933.683508] arch_call_rest_init+0x10/0x18\n[17933.687606] start_kernel+0x340/0x3b4\n[17933.691279] Code: aa0003f5 d503201f f953eaa8 8b344108 (b9400113)\n[17933.697373] ---[ end trace a24b8e26ffbda3c5 ]---\n[17933.767846] Kernel panic - not syncing: Fatal exception in interrupt", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -25,7 +30,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-28T09:15:39Z" diff --git a/advisories/unreviewed/2024/02/GHSA-h3qj-j9m5-8ffr/GHSA-h3qj-j9m5-8ffr.json b/advisories/unreviewed/2024/02/GHSA-h3qj-j9m5-8ffr/GHSA-h3qj-j9m5-8ffr.json index 7ed1ac6a322..8695b7a1eb6 100644 --- a/advisories/unreviewed/2024/02/GHSA-h3qj-j9m5-8ffr/GHSA-h3qj-j9m5-8ffr.json +++ b/advisories/unreviewed/2024/02/GHSA-h3qj-j9m5-8ffr/GHSA-h3qj-j9m5-8ffr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h3qj-j9m5-8ffr", - "modified": "2024-02-28T09:30:37Z", + "modified": "2025-01-08T18:30:41Z", "published": "2024-02-28T09:30:37Z", "aliases": [ "CVE-2021-47001" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nxprtrdma: Fix cwnd update ordering\n\nAfter a reconnect, the reply handler is opening the cwnd (and thus\nenabling more RPC Calls to be sent) /before/ rpcrdma_post_recvs()\ncan post enough Receive WRs to receive their replies. This causes an\nRNR and the new connection is lost immediately.\n\nThe race is most clearly exposed when KASAN and disconnect injection\nare enabled. This slows down rpcrdma_rep_create() enough to allow\nthe send side to post a bunch of RPC Calls before the Receive\ncompletion handler can invoke ib_post_recv().", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -33,7 +38,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-28T09:15:38Z" diff --git a/advisories/unreviewed/2024/02/GHSA-hmgx-rfwx-3mvq/GHSA-hmgx-rfwx-3mvq.json b/advisories/unreviewed/2024/02/GHSA-hmgx-rfwx-3mvq/GHSA-hmgx-rfwx-3mvq.json index c78e709a014..c0c88fe167a 100644 --- a/advisories/unreviewed/2024/02/GHSA-hmgx-rfwx-3mvq/GHSA-hmgx-rfwx-3mvq.json +++ b/advisories/unreviewed/2024/02/GHSA-hmgx-rfwx-3mvq/GHSA-hmgx-rfwx-3mvq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hmgx-rfwx-3mvq", - "modified": "2024-02-27T21:31:27Z", + "modified": "2025-01-08T18:30:40Z", "published": "2024-02-27T21:31:27Z", "aliases": [ "CVE-2021-46971" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nperf/core: Fix unconditional security_locked_down() call\n\nCurrently, the lockdown state is queried unconditionally, even though\nits result is used only if the PERF_SAMPLE_REGS_INTR bit is set in\nattr.sample_type. While that doesn't matter in case of the Lockdown LSM,\nit causes trouble with the SELinux's lockdown hook implementation.\n\nSELinux implements the locked_down hook with a check whether the current\ntask's type has the corresponding \"lockdown\" class permission\n(\"integrity\" or \"confidentiality\") allowed in the policy. This means\nthat calling the hook when the access control decision would be ignored\ngenerates a bogus permission check and audit record.\n\nFix this by checking sample_type first and only calling the hook when\nits result would be honored.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -37,7 +42,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-27T19:04:07Z" diff --git a/advisories/unreviewed/2024/02/GHSA-jfx3-f7mg-7cp3/GHSA-jfx3-f7mg-7cp3.json b/advisories/unreviewed/2024/02/GHSA-jfx3-f7mg-7cp3/GHSA-jfx3-f7mg-7cp3.json index d58e48dcd5a..e333409d03e 100644 --- a/advisories/unreviewed/2024/02/GHSA-jfx3-f7mg-7cp3/GHSA-jfx3-f7mg-7cp3.json +++ b/advisories/unreviewed/2024/02/GHSA-jfx3-f7mg-7cp3/GHSA-jfx3-f7mg-7cp3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jfx3-f7mg-7cp3", - "modified": "2024-02-27T21:31:27Z", + "modified": "2025-01-08T18:30:40Z", "published": "2024-02-27T21:31:27Z", "aliases": [ "CVE-2021-46970" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbus: mhi: pci_generic: Remove WQ_MEM_RECLAIM flag from state workqueue\n\nA recent change created a dedicated workqueue for the state-change work\nwith WQ_HIGHPRI (no strong reason for that) and WQ_MEM_RECLAIM flags,\nbut the state-change work (mhi_pm_st_worker) does not guarantee forward\nprogress under memory pressure, and will even wait on various memory\nallocations when e.g. creating devices, loading firmware, etc... The\nwork is then not part of a memory reclaim path...\n\nMoreover, this causes a warning in check_flush_dependency() since we end\nup in code that flushes a non-reclaim workqueue:\n\n[ 40.969601] workqueue: WQ_MEM_RECLAIM mhi_hiprio_wq:mhi_pm_st_worker [mhi] is flushing !WQ_MEM_RECLAIM events_highpri:flush_backlog\n[ 40.969612] WARNING: CPU: 4 PID: 158 at kernel/workqueue.c:2607 check_flush_dependency+0x11c/0x140\n[ 40.969733] Call Trace:\n[ 40.969740] __flush_work+0x97/0x1d0\n[ 40.969745] ? wake_up_process+0x15/0x20\n[ 40.969749] ? insert_work+0x70/0x80\n[ 40.969750] ? __queue_work+0x14a/0x3e0\n[ 40.969753] flush_work+0x10/0x20\n[ 40.969756] rollback_registered_many+0x1c9/0x510\n[ 40.969759] unregister_netdevice_queue+0x94/0x120\n[ 40.969761] unregister_netdev+0x1d/0x30\n[ 40.969765] mhi_net_remove+0x1a/0x40 [mhi_net]\n[ 40.969770] mhi_driver_remove+0x124/0x250 [mhi]\n[ 40.969776] device_release_driver_internal+0xf0/0x1d0\n[ 40.969778] device_release_driver+0x12/0x20\n[ 40.969782] bus_remove_device+0xe1/0x150\n[ 40.969786] device_del+0x17b/0x3e0\n[ 40.969791] mhi_destroy_device+0x9a/0x100 [mhi]\n[ 40.969796] ? mhi_unmap_single_use_bb+0x50/0x50 [mhi]\n[ 40.969799] device_for_each_child+0x5e/0xa0\n[ 40.969804] mhi_pm_st_worker+0x921/0xf50 [mhi]", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -29,7 +34,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-27T19:04:07Z" diff --git a/advisories/unreviewed/2024/02/GHSA-jvv7-jhh3-m96v/GHSA-jvv7-jhh3-m96v.json b/advisories/unreviewed/2024/02/GHSA-jvv7-jhh3-m96v/GHSA-jvv7-jhh3-m96v.json index b8c4a94f960..ab0b5cd5512 100644 --- a/advisories/unreviewed/2024/02/GHSA-jvv7-jhh3-m96v/GHSA-jvv7-jhh3-m96v.json +++ b/advisories/unreviewed/2024/02/GHSA-jvv7-jhh3-m96v/GHSA-jvv7-jhh3-m96v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jvv7-jhh3-m96v", - "modified": "2024-02-28T09:30:37Z", + "modified": "2025-01-08T18:30:41Z", "published": "2024-02-28T09:30:37Z", "aliases": [ "CVE-2021-47011" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm: memcontrol: slab: fix obtain a reference to a freeing memcg\n\nPatch series \"Use obj_cgroup APIs to charge kmem pages\", v5.\n\nSince Roman's series \"The new cgroup slab memory controller\" applied.\nAll slab objects are charged with the new APIs of obj_cgroup. The new\nAPIs introduce a struct obj_cgroup to charge slab objects. It prevents\nlong-living objects from pinning the original memory cgroup in the\nmemory. But there are still some corner objects (e.g. allocations\nlarger than order-1 page on SLUB) which are not charged with the new\nAPIs. Those objects (include the pages which are allocated from buddy\nallocator directly) are charged as kmem pages which still hold a\nreference to the memory cgroup.\n\nE.g. We know that the kernel stack is charged as kmem pages because the\nsize of the kernel stack can be greater than 2 pages (e.g. 16KB on\nx86_64 or arm64). If we create a thread (suppose the thread stack is\ncharged to memory cgroup A) and then move it from memory cgroup A to\nmemory cgroup B. Because the kernel stack of the thread hold a\nreference to the memory cgroup A. The thread can pin the memory cgroup\nA in the memory even if we remove the cgroup A. If we want to see this\nscenario by using the following script. We can see that the system has\nadded 500 dying cgroups (This is not a real world issue, just a script\nto show that the large kmallocs are charged as kmem pages which can pin\nthe memory cgroup in the memory).\n\n\t#!/bin/bash\n\n\tcat /proc/cgroups | grep memory\n\n\tcd /sys/fs/cgroup/memory\n\techo 1 > memory.move_charge_at_immigrate\n\n\tfor i in range{1..500}\n\tdo\n\t\tmkdir kmem_test\n\t\techo $$ > kmem_test/cgroup.procs\n\t\tsleep 3600 &\n\t\techo $$ > cgroup.procs\n\t\techo `cat kmem_test/cgroup.procs` > cgroup.procs\n\t\trmdir kmem_test\n\tdone\n\n\tcat /proc/cgroups | grep memory\n\nThis patchset aims to make those kmem pages to drop the reference to\nmemory cgroup by using the APIs of obj_cgroup. Finally, we can see that\nthe number of the dying cgroups will not increase if we run the above test\nscript.\n\nThis patch (of 7):\n\nThe rcu_read_lock/unlock only can guarantee that the memcg will not be\nfreed, but it cannot guarantee the success of css_get (which is in the\nrefill_stock when cached memcg changed) to memcg.\n\n rcu_read_lock()\n memcg = obj_cgroup_memcg(old)\n __memcg_kmem_uncharge(memcg)\n refill_stock(memcg)\n if (stock->cached != memcg)\n // css_get can change the ref counter from 0 back to 1.\n css_get(&memcg->css)\n rcu_read_unlock()\n\nThis fix is very like the commit:\n\n eefbfa7fd678 (\"mm: memcg/slab: fix use after free in obj_cgroup_charge\")\n\nFix this by holding a reference to the memcg which is passed to the\n__memcg_kmem_uncharge() before calling __memcg_kmem_uncharge().", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -33,7 +38,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-28T09:15:38Z" diff --git a/advisories/unreviewed/2024/02/GHSA-m99h-2hm4-q649/GHSA-m99h-2hm4-q649.json b/advisories/unreviewed/2024/02/GHSA-m99h-2hm4-q649/GHSA-m99h-2hm4-q649.json index abf43f8aa5d..60cb7248bb5 100644 --- a/advisories/unreviewed/2024/02/GHSA-m99h-2hm4-q649/GHSA-m99h-2hm4-q649.json +++ b/advisories/unreviewed/2024/02/GHSA-m99h-2hm4-q649/GHSA-m99h-2hm4-q649.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-m99h-2hm4-q649", - "modified": "2024-02-28T09:30:36Z", + "modified": "2025-01-08T18:30:40Z", "published": "2024-02-28T09:30:36Z", "aliases": [ "CVE-2021-46977" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: VMX: Disable preemption when probing user return MSRs\n\nDisable preemption when probing a user return MSR via RDSMR/WRMSR. If\nthe MSR holds a different value per logical CPU, the WRMSR could corrupt\nthe host's value if KVM is preempted between the RDMSR and WRMSR, and\nthen rescheduled on a different CPU.\n\nOpportunistically land the helper in common x86, SVM will use the helper\nin a future commit.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -33,7 +38,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-28T09:15:37Z" diff --git a/advisories/unreviewed/2024/02/GHSA-mvm9-g6f5-rfmr/GHSA-mvm9-g6f5-rfmr.json b/advisories/unreviewed/2024/02/GHSA-mvm9-g6f5-rfmr/GHSA-mvm9-g6f5-rfmr.json index 79c512a86c1..453b09418a4 100644 --- a/advisories/unreviewed/2024/02/GHSA-mvm9-g6f5-rfmr/GHSA-mvm9-g6f5-rfmr.json +++ b/advisories/unreviewed/2024/02/GHSA-mvm9-g6f5-rfmr/GHSA-mvm9-g6f5-rfmr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mvm9-g6f5-rfmr", - "modified": "2024-02-28T09:30:38Z", + "modified": "2025-01-08T18:30:41Z", "published": "2024-02-28T09:30:37Z", "aliases": [ "CVE-2021-47015" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbnxt_en: Fix RX consumer index logic in the error path.\n\nIn bnxt_rx_pkt(), the RX buffers are expected to complete in order.\nIf the RX consumer index indicates an out of order buffer completion,\nit means we are hitting a hardware bug and the driver will abort all\nremaining RX packets and reset the RX ring. The RX consumer index\nthat we pass to bnxt_discard_rx() is not correct. We should be\npassing the current index (tmp_raw_cons) instead of the old index\n(raw_cons). This bug can cause us to be at the wrong index when\ntrying to abort the next RX packet. It can crash like this:\n\n #0 [ffff9bbcdf5c39a8] machine_kexec at ffffffff9b05e007\n #1 [ffff9bbcdf5c3a00] __crash_kexec at ffffffff9b111232\n #2 [ffff9bbcdf5c3ad0] panic at ffffffff9b07d61e\n #3 [ffff9bbcdf5c3b50] oops_end at ffffffff9b030978\n #4 [ffff9bbcdf5c3b78] no_context at ffffffff9b06aaf0\n #5 [ffff9bbcdf5c3bd8] __bad_area_nosemaphore at ffffffff9b06ae2e\n #6 [ffff9bbcdf5c3c28] bad_area_nosemaphore at ffffffff9b06af24\n #7 [ffff9bbcdf5c3c38] __do_page_fault at ffffffff9b06b67e\n #8 [ffff9bbcdf5c3cb0] do_page_fault at ffffffff9b06bb12\n #9 [ffff9bbcdf5c3ce0] page_fault at ffffffff9bc015c5\n [exception RIP: bnxt_rx_pkt+237]\n RIP: ffffffffc0259cdd RSP: ffff9bbcdf5c3d98 RFLAGS: 00010213\n RAX: 000000005dd8097f RBX: ffff9ba4cb11b7e0 RCX: ffffa923cf6e9000\n RDX: 0000000000000fff RSI: 0000000000000627 RDI: 0000000000001000\n RBP: ffff9bbcdf5c3e60 R8: 0000000000420003 R9: 000000000000020d\n R10: ffffa923cf6ec138 R11: ffff9bbcdf5c3e83 R12: ffff9ba4d6f928c0\n R13: ffff9ba4cac28080 R14: ffff9ba4cb11b7f0 R15: ffff9ba4d5a30000\n ORIG_RAX: ffffffffffffffff CS: 0010 SS: 0018", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -37,7 +42,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-28T09:15:38Z" diff --git a/advisories/unreviewed/2024/02/GHSA-p768-cw2x-34vr/GHSA-p768-cw2x-34vr.json b/advisories/unreviewed/2024/02/GHSA-p768-cw2x-34vr/GHSA-p768-cw2x-34vr.json index ee1cd17a48a..36badbfb78a 100644 --- a/advisories/unreviewed/2024/02/GHSA-p768-cw2x-34vr/GHSA-p768-cw2x-34vr.json +++ b/advisories/unreviewed/2024/02/GHSA-p768-cw2x-34vr/GHSA-p768-cw2x-34vr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p768-cw2x-34vr", - "modified": "2024-02-28T09:30:38Z", + "modified": "2025-01-08T18:30:41Z", "published": "2024-02-28T09:30:37Z", "aliases": [ "CVE-2021-47018" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\npowerpc/64: Fix the definition of the fixmap area\n\nAt the time being, the fixmap area is defined at the top of\nthe address space or just below KASAN.\n\nThis definition is not valid for PPC64.\n\nFor PPC64, use the top of the I/O space.\n\nBecause of circular dependencies, it is not possible to include\nasm/fixmap.h in asm/book3s/64/pgtable.h , so define a fixed size\nAREA at the top of the I/O space for fixmap and ensure during\nbuild that the size is big enough.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -33,7 +38,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-28T09:15:39Z" diff --git a/advisories/unreviewed/2024/02/GHSA-pvcm-vr92-9wx7/GHSA-pvcm-vr92-9wx7.json b/advisories/unreviewed/2024/02/GHSA-pvcm-vr92-9wx7/GHSA-pvcm-vr92-9wx7.json index c29157120a6..57b70cb4909 100644 --- a/advisories/unreviewed/2024/02/GHSA-pvcm-vr92-9wx7/GHSA-pvcm-vr92-9wx7.json +++ b/advisories/unreviewed/2024/02/GHSA-pvcm-vr92-9wx7/GHSA-pvcm-vr92-9wx7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pvcm-vr92-9wx7", - "modified": "2024-02-27T21:31:27Z", + "modified": "2025-01-08T18:30:40Z", "published": "2024-02-27T21:31:27Z", "aliases": [ "CVE-2021-46964" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: qla2xxx: Reserve extra IRQ vectors\n\nCommit a6dcfe08487e (\"scsi: qla2xxx: Limit interrupt vectors to number of\nCPUs\") lowers the number of allocated MSI-X vectors to the number of CPUs.\n\nThat breaks vector allocation assumptions in qla83xx_iospace_config(),\nqla24xx_enable_msix() and qla2x00_iospace_config(). Either of the functions\ncomputes maximum number of qpairs as:\n\n ha->max_qpairs = ha->msix_count - 1 (MB interrupt) - 1 (default\n response queue) - 1 (ATIO, in dual or pure target mode)\n\nmax_qpairs is set to zero in case of two CPUs and initiator mode. The\nnumber is then used to allocate ha->queue_pair_map inside\nqla2x00_alloc_queues(). No allocation happens and ha->queue_pair_map is\nleft NULL but the driver thinks there are queue pairs available.\n\nqla2xxx_queuecommand() tries to find a qpair in the map and crashes:\n\n if (ha->mqenable) {\n uint32_t tag;\n uint16_t hwq;\n struct qla_qpair *qpair = NULL;\n\n tag = blk_mq_unique_tag(cmd->request);\n hwq = blk_mq_unique_tag_to_hwq(tag);\n qpair = ha->queue_pair_map[hwq]; # <- HERE\n\n if (qpair)\n return qla2xxx_mqueuecommand(host, cmd, qpair);\n }\n\n BUG: kernel NULL pointer dereference, address: 0000000000000000\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\n PGD 0 P4D 0\n Oops: 0000 [#1] SMP PTI\n CPU: 0 PID: 72 Comm: kworker/u4:3 Tainted: G W 5.10.0-rc1+ #25\n Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.0.0-prebuilt.qemu-project.org 04/01/2014\n Workqueue: scsi_wq_7 fc_scsi_scan_rport [scsi_transport_fc]\n RIP: 0010:qla2xxx_queuecommand+0x16b/0x3f0 [qla2xxx]\n Call Trace:\n scsi_queue_rq+0x58c/0xa60\n blk_mq_dispatch_rq_list+0x2b7/0x6f0\n ? __sbitmap_get_word+0x2a/0x80\n __blk_mq_sched_dispatch_requests+0xb8/0x170\n blk_mq_sched_dispatch_requests+0x2b/0x50\n __blk_mq_run_hw_queue+0x49/0xb0\n __blk_mq_delay_run_hw_queue+0xfb/0x150\n blk_mq_sched_insert_request+0xbe/0x110\n blk_execute_rq+0x45/0x70\n __scsi_execute+0x10e/0x250\n scsi_probe_and_add_lun+0x228/0xda0\n __scsi_scan_target+0xf4/0x620\n ? __pm_runtime_resume+0x4f/0x70\n scsi_scan_target+0x100/0x110\n fc_scsi_scan_rport+0xa1/0xb0 [scsi_transport_fc]\n process_one_work+0x1ea/0x3b0\n worker_thread+0x28/0x3b0\n ? process_one_work+0x3b0/0x3b0\n kthread+0x112/0x130\n ? kthread_park+0x80/0x80\n ret_from_fork+0x22/0x30\n\nThe driver should allocate enough vectors to provide every CPU it's own HW\nqueue and still handle reserved (MB, RSP, ATIO) interrupts.\n\nThe change fixes the crash on dual core VM and prevents unbalanced QP\nallocation where nr_hw_queues is two less than the number of CPUs.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-27T19:04:07Z" diff --git a/advisories/unreviewed/2024/02/GHSA-q466-f768-77v8/GHSA-q466-f768-77v8.json b/advisories/unreviewed/2024/02/GHSA-q466-f768-77v8/GHSA-q466-f768-77v8.json index dfd87ee9ff8..72dd84b1c84 100644 --- a/advisories/unreviewed/2024/02/GHSA-q466-f768-77v8/GHSA-q466-f768-77v8.json +++ b/advisories/unreviewed/2024/02/GHSA-q466-f768-77v8/GHSA-q466-f768-77v8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-q466-f768-77v8", - "modified": "2024-02-27T21:31:27Z", + "modified": "2025-01-08T18:30:40Z", "published": "2024-02-27T21:31:27Z", "aliases": [ "CVE-2021-46965" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmtd: physmap: physmap-bt1-rom: Fix unintentional stack access\n\nCast &data to (char *) in order to avoid unintentionally accessing\nthe stack.\n\nNotice that data is of type u32, so any increment to &data\nwill be in the order of 4-byte chunks, and this piece of code\nis actually intended to be a byte offset.\n\nAddresses-Coverity-ID: 1497765 (\"Out-of-bounds access\")", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-27T19:04:07Z" diff --git a/advisories/unreviewed/2024/02/GHSA-rcvc-x6h8-mpp2/GHSA-rcvc-x6h8-mpp2.json b/advisories/unreviewed/2024/02/GHSA-rcvc-x6h8-mpp2/GHSA-rcvc-x6h8-mpp2.json index b10659b97a9..d40c380d5d2 100644 --- a/advisories/unreviewed/2024/02/GHSA-rcvc-x6h8-mpp2/GHSA-rcvc-x6h8-mpp2.json +++ b/advisories/unreviewed/2024/02/GHSA-rcvc-x6h8-mpp2/GHSA-rcvc-x6h8-mpp2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rcvc-x6h8-mpp2", - "modified": "2024-02-27T21:31:27Z", + "modified": "2025-01-08T18:30:40Z", "published": "2024-02-27T21:31:27Z", "aliases": [ "CVE-2021-46968" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ns390/zcrypt: fix zcard and zqueue hot-unplug memleak\n\nTests with kvm and a kmemdebug kernel showed, that on hot unplug the\nzcard and zqueue structs for the unplugged card or queue are not\nproperly freed because of a mismatch with get/put for the embedded\nkref counter.\n\nThis fix now adjusts the handling of the kref counters. With init the\nkref counter starts with 1. This initial value needs to drop to zero\nwith the unregister of the card or queue to trigger the release and\nfree the object.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-27T19:04:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-45hm-gg77-pjg9/GHSA-45hm-gg77-pjg9.json b/advisories/unreviewed/2024/03/GHSA-45hm-gg77-pjg9/GHSA-45hm-gg77-pjg9.json index 7ed0b759364..9f566f3817e 100644 --- a/advisories/unreviewed/2024/03/GHSA-45hm-gg77-pjg9/GHSA-45hm-gg77-pjg9.json +++ b/advisories/unreviewed/2024/03/GHSA-45hm-gg77-pjg9/GHSA-45hm-gg77-pjg9.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-4h58-gcmv-6qjq/GHSA-4h58-gcmv-6qjq.json b/advisories/unreviewed/2024/03/GHSA-4h58-gcmv-6qjq/GHSA-4h58-gcmv-6qjq.json index 8bcdf625dae..c3d1786a9be 100644 --- a/advisories/unreviewed/2024/03/GHSA-4h58-gcmv-6qjq/GHSA-4h58-gcmv-6qjq.json +++ b/advisories/unreviewed/2024/03/GHSA-4h58-gcmv-6qjq/GHSA-4h58-gcmv-6qjq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4h58-gcmv-6qjq", - "modified": "2024-03-05T03:30:31Z", + "modified": "2025-01-08T18:30:41Z", "published": "2024-03-05T03:30:31Z", "aliases": [ "CVE-2024-1285" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-58qv-qvf3-f8mp/GHSA-58qv-qvf3-f8mp.json b/advisories/unreviewed/2024/03/GHSA-58qv-qvf3-f8mp/GHSA-58qv-qvf3-f8mp.json index 55f4d35e031..0f7110cb7f0 100644 --- a/advisories/unreviewed/2024/03/GHSA-58qv-qvf3-f8mp/GHSA-58qv-qvf3-f8mp.json +++ b/advisories/unreviewed/2024/03/GHSA-58qv-qvf3-f8mp/GHSA-58qv-qvf3-f8mp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-58qv-qvf3-f8mp", - "modified": "2024-03-23T03:30:24Z", + "modified": "2025-01-08T18:30:41Z", "published": "2024-03-03T21:31:25Z", "aliases": [ "CVE-2024-28084" ], "details": "p2putil.c in iNet wireless daemon (IWD) through 2.15 allows attackers to cause a denial of service (daemon crash) or possibly have unspecified other impact because of initialization issues in situations where parsing of advertised service information fails.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-665" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-03T21:15:49Z" diff --git a/advisories/unreviewed/2024/03/GHSA-c33g-4mp4-9vx4/GHSA-c33g-4mp4-9vx4.json b/advisories/unreviewed/2024/03/GHSA-c33g-4mp4-9vx4/GHSA-c33g-4mp4-9vx4.json index 81162af3b4b..025beb3c6b4 100644 --- a/advisories/unreviewed/2024/03/GHSA-c33g-4mp4-9vx4/GHSA-c33g-4mp4-9vx4.json +++ b/advisories/unreviewed/2024/03/GHSA-c33g-4mp4-9vx4/GHSA-c33g-4mp4-9vx4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c33g-4mp4-9vx4", - "modified": "2024-03-05T03:30:31Z", + "modified": "2025-01-08T18:30:41Z", "published": "2024-03-05T03:30:31Z", "aliases": [ "CVE-2024-1178" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-c6h8-8xgj-56vw/GHSA-c6h8-8xgj-56vw.json b/advisories/unreviewed/2024/03/GHSA-c6h8-8xgj-56vw/GHSA-c6h8-8xgj-56vw.json index fb2f91188c8..0dc46722024 100644 --- a/advisories/unreviewed/2024/03/GHSA-c6h8-8xgj-56vw/GHSA-c6h8-8xgj-56vw.json +++ b/advisories/unreviewed/2024/03/GHSA-c6h8-8xgj-56vw/GHSA-c6h8-8xgj-56vw.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-fv2v-wvxg-x978/GHSA-fv2v-wvxg-x978.json b/advisories/unreviewed/2024/03/GHSA-fv2v-wvxg-x978/GHSA-fv2v-wvxg-x978.json index 9f6efdc9724..b53fd252f10 100644 --- a/advisories/unreviewed/2024/03/GHSA-fv2v-wvxg-x978/GHSA-fv2v-wvxg-x978.json +++ b/advisories/unreviewed/2024/03/GHSA-fv2v-wvxg-x978/GHSA-fv2v-wvxg-x978.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fv2v-wvxg-x978", - "modified": "2024-03-28T03:30:59Z", + "modified": "2025-01-08T18:30:41Z", "published": "2024-03-28T03:30:59Z", "aliases": [ "CVE-2024-2111" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-hjp2-wg69-g55x/GHSA-hjp2-wg69-g55x.json b/advisories/unreviewed/2024/03/GHSA-hjp2-wg69-g55x/GHSA-hjp2-wg69-g55x.json index 0509a7568b8..624fa32a45f 100644 --- a/advisories/unreviewed/2024/03/GHSA-hjp2-wg69-g55x/GHSA-hjp2-wg69-g55x.json +++ b/advisories/unreviewed/2024/03/GHSA-hjp2-wg69-g55x/GHSA-hjp2-wg69-g55x.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-502" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-pcgx-35gv-6fvj/GHSA-pcgx-35gv-6fvj.json b/advisories/unreviewed/2024/03/GHSA-pcgx-35gv-6fvj/GHSA-pcgx-35gv-6fvj.json index 1ee09a6e1b5..287b9ecce72 100644 --- a/advisories/unreviewed/2024/03/GHSA-pcgx-35gv-6fvj/GHSA-pcgx-35gv-6fvj.json +++ b/advisories/unreviewed/2024/03/GHSA-pcgx-35gv-6fvj/GHSA-pcgx-35gv-6fvj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pcgx-35gv-6fvj", - "modified": "2024-03-28T03:30:59Z", + "modified": "2025-01-08T18:30:41Z", "published": "2024-03-28T03:30:59Z", "aliases": [ "CVE-2024-2110" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-r345-j492-57q4/GHSA-r345-j492-57q4.json b/advisories/unreviewed/2024/03/GHSA-r345-j492-57q4/GHSA-r345-j492-57q4.json index 56d72034a95..ed2531e6ff9 100644 --- a/advisories/unreviewed/2024/03/GHSA-r345-j492-57q4/GHSA-r345-j492-57q4.json +++ b/advisories/unreviewed/2024/03/GHSA-r345-j492-57q4/GHSA-r345-j492-57q4.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-120", "CWE-122" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/03/GHSA-vxwm-wx7w-rvwj/GHSA-vxwm-wx7w-rvwj.json b/advisories/unreviewed/2024/03/GHSA-vxwm-wx7w-rvwj/GHSA-vxwm-wx7w-rvwj.json index 79b47921d93..cd8d12cd957 100644 --- a/advisories/unreviewed/2024/03/GHSA-vxwm-wx7w-rvwj/GHSA-vxwm-wx7w-rvwj.json +++ b/advisories/unreviewed/2024/03/GHSA-vxwm-wx7w-rvwj/GHSA-vxwm-wx7w-rvwj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vxwm-wx7w-rvwj", - "modified": "2024-03-05T03:30:31Z", + "modified": "2025-01-08T18:30:41Z", "published": "2024-03-05T03:30:31Z", "aliases": [ "CVE-2024-1095" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-2jc9-36w4-pmqw/GHSA-2jc9-36w4-pmqw.json b/advisories/unreviewed/2024/04/GHSA-2jc9-36w4-pmqw/GHSA-2jc9-36w4-pmqw.json index 225d378721e..d7ca7f59fc7 100644 --- a/advisories/unreviewed/2024/04/GHSA-2jc9-36w4-pmqw/GHSA-2jc9-36w4-pmqw.json +++ b/advisories/unreviewed/2024/04/GHSA-2jc9-36w4-pmqw/GHSA-2jc9-36w4-pmqw.json @@ -58,7 +58,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-2mcw-fg5h-w8g7/GHSA-2mcw-fg5h-w8g7.json b/advisories/unreviewed/2024/04/GHSA-2mcw-fg5h-w8g7/GHSA-2mcw-fg5h-w8g7.json index cc637183ca3..34a69bb43f0 100644 --- a/advisories/unreviewed/2024/04/GHSA-2mcw-fg5h-w8g7/GHSA-2mcw-fg5h-w8g7.json +++ b/advisories/unreviewed/2024/04/GHSA-2mcw-fg5h-w8g7/GHSA-2mcw-fg5h-w8g7.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-2q2v-8vjq-r8m5/GHSA-2q2v-8vjq-r8m5.json b/advisories/unreviewed/2024/04/GHSA-2q2v-8vjq-r8m5/GHSA-2q2v-8vjq-r8m5.json index 3fd6361fb78..a639b344cf7 100644 --- a/advisories/unreviewed/2024/04/GHSA-2q2v-8vjq-r8m5/GHSA-2q2v-8vjq-r8m5.json +++ b/advisories/unreviewed/2024/04/GHSA-2q2v-8vjq-r8m5/GHSA-2q2v-8vjq-r8m5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2q2v-8vjq-r8m5", - "modified": "2024-04-05T09:30:38Z", + "modified": "2025-01-08T18:30:41Z", "published": "2024-04-05T09:30:38Z", "aliases": [ "CVE-2024-2115" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-4qwp-4p88-ww2v/GHSA-4qwp-4p88-ww2v.json b/advisories/unreviewed/2024/04/GHSA-4qwp-4p88-ww2v/GHSA-4qwp-4p88-ww2v.json index 6ac3828200f..843198d6cf7 100644 --- a/advisories/unreviewed/2024/04/GHSA-4qwp-4p88-ww2v/GHSA-4qwp-4p88-ww2v.json +++ b/advisories/unreviewed/2024/04/GHSA-4qwp-4p88-ww2v/GHSA-4qwp-4p88-ww2v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4qwp-4p88-ww2v", - "modified": "2024-04-19T03:31:04Z", + "modified": "2025-01-08T18:30:42Z", "published": "2024-04-19T03:31:04Z", "aliases": [ "CVE-2024-3560" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-4ww3-585w-6p9r/GHSA-4ww3-585w-6p9r.json b/advisories/unreviewed/2024/04/GHSA-4ww3-585w-6p9r/GHSA-4ww3-585w-6p9r.json index d8852781c69..ed057b79419 100644 --- a/advisories/unreviewed/2024/04/GHSA-4ww3-585w-6p9r/GHSA-4ww3-585w-6p9r.json +++ b/advisories/unreviewed/2024/04/GHSA-4ww3-585w-6p9r/GHSA-4ww3-585w-6p9r.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-79", "CWE-94" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/04/GHSA-53gv-p4jm-h5xv/GHSA-53gv-p4jm-h5xv.json b/advisories/unreviewed/2024/04/GHSA-53gv-p4jm-h5xv/GHSA-53gv-p4jm-h5xv.json index 69b42a86992..41a373174d4 100644 --- a/advisories/unreviewed/2024/04/GHSA-53gv-p4jm-h5xv/GHSA-53gv-p4jm-h5xv.json +++ b/advisories/unreviewed/2024/04/GHSA-53gv-p4jm-h5xv/GHSA-53gv-p4jm-h5xv.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-5mgw-pvjq-2c2v/GHSA-5mgw-pvjq-2c2v.json b/advisories/unreviewed/2024/04/GHSA-5mgw-pvjq-2c2v/GHSA-5mgw-pvjq-2c2v.json index b8485768ba5..5be11dacacb 100644 --- a/advisories/unreviewed/2024/04/GHSA-5mgw-pvjq-2c2v/GHSA-5mgw-pvjq-2c2v.json +++ b/advisories/unreviewed/2024/04/GHSA-5mgw-pvjq-2c2v/GHSA-5mgw-pvjq-2c2v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5mgw-pvjq-2c2v", - "modified": "2024-04-02T09:30:42Z", + "modified": "2025-01-08T18:30:41Z", "published": "2024-04-02T09:30:42Z", "aliases": [ "CVE-2024-2925" @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-73p8-jp88-9jjm/GHSA-73p8-jp88-9jjm.json b/advisories/unreviewed/2024/04/GHSA-73p8-jp88-9jjm/GHSA-73p8-jp88-9jjm.json index f0fb64f0079..3b558d6d865 100644 --- a/advisories/unreviewed/2024/04/GHSA-73p8-jp88-9jjm/GHSA-73p8-jp88-9jjm.json +++ b/advisories/unreviewed/2024/04/GHSA-73p8-jp88-9jjm/GHSA-73p8-jp88-9jjm.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-362", "CWE-591" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/04/GHSA-7jq6-7f95-hv67/GHSA-7jq6-7f95-hv67.json b/advisories/unreviewed/2024/04/GHSA-7jq6-7f95-hv67/GHSA-7jq6-7f95-hv67.json index 8bba25ff1f5..dcddc435371 100644 --- a/advisories/unreviewed/2024/04/GHSA-7jq6-7f95-hv67/GHSA-7jq6-7f95-hv67.json +++ b/advisories/unreviewed/2024/04/GHSA-7jq6-7f95-hv67/GHSA-7jq6-7f95-hv67.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-347" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-86p8-qv4v-vv9r/GHSA-86p8-qv4v-vv9r.json b/advisories/unreviewed/2024/04/GHSA-86p8-qv4v-vv9r/GHSA-86p8-qv4v-vv9r.json index 5293fb1eb60..74d7e986d93 100644 --- a/advisories/unreviewed/2024/04/GHSA-86p8-qv4v-vv9r/GHSA-86p8-qv4v-vv9r.json +++ b/advisories/unreviewed/2024/04/GHSA-86p8-qv4v-vv9r/GHSA-86p8-qv4v-vv9r.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-126" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/04/GHSA-8g89-49x9-pqr8/GHSA-8g89-49x9-pqr8.json b/advisories/unreviewed/2024/04/GHSA-8g89-49x9-pqr8/GHSA-8g89-49x9-pqr8.json index f213d4830f5..cdc65d06c37 100644 --- a/advisories/unreviewed/2024/04/GHSA-8g89-49x9-pqr8/GHSA-8g89-49x9-pqr8.json +++ b/advisories/unreviewed/2024/04/GHSA-8g89-49x9-pqr8/GHSA-8g89-49x9-pqr8.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-126" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/04/GHSA-cw34-gw9h-rxc6/GHSA-cw34-gw9h-rxc6.json b/advisories/unreviewed/2024/04/GHSA-cw34-gw9h-rxc6/GHSA-cw34-gw9h-rxc6.json index d4bb91a6c14..1d31effcc1f 100644 --- a/advisories/unreviewed/2024/04/GHSA-cw34-gw9h-rxc6/GHSA-cw34-gw9h-rxc6.json +++ b/advisories/unreviewed/2024/04/GHSA-cw34-gw9h-rxc6/GHSA-cw34-gw9h-rxc6.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-126" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/04/GHSA-cwxc-rm5r-crmq/GHSA-cwxc-rm5r-crmq.json b/advisories/unreviewed/2024/04/GHSA-cwxc-rm5r-crmq/GHSA-cwxc-rm5r-crmq.json index f2c0a8f4692..2a9f9aa1876 100644 --- a/advisories/unreviewed/2024/04/GHSA-cwxc-rm5r-crmq/GHSA-cwxc-rm5r-crmq.json +++ b/advisories/unreviewed/2024/04/GHSA-cwxc-rm5r-crmq/GHSA-cwxc-rm5r-crmq.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-f3x6-c3gw-gv5x/GHSA-f3x6-c3gw-gv5x.json b/advisories/unreviewed/2024/04/GHSA-f3x6-c3gw-gv5x/GHSA-f3x6-c3gw-gv5x.json index 6db27c5838f..35af4be92df 100644 --- a/advisories/unreviewed/2024/04/GHSA-f3x6-c3gw-gv5x/GHSA-f3x6-c3gw-gv5x.json +++ b/advisories/unreviewed/2024/04/GHSA-f3x6-c3gw-gv5x/GHSA-f3x6-c3gw-gv5x.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-jjch-qg3j-855w/GHSA-jjch-qg3j-855w.json b/advisories/unreviewed/2024/04/GHSA-jjch-qg3j-855w/GHSA-jjch-qg3j-855w.json index 9ed67280b9a..5e30b174e72 100644 --- a/advisories/unreviewed/2024/04/GHSA-jjch-qg3j-855w/GHSA-jjch-qg3j-855w.json +++ b/advisories/unreviewed/2024/04/GHSA-jjch-qg3j-855w/GHSA-jjch-qg3j-855w.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-362", "CWE-591" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/04/GHSA-pcjj-9wx4-9phh/GHSA-pcjj-9wx4-9phh.json b/advisories/unreviewed/2024/04/GHSA-pcjj-9wx4-9phh/GHSA-pcjj-9wx4-9phh.json index 47de4903339..2d8ae39fd0a 100644 --- a/advisories/unreviewed/2024/04/GHSA-pcjj-9wx4-9phh/GHSA-pcjj-9wx4-9phh.json +++ b/advisories/unreviewed/2024/04/GHSA-pcjj-9wx4-9phh/GHSA-pcjj-9wx4-9phh.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-qr85-xmff-4wqh/GHSA-qr85-xmff-4wqh.json b/advisories/unreviewed/2024/04/GHSA-qr85-xmff-4wqh/GHSA-qr85-xmff-4wqh.json index 180e747c276..d48e156b234 100644 --- a/advisories/unreviewed/2024/04/GHSA-qr85-xmff-4wqh/GHSA-qr85-xmff-4wqh.json +++ b/advisories/unreviewed/2024/04/GHSA-qr85-xmff-4wqh/GHSA-qr85-xmff-4wqh.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-r8v8-787r-c5p4/GHSA-r8v8-787r-c5p4.json b/advisories/unreviewed/2024/04/GHSA-r8v8-787r-c5p4/GHSA-r8v8-787r-c5p4.json index 7338454c8f9..c06c6886ba9 100644 --- a/advisories/unreviewed/2024/04/GHSA-r8v8-787r-c5p4/GHSA-r8v8-787r-c5p4.json +++ b/advisories/unreviewed/2024/04/GHSA-r8v8-787r-c5p4/GHSA-r8v8-787r-c5p4.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-rjmx-4pf7-6fpx/GHSA-rjmx-4pf7-6fpx.json b/advisories/unreviewed/2024/04/GHSA-rjmx-4pf7-6fpx/GHSA-rjmx-4pf7-6fpx.json index 27e643eb54e..4eed8b045e3 100644 --- a/advisories/unreviewed/2024/04/GHSA-rjmx-4pf7-6fpx/GHSA-rjmx-4pf7-6fpx.json +++ b/advisories/unreviewed/2024/04/GHSA-rjmx-4pf7-6fpx/GHSA-rjmx-4pf7-6fpx.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-126" + "CWE-126", + "CWE-362" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-rvh5-mpf7-h5hf/GHSA-rvh5-mpf7-h5hf.json b/advisories/unreviewed/2024/04/GHSA-rvh5-mpf7-h5hf/GHSA-rvh5-mpf7-h5hf.json index c00fbf9ee95..96fc70ef66d 100644 --- a/advisories/unreviewed/2024/04/GHSA-rvh5-mpf7-h5hf/GHSA-rvh5-mpf7-h5hf.json +++ b/advisories/unreviewed/2024/04/GHSA-rvh5-mpf7-h5hf/GHSA-rvh5-mpf7-h5hf.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-126" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/05/GHSA-mhcv-2f7w-4c7r/GHSA-mhcv-2f7w-4c7r.json b/advisories/unreviewed/2024/05/GHSA-mhcv-2f7w-4c7r/GHSA-mhcv-2f7w-4c7r.json index bf06fd185fd..aa93e1e30f2 100644 --- a/advisories/unreviewed/2024/05/GHSA-mhcv-2f7w-4c7r/GHSA-mhcv-2f7w-4c7r.json +++ b/advisories/unreviewed/2024/05/GHSA-mhcv-2f7w-4c7r/GHSA-mhcv-2f7w-4c7r.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-295" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-qj72-6765-vjx4/GHSA-qj72-6765-vjx4.json b/advisories/unreviewed/2024/05/GHSA-qj72-6765-vjx4/GHSA-qj72-6765-vjx4.json index 3a0c0832618..fa3b748f7e0 100644 --- a/advisories/unreviewed/2024/05/GHSA-qj72-6765-vjx4/GHSA-qj72-6765-vjx4.json +++ b/advisories/unreviewed/2024/05/GHSA-qj72-6765-vjx4/GHSA-qj72-6765-vjx4.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-362", "CWE-416" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/06/GHSA-2rhh-63xh-7gv7/GHSA-2rhh-63xh-7gv7.json b/advisories/unreviewed/2024/06/GHSA-2rhh-63xh-7gv7/GHSA-2rhh-63xh-7gv7.json index 666bcbbd943..2482ffeb3d5 100644 --- a/advisories/unreviewed/2024/06/GHSA-2rhh-63xh-7gv7/GHSA-2rhh-63xh-7gv7.json +++ b/advisories/unreviewed/2024/06/GHSA-2rhh-63xh-7gv7/GHSA-2rhh-63xh-7gv7.json @@ -45,7 +45,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-hcq4-pvmg-m2gp/GHSA-hcq4-pvmg-m2gp.json b/advisories/unreviewed/2024/06/GHSA-hcq4-pvmg-m2gp/GHSA-hcq4-pvmg-m2gp.json index d38474f6daa..c6a2645fb5b 100644 --- a/advisories/unreviewed/2024/06/GHSA-hcq4-pvmg-m2gp/GHSA-hcq4-pvmg-m2gp.json +++ b/advisories/unreviewed/2024/06/GHSA-hcq4-pvmg-m2gp/GHSA-hcq4-pvmg-m2gp.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1333", "CWE-400" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/06/GHSA-x3xf-ggm9-v393/GHSA-x3xf-ggm9-v393.json b/advisories/unreviewed/2024/06/GHSA-x3xf-ggm9-v393/GHSA-x3xf-ggm9-v393.json index 297140de19b..bdf9d5d0832 100644 --- a/advisories/unreviewed/2024/06/GHSA-x3xf-ggm9-v393/GHSA-x3xf-ggm9-v393.json +++ b/advisories/unreviewed/2024/06/GHSA-x3xf-ggm9-v393/GHSA-x3xf-ggm9-v393.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/12/GHSA-2c9f-4h7m-wqr9/GHSA-2c9f-4h7m-wqr9.json b/advisories/unreviewed/2024/12/GHSA-2c9f-4h7m-wqr9/GHSA-2c9f-4h7m-wqr9.json index e22ae8c1795..39cab11c598 100644 --- a/advisories/unreviewed/2024/12/GHSA-2c9f-4h7m-wqr9/GHSA-2c9f-4h7m-wqr9.json +++ b/advisories/unreviewed/2024/12/GHSA-2c9f-4h7m-wqr9/GHSA-2c9f-4h7m-wqr9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2c9f-4h7m-wqr9", - "modified": "2024-12-28T12:30:48Z", + "modified": "2025-01-08T18:30:48Z", "published": "2024-12-28T12:30:48Z", "aliases": [ "CVE-2024-56708" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nEDAC/igen6: Avoid segmentation fault on module unload\n\nThe segmentation fault happens because:\n\nDuring modprobe:\n1. In igen6_probe(), igen6_pvt will be allocated with kzalloc()\n2. In igen6_register_mci(), mci->pvt_info will point to\n &igen6_pvt->imc[mc]\n\nDuring rmmod:\n1. In mci_release() in edac_mc.c, it will kfree(mci->pvt_info)\n2. In igen6_remove(), it will kfree(igen6_pvt);\n\nFix this issue by setting mci->pvt_info to NULL to avoid the double\nkfree.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-415" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-28T10:15:20Z" diff --git a/advisories/unreviewed/2024/12/GHSA-3h64-ff22-jvm6/GHSA-3h64-ff22-jvm6.json b/advisories/unreviewed/2024/12/GHSA-3h64-ff22-jvm6/GHSA-3h64-ff22-jvm6.json index 193c7813478..7eb324afadb 100644 --- a/advisories/unreviewed/2024/12/GHSA-3h64-ff22-jvm6/GHSA-3h64-ff22-jvm6.json +++ b/advisories/unreviewed/2024/12/GHSA-3h64-ff22-jvm6/GHSA-3h64-ff22-jvm6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3h64-ff22-jvm6", - "modified": "2024-12-27T15:31:54Z", + "modified": "2025-01-08T18:30:47Z", "published": "2024-12-27T15:31:54Z", "aliases": [ "CVE-2024-56579" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: amphion: Set video drvdata before register video device\n\nThe video drvdata should be set before the video device is registered,\notherwise video_drvdata() may return NULL in the open() file ops, and led\nto oops.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T15:15:16Z" diff --git a/advisories/unreviewed/2024/12/GHSA-3px9-r72j-9hxj/GHSA-3px9-r72j-9hxj.json b/advisories/unreviewed/2024/12/GHSA-3px9-r72j-9hxj/GHSA-3px9-r72j-9hxj.json index 41416327b3e..e1f3b5d44a7 100644 --- a/advisories/unreviewed/2024/12/GHSA-3px9-r72j-9hxj/GHSA-3px9-r72j-9hxj.json +++ b/advisories/unreviewed/2024/12/GHSA-3px9-r72j-9hxj/GHSA-3px9-r72j-9hxj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3px9-r72j-9hxj", - "modified": "2024-12-27T15:31:53Z", + "modified": "2025-01-08T18:30:47Z", "published": "2024-12-27T15:31:53Z", "aliases": [ "CVE-2024-56535" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: rtw89: coex: check NULL return of kmalloc in btc_fw_set_monreg()\n\nkmalloc may fail, return value might be NULL and will cause\nNULL pointer dereference. Add check NULL return of kmalloc in\nbtc_fw_set_monreg().", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T14:15:33Z" diff --git a/advisories/unreviewed/2024/12/GHSA-5xcw-9q32-27qc/GHSA-5xcw-9q32-27qc.json b/advisories/unreviewed/2024/12/GHSA-5xcw-9q32-27qc/GHSA-5xcw-9q32-27qc.json index 2d4b6ad9bbc..87f49c201c0 100644 --- a/advisories/unreviewed/2024/12/GHSA-5xcw-9q32-27qc/GHSA-5xcw-9q32-27qc.json +++ b/advisories/unreviewed/2024/12/GHSA-5xcw-9q32-27qc/GHSA-5xcw-9q32-27qc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5xcw-9q32-27qc", - "modified": "2024-12-27T15:31:54Z", + "modified": "2025-01-08T18:30:47Z", "published": "2024-12-27T15:31:54Z", "aliases": [ "CVE-2024-56578" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: imx-jpeg: Set video drvdata before register video device\n\nThe video drvdata should be set before the video device is registered,\notherwise video_drvdata() may return NULL in the open() file ops, and led\nto oops.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T15:15:16Z" diff --git a/advisories/unreviewed/2024/12/GHSA-6779-v6gp-jmxv/GHSA-6779-v6gp-jmxv.json b/advisories/unreviewed/2024/12/GHSA-6779-v6gp-jmxv/GHSA-6779-v6gp-jmxv.json index 209e2c991b8..836cfe89d1a 100644 --- a/advisories/unreviewed/2024/12/GHSA-6779-v6gp-jmxv/GHSA-6779-v6gp-jmxv.json +++ b/advisories/unreviewed/2024/12/GHSA-6779-v6gp-jmxv/GHSA-6779-v6gp-jmxv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6779-v6gp-jmxv", - "modified": "2024-12-28T12:30:47Z", + "modified": "2025-01-08T18:30:48Z", "published": "2024-12-28T12:30:47Z", "aliases": [ "CVE-2024-56697" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: Fix the memory allocation issue in amdgpu_discovery_get_nps_info()\n\nFix two issues with memory allocation in amdgpu_discovery_get_nps_info()\nfor mem_ranges:\n\n - Add a check for allocation failure to avoid dereferencing a null\n pointer.\n\n - As suggested by Christophe, use kvcalloc() for memory allocation,\n which checks for multiplication overflow.\n\nAdditionally, assign the output parameters nps_type and range_cnt after\nthe kvcalloc() call to prevent modifying the output parameters in case\nof an error return.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-28T10:15:16Z" diff --git a/advisories/unreviewed/2024/12/GHSA-68cq-j9f2-ggv4/GHSA-68cq-j9f2-ggv4.json b/advisories/unreviewed/2024/12/GHSA-68cq-j9f2-ggv4/GHSA-68cq-j9f2-ggv4.json index 619c8ccaa0e..f804716b5a4 100644 --- a/advisories/unreviewed/2024/12/GHSA-68cq-j9f2-ggv4/GHSA-68cq-j9f2-ggv4.json +++ b/advisories/unreviewed/2024/12/GHSA-68cq-j9f2-ggv4/GHSA-68cq-j9f2-ggv4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-68cq-j9f2-ggv4", - "modified": "2024-12-29T09:30:46Z", + "modified": "2025-01-08T18:30:48Z", "published": "2024-12-29T09:30:46Z", "aliases": [ "CVE-2024-56711" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/panel: himax-hx83102: Add a check to prevent NULL pointer dereference\n\ndrm_mode_duplicate() could return NULL due to lack of memory,\nwhich will then call NULL pointer dereference. Add a check to\nprevent it.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-29T09:15:06Z" diff --git a/advisories/unreviewed/2024/12/GHSA-84gj-7736-4xgg/GHSA-84gj-7736-4xgg.json b/advisories/unreviewed/2024/12/GHSA-84gj-7736-4xgg/GHSA-84gj-7736-4xgg.json index dc08b39a389..d36ab0c57c9 100644 --- a/advisories/unreviewed/2024/12/GHSA-84gj-7736-4xgg/GHSA-84gj-7736-4xgg.json +++ b/advisories/unreviewed/2024/12/GHSA-84gj-7736-4xgg/GHSA-84gj-7736-4xgg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-84gj-7736-4xgg", - "modified": "2024-12-27T15:31:52Z", + "modified": "2025-01-08T18:30:47Z", "published": "2024-12-27T15:31:52Z", "aliases": [ "CVE-2024-53226" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/hns: Fix NULL pointer derefernce in hns_roce_map_mr_sg()\n\nib_map_mr_sg() allows ULPs to specify NULL as the sg_offset argument.\nThe driver needs to check whether it is a NULL pointer before\ndereferencing it.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T14:15:30Z" diff --git a/advisories/unreviewed/2024/12/GHSA-89vj-8q5m-mj67/GHSA-89vj-8q5m-mj67.json b/advisories/unreviewed/2024/12/GHSA-89vj-8q5m-mj67/GHSA-89vj-8q5m-mj67.json index cd3bdfba2f0..54b38537e31 100644 --- a/advisories/unreviewed/2024/12/GHSA-89vj-8q5m-mj67/GHSA-89vj-8q5m-mj67.json +++ b/advisories/unreviewed/2024/12/GHSA-89vj-8q5m-mj67/GHSA-89vj-8q5m-mj67.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-89vj-8q5m-mj67", - "modified": "2024-12-27T15:31:52Z", + "modified": "2025-01-08T18:30:47Z", "published": "2024-12-27T15:31:52Z", "aliases": [ "CVE-2024-53238" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: btmtk: adjust the position to init iso data anchor\n\nMediaTek iso data anchor init should be moved to where MediaTek\nclaims iso data interface.\nIf there is an unexpected BT usb disconnect during setup flow,\nit will cause a NULL pointer crash issue when releasing iso\nanchor since the anchor wasn't been init yet. Adjust the position\nto do iso data anchor init.\n\n[ 17.137991] pc : usb_kill_anchored_urbs+0x60/0x168\n[ 17.137998] lr : usb_kill_anchored_urbs+0x44/0x168\n[ 17.137999] sp : ffffffc0890cb5f0\n[ 17.138000] x29: ffffffc0890cb5f0 x28: ffffff80bb6c2e80\n[ 17.144081] gpio gpiochip0: registered chardev handle for 1 lines\n[ 17.148421] x27: 0000000000000000\n[ 17.148422] x26: ffffffd301ff4298 x25: 0000000000000003 x24: 00000000000000f0\n[ 17.148424] x23: 0000000000000000 x22: 00000000ffffffff x21: 0000000000000001\n[ 17.148425] x20: ffffffffffffffd8 x19: ffffff80c0f25560 x18: 0000000000000000\n[ 17.148427] x17: ffffffd33864e408 x16: ffffffd33808f7c8 x15: 0000000000200000\n[ 17.232789] x14: e0cd73cf80ffffff x13: 50f2137c0a0338c9 x12: 0000000000000001\n[ 17.239912] x11: 0000000080150011 x10: 0000000000000002 x9 : 0000000000000001\n[ 17.247035] x8 : 0000000000000000 x7 : 0000000000008080 x6 : 8080000000000000\n[ 17.254158] x5 : ffffffd33808ebc0 x4 : fffffffe033dcf20 x3 : 0000000080150011\n[ 17.261281] x2 : ffffff8087a91400 x1 : 0000000000000000 x0 : ffffff80c0f25588\n[ 17.268404] Call trace:\n[ 17.270841] usb_kill_anchored_urbs+0x60/0x168\n[ 17.275274] btusb_mtk_release_iso_intf+0x2c/0xd8 [btusb (HASH:5afe 6)]\n[ 17.284226] btusb_mtk_disconnect+0x14/0x28 [btusb (HASH:5afe 6)]\n[ 17.292652] btusb_disconnect+0x70/0x140 [btusb (HASH:5afe 6)]\n[ 17.300818] usb_unbind_interface+0xc4/0x240\n[ 17.305079] device_release_driver_internal+0x18c/0x258\n[ 17.310296] device_release_driver+0x1c/0x30\n[ 17.314557] bus_remove_device+0x140/0x160\n[ 17.318643] device_del+0x1c0/0x330\n[ 17.322121] usb_disable_device+0x80/0x180\n[ 17.326207] usb_disconnect+0xec/0x300\n[ 17.329948] hub_quiesce+0x80/0xd0\n[ 17.333339] hub_disconnect+0x44/0x190\n[ 17.337078] usb_unbind_interface+0xc4/0x240\n[ 17.341337] device_release_driver_internal+0x18c/0x258\n[ 17.346551] device_release_driver+0x1c/0x30\n[ 17.350810] usb_driver_release_interface+0x70/0x88\n[ 17.355677] proc_ioctl+0x13c/0x228\n[ 17.359157] proc_ioctl_default+0x50/0x80\n[ 17.363155] usbdev_ioctl+0x830/0xd08\n[ 17.366808] __arm64_sys_ioctl+0x94/0xd0\n[ 17.370723] invoke_syscall+0x6c/0xf8\n[ 17.374377] el0_svc_common+0x84/0xe0\n[ 17.378030] do_el0_svc+0x20/0x30\n[ 17.381334] el0_svc+0x34/0x60\n[ 17.384382] el0t_64_sync_handler+0x88/0xf0\n[ 17.388554] el0t_64_sync+0x180/0x188\n[ 17.392208] Code: f9400677 f100a2f4 54fffea0 d503201f (b8350288)\n[ 17.398289] ---[ end trace 0000000000000000 ]---", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T14:15:32Z" diff --git a/advisories/unreviewed/2024/12/GHSA-9pg7-c56m-xqjx/GHSA-9pg7-c56m-xqjx.json b/advisories/unreviewed/2024/12/GHSA-9pg7-c56m-xqjx/GHSA-9pg7-c56m-xqjx.json index 250c383773a..61cd94b2322 100644 --- a/advisories/unreviewed/2024/12/GHSA-9pg7-c56m-xqjx/GHSA-9pg7-c56m-xqjx.json +++ b/advisories/unreviewed/2024/12/GHSA-9pg7-c56m-xqjx/GHSA-9pg7-c56m-xqjx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9pg7-c56m-xqjx", - "modified": "2024-12-27T15:31:54Z", + "modified": "2025-01-08T18:30:47Z", "published": "2024-12-27T15:31:54Z", "aliases": [ "CVE-2024-56593" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: brcmfmac: Fix oops due to NULL pointer dereference in brcmf_sdiod_sglist_rw()\n\nThis patch fixes a NULL pointer dereference bug in brcmfmac that occurs\nwhen a high 'sd_sgentry_align' value applies (e.g. 512) and a lot of queued SKBs\nare sent from the pkt queue.\n\nThe problem is the number of entries in the pre-allocated sgtable, it is\nnents = max(rxglom_size, txglom_size) + max(rxglom_size, txglom_size) >> 4 + 1.\nGiven the default [rt]xglom_size=32 it's actually 35 which is too small.\nWorst case, the pkt queue can end up with 64 SKBs. This occurs when a new SKB\nis added for each original SKB if tailroom isn't enough to hold tail_pad.\nAt least one sg entry is needed for each SKB. So, eventually the \"skb_queue_walk loop\"\nin brcmf_sdiod_sglist_rw may run out of sg entries. This makes sg_next return\nNULL and this causes the oops.\n\nThe patch sets nents to max(rxglom_size, txglom_size) * 2 to be able handle\nthe worst-case.\nBtw. this requires only 64-35=29 * 16 (or 20 if CONFIG_NEED_SG_DMA_LENGTH) = 464\nadditional bytes of memory.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T15:15:18Z" diff --git a/advisories/unreviewed/2024/12/GHSA-f225-f9rp-hg69/GHSA-f225-f9rp-hg69.json b/advisories/unreviewed/2024/12/GHSA-f225-f9rp-hg69/GHSA-f225-f9rp-hg69.json index 500d1b1be33..50e0b775fce 100644 --- a/advisories/unreviewed/2024/12/GHSA-f225-f9rp-hg69/GHSA-f225-f9rp-hg69.json +++ b/advisories/unreviewed/2024/12/GHSA-f225-f9rp-hg69/GHSA-f225-f9rp-hg69.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-f225-f9rp-hg69", - "modified": "2024-12-28T12:30:47Z", + "modified": "2025-01-08T18:30:48Z", "published": "2024-12-28T12:30:47Z", "aliases": [ "CVE-2024-56694" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: fix recursive lock when verdict program return SK_PASS\n\nWhen the stream_verdict program returns SK_PASS, it places the received skb\ninto its own receive queue, but a recursive lock eventually occurs, leading\nto an operating system deadlock. This issue has been present since v6.9.\n\n'''\nsk_psock_strp_data_ready\n write_lock_bh(&sk->sk_callback_lock)\n strp_data_ready\n strp_read_sock\n read_sock -> tcp_read_sock\n strp_recv\n cb.rcv_msg -> sk_psock_strp_read\n # now stream_verdict return SK_PASS without peer sock assign\n __SK_PASS = sk_psock_map_verd(SK_PASS, NULL)\n sk_psock_verdict_apply\n sk_psock_skb_ingress_self\n sk_psock_skb_ingress_enqueue\n sk_psock_data_ready\n read_lock_bh(&sk->sk_callback_lock) <= dead lock\n\n'''\n\nThis topic has been discussed before, but it has not been fixed.\nPrevious discussion:\nhttps://lore.kernel.org/all/6684a5864ec86_403d20898@john.notmuch", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-667" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-28T10:15:15Z" diff --git a/advisories/unreviewed/2024/12/GHSA-g3c8-2g4x-qq2h/GHSA-g3c8-2g4x-qq2h.json b/advisories/unreviewed/2024/12/GHSA-g3c8-2g4x-qq2h/GHSA-g3c8-2g4x-qq2h.json index 0f633a2ac8e..b2b095e10b9 100644 --- a/advisories/unreviewed/2024/12/GHSA-g3c8-2g4x-qq2h/GHSA-g3c8-2g4x-qq2h.json +++ b/advisories/unreviewed/2024/12/GHSA-g3c8-2g4x-qq2h/GHSA-g3c8-2g4x-qq2h.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-g3c8-2g4x-qq2h", - "modified": "2024-12-27T15:31:55Z", + "modified": "2025-01-08T18:30:47Z", "published": "2024-12-27T15:31:55Z", "aliases": [ "CVE-2024-56621" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: ufs: core: Cancel RTC work during ufshcd_remove()\n\nCurrently, RTC work is only cancelled during __ufshcd_wl_suspend(). When\nufshcd is removed in ufshcd_remove(), RTC work is not cancelled. Due to\nthis, any further trigger of the RTC work after ufshcd_remove() would\nresult in a NULL pointer dereference as below:\n\nUnable to handle kernel NULL pointer dereference at virtual address 00000000000002a4\nWorkqueue: events ufshcd_rtc_work\nCall trace:\n _raw_spin_lock_irqsave+0x34/0x8c\n pm_runtime_get_if_active+0x24/0xb4\n ufshcd_rtc_work+0x124/0x19c\n process_scheduled_works+0x18c/0x2d8\n worker_thread+0x144/0x280\n kthread+0x11c/0x128\n ret_from_fork+0x10/0x20\n\nSince RTC work accesses the ufshcd internal structures, it should be cancelled\nwhen ufshcd is removed. So do that in ufshcd_remove(), as per the order in\nufshcd_init().", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T15:15:21Z" diff --git a/advisories/unreviewed/2024/12/GHSA-gh74-96w4-8m3h/GHSA-gh74-96w4-8m3h.json b/advisories/unreviewed/2024/12/GHSA-gh74-96w4-8m3h/GHSA-gh74-96w4-8m3h.json index e90827ad8df..c8584a2ef85 100644 --- a/advisories/unreviewed/2024/12/GHSA-gh74-96w4-8m3h/GHSA-gh74-96w4-8m3h.json +++ b/advisories/unreviewed/2024/12/GHSA-gh74-96w4-8m3h/GHSA-gh74-96w4-8m3h.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gh74-96w4-8m3h", - "modified": "2024-12-27T15:31:55Z", + "modified": "2025-01-08T18:30:47Z", "published": "2024-12-27T15:31:55Z", "aliases": [ "CVE-2024-56634" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ngpio: grgpio: Add NULL check in grgpio_probe\n\ndevm_kasprintf() can return a NULL pointer on failure,but this\nreturned value in grgpio_probe is not checked.\nAdd NULL check in grgpio_probe, to handle kernel NULL\npointer dereference error.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T15:15:23Z" diff --git a/advisories/unreviewed/2024/12/GHSA-gw7x-jcrq-44c3/GHSA-gw7x-jcrq-44c3.json b/advisories/unreviewed/2024/12/GHSA-gw7x-jcrq-44c3/GHSA-gw7x-jcrq-44c3.json index c59a9463098..1b299b3dc4a 100644 --- a/advisories/unreviewed/2024/12/GHSA-gw7x-jcrq-44c3/GHSA-gw7x-jcrq-44c3.json +++ b/advisories/unreviewed/2024/12/GHSA-gw7x-jcrq-44c3/GHSA-gw7x-jcrq-44c3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gw7x-jcrq-44c3", - "modified": "2024-12-28T12:30:47Z", + "modified": "2025-01-08T18:30:48Z", "published": "2024-12-28T12:30:47Z", "aliases": [ "CVE-2024-56696" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: core: Fix possible NULL dereference caused by kunit_kzalloc()\n\nkunit_kzalloc() may return a NULL pointer, dereferencing it without\nNULL check may lead to NULL dereference.\nAdd NULL checks for all the kunit_kzalloc() in sound_kunit.c", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-28T10:15:15Z" diff --git a/advisories/unreviewed/2024/12/GHSA-h345-5w6p-mhwf/GHSA-h345-5w6p-mhwf.json b/advisories/unreviewed/2024/12/GHSA-h345-5w6p-mhwf/GHSA-h345-5w6p-mhwf.json index a2bdc33bd37..d16d98de527 100644 --- a/advisories/unreviewed/2024/12/GHSA-h345-5w6p-mhwf/GHSA-h345-5w6p-mhwf.json +++ b/advisories/unreviewed/2024/12/GHSA-h345-5w6p-mhwf/GHSA-h345-5w6p-mhwf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h345-5w6p-mhwf", - "modified": "2024-12-27T15:31:55Z", + "modified": "2025-01-08T18:30:47Z", "published": "2024-12-27T15:31:55Z", "aliases": [ "CVE-2024-56608" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Fix out-of-bounds access in 'dcn21_link_encoder_create'\n\nAn issue was identified in the dcn21_link_encoder_create function where\nan out-of-bounds access could occur when the hpd_source index was used\nto reference the link_enc_hpd_regs array. This array has a fixed size\nand the index was not being checked against the array's bounds before\naccessing it.\n\nThis fix adds a conditional check to ensure that the hpd_source index is\nwithin the valid range of the link_enc_hpd_regs array. If the index is\nout of bounds, the function now returns NULL to prevent undefined\nbehavior.\n\nReferences:\n\n[ 65.920507] ------------[ cut here ]------------\n[ 65.920510] UBSAN: array-index-out-of-bounds in drivers/gpu/drm/amd/amdgpu/../display/dc/resource/dcn21/dcn21_resource.c:1312:29\n[ 65.920519] index 7 is out of range for type 'dcn10_link_enc_hpd_registers [5]'\n[ 65.920523] CPU: 3 PID: 1178 Comm: modprobe Tainted: G OE 6.8.0-cleanershaderfeatureresetasdntipmi200nv2132 #13\n[ 65.920525] Hardware name: AMD Majolica-RN/Majolica-RN, BIOS WMJ0429N_Weekly_20_04_2 04/29/2020\n[ 65.920527] Call Trace:\n[ 65.920529] \n[ 65.920532] dump_stack_lvl+0x48/0x70\n[ 65.920541] dump_stack+0x10/0x20\n[ 65.920543] __ubsan_handle_out_of_bounds+0xa2/0xe0\n[ 65.920549] dcn21_link_encoder_create+0xd9/0x140 [amdgpu]\n[ 65.921009] link_create+0x6d3/0xed0 [amdgpu]\n[ 65.921355] create_links+0x18a/0x4e0 [amdgpu]\n[ 65.921679] dc_create+0x360/0x720 [amdgpu]\n[ 65.921999] ? dmi_matches+0xa0/0x220\n[ 65.922004] amdgpu_dm_init+0x2b6/0x2c90 [amdgpu]\n[ 65.922342] ? console_unlock+0x77/0x120\n[ 65.922348] ? dev_printk_emit+0x86/0xb0\n[ 65.922354] dm_hw_init+0x15/0x40 [amdgpu]\n[ 65.922686] amdgpu_device_init+0x26a8/0x33a0 [amdgpu]\n[ 65.922921] amdgpu_driver_load_kms+0x1b/0xa0 [amdgpu]\n[ 65.923087] amdgpu_pci_probe+0x1b7/0x630 [amdgpu]\n[ 65.923087] local_pci_probe+0x4b/0xb0\n[ 65.923087] pci_device_probe+0xc8/0x280\n[ 65.923087] really_probe+0x187/0x300\n[ 65.923087] __driver_probe_device+0x85/0x130\n[ 65.923087] driver_probe_device+0x24/0x110\n[ 65.923087] __driver_attach+0xac/0x1d0\n[ 65.923087] ? __pfx___driver_attach+0x10/0x10\n[ 65.923087] bus_for_each_dev+0x7d/0xd0\n[ 65.923087] driver_attach+0x1e/0x30\n[ 65.923087] bus_add_driver+0xf2/0x200\n[ 65.923087] driver_register+0x64/0x130\n[ 65.923087] ? __pfx_amdgpu_init+0x10/0x10 [amdgpu]\n[ 65.923087] __pci_register_driver+0x61/0x70\n[ 65.923087] amdgpu_init+0x7d/0xff0 [amdgpu]\n[ 65.923087] do_one_initcall+0x49/0x310\n[ 65.923087] ? kmalloc_trace+0x136/0x360\n[ 65.923087] do_init_module+0x6a/0x270\n[ 65.923087] load_module+0x1fce/0x23a0\n[ 65.923087] init_module_from_file+0x9c/0xe0\n[ 65.923087] ? init_module_from_file+0x9c/0xe0\n[ 65.923087] idempotent_init_module+0x179/0x230\n[ 65.923087] __x64_sys_finit_module+0x5d/0xa0\n[ 65.923087] do_syscall_64+0x76/0x120\n[ 65.923087] entry_SYSCALL_64_after_hwframe+0x6e/0x76\n[ 65.923087] RIP: 0033:0x7f2d80f1e88d\n[ 65.923087] Code: 5b 41 5c c3 66 0f 1f 84 00 00 00 00 00 f3 0f 1e fa 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 8b 0d 73 b5 0f 00 f7 d8 64 89 01 48\n[ 65.923087] RSP: 002b:00007ffc7bc1aa78 EFLAGS: 00000246 ORIG_RAX: 0000000000000139\n[ 65.923087] RAX: ffffffffffffffda RBX: 0000564c9c1db130 RCX: 00007f2d80f1e88d\n[ 65.923087] RDX: 0000000000000000 RSI: 0000564c9c1e5480 RDI: 000000000000000f\n[ 65.923087] RBP: 0000000000040000 R08: 0000000000000000 R09: 0000000000000002\n[ 65.923087] R10: 000000000000000f R11: 0000000000000246 R12: 0000564c9c1e5480\n[ 65.923087] R13: 0000564c9c1db260 R14: 0000000000000000 R15: 0000564c9c1e54b0\n[ 65.923087] \n[ 65.923927] ---[ end trace ]---", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-129" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T15:15:20Z" diff --git a/advisories/unreviewed/2024/12/GHSA-hm4v-3pg5-6f5c/GHSA-hm4v-3pg5-6f5c.json b/advisories/unreviewed/2024/12/GHSA-hm4v-3pg5-6f5c/GHSA-hm4v-3pg5-6f5c.json index 519e17ffd37..3e3002ea056 100644 --- a/advisories/unreviewed/2024/12/GHSA-hm4v-3pg5-6f5c/GHSA-hm4v-3pg5-6f5c.json +++ b/advisories/unreviewed/2024/12/GHSA-hm4v-3pg5-6f5c/GHSA-hm4v-3pg5-6f5c.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hm4v-3pg5-6f5c", - "modified": "2024-12-27T15:31:53Z", + "modified": "2025-01-08T18:30:47Z", "published": "2024-12-27T15:31:53Z", "aliases": [ "CVE-2024-56549" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncachefiles: Fix NULL pointer dereference in object->file\n\nAt present, the object->file has the NULL pointer dereference problem in\nondemand-mode. The root cause is that the allocated fd and object->file\nlifetime are inconsistent, and the user-space invocation to anon_fd uses\nobject->file. Following is the process that triggers the issue:\n\n\t [write fd]\t\t\t\t[umount]\ncachefiles_ondemand_fd_write_iter\n\t\t\t\t fscache_cookie_state_machine\n\t\t\t\t\t cachefiles_withdraw_cookie\n if (!file) return -ENOBUFS\n\t\t\t\t\t cachefiles_clean_up_object\n\t\t\t\t\t cachefiles_unmark_inode_in_use\n\t\t\t\t\t fput(object->file)\n\t\t\t\t\t object->file = NULL\n // file NULL pointer dereference!\n __cachefiles_write(..., file, ...)\n\nFix this issue by add an additional reference count to the object->file\nbefore write/llseek, and decrement after it finished.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T14:15:34Z" diff --git a/advisories/unreviewed/2024/12/GHSA-j53q-3928-9255/GHSA-j53q-3928-9255.json b/advisories/unreviewed/2024/12/GHSA-j53q-3928-9255/GHSA-j53q-3928-9255.json index 046b0d7498b..17e069e6815 100644 --- a/advisories/unreviewed/2024/12/GHSA-j53q-3928-9255/GHSA-j53q-3928-9255.json +++ b/advisories/unreviewed/2024/12/GHSA-j53q-3928-9255/GHSA-j53q-3928-9255.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-j53q-3928-9255", - "modified": "2024-12-27T15:31:54Z", + "modified": "2025-01-08T18:30:47Z", "published": "2024-12-27T15:31:54Z", "aliases": [ "CVE-2024-56580" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: qcom: camss: fix error path on configuration of power domains\n\nThere is a chance to meet runtime issues during configuration of CAMSS\npower domains, because on the error path dev_pm_domain_detach() is\nunexpectedly called with NULL or error pointer.\n\nOne of the simplest ways to reproduce the problem is to probe CAMSS\ndriver before registration of CAMSS power domains, for instance if\na platform CAMCC driver is simply not built.\n\nWarning backtrace example:\n\n Unable to handle kernel NULL pointer dereference at virtual address 00000000000001a2\n\n \n\n pc : dev_pm_domain_detach+0x8/0x48\n lr : camss_probe+0x374/0x9c0\n\n \n\n Call trace:\n dev_pm_domain_detach+0x8/0x48\n platform_probe+0x70/0xf0\n really_probe+0xc4/0x2a8\n __driver_probe_device+0x80/0x140\n driver_probe_device+0x48/0x170\n __device_attach_driver+0xc0/0x148\n bus_for_each_drv+0x88/0xf0\n __device_attach+0xb0/0x1c0\n device_initial_probe+0x1c/0x30\n bus_probe_device+0xb4/0xc0\n deferred_probe_work_func+0x90/0xd0\n process_one_work+0x164/0x3e0\n worker_thread+0x310/0x420\n kthread+0x120/0x130\n ret_from_fork+0x10/0x20", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T15:15:17Z" diff --git a/advisories/unreviewed/2024/12/GHSA-m39v-c9r9-vmwh/GHSA-m39v-c9r9-vmwh.json b/advisories/unreviewed/2024/12/GHSA-m39v-c9r9-vmwh/GHSA-m39v-c9r9-vmwh.json index a8f06803a35..4df43f3f281 100644 --- a/advisories/unreviewed/2024/12/GHSA-m39v-c9r9-vmwh/GHSA-m39v-c9r9-vmwh.json +++ b/advisories/unreviewed/2024/12/GHSA-m39v-c9r9-vmwh/GHSA-m39v-c9r9-vmwh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-m39v-c9r9-vmwh", - "modified": "2024-12-27T15:31:55Z", + "modified": "2025-01-08T18:30:47Z", "published": "2024-12-27T15:31:55Z", "aliases": [ "CVE-2024-56620" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: ufs: qcom: Only free platform MSIs when ESI is enabled\n\nOtherwise, it will result in a NULL pointer dereference as below:\n\nUnable to handle kernel NULL pointer dereference at virtual address 0000000000000008\nCall trace:\n mutex_lock+0xc/0x54\n platform_device_msi_free_irqs_all+0x14/0x20\n ufs_qcom_remove+0x34/0x48 [ufs_qcom]\n platform_remove+0x28/0x44\n device_remove+0x4c/0x80\n device_release_driver_internal+0xd8/0x178\n driver_detach+0x50/0x9c\n bus_remove_driver+0x6c/0xbc\n driver_unregister+0x30/0x60\n platform_driver_unregister+0x14/0x20\n ufs_qcom_pltform_exit+0x18/0xb94 [ufs_qcom]\n __arm64_sys_delete_module+0x180/0x260\n invoke_syscall+0x44/0x100\n el0_svc_common.constprop.0+0xc0/0xe0\n do_el0_svc+0x1c/0x28\n el0_svc+0x34/0xdc\n el0t_64_sync_handler+0xc0/0xc4\n el0t_64_sync+0x190/0x194", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T15:15:21Z" diff --git a/advisories/unreviewed/2024/12/GHSA-q94m-6jg9-pcmh/GHSA-q94m-6jg9-pcmh.json b/advisories/unreviewed/2024/12/GHSA-q94m-6jg9-pcmh/GHSA-q94m-6jg9-pcmh.json index 2f6d95fac47..67089281c74 100644 --- a/advisories/unreviewed/2024/12/GHSA-q94m-6jg9-pcmh/GHSA-q94m-6jg9-pcmh.json +++ b/advisories/unreviewed/2024/12/GHSA-q94m-6jg9-pcmh/GHSA-q94m-6jg9-pcmh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-q94m-6jg9-pcmh", - "modified": "2024-12-28T12:30:47Z", + "modified": "2025-01-08T18:30:48Z", "published": "2024-12-28T12:30:47Z", "aliases": [ "CVE-2024-56689" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nPCI: endpoint: epf-mhi: Avoid NULL dereference if DT lacks 'mmio'\n\nIf platform_get_resource_byname() fails and returns NULL because DT lacks\nan 'mmio' property for the MHI endpoint, dereferencing res->start will\ncause a NULL pointer access. Add a check to prevent it.\n\n[kwilczynski: error message update per the review feedback]\n[bhelgaas: commit log]", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-28T10:15:13Z" diff --git a/advisories/unreviewed/2024/12/GHSA-qqv2-5qvx-v346/GHSA-qqv2-5qvx-v346.json b/advisories/unreviewed/2024/12/GHSA-qqv2-5qvx-v346/GHSA-qqv2-5qvx-v346.json index 6044dbebbdd..ad84188f9e8 100644 --- a/advisories/unreviewed/2024/12/GHSA-qqv2-5qvx-v346/GHSA-qqv2-5qvx-v346.json +++ b/advisories/unreviewed/2024/12/GHSA-qqv2-5qvx-v346/GHSA-qqv2-5qvx-v346.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qqv2-5qvx-v346", - "modified": "2024-12-27T15:31:55Z", + "modified": "2025-01-08T18:30:47Z", "published": "2024-12-27T15:31:55Z", "aliases": [ "CVE-2024-56613" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsched/numa: fix memory leak due to the overwritten vma->numab_state\n\n[Problem Description]\nWhen running the hackbench program of LTP, the following memory leak is\nreported by kmemleak.\n\n # /opt/ltp/testcases/bin/hackbench 20 thread 1000\n Running with 20*40 (== 800) tasks.\n\n # dmesg | grep kmemleak\n ...\n kmemleak: 480 new suspected memory leaks (see /sys/kernel/debug/kmemleak)\n kmemleak: 665 new suspected memory leaks (see /sys/kernel/debug/kmemleak)\n\n # cat /sys/kernel/debug/kmemleak\n unreferenced object 0xffff888cd8ca2c40 (size 64):\n comm \"hackbench\", pid 17142, jiffies 4299780315\n hex dump (first 32 bytes):\n ac 74 49 00 01 00 00 00 4c 84 49 00 01 00 00 00 .tI.....L.I.....\n 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n backtrace (crc bff18fd4):\n [] __kmalloc_cache_noprof+0x2f9/0x3f0\n [] task_numa_work+0x725/0xa00\n [] task_work_run+0x58/0x90\n [] syscall_exit_to_user_mode+0x1c8/0x1e0\n [] do_syscall_64+0x85/0x150\n [] entry_SYSCALL_64_after_hwframe+0x76/0x7e\n ...\n\nThis issue can be consistently reproduced on three different servers:\n * a 448-core server\n * a 256-core server\n * a 192-core server\n\n[Root Cause]\nSince multiple threads are created by the hackbench program (along with\nthe command argument 'thread'), a shared vma might be accessed by two or\nmore cores simultaneously. When two or more cores observe that\nvma->numab_state is NULL at the same time, vma->numab_state will be\noverwritten.\n\nAlthough current code ensures that only one thread scans the VMAs in a\nsingle 'numa_scan_period', there might be a chance for another thread\nto enter in the next 'numa_scan_period' while we have not gotten till\nnumab_state allocation [1].\n\nNote that the command `/opt/ltp/testcases/bin/hackbench 50 process 1000`\ncannot the reproduce the issue. It is verified with 200+ test runs.\n\n[Solution]\nUse the cmpxchg atomic operation to ensure that only one thread executes\nthe vma->numab_state assignment.\n\n[1] https://lore.kernel.org/lkml/1794be3c-358c-4cdc-a43d-a1f841d91ef7@amd.com/", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T15:15:20Z" diff --git a/advisories/unreviewed/2024/12/GHSA-qrq9-5x8v-ghpv/GHSA-qrq9-5x8v-ghpv.json b/advisories/unreviewed/2024/12/GHSA-qrq9-5x8v-ghpv/GHSA-qrq9-5x8v-ghpv.json index 333dc76084f..21bad9fba80 100644 --- a/advisories/unreviewed/2024/12/GHSA-qrq9-5x8v-ghpv/GHSA-qrq9-5x8v-ghpv.json +++ b/advisories/unreviewed/2024/12/GHSA-qrq9-5x8v-ghpv/GHSA-qrq9-5x8v-ghpv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qrq9-5x8v-ghpv", - "modified": "2024-12-27T15:31:53Z", + "modified": "2025-01-08T18:30:47Z", "published": "2024-12-27T15:31:53Z", "aliases": [ "CVE-2024-56536" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: cw1200: Fix potential NULL dereference\n\nA recent refactoring was identified by static analysis to\ncause a potential NULL dereference, fix this!", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T14:15:33Z" diff --git a/advisories/unreviewed/2024/12/GHSA-v859-83xr-7x5w/GHSA-v859-83xr-7x5w.json b/advisories/unreviewed/2024/12/GHSA-v859-83xr-7x5w/GHSA-v859-83xr-7x5w.json index 022a54301b2..dca42c3ed02 100644 --- a/advisories/unreviewed/2024/12/GHSA-v859-83xr-7x5w/GHSA-v859-83xr-7x5w.json +++ b/advisories/unreviewed/2024/12/GHSA-v859-83xr-7x5w/GHSA-v859-83xr-7x5w.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-v859-83xr-7x5w", - "modified": "2024-12-28T12:30:47Z", + "modified": "2025-01-08T18:30:47Z", "published": "2024-12-28T12:30:47Z", "aliases": [ "CVE-2024-56688" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsunrpc: clear XPRT_SOCK_UPD_TIMEOUT when reset transport\n\nSince transport->sock has been set to NULL during reset transport,\nXPRT_SOCK_UPD_TIMEOUT also needs to be cleared. Otherwise, the\nxs_tcp_set_socket_timeouts() may be triggered in xs_tcp_send_request()\nto dereference the transport->sock that has been set to NULL.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-28T10:15:12Z" diff --git a/advisories/unreviewed/2024/12/GHSA-v9jf-g2rr-85c3/GHSA-v9jf-g2rr-85c3.json b/advisories/unreviewed/2024/12/GHSA-v9jf-g2rr-85c3/GHSA-v9jf-g2rr-85c3.json index 96a4903aa4e..7602bbdfe1d 100644 --- a/advisories/unreviewed/2024/12/GHSA-v9jf-g2rr-85c3/GHSA-v9jf-g2rr-85c3.json +++ b/advisories/unreviewed/2024/12/GHSA-v9jf-g2rr-85c3/GHSA-v9jf-g2rr-85c3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-v9jf-g2rr-85c3", - "modified": "2024-12-27T15:31:55Z", + "modified": "2025-01-08T18:30:47Z", "published": "2024-12-27T15:31:55Z", "aliases": [ "CVE-2024-56614" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nxsk: fix OOB map writes when deleting elements\n\nJordy says:\n\n\"\nIn the xsk_map_delete_elem function an unsigned integer\n(map->max_entries) is compared with a user-controlled signed integer\n(k). Due to implicit type conversion, a large unsigned value for\nmap->max_entries can bypass the intended bounds check:\n\n\tif (k >= map->max_entries)\n\t\treturn -EINVAL;\n\nThis allows k to hold a negative value (between -2147483648 and -2),\nwhich is then used as an array index in m->xsk_map[k], which results\nin an out-of-bounds access.\n\n\tspin_lock_bh(&m->lock);\n\tmap_entry = &m->xsk_map[k]; // Out-of-bounds map_entry\n\told_xs = unrcu_pointer(xchg(map_entry, NULL)); // Oob write\n\tif (old_xs)\n\t\txsk_map_sock_delete(old_xs, map_entry);\n\tspin_unlock_bh(&m->lock);\n\nThe xchg operation can then be used to cause an out-of-bounds write.\nMoreover, the invalid map_entry passed to xsk_map_sock_delete can lead\nto further memory corruption.\n\"\n\nIt indeed results in following splat:\n\n[76612.897343] BUG: unable to handle page fault for address: ffffc8fc2e461108\n[76612.904330] #PF: supervisor write access in kernel mode\n[76612.909639] #PF: error_code(0x0002) - not-present page\n[76612.914855] PGD 0 P4D 0\n[76612.917431] Oops: Oops: 0002 [#1] PREEMPT SMP\n[76612.921859] CPU: 11 UID: 0 PID: 10318 Comm: a.out Not tainted 6.12.0-rc1+ #470\n[76612.929189] Hardware name: Intel Corporation S2600WFT/S2600WFT, BIOS SE5C620.86B.02.01.0008.031920191559 03/19/2019\n[76612.939781] RIP: 0010:xsk_map_delete_elem+0x2d/0x60\n[76612.944738] Code: 00 00 41 54 55 53 48 63 2e 3b 6f 24 73 38 4c 8d a7 f8 00 00 00 48 89 fb 4c 89 e7 e8 2d bf 05 00 48 8d b4 eb 00 01 00 00 31 ff <48> 87 3e 48 85 ff 74 05 e8 16 ff ff ff 4c 89 e7 e8 3e bc 05 00 31\n[76612.963774] RSP: 0018:ffffc9002e407df8 EFLAGS: 00010246\n[76612.969079] RAX: 0000000000000000 RBX: ffffc9002e461000 RCX: 0000000000000000\n[76612.976323] RDX: 0000000000000001 RSI: ffffc8fc2e461108 RDI: 0000000000000000\n[76612.983569] RBP: ffffffff80000001 R08: 0000000000000000 R09: 0000000000000007\n[76612.990812] R10: ffffc9002e407e18 R11: ffff888108a38858 R12: ffffc9002e4610f8\n[76612.998060] R13: ffff888108a38858 R14: 00007ffd1ae0ac78 R15: ffffc9002e4610c0\n[76613.005303] FS: 00007f80b6f59740(0000) GS:ffff8897e0ec0000(0000) knlGS:0000000000000000\n[76613.013517] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[76613.019349] CR2: ffffc8fc2e461108 CR3: 000000011e3ef001 CR4: 00000000007726f0\n[76613.026595] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n[76613.033841] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n[76613.041086] PKRU: 55555554\n[76613.043842] Call Trace:\n[76613.046331] \n[76613.048468] ? __die+0x20/0x60\n[76613.051581] ? page_fault_oops+0x15a/0x450\n[76613.055747] ? search_extable+0x22/0x30\n[76613.059649] ? search_bpf_extables+0x5f/0x80\n[76613.063988] ? exc_page_fault+0xa9/0x140\n[76613.067975] ? asm_exc_page_fault+0x22/0x30\n[76613.072229] ? xsk_map_delete_elem+0x2d/0x60\n[76613.076573] ? xsk_map_delete_elem+0x23/0x60\n[76613.080914] __sys_bpf+0x19b7/0x23c0\n[76613.084555] __x64_sys_bpf+0x1a/0x20\n[76613.088194] do_syscall_64+0x37/0xb0\n[76613.091832] entry_SYSCALL_64_after_hwframe+0x4b/0x53\n[76613.096962] RIP: 0033:0x7f80b6d1e88d\n[76613.100592] Code: 5b 41 5c c3 66 0f 1f 84 00 00 00 00 00 f3 0f 1e fa 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 8b 0d 73 b5 0f 00 f7 d8 64 89 01 48\n[76613.119631] RSP: 002b:00007ffd1ae0ac68 EFLAGS: 00000206 ORIG_RAX: 0000000000000141\n[76613.131330] RAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007f80b6d1e88d\n[76613.142632] RDX: 0000000000000098 RSI: 00007ffd1ae0ad20 RDI: 0000000000000003\n[76613.153967] RBP: 00007ffd1ae0adc0 R08: 0000000000000000 R09: 0000000000000000\n[76613.166030] R10: 00007f80b6f77040 R11: 0000000000000206 R12: 00007ffd1ae0aed8\n[76613.177130] R13: 000055ddf42ce1e9 R14: 000055ddf42d0d98 R15: 00\n---truncated---", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T15:15:20Z" diff --git a/advisories/unreviewed/2024/12/GHSA-vww8-w2qw-qhfg/GHSA-vww8-w2qw-qhfg.json b/advisories/unreviewed/2024/12/GHSA-vww8-w2qw-qhfg/GHSA-vww8-w2qw-qhfg.json index 482f87dc845..ee4cafb9591 100644 --- a/advisories/unreviewed/2024/12/GHSA-vww8-w2qw-qhfg/GHSA-vww8-w2qw-qhfg.json +++ b/advisories/unreviewed/2024/12/GHSA-vww8-w2qw-qhfg/GHSA-vww8-w2qw-qhfg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vww8-w2qw-qhfg", - "modified": "2024-12-27T15:31:55Z", + "modified": "2025-01-08T18:30:47Z", "published": "2024-12-27T15:31:55Z", "aliases": [ "CVE-2024-56612" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/gup: handle NULL pages in unpin_user_pages()\n\nThe recent addition of \"pofs\" (pages or folios) handling to gup has a\nflaw: it assumes that unpin_user_pages() handles NULL pages in the pages**\narray. That's not the case, as I discovered when I ran on a new\nconfiguration on my test machine.\n\nFix this by skipping NULL pages in unpin_user_pages(), just like\nunpin_folios() already does.\n\nDetails: when booting on x86 with \"numa=fake=2 movablecore=4G\" on Linux\n6.12, and running this:\n\n tools/testing/selftests/mm/gup_longterm\n\n...I get the following crash:\n\nBUG: kernel NULL pointer dereference, address: 0000000000000008\nRIP: 0010:sanity_check_pinned_pages+0x3a/0x2d0\n...\nCall Trace:\n \n ? __die_body+0x66/0xb0\n ? page_fault_oops+0x30c/0x3b0\n ? do_user_addr_fault+0x6c3/0x720\n ? irqentry_enter+0x34/0x60\n ? exc_page_fault+0x68/0x100\n ? asm_exc_page_fault+0x22/0x30\n ? sanity_check_pinned_pages+0x3a/0x2d0\n unpin_user_pages+0x24/0xe0\n check_and_migrate_movable_pages_or_folios+0x455/0x4b0\n __gup_longterm_locked+0x3bf/0x820\n ? mmap_read_lock_killable+0x12/0x50\n ? __pfx_mmap_read_lock_killable+0x10/0x10\n pin_user_pages+0x66/0xa0\n gup_test_ioctl+0x358/0xb20\n __se_sys_ioctl+0x6b/0xc0\n do_syscall_64+0x7b/0x150\n entry_SYSCALL_64_after_hwframe+0x76/0x7e", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T15:15:20Z" diff --git a/advisories/unreviewed/2025/01/GHSA-23fx-r767-q5g7/GHSA-23fx-r767-q5g7.json b/advisories/unreviewed/2025/01/GHSA-23fx-r767-q5g7/GHSA-23fx-r767-q5g7.json index 30ecbca71a8..a0ae5f7b325 100644 --- a/advisories/unreviewed/2025/01/GHSA-23fx-r767-q5g7/GHSA-23fx-r767-q5g7.json +++ b/advisories/unreviewed/2025/01/GHSA-23fx-r767-q5g7/GHSA-23fx-r767-q5g7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-23fx-r767-q5g7", - "modified": "2025-01-07T21:30:55Z", + "modified": "2025-01-08T18:30:48Z", "published": "2025-01-07T21:30:55Z", "aliases": [ "CVE-2022-45186" ], "details": "An issue was discovered in SuiteCRM 7.12.7. Authenticated users can recover an arbitrary field of a database.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -29,7 +34,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-07T20:15:28Z" diff --git a/advisories/unreviewed/2025/01/GHSA-2776-h8x3-vrr7/GHSA-2776-h8x3-vrr7.json b/advisories/unreviewed/2025/01/GHSA-2776-h8x3-vrr7/GHSA-2776-h8x3-vrr7.json index 1c2667f14bb..46e117346ce 100644 --- a/advisories/unreviewed/2025/01/GHSA-2776-h8x3-vrr7/GHSA-2776-h8x3-vrr7.json +++ b/advisories/unreviewed/2025/01/GHSA-2776-h8x3-vrr7/GHSA-2776-h8x3-vrr7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2776-h8x3-vrr7", - "modified": "2025-01-07T18:30:49Z", + "modified": "2025-01-08T18:30:48Z", "published": "2025-01-07T18:30:49Z", "aliases": [ "CVE-2025-0237" ], "details": "The WebChannel API, which is used to transport various information across processes, did not check the sending principal but rather accepted the principal being sent. This could have led to privilege escalation attacks. This vulnerability affects Firefox < 134 and Firefox ESR < 128.6.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-863" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-07T16:15:38Z" diff --git a/advisories/unreviewed/2025/01/GHSA-27cc-fvv7-2rh9/GHSA-27cc-fvv7-2rh9.json b/advisories/unreviewed/2025/01/GHSA-27cc-fvv7-2rh9/GHSA-27cc-fvv7-2rh9.json new file mode 100644 index 00000000000..ef42bb34ae8 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-27cc-fvv7-2rh9/GHSA-27cc-fvv7-2rh9.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-27cc-fvv7-2rh9", + "modified": "2025-01-08T18:30:49Z", + "published": "2025-01-08T18:30:49Z", + "aliases": [ + "CVE-2024-56786" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: put bpf_link's program when link is safe to be deallocated\n\nIn general, BPF link's underlying BPF program should be considered to be\nreachable through attach hook -> link -> prog chain, and, pessimistically,\nwe have to assume that as long as link's memory is not safe to free,\nattach hook's code might hold a pointer to BPF program and use it.\n\nAs such, it's not (generally) correct to put link's program early before\nwaiting for RCU GPs to go through. More eager bpf_prog_put() that we\ncurrently do is mostly correct due to BPF program's release code doing\nsimilar RCU GP waiting, but as will be shown in the following patches,\nBPF program can be non-sleepable (and, thus, reliant on only \"classic\"\nRCU GP), while BPF link's attach hook can have sleepable semantics and\nneeds to be protected by RCU Tasks Trace, and for such cases BPF link\nhas to go through RCU Tasks Trace + \"classic\" RCU GPs before being\ndeallocated. And so, if we put BPF program early, we might free BPF\nprogram before we free BPF link, leading to use-after-free situation.\n\nSo, this patch defers bpf_prog_put() until we are ready to perform\nbpf_link's deallocation. At worst, this delays BPF program freeing by\none extra RCU GP, but that seems completely acceptable. Alternatively,\nwe'd need more elaborate ways to determine BPF hook, BPF link, and BPF\nprogram lifetimes, and how they relate to each other, which seems like\nan unnecessary complication.\n\nNote, for most BPF links we still will perform eager bpf_prog_put() and\nlink dealloc, so for those BPF links there are no observable changes\nwhatsoever. Only BPF links that use deferred dealloc might notice\nslightly delayed freeing of BPF programs.\n\nAlso, to reduce code and logic duplication, extract program put + link\ndealloc logic into bpf_link_dealloc() helper.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56786" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2fcb921c2799c49ac5e365cf4110f94a64ae4885" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5fe23c57abadfd46a7a66e81f3536e4757252a0b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f44ec8733a8469143fde1984b5e6931b2e2f6f3f" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-08T18:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-2g52-qw8q-wfr9/GHSA-2g52-qw8q-wfr9.json b/advisories/unreviewed/2025/01/GHSA-2g52-qw8q-wfr9/GHSA-2g52-qw8q-wfr9.json index 42bce3b4c1c..0d9d5fda6ab 100644 --- a/advisories/unreviewed/2025/01/GHSA-2g52-qw8q-wfr9/GHSA-2g52-qw8q-wfr9.json +++ b/advisories/unreviewed/2025/01/GHSA-2g52-qw8q-wfr9/GHSA-2g52-qw8q-wfr9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2g52-qw8q-wfr9", - "modified": "2025-01-07T18:30:50Z", + "modified": "2025-01-08T18:30:48Z", "published": "2025-01-07T18:30:50Z", "aliases": [ "CVE-2025-0245" ], "details": "Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been be bypassed. This vulnerability affects Firefox < 134.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -25,7 +30,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-07T16:15:39Z" diff --git a/advisories/unreviewed/2025/01/GHSA-43hc-8q23-h42p/GHSA-43hc-8q23-h42p.json b/advisories/unreviewed/2025/01/GHSA-43hc-8q23-h42p/GHSA-43hc-8q23-h42p.json index 7ed724a93b7..3d8a39a57d9 100644 --- a/advisories/unreviewed/2025/01/GHSA-43hc-8q23-h42p/GHSA-43hc-8q23-h42p.json +++ b/advisories/unreviewed/2025/01/GHSA-43hc-8q23-h42p/GHSA-43hc-8q23-h42p.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-43hc-8q23-h42p", - "modified": "2025-01-08T00:30:49Z", + "modified": "2025-01-08T18:30:48Z", "published": "2025-01-08T00:30:49Z", "aliases": [ "CVE-2018-4301" ], "details": "This issue is fixed in SCSSU-201801. A potential stack based buffer overflow existed in GemaltoKeyHandle.cpp.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-08T00:15:24Z" diff --git a/advisories/unreviewed/2025/01/GHSA-4g5v-5q43-rwpj/GHSA-4g5v-5q43-rwpj.json b/advisories/unreviewed/2025/01/GHSA-4g5v-5q43-rwpj/GHSA-4g5v-5q43-rwpj.json new file mode 100644 index 00000000000..02a98b76ad6 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-4g5v-5q43-rwpj/GHSA-4g5v-5q43-rwpj.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4g5v-5q43-rwpj", + "modified": "2025-01-08T18:30:49Z", + "published": "2025-01-08T18:30:49Z", + "aliases": [ + "CVE-2024-56785" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nMIPS: Loongson64: DTS: Really fix PCIe port nodes for ls7a\n\nFix the dtc warnings:\n\n arch/mips/boot/dts/loongson/ls7a-pch.dtsi:68.16-416.5: Warning (interrupt_provider): /bus@10000000/pci@1a000000: '#interrupt-cells' found, but node is not an interrupt provider\n arch/mips/boot/dts/loongson/ls7a-pch.dtsi:68.16-416.5: Warning (interrupt_provider): /bus@10000000/pci@1a000000: '#interrupt-cells' found, but node is not an interrupt provider\n arch/mips/boot/dts/loongson/loongson64g_4core_ls7a.dtb: Warning (interrupt_map): Failed prerequisite 'interrupt_provider'\n\nAnd a runtime warning introduced in commit 045b14ca5c36 (\"of: WARN on\ndeprecated #address-cells/#size-cells handling\"):\n\n WARNING: CPU: 0 PID: 1 at drivers/of/base.c:106 of_bus_n_addr_cells+0x9c/0xe0\n Missing '#address-cells' in /bus@10000000/pci@1a000000/pci_bridge@9,0\n\nThe fix is similar to commit d89a415ff8d5 (\"MIPS: Loongson64: DTS: Fix PCIe\nport nodes for ls7a\"), which has fixed the issue for ls2k (despite its\nsubject mentions ls7a).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56785" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/01575f2ff8ba578a3436f230668bd056dc2eb823" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4fbd66d8254cedfd1218393f39d83b6c07a01917" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5a2eaa3ad2b803c7ea442c6db7379466ee73c024" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8ef9ea1503d0a129cc6f5cf48fb63633efa5d766" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a7fd78075031871bc68fc56fdaa6e7a3934064b1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c8ee41fc3522c6659e324d90bc2ccd3b6310d7fc" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-08T18:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-4rjf-m3j3-4xh4/GHSA-4rjf-m3j3-4xh4.json b/advisories/unreviewed/2025/01/GHSA-4rjf-m3j3-4xh4/GHSA-4rjf-m3j3-4xh4.json new file mode 100644 index 00000000000..555a207b3f2 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-4rjf-m3j3-4xh4/GHSA-4rjf-m3j3-4xh4.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4rjf-m3j3-4xh4", + "modified": "2025-01-08T18:30:48Z", + "published": "2025-01-08T18:30:48Z", + "aliases": [ + "CVE-2023-35685" + ], + "details": "In DevmemIntMapPages of devicemem_server.c, there is a possible physical page uaf due to a logic error in the code. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-35685" + }, + { + "type": "WEB", + "url": "https://issuetracker.google.com/issues/42420027" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-08T18:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-56h9-9qx5-f7gf/GHSA-56h9-9qx5-f7gf.json b/advisories/unreviewed/2025/01/GHSA-56h9-9qx5-f7gf/GHSA-56h9-9qx5-f7gf.json new file mode 100644 index 00000000000..fc71ba70360 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-56h9-9qx5-f7gf/GHSA-56h9-9qx5-f7gf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-56h9-9qx5-f7gf", + "modified": "2025-01-08T18:30:48Z", + "published": "2025-01-08T18:30:48Z", + "aliases": [ + "CVE-2025-20123" + ], + "details": "Multiple vulnerabilities in the web-based management interface of Cisco Crosswork Network Controller could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against users of the interface of an affected system.\n\nThese vulnerabilities exist because the web-based management interface does not properly validate user-supplied input. An attacker could exploit these vulnerabilities by inserting malicious data into specific data fields in the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit these vulnerabilities, the attacker must have valid administrative credentials.\nCisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20123" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-xwork-xss-KCcg7WwU" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-08T16:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-5c45-mgcf-3hhj/GHSA-5c45-mgcf-3hhj.json b/advisories/unreviewed/2025/01/GHSA-5c45-mgcf-3hhj/GHSA-5c45-mgcf-3hhj.json new file mode 100644 index 00000000000..b5fd9ec2ece --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-5c45-mgcf-3hhj/GHSA-5c45-mgcf-3hhj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5c45-mgcf-3hhj", + "modified": "2025-01-08T18:30:49Z", + "published": "2025-01-08T18:30:49Z", + "aliases": [ + "CVE-2025-21111" + ], + "details": "Dell VxRail, versions 8.0.000 through 8.0.311, contain(s) a Plaintext Storage of a Password vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21111" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000269958/dsa-2025-025-security-update-for-dell-vxrail-for-multiple-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-256" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-08T18:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-5grh-jq56-9254/GHSA-5grh-jq56-9254.json b/advisories/unreviewed/2025/01/GHSA-5grh-jq56-9254/GHSA-5grh-jq56-9254.json index 4dd97b479ee..68c789c710e 100644 --- a/advisories/unreviewed/2025/01/GHSA-5grh-jq56-9254/GHSA-5grh-jq56-9254.json +++ b/advisories/unreviewed/2025/01/GHSA-5grh-jq56-9254/GHSA-5grh-jq56-9254.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5grh-jq56-9254", - "modified": "2025-01-07T18:30:52Z", + "modified": "2025-01-08T18:30:48Z", "published": "2025-01-07T18:30:52Z", "aliases": [ "CVE-2024-55413" ], "details": "A vulnerability exits in driver snxppamd.sys in SUNIX Parallel Driver x64 - 10.1.0.0, which allows low-privileged users to read and write arbitary i/o port via specially crafted IOCTL requests . This can be exploited for privilege escalation, code execution under high privileges, and information disclosure. These signed drivers can also be used to bypass the Microsoft driver-signing policy to deploy malicious code.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-07T18:15:20Z" diff --git a/advisories/unreviewed/2025/01/GHSA-5gvr-6wv7-hpcv/GHSA-5gvr-6wv7-hpcv.json b/advisories/unreviewed/2025/01/GHSA-5gvr-6wv7-hpcv/GHSA-5gvr-6wv7-hpcv.json index 0d76e9c4f63..24bf7be09af 100644 --- a/advisories/unreviewed/2025/01/GHSA-5gvr-6wv7-hpcv/GHSA-5gvr-6wv7-hpcv.json +++ b/advisories/unreviewed/2025/01/GHSA-5gvr-6wv7-hpcv/GHSA-5gvr-6wv7-hpcv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5gvr-6wv7-hpcv", - "modified": "2025-01-08T06:30:55Z", + "modified": "2025-01-08T18:30:48Z", "published": "2025-01-08T06:30:55Z", "aliases": [ "CVE-2024-10151" ], "details": "The Auto iFrame WordPress plugin before 2.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-08T06:15:14Z" diff --git a/advisories/unreviewed/2025/01/GHSA-5hp7-929x-xgf8/GHSA-5hp7-929x-xgf8.json b/advisories/unreviewed/2025/01/GHSA-5hp7-929x-xgf8/GHSA-5hp7-929x-xgf8.json index 9b618c160f8..953f4ccf861 100644 --- a/advisories/unreviewed/2025/01/GHSA-5hp7-929x-xgf8/GHSA-5hp7-929x-xgf8.json +++ b/advisories/unreviewed/2025/01/GHSA-5hp7-929x-xgf8/GHSA-5hp7-929x-xgf8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5hp7-929x-xgf8", - "modified": "2025-01-07T00:31:39Z", + "modified": "2025-01-08T18:30:48Z", "published": "2025-01-07T00:31:39Z", "aliases": [ "CVE-2024-53933" ], "details": "The com.callerscreen.colorphone.themes.callflash (aka Color Call Theme & Call Screen) application through 1.0.7 for Android enables any application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.android.call.color.app.activities.DialerActivity component.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -25,7 +30,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-06T22:15:10Z" diff --git a/advisories/unreviewed/2025/01/GHSA-68r8-f4jc-vc2p/GHSA-68r8-f4jc-vc2p.json b/advisories/unreviewed/2025/01/GHSA-68r8-f4jc-vc2p/GHSA-68r8-f4jc-vc2p.json index 070c670bfd8..b668a8d46b2 100644 --- a/advisories/unreviewed/2025/01/GHSA-68r8-f4jc-vc2p/GHSA-68r8-f4jc-vc2p.json +++ b/advisories/unreviewed/2025/01/GHSA-68r8-f4jc-vc2p/GHSA-68r8-f4jc-vc2p.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-68r8-f4jc-vc2p", - "modified": "2025-01-07T18:30:50Z", + "modified": "2025-01-08T18:30:48Z", "published": "2025-01-07T18:30:50Z", "aliases": [ "CVE-2025-0244" ], "details": "When redirecting to an invalid protocol scheme, an attacker could spoof the address bar. \n*Note: This issue only affected Android operating systems. Other operating systems are unaffected.* This vulnerability affects Firefox < 134.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-07T16:15:39Z" diff --git a/advisories/unreviewed/2025/01/GHSA-6prq-q63r-xqhp/GHSA-6prq-q63r-xqhp.json b/advisories/unreviewed/2025/01/GHSA-6prq-q63r-xqhp/GHSA-6prq-q63r-xqhp.json index e8ac662983b..29f69db4b9c 100644 --- a/advisories/unreviewed/2025/01/GHSA-6prq-q63r-xqhp/GHSA-6prq-q63r-xqhp.json +++ b/advisories/unreviewed/2025/01/GHSA-6prq-q63r-xqhp/GHSA-6prq-q63r-xqhp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6prq-q63r-xqhp", - "modified": "2025-01-07T18:30:52Z", + "modified": "2025-01-08T18:30:48Z", "published": "2025-01-07T18:30:52Z", "aliases": [ "CVE-2024-55414" ], "details": "A vulnerability exits in driver SmSerl64.sys in Motorola SM56 Modem WDM Driver v6.12.23.0, which allows low-privileged users to mapping physical memory via specially crafted IOCTL requests . This can be exploited for privilege escalation, code execution under high privileges, and information disclosure. These signed drivers can also be used to bypass the Microsoft driver-signing policy to deploy malicious code.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-77" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-07T18:15:20Z" diff --git a/advisories/unreviewed/2025/01/GHSA-79x5-rf42-8f32/GHSA-79x5-rf42-8f32.json b/advisories/unreviewed/2025/01/GHSA-79x5-rf42-8f32/GHSA-79x5-rf42-8f32.json new file mode 100644 index 00000000000..60e6fa2493f --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-79x5-rf42-8f32/GHSA-79x5-rf42-8f32.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-79x5-rf42-8f32", + "modified": "2025-01-08T18:30:49Z", + "published": "2025-01-08T18:30:49Z", + "aliases": [ + "CVE-2024-6350" + ], + "details": "A malformed 802.15.4 packet causes a buffer overflow to occur leading to an assert and a denial of service. A watchdog reset clears the error condition automatically.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6350" + }, + { + "type": "WEB", + "url": "https://community.silabs.com/069Vm00000HtvDgIAJ" + }, + { + "type": "WEB", + "url": "https://github.com/SiliconLabs/simplicity_sdk/releases" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-08T18:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-7x89-2c7c-8xjf/GHSA-7x89-2c7c-8xjf.json b/advisories/unreviewed/2025/01/GHSA-7x89-2c7c-8xjf/GHSA-7x89-2c7c-8xjf.json new file mode 100644 index 00000000000..c78644c8c2d --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-7x89-2c7c-8xjf/GHSA-7x89-2c7c-8xjf.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7x89-2c7c-8xjf", + "modified": "2025-01-08T18:30:48Z", + "published": "2025-01-08T18:30:48Z", + "aliases": [ + "CVE-2025-20166" + ], + "details": "A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface.\n\nThis vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker must have at least a low-privileged account on an affected device.\nCisco has not released software updates that address this vulnerability. There are no workarounds that address this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20166" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cspc-xss-CDOJZyH" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-xwork-xss-KCcg7WwU" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-86" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-08T17:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-87rx-3vxp-6r9f/GHSA-87rx-3vxp-6r9f.json b/advisories/unreviewed/2025/01/GHSA-87rx-3vxp-6r9f/GHSA-87rx-3vxp-6r9f.json new file mode 100644 index 00000000000..2f7846e82e9 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-87rx-3vxp-6r9f/GHSA-87rx-3vxp-6r9f.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-87rx-3vxp-6r9f", + "modified": "2025-01-08T18:30:48Z", + "published": "2025-01-08T18:30:48Z", + "aliases": [ + "CVE-2024-13187" + ], + "details": "A vulnerability was found in Kingsoft WPS Office 6.14.0 on macOS. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component TCC Handler. The manipulation leads to code injection. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13187" + }, + { + "type": "WEB", + "url": "https://github.com/Rsec-1/wps" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.290779" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.290779" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.468013" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-08T17:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-89r5-96wf-852f/GHSA-89r5-96wf-852f.json b/advisories/unreviewed/2025/01/GHSA-89r5-96wf-852f/GHSA-89r5-96wf-852f.json index ec582b639a1..91a7189ac99 100644 --- a/advisories/unreviewed/2025/01/GHSA-89r5-96wf-852f/GHSA-89r5-96wf-852f.json +++ b/advisories/unreviewed/2025/01/GHSA-89r5-96wf-852f/GHSA-89r5-96wf-852f.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-89r5-96wf-852f", - "modified": "2025-01-07T00:31:39Z", + "modified": "2025-01-08T18:30:48Z", "published": "2025-01-07T00:31:39Z", "aliases": [ "CVE-2024-53934" ], "details": "The com.windymob.callscreen.ringtone.callcolor.colorphone (aka Color Phone Call Screen Themes) application through 1.1.2 for Android enables any application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.frovis.androidbase.call.DialerActivity component.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-281" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-06T22:15:10Z" diff --git a/advisories/unreviewed/2025/01/GHSA-928f-3rxq-5jvp/GHSA-928f-3rxq-5jvp.json b/advisories/unreviewed/2025/01/GHSA-928f-3rxq-5jvp/GHSA-928f-3rxq-5jvp.json index f345d5f12c1..ffc9f1d2f96 100644 --- a/advisories/unreviewed/2025/01/GHSA-928f-3rxq-5jvp/GHSA-928f-3rxq-5jvp.json +++ b/advisories/unreviewed/2025/01/GHSA-928f-3rxq-5jvp/GHSA-928f-3rxq-5jvp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-928f-3rxq-5jvp", - "modified": "2025-01-07T18:30:50Z", + "modified": "2025-01-08T18:30:48Z", "published": "2025-01-07T18:30:50Z", "aliases": [ "CVE-2025-0243" ], "details": "Memory safety bugs present in Firefox 133, Thunderbird 133, Firefox ESR 128.5, and Thunderbird 128.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 134 and Firefox ESR < 128.6.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -29,7 +34,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-07T16:15:38Z" diff --git a/advisories/unreviewed/2025/01/GHSA-93c4-8fxm-4wq3/GHSA-93c4-8fxm-4wq3.json b/advisories/unreviewed/2025/01/GHSA-93c4-8fxm-4wq3/GHSA-93c4-8fxm-4wq3.json new file mode 100644 index 00000000000..1037a52add3 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-93c4-8fxm-4wq3/GHSA-93c4-8fxm-4wq3.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-93c4-8fxm-4wq3", + "modified": "2025-01-08T18:30:48Z", + "published": "2025-01-08T18:30:48Z", + "aliases": [ + "CVE-2024-56776" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/sti: avoid potential dereference of error pointers\n\nThe return value of drm_atomic_get_crtc_state() needs to be\nchecked. To avoid use of error pointer 'crtc_state' in case\nof the failure.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56776" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/40725c5fabee804fecce41d4d5c5bae80c45e1c4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/831214f77037de02afc287eae93ce97f218d8c04" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8ab73ac97c0fa528f66eeccd9bb53eb6eb7d20dc" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e98ff67f5a68114804607de549c2350d27628fc7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f67786293193cf01ebcc6fdbcbd1587b24f52679" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-08T18:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-95w3-8433-6jf6/GHSA-95w3-8433-6jf6.json b/advisories/unreviewed/2025/01/GHSA-95w3-8433-6jf6/GHSA-95w3-8433-6jf6.json new file mode 100644 index 00000000000..3addcc4fd31 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-95w3-8433-6jf6/GHSA-95w3-8433-6jf6.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-95w3-8433-6jf6", + "modified": "2025-01-08T18:30:49Z", + "published": "2025-01-08T18:30:49Z", + "aliases": [ + "CVE-2024-56780" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nquota: flush quota_release_work upon quota writeback\n\nOne of the paths quota writeback is called from is:\n\nfreeze_super()\n sync_filesystem()\n ext4_sync_fs()\n dquot_writeback_dquots()\n\nSince we currently don't always flush the quota_release_work queue in\nthis path, we can end up with the following race:\n\n 1. dquot are added to releasing_dquots list during regular operations.\n 2. FS Freeze starts, however, this does not flush the quota_release_work queue.\n 3. Freeze completes.\n 4. Kernel eventually tries to flush the workqueue while FS is frozen which\n hits a WARN_ON since transaction gets started during frozen state:\n\n ext4_journal_check_start+0x28/0x110 [ext4] (unreliable)\n __ext4_journal_start_sb+0x64/0x1c0 [ext4]\n ext4_release_dquot+0x90/0x1d0 [ext4]\n quota_release_workfn+0x43c/0x4d0\n\nWhich is the following line:\n\n WARN_ON(sb->s_writers.frozen == SB_FREEZE_COMPLETE);\n\nWhich ultimately results in generic/390 failing due to dmesg\nnoise. This was detected on powerpc machine 15 cores.\n\nTo avoid this, make sure to flush the workqueue during\ndquot_writeback_dquots() so we dont have any pending workitems after\nfreeze.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56780" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3e6ff207cd5bd924ad94cd1a7c633bcdac0ba1cb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6f3821acd7c3143145999248087de5fb4b48cf26" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8ea87e34792258825d290f4dc5216276e91cb224" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a5abba5e0e586e258ded3e798fe5f69c66fec198" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ab6cfcf8ed2c7496f55d020b65b1d8cd55d9a2cb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ac6f420291b3fee1113f21d612fa88b628afab5b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bcacb52a985f1b6d280f698a470b873dfe52728a" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-08T18:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9vgr-6gpq-2rj5/GHSA-9vgr-6gpq-2rj5.json b/advisories/unreviewed/2025/01/GHSA-9vgr-6gpq-2rj5/GHSA-9vgr-6gpq-2rj5.json new file mode 100644 index 00000000000..65f5229a66d --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9vgr-6gpq-2rj5/GHSA-9vgr-6gpq-2rj5.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9vgr-6gpq-2rj5", + "modified": "2025-01-08T18:30:49Z", + "published": "2025-01-08T18:30:49Z", + "aliases": [ + "CVE-2024-56783" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_socket: remove WARN_ON_ONCE on maximum cgroup level\n\ncgroup maximum depth is INT_MAX by default, there is a cgroup toggle to\nrestrict this maximum depth to a more reasonable value not to harm\nperformance. Remove unnecessary WARN_ON_ONCE which is reachable from\nuserspace.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56783" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2f9bec0a749eb646b384fde0c7b7c24687b2ffae" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7064a6daa4a700a298fe3aee11dea296bfe59fc4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b7529880cb961d515642ce63f9d7570869bbbdc3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e227c042580ab065edc610c9ddc9bea691e6fc4d" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-08T18:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-cjgq-5qmw-rcj6/GHSA-cjgq-5qmw-rcj6.json b/advisories/unreviewed/2025/01/GHSA-cjgq-5qmw-rcj6/GHSA-cjgq-5qmw-rcj6.json new file mode 100644 index 00000000000..a6b0bce7019 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-cjgq-5qmw-rcj6/GHSA-cjgq-5qmw-rcj6.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cjgq-5qmw-rcj6", + "modified": "2025-01-08T18:30:48Z", + "published": "2025-01-08T18:30:48Z", + "aliases": [ + "CVE-2024-55459" + ], + "details": "An issue in keras 3.7.0 allows attackers to write arbitrary files to the user's machine via downloading a crafted tar file through the get_file function.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55459" + }, + { + "type": "WEB", + "url": "https://github.com/keras-team/keras" + }, + { + "type": "WEB", + "url": "https://github.com/mselbrede/CVE-2024-51442" + }, + { + "type": "WEB", + "url": "https://keras.io" + }, + { + "type": "WEB", + "url": "https://river-bicycle-f1e.notion.site/Arbitrary-File-Write-Vulnerability-in-get_file-function-11888e31952580179224e50892976d32" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-08T17:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-f3xq-g93v-w8cv/GHSA-f3xq-g93v-w8cv.json b/advisories/unreviewed/2025/01/GHSA-f3xq-g93v-w8cv/GHSA-f3xq-g93v-w8cv.json index 77d39af87cd..cf2e19cdc62 100644 --- a/advisories/unreviewed/2025/01/GHSA-f3xq-g93v-w8cv/GHSA-f3xq-g93v-w8cv.json +++ b/advisories/unreviewed/2025/01/GHSA-f3xq-g93v-w8cv/GHSA-f3xq-g93v-w8cv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-f3xq-g93v-w8cv", - "modified": "2025-01-07T18:30:50Z", + "modified": "2025-01-08T18:30:48Z", "published": "2025-01-07T18:30:49Z", "aliases": [ "CVE-2025-0240" ], "details": "Parsing a JavaScript module as JSON could, under some circumstances, cause cross-compartment access, which may result in a use-after-free. This vulnerability affects Firefox < 134 and Firefox ESR < 128.6.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-07T16:15:38Z" diff --git a/advisories/unreviewed/2025/01/GHSA-f4vg-m386-rcvq/GHSA-f4vg-m386-rcvq.json b/advisories/unreviewed/2025/01/GHSA-f4vg-m386-rcvq/GHSA-f4vg-m386-rcvq.json new file mode 100644 index 00000000000..1bdf9dd3b40 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-f4vg-m386-rcvq/GHSA-f4vg-m386-rcvq.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f4vg-m386-rcvq", + "modified": "2025-01-08T18:30:49Z", + "published": "2025-01-08T18:30:49Z", + "aliases": [ + "CVE-2024-56782" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nACPI: x86: Add adev NULL check to acpi_quirk_skip_serdev_enumeration()\n\nacpi_dev_hid_match() does not check for adev == NULL, dereferencing\nit unconditional.\n\nAdd a check for adev being NULL before calling acpi_dev_hid_match().\n\nAt the moment acpi_quirk_skip_serdev_enumeration() is never called with\na controller_parent without an ACPI companion, but better safe than sorry.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56782" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4a49194f587a62d972b602e3e1a2c3cfe6567966" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e173bce05f7032a8b4964cfef82a4b7668f5f3af" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-08T18:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-h4qv-2mm7-9gwm/GHSA-h4qv-2mm7-9gwm.json b/advisories/unreviewed/2025/01/GHSA-h4qv-2mm7-9gwm/GHSA-h4qv-2mm7-9gwm.json new file mode 100644 index 00000000000..648ca8a77d8 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-h4qv-2mm7-9gwm/GHSA-h4qv-2mm7-9gwm.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h4qv-2mm7-9gwm", + "modified": "2025-01-08T18:30:48Z", + "published": "2025-01-08T18:30:48Z", + "aliases": [ + "CVE-2024-51442" + ], + "details": "Command Injection in Minidlna version v1.3.3 and before allows an attacker to execute arbitrary OS commands via a specially crafted minidlna.conf configuration file.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51442" + }, + { + "type": "WEB", + "url": "https://github.com/mselbrede/CVE-2024-51442" + }, + { + "type": "WEB", + "url": "https://sourceforge.net/p/minidlna/bugs/364" + }, + { + "type": "WEB", + "url": "https://sourceforge.net/p/minidlna/git/ci/master/tree/minidlna.c" + }, + { + "type": "WEB", + "url": "https://sourceforge.net/projects/minidlna" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-08T18:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-hwmv-fpmh-92pc/GHSA-hwmv-fpmh-92pc.json b/advisories/unreviewed/2025/01/GHSA-hwmv-fpmh-92pc/GHSA-hwmv-fpmh-92pc.json new file mode 100644 index 00000000000..61218da4be7 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-hwmv-fpmh-92pc/GHSA-hwmv-fpmh-92pc.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hwmv-fpmh-92pc", + "modified": "2025-01-08T18:30:48Z", + "published": "2025-01-08T18:30:48Z", + "aliases": [ + "CVE-2025-20168" + ], + "details": "A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface.\n\nThis vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker must have at least a low-privileged account on an affected device.\nCisco has not released software updates that address this vulnerability. There are no workarounds that address this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20168" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cspc-xss-CDOJZyH" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-xwork-xss-KCcg7WwU" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-86" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-08T17:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-j3fj-gjrj-c97q/GHSA-j3fj-gjrj-c97q.json b/advisories/unreviewed/2025/01/GHSA-j3fj-gjrj-c97q/GHSA-j3fj-gjrj-c97q.json new file mode 100644 index 00000000000..404c4c5ecd3 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-j3fj-gjrj-c97q/GHSA-j3fj-gjrj-c97q.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j3fj-gjrj-c97q", + "modified": "2025-01-08T18:30:49Z", + "published": "2025-01-08T18:30:49Z", + "aliases": [ + "CVE-2024-56784" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Adding array index check to prevent memory corruption\n\n[Why & How]\nArray indices out of bound caused memory corruption. Adding checks to\nensure that array index stays in bound.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56784" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2c437d9a0b496168e1a1defd17b531f0a526dbe9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/dff526dc3e27f5484f5ba11471b9fbbe681467f2" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-08T18:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-jcv7-vfq5-hj4c/GHSA-jcv7-vfq5-hj4c.json b/advisories/unreviewed/2025/01/GHSA-jcv7-vfq5-hj4c/GHSA-jcv7-vfq5-hj4c.json index 4605e2455b4..657ad29d5e7 100644 --- a/advisories/unreviewed/2025/01/GHSA-jcv7-vfq5-hj4c/GHSA-jcv7-vfq5-hj4c.json +++ b/advisories/unreviewed/2025/01/GHSA-jcv7-vfq5-hj4c/GHSA-jcv7-vfq5-hj4c.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jcv7-vfq5-hj4c", - "modified": "2025-01-07T18:30:52Z", + "modified": "2025-01-08T18:30:48Z", "published": "2025-01-07T18:30:52Z", "aliases": [ "CVE-2024-50659" ], "details": "Cross Site Scripting vulnerability iPublish Media Solutions AdPortal 3.0.39 allows a remote attacker to escalate privileges via the shippingAsBilling parameter in updateuserinfo.html.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-07T18:15:19Z" diff --git a/advisories/unreviewed/2025/01/GHSA-jwc2-hj9w-9cff/GHSA-jwc2-hj9w-9cff.json b/advisories/unreviewed/2025/01/GHSA-jwc2-hj9w-9cff/GHSA-jwc2-hj9w-9cff.json new file mode 100644 index 00000000000..fcf913b3984 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-jwc2-hj9w-9cff/GHSA-jwc2-hj9w-9cff.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jwc2-hj9w-9cff", + "modified": "2025-01-08T18:30:48Z", + "published": "2025-01-08T18:30:48Z", + "aliases": [ + "CVE-2025-20126" + ], + "details": "A vulnerability in certification validation routines of Cisco ThousandEyes Endpoint Agent for macOS and RoomOS could allow an unauthenticated, remote attacker to intercept or manipulate metrics information.\n\nThis vulnerability exists because the affected software does not properly validate certificates for hosted metrics services. An on-path attacker could exploit this vulnerability by intercepting network traffic using a crafted certificate. A successful exploit could allow the attacker to masquerade as a trusted host and monitor or change communications between the remote metrics service and the vulnerable client.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20126" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-thousandeyes-cert-pqtJUv9N" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-xwork-xss-KCcg7WwU" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-295" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-08T16:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-m6c8-mv97-5jcm/GHSA-m6c8-mv97-5jcm.json b/advisories/unreviewed/2025/01/GHSA-m6c8-mv97-5jcm/GHSA-m6c8-mv97-5jcm.json new file mode 100644 index 00000000000..bf40b5800eb --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-m6c8-mv97-5jcm/GHSA-m6c8-mv97-5jcm.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m6c8-mv97-5jcm", + "modified": "2025-01-08T18:30:49Z", + "published": "2025-01-08T18:30:49Z", + "aliases": [ + "CVE-2024-56787" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsoc: imx8m: Probe the SoC driver as platform driver\n\nWith driver_async_probe=* on kernel command line, the following trace is\nproduced because on i.MX8M Plus hardware because the soc-imx8m.c driver\ncalls of_clk_get_by_name() which returns -EPROBE_DEFER because the clock\ndriver is not yet probed. This was not detected during regular testing\nwithout driver_async_probe.\n\nConvert the SoC code to platform driver and instantiate a platform device\nin its current device_initcall() to probe the platform driver. Rework\n.soc_revision callback to always return valid error code and return SoC\nrevision via parameter. This way, if anything in the .soc_revision callback\nreturn -EPROBE_DEFER, it gets propagated to .probe and the .probe will get\nretried later.\n\n\"\n------------[ cut here ]------------\nWARNING: CPU: 1 PID: 1 at drivers/soc/imx/soc-imx8m.c:115 imx8mm_soc_revision+0xdc/0x180\nCPU: 1 UID: 0 PID: 1 Comm: swapper/0 Not tainted 6.11.0-next-20240924-00002-g2062bb554dea #603\nHardware name: DH electronics i.MX8M Plus DHCOM Premium Developer Kit (3) (DT)\npstate: 20000005 (nzCv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)\npc : imx8mm_soc_revision+0xdc/0x180\nlr : imx8mm_soc_revision+0xd0/0x180\nsp : ffff8000821fbcc0\nx29: ffff8000821fbce0 x28: 0000000000000000 x27: ffff800081810120\nx26: ffff8000818a9970 x25: 0000000000000006 x24: 0000000000824311\nx23: ffff8000817f42c8 x22: ffff0000df8be210 x21: fffffffffffffdfb\nx20: ffff800082780000 x19: 0000000000000001 x18: ffffffffffffffff\nx17: ffff800081fff418 x16: ffff8000823e1000 x15: ffff0000c03b65e8\nx14: ffff0000c00051b0 x13: ffff800082790000 x12: 0000000000000801\nx11: ffff80008278ffff x10: ffff80008209d3a6 x9 : ffff80008062e95c\nx8 : ffff8000821fb9a0 x7 : 0000000000000000 x6 : 00000000000080e3\nx5 : ffff0000df8c03d8 x4 : 0000000000000000 x3 : 0000000000000000\nx2 : 0000000000000000 x1 : fffffffffffffdfb x0 : fffffffffffffdfb\nCall trace:\n imx8mm_soc_revision+0xdc/0x180\n imx8_soc_init+0xb0/0x1e0\n do_one_initcall+0x94/0x1a8\n kernel_init_freeable+0x240/0x2a8\n kernel_init+0x28/0x140\n ret_from_fork+0x10/0x20\n---[ end trace 0000000000000000 ]---\nSoC: i.MX8MP revision 1.1\n\"", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56787" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2129f6faa5dfe8c6b87aad11720bf75edd77d3e4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/997a3c04d7fa3d1d385c14691350d096fada648c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9cc832d37799dbea950c4c8a34721b02b8b5a8ff" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e497edb8f31ec2c2b6f4ce930e175aa2da8be334" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ea2ff66feb5f9b183f9e2f9d06c21340bd88de12" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-08T18:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-m7p9-xw5x-w2c4/GHSA-m7p9-xw5x-w2c4.json b/advisories/unreviewed/2025/01/GHSA-m7p9-xw5x-w2c4/GHSA-m7p9-xw5x-w2c4.json new file mode 100644 index 00000000000..a320d8712e7 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-m7p9-xw5x-w2c4/GHSA-m7p9-xw5x-w2c4.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m7p9-xw5x-w2c4", + "modified": "2025-01-08T18:30:48Z", + "published": "2025-01-08T18:30:48Z", + "aliases": [ + "CVE-2024-56770" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: netem: account for backlog updates from child qdisc\n\nIn general, 'qlen' of any classful qdisc should keep track of the\nnumber of packets that the qdisc itself and all of its children holds.\nIn case of netem, 'qlen' only accounts for the packets in its internal\ntfifo. When netem is used with a child qdisc, the child qdisc can use\n'qdisc_tree_reduce_backlog' to inform its parent, netem, about created\nor dropped SKBs. This function updates 'qlen' and the backlog statistics\nof netem, but netem does not account for changes made by a child qdisc.\n'qlen' then indicates the wrong number of packets in the tfifo.\nIf a child qdisc creates new SKBs during enqueue and informs its parent\nabout this, netem's 'qlen' value is increased. When netem dequeues the\nnewly created SKBs from the child, the 'qlen' in netem is not updated.\nIf 'qlen' reaches the configured sch->limit, the enqueue function stops\nworking, even though the tfifo is not full.\n\nReproduce the bug:\nEnsure that the sender machine has GSO enabled. Configure netem as root\nqdisc and tbf as its child on the outgoing interface of the machine\nas follows:\n$ tc qdisc add dev root handle 1: netem delay 100ms limit 100\n$ tc qdisc add dev parent 1:0 tbf rate 50Mbit burst 1542 latency 50ms\n\nSend bulk TCP traffic out via this interface, e.g., by running an iPerf3\nclient on the machine. Check the qdisc statistics:\n$ tc -s qdisc show dev \n\nStatistics after 10s of iPerf3 TCP test before the fix (note that\nnetem's backlog > limit, netem stopped accepting packets):\nqdisc netem 1: root refcnt 2 limit 1000 delay 100ms\n Sent 2767766 bytes 1848 pkt (dropped 652, overlimits 0 requeues 0)\n backlog 4294528236b 1155p requeues 0\nqdisc tbf 10: parent 1:1 rate 50Mbit burst 1537b lat 50ms\n Sent 2767766 bytes 1848 pkt (dropped 327, overlimits 7601 requeues 0)\n backlog 0b 0p requeues 0\n\nStatistics after the fix:\nqdisc netem 1: root refcnt 2 limit 1000 delay 100ms\n Sent 37766372 bytes 24974 pkt (dropped 9, overlimits 0 requeues 0)\n backlog 0b 0p requeues 0\nqdisc tbf 10: parent 1:1 rate 50Mbit burst 1537b lat 50ms\n Sent 37766372 bytes 24974 pkt (dropped 327, overlimits 96017 requeues 0)\n backlog 0b 0p requeues 0\n\ntbf segments the GSO SKBs (tbf_segment) and updates the netem's 'qlen'.\nThe interface fully stops transferring packets and \"locks\". In this case,\nthe child qdisc and tfifo are empty, but 'qlen' indicates the tfifo is at\nits limit and no more packets are accepted.\n\nThis patch adds a counter for the entries in the tfifo. Netem's 'qlen' is\nonly decreased when a packet is returned by its dequeue function, and not\nduring enqueuing into the child qdisc. External updates to 'qlen' are thus\naccounted for and only the behavior of the backlog statistics changes. As\nin other qdiscs, 'qlen' then keeps track of how many packets are held in\nnetem and all of its children. As before, sch->limit remains as the\nmaximum number of packets in the tfifo. The same applies to netem's\nbacklog statistics.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56770" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/10df49cfca73dfbbdb6c4150d859f7e8926ae427" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/216509dda290f6db92c816dd54b83c1df9da9e76" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/356078a5c55ec8d2061fcc009fb8599f5b0527f9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3824c5fad18eeb7abe0c4fc966f29959552dca3e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/83c6ab12f08dcc09d4c5ac86fdb89736b28f1d31" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c2047b0e216c8edce227d7c42f99ac2877dad0e4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f8d4bc455047cf3903cd6f85f49978987dbb3027" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-08T17:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-p48v-w2c7-4756/GHSA-p48v-w2c7-4756.json b/advisories/unreviewed/2025/01/GHSA-p48v-w2c7-4756/GHSA-p48v-w2c7-4756.json new file mode 100644 index 00000000000..e7c43f97514 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-p48v-w2c7-4756/GHSA-p48v-w2c7-4756.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p48v-w2c7-4756", + "modified": "2025-01-08T18:30:48Z", + "published": "2025-01-08T18:30:48Z", + "aliases": [ + "CVE-2024-55517" + ], + "details": "An issue was discovered in the Interllect Core Search in Polaris FT Intellect Core Banking 9.5. Input passed through the groupType parameter in /SCGController is mishandled before being used in SQL queries, allowing SQL injection in an authenticated session.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55517" + }, + { + "type": "WEB", + "url": "https://hackmd.io/@AowPhwc/SyvEiDsIye" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-08T16:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-p4q7-g7ff-823j/GHSA-p4q7-g7ff-823j.json b/advisories/unreviewed/2025/01/GHSA-p4q7-g7ff-823j/GHSA-p4q7-g7ff-823j.json index dbf08f45948..47b0ecf2189 100644 --- a/advisories/unreviewed/2025/01/GHSA-p4q7-g7ff-823j/GHSA-p4q7-g7ff-823j.json +++ b/advisories/unreviewed/2025/01/GHSA-p4q7-g7ff-823j/GHSA-p4q7-g7ff-823j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p4q7-g7ff-823j", - "modified": "2025-01-07T18:30:49Z", + "modified": "2025-01-08T18:30:48Z", "published": "2025-01-07T18:30:49Z", "aliases": [ "CVE-2025-0239" ], "details": "When using Alt-Svc, ALPN did not properly validate certificates when the original server is redirecting to an insecure site. This vulnerability affects Firefox < 134 and Firefox ESR < 128.6.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-295" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-07T16:15:38Z" diff --git a/advisories/unreviewed/2025/01/GHSA-p52h-3642-m4x3/GHSA-p52h-3642-m4x3.json b/advisories/unreviewed/2025/01/GHSA-p52h-3642-m4x3/GHSA-p52h-3642-m4x3.json index 321dc0f1123..37bd7fa6a0c 100644 --- a/advisories/unreviewed/2025/01/GHSA-p52h-3642-m4x3/GHSA-p52h-3642-m4x3.json +++ b/advisories/unreviewed/2025/01/GHSA-p52h-3642-m4x3/GHSA-p52h-3642-m4x3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p52h-3642-m4x3", - "modified": "2025-01-08T06:30:55Z", + "modified": "2025-01-08T18:30:48Z", "published": "2025-01-08T06:30:55Z", "aliases": [ "CVE-2024-12585" ], "details": "The Property Hive WordPress plugin before 2.1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-08T06:15:16Z" diff --git a/advisories/unreviewed/2025/01/GHSA-phcc-6pmp-qw9v/GHSA-phcc-6pmp-qw9v.json b/advisories/unreviewed/2025/01/GHSA-phcc-6pmp-qw9v/GHSA-phcc-6pmp-qw9v.json index f2afc72f1cb..f597a5e7b30 100644 --- a/advisories/unreviewed/2025/01/GHSA-phcc-6pmp-qw9v/GHSA-phcc-6pmp-qw9v.json +++ b/advisories/unreviewed/2025/01/GHSA-phcc-6pmp-qw9v/GHSA-phcc-6pmp-qw9v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-phcc-6pmp-qw9v", - "modified": "2025-01-07T18:30:49Z", + "modified": "2025-01-08T18:30:48Z", "published": "2025-01-07T18:30:49Z", "aliases": [ "CVE-2025-0238" ], "details": "Assuming a controlled failed memory allocation, an attacker could have caused a use-after-free, leading to a potentially exploitable crash. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, and Firefox ESR < 115.19.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-07T16:15:38Z" diff --git a/advisories/unreviewed/2025/01/GHSA-phf7-cpqm-749x/GHSA-phf7-cpqm-749x.json b/advisories/unreviewed/2025/01/GHSA-phf7-cpqm-749x/GHSA-phf7-cpqm-749x.json new file mode 100644 index 00000000000..e983e194582 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-phf7-cpqm-749x/GHSA-phf7-cpqm-749x.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-phf7-cpqm-749x", + "modified": "2025-01-08T18:30:48Z", + "published": "2025-01-08T18:30:48Z", + "aliases": [ + "CVE-2024-56774" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: add a sanity check for btrfs root in btrfs_search_slot()\n\nSyzbot reports a null-ptr-deref in btrfs_search_slot().\n\nThe reproducer is using rescue=ibadroots, and the extent tree root is\ncorrupted thus the extent tree is NULL.\n\nWhen scrub tries to search the extent tree to gather the needed extent\ninfo, btrfs_search_slot() doesn't check if the target root is NULL or\nnot, resulting the null-ptr-deref.\n\nAdd sanity check for btrfs root before using it in btrfs_search_slot().", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56774" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3ed51857a50f530ac7a1482e069dfbd1298558d4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/757171d1369b3b47f36932d40a05a0715496dcab" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/93992c3d9629b02dccf6849238559d5c24f2dece" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c71d114ef68c95da5a82ec85a721ab31f5bd905b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/db66fb87c21e8ae724886e6a464dcbac562a64c6" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-08T18:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-pj5p-wjjg-q3w5/GHSA-pj5p-wjjg-q3w5.json b/advisories/unreviewed/2025/01/GHSA-pj5p-wjjg-q3w5/GHSA-pj5p-wjjg-q3w5.json index 37461c40b93..172e318ba56 100644 --- a/advisories/unreviewed/2025/01/GHSA-pj5p-wjjg-q3w5/GHSA-pj5p-wjjg-q3w5.json +++ b/advisories/unreviewed/2025/01/GHSA-pj5p-wjjg-q3w5/GHSA-pj5p-wjjg-q3w5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pj5p-wjjg-q3w5", - "modified": "2025-01-07T18:30:52Z", + "modified": "2025-01-08T18:30:48Z", "published": "2025-01-07T18:30:52Z", "aliases": [ "CVE-2024-50658" ], "details": "Server-Side Template Injection (SSTI) was found in AdPortal 3.0.39 allows a remote attacker to execute arbitrary code via the shippingAsBilling and firstname parameters in updateuserinfo.html file", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-07T18:15:18Z" diff --git a/advisories/unreviewed/2025/01/GHSA-pm49-6j2c-6857/GHSA-pm49-6j2c-6857.json b/advisories/unreviewed/2025/01/GHSA-pm49-6j2c-6857/GHSA-pm49-6j2c-6857.json new file mode 100644 index 00000000000..8d5802d23e8 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-pm49-6j2c-6857/GHSA-pm49-6j2c-6857.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pm49-6j2c-6857", + "modified": "2025-01-08T18:30:48Z", + "published": "2025-01-08T18:30:48Z", + "aliases": [ + "CVE-2024-56775" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Fix handling of plane refcount\n\n[Why]\nThe mechanism to backup and restore plane states doesn't maintain\nrefcount, which can cause issues if the refcount of the plane changes\nin between backup and restore operations, such as memory leaks if the\nrefcount was supposed to go down, or double frees / invalid memory\naccesses if the refcount was supposed to go up.\n\n[How]\nCache and re-apply current refcount when restoring plane states.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56775" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/27227a234c1487cb7a684615f0749c455218833a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8cb2f6793845f135b28361ba8e96901cae3e5790" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-08T18:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-pxgr-mfpf-3qxj/GHSA-pxgr-mfpf-3qxj.json b/advisories/unreviewed/2025/01/GHSA-pxgr-mfpf-3qxj/GHSA-pxgr-mfpf-3qxj.json index 34dce46fd11..9b57de0c37e 100644 --- a/advisories/unreviewed/2025/01/GHSA-pxgr-mfpf-3qxj/GHSA-pxgr-mfpf-3qxj.json +++ b/advisories/unreviewed/2025/01/GHSA-pxgr-mfpf-3qxj/GHSA-pxgr-mfpf-3qxj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pxgr-mfpf-3qxj", - "modified": "2025-01-07T00:31:40Z", + "modified": "2025-01-08T18:30:48Z", "published": "2025-01-07T00:31:40Z", "aliases": [ "CVE-2024-53936" ], "details": "The com.asianmobile.callcolor (aka Color Phone Call Screen App) application through 24 for Android enables any application (with no permissions) to place phone calls without user interaction by sending a crafted intent via the com.asianmobile.callcolor.ui.component.call.CallActivity component.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -25,7 +30,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-06T22:15:10Z" diff --git a/advisories/unreviewed/2025/01/GHSA-q9q4-8gjg-4w35/GHSA-q9q4-8gjg-4w35.json b/advisories/unreviewed/2025/01/GHSA-q9q4-8gjg-4w35/GHSA-q9q4-8gjg-4w35.json new file mode 100644 index 00000000000..0d178f7e015 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-q9q4-8gjg-4w35/GHSA-q9q4-8gjg-4w35.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q9q4-8gjg-4w35", + "modified": "2025-01-08T18:30:48Z", + "published": "2025-01-08T18:30:48Z", + "aliases": [ + "CVE-2025-20167" + ], + "details": "A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface.\n\nThis vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker must have at least a low-privileged account on an affected device.\nCisco has not released software updates that address this vulnerability. There are no workarounds that address this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20167" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cspc-xss-CDOJZyH" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-xwork-xss-KCcg7WwU" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-86" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-08T17:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-qjmp-rfrj-7cv5/GHSA-qjmp-rfrj-7cv5.json b/advisories/unreviewed/2025/01/GHSA-qjmp-rfrj-7cv5/GHSA-qjmp-rfrj-7cv5.json index 5d86efe6cfb..9c9c4b266fb 100644 --- a/advisories/unreviewed/2025/01/GHSA-qjmp-rfrj-7cv5/GHSA-qjmp-rfrj-7cv5.json +++ b/advisories/unreviewed/2025/01/GHSA-qjmp-rfrj-7cv5/GHSA-qjmp-rfrj-7cv5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qjmp-rfrj-7cv5", - "modified": "2025-01-07T21:30:55Z", + "modified": "2025-01-08T18:30:48Z", "published": "2025-01-07T21:30:55Z", "aliases": [ "CVE-2022-45185" ], "details": "An issue was discovered in SuiteCRM 7.12.7. Authenticated users can use CRM functions to upload malicious files. Then, deserialization can be used to achieve code execution.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-07T20:15:28Z" diff --git a/advisories/unreviewed/2025/01/GHSA-qw28-p6qx-vj78/GHSA-qw28-p6qx-vj78.json b/advisories/unreviewed/2025/01/GHSA-qw28-p6qx-vj78/GHSA-qw28-p6qx-vj78.json index a72c02ce0de..943818c8680 100644 --- a/advisories/unreviewed/2025/01/GHSA-qw28-p6qx-vj78/GHSA-qw28-p6qx-vj78.json +++ b/advisories/unreviewed/2025/01/GHSA-qw28-p6qx-vj78/GHSA-qw28-p6qx-vj78.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qw28-p6qx-vj78", - "modified": "2025-01-07T18:30:50Z", + "modified": "2025-01-08T18:30:48Z", "published": "2025-01-07T18:30:50Z", "aliases": [ "CVE-2025-0242" ], "details": "Memory safety bugs present in Firefox 133, Thunderbird 133, Firefox ESR 115.18, Firefox ESR 128.5, Thunderbird 115.18, and Thunderbird 128.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, and Firefox ESR < 115.19.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-07T16:15:38Z" diff --git a/advisories/unreviewed/2025/01/GHSA-r7gg-4xq2-48h9/GHSA-r7gg-4xq2-48h9.json b/advisories/unreviewed/2025/01/GHSA-r7gg-4xq2-48h9/GHSA-r7gg-4xq2-48h9.json index bc24fa5c8cd..62e74c66008 100644 --- a/advisories/unreviewed/2025/01/GHSA-r7gg-4xq2-48h9/GHSA-r7gg-4xq2-48h9.json +++ b/advisories/unreviewed/2025/01/GHSA-r7gg-4xq2-48h9/GHSA-r7gg-4xq2-48h9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-r7gg-4xq2-48h9", - "modified": "2025-01-07T18:30:52Z", + "modified": "2025-01-08T18:30:48Z", "published": "2025-01-07T18:30:52Z", "aliases": [ "CVE-2024-55412" ], "details": "A vulnerability exits in driver snxpsamd.sys in SUNIX Serial Driver x64 - 10.1.0.0, which allows low-privileged users to read and write arbitary i/o port via specially crafted IOCTL requests . This can be exploited for privilege escalation, code execution under high privileges, and information disclosure. These signed drivers can also be used to bypass the Microsoft driver-signing policy to deploy malicious code.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-07T18:15:20Z" diff --git a/advisories/unreviewed/2025/01/GHSA-rpgv-42mm-c94j/GHSA-rpgv-42mm-c94j.json b/advisories/unreviewed/2025/01/GHSA-rpgv-42mm-c94j/GHSA-rpgv-42mm-c94j.json index c87e431ffdc..a4accfdbe8a 100644 --- a/advisories/unreviewed/2025/01/GHSA-rpgv-42mm-c94j/GHSA-rpgv-42mm-c94j.json +++ b/advisories/unreviewed/2025/01/GHSA-rpgv-42mm-c94j/GHSA-rpgv-42mm-c94j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rpgv-42mm-c94j", - "modified": "2025-01-07T18:30:52Z", + "modified": "2025-01-08T18:30:48Z", "published": "2025-01-07T18:30:52Z", "aliases": [ "CVE-2024-50660" ], "details": "File Upload Bypass was found in AdPortal 3.0.39 allows a remote attacker to execute arbitrary code via the file upload functionality", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-07T18:15:19Z" diff --git a/advisories/unreviewed/2025/01/GHSA-v6jm-7r7p-9979/GHSA-v6jm-7r7p-9979.json b/advisories/unreviewed/2025/01/GHSA-v6jm-7r7p-9979/GHSA-v6jm-7r7p-9979.json new file mode 100644 index 00000000000..f8dfd49490e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-v6jm-7r7p-9979/GHSA-v6jm-7r7p-9979.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v6jm-7r7p-9979", + "modified": "2025-01-08T18:30:49Z", + "published": "2025-01-08T18:30:49Z", + "aliases": [ + "CVE-2024-56779" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: fix nfs4_openowner leak when concurrent nfsd4_open occur\n\nThe action force umount(umount -f) will attempt to kill all rpc_task even\numount operation may ultimately fail if some files remain open.\nConsequently, if an action attempts to open a file, it can potentially\nsend two rpc_task to nfs server.\n\n NFS CLIENT\nthread1 thread2\nopen(\"file\")\n...\nnfs4_do_open\n _nfs4_do_open\n _nfs4_open_and_get_state\n _nfs4_proc_open\n nfs4_run_open_task\n /* rpc_task1 */\n rpc_run_task\n rpc_wait_for_completion_task\n\n umount -f\n nfs_umount_begin\n rpc_killall_tasks\n rpc_signal_task\n rpc_task1 been wakeup\n and return -512\n _nfs4_do_open // while loop\n ...\n nfs4_run_open_task\n /* rpc_task2 */\n rpc_run_task\n rpc_wait_for_completion_task\n\nWhile processing an open request, nfsd will first attempt to find or\nallocate an nfs4_openowner. If it finds an nfs4_openowner that is not\nmarked as NFS4_OO_CONFIRMED, this nfs4_openowner will released. Since\ntwo rpc_task can attempt to open the same file simultaneously from the\nclient to server, and because two instances of nfsd can run\nconcurrently, this situation can lead to lots of memory leak.\nAdditionally, when we echo 0 to /proc/fs/nfsd/threads, warning will be\ntriggered.\n\n NFS SERVER\nnfsd1 nfsd2 echo 0 > /proc/fs/nfsd/threads\n\nnfsd4_open\n nfsd4_process_open1\n find_or_alloc_open_stateowner\n // alloc oo1, stateid1\n nfsd4_open\n nfsd4_process_open1\n find_or_alloc_open_stateowner\n // find oo1, without NFS4_OO_CONFIRMED\n release_openowner\n unhash_openowner_locked\n list_del_init(&oo->oo_perclient)\n // cannot find this oo\n // from client, LEAK!!!\n alloc_stateowner // alloc oo2\n\n nfsd4_process_open2\n init_open_stateid\n // associate oo1\n // with stateid1, stateid1 LEAK!!!\n nfs4_get_vfs_file\n // alloc nfsd_file1 and nfsd_file_mark1\n // all LEAK!!!\n\n nfsd4_process_open2\n ...\n\n write_threads\n ...\n nfsd_destroy_serv\n nfsd_shutdown_net\n nfs4_state_shutdown_net\n nfs4_state_destroy_net\n destroy_client\n __destroy_client\n // won't find oo1!!!\n nfsd_shutdown_generic\n nfsd_file_cache_shutdown\n kmem_cache_destroy\n for nfsd_file_slab\n and nfsd_file_mark_slab\n // bark since nfsd_file1\n // and nfsd_file_mark1\n // still alive\n\n=======================================================================\nBUG nfsd_file (Not tainted): Objects remaining in nfsd_file on\n__kmem_cache_shutdown()\n-----------------------------------------------------------------------\n\nSlab 0xffd4000004438a80 objects=34 used=1 fp=0xff11000110e2ad28\nflags=0x17ffffc0000240(workingset|head|node=0|zone=2|lastcpupid=0x1fffff)\nCPU: 4 UID: 0 PID: 757 Comm: sh Not tainted 6.12.0-rc6+ #19\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS\n1.16.1-2.fc37 04/01/2014\nCall Trace:\n \n dum\n---truncated---", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56779" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0ab0a3ad24e970e894abcac58f85c332d1726749" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2d505a801e57428057563762f67a5a62009b2600" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/37dfc81266d3a32294524bfadd3396614f8633ee" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/45abb68c941ebc9a35c6d3a7b08196712093c636" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6f73f920b7ad0084373e46121d7ac34117aed652" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/98100e88dd8865999dc6379a3356cd799795fe7b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a85364f0d30dee01c5d5b4afa55a9629a8f36d8e" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-08T18:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-v6xw-pf6j-mpfg/GHSA-v6xw-pf6j-mpfg.json b/advisories/unreviewed/2025/01/GHSA-v6xw-pf6j-mpfg/GHSA-v6xw-pf6j-mpfg.json new file mode 100644 index 00000000000..51874c8f596 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-v6xw-pf6j-mpfg/GHSA-v6xw-pf6j-mpfg.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v6xw-pf6j-mpfg", + "modified": "2025-01-08T18:30:48Z", + "published": "2025-01-08T18:30:48Z", + "aliases": [ + "CVE-2024-56772" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nkunit: string-stream: Fix a UAF bug in kunit_init_suite()\n\nIn kunit_debugfs_create_suite(), if alloc_string_stream() fails in the\nkunit_suite_for_each_test_case() loop, the \"suite->log = stream\"\nhas assigned before, and the error path only free the suite->log's stream\nmemory but not set it to NULL, so the later string_stream_clear() of\nsuite->log in kunit_init_suite() will cause below UAF bug.\n\nSet stream pointer to NULL after free to fix it.\n\n\tUnable to handle kernel paging request at virtual address 006440150000030d\n\tMem abort info:\n\t ESR = 0x0000000096000004\n\t EC = 0x25: DABT (current EL), IL = 32 bits\n\t SET = 0, FnV = 0\n\t EA = 0, S1PTW = 0\n\t FSC = 0x04: level 0 translation fault\n\tData abort info:\n\t ISV = 0, ISS = 0x00000004, ISS2 = 0x00000000\n\t CM = 0, WnR = 0, TnD = 0, TagAccess = 0\n\t GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0\n\t[006440150000030d] address between user and kernel address ranges\n\tInternal error: Oops: 0000000096000004 [#1] PREEMPT SMP\n\tDumping ftrace buffer:\n\t (ftrace buffer empty)\n\tModules linked in: iio_test_gts industrialio_gts_helper cfg80211 rfkill ipv6 [last unloaded: iio_test_gts]\n\tCPU: 5 UID: 0 PID: 6253 Comm: modprobe Tainted: G B W N 6.12.0-rc4+ #458\n\tTainted: [B]=BAD_PAGE, [W]=WARN, [N]=TEST\n\tHardware name: linux,dummy-virt (DT)\n\tpstate: 40000005 (nZcv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n\tpc : string_stream_clear+0x54/0x1ac\n\tlr : string_stream_clear+0x1a8/0x1ac\n\tsp : ffffffc080b47410\n\tx29: ffffffc080b47410 x28: 006440550000030d x27: ffffff80c96b5e98\n\tx26: ffffff80c96b5e80 x25: ffffffe461b3f6c0 x24: 0000000000000003\n\tx23: ffffff80c96b5e88 x22: 1ffffff019cdf4fc x21: dfffffc000000000\n\tx20: ffffff80ce6fa7e0 x19: 032202a80000186d x18: 0000000000001840\n\tx17: 0000000000000000 x16: 0000000000000000 x15: ffffffe45c355cb4\n\tx14: ffffffe45c35589c x13: ffffffe45c03da78 x12: ffffffb810168e75\n\tx11: 1ffffff810168e74 x10: ffffffb810168e74 x9 : dfffffc000000000\n\tx8 : 0000000000000004 x7 : 0000000000000003 x6 : 0000000000000001\n\tx5 : ffffffc080b473a0 x4 : 0000000000000000 x3 : 0000000000000000\n\tx2 : 0000000000000001 x1 : ffffffe462fbf620 x0 : dfffffc000000000\n\tCall trace:\n\t string_stream_clear+0x54/0x1ac\n\t __kunit_test_suites_init+0x108/0x1d8\n\t kunit_exec_run_tests+0xb8/0x100\n\t kunit_module_notify+0x400/0x55c\n\t notifier_call_chain+0xfc/0x3b4\n\t blocking_notifier_call_chain+0x68/0x9c\n\t do_init_module+0x24c/0x5c8\n\t load_module+0x4acc/0x4e90\n\t init_module_from_file+0xd4/0x128\n\t idempotent_init_module+0x2d4/0x57c\n\t __arm64_sys_finit_module+0xac/0x100\n\t invoke_syscall+0x6c/0x258\n\t el0_svc_common.constprop.0+0x160/0x22c\n\t do_el0_svc+0x44/0x5c\n\t el0_svc+0x48/0xb8\n\t el0t_64_sync_handler+0x13c/0x158\n\t el0t_64_sync+0x190/0x194\n\tCode: f9400753 d2dff800 f2fbffe0 d343fe7c (38e06b80)\n\t---[ end trace 0000000000000000 ]---\n\tKernel panic - not syncing: Oops: Fatal exception", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56772" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3213b92754b94dec6836e8b4d6ec7d224a805b61" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/39e21403c978862846fa68b7f6d06f9cca235194" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-08T18:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-w3jp-95q8-wv48/GHSA-w3jp-95q8-wv48.json b/advisories/unreviewed/2025/01/GHSA-w3jp-95q8-wv48/GHSA-w3jp-95q8-wv48.json index 20886e5bf14..d8bacfa379a 100644 --- a/advisories/unreviewed/2025/01/GHSA-w3jp-95q8-wv48/GHSA-w3jp-95q8-wv48.json +++ b/advisories/unreviewed/2025/01/GHSA-w3jp-95q8-wv48/GHSA-w3jp-95q8-wv48.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-w3jp-95q8-wv48", - "modified": "2025-01-07T21:30:55Z", + "modified": "2025-01-08T18:30:48Z", "published": "2025-01-07T21:30:55Z", "aliases": [ "CVE-2024-53522" ], "details": "Bangkok Medical Software HOSxP XE v4.64.11.3 was discovered to contain a hardcoded IDEA Key-IV pair in the HOSxPXE4.exe and HOS-WIN32.INI components. This allows attackers to access sensitive information.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-331" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-07T20:15:30Z" diff --git a/advisories/unreviewed/2025/01/GHSA-w4pw-p565-4p8w/GHSA-w4pw-p565-4p8w.json b/advisories/unreviewed/2025/01/GHSA-w4pw-p565-4p8w/GHSA-w4pw-p565-4p8w.json new file mode 100644 index 00000000000..e9bad73bb68 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-w4pw-p565-4p8w/GHSA-w4pw-p565-4p8w.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w4pw-p565-4p8w", + "modified": "2025-01-08T18:30:48Z", + "published": "2025-01-08T18:30:48Z", + "aliases": [ + "CVE-2024-56777" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/sti: avoid potential dereference of error pointers in sti_gdp_atomic_check\n\nThe return value of drm_atomic_get_crtc_state() needs to be\nchecked. To avoid use of error pointer 'crtc_state' in case\nof the failure.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56777" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3cf2e7c448e246f7e700c7aa47450d1e27579559" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/997b64c3f4c1827c5cfda8ae7f5d13f78d28b541" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b79612ed6bc1a184c45427105c851b5b2d4342ca" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e965e771b069421c233d674c3c8cd8c7f7245f42" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f5804567cf9605d6e5ec46c0bb786f7d50f18c13" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-08T18:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-w5c9-x85v-xrxm/GHSA-w5c9-x85v-xrxm.json b/advisories/unreviewed/2025/01/GHSA-w5c9-x85v-xrxm/GHSA-w5c9-x85v-xrxm.json new file mode 100644 index 00000000000..d22940d621a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-w5c9-x85v-xrxm/GHSA-w5c9-x85v-xrxm.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w5c9-x85v-xrxm", + "modified": "2025-01-08T18:30:48Z", + "published": "2025-01-08T18:30:48Z", + "aliases": [ + "CVE-2024-56771" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmtd: spinand: winbond: Fix 512GW, 01GW, 01JW and 02JW ECC information\n\nThese four chips:\n* W25N512GW\n* W25N01GW\n* W25N01JW\n* W25N02JW\nall require a single bit of ECC strength and thus feature an on-die\nHamming-like ECC engine. There is no point in filling a ->get_status()\ncallback for them because the main ECC status bytes are located in\nstandard places, and retrieving the number of bitflips in case of\ncorrected chunk is both useless and unsupported (if there are bitflips,\nthen there is 1 at most, so no need to query the chip for that).\n\nWithout this change, a kernel warning triggers every time a bit flips.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56771" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/234d5f75c3ae911b52c5e4442b8a87fbbd129836" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fee9b240916df82a8b07aef0fdfe96785417a164" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-08T18:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-w993-3vv8-hxp8/GHSA-w993-3vv8-hxp8.json b/advisories/unreviewed/2025/01/GHSA-w993-3vv8-hxp8/GHSA-w993-3vv8-hxp8.json new file mode 100644 index 00000000000..6de59a6e5da --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-w993-3vv8-hxp8/GHSA-w993-3vv8-hxp8.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w993-3vv8-hxp8", + "modified": "2025-01-08T18:30:48Z", + "published": "2025-01-08T18:30:48Z", + "aliases": [ + "CVE-2024-56773" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nkunit: Fix potential null dereference in kunit_device_driver_test()\n\nkunit_kzalloc() may return a NULL pointer, dereferencing it without\nNULL check may lead to NULL dereference.\nAdd a NULL check for test_state.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56773" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/435c20eed572a95709b1536ff78832836b2f91b1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5d28fac59369b5d3c48cdf09e50275a61ff91202" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-08T18:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-x99c-gp84-c52f/GHSA-x99c-gp84-c52f.json b/advisories/unreviewed/2025/01/GHSA-x99c-gp84-c52f/GHSA-x99c-gp84-c52f.json new file mode 100644 index 00000000000..d6a50afcdce --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-x99c-gp84-c52f/GHSA-x99c-gp84-c52f.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x99c-gp84-c52f", + "modified": "2025-01-08T18:30:49Z", + "published": "2025-01-08T18:30:49Z", + "aliases": [ + "CVE-2024-56781" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\npowerpc/prom_init: Fixup missing powermac #size-cells\n\nOn some powermacs `escc` nodes are missing `#size-cells` properties,\nwhich is deprecated and now triggers a warning at boot since commit\n045b14ca5c36 (\"of: WARN on deprecated #address-cells/#size-cells\nhandling\").\n\nFor example:\n\n Missing '#size-cells' in /pci@f2000000/mac-io@c/escc@13000\n WARNING: CPU: 0 PID: 0 at drivers/of/base.c:133 of_bus_n_size_cells+0x98/0x108\n Hardware name: PowerMac3,1 7400 0xc0209 PowerMac\n ...\n Call Trace:\n of_bus_n_size_cells+0x98/0x108 (unreliable)\n of_bus_default_count_cells+0x40/0x60\n __of_get_address+0xc8/0x21c\n __of_address_to_resource+0x5c/0x228\n pmz_init_port+0x5c/0x2ec\n pmz_probe.isra.0+0x144/0x1e4\n pmz_console_init+0x10/0x48\n console_init+0xcc/0x138\n start_kernel+0x5c4/0x694\n\nAs powermacs boot via prom_init it's possible to add the missing\nproperties to the device tree during boot, avoiding the warning. Note\nthat `escc-legacy` nodes are also missing `#size-cells` properties, but\nthey are skipped by the macio driver, so leave them alone.\n\nDepends-on: 045b14ca5c36 (\"of: WARN on deprecated #address-cells/#size-cells handling\")", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56781" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0b94d838018fb0a824e0cd3149034928c99fb1b7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/296a109fa77110ba5267fe0e90a26005eecc2726" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/691284c2cd33ffaa0b35ce53b3286b90621e9dc9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6d5f0453a2228607333bff0c85238a3cb495d194" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a79a7e3c03ae2a07f68b5f24d5ed549f9799ec89" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cf89c9434af122f28a3552e6f9cc5158c33ce50a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ee68554d2c03e32077f7b984e5289fdb005036d2" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-08T18:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-x9pj-5qm2-7p6v/GHSA-x9pj-5qm2-7p6v.json b/advisories/unreviewed/2025/01/GHSA-x9pj-5qm2-7p6v/GHSA-x9pj-5qm2-7p6v.json new file mode 100644 index 00000000000..ed61be75255 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-x9pj-5qm2-7p6v/GHSA-x9pj-5qm2-7p6v.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x9pj-5qm2-7p6v", + "modified": "2025-01-08T18:30:49Z", + "published": "2025-01-08T18:30:49Z", + "aliases": [ + "CVE-2024-56778" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/sti: avoid potential dereference of error pointers in sti_hqvdp_atomic_check\n\nThe return value of drm_atomic_get_crtc_state() needs to be\nchecked. To avoid use of error pointer 'crtc_state' in case\nof the failure.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56778" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/31c857e7496d34e5a32a6f75bc024d0b06fd646a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6b0d0d6e9d3c26697230bf7dc9e6b52bdb24086f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/82a5312f874fb18f045d9658e9bd290e3b0621c0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/837eb99ad3340c7a9febf454f41c8e3edb68ac1e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c1ab40a1fdfee732c7e6ff2fb8253760293e47e8" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-08T18:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-xwpw-pxrm-39pm/GHSA-xwpw-pxrm-39pm.json b/advisories/unreviewed/2025/01/GHSA-xwpw-pxrm-39pm/GHSA-xwpw-pxrm-39pm.json index c3eb36fd90b..30a1d5d8293 100644 --- a/advisories/unreviewed/2025/01/GHSA-xwpw-pxrm-39pm/GHSA-xwpw-pxrm-39pm.json +++ b/advisories/unreviewed/2025/01/GHSA-xwpw-pxrm-39pm/GHSA-xwpw-pxrm-39pm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xwpw-pxrm-39pm", - "modified": "2025-01-07T18:30:50Z", + "modified": "2025-01-08T18:30:48Z", "published": "2025-01-07T18:30:50Z", "aliases": [ "CVE-2025-0246" ], "details": "When using an invalid protocol scheme, an attacker could spoof the address bar. \n*Note: This issue only affected Android operating systems. Other operating systems are unaffected.*\n*Note: This issue is a different issue from CVE-2025-0244. This vulnerability affects Firefox < 134.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -25,7 +30,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-07T16:15:39Z"