diff --git a/advisories/unreviewed/2022/05/GHSA-8xqh-j9rj-w265/GHSA-8xqh-j9rj-w265.json b/advisories/unreviewed/2022/05/GHSA-8xqh-j9rj-w265/GHSA-8xqh-j9rj-w265.json index a262af4a744..5d04c32fb75 100644 --- a/advisories/unreviewed/2022/05/GHSA-8xqh-j9rj-w265/GHSA-8xqh-j9rj-w265.json +++ b/advisories/unreviewed/2022/05/GHSA-8xqh-j9rj-w265/GHSA-8xqh-j9rj-w265.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8xqh-j9rj-w265", - "modified": "2025-04-20T03:40:37Z", + "modified": "2025-05-01T15:31:26Z", "published": "2022-05-14T01:50:42Z", "aliases": [ "CVE-2017-9844" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://erpscan.io/advisories/erpscan-17-014-sap-netweaver-java-deserialization-untrusted-user-value-metadatauploader" }, + { + "type": "WEB", + "url": "https://me.sap.com/notes/2399804" + }, { "type": "WEB", "url": "http://www.securityfocus.com/bid/96865" diff --git a/advisories/unreviewed/2022/11/GHSA-2mp6-9mjc-p6jg/GHSA-2mp6-9mjc-p6jg.json b/advisories/unreviewed/2022/11/GHSA-2mp6-9mjc-p6jg/GHSA-2mp6-9mjc-p6jg.json index 7eb7b5b07f2..96321737e52 100644 --- a/advisories/unreviewed/2022/11/GHSA-2mp6-9mjc-p6jg/GHSA-2mp6-9mjc-p6jg.json +++ b/advisories/unreviewed/2022/11/GHSA-2mp6-9mjc-p6jg/GHSA-2mp6-9mjc-p6jg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2mp6-9mjc-p6jg", - "modified": "2022-11-10T12:01:17Z", + "modified": "2025-05-01T15:31:28Z", "published": "2022-11-09T12:00:19Z", "aliases": [ "CVE-2022-45061" @@ -27,6 +27,66 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ORVCQGJCCAVLN4DJDTWGREFCUWXKQRML" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/O67LRHDTJWH544KXB6KY4HMHQLYDXFPK" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LKWAMPURWUV3DCCT4J7VHRF4NT2CFVBR" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KNE4GMD45RGC2HWUAAIGTDHT5VJ2E4O4" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JTYVESWVBPD57ZJC35G5722Q6TS37WSB" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JCDJXNBHWXNYUTOEV4H2HCFSRKV3SYL3" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IN26PWZTYG6IF3APLRXQJBVACQHZUPT2" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GTPVDZDATRQFE6KAT6B4BQIQ4GRHIIIJ" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BWJREJHWVRBYDP43YB5WRL3QC7UBA7BR" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/B4MYQ3IV6NWA4CKSXEHW45CH2YNDHEPH" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/B3YI6JYARWU6GULWOHNUROSACT54XFFS" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7WQPHKGNXUJC3TC3BDW5RKGROWRJVSFR" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/63FS6VHY4DCS74HBTEINUDOECQ2X6ZCH" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4WBZJNSALFGMPYTINIF57HAAK46U72WQ" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/35YDIWCUMWTMDBWFRAVENFH6BLB65D6S" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PLQ2BNZVBBAQPV3SPRU24ZD37UYJJS7W" @@ -87,73 +147,129 @@ "type": "WEB", "url": "https://security.netapp.com/advisory/ntap-20221209-0007" }, - { - "type": "WEB", - "url": "https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html" - }, { "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2023/06/msg00039.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2AOUKI72ACV6CHY2QUFO6VK2DNMVJ2MB" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/35YDIWCUMWTMDBWFRAVENFH6BLB65D6S" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4WBZJNSALFGMPYTINIF57HAAK46U72WQ" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/63FS6VHY4DCS74HBTEINUDOECQ2X6ZCH" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7WQPHKGNXUJC3TC3BDW5RKGROWRJVSFR" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/B3YI6JYARWU6GULWOHNUROSACT54XFFS" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/B4MYQ3IV6NWA4CKSXEHW45CH2YNDHEPH" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BWJREJHWVRBYDP43YB5WRL3QC7UBA7BR" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GTPVDZDATRQFE6KAT6B4BQIQ4GRHIIIJ" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IN26PWZTYG6IF3APLRXQJBVACQHZUPT2" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JCDJXNBHWXNYUTOEV4H2HCFSRKV3SYL3" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JTYVESWVBPD57ZJC35G5722Q6TS37WSB" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KNE4GMD45RGC2HWUAAIGTDHT5VJ2E4O4" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LKWAMPURWUV3DCCT4J7VHRF4NT2CFVBR" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/O67LRHDTJWH544KXB6KY4HMHQLYDXFPK" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ORVCQGJCCAVLN4DJDTWGREFCUWXKQRML" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PLQ2BNZVBBAQPV3SPRU24ZD37UYJJS7W" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QCKD4AFBHXIMHS64ZER2U7QRT33HNE7L" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QLUGZSEAO3MBWGKCUSMKQIRYJZKJCIOB" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RDK3ZZBRYFO47ET3N4BNTKVXN47U6ICY" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RH57BNT4VQERGEJ5SXNXSVMDYP66YD4H" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RTN2OOLKYTG34DODUEJGT5MLC2PFGPBA" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T3D5TX4TDJPXHXD2QICKTY3OCQC3JARP" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UHVW73QZJMHA4MK7JBT7CXX7XSNYQEGF" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VCMDX6IFKLOA3NXUQEV524L5LHTPI2JI" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X3EJ6J7PXVQOULBQZQGBXCXY6LFF6LZD" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XXZJL3CNAFS5PAIR7K4RL62S3Y7THR7O" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YPNWZKXPKTNHS5FVMN7UQZ2UPCSEFJUK" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZB5YCMIRVX35RUB6XPOWKENCVCJEVDRK" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2AOUKI72ACV6CHY2QUFO6VK2DNMVJ2MB" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/35YDIWCUMWTMDBWFRAVENFH6BLB65D6S" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4WBZJNSALFGMPYTINIF57HAAK46U72WQ" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/63FS6VHY4DCS74HBTEINUDOECQ2X6ZCH" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7WQPHKGNXUJC3TC3BDW5RKGROWRJVSFR" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/B3YI6JYARWU6GULWOHNUROSACT54XFFS" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/B4MYQ3IV6NWA4CKSXEHW45CH2YNDHEPH" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BWJREJHWVRBYDP43YB5WRL3QC7UBA7BR" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GTPVDZDATRQFE6KAT6B4BQIQ4GRHIIIJ" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IN26PWZTYG6IF3APLRXQJBVACQHZUPT2" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JCDJXNBHWXNYUTOEV4H2HCFSRKV3SYL3" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JTYVESWVBPD57ZJC35G5722Q6TS37WSB" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KNE4GMD45RGC2HWUAAIGTDHT5VJ2E4O4" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LKWAMPURWUV3DCCT4J7VHRF4NT2CFVBR" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/O67LRHDTJWH544KXB6KY4HMHQLYDXFPK" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/11/GHSA-3q5h-7hjh-52j2/GHSA-3q5h-7hjh-52j2.json b/advisories/unreviewed/2022/11/GHSA-3q5h-7hjh-52j2/GHSA-3q5h-7hjh-52j2.json index 8b8a01c9f3e..a1b3ca01856 100644 --- a/advisories/unreviewed/2022/11/GHSA-3q5h-7hjh-52j2/GHSA-3q5h-7hjh-52j2.json +++ b/advisories/unreviewed/2022/11/GHSA-3q5h-7hjh-52j2/GHSA-3q5h-7hjh-52j2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3q5h-7hjh-52j2", - "modified": "2022-11-15T12:00:21Z", + "modified": "2025-05-01T15:31:30Z", "published": "2022-11-10T12:01:16Z", "aliases": [ "CVE-2022-44557" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-276" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-4275-m544-m6p7/GHSA-4275-m544-m6p7.json b/advisories/unreviewed/2022/11/GHSA-4275-m544-m6p7/GHSA-4275-m544-m6p7.json index fce110d3078..f8b771709a5 100644 --- a/advisories/unreviewed/2022/11/GHSA-4275-m544-m6p7/GHSA-4275-m544-m6p7.json +++ b/advisories/unreviewed/2022/11/GHSA-4275-m544-m6p7/GHSA-4275-m544-m6p7.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-4q54-qw95-qm44/GHSA-4q54-qw95-qm44.json b/advisories/unreviewed/2022/11/GHSA-4q54-qw95-qm44/GHSA-4q54-qw95-qm44.json index 2bf6a4e487e..9079b9487a9 100644 --- a/advisories/unreviewed/2022/11/GHSA-4q54-qw95-qm44/GHSA-4q54-qw95-qm44.json +++ b/advisories/unreviewed/2022/11/GHSA-4q54-qw95-qm44/GHSA-4q54-qw95-qm44.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-94" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-4r92-2gjg-4mqw/GHSA-4r92-2gjg-4mqw.json b/advisories/unreviewed/2022/11/GHSA-4r92-2gjg-4mqw/GHSA-4r92-2gjg-4mqw.json index b1179da6569..2c9ef19bed8 100644 --- a/advisories/unreviewed/2022/11/GHSA-4r92-2gjg-4mqw/GHSA-4r92-2gjg-4mqw.json +++ b/advisories/unreviewed/2022/11/GHSA-4r92-2gjg-4mqw/GHSA-4r92-2gjg-4mqw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4r92-2gjg-4mqw", - "modified": "2022-11-10T19:01:10Z", + "modified": "2025-05-01T15:31:30Z", "published": "2022-11-10T12:01:16Z", "aliases": [ "CVE-2022-44563" diff --git a/advisories/unreviewed/2022/11/GHSA-534h-8p2m-59rg/GHSA-534h-8p2m-59rg.json b/advisories/unreviewed/2022/11/GHSA-534h-8p2m-59rg/GHSA-534h-8p2m-59rg.json index 9b65d41a50d..3f273654473 100644 --- a/advisories/unreviewed/2022/11/GHSA-534h-8p2m-59rg/GHSA-534h-8p2m-59rg.json +++ b/advisories/unreviewed/2022/11/GHSA-534h-8p2m-59rg/GHSA-534h-8p2m-59rg.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-269" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-5684-vxhc-x77c/GHSA-5684-vxhc-x77c.json b/advisories/unreviewed/2022/11/GHSA-5684-vxhc-x77c/GHSA-5684-vxhc-x77c.json index 3c0e97313cf..6ca2385759f 100644 --- a/advisories/unreviewed/2022/11/GHSA-5684-vxhc-x77c/GHSA-5684-vxhc-x77c.json +++ b/advisories/unreviewed/2022/11/GHSA-5684-vxhc-x77c/GHSA-5684-vxhc-x77c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5684-vxhc-x77c", - "modified": "2022-11-10T12:01:17Z", + "modified": "2025-05-01T15:31:27Z", "published": "2022-11-09T12:00:19Z", "aliases": [ "CVE-2022-45062" @@ -35,6 +35,10 @@ "type": "WEB", "url": "https://gitlab.xfce.org/xfce/xfce4-settings/-/tags" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XGTGTTPFHDUB3EZHVKDK4H32QUUYPPFF" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XGTGTTPFHDUB3EZHVKDK4H32QUUYPPFF" diff --git a/advisories/unreviewed/2022/11/GHSA-57w2-43hc-hjm2/GHSA-57w2-43hc-hjm2.json b/advisories/unreviewed/2022/11/GHSA-57w2-43hc-hjm2/GHSA-57w2-43hc-hjm2.json index 0091979adc7..bbcd8d10487 100644 --- a/advisories/unreviewed/2022/11/GHSA-57w2-43hc-hjm2/GHSA-57w2-43hc-hjm2.json +++ b/advisories/unreviewed/2022/11/GHSA-57w2-43hc-hjm2/GHSA-57w2-43hc-hjm2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-57w2-43hc-hjm2", - "modified": "2022-11-15T12:00:20Z", + "modified": "2025-05-01T15:31:29Z", "published": "2022-11-10T12:01:16Z", "aliases": [ "CVE-2022-44552" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-404" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-57xm-4xq9-96rw/GHSA-57xm-4xq9-96rw.json b/advisories/unreviewed/2022/11/GHSA-57xm-4xq9-96rw/GHSA-57xm-4xq9-96rw.json index bef725afed1..8378d1f5e03 100644 --- a/advisories/unreviewed/2022/11/GHSA-57xm-4xq9-96rw/GHSA-57xm-4xq9-96rw.json +++ b/advisories/unreviewed/2022/11/GHSA-57xm-4xq9-96rw/GHSA-57xm-4xq9-96rw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-57xm-4xq9-96rw", - "modified": "2022-11-15T19:00:51Z", + "modified": "2025-05-01T15:31:30Z", "published": "2022-11-10T12:01:03Z", "aliases": [ "CVE-2022-45130" diff --git a/advisories/unreviewed/2022/11/GHSA-5qx3-w3fr-rpx2/GHSA-5qx3-w3fr-rpx2.json b/advisories/unreviewed/2022/11/GHSA-5qx3-w3fr-rpx2/GHSA-5qx3-w3fr-rpx2.json index 4777816afa5..14bb2a0457c 100644 --- a/advisories/unreviewed/2022/11/GHSA-5qx3-w3fr-rpx2/GHSA-5qx3-w3fr-rpx2.json +++ b/advisories/unreviewed/2022/11/GHSA-5qx3-w3fr-rpx2/GHSA-5qx3-w3fr-rpx2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5qx3-w3fr-rpx2", - "modified": "2022-11-15T12:00:19Z", + "modified": "2025-05-01T15:31:29Z", "published": "2022-11-10T12:01:16Z", "aliases": [ "CVE-2022-44551" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-362" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-6569-xvvw-c52h/GHSA-6569-xvvw-c52h.json b/advisories/unreviewed/2022/11/GHSA-6569-xvvw-c52h/GHSA-6569-xvvw-c52h.json index 03e1506bad0..04309dc522e 100644 --- a/advisories/unreviewed/2022/11/GHSA-6569-xvvw-c52h/GHSA-6569-xvvw-c52h.json +++ b/advisories/unreviewed/2022/11/GHSA-6569-xvvw-c52h/GHSA-6569-xvvw-c52h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6569-xvvw-c52h", - "modified": "2022-11-15T12:00:20Z", + "modified": "2025-05-01T15:31:29Z", "published": "2022-11-10T12:01:16Z", "aliases": [ "CVE-2022-44553" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-20" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-6578-54qh-w6g3/GHSA-6578-54qh-w6g3.json b/advisories/unreviewed/2022/11/GHSA-6578-54qh-w6g3/GHSA-6578-54qh-w6g3.json index f85647aba99..ef69012e2a6 100644 --- a/advisories/unreviewed/2022/11/GHSA-6578-54qh-w6g3/GHSA-6578-54qh-w6g3.json +++ b/advisories/unreviewed/2022/11/GHSA-6578-54qh-w6g3/GHSA-6578-54qh-w6g3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6578-54qh-w6g3", - "modified": "2023-01-26T21:30:24Z", + "modified": "2025-05-01T15:31:31Z", "published": "2022-11-14T12:00:15Z", "aliases": [ "CVE-2022-37290" @@ -31,6 +31,14 @@ "type": "WEB", "url": "https://gitlab.gnome.org/GNOME/nautilus/-/tree/master" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PX5CVF4FAHFA6UNKHFBBLOP2NUMIQJAY" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XYPDZ7LBBUVU3WFK7DCGDFGK2GXTKGT5" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PX5CVF4FAHFA6UNKHFBBLOP2NUMIQJAY" diff --git a/advisories/unreviewed/2022/11/GHSA-6xvj-x5f6-3fg6/GHSA-6xvj-x5f6-3fg6.json b/advisories/unreviewed/2022/11/GHSA-6xvj-x5f6-3fg6/GHSA-6xvj-x5f6-3fg6.json index 663d7311904..e6e87a33582 100644 --- a/advisories/unreviewed/2022/11/GHSA-6xvj-x5f6-3fg6/GHSA-6xvj-x5f6-3fg6.json +++ b/advisories/unreviewed/2022/11/GHSA-6xvj-x5f6-3fg6/GHSA-6xvj-x5f6-3fg6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6xvj-x5f6-3fg6", - "modified": "2022-11-10T19:01:10Z", + "modified": "2025-05-01T15:31:29Z", "published": "2022-11-10T12:01:16Z", "aliases": [ "CVE-2022-44548" diff --git a/advisories/unreviewed/2022/11/GHSA-7498-cq96-62m6/GHSA-7498-cq96-62m6.json b/advisories/unreviewed/2022/11/GHSA-7498-cq96-62m6/GHSA-7498-cq96-62m6.json index 0895db347a2..1dbf7d2ed1b 100644 --- a/advisories/unreviewed/2022/11/GHSA-7498-cq96-62m6/GHSA-7498-cq96-62m6.json +++ b/advisories/unreviewed/2022/11/GHSA-7498-cq96-62m6/GHSA-7498-cq96-62m6.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-94" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-78x9-jhxm-553x/GHSA-78x9-jhxm-553x.json b/advisories/unreviewed/2022/11/GHSA-78x9-jhxm-553x/GHSA-78x9-jhxm-553x.json index 55c3c487bef..46efb226a47 100644 --- a/advisories/unreviewed/2022/11/GHSA-78x9-jhxm-553x/GHSA-78x9-jhxm-553x.json +++ b/advisories/unreviewed/2022/11/GHSA-78x9-jhxm-553x/GHSA-78x9-jhxm-553x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-78x9-jhxm-553x", - "modified": "2022-11-10T12:01:17Z", + "modified": "2025-05-01T15:31:27Z", "published": "2022-11-09T12:00:19Z", "aliases": [ "CVE-2022-45060" @@ -27,6 +27,18 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2022/11/msg00036.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/G6ZMOZVBLZXHEV5VRW4I4SOWLQEK5OF5" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M4KVVCIQVINQQ2D7ORNARSYALMJUMP3I" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XGF6LFTHXCSYMYUX5HLMVXQH3WHCSFLU" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/G6ZMOZVBLZXHEV5VRW4I4SOWLQEK5OF5" @@ -49,7 +61,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-20" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-7rw9-fmjv-626x/GHSA-7rw9-fmjv-626x.json b/advisories/unreviewed/2022/11/GHSA-7rw9-fmjv-626x/GHSA-7rw9-fmjv-626x.json index b7b3922ad25..afbb5f26895 100644 --- a/advisories/unreviewed/2022/11/GHSA-7rw9-fmjv-626x/GHSA-7rw9-fmjv-626x.json +++ b/advisories/unreviewed/2022/11/GHSA-7rw9-fmjv-626x/GHSA-7rw9-fmjv-626x.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-94" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-7xw3-w6q8-q6wg/GHSA-7xw3-w6q8-q6wg.json b/advisories/unreviewed/2022/11/GHSA-7xw3-w6q8-q6wg/GHSA-7xw3-w6q8-q6wg.json index 6d799e0c209..32d897cdfbf 100644 --- a/advisories/unreviewed/2022/11/GHSA-7xw3-w6q8-q6wg/GHSA-7xw3-w6q8-q6wg.json +++ b/advisories/unreviewed/2022/11/GHSA-7xw3-w6q8-q6wg/GHSA-7xw3-w6q8-q6wg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7xw3-w6q8-q6wg", - "modified": "2022-11-15T12:00:21Z", + "modified": "2025-05-01T15:31:30Z", "published": "2022-11-10T12:01:16Z", "aliases": [ "CVE-2022-44559" diff --git a/advisories/unreviewed/2022/11/GHSA-83w2-v7jh-w547/GHSA-83w2-v7jh-w547.json b/advisories/unreviewed/2022/11/GHSA-83w2-v7jh-w547/GHSA-83w2-v7jh-w547.json index b8dabdf85b5..c62ce5c8dbe 100644 --- a/advisories/unreviewed/2022/11/GHSA-83w2-v7jh-w547/GHSA-83w2-v7jh-w547.json +++ b/advisories/unreviewed/2022/11/GHSA-83w2-v7jh-w547/GHSA-83w2-v7jh-w547.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-83w2-v7jh-w547", - "modified": "2022-11-15T12:00:21Z", + "modified": "2025-05-01T15:31:30Z", "published": "2022-11-10T12:01:16Z", "aliases": [ "CVE-2022-44558" diff --git a/advisories/unreviewed/2022/11/GHSA-9545-r5rj-jc95/GHSA-9545-r5rj-jc95.json b/advisories/unreviewed/2022/11/GHSA-9545-r5rj-jc95/GHSA-9545-r5rj-jc95.json index ddac4059a60..4e973185e89 100644 --- a/advisories/unreviewed/2022/11/GHSA-9545-r5rj-jc95/GHSA-9545-r5rj-jc95.json +++ b/advisories/unreviewed/2022/11/GHSA-9545-r5rj-jc95/GHSA-9545-r5rj-jc95.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9545-r5rj-jc95", - "modified": "2022-11-16T12:00:24Z", + "modified": "2025-05-01T15:31:31Z", "published": "2022-11-11T12:00:28Z", "aliases": [ "CVE-2022-26088" diff --git a/advisories/unreviewed/2022/11/GHSA-c8rr-vr4h-5x87/GHSA-c8rr-vr4h-5x87.json b/advisories/unreviewed/2022/11/GHSA-c8rr-vr4h-5x87/GHSA-c8rr-vr4h-5x87.json index 8b12814a20d..a6bdc7b497c 100644 --- a/advisories/unreviewed/2022/11/GHSA-c8rr-vr4h-5x87/GHSA-c8rr-vr4h-5x87.json +++ b/advisories/unreviewed/2022/11/GHSA-c8rr-vr4h-5x87/GHSA-c8rr-vr4h-5x87.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c8rr-vr4h-5x87", - "modified": "2022-11-17T15:30:23Z", + "modified": "2025-05-01T15:31:31Z", "published": "2022-11-15T12:00:17Z", "aliases": [ "CVE-2022-43146" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43146" }, + { + "type": "WEB", + "url": "https://medium.com/%40syedmudassiruddinalvi/cve-2022-43146-rce-via-arbitrary-file-upload-28dfa77c5de7" + }, { "type": "WEB", "url": "https://medium.com/@syedmudassiruddinalvi/cve-2022-43146-rce-via-arbitrary-file-upload-28dfa77c5de7" diff --git a/advisories/unreviewed/2022/11/GHSA-cf9w-6prv-pr7r/GHSA-cf9w-6prv-pr7r.json b/advisories/unreviewed/2022/11/GHSA-cf9w-6prv-pr7r/GHSA-cf9w-6prv-pr7r.json index e847c60f331..37a19cd7e7e 100644 --- a/advisories/unreviewed/2022/11/GHSA-cf9w-6prv-pr7r/GHSA-cf9w-6prv-pr7r.json +++ b/advisories/unreviewed/2022/11/GHSA-cf9w-6prv-pr7r/GHSA-cf9w-6prv-pr7r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cf9w-6prv-pr7r", - "modified": "2022-11-16T19:00:25Z", + "modified": "2025-05-01T15:31:31Z", "published": "2022-11-12T12:00:29Z", "aliases": [ "CVE-2022-45194" diff --git a/advisories/unreviewed/2022/11/GHSA-cm49-fh74-75ch/GHSA-cm49-fh74-75ch.json b/advisories/unreviewed/2022/11/GHSA-cm49-fh74-75ch/GHSA-cm49-fh74-75ch.json index e45126be456..6f1c51e7272 100644 --- a/advisories/unreviewed/2022/11/GHSA-cm49-fh74-75ch/GHSA-cm49-fh74-75ch.json +++ b/advisories/unreviewed/2022/11/GHSA-cm49-fh74-75ch/GHSA-cm49-fh74-75ch.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-347" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-f2wh-crm6-349c/GHSA-f2wh-crm6-349c.json b/advisories/unreviewed/2022/11/GHSA-f2wh-crm6-349c/GHSA-f2wh-crm6-349c.json index 99c62448425..2cf38cf7f8e 100644 --- a/advisories/unreviewed/2022/11/GHSA-f2wh-crm6-349c/GHSA-f2wh-crm6-349c.json +++ b/advisories/unreviewed/2022/11/GHSA-f2wh-crm6-349c/GHSA-f2wh-crm6-349c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f2wh-crm6-349c", - "modified": "2022-11-11T12:00:35Z", + "modified": "2025-05-01T15:31:29Z", "published": "2022-11-10T12:01:16Z", "aliases": [ "CVE-2022-44549" @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-668" + "CWE-668", + "CWE-862" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/11/GHSA-fqxf-7mq3-hv59/GHSA-fqxf-7mq3-hv59.json b/advisories/unreviewed/2022/11/GHSA-fqxf-7mq3-hv59/GHSA-fqxf-7mq3-hv59.json index e9aa199c2d1..4186c585221 100644 --- a/advisories/unreviewed/2022/11/GHSA-fqxf-7mq3-hv59/GHSA-fqxf-7mq3-hv59.json +++ b/advisories/unreviewed/2022/11/GHSA-fqxf-7mq3-hv59/GHSA-fqxf-7mq3-hv59.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-20" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-frv7-33r5-fg4g/GHSA-frv7-33r5-fg4g.json b/advisories/unreviewed/2022/11/GHSA-frv7-33r5-fg4g/GHSA-frv7-33r5-fg4g.json index f0a0f7b8e3e..c72998a6b2e 100644 --- a/advisories/unreviewed/2022/11/GHSA-frv7-33r5-fg4g/GHSA-frv7-33r5-fg4g.json +++ b/advisories/unreviewed/2022/11/GHSA-frv7-33r5-fg4g/GHSA-frv7-33r5-fg4g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-frv7-33r5-fg4g", - "modified": "2022-11-17T21:30:51Z", + "modified": "2025-05-01T15:31:31Z", "published": "2022-11-15T12:00:17Z", "aliases": [ "CVE-2022-38167" diff --git a/advisories/unreviewed/2022/11/GHSA-ggxh-673w-p257/GHSA-ggxh-673w-p257.json b/advisories/unreviewed/2022/11/GHSA-ggxh-673w-p257/GHSA-ggxh-673w-p257.json index 8f23115bea7..ab639bde22f 100644 --- a/advisories/unreviewed/2022/11/GHSA-ggxh-673w-p257/GHSA-ggxh-673w-p257.json +++ b/advisories/unreviewed/2022/11/GHSA-ggxh-673w-p257/GHSA-ggxh-673w-p257.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ggxh-673w-p257", - "modified": "2022-11-16T12:00:25Z", + "modified": "2025-05-01T15:31:31Z", "published": "2022-11-10T19:01:06Z", "aliases": [ "CVE-2022-44727" diff --git a/advisories/unreviewed/2022/11/GHSA-j6r3-f3gp-mvmr/GHSA-j6r3-f3gp-mvmr.json b/advisories/unreviewed/2022/11/GHSA-j6r3-f3gp-mvmr/GHSA-j6r3-f3gp-mvmr.json index 6afe3bfa006..7d2e7fa018e 100644 --- a/advisories/unreviewed/2022/11/GHSA-j6r3-f3gp-mvmr/GHSA-j6r3-f3gp-mvmr.json +++ b/advisories/unreviewed/2022/11/GHSA-j6r3-f3gp-mvmr/GHSA-j6r3-f3gp-mvmr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j6r3-f3gp-mvmr", - "modified": "2022-11-18T00:30:19Z", + "modified": "2025-05-01T15:31:30Z", "published": "2022-11-10T12:01:16Z", "aliases": [ "CVE-2022-44561" diff --git a/advisories/unreviewed/2022/11/GHSA-jm9q-fgcx-m964/GHSA-jm9q-fgcx-m964.json b/advisories/unreviewed/2022/11/GHSA-jm9q-fgcx-m964/GHSA-jm9q-fgcx-m964.json index fa04cb1eaca..097b847ece0 100644 --- a/advisories/unreviewed/2022/11/GHSA-jm9q-fgcx-m964/GHSA-jm9q-fgcx-m964.json +++ b/advisories/unreviewed/2022/11/GHSA-jm9q-fgcx-m964/GHSA-jm9q-fgcx-m964.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-20" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-jmr9-5qpr-rmhc/GHSA-jmr9-5qpr-rmhc.json b/advisories/unreviewed/2022/11/GHSA-jmr9-5qpr-rmhc/GHSA-jmr9-5qpr-rmhc.json index 7121fdb31a8..8641bec044b 100644 --- a/advisories/unreviewed/2022/11/GHSA-jmr9-5qpr-rmhc/GHSA-jmr9-5qpr-rmhc.json +++ b/advisories/unreviewed/2022/11/GHSA-jmr9-5qpr-rmhc/GHSA-jmr9-5qpr-rmhc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jmr9-5qpr-rmhc", - "modified": "2022-11-11T12:00:38Z", + "modified": "2025-05-01T15:31:29Z", "published": "2022-11-10T12:01:16Z", "aliases": [ "CVE-2022-44550" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-416" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-mfq3-8xp6-5mj3/GHSA-mfq3-8xp6-5mj3.json b/advisories/unreviewed/2022/11/GHSA-mfq3-8xp6-5mj3/GHSA-mfq3-8xp6-5mj3.json index cb9bc2b16ed..1da613508c4 100644 --- a/advisories/unreviewed/2022/11/GHSA-mfq3-8xp6-5mj3/GHSA-mfq3-8xp6-5mj3.json +++ b/advisories/unreviewed/2022/11/GHSA-mfq3-8xp6-5mj3/GHSA-mfq3-8xp6-5mj3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mfq3-8xp6-5mj3", - "modified": "2022-11-16T19:00:26Z", + "modified": "2025-05-01T15:31:31Z", "published": "2022-11-12T12:00:29Z", "aliases": [ "CVE-2022-40773" @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-20", "CWE-863" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/11/GHSA-mrmc-wj93-w962/GHSA-mrmc-wj93-w962.json b/advisories/unreviewed/2022/11/GHSA-mrmc-wj93-w962/GHSA-mrmc-wj93-w962.json index ebb997413c7..d38ac9b191f 100644 --- a/advisories/unreviewed/2022/11/GHSA-mrmc-wj93-w962/GHSA-mrmc-wj93-w962.json +++ b/advisories/unreviewed/2022/11/GHSA-mrmc-wj93-w962/GHSA-mrmc-wj93-w962.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-p22x-6r5h-g873/GHSA-p22x-6r5h-g873.json b/advisories/unreviewed/2022/11/GHSA-p22x-6r5h-g873/GHSA-p22x-6r5h-g873.json index ee8c8394077..e6d2625d1d9 100644 --- a/advisories/unreviewed/2022/11/GHSA-p22x-6r5h-g873/GHSA-p22x-6r5h-g873.json +++ b/advisories/unreviewed/2022/11/GHSA-p22x-6r5h-g873/GHSA-p22x-6r5h-g873.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p22x-6r5h-g873", - "modified": "2022-11-10T12:01:17Z", + "modified": "2025-05-01T15:31:27Z", "published": "2022-11-09T12:00:19Z", "aliases": [ "CVE-2022-45059" @@ -19,6 +19,18 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45059" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/G6ZMOZVBLZXHEV5VRW4I4SOWLQEK5OF5" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M4KVVCIQVINQQ2D7ORNARSYALMJUMP3I" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XGF6LFTHXCSYMYUX5HLMVXQH3WHCSFLU" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/G6ZMOZVBLZXHEV5VRW4I4SOWLQEK5OF5" diff --git a/advisories/unreviewed/2022/11/GHSA-phjf-69j5-93r8/GHSA-phjf-69j5-93r8.json b/advisories/unreviewed/2022/11/GHSA-phjf-69j5-93r8/GHSA-phjf-69j5-93r8.json index a09d38def33..4bd694de332 100644 --- a/advisories/unreviewed/2022/11/GHSA-phjf-69j5-93r8/GHSA-phjf-69j5-93r8.json +++ b/advisories/unreviewed/2022/11/GHSA-phjf-69j5-93r8/GHSA-phjf-69j5-93r8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-phjf-69j5-93r8", - "modified": "2022-11-15T12:00:21Z", + "modified": "2025-05-01T15:31:29Z", "published": "2022-11-10T12:01:16Z", "aliases": [ "CVE-2022-44555" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-294" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-r758-9895-gf62/GHSA-r758-9895-gf62.json b/advisories/unreviewed/2022/11/GHSA-r758-9895-gf62/GHSA-r758-9895-gf62.json index 5d817a2aecc..87a63e39b0b 100644 --- a/advisories/unreviewed/2022/11/GHSA-r758-9895-gf62/GHSA-r758-9895-gf62.json +++ b/advisories/unreviewed/2022/11/GHSA-r758-9895-gf62/GHSA-r758-9895-gf62.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r758-9895-gf62", - "modified": "2022-11-17T15:30:21Z", + "modified": "2025-05-01T15:31:30Z", "published": "2022-11-10T12:01:16Z", "aliases": [ "CVE-2022-44560" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-601" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-vhxx-j997-pw24/GHSA-vhxx-j997-pw24.json b/advisories/unreviewed/2022/11/GHSA-vhxx-j997-pw24/GHSA-vhxx-j997-pw24.json index a5f21692454..fcb704fec60 100644 --- a/advisories/unreviewed/2022/11/GHSA-vhxx-j997-pw24/GHSA-vhxx-j997-pw24.json +++ b/advisories/unreviewed/2022/11/GHSA-vhxx-j997-pw24/GHSA-vhxx-j997-pw24.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vhxx-j997-pw24", - "modified": "2022-11-15T12:00:20Z", + "modified": "2025-05-01T15:31:29Z", "published": "2022-11-10T12:01:16Z", "aliases": [ "CVE-2022-44554" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-276" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-vmcm-fv4m-prc7/GHSA-vmcm-fv4m-prc7.json b/advisories/unreviewed/2022/11/GHSA-vmcm-fv4m-prc7/GHSA-vmcm-fv4m-prc7.json index 8a7d33c3eda..70c6f824acb 100644 --- a/advisories/unreviewed/2022/11/GHSA-vmcm-fv4m-prc7/GHSA-vmcm-fv4m-prc7.json +++ b/advisories/unreviewed/2022/11/GHSA-vmcm-fv4m-prc7/GHSA-vmcm-fv4m-prc7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vmcm-fv4m-prc7", - "modified": "2022-11-11T12:00:38Z", + "modified": "2025-05-01T15:31:30Z", "published": "2022-11-10T12:01:16Z", "aliases": [ "CVE-2022-44562" @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-269" + "CWE-269", + "CWE-502" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/11/GHSA-wj56-g2wq-p3pw/GHSA-wj56-g2wq-p3pw.json b/advisories/unreviewed/2022/11/GHSA-wj56-g2wq-p3pw/GHSA-wj56-g2wq-p3pw.json index c049ac13ee5..2aed004d37c 100644 --- a/advisories/unreviewed/2022/11/GHSA-wj56-g2wq-p3pw/GHSA-wj56-g2wq-p3pw.json +++ b/advisories/unreviewed/2022/11/GHSA-wj56-g2wq-p3pw/GHSA-wj56-g2wq-p3pw.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-xxfg-pm66-vc8j/GHSA-xxfg-pm66-vc8j.json b/advisories/unreviewed/2022/11/GHSA-xxfg-pm66-vc8j/GHSA-xxfg-pm66-vc8j.json index ec92feb1b9f..bc45a057c34 100644 --- a/advisories/unreviewed/2022/11/GHSA-xxfg-pm66-vc8j/GHSA-xxfg-pm66-vc8j.json +++ b/advisories/unreviewed/2022/11/GHSA-xxfg-pm66-vc8j/GHSA-xxfg-pm66-vc8j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xxfg-pm66-vc8j", - "modified": "2022-11-16T19:00:25Z", + "modified": "2025-05-01T15:31:31Z", "published": "2022-11-12T12:00:29Z", "aliases": [ "CVE-2022-45182" @@ -41,7 +41,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-233" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-v8h9-wj87-q8vr/GHSA-v8h9-wj87-q8vr.json b/advisories/unreviewed/2022/12/GHSA-v8h9-wj87-q8vr/GHSA-v8h9-wj87-q8vr.json index 60115302cac..a0856dc9842 100644 --- a/advisories/unreviewed/2022/12/GHSA-v8h9-wj87-q8vr/GHSA-v8h9-wj87-q8vr.json +++ b/advisories/unreviewed/2022/12/GHSA-v8h9-wj87-q8vr/GHSA-v8h9-wj87-q8vr.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/02/GHSA-4348-46gx-472v/GHSA-4348-46gx-472v.json b/advisories/unreviewed/2023/02/GHSA-4348-46gx-472v/GHSA-4348-46gx-472v.json index 4f80d236de7..393e37d9b47 100644 --- a/advisories/unreviewed/2023/02/GHSA-4348-46gx-472v/GHSA-4348-46gx-472v.json +++ b/advisories/unreviewed/2023/02/GHSA-4348-46gx-472v/GHSA-4348-46gx-472v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4348-46gx-472v", - "modified": "2023-02-22T18:30:33Z", + "modified": "2025-05-01T15:31:32Z", "published": "2023-02-14T18:30:21Z", "aliases": [ "CVE-2023-0830" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], @@ -23,6 +27,10 @@ "type": "WEB", "url": "https://gist.github.com/xbz0n/674af0e802efaaafe90d2f67464c2690" }, + { + "type": "WEB", + "url": "https://github.com/xbz0n/CVE-2023-0830" + }, { "type": "WEB", "url": "https://vuldb.com/?ctiid.220950" @@ -30,10 +38,19 @@ { "type": "WEB", "url": "https://vuldb.com/?id.220950" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.86683" + }, + { + "type": "WEB", + "url": "https://www.exploit-db.com/exploits/51266" } ], "database_specific": { "cwe_ids": [ + "CWE-77", "CWE-78" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/07/GHSA-5v6h-fqxx-8wv5/GHSA-5v6h-fqxx-8wv5.json b/advisories/unreviewed/2023/07/GHSA-5v6h-fqxx-8wv5/GHSA-5v6h-fqxx-8wv5.json index 0d7bdba2e55..240984343e3 100644 --- a/advisories/unreviewed/2023/07/GHSA-5v6h-fqxx-8wv5/GHSA-5v6h-fqxx-8wv5.json +++ b/advisories/unreviewed/2023/07/GHSA-5v6h-fqxx-8wv5/GHSA-5v6h-fqxx-8wv5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5v6h-fqxx-8wv5", - "modified": "2024-04-04T05:30:14Z", + "modified": "2025-05-01T15:31:28Z", "published": "2023-07-06T19:24:03Z", "aliases": [ "CVE-2021-26360" @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-284", "CWE-863" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/07/GHSA-vrr6-jm4r-hqvp/GHSA-vrr6-jm4r-hqvp.json b/advisories/unreviewed/2023/07/GHSA-vrr6-jm4r-hqvp/GHSA-vrr6-jm4r-hqvp.json index ededa72018e..62edcd6c98f 100644 --- a/advisories/unreviewed/2023/07/GHSA-vrr6-jm4r-hqvp/GHSA-vrr6-jm4r-hqvp.json +++ b/advisories/unreviewed/2023/07/GHSA-vrr6-jm4r-hqvp/GHSA-vrr6-jm4r-hqvp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vrr6-jm4r-hqvp", - "modified": "2024-04-04T05:30:17Z", + "modified": "2025-05-01T15:31:31Z", "published": "2023-07-06T19:24:04Z", "aliases": [ "CVE-2022-3238" diff --git a/advisories/unreviewed/2024/02/GHSA-28qc-v7xx-3vpf/GHSA-28qc-v7xx-3vpf.json b/advisories/unreviewed/2024/02/GHSA-28qc-v7xx-3vpf/GHSA-28qc-v7xx-3vpf.json index 7d18b0ab123..872691efc8e 100644 --- a/advisories/unreviewed/2024/02/GHSA-28qc-v7xx-3vpf/GHSA-28qc-v7xx-3vpf.json +++ b/advisories/unreviewed/2024/02/GHSA-28qc-v7xx-3vpf/GHSA-28qc-v7xx-3vpf.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-5cw4-8rvf-84w3/GHSA-5cw4-8rvf-84w3.json b/advisories/unreviewed/2024/02/GHSA-5cw4-8rvf-84w3/GHSA-5cw4-8rvf-84w3.json index ca24bb732bc..0cbe000e7ea 100644 --- a/advisories/unreviewed/2024/02/GHSA-5cw4-8rvf-84w3/GHSA-5cw4-8rvf-84w3.json +++ b/advisories/unreviewed/2024/02/GHSA-5cw4-8rvf-84w3/GHSA-5cw4-8rvf-84w3.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-8c5f-qpcm-fgcv/GHSA-8c5f-qpcm-fgcv.json b/advisories/unreviewed/2024/02/GHSA-8c5f-qpcm-fgcv/GHSA-8c5f-qpcm-fgcv.json index 73d82c6022d..035647422b8 100644 --- a/advisories/unreviewed/2024/02/GHSA-8c5f-qpcm-fgcv/GHSA-8c5f-qpcm-fgcv.json +++ b/advisories/unreviewed/2024/02/GHSA-8c5f-qpcm-fgcv/GHSA-8c5f-qpcm-fgcv.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-639" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-36p4-cjjg-rccj/GHSA-36p4-cjjg-rccj.json b/advisories/unreviewed/2024/04/GHSA-36p4-cjjg-rccj/GHSA-36p4-cjjg-rccj.json index f7afa8c7d37..39583ed7ed5 100644 --- a/advisories/unreviewed/2024/04/GHSA-36p4-cjjg-rccj/GHSA-36p4-cjjg-rccj.json +++ b/advisories/unreviewed/2024/04/GHSA-36p4-cjjg-rccj/GHSA-36p4-cjjg-rccj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-36p4-cjjg-rccj", - "modified": "2024-04-07T21:30:28Z", + "modified": "2025-05-01T15:31:34Z", "published": "2024-04-07T21:30:28Z", "aliases": [ "CVE-2024-31950" ], "details": "In FRRouting (FRR) through 9.1, there can be a buffer overflow and daemon crash in ospf_te_parse_ri for OSPF LSA packets during an attempt to read Segment Routing subTLVs (their size is not validated).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-07T21:15:07Z" diff --git a/advisories/unreviewed/2024/04/GHSA-f3q5-vrp5-crqj/GHSA-f3q5-vrp5-crqj.json b/advisories/unreviewed/2024/04/GHSA-f3q5-vrp5-crqj/GHSA-f3q5-vrp5-crqj.json index c3e16f81129..bc0e06250d6 100644 --- a/advisories/unreviewed/2024/04/GHSA-f3q5-vrp5-crqj/GHSA-f3q5-vrp5-crqj.json +++ b/advisories/unreviewed/2024/04/GHSA-f3q5-vrp5-crqj/GHSA-f3q5-vrp5-crqj.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-835" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-66mc-jppc-fm4m/GHSA-66mc-jppc-fm4m.json b/advisories/unreviewed/2025/04/GHSA-66mc-jppc-fm4m/GHSA-66mc-jppc-fm4m.json index 6457f66c2e5..e9a441238f2 100644 --- a/advisories/unreviewed/2025/04/GHSA-66mc-jppc-fm4m/GHSA-66mc-jppc-fm4m.json +++ b/advisories/unreviewed/2025/04/GHSA-66mc-jppc-fm4m/GHSA-66mc-jppc-fm4m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-66mc-jppc-fm4m", - "modified": "2025-04-30T21:31:49Z", + "modified": "2025-05-01T15:31:39Z", "published": "2025-04-30T21:31:49Z", "aliases": [ "CVE-2025-2170" ], "details": "A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface, which in specific conditions could potentially enable a remote unauthenticated attacker to cause the appliance to make requests to an unintended location.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -27,7 +32,7 @@ "cwe_ids": [ "CWE-918" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-30T19:15:55Z" diff --git a/advisories/unreviewed/2025/04/GHSA-jg9f-xcjm-xm8p/GHSA-jg9f-xcjm-xm8p.json b/advisories/unreviewed/2025/04/GHSA-jg9f-xcjm-xm8p/GHSA-jg9f-xcjm-xm8p.json index 2537f474d45..94a3ce7e494 100644 --- a/advisories/unreviewed/2025/04/GHSA-jg9f-xcjm-xm8p/GHSA-jg9f-xcjm-xm8p.json +++ b/advisories/unreviewed/2025/04/GHSA-jg9f-xcjm-xm8p/GHSA-jg9f-xcjm-xm8p.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jg9f-xcjm-xm8p", - "modified": "2025-04-30T21:31:50Z", + "modified": "2025-05-01T15:31:39Z", "published": "2025-04-30T21:31:50Z", "aliases": [ "CVE-2025-24132" ], "details": "The issue was addressed with improved memory handling. This issue is fixed in AirPlay audio SDK 2.7.1, AirPlay video SDK 3.6.0.126, CarPlay Communication Plug-in R18.1. An attacker on the local network may cause an unexpected app termination.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-30T21:15:54Z" diff --git a/advisories/unreviewed/2025/04/GHSA-xpg9-62c8-xpvc/GHSA-xpg9-62c8-xpvc.json b/advisories/unreviewed/2025/04/GHSA-xpg9-62c8-xpvc/GHSA-xpg9-62c8-xpvc.json index b6adff1806f..53622403fb2 100644 --- a/advisories/unreviewed/2025/04/GHSA-xpg9-62c8-xpvc/GHSA-xpg9-62c8-xpvc.json +++ b/advisories/unreviewed/2025/04/GHSA-xpg9-62c8-xpvc/GHSA-xpg9-62c8-xpvc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xpg9-62c8-xpvc", - "modified": "2025-04-30T21:31:50Z", + "modified": "2025-05-01T15:31:39Z", "published": "2025-04-30T21:31:50Z", "aliases": [ "CVE-2025-30422" ], "details": "A buffer overflow was addressed with improved input validation. This issue is fixed in AirPlay audio SDK 2.7.1, AirPlay video SDK 3.6.0.126, CarPlay Communication Plug-in R18.1. An attacker on the local network may cause an unexpected app termination.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-30T21:15:54Z" diff --git a/advisories/unreviewed/2025/05/GHSA-22ff-fvm7-6wj7/GHSA-22ff-fvm7-6wj7.json b/advisories/unreviewed/2025/05/GHSA-22ff-fvm7-6wj7/GHSA-22ff-fvm7-6wj7.json new file mode 100644 index 00000000000..7848dae37b6 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-22ff-fvm7-6wj7/GHSA-22ff-fvm7-6wj7.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-22ff-fvm7-6wj7", + "modified": "2025-05-01T15:31:46Z", + "published": "2025-05-01T15:31:45Z", + "aliases": [ + "CVE-2022-49769" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ngfs2: Check sb_bsize_shift after reading superblock\n\nFuzzers like to scribble over sb_bsize_shift but in reality it's very\nunlikely that this field would be corrupted on its own. Nevertheless it\nshould be checked to avoid the possibility of messy mount errors due to\nbad calculations. It's always a fixed value based on the block size so\nwe can just check that it's the expected value.\n\nTested with:\n\n mkfs.gfs2 -O -p lock_nolock /dev/vdb\n for i in 0 -1 64 65 32 33; do\n gfs2_edit -p sb field sb_bsize_shift $i /dev/vdb\n mount /dev/vdb /mnt/test && umount /mnt/test\n done\n\nBefore this patch we get a withdraw after\n\n[ 76.413681] gfs2: fsid=loop0.0: fatal: invalid metadata block\n[ 76.413681] bh = 19 (type: exp=5, found=4)\n[ 76.413681] function = gfs2_meta_buffer, file = fs/gfs2/meta_io.c, line = 492\n\nand with UBSAN configured we also get complaints like\n\n[ 76.373395] UBSAN: shift-out-of-bounds in fs/gfs2/ops_fstype.c:295:19\n[ 76.373815] shift exponent 4294967287 is too large for 64-bit type 'long unsigned int'\n\nAfter the patch, these complaints don't appear, mount fails immediately\nand we get an explanation in dmesg.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49769" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/15c83fa0fd659dd9fbdc940a560b61236e876a80" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/16670534c7cff1acd918a6a5ec751b14e7436b76" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1ad197097343568066a8ffaa27ee7d0ae6d9f476" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/28275a7c84d21c55ab3282d897f284d8d527173c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5fa30be7ba81191b0a0c7239a89befc0c94286d5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/670f8ce56dd0632dc29a0322e188cc73ce3c6b92" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8b6534c9ae9dba5489703a19d8ba6c8f2cfa33c2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d6b1e8ea6f3418c3b461ad5a35cdc93c996b2c87" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-23wh-q78v-xxm4/GHSA-23wh-q78v-xxm4.json b/advisories/unreviewed/2025/05/GHSA-23wh-q78v-xxm4/GHSA-23wh-q78v-xxm4.json new file mode 100644 index 00000000000..d86ce4f3ec3 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-23wh-q78v-xxm4/GHSA-23wh-q78v-xxm4.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-23wh-q78v-xxm4", + "modified": "2025-05-01T15:31:47Z", + "published": "2025-05-01T15:31:47Z", + "aliases": [ + "CVE-2022-49797" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: kprobe: Fix potential null-ptr-deref on trace_event_file in kprobe_event_gen_test_exit()\n\nWhen trace_get_event_file() failed, gen_kretprobe_test will be assigned\nas the error code. If module kprobe_event_gen_test is removed now, the\nnull pointer dereference will happen in kprobe_event_gen_test_exit().\nCheck if gen_kprobe_test or gen_kretprobe_test is error code or NULL\nbefore dereference them.\n\nBUG: kernel NULL pointer dereference, address: 0000000000000012\nPGD 0 P4D 0\nOops: 0000 [#1] SMP PTI\nCPU: 3 PID: 2210 Comm: modprobe Not tainted\n6.1.0-rc1-00171-g2159299a3b74-dirty #217\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS\nrel-1.15.0-0-g2dd4b9b3f840-prebuilt.qemu.org 04/01/2014\nRIP: 0010:kprobe_event_gen_test_exit+0x1c/0xb5 [kprobe_event_gen_test]\nCode: Unable to access opcode bytes at 0xffffffff9ffffff2.\nRSP: 0018:ffffc900015bfeb8 EFLAGS: 00010246\nRAX: ffffffffffffffea RBX: ffffffffa0002080 RCX: 0000000000000000\nRDX: ffffffffa0001054 RSI: ffffffffa0001064 RDI: ffffffffdfc6349c\nRBP: ffffffffa0000000 R08: 0000000000000004 R09: 00000000001e95c0\nR10: 0000000000000000 R11: 0000000000000001 R12: 0000000000000800\nR13: ffffffffa0002420 R14: 0000000000000000 R15: 0000000000000000\nFS: 00007f56b75be540(0000) GS:ffff88813bc00000(0000)\nknlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: ffffffff9ffffff2 CR3: 000000010874a006 CR4: 0000000000330ee0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nCall Trace:\n \n __x64_sys_delete_module+0x206/0x380\n ? lockdep_hardirqs_on_prepare+0xd8/0x190\n ? syscall_enter_from_user_mode+0x1c/0x50\n do_syscall_64+0x3f/0x90\n entry_SYSCALL_64_after_hwframe+0x63/0xcd", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49797" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3a41c0f2a5c3bf72b4c4e9dd4b1025378201e332" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bb70fcae4115d24b7e8cee17a6da8b1943f546bb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e0d75267f59d7084e0468bd68beeb1bf9c71d7c0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fd0efd4f7bfe611a8339ba01bc2ac3c33e79159d" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-262g-44pp-38c2/GHSA-262g-44pp-38c2.json b/advisories/unreviewed/2025/05/GHSA-262g-44pp-38c2/GHSA-262g-44pp-38c2.json new file mode 100644 index 00000000000..7e7364f9af7 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-262g-44pp-38c2/GHSA-262g-44pp-38c2.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-262g-44pp-38c2", + "modified": "2025-05-01T15:31:53Z", + "published": "2025-05-01T15:31:53Z", + "aliases": [ + "CVE-2022-49926" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: dsa: Fix possible memory leaks in dsa_loop_init()\n\nkmemleak reported memory leaks in dsa_loop_init():\n\nkmemleak: 12 new suspected memory leaks\n\nunreferenced object 0xffff8880138ce000 (size 2048):\n comm \"modprobe\", pid 390, jiffies 4295040478 (age 238.976s)\n backtrace:\n [<000000006a94f1d5>] kmalloc_trace+0x26/0x60\n [<00000000a9c44622>] phy_device_create+0x5d/0x970\n [<00000000d0ee2afc>] get_phy_device+0xf3/0x2b0\n [<00000000dca0c71f>] __fixed_phy_register.part.0+0x92/0x4e0\n [<000000008a834798>] fixed_phy_register+0x84/0xb0\n [<0000000055223fcb>] dsa_loop_init+0xa9/0x116 [dsa_loop]\n ...\n\nThere are two reasons for memleak in dsa_loop_init().\n\nFirst, fixed_phy_register() create and register phy_device:\n\nfixed_phy_register()\n get_phy_device()\n phy_device_create() # freed by phy_device_free()\n phy_device_register() # freed by phy_device_remove()\n\nBut fixed_phy_unregister() only calls phy_device_remove().\nSo the memory allocated in phy_device_create() is leaked.\n\nSecond, when mdio_driver_register() fail in dsa_loop_init(),\nit just returns and there is no cleanup for phydevs.\n\nFix the problems by catching the error of mdio_driver_register()\nin dsa_loop_init(), then calling both fixed_phy_unregister() and\nphy_device_free() to release phydevs.\nAlso add a function for phydevs cleanup to avoid duplacate.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49926" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/37a098fc9b42bd7fce66764866aa514639667b6e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4d2024b138d9f7b02ae13ee997fd3a71e9e46254" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/633efc8b3dc96f56f5a57f2a49764853a2fa3f50" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/935b4beb724946a37cebf97191592d4879d3a3a3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9f555b1584fc2d5d16ee3c4d9438e93ac7c502c7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bbc5d7b46a729bfcbb5544f6612b7a67dd4f4d6f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d593e1ede655b74c42e4e4fe285ea64aee96fb5c" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-262x-vpc4-rwc6/GHSA-262x-vpc4-rwc6.json b/advisories/unreviewed/2025/05/GHSA-262x-vpc4-rwc6/GHSA-262x-vpc4-rwc6.json new file mode 100644 index 00000000000..af6a6654808 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-262x-vpc4-rwc6/GHSA-262x-vpc4-rwc6.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-262x-vpc4-rwc6", + "modified": "2025-05-01T15:31:49Z", + "published": "2025-05-01T15:31:49Z", + "aliases": [ + "CVE-2022-49838" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: clear out_curr if all frag chunks of current msg are pruned\n\nA crash was reported by Zhen Chen:\n\n list_del corruption, ffffa035ddf01c18->next is NULL\n WARNING: CPU: 1 PID: 250682 at lib/list_debug.c:49 __list_del_entry_valid+0x59/0xe0\n RIP: 0010:__list_del_entry_valid+0x59/0xe0\n Call Trace:\n sctp_sched_dequeue_common+0x17/0x70 [sctp]\n sctp_sched_fcfs_dequeue+0x37/0x50 [sctp]\n sctp_outq_flush_data+0x85/0x360 [sctp]\n sctp_outq_uncork+0x77/0xa0 [sctp]\n sctp_cmd_interpreter.constprop.0+0x164/0x1450 [sctp]\n sctp_side_effects+0x37/0xe0 [sctp]\n sctp_do_sm+0xd0/0x230 [sctp]\n sctp_primitive_SEND+0x2f/0x40 [sctp]\n sctp_sendmsg_to_asoc+0x3fa/0x5c0 [sctp]\n sctp_sendmsg+0x3d5/0x440 [sctp]\n sock_sendmsg+0x5b/0x70\n\nand in sctp_sched_fcfs_dequeue() it dequeued a chunk from stream\nout_curr outq while this outq was empty.\n\nNormally stream->out_curr must be set to NULL once all frag chunks of\ncurrent msg are dequeued, as we can see in sctp_sched_dequeue_done().\nHowever, in sctp_prsctp_prune_unsent() as it is not a proper dequeue,\nsctp_sched_dequeue_done() is not called to do this.\n\nThis patch is to fix it by simply setting out_curr to NULL when the\nlast frag chunk of current msg is dequeued from out_curr stream in\nsctp_prsctp_prune_unsent().", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49838" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2ea600b598dd3e061854dd4dd5b4c815397dfcea" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2f201ae14ae0f91dbf1cffea7bb1e29e81d4d108" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3eff34e01062ec08fbb45ce2baaaa644550be821" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e27458b18b35caee4b27b37a4a9c503b93cae5cc" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-2cfw-3h9f-mpm2/GHSA-2cfw-3h9f-mpm2.json b/advisories/unreviewed/2025/05/GHSA-2cfw-3h9f-mpm2/GHSA-2cfw-3h9f-mpm2.json new file mode 100644 index 00000000000..fb42f67fa5f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-2cfw-3h9f-mpm2/GHSA-2cfw-3h9f-mpm2.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2cfw-3h9f-mpm2", + "modified": "2025-05-01T15:31:50Z", + "published": "2025-05-01T15:31:50Z", + "aliases": [ + "CVE-2022-49859" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: lapbether: fix issue of invalid opcode in lapbeth_open()\n\nIf lapb_register() failed when lapb device goes to up for the first time,\nthe NAPI is not disabled. As a result, the invalid opcode issue is\nreported when the lapb device goes to up for the second time.\n\nThe stack info is as follows:\n[ 1958.311422][T11356] kernel BUG at net/core/dev.c:6442!\n[ 1958.312206][T11356] invalid opcode: 0000 [#1] PREEMPT SMP KASAN\n[ 1958.315979][T11356] RIP: 0010:napi_enable+0x16a/0x1f0\n[ 1958.332310][T11356] Call Trace:\n[ 1958.332817][T11356] \n[ 1958.336135][T11356] lapbeth_open+0x18/0x90\n[ 1958.337446][T11356] __dev_open+0x258/0x490\n[ 1958.341672][T11356] __dev_change_flags+0x4d4/0x6a0\n[ 1958.345325][T11356] dev_change_flags+0x93/0x160\n[ 1958.346027][T11356] devinet_ioctl+0x1276/0x1bf0\n[ 1958.346738][T11356] inet_ioctl+0x1c8/0x2d0\n[ 1958.349638][T11356] sock_ioctl+0x5d1/0x750\n[ 1958.356059][T11356] __x64_sys_ioctl+0x3ec/0x1790\n[ 1958.365594][T11356] do_syscall_64+0x35/0x80\n[ 1958.366239][T11356] entry_SYSCALL_64_after_hwframe+0x46/0xb0\n[ 1958.377381][T11356] ", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49859" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3faf7e14ec0c3462c2d747fa6793b8645d1391df" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4689bd3a1b23a1bd917899e63b81bca2ccdfab45" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ed4940050a7ce7fc2ccd51db580ef1ade64290b1" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-2crp-r6g2-9c5p/GHSA-2crp-r6g2-9c5p.json b/advisories/unreviewed/2025/05/GHSA-2crp-r6g2-9c5p/GHSA-2crp-r6g2-9c5p.json new file mode 100644 index 00000000000..a7ad2399b8e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-2crp-r6g2-9c5p/GHSA-2crp-r6g2-9c5p.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2crp-r6g2-9c5p", + "modified": "2025-05-01T15:31:50Z", + "published": "2025-05-01T15:31:50Z", + "aliases": [ + "CVE-2022-49867" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: wwan: iosm: fix memory leak in ipc_wwan_dellink\n\nIOSM driver registers network device without setting the\nneeds_free_netdev flag, and does NOT call free_netdev() when\nunregisters network device, which causes a memory leak.\n\nThis patch sets needs_free_netdev to true when registers\nnetwork device, which makes netdev subsystem call free_netdev()\nautomatically after unregister_netdevice().", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49867" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/128514b51a5ba2c82f9e4a106f1c10423907618a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2ce2348c2858d723f7fe389dead9b43b08e0944e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f25caaca424703d5a0607310f0452f978f1f78d9" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-2f6p-9573-fp98/GHSA-2f6p-9573-fp98.json b/advisories/unreviewed/2025/05/GHSA-2f6p-9573-fp98/GHSA-2f6p-9573-fp98.json new file mode 100644 index 00000000000..350c6881557 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-2f6p-9573-fp98/GHSA-2f6p-9573-fp98.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2f6p-9573-fp98", + "modified": "2025-05-01T15:31:53Z", + "published": "2025-05-01T15:31:52Z", + "aliases": [ + "CVE-2022-49909" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: fix use-after-free in l2cap_conn_del()\n\nWhen l2cap_recv_frame() is invoked to receive data, and the cid is\nL2CAP_CID_A2MP, if the channel does not exist, it will create a channel.\nHowever, after a channel is created, the hold operation of the channel\nis not performed. In this case, the value of channel reference counting\nis 1. As a result, after hci_error_reset() is triggered, l2cap_conn_del()\ninvokes the close hook function of A2MP to release the channel. Then\n l2cap_chan_unlock(chan) will trigger UAF issue.\n\nThe process is as follows:\nReceive data:\nl2cap_data_channel()\n a2mp_channel_create() --->channel ref is 2\n l2cap_chan_put() --->channel ref is 1\n\nTriger event:\n hci_error_reset()\n hci_dev_do_close()\n ...\n l2cap_disconn_cfm()\n l2cap_conn_del()\n l2cap_chan_hold() --->channel ref is 2\n l2cap_chan_del() --->channel ref is 1\n a2mp_chan_close_cb() --->channel ref is 0, release channel\n l2cap_chan_unlock() --->UAF of channel\n\nThe detailed Call Trace is as follows:\nBUG: KASAN: use-after-free in __mutex_unlock_slowpath+0xa6/0x5e0\nRead of size 8 at addr ffff8880160664b8 by task kworker/u11:1/7593\nWorkqueue: hci0 hci_error_reset\nCall Trace:\n \n dump_stack_lvl+0xcd/0x134\n print_report.cold+0x2ba/0x719\n kasan_report+0xb1/0x1e0\n kasan_check_range+0x140/0x190\n __mutex_unlock_slowpath+0xa6/0x5e0\n l2cap_conn_del+0x404/0x7b0\n l2cap_disconn_cfm+0x8c/0xc0\n hci_conn_hash_flush+0x11f/0x260\n hci_dev_close_sync+0x5f5/0x11f0\n hci_dev_do_close+0x2d/0x70\n hci_error_reset+0x9e/0x140\n process_one_work+0x98a/0x1620\n worker_thread+0x665/0x1080\n kthread+0x2e4/0x3a0\n ret_from_fork+0x1f/0x30\n \n\nAllocated by task 7593:\n kasan_save_stack+0x1e/0x40\n __kasan_kmalloc+0xa9/0xd0\n l2cap_chan_create+0x40/0x930\n amp_mgr_create+0x96/0x990\n a2mp_channel_create+0x7d/0x150\n l2cap_recv_frame+0x51b8/0x9a70\n l2cap_recv_acldata+0xaa3/0xc00\n hci_rx_work+0x702/0x1220\n process_one_work+0x98a/0x1620\n worker_thread+0x665/0x1080\n kthread+0x2e4/0x3a0\n ret_from_fork+0x1f/0x30\n\nFreed by task 7593:\n kasan_save_stack+0x1e/0x40\n kasan_set_track+0x21/0x30\n kasan_set_free_info+0x20/0x30\n ____kasan_slab_free+0x167/0x1c0\n slab_free_freelist_hook+0x89/0x1c0\n kfree+0xe2/0x580\n l2cap_chan_put+0x22a/0x2d0\n l2cap_conn_del+0x3fc/0x7b0\n l2cap_disconn_cfm+0x8c/0xc0\n hci_conn_hash_flush+0x11f/0x260\n hci_dev_close_sync+0x5f5/0x11f0\n hci_dev_do_close+0x2d/0x70\n hci_error_reset+0x9e/0x140\n process_one_work+0x98a/0x1620\n worker_thread+0x665/0x1080\n kthread+0x2e4/0x3a0\n ret_from_fork+0x1f/0x30\n\nLast potentially related work creation:\n kasan_save_stack+0x1e/0x40\n __kasan_record_aux_stack+0xbe/0xd0\n call_rcu+0x99/0x740\n netlink_release+0xe6a/0x1cf0\n __sock_release+0xcd/0x280\n sock_close+0x18/0x20\n __fput+0x27c/0xa90\n task_work_run+0xdd/0x1a0\n exit_to_user_mode_prepare+0x23c/0x250\n syscall_exit_to_user_mode+0x19/0x50\n do_syscall_64+0x42/0x80\n entry_SYSCALL_64_after_hwframe+0x63/0xcd\n\nSecond to last potentially related work creation:\n kasan_save_stack+0x1e/0x40\n __kasan_record_aux_stack+0xbe/0xd0\n call_rcu+0x99/0x740\n netlink_release+0xe6a/0x1cf0\n __sock_release+0xcd/0x280\n sock_close+0x18/0x20\n __fput+0x27c/0xa90\n task_work_run+0xdd/0x1a0\n exit_to_user_mode_prepare+0x23c/0x250\n syscall_exit_to_user_mode+0x19/0x50\n do_syscall_64+0x42/0x80\n entry_SYSCALL_64_after_hwframe+0x63/0xcd", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49909" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0d0e2d032811280b927650ff3c15fe5020e82533" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/17c6164854f8bb80bf76f32b2c2f199c16b53703" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7f7bfdd9a9af3b12c33d9da9a012e7f4d5c91f4b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8f7e4cf0694149a5d999d676ebd9ecf1b4cb2cc9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a3a7b2ac64de232edb67279e804932cb42f0b52a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c1f594dddd9ffd747c39f49cc5b67a9b7677d2ab" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d9ec6e2fbd4a565b2345d4852f586b7ae3ab41fd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/db4a0783ed78beb2ebaa32f5f785bfd79c580689" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-2jgx-99cr-362f/GHSA-2jgx-99cr-362f.json b/advisories/unreviewed/2025/05/GHSA-2jgx-99cr-362f/GHSA-2jgx-99cr-362f.json new file mode 100644 index 00000000000..8a8ebf1cd2f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-2jgx-99cr-362f/GHSA-2jgx-99cr-362f.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2jgx-99cr-362f", + "modified": "2025-05-01T15:31:46Z", + "published": "2025-05-01T15:31:46Z", + "aliases": [ + "CVE-2022-49779" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nkprobes: Skip clearing aggrprobe's post_handler in kprobe-on-ftrace case\n\nIn __unregister_kprobe_top(), if the currently unregistered probe has\npost_handler but other child probes of the aggrprobe do not have\npost_handler, the post_handler of the aggrprobe is cleared. If this is\na ftrace-based probe, there is a problem. In later calls to\ndisarm_kprobe(), we will use kprobe_ftrace_ops because post_handler is\nNULL. But we're armed with kprobe_ipmodify_ops. This triggers a WARN in\n__disarm_kprobe_ftrace() and may even cause use-after-free:\n\n Failed to disarm kprobe-ftrace at kernel_clone+0x0/0x3c0 (error -2)\n WARNING: CPU: 5 PID: 137 at kernel/kprobes.c:1135 __disarm_kprobe_ftrace.isra.21+0xcf/0xe0\n Modules linked in: testKprobe_007(-)\n CPU: 5 PID: 137 Comm: rmmod Not tainted 6.1.0-rc4-dirty #18\n [...]\n Call Trace:\n \n __disable_kprobe+0xcd/0xe0\n __unregister_kprobe_top+0x12/0x150\n ? mutex_lock+0xe/0x30\n unregister_kprobes.part.23+0x31/0xa0\n unregister_kprobe+0x32/0x40\n __x64_sys_delete_module+0x15e/0x260\n ? do_user_addr_fault+0x2cd/0x6b0\n do_syscall_64+0x3a/0x90\n entry_SYSCALL_64_after_hwframe+0x63/0xcd\n [...]\n\nFor the kprobe-on-ftrace case, we keep the post_handler setting to\nidentify this aggrprobe armed with kprobe_ipmodify_ops. This way we\ncan disarm it correctly.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49779" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/55788ebbe8b365b4375bd56b4ba7db79d393a370" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5dd7caf0bdc5d0bae7cf9776b4d739fb09bd5ebb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7b0007b28dd970176f2e297c06ae63eea2447127" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7d606ae1abcc3eab5408e42444d789dc7def51b8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c49cc2c059b503e962c2f13a806c105f9b757df4" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-32c5-q8cj-xx83/GHSA-32c5-q8cj-xx83.json b/advisories/unreviewed/2025/05/GHSA-32c5-q8cj-xx83/GHSA-32c5-q8cj-xx83.json new file mode 100644 index 00000000000..5c1f640deae --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-32c5-q8cj-xx83/GHSA-32c5-q8cj-xx83.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-32c5-q8cj-xx83", + "modified": "2025-05-01T15:31:50Z", + "published": "2025-05-01T15:31:50Z", + "aliases": [ + "CVE-2022-49866" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: wwan: mhi: fix memory leak in mhi_mbim_dellink\n\nMHI driver registers network device without setting the\nneeds_free_netdev flag, and does NOT call free_netdev() when\nunregisters network device, which causes a memory leak.\n\nThis patch sets needs_free_netdev to true when registers\nnetwork device, which makes netdev subsystem call free_netdev()\nautomatically after unregister_netdevice().", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49866" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2845bc9070cef0c651987487d84d4813d64675dd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3cd3ffe952f78ec5dadf300cb58d4b38a0c0106d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/668205b9c9f94d5ed6ab00cce9a46a654c2b5d16" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-36j9-2v33-g5mg/GHSA-36j9-2v33-g5mg.json b/advisories/unreviewed/2025/05/GHSA-36j9-2v33-g5mg/GHSA-36j9-2v33-g5mg.json new file mode 100644 index 00000000000..2efeb799a0a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-36j9-2v33-g5mg/GHSA-36j9-2v33-g5mg.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-36j9-2v33-g5mg", + "modified": "2025-05-01T15:31:42Z", + "published": "2025-05-01T15:31:42Z", + "aliases": [ + "CVE-2025-37748" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\niommu/mediatek: Fix NULL pointer deference in mtk_iommu_device_group\n\nCurrently, mtk_iommu calls during probe iommu_device_register before\nthe hw_list from driver data is initialized. Since iommu probing issue\nfix, it leads to NULL pointer dereference in mtk_iommu_device_group when\nhw_list is accessed with list_first_entry (not null safe).\n\nSo, change the call order to ensure iommu_device_register is called\nafter the driver data are initialized.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37748" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2f75cb27bef43c8692b0f5e471e5632f6a9beb99" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/38e8844005e6068f336a3ad45451a562a0040ca1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/69f9d2d37d1207c5a73dac52a4ce1361ead707f5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6abd09bed43b8d83d461e0fb5b9a200a06aa8a27" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a0842539e8ef9386c070156103aff888e558a60c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ce7d3b2f6f393fa35f0ea12861b83a1ca28b295c" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T13:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-36jv-w59f-85w3/GHSA-36jv-w59f-85w3.json b/advisories/unreviewed/2025/05/GHSA-36jv-w59f-85w3/GHSA-36jv-w59f-85w3.json index 09f2c71bcd3..75d420e9710 100644 --- a/advisories/unreviewed/2025/05/GHSA-36jv-w59f-85w3/GHSA-36jv-w59f-85w3.json +++ b/advisories/unreviewed/2025/05/GHSA-36jv-w59f-85w3/GHSA-36jv-w59f-85w3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-36jv-w59f-85w3", - "modified": "2025-05-01T06:30:28Z", + "modified": "2025-05-01T15:31:39Z", "published": "2025-05-01T06:30:28Z", "aliases": [ "CVE-2025-3504" ], "details": "The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-01T06:15:35Z" diff --git a/advisories/unreviewed/2025/05/GHSA-39cv-hx7c-vjcq/GHSA-39cv-hx7c-vjcq.json b/advisories/unreviewed/2025/05/GHSA-39cv-hx7c-vjcq/GHSA-39cv-hx7c-vjcq.json new file mode 100644 index 00000000000..4de5d55a9fd --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-39cv-hx7c-vjcq/GHSA-39cv-hx7c-vjcq.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-39cv-hx7c-vjcq", + "modified": "2025-05-01T15:31:43Z", + "published": "2025-05-01T15:31:42Z", + "aliases": [ + "CVE-2025-37752" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet_sched: sch_sfq: move the limit validation\n\nIt is not sufficient to directly validate the limit on the data that\nthe user passes as it can be updated based on how the other parameters\nare changed.\n\nMove the check at the end of the configuration update process to also\ncatch scenarios where the limit is indirectly updated, for example\nwith the following configurations:\n\ntc qdisc add dev dummy0 handle 1: root sfq limit 2 flows 1 depth 1\ntc qdisc add dev dummy0 handle 1: root sfq limit 2 flows 1 divisor 1\n\nThis fixes the following syzkaller reported crash:\n\n------------[ cut here ]------------\nUBSAN: array-index-out-of-bounds in net/sched/sch_sfq.c:203:6\nindex 65535 is out of range for type 'struct sfq_head[128]'\nCPU: 1 UID: 0 PID: 3037 Comm: syz.2.16 Not tainted 6.14.0-rc2-syzkaller #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 12/27/2024\nCall Trace:\n \n __dump_stack lib/dump_stack.c:94 [inline]\n dump_stack_lvl+0x201/0x300 lib/dump_stack.c:120\n ubsan_epilogue lib/ubsan.c:231 [inline]\n __ubsan_handle_out_of_bounds+0xf5/0x120 lib/ubsan.c:429\n sfq_link net/sched/sch_sfq.c:203 [inline]\n sfq_dec+0x53c/0x610 net/sched/sch_sfq.c:231\n sfq_dequeue+0x34e/0x8c0 net/sched/sch_sfq.c:493\n sfq_reset+0x17/0x60 net/sched/sch_sfq.c:518\n qdisc_reset+0x12e/0x600 net/sched/sch_generic.c:1035\n tbf_reset+0x41/0x110 net/sched/sch_tbf.c:339\n qdisc_reset+0x12e/0x600 net/sched/sch_generic.c:1035\n dev_reset_queue+0x100/0x1b0 net/sched/sch_generic.c:1311\n netdev_for_each_tx_queue include/linux/netdevice.h:2590 [inline]\n dev_deactivate_many+0x7e5/0xe70 net/sched/sch_generic.c:1375", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37752" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1348214fa042a71406964097e743c87a42c85a49" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5e5e1fcc1b8ed57f902c424c5d9b328a3a19073d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b36a68192037d1614317a09b0d78c7814e2eecf9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b3bf8f63e6179076b57c9de660c9f80b5abefe70" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d2718324f9e329b10ddc091fba5a0ba2b9d4d96a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f86293adce0c201cfabb283ef9d6f21292089bb8" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T13:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-3cfh-wr8w-8mhf/GHSA-3cfh-wr8w-8mhf.json b/advisories/unreviewed/2025/05/GHSA-3cfh-wr8w-8mhf/GHSA-3cfh-wr8w-8mhf.json new file mode 100644 index 00000000000..5ca062c03cc --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-3cfh-wr8w-8mhf/GHSA-3cfh-wr8w-8mhf.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3cfh-wr8w-8mhf", + "modified": "2025-05-01T15:31:40Z", + "published": "2025-05-01T15:31:40Z", + "aliases": [ + "CVE-2025-23144" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbacklight: led_bl: Hold led_access lock when calling led_sysfs_disable()\n\nLockdep detects the following issue on led-backlight removal:\n [ 142.315935] ------------[ cut here ]------------\n [ 142.315954] WARNING: CPU: 2 PID: 292 at drivers/leds/led-core.c:455 led_sysfs_enable+0x54/0x80\n ...\n [ 142.500725] Call trace:\n [ 142.503176] led_sysfs_enable+0x54/0x80 (P)\n [ 142.507370] led_bl_remove+0x80/0xa8 [led_bl]\n [ 142.511742] platform_remove+0x30/0x58\n [ 142.515501] device_remove+0x54/0x90\n ...\n\nIndeed, led_sysfs_enable() has to be called with the led_access\nlock held.\n\nHold the lock when calling led_sysfs_disable().", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23144" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/11d128f7eacec276c75cf4712880a6307ca9c885" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1c82f5a393d8b9a5c1ea032413719862098afd4b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/276822a00db3c1061382b41e72cafc09d6a0ec30" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/61a5c565fd2442d3128f3bab5f022658adc3a4e6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b8ddf5107f53789448900f04fa220f34cd2f777e" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T13:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-3g3w-hwv4-w6vm/GHSA-3g3w-hwv4-w6vm.json b/advisories/unreviewed/2025/05/GHSA-3g3w-hwv4-w6vm/GHSA-3g3w-hwv4-w6vm.json new file mode 100644 index 00000000000..5e6429bc228 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-3g3w-hwv4-w6vm/GHSA-3g3w-hwv4-w6vm.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3g3w-hwv4-w6vm", + "modified": "2025-05-01T15:31:48Z", + "published": "2025-05-01T15:31:48Z", + "aliases": [ + "CVE-2022-49816" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nxen/pcpu: fix possible memory leak in register_pcpu()\n\nIn device_add(), dev_set_name() is called to allocate name, if it returns\nerror, the name need be freed. As comment of device_register() says, it\nshould use put_device() to give up the reference in the error path. So fix\nthis by calling put_device(), then the name can be freed in kobject_cleanup().", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49816" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0199bf0a8f74509736744c9e36f4473a5892a09d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6209a85079a035b5c2279b15b197531156b549fa" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7ed540bcee2e24479524b9705cc7462b2652f944" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bb9924a6edd9d4a9ef83a5f337af60f8a7a68f98" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c08c13cb13fa3866dd0700db3b246fcd2043ab81" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ccb22c876e8e7f62377e749c971907efe65d34c2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/da36a2a76b01b210ffaa55cdc2c99bc8783697c5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e948f3c129d78537ded70bcc99c31f0b45f05dd7" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-3g7w-h796-wcg5/GHSA-3g7w-h796-wcg5.json b/advisories/unreviewed/2025/05/GHSA-3g7w-h796-wcg5/GHSA-3g7w-h796-wcg5.json new file mode 100644 index 00000000000..14aef784598 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-3g7w-h796-wcg5/GHSA-3g7w-h796-wcg5.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3g7w-h796-wcg5", + "modified": "2025-05-01T15:31:51Z", + "published": "2025-05-01T15:31:51Z", + "aliases": [ + "CVE-2022-49896" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncxl/pmem: Fix cxl_pmem_region and cxl_memdev leak\n\nWhen a cxl_nvdimm object goes through a ->remove() event (device\nphysically removed, nvdimm-bridge disabled, or nvdimm device disabled),\nthen any associated regions must also be disabled. As highlighted by the\ncxl-create-region.sh test [1], a single device may host multiple\nregions, but the driver was only tracking one region at a time. This\nleads to a situation where only the last enabled region per nvdimm\ndevice is cleaned up properly. Other regions are leaked, and this also\ncauses cxl_memdev reference leaks.\n\nFix the tracking by allowing cxl_nvdimm objects to track multiple region\nassociations.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49896" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4d07ae22e79ebc2d7528bbc69daa53b86981cb3a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f43b6bfdbab78606735ba81185cf0602b81e40b6" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-3gpq-jcrp-xp2r/GHSA-3gpq-jcrp-xp2r.json b/advisories/unreviewed/2025/05/GHSA-3gpq-jcrp-xp2r/GHSA-3gpq-jcrp-xp2r.json new file mode 100644 index 00000000000..af8a1751180 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-3gpq-jcrp-xp2r/GHSA-3gpq-jcrp-xp2r.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3gpq-jcrp-xp2r", + "modified": "2025-05-01T15:31:48Z", + "published": "2025-05-01T15:31:48Z", + "aliases": [ + "CVE-2022-49815" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nerofs: fix missing xas_retry() in fscache mode\n\nThe xarray iteration only holds the RCU read lock and thus may encounter\nXA_RETRY_ENTRY if there's process modifying the xarray concurrently.\nThis will cause oops when referring to the invalid entry.\n\nFix this by adding the missing xas_retry(), which will make the\niteration wind back to the root node if XA_RETRY_ENTRY is encountered.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49815" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/37020bbb71d911431e16c2c940b97cf86ae4f2f6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/dbc98fe99e17ed18f2f272d5fe880d844b1c68c3" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-3hvv-xgr4-fr7x/GHSA-3hvv-xgr4-fr7x.json b/advisories/unreviewed/2025/05/GHSA-3hvv-xgr4-fr7x/GHSA-3hvv-xgr4-fr7x.json new file mode 100644 index 00000000000..9d1b32a5936 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-3hvv-xgr4-fr7x/GHSA-3hvv-xgr4-fr7x.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3hvv-xgr4-fr7x", + "modified": "2025-05-01T15:31:41Z", + "published": "2025-05-01T15:31:41Z", + "aliases": [ + "CVE-2025-23159" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: venus: hfi: add a check to handle OOB in sfr region\n\nsfr->buf_size is in shared memory and can be modified by malicious user.\nOOB write is possible when the size is made higher than actual sfr data\nbuffer. Cap the size to allocated size for such cases.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23159" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4e95233af57715d81830fe82b408c633edff59f4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/530f623f56a6680792499a8404083e17f8ec51f4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5af611c70fb889d46d2f654b8996746e59556750" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a062d8de0be5525ec8c52f070acf7607ec8cbfe4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d78a8388a27b265fcb2b8d064f088168ac9356b0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f4b211714bcc70effa60c34d9fa613d182e3ef1e" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T13:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-3mh8-97g4-p2mv/GHSA-3mh8-97g4-p2mv.json b/advisories/unreviewed/2025/05/GHSA-3mh8-97g4-p2mv/GHSA-3mh8-97g4-p2mv.json new file mode 100644 index 00000000000..efc22e761ca --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-3mh8-97g4-p2mv/GHSA-3mh8-97g4-p2mv.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3mh8-97g4-p2mv", + "modified": "2025-05-01T15:31:53Z", + "published": "2025-05-01T15:31:53Z", + "aliases": [ + "CVE-2022-49919" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: release flow rule object from commit path\n\nNo need to postpone this to the commit release path, since no packets\nare walking over this object, this is accessed from control plane only.\nThis helped uncovered UAF triggered by races with the netlink notifier.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49919" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/26b5934ff4194e13196bedcba373cd4915071d0e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4ab6f96444e936f5e4a936d5c0bc948144bcded3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6044791b7be707fd0e709f26e961a446424e5051" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/74fd5839467054cd9c4d050614d3ee8788386171" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b2d7a92aff0fbd93c29d2aa6451fb99f050e2c4e" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-3qx4-pq69-7jwx/GHSA-3qx4-pq69-7jwx.json b/advisories/unreviewed/2025/05/GHSA-3qx4-pq69-7jwx/GHSA-3qx4-pq69-7jwx.json new file mode 100644 index 00000000000..6737072ff16 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-3qx4-pq69-7jwx/GHSA-3qx4-pq69-7jwx.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3qx4-pq69-7jwx", + "modified": "2025-05-01T15:31:44Z", + "published": "2025-05-01T15:31:44Z", + "aliases": [ + "CVE-2025-37784" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ti: icss-iep: Fix possible NULL pointer dereference for perout request\n\nThe ICSS IEP driver tracks perout and pps enable state with flags.\nCurrently when disabling pps and perout signals during icss_iep_exit(),\nresults in NULL pointer dereference for perout.\n\nTo fix the null pointer dereference issue, the icss_iep_perout_enable_hw\nfunction can be modified to directly clear the IEP CMP registers when\ndisabling PPS or PEROUT, without referencing the ptp_perout_request\nstructure, as its contents are irrelevant in this case.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37784" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7349c9e9979333abfce42da5f9025598083b59c9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7891619d21f07a88e0275d6d43db74035aa74f69" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/da5035d7aeadcfa44096dd34689bfed6c657f559" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/eeec66327001421531b3fb1a2ac32efc8a2493b0" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T14:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-3r7x-52q9-w4pw/GHSA-3r7x-52q9-w4pw.json b/advisories/unreviewed/2025/05/GHSA-3r7x-52q9-w4pw/GHSA-3r7x-52q9-w4pw.json new file mode 100644 index 00000000000..efa14b8736b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-3r7x-52q9-w4pw/GHSA-3r7x-52q9-w4pw.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3r7x-52q9-w4pw", + "modified": "2025-05-01T15:31:40Z", + "published": "2025-05-01T15:31:40Z", + "aliases": [ + "CVE-2025-23145" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: fix NULL pointer in can_accept_new_subflow\n\nWhen testing valkey benchmark tool with MPTCP, the kernel panics in\n'mptcp_can_accept_new_subflow' because subflow_req->msk is NULL.\n\nCall trace:\n\n mptcp_can_accept_new_subflow (./net/mptcp/subflow.c:63 (discriminator 4)) (P)\n subflow_syn_recv_sock (./net/mptcp/subflow.c:854)\n tcp_check_req (./net/ipv4/tcp_minisocks.c:863)\n tcp_v4_rcv (./net/ipv4/tcp_ipv4.c:2268)\n ip_protocol_deliver_rcu (./net/ipv4/ip_input.c:207)\n ip_local_deliver_finish (./net/ipv4/ip_input.c:234)\n ip_local_deliver (./net/ipv4/ip_input.c:254)\n ip_rcv_finish (./net/ipv4/ip_input.c:449)\n ...\n\nAccording to the debug log, the same req received two SYN-ACK in a very\nshort time, very likely because the client retransmits the syn ack due\nto multiple reasons.\n\nEven if the packets are transmitted with a relevant time interval, they\ncan be processed by the server on different CPUs concurrently). The\n'subflow_req->msk' ownership is transferred to the subflow the first,\nand there will be a risk of a null pointer dereference here.\n\nThis patch fixes this issue by moving the 'subflow_req->msk' under the\n`own_req == true` conditional.\n\nNote that the !msk check in subflow_hmac_valid() can be dropped, because\nthe same check already exists under the own_req mpj branch where the\ncode has been moved to.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23145" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/443041deb5ef6a1289a99ed95015ec7442f141dc" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4b2649b9717678aeb097893cc49f59311a1ecab0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7f9ae060ed64aef8f174c5f1ea513825b1be9af1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/855bf0aacd51fced11ea9aa0d5101ee0febaeadb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/dc81e41a307df523072186b241fa8244fecd7803" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/efd58a8dd9e7a709a90ee486a4247c923d27296f" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T13:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-3vg9-6vwr-fh6q/GHSA-3vg9-6vwr-fh6q.json b/advisories/unreviewed/2025/05/GHSA-3vg9-6vwr-fh6q/GHSA-3vg9-6vwr-fh6q.json new file mode 100644 index 00000000000..cea10cfa1d2 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-3vg9-6vwr-fh6q/GHSA-3vg9-6vwr-fh6q.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3vg9-6vwr-fh6q", + "modified": "2025-05-01T15:31:53Z", + "published": "2025-05-01T15:31:52Z", + "aliases": [ + "CVE-2022-49910" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: Fix use-after-free caused by l2cap_reassemble_sdu\n\nFix the race condition between the following two flows that run in\nparallel:\n\n1. l2cap_reassemble_sdu -> chan->ops->recv (l2cap_sock_recv_cb) ->\n __sock_queue_rcv_skb.\n\n2. bt_sock_recvmsg -> skb_recv_datagram, skb_free_datagram.\n\nAn SKB can be queued by the first flow and immediately dequeued and\nfreed by the second flow, therefore the callers of l2cap_reassemble_sdu\ncan't use the SKB after that function returns. However, some places\ncontinue accessing struct l2cap_ctrl that resides in the SKB's CB for a\nshort time after l2cap_reassemble_sdu returns, leading to a\nuse-after-free condition (the stack trace is below, line numbers for\nkernel 5.19.8).\n\nFix it by keeping a local copy of struct l2cap_ctrl.\n\nBUG: KASAN: use-after-free in l2cap_rx_state_recv (net/bluetooth/l2cap_core.c:6906) bluetooth\nRead of size 1 at addr ffff88812025f2f0 by task kworker/u17:3/43169\n\nWorkqueue: hci0 hci_rx_work [bluetooth]\nCall Trace:\n \n dump_stack_lvl (lib/dump_stack.c:107 (discriminator 4))\n print_report.cold (mm/kasan/report.c:314 mm/kasan/report.c:429)\n ? l2cap_rx_state_recv (net/bluetooth/l2cap_core.c:6906) bluetooth\n kasan_report (mm/kasan/report.c:162 mm/kasan/report.c:493)\n ? l2cap_rx_state_recv (net/bluetooth/l2cap_core.c:6906) bluetooth\n l2cap_rx_state_recv (net/bluetooth/l2cap_core.c:6906) bluetooth\n l2cap_rx (net/bluetooth/l2cap_core.c:7236 net/bluetooth/l2cap_core.c:7271) bluetooth\n ret_from_fork (arch/x86/entry/entry_64.S:306)\n \n\nAllocated by task 43169:\n kasan_save_stack (mm/kasan/common.c:39)\n __kasan_slab_alloc (mm/kasan/common.c:45 mm/kasan/common.c:436 mm/kasan/common.c:469)\n kmem_cache_alloc_node (mm/slab.h:750 mm/slub.c:3243 mm/slub.c:3293)\n __alloc_skb (net/core/skbuff.c:414)\n l2cap_recv_frag (./include/net/bluetooth/bluetooth.h:425 net/bluetooth/l2cap_core.c:8329) bluetooth\n l2cap_recv_acldata (net/bluetooth/l2cap_core.c:8442) bluetooth\n hci_rx_work (net/bluetooth/hci_core.c:3642 net/bluetooth/hci_core.c:3832) bluetooth\n process_one_work (kernel/workqueue.c:2289)\n worker_thread (./include/linux/list.h:292 kernel/workqueue.c:2437)\n kthread (kernel/kthread.c:376)\n ret_from_fork (arch/x86/entry/entry_64.S:306)\n\nFreed by task 27920:\n kasan_save_stack (mm/kasan/common.c:39)\n kasan_set_track (mm/kasan/common.c:45)\n kasan_set_free_info (mm/kasan/generic.c:372)\n ____kasan_slab_free (mm/kasan/common.c:368 mm/kasan/common.c:328)\n slab_free_freelist_hook (mm/slub.c:1780)\n kmem_cache_free (mm/slub.c:3536 mm/slub.c:3553)\n skb_free_datagram (./include/net/sock.h:1578 ./include/net/sock.h:1639 net/core/datagram.c:323)\n bt_sock_recvmsg (net/bluetooth/af_bluetooth.c:295) bluetooth\n l2cap_sock_recvmsg (net/bluetooth/l2cap_sock.c:1212) bluetooth\n sock_read_iter (net/socket.c:1087)\n new_sync_read (./include/linux/fs.h:2052 fs/read_write.c:401)\n vfs_read (fs/read_write.c:482)\n ksys_read (fs/read_write.c:620)\n do_syscall_64 (arch/x86/entry/common.c:50 arch/x86/entry/common.c:80)\n entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:120)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49910" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/03af22e23b96fb7ef75fb7885407ef457e8b403d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3aff8aaca4e36dc8b17eaa011684881a80238966" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4cd094fd5d872862ca278e15b9b51b07e915ef3f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6c7407bfbeafc80a04e6eaedcf34d378532a04f2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8278a87bb1eeea94350d675ef961ee5a03341fde" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9a04161244603f502c6e453913e51edd59cb70c1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cb1c012099ef5904cd468bdb8d6fcdfdd9bcb569" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/dc30e05bb18852303084430c03ca76e69257d9ea" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-3x3q-3c9j-4x72/GHSA-3x3q-3c9j-4x72.json b/advisories/unreviewed/2025/05/GHSA-3x3q-3c9j-4x72/GHSA-3x3q-3c9j-4x72.json new file mode 100644 index 00000000000..41676909f03 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-3x3q-3c9j-4x72/GHSA-3x3q-3c9j-4x72.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3x3q-3c9j-4x72", + "modified": "2025-05-01T15:31:47Z", + "published": "2025-05-01T15:31:47Z", + "aliases": [ + "CVE-2022-49790" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nInput: iforce - invert valid length check when fetching device IDs\n\nsyzbot is reporting uninitialized value at iforce_init_device() [1], for\ncommit 6ac0aec6b0a6 (\"Input: iforce - allow callers supply data buffer\nwhen fetching device IDs\") is checking that valid length is shorter than\nbytes to read. Since iforce_get_id_packet() stores valid length when\nreturning 0, the caller needs to check that valid length is longer than or\nequals to bytes to read.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49790" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/24cc679abbf31477d0cc6106ec83c2fbae6b3cdf" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5d53797ce7ce8fb1d95a5bebc5efa9418c4217a3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6365569d62a75ddf53fb0c2936c16587a365984c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b8ebf250997c5fb253582f42bfe98673801ebebd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fdd57c20d4408cac3c3c535c120d244e083406c9" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-3x6x-q36v-32gj/GHSA-3x6x-q36v-32gj.json b/advisories/unreviewed/2025/05/GHSA-3x6x-q36v-32gj/GHSA-3x6x-q36v-32gj.json new file mode 100644 index 00000000000..e754a0ef065 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-3x6x-q36v-32gj/GHSA-3x6x-q36v-32gj.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3x6x-q36v-32gj", + "modified": "2025-05-01T15:31:51Z", + "published": "2025-05-01T15:31:51Z", + "aliases": [ + "CVE-2022-49883" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: x86: smm: number of GPRs in the SMRAM image depends on the image format\n\nOn 64 bit host, if the guest doesn't have X86_FEATURE_LM, KVM will\naccess 16 gprs to 32-bit smram image, causing out-ouf-bound ram\naccess.\n\nOn 32 bit host, the rsm_load_state_64/enter_smm_save_state_64\nis compiled out, thus access overflow can't happen.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49883" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/696db303e54f7352623d9f640e6c51d8fa9d5588" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a7ebfbea0f52550d7cdf12c38f3f5eaa7b2b6494" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-43gf-2x57-fwxf/GHSA-43gf-2x57-fwxf.json b/advisories/unreviewed/2025/05/GHSA-43gf-2x57-fwxf/GHSA-43gf-2x57-fwxf.json new file mode 100644 index 00000000000..8474c79eeb5 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-43gf-2x57-fwxf/GHSA-43gf-2x57-fwxf.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-43gf-2x57-fwxf", + "modified": "2025-05-01T15:31:43Z", + "published": "2025-05-01T15:31:43Z", + "aliases": [ + "CVE-2025-37762" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/virtio: Fix missed dmabuf unpinning in error path of prepare_fb()\n\nCorrect error handling in prepare_fb() to fix leaking resources when\nerror happens.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37762" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/395cc80051f8da267b27496a4029dd931a198855" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fe983e925bf7062d7b975357afcbc77bb7f354d8" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T14:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-43jc-vxjx-v42r/GHSA-43jc-vxjx-v42r.json b/advisories/unreviewed/2025/05/GHSA-43jc-vxjx-v42r/GHSA-43jc-vxjx-v42r.json new file mode 100644 index 00000000000..71259b50e5b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-43jc-vxjx-v42r/GHSA-43jc-vxjx-v42r.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-43jc-vxjx-v42r", + "modified": "2025-05-01T15:31:40Z", + "published": "2025-05-01T15:31:40Z", + "aliases": [ + "CVE-2025-23146" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmfd: ene-kb3930: Fix a potential NULL pointer dereference\n\nThe off_gpios could be NULL. Add missing check in the kb3930_probe().\nThis is similar to the issue fixed in commit b1ba8bcb2d1f\n(\"backlight: hx8357: Fix potential NULL pointer dereference\").\n\nThis was detected by our static analysis tool.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23146" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2edb5b29b197d90b4d08cd45e911c0bcf24cb895" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4cdf1d2a816a93fa02f7b6b5492dc7f55af2a199" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/76d0f4199bc5b51acb7b96c6663a8953543733ad" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7b47df6498f223c8956bfe0d994a0e42a520dfcd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b1758417310d2cc77e52cd15103497e52e2614f6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ea07760676bba49319d553af80c239da053b5fb1" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T13:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-4485-mg4q-xjgv/GHSA-4485-mg4q-xjgv.json b/advisories/unreviewed/2025/05/GHSA-4485-mg4q-xjgv/GHSA-4485-mg4q-xjgv.json new file mode 100644 index 00000000000..9aee99110ff --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4485-mg4q-xjgv/GHSA-4485-mg4q-xjgv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4485-mg4q-xjgv", + "modified": "2025-05-01T15:31:43Z", + "published": "2025-05-01T15:31:43Z", + "aliases": [ + "CVE-2025-23254" + ], + "details": "NVIDIA TensorRT-LLM for any platform contains a vulnerability in python executor where an attacker may cause a data validation issue by local access to the TRTLLM server. A successful exploit of this vulnerability may lead to code execution, information disclosure and data tampering.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23254" + }, + { + "type": "WEB", + "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5648" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T14:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-45gw-fx24-h4pv/GHSA-45gw-fx24-h4pv.json b/advisories/unreviewed/2025/05/GHSA-45gw-fx24-h4pv/GHSA-45gw-fx24-h4pv.json new file mode 100644 index 00000000000..b801937efd8 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-45gw-fx24-h4pv/GHSA-45gw-fx24-h4pv.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-45gw-fx24-h4pv", + "modified": "2025-05-01T15:31:44Z", + "published": "2025-05-01T15:31:44Z", + "aliases": [ + "CVE-2025-37778" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: Fix dangling pointer in krb_authenticate\n\nkrb_authenticate frees sess->user and does not set the pointer\nto NULL. It calls ksmbd_krb5_authenticate to reinitialise\nsess->user but that function may return without doing so. If\nthat happens then smb2_sess_setup, which calls krb_authenticate,\nwill be accessing free'd memory when it later uses sess->user.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37778" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1db2451de23e98bc864c6a6e52aa0d82c91cb325" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1e440d5b25b7efccb3defe542a73c51005799a5f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6e30c0e10210c714f3d4453dc258d4abcc70364e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d5b554bc8d554ed6ddf443d3db2fad9f665cec10" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e83e39a5f6a01a81411a4558a59a10f87aa88dd6" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T14:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-4748-h423-7xq4/GHSA-4748-h423-7xq4.json b/advisories/unreviewed/2025/05/GHSA-4748-h423-7xq4/GHSA-4748-h423-7xq4.json new file mode 100644 index 00000000000..5fed15b2d0d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4748-h423-7xq4/GHSA-4748-h423-7xq4.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4748-h423-7xq4", + "modified": "2025-05-01T15:31:44Z", + "published": "2025-05-01T15:31:44Z", + "aliases": [ + "CVE-2025-37777" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix use-after-free in __smb2_lease_break_noti()\n\nMove tcp_transport free to ksmbd_conn_free. If ksmbd connection is\nreferenced when ksmbd server thread terminates, It will not be freed,\nbut conn->tcp_transport is freed. __smb2_lease_break_noti can be performed\nasynchronously when the connection is disconnected. __smb2_lease_break_noti\ncalls ksmbd_conn_write, which can cause use-after-free\nwhen conn->ksmbd_transport is already freed.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37777" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/21a4e47578d44c6b37c4fc4aba8ed7cc8dbb13de" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e59796fc80603bcd8569d4d2e10b213c1918edb4" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T14:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-4g9q-6gcq-f3vx/GHSA-4g9q-6gcq-f3vx.json b/advisories/unreviewed/2025/05/GHSA-4g9q-6gcq-f3vx/GHSA-4g9q-6gcq-f3vx.json new file mode 100644 index 00000000000..298eb4e3342 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4g9q-6gcq-f3vx/GHSA-4g9q-6gcq-f3vx.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4g9q-6gcq-f3vx", + "modified": "2025-05-01T15:31:51Z", + "published": "2025-05-01T15:31:51Z", + "aliases": [ + "CVE-2022-49891" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: kprobe: Fix memory leak in test_gen_kprobe/kretprobe_cmd()\n\ntest_gen_kprobe_cmd() only free buf in fail path, hence buf will leak\nwhen there is no failure. Move kfree(buf) from fail path to common path\nto prevent the memleak. The same reason and solution in\ntest_gen_kretprobe_cmd().\n\nunreferenced object 0xffff888143b14000 (size 2048):\n comm \"insmod\", pid 52490, jiffies 4301890980 (age 40.553s)\n hex dump (first 32 bytes):\n 70 3a 6b 70 72 6f 62 65 73 2f 67 65 6e 5f 6b 70 p:kprobes/gen_kp\n 72 6f 62 65 5f 74 65 73 74 20 64 6f 5f 73 79 73 robe_test do_sys\n backtrace:\n [<000000006d7b836b>] kmalloc_trace+0x27/0xa0\n [<0000000009528b5b>] 0xffffffffa059006f\n [<000000008408b580>] do_one_initcall+0x87/0x2a0\n [<00000000c4980a7e>] do_init_module+0xdf/0x320\n [<00000000d775aad0>] load_module+0x3006/0x3390\n [<00000000e9a74b80>] __do_sys_finit_module+0x113/0x1b0\n [<000000003726480d>] do_syscall_64+0x35/0x80\n [<000000003441e93b>] entry_SYSCALL_64_after_hwframe+0x46/0xb0", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49891" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/66f0919c953ef7b55e5ab94389a013da2ce80a2c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/71aeb8d01a8c7ab5cf7da3f81b35206f56ce6bca" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bef08acbe560a926b4cee9cc46404cc98ae5703b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d1b6a8e3414aeaa0985139180c145d2d0fbd2a49" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-4jf5-7pvp-xf23/GHSA-4jf5-7pvp-xf23.json b/advisories/unreviewed/2025/05/GHSA-4jf5-7pvp-xf23/GHSA-4jf5-7pvp-xf23.json new file mode 100644 index 00000000000..209c8674068 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4jf5-7pvp-xf23/GHSA-4jf5-7pvp-xf23.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4jf5-7pvp-xf23", + "modified": "2025-05-01T15:31:45Z", + "published": "2025-05-01T15:31:45Z", + "aliases": [ + "CVE-2025-37791" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nethtool: cmis_cdb: use correct rpl size in ethtool_cmis_module_poll()\n\nrpl is passed as a pointer to ethtool_cmis_module_poll(), so the correct\nsize of rpl is sizeof(*rpl) which should be just 1 byte. Using the\npointer size instead can cause stack corruption:\n\nKernel panic - not syncing: stack-protector: Kernel stack is corrupted in: ethtool_cmis_wait_for_cond+0xf4/0x100\nCPU: 72 UID: 0 PID: 4440 Comm: kworker/72:2 Kdump: loaded Tainted: G OE 6.11.0 #24\nTainted: [O]=OOT_MODULE, [E]=UNSIGNED_MODULE\nHardware name: Dell Inc. PowerEdge R760/04GWWM, BIOS 1.6.6 09/20/2023\nWorkqueue: events module_flash_fw_work\nCall Trace:\n \n panic+0x339/0x360\n ? ethtool_cmis_wait_for_cond+0xf4/0x100\n ? __pfx_status_success+0x10/0x10\n ? __pfx_status_fail+0x10/0x10\n __stack_chk_fail+0x10/0x10\n ethtool_cmis_wait_for_cond+0xf4/0x100\n ethtool_cmis_cdb_execute_cmd+0x1fc/0x330\n ? __pfx_status_fail+0x10/0x10\n cmis_cdb_module_features_get+0x6d/0xd0\n ethtool_cmis_cdb_init+0x8a/0xd0\n ethtool_cmis_fw_update+0x46/0x1d0\n module_flash_fw_work+0x17/0xa0\n process_one_work+0x179/0x390\n worker_thread+0x239/0x340\n ? __pfx_worker_thread+0x10/0x10\n kthread+0xcc/0x100\n ? __pfx_kthread+0x10/0x10\n ret_from_fork+0x2d/0x50\n ? __pfx_kthread+0x10/0x10\n ret_from_fork_asm+0x1a/0x30\n ", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37791" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/61765e1b417a23371c3735e3cddf4ad9354ed2e9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7eb0a0072f966bb0b01d8b7d529d9743a7187bd1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f3fdd4fba16c74697d8bc730b82fb7c1eff7fab3" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T14:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-4jq9-rx3w-p8vg/GHSA-4jq9-rx3w-p8vg.json b/advisories/unreviewed/2025/05/GHSA-4jq9-rx3w-p8vg/GHSA-4jq9-rx3w-p8vg.json new file mode 100644 index 00000000000..84e2d155a23 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4jq9-rx3w-p8vg/GHSA-4jq9-rx3w-p8vg.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4jq9-rx3w-p8vg", + "modified": "2025-05-01T15:31:49Z", + "published": "2025-05-01T15:31:49Z", + "aliases": [ + "CVE-2022-49836" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsiox: fix possible memory leak in siox_device_add()\n\nIf device_register() returns error in siox_device_add(),\nthe name allocated by dev_set_name() need be freed. As\ncomment of device_register() says, it should use put_device()\nto give up the reference in the error path. So fix this\nby calling put_device(), then the name can be freed in\nkobject_cleanup(), and sdevice is freed in siox_device_release(),\nset it to null in error path.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49836" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0a5da069603ecc3d7aa09167450235462adaa295" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5d03c2911c529ea4d6ebfec53425f1091e8d402b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6e63153db50059fb78b8a8447b132664887d24e3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a4b5423f88a17a36550ae8c16c46779b1ee42f4b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d9c31e728843259209fb530c59995e4fe262699f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f9fe7ba4ea5b24ffdf8e125f660aca3ba4a147fb" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-4m85-4x3p-6jmv/GHSA-4m85-4x3p-6jmv.json b/advisories/unreviewed/2025/05/GHSA-4m85-4x3p-6jmv/GHSA-4m85-4x3p-6jmv.json new file mode 100644 index 00000000000..58228a681f2 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4m85-4x3p-6jmv/GHSA-4m85-4x3p-6jmv.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4m85-4x3p-6jmv", + "modified": "2025-05-01T15:31:51Z", + "published": "2025-05-01T15:31:51Z", + "aliases": [ + "CVE-2022-49884" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: Initialize gfn_to_pfn_cache locks in dedicated helper\n\nMove the gfn_to_pfn_cache lock initialization to another helper and\ncall the new helper during VM/vCPU creation. There are race\nconditions possible due to kvm_gfn_to_pfn_cache_init()'s\nability to re-initialize the cache's locks.\n\nFor example: a race between ioctl(KVM_XEN_HVM_EVTCHN_SEND) and\nkvm_gfn_to_pfn_cache_init() leads to a corrupted shinfo gpc lock.\n\n (thread 1) | (thread 2)\n |\n kvm_xen_set_evtchn_fast |\n read_lock_irqsave(&gpc->lock, ...) |\n | kvm_gfn_to_pfn_cache_init\n | rwlock_init(&gpc->lock)\n read_unlock_irqrestore(&gpc->lock, ...) |\n\nRename \"cache_init\" and \"cache_destroy\" to activate+deactivate to\navoid implying that the cache really is destroyed/freed.\n\nNote, there more races in the newly named kvm_gpc_activate() that will\nbe addressed separately.\n\n[sean: call out that this is a bug fix]", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49884" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/52491a38b2c2411f3f0229dc6ad610349c704a41" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/61242001d6c9c253df7645dab090842d8da08764" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-4m98-x48v-hh97/GHSA-4m98-x48v-hh97.json b/advisories/unreviewed/2025/05/GHSA-4m98-x48v-hh97/GHSA-4m98-x48v-hh97.json new file mode 100644 index 00000000000..aa6aadfddd0 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4m98-x48v-hh97/GHSA-4m98-x48v-hh97.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4m98-x48v-hh97", + "modified": "2025-05-01T15:31:48Z", + "published": "2025-05-01T15:31:48Z", + "aliases": [ + "CVE-2022-49813" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ena: Fix error handling in ena_init()\n\nThe ena_init() won't destroy workqueue created by\ncreate_singlethread_workqueue() when pci_register_driver() failed.\nCall destroy_workqueue() when pci_register_driver() failed to prevent the\nresource leak.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49813" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0e2369223b174d198ec42a3ec0a7f06c8727b968" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3f7b2ef8fe924e299bc339811ea3f1b9935c040f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6b23a4b252044e4fd23438930d452244818d7000" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d349e9be5a2c2d7588a2c4e4bfa0bb3dc1226769" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-4pmq-325h-rx32/GHSA-4pmq-325h-rx32.json b/advisories/unreviewed/2025/05/GHSA-4pmq-325h-rx32/GHSA-4pmq-325h-rx32.json new file mode 100644 index 00000000000..e8714ff16d2 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4pmq-325h-rx32/GHSA-4pmq-325h-rx32.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4pmq-325h-rx32", + "modified": "2025-05-01T15:31:52Z", + "published": "2025-05-01T15:31:52Z", + "aliases": [ + "CVE-2022-49906" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nibmvnic: Free rwi on reset success\n\nFree the rwi structure in the event that the last rwi in the list\nprocessed successfully. The logic in commit 4f408e1fa6e1 (\"ibmvnic:\nretry reset if there are no other resets\") introduces an issue that\nresults in a 32 byte memory leak whenever the last rwi in the list\ngets processed.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49906" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/535b78739ae75f257c894a05b1afa86ad9a3669e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c3543a287cfba9105dcc4bb41eb817f51266caaf" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d6dd2fe71153f0ff748bf188bd4af076fe09a0a6" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-4vff-8c4j-m2j6/GHSA-4vff-8c4j-m2j6.json b/advisories/unreviewed/2025/05/GHSA-4vff-8c4j-m2j6/GHSA-4vff-8c4j-m2j6.json new file mode 100644 index 00000000000..205853f1b47 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4vff-8c4j-m2j6/GHSA-4vff-8c4j-m2j6.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4vff-8c4j-m2j6", + "modified": "2025-05-01T15:31:49Z", + "published": "2025-05-01T15:31:49Z", + "aliases": [ + "CVE-2022-49831" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: zoned: initialize device's zone info for seeding\n\nWhen performing seeding on a zoned filesystem it is necessary to\ninitialize each zoned device's btrfs_zoned_device_info structure,\notherwise mounting the filesystem will cause a NULL pointer dereference.\n\nThis was uncovered by fstests' testcase btrfs/163.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49831" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/544f38a738343d7e75f104e5e9d1ade58d8b71bd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/91c38504e589dadbcde47b1cacdfc5b684154d44" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a8d1b1647bf8244a5f270538e9e636e2657fffa3" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-4vrr-6gm8-fwf2/GHSA-4vrr-6gm8-fwf2.json b/advisories/unreviewed/2025/05/GHSA-4vrr-6gm8-fwf2/GHSA-4vrr-6gm8-fwf2.json new file mode 100644 index 00000000000..a4b03861cdb --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4vrr-6gm8-fwf2/GHSA-4vrr-6gm8-fwf2.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4vrr-6gm8-fwf2", + "modified": "2025-05-01T15:31:48Z", + "published": "2025-05-01T15:31:48Z", + "aliases": [ + "CVE-2022-49823" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nata: libata-transport: fix error handling in ata_tdev_add()\n\nIn ata_tdev_add(), the return value of transport_add_device() is\nnot checked. As a result, it causes null-ptr-deref while removing\nthe module, because transport_remove_device() is called to remove\nthe device that was not added.\n\nUnable to handle kernel NULL pointer dereference at virtual address 00000000000000d0\nCPU: 13 PID: 13603 Comm: rmmod Kdump: loaded Tainted: G W 6.1.0-rc3+ #36\npstate: 60400009 (nZCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)\npc : device_del+0x48/0x3a0\nlr : device_del+0x44/0x3a0\nCall trace:\n device_del+0x48/0x3a0\n attribute_container_class_device_del+0x28/0x40\n transport_remove_classdev+0x60/0x7c\n attribute_container_device_trigger+0x118/0x120\n transport_remove_device+0x20/0x30\n ata_tdev_delete+0x24/0x50 [libata]\n ata_tlink_delete+0x40/0xa0 [libata]\n ata_tport_delete+0x2c/0x60 [libata]\n ata_port_detach+0x148/0x1b0 [libata]\n ata_pci_remove_one+0x50/0x80 [libata]\n ahci_remove_one+0x4c/0x8c [ahci]\n\nFix this by checking and handling return value of transport_add_device()\nin ata_tdev_add(). In the error path, device_del() is called to delete\nthe device which was added earlier in this function, and ata_tdev_free()\nis called to free ata_dev.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49823" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1ff36351309e3eadcff297480baf4785e726de9b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ef2ac07ab83163b9a53f45da20e14302591ad9cc" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f23058dc2398db1d8faca9a2b1ce30b85cdd8b22" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f54331962883f4fc4bf5e487e6e7cf07c4567fef" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-4whg-gh4g-7j3j/GHSA-4whg-gh4g-7j3j.json b/advisories/unreviewed/2025/05/GHSA-4whg-gh4g-7j3j/GHSA-4whg-gh4g-7j3j.json new file mode 100644 index 00000000000..89134e2d9e3 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4whg-gh4g-7j3j/GHSA-4whg-gh4g-7j3j.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4whg-gh4g-7j3j", + "modified": "2025-05-01T15:31:50Z", + "published": "2025-05-01T15:31:50Z", + "aliases": [ + "CVE-2022-49856" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: tun: call napi_schedule_prep() to ensure we own a napi\n\nA recent patch exposed another issue in napi_get_frags()\ncaught by syzbot [1]\n\nBefore feeding packets to GRO, and calling napi_complete()\nwe must first grab NAPI_STATE_SCHED.\n\n[1]\nWARNING: CPU: 0 PID: 3612 at net/core/dev.c:6076 napi_complete_done+0x45b/0x880 net/core/dev.c:6076\nModules linked in:\nCPU: 0 PID: 3612 Comm: syz-executor408 Not tainted 6.1.0-rc3-syzkaller-00175-g1118b2049d77 #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/26/2022\nRIP: 0010:napi_complete_done+0x45b/0x880 net/core/dev.c:6076\nCode: c1 ea 03 0f b6 14 02 4c 89 f0 83 e0 07 83 c0 03 38 d0 7c 08 84 d2 0f 85 24 04 00 00 41 89 5d 1c e9 73 fc ff ff e8 b5 53 22 fa <0f> 0b e9 82 fe ff ff e8 a9 53 22 fa 48 8b 5c 24 08 31 ff 48 89 de\nRSP: 0018:ffffc90003c4f920 EFLAGS: 00010293\nRAX: 0000000000000000 RBX: 0000000000000030 RCX: 0000000000000000\nRDX: ffff8880251c0000 RSI: ffffffff875a58db RDI: 0000000000000007\nRBP: 0000000000000001 R08: 0000000000000007 R09: 0000000000000000\nR10: 0000000000000001 R11: 0000000000000001 R12: ffff888072d02628\nR13: ffff888072d02618 R14: ffff888072d02634 R15: 0000000000000000\nFS: 0000555555f13300(0000) GS:ffff8880b9a00000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 000055c44d3892b8 CR3: 00000000172d2000 CR4: 00000000003506f0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nCall Trace:\n\nnapi_complete include/linux/netdevice.h:510 [inline]\ntun_get_user+0x206d/0x3a60 drivers/net/tun.c:1980\ntun_chr_write_iter+0xdb/0x200 drivers/net/tun.c:2027\ncall_write_iter include/linux/fs.h:2191 [inline]\ndo_iter_readv_writev+0x20b/0x3b0 fs/read_write.c:735\ndo_iter_write+0x182/0x700 fs/read_write.c:861\nvfs_writev+0x1aa/0x630 fs/read_write.c:934\ndo_writev+0x133/0x2f0 fs/read_write.c:977\ndo_syscall_x64 arch/x86/entry/common.c:50 [inline]\ndo_syscall_64+0x35/0xb0 arch/x86/entry/common.c:80\nentry_SYSCALL_64_after_hwframe+0x63/0xcd\nRIP: 0033:0x7f37021a3c19", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49856" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/07d120aa33cc9d9115753d159f64d20c94458781" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/30b0263d0366ea63aa7cad0407dfd945cc348580" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/310f0855352ee4b2eb38855c99185c23e6e1496b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/534762e261c84d43e5d56a780e40278b94c20540" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9132fa043f96ac545254ab326db5c6fd47d54acb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/999550c8cbb3fcb535f542d652fe1cb936839e5f" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-4xp6-cpfv-9qq6/GHSA-4xp6-cpfv-9qq6.json b/advisories/unreviewed/2025/05/GHSA-4xp6-cpfv-9qq6/GHSA-4xp6-cpfv-9qq6.json new file mode 100644 index 00000000000..1107b89bcba --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4xp6-cpfv-9qq6/GHSA-4xp6-cpfv-9qq6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4xp6-cpfv-9qq6", + "modified": "2025-05-01T15:31:43Z", + "published": "2025-05-01T15:31:43Z", + "aliases": [ + "CVE-2024-52976" + ], + "details": "Inclusion of functionality from an untrusted control sphere in Elastic Agent subprocess, osqueryd, allows local attackers to execute arbitrary code via parameter injection.\n\nAn attacker requires local access and the ability to modify osqueryd configurations.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52976" + }, + { + "type": "WEB", + "url": "https://discuss.elastic.co/t/elastic-agent-7-17-25-and-8-15-4-security-update-esa-2024-39/377708" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-829" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T14:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-52fr-53gv-g23j/GHSA-52fr-53gv-g23j.json b/advisories/unreviewed/2025/05/GHSA-52fr-53gv-g23j/GHSA-52fr-53gv-g23j.json new file mode 100644 index 00000000000..341c5805202 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-52fr-53gv-g23j/GHSA-52fr-53gv-g23j.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-52fr-53gv-g23j", + "modified": "2025-05-01T15:31:52Z", + "published": "2025-05-01T15:31:52Z", + "aliases": [ + "CVE-2022-49897" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfscrypt: fix keyring memory leak on mount failure\n\nCommit d7e7b9af104c (\"fscrypt: stop using keyrings subsystem for\nfscrypt_master_key\") moved the keyring destruction from __put_super() to\ngeneric_shutdown_super() so that the filesystem's block device(s) are\nstill available. Unfortunately, this causes a memory leak in the case\nwhere a mount is attempted with the test_dummy_encryption mount option,\nbut the mount fails after the option has already been processed.\n\nTo fix this, attempt the keyring destruction in both places.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49897" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0b1747653b102c555bac745ebe5ca86cdd20e43f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/29997a6fa60de1de2fa0de471e7652efa6e95868" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ccd30a476f8e864732de220bd50e6f372f5ebcab" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cff805b1518f38d57866065343db2285f2dcd5ab" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-52wf-qx53-m2m5/GHSA-52wf-qx53-m2m5.json b/advisories/unreviewed/2025/05/GHSA-52wf-qx53-m2m5/GHSA-52wf-qx53-m2m5.json new file mode 100644 index 00000000000..037da36cf34 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-52wf-qx53-m2m5/GHSA-52wf-qx53-m2m5.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-52wf-qx53-m2m5", + "modified": "2025-05-01T15:31:46Z", + "published": "2025-05-01T15:31:46Z", + "aliases": [ + "CVE-2022-49775" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: cdg: allow tcp_cdg_release() to be called multiple times\n\nApparently, mptcp is able to call tcp_disconnect() on an already\ndisconnected flow. This is generally fine, unless current congestion\ncontrol is CDG, because it might trigger a double-free [1]\n\nInstead of fixing MPTCP, and future bugs, we can make tcp_disconnect()\nmore resilient.\n\n[1]\nBUG: KASAN: double-free in slab_free mm/slub.c:3539 [inline]\nBUG: KASAN: double-free in kfree+0xe2/0x580 mm/slub.c:4567\n\nCPU: 0 PID: 3645 Comm: kworker/0:7 Not tainted 6.0.0-syzkaller-02734-g0326074ff465 #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/22/2022\nWorkqueue: events mptcp_worker\nCall Trace:\n\n__dump_stack lib/dump_stack.c:88 [inline]\ndump_stack_lvl+0xcd/0x134 lib/dump_stack.c:106\nprint_address_description mm/kasan/report.c:317 [inline]\nprint_report.cold+0x2ba/0x719 mm/kasan/report.c:433\nkasan_report_invalid_free+0x81/0x190 mm/kasan/report.c:462\n____kasan_slab_free+0x18b/0x1c0 mm/kasan/common.c:356\nkasan_slab_free include/linux/kasan.h:200 [inline]\nslab_free_hook mm/slub.c:1759 [inline]\nslab_free_freelist_hook+0x8b/0x1c0 mm/slub.c:1785\nslab_free mm/slub.c:3539 [inline]\nkfree+0xe2/0x580 mm/slub.c:4567\ntcp_disconnect+0x980/0x1e20 net/ipv4/tcp.c:3145\n__mptcp_close_ssk+0x5ca/0x7e0 net/mptcp/protocol.c:2327\nmptcp_do_fastclose net/mptcp/protocol.c:2592 [inline]\nmptcp_worker+0x78c/0xff0 net/mptcp/protocol.c:2627\nprocess_one_work+0x991/0x1610 kernel/workqueue.c:2289\nworker_thread+0x665/0x1080 kernel/workqueue.c:2436\nkthread+0x2e4/0x3a0 kernel/kthread.c:376\nret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:306\n\n\nAllocated by task 3671:\nkasan_save_stack+0x1e/0x40 mm/kasan/common.c:38\nkasan_set_track mm/kasan/common.c:45 [inline]\nset_alloc_info mm/kasan/common.c:437 [inline]\n____kasan_kmalloc mm/kasan/common.c:516 [inline]\n____kasan_kmalloc mm/kasan/common.c:475 [inline]\n__kasan_kmalloc+0xa9/0xd0 mm/kasan/common.c:525\nkmalloc_array include/linux/slab.h:640 [inline]\nkcalloc include/linux/slab.h:671 [inline]\ntcp_cdg_init+0x10d/0x170 net/ipv4/tcp_cdg.c:380\ntcp_init_congestion_control+0xab/0x550 net/ipv4/tcp_cong.c:193\ntcp_reinit_congestion_control net/ipv4/tcp_cong.c:217 [inline]\ntcp_set_congestion_control+0x96c/0xaa0 net/ipv4/tcp_cong.c:391\ndo_tcp_setsockopt+0x505/0x2320 net/ipv4/tcp.c:3513\ntcp_setsockopt+0xd4/0x100 net/ipv4/tcp.c:3801\nmptcp_setsockopt+0x35f/0x2570 net/mptcp/sockopt.c:844\n__sys_setsockopt+0x2d6/0x690 net/socket.c:2252\n__do_sys_setsockopt net/socket.c:2263 [inline]\n__se_sys_setsockopt net/socket.c:2260 [inline]\n__x64_sys_setsockopt+0xba/0x150 net/socket.c:2260\ndo_syscall_x64 arch/x86/entry/common.c:50 [inline]\ndo_syscall_64+0x35/0xb0 arch/x86/entry/common.c:80\nentry_SYSCALL_64_after_hwframe+0x63/0xcd\n\nFreed by task 16:\nkasan_save_stack+0x1e/0x40 mm/kasan/common.c:38\nkasan_set_track+0x21/0x30 mm/kasan/common.c:45\nkasan_set_free_info+0x20/0x30 mm/kasan/generic.c:370\n____kasan_slab_free mm/kasan/common.c:367 [inline]\n____kasan_slab_free+0x166/0x1c0 mm/kasan/common.c:329\nkasan_slab_free include/linux/kasan.h:200 [inline]\nslab_free_hook mm/slub.c:1759 [inline]\nslab_free_freelist_hook+0x8b/0x1c0 mm/slub.c:1785\nslab_free mm/slub.c:3539 [inline]\nkfree+0xe2/0x580 mm/slub.c:4567\ntcp_cleanup_congestion_control+0x70/0x120 net/ipv4/tcp_cong.c:226\ntcp_v4_destroy_sock+0xdd/0x750 net/ipv4/tcp_ipv4.c:2254\ntcp_v6_destroy_sock+0x11/0x20 net/ipv6/tcp_ipv6.c:1969\ninet_csk_destroy_sock+0x196/0x440 net/ipv4/inet_connection_sock.c:1157\ntcp_done+0x23b/0x340 net/ipv4/tcp.c:4649\ntcp_rcv_state_process+0x40e7/0x4990 net/ipv4/tcp_input.c:6624\ntcp_v6_do_rcv+0x3fc/0x13c0 net/ipv6/tcp_ipv6.c:1525\ntcp_v6_rcv+0x2e8e/0x3830 net/ipv6/tcp_ipv6.c:1759\nip6_protocol_deliver_rcu+0x2db/0x1950 net/ipv6/ip6_input.c:439\nip6_input_finish+0x14c/0x2c0 net/ipv6/ip6_input.c:484\nNF_HOOK include/linux/netfilter.h:302 [inline]\nNF_HOOK include/linux/netfilter.h:296 [inline]\nip6_input+0x9c/0xd\n---truncated---", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49775" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0b19171439016a8e4c97eafe543670ac86e2b8fe" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1b639be27cbf428a5ca01dcf8b5d654194c956f8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/35309be06b6feded2ab2cafbc2bca8534c2fa41e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4026033907cc6186d86b48daa4a252c860db2536" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/72e560cb8c6f80fc2b4afc5d3634a32465e13a51" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/78be2ee0112409ae4e9ee9e326151e0559b3d239" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9e481d87349d2282f400ee1d010a169c99f766b8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b49026d9c86f35a4c5bfb8d7345c9c4379828c6b" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-53c5-74px-fwch/GHSA-53c5-74px-fwch.json b/advisories/unreviewed/2025/05/GHSA-53c5-74px-fwch/GHSA-53c5-74px-fwch.json new file mode 100644 index 00000000000..11f9bd5caec --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-53c5-74px-fwch/GHSA-53c5-74px-fwch.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-53c5-74px-fwch", + "modified": "2025-05-01T15:31:40Z", + "published": "2025-05-01T15:31:40Z", + "aliases": [ + "CVE-2025-23151" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbus: mhi: host: Fix race between unprepare and queue_buf\n\nA client driver may use mhi_unprepare_from_transfer() to quiesce\nincoming data during the client driver's tear down. The client driver\nmight also be processing data at the same time, resulting in a call to\nmhi_queue_buf() which will invoke mhi_gen_tre(). If mhi_gen_tre() runs\nafter mhi_unprepare_from_transfer() has torn down the channel, a panic\nwill occur due to an invalid dereference leading to a page fault.\n\nThis occurs because mhi_gen_tre() does not verify the channel state\nafter locking it. Fix this by having mhi_gen_tre() confirm the channel\nstate is valid, or return error to avoid accessing deinitialized data.\n\n[mani: added stable tag]", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23151" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0686a818d77a431fc3ba2fab4b46bbb04e8c9380" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/178e5657c8fd285125cc6743a81b513bce099760" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3e7ecf181cbdde9753204ada3883ca1704d8702b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5f084993c90d9d0b4a52a349ede5120f992a7ca1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a77955f7704b2a00385e232cbcc1cb06b5c7a425" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ee1fce83ed56450087309b9b74ad9bcb2b010fa6" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T13:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-54j7-px5q-9wrr/GHSA-54j7-px5q-9wrr.json b/advisories/unreviewed/2025/05/GHSA-54j7-px5q-9wrr/GHSA-54j7-px5q-9wrr.json new file mode 100644 index 00000000000..b1596a39650 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-54j7-px5q-9wrr/GHSA-54j7-px5q-9wrr.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-54j7-px5q-9wrr", + "modified": "2025-05-01T15:31:46Z", + "published": "2025-05-01T15:31:46Z", + "aliases": [ + "CVE-2022-49778" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\narm64/mm: fix incorrect file_map_count for non-leaf pmd/pud\n\nThe page table check trigger BUG_ON() unexpectedly when collapse hugepage:\n\n ------------[ cut here ]------------\n kernel BUG at mm/page_table_check.c:82!\n Internal error: Oops - BUG: 00000000f2000800 [#1] SMP\n Dumping ftrace buffer:\n (ftrace buffer empty)\n Modules linked in:\n CPU: 6 PID: 68 Comm: khugepaged Not tainted 6.1.0-rc3+ #750\n Hardware name: linux,dummy-virt (DT)\n pstate: 60000005 (nZCv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n pc : page_table_check_clear.isra.0+0x258/0x3f0\n lr : page_table_check_clear.isra.0+0x240/0x3f0\n[...]\n Call trace:\n page_table_check_clear.isra.0+0x258/0x3f0\n __page_table_check_pmd_clear+0xbc/0x108\n pmdp_collapse_flush+0xb0/0x160\n collapse_huge_page+0xa08/0x1080\n hpage_collapse_scan_pmd+0xf30/0x1590\n khugepaged_scan_mm_slot.constprop.0+0x52c/0xac8\n khugepaged+0x338/0x518\n kthread+0x278/0x2f8\n ret_from_fork+0x10/0x20\n[...]\n\nSince pmd_user_accessible_page() doesn't check if a pmd is leaf, it\ndecrease file_map_count for a non-leaf pmd comes from collapse_huge_page().\nand so trigger BUG_ON() unexpectedly.\n\nFix this problem by using pmd_leaf() insteal of pmd_present() in\npmd_user_accessible_page(). Moreover, use pud_leaf() for\npud_user_accessible_page() too.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49778" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2d458046df634088611d44fd77f45465e833ef78" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5b47348fc0b18a78c96f8474cc90b7525ad1bbfe" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-5573-9qmv-c9ph/GHSA-5573-9qmv-c9ph.json b/advisories/unreviewed/2025/05/GHSA-5573-9qmv-c9ph/GHSA-5573-9qmv-c9ph.json new file mode 100644 index 00000000000..d2b8d068b3a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-5573-9qmv-c9ph/GHSA-5573-9qmv-c9ph.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5573-9qmv-c9ph", + "modified": "2025-05-01T15:31:45Z", + "published": "2025-05-01T15:31:45Z", + "aliases": [ + "CVE-2022-49762" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nntfs: check overflow when iterating ATTR_RECORDs\n\nKernel iterates over ATTR_RECORDs in mft record in ntfs_attr_find(). \nBecause the ATTR_RECORDs are next to each other, kernel can get the next\nATTR_RECORD from end address of current ATTR_RECORD, through current\nATTR_RECORD length field.\n\nThe problem is that during iteration, when kernel calculates the end\naddress of current ATTR_RECORD, kernel may trigger an integer overflow bug\nin executing `a = (ATTR_RECORD*)((u8*)a + le32_to_cpu(a->length))`. This\nmay wrap, leading to a forever iteration on 32bit systems.\n\nThis patch solves it by adding some checks on calculating end address\nof current ATTR_RECORD during iteration.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49762" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/45683723f6b53e39e8a4cec0894e61fd6ec71989" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5559eb5809353a83a40a1e4e7f066431c7b83020" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/63095f4f3af59322bea984a6ae44337439348fe0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/785b2af9654b8beac55644e36da0085c5d776361" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/86f36de14dce5802856bb7a5921d74439db00b64" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/957732a09c3828267c2819d31c425aa793dd475b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b612f924f296408d7d02fb4cd01218afd4ed7184" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b63ddb3ba61e2d3539f87e095c881e552bc45dab" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-56f2-3g4j-6qjh/GHSA-56f2-3g4j-6qjh.json b/advisories/unreviewed/2025/05/GHSA-56f2-3g4j-6qjh/GHSA-56f2-3g4j-6qjh.json new file mode 100644 index 00000000000..d9315430210 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-56f2-3g4j-6qjh/GHSA-56f2-3g4j-6qjh.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-56f2-3g4j-6qjh", + "modified": "2025-05-01T15:31:48Z", + "published": "2025-05-01T15:31:48Z", + "aliases": [ + "CVE-2022-49826" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nata: libata-transport: fix double ata_host_put() in ata_tport_add()\n\nIn the error path in ata_tport_add(), when calling put_device(),\nata_tport_release() is called, it will put the refcount of 'ap->host'.\n\nAnd then ata_host_put() is called again, the refcount is decreased\nto 0, ata_host_release() is called, all ports are freed and set to\nnull.\n\nWhen unbinding the device after failure, ata_host_stop() is called\nto release the resources, it leads a null-ptr-deref(), because all\nthe ports all freed and null.\n\nUnable to handle kernel NULL pointer dereference at virtual address 0000000000000008\nCPU: 7 PID: 18671 Comm: modprobe Kdump: loaded Tainted: G E 6.1.0-rc3+ #8\npstate: 80400009 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)\npc : ata_host_stop+0x3c/0x84 [libata]\nlr : release_nodes+0x64/0xd0\nCall trace:\n ata_host_stop+0x3c/0x84 [libata]\n release_nodes+0x64/0xd0\n devres_release_all+0xbc/0x1b0\n device_unbind_cleanup+0x20/0x70\n really_probe+0x158/0x320\n __driver_probe_device+0x84/0x120\n driver_probe_device+0x44/0x120\n __driver_attach+0xb4/0x220\n bus_for_each_dev+0x78/0xdc\n driver_attach+0x2c/0x40\n bus_add_driver+0x184/0x240\n driver_register+0x80/0x13c\n __pci_register_driver+0x4c/0x60\n ahci_pci_driver_init+0x30/0x1000 [ahci]\n\nFix this by removing redundant ata_host_put() in the error path.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49826" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/30e12e2be27ac6c4be2af4163c70db381364706f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/377ff82c33c0cb74562a353361b64b33c09562cf" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/865a6da40ba092c18292ae5f6194756131293745" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8c76310740807ade5ecdab5888f70ecb6d35732e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ac471468f7c16cda2525909946ca13ddbcd14000" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bec9ded5404cb14e5f5470103d0973a2ff83d6a5" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-59mw-5p3c-3rh3/GHSA-59mw-5p3c-3rh3.json b/advisories/unreviewed/2025/05/GHSA-59mw-5p3c-3rh3/GHSA-59mw-5p3c-3rh3.json new file mode 100644 index 00000000000..6d508f0717c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-59mw-5p3c-3rh3/GHSA-59mw-5p3c-3rh3.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-59mw-5p3c-3rh3", + "modified": "2025-05-01T15:31:49Z", + "published": "2025-05-01T15:31:49Z", + "aliases": [ + "CVE-2022-49832" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\npinctrl: devicetree: fix null pointer dereferencing in pinctrl_dt_to_map\n\nHere is the BUG report by KASAN about null pointer dereference:\n\nBUG: KASAN: null-ptr-deref in strcmp+0x2e/0x50\nRead of size 1 at addr 0000000000000000 by task python3/2640\nCall Trace:\n strcmp\n __of_find_property\n of_find_property\n pinctrl_dt_to_map\n\nkasprintf() would return NULL pointer when kmalloc() fail to allocate.\nSo directly return ENOMEM, if kasprintf() return NULL pointer.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49832" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/040f726fecd88121f3b95e70369785ad452dddf9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5834a3a98cd266ad35a229923c0adbd0addc8d68" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/777430aa4ddccaa5accec6db90ffc1d47f00d471" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/91d5c5060ee24fe8da88cd585bb43b843d2f0dce" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/97e5b508e96176f1a73888ed89df396d7041bfcb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a988dcd3dd9e691c5ccc3324b209688f3b5453e9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/aaf552c5d53abe4659176e099575fe870d2e4768" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b4d9f55cd38435358bc16d580612bc0d798d7b4c" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-5cvr-qr2r-c7rm/GHSA-5cvr-qr2r-c7rm.json b/advisories/unreviewed/2025/05/GHSA-5cvr-qr2r-c7rm/GHSA-5cvr-qr2r-c7rm.json new file mode 100644 index 00000000000..f66667a3c72 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-5cvr-qr2r-c7rm/GHSA-5cvr-qr2r-c7rm.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5cvr-qr2r-c7rm", + "modified": "2025-05-01T15:31:43Z", + "published": "2025-05-01T15:31:43Z", + "aliases": [ + "CVE-2025-37756" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: tls: explicitly disallow disconnect\n\nsyzbot discovered that it can disconnect a TLS socket and then\nrun into all sort of unexpected corner cases. I have a vague\nrecollection of Eric pointing this out to us a long time ago.\nSupporting disconnect is really hard, for one thing if offload\nis enabled we'd need to wait for all packets to be _acked_.\nDisconnect is not commonly used, disallow it.\n\nThe immediate problem syzbot run into is the warning in the strp,\nbut that's just the easiest bug to trigger:\n\n WARNING: CPU: 0 PID: 5834 at net/tls/tls_strp.c:486 tls_strp_msg_load+0x72e/0xa80 net/tls/tls_strp.c:486\n RIP: 0010:tls_strp_msg_load+0x72e/0xa80 net/tls/tls_strp.c:486\n Call Trace:\n \n tls_rx_rec_wait+0x280/0xa60 net/tls/tls_sw.c:1363\n tls_sw_recvmsg+0x85c/0x1c30 net/tls/tls_sw.c:2043\n inet6_recvmsg+0x2c9/0x730 net/ipv6/af_inet6.c:678\n sock_recvmsg_nosec net/socket.c:1023 [inline]\n sock_recvmsg+0x109/0x280 net/socket.c:1045\n __sys_recvfrom+0x202/0x380 net/socket.c:2237", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37756" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2bcad8fefcecdd5f005d8c550b25d703c063c34a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5071a1e606b30c0c11278d3c6620cd6a24724cf6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8513411ec321942bd3cfed53d5bb700665c67d86" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9fcbca0f801580cbb583e9cb274e2c7fbe766ca6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c665bef891e8972e1d3ce5bbc0d42a373346a2c3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f3ce4d3f874ab7919edca364c147ac735f9f1d04" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T13:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-5fcv-vwgv-jrcx/GHSA-5fcv-vwgv-jrcx.json b/advisories/unreviewed/2025/05/GHSA-5fcv-vwgv-jrcx/GHSA-5fcv-vwgv-jrcx.json new file mode 100644 index 00000000000..9e713e336e4 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-5fcv-vwgv-jrcx/GHSA-5fcv-vwgv-jrcx.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5fcv-vwgv-jrcx", + "modified": "2025-05-01T15:31:47Z", + "published": "2025-05-01T15:31:47Z", + "aliases": [ + "CVE-2022-49802" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nftrace: Fix null pointer dereference in ftrace_add_mod()\n\nThe @ftrace_mod is allocated by kzalloc(), so both the members {prev,next}\nof @ftrace_mode->list are NULL, it's not a valid state to call list_del().\nIf kstrdup() for @ftrace_mod->{func|module} fails, it goes to @out_free\ntag and calls free_ftrace_mod() to destroy @ftrace_mod, then list_del()\nwill write prev->next and next->prev, where null pointer dereference\nhappens.\n\nBUG: kernel NULL pointer dereference, address: 0000000000000008\nOops: 0002 [#1] PREEMPT SMP NOPTI\nCall Trace:\n \n ftrace_mod_callback+0x20d/0x220\n ? do_filp_open+0xd9/0x140\n ftrace_process_regex.isra.51+0xbf/0x130\n ftrace_regex_write.isra.52.part.53+0x6e/0x90\n vfs_write+0xee/0x3a0\n ? __audit_filter_op+0xb1/0x100\n ? auditd_test_task+0x38/0x50\n ksys_write+0xa5/0xe0\n do_syscall_64+0x3a/0x90\n entry_SYSCALL_64_after_hwframe+0x63/0xcd\nKernel panic - not syncing: Fatal exception\n\nSo call INIT_LIST_HEAD() to initialize the list member to fix this issue.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49802" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/19ba6c8af9382c4c05dc6a0a79af3013b9a35cd0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1bea037a1abb23a6729bef36a2265a4565f5ea77" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/665b4c6648bf2b91f69b33817f4321cf4c3cafe9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6a14828caddad0d989495a72af678adf60992704" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6e50eb4b1807017f6c2d5089064256ce2de8aef1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b5bfc61f541d3f092b13dedcfe000d86eb8e133c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f715f31559b82e3f75ce047fa476de63d8107584" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-5fcx-mjhh-4qw9/GHSA-5fcx-mjhh-4qw9.json b/advisories/unreviewed/2025/05/GHSA-5fcx-mjhh-4qw9/GHSA-5fcx-mjhh-4qw9.json new file mode 100644 index 00000000000..a9f5eeee391 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-5fcx-mjhh-4qw9/GHSA-5fcx-mjhh-4qw9.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5fcx-mjhh-4qw9", + "modified": "2025-05-01T15:31:44Z", + "published": "2025-05-01T15:31:44Z", + "aliases": [ + "CVE-2025-37768" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/pm: Prevent division by zero\n\nThe user can set any speed value.\nIf speed is greater than UINT_MAX/8, division by zero is possible.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37768" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5fc4fb54f6f064c25bfbbfd443aa861d3422dd4c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7c246a05df51c52fe0852ce56ba10c41e6ed1f39" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8e9c4f8d197d5709c75effa5d58e80b4fa01981a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9e4f1e21fe7b93a8ef57db433071266c2590e260" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b0742a709be7979c7a480772046a1f36d09dab00" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T14:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-5gp6-334q-267g/GHSA-5gp6-334q-267g.json b/advisories/unreviewed/2025/05/GHSA-5gp6-334q-267g/GHSA-5gp6-334q-267g.json new file mode 100644 index 00000000000..1cf967e55ef --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-5gp6-334q-267g/GHSA-5gp6-334q-267g.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5gp6-334q-267g", + "modified": "2025-05-01T15:31:53Z", + "published": "2025-05-01T15:31:53Z", + "aliases": [ + "CVE-2022-49921" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: sched: Fix use after free in red_enqueue()\n\nWe can't use \"skb\" again after passing it to qdisc_enqueue(). This is\nbasically identical to commit 2f09707d0c97 (\"sch_sfb: Also store skb\nlen before calling child enqueue\").", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49921" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/170e5317042c302777ed6d59fdb84af9b0219d4e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/52e0429471976785c155bfbf51d80990c6cd46e2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5960b9081baca85cc7dcb14aec1de85999ea9d36" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/795afe0b9bb6c915f0299a8e309936519be01619" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8bdc2acd420c6f3dd1f1c78750ec989f02a1e2b9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a238cdcf2bdc72207c74375fc8be13ee549ca9db" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e877f8fa49fbccc63cb2df2e9179bddc695b825a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fc4b50adb400ee5ec527a04073174e8e73a139fa" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-5gw7-g26r-r6wh/GHSA-5gw7-g26r-r6wh.json b/advisories/unreviewed/2025/05/GHSA-5gw7-g26r-r6wh/GHSA-5gw7-g26r-r6wh.json new file mode 100644 index 00000000000..5250e6c21bb --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-5gw7-g26r-r6wh/GHSA-5gw7-g26r-r6wh.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5gw7-g26r-r6wh", + "modified": "2025-05-01T15:31:45Z", + "published": "2025-05-01T15:31:45Z", + "aliases": [ + "CVE-2025-37795" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: Update skb's control block key in ieee80211_tx_dequeue()\n\nThe ieee80211 skb control block key (set when skb was queued) could have\nbeen removed before ieee80211_tx_dequeue() call. ieee80211_tx_dequeue()\nalready called ieee80211_tx_h_select_key() to get the current key, but\nthe latter do not update the key in skb control block in case it is\nNULL. Because some drivers actually use this key in their TX callbacks\n(e.g. ath1{1,2}k_mac_op_tx()) this could lead to the use after free\nbelow:\n\n BUG: KASAN: slab-use-after-free in ath11k_mac_op_tx+0x590/0x61c\n Read of size 4 at addr ffffff803083c248 by task kworker/u16:4/1440\n\n CPU: 3 UID: 0 PID: 1440 Comm: kworker/u16:4 Not tainted 6.13.0-ge128f627f404 #2\n Hardware name: HW (DT)\n Workqueue: bat_events batadv_send_outstanding_bcast_packet\n Call trace:\n show_stack+0x14/0x1c (C)\n dump_stack_lvl+0x58/0x74\n print_report+0x164/0x4c0\n kasan_report+0xac/0xe8\n __asan_report_load4_noabort+0x1c/0x24\n ath11k_mac_op_tx+0x590/0x61c\n ieee80211_handle_wake_tx_queue+0x12c/0x1c8\n ieee80211_queue_skb+0xdcc/0x1b4c\n ieee80211_tx+0x1ec/0x2bc\n ieee80211_xmit+0x224/0x324\n __ieee80211_subif_start_xmit+0x85c/0xcf8\n ieee80211_subif_start_xmit+0xc0/0xec4\n dev_hard_start_xmit+0xf4/0x28c\n __dev_queue_xmit+0x6ac/0x318c\n batadv_send_skb_packet+0x38c/0x4b0\n batadv_send_outstanding_bcast_packet+0x110/0x328\n process_one_work+0x578/0xc10\n worker_thread+0x4bc/0xc7c\n kthread+0x2f8/0x380\n ret_from_fork+0x10/0x20\n\n Allocated by task 1906:\n kasan_save_stack+0x28/0x4c\n kasan_save_track+0x1c/0x40\n kasan_save_alloc_info+0x3c/0x4c\n __kasan_kmalloc+0xac/0xb0\n __kmalloc_noprof+0x1b4/0x380\n ieee80211_key_alloc+0x3c/0xb64\n ieee80211_add_key+0x1b4/0x71c\n nl80211_new_key+0x2b4/0x5d8\n genl_family_rcv_msg_doit+0x198/0x240\n <...>\n\n Freed by task 1494:\n kasan_save_stack+0x28/0x4c\n kasan_save_track+0x1c/0x40\n kasan_save_free_info+0x48/0x94\n __kasan_slab_free+0x48/0x60\n kfree+0xc8/0x31c\n kfree_sensitive+0x70/0x80\n ieee80211_key_free_common+0x10c/0x174\n ieee80211_free_keys+0x188/0x46c\n ieee80211_stop_mesh+0x70/0x2cc\n ieee80211_leave_mesh+0x1c/0x60\n cfg80211_leave_mesh+0xe0/0x280\n cfg80211_leave+0x1e0/0x244\n <...>\n\nReset SKB control block key before calling ieee80211_tx_h_select_key()\nto avoid that.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37795" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0cbd747f343c28d911443dd4174820600cc0d952" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/159499c1341f66a71d985e9b79f2131e88d1c646" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7fa75affe2a97abface2b0d9b95e15728967dda7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a104042e2bf6528199adb6ca901efe7b60c2c27f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a167a2833d3f862e800cc23067b21ff1df3a1085" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T14:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-5jv4-93fg-hvqc/GHSA-5jv4-93fg-hvqc.json b/advisories/unreviewed/2025/05/GHSA-5jv4-93fg-hvqc/GHSA-5jv4-93fg-hvqc.json new file mode 100644 index 00000000000..2eaa962f6a3 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-5jv4-93fg-hvqc/GHSA-5jv4-93fg-hvqc.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5jv4-93fg-hvqc", + "modified": "2025-05-01T15:31:50Z", + "published": "2025-05-01T15:31:50Z", + "aliases": [ + "CVE-2022-49865" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: addrlabel: fix infoleak when sending struct ifaddrlblmsg to network\n\nWhen copying a `struct ifaddrlblmsg` to the network, __ifal_reserved\nremained uninitialized, resulting in a 1-byte infoleak:\n\n BUG: KMSAN: kernel-network-infoleak in __netdev_start_xmit ./include/linux/netdevice.h:4841\n __netdev_start_xmit ./include/linux/netdevice.h:4841\n netdev_start_xmit ./include/linux/netdevice.h:4857\n xmit_one net/core/dev.c:3590\n dev_hard_start_xmit+0x1dc/0x800 net/core/dev.c:3606\n __dev_queue_xmit+0x17e8/0x4350 net/core/dev.c:4256\n dev_queue_xmit ./include/linux/netdevice.h:3009\n __netlink_deliver_tap_skb net/netlink/af_netlink.c:307\n __netlink_deliver_tap+0x728/0xad0 net/netlink/af_netlink.c:325\n netlink_deliver_tap net/netlink/af_netlink.c:338\n __netlink_sendskb net/netlink/af_netlink.c:1263\n netlink_sendskb+0x1d9/0x200 net/netlink/af_netlink.c:1272\n netlink_unicast+0x56d/0xf50 net/netlink/af_netlink.c:1360\n nlmsg_unicast ./include/net/netlink.h:1061\n rtnl_unicast+0x5a/0x80 net/core/rtnetlink.c:758\n ip6addrlbl_get+0xfad/0x10f0 net/ipv6/addrlabel.c:628\n rtnetlink_rcv_msg+0xb33/0x1570 net/core/rtnetlink.c:6082\n ...\n Uninit was created at:\n slab_post_alloc_hook+0x118/0xb00 mm/slab.h:742\n slab_alloc_node mm/slub.c:3398\n __kmem_cache_alloc_node+0x4f2/0x930 mm/slub.c:3437\n __do_kmalloc_node mm/slab_common.c:954\n __kmalloc_node_track_caller+0x117/0x3d0 mm/slab_common.c:975\n kmalloc_reserve net/core/skbuff.c:437\n __alloc_skb+0x27a/0xab0 net/core/skbuff.c:509\n alloc_skb ./include/linux/skbuff.h:1267\n nlmsg_new ./include/net/netlink.h:964\n ip6addrlbl_get+0x490/0x10f0 net/ipv6/addrlabel.c:608\n rtnetlink_rcv_msg+0xb33/0x1570 net/core/rtnetlink.c:6082\n netlink_rcv_skb+0x299/0x550 net/netlink/af_netlink.c:2540\n rtnetlink_rcv+0x26/0x30 net/core/rtnetlink.c:6109\n netlink_unicast_kernel net/netlink/af_netlink.c:1319\n netlink_unicast+0x9ab/0xf50 net/netlink/af_netlink.c:1345\n netlink_sendmsg+0xebc/0x10f0 net/netlink/af_netlink.c:1921\n ...\n\nThis patch ensures that the reserved field is always initialized.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49865" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0f85b7ae7c4b5d7b4bbf7ac653a733c181a8a2bf" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2acb2779b147decd300c117683d5a32ce61c75d6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/49e92ba5ecd7d72ba369dde2ccff738edd028a47" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/568a47ff756f913e8b374c2af9d22cd2c772c744" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/58cd7fdc8c1e6c7873acc08f190069fed88d1c12" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6d26d0587abccb9835382a0b53faa7b9b1cd83e3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a033b86c7f7621fde31f0364af8986f43b44914f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c23fb2c82267638f9d206cb96bb93e1f93ad7828" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-5q7j-4fw2-f268/GHSA-5q7j-4fw2-f268.json b/advisories/unreviewed/2025/05/GHSA-5q7j-4fw2-f268/GHSA-5q7j-4fw2-f268.json new file mode 100644 index 00000000000..397e8492f52 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-5q7j-4fw2-f268/GHSA-5q7j-4fw2-f268.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5q7j-4fw2-f268", + "modified": "2025-05-01T15:31:51Z", + "published": "2025-05-01T15:31:50Z", + "aliases": [ + "CVE-2022-49874" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: hyperv: fix possible memory leak in mousevsc_probe()\n\nIf hid_add_device() returns error, it should call hid_destroy_device()\nto free hid_dev which is allocated in hid_allocate_device().", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49874" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/249b743801c00542e9324f87b380032e957a43e8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5ad95d71344b7ffec360d62591633b3c465dc049" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5f3aba6566b866f5b0a4916f0b2e8a6ae66a6451" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8597b59e3d22b27849bd3e4f92a3d466774bfb04" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a6d2fb1874c52ace1f5cf1966ee558829c5c19b6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b5bcb94b0954a026bbd671741fdb00e7141f9c91" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e29289d0d8193fca6d2c1f0a1de75cfc80edec00" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ed75d1a1c31a0cae8ecc8bcea710b25c0be68da0" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-5qqg-7vmr-gjg2/GHSA-5qqg-7vmr-gjg2.json b/advisories/unreviewed/2025/05/GHSA-5qqg-7vmr-gjg2/GHSA-5qqg-7vmr-gjg2.json new file mode 100644 index 00000000000..f1b6d178aca --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-5qqg-7vmr-gjg2/GHSA-5qqg-7vmr-gjg2.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5qqg-7vmr-gjg2", + "modified": "2025-05-01T15:31:48Z", + "published": "2025-05-01T15:31:48Z", + "aliases": [ + "CVE-2022-49810" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfs: Fix missing xas_retry() calls in xarray iteration\n\nnetfslib has a number of places in which it performs iteration of an xarray\nwhilst being under the RCU read lock. It *should* call xas_retry() as the\nfirst thing inside of the loop and do \"continue\" if it returns true in case\nthe xarray walker passed out a special value indicating that the walk needs\nto be redone from the root[*].\n\nFix this by adding the missing retry checks.\n\n[*] I wonder if this should be done inside xas_find(), xas_next_node() and\n suchlike, but I'm told that's not an simple change to effect.\n\nThis can cause an oops like that below. Note the faulting address - this\nis an internal value (|0x2) returned from xarray.\n\nBUG: kernel NULL pointer dereference, address: 0000000000000402\n...\nRIP: 0010:netfs_rreq_unlock+0xef/0x380 [netfs]\n...\nCall Trace:\n netfs_rreq_assess+0xa6/0x240 [netfs]\n netfs_readpage+0x173/0x3b0 [netfs]\n ? init_wait_var_entry+0x50/0x50\n filemap_read_page+0x33/0xf0\n filemap_get_pages+0x2f2/0x3f0\n filemap_read+0xaa/0x320\n ? do_filp_open+0xb2/0x150\n ? rmqueue+0x3be/0xe10\n ceph_read_iter+0x1fe/0x680 [ceph]\n ? new_sync_read+0x115/0x1a0\n new_sync_read+0x115/0x1a0\n vfs_read+0xf3/0x180\n ksys_read+0x5f/0xe0\n do_syscall_64+0x38/0x90\n entry_SYSCALL_64_after_hwframe+0x44/0xae\n\nChanges:\n========\nver #2)\n - Changed an unsigned int to a size_t to reduce the likelihood of an\n overflow as per Willy's suggestion.\n - Added an additional patch to fix the maths.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49810" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7e043a80b5dae5c2d2cf84031501de7827fd6c00" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b2cc07a76f1eb12de3b22caf5fdbf856a7bef16d" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-5rmr-vqfv-62q6/GHSA-5rmr-vqfv-62q6.json b/advisories/unreviewed/2025/05/GHSA-5rmr-vqfv-62q6/GHSA-5rmr-vqfv-62q6.json new file mode 100644 index 00000000000..41abd16d567 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-5rmr-vqfv-62q6/GHSA-5rmr-vqfv-62q6.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5rmr-vqfv-62q6", + "modified": "2025-05-01T15:31:45Z", + "published": "2025-05-01T15:31:45Z", + "aliases": [ + "CVE-2022-49765" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/9p: use a dedicated spinlock for trans_fd\n\nShamelessly copying the explanation from Tetsuo Handa's suggested\npatch[1] (slightly reworded):\nsyzbot is reporting inconsistent lock state in p9_req_put()[2],\nfor p9_tag_remove() from p9_req_put() from IRQ context is using\nspin_lock_irqsave() on \"struct p9_client\"->lock but trans_fd\n(not from IRQ context) is using spin_lock().\n\nSince the locks actually protect different things in client.c and in\ntrans_fd.c, just replace trans_fd.c's lock by a new one specific to the\ntransport (client.c's protect the idr for fid/tag allocations,\nwhile trans_fd.c's protects its own req list and request status field\nthat acts as the transport's state machine)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49765" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/296ab4a813841ba1d5f40b03190fd1bd8f25aab0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/43bbadb7e4636dc02f6a283c2a39e6438e6173cd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/717b9b4f38703d7f5293059e3a242d16f76fa045" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-5w74-h8v5-q653/GHSA-5w74-h8v5-q653.json b/advisories/unreviewed/2025/05/GHSA-5w74-h8v5-q653/GHSA-5w74-h8v5-q653.json new file mode 100644 index 00000000000..de747bd8dff --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-5w74-h8v5-q653/GHSA-5w74-h8v5-q653.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5w74-h8v5-q653", + "modified": "2025-05-01T15:31:50Z", + "published": "2025-05-01T15:31:49Z", + "aliases": [ + "CVE-2022-49854" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmctp: Fix an error handling path in mctp_init()\n\nIf mctp_neigh_init() return error, the routes resources should\nbe released in the error handling path. Otherwise some resources\nleak.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49854" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/216c83222d2eb24b0e63df56e8740b02c33286e8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/49d8a6e24a3496d86e8d8ae748375df984fb6d6f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d4072058af4fd8fb4658e7452289042a406a9398" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-6555-7w66-v874/GHSA-6555-7w66-v874.json b/advisories/unreviewed/2025/05/GHSA-6555-7w66-v874/GHSA-6555-7w66-v874.json new file mode 100644 index 00000000000..d6f2e6e8e01 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-6555-7w66-v874/GHSA-6555-7w66-v874.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6555-7w66-v874", + "modified": "2025-05-01T15:31:50Z", + "published": "2025-05-01T15:31:50Z", + "aliases": [ + "CVE-2022-49861" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: mv_xor_v2: Fix a resource leak in mv_xor_v2_remove()\n\nA clk_prepare_enable() call in the probe is not balanced by a corresponding\nclk_disable_unprepare() in the remove function.\n\nAdd the missing call.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49861" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/04f2cc56d80a1ac058045a7835c5bfd910f17863" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/081195d17a0c4c636da2b869bd5809d42e8cbb13" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0b7ee3d50f32d277bf024b4ddb4de54da43a3025" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1d84887327659c58a6637060ac8c50c3a952a163" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/20479886b40c0ed4864a5fc8490a1f6b70cccf1b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4b6641c3a2ba95ddcfecec263b4a5e572a4b0641" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/992e966caf57e00855edbd79f19d911809732a69" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a1cb72e20a64a3c83f9b4ee993fbf97e4c1d7714" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-65f7-9jmg-75c7/GHSA-65f7-9jmg-75c7.json b/advisories/unreviewed/2025/05/GHSA-65f7-9jmg-75c7/GHSA-65f7-9jmg-75c7.json new file mode 100644 index 00000000000..d79b21b461a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-65f7-9jmg-75c7/GHSA-65f7-9jmg-75c7.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-65f7-9jmg-75c7", + "modified": "2025-05-01T15:31:47Z", + "published": "2025-05-01T15:31:46Z", + "aliases": [ + "CVE-2022-49788" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmisc/vmw_vmci: fix an infoleak in vmci_host_do_receive_datagram()\n\n`struct vmci_event_qp` allocated by qp_notify_peer() contains padding,\nwhich may carry uninitialized data to the userspace, as observed by\nKMSAN:\n\n BUG: KMSAN: kernel-infoleak in instrument_copy_to_user ./include/linux/instrumented.h:121\n instrument_copy_to_user ./include/linux/instrumented.h:121\n _copy_to_user+0x5f/0xb0 lib/usercopy.c:33\n copy_to_user ./include/linux/uaccess.h:169\n vmci_host_do_receive_datagram drivers/misc/vmw_vmci/vmci_host.c:431\n vmci_host_unlocked_ioctl+0x33d/0x43d0 drivers/misc/vmw_vmci/vmci_host.c:925\n vfs_ioctl fs/ioctl.c:51\n ...\n\n Uninit was stored to memory at:\n kmemdup+0x74/0xb0 mm/util.c:131\n dg_dispatch_as_host drivers/misc/vmw_vmci/vmci_datagram.c:271\n vmci_datagram_dispatch+0x4f8/0xfc0 drivers/misc/vmw_vmci/vmci_datagram.c:339\n qp_notify_peer+0x19a/0x290 drivers/misc/vmw_vmci/vmci_queue_pair.c:1479\n qp_broker_attach drivers/misc/vmw_vmci/vmci_queue_pair.c:1662\n qp_broker_alloc+0x2977/0x2f30 drivers/misc/vmw_vmci/vmci_queue_pair.c:1750\n vmci_qp_broker_alloc+0x96/0xd0 drivers/misc/vmw_vmci/vmci_queue_pair.c:1940\n vmci_host_do_alloc_queuepair drivers/misc/vmw_vmci/vmci_host.c:488\n vmci_host_unlocked_ioctl+0x24fd/0x43d0 drivers/misc/vmw_vmci/vmci_host.c:927\n ...\n\n Local variable ev created at:\n qp_notify_peer+0x54/0x290 drivers/misc/vmw_vmci/vmci_queue_pair.c:1456\n qp_broker_attach drivers/misc/vmw_vmci/vmci_queue_pair.c:1662\n qp_broker_alloc+0x2977/0x2f30 drivers/misc/vmw_vmci/vmci_queue_pair.c:1750\n\n Bytes 28-31 of 48 are uninitialized\n Memory access of size 48 starts at ffff888035155e00\n Data copied to user address 0000000020000100\n\nUse memset() to prevent the infoleaks.\n\nAlso speculatively fix qp_notify_peer_local(), which may suffer from the\nsame problem.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49788" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5a275528025ae4bc7e2232866856dfebf84b2fad" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/62634b43d3c4e1bf62fd540196f7081bf0885c0a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/76c50d77b928a33e5290aaa9fdc10e88254ff8c7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7ccf7229b96fadc3a185d1391f814a604c7ef609" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8e2f33c598370bcf828bab4d667d1d38bcd3c57d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e5b0d06d9b10f5f43101bd6598b076c347f9295f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e7061dd1fef2dfb6458cd521aef27aa66f510d31" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f04586c2315cfd03d72ad0395705435e7ed07b1a" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-68wc-qrqf-rfh5/GHSA-68wc-qrqf-rfh5.json b/advisories/unreviewed/2025/05/GHSA-68wc-qrqf-rfh5/GHSA-68wc-qrqf-rfh5.json new file mode 100644 index 00000000000..21c2f340811 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-68wc-qrqf-rfh5/GHSA-68wc-qrqf-rfh5.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-68wc-qrqf-rfh5", + "modified": "2025-05-01T15:31:44Z", + "published": "2025-05-01T15:31:44Z", + "aliases": [ + "CVE-2025-37776" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix use-after-free in smb_break_all_levII_oplock()\n\nThere is a room in smb_break_all_levII_oplock that can cause racy issues\nwhen unlocking in the middle of the loop. This patch use read lock\nto protect whole loop.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37776" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/18b4fac5ef17f77fed9417d22210ceafd6525fc7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/296cb5457cc6f4a754c4ae29855f8a253d52bcc6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d54ab1520d43e95f9b2e22d7a05fc9614192e5a5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d73686367ad68534257cd88a36ca3c52cb8b81d8" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T14:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-69cq-v3pw-hrr3/GHSA-69cq-v3pw-hrr3.json b/advisories/unreviewed/2025/05/GHSA-69cq-v3pw-hrr3/GHSA-69cq-v3pw-hrr3.json new file mode 100644 index 00000000000..129063441b0 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-69cq-v3pw-hrr3/GHSA-69cq-v3pw-hrr3.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-69cq-v3pw-hrr3", + "modified": "2025-05-01T15:31:42Z", + "published": "2025-05-01T15:31:42Z", + "aliases": [ + "CVE-2025-37742" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\njfs: Fix uninit-value access of imap allocated in the diMount() function\n\nsyzbot reports that hex_dump_to_buffer is using uninit-value:\n\n=====================================================\nBUG: KMSAN: uninit-value in hex_dump_to_buffer+0x888/0x1100 lib/hexdump.c:171\nhex_dump_to_buffer+0x888/0x1100 lib/hexdump.c:171\nprint_hex_dump+0x13d/0x3e0 lib/hexdump.c:276\ndiFree+0x5ba/0x4350 fs/jfs/jfs_imap.c:876\njfs_evict_inode+0x510/0x550 fs/jfs/inode.c:156\nevict+0x723/0xd10 fs/inode.c:796\niput_final fs/inode.c:1946 [inline]\niput+0x97b/0xdb0 fs/inode.c:1972\ntxUpdateMap+0xf3e/0x1150 fs/jfs/jfs_txnmgr.c:2367\ntxLazyCommit fs/jfs/jfs_txnmgr.c:2664 [inline]\njfs_lazycommit+0x627/0x11d0 fs/jfs/jfs_txnmgr.c:2733\nkthread+0x6b9/0xef0 kernel/kthread.c:464\nret_from_fork+0x6d/0x90 arch/x86/kernel/process.c:148\nret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:244\n\nUninit was created at:\nslab_post_alloc_hook mm/slub.c:4121 [inline]\nslab_alloc_node mm/slub.c:4164 [inline]\n__kmalloc_cache_noprof+0x8e3/0xdf0 mm/slub.c:4320\nkmalloc_noprof include/linux/slab.h:901 [inline]\ndiMount+0x61/0x7f0 fs/jfs/jfs_imap.c:105\njfs_mount+0xa8e/0x11d0 fs/jfs/jfs_mount.c:176\njfs_fill_super+0xa47/0x17c0 fs/jfs/super.c:523\nget_tree_bdev_flags+0x6ec/0x910 fs/super.c:1636\nget_tree_bdev+0x37/0x50 fs/super.c:1659\njfs_get_tree+0x34/0x40 fs/jfs/super.c:635\nvfs_get_tree+0xb1/0x5a0 fs/super.c:1814\ndo_new_mount+0x71f/0x15e0 fs/namespace.c:3560\npath_mount+0x742/0x1f10 fs/namespace.c:3887\ndo_mount fs/namespace.c:3900 [inline]\n__do_sys_mount fs/namespace.c:4111 [inline]\n__se_sys_mount+0x71f/0x800 fs/namespace.c:4088\n__x64_sys_mount+0xe4/0x150 fs/namespace.c:4088\nx64_sys_call+0x39bf/0x3c30 arch/x86/include/generated/asm/syscalls_64.h:166\ndo_syscall_x64 arch/x86/entry/common.c:52 [inline]\ndo_syscall_64+0xcd/0x1e0 arch/x86/entry/common.c:83\nentry_SYSCALL_64_after_hwframe+0x77/0x7f\n=====================================================\n\nThe reason is that imap is not properly initialized after memory\nallocation. It will cause the snprintf() function to write uninitialized\ndata into linebuf within hex_dump_to_buffer().\n\nFix this by using kzalloc instead of kmalloc to clear its content at the\nbeginning in diMount().", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37742" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/067347e00a3a7d04afed93f080c6c131e5dd15ee" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/63148ce4904faa668daffdd1d3c1199ae315ef2c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7057f3aab47629d38e54eae83505813cf0da1e4b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9629d7d66c621671d9a47afe27ca9336bfc8a9ea" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cab1852368dd74d629ee02abdbc559218ca64dde" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d0d7eca253ccd0619b3d2b683ffe32218ebca9ac" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T13:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-6chx-4cx4-vrw4/GHSA-6chx-4cx4-vrw4.json b/advisories/unreviewed/2025/05/GHSA-6chx-4cx4-vrw4/GHSA-6chx-4cx4-vrw4.json new file mode 100644 index 00000000000..36a074b2484 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-6chx-4cx4-vrw4/GHSA-6chx-4cx4-vrw4.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6chx-4cx4-vrw4", + "modified": "2025-05-01T15:31:50Z", + "published": "2025-05-01T15:31:50Z", + "aliases": [ + "CVE-2022-49858" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nocteontx2-pf: Fix SQE threshold checking\n\nCurrent way of checking available SQE count which is based on\nHW updated SQB count could result in driver submitting an SQE\neven before CQE for the previously transmitted SQE at the same\nindex is processed in NAPI resulting losing SKB pointers,\nhence a leak. Fix this by checking a consumer index which\nis updated once CQE is processed.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49858" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/015e3c0a3b16193aab23beefe4719484b9984c2d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f0dfc4c88ef39be0ba736aa0ce6119263fc19aeb" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-6cmp-hmx3-m4rx/GHSA-6cmp-hmx3-m4rx.json b/advisories/unreviewed/2025/05/GHSA-6cmp-hmx3-m4rx/GHSA-6cmp-hmx3-m4rx.json new file mode 100644 index 00000000000..1540848ca32 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-6cmp-hmx3-m4rx/GHSA-6cmp-hmx3-m4rx.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6cmp-hmx3-m4rx", + "modified": "2025-05-01T15:31:49Z", + "published": "2025-05-01T15:31:49Z", + "aliases": [ + "CVE-2022-49845" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: j1939: j1939_send_one(): fix missing CAN header initialization\n\nThe read access to struct canxl_frame::len inside of a j1939 created\nskbuff revealed a missing initialization of reserved and later filled\nelements in struct can_frame.\n\nThis patch initializes the 8 byte CAN header with zero.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49845" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2719f82ad5d8199cf5f346ea8bb3998ad5323b72" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3eb3d283e8579a22b81dd2ac3987b77465b2a22f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/69e86c6268d59ceddd0abe9ae8f1f5296f316c3c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d0513b095e1ef1469718564dec3fb3348556d0a8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f8e0edeaa0f2b860bdbbf0aafb4492533043d650" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-6cv4-fcr9-fcmw/GHSA-6cv4-fcr9-fcmw.json b/advisories/unreviewed/2025/05/GHSA-6cv4-fcr9-fcmw/GHSA-6cv4-fcr9-fcmw.json new file mode 100644 index 00000000000..973a6999dd5 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-6cv4-fcr9-fcmw/GHSA-6cv4-fcr9-fcmw.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6cv4-fcr9-fcmw", + "modified": "2025-05-01T15:31:49Z", + "published": "2025-05-01T15:31:49Z", + "aliases": [ + "CVE-2022-49828" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nhugetlbfs: don't delete error page from pagecache\n\nThis change is very similar to the change that was made for shmem [1], and\nit solves the same problem but for HugeTLBFS instead.\n\nCurrently, when poison is found in a HugeTLB page, the page is removed\nfrom the page cache. That means that attempting to map or read that\nhugepage in the future will result in a new hugepage being allocated\ninstead of notifying the user that the page was poisoned. As [1] states,\nthis is effectively memory corruption.\n\nThe fix is to leave the page in the page cache. If the user attempts to\nuse a poisoned HugeTLB page with a syscall, the syscall will fail with\nEIO, the same error code that shmem uses. For attempts to map the page,\nthe thread will get a BUS_MCEERR_AR SIGBUS.\n\n[1]: commit a76054266661 (\"mm: shmem: don't truncate page if memory failure happens\")", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49828" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/30571f28bb35c826219971c63bcf60d2517112ed" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8625147cafaa9ba74713d682f5185eb62cb2aedb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ec667443b2dbc6cdbbac4073e51a17733158ec6a" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-6cv8-8h5r-cc95/GHSA-6cv8-8h5r-cc95.json b/advisories/unreviewed/2025/05/GHSA-6cv8-8h5r-cc95/GHSA-6cv8-8h5r-cc95.json new file mode 100644 index 00000000000..8f41b604fb1 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-6cv8-8h5r-cc95/GHSA-6cv8-8h5r-cc95.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6cv8-8h5r-cc95", + "modified": "2025-05-01T15:31:53Z", + "published": "2025-05-01T15:31:53Z", + "aliases": [ + "CVE-2025-23246" + ], + "details": "NVIDIA vGPU software for Windows and Linux contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it allows a guest to consume uncontrolled resources. A successful exploit of this vulnerability might lead to denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23246" + }, + { + "type": "WEB", + "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5630" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-6f84-p6h5-x3qm/GHSA-6f84-p6h5-x3qm.json b/advisories/unreviewed/2025/05/GHSA-6f84-p6h5-x3qm/GHSA-6f84-p6h5-x3qm.json new file mode 100644 index 00000000000..f50640a7a1e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-6f84-p6h5-x3qm/GHSA-6f84-p6h5-x3qm.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6f84-p6h5-x3qm", + "modified": "2025-05-01T15:31:40Z", + "published": "2025-05-01T15:31:40Z", + "aliases": [ + "CVE-2025-23147" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ni3c: Add NULL pointer check in i3c_master_queue_ibi()\n\nThe I3C master driver may receive an IBI from a target device that has not\nbeen probed yet. In such cases, the master calls `i3c_master_queue_ibi()`\nto queue an IBI work task, leading to \"Unable to handle kernel read from\nunreadable memory\" and resulting in a kernel panic.\n\nTypical IBI handling flow:\n1. The I3C master scans target devices and probes their respective drivers.\n2. The target device driver calls `i3c_device_request_ibi()` to enable IBI\n and assigns `dev->ibi = ibi`.\n3. The I3C master receives an IBI from the target device and calls\n `i3c_master_queue_ibi()` to queue the target device driver’s IBI\n handler task.\n\nHowever, since target device events are asynchronous to the I3C probe\nsequence, step 3 may occur before step 2, causing `dev->ibi` to be `NULL`,\nleading to a kernel panic.\n\nAdd a NULL pointer check in `i3c_master_queue_ibi()` to prevent accessing\nan uninitialized `dev->ibi`, ensuring stability.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23147" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6871a676aa534e8f218279672e0445c725f81026" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bd496a44f041da9ef3afe14d1d6193d460424e91" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d83b0c03ef8fbea2f03029a1cc1f5041f0e1d47f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e6bba328578feb58c614c11868c259b40484c5fa" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fe4a4fc179b7898055555a11685915473588392e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ff9d61db59bb27d16d3f872bff2620d50856b80c" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T13:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-6fmv-c3mq-xjpq/GHSA-6fmv-c3mq-xjpq.json b/advisories/unreviewed/2025/05/GHSA-6fmv-c3mq-xjpq/GHSA-6fmv-c3mq-xjpq.json new file mode 100644 index 00000000000..8a3ac3d6737 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-6fmv-c3mq-xjpq/GHSA-6fmv-c3mq-xjpq.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6fmv-c3mq-xjpq", + "modified": "2025-05-01T15:31:53Z", + "published": "2025-05-01T15:31:53Z", + "aliases": [ + "CVE-2022-49922" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: nfcmrvl: Fix potential memory leak in nfcmrvl_i2c_nci_send()\n\nnfcmrvl_i2c_nci_send() will be called by nfcmrvl_nci_send(), and skb\nshould be freed in nfcmrvl_i2c_nci_send(). However, nfcmrvl_nci_send()\nwill only free skb when i2c_master_send() return >=0, which means skb\nwill memleak when i2c_master_send() failed. Free skb no matter whether\ni2c_master_send() succeeds.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49922" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/52438e734c1566f5e2bcd9a065d2d65e306c0555" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5dfdac5e3f8db5f4445228c44f64091045644a3b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/825656ae61e73ddc05f585e6258d284c87064b10" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/92a1df9c6da20c02cf9872f8b025a66ddb307aeb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/93d904a734a74c54d945a9884b4962977f1176cd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c8e7d4a1166f063703955f1b2e765a6db5bf1771" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/dd0ee55ead91fbb16889dbe7ff0b0f7c9e4e849d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f30060efcf18883748a0541aa41acef183cd9c0e" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-6j92-j58g-fc8v/GHSA-6j92-j58g-fc8v.json b/advisories/unreviewed/2025/05/GHSA-6j92-j58g-fc8v/GHSA-6j92-j58g-fc8v.json new file mode 100644 index 00000000000..8ff6bf21621 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-6j92-j58g-fc8v/GHSA-6j92-j58g-fc8v.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6j92-j58g-fc8v", + "modified": "2025-05-01T15:31:53Z", + "published": "2025-05-01T15:31:52Z", + "aliases": [ + "CVE-2022-49913" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix inode list leak during backref walking at find_parent_nodes()\n\nDuring backref walking, at find_parent_nodes(), if we are dealing with a\ndata extent and we get an error while resolving the indirect backrefs, at\nresolve_indirect_refs(), or in the while loop that iterates over the refs\nin the direct refs rbtree, we end up leaking the inode lists attached to\nthe direct refs we have in the direct refs rbtree that were not yet added\nto the refs ulist passed as argument to find_parent_nodes(). Since they\nwere not yet added to the refs ulist and prelim_release() does not free\nthe lists, on error the caller can only free the lists attached to the\nrefs that were added to the refs ulist, all the remaining refs get their\ninode lists never freed, therefore leaking their memory.\n\nFix this by having prelim_release() always free any attached inode list\nto each ref found in the rbtree, and have find_parent_nodes() set the\nref's inode list to NULL once it transfers ownership of the inode list\nto a ref added to the refs ulist passed to find_parent_nodes().", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49913" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/222a3d533027b9492d5b7f5ecdc01a90f57bb5a9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/61e06128113711df0534c404fb6bb528eb7d2332" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6a6731a0df8c47ecc703bd7bb73459df767051e0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/83ea8c5b54d452a5769e605e3c5c687e8ca06d89" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/92876eec382a0f19f33d09d2c939e9ca49038ae5" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-6mfv-xmmj-jgwf/GHSA-6mfv-xmmj-jgwf.json b/advisories/unreviewed/2025/05/GHSA-6mfv-xmmj-jgwf/GHSA-6mfv-xmmj-jgwf.json new file mode 100644 index 00000000000..8727f3fb84c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-6mfv-xmmj-jgwf/GHSA-6mfv-xmmj-jgwf.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6mfv-xmmj-jgwf", + "modified": "2025-05-01T15:31:52Z", + "published": "2025-05-01T15:31:52Z", + "aliases": [ + "CVE-2022-49917" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nipvs: fix WARNING in ip_vs_app_net_cleanup()\n\nDuring the initialization of ip_vs_app_net_init(), if file ip_vs_app\nfails to be created, the initialization is successful by default.\nTherefore, the ip_vs_app file doesn't be found during the remove in\nip_vs_app_net_cleanup(). It will cause WRNING.\n\nThe following is the stack information:\nname 'ip_vs_app'\nWARNING: CPU: 1 PID: 9 at fs/proc/generic.c:712 remove_proc_entry+0x389/0x460\nModules linked in:\nWorkqueue: netns cleanup_net\nRIP: 0010:remove_proc_entry+0x389/0x460\nCall Trace:\n\nops_exit_list+0x125/0x170\ncleanup_net+0x4ea/0xb00\nprocess_one_work+0x9bf/0x1710\nworker_thread+0x665/0x1080\nkthread+0x2e4/0x3a0\nret_from_fork+0x1f/0x30\n", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49917" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/06d7596d18725f1a93cf817662d36050e5afb989" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2c8d81bdb2684d53d6cedad7410ba4cf9090e343" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5663ed63adb9619c98ab7479aa4606fa9b7a548c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8457a00c981fe1a799ce34123908856b0f5973b8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/97f872b00937f2689bff2dab4ad9ed259482840f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/adc76740ccd52e4a1d910767cd1223e134a7078b" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-6mx2-jh62-9j5h/GHSA-6mx2-jh62-9j5h.json b/advisories/unreviewed/2025/05/GHSA-6mx2-jh62-9j5h/GHSA-6mx2-jh62-9j5h.json new file mode 100644 index 00000000000..aebaf4b1bae --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-6mx2-jh62-9j5h/GHSA-6mx2-jh62-9j5h.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6mx2-jh62-9j5h", + "modified": "2025-05-01T15:31:47Z", + "published": "2025-05-01T15:31:47Z", + "aliases": [ + "CVE-2022-49804" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ns390: avoid using global register for current_stack_pointer\n\nCommit 30de14b1884b (\"s390: current_stack_pointer shouldn't be a\nfunction\") made current_stack_pointer a global register variable like\non many other architectures. Unfortunately on s390 it uncovers old\ngcc bug which is fixed only since gcc-9.1 [gcc commit 3ad7fed1cc87\n(\"S/390: Fix PR89775. Stackpointer save/restore instructions removed\")]\nand backported to gcc-8.4 and later. Due to this bug gcc versions prior\nto 8.4 generate broken code which leads to stack corruptions.\n\nCurrent minimal gcc version required to build the kernel is declared\nas 5.1. It is not possible to fix all old gcc versions, so work\naround this problem by avoiding using global register variable for\ncurrent_stack_pointer.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49804" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a478952a8ac44e32316dc046a063a7dc34825aa6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e3c11025bcd2142a61abe5806b2f86a0e78118df" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-6p36-94f3-3rfp/GHSA-6p36-94f3-3rfp.json b/advisories/unreviewed/2025/05/GHSA-6p36-94f3-3rfp/GHSA-6p36-94f3-3rfp.json new file mode 100644 index 00000000000..19cfcc2983a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-6p36-94f3-3rfp/GHSA-6p36-94f3-3rfp.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6p36-94f3-3rfp", + "modified": "2025-05-01T15:31:45Z", + "published": "2025-05-01T15:31:45Z", + "aliases": [ + "CVE-2022-49768" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\n9p: trans_fd/p9_conn_cancel: drop client lock earlier\n\nsyzbot reported a double-lock here and we no longer need this\nlock after requests have been moved off to local list:\njust drop the lock earlier.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49768" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/52f1c45dde9136f964d63a77d19826c8a74e2c7f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/612c977f5d481f551d03d83d0aef588845c1300c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/82825dbf393f7c7979d462f9609a15bde8092b3f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/96760723aae1b45f733f702abb4333137143909f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a4f1a01b2e81378fce9ca528d4d8a049e4b58fcd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e3031280fe4eaf61a09e60823331f81f321be8e1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f14858bc77c567e089965962877ee726ffad0556" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fec1406f5e7ab20b71f6d231792b0040e3300aaf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-6qgr-97mx-84hr/GHSA-6qgr-97mx-84hr.json b/advisories/unreviewed/2025/05/GHSA-6qgr-97mx-84hr/GHSA-6qgr-97mx-84hr.json new file mode 100644 index 00000000000..00a68a40ad7 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-6qgr-97mx-84hr/GHSA-6qgr-97mx-84hr.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6qgr-97mx-84hr", + "modified": "2025-05-01T15:31:51Z", + "published": "2025-05-01T15:31:51Z", + "aliases": [ + "CVE-2022-49880" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\next4: fix warning in 'ext4_da_release_space'\n\nSyzkaller report issue as follows:\nEXT4-fs (loop0): Free/Dirty block details\nEXT4-fs (loop0): free_blocks=0\nEXT4-fs (loop0): dirty_blocks=0\nEXT4-fs (loop0): Block reservation details\nEXT4-fs (loop0): i_reserved_data_blocks=0\nEXT4-fs warning (device loop0): ext4_da_release_space:1527: ext4_da_release_space: ino 18, to_free 1 with only 0 reserved data blocks\n------------[ cut here ]------------\nWARNING: CPU: 0 PID: 92 at fs/ext4/inode.c:1528 ext4_da_release_space+0x25e/0x370 fs/ext4/inode.c:1524\nModules linked in:\nCPU: 0 PID: 92 Comm: kworker/u4:4 Not tainted 6.0.0-syzkaller-09423-g493ffd6605b2 #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/22/2022\nWorkqueue: writeback wb_workfn (flush-7:0)\nRIP: 0010:ext4_da_release_space+0x25e/0x370 fs/ext4/inode.c:1528\nRSP: 0018:ffffc900015f6c90 EFLAGS: 00010296\nRAX: 42215896cd52ea00 RBX: 0000000000000000 RCX: 42215896cd52ea00\nRDX: 0000000000000000 RSI: 0000000080000001 RDI: 0000000000000000\nRBP: 1ffff1100e907d96 R08: ffffffff816aa79d R09: fffff520002bece5\nR10: fffff520002bece5 R11: 1ffff920002bece4 R12: ffff888021fd2000\nR13: ffff88807483ecb0 R14: 0000000000000001 R15: ffff88807483e740\nFS: 0000000000000000(0000) GS:ffff8880b9a00000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00005555569ba628 CR3: 000000000c88e000 CR4: 00000000003506f0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nCall Trace:\n \n ext4_es_remove_extent+0x1ab/0x260 fs/ext4/extents_status.c:1461\n mpage_release_unused_pages+0x24d/0xef0 fs/ext4/inode.c:1589\n ext4_writepages+0x12eb/0x3be0 fs/ext4/inode.c:2852\n do_writepages+0x3c3/0x680 mm/page-writeback.c:2469\n __writeback_single_inode+0xd1/0x670 fs/fs-writeback.c:1587\n writeback_sb_inodes+0xb3b/0x18f0 fs/fs-writeback.c:1870\n wb_writeback+0x41f/0x7b0 fs/fs-writeback.c:2044\n wb_do_writeback fs/fs-writeback.c:2187 [inline]\n wb_workfn+0x3cb/0xef0 fs/fs-writeback.c:2227\n process_one_work+0x877/0xdb0 kernel/workqueue.c:2289\n worker_thread+0xb14/0x1330 kernel/workqueue.c:2436\n kthread+0x266/0x300 kernel/kthread.c:376\n ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:306\n \n\nAbove issue may happens as follows:\next4_da_write_begin\n ext4_create_inline_data\n ext4_clear_inode_flag(inode, EXT4_INODE_EXTENTS);\n ext4_set_inode_flag(inode, EXT4_INODE_INLINE_DATA);\n__ext4_ioctl\n ext4_ext_migrate -> will lead to eh->eh_entries not zero, and set extent flag\next4_da_write_begin\n ext4_da_convert_inline_data_to_extent\n ext4_da_write_inline_data_begin\n ext4_da_map_blocks\n ext4_insert_delayed_block\n\t if (!ext4_es_scan_clu(inode, &ext4_es_is_delonly, lblk))\n\t if (!ext4_es_scan_clu(inode, &ext4_es_is_mapped, lblk))\n\t ext4_clu_mapped(inode, EXT4_B2C(sbi, lblk)); -> will return 1\n\t allocated = true;\n ext4_es_insert_delayed_block(inode, lblk, allocated);\next4_writepages\n mpage_map_and_submit_extent(handle, &mpd, &give_up_on_write); -> return -ENOSPC\n mpage_release_unused_pages(&mpd, give_up_on_write); -> give_up_on_write == 1\n ext4_es_remove_extent\n ext4_da_release_space(inode, reserved);\n if (unlikely(to_free > ei->i_reserved_data_blocks))\n\t -> to_free == 1 but ei->i_reserved_data_blocks == 0\n\t -> then trigger warning as above\n\nTo solve above issue, forbid inode do migrate which has inline data.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49880" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0a43c015e98121c91a76154edf42280ce1a8a883" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0de5ee103747fd3a24f1c010c79caabe35e8f0bb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1b8f787ef547230a3249bcf897221ef0cc78481b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5370b965b7a945bb8f48b9ee23d83a76a947902e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/72743d5598b9096950bbfd6a9b7f173d156eea97" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/890d738f569fa9412b70ba09f15407f17a52da20" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/89bee03d2fb8c54119b38ac6c24e7d60fae036b6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c3bf1e95cfa7d950dc3c064d0c2e3d06b427bc63" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-6vr6-r6mg-9m3f/GHSA-6vr6-r6mg-9m3f.json b/advisories/unreviewed/2025/05/GHSA-6vr6-r6mg-9m3f/GHSA-6vr6-r6mg-9m3f.json new file mode 100644 index 00000000000..b5110c7f687 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-6vr6-r6mg-9m3f/GHSA-6vr6-r6mg-9m3f.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6vr6-r6mg-9m3f", + "modified": "2025-05-01T15:31:53Z", + "published": "2025-05-01T15:31:53Z", + "aliases": [ + "CVE-2022-49931" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nIB/hfi1: Correctly move list in sc_disable()\n\nCommit 13bac861952a (\"IB/hfi1: Fix abba locking issue with sc_disable()\")\nincorrectly tries to move a list from one list head to another. The\nresult is a kernel crash.\n\nThe crash is triggered when a link goes down and there are waiters for a\nsend to complete. The following signature is seen:\n\n BUG: kernel NULL pointer dereference, address: 0000000000000030\n [...]\n Call Trace:\n sc_disable+0x1ba/0x240 [hfi1]\n pio_freeze+0x3d/0x60 [hfi1]\n handle_freeze+0x27/0x1b0 [hfi1]\n process_one_work+0x1b0/0x380\n ? process_one_work+0x380/0x380\n worker_thread+0x30/0x360\n ? process_one_work+0x380/0x380\n kthread+0xd7/0x100\n ? kthread_complete_and_exit+0x20/0x20\n ret_from_fork+0x1f/0x30\n\nThe fix is to use the correct call to move the list.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49931" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1afac08b39d85437187bb2a92d89a741b1078f55" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/25760a41e3802f54aadcc31385543665ab349b8e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7c4260f8f188df32414a5ecad63e8b934c2aa3f0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b8bcff99b07cc175a6ee12a52db51cdd2229586c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ba95409d6b580501ff6d78efd00064f7df669926" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-6xrp-v9gf-f7mv/GHSA-6xrp-v9gf-f7mv.json b/advisories/unreviewed/2025/05/GHSA-6xrp-v9gf-f7mv/GHSA-6xrp-v9gf-f7mv.json new file mode 100644 index 00000000000..62bea12b4d4 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-6xrp-v9gf-f7mv/GHSA-6xrp-v9gf-f7mv.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6xrp-v9gf-f7mv", + "modified": "2025-05-01T15:31:52Z", + "published": "2025-05-01T15:31:52Z", + "aliases": [ + "CVE-2022-49899" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfscrypt: stop using keyrings subsystem for fscrypt_master_key\n\nThe approach of fs/crypto/ internally managing the fscrypt_master_key\nstructs as the payloads of \"struct key\" objects contained in a\n\"struct key\" keyring has outlived its usefulness. The original idea was\nto simplify the code by reusing code from the keyrings subsystem.\nHowever, several issues have arisen that can't easily be resolved:\n\n- When a master key struct is destroyed, blk_crypto_evict_key() must be\n called on any per-mode keys embedded in it. (This started being the\n case when inline encryption support was added.) Yet, the keyrings\n subsystem can arbitrarily delay the destruction of keys, even past the\n time the filesystem was unmounted. Therefore, currently there is no\n easy way to call blk_crypto_evict_key() when a master key is\n destroyed. Currently, this is worked around by holding an extra\n reference to the filesystem's request_queue(s). But it was overlooked\n that the request_queue reference is *not* guaranteed to pin the\n corresponding blk_crypto_profile too; for device-mapper devices that\n support inline crypto, it doesn't. This can cause a use-after-free.\n\n- When the last inode that was using an incompletely-removed master key\n is evicted, the master key removal is completed by removing the key\n struct from the keyring. Currently this is done via key_invalidate().\n Yet, key_invalidate() takes the key semaphore. This can deadlock when\n called from the shrinker, since in fscrypt_ioctl_add_key(), memory is\n allocated with GFP_KERNEL under the same semaphore.\n\n- More generally, the fact that the keyrings subsystem can arbitrarily\n delay the destruction of keys (via garbage collection delay, or via\n random processes getting temporary key references) is undesirable, as\n it means we can't strictly guarantee that all secrets are ever wiped.\n\n- Doing the master key lookups via the keyrings subsystem results in the\n key_permission LSM hook being called. fscrypt doesn't want this, as\n all access control for encrypted files is designed to happen via the\n files themselves, like any other files. The workaround which SELinux\n users are using is to change their SELinux policy to grant key search\n access to all domains. This works, but it is an odd extra step that\n shouldn't really have to be done.\n\nThe fix for all these issues is to change the implementation to what I\nshould have done originally: don't use the keyrings subsystem to keep\ntrack of the filesystem's fscrypt_master_key structs. Instead, just\nstore them in a regular kernel data structure, and rework the reference\ncounting, locking, and lifetime accordingly. Retain support for\nRCU-mode key lookups by using a hash table. Replace fscrypt_sb_free()\nwith fscrypt_sb_delete(), which releases the keys synchronously and runs\na bit earlier during unmount, so that block devices are still available.\n\nA side effect of this patch is that neither the master keys themselves\nnor the filesystem keyrings will be listed in /proc/keys anymore.\n(\"Master key users\" and the master key users keyrings will still be\nlisted.) However, this was mostly an implementation detail, and it was\nintended just for debugging purposes. I don't know of anyone using it.\n\nThis patch does *not* change how \"master key users\" (->mk_users) works;\nthat still uses the keyrings subsystem. That is still needed for key\nquotas, and changing that isn't necessary to solve the issues listed\nabove. If we decide to change that too, it would be a separate patch.\n\nI've marked this as fixing the original commit that added the fscrypt\nkeyring, but as noted above the most important issue that this patch\nfixes wasn't introduced until the addition of inline encryption support.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49899" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/391cceee6d435e616f68631e68f5b32d480b1e67" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/68d15d6558a386f46d815a6ac39edecad713a1bf" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d7e7b9af104c7b389a0c21eb26532511bce4b510" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e6f4fd85ef1ee6ab356bfbd64df28c1cb73aee7e" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-753r-chc3-hcvj/GHSA-753r-chc3-hcvj.json b/advisories/unreviewed/2025/05/GHSA-753r-chc3-hcvj/GHSA-753r-chc3-hcvj.json new file mode 100644 index 00000000000..1b5cf555a71 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-753r-chc3-hcvj/GHSA-753r-chc3-hcvj.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-753r-chc3-hcvj", + "modified": "2025-05-01T15:31:44Z", + "published": "2025-05-01T15:31:44Z", + "aliases": [ + "CVE-2025-37773" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nvirtiofs: add filesystem context source name check\n\nIn certain scenarios, for example, during fuzz testing, the source\nname may be NULL, which could lead to a kernel panic. Therefore, an\nextra check for the source name should be added.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37773" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/599d1e2a6aecc44acf22fe7ea6f5e84a7e526abe" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a648d80f8d9b208beee03a2d9aa690cfacf1d41e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a94fd938df2b1628da66b498aa0eeb89593bc7a2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c3e31d613951c299487844c4d1686a933e8ee291" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f6ec52710dc5e156b774cbef5d0f5c99b1c53a80" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T14:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-75wh-ww84-2q6c/GHSA-75wh-ww84-2q6c.json b/advisories/unreviewed/2025/05/GHSA-75wh-ww84-2q6c/GHSA-75wh-ww84-2q6c.json new file mode 100644 index 00000000000..bb4ae43cc3e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-75wh-ww84-2q6c/GHSA-75wh-ww84-2q6c.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-75wh-ww84-2q6c", + "modified": "2025-05-01T15:31:44Z", + "published": "2025-05-01T15:31:44Z", + "aliases": [ + "CVE-2025-37775" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix the warning from __kernel_write_iter\n\n[ 2110.972290] ------------[ cut here ]------------\n[ 2110.972301] WARNING: CPU: 3 PID: 735 at fs/read_write.c:599 __kernel_write_iter+0x21b/0x280\n\nThis patch doesn't allow writing to directory.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37775" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1ed343481ba6911178bc5ca7a51be319eafcc747" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2a879da5c34a1e5d971e815d5b30f27eb6d69efc" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/44079e544c9f6e3e9fb43a16ddf8b08cf686d657" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b37f2f332b40ad1c27f18682a495850f2f04db0a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b7ce8db490286c2e009758fa1416d66aeb333614" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T14:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-76hj-mcwf-qj3w/GHSA-76hj-mcwf-qj3w.json b/advisories/unreviewed/2025/05/GHSA-76hj-mcwf-qj3w/GHSA-76hj-mcwf-qj3w.json new file mode 100644 index 00000000000..3b1e0085ae3 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-76hj-mcwf-qj3w/GHSA-76hj-mcwf-qj3w.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-76hj-mcwf-qj3w", + "modified": "2025-05-01T15:31:46Z", + "published": "2025-05-01T15:31:46Z", + "aliases": [ + "CVE-2022-49781" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nperf/x86/amd: Fix crash due to race between amd_pmu_enable_all, perf NMI and throttling\n\namd_pmu_enable_all() does:\n\n if (!test_bit(idx, cpuc->active_mask))\n continue;\n\n amd_pmu_enable_event(cpuc->events[idx]);\n\nA perf NMI of another event can come between these two steps. Perf NMI\nhandler internally disables and enables _all_ events, including the one\nwhich nmi-intercepted amd_pmu_enable_all() was in process of enabling.\nIf that unintentionally enabled event has very low sampling period and\ncauses immediate successive NMI, causing the event to be throttled,\ncpuc->events[idx] and cpuc->active_mask gets cleared by x86_pmu_stop().\nThis will result in amd_pmu_enable_event() getting called with event=NULL\nwhen amd_pmu_enable_all() resumes after handling the NMIs. This causes a\nkernel crash:\n\n BUG: kernel NULL pointer dereference, address: 0000000000000198\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\n [...]\n Call Trace:\n \n amd_pmu_enable_all+0x68/0xb0\n ctx_resched+0xd9/0x150\n event_function+0xb8/0x130\n ? hrtimer_start_range_ns+0x141/0x4a0\n ? perf_duration_warn+0x30/0x30\n remote_function+0x4d/0x60\n __flush_smp_call_function_queue+0xc4/0x500\n flush_smp_call_function_queue+0x11d/0x1b0\n do_idle+0x18f/0x2d0\n cpu_startup_entry+0x19/0x20\n start_secondary+0x121/0x160\n secondary_startup_64_no_verify+0xe5/0xeb\n \n\namd_pmu_disable_all()/amd_pmu_enable_all() calls inside perf NMI handler\nwere recently added as part of BRS enablement but I'm not sure whether\nwe really need them. We can just disable BRS in the beginning and enable\nit back while returning from NMI. This will solve the issue by not\nenabling those events whose active_masks are set but are not yet enabled\nin hw pmu.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49781" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/baa014b9543c8e5e94f5d15b66abfe60750b8284" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fd5e454b856ed86b090336e269695d9908609b71" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7892-j586-2q4m/GHSA-7892-j586-2q4m.json b/advisories/unreviewed/2025/05/GHSA-7892-j586-2q4m/GHSA-7892-j586-2q4m.json new file mode 100644 index 00000000000..38b0ab95b63 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7892-j586-2q4m/GHSA-7892-j586-2q4m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7892-j586-2q4m", + "modified": "2025-05-01T15:31:43Z", + "published": "2025-05-01T15:31:43Z", + "aliases": [ + "CVE-2025-23244" + ], + "details": "NVIDIA GPU Display Driver for Linux contains a vulnerability which could allow an unprivileged attacker to escalate permissions. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23244" + }, + { + "type": "WEB", + "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5630" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T14:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-79gf-mr55-pw4g/GHSA-79gf-mr55-pw4g.json b/advisories/unreviewed/2025/05/GHSA-79gf-mr55-pw4g/GHSA-79gf-mr55-pw4g.json new file mode 100644 index 00000000000..1d8e49cf42f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-79gf-mr55-pw4g/GHSA-79gf-mr55-pw4g.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-79gf-mr55-pw4g", + "modified": "2025-05-01T15:31:50Z", + "published": "2025-05-01T15:31:49Z", + "aliases": [ + "CVE-2022-49846" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nudf: Fix a slab-out-of-bounds write bug in udf_find_entry()\n\nSyzbot reported a slab-out-of-bounds Write bug:\n\nloop0: detected capacity change from 0 to 2048\n==================================================================\nBUG: KASAN: slab-out-of-bounds in udf_find_entry+0x8a5/0x14f0\nfs/udf/namei.c:253\nWrite of size 105 at addr ffff8880123ff896 by task syz-executor323/3610\n\nCPU: 0 PID: 3610 Comm: syz-executor323 Not tainted\n6.1.0-rc2-syzkaller-00105-gb229b6ca5abb #0\nHardware name: Google Compute Engine/Google Compute Engine, BIOS\nGoogle 10/11/2022\nCall Trace:\n \n __dump_stack lib/dump_stack.c:88 [inline]\n dump_stack_lvl+0x1b1/0x28e lib/dump_stack.c:106\n print_address_description+0x74/0x340 mm/kasan/report.c:284\n print_report+0x107/0x1f0 mm/kasan/report.c:395\n kasan_report+0xcd/0x100 mm/kasan/report.c:495\n kasan_check_range+0x2a7/0x2e0 mm/kasan/generic.c:189\n memcpy+0x3c/0x60 mm/kasan/shadow.c:66\n udf_find_entry+0x8a5/0x14f0 fs/udf/namei.c:253\n udf_lookup+0xef/0x340 fs/udf/namei.c:309\n lookup_open fs/namei.c:3391 [inline]\n open_last_lookups fs/namei.c:3481 [inline]\n path_openat+0x10e6/0x2df0 fs/namei.c:3710\n do_filp_open+0x264/0x4f0 fs/namei.c:3740\n do_sys_openat2+0x124/0x4e0 fs/open.c:1310\n do_sys_open fs/open.c:1326 [inline]\n __do_sys_creat fs/open.c:1402 [inline]\n __se_sys_creat fs/open.c:1396 [inline]\n __x64_sys_creat+0x11f/0x160 fs/open.c:1396\n do_syscall_x64 arch/x86/entry/common.c:50 [inline]\n do_syscall_64+0x3d/0xb0 arch/x86/entry/common.c:80\n entry_SYSCALL_64_after_hwframe+0x63/0xcd\nRIP: 0033:0x7ffab0d164d9\nCode: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89\nf7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01\nf0 ff ff 73 01 c3 48 c7 c1 c0 ff ff ff f7 d8 64 89 01 48\nRSP: 002b:00007ffe1a7e6bb8 EFLAGS: 00000246 ORIG_RAX: 0000000000000055\nRAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007ffab0d164d9\nRDX: 00007ffab0d164d9 RSI: 0000000000000000 RDI: 0000000020000180\nRBP: 00007ffab0cd5a10 R08: 0000000000000000 R09: 0000000000000000\nR10: 00005555573552c0 R11: 0000000000000246 R12: 00007ffab0cd5aa0\nR13: 0000000000000000 R14: 0000000000000000 R15: 0000000000000000\n \n\nAllocated by task 3610:\n kasan_save_stack mm/kasan/common.c:45 [inline]\n kasan_set_track+0x3d/0x60 mm/kasan/common.c:52\n ____kasan_kmalloc mm/kasan/common.c:371 [inline]\n __kasan_kmalloc+0x97/0xb0 mm/kasan/common.c:380\n kmalloc include/linux/slab.h:576 [inline]\n udf_find_entry+0x7b6/0x14f0 fs/udf/namei.c:243\n udf_lookup+0xef/0x340 fs/udf/namei.c:309\n lookup_open fs/namei.c:3391 [inline]\n open_last_lookups fs/namei.c:3481 [inline]\n path_openat+0x10e6/0x2df0 fs/namei.c:3710\n do_filp_open+0x264/0x4f0 fs/namei.c:3740\n do_sys_openat2+0x124/0x4e0 fs/open.c:1310\n do_sys_open fs/open.c:1326 [inline]\n __do_sys_creat fs/open.c:1402 [inline]\n __se_sys_creat fs/open.c:1396 [inline]\n __x64_sys_creat+0x11f/0x160 fs/open.c:1396\n do_syscall_x64 arch/x86/entry/common.c:50 [inline]\n do_syscall_64+0x3d/0xb0 arch/x86/entry/common.c:80\n entry_SYSCALL_64_after_hwframe+0x63/0xcd\n\nThe buggy address belongs to the object at ffff8880123ff800\n which belongs to the cache kmalloc-256 of size 256\nThe buggy address is located 150 bytes inside of\n 256-byte region [ffff8880123ff800, ffff8880123ff900)\n\nThe buggy address belongs to the physical page:\npage:ffffea000048ff80 refcount:1 mapcount:0 mapping:0000000000000000\nindex:0x0 pfn:0x123fe\nhead:ffffea000048ff80 order:1 compound_mapcount:0 compound_pincount:0\nflags: 0xfff00000010200(slab|head|node=0|zone=1|lastcpupid=0x7ff)\nraw: 00fff00000010200 ffffea00004b8500 dead000000000003 ffff888012041b40\nraw: 0000000000000000 0000000080100010 00000001ffffffff 0000000000000000\npage dumped because: kasan: bad access detected\npage_owner tracks the page as allocated\npage last allocated via order 0, migratetype Unmovable, gfp_mask 0x0(),\npid 1, tgid 1 (swapper/0), ts 1841222404, free_ts 0\n create_dummy_stack mm/page_owner.c:\n---truncated---", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49846" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/03f9582a6a2ebd25a440896475c968428c4b63e7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/583fdd98d94acba1e7225e5cc29063aef0741030" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7a6051d734f1ed0031e2216f9a538621235c11a4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ac79001b8e603226fab17240a79cb9ef679d3cd9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c736ed8541605e3a25075bb1cbf8f38cb3083238" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c8af247de385ce49afabc3bf1cf4fd455c94bfe8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d8971f410739a864c537e0ac29344a7b6c450232" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f1517721c408631f09d54c743aa70cb07fd3eebd" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7c48-pxh3-297c/GHSA-7c48-pxh3-297c.json b/advisories/unreviewed/2025/05/GHSA-7c48-pxh3-297c/GHSA-7c48-pxh3-297c.json new file mode 100644 index 00000000000..be88c5d509b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7c48-pxh3-297c/GHSA-7c48-pxh3-297c.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7c48-pxh3-297c", + "modified": "2025-05-01T15:31:45Z", + "published": "2025-05-01T15:31:45Z", + "aliases": [ + "CVE-2025-37796" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: at76c50x: fix use after free access in at76_disconnect\n\nThe memory pointed to by priv is freed at the end of at76_delete_device\nfunction (using ieee80211_free_hw). But the code then accesses the udev\nfield of the freed object to put the USB device. This may also lead to a\nmemory leak of the usb device. Fix this by using udev from interface.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37796" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/152721cbae42713ecfbca6847e0f102ee6b19546" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/27c7e63b3cb1a20bb78ed4a36c561ea4579fd7da" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5e7df74745700f059dc117a620e566964a2e8f2c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7ca513631fa6ad3011b8b9197cdde0f351103704" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a9682bfef2cf3802515a902e964d774e137be1b9" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T14:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7crj-grwh-6247/GHSA-7crj-grwh-6247.json b/advisories/unreviewed/2025/05/GHSA-7crj-grwh-6247/GHSA-7crj-grwh-6247.json new file mode 100644 index 00000000000..19c82935721 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7crj-grwh-6247/GHSA-7crj-grwh-6247.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7crj-grwh-6247", + "modified": "2025-05-01T15:31:49Z", + "published": "2025-05-01T15:31:49Z", + "aliases": [ + "CVE-2022-49840" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf, test_run: Fix alignment problem in bpf_prog_test_run_skb()\n\nWe got a syzkaller problem because of aarch64 alignment fault\nif KFENCE enabled. When the size from user bpf program is an odd\nnumber, like 399, 407, etc, it will cause the struct skb_shared_info's\nunaligned access. As seen below:\n\n BUG: KFENCE: use-after-free read in __skb_clone+0x23c/0x2a0 net/core/skbuff.c:1032\n\n Use-after-free read at 0xffff6254fffac077 (in kfence-#213):\n __lse_atomic_add arch/arm64/include/asm/atomic_lse.h:26 [inline]\n arch_atomic_add arch/arm64/include/asm/atomic.h:28 [inline]\n arch_atomic_inc include/linux/atomic-arch-fallback.h:270 [inline]\n atomic_inc include/asm-generic/atomic-instrumented.h:241 [inline]\n __skb_clone+0x23c/0x2a0 net/core/skbuff.c:1032\n skb_clone+0xf4/0x214 net/core/skbuff.c:1481\n ____bpf_clone_redirect net/core/filter.c:2433 [inline]\n bpf_clone_redirect+0x78/0x1c0 net/core/filter.c:2420\n bpf_prog_d3839dd9068ceb51+0x80/0x330\n bpf_dispatcher_nop_func include/linux/bpf.h:728 [inline]\n bpf_test_run+0x3c0/0x6c0 net/bpf/test_run.c:53\n bpf_prog_test_run_skb+0x638/0xa7c net/bpf/test_run.c:594\n bpf_prog_test_run kernel/bpf/syscall.c:3148 [inline]\n __do_sys_bpf kernel/bpf/syscall.c:4441 [inline]\n __se_sys_bpf+0xad0/0x1634 kernel/bpf/syscall.c:4381\n\n kfence-#213: 0xffff6254fffac000-0xffff6254fffac196, size=407, cache=kmalloc-512\n\n allocated by task 15074 on cpu 0 at 1342.585390s:\n kmalloc include/linux/slab.h:568 [inline]\n kzalloc include/linux/slab.h:675 [inline]\n bpf_test_init.isra.0+0xac/0x290 net/bpf/test_run.c:191\n bpf_prog_test_run_skb+0x11c/0xa7c net/bpf/test_run.c:512\n bpf_prog_test_run kernel/bpf/syscall.c:3148 [inline]\n __do_sys_bpf kernel/bpf/syscall.c:4441 [inline]\n __se_sys_bpf+0xad0/0x1634 kernel/bpf/syscall.c:4381\n __arm64_sys_bpf+0x50/0x60 kernel/bpf/syscall.c:4381\n\nTo fix the problem, we adjust @size so that (@size + @hearoom) is a\nmultiple of SMP_CACHE_BYTES. So we make sure the struct skb_shared_info\nis aligned to a cache line.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49840" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/047824a730699c6c66df43306b80f700c9dfc2fd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1b597f2d6a55e9f549989913860ad5170da04964" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/730fb1ef974a13915bc7651364d8b3318891cd70" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7a704dbfd3735304e261f2787c52fbc7c3884736" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d3fd203f36d46aa29600a72d57a1b61af80e4a25" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e60f37a1d379c821c17b08f366412dce9ef3d99f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/eaa8edd86514afac9deb9bf9a5053e74f37edf40" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7fmq-qw39-x2x2/GHSA-7fmq-qw39-x2x2.json b/advisories/unreviewed/2025/05/GHSA-7fmq-qw39-x2x2/GHSA-7fmq-qw39-x2x2.json new file mode 100644 index 00000000000..47bba19dc7c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7fmq-qw39-x2x2/GHSA-7fmq-qw39-x2x2.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7fmq-qw39-x2x2", + "modified": "2025-05-01T15:31:49Z", + "published": "2025-05-01T15:31:49Z", + "aliases": [ + "CVE-2022-49830" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/drv: Fix potential memory leak in drm_dev_init()\n\ndrm_dev_init() will add drm_dev_init_release() as a callback. When\ndrmm_add_action() failed, the release function won't be added. As the\nresult, the ref cnt added by device_get() in drm_dev_init() won't be put\nby drm_dev_init_release(), which leads to the memleak. Use\ndrmm_add_action_or_reset() instead of drmm_add_action() to prevent\nmemleak.\n\nunreferenced object 0xffff88810bc0c800 (size 2048):\n comm \"modprobe\", pid 8322, jiffies 4305809845 (age 15.292s)\n hex dump (first 32 bytes):\n e8 cc c0 0b 81 88 ff ff ff ff ff ff 00 00 00 00 ................\n 20 24 3c 0c 81 88 ff ff 18 c8 c0 0b 81 88 ff ff $<.............\n backtrace:\n [<000000007251f72d>] __kmalloc+0x4b/0x1c0\n [<0000000045f21f26>] platform_device_alloc+0x2d/0xe0\n [<000000004452a479>] platform_device_register_full+0x24/0x1c0\n [<0000000089f4ea61>] 0xffffffffa0736051\n [<00000000235b2441>] do_one_initcall+0x7a/0x380\n [<0000000001a4a177>] do_init_module+0x5c/0x230\n [<000000002bf8a8e2>] load_module+0x227d/0x2420\n [<00000000637d6d0a>] __do_sys_finit_module+0xd5/0x140\n [<00000000c99fc324>] do_syscall_64+0x3f/0x90\n [<000000004d85aa77>] entry_SYSCALL_64_after_hwframe+0x63/0xcd", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49830" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/07e56de8766fe5be67252596244b84ac0ec0de91" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bd8d1335e6e70a396094ef98913b513140c0b86b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c47a823ea186263ab69cfb665327b7f72cb5e779" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ff963634f7b2e0dc011349abb3fb81a0d074f443" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7jp4-523x-8hmf/GHSA-7jp4-523x-8hmf.json b/advisories/unreviewed/2025/05/GHSA-7jp4-523x-8hmf/GHSA-7jp4-523x-8hmf.json new file mode 100644 index 00000000000..e02d2c417a1 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7jp4-523x-8hmf/GHSA-7jp4-523x-8hmf.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7jp4-523x-8hmf", + "modified": "2025-05-01T15:31:46Z", + "published": "2025-05-01T15:31:46Z", + "aliases": [ + "CVE-2022-49774" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: x86/xen: Fix eventfd error handling in kvm_xen_eventfd_assign()\n\nShould not call eventfd_ctx_put() in case of error.\n\n[Introduce new goto target instead. - Paolo]", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49774" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7353633814f6e5b4899fb9ee1483709d6bb0e1cd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d76f46f47dfde220712d1420ee5dbc546c8fc674" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7jq4-g7p4-jx98/GHSA-7jq4-g7p4-jx98.json b/advisories/unreviewed/2025/05/GHSA-7jq4-g7p4-jx98/GHSA-7jq4-g7p4-jx98.json new file mode 100644 index 00000000000..301d577df73 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7jq4-g7p4-jx98/GHSA-7jq4-g7p4-jx98.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7jq4-g7p4-jx98", + "modified": "2025-05-01T15:31:44Z", + "published": "2025-05-01T15:31:44Z", + "aliases": [ + "CVE-2025-37771" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/pm: Prevent division by zero\n\nThe user can set any speed value.\nIf speed is greater than UINT_MAX/8, division by zero is possible.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37771" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/402964994e8ece29702383b234fabcf04791ff95" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5096174074114f83c700a27869c54362cbb10f3e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6413fed016208171592c88b5df002af8a1387e24" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7d641c2b83275d3b0424127b2e0d2d0f7dd82aef" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/baa54adb5e0599299b8f088efb5544d876a3eb62" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T14:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7jwj-6g7w-4c9q/GHSA-7jwj-6g7w-4c9q.json b/advisories/unreviewed/2025/05/GHSA-7jwj-6g7w-4c9q/GHSA-7jwj-6g7w-4c9q.json new file mode 100644 index 00000000000..17e20c005db --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7jwj-6g7w-4c9q/GHSA-7jwj-6g7w-4c9q.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7jwj-6g7w-4c9q", + "modified": "2025-05-01T15:31:49Z", + "published": "2025-05-01T15:31:49Z", + "aliases": [ + "CVE-2022-49834" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: fix use-after-free bug of ns_writer on remount\n\nIf a nilfs2 filesystem is downgraded to read-only due to metadata\ncorruption on disk and is remounted read/write, or if emergency read-only\nremount is performed, detaching a log writer and synchronizing the\nfilesystem can be done at the same time.\n\nIn these cases, use-after-free of the log writer (hereinafter\nnilfs->ns_writer) can happen as shown in the scenario below:\n\n Task1 Task2\n -------------------------------- ------------------------------\n nilfs_construct_segment\n nilfs_segctor_sync\n init_wait\n init_waitqueue_entry\n add_wait_queue\n schedule\n nilfs_remount (R/W remount case)\n\t\t\t\t nilfs_attach_log_writer\n nilfs_detach_log_writer\n nilfs_segctor_destroy\n kfree\n finish_wait\n _raw_spin_lock_irqsave\n __raw_spin_lock_irqsave\n do_raw_spin_lock\n debug_spin_lock_before <-- use-after-free\n\nWhile Task1 is sleeping, nilfs->ns_writer is freed by Task2. After Task1\nwaked up, Task1 accesses nilfs->ns_writer which is already freed. This\nscenario diagram is based on the Shigeru Yoshida's post [1].\n\nThis patch fixes the issue by not detaching nilfs->ns_writer on remount so\nthat this UAF race doesn't happen. Along with this change, this patch\nalso inserts a few necessary read-only checks with superblock instance\nwhere only the ns_writer pointer was used to check if the filesystem is\nread-only.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49834" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/39a3ed68270b079c6b874d4e4727a512b9b4882c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4feedde5486c07ea79787839153a71ca71329c7d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8cccf05fe857a18ee26e20d11a8455a73ffd4efd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9b162e81045266a2d5b44df9dffdf05c54de9cca" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/afbd1188382a75f6cfe22c0b68533f7f9664f182" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b152300d5a1ba4258dacf9916bff20e6a8c7603b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b2fbf10040216ef5ee270773755fc2f5da65b749" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b4736ab5542112fe0a40f140a0a0b072954f34da" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7m6j-5mcx-6jmq/GHSA-7m6j-5mcx-6jmq.json b/advisories/unreviewed/2025/05/GHSA-7m6j-5mcx-6jmq/GHSA-7m6j-5mcx-6jmq.json new file mode 100644 index 00000000000..7472024d3ab --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7m6j-5mcx-6jmq/GHSA-7m6j-5mcx-6jmq.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7m6j-5mcx-6jmq", + "modified": "2025-05-01T15:31:52Z", + "published": "2025-05-01T15:31:52Z", + "aliases": [ + "CVE-2022-49903" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: fix WARNING in ip6_route_net_exit_late()\n\nDuring the initialization of ip6_route_net_init_late(), if file\nipv6_route or rt6_stats fails to be created, the initialization is\nsuccessful by default. Therefore, the ipv6_route or rt6_stats file\ndoesn't be found during the remove in ip6_route_net_exit_late(). It\nwill cause WRNING.\n\nThe following is the stack information:\nname 'rt6_stats'\nWARNING: CPU: 0 PID: 9 at fs/proc/generic.c:712 remove_proc_entry+0x389/0x460\nModules linked in:\nWorkqueue: netns cleanup_net\nRIP: 0010:remove_proc_entry+0x389/0x460\nPKRU: 55555554\nCall Trace:\n\nops_exit_list+0xb0/0x170\ncleanup_net+0x4ea/0xb00\nprocess_one_work+0x9bf/0x1710\nworker_thread+0x665/0x1080\nkthread+0x2e4/0x3a0\nret_from_fork+0x1f/0x30\n", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49903" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/080589287127838046077904f34d5054ea0f895c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0ed71af4d017d2bd2cbb8f7254f613a4914def26" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/381453770f731f0f43616a1cd4c759b7807a1517" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5dbb47ee89762da433cd8458788d7640c85f1a07" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/768b3c745fe5789f2430bdab02f35a9ad1148d97" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/83fbf246ced54dadd7b9adc2a16efeff30ba944d" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7mv8-qr93-j282/GHSA-7mv8-qr93-j282.json b/advisories/unreviewed/2025/05/GHSA-7mv8-qr93-j282/GHSA-7mv8-qr93-j282.json new file mode 100644 index 00000000000..8ae82c84e79 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7mv8-qr93-j282/GHSA-7mv8-qr93-j282.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7mv8-qr93-j282", + "modified": "2025-05-01T15:31:44Z", + "published": "2025-05-01T15:31:44Z", + "aliases": [ + "CVE-2025-37786" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: dsa: free routing table on probe failure\n\nIf complete = true in dsa_tree_setup(), it means that we are the last\nswitch of the tree which is successfully probing, and we should be\nsetting up all switches from our probe path.\n\nAfter \"complete\" becomes true, dsa_tree_setup_cpu_ports() or any\nsubsequent function may fail. If that happens, the entire tree setup is\nin limbo: the first N-1 switches have successfully finished probing\n(doing nothing but having allocated persistent memory in the tree's\ndst->ports, and maybe dst->rtable), and switch N failed to probe, ending\nthe tree setup process before anything is tangible from the user's PoV.\n\nIf switch N fails to probe, its memory (ports) will be freed and removed\nfrom dst->ports. However, the dst->rtable elements pointing to its ports,\nas created by dsa_link_touch(), will remain there, and will lead to\nuse-after-free if dereferenced.\n\nIf dsa_tree_setup_switches() returns -EPROBE_DEFER, which is entirely\npossible because that is where ds->ops->setup() is, we get a kasan\nreport like this:\n\n==================================================================\nBUG: KASAN: slab-use-after-free in mv88e6xxx_setup_upstream_port+0x240/0x568\nRead of size 8 at addr ffff000004f56020 by task kworker/u8:3/42\n\nCall trace:\n __asan_report_load8_noabort+0x20/0x30\n mv88e6xxx_setup_upstream_port+0x240/0x568\n mv88e6xxx_setup+0xebc/0x1eb0\n dsa_register_switch+0x1af4/0x2ae0\n mv88e6xxx_register_switch+0x1b8/0x2a8\n mv88e6xxx_probe+0xc4c/0xf60\n mdio_probe+0x78/0xb8\n really_probe+0x2b8/0x5a8\n __driver_probe_device+0x164/0x298\n driver_probe_device+0x78/0x258\n __device_attach_driver+0x274/0x350\n\nAllocated by task 42:\n __kasan_kmalloc+0x84/0xa0\n __kmalloc_cache_noprof+0x298/0x490\n dsa_switch_touch_ports+0x174/0x3d8\n dsa_register_switch+0x800/0x2ae0\n mv88e6xxx_register_switch+0x1b8/0x2a8\n mv88e6xxx_probe+0xc4c/0xf60\n mdio_probe+0x78/0xb8\n really_probe+0x2b8/0x5a8\n __driver_probe_device+0x164/0x298\n driver_probe_device+0x78/0x258\n __device_attach_driver+0x274/0x350\n\nFreed by task 42:\n __kasan_slab_free+0x48/0x68\n kfree+0x138/0x418\n dsa_register_switch+0x2694/0x2ae0\n mv88e6xxx_register_switch+0x1b8/0x2a8\n mv88e6xxx_probe+0xc4c/0xf60\n mdio_probe+0x78/0xb8\n really_probe+0x2b8/0x5a8\n __driver_probe_device+0x164/0x298\n driver_probe_device+0x78/0x258\n __device_attach_driver+0x274/0x350\n\nThe simplest way to fix the bug is to delete the routing table in its\nentirety. dsa_tree_setup_routing_table() has no problem in regenerating\nit even if we deleted links between ports other than those of switch N,\nbecause dsa_link_touch() first checks whether the port pair already\nexists in dst->rtable, allocating if not.\n\nThe deletion of the routing table in its entirety already exists in\ndsa_tree_teardown(), so refactor that into a function that can also be\ncalled from the tree setup error path.\n\nIn my analysis of the commit to blame, it is the one which added\ndsa_link elements to dst->rtable. Prior to that, each switch had its own\nds->rtable which is freed when the switch fails to probe. But the tree\nis potentially persistent memory.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37786" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5c8066fbdb9653c6e9a224bdcd8f9c91a484f0de" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8bf108d7161ffc6880ad13a0cc109de3cf631727" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a038f5f15af455dfe35bc68549e02b950978700a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fb12b460ec46c9efad98de6d9ba349691db51dc7" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T14:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7pwg-2v7p-j53q/GHSA-7pwg-2v7p-j53q.json b/advisories/unreviewed/2025/05/GHSA-7pwg-2v7p-j53q/GHSA-7pwg-2v7p-j53q.json new file mode 100644 index 00000000000..05986249c08 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7pwg-2v7p-j53q/GHSA-7pwg-2v7p-j53q.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7pwg-2v7p-j53q", + "modified": "2025-05-01T15:31:44Z", + "published": "2025-05-01T15:31:44Z", + "aliases": [ + "CVE-2025-37779" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nlib/iov_iter: fix to increase non slab folio refcount\n\nWhen testing EROFS file-backed mount over v9fs on qemu, I encountered a\nfolio UAF issue. The page sanity check reports the following call trace. \nThe root cause is that pages in bvec are coalesced across a folio bounary.\nThe refcount of all non-slab folios should be increased to ensure\np9_releas_pages can put them correctly.\n\nBUG: Bad page state in process md5sum pfn:18300\npage: refcount:0 mapcount:0 mapping:00000000d5ad8e4e index:0x60 pfn:0x18300\nhead: order:0 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0\naops:z_erofs_aops ino:30b0f dentry name(?):\"GoogleExtServicesCn.apk\"\nflags: 0x100000000000041(locked|head|node=0|zone=1)\nraw: 0100000000000041 dead000000000100 dead000000000122 ffff888014b13bd0\nraw: 0000000000000060 0000000000000020 00000000ffffffff 0000000000000000\nhead: 0100000000000041 dead000000000100 dead000000000122 ffff888014b13bd0\nhead: 0000000000000060 0000000000000020 00000000ffffffff 0000000000000000\nhead: 0100000000000000 0000000000000000 ffffffffffffffff 0000000000000000\nhead: 0000000000000010 0000000000000000 00000000ffffffff 0000000000000000\npage dumped because: PAGE_FLAGS_CHECK_AT_FREE flag(s) set\nCall Trace:\n dump_stack_lvl+0x53/0x70\n bad_page+0xd4/0x220\n __free_pages_ok+0x76d/0xf30\n __folio_put+0x230/0x320\n p9_release_pages+0x179/0x1f0\n p9_virtio_zc_request+0xa2a/0x1230\n p9_client_zc_rpc.constprop.0+0x247/0x700\n p9_client_read_once+0x34d/0x810\n p9_client_read+0xf3/0x150\n v9fs_issue_read+0x111/0x360\n netfs_unbuffered_read_iter_locked+0x927/0x1390\n netfs_unbuffered_read_iter+0xa2/0xe0\n vfs_iocb_iter_read+0x2c7/0x460\n erofs_fileio_rq_submit+0x46b/0x5b0\n z_erofs_runqueue+0x1203/0x21e0\n z_erofs_readahead+0x579/0x8b0\n read_pages+0x19f/0xa70\n page_cache_ra_order+0x4ad/0xb80\n filemap_readahead.isra.0+0xe7/0x150\n filemap_get_pages+0x7aa/0x1890\n filemap_read+0x320/0xc80\n vfs_read+0x6c6/0xa30\n ksys_read+0xf9/0x1c0\n do_syscall_64+0x9e/0x1a0\n entry_SYSCALL_64_after_hwframe+0x71/0x79", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37779" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/770c8d55c42868239c748a3ebc57c9e37755f842" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d833f21162c4d536d729628f8cf1ee8d4110f2b7" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T14:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7qcm-qx74-j7hr/GHSA-7qcm-qx74-j7hr.json b/advisories/unreviewed/2025/05/GHSA-7qcm-qx74-j7hr/GHSA-7qcm-qx74-j7hr.json new file mode 100644 index 00000000000..9f253cfeaab --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7qcm-qx74-j7hr/GHSA-7qcm-qx74-j7hr.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7qcm-qx74-j7hr", + "modified": "2025-05-01T15:31:53Z", + "published": "2025-05-01T15:31:52Z", + "aliases": [ + "CVE-2022-49916" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nrose: Fix NULL pointer dereference in rose_send_frame()\n\nThe syzkaller reported an issue:\n\nKASAN: null-ptr-deref in range [0x0000000000000380-0x0000000000000387]\nCPU: 0 PID: 4069 Comm: kworker/0:15 Not tainted 6.0.0-syzkaller-02734-g0326074ff465 #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/22/2022\nWorkqueue: rcu_gp srcu_invoke_callbacks\nRIP: 0010:rose_send_frame+0x1dd/0x2f0 net/rose/rose_link.c:101\nCall Trace:\n \n rose_transmit_clear_request+0x1d5/0x290 net/rose/rose_link.c:255\n rose_rx_call_request+0x4c0/0x1bc0 net/rose/af_rose.c:1009\n rose_loopback_timer+0x19e/0x590 net/rose/rose_loopback.c:111\n call_timer_fn+0x1a0/0x6b0 kernel/time/timer.c:1474\n expire_timers kernel/time/timer.c:1519 [inline]\n __run_timers.part.0+0x674/0xa80 kernel/time/timer.c:1790\n __run_timers kernel/time/timer.c:1768 [inline]\n run_timer_softirq+0xb3/0x1d0 kernel/time/timer.c:1803\n __do_softirq+0x1d0/0x9c8 kernel/softirq.c:571\n [...]\n \n\nIt triggers NULL pointer dereference when 'neigh->dev->dev_addr' is\ncalled in the rose_send_frame(). It's the first occurrence of the\n`neigh` is in rose_loopback_timer() as `rose_loopback_neigh', and\nthe 'dev' in 'rose_loopback_neigh' is initialized sa nullptr.\n\nIt had been fixed by commit 3b3fd068c56e3fbea30090859216a368398e39bf\n(\"rose: Fix Null pointer dereference in rose_send_frame()\") ever.\nBut it's introduced by commit 3c53cd65dece47dd1f9d3a809f32e59d1d87b2b8\n(\"rose: check NULL rose_loopback_neigh->loopback\") again.\n\nWe fix it by add NULL check in rose_transmit_clear_request(). When\nthe 'dev' in 'neigh' is NULL, we don't reply the request and just\nclear it.\n\nsyzkaller don't provide repro, and I provide a syz repro like:\nr0 = syz_init_net_socket$bt_sco(0x1f, 0x5, 0x2)\nioctl$sock_inet_SIOCSIFFLAGS(r0, 0x8914, &(0x7f0000000180)={'rose0\\x00', 0x201})\nr1 = syz_init_net_socket$rose(0xb, 0x5, 0x0)\nbind$rose(r1, &(0x7f00000000c0)=@full={0xb, @dev, @null, 0x0, [@null, @null, @netrom, @netrom, @default, @null]}, 0x40)\nconnect$rose(r1, &(0x7f0000000240)=@short={0xb, @dev={0xbb, 0xbb, 0xbb, 0x1, 0x0}, @remote={0xcc, 0xcc, 0xcc, 0xcc, 0xcc, 0xcc, 0x1}, 0x1, @netrom={0xbb, 0xbb, 0xbb, 0xbb, 0xbb, 0x0, 0x0}}, 0x1c)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49916" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/01b9c68c121847d05a4ccef68244dadf82bfa331" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3e2129c67daca21043a26575108f6286c85e71f6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5b46adfbee1e429f33b10a88d6c00fa88f3d6c77" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a601e5eded33bb88b8a42743db8fef3ad41dd97e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b13be5e852b03f376058027e462fad4230240891" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bbc03d74e641e824754443b908454ca9e203773e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e97c089d7a49f67027395ddf70bf327eeac2611e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f06186e5271b980bac03f5c97276ed0146ddc9b0" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7vfx-9973-f38h/GHSA-7vfx-9973-f38h.json b/advisories/unreviewed/2025/05/GHSA-7vfx-9973-f38h/GHSA-7vfx-9973-f38h.json new file mode 100644 index 00000000000..78c4471778f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7vfx-9973-f38h/GHSA-7vfx-9973-f38h.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7vfx-9973-f38h", + "modified": "2025-05-01T15:31:45Z", + "published": "2025-05-01T15:31:44Z", + "aliases": [ + "CVE-2025-37783" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/msm/dpu: Fix error pointers in dpu_plane_virtual_atomic_check\n\nThe function dpu_plane_virtual_atomic_check was dereferencing pointers\nreturned by drm_atomic_get_plane_state without checking for errors. This\ncould lead to undefined behavior if the function returns an error pointer.\n\nThis commit adds checks using IS_ERR to ensure that plane_state is\nvalid before dereferencing them.\n\nSimilar to commit da29abe71e16\n(\"drm/amd/display: Fix error pointers in amdgpu_dm_crtc_mem_type_changed\").\n\nPatchwork: https://patchwork.freedesktop.org/patch/643132/", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37783" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5cb1b130e1cd04239cc9c26a98279f4660dce583" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a9670ed1cce3216778c89936d3ae91cf0d436035" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T14:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7wj3-cv8c-chpx/GHSA-7wj3-cv8c-chpx.json b/advisories/unreviewed/2025/05/GHSA-7wj3-cv8c-chpx/GHSA-7wj3-cv8c-chpx.json new file mode 100644 index 00000000000..67167d4b1cb --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7wj3-cv8c-chpx/GHSA-7wj3-cv8c-chpx.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7wj3-cv8c-chpx", + "modified": "2025-05-01T15:31:46Z", + "published": "2025-05-01T15:31:46Z", + "aliases": [ + "CVE-2022-49764" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Prevent bpf program recursion for raw tracepoint probes\n\nWe got report from sysbot [1] about warnings that were caused by\nbpf program attached to contention_begin raw tracepoint triggering\nthe same tracepoint by using bpf_trace_printk helper that takes\ntrace_printk_lock lock.\n\n Call Trace:\n \n ? trace_event_raw_event_bpf_trace_printk+0x5f/0x90\n bpf_trace_printk+0x2b/0xe0\n bpf_prog_a9aec6167c091eef_prog+0x1f/0x24\n bpf_trace_run2+0x26/0x90\n native_queued_spin_lock_slowpath+0x1c6/0x2b0\n _raw_spin_lock_irqsave+0x44/0x50\n bpf_trace_printk+0x3f/0xe0\n bpf_prog_a9aec6167c091eef_prog+0x1f/0x24\n bpf_trace_run2+0x26/0x90\n native_queued_spin_lock_slowpath+0x1c6/0x2b0\n _raw_spin_lock_irqsave+0x44/0x50\n bpf_trace_printk+0x3f/0xe0\n bpf_prog_a9aec6167c091eef_prog+0x1f/0x24\n bpf_trace_run2+0x26/0x90\n native_queued_spin_lock_slowpath+0x1c6/0x2b0\n _raw_spin_lock_irqsave+0x44/0x50\n bpf_trace_printk+0x3f/0xe0\n bpf_prog_a9aec6167c091eef_prog+0x1f/0x24\n bpf_trace_run2+0x26/0x90\n native_queued_spin_lock_slowpath+0x1c6/0x2b0\n _raw_spin_lock_irqsave+0x44/0x50\n __unfreeze_partials+0x5b/0x160\n ...\n\nThe can be reproduced by attaching bpf program as raw tracepoint on\ncontention_begin tracepoint. The bpf prog calls bpf_trace_printk\nhelper. Then by running perf bench the spin lock code is forced to\ntake slow path and call contention_begin tracepoint.\n\nFixing this by skipping execution of the bpf program if it's\nalready running, Using bpf prog 'active' field, which is being\ncurrently used by trampoline programs for the same reason.\n\nMoving bpf_prog_inc_misses_counter to syscall.c because\ntrampoline.c is compiled in just for CONFIG_BPF_JIT option.\n\n[1] https://lore.kernel.org/bpf/YxhFe3EwqchC%2FfYf@krava/T/#t", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49764" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/05b24ff9b2cfabfcfd951daaa915a036ab53c9e1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2e5399879024fedd6cdc41f73fbf9bbe7208f899" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-82pr-9mpc-vgv5/GHSA-82pr-9mpc-vgv5.json b/advisories/unreviewed/2025/05/GHSA-82pr-9mpc-vgv5/GHSA-82pr-9mpc-vgv5.json new file mode 100644 index 00000000000..8920d43c278 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-82pr-9mpc-vgv5/GHSA-82pr-9mpc-vgv5.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-82pr-9mpc-vgv5", + "modified": "2025-05-01T15:31:51Z", + "published": "2025-05-01T15:31:51Z", + "aliases": [ + "CVE-2022-49879" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\next4: fix BUG_ON() when directory entry has invalid rec_len\n\nThe rec_len field in the directory entry has to be a multiple of 4. A\ncorrupted filesystem image can be used to hit a BUG() in\next4_rec_len_to_disk(), called from make_indexed_dir().\n\n ------------[ cut here ]------------\n kernel BUG at fs/ext4/ext4.h:2413!\n ...\n RIP: 0010:make_indexed_dir+0x53f/0x5f0\n ...\n Call Trace:\n \n ? add_dirent_to_buf+0x1b2/0x200\n ext4_add_entry+0x36e/0x480\n ext4_add_nondir+0x2b/0xc0\n ext4_create+0x163/0x200\n path_openat+0x635/0xe90\n do_filp_open+0xb4/0x160\n ? __create_object.isra.0+0x1de/0x3b0\n ? _raw_spin_unlock+0x12/0x30\n do_sys_openat2+0x91/0x150\n __x64_sys_open+0x6c/0xa0\n do_syscall_64+0x3c/0x80\n entry_SYSCALL_64_after_hwframe+0x46/0xb0\n\nThe fix simply adds a call to ext4_check_dir_entry() to validate the\ndirectory entry, returning -EFSCORRUPTED if the entry is invalid.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49879" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/156451a67b93986fb07c274ef6995ff40766c5ad" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/17a0bc9bd697f75cfdf9b378d5eb2d7409c91340" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2fa24d0274fbf913b56ee31f15bc01168669d909" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/999cff2b6ce3b45c08abf793bf55534777421327" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ce1ee2c8827fb6493e91acbd50f664cf2a972c3d" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8cr8-whqv-vm3j/GHSA-8cr8-whqv-vm3j.json b/advisories/unreviewed/2025/05/GHSA-8cr8-whqv-vm3j/GHSA-8cr8-whqv-vm3j.json new file mode 100644 index 00000000000..4b4794bfe28 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8cr8-whqv-vm3j/GHSA-8cr8-whqv-vm3j.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8cr8-whqv-vm3j", + "modified": "2025-05-01T15:31:49Z", + "published": "2025-05-01T15:31:49Z", + "aliases": [ + "CVE-2022-49839" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: scsi_transport_sas: Fix error handling in sas_phy_add()\n\nIf transport_add_device() fails in sas_phy_add(), the kernel will crash\ntrying to delete the device in transport_remove_device() called from\nsas_remove_host().\n\nUnable to handle kernel NULL pointer dereference at virtual address 0000000000000108\nCPU: 61 PID: 42829 Comm: rmmod Kdump: loaded Tainted: G W 6.1.0-rc1+ #173\npstate: 60000005 (nZCv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)\npc : device_del+0x54/0x3d0\nlr : device_del+0x37c/0x3d0\nCall trace:\n device_del+0x54/0x3d0\n attribute_container_class_device_del+0x28/0x38\n transport_remove_classdev+0x6c/0x80\n attribute_container_device_trigger+0x108/0x110\n transport_remove_device+0x28/0x38\n sas_phy_delete+0x30/0x60 [scsi_transport_sas]\n do_sas_phy_delete+0x6c/0x80 [scsi_transport_sas]\n device_for_each_child+0x68/0xb0\n sas_remove_children+0x40/0x50 [scsi_transport_sas]\n sas_remove_host+0x20/0x38 [scsi_transport_sas]\n hisi_sas_remove+0x40/0x68 [hisi_sas_main]\n hisi_sas_v2_remove+0x20/0x30 [hisi_sas_v2_hw]\n platform_remove+0x2c/0x60\n\nFix this by checking and handling return value of transport_add_device()\nin sas_phy_add().", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49839" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/03aabcb88aeeb7221ddb6196ae84ad5fb17b743f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2f21d653c648735657e23948b1d7ac7273de0f87" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5d7bebf2dfb0dc97aac1fbace0910e557ecdb16f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c736876ee294bb4f271d76a25cc7d70c8537bc5d" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8fmx-5gmc-pfcw/GHSA-8fmx-5gmc-pfcw.json b/advisories/unreviewed/2025/05/GHSA-8fmx-5gmc-pfcw/GHSA-8fmx-5gmc-pfcw.json new file mode 100644 index 00000000000..3b63c173926 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8fmx-5gmc-pfcw/GHSA-8fmx-5gmc-pfcw.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8fmx-5gmc-pfcw", + "modified": "2025-05-01T15:31:52Z", + "published": "2025-05-01T15:31:52Z", + "aliases": [ + "CVE-2022-49905" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/smc: Fix possible leaked pernet namespace in smc_init()\n\nIn smc_init(), register_pernet_subsys(&smc_net_stat_ops) is called\nwithout any error handling.\nIf it fails, registering of &smc_net_ops won't be reverted.\nAnd if smc_nl_init() fails, &smc_net_stat_ops itself won't be reverted.\n\nThis leaves wild ops in subsystem linkedlist and when another module\ntries to call register_pernet_operations() it triggers page fault:\n\nBUG: unable to handle page fault for address: fffffbfff81b964c\nRIP: 0010:register_pernet_operations+0x1b9/0x5f0\nCall Trace:\n \n register_pernet_subsys+0x29/0x40\n ebtables_init+0x58/0x1000 [ebtables]\n ...", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49905" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/61defd6450a9ef4a1487090449999b0fd83518ef" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/62ff373da2534534c55debe6c724c7fe14adb97f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c97daf836f7caf81d3144b8cd2b2a51f9bc3bd09" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8gr9-8p2v-p75h/GHSA-8gr9-8p2v-p75h.json b/advisories/unreviewed/2025/05/GHSA-8gr9-8p2v-p75h/GHSA-8gr9-8p2v-p75h.json new file mode 100644 index 00000000000..41c215fad25 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8gr9-8p2v-p75h/GHSA-8gr9-8p2v-p75h.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8gr9-8p2v-p75h", + "modified": "2025-05-01T15:31:45Z", + "published": "2025-05-01T15:31:45Z", + "aliases": [ + "CVE-2025-44835" + ], + "details": "D-Link DIR-816 A2V1.1.0B05 was found to contain a command injection in iptablesWebsFilterRun, which allows remote attackers to execute arbitrary commands via shell.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44835" + }, + { + "type": "WEB", + "url": "https://github.com/n0wstr/IOTVuln/tree/main/DIR-816/IptablesWebsFilterRun" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T14:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8hc6-8j6c-v3p8/GHSA-8hc6-8j6c-v3p8.json b/advisories/unreviewed/2025/05/GHSA-8hc6-8j6c-v3p8/GHSA-8hc6-8j6c-v3p8.json new file mode 100644 index 00000000000..c60fe9223b0 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8hc6-8j6c-v3p8/GHSA-8hc6-8j6c-v3p8.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8hc6-8j6c-v3p8", + "modified": "2025-05-01T15:31:46Z", + "published": "2025-05-01T15:31:46Z", + "aliases": [ + "CVE-2022-49777" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nInput: i8042 - fix leaking of platform device on module removal\n\nAvoid resetting the module-wide i8042_platform_device pointer in\ni8042_probe() or i8042_remove(), so that the device can be properly\ndestroyed by i8042_exit() on module unload.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49777" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3f25add5ecf88de0f8ff2b27b6c0731a1f1b38ed" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4f348b60c79671eee33c1389efe89109c93047da" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/81cd7e8489278d28794e7b272950c3e00c344e44" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/81df118e79b2136b5c016394f67a051dc508b7b6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a32cd7feb0127bf629a82686b6e2c128139a86e5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d5f7f6e63fed9c2ed09725d90059a28907e197e3" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8mgc-hp6q-8pj5/GHSA-8mgc-hp6q-8pj5.json b/advisories/unreviewed/2025/05/GHSA-8mgc-hp6q-8pj5/GHSA-8mgc-hp6q-8pj5.json new file mode 100644 index 00000000000..337a647c89d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8mgc-hp6q-8pj5/GHSA-8mgc-hp6q-8pj5.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8mgc-hp6q-8pj5", + "modified": "2025-05-01T15:31:46Z", + "published": "2025-05-01T15:31:46Z", + "aliases": [ + "CVE-2022-49773" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Fix optc2_configure warning on dcn314\n\n[Why]\ndcn314 uses optc2_configure_crc() that wraps\noptc1_configure_crc() + set additional registers\nnot applicable to dcn314.\nIt's not critical but when used leads to warning like:\nWARNING: drivers/gpu/drm/amd/amdgpu/../display/dc/dc_helper.c\nCall Trace:\n\ngeneric_reg_set_ex+0x6d/0xe0 [amdgpu]\noptc2_configure_crc+0x60/0x80 [amdgpu]\ndc_stream_configure_crc+0x129/0x150 [amdgpu]\namdgpu_dm_crtc_configure_crc_source+0x5d/0xe0 [amdgpu]\n\n[How]\nUse optc1_configure_crc() directly", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49773" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e7e4f77c991c9abf90924929a9d55f90b0bb78de" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f67ef5aa88e3db0a13ae3befab2ddf14ac00a91c" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8p4g-7vvj-g5r6/GHSA-8p4g-7vvj-g5r6.json b/advisories/unreviewed/2025/05/GHSA-8p4g-7vvj-g5r6/GHSA-8p4g-7vvj-g5r6.json new file mode 100644 index 00000000000..454bd0b0520 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8p4g-7vvj-g5r6/GHSA-8p4g-7vvj-g5r6.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8p4g-7vvj-g5r6", + "modified": "2025-05-01T15:31:52Z", + "published": "2025-05-01T15:31:52Z", + "aliases": [ + "CVE-2022-49915" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmISDN: fix possible memory leak in mISDN_register_device()\n\nAfer commit 1fa5ae857bb1 (\"driver core: get rid of struct device's\nbus_id string array\"), the name of device is allocated dynamically,\nadd put_device() to give up the reference, so that the name can be\nfreed in kobject_cleanup() when the refcount is 0.\n\nSet device class before put_device() to avoid null release() function\nWARN message in device_release().", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49915" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/029d5b7688a2f3a86f2a3be5a6ba9cc968c80e41" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/080aabfb29b2ee9cbb8894a1d039651943d3773e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0d4e91efcaee081e919b3c50e875ecbb84290e41" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2ff6b669523d3b3d253a044fa9636a67d0694995" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a636fc5a7cabd05699b5692ad838c2c7a3abec7b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d1d1aede313eb2b9a84afd60ff6cfb7c33631e0e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e77d213843e67b4373285712699b692f9c743f61" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e7d1d4d9ac0dfa40be4c2c8abd0731659869b297" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8p4q-63f6-rqfp/GHSA-8p4q-63f6-rqfp.json b/advisories/unreviewed/2025/05/GHSA-8p4q-63f6-rqfp/GHSA-8p4q-63f6-rqfp.json new file mode 100644 index 00000000000..75e71ee9327 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8p4q-63f6-rqfp/GHSA-8p4q-63f6-rqfp.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8p4q-63f6-rqfp", + "modified": "2025-05-01T15:31:52Z", + "published": "2025-05-01T15:31:52Z", + "aliases": [ + "CVE-2022-49902" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nblock: Fix possible memory leak for rq_wb on add_disk failure\n\nkmemleak reported memory leaks in device_add_disk():\n\nkmemleak: 3 new suspected memory leaks\n\nunreferenced object 0xffff88800f420800 (size 512):\n comm \"modprobe\", pid 4275, jiffies 4295639067 (age 223.512s)\n hex dump (first 32 bytes):\n 04 00 00 00 08 00 00 00 01 00 00 00 00 00 00 00 ................\n 00 e1 f5 05 00 00 00 00 00 00 00 00 00 00 00 00 ................\n backtrace:\n [<00000000d3662699>] kmalloc_trace+0x26/0x60\n [<00000000edc7aadc>] wbt_init+0x50/0x6f0\n [<0000000069601d16>] wbt_enable_default+0x157/0x1c0\n [<0000000028fc393f>] blk_register_queue+0x2a4/0x420\n [<000000007345a042>] device_add_disk+0x6fd/0xe40\n [<0000000060e6aab0>] nbd_dev_add+0x828/0xbf0 [nbd]\n ...\n\nIt is because the memory allocated in wbt_enable_default() is not\nreleased in device_add_disk() error path.\nNormally, these memory are freed in:\n\ndel_gendisk()\n rq_qos_exit()\n rqos->ops->exit(rqos);\n wbt_exit()\n\nSo rq_qos_exit() is called to free the rq_wb memory for wbt_init().\nHowever in the error path of device_add_disk(), only\nblk_unregister_queue() is called and make rq_wb memory leaked.\n\nAdd rq_qos_exit() to the error path to fix it.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49902" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4e68c5da60cd79950bd56287ae80b39d6261f995" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/528677d3b4af985445bd4ac667485ded1ed11220" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fa81cbafbf5764ad5053512152345fab37a1fe18" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8r5m-9xx4-3v9j/GHSA-8r5m-9xx4-3v9j.json b/advisories/unreviewed/2025/05/GHSA-8r5m-9xx4-3v9j/GHSA-8r5m-9xx4-3v9j.json new file mode 100644 index 00000000000..7ae196d9bf6 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8r5m-9xx4-3v9j/GHSA-8r5m-9xx4-3v9j.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8r5m-9xx4-3v9j", + "modified": "2025-05-01T15:31:53Z", + "published": "2025-05-01T15:31:53Z", + "aliases": [ + "CVE-2022-49920" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: netlink notifier might race to release objects\n\ncommit release path is invoked via call_rcu and it runs lockless to\nrelease the objects after rcu grace period. The netlink notifier handler\nmight win race to remove objects that the transaction context is still\nreferencing from the commit release path.\n\nCall rcu_barrier() to ensure pending rcu callbacks run to completion\nif the list of transactions to be destroyed is not empty.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49920" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1ffe7100411a8b9015115ce124cd6c9c9da6f8e3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d4bc8271db21ea9f1c86a1ca4d64999f184d4aae" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e40b7c44d19e327ad8b49a491ef1fa8dcc4566e0" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8r89-r77h-8gvm/GHSA-8r89-r77h-8gvm.json b/advisories/unreviewed/2025/05/GHSA-8r89-r77h-8gvm/GHSA-8r89-r77h-8gvm.json new file mode 100644 index 00000000000..983667b84c2 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8r89-r77h-8gvm/GHSA-8r89-r77h-8gvm.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8r89-r77h-8gvm", + "modified": "2025-05-01T15:31:49Z", + "published": "2025-05-01T15:31:49Z", + "aliases": [ + "CVE-2022-49842" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: core: Fix use-after-free in snd_soc_exit()\n\nKASAN reports a use-after-free:\n\nBUG: KASAN: use-after-free in device_del+0xb5b/0xc60\nRead of size 8 at addr ffff888008655050 by task rmmod/387\nCPU: 2 PID: 387 Comm: rmmod\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996)\nCall Trace:\n\ndump_stack_lvl+0x79/0x9a\nprint_report+0x17f/0x47b\nkasan_report+0xbb/0xf0\ndevice_del+0xb5b/0xc60\nplatform_device_del.part.0+0x24/0x200\nplatform_device_unregister+0x2e/0x40\nsnd_soc_exit+0xa/0x22 [snd_soc_core]\n__do_sys_delete_module.constprop.0+0x34f/0x5b0\ndo_syscall_64+0x3a/0x90\nentry_SYSCALL_64_after_hwframe+0x63/0xcd\n...\n\n\nIt's bacause in snd_soc_init(), snd_soc_util_init() is possble to fail,\nbut its ret is ignored, which makes soc_dummy_dev unregistered twice.\n\nsnd_soc_init()\n snd_soc_util_init()\n platform_device_register_simple(soc_dummy_dev)\n platform_driver_register() # fail\n \tplatform_device_unregister(soc_dummy_dev)\n platform_driver_register() # success\n...\nsnd_soc_exit()\n snd_soc_util_exit()\n # soc_dummy_dev will be unregistered for second time\n\nTo fix it, handle error and stop snd_soc_init() when util_init() fail.\nAlso clean debugfs when util_init() or driver_register() fail.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49842" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2ec3f558db343b045a7c7419cdbaec266b8ac1a7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/34eee4189bcebbd5f6a2ff25ef0cb893ad33d51e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/41fad4f712e081acdfde8b59847f9f66eaf407a0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6ec27c53886c8963729885bcf2dd996eba2767a7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8d21554ec7680e9585fb852d933203c3db60dad1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/90bbdf30a51e42378cb23a312005a022794b8e1e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a3365e62239dc064019a244bde5686ac18527c22" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c5674bd073c0fd9f620ca550c5ff08d0d429bdd9" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8v6j-v3r3-p944/GHSA-8v6j-v3r3-p944.json b/advisories/unreviewed/2025/05/GHSA-8v6j-v3r3-p944/GHSA-8v6j-v3r3-p944.json new file mode 100644 index 00000000000..3565b1c9615 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8v6j-v3r3-p944/GHSA-8v6j-v3r3-p944.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8v6j-v3r3-p944", + "modified": "2025-05-01T15:31:47Z", + "published": "2025-05-01T15:31:47Z", + "aliases": [ + "CVE-2022-49800" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: Fix memory leak in test_gen_synth_cmd() and test_empty_synth_event()\n\ntest_gen_synth_cmd() only free buf in fail path, hence buf will leak\nwhen there is no failure. Add kfree(buf) to prevent the memleak. The\nsame reason and solution in test_empty_synth_event().\n\nunreferenced object 0xffff8881127de000 (size 2048):\n comm \"modprobe\", pid 247, jiffies 4294972316 (age 78.756s)\n hex dump (first 32 bytes):\n 20 67 65 6e 5f 73 79 6e 74 68 5f 74 65 73 74 20 gen_synth_test\n 20 70 69 64 5f 74 20 6e 65 78 74 5f 70 69 64 5f pid_t next_pid_\n backtrace:\n [<000000004254801a>] kmalloc_trace+0x26/0x100\n [<0000000039eb1cf5>] 0xffffffffa00083cd\n [<000000000e8c3bc8>] 0xffffffffa00086ba\n [<00000000c293d1ea>] do_one_initcall+0xdb/0x480\n [<00000000aa189e6d>] do_init_module+0x1cf/0x680\n [<00000000d513222b>] load_module+0x6a50/0x70a0\n [<000000001fd4d529>] __do_sys_finit_module+0x12f/0x1c0\n [<00000000b36c4c0f>] do_syscall_64+0x3f/0x90\n [<00000000bbf20cf3>] entry_SYSCALL_64_after_hwframe+0x63/0xcd\nunreferenced object 0xffff8881127df000 (size 2048):\n comm \"modprobe\", pid 247, jiffies 4294972324 (age 78.728s)\n hex dump (first 32 bytes):\n 20 65 6d 70 74 79 5f 73 79 6e 74 68 5f 74 65 73 empty_synth_tes\n 74 20 20 70 69 64 5f 74 20 6e 65 78 74 5f 70 69 t pid_t next_pi\n backtrace:\n [<000000004254801a>] kmalloc_trace+0x26/0x100\n [<00000000d4db9a3d>] 0xffffffffa0008071\n [<00000000c31354a5>] 0xffffffffa00086ce\n [<00000000c293d1ea>] do_one_initcall+0xdb/0x480\n [<00000000aa189e6d>] do_init_module+0x1cf/0x680\n [<00000000d513222b>] load_module+0x6a50/0x70a0\n [<000000001fd4d529>] __do_sys_finit_module+0x12f/0x1c0\n [<00000000b36c4c0f>] do_syscall_64+0x3f/0x90\n [<00000000bbf20cf3>] entry_SYSCALL_64_after_hwframe+0x63/0xcd", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49800" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/07ba4f0603aba288580866394f2916dfe55823a2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0e5baaa181a052d968701bb9c5b1d55847f00942" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/65ba7e7c241122ef0a9e61d1920f2ae9689aa796" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a4527fef9afe5c903c718d0cd24609fe9c754250" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8v7q-6cgm-98qq/GHSA-8v7q-6cgm-98qq.json b/advisories/unreviewed/2025/05/GHSA-8v7q-6cgm-98qq/GHSA-8v7q-6cgm-98qq.json new file mode 100644 index 00000000000..77bc75f000c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8v7q-6cgm-98qq/GHSA-8v7q-6cgm-98qq.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8v7q-6cgm-98qq", + "modified": "2025-05-01T15:31:45Z", + "published": "2025-05-01T15:31:45Z", + "aliases": [ + "CVE-2025-37788" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncxgb4: fix memory leak in cxgb4_init_ethtool_filters() error path\n\nIn the for loop used to allocate the loc_array and bmap for each port, a\nmemory leak is possible when the allocation for loc_array succeeds,\nbut the allocation for bmap fails. This is because when the control flow\ngoes to the label free_eth_finfo, only the allocations starting from\n(i-1)th iteration are freed.\n\nFix that by freeing the loc_array in the bmap allocation error path.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37788" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/00ffb3724ce743578163f5ade2884374554ca021" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/08aa59c0be768596467552c129e9f82166779a67" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/76deedea08899885f076aba0bb80bd1276446822" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/dafb6e433ab2333b67be05433dc9c6ccbc7b1284" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fa2d7708955e4f8212fd69bab1da604e60cb0b15" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T14:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8w66-gh7h-jgjh/GHSA-8w66-gh7h-jgjh.json b/advisories/unreviewed/2025/05/GHSA-8w66-gh7h-jgjh/GHSA-8w66-gh7h-jgjh.json new file mode 100644 index 00000000000..addf97d23f5 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8w66-gh7h-jgjh/GHSA-8w66-gh7h-jgjh.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8w66-gh7h-jgjh", + "modified": "2025-05-01T15:31:51Z", + "published": "2025-05-01T15:31:51Z", + "aliases": [ + "CVE-2022-49894" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncxl/region: Fix region HPA ordering validation\n\nSome regions may not have any address space allocated. Skip them when\nvalidating HPA order otherwise a crash like the following may result:\n\n devm_cxl_add_region: cxl_acpi cxl_acpi.0: decoder3.4: created region9\n BUG: kernel NULL pointer dereference, address: 0000000000000000\n [..]\n RIP: 0010:store_targetN+0x655/0x1740 [cxl_core]\n [..]\n Call Trace:\n \n kernfs_fop_write_iter+0x144/0x200\n vfs_write+0x24a/0x4d0\n ksys_write+0x69/0xf0\n do_syscall_64+0x3a/0x90\n\nstore_targetN+0x655/0x1740:\nalloc_region_ref at drivers/cxl/core/region.c:676\n(inlined by) cxl_port_attach_region at drivers/cxl/core/region.c:850\n(inlined by) cxl_region_attach at drivers/cxl/core/region.c:1290\n(inlined by) attach_target at drivers/cxl/core/region.c:1410\n(inlined by) store_targetN at drivers/cxl/core/region.c:1453", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49894" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/12316b9f7c18138ae656050cfd716728e27b7e2f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a90accb358ae33ea982a35595573f7a045993f8b" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8ww3-pfqc-q6wm/GHSA-8ww3-pfqc-q6wm.json b/advisories/unreviewed/2025/05/GHSA-8ww3-pfqc-q6wm/GHSA-8ww3-pfqc-q6wm.json new file mode 100644 index 00000000000..b353533e3a9 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8ww3-pfqc-q6wm/GHSA-8ww3-pfqc-q6wm.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8ww3-pfqc-q6wm", + "modified": "2025-05-01T15:31:51Z", + "published": "2025-05-01T15:31:51Z", + "aliases": [ + "CVE-2022-49886" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/tdx: Panic on bad configs that #VE on \"private\" memory access\n\nAll normal kernel memory is \"TDX private memory\". This includes\neverything from kernel stacks to kernel text. Handling\nexceptions on arbitrary accesses to kernel memory is essentially\nimpossible because they can happen in horribly nasty places like\nkernel entry/exit. But, TDX hardware can theoretically _deliver_\na virtualization exception (#VE) on any access to private memory.\n\nBut, it's not as bad as it sounds. TDX can be configured to never\ndeliver these exceptions on private memory with a \"TD attribute\"\ncalled ATTR_SEPT_VE_DISABLE. The guest has no way to *set* this\nattribute, but it can check it.\n\nEnsure ATTR_SEPT_VE_DISABLE is set in early boot. panic() if it\nis unset. There is no sane way for Linux to run with this\nattribute clear so a panic() is appropriate.\n\nThere's small window during boot before the check where kernel\nhas an early #VE handler. But the handler is only for port I/O\nand will also panic() as soon as it sees any other #VE, such as\na one generated by a private memory access.\n\n[ dhansen: Rewrite changelog and rebase on new tdx_parse_tdinfo().\n\t Add Kirill's tested-by because I made changes since\n\t he wrote this. ]", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49886" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/373e715e31bf4e0f129befe87613a278fac228d3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/895c168c8f78079f21ad50fead7593ffa352f795" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8xvq-q955-pv4g/GHSA-8xvq-q955-pv4g.json b/advisories/unreviewed/2025/05/GHSA-8xvq-q955-pv4g/GHSA-8xvq-q955-pv4g.json new file mode 100644 index 00000000000..a74259f498b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8xvq-q955-pv4g/GHSA-8xvq-q955-pv4g.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8xvq-q955-pv4g", + "modified": "2025-05-01T15:31:47Z", + "published": "2025-05-01T15:31:47Z", + "aliases": [ + "CVE-2022-49793" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\niio: trigger: sysfs: fix possible memory leak in iio_sysfs_trig_init()\n\ndev_set_name() allocates memory for name, it need be freed\nwhen device_add() fails, call put_device() to give up the\nreference that hold in device_initialize(), so that it can\nbe freed in kobject_cleanup() when the refcount hit to 0.\n\nFault injection test can trigger this:\n\nunreferenced object 0xffff8e8340a7b4c0 (size 32):\n comm \"modprobe\", pid 243, jiffies 4294678145 (age 48.845s)\n hex dump (first 32 bytes):\n 69 69 6f 5f 73 79 73 66 73 5f 74 72 69 67 67 65 iio_sysfs_trigge\n 72 00 a7 40 83 8e ff ff 00 86 13 c4 f6 ee ff ff r..@............\n backtrace:\n [<0000000074999de8>] __kmem_cache_alloc_node+0x1e9/0x360\n [<00000000497fd30b>] __kmalloc_node_track_caller+0x44/0x1a0\n [<000000003636c520>] kstrdup+0x2d/0x60\n [<0000000032f84da2>] kobject_set_name_vargs+0x1e/0x90\n [<0000000092efe493>] dev_set_name+0x4e/0x70", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49793" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0dd52e141afde089304de470148d311b05c14564" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2c4e65285bdea23fd36d2ff376006ac64db6f42e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5a39382aa5411d64b25a71516c2c7480aab13bb7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/656f670613662b6cc77aad14112db2803ad18fa8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8dddf2699da296c84205582aaead6b43dd7e8c4b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b47bb521961f027b4dcf8683337a7a1ba9e5ea1f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/efa17e90e1711bdb084e3954fa44afb6647331c0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f68c96821b61d2c71a35dbb8bf90c347fad624d9" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9345-c789-3fjx/GHSA-9345-c789-3fjx.json b/advisories/unreviewed/2025/05/GHSA-9345-c789-3fjx/GHSA-9345-c789-3fjx.json new file mode 100644 index 00000000000..53a219000cf --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9345-c789-3fjx/GHSA-9345-c789-3fjx.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9345-c789-3fjx", + "modified": "2025-05-01T15:31:44Z", + "published": "2025-05-01T15:31:44Z", + "aliases": [ + "CVE-2025-37782" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nhfs/hfsplus: fix slab-out-of-bounds in hfs_bnode_read_key\n\nSyzbot reported an issue in hfs subsystem:\n\nBUG: KASAN: slab-out-of-bounds in memcpy_from_page include/linux/highmem.h:423 [inline]\nBUG: KASAN: slab-out-of-bounds in hfs_bnode_read fs/hfs/bnode.c:35 [inline]\nBUG: KASAN: slab-out-of-bounds in hfs_bnode_read_key+0x314/0x450 fs/hfs/bnode.c:70\nWrite of size 94 at addr ffff8880123cd100 by task syz-executor237/5102\n\nCall Trace:\n \n __dump_stack lib/dump_stack.c:94 [inline]\n dump_stack_lvl+0x241/0x360 lib/dump_stack.c:120\n print_address_description mm/kasan/report.c:377 [inline]\n print_report+0x169/0x550 mm/kasan/report.c:488\n kasan_report+0x143/0x180 mm/kasan/report.c:601\n kasan_check_range+0x282/0x290 mm/kasan/generic.c:189\n __asan_memcpy+0x40/0x70 mm/kasan/shadow.c:106\n memcpy_from_page include/linux/highmem.h:423 [inline]\n hfs_bnode_read fs/hfs/bnode.c:35 [inline]\n hfs_bnode_read_key+0x314/0x450 fs/hfs/bnode.c:70\n hfs_brec_insert+0x7f3/0xbd0 fs/hfs/brec.c:159\n hfs_cat_create+0x41d/0xa50 fs/hfs/catalog.c:118\n hfs_mkdir+0x6c/0xe0 fs/hfs/dir.c:232\n vfs_mkdir+0x2f9/0x4f0 fs/namei.c:4257\n do_mkdirat+0x264/0x3a0 fs/namei.c:4280\n __do_sys_mkdir fs/namei.c:4300 [inline]\n __se_sys_mkdir fs/namei.c:4298 [inline]\n __x64_sys_mkdir+0x6c/0x80 fs/namei.c:4298\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\nRIP: 0033:0x7fbdd6057a99\n\nAdd a check for key length in hfs_bnode_read_key to prevent\nout-of-bounds memory access. If the key length is invalid, the\nkey buffer is cleared, improving stability and reliability.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37782" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0296f9733543c7c8e666e69da743cfffd32dd805" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/84e8719c087e68c967975b78e67be54f697c957f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9c93fb4ad8d3b730afe1a09949ebbea64d4f60eb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9f77aa584a659b21211a794e53522e6fb16d4a16" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bb5e07cb927724e0b47be371fa081141cfb14414" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T14:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-95vc-3fw2-mxm8/GHSA-95vc-3fw2-mxm8.json b/advisories/unreviewed/2025/05/GHSA-95vc-3fw2-mxm8/GHSA-95vc-3fw2-mxm8.json new file mode 100644 index 00000000000..7da47de491f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-95vc-3fw2-mxm8/GHSA-95vc-3fw2-mxm8.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-95vc-3fw2-mxm8", + "modified": "2025-05-01T15:31:43Z", + "published": "2025-05-01T15:31:43Z", + "aliases": [ + "CVE-2025-37763" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/imagination: take paired job reference\n\nFor paired jobs, have the fragment job take a reference on the\ngeometry job, so that the geometry job cannot be freed until\nthe fragment job has finished with it.\n\nThe geometry job structure is accessed when the fragment job is being\nprepared by the GPU scheduler. Taking the reference prevents the\ngeometry job being freed until the fragment job no longer requires it.\n\nFixes a use after free bug detected by KASAN:\n\n[ 124.256386] BUG: KASAN: slab-use-after-free in pvr_queue_prepare_job+0x108/0x868 [powervr]\n[ 124.264893] Read of size 1 at addr ffff0000084cb960 by task kworker/u16:4/63", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37763" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4ba2abe154ef68f9612eee9d6fbfe53a1736b064" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b5a6f97a78e2fc008fd6503b7040cb7e1120b873" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c90b95e12eb88d23740e5ea2c43d71675d17ac8d" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T14:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9633-355p-9wpx/GHSA-9633-355p-9wpx.json b/advisories/unreviewed/2025/05/GHSA-9633-355p-9wpx/GHSA-9633-355p-9wpx.json new file mode 100644 index 00000000000..ccaac082149 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9633-355p-9wpx/GHSA-9633-355p-9wpx.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9633-355p-9wpx", + "modified": "2025-05-01T15:31:48Z", + "published": "2025-05-01T15:31:48Z", + "aliases": [ + "CVE-2022-49805" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: lan966x: Fix potential null-ptr-deref in lan966x_stats_init()\n\nlan966x_stats_init() calls create_singlethread_workqueue() and not\nchecked the ret value, which may return NULL. And a null-ptr-deref may\nhappen:\n\nlan966x_stats_init()\n create_singlethread_workqueue() # failed, lan966x->stats_queue is NULL\n queue_delayed_work()\n queue_delayed_work_on()\n __queue_delayed_work() # warning here, but continue\n __queue_work() # access wq->flags, null-ptr-deref\n\nCheck the ret value and return -ENOMEM if it is NULL.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49805" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4a43c1c6040e848e1344c7b16ac696b68fbc439c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ba86af3733aece88dbcee0dfebf7e2dcfefb2be4" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-965c-2m8v-wcjh/GHSA-965c-2m8v-wcjh.json b/advisories/unreviewed/2025/05/GHSA-965c-2m8v-wcjh/GHSA-965c-2m8v-wcjh.json new file mode 100644 index 00000000000..352c83db3b8 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-965c-2m8v-wcjh/GHSA-965c-2m8v-wcjh.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-965c-2m8v-wcjh", + "modified": "2025-05-01T15:31:53Z", + "published": "2025-05-01T15:31:53Z", + "aliases": [ + "CVE-2022-49927" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfs4: Fix kmemleak when allocate slot failed\n\nIf one of the slot allocate failed, should cleanup all the other\nallocated slots, otherwise, the allocated slots will leak:\n\n unreferenced object 0xffff8881115aa100 (size 64):\n comm \"\"mount.nfs\"\", pid 679, jiffies 4294744957 (age 115.037s)\n hex dump (first 32 bytes):\n 00 cc 19 73 81 88 ff ff 00 a0 5a 11 81 88 ff ff ...s......Z.....\n 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n backtrace:\n [<000000007a4c434a>] nfs4_find_or_create_slot+0x8e/0x130\n [<000000005472a39c>] nfs4_realloc_slot_table+0x23f/0x270\n [<00000000cd8ca0eb>] nfs40_init_client+0x4a/0x90\n [<00000000128486db>] nfs4_init_client+0xce/0x270\n [<000000008d2cacad>] nfs4_set_client+0x1a2/0x2b0\n [<000000000e593b52>] nfs4_create_server+0x300/0x5f0\n [<00000000e4425dd2>] nfs4_try_get_tree+0x65/0x110\n [<00000000d3a6176f>] vfs_get_tree+0x41/0xf0\n [<0000000016b5ad4c>] path_mount+0x9b3/0xdd0\n [<00000000494cae71>] __x64_sys_mount+0x190/0x1d0\n [<000000005d56bdec>] do_syscall_64+0x35/0x80\n [<00000000687c9ae4>] entry_SYSCALL_64_after_hwframe+0x46/0xb0", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49927" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/24641993a7dce6b1628645f4e1d97ca06c9f765d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/45aea4fbf61e205649c29200726b9f45c1718a67" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7e8436728e22181c3f12a5dbabd35ed3a8b8c593" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/84b5cb476903003ae9ca88f32b57ff0eaefa6d4c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/86ce0e93cf6fb4d0c447323ac66577c642628b9d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/925cb538bd5851154602818dc80bf4b4d924c127" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/aae35a0c8a775fa4afa6a4e7dab3f936f1f89bbb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/db333ae981fb8843c383aa7dbf62cc682597d401" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-988r-r585-2mrv/GHSA-988r-r585-2mrv.json b/advisories/unreviewed/2025/05/GHSA-988r-r585-2mrv/GHSA-988r-r585-2mrv.json new file mode 100644 index 00000000000..fafa92b40c0 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-988r-r585-2mrv/GHSA-988r-r585-2mrv.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-988r-r585-2mrv", + "modified": "2025-05-01T15:31:47Z", + "published": "2025-05-01T15:31:47Z", + "aliases": [ + "CVE-2022-49796" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: kprobe: Fix potential null-ptr-deref on trace_array in kprobe_event_gen_test_exit()\n\nWhen test_gen_kprobe_cmd() failed after kprobe_event_gen_cmd_end(), it\nwill goto delete, which will call kprobe_event_delete() and release the\ncorresponding resource. However, the trace_array in gen_kretprobe_test\nwill point to the invalid resource. Set gen_kretprobe_test to NULL\nafter called kprobe_event_delete() to prevent null-ptr-deref.\n\nBUG: kernel NULL pointer dereference, address: 0000000000000070\nPGD 0 P4D 0\nOops: 0000 [#1] SMP PTI\nCPU: 0 PID: 246 Comm: modprobe Tainted: G W\n6.1.0-rc1-00174-g9522dc5c87da-dirty #248\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS\nrel-1.15.0-0-g2dd4b9b3f840-prebuilt.qemu.org 04/01/2014\nRIP: 0010:__ftrace_set_clr_event_nolock+0x53/0x1b0\nCode: e8 82 26 fc ff 49 8b 1e c7 44 24 0c ea ff ff ff 49 39 de 0f 84 3c\n01 00 00 c7 44 24 18 00 00 00 00 e8 61 26 fc ff 48 8b 6b 10 <44> 8b 65\n70 4c 8b 6d 18 41 f7 c4 00 02 00 00 75 2f\nRSP: 0018:ffffc9000159fe00 EFLAGS: 00010293\nRAX: 0000000000000000 RBX: ffff88810971d268 RCX: 0000000000000000\nRDX: ffff8881080be600 RSI: ffffffff811b48ff RDI: ffff88810971d058\nRBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000000001\nR10: ffffc9000159fe58 R11: 0000000000000001 R12: ffffffffa0001064\nR13: ffffffffa000106c R14: ffff88810971d238 R15: 0000000000000000\nFS: 00007f89eeff6540(0000) GS:ffff88813b600000(0000)\nknlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000000000000070 CR3: 000000010599e004 CR4: 0000000000330ef0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nCall Trace:\n \n __ftrace_set_clr_event+0x3e/0x60\n trace_array_set_clr_event+0x35/0x50\n ? 0xffffffffa0000000\n kprobe_event_gen_test_exit+0xcd/0x10b [kprobe_event_gen_test]\n __x64_sys_delete_module+0x206/0x380\n ? lockdep_hardirqs_on_prepare+0xd8/0x190\n ? syscall_enter_from_user_mode+0x1c/0x50\n do_syscall_64+0x3f/0x90\n entry_SYSCALL_64_after_hwframe+0x63/0xcd\nRIP: 0033:0x7f89eeb061b7", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49796" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/22ea4ca9631eb137e64e5ab899e9c89cb6670959" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/28a54854a95923b6266a9479ad660ca2cc0e1d5f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/510c12f93674ea0a1423b24f36c67357168a262a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e57daa750369fedbf678346aec724a43b9a51749" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9cm2-ww33-pjpc/GHSA-9cm2-ww33-pjpc.json b/advisories/unreviewed/2025/05/GHSA-9cm2-ww33-pjpc/GHSA-9cm2-ww33-pjpc.json new file mode 100644 index 00000000000..ba9927f0521 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9cm2-ww33-pjpc/GHSA-9cm2-ww33-pjpc.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9cm2-ww33-pjpc", + "modified": "2025-05-01T15:31:48Z", + "published": "2025-05-01T15:31:48Z", + "aliases": [ + "CVE-2022-49822" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncifs: Fix connections leak when tlink setup failed\n\nIf the tlink setup failed, lost to put the connections, then\nthe module refcnt leak since the cifsd kthread not exit.\n\nAlso leak the fscache info, and for next mount with fsc, it will\nprint the follow errors:\n CIFS: Cache volume key already in use (cifs,127.0.0.1:445,TEST)\n\nLet's check the result of tlink setup, and do some cleanup.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49822" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0a087842d10b5daa123ee5291e386cdd78413705" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1dcdf5f5b2137185cbdd5385f29949ab3da4f00c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a9059e338fc000c0b87d8cf29e93c74fd703212e" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9cv9-84qq-79g4/GHSA-9cv9-84qq-79g4.json b/advisories/unreviewed/2025/05/GHSA-9cv9-84qq-79g4/GHSA-9cv9-84qq-79g4.json new file mode 100644 index 00000000000..67668defd1c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9cv9-84qq-79g4/GHSA-9cv9-84qq-79g4.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9cv9-84qq-79g4", + "modified": "2025-05-01T15:31:48Z", + "published": "2025-05-01T15:31:48Z", + "aliases": [ + "CVE-2022-49825" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nata: libata-transport: fix error handling in ata_tport_add()\n\nIn ata_tport_add(), the return value of transport_add_device() is\nnot checked. As a result, it causes null-ptr-deref while removing\nthe module, because transport_remove_device() is called to remove\nthe device that was not added.\n\nUnable to handle kernel NULL pointer dereference at virtual address 00000000000000d0\nCPU: 12 PID: 13605 Comm: rmmod Kdump: loaded Tainted: G W 6.1.0-rc3+ #8\npstate: 60400009 (nZCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)\npc : device_del+0x48/0x39c\nlr : device_del+0x44/0x39c\nCall trace:\n device_del+0x48/0x39c\n attribute_container_class_device_del+0x28/0x40\n transport_remove_classdev+0x60/0x7c\n attribute_container_device_trigger+0x118/0x120\n transport_remove_device+0x20/0x30\n ata_tport_delete+0x34/0x60 [libata]\n ata_port_detach+0x148/0x1b0 [libata]\n ata_pci_remove_one+0x50/0x80 [libata]\n ahci_remove_one+0x4c/0x8c [ahci]\n\nFix this by checking and handling return value of transport_add_device()\nin ata_tport_add().", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49825" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3613dbe3909dcc637fe6be00e4dc43b4aa0470ee" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/52d9bb0adae9359711a0c5271430afd3754069e7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b5362dc1634d8b8d5f30920f33ac11a3276b7ed9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e7bb1b7a7bf26f6b7372b7b683daece4a42fda02" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9jjh-93j4-23f2/GHSA-9jjh-93j4-23f2.json b/advisories/unreviewed/2025/05/GHSA-9jjh-93j4-23f2/GHSA-9jjh-93j4-23f2.json new file mode 100644 index 00000000000..bce77747e31 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9jjh-93j4-23f2/GHSA-9jjh-93j4-23f2.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9jjh-93j4-23f2", + "modified": "2025-05-01T15:31:50Z", + "published": "2025-05-01T15:31:50Z", + "aliases": [ + "CVE-2022-49876" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: fix general-protection-fault in ieee80211_subif_start_xmit()\n\nWhen device is running and the interface status is changed, the gpf issue\nis triggered. The problem triggering process is as follows:\nThread A: Thread B\nieee80211_runtime_change_iftype() process_one_work()\n ... ...\n ieee80211_do_stop() ...\n ... ...\n sdata->bss = NULL ...\n ... ieee80211_subif_start_xmit()\n ieee80211_multicast_to_unicast\n //!sdata->bss->multicast_to_unicast\n cause gpf issue\n\nWhen the interface status is changed, the sending queue continues to send\npackets. After the bss is set to NULL, the bss is accessed. As a result,\nthis causes a general-protection-fault issue.\n\nThe following is the stack information:\ngeneral protection fault, probably for non-canonical address\n0xdffffc000000002f: 0000 [#1] PREEMPT SMP KASAN\nKASAN: null-ptr-deref in range [0x0000000000000178-0x000000000000017f]\nWorkqueue: mld mld_ifc_work\nRIP: 0010:ieee80211_subif_start_xmit+0x25b/0x1310\nCall Trace:\n\ndev_hard_start_xmit+0x1be/0x990\n__dev_queue_xmit+0x2c9a/0x3b60\nip6_finish_output2+0xf92/0x1520\nip6_finish_output+0x6af/0x11e0\nip6_output+0x1ed/0x540\nmld_sendpack+0xa09/0xe70\nmld_ifc_work+0x71c/0xdb0\nprocess_one_work+0x9bf/0x1710\nworker_thread+0x665/0x1080\nkthread+0x2e4/0x3a0\nret_from_fork+0x1f/0x30\n", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49876" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/03eb68c72cee249aeb7af7d04a83c033aca3d6d9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/780854186946e0de2be192ee7fa5125666533b3a" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9q6h-q6v8-gjmr/GHSA-9q6h-q6v8-gjmr.json b/advisories/unreviewed/2025/05/GHSA-9q6h-q6v8-gjmr/GHSA-9q6h-q6v8-gjmr.json new file mode 100644 index 00000000000..5131eae99ed --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9q6h-q6v8-gjmr/GHSA-9q6h-q6v8-gjmr.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9q6h-q6v8-gjmr", + "modified": "2025-05-01T15:31:53Z", + "published": "2025-05-01T15:31:52Z", + "aliases": [ + "CVE-2022-49918" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nipvs: fix WARNING in __ip_vs_cleanup_batch()\n\nDuring the initialization of ip_vs_conn_net_init(), if file ip_vs_conn\nor ip_vs_conn_sync fails to be created, the initialization is successful\nby default. Therefore, the ip_vs_conn or ip_vs_conn_sync file doesn't\nbe found during the remove.\n\nThe following is the stack information:\nname 'ip_vs_conn_sync'\nWARNING: CPU: 3 PID: 9 at fs/proc/generic.c:712\nremove_proc_entry+0x389/0x460\nModules linked in:\nWorkqueue: netns cleanup_net\nRIP: 0010:remove_proc_entry+0x389/0x460\nCall Trace:\n\n__ip_vs_cleanup_batch+0x7d/0x120\nops_exit_list+0x125/0x170\ncleanup_net+0x4ea/0xb00\nprocess_one_work+0x9bf/0x1710\nworker_thread+0x665/0x1080\nkthread+0x2e4/0x3a0\nret_from_fork+0x1f/0x30\n", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49918" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3d00c6a0da8ddcf75213e004765e4a42acc71d5d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5ee2d6b726b0ce339e36569e5849692f4cf4595e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7effc4ce3d1434ce6ff286866585a6e905fdbfc1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/931f56d59c854263b32075bfac56fdb3b1598d1b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e724220b826e008764309d2a1f55a9434a4e1530" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f08ee2aa24c076f81d84e26e213d8c6f4efd9f50" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9qj7-j3p9-hf88/GHSA-9qj7-j3p9-hf88.json b/advisories/unreviewed/2025/05/GHSA-9qj7-j3p9-hf88/GHSA-9qj7-j3p9-hf88.json new file mode 100644 index 00000000000..be58fca8774 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9qj7-j3p9-hf88/GHSA-9qj7-j3p9-hf88.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9qj7-j3p9-hf88", + "modified": "2025-05-01T15:31:40Z", + "published": "2025-05-01T15:31:40Z", + "aliases": [ + "CVE-2025-23149" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntpm: do not start chip while suspended\n\nChecking TPM_CHIP_FLAG_SUSPENDED after the call to tpm_find_get_ops() can\nlead to a spurious tpm_chip_start() call:\n\n[35985.503771] i2c i2c-1: Transfer while suspended\n[35985.503796] WARNING: CPU: 0 PID: 74 at drivers/i2c/i2c-core.h:56 __i2c_transfer+0xbe/0x810\n[35985.503802] Modules linked in:\n[35985.503808] CPU: 0 UID: 0 PID: 74 Comm: hwrng Tainted: G W 6.13.0-next-20250203-00005-gfa0cb5642941 #19 9c3d7f78192f2d38e32010ac9c90fdc71109ef6f\n[35985.503814] Tainted: [W]=WARN\n[35985.503817] Hardware name: Google Morphius/Morphius, BIOS Google_Morphius.13434.858.0 10/26/2023\n[35985.503819] RIP: 0010:__i2c_transfer+0xbe/0x810\n[35985.503825] Code: 30 01 00 00 4c 89 f7 e8 40 fe d8 ff 48 8b 93 80 01 00 00 48 85 d2 75 03 49 8b 16 48 c7 c7 0a fb 7c a7 48 89 c6 e8 32 ad b0 fe <0f> 0b b8 94 ff ff ff e9 33 04 00 00 be 02 00 00 00 83 fd 02 0f 5\n[35985.503828] RSP: 0018:ffffa106c0333d30 EFLAGS: 00010246\n[35985.503833] RAX: 074ba64aa20f7000 RBX: ffff8aa4c1167120 RCX: 0000000000000000\n[35985.503836] RDX: 0000000000000000 RSI: ffffffffa77ab0e4 RDI: 0000000000000001\n[35985.503838] RBP: 0000000000000001 R08: 0000000000000001 R09: 0000000000000000\n[35985.503841] R10: 0000000000000004 R11: 00000001000313d5 R12: ffff8aa4c10f1820\n[35985.503843] R13: ffff8aa4c0e243c0 R14: ffff8aa4c1167250 R15: ffff8aa4c1167120\n[35985.503846] FS: 0000000000000000(0000) GS:ffff8aa4eae00000(0000) knlGS:0000000000000000\n[35985.503849] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[35985.503852] CR2: 00007fab0aaf1000 CR3: 0000000105328000 CR4: 00000000003506f0\n[35985.503855] Call Trace:\n[35985.503859] \n[35985.503863] ? __warn+0xd4/0x260\n[35985.503868] ? __i2c_transfer+0xbe/0x810\n[35985.503874] ? report_bug+0xf3/0x210\n[35985.503882] ? handle_bug+0x63/0xb0\n[35985.503887] ? exc_invalid_op+0x16/0x50\n[35985.503892] ? asm_exc_invalid_op+0x16/0x20\n[35985.503904] ? __i2c_transfer+0xbe/0x810\n[35985.503913] tpm_cr50_i2c_transfer_message+0x24/0xf0\n[35985.503920] tpm_cr50_i2c_read+0x8e/0x120\n[35985.503928] tpm_cr50_request_locality+0x75/0x170\n[35985.503935] tpm_chip_start+0x116/0x160\n[35985.503942] tpm_try_get_ops+0x57/0x90\n[35985.503948] tpm_find_get_ops+0x26/0xd0\n[35985.503955] tpm_get_random+0x2d/0x80\n\nDon't move forward with tpm_chip_start() inside tpm_try_get_ops(), unless\nTPM_CHIP_FLAG_SUSPENDED is not set. tpm_find_get_ops() will return NULL in\nsuch a failure case.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23149" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1404dff1e11bf927b70ac25e1de97bed9742ede4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/17d253af4c2c8a2acf84bb55a0c2045f150b7dfd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e74e2394eed90aff5c3a08c1f51f476d4de71d02" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f1044e995b64d70ef90ef6f2b89955b127497702" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f3cb81cb96d587f9f235a11789d1ec0992643078" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T13:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9x8c-4rx4-5mxv/GHSA-9x8c-4rx4-5mxv.json b/advisories/unreviewed/2025/05/GHSA-9x8c-4rx4-5mxv/GHSA-9x8c-4rx4-5mxv.json new file mode 100644 index 00000000000..88e0740e0e8 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9x8c-4rx4-5mxv/GHSA-9x8c-4rx4-5mxv.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9x8c-4rx4-5mxv", + "modified": "2025-05-01T15:31:48Z", + "published": "2025-05-01T15:31:48Z", + "aliases": [ + "CVE-2022-49812" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbridge: switchdev: Fix memory leaks when changing VLAN protocol\n\nThe bridge driver can offload VLANs to the underlying hardware either\nvia switchdev or the 8021q driver. When the former is used, the VLAN is\nmarked in the bridge driver with the 'BR_VLFLAG_ADDED_BY_SWITCHDEV'\nprivate flag.\n\nTo avoid the memory leaks mentioned in the cited commit, the bridge\ndriver will try to delete a VLAN via the 8021q driver if the VLAN is not\nmarked with the previously mentioned flag.\n\nWhen the VLAN protocol of the bridge changes, switchdev drivers are\nnotified via the 'SWITCHDEV_ATTR_ID_BRIDGE_VLAN_PROTOCOL' attribute, but\nthe 8021q driver is also called to add the existing VLANs with the new\nprotocol and delete them with the old protocol.\n\nIn case the VLANs were offloaded via switchdev, the above behavior is\nboth redundant and buggy. Redundant because the VLANs are already\nprogrammed in hardware and drivers that support VLAN protocol change\n(currently only mlx5) change the protocol upon the switchdev attribute\nnotification. Buggy because the 8021q driver is called despite these\nVLANs being marked with 'BR_VLFLAG_ADDED_BY_SWITCHDEV'. This leads to\nmemory leaks [1] when the VLANs are deleted.\n\nFix by not calling the 8021q driver for VLANs that were already\nprogrammed via switchdev.\n\n[1]\nunreferenced object 0xffff8881f6771200 (size 256):\n comm \"ip\", pid 446855, jiffies 4298238841 (age 55.240s)\n hex dump (first 32 bytes):\n 00 00 7f 0e 83 88 ff ff 00 00 00 00 00 00 00 00 ................\n 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n backtrace:\n [<00000000012819ac>] vlan_vid_add+0x437/0x750\n [<00000000f2281fad>] __br_vlan_set_proto+0x289/0x920\n [<000000000632b56f>] br_changelink+0x3d6/0x13f0\n [<0000000089d25f04>] __rtnl_newlink+0x8ae/0x14c0\n [<00000000f6276baf>] rtnl_newlink+0x5f/0x90\n [<00000000746dc902>] rtnetlink_rcv_msg+0x336/0xa00\n [<000000001c2241c0>] netlink_rcv_skb+0x11d/0x340\n [<0000000010588814>] netlink_unicast+0x438/0x710\n [<00000000e1a4cd5c>] netlink_sendmsg+0x788/0xc40\n [<00000000e8992d4e>] sock_sendmsg+0xb0/0xe0\n [<00000000621b8f91>] ____sys_sendmsg+0x4ff/0x6d0\n [<000000000ea26996>] ___sys_sendmsg+0x12e/0x1b0\n [<00000000684f7e25>] __sys_sendmsg+0xab/0x130\n [<000000004538b104>] do_syscall_64+0x3d/0x90\n [<0000000091ed9678>] entry_SYSCALL_64_after_hwframe+0x46/0xb0", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49812" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/347f1793b573466424c550f2748ed837b6690fe7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9d45921ee4cb364910097e7d1b7558559c2f9fd2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f8926e2d2225eb7b7e11cd3fa266aaad9075b767" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fc16a2c81a3eb1cbba8775f5bdc67856df903a7c" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-c2p4-prc5-v3mc/GHSA-c2p4-prc5-v3mc.json b/advisories/unreviewed/2025/05/GHSA-c2p4-prc5-v3mc/GHSA-c2p4-prc5-v3mc.json new file mode 100644 index 00000000000..40337de2b22 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-c2p4-prc5-v3mc/GHSA-c2p4-prc5-v3mc.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c2p4-prc5-v3mc", + "modified": "2025-05-01T15:31:51Z", + "published": "2025-05-01T15:31:51Z", + "aliases": [ + "CVE-2022-49893" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncxl/region: Fix cxl_region leak, cleanup targets at region delete\n\nWhen a region is deleted any targets that have been previously assigned\nto that region hold references to it. Trigger those references to\ndrop by detaching all targets at unregister_region() time.\n\nOtherwise that region object will leak as userspace has lost the ability\nto detach targets once region sysfs is torn down.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49893" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0d9e734018d70cecf79e2e4c6082167160a0f13f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/45d9fb4b758b9d602ee7776eb6754b0349946aad" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-c6pq-53v5-wcc7/GHSA-c6pq-53v5-wcc7.json b/advisories/unreviewed/2025/05/GHSA-c6pq-53v5-wcc7/GHSA-c6pq-53v5-wcc7.json new file mode 100644 index 00000000000..b970ed3d5d4 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-c6pq-53v5-wcc7/GHSA-c6pq-53v5-wcc7.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c6pq-53v5-wcc7", + "modified": "2025-05-01T15:31:41Z", + "published": "2025-05-01T15:31:41Z", + "aliases": [ + "CVE-2025-23160" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: mediatek: vcodec: Fix a resource leak related to the scp device in FW initialization\n\nOn Mediatek devices with a system companion processor (SCP) the mtk_scp\nstructure has to be removed explicitly to avoid a resource leak.\nFree the structure in case the allocation of the firmware structure fails\nduring the firmware initialization.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23160" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4936cd5817af35d23e4d283f48fa59a18ef481e4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9f009fa823c54ca0857c81f7525ea5a5d32de29c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ac94e1db4b2053059779472eb58a64d504964240" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d6cb086aa52bd51378a4c9e2b25d2def97770205" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fd7bb97ede487b9f075707b7408a9073e0d474b1" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T13:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-c7fj-w636-m5xx/GHSA-c7fj-w636-m5xx.json b/advisories/unreviewed/2025/05/GHSA-c7fj-w636-m5xx/GHSA-c7fj-w636-m5xx.json new file mode 100644 index 00000000000..6a86f00be1b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-c7fj-w636-m5xx/GHSA-c7fj-w636-m5xx.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c7fj-w636-m5xx", + "modified": "2025-05-01T15:31:49Z", + "published": "2025-05-01T15:31:49Z", + "aliases": [ + "CVE-2022-49849" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix match incorrectly in dev_args_match_device\n\nsyzkaller found a failed assertion:\n\n assertion failed: (args->devid != (u64)-1) || args->missing, in fs/btrfs/volumes.c:6921\n\nThis can be triggered when we set devid to (u64)-1 by ioctl. In this\ncase, the match of devid will be skipped and the match of device may\nsucceed incorrectly.\n\nPatch 562d7b1512f7 introduced this function which is used to match device.\nThis function contains two matching scenarios, we can distinguish them by\nchecking the value of args->missing rather than check whether args->devid\nand args->uuid is default value.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49849" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0fca385d6ebc3cabb20f67bcf8a71f1448bdc001" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bc6c127c377010f136360552ebf91c2723081c1b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c9fe4719c662e0af17eea723cf345e37719fd3c9" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-c7jg-hhpr-v5pq/GHSA-c7jg-hhpr-v5pq.json b/advisories/unreviewed/2025/05/GHSA-c7jg-hhpr-v5pq/GHSA-c7jg-hhpr-v5pq.json new file mode 100644 index 00000000000..afa50b8fd0b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-c7jg-hhpr-v5pq/GHSA-c7jg-hhpr-v5pq.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c7jg-hhpr-v5pq", + "modified": "2025-05-01T15:31:50Z", + "published": "2025-05-01T15:31:50Z", + "aliases": [ + "CVE-2022-49869" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbnxt_en: Fix possible crash in bnxt_hwrm_set_coal()\n\nDuring the error recovery sequence, the rtnl_lock is not held for the\nentire duration and some datastructures may be freed during the sequence.\nCheck for the BNXT_STATE_OPEN flag instead of netif_running() to ensure\nthat the device is fully operational before proceeding to reconfigure\nthe coalescing settings.\n\nThis will fix a possible crash like this:\n\nBUG: unable to handle kernel NULL pointer dereference at 0000000000000000\nPGD 0 P4D 0\nOops: 0000 [#1] SMP NOPTI\nCPU: 10 PID: 181276 Comm: ethtool Kdump: loaded Tainted: G IOE --------- - - 4.18.0-348.el8.x86_64 #1\nHardware name: Dell Inc. PowerEdge R740/0F9N89, BIOS 2.3.10 08/15/2019\nRIP: 0010:bnxt_hwrm_set_coal+0x1fb/0x2a0 [bnxt_en]\nCode: c2 66 83 4e 22 08 66 89 46 1c e8 10 cb 00 00 41 83 c6 01 44 39 b3 68 01 00 00 0f 8e a3 00 00 00 48 8b 93 c8 00 00 00 49 63 c6 <48> 8b 2c c2 48 8b 85 b8 02 00 00 48 85 c0 74 2e 48 8b 74 24 08 f6\nRSP: 0018:ffffb11c8dcaba50 EFLAGS: 00010246\nRAX: 0000000000000000 RBX: ffff8d168a8b0ac0 RCX: 00000000000000c5\nRDX: 0000000000000000 RSI: ffff8d162f72c000 RDI: ffff8d168a8b0b28\nRBP: 0000000000000000 R08: b6e1f68a12e9a7eb R09: 0000000000000000\nR10: 0000000000000001 R11: 0000000000000037 R12: ffff8d168a8b109c\nR13: ffff8d168a8b10aa R14: 0000000000000000 R15: ffffffffc01ac4e0\nFS: 00007f3852e4c740(0000) GS:ffff8d24c0080000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000000000000000 CR3: 000000041b3ee003 CR4: 00000000007706e0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nPKRU: 55555554\nCall Trace:\n ethnl_set_coalesce+0x3ce/0x4c0\n genl_family_rcv_msg_doit.isra.15+0x10f/0x150\n genl_family_rcv_msg+0xb3/0x160\n ? coalesce_fill_reply+0x480/0x480\n genl_rcv_msg+0x47/0x90\n ? genl_family_rcv_msg+0x160/0x160\n netlink_rcv_skb+0x4c/0x120\n genl_rcv+0x24/0x40\n netlink_unicast+0x196/0x230\n netlink_sendmsg+0x204/0x3d0\n sock_sendmsg+0x4c/0x50\n __sys_sendto+0xee/0x160\n ? syscall_trace_enter+0x1d3/0x2c0\n ? __audit_syscall_exit+0x249/0x2a0\n __x64_sys_sendto+0x24/0x30\n do_syscall_64+0x5b/0x1a0\n entry_SYSCALL_64_after_hwframe+0x65/0xca\nRIP: 0033:0x7f38524163bb", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49869" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/38147073c96dce8c7e142ce0e5f305a420a729ba" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6d81ea3765dfa6c8a20822613c81edad1c4a16a0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7781e32984cde65549bedc3201537e253297c98d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a5a05fbef4a0dfe45fe03b2f1d02ba23aebf5384" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ac257c43fa615d22180916074feed803b8bb8cb0" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-c7x8-xx5v-964j/GHSA-c7x8-xx5v-964j.json b/advisories/unreviewed/2025/05/GHSA-c7x8-xx5v-964j/GHSA-c7x8-xx5v-964j.json new file mode 100644 index 00000000000..124bf02ba3d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-c7x8-xx5v-964j/GHSA-c7x8-xx5v-964j.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c7x8-xx5v-964j", + "modified": "2025-05-01T15:31:42Z", + "published": "2025-05-01T15:31:42Z", + "aliases": [ + "CVE-2025-37740" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\njfs: add sanity check for agwidth in dbMount\n\nThe width in dmapctl of the AG is zero, it trigger a divide error when\ncalculating the control page level in dbAllocAG.\n\nTo avoid this issue, add a check for agwidth in dbAllocAG.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37740" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a260bf14cd347878f01f70739ba829442a474a16" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c8c96a9e7660e5e5eea445978fe8f2e432d91c1f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cc0bc4cb62ce5fa0c383e3bf0765d01f46bd49ac" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ccd97c8a4f90810f228ee40d1055148fa146dd57" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ddf2846f22e8575d6b4b6a66f2100f168b8cd73d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e3f85edb03183fb06539e5b50dd2c4bb42b869f0" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T13:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-c89r-xwv9-fq4w/GHSA-c89r-xwv9-fq4w.json b/advisories/unreviewed/2025/05/GHSA-c89r-xwv9-fq4w/GHSA-c89r-xwv9-fq4w.json new file mode 100644 index 00000000000..3589c796051 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-c89r-xwv9-fq4w/GHSA-c89r-xwv9-fq4w.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c89r-xwv9-fq4w", + "modified": "2025-05-01T15:31:45Z", + "published": "2025-05-01T15:31:45Z", + "aliases": [ + "CVE-2025-44854" + ], + "details": "Totolink CP900 V6.3c.1144_B20190715 was found to contain a command injection vulnerability in the setUpgradeUboot function via the FileName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44854" + }, + { + "type": "WEB", + "url": "https://github.com/Summermu/VulnForIoT/tree/main/Totolink_CP900/setUpgradeUboot/readme.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T14:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-c8r4-j2q4-mjgj/GHSA-c8r4-j2q4-mjgj.json b/advisories/unreviewed/2025/05/GHSA-c8r4-j2q4-mjgj/GHSA-c8r4-j2q4-mjgj.json new file mode 100644 index 00000000000..fad2c5b5fec --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-c8r4-j2q4-mjgj/GHSA-c8r4-j2q4-mjgj.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c8r4-j2q4-mjgj", + "modified": "2025-05-01T15:31:51Z", + "published": "2025-05-01T15:31:51Z", + "aliases": [ + "CVE-2022-49875" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpftool: Fix NULL pointer dereference when pin {PROG, MAP, LINK} without FILE\n\nWhen using bpftool to pin {PROG, MAP, LINK} without FILE,\nsegmentation fault will occur. The reson is that the lack\nof FILE will cause strlen to trigger NULL pointer dereference.\nThe corresponding stacktrace is shown below:\n\ndo_pin\n do_pin_any\n do_pin_fd\n mount_bpffs_for_pin\n strlen(name) <- NULL pointer dereference\n\nFix it by adding validation to the common process.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49875" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/34de8e6e0e1f66e431abf4123934a2581cb5f133" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6dcdd1b68b7f9333d48d48fc77b75e7f235f6a4a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8c80b2fca4112d724dde477aed13f7b0510a2792" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/da5161ba94c5e9182c301dd4f09c94f715c068bd" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-cfgj-2h5j-cvp7/GHSA-cfgj-2h5j-cvp7.json b/advisories/unreviewed/2025/05/GHSA-cfgj-2h5j-cvp7/GHSA-cfgj-2h5j-cvp7.json new file mode 100644 index 00000000000..269f972fbcb --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-cfgj-2h5j-cvp7/GHSA-cfgj-2h5j-cvp7.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cfgj-2h5j-cvp7", + "modified": "2025-05-01T15:31:46Z", + "published": "2025-05-01T15:31:45Z", + "aliases": [ + "CVE-2022-49767" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\n9p/trans_fd: always use O_NONBLOCK read/write\n\nsyzbot is reporting hung task at p9_fd_close() [1], for p9_mux_poll_stop()\n from p9_conn_destroy() from p9_fd_close() is failing to interrupt already\nstarted kernel_read() from p9_fd_read() from p9_read_work() and/or\nkernel_write() from p9_fd_write() from p9_write_work() requests.\n\nSince p9_socket_open() sets O_NONBLOCK flag, p9_mux_poll_stop() does not\nneed to interrupt kernel_read()/kernel_write(). However, since p9_fd_open()\ndoes not set O_NONBLOCK flag, but pipe blocks unless signal is pending,\np9_mux_poll_stop() needs to interrupt kernel_read()/kernel_write() when\nthe file descriptor refers to a pipe. In other words, pipe file descriptor\nneeds to be handled as if socket file descriptor.\n\nWe somehow need to interrupt kernel_read()/kernel_write() on pipes.\n\nA minimal change, which this patch is doing, is to set O_NONBLOCK flag\n from p9_fd_open(), for O_NONBLOCK flag does not affect reading/writing\nof regular files. But this approach changes O_NONBLOCK flag on userspace-\nsupplied file descriptors (which might break userspace programs), and\nO_NONBLOCK flag could be changed by userspace. It would be possible to set\nO_NONBLOCK flag every time p9_fd_read()/p9_fd_write() is invoked, but still\nremains small race window for clearing O_NONBLOCK flag.\n\nIf we don't want to manipulate O_NONBLOCK flag, we might be able to\nsurround kernel_read()/kernel_write() with set_thread_flag(TIF_SIGPENDING)\nand recalc_sigpending(). Since p9_read_work()/p9_write_work() works are\nprocessed by kernel threads which process global system_wq workqueue,\nsignals could not be delivered from remote threads when p9_mux_poll_stop()\n from p9_conn_destroy() from p9_fd_close() is called. Therefore, calling\nset_thread_flag(TIF_SIGPENDING)/recalc_sigpending() every time would be\nneeded if we count on signals for making kernel_read()/kernel_write()\nnon-blocking.\n\n[Dominique: add comment at Christian's suggestion]", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49767" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0b5e6bd72b8171364616841603a70e4ba9837063" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0e07032b4b4724b8ad1003698cb81083c1818999" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5af16182c5639349415118e9e9aecd8355f7a08b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7abf40f06a76c0dff42eada10597917e9776fbd4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9f8554615df668e4bf83294633ee9d232b28ce45" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a8e2fc8f7b41fa9d9ca5f624f4e4d34fce5b40a9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b1ad04da7fe4515e2ce2d5f2dcab3b5b6d45614b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ef575281b21e9a34dfae544a187c6aac2ae424a9" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-cfq2-3x3p-fqxp/GHSA-cfq2-3x3p-fqxp.json b/advisories/unreviewed/2025/05/GHSA-cfq2-3x3p-fqxp/GHSA-cfq2-3x3p-fqxp.json new file mode 100644 index 00000000000..4607a12cf19 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-cfq2-3x3p-fqxp/GHSA-cfq2-3x3p-fqxp.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cfq2-3x3p-fqxp", + "modified": "2025-05-01T15:31:53Z", + "published": "2025-05-01T15:31:52Z", + "aliases": [ + "CVE-2022-49904" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet, neigh: Fix null-ptr-deref in neigh_table_clear()\n\nWhen IPv6 module gets initialized but hits an error in the middle,\nkenel panic with:\n\nKASAN: null-ptr-deref in range [0x0000000000000598-0x000000000000059f]\nCPU: 1 PID: 361 Comm: insmod\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996)\nRIP: 0010:__neigh_ifdown.isra.0+0x24b/0x370\nRSP: 0018:ffff888012677908 EFLAGS: 00000202\n...\nCall Trace:\n \n neigh_table_clear+0x94/0x2d0\n ndisc_cleanup+0x27/0x40 [ipv6]\n inet6_init+0x21c/0x2cb [ipv6]\n do_one_initcall+0xd3/0x4d0\n do_init_module+0x1ae/0x670\n...\nKernel panic - not syncing: Fatal exception\n\nWhen ipv6 initialization fails, it will try to cleanup and calls:\n\nneigh_table_clear()\n neigh_ifdown(tbl, NULL)\n pneigh_queue_purge(&tbl->proxy_queue, dev_net(dev == NULL))\n # dev_net(NULL) triggers null-ptr-deref.\n\nFix it by passing NULL to pneigh_queue_purge() in neigh_ifdown() if dev\nis NULL, to make kernel not panic immediately.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49904" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0d38b4ca6679e72860ff8730e79bb99d0e9fa3b0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1c89642e7f2b7ecc9635610653f5c2f0276c0051" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2b45d6d0c41cb9593868e476681efb1aae5078a1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a99a8ec4c62180c889482a2ff6465033e0743458" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b49f6b2f21f543d4dc88fb7b1ec2adccb822f27c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b736592de2aa53aee2d48d6b129bc0c892007bbe" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f8017317cb0b279b8ab98b0f3901a2e0ac880dad" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-cmwh-vhg7-3c9r/GHSA-cmwh-vhg7-3c9r.json b/advisories/unreviewed/2025/05/GHSA-cmwh-vhg7-3c9r/GHSA-cmwh-vhg7-3c9r.json new file mode 100644 index 00000000000..8ddb0256f9b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-cmwh-vhg7-3c9r/GHSA-cmwh-vhg7-3c9r.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cmwh-vhg7-3c9r", + "modified": "2025-05-01T15:31:40Z", + "published": "2025-05-01T15:31:40Z", + "aliases": [ + "CVE-2025-23148" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsoc: samsung: exynos-chipid: Add NULL pointer check in exynos_chipid_probe()\n\nsoc_dev_attr->revision could be NULL, thus,\na pointer check is added to prevent potential NULL pointer dereference.\nThis is similar to the fix in commit 3027e7b15b02\n(\"ice: Fix some null pointer dereference issues in ice_ptp.c\").\n\nThis issue is found by our static analysis tool.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23148" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4129760e462f45f14e61b10408ace61aa7c2ed30" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/44a2572a0fdcf3e7565763690d579b998a8f0562" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/475b9b45dc32eba58ab794b5d47ac689fc018398" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4f51d169fd0d4821bce775618db024062b09a3f7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5f80fd2ff8bfd13e41554741740e0ca8e6445ded" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c8222ef6cf29dd7cad21643228f96535cc02b327" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T13:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-crf9-7wj5-4jxg/GHSA-crf9-7wj5-4jxg.json b/advisories/unreviewed/2025/05/GHSA-crf9-7wj5-4jxg/GHSA-crf9-7wj5-4jxg.json new file mode 100644 index 00000000000..187cabc5cd1 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-crf9-7wj5-4jxg/GHSA-crf9-7wj5-4jxg.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-crf9-7wj5-4jxg", + "modified": "2025-05-01T15:31:47Z", + "published": "2025-05-01T15:31:47Z", + "aliases": [ + "CVE-2022-49799" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: Fix wild-memory-access in register_synth_event()\n\nIn register_synth_event(), if set_synth_event_print_fmt() failed, then\nboth trace_remove_event_call() and unregister_trace_event() will be\ncalled, which means the trace_event_call will call\n__unregister_trace_event() twice. As the result, the second unregister\nwill causes the wild-memory-access.\n\nregister_synth_event\n set_synth_event_print_fmt failed\n trace_remove_event_call\n event_remove\n if call->event.funcs then\n __unregister_trace_event (first call)\n unregister_trace_event\n __unregister_trace_event (second call)\n\nFix the bug by avoiding to call the second __unregister_trace_event() by\nchecking if the first one is called.\n\ngeneral protection fault, probably for non-canonical address\n\t0xfbd59c0000000024: 0000 [#1] SMP KASAN PTI\nKASAN: maybe wild-memory-access in range\n[0xdead000000000120-0xdead000000000127]\nCPU: 0 PID: 3807 Comm: modprobe Not tainted\n6.1.0-rc1-00186-g76f33a7eedb4 #299\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS\nrel-1.15.0-0-g2dd4b9b3f840-prebuilt.qemu.org 04/01/2014\nRIP: 0010:unregister_trace_event+0x6e/0x280\nCode: 00 fc ff df 4c 89 ea 48 c1 ea 03 80 3c 02 00 0f 85 0e 02 00 00 48\nb8 00 00 00 00 00 fc ff df 4c 8b 63 08 4c 89 e2 48 c1 ea 03 <80> 3c 02\n00 0f 85 e2 01 00 00 49 89 2c 24 48 85 ed 74 28 e8 7a 9b\nRSP: 0018:ffff88810413f370 EFLAGS: 00010a06\nRAX: dffffc0000000000 RBX: ffff888105d050b0 RCX: 0000000000000000\nRDX: 1bd5a00000000024 RSI: ffff888119e276e0 RDI: ffffffff835a8b20\nRBP: dead000000000100 R08: 0000000000000000 R09: fffffbfff0913481\nR10: ffffffff8489a407 R11: fffffbfff0913480 R12: dead000000000122\nR13: ffff888105d050b8 R14: 0000000000000000 R15: ffff888105d05028\nFS: 00007f7823e8d540(0000) GS:ffff888119e00000(0000)\nknlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007f7823e7ebec CR3: 000000010a058002 CR4: 0000000000330ef0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nCall Trace:\n \n __create_synth_event+0x1e37/0x1eb0\n create_or_delete_synth_event+0x110/0x250\n synth_event_run_command+0x2f/0x110\n test_gen_synth_cmd+0x170/0x2eb [synth_event_gen_test]\n synth_event_gen_test_init+0x76/0x9bc [synth_event_gen_test]\n do_one_initcall+0xdb/0x480\n do_init_module+0x1cf/0x680\n load_module+0x6a50/0x70a0\n __do_sys_finit_module+0x12f/0x1c0\n do_syscall_64+0x3f/0x90\n entry_SYSCALL_64_after_hwframe+0x63/0xcd", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49799" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1b5f1c34d3f5a664a57a5a7557a50e4e3cc2505c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/315b149f08229a233d47532eb5da1707b28f764c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6517b97134f724d12f673f9fb4f456d75c7a905f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a5bfa53e5036b3e7a80be902dd3719a930accabd" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-crgv-wqmc-m2wr/GHSA-crgv-wqmc-m2wr.json b/advisories/unreviewed/2025/05/GHSA-crgv-wqmc-m2wr/GHSA-crgv-wqmc-m2wr.json new file mode 100644 index 00000000000..06764228270 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-crgv-wqmc-m2wr/GHSA-crgv-wqmc-m2wr.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-crgv-wqmc-m2wr", + "modified": "2025-05-01T15:31:51Z", + "published": "2025-05-01T15:31:51Z", + "aliases": [ + "CVE-2022-49882" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: Reject attempts to consume or refresh inactive gfn_to_pfn_cache\n\nReject kvm_gpc_check() and kvm_gpc_refresh() if the cache is inactive.\nNot checking the active flag during refresh is particularly egregious, as\nKVM can end up with a valid, inactive cache, which can lead to a variety\nof use-after-free bugs, e.g. consuming a NULL kernel pointer or missing\nan mmu_notifier invalidation due to the cache not being on the list of\ngfns to invalidate.\n\nNote, \"active\" needs to be set if and only if the cache is on the list\nof caches, i.e. is reachable via mmu_notifier events. If a relevant\nmmu_notifier event occurs while the cache is \"active\" but not on the\nlist, KVM will not acquire the cache's lock and so will not serailize\nthe mmu_notifier event with active users and/or kvm_gpc_refresh().\n\nA race between KVM_XEN_ATTR_TYPE_SHARED_INFO and KVM_XEN_HVM_EVTCHN_SEND\ncan be exploited to trigger the bug.\n\n1. Deactivate shinfo cache:\n\nkvm_xen_hvm_set_attr\ncase KVM_XEN_ATTR_TYPE_SHARED_INFO\n kvm_gpc_deactivate\n kvm_gpc_unmap\n gpc->valid = false\n gpc->khva = NULL\n gpc->active = false\n\nResult: active = false, valid = false\n\n2. Cause cache refresh:\n\nkvm_arch_vm_ioctl\ncase KVM_XEN_HVM_EVTCHN_SEND\n kvm_xen_hvm_evtchn_send\n kvm_xen_set_evtchn\n kvm_xen_set_evtchn_fast\n kvm_gpc_check\n return -EWOULDBLOCK because !gpc->valid\n kvm_xen_set_evtchn_fast\n return -EWOULDBLOCK\n kvm_gpc_refresh\n hva_to_pfn_retry\n gpc->valid = true\n gpc->khva = not NULL\n\nResult: active = false, valid = true\n\n3. Race ioctl KVM_XEN_HVM_EVTCHN_SEND against ioctl\nKVM_XEN_ATTR_TYPE_SHARED_INFO:\n\nkvm_arch_vm_ioctl\ncase KVM_XEN_HVM_EVTCHN_SEND\n kvm_xen_hvm_evtchn_send\n kvm_xen_set_evtchn\n kvm_xen_set_evtchn_fast\n read_lock gpc->lock\n kvm_xen_hvm_set_attr case\n KVM_XEN_ATTR_TYPE_SHARED_INFO\n mutex_lock kvm->lock\n kvm_xen_shared_info_init\n kvm_gpc_activate\n gpc->khva = NULL\n kvm_gpc_check\n [ Check passes because gpc->valid is\n still true, even though gpc->khva\n is already NULL. ]\n shinfo = gpc->khva\n pending_bits = shinfo->evtchn_pending\n CRASH: test_and_set_bit(..., pending_bits)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49882" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bfa9672f8fc9eb118124bab61899d2dd497f95ba" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ecbcf030b45666ad11bc98565e71dfbcb7be4393" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-crp4-4q2h-fprq/GHSA-crp4-4q2h-fprq.json b/advisories/unreviewed/2025/05/GHSA-crp4-4q2h-fprq/GHSA-crp4-4q2h-fprq.json new file mode 100644 index 00000000000..ff047b36751 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-crp4-4q2h-fprq/GHSA-crp4-4q2h-fprq.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-crp4-4q2h-fprq", + "modified": "2025-05-01T15:31:39Z", + "published": "2025-05-01T15:31:39Z", + "aliases": [ + "CVE-2025-23141" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: x86: Acquire SRCU in KVM_GET_MP_STATE to protect guest memory accesses\n\nAcquire a lock on kvm->srcu when userspace is getting MP state to handle a\nrather extreme edge case where \"accepting\" APIC events, i.e. processing\npending INIT or SIPI, can trigger accesses to guest memory. If the vCPU\nis in L2 with INIT *and* a TRIPLE_FAULT request pending, then getting MP\nstate will trigger a nested VM-Exit by way of ->check_nested_events(), and\nemuating the nested VM-Exit can access guest memory.\n\nThe splat was originally hit by syzkaller on a Google-internal kernel, and\nreproduced on an upstream kernel by hacking the triple_fault_event_test\nselftest to stuff a pending INIT, store an MSR on VM-Exit (to generate a\nmemory access on VMX), and do vcpu_mp_state_get() to trigger the scenario.\n\n =============================\n WARNING: suspicious RCU usage\n 6.14.0-rc3-b112d356288b-vmx/pi_lockdep_false_pos-lock #3 Not tainted\n -----------------------------\n include/linux/kvm_host.h:1058 suspicious rcu_dereference_check() usage!\n\n other info that might help us debug this:\n\n rcu_scheduler_active = 2, debug_locks = 1\n 1 lock held by triple_fault_ev/1256:\n #0: ffff88810df5a330 (&vcpu->mutex){+.+.}-{4:4}, at: kvm_vcpu_ioctl+0x8b/0x9a0 [kvm]\n\n stack backtrace:\n CPU: 11 UID: 1000 PID: 1256 Comm: triple_fault_ev Not tainted 6.14.0-rc3-b112d356288b-vmx #3\n Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 0.0.0 02/06/2015\n Call Trace:\n \n dump_stack_lvl+0x7f/0x90\n lockdep_rcu_suspicious+0x144/0x190\n kvm_vcpu_gfn_to_memslot+0x156/0x180 [kvm]\n kvm_vcpu_read_guest+0x3e/0x90 [kvm]\n read_and_check_msr_entry+0x2e/0x180 [kvm_intel]\n __nested_vmx_vmexit+0x550/0xde0 [kvm_intel]\n kvm_check_nested_events+0x1b/0x30 [kvm]\n kvm_apic_accept_events+0x33/0x100 [kvm]\n kvm_arch_vcpu_ioctl_get_mpstate+0x30/0x1d0 [kvm]\n kvm_vcpu_ioctl+0x33e/0x9a0 [kvm]\n __x64_sys_ioctl+0x8b/0xb0\n do_syscall_64+0x6c/0x170\n entry_SYSCALL_64_after_hwframe+0x4b/0x53\n ", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23141" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0357c8406dfa09430dd9858ebe813feb65524b6e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/592e040572f216d916f465047c8ce4a308fcca44" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7bc5c360375d28ba5ef6298b0d53e735c81d66a1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8a3df0aa1087a89f5ce55f4aba816bfcb1ecf1be" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ef01cac401f18647d62720cf773d7bb0541827da" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f5cbe725b7477b4cd677be1b86b4e08f90572997" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T13:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-f248-rm72-p5mx/GHSA-f248-rm72-p5mx.json b/advisories/unreviewed/2025/05/GHSA-f248-rm72-p5mx/GHSA-f248-rm72-p5mx.json new file mode 100644 index 00000000000..e03ec36f3a4 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-f248-rm72-p5mx/GHSA-f248-rm72-p5mx.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f248-rm72-p5mx", + "modified": "2025-05-01T15:31:47Z", + "published": "2025-05-01T15:31:46Z", + "aliases": [ + "CVE-2022-49787" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmmc: sdhci-pci: Fix possible memory leak caused by missing pci_dev_put()\n\npci_get_device() will increase the reference count for the returned\npci_dev. We need to use pci_dev_put() to decrease the reference count\nbefore amd_probe() returns. There is no problem for the 'smbus_dev ==\nNULL' branch because pci_dev_put() can also handle the NULL input\nparameter case.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49787" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/222cfa0118aa68687ace74aab8fdf77ce8fbd7e6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/27f712cd47d65e14cd52cc32a23d42aeef583d5d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/35bca18092685b488003509fef7055aa2d4f2ebc" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4423866d31a06a810db22062ed13389416a66b22" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5dbd6378dbf96787d6dbcca44156c511ae085ea3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7570e5b5419ffd34b6dc45a88c51e113a9a187e3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a99a547658e5d451f01ed307426286716b6f01bf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-f24m-gff5-ch5w/GHSA-f24m-gff5-ch5w.json b/advisories/unreviewed/2025/05/GHSA-f24m-gff5-ch5w/GHSA-f24m-gff5-ch5w.json new file mode 100644 index 00000000000..c189abe2fad --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-f24m-gff5-ch5w/GHSA-f24m-gff5-ch5w.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f24m-gff5-ch5w", + "modified": "2025-05-01T15:31:49Z", + "published": "2025-05-01T15:31:49Z", + "aliases": [ + "CVE-2022-49847" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ethernet: ti: am65-cpsw: Fix segmentation fault at module unload\n\nMove am65_cpsw_nuss_phylink_cleanup() call to after\nam65_cpsw_nuss_cleanup_ndev() so phylink is still valid\nto prevent the below Segmentation fault on module remove when\nfirst slave link is up.\n\n[ 31.652944] Unable to handle kernel paging request at virtual address 00040008000005f4\n[ 31.684627] Mem abort info:\n[ 31.687446] ESR = 0x0000000096000004\n[ 31.704614] EC = 0x25: DABT (current EL), IL = 32 bits\n[ 31.720663] SET = 0, FnV = 0\n[ 31.723729] EA = 0, S1PTW = 0\n[ 31.740617] FSC = 0x04: level 0 translation fault\n[ 31.756624] Data abort info:\n[ 31.759508] ISV = 0, ISS = 0x00000004\n[ 31.776705] CM = 0, WnR = 0\n[ 31.779695] [00040008000005f4] address between user and kernel address ranges\n[ 31.808644] Internal error: Oops: 0000000096000004 [#1] PREEMPT SMP\n[ 31.814928] Modules linked in: wlcore_sdio wl18xx wlcore mac80211 libarc4 cfg80211 rfkill crct10dif_ce phy_gmii_sel ti_am65_cpsw_nuss(-) sch_fq_codel ipv6\n[ 31.828776] CPU: 0 PID: 1026 Comm: modprobe Not tainted 6.1.0-rc2-00012-gfabfcf7dafdb-dirty #160\n[ 31.837547] Hardware name: Texas Instruments AM625 (DT)\n[ 31.842760] pstate: 40000005 (nZcv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n[ 31.849709] pc : phy_stop+0x18/0xf8\n[ 31.853202] lr : phylink_stop+0x38/0xf8\n[ 31.857031] sp : ffff80000a0839f0\n[ 31.860335] x29: ffff80000a0839f0 x28: ffff000000de1c80 x27: 0000000000000000\n[ 31.867462] x26: 0000000000000000 x25: 0000000000000000 x24: ffff80000a083b98\n[ 31.874589] x23: 0000000000000800 x22: 0000000000000001 x21: ffff000001bfba90\n[ 31.881715] x20: ffff0000015ee000 x19: 0004000800000200 x18: 0000000000000000\n[ 31.888842] x17: ffff800076c45000 x16: ffff800008004000 x15: 000058e39660b106\n[ 31.895969] x14: 0000000000000144 x13: 0000000000000144 x12: 0000000000000000\n[ 31.903095] x11: 000000000000275f x10: 00000000000009e0 x9 : ffff80000a0837d0\n[ 31.910222] x8 : ffff000000de26c0 x7 : ffff00007fbd6540 x6 : ffff00007fbd64c0\n[ 31.917349] x5 : ffff00007fbd0b10 x4 : ffff00007fbd0b10 x3 : ffff00007fbd3920\n[ 31.924476] x2 : d0a07fcff8b8d500 x1 : 0000000000000000 x0 : 0004000800000200\n[ 31.931603] Call trace:\n[ 31.934042] phy_stop+0x18/0xf8\n[ 31.937177] phylink_stop+0x38/0xf8\n[ 31.940657] am65_cpsw_nuss_ndo_slave_stop+0x28/0x1e0 [ti_am65_cpsw_nuss]\n[ 31.947452] __dev_close_many+0xa4/0x140\n[ 31.951371] dev_close_many+0x84/0x128\n[ 31.955115] unregister_netdevice_many+0x130/0x6d0\n[ 31.959897] unregister_netdevice_queue+0x94/0xd8\n[ 31.964591] unregister_netdev+0x24/0x38\n[ 31.968504] am65_cpsw_nuss_cleanup_ndev.isra.0+0x48/0x70 [ti_am65_cpsw_nuss]\n[ 31.975637] am65_cpsw_nuss_remove+0x58/0xf8 [ti_am65_cpsw_nuss]", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49847" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1a0c016a4831ea29be09bbc8162d4a2a0690b4b8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/442fd1bfe599bc54d118775e9e1a4fe913e4b369" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-f372-2jpp-jxj9/GHSA-f372-2jpp-jxj9.json b/advisories/unreviewed/2025/05/GHSA-f372-2jpp-jxj9/GHSA-f372-2jpp-jxj9.json new file mode 100644 index 00000000000..53f56484656 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-f372-2jpp-jxj9/GHSA-f372-2jpp-jxj9.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f372-2jpp-jxj9", + "modified": "2025-05-01T15:31:48Z", + "published": "2025-05-01T15:31:48Z", + "aliases": [ + "CVE-2022-49811" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrbd: use after free in drbd_create_device()\n\nThe drbd_destroy_connection() frees the \"connection\" so use the _safe()\niterator to prevent a use after free.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49811" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7d93417d596402ddd46bd76c721f205d09d0d025" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/813a8dd9c45fd46f5cbbfbedf0791afa7740ccf5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9ed51414aef6e59e832e2960f10766dce2d5b1a1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a7a1598189228b5007369a9622ccdf587be0730f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bf47ca1b35fc1f55091ffaff5fbe41ea0c6f59a1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c2a00b149836d60c222930bbea6b2139caf34d4f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fc1897f16ebcfd22364f2afcc27f53a740f3bc7a" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-f3p5-h83r-f8vf/GHSA-f3p5-h83r-f8vf.json b/advisories/unreviewed/2025/05/GHSA-f3p5-h83r-f8vf/GHSA-f3p5-h83r-f8vf.json new file mode 100644 index 00000000000..540480a8ebd --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-f3p5-h83r-f8vf/GHSA-f3p5-h83r-f8vf.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f3p5-h83r-f8vf", + "modified": "2025-05-01T15:31:45Z", + "published": "2025-05-01T15:31:45Z", + "aliases": [ + "CVE-2025-37789" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: openvswitch: fix nested key length validation in the set() action\n\nIt's not safe to access nla_len(ovs_key) if the data is smaller than\nthe netlink header. Check that the attribute is OK first.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37789" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/03d7262dd53e8c404da35cc81aaa887fd901f76b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1489c195c8eecd262aa6712761ba5288203e28ec" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/65d91192aa66f05710cfddf6a14b5a25ee554dba" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/824a7c2df5127b2402b68a21a265d413e78dcad7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/be80768d4f3b6fd13f421451cc3fee8778aba8bc" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T14:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-f6f3-grvj-5rhr/GHSA-f6f3-grvj-5rhr.json b/advisories/unreviewed/2025/05/GHSA-f6f3-grvj-5rhr/GHSA-f6f3-grvj-5rhr.json index a6fb8c9a68b..e20ad23cace 100644 --- a/advisories/unreviewed/2025/05/GHSA-f6f3-grvj-5rhr/GHSA-f6f3-grvj-5rhr.json +++ b/advisories/unreviewed/2025/05/GHSA-f6f3-grvj-5rhr/GHSA-f6f3-grvj-5rhr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-f6f3-grvj-5rhr", - "modified": "2025-05-01T06:30:28Z", + "modified": "2025-05-01T15:31:39Z", "published": "2025-05-01T06:30:28Z", "aliases": [ "CVE-2025-3502" ], "details": "The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-01T06:15:34Z" diff --git a/advisories/unreviewed/2025/05/GHSA-f6mf-84fx-cph2/GHSA-f6mf-84fx-cph2.json b/advisories/unreviewed/2025/05/GHSA-f6mf-84fx-cph2/GHSA-f6mf-84fx-cph2.json new file mode 100644 index 00000000000..8240a3476a3 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-f6mf-84fx-cph2/GHSA-f6mf-84fx-cph2.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f6mf-84fx-cph2", + "modified": "2025-05-01T15:31:41Z", + "published": "2025-05-01T15:31:41Z", + "aliases": [ + "CVE-2025-23154" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nio_uring/net: fix io_req_post_cqe abuse by send bundle\n\n[ 114.987980][ T5313] WARNING: CPU: 6 PID: 5313 at io_uring/io_uring.c:872 io_req_post_cqe+0x12e/0x4f0\n[ 114.991597][ T5313] RIP: 0010:io_req_post_cqe+0x12e/0x4f0\n[ 115.001880][ T5313] Call Trace:\n[ 115.002222][ T5313] \n[ 115.007813][ T5313] io_send+0x4fe/0x10f0\n[ 115.009317][ T5313] io_issue_sqe+0x1a6/0x1740\n[ 115.012094][ T5313] io_wq_submit_work+0x38b/0xed0\n[ 115.013223][ T5313] io_worker_handle_work+0x62a/0x1600\n[ 115.013876][ T5313] io_wq_worker+0x34f/0xdf0\n\nAs the comment states, io_req_post_cqe() should only be used by\nmultishot requests, i.e. REQ_F_APOLL_MULTISHOT, which bundled sends are\nnot. Add a flag signifying whether a request wants to post multiple\nCQEs. Eventually REQ_F_APOLL_MULTISHOT should imply the new flag, but\nthat's left out for simplicity.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23154" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6889ae1b4df1579bcdffef023e2ea9a982565dff" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7888c9fc0b2d3636f2e821ed1ad3c6920fa8e378" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9aa804e6b9696998308095fb9d335046a71550f1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b7c6d081c19a5e11bbd77bb97a62cff2b6b21cb5" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T13:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-f6mg-77cc-c9pm/GHSA-f6mg-77cc-c9pm.json b/advisories/unreviewed/2025/05/GHSA-f6mg-77cc-c9pm/GHSA-f6mg-77cc-c9pm.json new file mode 100644 index 00000000000..15f87730f82 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-f6mg-77cc-c9pm/GHSA-f6mg-77cc-c9pm.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f6mg-77cc-c9pm", + "modified": "2025-05-01T15:31:41Z", + "published": "2025-05-01T15:31:41Z", + "aliases": [ + "CVE-2025-23158" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: venus: hfi: add check to handle incorrect queue size\n\nqsize represents size of shared queued between driver and video\nfirmware. Firmware can modify this value to an invalid large value. In\nsuch situation, empty_space will be bigger than the space actually\navailable. Since new_wr_idx is not checked, so the following code will\nresult in an OOB write.\n...\nqsize = qhdr->q_size\n\nif (wr_idx >= rd_idx)\n empty_space = qsize - (wr_idx - rd_idx)\n....\nif (new_wr_idx < qsize) {\n memcpy(wr_ptr, packet, dwords << 2) --> OOB write\n\nAdd check to ensure qsize is within the allocated size while\nreading and writing packets into the queue.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23158" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/101a86619aab42bb61f2253bbf720121022eab86" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/40084302f639b3fe954398c5ba5ee556b7242b54" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/679424f8b31446f90080befd0300ea915485b096" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/69baf245b23e20efda0079238b27fc63ecf13de1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cf5f7bb4e0d786f4d9d50ae6b5963935eab71d75" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/edb89d69b1438681daaf5ca90aed3242df94cc96" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T13:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-f76m-q4g4-c63m/GHSA-f76m-q4g4-c63m.json b/advisories/unreviewed/2025/05/GHSA-f76m-q4g4-c63m/GHSA-f76m-q4g4-c63m.json new file mode 100644 index 00000000000..1a42e69b12f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-f76m-q4g4-c63m/GHSA-f76m-q4g4-c63m.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f76m-q4g4-c63m", + "modified": "2025-05-01T15:31:52Z", + "published": "2025-05-01T15:31:52Z", + "aliases": [ + "CVE-2022-49912" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix ulist leaks in error paths of qgroup self tests\n\nIn the test_no_shared_qgroup() and test_multiple_refs() qgroup self tests,\nif we fail to add the tree ref, remove the extent item or remove the\nextent ref, we are returning from the test function without freeing the\n\"old_roots\" ulist that was allocated by the previous calls to\nbtrfs_find_all_roots(). Fix that by calling ulist_free() before returning.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49912" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0a0dead4ad1a2e2a9bdf133ef45111d7c8daef84" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/203204798831c35d855ecc6417d98267d2d2184b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3f58283d83a588ff5da62fc150de19e798ed2ec2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5d1a47ebf84540e40b5b43fc21aef0d6c0f627d9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d37de92b38932d40e4a251e876cc388f9aee5f42" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d81370396025cf63a7a1b5f8bb25a3479203b2ca" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/da7003434bcab0ae9aba3f2c003e734cae093326" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f46ea5fa3320dca4fe0c0926b49a5f14cb85de62" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-ff3g-qxwq-qv29/GHSA-ff3g-qxwq-qv29.json b/advisories/unreviewed/2025/05/GHSA-ff3g-qxwq-qv29/GHSA-ff3g-qxwq-qv29.json new file mode 100644 index 00000000000..592ac2a5235 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-ff3g-qxwq-qv29/GHSA-ff3g-qxwq-qv29.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ff3g-qxwq-qv29", + "modified": "2025-05-01T15:31:46Z", + "published": "2025-05-01T15:31:46Z", + "aliases": [ + "CVE-2022-49786" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nblk-cgroup: properly pin the parent in blkcg_css_online\n\nblkcg_css_online is supposed to pin the blkcg of the parent, but\n397c9f46ee4d refactored things and along the way, changed it to pin the\ncss instead. This results in extra pins, and we end up leaking blkcgs\nand cgroups.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49786" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d118247e404d6338f7b90636a3c6b95a387ed163" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d7dbd43f4a828fa1d9a8614d5b0ac40aee6375fe" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-ffcr-3gvq-xq62/GHSA-ffcr-3gvq-xq62.json b/advisories/unreviewed/2025/05/GHSA-ffcr-3gvq-xq62/GHSA-ffcr-3gvq-xq62.json new file mode 100644 index 00000000000..35edf8869a9 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-ffcr-3gvq-xq62/GHSA-ffcr-3gvq-xq62.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ffcr-3gvq-xq62", + "modified": "2025-05-01T15:31:43Z", + "published": "2025-05-01T15:31:43Z", + "aliases": [ + "CVE-2025-37764" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/imagination: fix firmware memory leaks\n\nFree the memory used to hold the results of firmware image processing\nwhen the module is unloaded.\n\nFix the related issue of the same memory being leaked if processing\nof the firmware image fails during module load.\n\nEnsure all firmware GEM objects are destroyed if firmware image\nprocessing fails.\n\nFixes memory leaks on powervr module unload detected by Kmemleak:\n\nunreferenced object 0xffff000042e20000 (size 94208):\n comm \"modprobe\", pid 470, jiffies 4295277154\n hex dump (first 32 bytes):\n 02 ae 7f ed bf 45 84 00 3c 5b 1f ed 9f 45 45 05 .....E..<[...EE.\n d5 4f 5d 14 6c 00 3d 23 30 d0 3a 4a 66 0e 48 c8 .O].l.=#0.:Jf.H.\n backtrace (crc dd329dec):\n kmemleak_alloc+0x30/0x40\n ___kmalloc_large_node+0x140/0x188\n __kmalloc_large_node_noprof+0x2c/0x13c\n __kmalloc_noprof+0x48/0x4c0\n pvr_fw_init+0xaa4/0x1f50 [powervr]\n\nunreferenced object 0xffff000042d20000 (size 20480):\n comm \"modprobe\", pid 470, jiffies 4295277154\n hex dump (first 32 bytes):\n 00 00 00 00 00 00 00 00 09 00 00 00 0b 00 00 00 ................\n 00 00 00 00 00 00 00 00 07 00 00 00 08 00 00 00 ................\n backtrace (crc 395b02e3):\n kmemleak_alloc+0x30/0x40\n ___kmalloc_large_node+0x140/0x188\n __kmalloc_large_node_noprof+0x2c/0x13c\n __kmalloc_noprof+0x48/0x4c0\n pvr_fw_init+0xb0c/0x1f50 [powervr]", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37764" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/490c30fd554597e78f66650044877e7defb5f83c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/891c12ba855ccb34c06a2e5da75c644683087036" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a5b230e7f3a55bd8bd8d012eec75a4b7baa671d5" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T14:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-fpwm-r92q-hvjc/GHSA-fpwm-r92q-hvjc.json b/advisories/unreviewed/2025/05/GHSA-fpwm-r92q-hvjc/GHSA-fpwm-r92q-hvjc.json new file mode 100644 index 00000000000..2312508fcd5 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-fpwm-r92q-hvjc/GHSA-fpwm-r92q-hvjc.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fpwm-r92q-hvjc", + "modified": "2025-05-01T15:31:50Z", + "published": "2025-05-01T15:31:50Z", + "aliases": [ + "CVE-2022-49863" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: af_can: fix NULL pointer dereference in can_rx_register()\n\nIt causes NULL pointer dereference when testing as following:\n(a) use syscall(__NR_socket, 0x10ul, 3ul, 0) to create netlink socket.\n(b) use syscall(__NR_sendmsg, ...) to create bond link device and vxcan\n link device, and bind vxcan device to bond device (can also use\n ifenslave command to bind vxcan device to bond device).\n(c) use syscall(__NR_socket, 0x1dul, 3ul, 1) to create CAN socket.\n(d) use syscall(__NR_bind, ...) to bind the bond device to CAN socket.\n\nThe bond device invokes the can-raw protocol registration interface to\nreceive CAN packets. However, ml_priv is not allocated to the dev,\ndev_rcv_lists is assigned to NULL in can_rx_register(). In this case,\nit will occur the NULL pointer dereference issue.\n\nThe following is the stack information:\nBUG: kernel NULL pointer dereference, address: 0000000000000008\nPGD 122a4067 P4D 122a4067 PUD 1223c067 PMD 0\nOops: 0000 [#1] PREEMPT SMP\nRIP: 0010:can_rx_register+0x12d/0x1e0\nCall Trace:\n\nraw_enable_filters+0x8d/0x120\nraw_enable_allfilters+0x3b/0x130\nraw_bind+0x118/0x4f0\n__sys_bind+0x163/0x1a0\n__x64_sys_bind+0x1e/0x30\ndo_syscall_64+0x35/0x80\nentry_SYSCALL_64_after_hwframe+0x63/0xcd\n", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49863" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/261178a1c2623077d62e374a75c195e6c99a6f05" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8aa59e355949442c408408c2d836e561794c40a1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a8055677b054bc2bb78beb1080fdc2dc5158c2fe" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/afab4655750fcb3fca359bc7d7214e3d634cdf9c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d68fa77ee3d03bad6fe84e89759ddf7005f9e9c6" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-frjr-3w6j-qh2v/GHSA-frjr-3w6j-qh2v.json b/advisories/unreviewed/2025/05/GHSA-frjr-3w6j-qh2v/GHSA-frjr-3w6j-qh2v.json new file mode 100644 index 00000000000..fa8d4416267 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-frjr-3w6j-qh2v/GHSA-frjr-3w6j-qh2v.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-frjr-3w6j-qh2v", + "modified": "2025-05-01T15:31:44Z", + "published": "2025-05-01T15:31:44Z", + "aliases": [ + "CVE-2025-37772" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/cma: Fix workqueue crash in cma_netevent_work_handler\n\nstruct rdma_cm_id has member \"struct work_struct net_work\"\nthat is reused for enqueuing cma_netevent_work_handler()s\nonto cma_wq.\n\nBelow crash[1] can occur if more than one call to\ncma_netevent_callback() occurs in quick succession,\nwhich further enqueues cma_netevent_work_handler()s for the\nsame rdma_cm_id, overwriting any previously queued work-item(s)\nthat was just scheduled to run i.e. there is no guarantee\nthe queued work item may run between two successive calls\nto cma_netevent_callback() and the 2nd INIT_WORK would overwrite\nthe 1st work item (for the same rdma_cm_id), despite grabbing\nid_table_lock during enqueue.\n\nAlso drgn analysis [2] indicates the work item was likely overwritten.\n\nFix this by moving the INIT_WORK() to __rdma_create_id(),\nso that it doesn't race with any existing queue_work() or\nits worker thread.\n\n[1] Trimmed crash stack:\n=============================================\nBUG: kernel NULL pointer dereference, address: 0000000000000008\nkworker/u256:6 ... 6.12.0-0...\nWorkqueue: cma_netevent_work_handler [rdma_cm] (rdma_cm)\nRIP: 0010:process_one_work+0xba/0x31a\nCall Trace:\n worker_thread+0x266/0x3a0\n kthread+0xcf/0x100\n ret_from_fork+0x31/0x50\n ret_from_fork_asm+0x1a/0x30\n=============================================\n\n[2] drgn crash analysis:\n\n>>> trace = prog.crashed_thread().stack_trace()\n>>> trace\n(0) crash_setup_regs (./arch/x86/include/asm/kexec.h:111:15)\n(1) __crash_kexec (kernel/crash_core.c:122:4)\n(2) panic (kernel/panic.c:399:3)\n(3) oops_end (arch/x86/kernel/dumpstack.c:382:3)\n...\n(8) process_one_work (kernel/workqueue.c:3168:2)\n(9) process_scheduled_works (kernel/workqueue.c:3310:3)\n(10) worker_thread (kernel/workqueue.c:3391:4)\n(11) kthread (kernel/kthread.c:389:9)\n\nLine workqueue.c:3168 for this kernel version is in process_one_work():\n3168\tstrscpy(worker->desc, pwq->wq->name, WORKER_DESC_LEN);\n\n>>> trace[8][\"work\"]\n*(struct work_struct *)0xffff92577d0a21d8 = {\n\t.data = (atomic_long_t){\n\t\t.counter = (s64)536870912, <=== Note\n\t},\n\t.entry = (struct list_head){\n\t\t.next = (struct list_head *)0xffff924d075924c0,\n\t\t.prev = (struct list_head *)0xffff924d075924c0,\n\t},\n\t.func = (work_func_t)cma_netevent_work_handler+0x0 = 0xffffffffc2cec280,\n}\n\nSuspicion is that pwq is NULL:\n>>> trace[8][\"pwq\"]\n(struct pool_workqueue *)\n\nIn process_one_work(), pwq is assigned from:\nstruct pool_workqueue *pwq = get_work_pwq(work);\n\nand get_work_pwq() is:\nstatic struct pool_workqueue *get_work_pwq(struct work_struct *work)\n{\n \tunsigned long data = atomic_long_read(&work->data);\n\n \tif (data & WORK_STRUCT_PWQ)\n \t\treturn work_struct_pwq(data);\n \telse\n \t\treturn NULL;\n}\n\nWORK_STRUCT_PWQ is 0x4:\n>>> print(repr(prog['WORK_STRUCT_PWQ']))\nObject(prog, 'enum work_flags', value=4)\n\nBut work->data is 536870912 which is 0x20000000.\nSo, get_work_pwq() returns NULL and we crash in process_one_work():\n3168\tstrscpy(worker->desc, pwq->wq->name, WORKER_DESC_LEN);\n=============================================", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37772" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/45f5dcdd049719fb999393b30679605f16ebce14" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/51003b2c872c63d28bcf5fbcc52cf7b05615f7b7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b172a4a0de254f1fcce7591833a9a63547c2f447" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c2b169fc7a12665d8a675c1ff14bca1b9c63fb9a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d23fd7a539ac078df119707110686a5b226ee3bb" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T14:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-fw2p-r2v5-6jjq/GHSA-fw2p-r2v5-6jjq.json b/advisories/unreviewed/2025/05/GHSA-fw2p-r2v5-6jjq/GHSA-fw2p-r2v5-6jjq.json new file mode 100644 index 00000000000..1f15204aab0 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-fw2p-r2v5-6jjq/GHSA-fw2p-r2v5-6jjq.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fw2p-r2v5-6jjq", + "modified": "2025-05-01T15:31:51Z", + "published": "2025-05-01T15:31:51Z", + "aliases": [ + "CVE-2022-49881" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: cfg80211: fix memory leak in query_regdb_file()\n\nIn the function query_regdb_file() the alpha2 parameter is duplicated\nusing kmemdup() and subsequently freed in regdb_fw_cb(). However,\nrequest_firmware_nowait() can fail without calling regdb_fw_cb() and\nthus leak memory.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49881" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0ede1a988299e95d54bd89551fd635980572e920" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/219446396786330937bcd382a7bc4ccd767383bc" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/38c9fa2cc6bf4b6e1a74057aef8b5cffd23d3264" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/57b962e627ec0ae53d4d16d7bd1033e27e67677a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e1e12180321f416d83444f2cdc9259e0f5093d35" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e9b5a4566d5bc71cc901be50d1fa24da00613120" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-fw9v-j9g8-g322/GHSA-fw9v-j9g8-g322.json b/advisories/unreviewed/2025/05/GHSA-fw9v-j9g8-g322/GHSA-fw9v-j9g8-g322.json new file mode 100644 index 00000000000..8c4bb6410ae --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-fw9v-j9g8-g322/GHSA-fw9v-j9g8-g322.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fw9v-j9g8-g322", + "modified": "2025-05-01T15:31:50Z", + "published": "2025-05-01T15:31:50Z", + "aliases": [ + "CVE-2022-49870" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncapabilities: fix undefined behavior in bit shift for CAP_TO_MASK\n\nShifting signed 32-bit value by 31 bits is undefined, so changing\nsignificant bit to unsigned. The UBSAN warning calltrace like below:\n\nUBSAN: shift-out-of-bounds in security/commoncap.c:1252:2\nleft shift of 1 by 31 places cannot be represented in type 'int'\nCall Trace:\n \n dump_stack_lvl+0x7d/0xa5\n dump_stack+0x15/0x1b\n ubsan_epilogue+0xe/0x4e\n __ubsan_handle_shift_out_of_bounds+0x1e7/0x20c\n cap_task_prctl+0x561/0x6f0\n security_task_prctl+0x5a/0xb0\n __x64_sys_prctl+0x61/0x8f0\n do_syscall_64+0x58/0x80\n entry_SYSCALL_64_after_hwframe+0x63/0xcd\n ", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49870" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/151dc8087b5609e53b069c068e3f3ee100efa586" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/27bdb134c043ff32c459d98f16550d0ffa0b3c34" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/46653972e3ea64f79e7f8ae3aa41a4d3fdb70a13" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5661f111a1616ac105ec8cec81bff99b60f847ac" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5b79fa628e2ab789e629a83cd211ef9b4c1a593e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/65b0bc7a0690861812ade523d19f82688ab819dc" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/dbaab08c8677d598244d21afb7818e44e1c5d826" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fcbd2b336834bd24e1d9454ad5737856470c10d7" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-fx77-mj6g-j23r/GHSA-fx77-mj6g-j23r.json b/advisories/unreviewed/2025/05/GHSA-fx77-mj6g-j23r/GHSA-fx77-mj6g-j23r.json new file mode 100644 index 00000000000..fa24cfafbd9 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-fx77-mj6g-j23r/GHSA-fx77-mj6g-j23r.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fx77-mj6g-j23r", + "modified": "2025-05-01T15:31:43Z", + "published": "2025-05-01T15:31:43Z", + "aliases": [ + "CVE-2025-37758" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nata: pata_pxa: Fix potential NULL pointer dereference in pxa_ata_probe()\n\ndevm_ioremap() returns NULL on error. Currently, pxa_ata_probe() does\nnot check for this case, which can result in a NULL pointer dereference.\n\nAdd NULL check after devm_ioremap() to prevent this issue.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37758" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2ba9e4c69207777bb0775c7c091800ecd69de144" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2dc53c7a0c1f57b082931facafa804a7ca32a9a6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5b09bf6243b0bc0ae58bd9efdf6f0de5546f8d06" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ad320e408a8c95a282ab9c05cdf0c9b95e317985" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c022287f6e599422511aa227dc6da37b58d9ceac" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ee2b0301d6bfe16b35d57947687c664ecb815775" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T13:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-g26c-fp96-224v/GHSA-g26c-fp96-224v.json b/advisories/unreviewed/2025/05/GHSA-g26c-fp96-224v/GHSA-g26c-fp96-224v.json new file mode 100644 index 00000000000..9a461b0ee55 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-g26c-fp96-224v/GHSA-g26c-fp96-224v.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g26c-fp96-224v", + "modified": "2025-05-01T15:31:47Z", + "published": "2025-05-01T15:31:47Z", + "aliases": [ + "CVE-2022-49798" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: Fix race where eprobes can be called before the event\n\nThe flag that tells the event to call its triggers after reading the event\nis set for eprobes after the eprobe is enabled. This leads to a race where\nthe eprobe may be triggered at the beginning of the event where the record\ninformation is NULL. The eprobe then dereferences the NULL record causing\na NULL kernel pointer bug.\n\nTest for a NULL record to keep this from happening.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49798" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7291dec4f2d17a2d3fd1f789fb41e58476539f21" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/73f5191467ffe3af82f27fe0ea6a8c2fac724d3f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/94eedf3dded5fb472ce97bfaf3ac1c6c29c35d26" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-g3xx-h684-wg52/GHSA-g3xx-h684-wg52.json b/advisories/unreviewed/2025/05/GHSA-g3xx-h684-wg52/GHSA-g3xx-h684-wg52.json new file mode 100644 index 00000000000..dc90f0aec8d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-g3xx-h684-wg52/GHSA-g3xx-h684-wg52.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g3xx-h684-wg52", + "modified": "2025-05-01T15:31:44Z", + "published": "2025-05-01T15:31:44Z", + "aliases": [ + "CVE-2025-37770" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/pm: Prevent division by zero\n\nThe user can set any speed value.\nIf speed is greater than UINT_MAX/8, division by zero is possible.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37770" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/05de66de280ea1bd0459c994bfd2dd332cfbc2a9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4b8c3c0d17c07f301011e2908fecd2ebdcfe3d1c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/587de3ca7875c06fe3c3aa4073a85c4eff46591f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/836a189fb422e7efb81c51d5160e47ec7bc11500" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bd4d90adbca1862d03e581e10e74ab73ec75e61b" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T14:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-g46r-j95v-9f3q/GHSA-g46r-j95v-9f3q.json b/advisories/unreviewed/2025/05/GHSA-g46r-j95v-9f3q/GHSA-g46r-j95v-9f3q.json new file mode 100644 index 00000000000..f9d397b235d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-g46r-j95v-9f3q/GHSA-g46r-j95v-9f3q.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g46r-j95v-9f3q", + "modified": "2025-05-01T15:31:49Z", + "published": "2025-05-01T15:31:49Z", + "aliases": [ + "CVE-2022-49829" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/scheduler: fix fence ref counting\n\nWe leaked dependency fences when processes were beeing killed.\n\nAdditional to that grab a reference to the last scheduled fence.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49829" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b3af84383e7abdc5e63435817bb73a268e7c3637" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e5f4b38362df93594cb426b04979d8834122f159" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-g5p7-q8gg-6qmf/GHSA-g5p7-q8gg-6qmf.json b/advisories/unreviewed/2025/05/GHSA-g5p7-q8gg-6qmf/GHSA-g5p7-q8gg-6qmf.json new file mode 100644 index 00000000000..c9f48bb564e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-g5p7-q8gg-6qmf/GHSA-g5p7-q8gg-6qmf.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g5p7-q8gg-6qmf", + "modified": "2025-05-01T15:31:46Z", + "published": "2025-05-01T15:31:46Z", + "aliases": [ + "CVE-2022-49783" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/fpu: Drop fpregs lock before inheriting FPU permissions\n\nMike Galbraith reported the following against an old fork of preempt-rt\nbut the same issue also applies to the current preempt-rt tree.\n\n BUG: sleeping function called from invalid context at kernel/locking/spinlock_rt.c:46\n in_atomic(): 1, irqs_disabled(): 0, non_block: 0, pid: 1, name: systemd\n preempt_count: 1, expected: 0\n RCU nest depth: 0, expected: 0\n Preemption disabled at:\n fpu_clone\n CPU: 6 PID: 1 Comm: systemd Tainted: G E (unreleased)\n Call Trace:\n \n dump_stack_lvl\n ? fpu_clone\n __might_resched\n rt_spin_lock\n fpu_clone\n ? copy_thread\n ? copy_process\n ? shmem_alloc_inode\n ? kmem_cache_alloc\n ? kernel_clone\n ? __do_sys_clone\n ? do_syscall_64\n ? __x64_sys_rt_sigprocmask\n ? syscall_exit_to_user_mode\n ? do_syscall_64\n ? syscall_exit_to_user_mode\n ? do_syscall_64\n ? syscall_exit_to_user_mode\n ? do_syscall_64\n ? exc_page_fault\n ? entry_SYSCALL_64_after_hwframe\n \n\nMike says:\n\n The splat comes from fpu_inherit_perms() being called under fpregs_lock(),\n and us reaching the spin_lock_irq() therein due to fpu_state_size_dynamic()\n returning true despite static key __fpu_state_size_dynamic having never\n been enabled.\n\nMike's assessment looks correct. fpregs_lock on a PREEMPT_RT kernel disables\npreemption so calling spin_lock_irq() in fpu_inherit_perms() is unsafe. This\nproblem exists since commit\n\n 9e798e9aa14c (\"x86/fpu: Prepare fpu_clone() for dynamically enabled features\").\n\nEven though the original bug report should not have enabled the paths at\nall, the bug still exists.\n\nfpregs_lock is necessary when editing the FPU registers or a task's FP\nstate but it is not necessary for fpu_inherit_perms(). The only write\nof any FP state in fpu_inherit_perms() is for the new child which is\nnot running yet and cannot context switch or be borrowed by a kernel\nthread yet. Hence, fpregs_lock is not protecting anything in the new\nchild until clone() completes and can be dropped earlier. The siglock\nstill needs to be acquired by fpu_inherit_perms() as the read of the\nparent's permissions has to be serialised.\n\n [ bp: Cleanup splat. ]", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49783" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/36b038791e1e2baea892e9276588815fd14894b4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c6e8a7a1780af3da65e78a615f7d0874da6aabb0" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-g77v-vvxx-rcj7/GHSA-g77v-vvxx-rcj7.json b/advisories/unreviewed/2025/05/GHSA-g77v-vvxx-rcj7/GHSA-g77v-vvxx-rcj7.json new file mode 100644 index 00000000000..19ce67da240 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-g77v-vvxx-rcj7/GHSA-g77v-vvxx-rcj7.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g77v-vvxx-rcj7", + "modified": "2025-05-01T15:31:53Z", + "published": "2025-05-01T15:31:53Z", + "aliases": [ + "CVE-2022-49930" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/hns: Fix NULL pointer problem in free_mr_init()\n\nLock grab occurs in a concurrent scenario, resulting in stepping on a NULL\npointer. It should be init mutex_init() first before use the lock.\n\n Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000\n Call trace:\n __mutex_lock.constprop.0+0xd0/0x5c0\n __mutex_lock_slowpath+0x1c/0x2c\n mutex_lock+0x44/0x50\n free_mr_send_cmd_to_hw+0x7c/0x1c0 [hns_roce_hw_v2]\n hns_roce_v2_dereg_mr+0x30/0x40 [hns_roce_hw_v2]\n hns_roce_dereg_mr+0x4c/0x130 [hns_roce_hw_v2]\n ib_dereg_mr_user+0x54/0x124\n uverbs_free_mr+0x24/0x30\n destroy_hw_idr_uobject+0x38/0x74\n uverbs_destroy_uobject+0x48/0x1c4\n uobj_destroy+0x74/0xcc\n ib_uverbs_cmd_verbs+0x368/0xbb0\n ib_uverbs_ioctl+0xec/0x1a4\n __arm64_sys_ioctl+0xb4/0x100\n invoke_syscall+0x50/0x120\n el0_svc_common.constprop.0+0x58/0x190\n do_el0_svc+0x30/0x90\n el0_svc+0x2c/0xb4\n el0t_64_sync_handler+0x1a4/0x1b0\n el0t_64_sync+0x19c/0x1a0", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49930" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0e23e85d86b78e734dd6654f1b69fbaeb5534c81" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/12bcaf87d8b66d8cd812479c8a6349dcb245375c" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-g7p4-4259-746x/GHSA-g7p4-4259-746x.json b/advisories/unreviewed/2025/05/GHSA-g7p4-4259-746x/GHSA-g7p4-4259-746x.json new file mode 100644 index 00000000000..819f5aa1625 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-g7p4-4259-746x/GHSA-g7p4-4259-746x.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g7p4-4259-746x", + "modified": "2025-05-01T15:31:42Z", + "published": "2025-05-01T15:31:42Z", + "aliases": [ + "CVE-2025-37747" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nperf: Fix hang while freeing sigtrap event\n\nPerf can hang while freeing a sigtrap event if a related deferred\nsignal hadn't managed to be sent before the file got closed:\n\nperf_event_overflow()\n task_work_add(perf_pending_task)\n\nfput()\n task_work_add(____fput())\n\ntask_work_run()\n ____fput()\n perf_release()\n perf_event_release_kernel()\n _free_event()\n perf_pending_task_sync()\n task_work_cancel() -> FAILED\n rcuwait_wait_event()\n\nOnce task_work_run() is running, the list of pending callbacks is\nremoved from the task_struct and from this point on task_work_cancel()\ncan't remove any pending and not yet started work items, hence the\ntask_work_cancel() failure and the hang on rcuwait_wait_event().\n\nTask work could be changed to remove one work at a time, so a work\nrunning on the current task can always cancel a pending one, however\nthe wait / wake design is still subject to inverted dependencies when\nremote targets are involved, as pictured by Oleg:\n\nT1 T2\n\nfd = perf_event_open(pid => T2->pid); fd = perf_event_open(pid => T1->pid);\nclose(fd) close(fd)\n \n perf_event_overflow() perf_event_overflow()\n task_work_add(perf_pending_task) task_work_add(perf_pending_task)\n \n fput() fput()\n task_work_add(____fput()) task_work_add(____fput())\n\n task_work_run() task_work_run()\n ____fput() ____fput()\n perf_release() perf_release()\n perf_event_release_kernel() perf_event_release_kernel()\n _free_event() _free_event()\n perf_pending_task_sync() perf_pending_task_sync()\n rcuwait_wait_event() rcuwait_wait_event()\n\nTherefore the only option left is to acquire the event reference count\nupon queueing the perf task work and release it from the task work, just\nlike it was done before 3a5465418f5f (\"perf: Fix event leak upon exec and file release\")\nbut without the leaks it fixed.\n\nSome adjustments are necessary to make it work:\n\n* A child event might dereference its parent upon freeing. Care must be\n taken to release the parent last.\n\n* Some places assuming the event doesn't have any reference held and\n therefore can be freed right away must instead put the reference and\n let the reference counting to its job.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37747" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1267bd38f161c1a27d9b722de017027167a225a0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/56799bc035658738f362acec3e7647bb84e68933" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/665b87b8f8b3aeb49083ef3b65c4953e7753fc12" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fa1827fa968c0674e9b6fca223fa9fb4da4493eb" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T13:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-g9q4-8883-7234/GHSA-g9q4-8883-7234.json b/advisories/unreviewed/2025/05/GHSA-g9q4-8883-7234/GHSA-g9q4-8883-7234.json new file mode 100644 index 00000000000..9f814b2d403 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-g9q4-8883-7234/GHSA-g9q4-8883-7234.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g9q4-8883-7234", + "modified": "2025-05-01T15:31:44Z", + "published": "2025-05-01T15:31:44Z", + "aliases": [ + "CVE-2025-37774" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nslab: ensure slab->obj_exts is clear in a newly allocated slab page\n\nktest recently reported crashes while running several buffered io tests\nwith __alloc_tagging_slab_alloc_hook() at the top of the crash call stack.\nThe signature indicates an invalid address dereference with low bits of\nslab->obj_exts being set. The bits were outside of the range used by\npage_memcg_data_flags and objext_flags and hence were not masked out\nby slab_obj_exts() when obtaining the pointer stored in slab->obj_exts.\nThe typical crash log looks like this:\n\n00510 Unable to handle kernel NULL pointer dereference at virtual address 0000000000000010\n00510 Mem abort info:\n00510 ESR = 0x0000000096000045\n00510 EC = 0x25: DABT (current EL), IL = 32 bits\n00510 SET = 0, FnV = 0\n00510 EA = 0, S1PTW = 0\n00510 FSC = 0x05: level 1 translation fault\n00510 Data abort info:\n00510 ISV = 0, ISS = 0x00000045, ISS2 = 0x00000000\n00510 CM = 0, WnR = 1, TnD = 0, TagAccess = 0\n00510 GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0\n00510 user pgtable: 4k pages, 39-bit VAs, pgdp=0000000104175000\n00510 [0000000000000010] pgd=0000000000000000, p4d=0000000000000000, pud=0000000000000000\n00510 Internal error: Oops: 0000000096000045 [#1] SMP\n00510 Modules linked in:\n00510 CPU: 10 UID: 0 PID: 7692 Comm: cat Not tainted 6.15.0-rc1-ktest-g189e17946605 #19327 NONE\n00510 Hardware name: linux,dummy-virt (DT)\n00510 pstate: 20001005 (nzCv daif -PAN -UAO -TCO -DIT +SSBS BTYPE=--)\n00510 pc : __alloc_tagging_slab_alloc_hook+0xe0/0x190\n00510 lr : __kmalloc_noprof+0x150/0x310\n00510 sp : ffffff80c87df6c0\n00510 x29: ffffff80c87df6c0 x28: 000000000013d1ff x27: 000000000013d200\n00510 x26: ffffff80c87df9e0 x25: 0000000000000000 x24: 0000000000000001\n00510 x23: ffffffc08041953c x22: 000000000000004c x21: ffffff80c0002180\n00510 x20: fffffffec3120840 x19: ffffff80c4821000 x18: 0000000000000000\n00510 x17: fffffffec3d02f00 x16: fffffffec3d02e00 x15: fffffffec3d00700\n00510 x14: fffffffec3d00600 x13: 0000000000000200 x12: 0000000000000006\n00510 x11: ffffffc080bb86c0 x10: 0000000000000000 x9 : ffffffc080201e58\n00510 x8 : ffffff80c4821060 x7 : 0000000000000000 x6 : 0000000055555556\n00510 x5 : 0000000000000001 x4 : 0000000000000010 x3 : 0000000000000060\n00510 x2 : 0000000000000000 x1 : ffffffc080f50cf8 x0 : ffffff80d801d000\n00510 Call trace:\n00510 __alloc_tagging_slab_alloc_hook+0xe0/0x190 (P)\n00510 __kmalloc_noprof+0x150/0x310\n00510 __bch2_folio_create+0x5c/0xf8\n00510 bch2_folio_create+0x2c/0x40\n00510 bch2_readahead+0xc0/0x460\n00510 read_pages+0x7c/0x230\n00510 page_cache_ra_order+0x244/0x3a8\n00510 page_cache_async_ra+0x124/0x170\n00510 filemap_readahead.isra.0+0x58/0xa0\n00510 filemap_get_pages+0x454/0x7b0\n00510 filemap_read+0xdc/0x418\n00510 bch2_read_iter+0x100/0x1b0\n00510 vfs_read+0x214/0x300\n00510 ksys_read+0x6c/0x108\n00510 __arm64_sys_read+0x20/0x30\n00510 invoke_syscall.constprop.0+0x54/0xe8\n00510 do_el0_svc+0x44/0xc8\n00510 el0_svc+0x18/0x58\n00510 el0t_64_sync_handler+0x104/0x130\n00510 el0t_64_sync+0x154/0x158\n00510 Code: d5384100 f9401c01 b9401aa3 b40002e1 (f8227881)\n00510 ---[ end trace 0000000000000000 ]---\n00510 Kernel panic - not syncing: Oops: Fatal exception\n00510 SMP: stopping secondary CPUs\n00510 Kernel Offset: disabled\n00510 CPU features: 0x0000,000000e0,00000410,8240500b\n00510 Memory Limit: none\n\nInvestigation indicates that these bits are already set when we allocate\nslab page and are not zeroed out after allocation. We are not yet sure\nwhy these crashes start happening only recently but regardless of the\nreason, not initializing a field that gets used later is wrong. Fix it\nby initializing slab->obj_exts during slab page allocation.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37774" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/28bef6622a1a874fe63aceeb0c684fab75afb3ae" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8baa747193591410a853bac9c3710142dfa4937b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d2f5819b6ed357c0c350c0616b6b9f38be59adf6" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T14:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-gh2h-q6h9-qfrw/GHSA-gh2h-q6h9-qfrw.json b/advisories/unreviewed/2025/05/GHSA-gh2h-q6h9-qfrw/GHSA-gh2h-q6h9-qfrw.json new file mode 100644 index 00000000000..1e651123935 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-gh2h-q6h9-qfrw/GHSA-gh2h-q6h9-qfrw.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gh2h-q6h9-qfrw", + "modified": "2025-05-01T15:31:40Z", + "published": "2025-05-01T15:31:40Z", + "aliases": [ + "CVE-2025-23143" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: Fix null-ptr-deref by sock_lock_init_class_and_name() and rmmod.\n\nWhen I ran the repro [0] and waited a few seconds, I observed two\nLOCKDEP splats: a warning immediately followed by a null-ptr-deref. [1]\n\nReproduction Steps:\n\n 1) Mount CIFS\n 2) Add an iptables rule to drop incoming FIN packets for CIFS\n 3) Unmount CIFS\n 4) Unload the CIFS module\n 5) Remove the iptables rule\n\nAt step 3), the CIFS module calls sock_release() for the underlying\nTCP socket, and it returns quickly. However, the socket remains in\nFIN_WAIT_1 because incoming FIN packets are dropped.\n\nAt this point, the module's refcnt is 0 while the socket is still\nalive, so the following rmmod command succeeds.\n\n # ss -tan\n State Recv-Q Send-Q Local Address:Port Peer Address:Port\n FIN-WAIT-1 0 477 10.0.2.15:51062 10.0.0.137:445\n\n # lsmod | grep cifs\n cifs 1159168 0\n\nThis highlights a discrepancy between the lifetime of the CIFS module\nand the underlying TCP socket. Even after CIFS calls sock_release()\nand it returns, the TCP socket does not die immediately in order to\nclose the connection gracefully.\n\nWhile this is generally fine, it causes an issue with LOCKDEP because\nCIFS assigns a different lock class to the TCP socket's sk->sk_lock\nusing sock_lock_init_class_and_name().\n\nOnce an incoming packet is processed for the socket or a timer fires,\nsk->sk_lock is acquired.\n\nThen, LOCKDEP checks the lock context in check_wait_context(), where\nhlock_class() is called to retrieve the lock class. However, since\nthe module has already been unloaded, hlock_class() logs a warning\nand returns NULL, triggering the null-ptr-deref.\n\nIf LOCKDEP is enabled, we must ensure that a module calling\nsock_lock_init_class_and_name() (CIFS, NFS, etc) cannot be unloaded\nwhile such a socket is still alive to prevent this issue.\n\nLet's hold the module reference in sock_lock_init_class_and_name()\nand release it when the socket is freed in sk_prot_free().\n\nNote that sock_lock_init() clears sk->sk_owner for svc_create_socket()\nthat calls sock_lock_init_class_and_name() for a listening socket,\nwhich clones a socket by sk_clone_lock() without GFP_ZERO.\n\n[0]:\nCIFS_SERVER=\"10.0.0.137\"\nCIFS_PATH=\"//${CIFS_SERVER}/Users/Administrator/Desktop/CIFS_TEST\"\nDEV=\"enp0s3\"\nCRED=\"/root/WindowsCredential.txt\"\n\nMNT=$(mktemp -d /tmp/XXXXXX)\nmount -t cifs ${CIFS_PATH} ${MNT} -o vers=3.0,credentials=${CRED},cache=none,echo_interval=1\n\niptables -A INPUT -s ${CIFS_SERVER} -j DROP\n\nfor i in $(seq 10);\ndo\n umount ${MNT}\n rmmod cifs\n sleep 1\ndone\n\nrm -r ${MNT}\n\niptables -D INPUT -s ${CIFS_SERVER} -j DROP\n\n[1]:\nDEBUG_LOCKS_WARN_ON(1)\nWARNING: CPU: 10 PID: 0 at kernel/locking/lockdep.c:234 hlock_class (kernel/locking/lockdep.c:234 kernel/locking/lockdep.c:223)\nModules linked in: cifs_arc4 nls_ucs2_utils cifs_md4 [last unloaded: cifs]\nCPU: 10 UID: 0 PID: 0 Comm: swapper/10 Not tainted 6.14.0 #36\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.0-0-gd239552ce722-prebuilt.qemu.org 04/01/2014\nRIP: 0010:hlock_class (kernel/locking/lockdep.c:234 kernel/locking/lockdep.c:223)\n...\nCall Trace:\n \n __lock_acquire (kernel/locking/lockdep.c:4853 kernel/locking/lockdep.c:5178)\n lock_acquire (kernel/locking/lockdep.c:469 kernel/locking/lockdep.c:5853 kernel/locking/lockdep.c:5816)\n _raw_spin_lock_nested (kernel/locking/spinlock.c:379)\n tcp_v4_rcv (./include/linux/skbuff.h:1678 ./include/net/tcp.h:2547 net/ipv4/tcp_ipv4.c:2350)\n...\n\nBUG: kernel NULL pointer dereference, address: 00000000000000c4\n PF: supervisor read access in kernel mode\n PF: error_code(0x0000) - not-present page\nPGD 0\nOops: Oops: 0000 [#1] PREEMPT SMP NOPTI\nCPU: 10 UID: 0 PID: 0 Comm: swapper/10 Tainted: G W 6.14.0 #36\nTainted: [W]=WARN\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.0-0-gd239552ce722-prebuilt.qemu.org 04/01/2014\nRIP: 0010:__lock_acquire (kernel/\n---truncated---", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23143" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0bb2f7a1ad1f11d861f58e5ee5051c8974ff9569" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2155802d3313d7b8365935c6b8d6edc0ddd7eb94" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5f7f6abd92b6c8dc8f19625ef93c3a18549ede04" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c11247a21aab4b50a23c8b696727d7483de2f1e1" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T13:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-gh6c-2563-rvgg/GHSA-gh6c-2563-rvgg.json b/advisories/unreviewed/2025/05/GHSA-gh6c-2563-rvgg/GHSA-gh6c-2563-rvgg.json new file mode 100644 index 00000000000..d0294863c9a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-gh6c-2563-rvgg/GHSA-gh6c-2563-rvgg.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gh6c-2563-rvgg", + "modified": "2025-05-01T15:31:48Z", + "published": "2025-05-01T15:31:48Z", + "aliases": [ + "CVE-2022-49824" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nata: libata-transport: fix error handling in ata_tlink_add()\n\nIn ata_tlink_add(), the return value of transport_add_device() is\nnot checked. As a result, it causes null-ptr-deref while removing\nthe module, because transport_remove_device() is called to remove\nthe device that was not added.\n\nUnable to handle kernel NULL pointer dereference at virtual address 00000000000000d0\nCPU: 33 PID: 13850 Comm: rmmod Kdump: loaded Tainted: G W 6.1.0-rc3+ #12\npstate: 60400009 (nZCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)\npc : device_del+0x48/0x39c\nlr : device_del+0x44/0x39c\nCall trace:\n device_del+0x48/0x39c\n attribute_container_class_device_del+0x28/0x40\n transport_remove_classdev+0x60/0x7c\n attribute_container_device_trigger+0x118/0x120\n transport_remove_device+0x20/0x30\n ata_tlink_delete+0x88/0xb0 [libata]\n ata_tport_delete+0x2c/0x60 [libata]\n ata_port_detach+0x148/0x1b0 [libata]\n ata_pci_remove_one+0x50/0x80 [libata]\n ahci_remove_one+0x4c/0x8c [ahci]\n\nFix this by checking and handling return value of transport_add_device()\nin ata_tlink_add().", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49824" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/67b219314628b90b3a314528e177335b0cd5c70b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7377a14598f6b04446c54bc4a50cd249470d6c6f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cf0816f6322c5c37ee52655f928e91ecf32da103" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d5234480ca822bdcf03fe4d6a590ddcb854558f7" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-gh7x-chcc-crpq/GHSA-gh7x-chcc-crpq.json b/advisories/unreviewed/2025/05/GHSA-gh7x-chcc-crpq/GHSA-gh7x-chcc-crpq.json new file mode 100644 index 00000000000..d4818d293bf --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-gh7x-chcc-crpq/GHSA-gh7x-chcc-crpq.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gh7x-chcc-crpq", + "modified": "2025-05-01T15:31:45Z", + "published": "2025-05-01T15:31:45Z", + "aliases": [ + "CVE-2025-37790" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: mctp: Set SOCK_RCU_FREE\n\nBind lookup runs under RCU, so ensure that a socket doesn't go away in\nthe middle of a lookup.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37790" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3f899bd6dd56ddc46509b526e23a8f0a97712a6d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/52024cd6ec71a6ca934d0cc12452bd8d49850679" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a8a3b61ce140e2b0a72a779e8d70f60c0cf1e47a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b9764ebebb007249fb733a131b6110ff333b6616" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e3b5edbdb45924a7d4206d13868a2aac71f1e53d" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T14:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-gjh2-vjq2-jqwc/GHSA-gjh2-vjq2-jqwc.json b/advisories/unreviewed/2025/05/GHSA-gjh2-vjq2-jqwc/GHSA-gjh2-vjq2-jqwc.json new file mode 100644 index 00000000000..b2452f4ada0 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-gjh2-vjq2-jqwc/GHSA-gjh2-vjq2-jqwc.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gjh2-vjq2-jqwc", + "modified": "2025-05-01T15:31:53Z", + "published": "2025-05-01T15:31:53Z", + "aliases": [ + "CVE-2022-49923" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: nxp-nci: Fix potential memory leak in nxp_nci_send()\n\nnxp_nci_send() will call nxp_nci_i2c_write(), and only free skb when\nnxp_nci_i2c_write() failed. However, even if the nxp_nci_i2c_write()\nrun succeeds, the skb will not be freed in nxp_nci_i2c_write(). As the\nresult, the skb will memleak. nxp_nci_send() should also free the skb\nwhen nxp_nci_i2c_write() succeeds.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49923" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3cba1f061bfe23fece2841129ca2862cdec29d5c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3ecf0f4227029b2c42e036b10ff6e5d09e20821e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7bf1ed6aff0f70434bd0cdd45495e83f1dffb551" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9ae2c9a91ff068f4c3e392f47e8e26a1c9f85ebb" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-gp22-5fgh-q68v/GHSA-gp22-5fgh-q68v.json b/advisories/unreviewed/2025/05/GHSA-gp22-5fgh-q68v/GHSA-gp22-5fgh-q68v.json new file mode 100644 index 00000000000..a546716c3be --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-gp22-5fgh-q68v/GHSA-gp22-5fgh-q68v.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gp22-5fgh-q68v", + "modified": "2025-05-01T15:31:53Z", + "published": "2025-05-01T15:31:53Z", + "aliases": [ + "CVE-2022-49924" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: fdp: Fix potential memory leak in fdp_nci_send()\n\nfdp_nci_send() will call fdp_nci_i2c_write that will not free skb in\nthe function. As a result, when fdp_nci_i2c_write() finished, the skb\nwill memleak. fdp_nci_send() should free skb after fdp_nci_i2c_write()\nfinished.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49924" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1a7a898f8f7b56c0eaa2baf67a0c96235a30bc29" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/44bc1868a4f542502ea2221fe5ad88ca66d1c6b6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8e4aae6b8ca76afb1fb64dcb24be44ba814e7f8a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e8c11ee2d07f7c4dfa2ac0ea8efc4f627e58ea57" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-gpc4-vc7c-37hj/GHSA-gpc4-vc7c-37hj.json b/advisories/unreviewed/2025/05/GHSA-gpc4-vc7c-37hj/GHSA-gpc4-vc7c-37hj.json new file mode 100644 index 00000000000..5ad4799037e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-gpc4-vc7c-37hj/GHSA-gpc4-vc7c-37hj.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gpc4-vc7c-37hj", + "modified": "2025-05-01T15:31:46Z", + "published": "2025-05-01T15:31:46Z", + "aliases": [ + "CVE-2022-49776" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmacvlan: enforce a consistent minimal mtu\n\nmacvlan should enforce a minimal mtu of 68, even at link creation.\n\nThis patch avoids the current behavior (which could lead to crashes\nin ipv6 stack if the link is brought up)\n\n$ ip link add macvlan1 link eno1 mtu 8 type macvlan # This should fail !\n$ ip link sh dev macvlan1\n5: macvlan1@eno1: mtu 8 qdisc noop\n state DOWN mode DEFAULT group default qlen 1000\n link/ether 02:47:6c:24:74:82 brd ff:ff:ff:ff:ff:ff\n$ ip link set macvlan1 mtu 67\nError: mtu less than device minimum.\n$ ip link set macvlan1 mtu 68\n$ ip link set macvlan1 mtu 8\nError: mtu less than device minimum.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49776" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2b055c719d8f94c15ec9b7659978133030c6a353" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/650137a7c0b2892df2e5b0bc112d7b09a78c93c8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a62aa84fe19eb24d083d600a074c009a0a66d4f3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b64085b00044bdf3cd1c9825e9ef5b2e0feae91a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d2fee7d121d189c6dc905b727d60e7043a6655bb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e41cbf98df22d08402e65174d147cbb187fe1a33" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e929ec98c0c3b10d9c07f3776df0c1a02d7a763e" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-gr6f-7hfg-779m/GHSA-gr6f-7hfg-779m.json b/advisories/unreviewed/2025/05/GHSA-gr6f-7hfg-779m/GHSA-gr6f-7hfg-779m.json new file mode 100644 index 00000000000..ca895ac45c4 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-gr6f-7hfg-779m/GHSA-gr6f-7hfg-779m.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gr6f-7hfg-779m", + "modified": "2025-05-01T15:31:47Z", + "published": "2025-05-01T15:31:47Z", + "aliases": [ + "CVE-2022-49806" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: microchip: sparx5: Fix potential null-ptr-deref in sparx_stats_init() and sparx5_start()\n\nsparx_stats_init() calls create_singlethread_workqueue() and not\nchecked the ret value, which may return NULL. And a null-ptr-deref may\nhappen:\n\nsparx_stats_init()\n create_singlethread_workqueue() # failed, sparx5->stats_queue is NULL\n queue_delayed_work()\n queue_delayed_work_on()\n __queue_delayed_work() # warning here, but continue\n __queue_work() # access wq->flags, null-ptr-deref\n\nCheck the ret value and return -ENOMEM if it is NULL. So as\nsparx5_start().", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49806" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/456327e565dc49d18b2f595f39f47df8a36f1057" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/639f5d006e36bb303f525d9479448c412b720c39" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/80e590aeb132887102c3fa79d99b338f099dc952" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-h3mh-rq8w-j65m/GHSA-h3mh-rq8w-j65m.json b/advisories/unreviewed/2025/05/GHSA-h3mh-rq8w-j65m/GHSA-h3mh-rq8w-j65m.json new file mode 100644 index 00000000000..d24344d1329 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-h3mh-rq8w-j65m/GHSA-h3mh-rq8w-j65m.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h3mh-rq8w-j65m", + "modified": "2025-05-01T15:31:52Z", + "published": "2025-05-01T15:31:52Z", + "aliases": [ + "CVE-2022-49900" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ni2c: piix4: Fix adapter not be removed in piix4_remove()\n\nIn piix4_probe(), the piix4 adapter will be registered in:\n\n piix4_probe()\n piix4_add_adapters_sb800() / piix4_add_adapter()\n i2c_add_adapter()\n\nBased on the probed device type, piix4_add_adapters_sb800() or single\npiix4_add_adapter() will be called.\nFor the former case, piix4_adapter_count is set as the number of adapters,\nwhile for antoher case it is not set and kept default *zero*.\n\nWhen piix4 is removed, piix4_remove() removes the adapters added in\npiix4_probe(), basing on the piix4_adapter_count value.\nBecause the count is zero for the single adapter case, the adapter won't\nbe removed and makes the sources allocated for adapter leaked, such as\nthe i2c client and device.\n\nThese sources can still be accessed by i2c or bus and cause problems.\nAn easily reproduced case is that if a new adapter is registered, i2c\nwill get the leaked adapter and try to call smbus_algorithm, which was\nalready freed:\n\nTriggered by: rmmod i2c_piix4 && modprobe max31730\n\n BUG: unable to handle page fault for address: ffffffffc053d860\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\n Oops: 0000 [#1] PREEMPT SMP KASAN\n CPU: 0 PID: 3752 Comm: modprobe Tainted: G\n Hardware name: QEMU Standard PC (i440FX + PIIX, 1996)\n RIP: 0010:i2c_default_probe (drivers/i2c/i2c-core-base.c:2259) i2c_core\n RSP: 0018:ffff888107477710 EFLAGS: 00000246\n ...\n \n i2c_detect (drivers/i2c/i2c-core-base.c:2302) i2c_core\n __process_new_driver (drivers/i2c/i2c-core-base.c:1336) i2c_core\n bus_for_each_dev (drivers/base/bus.c:301)\n i2c_for_each_dev (drivers/i2c/i2c-core-base.c:1823) i2c_core\n i2c_register_driver (drivers/i2c/i2c-core-base.c:1861) i2c_core\n do_one_initcall (init/main.c:1296)\n do_init_module (kernel/module/main.c:2455)\n ...\n \n ---[ end trace 0000000000000000 ]---\n\nFix this problem by correctly set piix4_adapter_count as 1 for the\nsingle adapter so it can be normally removed.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49900" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/569bea74c94d37785682b11bab76f557520477cd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bfd5e62f9a7ee214661cb6f143a3b40ccc63317f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d78ccdce662e88f41e87e90cf2bee63c1715d2a5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fe51636fffc8108c7c4da6aa393010e786530ad9" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-h4jf-hv6r-g8qq/GHSA-h4jf-hv6r-g8qq.json b/advisories/unreviewed/2025/05/GHSA-h4jf-hv6r-g8qq/GHSA-h4jf-hv6r-g8qq.json new file mode 100644 index 00000000000..baf040ed69f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-h4jf-hv6r-g8qq/GHSA-h4jf-hv6r-g8qq.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h4jf-hv6r-g8qq", + "modified": "2025-05-01T15:31:46Z", + "published": "2025-05-01T15:31:45Z", + "aliases": [ + "CVE-2022-49763" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nntfs: fix use-after-free in ntfs_attr_find()\n\nPatch series \"ntfs: fix bugs about Attribute\", v2.\n\nThis patchset fixes three bugs relative to Attribute in record:\n\nPatch 1 adds a sanity check to ensure that, attrs_offset field in first\nmft record loading from disk is within bounds.\n\nPatch 2 moves the ATTR_RECORD's bounds checking earlier, to avoid\ndereferencing ATTR_RECORD before checking this ATTR_RECORD is within\nbounds.\n\nPatch 3 adds an overflow checking to avoid possible forever loop in\nntfs_attr_find().\n\nWithout patch 1 and patch 2, the kernel triggersa KASAN use-after-free\ndetection as reported by Syzkaller.\n\nAlthough one of patch 1 or patch 2 can fix this, we still need both of\nthem. Because patch 1 fixes the root cause, and patch 2 not only fixes\nthe direct cause, but also fixes the potential out-of-bounds bug.\n\n\nThis patch (of 3):\n\nSyzkaller reported use-after-free read as follows:\n==================================================================\nBUG: KASAN: use-after-free in ntfs_attr_find+0xc02/0xce0 fs/ntfs/attrib.c:597\nRead of size 2 at addr ffff88807e352009 by task syz-executor153/3607\n\n[...]\nCall Trace:\n \n __dump_stack lib/dump_stack.c:88 [inline]\n dump_stack_lvl+0xcd/0x134 lib/dump_stack.c:106\n print_address_description mm/kasan/report.c:317 [inline]\n print_report.cold+0x2ba/0x719 mm/kasan/report.c:433\n kasan_report+0xb1/0x1e0 mm/kasan/report.c:495\n ntfs_attr_find+0xc02/0xce0 fs/ntfs/attrib.c:597\n ntfs_attr_lookup+0x1056/0x2070 fs/ntfs/attrib.c:1193\n ntfs_read_inode_mount+0x89a/0x2580 fs/ntfs/inode.c:1845\n ntfs_fill_super+0x1799/0x9320 fs/ntfs/super.c:2854\n mount_bdev+0x34d/0x410 fs/super.c:1400\n legacy_get_tree+0x105/0x220 fs/fs_context.c:610\n vfs_get_tree+0x89/0x2f0 fs/super.c:1530\n do_new_mount fs/namespace.c:3040 [inline]\n path_mount+0x1326/0x1e20 fs/namespace.c:3370\n do_mount fs/namespace.c:3383 [inline]\n __do_sys_mount fs/namespace.c:3591 [inline]\n __se_sys_mount fs/namespace.c:3568 [inline]\n __x64_sys_mount+0x27f/0x300 fs/namespace.c:3568\n do_syscall_x64 arch/x86/entry/common.c:50 [inline]\n do_syscall_64+0x35/0xb0 arch/x86/entry/common.c:80\n entry_SYSCALL_64_after_hwframe+0x63/0xcd\n [...]\n \n\nThe buggy address belongs to the physical page:\npage:ffffea0001f8d400 refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x7e350\nhead:ffffea0001f8d400 order:3 compound_mapcount:0 compound_pincount:0\nflags: 0xfff00000010200(slab|head|node=0|zone=1|lastcpupid=0x7ff)\nraw: 00fff00000010200 0000000000000000 dead000000000122 ffff888011842140\nraw: 0000000000000000 0000000000040004 00000001ffffffff 0000000000000000\npage dumped because: kasan: bad access detected\nMemory state around the buggy address:\n ffff88807e351f00: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc\n ffff88807e351f80: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc\n>ffff88807e352000: fa fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb\n ^\n ffff88807e352080: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb\n ffff88807e352100: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb\n==================================================================\n\nKernel will loads $MFT/$DATA's first mft record in\nntfs_read_inode_mount().\n\nYet the problem is that after loading, kernel doesn't check whether\nattrs_offset field is a valid value.\n\nTo be more specific, if attrs_offset field is larger than bytes_allocated\nfield, then it may trigger the out-of-bounds read bug(reported as\nuse-after-free bug) in ntfs_attr_find(), when kernel tries to access the\ncorresponding mft record's attribute.\n\nThis patch solves it by adding the sanity check between attrs_offset field\nand bytes_allocated field, after loading the first mft record.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49763" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/266bd5306286316758e6246ea0345133427b0f62" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4863f815463034f588a035cfd99cdca97a4f1069" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5330c423b86263ac7883fef0260b9e2229cb531e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/79f3ac7dcd12c05b7539239a4c6fa229a50d786c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b825bfbbaafbe8da2037e3a778ad660c59f9e054" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d0006d739738a658a9c29b438444259d9f71dfa0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d85a1bec8e8d552ab13163ca1874dcd82f3d1550" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fb2004bafd1932e08d21ca604ee5844f2b7f212d" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-h557-5h69-jf25/GHSA-h557-5h69-jf25.json b/advisories/unreviewed/2025/05/GHSA-h557-5h69-jf25/GHSA-h557-5h69-jf25.json new file mode 100644 index 00000000000..fb432005c1c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-h557-5h69-jf25/GHSA-h557-5h69-jf25.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h557-5h69-jf25", + "modified": "2025-05-01T15:31:46Z", + "published": "2025-05-01T15:31:46Z", + "aliases": [ + "CVE-2022-49782" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nperf: Improve missing SIGTRAP checking\n\nTo catch missing SIGTRAP we employ a WARN in __perf_event_overflow(),\nwhich fires if pending_sigtrap was already set: returning to user space\nwithout consuming pending_sigtrap, and then having the event fire again\nwould re-enter the kernel and trigger the WARN.\n\nThis, however, seemed to miss the case where some events not associated\nwith progress in the user space task can fire and the interrupt handler\nruns before the IRQ work meant to consume pending_sigtrap (and generate\nthe SIGTRAP).\n\nsyzbot gifted us this stack trace:\n\n | WARNING: CPU: 0 PID: 3607 at kernel/events/core.c:9313 __perf_event_overflow\n | Modules linked in:\n | CPU: 0 PID: 3607 Comm: syz-executor100 Not tainted 6.1.0-rc2-syzkaller-00073-g88619e77b33d #0\n | Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/11/2022\n | RIP: 0010:__perf_event_overflow+0x498/0x540 kernel/events/core.c:9313\n | <...>\n | Call Trace:\n | \n | perf_swevent_hrtimer+0x34f/0x3c0 kernel/events/core.c:10729\n | __run_hrtimer kernel/time/hrtimer.c:1685 [inline]\n | __hrtimer_run_queues+0x1c6/0xfb0 kernel/time/hrtimer.c:1749\n | hrtimer_interrupt+0x31c/0x790 kernel/time/hrtimer.c:1811\n | local_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1096 [inline]\n | __sysvec_apic_timer_interrupt+0x17c/0x640 arch/x86/kernel/apic/apic.c:1113\n | sysvec_apic_timer_interrupt+0x40/0xc0 arch/x86/kernel/apic/apic.c:1107\n | asm_sysvec_apic_timer_interrupt+0x16/0x20 arch/x86/include/asm/idtentry.h:649\n | <...>\n | \n\nIn this case, syzbot produced a program with event type\nPERF_TYPE_SOFTWARE and config PERF_COUNT_SW_CPU_CLOCK. The hrtimer\nmanages to fire again before the IRQ work got a chance to run, all while\nnever having returned to user space.\n\nImprove the WARN to check for real progress in user space: approximate\nthis by storing a 32-bit hash of the current IP into pending_sigtrap,\nand if an event fires while pending_sigtrap still matches the previous\nIP, we assume no progress (false negatives are possible given we could\nreturn to user space and trigger again on the same IP).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49782" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/35c60b4e8ca76712dd03bafe2598e31578248916" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b09221f1b4944d2866d06ac35e59d7a6f8916c9f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bb88f9695460bec25aa30ba9072595025cf6c8af" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-h8g4-6mrj-mfm8/GHSA-h8g4-6mrj-mfm8.json b/advisories/unreviewed/2025/05/GHSA-h8g4-6mrj-mfm8/GHSA-h8g4-6mrj-mfm8.json new file mode 100644 index 00000000000..45b98a06834 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-h8g4-6mrj-mfm8/GHSA-h8g4-6mrj-mfm8.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h8g4-6mrj-mfm8", + "modified": "2025-05-01T15:31:51Z", + "published": "2025-05-01T15:31:50Z", + "aliases": [ + "CVE-2022-49877" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf, sockmap: Fix the sk->sk_forward_alloc warning of sk_stream_kill_queues\n\nWhen running `test_sockmap` selftests, the following warning appears:\n\n WARNING: CPU: 2 PID: 197 at net/core/stream.c:205 sk_stream_kill_queues+0xd3/0xf0\n Call Trace:\n \n inet_csk_destroy_sock+0x55/0x110\n tcp_rcv_state_process+0xd28/0x1380\n ? tcp_v4_do_rcv+0x77/0x2c0\n tcp_v4_do_rcv+0x77/0x2c0\n __release_sock+0x106/0x130\n __tcp_close+0x1a7/0x4e0\n tcp_close+0x20/0x70\n inet_release+0x3c/0x80\n __sock_release+0x3a/0xb0\n sock_close+0x14/0x20\n __fput+0xa3/0x260\n task_work_run+0x59/0xb0\n exit_to_user_mode_prepare+0x1b3/0x1c0\n syscall_exit_to_user_mode+0x19/0x50\n do_syscall_64+0x48/0x90\n entry_SYSCALL_64_after_hwframe+0x44/0xae\n\nThe root case is in commit 84472b436e76 (\"bpf, sockmap: Fix more uncharged\nwhile msg has more_data\"), where I used msg->sg.size to replace the tosend,\ncausing breakage:\n\n if (msg->apply_bytes && msg->apply_bytes < tosend)\n tosend = psock->apply_bytes;", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49877" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/14e8bc3bf7bd6af64d7538a0684c8238d96cdfd7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8ec95b94716a1e4d126edc3fb2bc426a717e2dba" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/95adbd2ac8de82e43fd6b347e7e1b47f74dc1abb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cc21dc48a78cc9e5af9a4d039cd456446a6e73ff" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d975bec1eaeb52341acc9273db79ddb078220399" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-h8wv-w7mj-x6rc/GHSA-h8wv-w7mj-x6rc.json b/advisories/unreviewed/2025/05/GHSA-h8wv-w7mj-x6rc/GHSA-h8wv-w7mj-x6rc.json new file mode 100644 index 00000000000..43cdd223e82 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-h8wv-w7mj-x6rc/GHSA-h8wv-w7mj-x6rc.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h8wv-w7mj-x6rc", + "modified": "2025-05-01T15:31:44Z", + "published": "2025-05-01T15:31:44Z", + "aliases": [ + "CVE-2025-37767" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/pm: Prevent division by zero\n\nThe user can set any speed value.\nIf speed is greater than UINT_MAX/8, division by zero is possible.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37767" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/327107bd7f052f4ee2d0c966c7ae879822f1814f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8f7b5987e21e003cafac28f0e4d323e6496f83ba" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c3ff73e3bddf1a6c30d7effe4018d12ba0cadd2e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f23e9116ebb71b63fe9cec0dcac792aa9af30b0c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fb803d4bb9ea0a61c21c4987505e4d4ae18f9fdc" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T14:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hfj5-q228-92r2/GHSA-hfj5-q228-92r2.json b/advisories/unreviewed/2025/05/GHSA-hfj5-q228-92r2/GHSA-hfj5-q228-92r2.json new file mode 100644 index 00000000000..9b4b50c1255 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-hfj5-q228-92r2/GHSA-hfj5-q228-92r2.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hfj5-q228-92r2", + "modified": "2025-05-01T15:31:45Z", + "published": "2025-05-01T15:31:45Z", + "aliases": [ + "CVE-2025-37787" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: dsa: mv88e6xxx: avoid unregistering devlink regions which were never registered\n\nRussell King reports that a system with mv88e6xxx dereferences a NULL\npointer when unbinding this driver:\nhttps://lore.kernel.org/netdev/Z_lRkMlTJ1KQ0kVX@shell.armlinux.org.uk/\n\nThe crash seems to be in devlink_region_destroy(), which is not NULL\ntolerant but is given a NULL devlink global region pointer.\n\nAt least on some chips, some devlink regions are conditionally registered\nsince the blamed commit, see mv88e6xxx_setup_devlink_regions_global():\n\n\t\tif (cond && !cond(chip))\n\t\t\tcontinue;\n\nThese are MV88E6XXX_REGION_STU and MV88E6XXX_REGION_PVT. If the chip\ndoes not have an STU or PVT, it should crash like this.\n\nTo fix the issue, avoid unregistering those regions which are NULL, i.e.\nwere skipped at mv88e6xxx_setup_devlink_regions_global() time.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37787" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3665695e3572239dc233216f06b41f40cc771889" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5f5e95945bb1e08be7655da6acba648274db457d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b3c70dfe51f10df60db2646c08cebd24bcdc5247" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bbb80f004f7a90c3dcaacc982c59967457254a05" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c84f6ce918a9e6f4996597cbc62536bbf2247c96" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T14:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hpf7-wq23-7pvr/GHSA-hpf7-wq23-7pvr.json b/advisories/unreviewed/2025/05/GHSA-hpf7-wq23-7pvr/GHSA-hpf7-wq23-7pvr.json new file mode 100644 index 00000000000..e0cc220b6b0 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-hpf7-wq23-7pvr/GHSA-hpf7-wq23-7pvr.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hpf7-wq23-7pvr", + "modified": "2025-05-01T15:31:50Z", + "published": "2025-05-01T15:31:50Z", + "aliases": [ + "CVE-2022-49860" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndmaengine: ti: k3-udma-glue: fix memory leak when register device fail\n\nIf device_register() fails, it should call put_device() to give\nup reference, the name allocated in dev_set_name() can be freed\nin callback function kobject_cleanup().", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49860" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/025eab5189fc7ee223ae9b4bc49d7df196543e53" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1dd27541aa2b95bde71bddd43d73f9c16d73272c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ac2b9f34f02052709aea7b34bb2a165e1853eb41" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hpgq-64pq-cxw5/GHSA-hpgq-64pq-cxw5.json b/advisories/unreviewed/2025/05/GHSA-hpgq-64pq-cxw5/GHSA-hpgq-64pq-cxw5.json new file mode 100644 index 00000000000..5101749ada3 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-hpgq-64pq-cxw5/GHSA-hpgq-64pq-cxw5.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hpgq-64pq-cxw5", + "modified": "2025-05-01T15:31:53Z", + "published": "2025-05-01T15:31:53Z", + "aliases": [ + "CVE-2025-44836" + ], + "details": "TOTOLINK CPE CP900 V6.3c.1144_B20190715 was discovered to contain a command injection vulnerability in the setApRebootScheCfg function via the hour or minute parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44836" + }, + { + "type": "WEB", + "url": "https://github.com/n0wstr/IOTVuln/tree/main/CP900/setApRebootScheCfg" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hx26-xg26-jr99/GHSA-hx26-xg26-jr99.json b/advisories/unreviewed/2025/05/GHSA-hx26-xg26-jr99/GHSA-hx26-xg26-jr99.json new file mode 100644 index 00000000000..0522d21f25a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-hx26-xg26-jr99/GHSA-hx26-xg26-jr99.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hx26-xg26-jr99", + "modified": "2025-05-01T15:31:41Z", + "published": "2025-05-01T15:31:41Z", + "aliases": [ + "CVE-2025-23156" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: venus: hfi_parser: refactor hfi packet parsing logic\n\nwords_count denotes the number of words in total payload, while data\npoints to payload of various property within it. When words_count\nreaches last word, data can access memory beyond the total payload. This\ncan lead to OOB access. With this patch, the utility api for handling\nindividual properties now returns the size of data consumed. Accordingly\nremaining bytes are calculated before parsing the payload, thereby\neliminates the OOB access possibilities.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23156" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/05b07e52a0d08239147ba3460045855f4fb398de" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0f9a4bab7d83738963365372e4745854938eab2d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6d278c5548d840c4d85d445347b2a5c31b2ab3a0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9edaaa8e3e15aab1ca413ab50556de1975bcb329" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a736c72d476d1c7ca7be5018f2614ee61168ad01" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bb3fd8b7906a12dc2b61389abb742bf6542d97fb" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T13:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-j78r-hv87-26mj/GHSA-j78r-hv87-26mj.json b/advisories/unreviewed/2025/05/GHSA-j78r-hv87-26mj/GHSA-j78r-hv87-26mj.json new file mode 100644 index 00000000000..4472fa89106 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-j78r-hv87-26mj/GHSA-j78r-hv87-26mj.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j78r-hv87-26mj", + "modified": "2025-05-01T15:31:52Z", + "published": "2025-05-01T15:31:52Z", + "aliases": [ + "CVE-2022-49907" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: mdio: fix undefined behavior in bit shift for __mdiobus_register\n\nShifting signed 32-bit value by 31 bits is undefined, so changing\nsignificant bit to unsigned. The UBSAN warning calltrace like below:\n\nUBSAN: shift-out-of-bounds in drivers/net/phy/mdio_bus.c:586:27\nleft shift of 1 by 31 places cannot be represented in type 'int'\nCall Trace:\n \n dump_stack_lvl+0x7d/0xa5\n dump_stack+0x15/0x1b\n ubsan_epilogue+0xe/0x4e\n __ubsan_handle_shift_out_of_bounds+0x1e7/0x20c\n __mdiobus_register+0x49d/0x4e0\n fixed_mdio_bus_init+0xd8/0x12d\n do_one_initcall+0x76/0x430\n kernel_init_freeable+0x3b3/0x422\n kernel_init+0x24/0x1e0\n ret_from_fork+0x1f/0x30\n ", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49907" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/20ed01a7b9af6e6a3c33761eebbb710ea6dd49b7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/40e4eb324c59e11fcb927aa46742d28aba6ecb8a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4954b5359eb141499492fadfab891e28905509e2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/634f066d02bdb22a26da7deb0c7617ab1a65fc9d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6ce6f8f8f6316da6f92afe7490bc2f0b654d68e0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7006176a3c863e3e353ce1b8a349ef5bb1b9320e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/985a88bf0b27193522bba7856b1763f428cef19d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a3fafc974be37319679f36dc4e7cca7db1e02973" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-j8gp-j2vw-f2f6/GHSA-j8gp-j2vw-f2f6.json b/advisories/unreviewed/2025/05/GHSA-j8gp-j2vw-f2f6/GHSA-j8gp-j2vw-f2f6.json new file mode 100644 index 00000000000..e2f1644ee0e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-j8gp-j2vw-f2f6/GHSA-j8gp-j2vw-f2f6.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j8gp-j2vw-f2f6", + "modified": "2025-05-01T15:31:39Z", + "published": "2025-05-01T15:31:39Z", + "aliases": [ + "CVE-2025-23139" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_uart: Fix another race during initialization\n\nDo not set 'HCI_UART_PROTO_READY' before call 'hci_uart_register_dev()'.\nPossible race is when someone calls 'hci_tty_uart_close()' after this bit\nis set, but 'hci_uart_register_dev()' wasn't done. This leads to access\nto uninitialized fields. To fix it let's set this bit after device was\nregistered (as before patch c411c62cc133) and to fix previous problem let's\nadd one more bit in addition to 'HCI_UART_PROTO_READY' which allows to\nperform power up without original bit set (pls see commit c411c62cc133).\n\nCrash backtrace from syzbot report:\n\nRIP: 0010:skb_queue_empty_lockless include/linux/skbuff.h:1887 [inline]\nRIP: 0010:skb_queue_purge_reason+0x6d/0x140 net/core/skbuff.c:3936\n\nCall Trace:\n \n skb_queue_purge include/linux/skbuff.h:3364 [inline]\n mrvl_close+0x2f/0x90 drivers/bluetooth/hci_mrvl.c:100\n hci_uart_tty_close+0xb6/0x120 drivers/bluetooth/hci_ldisc.c:557\n tty_ldisc_close drivers/tty/tty_ldisc.c:455 [inline]\n tty_ldisc_kill+0x66/0xc0 drivers/tty/tty_ldisc.c:613\n tty_ldisc_release+0xc9/0x120 drivers/tty/tty_ldisc.c:781\n tty_release_struct+0x10/0x80 drivers/tty/tty_io.c:1690\n tty_release+0x4ef/0x640 drivers/tty/tty_io.c:1861\n __fput+0x86/0x2a0 fs/file_table.c:450\n task_work_run+0x82/0xb0 kernel/task_work.c:239\n resume_user_mode_work include/linux/resume_user_mode.h:50 [inline]\n exit_to_user_mode_loop kernel/entry/common.c:114 [inline]\n exit_to_user_mode_prepare include/linux/entry-common.h:329 [inline]\n __syscall_exit_to_user_mode_work kernel/entry/common.c:207 [inline]\n syscall_exit_to_user_mode+0xa3/0x1b0 kernel/entry/common.c:218\n do_syscall_64+0x9a/0x190 arch/x86/entry/common.c:89\n entry_SYSCALL_64_after_hwframe+0x77/0x7f", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23139" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/02e1bcdfdf769974e7e9fa285e295cd9852e2a38" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/281782d2c6730241e300d630bb9f200d831ede71" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5df5dafc171b90d0b8d51547a82657cd5a1986c7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/80f14e9de6a43a0bd8194cad1003a3e6dcbc3984" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8e5aff600539e5faea294d9612cca50220e602b8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/db7509fa110dd9b11134b75894677f30353b2c51" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T13:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-j9f5-mv8w-78qj/GHSA-j9f5-mv8w-78qj.json b/advisories/unreviewed/2025/05/GHSA-j9f5-mv8w-78qj/GHSA-j9f5-mv8w-78qj.json new file mode 100644 index 00000000000..5145fd144d0 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-j9f5-mv8w-78qj/GHSA-j9f5-mv8w-78qj.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j9f5-mv8w-78qj", + "modified": "2025-05-01T15:31:46Z", + "published": "2025-05-01T15:31:46Z", + "aliases": [ + "CVE-2022-49789" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: zfcp: Fix double free of FSF request when qdio send fails\n\nWe used to use the wrong type of integer in 'zfcp_fsf_req_send()' to cache\nthe FSF request ID when sending a new FSF request. This is used in case the\nsending fails and we need to remove the request from our internal hash\ntable again (so we don't keep an invalid reference and use it when we free\nthe request again).\n\nIn 'zfcp_fsf_req_send()' we used to cache the ID as 'int' (signed and 32\nbit wide), but the rest of the zfcp code (and the firmware specification)\nhandles the ID as 'unsigned long'/'u64' (unsigned and 64 bit wide [s390x\nELF ABI]). For one this has the obvious problem that when the ID grows\npast 32 bit (this can happen reasonably fast) it is truncated to 32 bit\nwhen storing it in the cache variable and so doesn't match the original ID\nanymore. The second less obvious problem is that even when the original ID\nhas not yet grown past 32 bit, as soon as the 32nd bit is set in the\noriginal ID (0x80000000 = 2'147'483'648) we will have a mismatch when we\ncast it back to 'unsigned long'. As the cached variable is of a signed\ntype, the compiler will choose a sign-extending instruction to load the 32\nbit variable into a 64 bit register (e.g.: 'lgf %r11,188(%r15)'). So once\nwe pass the cached variable into 'zfcp_reqlist_find_rm()' to remove the\nrequest again all the leading zeros will be flipped to ones to extend the\nsign and won't match the original ID anymore (this has been observed in\npractice).\n\nIf we can't successfully remove the request from the hash table again after\n'zfcp_qdio_send()' fails (this happens regularly when zfcp cannot notify\nthe adapter about new work because the adapter is already gone during\ne.g. a ChpID toggle) we will end up with a double free. We unconditionally\nfree the request in the calling function when 'zfcp_fsf_req_send()' fails,\nbut because the request is still in the hash table we end up with a stale\nmemory reference, and once the zfcp adapter is either reset during recovery\nor shutdown we end up freeing the same memory twice.\n\nThe resulting stack traces vary depending on the kernel and have no direct\ncorrelation to the place where the bug occurs. Here are three examples that\nhave been seen in practice:\n\n list_del corruption. next->prev should be 00000001b9d13800, but was 00000000dead4ead. (next=00000001bd131a00)\n ------------[ cut here ]------------\n kernel BUG at lib/list_debug.c:62!\n monitor event: 0040 ilc:2 [#1] PREEMPT SMP\n Modules linked in: ...\n CPU: 9 PID: 1617 Comm: zfcperp0.0.1740 Kdump: loaded\n Hardware name: ...\n Krnl PSW : 0704d00180000000 00000003cbeea1f8 (__list_del_entry_valid+0x98/0x140)\n R:0 T:1 IO:1 EX:1 Key:0 M:1 W:0 P:0 AS:3 CC:1 PM:0 RI:0 EA:3\n Krnl GPRS: 00000000916d12f1 0000000080000000 000000000000006d 00000003cb665cd6\n 0000000000000001 0000000000000000 0000000000000000 00000000d28d21e8\n 00000000d3844000 00000380099efd28 00000001bd131a00 00000001b9d13800\n 00000000d3290100 0000000000000000 00000003cbeea1f4 00000380099efc70\n Krnl Code: 00000003cbeea1e8: c020004f68a7 larl %r2,00000003cc8d7336\n 00000003cbeea1ee: c0e50027fd65 brasl %r14,00000003cc3e9cb8\n #00000003cbeea1f4: af000000 mc 0,0\n >00000003cbeea1f8: c02000920440 larl %r2,00000003cd12aa78\n 00000003cbeea1fe: c0e500289c25 brasl %r14,00000003cc3fda48\n 00000003cbeea204: b9040043 lgr %r4,%r3\n 00000003cbeea208: b9040051 lgr %r5,%r1\n 00000003cbeea20c: b9040032 lgr %r3,%r2\n Call Trace:\n [<00000003cbeea1f8>] __list_del_entry_valid+0x98/0x140\n ([<00000003cbeea1f4>] __list_del_entry_valid+0x94/0x140)\n [<000003ff7ff502fe>] zfcp_fsf_req_dismiss_all+0xde/0x150 [zfcp]\n [<000003ff7ff49cd0>] zfcp_erp_strategy_do_action+0x160/0x280 [zfcp]\n---truncated---", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49789" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0954256e970ecf371b03a6c9af2cf91b9c4085ff" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/11edbdee4399401f533adda9bffe94567aa08b96" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1bf8ed585501bb2dd0b5f67c824eab45adfbdccd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/90a49a6b015fa439cd62e45121390284c125a91f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d2c7d8f58e9cde8ac8d1f75e9d66c2a813ffe0ab" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-jf2p-fggv-v92v/GHSA-jf2p-fggv-v92v.json b/advisories/unreviewed/2025/05/GHSA-jf2p-fggv-v92v/GHSA-jf2p-fggv-v92v.json new file mode 100644 index 00000000000..625a437df1c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-jf2p-fggv-v92v/GHSA-jf2p-fggv-v92v.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jf2p-fggv-v92v", + "modified": "2025-05-01T15:31:40Z", + "published": "2025-05-01T15:31:40Z", + "aliases": [ + "CVE-2025-23150" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\next4: fix off-by-one error in do_split\n\nSyzkaller detected a use-after-free issue in ext4_insert_dentry that was\ncaused by out-of-bounds access due to incorrect splitting in do_split.\n\nBUG: KASAN: use-after-free in ext4_insert_dentry+0x36a/0x6d0 fs/ext4/namei.c:2109\nWrite of size 251 at addr ffff888074572f14 by task syz-executor335/5847\n\nCPU: 0 UID: 0 PID: 5847 Comm: syz-executor335 Not tainted 6.12.0-rc6-syzkaller-00318-ga9cda7c0ffed #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/30/2024\nCall Trace:\n \n __dump_stack lib/dump_stack.c:94 [inline]\n dump_stack_lvl+0x241/0x360 lib/dump_stack.c:120\n print_address_description mm/kasan/report.c:377 [inline]\n print_report+0x169/0x550 mm/kasan/report.c:488\n kasan_report+0x143/0x180 mm/kasan/report.c:601\n kasan_check_range+0x282/0x290 mm/kasan/generic.c:189\n __asan_memcpy+0x40/0x70 mm/kasan/shadow.c:106\n ext4_insert_dentry+0x36a/0x6d0 fs/ext4/namei.c:2109\n add_dirent_to_buf+0x3d9/0x750 fs/ext4/namei.c:2154\n make_indexed_dir+0xf98/0x1600 fs/ext4/namei.c:2351\n ext4_add_entry+0x222a/0x25d0 fs/ext4/namei.c:2455\n ext4_add_nondir+0x8d/0x290 fs/ext4/namei.c:2796\n ext4_symlink+0x920/0xb50 fs/ext4/namei.c:3431\n vfs_symlink+0x137/0x2e0 fs/namei.c:4615\n do_symlinkat+0x222/0x3a0 fs/namei.c:4641\n __do_sys_symlink fs/namei.c:4662 [inline]\n __se_sys_symlink fs/namei.c:4660 [inline]\n __x64_sys_symlink+0x7a/0x90 fs/namei.c:4660\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n \n\nThe following loop is located right above 'if' statement.\n\nfor (i = count-1; i >= 0; i--) {\n\t/* is more than half of this entry in 2nd half of the block? */\n\tif (size + map[i].size/2 > blocksize/2)\n\t\tbreak;\n\tsize += map[i].size;\n\tmove++;\n}\n\n'i' in this case could go down to -1, in which case sum of active entries\nwouldn't exceed half the block size, but previous behaviour would also do\nsplit in half if sum would exceed at the very last block, which in case of\nhaving too many long name files in a single block could lead to\nout-of-bounds access and following use-after-free.\n\nFound by Linux Verification Center (linuxtesting.org) with Syzkaller.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23150" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/16d9067f00e3a7d1df7c3aa9c20d214923d27e10" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/17df39f455f1289319d4d09e4826aa46852ffd17" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2eeb1085bf7bd5c7ba796ca4119925fa5d336a3f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/35d0aa6db9d93307085871ceab8a729594a98162" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/94824ac9a8aaf2fb3c54b4bdde842db80ffa555d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ab0cc5c25552ae0d20eae94b40a93be11b080fc5" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T13:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-jfrj-r763-gv36/GHSA-jfrj-r763-gv36.json b/advisories/unreviewed/2025/05/GHSA-jfrj-r763-gv36/GHSA-jfrj-r763-gv36.json new file mode 100644 index 00000000000..794a7319873 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-jfrj-r763-gv36/GHSA-jfrj-r763-gv36.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jfrj-r763-gv36", + "modified": "2025-05-01T15:31:43Z", + "published": "2025-05-01T15:31:42Z", + "aliases": [ + "CVE-2025-37755" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: libwx: handle page_pool_dev_alloc_pages error\n\npage_pool_dev_alloc_pages could return NULL. There was a WARN_ON(!page)\nbut it would still proceed to use the NULL pointer and then crash.\n\nThis is similar to commit 001ba0902046\n(\"net: fec: handle page_pool_dev_alloc_pages error\").\n\nThis is found by our static analysis tool KNighter.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37755" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1dd13c60348f515acd8c6f25a561b9c4e3b04fea" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7f1ff1b38a7c8b872382b796023419d87d78c47e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/90bec7cef8805f9a23145e070dff28a02bb584eb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ad81d666e114ebf989fc9994d4c93d451dc60056" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c17ef974bfcf1a50818168b47c4606b425a957c4" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T13:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-jfw6-w783-5hhm/GHSA-jfw6-w783-5hhm.json b/advisories/unreviewed/2025/05/GHSA-jfw6-w783-5hhm/GHSA-jfw6-w783-5hhm.json new file mode 100644 index 00000000000..5bbdd45d13a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-jfw6-w783-5hhm/GHSA-jfw6-w783-5hhm.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jfw6-w783-5hhm", + "modified": "2025-05-01T15:31:50Z", + "published": "2025-05-01T15:31:50Z", + "aliases": [ + "CVE-2022-49871" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: tun: Fix memory leaks of napi_get_frags\n\nkmemleak reports after running test_progs:\n\nunreferenced object 0xffff8881b1672dc0 (size 232):\n comm \"test_progs\", pid 394388, jiffies 4354712116 (age 841.975s)\n hex dump (first 32 bytes):\n e0 84 d7 a8 81 88 ff ff 80 2c 67 b1 81 88 ff ff .........,g.....\n 00 40 c5 9b 81 88 ff ff 00 00 00 00 00 00 00 00 .@..............\n backtrace:\n [<00000000c8f01748>] napi_skb_cache_get+0xd4/0x150\n [<0000000041c7fc09>] __napi_build_skb+0x15/0x50\n [<00000000431c7079>] __napi_alloc_skb+0x26e/0x540\n [<000000003ecfa30e>] napi_get_frags+0x59/0x140\n [<0000000099b2199e>] tun_get_user+0x183d/0x3bb0 [tun]\n [<000000008a5adef0>] tun_chr_write_iter+0xc0/0x1b1 [tun]\n [<0000000049993ff4>] do_iter_readv_writev+0x19f/0x320\n [<000000008f338ea2>] do_iter_write+0x135/0x630\n [<000000008a3377a4>] vfs_writev+0x12e/0x440\n [<00000000a6b5639a>] do_writev+0x104/0x280\n [<00000000ccf065d8>] do_syscall_64+0x3b/0x90\n [<00000000d776e329>] entry_SYSCALL_64_after_hwframe+0x63/0xcd\n\nThe issue occurs in the following scenarios:\ntun_get_user()\n napi_gro_frags()\n napi_frags_finish()\n case GRO_NORMAL:\n gro_normal_one()\n list_add_tail(&skb->list, &napi->rx_list);\n <-- While napi->rx_count < READ_ONCE(gro_normal_batch),\n <-- gro_normal_list() is not called, napi->rx_list is not empty\n <-- not ask to complete the gro work, will cause memory leaks in\n <-- following tun_napi_del()\n...\ntun_napi_del()\n netif_napi_del()\n __netif_napi_del()\n <-- &napi->rx_list is not empty, which caused memory leaks\n\nTo fix, add napi_complete() after napi_gro_frags().", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49871" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1118b2049d77ca0b505775fc1a8d1909cf19a7ec" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/223ef6a94e52331a6a7ef31e59921e0e82d2d40a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3401f964028ac941425b9b2c8ff8a022539ef44a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8b12a020b20a78f62bedc50f26db3bf4fadf8cb9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a4f73f6adc53fd7a3f9771cbc89a03ef39b0b755" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d7569302a7a52a9305d2fb054df908ff985553bb" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-jfxf-grc2-gr7w/GHSA-jfxf-grc2-gr7w.json b/advisories/unreviewed/2025/05/GHSA-jfxf-grc2-gr7w/GHSA-jfxf-grc2-gr7w.json new file mode 100644 index 00000000000..2fd96ec4e5b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-jfxf-grc2-gr7w/GHSA-jfxf-grc2-gr7w.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jfxf-grc2-gr7w", + "modified": "2025-05-01T15:31:50Z", + "published": "2025-05-01T15:31:50Z", + "aliases": [ + "CVE-2022-49868" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nphy: ralink: mt7621-pci: add sentinel to quirks table\n\nWith mt7621 soc_dev_attr fixed to register the soc as a device,\nkernel will experience an oops in soc_device_match_attr\n\nThis quirk test was introduced in the staging driver in\ncommit 9445ccb3714c (\"staging: mt7621-pci-phy: add quirks for 'E2'\nrevision using 'soc_device_attribute'\"). The staging driver was removed,\nand later re-added in commit d87da32372a0 (\"phy: ralink: Add PHY driver\nfor MT7621 PCIe PHY\") for kernel 5.11", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49868" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/500bcd3a99eae84412067c3b9e7ffba1c66e6383" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/819b885cd886c193782891c4f51bbcab3de119a4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d539cfd1202d66c2dcea383f1d96835ae72d5809" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-jgm3-v9g7-rfc3/GHSA-jgm3-v9g7-rfc3.json b/advisories/unreviewed/2025/05/GHSA-jgm3-v9g7-rfc3/GHSA-jgm3-v9g7-rfc3.json new file mode 100644 index 00000000000..cda742ae8a8 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-jgm3-v9g7-rfc3/GHSA-jgm3-v9g7-rfc3.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jgm3-v9g7-rfc3", + "modified": "2025-05-01T15:31:52Z", + "published": "2025-05-01T15:31:52Z", + "aliases": [ + "CVE-2022-49914" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix inode list leak during backref walking at resolve_indirect_refs()\n\nDuring backref walking, at resolve_indirect_refs(), if we get an error\nwe jump to the 'out' label and call ulist_free() on the 'parents' ulist,\nwhich frees all the elements in the ulist - however that does not free\nany inode lists that may be attached to elements, through the 'aux' field\nof a ulist node, so we end up leaking lists if we have any attached to\nthe unodes.\n\nFix this by calling free_leaf_list() instead of ulist_free() when we exit\nfrom resolve_indirect_refs(). The static function free_leaf_list() is\nmoved up for this to be possible and it's slightly simplified by removing\nunnecessary code.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49914" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2c0329406bb28109c07c6e23e5e3e0fa618a95d7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/396515db923ad5cbeb179d6b88927870b4cbebb7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5614dc3a47e3310fbc77ea3b67eaadd1c6417bf1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6ba3479f9e96b9ad460c7e77abc26dd16e5dec4f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a52e24c7fcc3c5ce3588a14e3663c00868d36623" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b1dc9019bb5f89abae85645de1a2dd4830c1f8e9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cded2c89774b99b67c98147ae103ea878c92a206" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-jjg4-p57c-87j3/GHSA-jjg4-p57c-87j3.json b/advisories/unreviewed/2025/05/GHSA-jjg4-p57c-87j3/GHSA-jjg4-p57c-87j3.json new file mode 100644 index 00000000000..5d90c00a4cf --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-jjg4-p57c-87j3/GHSA-jjg4-p57c-87j3.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jjg4-p57c-87j3", + "modified": "2025-05-01T15:31:49Z", + "published": "2025-05-01T15:31:49Z", + "aliases": [ + "CVE-2022-49844" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: dev: fix skb drop check\n\nIn commit a6d190f8c767 (\"can: skb: drop tx skb if in listen only\nmode\") the priv->ctrlmode element is read even on virtual CAN\ninterfaces that do not create the struct can_priv at startup. This\nout-of-bounds read may lead to CAN frame drops for virtual CAN\ninterfaces like vcan and vxcan.\n\nThis patch mainly reverts the original commit and adds a new helper\nfor CAN interface drivers that provide the required information in\nstruct can_priv.\n\n[mkl: patch pch_can, too]", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49844" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/386c49fe31ee748e053860b3bac7794a933ac9ac" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ae64438be1923e3c1102d90fd41db7afcfaf54cc" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-jqp5-hv8x-q94p/GHSA-jqp5-hv8x-q94p.json b/advisories/unreviewed/2025/05/GHSA-jqp5-hv8x-q94p/GHSA-jqp5-hv8x-q94p.json new file mode 100644 index 00000000000..99b58eca0ea --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-jqp5-hv8x-q94p/GHSA-jqp5-hv8x-q94p.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jqp5-hv8x-q94p", + "modified": "2025-05-01T15:31:45Z", + "published": "2025-05-01T15:31:45Z", + "aliases": [ + "CVE-2020-36790" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet: fix a memory leak\n\nWe forgot to free new_model_number", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-36790" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/227064b2ca9e62270ed445665ae849c73f0dfb2c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/382fee1a8b623e2546a3e15e80517389e0e0673e" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-jw72-qv66-6947/GHSA-jw72-qv66-6947.json b/advisories/unreviewed/2025/05/GHSA-jw72-qv66-6947/GHSA-jw72-qv66-6947.json new file mode 100644 index 00000000000..b61eb1a0bb0 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-jw72-qv66-6947/GHSA-jw72-qv66-6947.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jw72-qv66-6947", + "modified": "2025-05-01T15:31:42Z", + "published": "2025-05-01T15:31:42Z", + "aliases": [ + "CVE-2025-37738" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\next4: ignore xattrs past end\n\nOnce inside 'ext4_xattr_inode_dec_ref_all' we should\nignore xattrs entries past the 'end' entry.\n\nThis fixes the following KASAN reported issue:\n\n==================================================================\nBUG: KASAN: slab-use-after-free in ext4_xattr_inode_dec_ref_all+0xb8c/0xe90\nRead of size 4 at addr ffff888012c120c4 by task repro/2065\n\nCPU: 1 UID: 0 PID: 2065 Comm: repro Not tainted 6.13.0-rc2+ #11\nHardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014\nCall Trace:\n \n dump_stack_lvl+0x1fd/0x300\n ? tcp_gro_dev_warn+0x260/0x260\n ? _printk+0xc0/0x100\n ? read_lock_is_recursive+0x10/0x10\n ? irq_work_queue+0x72/0xf0\n ? __virt_addr_valid+0x17b/0x4b0\n print_address_description+0x78/0x390\n print_report+0x107/0x1f0\n ? __virt_addr_valid+0x17b/0x4b0\n ? __virt_addr_valid+0x3ff/0x4b0\n ? __phys_addr+0xb5/0x160\n ? ext4_xattr_inode_dec_ref_all+0xb8c/0xe90\n kasan_report+0xcc/0x100\n ? ext4_xattr_inode_dec_ref_all+0xb8c/0xe90\n ext4_xattr_inode_dec_ref_all+0xb8c/0xe90\n ? ext4_xattr_delete_inode+0xd30/0xd30\n ? __ext4_journal_ensure_credits+0x5f0/0x5f0\n ? __ext4_journal_ensure_credits+0x2b/0x5f0\n ? inode_update_timestamps+0x410/0x410\n ext4_xattr_delete_inode+0xb64/0xd30\n ? ext4_truncate+0xb70/0xdc0\n ? ext4_expand_extra_isize_ea+0x1d20/0x1d20\n ? __ext4_mark_inode_dirty+0x670/0x670\n ? ext4_journal_check_start+0x16f/0x240\n ? ext4_inode_is_fast_symlink+0x2f2/0x3a0\n ext4_evict_inode+0xc8c/0xff0\n ? ext4_inode_is_fast_symlink+0x3a0/0x3a0\n ? do_raw_spin_unlock+0x53/0x8a0\n ? ext4_inode_is_fast_symlink+0x3a0/0x3a0\n evict+0x4ac/0x950\n ? proc_nr_inodes+0x310/0x310\n ? trace_ext4_drop_inode+0xa2/0x220\n ? _raw_spin_unlock+0x1a/0x30\n ? iput+0x4cb/0x7e0\n do_unlinkat+0x495/0x7c0\n ? try_break_deleg+0x120/0x120\n ? 0xffffffff81000000\n ? __check_object_size+0x15a/0x210\n ? strncpy_from_user+0x13e/0x250\n ? getname_flags+0x1dc/0x530\n __x64_sys_unlinkat+0xc8/0xf0\n do_syscall_64+0x65/0x110\n entry_SYSCALL_64_after_hwframe+0x67/0x6f\nRIP: 0033:0x434ffd\nCode: 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 00 f3 0f 1e fa 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 8\nRSP: 002b:00007ffc50fa7b28 EFLAGS: 00000246 ORIG_RAX: 0000000000000107\nRAX: ffffffffffffffda RBX: 00007ffc50fa7e18 RCX: 0000000000434ffd\nRDX: 0000000000000000 RSI: 0000000020000240 RDI: 0000000000000005\nRBP: 00007ffc50fa7be0 R08: 0000000000000000 R09: 0000000000000000\nR10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000001\nR13: 00007ffc50fa7e08 R14: 00000000004bbf30 R15: 0000000000000001\n \n\nThe buggy address belongs to the object at ffff888012c12000\n which belongs to the cache filp of size 360\nThe buggy address is located 196 bytes inside of\n freed 360-byte region [ffff888012c12000, ffff888012c12168)\n\nThe buggy address belongs to the physical page:\npage: refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x12c12\nhead: order:1 mapcount:0 entire_mapcount:0 nr_pages_mapped:0 pincount:0\nflags: 0x40(head|node=0|zone=0)\npage_type: f5(slab)\nraw: 0000000000000040 ffff888000ad7640 ffffea0000497a00 dead000000000004\nraw: 0000000000000000 0000000000100010 00000001f5000000 0000000000000000\nhead: 0000000000000040 ffff888000ad7640 ffffea0000497a00 dead000000000004\nhead: 0000000000000000 0000000000100010 00000001f5000000 0000000000000000\nhead: 0000000000000001 ffffea00004b0481 ffffffffffffffff 0000000000000000\nhead: 0000000000000002 0000000000000000 00000000ffffffff 0000000000000000\npage dumped because: kasan: bad access detected\n\nMemory state around the buggy address:\n ffff888012c11f80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\n ffff888012c12000: fa fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb\n> ffff888012c12080: fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb\n ^\n ffff888012c12100: fb fb fb fb fb fb fb fb fb fb fb fb fb fc fc fc\n ffff888012c12180: fc fc fc fc fc fc fc fc fc\n---truncated---", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37738" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/362a90cecd36e8a5c415966d0b75b04a0270e4dd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3bc6317033f365ce578eb6039445fb66162722fd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/836e625b03a666cf93ff5be328c8cb30336db872" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c8e008b60492cf6fd31ef127aea6d02fd3d314cd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cf9291a3449b04688b81e32621e88de8f4314b54" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/eb59cc31b6ea076021d14b04e7faab1636b87d0e" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T13:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-m3j7-r27p-7m78/GHSA-m3j7-r27p-7m78.json b/advisories/unreviewed/2025/05/GHSA-m3j7-r27p-7m78/GHSA-m3j7-r27p-7m78.json new file mode 100644 index 00000000000..817982a853e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-m3j7-r27p-7m78/GHSA-m3j7-r27p-7m78.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m3j7-r27p-7m78", + "modified": "2025-05-01T15:31:50Z", + "published": "2025-05-01T15:31:50Z", + "aliases": [ + "CVE-2022-49855" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: wwan: iosm: fix memory leak in ipc_pcie_read_bios_cfg\n\nipc_pcie_read_bios_cfg() is using the acpi_evaluate_dsm() to\nobtain the wwan power state configuration from BIOS but is\nnot freeing the acpi_object. The acpi_evaluate_dsm() returned\nacpi_object to be freed.\n\nFree the acpi_object after use.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49855" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/13b1ea861e8aeb701bcfbfe436b943efa2d44029" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7560ceef4d2832a67e8781d924e129c7f542376f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d38a648d2d6cc7bee11c6f533ff9426a00c2a74c" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-m55q-77wq-m8pr/GHSA-m55q-77wq-m8pr.json b/advisories/unreviewed/2025/05/GHSA-m55q-77wq-m8pr/GHSA-m55q-77wq-m8pr.json new file mode 100644 index 00000000000..a2c6190c909 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-m55q-77wq-m8pr/GHSA-m55q-77wq-m8pr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m55q-77wq-m8pr", + "modified": "2025-05-01T15:31:43Z", + "published": "2025-05-01T15:31:43Z", + "aliases": [ + "CVE-2025-23245" + ], + "details": "NVIDIA vGPU software for Windows and Linux contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it allows a guest to access global resources. A successful exploit of this vulnerability might lead to denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23245" + }, + { + "type": "WEB", + "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5630" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-732" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T14:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-m6c5-jhrw-6658/GHSA-m6c5-jhrw-6658.json b/advisories/unreviewed/2025/05/GHSA-m6c5-jhrw-6658/GHSA-m6c5-jhrw-6658.json new file mode 100644 index 00000000000..52788768e6b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-m6c5-jhrw-6658/GHSA-m6c5-jhrw-6658.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m6c5-jhrw-6658", + "modified": "2025-05-01T15:31:47Z", + "published": "2025-05-01T15:31:46Z", + "aliases": [ + "CVE-2022-49784" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nperf/x86/amd/uncore: Fix memory leak for events array\n\nWhen a CPU comes online, the per-CPU NB and LLC uncore contexts are\nfreed but not the events array within the context structure. This\ncauses a memory leak as identified by the kmemleak detector.\n\n [...]\n unreferenced object 0xffff8c5944b8e320 (size 32):\n comm \"swapper/0\", pid 1, jiffies 4294670387 (age 151.072s)\n hex dump (first 32 bytes):\n 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n backtrace:\n [<000000000759fb79>] amd_uncore_cpu_up_prepare+0xaf/0x230\n [<00000000ddc9e126>] cpuhp_invoke_callback+0x2cf/0x470\n [<0000000093e727d4>] cpuhp_issue_call+0x14d/0x170\n [<0000000045464d54>] __cpuhp_setup_state_cpuslocked+0x11e/0x330\n [<0000000069f67cbd>] __cpuhp_setup_state+0x6b/0x110\n [<0000000015365e0f>] amd_uncore_init+0x260/0x321\n [<00000000089152d2>] do_one_initcall+0x3f/0x1f0\n [<000000002d0bd18d>] kernel_init_freeable+0x1ca/0x212\n [<0000000030be8dde>] kernel_init+0x11/0x120\n [<0000000059709e59>] ret_from_fork+0x22/0x30\n unreferenced object 0xffff8c5944b8dd40 (size 64):\n comm \"swapper/0\", pid 1, jiffies 4294670387 (age 151.072s)\n hex dump (first 32 bytes):\n 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n backtrace:\n [<00000000306efe8b>] amd_uncore_cpu_up_prepare+0x183/0x230\n [<00000000ddc9e126>] cpuhp_invoke_callback+0x2cf/0x470\n [<0000000093e727d4>] cpuhp_issue_call+0x14d/0x170\n [<0000000045464d54>] __cpuhp_setup_state_cpuslocked+0x11e/0x330\n [<0000000069f67cbd>] __cpuhp_setup_state+0x6b/0x110\n [<0000000015365e0f>] amd_uncore_init+0x260/0x321\n [<00000000089152d2>] do_one_initcall+0x3f/0x1f0\n [<000000002d0bd18d>] kernel_init_freeable+0x1ca/0x212\n [<0000000030be8dde>] kernel_init+0x11/0x120\n [<0000000059709e59>] ret_from_fork+0x22/0x30\n [...]\n\nFix the problem by freeing the events array before freeing the uncore\ncontext.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49784" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bdfe34597139cfcecd47a2eb97fea44d77157491" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f75be9885d49e3717de962345c4572ddab52b178" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-m8x7-f64c-28w3/GHSA-m8x7-f64c-28w3.json b/advisories/unreviewed/2025/05/GHSA-m8x7-f64c-28w3/GHSA-m8x7-f64c-28w3.json new file mode 100644 index 00000000000..cb4ee3ff4e2 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-m8x7-f64c-28w3/GHSA-m8x7-f64c-28w3.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m8x7-f64c-28w3", + "modified": "2025-05-01T15:31:49Z", + "published": "2025-05-01T15:31:49Z", + "aliases": [ + "CVE-2022-49850" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: fix deadlock in nilfs_count_free_blocks()\n\nA semaphore deadlock can occur if nilfs_get_block() detects metadata\ncorruption while locating data blocks and a superblock writeback occurs at\nthe same time:\n\ntask 1 task 2\n------ ------\n* A file operation *\nnilfs_truncate()\n nilfs_get_block()\n down_read(rwsem A) <--\n nilfs_bmap_lookup_contig()\n ... generic_shutdown_super()\n nilfs_put_super()\n * Prepare to write superblock *\n down_write(rwsem B) <--\n nilfs_cleanup_super()\n * Detect b-tree corruption * nilfs_set_log_cursor()\n nilfs_bmap_convert_error() nilfs_count_free_blocks()\n __nilfs_error() down_read(rwsem A) <--\n nilfs_set_error()\n down_write(rwsem B) <--\n\n *** DEADLOCK ***\n\nHere, nilfs_get_block() readlocks rwsem A (= NILFS_MDT(dat_inode)->mi_sem)\nand then calls nilfs_bmap_lookup_contig(), but if it fails due to metadata\ncorruption, __nilfs_error() is called from nilfs_bmap_convert_error()\ninside the lock section.\n\nSince __nilfs_error() calls nilfs_set_error() unless the filesystem is\nread-only and nilfs_set_error() attempts to writelock rwsem B (=\nnilfs->ns_sem) to write back superblock exclusively, hierarchical lock\nacquisition occurs in the order rwsem A -> rwsem B.\n\nNow, if another task starts updating the superblock, it may writelock\nrwsem B during the lock sequence above, and can deadlock trying to\nreadlock rwsem A in nilfs_count_free_blocks().\n\nHowever, there is actually no need to take rwsem A in\nnilfs_count_free_blocks() because it, within the lock section, only reads\na single integer data on a shared struct with\nnilfs_sufile_get_ncleansegs(). This has been the case after commit\naa474a220180 (\"nilfs2: add local variable to cache the number of clean\nsegments\"), that is, even before this bug was introduced.\n\nSo, this resolves the deadlock problem by just not taking the semaphore in\nnilfs_count_free_blocks().", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49850" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1d4ff73062096c21b47954d2996b4df259777bda" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/36ff974b0310771417c0be64b64aa221bd70d63d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3c89ca6d3dfa6c09c515807a7a97a521f5d5147e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8ac932a4921a96ca52f61935dbba64ea87bbd5dc" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8b4506cff6630bb474bb46a2a75c31e533a756ba" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/abc082aac0d9b6b926038fc3adb7008306581be2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cb029b54953420f7a2d65100f1c5107f14411bdc" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f0cc93080d4c09510b74ecba87fd778cca390bb1" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-m9hv-2rww-w638/GHSA-m9hv-2rww-w638.json b/advisories/unreviewed/2025/05/GHSA-m9hv-2rww-w638/GHSA-m9hv-2rww-w638.json new file mode 100644 index 00000000000..a87b56e60c4 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-m9hv-2rww-w638/GHSA-m9hv-2rww-w638.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m9hv-2rww-w638", + "modified": "2025-05-01T15:31:48Z", + "published": "2025-05-01T15:31:48Z", + "aliases": [ + "CVE-2022-49808" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: dsa: don't leak tagger-owned storage on switch driver unbind\n\nIn the initial commit dc452a471dba (\"net: dsa: introduce tagger-owned\nstorage for private and shared data\"), we had a call to\ntag_ops->disconnect(dst) issued from dsa_tree_free(), which is called at\ntree teardown time.\n\nThere were problems with connecting to a switch tree as a whole, so this\ngot reworked to connecting to individual switches within the tree. In\nthis process, tag_ops->disconnect(ds) was made to be called only from\nswitch.c (cross-chip notifiers emitted as a result of dynamic tag proto\nchanges), but the normal driver teardown code path wasn't replaced with\nanything.\n\nSolve this problem by adding a function that does the opposite of\ndsa_switch_setup_tag_protocol(), which is called from the equivalent\nspot in dsa_switch_teardown(). The positioning here also ensures that we\nwon't have any use-after-free in tagging protocol (*rcv) ops, since the\nteardown sequence is as follows:\n\ndsa_tree_teardown\n-> dsa_tree_teardown_master\n -> dsa_master_teardown\n -> unsets master->dsa_ptr, making no further packets match the\n ETH_P_XDSA packet type handler\n-> dsa_tree_teardown_ports\n -> dsa_port_teardown\n -> dsa_slave_destroy\n -> unregisters DSA net devices, there is even a synchronize_net()\n in unregister_netdevice_many()\n-> dsa_tree_teardown_switches\n -> dsa_switch_teardown\n -> dsa_switch_teardown_tag_protocol\n -> finally frees the tagger-owned storage", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49808" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4e0c19fcb8b5323716140fa82b79aa9f60e60407" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5809fb03942dbac25144db5bebea84fa003ecaca" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-mc9r-5hj8-m6xw/GHSA-mc9r-5hj8-m6xw.json b/advisories/unreviewed/2025/05/GHSA-mc9r-5hj8-m6xw/GHSA-mc9r-5hj8-m6xw.json new file mode 100644 index 00000000000..a1064928d5a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-mc9r-5hj8-m6xw/GHSA-mc9r-5hj8-m6xw.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mc9r-5hj8-m6xw", + "modified": "2025-05-01T15:31:48Z", + "published": "2025-05-01T15:31:48Z", + "aliases": [ + "CVE-2022-49827" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm: Fix potential null-ptr-deref in drm_vblank_destroy_worker()\n\ndrm_vblank_init() call drmm_add_action_or_reset() with\ndrm_vblank_init_release() as action. If __drmm_add_action() failed, will\ndirectly call drm_vblank_init_release() with the vblank whose worker is\nNULL. As the resule, a null-ptr-deref will happen in\nkthread_destroy_worker(). Add the NULL check before calling\ndrm_vblank_destroy_worker().\n\nBUG: null-ptr-deref\nKASAN: null-ptr-deref in range [0x0000000000000068-0x000000000000006f]\nCPU: 5 PID: 961 Comm: modprobe Not tainted 6.0.0-11331-gd465bff130bf-dirty\nRIP: 0010:kthread_destroy_worker+0x25/0xb0\n Call Trace:\n \n drm_vblank_init_release+0x124/0x220 [drm]\n ? drm_crtc_vblank_restore+0x8b0/0x8b0 [drm]\n __drmm_add_action_or_reset+0x41/0x50 [drm]\n drm_vblank_init+0x282/0x310 [drm]\n vkms_init+0x35f/0x1000 [vkms]\n ? 0xffffffffc4508000\n ? lock_is_held_type+0xd7/0x130\n ? __kmem_cache_alloc_node+0x1c2/0x2b0\n ? lock_is_held_type+0xd7/0x130\n ? 0xffffffffc4508000\n do_one_initcall+0xd0/0x4f0\n ...\n do_syscall_64+0x35/0x80\n entry_SYSCALL_64_after_hwframe+0x46/0xb0", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49827" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1d160dfb3fdf11ba9447e862c548447f91f4e74a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3acd2016421b2e628acad65495d15493bf7a3bc3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4979524f5a2a8210e87fde2f642b0dc060860821" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e884a6c2d49a6c12761e5bed851e9fe93bd923a1" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-mgh7-45p9-8c23/GHSA-mgh7-45p9-8c23.json b/advisories/unreviewed/2025/05/GHSA-mgh7-45p9-8c23/GHSA-mgh7-45p9-8c23.json new file mode 100644 index 00000000000..71b0723ce36 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-mgh7-45p9-8c23/GHSA-mgh7-45p9-8c23.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mgh7-45p9-8c23", + "modified": "2025-05-01T15:31:48Z", + "published": "2025-05-01T15:31:48Z", + "aliases": [ + "CVE-2022-49809" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/x25: Fix skb leak in x25_lapb_receive_frame()\n\nx25_lapb_receive_frame() using skb_copy() to get a private copy of\nskb, the new skb should be freed in the undersized/fragmented skb\nerror handling path. Otherwise there is a memory leak.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49809" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0ef17d966445358a55c5f4ccf2c73cca3e39192b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2929cceb2fcf0ded7182562e4888afafece82cce" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2d675be16a461310d738d93f9f1a00da62055c5a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9f00da9c866d506998bf0a3f699ec900730472da" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c8baf1fc248b2e88642f094fea9509a9bf98c5bb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/dfcfbe4f2e4b2c81cff4e79b48502d97fda73118" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e109b41870db995cae25dfaf0cc3922f9028b1a1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fda0ba7c84b46d10947c687320804b9de149a921" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-mgjq-wwgf-853f/GHSA-mgjq-wwgf-853f.json b/advisories/unreviewed/2025/05/GHSA-mgjq-wwgf-853f/GHSA-mgjq-wwgf-853f.json new file mode 100644 index 00000000000..08fbd2046a6 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-mgjq-wwgf-853f/GHSA-mgjq-wwgf-853f.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mgjq-wwgf-853f", + "modified": "2025-05-01T15:31:49Z", + "published": "2025-05-01T15:31:49Z", + "aliases": [ + "CVE-2022-49843" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdkfd: Migrate in CPU page fault use current mm\n\nmigrate_vma_setup shows below warning because we don't hold another\nprocess mm mmap_lock. We should use current vmf->vma->vm_mm instead, the\ncaller already hold current mmap lock inside CPU page fault handler.\n\n WARNING: CPU: 10 PID: 3054 at include/linux/mmap_lock.h:155 find_vma\n Call Trace:\n walk_page_range+0x76/0x150\n migrate_vma_setup+0x18a/0x640\n svm_migrate_vram_to_ram+0x245/0xa10 [amdgpu]\n svm_migrate_to_ram+0x36f/0x470 [amdgpu]\n do_swap_page+0xcfe/0xec0\n __handle_mm_fault+0x96b/0x15e0\n handle_mm_fault+0x13f/0x3e0\n do_user_addr_fault+0x1e7/0x690", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49843" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/128e284c6cccf5875261569fa3bb07558870c17f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1dea25e25acd990d7657940ffcab8354c28fa292" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3a876060892ba52dd67d197c78b955e62657d906" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-mm3m-5497-xggg/GHSA-mm3m-5497-xggg.json b/advisories/unreviewed/2025/05/GHSA-mm3m-5497-xggg/GHSA-mm3m-5497-xggg.json new file mode 100644 index 00000000000..b8f49ffdf2c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-mm3m-5497-xggg/GHSA-mm3m-5497-xggg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mm3m-5497-xggg", + "modified": "2025-05-01T15:31:43Z", + "published": "2025-05-01T15:31:43Z", + "aliases": [ + "CVE-2024-52979" + ], + "details": "Uncontrolled Resource Consumption in Elasticsearch while evaluating specifically crafted search templates with Mustache functions can lead to Denial of Service by causing the Elasticsearch node to crash.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52979" + }, + { + "type": "WEB", + "url": "https://discuss.elastic.co/t/elasticsearch-7-17-25-and-8-16-0-security-update-esa-2024-40/377709" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T14:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-mmr7-75gg-rpc3/GHSA-mmr7-75gg-rpc3.json b/advisories/unreviewed/2025/05/GHSA-mmr7-75gg-rpc3/GHSA-mmr7-75gg-rpc3.json new file mode 100644 index 00000000000..6e3b9c4d1e2 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-mmr7-75gg-rpc3/GHSA-mmr7-75gg-rpc3.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mmr7-75gg-rpc3", + "modified": "2025-05-01T15:31:42Z", + "published": "2025-05-01T15:31:42Z", + "aliases": [ + "CVE-2025-37754" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/i915/huc: Fix fence not released on early probe errors\n\nHuC delayed loading fence, introduced with commit 27536e03271da\n(\"drm/i915/huc: track delayed HuC load with a fence\"), is registered with\nobject tracker early on driver probe but unregistered only from driver\nremove, which is not called on early probe errors. Since its memory is\nallocated under devres, then released anyway, it may happen to be\nallocated again to the fence and reused on future driver probes, resulting\nin kernel warnings that taint the kernel:\n\n<4> [309.731371] ------------[ cut here ]------------\n<3> [309.731373] ODEBUG: init destroyed (active state 0) object: ffff88813d7dd2e0 object type: i915_sw_fence hint: sw_fence_dummy_notify+0x0/0x20 [i915]\n<4> [309.731575] WARNING: CPU: 2 PID: 3161 at lib/debugobjects.c:612 debug_print_object+0x93/0xf0\n...\n<4> [309.731693] CPU: 2 UID: 0 PID: 3161 Comm: i915_module_loa Tainted: G U 6.14.0-CI_DRM_16362-gf0fd77956987+ #1\n...\n<4> [309.731700] RIP: 0010:debug_print_object+0x93/0xf0\n...\n<4> [309.731728] Call Trace:\n<4> [309.731730] \n...\n<4> [309.731949] __debug_object_init+0x17b/0x1c0\n<4> [309.731957] debug_object_init+0x34/0x50\n<4> [309.732126] __i915_sw_fence_init+0x34/0x60 [i915]\n<4> [309.732256] intel_huc_init_early+0x4b/0x1d0 [i915]\n<4> [309.732468] intel_uc_init_early+0x61/0x680 [i915]\n<4> [309.732667] intel_gt_common_init_early+0x105/0x130 [i915]\n<4> [309.732804] intel_root_gt_init_early+0x63/0x80 [i915]\n<4> [309.732938] i915_driver_probe+0x1fa/0xeb0 [i915]\n<4> [309.733075] i915_pci_probe+0xe6/0x220 [i915]\n<4> [309.733198] local_pci_probe+0x44/0xb0\n<4> [309.733203] pci_device_probe+0xf4/0x270\n<4> [309.733209] really_probe+0xee/0x3c0\n<4> [309.733215] __driver_probe_device+0x8c/0x180\n<4> [309.733219] driver_probe_device+0x24/0xd0\n<4> [309.733223] __driver_attach+0x10f/0x220\n<4> [309.733230] bus_for_each_dev+0x7d/0xe0\n<4> [309.733236] driver_attach+0x1e/0x30\n<4> [309.733239] bus_add_driver+0x151/0x290\n<4> [309.733244] driver_register+0x5e/0x130\n<4> [309.733247] __pci_register_driver+0x7d/0x90\n<4> [309.733251] i915_pci_register_driver+0x23/0x30 [i915]\n<4> [309.733413] i915_init+0x34/0x120 [i915]\n<4> [309.733655] do_one_initcall+0x62/0x3f0\n<4> [309.733667] do_init_module+0x97/0x2a0\n<4> [309.733671] load_module+0x25ff/0x2890\n<4> [309.733688] init_module_from_file+0x97/0xe0\n<4> [309.733701] idempotent_init_module+0x118/0x330\n<4> [309.733711] __x64_sys_finit_module+0x77/0x100\n<4> [309.733715] x64_sys_call+0x1f37/0x2650\n<4> [309.733719] do_syscall_64+0x91/0x180\n<4> [309.733763] entry_SYSCALL_64_after_hwframe+0x76/0x7e\n<4> [309.733792] \n...\n<4> [309.733806] ---[ end trace 0000000000000000 ]---\n\nThat scenario is most easily reproducible with\nigt@i915_module_load@reload-with-fault-injection.\n\nFix the issue by moving the cleanup step to driver release path.\n\n(cherry picked from commit 795dbde92fe5c6996a02a5b579481de73035e7bf)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37754" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4bd4bf79bcfe101f0385ab81dbabb6e3f7d96c00" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9f5ef4a5eaa61a7a4ed31231da45deb85065397a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c5a906806162aea62dbe5d327760ce3b7117ca17" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e3ea2eae70692a455e256787e4f54153fb739b90" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f104ef4db9f8f3923cc06ed1fafb3da38df6006d" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T13:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-mmv8-63hv-mhrh/GHSA-mmv8-63hv-mhrh.json b/advisories/unreviewed/2025/05/GHSA-mmv8-63hv-mhrh/GHSA-mmv8-63hv-mhrh.json new file mode 100644 index 00000000000..c17cc8f9ac3 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-mmv8-63hv-mhrh/GHSA-mmv8-63hv-mhrh.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mmv8-63hv-mhrh", + "modified": "2025-05-01T15:31:43Z", + "published": "2025-05-01T15:31:43Z", + "aliases": [ + "CVE-2025-37761" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe: Fix an out-of-bounds shift when invalidating TLB\n\nWhen the size of the range invalidated is larger than\nrounddown_pow_of_two(ULONG_MAX),\nThe function macro roundup_pow_of_two(length) will hit an out-of-bounds\nshift [1].\n\nUse a full TLB invalidation for such cases.\nv2:\n- Use a define for the range size limit over which we use a full\n TLB invalidation. (Lucas)\n- Use a better calculation of the limit.\n\n[1]:\n[ 39.202421] ------------[ cut here ]------------\n[ 39.202657] UBSAN: shift-out-of-bounds in ./include/linux/log2.h:57:13\n[ 39.202673] shift exponent 64 is too large for 64-bit type 'long unsigned int'\n[ 39.202688] CPU: 8 UID: 0 PID: 3129 Comm: xe_exec_system_ Tainted: G U 6.14.0+ #10\n[ 39.202690] Tainted: [U]=USER\n[ 39.202690] Hardware name: ASUS System Product Name/PRIME B560M-A AC, BIOS 2001 02/01/2023\n[ 39.202691] Call Trace:\n[ 39.202692] \n[ 39.202695] dump_stack_lvl+0x6e/0xa0\n[ 39.202699] ubsan_epilogue+0x5/0x30\n[ 39.202701] __ubsan_handle_shift_out_of_bounds.cold+0x61/0xe6\n[ 39.202705] xe_gt_tlb_invalidation_range.cold+0x1d/0x3a [xe]\n[ 39.202800] ? find_held_lock+0x2b/0x80\n[ 39.202803] ? mark_held_locks+0x40/0x70\n[ 39.202806] xe_svm_invalidate+0x459/0x700 [xe]\n[ 39.202897] drm_gpusvm_notifier_invalidate+0x4d/0x70 [drm_gpusvm]\n[ 39.202900] __mmu_notifier_release+0x1f5/0x270\n[ 39.202905] exit_mmap+0x40e/0x450\n[ 39.202912] __mmput+0x45/0x110\n[ 39.202914] exit_mm+0xc5/0x130\n[ 39.202916] do_exit+0x21c/0x500\n[ 39.202918] ? lockdep_hardirqs_on_prepare+0xdb/0x190\n[ 39.202920] do_group_exit+0x36/0xa0\n[ 39.202922] get_signal+0x8f8/0x900\n[ 39.202926] arch_do_signal_or_restart+0x35/0x100\n[ 39.202930] syscall_exit_to_user_mode+0x1fc/0x290\n[ 39.202932] do_syscall_64+0xa1/0x180\n[ 39.202934] ? do_user_addr_fault+0x59f/0x8a0\n[ 39.202937] ? lock_release+0xd2/0x2a0\n[ 39.202939] ? do_user_addr_fault+0x5a9/0x8a0\n[ 39.202942] ? trace_hardirqs_off+0x4b/0xc0\n[ 39.202944] ? clear_bhb_loop+0x25/0x80\n[ 39.202946] ? clear_bhb_loop+0x25/0x80\n[ 39.202947] ? clear_bhb_loop+0x25/0x80\n[ 39.202950] entry_SYSCALL_64_after_hwframe+0x76/0x7e\n[ 39.202952] RIP: 0033:0x7fa945e543e1\n[ 39.202961] Code: Unable to access opcode bytes at 0x7fa945e543b7.\n[ 39.202962] RSP: 002b:00007ffca8fb4170 EFLAGS: 00000293\n[ 39.202963] RAX: 000000000000003d RBX: 0000000000000000 RCX: 00007fa945e543e3\n[ 39.202964] RDX: 0000000000000000 RSI: 00007ffca8fb41ac RDI: 00000000ffffffff\n[ 39.202964] RBP: 00007ffca8fb4190 R08: 0000000000000000 R09: 00007fa945f600a0\n[ 39.202965] R10: 0000000000000000 R11: 0000000000000293 R12: 0000000000000000\n[ 39.202966] R13: 00007fa9460dd310 R14: 00007ffca8fb41ac R15: 0000000000000000\n[ 39.202970] \n[ 39.202970] ---[ end trace ]---\n\n(cherry picked from commit b88f48f86500bc0b44b4f73ac66d500a40d320ad)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37761" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/28477f701b63922ff88e9fb13f5519c11cd48b86" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7bcfeddb36b77f9fe3b010bb0b282b7618420bba" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e4715858f87b78ce58cfa03bbe140321edbbaf20" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T14:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-mr7g-g7q3-wvpx/GHSA-mr7g-g7q3-wvpx.json b/advisories/unreviewed/2025/05/GHSA-mr7g-g7q3-wvpx/GHSA-mr7g-g7q3-wvpx.json new file mode 100644 index 00000000000..cf022224f46 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-mr7g-g7q3-wvpx/GHSA-mr7g-g7q3-wvpx.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mr7g-g7q3-wvpx", + "modified": "2025-05-01T15:31:41Z", + "published": "2025-05-01T15:31:41Z", + "aliases": [ + "CVE-2025-23157" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: venus: hfi_parser: add check to avoid out of bound access\n\nThere is a possibility that init_codecs is invoked multiple times during\nmanipulated payload from video firmware. In such case, if codecs_count\ncan get incremented to value more than MAX_CODEC_NUM, there can be OOB\naccess. Reset the count so that it always starts from beginning.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23157" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/172bf5a9ef70a399bb227809db78442dc01d9e48" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/26bbedd06d85770581fda5d78e78539bb088fad1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/53e376178ceacca3ef1795038b22fc9ef45ff1d3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b2541e29d82da8a0df728aadec3e0a8db55d517b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cb5be9039f91979f8a2fac29f529f746d7848f3e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d4d88ece4ba91df5b02f1d3f599650f9e9fc0f45" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T13:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-mrf4-wfh4-qj5w/GHSA-mrf4-wfh4-qj5w.json b/advisories/unreviewed/2025/05/GHSA-mrf4-wfh4-qj5w/GHSA-mrf4-wfh4-qj5w.json new file mode 100644 index 00000000000..185040f78da --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-mrf4-wfh4-qj5w/GHSA-mrf4-wfh4-qj5w.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mrf4-wfh4-qj5w", + "modified": "2025-05-01T15:31:45Z", + "published": "2025-05-01T15:31:45Z", + "aliases": [ + "CVE-2025-37794" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: Purge vif txq in ieee80211_do_stop()\n\nAfter ieee80211_do_stop() SKB from vif's txq could still be processed.\nIndeed another concurrent vif schedule_and_wake_txq call could cause\nthose packets to be dequeued (see ieee80211_handle_wake_tx_queue())\nwithout checking the sdata current state.\n\nBecause vif.drv_priv is now cleared in this function, this could lead to\ndriver crash.\n\nFor example in ath12k, ahvif is store in vif.drv_priv. Thus if\nath12k_mac_op_tx() is called after ieee80211_do_stop(), ahvif->ah can be\nNULL, leading the ath12k_warn(ahvif->ah,...) call in this function to\ntrigger the NULL deref below.\n\n Unable to handle kernel paging request at virtual address dfffffc000000001\n KASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f]\n batman_adv: bat0: Interface deactivated: brbh1337\n Mem abort info:\n ESR = 0x0000000096000004\n EC = 0x25: DABT (current EL), IL = 32 bits\n SET = 0, FnV = 0\n EA = 0, S1PTW = 0\n FSC = 0x04: level 0 translation fault\n Data abort info:\n ISV = 0, ISS = 0x00000004, ISS2 = 0x00000000\n CM = 0, WnR = 0, TnD = 0, TagAccess = 0\n GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0\n [dfffffc000000001] address between user and kernel address ranges\n Internal error: Oops: 0000000096000004 [#1] SMP\n CPU: 1 UID: 0 PID: 978 Comm: lbd Not tainted 6.13.0-g633f875b8f1e #114\n Hardware name: HW (DT)\n pstate: 10000005 (nzcV daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n pc : ath12k_mac_op_tx+0x6cc/0x29b8 [ath12k]\n lr : ath12k_mac_op_tx+0x174/0x29b8 [ath12k]\n sp : ffffffc086ace450\n x29: ffffffc086ace450 x28: 0000000000000000 x27: 1ffffff810d59ca4\n x26: ffffff801d05f7c0 x25: 0000000000000000 x24: 000000004000001e\n x23: ffffff8009ce4926 x22: ffffff801f9c0800 x21: ffffff801d05f7f0\n x20: ffffff8034a19f40 x19: 0000000000000000 x18: ffffff801f9c0958\n x17: ffffff800bc0a504 x16: dfffffc000000000 x15: ffffffc086ace4f8\n x14: ffffff801d05f83c x13: 0000000000000000 x12: ffffffb003a0bf03\n x11: 0000000000000000 x10: ffffffb003a0bf02 x9 : ffffff8034a19f40\n x8 : ffffff801d05f818 x7 : 1ffffff0069433dc x6 : ffffff8034a19ee0\n x5 : ffffff801d05f7f0 x4 : 0000000000000000 x3 : 0000000000000001\n x2 : 0000000000000000 x1 : dfffffc000000000 x0 : 0000000000000008\n Call trace:\n ath12k_mac_op_tx+0x6cc/0x29b8 [ath12k] (P)\n ieee80211_handle_wake_tx_queue+0x16c/0x260\n ieee80211_queue_skb+0xeec/0x1d20\n ieee80211_tx+0x200/0x2c8\n ieee80211_xmit+0x22c/0x338\n __ieee80211_subif_start_xmit+0x7e8/0xc60\n ieee80211_subif_start_xmit+0xc4/0xee0\n __ieee80211_subif_start_xmit_8023.isra.0+0x854/0x17a0\n ieee80211_subif_start_xmit_8023+0x124/0x488\n dev_hard_start_xmit+0x160/0x5a8\n __dev_queue_xmit+0x6f8/0x3120\n br_dev_queue_push_xmit+0x120/0x4a8\n __br_forward+0xe4/0x2b0\n deliver_clone+0x5c/0xd0\n br_flood+0x398/0x580\n br_dev_xmit+0x454/0x9f8\n dev_hard_start_xmit+0x160/0x5a8\n __dev_queue_xmit+0x6f8/0x3120\n ip6_finish_output2+0xc28/0x1b60\n __ip6_finish_output+0x38c/0x638\n ip6_output+0x1b4/0x338\n ip6_local_out+0x7c/0xa8\n ip6_send_skb+0x7c/0x1b0\n ip6_push_pending_frames+0x94/0xd0\n rawv6_sendmsg+0x1a98/0x2898\n inet_sendmsg+0x94/0xe0\n __sys_sendto+0x1e4/0x308\n __arm64_sys_sendto+0xc4/0x140\n do_el0_svc+0x110/0x280\n el0_svc+0x20/0x60\n el0t_64_sync_handler+0x104/0x138\n el0t_64_sync+0x154/0x158\n\nTo avoid that, empty vif's txq at ieee80211_do_stop() so no packet could\nbe dequeued after ieee80211_do_stop() (new packets cannot be queued\nbecause SDATA_STATE_RUNNING is cleared at this point).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37794" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/378677eb8f44621ecc9ce659f7af61e5baa94d81" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5f6863dc407f25fcf23fc857f9ac51756a09ea2c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8bc34db7f771a464ff8f686b6f8d4e04963fec27" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a8df245b5b29f6de98d016dc18e2bb35ec70b0cb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c74b84544dee27298a71715b3ce2c40d372b5a23" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T14:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-mrq3-qx26-xjxj/GHSA-mrq3-qx26-xjxj.json b/advisories/unreviewed/2025/05/GHSA-mrq3-qx26-xjxj/GHSA-mrq3-qx26-xjxj.json new file mode 100644 index 00000000000..df84a20585a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-mrq3-qx26-xjxj/GHSA-mrq3-qx26-xjxj.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mrq3-qx26-xjxj", + "modified": "2025-05-01T15:31:44Z", + "published": "2025-05-01T15:31:44Z", + "aliases": [ + "CVE-2025-37781" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ni2c: cros-ec-tunnel: defer probe if parent EC is not present\n\nWhen i2c-cros-ec-tunnel and the EC driver are built-in, the EC parent\ndevice will not be found, leading to NULL pointer dereference.\n\nThat can also be reproduced by unbinding the controller driver and then\nloading i2c-cros-ec-tunnel module (or binding the device).\n\n[ 271.991245] BUG: kernel NULL pointer dereference, address: 0000000000000058\n[ 271.998215] #PF: supervisor read access in kernel mode\n[ 272.003351] #PF: error_code(0x0000) - not-present page\n[ 272.008485] PGD 0 P4D 0\n[ 272.011022] Oops: Oops: 0000 [#1] SMP NOPTI\n[ 272.015207] CPU: 0 UID: 0 PID: 3859 Comm: insmod Tainted: G S 6.15.0-rc1-00004-g44722359ed83 #30 PREEMPT(full) 3c7fb39a552e7d949de2ad921a7d6588d3a4fdc5\n[ 272.030312] Tainted: [S]=CPU_OUT_OF_SPEC\n[ 272.034233] Hardware name: HP Berknip/Berknip, BIOS Google_Berknip.13434.356.0 05/17/2021\n[ 272.042400] RIP: 0010:ec_i2c_probe+0x2b/0x1c0 [i2c_cros_ec_tunnel]\n[ 272.048577] Code: 1f 44 00 00 41 57 41 56 41 55 41 54 53 48 83 ec 10 65 48 8b 05 06 a0 6c e7 48 89 44 24 08 4c 8d 7f 10 48 8b 47 50 4c 8b 60 78 <49> 83 7c 24 58 00 0f 84 2f 01 00 00 48 89 fb be 30 06 00 00 4c 9\n[ 272.067317] RSP: 0018:ffffa32082a03940 EFLAGS: 00010282\n[ 272.072541] RAX: ffff969580b6a810 RBX: ffff969580b68c10 RCX: 0000000000000000\n[ 272.079672] RDX: 0000000000000000 RSI: 0000000000000282 RDI: ffff969580b68c00\n[ 272.086804] RBP: 00000000fffffdfb R08: 0000000000000000 R09: 0000000000000000\n[ 272.093936] R10: 0000000000000000 R11: ffffffffc0600000 R12: 0000000000000000\n[ 272.101067] R13: ffffffffa666fbb8 R14: ffffffffc05b5528 R15: ffff969580b68c10\n[ 272.108198] FS: 00007b930906fc40(0000) GS:ffff969603149000(0000) knlGS:0000000000000000\n[ 272.116282] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 272.122024] CR2: 0000000000000058 CR3: 000000012631c000 CR4: 00000000003506f0\n[ 272.129155] Call Trace:\n[ 272.131606] \n[ 272.133709] ? acpi_dev_pm_attach+0xdd/0x110\n[ 272.137985] platform_probe+0x69/0xa0\n[ 272.141652] really_probe+0x152/0x310\n[ 272.145318] __driver_probe_device+0x77/0x110\n[ 272.149678] driver_probe_device+0x1e/0x190\n[ 272.153864] __driver_attach+0x10b/0x1e0\n[ 272.157790] ? driver_attach+0x20/0x20\n[ 272.161542] bus_for_each_dev+0x107/0x150\n[ 272.165553] bus_add_driver+0x15d/0x270\n[ 272.169392] driver_register+0x65/0x110\n[ 272.173232] ? cleanup_module+0xa80/0xa80 [i2c_cros_ec_tunnel 3a00532f3f4af4a9eade753f86b0f8dd4e4e5698]\n[ 272.182617] do_one_initcall+0x110/0x350\n[ 272.186543] ? security_kernfs_init_security+0x49/0xd0\n[ 272.191682] ? __kernfs_new_node+0x1b9/0x240\n[ 272.195954] ? security_kernfs_init_security+0x49/0xd0\n[ 272.201093] ? __kernfs_new_node+0x1b9/0x240\n[ 272.205365] ? kernfs_link_sibling+0x105/0x130\n[ 272.209810] ? kernfs_next_descendant_post+0x1c/0xa0\n[ 272.214773] ? kernfs_activate+0x57/0x70\n[ 272.218699] ? kernfs_add_one+0x118/0x160\n[ 272.222710] ? __kernfs_create_file+0x71/0xa0\n[ 272.227069] ? sysfs_add_bin_file_mode_ns+0xd6/0x110\n[ 272.232033] ? internal_create_group+0x453/0x4a0\n[ 272.236651] ? __vunmap_range_noflush+0x214/0x2d0\n[ 272.241355] ? __free_frozen_pages+0x1dc/0x420\n[ 272.245799] ? free_vmap_area_noflush+0x10a/0x1c0\n[ 272.250505] ? load_module+0x1509/0x16f0\n[ 272.254431] do_init_module+0x60/0x230\n[ 272.258181] __se_sys_finit_module+0x27a/0x370\n[ 272.262627] do_syscall_64+0x6a/0xf0\n[ 272.266206] ? do_syscall_64+0x76/0xf0\n[ 272.269956] ? irqentry_exit_to_user_mode+0x79/0x90\n[ 272.274836] entry_SYSCALL_64_after_hwframe+0x55/0x5d\n[ 272.279887] RIP: 0033:0x7b9309168d39\n[ 272.283466] Code: 5b 41 5c 5d c3 66 2e 0f 1f 84 00 00 00 00 00 66 90 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 8b 0d af 40 0c 00 f7 d8 64 89 01 8\n[ 272.302210] RSP: 002b:00007fff50f1a288 EFLAGS: 00000246 ORIG_RAX: 000\n---truncated---", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37781" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1355b5ca4782be85a2ef7275e4c508f770d0fb27" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3090cad5ccff8963b95160f4060068048a1e4c4c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/424eafe65647a8d6c690284536e711977153195a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/da8edc9eb2516aface7f86be5fa6d09c0d07b9f8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e89bf1311d4497c6743f3021e9c481b16c3a41c9" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T14:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-mv8v-9jrg-2c2w/GHSA-mv8v-9jrg-2c2w.json b/advisories/unreviewed/2025/05/GHSA-mv8v-9jrg-2c2w/GHSA-mv8v-9jrg-2c2w.json new file mode 100644 index 00000000000..45ba07bbc05 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-mv8v-9jrg-2c2w/GHSA-mv8v-9jrg-2c2w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mv8v-9jrg-2c2w", + "modified": "2025-05-01T15:31:43Z", + "published": "2025-05-01T15:31:43Z", + "aliases": [ + "CVE-2024-11390" + ], + "details": "Unrestricted upload of a file with dangerous type in Kibana can lead to arbitrary JavaScript execution in a victim’s browser (XSS) via crafted HTML and JavaScript files.\n\nThe attacker must have access to the Synthetics app AND/OR have access to write to the synthetics indices.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11390" + }, + { + "type": "WEB", + "url": "https://discuss.elastic.co/t/kibana-7-17-24-and-8-12-0-security-update-esa-2024-20/377712" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T14:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-mw9j-m44f-pxpp/GHSA-mw9j-m44f-pxpp.json b/advisories/unreviewed/2025/05/GHSA-mw9j-m44f-pxpp/GHSA-mw9j-m44f-pxpp.json new file mode 100644 index 00000000000..74c61c6bdeb --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-mw9j-m44f-pxpp/GHSA-mw9j-m44f-pxpp.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mw9j-m44f-pxpp", + "modified": "2025-05-01T15:31:52Z", + "published": "2025-05-01T15:31:51Z", + "aliases": [ + "CVE-2022-49898" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix tree mod log mishandling of reallocated nodes\n\nWe have been seeing the following panic in production\n\n kernel BUG at fs/btrfs/tree-mod-log.c:677!\n invalid opcode: 0000 [#1] SMP\n RIP: 0010:tree_mod_log_rewind+0x1b4/0x200\n RSP: 0000:ffffc9002c02f890 EFLAGS: 00010293\n RAX: 0000000000000003 RBX: ffff8882b448c700 RCX: 0000000000000000\n RDX: 0000000000008000 RSI: 00000000000000a7 RDI: ffff88877d831c00\n RBP: 0000000000000002 R08: 000000000000009f R09: 0000000000000000\n R10: 0000000000000000 R11: 0000000000100c40 R12: 0000000000000001\n R13: ffff8886c26d6a00 R14: ffff88829f5424f8 R15: ffff88877d831a00\n FS: 00007fee1d80c780(0000) GS:ffff8890400c0000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 00007fee1963a020 CR3: 0000000434f33002 CR4: 00000000007706e0\n DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n PKRU: 55555554\n Call Trace:\n btrfs_get_old_root+0x12b/0x420\n btrfs_search_old_slot+0x64/0x2f0\n ? tree_mod_log_oldest_root+0x3d/0xf0\n resolve_indirect_ref+0xfd/0x660\n ? ulist_alloc+0x31/0x60\n ? kmem_cache_alloc_trace+0x114/0x2c0\n find_parent_nodes+0x97a/0x17e0\n ? ulist_alloc+0x30/0x60\n btrfs_find_all_roots_safe+0x97/0x150\n iterate_extent_inodes+0x154/0x370\n ? btrfs_search_path_in_tree+0x240/0x240\n iterate_inodes_from_logical+0x98/0xd0\n ? btrfs_search_path_in_tree+0x240/0x240\n btrfs_ioctl_logical_to_ino+0xd9/0x180\n btrfs_ioctl+0xe2/0x2ec0\n ? __mod_memcg_lruvec_state+0x3d/0x280\n ? do_sys_openat2+0x6d/0x140\n ? kretprobe_dispatcher+0x47/0x70\n ? kretprobe_rethook_handler+0x38/0x50\n ? rethook_trampoline_handler+0x82/0x140\n ? arch_rethook_trampoline_callback+0x3b/0x50\n ? kmem_cache_free+0xfb/0x270\n ? do_sys_openat2+0xd5/0x140\n __x64_sys_ioctl+0x71/0xb0\n do_syscall_64+0x2d/0x40\n\nWhich is this code in tree_mod_log_rewind()\n\n\tswitch (tm->op) {\n case BTRFS_MOD_LOG_KEY_REMOVE_WHILE_FREEING:\n\t\tBUG_ON(tm->slot < n);\n\nThis occurs because we replay the nodes in order that they happened, and\nwhen we do a REPLACE we will log a REMOVE_WHILE_FREEING for every slot,\nstarting at 0. 'n' here is the number of items in this block, which in\nthis case was 1, but we had 2 REMOVE_WHILE_FREEING operations.\n\nThe actual root cause of this was that we were replaying operations for\na block that shouldn't have been replayed. Consider the following\nsequence of events\n\n1. We have an already modified root, and we do a btrfs_get_tree_mod_seq().\n2. We begin removing items from this root, triggering KEY_REPLACE for\n it's child slots.\n3. We remove one of the 2 children this root node points to, thus triggering\n the root node promotion of the remaining child, and freeing this node.\n4. We modify a new root, and re-allocate the above node to the root node of\n this other root.\n\nThe tree mod log looks something like this\n\n\tlogical 0\top KEY_REPLACE (slot 1)\t\t\tseq 2\n\tlogical 0\top KEY_REMOVE (slot 1)\t\t\tseq 3\n\tlogical 0\top KEY_REMOVE_WHILE_FREEING (slot 0)\tseq 4\n\tlogical 4096\top LOG_ROOT_REPLACE (old logical 0)\tseq 5\n\tlogical 8192\top KEY_REMOVE_WHILE_FREEING (slot 1)\tseq 6\n\tlogical 8192\top KEY_REMOVE_WHILE_FREEING (slot 0)\tseq 7\n\tlogical 0\top LOG_ROOT_REPLACE (old logical 8192)\tseq 8\n\n>From here the bug is triggered by the following steps\n\n1. Call btrfs_get_old_root() on the new_root.\n2. We call tree_mod_log_oldest_root(btrfs_root_node(new_root)), which is\n currently logical 0.\n3. tree_mod_log_oldest_root() calls tree_mod_log_search_oldest(), which\n gives us the KEY_REPLACE seq 2, and since that's not a\n LOG_ROOT_REPLACE we incorrectly believe that we don't have an old\n root, because we expect that the most recent change should be a\n LOG_ROOT_REPLACE.\n4. Back in tree_mod_log_oldest_root() we don't have a LOG_ROOT_REPLACE,\n so we don't set old_root, we simply use our e\n---truncated---", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49898" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/007058eb8292efc4c88f921752194b83269da085" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/52b2b65c9eb56fd829dda323786db828627ff7e6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/968b71583130b6104c9f33ba60446d598e327a8b" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-mx7w-69f4-mg2q/GHSA-mx7w-69f4-mg2q.json b/advisories/unreviewed/2025/05/GHSA-mx7w-69f4-mg2q/GHSA-mx7w-69f4-mg2q.json new file mode 100644 index 00000000000..c067c2d699e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-mx7w-69f4-mg2q/GHSA-mx7w-69f4-mg2q.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mx7w-69f4-mg2q", + "modified": "2025-05-01T15:31:53Z", + "published": "2025-05-01T15:31:53Z", + "aliases": [ + "CVE-2022-49925" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/core: Fix null-ptr-deref in ib_core_cleanup()\n\nKASAN reported a null-ptr-deref error:\n\n KASAN: null-ptr-deref in range [0x0000000000000118-0x000000000000011f]\n CPU: 1 PID: 379\n Hardware name: QEMU Standard PC (i440FX + PIIX, 1996)\n RIP: 0010:destroy_workqueue+0x2f/0x740\n RSP: 0018:ffff888016137df8 EFLAGS: 00000202\n ...\n Call Trace:\n ib_core_cleanup+0xa/0xa1 [ib_core]\n __do_sys_delete_module.constprop.0+0x34f/0x5b0\n do_syscall_64+0x3a/0x90\n entry_SYSCALL_64_after_hwframe+0x63/0xcd\n RIP: 0033:0x7fa1a0d221b7\n ...\n\nIt is because the fail of roce_gid_mgmt_init() is ignored:\n\n ib_core_init()\n roce_gid_mgmt_init()\n gid_cache_wq = alloc_ordered_workqueue # fail\n ...\n ib_core_cleanup()\n roce_gid_mgmt_cleanup()\n destroy_workqueue(gid_cache_wq)\n # destroy an unallocated wq\n\nFix this by catching the fail of roce_gid_mgmt_init() in ib_core_init().", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49925" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/07c0d131cc0fe1f3981a42958fc52d573d303d89" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6b3d5dcb12347f3518308c2c9d2cf72453a3e1e5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ab817f75e5e0fa58d9be0825da6a7b7d8a1fa1d9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/af8fb5a0600e9ae29950e9422a032c3c22649ee5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d360e875c011a005628525bf290322058927e7dc" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-mx8w-x2cj-333g/GHSA-mx8w-x2cj-333g.json b/advisories/unreviewed/2025/05/GHSA-mx8w-x2cj-333g/GHSA-mx8w-x2cj-333g.json new file mode 100644 index 00000000000..ef15e1c332b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-mx8w-x2cj-333g/GHSA-mx8w-x2cj-333g.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mx8w-x2cj-333g", + "modified": "2025-05-01T15:31:49Z", + "published": "2025-05-01T15:31:49Z", + "aliases": [ + "CVE-2022-49851" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nriscv: fix reserved memory setup\n\nCurrently, RISC-V sets up reserved memory using the \"early\" copy of the\ndevice tree. As a result, when trying to get a reserved memory region\nusing of_reserved_mem_lookup(), the pointer to reserved memory regions\nis using the early, pre-virtual-memory address which causes a kernel\npanic when trying to use the buffer's name:\n\n Unable to handle kernel paging request at virtual address 00000000401c31ac\n Oops [#1]\n Modules linked in:\n CPU: 0 PID: 0 Comm: swapper Not tainted 6.0.0-rc1-00001-g0d9d6953d834 #1\n Hardware name: Microchip PolarFire-SoC Icicle Kit (DT)\n epc : string+0x4a/0xea\n ra : vsnprintf+0x1e4/0x336\n epc : ffffffff80335ea0 ra : ffffffff80338936 sp : ffffffff81203be0\n gp : ffffffff812e0a98 tp : ffffffff8120de40 t0 : 0000000000000000\n t1 : ffffffff81203e28 t2 : 7265736572203a46 s0 : ffffffff81203c20\n s1 : ffffffff81203e28 a0 : ffffffff81203d22 a1 : 0000000000000000\n a2 : ffffffff81203d08 a3 : 0000000081203d21 a4 : ffffffffffffffff\n a5 : 00000000401c31ac a6 : ffff0a00ffffff04 a7 : ffffffffffffffff\n s2 : ffffffff81203d08 s3 : ffffffff81203d00 s4 : 0000000000000008\n s5 : ffffffff000000ff s6 : 0000000000ffffff s7 : 00000000ffffff00\n s8 : ffffffff80d9821a s9 : ffffffff81203d22 s10: 0000000000000002\n s11: ffffffff80d9821c t3 : ffffffff812f3617 t4 : ffffffff812f3617\n t5 : ffffffff812f3618 t6 : ffffffff81203d08\n status: 0000000200000100 badaddr: 00000000401c31ac cause: 000000000000000d\n [] vsnprintf+0x1e4/0x336\n [] vprintk_store+0xf6/0x344\n [] vprintk_emit+0x56/0x192\n [] vprintk_default+0x16/0x1e\n [] vprintk+0x72/0x80\n [] _printk+0x36/0x50\n [] print_reserved_mem+0x1c/0x24\n [] paging_init+0x528/0x5bc\n [] setup_arch+0xd0/0x592\n [] start_kernel+0x82/0x73c\n\nearly_init_fdt_scan_reserved_mem() takes no arguments as it operates on\ninitial_boot_params, which is populated by early_init_dt_verify(). On\nRISC-V, early_init_dt_verify() is called twice. Once, directly, in\nsetup_arch() if CONFIG_BUILTIN_DTB is not enabled and once indirectly,\nvery early in the boot process, by parse_dtb() when it calls\nearly_init_dt_scan_nodes().\n\nThis first call uses dtb_early_va to set initial_boot_params, which is\nnot usable later in the boot process when\nearly_init_fdt_scan_reserved_mem() is called. On arm64 for example, the\ncorresponding call to early_init_dt_scan_nodes() uses fixmap addresses\nand doesn't suffer the same fate.\n\nMove early_init_fdt_scan_reserved_mem() further along the boot sequence,\nafter the direct call to early_init_dt_verify() in setup_arch() so that\nthe names use the correct virtual memory addresses. The above supposed\nthat CONFIG_BUILTIN_DTB was not set, but should work equally in the case\nwhere it is - unflatted_and_copy_device_tree() also updates\ninitial_boot_params.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49851" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/50e63dd8ed92045eb70a72d7ec725488320fb68b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/518e49f0590de66555503aabe199ba8d3f2e24ac" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/93598deb101540c4f9e7de15099ea8255b965fc2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/94ab8f88feb75e3b1486102c0c9c550f37d9d137" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-p267-6p34-qmhj/GHSA-p267-6p34-qmhj.json b/advisories/unreviewed/2025/05/GHSA-p267-6p34-qmhj/GHSA-p267-6p34-qmhj.json new file mode 100644 index 00000000000..6ca62863ad4 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-p267-6p34-qmhj/GHSA-p267-6p34-qmhj.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p267-6p34-qmhj", + "modified": "2025-05-01T15:31:43Z", + "published": "2025-05-01T15:31:43Z", + "aliases": [ + "CVE-2025-37757" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: fix memory leak in tipc_link_xmit\n\nIn case the backlog transmit queue for system-importance messages is overloaded,\ntipc_link_xmit() returns -ENOBUFS but the skb list is not purged. This leads to\nmemory leak and failure when a skb is allocated.\n\nThis commit fixes this issue by purging the skb list before tipc_link_xmit()\nreturns.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37757" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/09c2dcda2c551bba30710c33f6ac678ae7395389" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/24e6280cdd7f8d01fc6b9b365fb800c2fb7ea9bb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/69ae94725f4fc9e75219d2d69022029c5b24bc9a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7c5957f7905b4aede9d7a559d271438f3ca9e852" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a40cbfbb8f95c325430f017883da669b2aa927d4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d0e02d3d27a0b4dcb13f954f537ca1dd8f282dcf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T13:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-p39f-f66f-x437/GHSA-p39f-f66f-x437.json b/advisories/unreviewed/2025/05/GHSA-p39f-f66f-x437/GHSA-p39f-f66f-x437.json new file mode 100644 index 00000000000..8eacbd64578 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-p39f-f66f-x437/GHSA-p39f-f66f-x437.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p39f-f66f-x437", + "modified": "2025-05-01T15:31:51Z", + "published": "2025-05-01T15:31:51Z", + "aliases": [ + "CVE-2022-49878" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf, verifier: Fix memory leak in array reallocation for stack state\n\nIf an error (NULL) is returned by krealloc(), callers of realloc_array()\nwere setting their allocation pointers to NULL, but on error krealloc()\ndoes not touch the original allocation. This would result in a memory\nresource leak. Instead, free the old allocation on the error handling\npath.\n\nThe memory leak information is as follows as also reported by Zhengchao:\n\n unreferenced object 0xffff888019801800 (size 256):\n comm \"bpf_repo\", pid 6490, jiffies 4294959200 (age 17.170s)\n hex dump (first 32 bytes):\n 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n backtrace:\n [<00000000b211474b>] __kmalloc_node_track_caller+0x45/0xc0\n [<0000000086712a0b>] krealloc+0x83/0xd0\n [<00000000139aab02>] realloc_array+0x82/0xe2\n [<00000000b1ca41d1>] grow_stack_state+0xfb/0x186\n [<00000000cd6f36d2>] check_mem_access.cold+0x141/0x1341\n [<0000000081780455>] do_check_common+0x5358/0xb350\n [<0000000015f6b091>] bpf_check.cold+0xc3/0x29d\n [<000000002973c690>] bpf_prog_load+0x13db/0x2240\n [<00000000028d1644>] __sys_bpf+0x1605/0x4ce0\n [<00000000053f29bd>] __x64_sys_bpf+0x75/0xb0\n [<0000000056fedaf5>] do_syscall_64+0x35/0x80\n [<000000002bd58261>] entry_SYSCALL_64_after_hwframe+0x63/0xcd", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49878" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/06615967d4889b08b19ff3dda96e8b131282f73d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3e210891c4a4c2d858cd6f9f61d5809af251d4df" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/42378a9ca55347102bbf86708776061d8fe3ece2" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-p4vj-hhfc-5j8x/GHSA-p4vj-hhfc-5j8x.json b/advisories/unreviewed/2025/05/GHSA-p4vj-hhfc-5j8x/GHSA-p4vj-hhfc-5j8x.json new file mode 100644 index 00000000000..02a7cba479a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-p4vj-hhfc-5j8x/GHSA-p4vj-hhfc-5j8x.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p4vj-hhfc-5j8x", + "modified": "2025-05-01T15:31:43Z", + "published": "2025-05-01T15:31:43Z", + "aliases": [ + "CVE-2025-37760" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/vma: add give_up_on_oom option on modify/merge, use in uffd release\n\nCurrently, if a VMA merge fails due to an OOM condition arising on commit\nmerge or a failure to duplicate anon_vma's, we report this so the caller\ncan handle it.\n\nHowever there are cases where the caller is only ostensibly trying a\nmerge, and doesn't mind if it fails due to this condition.\n\nSince we do not want to introduce an implicit assumption that we only\nactually modify VMAs after OOM conditions might arise, add a 'give up on\noom' option and make an explicit contract that, should this flag be set, we\nabsolutely will not modify any VMAs should OOM arise and just bail out.\n\nSince it'd be very unusual for a user to try to vma_modify() with this flag\nset but be specifying a range within a VMA which ends up being split (which\ncan fail due to rlimit issues, not only OOM), we add a debug warning for\nthis condition.\n\nThe motivating reason for this is uffd release - syzkaller (and Pedro\nFalcato's VERY astute analysis) found a way in which an injected fault on\nallocation, triggering an OOM condition on commit merge, would result in\nuffd code becoming confused and treating an error value as if it were a VMA\npointer.\n\nTo avoid this, we make use of this new VMG flag to ensure that this never\noccurs, utilising the fact that, should we be clearing entire VMAs, we do\nnot wish an OOM event to be reported to us.\n\nMany thanks to Pedro Falcato for his excellent analysis and Jann Horn for\nhis insightful and intelligent analysis of the situation, both of whom were\ninstrumental in this fix.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37760" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/41e6ddcaa0f18dda4c3fadf22533775a30d6f72f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b906c1ad25adce6ff35be19b65a1aa7d960fe1d7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c103a75c61648203d731e3b97a6fbeea4003cb15" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T14:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-p574-w2vr-cgv8/GHSA-p574-w2vr-cgv8.json b/advisories/unreviewed/2025/05/GHSA-p574-w2vr-cgv8/GHSA-p574-w2vr-cgv8.json new file mode 100644 index 00000000000..8f04eb37370 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-p574-w2vr-cgv8/GHSA-p574-w2vr-cgv8.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p574-w2vr-cgv8", + "modified": "2025-05-01T15:31:53Z", + "published": "2025-05-01T15:31:53Z", + "aliases": [ + "CVE-2022-49929" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/rxe: Fix mr leak in RESPST_ERR_RNR\n\nrxe_recheck_mr() will increase mr's ref_cnt, so we should call rxe_put(mr)\nto drop mr's ref_cnt in RESPST_ERR_RNR to avoid below warning:\n\n WARNING: CPU: 0 PID: 4156 at drivers/infiniband/sw/rxe/rxe_pool.c:259 __rxe_cleanup+0x1df/0x240 [rdma_rxe]\n...\n Call Trace:\n rxe_dereg_mr+0x4c/0x60 [rdma_rxe]\n ib_dereg_mr_user+0xa8/0x200 [ib_core]\n ib_mr_pool_destroy+0x77/0xb0 [ib_core]\n nvme_rdma_destroy_queue_ib+0x89/0x240 [nvme_rdma]\n nvme_rdma_free_queue+0x40/0x50 [nvme_rdma]\n nvme_rdma_teardown_io_queues.part.0+0xc3/0x120 [nvme_rdma]\n nvme_rdma_error_recovery_work+0x4d/0xf0 [nvme_rdma]\n process_one_work+0x582/0xa40\n ? pwq_dec_nr_in_flight+0x100/0x100\n ? rwlock_bug.part.0+0x60/0x60\n worker_thread+0x2a9/0x700\n ? process_one_work+0xa40/0xa40\n kthread+0x168/0x1a0\n ? kthread_complete_and_exit+0x20/0x20\n ret_from_fork+0x22/0x30", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49929" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/50b35ad2864a9d66f802f9ce193d99bbef64e219" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b5f9a01fae42684648c2ee3cd9985f80c67ab9f7" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-p59w-r597-mmwf/GHSA-p59w-r597-mmwf.json b/advisories/unreviewed/2025/05/GHSA-p59w-r597-mmwf/GHSA-p59w-r597-mmwf.json new file mode 100644 index 00000000000..919f82be465 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-p59w-r597-mmwf/GHSA-p59w-r597-mmwf.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p59w-r597-mmwf", + "modified": "2025-05-01T15:31:50Z", + "published": "2025-05-01T15:31:50Z", + "aliases": [ + "CVE-2022-49873" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix wrong reg type conversion in release_reference()\n\nSome helper functions will allocate memory. To avoid memory leaks, the\nverifier requires the eBPF program to release these memories by calling\nthe corresponding helper functions.\n\nWhen a resource is released, all pointer registers corresponding to the\nresource should be invalidated. The verifier use release_references() to\ndo this job, by apply __mark_reg_unknown() to each relevant register.\n\nIt will give these registers the type of SCALAR_VALUE. A register that\nwill contain a pointer value at runtime, but of type SCALAR_VALUE, which\nmay allow the unprivileged user to get a kernel pointer by storing this\nregister into a map.\n\nUsing __mark_reg_not_init() while NOT allow_ptr_leaks can mitigate this\nproblem.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49873" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/466ce46f251dfb259a8cbaa895ab9edd6fb56240" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ae5ccad6c711db0f2ca1231be051935dd128b8f5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cedd4f01f67be94735f15123158f485028571037" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f1db20814af532f85e091231223e5e4818e8464b" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-p69q-m87v-6q9x/GHSA-p69q-m87v-6q9x.json b/advisories/unreviewed/2025/05/GHSA-p69q-m87v-6q9x/GHSA-p69q-m87v-6q9x.json new file mode 100644 index 00000000000..d24dad23c74 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-p69q-m87v-6q9x/GHSA-p69q-m87v-6q9x.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p69q-m87v-6q9x", + "modified": "2025-05-01T15:31:45Z", + "published": "2025-05-01T15:31:45Z", + "aliases": [ + "CVE-2025-37793" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: Intel: avs: Fix null-ptr-deref in avs_component_probe()\n\ndevm_kasprintf() returns NULL when memory allocation fails. Currently,\navs_component_probe() does not check for this case, which results in a\nNULL pointer dereference.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37793" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/23fde311ea1d0a6c36bf92ce48b90b77d0ece1a4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/95f723cf141b95e3b3a5b92cf2ea98a863fe7275" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/aaa93b8846101461de815759d39979661b82d5a5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c2825073271b6f15e669a424b363612082494863" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T14:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-p892-989h-g84m/GHSA-p892-989h-g84m.json b/advisories/unreviewed/2025/05/GHSA-p892-989h-g84m/GHSA-p892-989h-g84m.json new file mode 100644 index 00000000000..c1a20f5b851 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-p892-989h-g84m/GHSA-p892-989h-g84m.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p892-989h-g84m", + "modified": "2025-05-01T15:31:48Z", + "published": "2025-05-01T15:31:48Z", + "aliases": [ + "CVE-2022-49818" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmISDN: fix misuse of put_device() in mISDN_register_device()\n\nWe should not release reference by put_device() before calling device_initialize().", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49818" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2d25107e111a85c56f601a5470f1780ec054e6ac" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/44658d65f6b3118f595a1229d7eed74845a5e2ac" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/596230471da3415e92ae6b9d2a4e26f4a81cac5a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/709aa1f73d3e9e9ea16e2c4e44f2874c5d2c382c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/81db4f182744acd004f17d7cc52dde9ea53467e6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/83672c1b83d107b0d4fe0accf1bf64d8988398e6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/87b336aa158201dc30a318431e63e8c5b26c4156" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d40b35a7922f4df3767ad6fb8ef3dc86e31d7ba3" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-p93v-94fp-qv28/GHSA-p93v-94fp-qv28.json b/advisories/unreviewed/2025/05/GHSA-p93v-94fp-qv28/GHSA-p93v-94fp-qv28.json new file mode 100644 index 00000000000..d1a740f7d2a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-p93v-94fp-qv28/GHSA-p93v-94fp-qv28.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p93v-94fp-qv28", + "modified": "2025-05-01T15:31:43Z", + "published": "2025-05-01T15:31:43Z", + "aliases": [ + "CVE-2024-11994" + ], + "details": "APM server logs could contain parts of the document body from a partially failed bulk index request. Depending on the nature of the document, this could disclose sensitive information in APM Server error logs.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11994" + }, + { + "type": "WEB", + "url": "https://discuss.elastic.co/t/apm-server-8-16-1-security-update-esa-2024-41/377710" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T14:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-p98w-xrc8-4w6x/GHSA-p98w-xrc8-4w6x.json b/advisories/unreviewed/2025/05/GHSA-p98w-xrc8-4w6x/GHSA-p98w-xrc8-4w6x.json new file mode 100644 index 00000000000..704aedb9c2b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-p98w-xrc8-4w6x/GHSA-p98w-xrc8-4w6x.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p98w-xrc8-4w6x", + "modified": "2025-05-01T15:31:52Z", + "published": "2025-05-01T15:31:52Z", + "aliases": [ + "CVE-2022-49908" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: Fix memory leak in vhci_write\n\nSyzkaller reports a memory leak as follows:\n====================================\nBUG: memory leak\nunreferenced object 0xffff88810d81ac00 (size 240):\n [...]\n hex dump (first 32 bytes):\n 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n backtrace:\n [] __alloc_skb+0x1f9/0x270 net/core/skbuff.c:418\n [] alloc_skb include/linux/skbuff.h:1257 [inline]\n [] bt_skb_alloc include/net/bluetooth/bluetooth.h:469 [inline]\n [] vhci_get_user drivers/bluetooth/hci_vhci.c:391 [inline]\n [] vhci_write+0x5f/0x230 drivers/bluetooth/hci_vhci.c:511\n [] call_write_iter include/linux/fs.h:2192 [inline]\n [] new_sync_write fs/read_write.c:491 [inline]\n [] vfs_write+0x42d/0x540 fs/read_write.c:578\n [] ksys_write+0x9d/0x160 fs/read_write.c:631\n [] do_syscall_x64 arch/x86/entry/common.c:50 [inline]\n [] do_syscall_64+0x35/0xb0 arch/x86/entry/common.c:80\n [] entry_SYSCALL_64_after_hwframe+0x63/0xcd\n====================================\n\nHCI core will uses hci_rx_work() to process frame, which is queued to\nthe hdev->rx_q tail in hci_recv_frame() by HCI driver.\n\nYet the problem is that, HCI core may not free the skb after handling\nACL data packets. To be more specific, when start fragment does not\ncontain the L2CAP length, HCI core just copies skb into conn->rx_skb and\nfinishes frame process in l2cap_recv_acldata(), without freeing the skb,\nwhich triggers the above memory leak.\n\nThis patch solves it by releasing the relative skb, after processing\nthe above case in l2cap_recv_acldata().", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49908" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5b4f039a2f487c5edae681d763fe1af505f84c13" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7c9524d929648935bac2bbb4c20437df8f9c3f42" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/aa16cac06b752e5f609c106735bd7838f444784c" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-pg76-q8r9-xqw5/GHSA-pg76-q8r9-xqw5.json b/advisories/unreviewed/2025/05/GHSA-pg76-q8r9-xqw5/GHSA-pg76-q8r9-xqw5.json new file mode 100644 index 00000000000..c9cc277c98b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-pg76-q8r9-xqw5/GHSA-pg76-q8r9-xqw5.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pg76-q8r9-xqw5", + "modified": "2025-05-01T15:31:49Z", + "published": "2025-05-01T15:31:49Z", + "aliases": [ + "CVE-2022-49848" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nphy: qcom-qmp-combo: fix NULL-deref on runtime resume\n\nCommit fc64623637da (\"phy: qcom-qmp-combo,usb: add support for separate\nPCS_USB region\") started treating the PCS_USB registers as potentially\nseparate from the PCS registers but used the wrong base when no PCS_USB\noffset has been provided.\n\nFix the PCS_USB base used at runtime resume to prevent dereferencing a\nNULL pointer on platforms that do not provide a PCS_USB offset (e.g.\nSC7180).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49848" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/04948e757148f870a31f4887ea2239403f516c3c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c559a8b5cfa3db196ced0257b288f17027621348" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-ph3p-q84c-pqrw/GHSA-ph3p-q84c-pqrw.json b/advisories/unreviewed/2025/05/GHSA-ph3p-q84c-pqrw/GHSA-ph3p-q84c-pqrw.json new file mode 100644 index 00000000000..b1c435b48f6 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-ph3p-q84c-pqrw/GHSA-ph3p-q84c-pqrw.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ph3p-q84c-pqrw", + "modified": "2025-05-01T15:31:44Z", + "published": "2025-05-01T15:31:43Z", + "aliases": [ + "CVE-2025-37766" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/pm: Prevent division by zero\n\nThe user can set any speed value.\nIf speed is greater than UINT_MAX/8, division by zero is possible.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37766" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/068091b796480819bf70b159f17e222ad8bea900" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/42f7b5d12c28b2a601a98d10a80c6db1fe1a2900" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4e3d9508c056d7e0a56b58d5c81253e2a0d22b6c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/affd2241927a1e74c0aecd50c2d920dc4213c56d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ffd688804425579a472fbd2525bedb58b1d28bd9" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T14:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-pj73-39g5-xmf7/GHSA-pj73-39g5-xmf7.json b/advisories/unreviewed/2025/05/GHSA-pj73-39g5-xmf7/GHSA-pj73-39g5-xmf7.json new file mode 100644 index 00000000000..a5fe292c687 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-pj73-39g5-xmf7/GHSA-pj73-39g5-xmf7.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pj73-39g5-xmf7", + "modified": "2025-05-01T15:31:42Z", + "published": "2025-05-01T15:31:42Z", + "aliases": [ + "CVE-2025-23163" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: vlan: don't propagate flags on open\n\nWith the device instance lock, there is now a possibility of a deadlock:\n\n[ 1.211455] ============================================\n[ 1.211571] WARNING: possible recursive locking detected\n[ 1.211687] 6.14.0-rc5-01215-g032756b4ca7a-dirty #5 Not tainted\n[ 1.211823] --------------------------------------------\n[ 1.211936] ip/184 is trying to acquire lock:\n[ 1.212032] ffff8881024a4c30 (&dev->lock){+.+.}-{4:4}, at: dev_set_allmulti+0x4e/0xb0\n[ 1.212207]\n[ 1.212207] but task is already holding lock:\n[ 1.212332] ffff8881024a4c30 (&dev->lock){+.+.}-{4:4}, at: dev_open+0x50/0xb0\n[ 1.212487]\n[ 1.212487] other info that might help us debug this:\n[ 1.212626] Possible unsafe locking scenario:\n[ 1.212626]\n[ 1.212751] CPU0\n[ 1.212815] ----\n[ 1.212871] lock(&dev->lock);\n[ 1.212944] lock(&dev->lock);\n[ 1.213016]\n[ 1.213016] *** DEADLOCK ***\n[ 1.213016]\n[ 1.213143] May be due to missing lock nesting notation\n[ 1.213143]\n[ 1.213294] 3 locks held by ip/184:\n[ 1.213371] #0: ffffffff838b53e0 (rtnl_mutex){+.+.}-{4:4}, at: rtnl_nets_lock+0x1b/0xa0\n[ 1.213543] #1: ffffffff84e5fc70 (&net->rtnl_mutex){+.+.}-{4:4}, at: rtnl_nets_lock+0x37/0xa0\n[ 1.213727] #2: ffff8881024a4c30 (&dev->lock){+.+.}-{4:4}, at: dev_open+0x50/0xb0\n[ 1.213895]\n[ 1.213895] stack backtrace:\n[ 1.213991] CPU: 0 UID: 0 PID: 184 Comm: ip Not tainted 6.14.0-rc5-01215-g032756b4ca7a-dirty #5\n[ 1.213993] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS Arch Linux 1.16.3-1-1 04/01/2014\n[ 1.213994] Call Trace:\n[ 1.213995] \n[ 1.213996] dump_stack_lvl+0x8e/0xd0\n[ 1.214000] print_deadlock_bug+0x28b/0x2a0\n[ 1.214020] lock_acquire+0xea/0x2a0\n[ 1.214027] __mutex_lock+0xbf/0xd40\n[ 1.214038] dev_set_allmulti+0x4e/0xb0 # real_dev->flags & IFF_ALLMULTI\n[ 1.214040] vlan_dev_open+0xa5/0x170 # ndo_open on vlandev\n[ 1.214042] __dev_open+0x145/0x270\n[ 1.214046] __dev_change_flags+0xb0/0x1e0\n[ 1.214051] netif_change_flags+0x22/0x60 # IFF_UP vlandev\n[ 1.214053] dev_change_flags+0x61/0xb0 # for each device in group from dev->vlan_info\n[ 1.214055] vlan_device_event+0x766/0x7c0 # on netdevsim0\n[ 1.214058] notifier_call_chain+0x78/0x120\n[ 1.214062] netif_open+0x6d/0x90\n[ 1.214064] dev_open+0x5b/0xb0 # locks netdevsim0\n[ 1.214066] bond_enslave+0x64c/0x1230\n[ 1.214075] do_set_master+0x175/0x1e0 # on netdevsim0\n[ 1.214077] do_setlink+0x516/0x13b0\n[ 1.214094] rtnl_newlink+0xaba/0xb80\n[ 1.214132] rtnetlink_rcv_msg+0x440/0x490\n[ 1.214144] netlink_rcv_skb+0xeb/0x120\n[ 1.214150] netlink_unicast+0x1f9/0x320\n[ 1.214153] netlink_sendmsg+0x346/0x3f0\n[ 1.214157] __sock_sendmsg+0x86/0xb0\n[ 1.214160] ____sys_sendmsg+0x1c8/0x220\n[ 1.214164] ___sys_sendmsg+0x28f/0x2d0\n[ 1.214179] __x64_sys_sendmsg+0xef/0x140\n[ 1.214184] do_syscall_64+0xec/0x1d0\n[ 1.214190] entry_SYSCALL_64_after_hwframe+0x77/0x7f\n[ 1.214191] RIP: 0033:0x7f2d1b4a7e56\n\nDevice setup:\n\n netdevsim0 (down)\n ^ ^\n bond netdevsim1.100@netdevsim1 allmulticast=on (down)\n\nWhen we enslave the lower device (netdevsim0) which has a vlan, we\npropagate vlan's allmuti/promisc flags during ndo_open. This causes\n(re)locking on of the real_dev.\n\nPropagate allmulti/promisc on flags change, not on the open. There\nis a slight semantics change that vlans that are down now propagate\nthe flags, but this seems unlikely to result in the real issues.\n\nReproducer:\n\n echo 0 1 > /sys/bus/netdevsim/new_device\n\n dev_path=$(ls -d /sys/bus/netdevsim/devices/netdevsim0/net/*)\n dev=$(echo $dev_path | rev | cut -d/ -f1 | rev)\n\n ip link set dev $dev name netdevsim0\n ip link set dev netdevsim0 up\n\n ip link add link netdevsim0 name netdevsim0.100 type vlan id 100\n ip link set dev netdevsim0.100 allm\n---truncated---", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23163" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/27b918007d96402aba10ed52a6af8015230f1793" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/299d7d27af6b5844cda06a0fdfa635705e1bc50f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/538b43aa21e3b17c110104efd218b966d2eda5f8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/53fb25e90c0a503a17c639341ba5e755cb2feb5c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8980018a9806743d9b80837330d46f06ecf78516" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d537859e56bcc3091805c524484a4c85386b3cc8" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T13:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-pmj7-4375-32j4/GHSA-pmj7-4375-32j4.json b/advisories/unreviewed/2025/05/GHSA-pmj7-4375-32j4/GHSA-pmj7-4375-32j4.json new file mode 100644 index 00000000000..7f5c04e7fd9 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-pmj7-4375-32j4/GHSA-pmj7-4375-32j4.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pmj7-4375-32j4", + "modified": "2025-05-01T15:31:52Z", + "published": "2025-05-01T15:31:51Z", + "aliases": [ + "CVE-2022-49901" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nblk-mq: Fix kmemleak in blk_mq_init_allocated_queue\n\nThere is a kmemleak caused by modprobe null_blk.ko\n\nunreferenced object 0xffff8881acb1f000 (size 1024):\n comm \"modprobe\", pid 836, jiffies 4294971190 (age 27.068s)\n hex dump (first 32 bytes):\n 00 00 00 00 ad 4e ad de ff ff ff ff 00 00 00 00 .....N..........\n ff ff ff ff ff ff ff ff 00 53 99 9e ff ff ff ff .........S......\n backtrace:\n [<000000004a10c249>] kmalloc_node_trace+0x22/0x60\n [<00000000648f7950>] blk_mq_alloc_and_init_hctx+0x289/0x350\n [<00000000af06de0e>] blk_mq_realloc_hw_ctxs+0x2fe/0x3d0\n [<00000000e00c1872>] blk_mq_init_allocated_queue+0x48c/0x1440\n [<00000000d16b4e68>] __blk_mq_alloc_disk+0xc8/0x1c0\n [<00000000d10c98c3>] 0xffffffffc450d69d\n [<00000000b9299f48>] 0xffffffffc4538392\n [<0000000061c39ed6>] do_one_initcall+0xd0/0x4f0\n [<00000000b389383b>] do_init_module+0x1a4/0x680\n [<0000000087cf3542>] load_module+0x6249/0x7110\n [<00000000beba61b8>] __do_sys_finit_module+0x140/0x200\n [<00000000fdcfff51>] do_syscall_64+0x35/0x80\n [<000000003c0f1f71>] entry_SYSCALL_64_after_hwframe+0x46/0xb0\n\nThat is because q->ma_ops is set to NULL before blk_release_queue is\ncalled.\n\nblk_mq_init_queue_data\n blk_mq_init_allocated_queue\n blk_mq_realloc_hw_ctxs\n for (i = 0; i < set->nr_hw_queues; i++) {\n old_hctx = xa_load(&q->hctx_table, i);\n if (!blk_mq_alloc_and_init_hctx(.., i, ..))\t\t[1]\n if (!old_hctx)\n\t break;\n\n xa_for_each_start(&q->hctx_table, j, hctx, j)\n blk_mq_exit_hctx(q, set, hctx, j); \t\t\t[2]\n\n if (!q->nr_hw_queues)\t\t\t\t\t[3]\n goto err_hctxs;\n\n err_exit:\n q->mq_ops = NULL;\t\t\t \t\t\t[4]\n\n blk_put_queue\n blk_release_queue\n if (queue_is_mq(q))\t\t\t\t\t[5]\n blk_mq_release(q);\n\n[1]: blk_mq_alloc_and_init_hctx failed at i != 0.\n[2]: The hctxs allocated by [1] are moved to q->unused_hctx_list and\nwill be cleaned up in blk_mq_release.\n[3]: q->nr_hw_queues is 0.\n[4]: Set q->mq_ops to NULL.\n[5]: queue_is_mq returns false due to [4]. And blk_mq_release\nwill not be called. The hctxs in q->unused_hctx_list are leaked.\n\nTo fix it, call blk_release_queue in exception path.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49901" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2dc97e15a54b7bdf457848aa8c663c98a24e58a6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/943f45b9399ed8b2b5190cbc797995edaa97f58f" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-px2q-r9rv-q5m3/GHSA-px2q-r9rv-q5m3.json b/advisories/unreviewed/2025/05/GHSA-px2q-r9rv-q5m3/GHSA-px2q-r9rv-q5m3.json new file mode 100644 index 00000000000..4b96429b346 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-px2q-r9rv-q5m3/GHSA-px2q-r9rv-q5m3.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-px2q-r9rv-q5m3", + "modified": "2025-05-01T15:31:47Z", + "published": "2025-05-01T15:31:46Z", + "aliases": [ + "CVE-2022-49780" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: target: tcm_loop: Fix possible name leak in tcm_loop_setup_hba_bus()\n\nIf device_register() fails in tcm_loop_setup_hba_bus(), the name allocated\nby dev_set_name() need be freed. As comment of device_register() says, it\nshould use put_device() to give up the reference in the error path. So fix\nthis by calling put_device(), then the name can be freed in kobject_cleanup().\nThe 'tl_hba' will be freed in tcm_loop_release_adapter(), so it don't need\ngoto error label in this case.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49780" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/28f7ff5e7559d226e63c7c5de74eb075a83d8c53" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/41a6b8b527a5957fab41c3c05e25ad125268e2e9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/75205f1b47a88c3fac4f30bd7567e89b2887c7fd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a636772988bafab89278e7bb3420d8e8eacfe912" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bc68e428d4963af0201e92159629ab96948f0893" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/dce0589a3faec9e2e543e97bca7e62592ec85585" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-q2h8-9338-55xq/GHSA-q2h8-9338-55xq.json b/advisories/unreviewed/2025/05/GHSA-q2h8-9338-55xq/GHSA-q2h8-9338-55xq.json new file mode 100644 index 00000000000..aeb9a02301f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-q2h8-9338-55xq/GHSA-q2h8-9338-55xq.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q2h8-9338-55xq", + "modified": "2025-05-01T15:31:42Z", + "published": "2025-05-01T15:31:42Z", + "aliases": [ + "CVE-2025-37741" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\njfs: Prevent copying of nlink with value 0 from disk inode\n\nsyzbot report a deadlock in diFree. [1]\n\nWhen calling \"ioctl$LOOP_SET_STATUS64\", the offset value passed in is 4,\nwhich does not match the mounted loop device, causing the mapping of the\nmounted loop device to be invalidated.\n\nWhen creating the directory and creating the inode of iag in diReadSpecial(),\nread the page of fixed disk inode (AIT) in raw mode in read_metapage(), the\nmetapage data it returns is corrupted, which causes the nlink value of 0 to be\nassigned to the iag inode when executing copy_from_dinode(), which ultimately\ncauses a deadlock when entering diFree().\n\nTo avoid this, first check the nlink value of dinode before setting iag inode.\n\n[1]\nWARNING: possible recursive locking detected\n6.12.0-rc7-syzkaller-00212-g4a5df3796467 #0 Not tainted\n--------------------------------------------\nsyz-executor301/5309 is trying to acquire lock:\nffff888044548920 (&(imap->im_aglock[index])){+.+.}-{3:3}, at: diFree+0x37c/0x2fb0 fs/jfs/jfs_imap.c:889\n\nbut task is already holding lock:\nffff888044548920 (&(imap->im_aglock[index])){+.+.}-{3:3}, at: diAlloc+0x1b6/0x1630\n\nother info that might help us debug this:\n Possible unsafe locking scenario:\n\n CPU0\n ----\n lock(&(imap->im_aglock[index]));\n lock(&(imap->im_aglock[index]));\n\n *** DEADLOCK ***\n\n May be due to missing lock nesting notation\n\n5 locks held by syz-executor301/5309:\n #0: ffff8880422a4420 (sb_writers#9){.+.+}-{0:0}, at: mnt_want_write+0x3f/0x90 fs/namespace.c:515\n #1: ffff88804755b390 (&type->i_mutex_dir_key#6/1){+.+.}-{3:3}, at: inode_lock_nested include/linux/fs.h:850 [inline]\n #1: ffff88804755b390 (&type->i_mutex_dir_key#6/1){+.+.}-{3:3}, at: filename_create+0x260/0x540 fs/namei.c:4026\n #2: ffff888044548920 (&(imap->im_aglock[index])){+.+.}-{3:3}, at: diAlloc+0x1b6/0x1630\n #3: ffff888044548890 (&imap->im_freelock){+.+.}-{3:3}, at: diNewIAG fs/jfs/jfs_imap.c:2460 [inline]\n #3: ffff888044548890 (&imap->im_freelock){+.+.}-{3:3}, at: diAllocExt fs/jfs/jfs_imap.c:1905 [inline]\n #3: ffff888044548890 (&imap->im_freelock){+.+.}-{3:3}, at: diAllocAG+0x4b7/0x1e50 fs/jfs/jfs_imap.c:1669\n #4: ffff88804755a618 (&jfs_ip->rdwrlock/1){++++}-{3:3}, at: diNewIAG fs/jfs/jfs_imap.c:2477 [inline]\n #4: ffff88804755a618 (&jfs_ip->rdwrlock/1){++++}-{3:3}, at: diAllocExt fs/jfs/jfs_imap.c:1905 [inline]\n #4: ffff88804755a618 (&jfs_ip->rdwrlock/1){++++}-{3:3}, at: diAllocAG+0x869/0x1e50 fs/jfs/jfs_imap.c:1669\n\nstack backtrace:\nCPU: 0 UID: 0 PID: 5309 Comm: syz-executor301 Not tainted 6.12.0-rc7-syzkaller-00212-g4a5df3796467 #0\nHardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2~bpo12+1 04/01/2014\nCall Trace:\n \n __dump_stack lib/dump_stack.c:94 [inline]\n dump_stack_lvl+0x241/0x360 lib/dump_stack.c:120\n print_deadlock_bug+0x483/0x620 kernel/locking/lockdep.c:3037\n check_deadlock kernel/locking/lockdep.c:3089 [inline]\n validate_chain+0x15e2/0x5920 kernel/locking/lockdep.c:3891\n __lock_acquire+0x1384/0x2050 kernel/locking/lockdep.c:5202\n lock_acquire+0x1ed/0x550 kernel/locking/lockdep.c:5825\n __mutex_lock_common kernel/locking/mutex.c:608 [inline]\n __mutex_lock+0x136/0xd70 kernel/locking/mutex.c:752\n diFree+0x37c/0x2fb0 fs/jfs/jfs_imap.c:889\n jfs_evict_inode+0x32d/0x440 fs/jfs/inode.c:156\n evict+0x4e8/0x9b0 fs/inode.c:725\n diFreeSpecial fs/jfs/jfs_imap.c:552 [inline]\n duplicateIXtree+0x3c6/0x550 fs/jfs/jfs_imap.c:3022\n diNewIAG fs/jfs/jfs_imap.c:2597 [inline]\n diAllocExt fs/jfs/jfs_imap.c:1905 [inline]\n diAllocAG+0x17dc/0x1e50 fs/jfs/jfs_imap.c:1669\n diAlloc+0x1d2/0x1630 fs/jfs/jfs_imap.c:1590\n ialloc+0x8f/0x900 fs/jfs/jfs_inode.c:56\n jfs_mkdir+0x1c5/0xba0 fs/jfs/namei.c:225\n vfs_mkdir+0x2f9/0x4f0 fs/namei.c:4257\n do_mkdirat+0x264/0x3a0 fs/namei.c:4280\n __do_sys_mkdirat fs/namei.c:4295 [inline]\n __se_sys_mkdirat fs/namei.c:4293 [inline]\n __x64_sys_mkdirat+0x87/0xa0 fs/namei.c:4293\n do_syscall_x64 arch/x86/en\n---truncated---", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37741" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/994787341358816d91b2fded288ecb7f129f2b27" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a2b560815528ae8e266fca6038bb5585d13aaef4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/aeb926e605f97857504bdf748f575e40617e2ef9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b3c4884b987e5d8d0ec061a4d52653c4f4b9c37e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b61e69bb1c049cf507e3c654fa3dc1568231bd07" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c9541c2bd0edbdbc5c1148a84d3b48dc8d1b8af2" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T13:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-q2ww-4r37-g77p/GHSA-q2ww-4r37-g77p.json b/advisories/unreviewed/2025/05/GHSA-q2ww-4r37-g77p/GHSA-q2ww-4r37-g77p.json new file mode 100644 index 00000000000..ee15ce865a0 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-q2ww-4r37-g77p/GHSA-q2ww-4r37-g77p.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q2ww-4r37-g77p", + "modified": "2025-05-01T15:31:47Z", + "published": "2025-05-01T15:31:47Z", + "aliases": [ + "CVE-2022-49792" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\niio: adc: mp2629: fix potential array out of bound access\n\nAdd sentinel at end of maps to avoid potential array out of\nbound access in iio core.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49792" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1678d4abb2dc2ca3b05b998a9d88616976e4f947" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/399b2105a2240e730b9f3880bd8f154247539aa7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ca1547ab15f48dc81624183ae17a2fd1bad06dfc" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d95b85c5084ad70011988861ee864529eefa1da0" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-q3v6-chw5-g495/GHSA-q3v6-chw5-g495.json b/advisories/unreviewed/2025/05/GHSA-q3v6-chw5-g495/GHSA-q3v6-chw5-g495.json new file mode 100644 index 00000000000..ec8de375a50 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-q3v6-chw5-g495/GHSA-q3v6-chw5-g495.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q3v6-chw5-g495", + "modified": "2025-05-01T15:31:41Z", + "published": "2025-05-01T15:31:41Z", + "aliases": [ + "CVE-2025-23161" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nPCI: vmd: Make vmd_dev::cfg_lock a raw_spinlock_t type\n\nThe access to the PCI config space via pci_ops::read and pci_ops::write is\na low-level hardware access. The functions can be accessed with disabled\ninterrupts even on PREEMPT_RT. The pci_lock is a raw_spinlock_t for this\npurpose.\n\nA spinlock_t becomes a sleeping lock on PREEMPT_RT, so it cannot be\nacquired with disabled interrupts. The vmd_dev::cfg_lock is accessed in\nthe same context as the pci_lock.\n\nMake vmd_dev::cfg_lock a raw_spinlock_t type so it can be used with\ninterrupts disabled.\n\nThis was reported as:\n\n BUG: sleeping function called from invalid context at kernel/locking/spinlock_rt.c:48\n Call Trace:\n rt_spin_lock+0x4e/0x130\n vmd_pci_read+0x8d/0x100 [vmd]\n pci_user_read_config_byte+0x6f/0xe0\n pci_read_config+0xfe/0x290\n sysfs_kf_bin_read+0x68/0x90\n\n[bigeasy: reword commit message]\nTested-off-by: Luis Claudio R. Goncalves \n[kwilczynski: commit log]\n[bhelgaas: add back report info from\nhttps://lore.kernel.org/lkml/20241218115951.83062-1-ryotkkr98@gmail.com/]", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23161" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/13e5148f70e81991acbe0bab5b1b50ba699116e7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/18056a48669a040bef491e63b25896561ee14d90" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/20d0a9062c031068fa39f725a32f182b709b5525" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2358046ead696ca5c7c628d6c0e2c6792619a3e5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5c3cfcf0b4bf43530788b08a8eaf7896ec567484" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c2968c812339593ac6e2bdd5cc3adabe3f05fa53" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T13:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-q725-94pj-f5xx/GHSA-q725-94pj-f5xx.json b/advisories/unreviewed/2025/05/GHSA-q725-94pj-f5xx/GHSA-q725-94pj-f5xx.json new file mode 100644 index 00000000000..66dcd8479ef --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-q725-94pj-f5xx/GHSA-q725-94pj-f5xx.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q725-94pj-f5xx", + "modified": "2025-05-01T15:31:47Z", + "published": "2025-05-01T15:31:47Z", + "aliases": [ + "CVE-2022-49801" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: Fix memory leak in tracing_read_pipe()\n\nkmemleak reports this issue:\n\nunreferenced object 0xffff888105a18900 (size 128):\n comm \"test_progs\", pid 18933, jiffies 4336275356 (age 22801.766s)\n hex dump (first 32 bytes):\n 25 73 00 90 81 88 ff ff 26 05 00 00 42 01 58 04 %s......&...B.X.\n 03 00 00 00 02 00 00 00 00 00 00 00 00 00 00 00 ................\n backtrace:\n [<00000000560143a1>] __kmalloc_node_track_caller+0x4a/0x140\n [<000000006af00822>] krealloc+0x8d/0xf0\n [<00000000c309be6a>] trace_iter_expand_format+0x99/0x150\n [<000000005a53bdb6>] trace_check_vprintf+0x1e0/0x11d0\n [<0000000065629d9d>] trace_event_printf+0xb6/0xf0\n [<000000009a690dc7>] trace_raw_output_bpf_trace_printk+0x89/0xc0\n [<00000000d22db172>] print_trace_line+0x73c/0x1480\n [<00000000cdba76ba>] tracing_read_pipe+0x45c/0x9f0\n [<0000000015b58459>] vfs_read+0x17b/0x7c0\n [<000000004aeee8ed>] ksys_read+0xed/0x1c0\n [<0000000063d3d898>] do_syscall_64+0x3b/0x90\n [<00000000a06dda7f>] entry_SYSCALL_64_after_hwframe+0x63/0xcd\n\niter->fmt alloced in\n tracing_read_pipe() -> .. ->trace_iter_expand_format(), but not\nfreed, to fix, add free in tracing_release_pipe()", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49801" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2c21ee020ce43d744ecd7f3e9bddfcaafef270ce" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/649e72070cbbb8600eb823833e4748f5a0815116" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a7d3f8f33c113478737bc61bb32ec5f9a987da7d" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-q7q7-437c-qxh7/GHSA-q7q7-437c-qxh7.json b/advisories/unreviewed/2025/05/GHSA-q7q7-437c-qxh7/GHSA-q7q7-437c-qxh7.json new file mode 100644 index 00000000000..b4fa546f000 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-q7q7-437c-qxh7/GHSA-q7q7-437c-qxh7.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q7q7-437c-qxh7", + "modified": "2025-05-01T15:31:39Z", + "published": "2025-05-01T15:31:39Z", + "aliases": [ + "CVE-2025-23142" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: detect and prevent references to a freed transport in sendmsg\n\nsctp_sendmsg() re-uses associations and transports when possible by\ndoing a lookup based on the socket endpoint and the message destination\naddress, and then sctp_sendmsg_to_asoc() sets the selected transport in\nall the message chunks to be sent.\n\nThere's a possible race condition if another thread triggers the removal\nof that selected transport, for instance, by explicitly unbinding an\naddress with setsockopt(SCTP_SOCKOPT_BINDX_REM), after the chunks have\nbeen set up and before the message is sent. This can happen if the send\nbuffer is full, during the period when the sender thread temporarily\nreleases the socket lock in sctp_wait_for_sndbuf().\n\nThis causes the access to the transport data in\nsctp_outq_select_transport(), when the association outqueue is flushed,\nto result in a use-after-free read.\n\nThis change avoids this scenario by having sctp_transport_free() signal\nthe freeing of the transport, tagging it as \"dead\". In order to do this,\nthe patch restores the \"dead\" bit in struct sctp_transport, which was\nremoved in\ncommit 47faa1e4c50e (\"sctp: remove the dead field of sctp_transport\").\n\nThen, in the scenario where the sender thread has released the socket\nlock in sctp_wait_for_sndbuf(), the bit is checked again after\nre-acquiring the socket lock to detect the deletion. This is done while\nholding a reference to the transport to prevent it from being freed in\nthe process.\n\nIf the transport was deleted while the socket lock was relinquished,\nsctp_sendmsg_to_asoc() will return -EAGAIN to let userspace retry the\nsend.\n\nThe bug was found by a private syzbot instance (see the error report [1]\nand the C reproducer that triggers it [2]).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23142" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2e5068b7e0ae0a54f6cfd03a2f80977da657f1ee" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5bc83bdf5f5b8010d1ca5a4555537e62413ab4e2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7a63f4fb0efb4e69efd990cbb740a848679ec4b0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9e7c37fadb3be1fc33073fcf10aa96d166caa697" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c6fefcb71d246baaf3bacdad1af7ff50ebcfe652" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f1a69a940de58b16e8249dff26f74c8cc59b32be" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T13:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-q7v8-cc74-49m7/GHSA-q7v8-cc74-49m7.json b/advisories/unreviewed/2025/05/GHSA-q7v8-cc74-49m7/GHSA-q7v8-cc74-49m7.json new file mode 100644 index 00000000000..e4e404a6ca9 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-q7v8-cc74-49m7/GHSA-q7v8-cc74-49m7.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q7v8-cc74-49m7", + "modified": "2025-05-01T15:31:53Z", + "published": "2025-05-01T15:31:53Z", + "aliases": [ + "CVE-2025-44838" + ], + "details": "TOTOLINK CPE CP900 V6.3c.1144_B20190715 was discovered to contain a command injection vulnerability in the setUploadUserData function via the FileName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44838" + }, + { + "type": "WEB", + "url": "https://github.com/n0wstr/IOTVuln/tree/main/CP900/setUploadUserData" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-qc3f-4c25-g23q/GHSA-qc3f-4c25-g23q.json b/advisories/unreviewed/2025/05/GHSA-qc3f-4c25-g23q/GHSA-qc3f-4c25-g23q.json new file mode 100644 index 00000000000..ebfe5a0a5b1 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-qc3f-4c25-g23q/GHSA-qc3f-4c25-g23q.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qc3f-4c25-g23q", + "modified": "2025-05-01T15:31:42Z", + "published": "2025-05-01T15:31:42Z", + "aliases": [ + "CVE-2025-37739" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to avoid out-of-bounds access in f2fs_truncate_inode_blocks()\n\nsyzbot reports an UBSAN issue as below:\n\n------------[ cut here ]------------\nUBSAN: array-index-out-of-bounds in fs/f2fs/node.h:381:10\nindex 18446744073709550692 is out of range for type '__le32[5]' (aka 'unsigned int[5]')\nCPU: 0 UID: 0 PID: 5318 Comm: syz.0.0 Not tainted 6.14.0-rc3-syzkaller-00060-g6537cfb395f3 #0\nCall Trace:\n \n __dump_stack lib/dump_stack.c:94 [inline]\n dump_stack_lvl+0x241/0x360 lib/dump_stack.c:120\n ubsan_epilogue lib/ubsan.c:231 [inline]\n __ubsan_handle_out_of_bounds+0x121/0x150 lib/ubsan.c:429\n get_nid fs/f2fs/node.h:381 [inline]\n f2fs_truncate_inode_blocks+0xa5e/0xf60 fs/f2fs/node.c:1181\n f2fs_do_truncate_blocks+0x782/0x1030 fs/f2fs/file.c:808\n f2fs_truncate_blocks+0x10d/0x300 fs/f2fs/file.c:836\n f2fs_truncate+0x417/0x720 fs/f2fs/file.c:886\n f2fs_file_write_iter+0x1bdb/0x2550 fs/f2fs/file.c:5093\n aio_write+0x56b/0x7c0 fs/aio.c:1633\n io_submit_one+0x8a7/0x18a0 fs/aio.c:2052\n __do_sys_io_submit fs/aio.c:2111 [inline]\n __se_sys_io_submit+0x171/0x2e0 fs/aio.c:2081\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\nRIP: 0033:0x7f238798cde9\n\nindex 18446744073709550692 (decimal, unsigned long long)\n= 0xfffffffffffffc64 (hexadecimal, unsigned long long)\n= -924 (decimal, long long)\n\nIn f2fs_truncate_inode_blocks(), UBSAN detects that get_nid() tries to\naccess .i_nid[-924], it means both offset[0] and level should zero.\n\nThe possible case should be in f2fs_do_truncate_blocks(), we try to\ntruncate inode size to zero, however, dn.ofs_in_node is zero and\ndn.node_page is not an inode page, so it fails to truncate inode page,\nand then pass zeroed free_from to f2fs_truncate_inode_blocks(), result\nin this issue.\n\n\tif (dn.ofs_in_node || IS_INODE(dn.node_page)) {\n\t\tf2fs_truncate_data_blocks_range(&dn, count);\n\t\tfree_from += count;\n\t}\n\nI guess the reason why dn.node_page is not an inode page could be: there\nare multiple nat entries share the same node block address, once the node\nblock address was reused, f2fs_get_node_page() may load a non-inode block.\n\nLet's add a sanity check for such condition to avoid out-of-bounds access\nissue.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37739" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6ba8b41d0aa4b82f90f0c416cb53fcef9696525d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8b5e5aac44fee122947a269f9034c048e4c295de" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/98dbf2af63de0b551082c9bc48333910e009b09f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d7242fd7946d4cba0411effb6b5048ca55125747" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e6494977bd4a83862118a05f57a8df40256951c0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ecc461331604b07cdbdb7360dbdf78471653264c" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T13:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-qp6f-hq95-gpp9/GHSA-qp6f-hq95-gpp9.json b/advisories/unreviewed/2025/05/GHSA-qp6f-hq95-gpp9/GHSA-qp6f-hq95-gpp9.json new file mode 100644 index 00000000000..8617e5385e3 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-qp6f-hq95-gpp9/GHSA-qp6f-hq95-gpp9.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qp6f-hq95-gpp9", + "modified": "2025-05-01T15:31:50Z", + "published": "2025-05-01T15:31:50Z", + "aliases": [ + "CVE-2022-49862" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: fix the msg->req tlv len check in tipc_nl_compat_name_table_dump_header\n\nThis is a follow-up for commit 974cb0e3e7c9 (\"tipc: fix uninit-value\nin tipc_nl_compat_name_table_dump\") where it should have type casted\nsizeof(..) to int to work when TLV_GET_DATA_LEN() returns a negative\nvalue.\n\nsyzbot reported a call trace because of it:\n\n BUG: KMSAN: uninit-value in ...\n tipc_nl_compat_name_table_dump+0x841/0xea0 net/tipc/netlink_compat.c:934\n __tipc_nl_compat_dumpit+0xab2/0x1320 net/tipc/netlink_compat.c:238\n tipc_nl_compat_dumpit+0x991/0xb50 net/tipc/netlink_compat.c:321\n tipc_nl_compat_recv+0xb6e/0x1640 net/tipc/netlink_compat.c:1324\n genl_family_rcv_msg_doit net/netlink/genetlink.c:731 [inline]\n genl_family_rcv_msg net/netlink/genetlink.c:775 [inline]\n genl_rcv_msg+0x103f/0x1260 net/netlink/genetlink.c:792\n netlink_rcv_skb+0x3a5/0x6c0 net/netlink/af_netlink.c:2501\n genl_rcv+0x3c/0x50 net/netlink/genetlink.c:803\n netlink_unicast_kernel net/netlink/af_netlink.c:1319 [inline]\n netlink_unicast+0xf3b/0x1270 net/netlink/af_netlink.c:1345\n netlink_sendmsg+0x1288/0x1440 net/netlink/af_netlink.c:1921\n sock_sendmsg_nosec net/socket.c:714 [inline]\n sock_sendmsg net/socket.c:734 [inline]", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49862" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/082707d3df191bf5bb8801d43e4ce3dea39ca173" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1c075b192fe41030457cd4a5f7dea730412bca40" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/301caa06091af4d5cf056ac8249cbda4e6029c6a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/36769b9477491a7af6635863bd950309c1e1b96c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/55a253a6753a603e80b95932ca971ba514aa6ce7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6cee2c60bd168279852ac7dbe54c2b70d1028644" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a0ead1d648df9c456baec832b494513ef405949a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f31dd158580940938f77514b87337a777520185a" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-qp86-w2fg-h37h/GHSA-qp86-w2fg-h37h.json b/advisories/unreviewed/2025/05/GHSA-qp86-w2fg-h37h/GHSA-qp86-w2fg-h37h.json new file mode 100644 index 00000000000..39fc7741b9d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-qp86-w2fg-h37h/GHSA-qp86-w2fg-h37h.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qp86-w2fg-h37h", + "modified": "2025-05-01T15:31:46Z", + "published": "2025-05-01T15:31:46Z", + "aliases": [ + "CVE-2022-49771" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndm ioctl: fix misbehavior if list_versions races with module loading\n\n__list_versions will first estimate the required space using the\n\"dm_target_iterate(list_version_get_needed, &needed)\" call and then will\nfill the space using the \"dm_target_iterate(list_version_get_info,\n&iter_info)\" call. Each of these calls locks the targets using the\n\"down_read(&_lock)\" and \"up_read(&_lock)\" calls, however between the first\nand second \"dm_target_iterate\" there is no lock held and the target\nmodules can be loaded at this point, so the second \"dm_target_iterate\"\ncall may need more space than what was the first \"dm_target_iterate\"\nreturned.\n\nThe code tries to handle this overflow (see the beginning of\nlist_version_get_info), however this handling is incorrect.\n\nThe code sets \"param->data_size = param->data_start + needed\" and\n\"iter_info.end = (char *)vers+len\" - \"needed\" is the size returned by the\nfirst dm_target_iterate call; \"len\" is the size of the buffer allocated by\nuserspace.\n\n\"len\" may be greater than \"needed\"; in this case, the code will write up\nto \"len\" bytes into the buffer, however param->data_size is set to\n\"needed\", so it may write data past the param->data_size value. The ioctl\ninterface copies only up to param->data_size into userspace, thus part of\nthe result will be truncated.\n\nFix this bug by setting \"iter_info.end = (char *)vers + needed;\" - this\nguarantees that the second \"dm_target_iterate\" call will write only up to\nthe \"needed\" buffer and it will exit with \"DM_BUFFER_FULL_FLAG\" if it\noverflows the \"needed\" space - in this case, userspace will allocate a\nlarger buffer and retry.\n\nNote that there is also a bug in list_version_get_needed - we need to add\n\"strlen(tt->name) + 1\" to the needed size, not \"strlen(tt->name)\".", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49771" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0c8d4112df329bf3dfbf27693f918c3b08676538" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3a1c35d72dc0b34d1e746ed705790c0f630aa427" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4fe1ec995483737f3d2a14c3fe1d8fe634972979" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5398b8e275bf81a2517b327d216c0f37ac9ac5ae" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6a818db0d5aecf80d4ba9e10ac153f60adc629ca" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6ffce7a92ef5c68f7e5d6f4d722c2f96280c064b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b545c0e1e4094d4de2bdfe9a3823f9154b0c0005" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f59f5a269ca5e43c567aca7f1f52500a0186e9b7" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-qq9j-c8r5-5xf6/GHSA-qq9j-c8r5-5xf6.json b/advisories/unreviewed/2025/05/GHSA-qq9j-c8r5-5xf6/GHSA-qq9j-c8r5-5xf6.json new file mode 100644 index 00000000000..2fdd55d620d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-qq9j-c8r5-5xf6/GHSA-qq9j-c8r5-5xf6.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qq9j-c8r5-5xf6", + "modified": "2025-05-01T15:31:49Z", + "published": "2025-05-01T15:31:49Z", + "aliases": [ + "CVE-2022-49833" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: zoned: clone zoned device info when cloning a device\n\nWhen cloning a btrfs_device, we're not cloning the associated\nbtrfs_zoned_device_info structure of the device in case of a zoned\nfilesystem.\n\nLater on this leads to a NULL pointer dereference when accessing the\ndevice's zone_info for instance when setting a zone as active.\n\nThis was uncovered by fstests' testcase btrfs/161.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49833" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/21e61ec6d0bb786818490e926aa9aeb4de95ad0d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ad88cabcec942c033f980cd1e28d56ecdaf5f3b8" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-qqpc-5fw9-5q24/GHSA-qqpc-5fw9-5q24.json b/advisories/unreviewed/2025/05/GHSA-qqpc-5fw9-5q24/GHSA-qqpc-5fw9-5q24.json new file mode 100644 index 00000000000..06cf548fe1f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-qqpc-5fw9-5q24/GHSA-qqpc-5fw9-5q24.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qqpc-5fw9-5q24", + "modified": "2025-05-01T15:31:45Z", + "published": "2025-05-01T15:31:45Z", + "aliases": [ + "CVE-2022-49766" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetlink: Bounds-check struct nlmsgerr creation\n\nIn preparation for FORTIFY_SOURCE doing bounds-check on memcpy(),\nswitch from __nlmsg_put to nlmsg_put(), and explain the bounds check\nfor dealing with the memcpy() across a composite flexible array struct.\nAvoids this future run-time warning:\n\n memcpy: detected field-spanning write (size 32) of single field \"&errmsg->msg\" at net/netlink/af_netlink.c:2447 (size 16)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49766" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/710d21fdff9a98d621cd4e64167f3ef8af4e2fd1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/aff4eb16f589c3af322a2582044bca365381fcd6" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-qrxq-fh5p-2v4x/GHSA-qrxq-fh5p-2v4x.json b/advisories/unreviewed/2025/05/GHSA-qrxq-fh5p-2v4x/GHSA-qrxq-fh5p-2v4x.json new file mode 100644 index 00000000000..d403afedd48 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-qrxq-fh5p-2v4x/GHSA-qrxq-fh5p-2v4x.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qrxq-fh5p-2v4x", + "modified": "2025-05-01T15:31:46Z", + "published": "2025-05-01T15:31:46Z", + "aliases": [ + "CVE-2022-49791" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nio_uring: fix multishot accept request leaks\n\nHaving REQ_F_POLLED set doesn't guarantee that the request is\nexecuted as a multishot from the polling path. Fortunately for us, if\nthe code thinks it's multishot issue when it's not, it can only ask to\nskip completion so leaking the request. Use issue_flags to mark\nmultipoll issues.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49791" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0e4626de856ef8f25ecd9c716e76d4f95ce95639" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/91482864768a874c4290ef93b84a78f4f1dac51b" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-r3p6-jggx-m3qg/GHSA-r3p6-jggx-m3qg.json b/advisories/unreviewed/2025/05/GHSA-r3p6-jggx-m3qg/GHSA-r3p6-jggx-m3qg.json new file mode 100644 index 00000000000..7a523f8e275 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-r3p6-jggx-m3qg/GHSA-r3p6-jggx-m3qg.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r3p6-jggx-m3qg", + "modified": "2025-05-01T15:31:42Z", + "published": "2025-05-01T15:31:42Z", + "aliases": [ + "CVE-2025-37750" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix UAF in decryption with multichannel\n\nAfter commit f7025d861694 (\"smb: client: allocate crypto only for\nprimary server\") and commit b0abcd65ec54 (\"smb: client: fix UAF in\nasync decryption\"), the channels started reusing AEAD TFM from primary\nchannel to perform synchronous decryption, but that can't done as\nthere could be multiple cifsd threads (one per channel) simultaneously\naccessing it to perform decryption.\n\nThis fixes the following KASAN splat when running fstest generic/249\nwith 'vers=3.1.1,multichannel,max_channels=4,seal' against Windows\nServer 2022:\n\nBUG: KASAN: slab-use-after-free in gf128mul_4k_lle+0xba/0x110\nRead of size 8 at addr ffff8881046c18a0 by task cifsd/986\nCPU: 3 UID: 0 PID: 986 Comm: cifsd Not tainted 6.15.0-rc1 #1\nPREEMPT(voluntary)\nHardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-3.fc41\n04/01/2014\nCall Trace:\n \n dump_stack_lvl+0x5d/0x80\n print_report+0x156/0x528\n ? gf128mul_4k_lle+0xba/0x110\n ? __virt_addr_valid+0x145/0x300\n ? __phys_addr+0x46/0x90\n ? gf128mul_4k_lle+0xba/0x110\n kasan_report+0xdf/0x1a0\n ? gf128mul_4k_lle+0xba/0x110\n gf128mul_4k_lle+0xba/0x110\n ghash_update+0x189/0x210\n shash_ahash_update+0x295/0x370\n ? __pfx_shash_ahash_update+0x10/0x10\n ? __pfx_shash_ahash_update+0x10/0x10\n ? __pfx_extract_iter_to_sg+0x10/0x10\n ? ___kmalloc_large_node+0x10e/0x180\n ? __asan_memset+0x23/0x50\n crypto_ahash_update+0x3c/0xc0\n gcm_hash_assoc_remain_continue+0x93/0xc0\n crypt_message+0xe09/0xec0 [cifs]\n ? __pfx_crypt_message+0x10/0x10 [cifs]\n ? _raw_spin_unlock+0x23/0x40\n ? __pfx_cifs_readv_from_socket+0x10/0x10 [cifs]\n decrypt_raw_data+0x229/0x380 [cifs]\n ? __pfx_decrypt_raw_data+0x10/0x10 [cifs]\n ? __pfx_cifs_read_iter_from_socket+0x10/0x10 [cifs]\n smb3_receive_transform+0x837/0xc80 [cifs]\n ? __pfx_smb3_receive_transform+0x10/0x10 [cifs]\n ? __pfx___might_resched+0x10/0x10\n ? __pfx_smb3_is_transform_hdr+0x10/0x10 [cifs]\n cifs_demultiplex_thread+0x692/0x1570 [cifs]\n ? __pfx_cifs_demultiplex_thread+0x10/0x10 [cifs]\n ? rcu_is_watching+0x20/0x50\n ? rcu_lockdep_current_cpu_online+0x62/0xb0\n ? find_held_lock+0x32/0x90\n ? kvm_sched_clock_read+0x11/0x20\n ? local_clock_noinstr+0xd/0xd0\n ? trace_irq_enable.constprop.0+0xa8/0xe0\n ? __pfx_cifs_demultiplex_thread+0x10/0x10 [cifs]\n kthread+0x1fe/0x380\n ? kthread+0x10f/0x380\n ? __pfx_kthread+0x10/0x10\n ? local_clock_noinstr+0xd/0xd0\n ? ret_from_fork+0x1b/0x60\n ? local_clock+0x15/0x30\n ? lock_release+0x29b/0x390\n ? rcu_is_watching+0x20/0x50\n ? __pfx_kthread+0x10/0x10\n ret_from_fork+0x31/0x60\n ? __pfx_kthread+0x10/0x10\n ret_from_fork_asm+0x1a/0x30\n ", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37750" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9502dd5c7029902f4a425bf959917a5a9e7c0e50" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/950557922c1298464749c216d8763e97faf5d0a6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/aa5a1e4b882964eb79d5b5d1d1e8a1a5efbb1d15" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e859b216d94668bc66330e61be201234f4413d1a" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T13:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rc8q-6743-jh4w/GHSA-rc8q-6743-jh4w.json b/advisories/unreviewed/2025/05/GHSA-rc8q-6743-jh4w/GHSA-rc8q-6743-jh4w.json new file mode 100644 index 00000000000..92bd795b596 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-rc8q-6743-jh4w/GHSA-rc8q-6743-jh4w.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rc8q-6743-jh4w", + "modified": "2025-05-01T15:31:50Z", + "published": "2025-05-01T15:31:49Z", + "aliases": [ + "CVE-2022-49853" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: macvlan: fix memory leaks of macvlan_common_newlink\n\nkmemleak reports memory leaks in macvlan_common_newlink, as follows:\n\n ip link add link eth0 name .. type macvlan mode source macaddr add\n \n\nkmemleak reports:\n\nunreferenced object 0xffff8880109bb140 (size 64):\n comm \"ip\", pid 284, jiffies 4294986150 (age 430.108s)\n hex dump (first 32 bytes):\n 00 00 00 00 00 00 00 00 b8 aa 5a 12 80 88 ff ff ..........Z.....\n 80 1b fa 0d 80 88 ff ff 1e ff ac af c7 c1 6b 6b ..............kk\n backtrace:\n [] kmem_cache_alloc_trace+0x1c7/0x300\n [] macvlan_hash_add_source+0x45/0xc0\n [] macvlan_changelink_sources+0xd7/0x170\n [] macvlan_common_newlink+0x38c/0x5a0\n [] macvlan_newlink+0xe/0x20\n [] __rtnl_newlink+0x7af/0xa50\n [] rtnl_newlink+0x48/0x70\n ...\n\nIn the scenario where the macvlan mode is configured as 'source',\nmacvlan_changelink_sources() will be execured to reconfigure list of\nremote source mac addresses, at the same time, if register_netdevice()\nreturn an error, the resource generated by macvlan_changelink_sources()\nis not cleaned up.\n\nUsing this patch, in the case of an error, it will execute\nmacvlan_flush_sources() to ensure that the resource is cleaned up.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49853" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/21d3a8b6a1e39e7529ce9de07316ee13a63f305b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/23569b5652ee8e8e55a12f7835f59af6f3cefc30" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/685e73e3f7a9fb75cbf049a9d0b7c45cc6b57b2e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/956e0216a19994443c90ba2ea6b0b284c9c4f9cb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9ea003c4671b2fc455320ecf6d4a43b0a3c1878a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9f288e338be206713d79b29144c27fca4503c39b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a81b44d1df1f07f00c0dcc0a0b3d2fa24a46289e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a8d67367ab33604326cc37ab44fd1801bf5691ba" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rg5g-h6w9-p8cj/GHSA-rg5g-h6w9-p8cj.json b/advisories/unreviewed/2025/05/GHSA-rg5g-h6w9-p8cj/GHSA-rg5g-h6w9-p8cj.json new file mode 100644 index 00000000000..4c96c6e7d49 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-rg5g-h6w9-p8cj/GHSA-rg5g-h6w9-p8cj.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rg5g-h6w9-p8cj", + "modified": "2025-05-01T15:31:42Z", + "published": "2025-05-01T15:31:42Z", + "aliases": [ + "CVE-2025-37746" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nperf/dwc_pcie: fix duplicate pci_dev devices\n\nDuring platform_device_register, wrongly using struct device\npci_dev as platform_data caused a kmemdup copy of pci_dev. Worse\nstill, accessing the duplicated device leads to list corruption as its\nmutex content (e.g., list, magic) remains the same as the original.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37746" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7f35b429802a8065aa61e2a3f567089649f4d98e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a71c6fc87b2b9905dc2e38887fe4122287216be9" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T13:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rpgj-4c7v-rffq/GHSA-rpgj-4c7v-rffq.json b/advisories/unreviewed/2025/05/GHSA-rpgj-4c7v-rffq/GHSA-rpgj-4c7v-rffq.json new file mode 100644 index 00000000000..bc1eacb968b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-rpgj-4c7v-rffq/GHSA-rpgj-4c7v-rffq.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rpgj-4c7v-rffq", + "modified": "2025-05-01T15:31:46Z", + "published": "2025-05-01T15:31:46Z", + "aliases": [ + "CVE-2022-49785" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/sgx: Add overflow check in sgx_validate_offset_length()\n\nsgx_validate_offset_length() function verifies \"offset\" and \"length\"\narguments provided by userspace, but was missing an overflow check on\ntheir addition. Add it.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49785" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3b1c10fb754b0b67165e3f055a4208e5ba26dc89" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5277e3d633a5d4157987f4aff068caa55e36db19" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f0861f49bd946ff94fce4f82509c45e167f63690" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rrmw-h9hh-7q5m/GHSA-rrmw-h9hh-7q5m.json b/advisories/unreviewed/2025/05/GHSA-rrmw-h9hh-7q5m/GHSA-rrmw-h9hh-7q5m.json new file mode 100644 index 00000000000..a0b25d54eed --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-rrmw-h9hh-7q5m/GHSA-rrmw-h9hh-7q5m.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rrmw-h9hh-7q5m", + "modified": "2025-05-01T15:31:53Z", + "published": "2025-05-01T15:31:53Z", + "aliases": [ + "CVE-2022-49928" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nSUNRPC: Fix null-ptr-deref when xps sysfs alloc failed\n\nThere is a null-ptr-deref when xps sysfs alloc failed:\n BUG: KASAN: null-ptr-deref in sysfs_do_create_link_sd+0x40/0xd0\n Read of size 8 at addr 0000000000000030 by task gssproxy/457\n\n CPU: 5 PID: 457 Comm: gssproxy Not tainted 6.0.0-09040-g02357b27ee03 #9\n Call Trace:\n \n dump_stack_lvl+0x34/0x44\n kasan_report+0xa3/0x120\n sysfs_do_create_link_sd+0x40/0xd0\n rpc_sysfs_client_setup+0x161/0x1b0\n rpc_new_client+0x3fc/0x6e0\n rpc_create_xprt+0x71/0x220\n rpc_create+0x1d4/0x350\n gssp_rpc_create+0xc3/0x160\n set_gssp_clnt+0xbc/0x140\n write_gssp+0x116/0x1a0\n proc_reg_write+0xd6/0x130\n vfs_write+0x177/0x690\n ksys_write+0xb9/0x150\n do_syscall_64+0x35/0x80\n entry_SYSCALL_64_after_hwframe+0x46/0xb0\n\nWhen the xprt_switch sysfs alloc failed, should not add xprt and\nswitch sysfs to it, otherwise, maybe null-ptr-deref; also initialize\nthe 'xps_sysfs' to NULL to avoid oops when destroy it.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49928" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7b189b0aa8dab14b49c31c65af8a982e96e25b62" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cbdeaee94a415800c65a8c3fa04d9664a8b8fb3a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d59722d088a9d86ce6d9d39979e5d1d669d249f7" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rvcv-v2wq-wg64/GHSA-rvcv-v2wq-wg64.json b/advisories/unreviewed/2025/05/GHSA-rvcv-v2wq-wg64/GHSA-rvcv-v2wq-wg64.json new file mode 100644 index 00000000000..6e7588b7f25 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-rvcv-v2wq-wg64/GHSA-rvcv-v2wq-wg64.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rvcv-v2wq-wg64", + "modified": "2025-05-01T15:31:41Z", + "published": "2025-05-01T15:31:41Z", + "aliases": [ + "CVE-2025-23162" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe/vf: Don't try to trigger a full GT reset if VF\n\nVFs don't have access to the GDRST(0x941c) register that driver\nuses to reset a GT. Attempt to trigger a reset using debugfs:\n\n $ cat /sys/kernel/debug/dri/0000:00:02.1/gt0/force_reset\n\nor due to a hang condition detected by the driver leads to:\n\n [ ] xe 0000:00:02.1: [drm] GT0: trying reset from force_reset [xe]\n [ ] xe 0000:00:02.1: [drm] GT0: reset queued\n [ ] xe 0000:00:02.1: [drm] GT0: reset started\n [ ] ------------[ cut here ]------------\n [ ] xe 0000:00:02.1: [drm] GT0: VF is trying to write 0x1 to an inaccessible register 0x941c+0x0\n [ ] WARNING: CPU: 3 PID: 3069 at drivers/gpu/drm/xe/xe_gt_sriov_vf.c:996 xe_gt_sriov_vf_write32+0xc6/0x580 [xe]\n [ ] RIP: 0010:xe_gt_sriov_vf_write32+0xc6/0x580 [xe]\n [ ] Call Trace:\n [ ] \n [ ] ? show_regs+0x6c/0x80\n [ ] ? __warn+0x93/0x1c0\n [ ] ? xe_gt_sriov_vf_write32+0xc6/0x580 [xe]\n [ ] ? report_bug+0x182/0x1b0\n [ ] ? handle_bug+0x6e/0xb0\n [ ] ? exc_invalid_op+0x18/0x80\n [ ] ? asm_exc_invalid_op+0x1b/0x20\n [ ] ? xe_gt_sriov_vf_write32+0xc6/0x580 [xe]\n [ ] ? xe_gt_sriov_vf_write32+0xc6/0x580 [xe]\n [ ] ? xe_gt_tlb_invalidation_reset+0xef/0x110 [xe]\n [ ] ? __mutex_unlock_slowpath+0x41/0x2e0\n [ ] xe_mmio_write32+0x64/0x150 [xe]\n [ ] do_gt_reset+0x2f/0xa0 [xe]\n [ ] gt_reset_worker+0x14e/0x1e0 [xe]\n [ ] process_one_work+0x21c/0x740\n [ ] worker_thread+0x1db/0x3c0\n\nFix that by sending H2G VF_RESET(0x5507) action instead.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23162" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2eec2fa8666dcecebae33a565a818c9de9af8b50" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/459777724d306315070d24608fcd89aea85516d6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/90b16edb3213e4ae4a3138bb20703ae367e88a01" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a9bc61a61372897886f58fdaa5582e3f7bf9a50b" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T13:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-v3g9-9rfh-r7cr/GHSA-v3g9-9rfh-r7cr.json b/advisories/unreviewed/2025/05/GHSA-v3g9-9rfh-r7cr/GHSA-v3g9-9rfh-r7cr.json new file mode 100644 index 00000000000..ce4b5c3dd5b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-v3g9-9rfh-r7cr/GHSA-v3g9-9rfh-r7cr.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v3g9-9rfh-r7cr", + "modified": "2025-05-01T15:31:42Z", + "published": "2025-05-01T15:31:42Z", + "aliases": [ + "CVE-2025-37749" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ppp: Add bound checking for skb data on ppp_sync_txmung\n\nEnsure we have enough data in linear buffer from skb before accessing\ninitial bytes. This prevents potential out-of-bounds accesses\nwhen processing short packets.\n\nWhen ppp_sync_txmung receives an incoming package with an empty\npayload:\n(remote) gef➤ p *(struct pppoe_hdr *) (skb->head + skb->network_header)\n$18 = {\n\ttype = 0x1,\n\tver = 0x1,\n\tcode = 0x0,\n\tsid = 0x2,\n length = 0x0,\n\ttag = 0xffff8880371cdb96\n}\n\nfrom the skb struct (trimmed)\n tail = 0x16,\n end = 0x140,\n head = 0xffff88803346f400 \"4\",\n data = 0xffff88803346f416 \":\\377\",\n truesize = 0x380,\n len = 0x0,\n data_len = 0x0,\n mac_len = 0xe,\n hdr_len = 0x0,\n\nit is not safe to access data[2].\n\n[pabeni@redhat.com: fixed subj typo]", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37749" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1f6eb9fa87a781d5370c0de7794ae242f1a95ee5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6e8a6bf43cea4347121ab21bb1ed8d7bef7e732e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/aabc6596ffb377c4c9c8f335124b92ea282c9821" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b4c836d33ca888695b2f2665f948bc1b34fbd533" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b78f2b458f56a5a4d976c8e01c43dbf58d3ea2ca" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fbaffe8bccf148ece8ad67eb5d7aa852cabf59c8" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T13:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-v46c-rcr5-cw3j/GHSA-v46c-rcr5-cw3j.json b/advisories/unreviewed/2025/05/GHSA-v46c-rcr5-cw3j/GHSA-v46c-rcr5-cw3j.json new file mode 100644 index 00000000000..3c5d9c2bc32 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-v46c-rcr5-cw3j/GHSA-v46c-rcr5-cw3j.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v46c-rcr5-cw3j", + "modified": "2025-05-01T15:31:44Z", + "published": "2025-05-01T15:31:43Z", + "aliases": [ + "CVE-2025-37765" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/nouveau: prime: fix ttm_bo_delayed_delete oops\n\nFix an oops in ttm_bo_delayed_delete which results from dererencing a\ndangling pointer:\n\nOops: general protection fault, probably for non-canonical address 0x6b6b6b6b6b6b6b7b: 0000 [#1] PREEMPT SMP\nCPU: 4 UID: 0 PID: 1082 Comm: kworker/u65:2 Not tainted 6.14.0-rc4-00267-g505460b44513-dirty #216\nHardware name: LENOVO 82N6/LNVNB161216, BIOS GKCN65WW 01/16/2024\nWorkqueue: ttm ttm_bo_delayed_delete [ttm]\nRIP: 0010:dma_resv_iter_first_unlocked+0x55/0x290\nCode: 31 f6 48 c7 c7 00 2b fa aa e8 97 bd 52 ff e8 a2 c1 53 00 5a 85 c0 74 48 e9 88 01 00 00 4c 89 63 20 4d 85 e4 0f 84 30 01 00 00 <41> 8b 44 24 10 c6 43 2c 01 48 89 df 89 43 28 e8 97 fd ff ff 4c 8b\nRSP: 0018:ffffbf9383473d60 EFLAGS: 00010202\nRAX: 0000000000000001 RBX: ffffbf9383473d88 RCX: 0000000000000000\nRDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000\nRBP: ffffbf9383473d78 R08: 0000000000000000 R09: 0000000000000000\nR10: 0000000000000000 R11: 0000000000000000 R12: 6b6b6b6b6b6b6b6b\nR13: ffffa003bbf78580 R14: ffffa003a6728040 R15: 00000000000383cc\nFS: 0000000000000000(0000) GS:ffffa00991c00000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000758348024dd0 CR3: 000000012c259000 CR4: 0000000000f50ef0\nPKRU: 55555554\nCall Trace:\n \n ? __die_body.cold+0x19/0x26\n ? die_addr+0x3d/0x70\n ? exc_general_protection+0x159/0x460\n ? asm_exc_general_protection+0x27/0x30\n ? dma_resv_iter_first_unlocked+0x55/0x290\n dma_resv_wait_timeout+0x56/0x100\n ttm_bo_delayed_delete+0x69/0xb0 [ttm]\n process_one_work+0x217/0x5c0\n worker_thread+0x1c8/0x3d0\n ? apply_wqattrs_cleanup.part.0+0xc0/0xc0\n kthread+0x10b/0x240\n ? kthreads_online_cpu+0x140/0x140\n ret_from_fork+0x40/0x70\n ? kthreads_online_cpu+0x140/0x140\n ret_from_fork_asm+0x11/0x20\n \n\nThe cause of this is:\n\n- drm_prime_gem_destroy calls dma_buf_put(dma_buf) which releases the\n reference to the shared dma_buf. The reference count is 0, so the\n dma_buf is destroyed, which in turn decrements the corresponding\n amdgpu_bo reference count to 0, and the amdgpu_bo is destroyed -\n calling drm_gem_object_release then dma_resv_fini (which destroys the\n reservation object), then finally freeing the amdgpu_bo.\n\n- nouveau_bo obj->bo.base.resv is now a dangling pointer to the memory\n formerly allocated to the amdgpu_bo.\n\n- nouveau_gem_object_del calls ttm_bo_put(&nvbo->bo) which calls\n ttm_bo_release, which schedules ttm_bo_delayed_delete.\n\n- ttm_bo_delayed_delete runs and dereferences the dangling resv pointer,\n resulting in a general protection fault.\n\nFix this by moving the drm_prime_gem_destroy call from\nnouveau_gem_object_del to nouveau_bo_del_ttm. This ensures that it will\nbe run after ttm_bo_delayed_delete.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37765" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/12b038d521c75e3521522503becf3bc162628469" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/31e94c7989572f96926673614a3b958915a13ca9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6b95947ee780f4e1fb26413a1437d05bcb99712b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6e2c805996a49998d31ac522beb1534ca417e761" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8ec0fbb28d049273bfd4f1e7a5ae4c74884beed3" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T14:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-v49w-m7p6-cj8x/GHSA-v49w-m7p6-cj8x.json b/advisories/unreviewed/2025/05/GHSA-v49w-m7p6-cj8x/GHSA-v49w-m7p6-cj8x.json new file mode 100644 index 00000000000..74fbc110d4c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-v49w-m7p6-cj8x/GHSA-v49w-m7p6-cj8x.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v49w-m7p6-cj8x", + "modified": "2025-05-01T15:31:48Z", + "published": "2025-05-01T15:31:48Z", + "aliases": [ + "CVE-2022-49814" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nkcm: close race conditions on sk_receive_queue\n\nsk->sk_receive_queue is protected by skb queue lock, but for KCM\nsockets its RX path takes mux->rx_lock to protect more than just\nskb queue. However, kcm_recvmsg() still only grabs the skb queue\nlock, so race conditions still exist.\n\nWe can teach kcm_recvmsg() to grab mux->rx_lock too but this would\nintroduce a potential performance regression as struct kcm_mux can\nbe shared by multiple KCM sockets.\n\nSo we have to enforce skb queue lock in requeue_rx_msgs() and handle\nskb peek case carefully in kcm_wait_data(). Fortunately,\nskb_recv_datagram() already handles it nicely and is widely used by\nother sockets, we can just switch to skb_recv_datagram() after\ngetting rid of the unnecessary sock lock in kcm_recvmsg() and\nkcm_splice_read(). Side note: SOCK_DONE is not used by KCM sockets,\nso it is safe to get rid of this check too.\n\nI ran the original syzbot reproducer for 30 min without seeing any\nissue.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49814" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/22f6b5d47396b4287662668ee3f5c1f766cb4259" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4154b6afa2bd639214ff259d912faad984f7413a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5121197ecc5db58c07da95eb1ff82b98b121a221" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bf92e54597d842da127c59833b365d6faeeaf020" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ce57d6474ae999a3b2d442314087473a646a65c7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d9ad4de92e184b19bcae4da10dac0275abf83931" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f7b0e95071bb4be4b811af3f0bfc3e200eedeaa3" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-v832-47wf-r9vp/GHSA-v832-47wf-r9vp.json b/advisories/unreviewed/2025/05/GHSA-v832-47wf-r9vp/GHSA-v832-47wf-r9vp.json new file mode 100644 index 00000000000..792a0f4ce36 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-v832-47wf-r9vp/GHSA-v832-47wf-r9vp.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v832-47wf-r9vp", + "modified": "2025-05-01T15:31:51Z", + "published": "2025-05-01T15:31:50Z", + "aliases": [ + "CVE-2022-49872" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: gso: fix panic on frag_list with mixed head alloc types\n\nSince commit 3dcbdb134f32 (\"net: gso: Fix skb_segment splat when\nsplitting gso_size mangled skb having linear-headed frag_list\"), it is\nallowed to change gso_size of a GRO packet. However, that commit assumes\nthat \"checking the first list_skb member suffices; i.e if either of the\nlist_skb members have non head_frag head, then the first one has too\".\n\nIt turns out this assumption does not hold. We've seen BUG_ON being hit\nin skb_segment when skbs on the frag_list had differing head_frag with\nthe vmxnet3 driver. This happens because __netdev_alloc_skb and\n__napi_alloc_skb can return a skb that is page backed or kmalloced\ndepending on the requested size. As the result, the last small skb in\nthe GRO packet can be kmalloced.\n\nThere are three different locations where this can be fixed:\n\n(1) We could check head_frag in GRO and not allow GROing skbs with\n different head_frag. However, that would lead to performance\n regression on normal forward paths with unmodified gso_size, where\n !head_frag in the last packet is not a problem.\n\n(2) Set a flag in bpf_skb_net_grow and bpf_skb_net_shrink indicating\n that NETIF_F_SG is undesirable. That would need to eat a bit in\n sk_buff. Furthermore, that flag can be unset when all skbs on the\n frag_list are page backed. To retain good performance,\n bpf_skb_net_grow/shrink would have to walk the frag_list.\n\n(3) Walk the frag_list in skb_segment when determining whether\n NETIF_F_SG should be cleared. This of course slows things down.\n\nThis patch implements (3). To limit the performance impact in\nskb_segment, the list is walked only for skbs with SKB_GSO_DODGY set\nthat have gso_size changed. Normal paths thus will not hit it.\n\nWe could check only the last skb but since we need to walk the whole\nlist anyway, let's stay on the safe side.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49872" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0a9f56e525ea871d3950b90076912f5c7494f00f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/50868de7dc4e7f0fcadd6029f32bf4387c102ee6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5876b7f249a1ecbbcc8e35072c3828d6526d1c3a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/598d9e30927b15731e83797fbd700ecf399f42dd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/65ad047fd83502447269fda8fd26c99077a9af47" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9e4b7a99a03aefd37ba7bb1f022c8efab5019165" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ad25a115f50800c6847e0d841c5c7992a9f7c1b3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bd5362e58721e4d0d1a37796593bd6e51536ce7a" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-v99v-6wp3-34rf/GHSA-v99v-6wp3-34rf.json b/advisories/unreviewed/2025/05/GHSA-v99v-6wp3-34rf/GHSA-v99v-6wp3-34rf.json new file mode 100644 index 00000000000..b3a226d5ea1 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-v99v-6wp3-34rf/GHSA-v99v-6wp3-34rf.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v99v-6wp3-34rf", + "modified": "2025-05-01T15:31:42Z", + "published": "2025-05-01T15:31:42Z", + "aliases": [ + "CVE-2025-37743" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath12k: Avoid memory leak while enabling statistics\n\nDriver uses monitor destination rings for extended statistics mode and\nstandalone monitor mode. In extended statistics mode, TLVs are parsed from\nthe buffer received from the monitor destination ring and assigned to the\nppdu_info structure to update per-packet statistics. In standalone monitor\nmode, along with per-packet statistics, the packet data (payload) is\ncaptured, and the driver updates per MSDU to mac80211.\n\nWhen the AP interface is enabled, only extended statistics mode is\nactivated. As part of enabling monitor rings for collecting statistics,\nthe driver subscribes to HAL_RX_MPDU_START TLV in the filter\nconfiguration. This TLV is received from the monitor destination ring, and\nkzalloc for the mon_mpdu object occurs, which is not freed, leading to a\nmemory leak. The kzalloc for the mon_mpdu object is only required while\nenabling the standalone monitor interface. This causes a memory leak while\nenabling extended statistics mode in the driver.\n\nFix this memory leak by removing the kzalloc for the mon_mpdu object in\nthe HAL_RX_MPDU_START TLV handling. Additionally, remove the standalone\nmonitor mode handlings in the HAL_MON_BUF_ADDR and HAL_RX_MSDU_END TLVs.\nThese TLV tags will be handled properly when enabling standalone monitor\nmode in the future.\n\nTested-on: QCN9274 hw2.0 PCI WLAN.WBE.1.3.1-00173-QCAHKSWPL_SILICONZ-1\nTested-on: WCN7850 hw2.0 PCI WLAN.HMT.1.0.c5-00481-QCAHMTSWPL_V1.0_V2.0_SILICONZ-3", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37743" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/286bab0fc7b9db728dab8c63cadf6be9b3facf8c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ecfc131389923405be8e7a6f4408fd9321e4d19b" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T13:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vc2j-428r-9px5/GHSA-vc2j-428r-9px5.json b/advisories/unreviewed/2025/05/GHSA-vc2j-428r-9px5/GHSA-vc2j-428r-9px5.json new file mode 100644 index 00000000000..612f0986c7e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vc2j-428r-9px5/GHSA-vc2j-428r-9px5.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vc2j-428r-9px5", + "modified": "2025-05-01T15:31:46Z", + "published": "2025-05-01T15:31:46Z", + "aliases": [ + "CVE-2022-49770" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nceph: avoid putting the realm twice when decoding snaps fails\n\nWhen decoding the snaps fails it maybe leaving the 'first_realm'\nand 'realm' pointing to the same snaprealm memory. And then it'll\nput it twice and could cause random use-after-free, BUG_ON, etc\nissues.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49770" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/044bc6d3c2c0e9090b0841e7b723875756534b45" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/274e4c79a3a2a24fba7cfe0e41113f1138785c37" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2f6e2de3a5289004650118b61f138fe7c28e1905" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/51884d153f7ec85e18d607b2467820a90e0f4359" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cb7495fe957526555782ce0723f79ce92a6db22e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fd879c83e87735ab8f00ef7755752cf0cbae24b2" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vcw3-9m5f-w235/GHSA-vcw3-9m5f-w235.json b/advisories/unreviewed/2025/05/GHSA-vcw3-9m5f-w235/GHSA-vcw3-9m5f-w235.json new file mode 100644 index 00000000000..e1fb1972015 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vcw3-9m5f-w235/GHSA-vcw3-9m5f-w235.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vcw3-9m5f-w235", + "modified": "2025-05-01T15:31:53Z", + "published": "2025-05-01T15:31:53Z", + "aliases": [ + "CVE-2025-44837" + ], + "details": "TOTOLINK CPE CP900 V6.3c.1144_B20190715 was discovered to contain a command injection vulnerability in the CloudSrvUserdataVersionCheck function via the url or magicid parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44837" + }, + { + "type": "WEB", + "url": "https://github.com/n0wstr/IOTVuln/tree/main/CP900/CloudSrvUserdataVersionCheck" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vm29-jh4p-x8cp/GHSA-vm29-jh4p-x8cp.json b/advisories/unreviewed/2025/05/GHSA-vm29-jh4p-x8cp/GHSA-vm29-jh4p-x8cp.json new file mode 100644 index 00000000000..12730731be0 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vm29-jh4p-x8cp/GHSA-vm29-jh4p-x8cp.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vm29-jh4p-x8cp", + "modified": "2025-05-01T15:31:51Z", + "published": "2025-05-01T15:31:51Z", + "aliases": [ + "CVE-2022-49895" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncxl/region: Fix decoder allocation crash\n\nWhen an intermediate port's decoders have been exhausted by existing\nregions, and creating a new region with the port in question in it's\nhierarchical path is attempted, cxl_port_attach_region() fails to find a\nport decoder (as would be expected), and drops into the failure / cleanup\npath.\n\nHowever, during cleanup of the region reference, a sanity check attempts\nto dereference the decoder, which in the above case didn't exist. This\ncauses a NULL pointer dereference BUG.\n\nTo fix this, refactor the decoder allocation and de-allocation into\nhelper routines, and in this 'free' routine, check that the decoder,\n@cxld, is valid before attempting any operations on it.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49895" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/71ee71d7adcba648077997a29a91158d20c40b09" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c6813b5610ac53af73edd87a660d23a0511faa47" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vq36-qmwm-crh2/GHSA-vq36-qmwm-crh2.json b/advisories/unreviewed/2025/05/GHSA-vq36-qmwm-crh2/GHSA-vq36-qmwm-crh2.json new file mode 100644 index 00000000000..7d57320fc28 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vq36-qmwm-crh2/GHSA-vq36-qmwm-crh2.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vq36-qmwm-crh2", + "modified": "2025-05-01T15:31:51Z", + "published": "2025-05-01T15:31:51Z", + "aliases": [ + "CVE-2022-49885" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nACPI: APEI: Fix integer overflow in ghes_estatus_pool_init()\n\nChange num_ghes from int to unsigned int, preventing an overflow\nand causing subsequent vmalloc() to fail.\n\nThe overflow happens in ghes_estatus_pool_init() when calculating\nlen during execution of the statement below as both multiplication\noperands here are signed int:\n\nlen += (num_ghes * GHES_ESOURCE_PREALLOC_MAX_SIZE);\n\nThe following call trace is observed because of this bug:\n\n[ 9.317108] swapper/0: vmalloc error: size 18446744071562596352, exceeds total pages, mode:0xcc0(GFP_KERNEL), nodemask=(null),cpuset=/,mems_allowed=0-1\n[ 9.317131] Call Trace:\n[ 9.317134] \n[ 9.317137] dump_stack_lvl+0x49/0x5f\n[ 9.317145] dump_stack+0x10/0x12\n[ 9.317146] warn_alloc.cold+0x7b/0xdf\n[ 9.317150] ? __device_attach+0x16a/0x1b0\n[ 9.317155] __vmalloc_node_range+0x702/0x740\n[ 9.317160] ? device_add+0x17f/0x920\n[ 9.317164] ? dev_set_name+0x53/0x70\n[ 9.317166] ? platform_device_add+0xf9/0x240\n[ 9.317168] __vmalloc_node+0x49/0x50\n[ 9.317170] ? ghes_estatus_pool_init+0x43/0xa0\n[ 9.317176] vmalloc+0x21/0x30\n[ 9.317177] ghes_estatus_pool_init+0x43/0xa0\n[ 9.317179] acpi_hest_init+0x129/0x19c\n[ 9.317185] acpi_init+0x434/0x4a4\n[ 9.317188] ? acpi_sleep_proc_init+0x2a/0x2a\n[ 9.317190] do_one_initcall+0x48/0x200\n[ 9.317195] kernel_init_freeable+0x221/0x284\n[ 9.317200] ? rest_init+0xe0/0xe0\n[ 9.317204] kernel_init+0x1a/0x130\n[ 9.317205] ret_from_fork+0x22/0x30\n[ 9.317208] \n\n[ rjw: Subject and changelog edits ]", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49885" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/43d2748394c3feb86c0c771466f5847e274fc043" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4c10c854113720cbfe75d4f51db79b700a629e73" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9edf20e5a1d805855e78f241cf221d741b50d482" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c50ec15725e005e9fb20bce69b6c23b135a4a9b7" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vq6r-mvmf-6f45/GHSA-vq6r-mvmf-6f45.json b/advisories/unreviewed/2025/05/GHSA-vq6r-mvmf-6f45/GHSA-vq6r-mvmf-6f45.json new file mode 100644 index 00000000000..0f01a8a7fb0 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vq6r-mvmf-6f45/GHSA-vq6r-mvmf-6f45.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vq6r-mvmf-6f45", + "modified": "2025-05-01T15:31:41Z", + "published": "2025-05-01T15:31:41Z", + "aliases": [ + "CVE-2025-23153" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\narm/crc-t10dif: fix use of out-of-scope array in crc_t10dif_arch()\n\nFix a silly bug where an array was used outside of its scope.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23153" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3371f569223c4e8d36edbb0ba789ee5f5cb7316f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d8eba735be74e74776f9f6d9c691bdb75b08b29c" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T13:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vrw4-655g-rq7m/GHSA-vrw4-655g-rq7m.json b/advisories/unreviewed/2025/05/GHSA-vrw4-655g-rq7m/GHSA-vrw4-655g-rq7m.json new file mode 100644 index 00000000000..6fe8bfc67e2 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vrw4-655g-rq7m/GHSA-vrw4-655g-rq7m.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vrw4-655g-rq7m", + "modified": "2025-05-01T15:31:49Z", + "published": "2025-05-01T15:31:49Z", + "aliases": [ + "CVE-2022-49841" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nserial: imx: Add missing .thaw_noirq hook\n\nThe following warning is seen with non-console UART instance when\nsystem hibernates.\n\n[ 37.371969] ------------[ cut here ]------------\n[ 37.376599] uart3_root_clk already disabled\n[ 37.380810] WARNING: CPU: 0 PID: 296 at drivers/clk/clk.c:952 clk_core_disable+0xa4/0xb0\n...\n[ 37.506986] Call trace:\n[ 37.509432] clk_core_disable+0xa4/0xb0\n[ 37.513270] clk_disable+0x34/0x50\n[ 37.516672] imx_uart_thaw+0x38/0x5c\n[ 37.520250] platform_pm_thaw+0x30/0x6c\n[ 37.524089] dpm_run_callback.constprop.0+0x3c/0xd4\n[ 37.528972] device_resume+0x7c/0x160\n[ 37.532633] dpm_resume+0xe8/0x230\n[ 37.536036] hibernation_snapshot+0x288/0x430\n[ 37.540397] hibernate+0x10c/0x2e0\n[ 37.543798] state_store+0xc4/0xd0\n[ 37.547203] kobj_attr_store+0x1c/0x30\n[ 37.550953] sysfs_kf_write+0x48/0x60\n[ 37.554619] kernfs_fop_write_iter+0x118/0x1ac\n[ 37.559063] new_sync_write+0xe8/0x184\n[ 37.562812] vfs_write+0x230/0x290\n[ 37.566214] ksys_write+0x68/0xf4\n[ 37.569529] __arm64_sys_write+0x20/0x2c\n[ 37.573452] invoke_syscall.constprop.0+0x50/0xf0\n[ 37.578156] do_el0_svc+0x11c/0x150\n[ 37.581648] el0_svc+0x30/0x140\n[ 37.584792] el0t_64_sync_handler+0xe8/0xf0\n[ 37.588976] el0t_64_sync+0x1a0/0x1a4\n[ 37.592639] ---[ end trace 56e22eec54676d75 ]---\n\nOn hibernating, pm core calls into related hooks in sequence like:\n\n .freeze\n .freeze_noirq\n .thaw_noirq\n .thaw\n\nWith .thaw_noirq hook being absent, the clock will be disabled in a\nunbalanced call which results the warning above.\n\n imx_uart_freeze()\n clk_prepare_enable()\n imx_uart_suspend_noirq()\n clk_disable()\n imx_uart_thaw\n clk_disable_unprepare()\n\nAdding the missing .thaw_noirq hook as imx_uart_resume_noirq() will have\nthe call sequence corrected as below and thus fix the warning.\n\n imx_uart_freeze()\n clk_prepare_enable()\n imx_uart_suspend_noirq()\n clk_disable()\n imx_uart_resume_noirq()\n clk_enable()\n imx_uart_thaw\n clk_disable_unprepare()", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49841" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0a3160f4ffc70ee4bfa1521f698dace06e6091fd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4561d8008a467cb05ac632a215391d6b787f40aa" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/476b09e07bd519ec7ba5941a6a6f9a02256dbb21" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ae22294e213a402a70fa1731538367d1b758ffe7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e3f9d87d6f0732827c443bd1474df21c2fad704b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e401312ca6e180ee1bd65f6a766e99dd40aa95e7" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vv75-456q-6j78/GHSA-vv75-456q-6j78.json b/advisories/unreviewed/2025/05/GHSA-vv75-456q-6j78/GHSA-vv75-456q-6j78.json new file mode 100644 index 00000000000..a7043ac6999 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vv75-456q-6j78/GHSA-vv75-456q-6j78.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vv75-456q-6j78", + "modified": "2025-05-01T15:31:49Z", + "published": "2025-05-01T15:31:49Z", + "aliases": [ + "CVE-2022-49835" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: hda: fix potential memleak in 'add_widget_node'\n\nAs 'kobject_add' may allocated memory for 'kobject->name' when return error.\nAnd in this function, if call 'kobject_add' failed didn't free kobject.\nSo call 'kobject_put' to recycling resources.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49835" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/02dea987ec1cac712c78e75d224ceb9bb73519ed" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3a79f9568de08657fcdbc41d6fc4c0ca145a7a2b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/455d99bd6baf19688048b6d42d9fa74eae27f93b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7140d7aaf93da6a665b454f91bb4dc6b1de218bd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/90b7d055e2b5f39429f9a9e3815b48a48530ef28" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9a5523f72bd2b0d66eef3d58810c6eb7b5ffc143" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b688a3ec235222d9a84e43a48a6f31acb95baf2d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bb0ac8d5e541224f599bc8e8f31a313faa4bf7b7" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vvgj-gr7g-xwww/GHSA-vvgj-gr7g-xwww.json b/advisories/unreviewed/2025/05/GHSA-vvgj-gr7g-xwww/GHSA-vvgj-gr7g-xwww.json new file mode 100644 index 00000000000..3c55190ab87 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vvgj-gr7g-xwww/GHSA-vvgj-gr7g-xwww.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vvgj-gr7g-xwww", + "modified": "2025-05-01T15:31:39Z", + "published": "2025-05-01T15:31:39Z", + "aliases": [ + "CVE-2025-23140" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmisc: pci_endpoint_test: Avoid issue of interrupts remaining after request_irq error\n\nAfter devm_request_irq() fails with error in pci_endpoint_test_request_irq(),\nthe pci_endpoint_test_free_irq_vectors() is called assuming that all IRQs\nhave been released.\n\nHowever, some requested IRQs remain unreleased, so there are still\n/proc/irq/* entries remaining, and this results in WARN() with the\nfollowing message:\n\n remove_proc_entry: removing non-empty directory 'irq/30', leaking at least 'pci-endpoint-test.0'\n WARNING: CPU: 0 PID: 202 at fs/proc/generic.c:719 remove_proc_entry +0x190/0x19c\n\nTo solve this issue, set the number of remaining IRQs to test->num_irqs,\nand release IRQs in advance by calling pci_endpoint_test_release_irq().\n\n[kwilczynski: commit log]", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23140" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0557e70e2aeba8647bf5a950820b67cfb86533db" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5a4b7181213268c9b07bef8800905528435db44a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/770407f6173f4f39f4e2c1b54422b79ce6c98bdb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9d5118b107b1a2353ed0dff24404aee2e6b7ca0a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f6cb7828c8e17520d4f5afb416515d3fae1af9a9" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T13:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vvp4-j3wj-9jvq/GHSA-vvp4-j3wj-9jvq.json b/advisories/unreviewed/2025/05/GHSA-vvp4-j3wj-9jvq/GHSA-vvp4-j3wj-9jvq.json new file mode 100644 index 00000000000..6683469cabb --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vvp4-j3wj-9jvq/GHSA-vvp4-j3wj-9jvq.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vvp4-j3wj-9jvq", + "modified": "2025-05-01T15:31:49Z", + "published": "2025-05-01T15:31:49Z", + "aliases": [ + "CVE-2022-49837" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix memory leaks in __check_func_call\n\nkmemleak reports this issue:\n\nunreferenced object 0xffff88817139d000 (size 2048):\n comm \"test_progs\", pid 33246, jiffies 4307381979 (age 45851.820s)\n hex dump (first 32 bytes):\n 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n backtrace:\n [<0000000045f075f0>] kmalloc_trace+0x27/0xa0\n [<0000000098b7c90a>] __check_func_call+0x316/0x1230\n [<00000000b4c3c403>] check_helper_call+0x172e/0x4700\n [<00000000aa3875b7>] do_check+0x21d8/0x45e0\n [<000000001147357b>] do_check_common+0x767/0xaf0\n [<00000000b5a595b4>] bpf_check+0x43e3/0x5bc0\n [<0000000011e391b1>] bpf_prog_load+0xf26/0x1940\n [<0000000007f765c0>] __sys_bpf+0xd2c/0x3650\n [<00000000839815d6>] __x64_sys_bpf+0x75/0xc0\n [<00000000946ee250>] do_syscall_64+0x3b/0x90\n [<0000000000506b7f>] entry_SYSCALL_64_after_hwframe+0x63/0xcd\n\nThe root case here is: In function prepare_func_exit(), the callee is\nnot released in the abnormal scenario after \"state->curframe--;\". To\nfix, move \"state->curframe--;\" to the very bottom of the function,\nright when we free callee and reset frame[] pointer to NULL, as Andrii\nsuggested.\n\nIn addition, function __check_func_call() has a similar problem. In\nthe abnormal scenario before \"state->curframe++;\", the callee also\nshould be released by free_func_state().", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49837" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/83946d772e756734a900ef99dbe0aeda506adf37" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d4944497827a3d14bc5a26dbcfb7433eb5a956c0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/eb86559a691cea5fa63e57a03ec3dc9c31e97955" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vxf7-8458-rq8x/GHSA-vxf7-8458-rq8x.json b/advisories/unreviewed/2025/05/GHSA-vxf7-8458-rq8x/GHSA-vxf7-8458-rq8x.json new file mode 100644 index 00000000000..83d0b24a567 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vxf7-8458-rq8x/GHSA-vxf7-8458-rq8x.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vxf7-8458-rq8x", + "modified": "2025-05-01T15:31:48Z", + "published": "2025-05-01T15:31:48Z", + "aliases": [ + "CVE-2022-49817" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: mhi: Fix memory leak in mhi_net_dellink()\n\nMHI driver registers network device without setting the\nneeds_free_netdev flag, and does NOT call free_netdev() when\nunregisters network device, which causes a memory leak.\n\nThis patch calls free_netdev() to fix it since netdev_priv\nis used after unregister.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49817" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/25a270343b0f16e1f6e65f541a15975a35e238ff" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/88da008e5e2f9753726ea5a51ef2eb144e9de927" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f7c125bd79f50ec6094761090be81d02726ec6f4" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-w4x2-878r-xjgp/GHSA-w4x2-878r-xjgp.json b/advisories/unreviewed/2025/05/GHSA-w4x2-878r-xjgp/GHSA-w4x2-878r-xjgp.json new file mode 100644 index 00000000000..a651aa748fe --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-w4x2-878r-xjgp/GHSA-w4x2-878r-xjgp.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w4x2-878r-xjgp", + "modified": "2025-05-01T15:31:41Z", + "published": "2025-05-01T15:31:41Z", + "aliases": [ + "CVE-2025-23155" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: stmmac: Fix accessing freed irq affinity_hint\n\nThe cpumask should not be a local variable, since its pointer is saved\nto irq_desc and may be accessed from procfs.\nTo fix it, use the persistent mask cpumask_of(cpu#).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23155" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9e51a6a44e2c4de780a26e8fe110d708e806a8cd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c60d101a226f18e9a8f01bb4c6ca2b47dfcb15ef" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e148266e104fce396ad624079a6812ac3a9982ef" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T13:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-w595-4hr6-r5fv/GHSA-w595-4hr6-r5fv.json b/advisories/unreviewed/2025/05/GHSA-w595-4hr6-r5fv/GHSA-w595-4hr6-r5fv.json new file mode 100644 index 00000000000..d4b85600fd6 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-w595-4hr6-r5fv/GHSA-w595-4hr6-r5fv.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w595-4hr6-r5fv", + "modified": "2025-05-01T15:31:44Z", + "published": "2025-05-01T15:31:44Z", + "aliases": [ + "CVE-2025-37780" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nisofs: Prevent the use of too small fid\n\nsyzbot reported a slab-out-of-bounds Read in isofs_fh_to_parent. [1]\n\nThe handle_bytes value passed in by the reproducing program is equal to 12.\nIn handle_to_path(), only 12 bytes of memory are allocated for the structure\nfile_handle->f_handle member, which causes an out-of-bounds access when\naccessing the member parent_block of the structure isofs_fid in isofs,\nbecause accessing parent_block requires at least 16 bytes of f_handle.\nHere, fh_len is used to indirectly confirm that the value of handle_bytes\nis greater than 3 before accessing parent_block.\n\n[1]\nBUG: KASAN: slab-out-of-bounds in isofs_fh_to_parent+0x1b8/0x210 fs/isofs/export.c:183\nRead of size 4 at addr ffff0000cc030d94 by task syz-executor215/6466\nCPU: 1 UID: 0 PID: 6466 Comm: syz-executor215 Not tainted 6.14.0-rc7-syzkaller-ga2392f333575 #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/12/2025\nCall trace:\n show_stack+0x2c/0x3c arch/arm64/kernel/stacktrace.c:466 (C)\n __dump_stack lib/dump_stack.c:94 [inline]\n dump_stack_lvl+0xe4/0x150 lib/dump_stack.c:120\n print_address_description mm/kasan/report.c:408 [inline]\n print_report+0x198/0x550 mm/kasan/report.c:521\n kasan_report+0xd8/0x138 mm/kasan/report.c:634\n __asan_report_load4_noabort+0x20/0x2c mm/kasan/report_generic.c:380\n isofs_fh_to_parent+0x1b8/0x210 fs/isofs/export.c:183\n exportfs_decode_fh_raw+0x2dc/0x608 fs/exportfs/expfs.c:523\n do_handle_to_path+0xa0/0x198 fs/fhandle.c:257\n handle_to_path fs/fhandle.c:385 [inline]\n do_handle_open+0x8cc/0xb8c fs/fhandle.c:403\n __do_sys_open_by_handle_at fs/fhandle.c:443 [inline]\n __se_sys_open_by_handle_at fs/fhandle.c:434 [inline]\n __arm64_sys_open_by_handle_at+0x80/0x94 fs/fhandle.c:434\n __invoke_syscall arch/arm64/kernel/syscall.c:35 [inline]\n invoke_syscall+0x98/0x2b8 arch/arm64/kernel/syscall.c:49\n el0_svc_common+0x130/0x23c arch/arm64/kernel/syscall.c:132\n do_el0_svc+0x48/0x58 arch/arm64/kernel/syscall.c:151\n el0_svc+0x54/0x168 arch/arm64/kernel/entry-common.c:744\n el0t_64_sync_handler+0x84/0x108 arch/arm64/kernel/entry-common.c:762\n el0t_64_sync+0x198/0x19c arch/arm64/kernel/entry.S:600\n\nAllocated by task 6466:\n kasan_save_stack mm/kasan/common.c:47 [inline]\n kasan_save_track+0x40/0x78 mm/kasan/common.c:68\n kasan_save_alloc_info+0x40/0x50 mm/kasan/generic.c:562\n poison_kmalloc_redzone mm/kasan/common.c:377 [inline]\n __kasan_kmalloc+0xac/0xc4 mm/kasan/common.c:394\n kasan_kmalloc include/linux/kasan.h:260 [inline]\n __do_kmalloc_node mm/slub.c:4294 [inline]\n __kmalloc_noprof+0x32c/0x54c mm/slub.c:4306\n kmalloc_noprof include/linux/slab.h:905 [inline]\n handle_to_path fs/fhandle.c:357 [inline]\n do_handle_open+0x5a4/0xb8c fs/fhandle.c:403\n __do_sys_open_by_handle_at fs/fhandle.c:443 [inline]\n __se_sys_open_by_handle_at fs/fhandle.c:434 [inline]\n __arm64_sys_open_by_handle_at+0x80/0x94 fs/fhandle.c:434\n __invoke_syscall arch/arm64/kernel/syscall.c:35 [inline]\n invoke_syscall+0x98/0x2b8 arch/arm64/kernel/syscall.c:49\n el0_svc_common+0x130/0x23c arch/arm64/kernel/syscall.c:132\n do_el0_svc+0x48/0x58 arch/arm64/kernel/syscall.c:151\n el0_svc+0x54/0x168 arch/arm64/kernel/entry-common.c:744\n el0t_64_sync_handler+0x84/0x108 arch/arm64/kernel/entry-common.c:762\n el0t_64_sync+0x198/0x19c arch/arm64/kernel/entry.S:600", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37780" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/007124c896e7d4614ac1f6bd4dedb975c35a2a8e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0405d4b63d082861f4eaff9d39c78ee9dc34f845" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0fdafdaef796816a9ed0fd7ac812932d569d9beb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/56dfffea9fd3be0b3795a9ca6401e133a8427e0b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/952e7a7e317f126d0a2b879fc531b716932d5ffa" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T14:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-w642-f79m-mr3c/GHSA-w642-f79m-mr3c.json b/advisories/unreviewed/2025/05/GHSA-w642-f79m-mr3c/GHSA-w642-f79m-mr3c.json new file mode 100644 index 00000000000..661fd1fd022 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-w642-f79m-mr3c/GHSA-w642-f79m-mr3c.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w642-f79m-mr3c", + "modified": "2025-05-01T15:31:48Z", + "published": "2025-05-01T15:31:48Z", + "aliases": [ + "CVE-2022-49821" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmISDN: fix possible memory leak in mISDN_dsp_element_register()\n\nAfer commit 1fa5ae857bb1 (\"driver core: get rid of struct device's\nbus_id string array\"), the name of device is allocated dynamically,\nuse put_device() to give up the reference, so that the name can be\nfreed in kobject_cleanup() when the refcount is 0.\n\nThe 'entry' is going to be freed in mISDN_dsp_dev_release(), so the\nkfree() is removed. list_del() is called in mISDN_dsp_dev_release(),\nso it need be initialized.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49821" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/083a2c9ef82e184bdf0b9f9a1e5fc38d32afbb47" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0f2c681900a01e3f23789bca26d88268c3d5b51d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/727ed7d28348c026c7ef4d852f3d0e5054d376e8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7a05e3929668c8cfef495c69752a9e91fac4878f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/98a2ac1ca8fd6eca6867726fe238d06e75eb1acd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b119bedbefb7dd9ed8bf8cb9f1056504250d610e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bbd53d05c4c892080ef3b617eff4f57903acecb9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d4b8394725079670be309f9a35ad88a8cbbaaefd" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-w77p-v2rp-vmv8/GHSA-w77p-v2rp-vmv8.json b/advisories/unreviewed/2025/05/GHSA-w77p-v2rp-vmv8/GHSA-w77p-v2rp-vmv8.json new file mode 100644 index 00000000000..66652da6e36 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-w77p-v2rp-vmv8/GHSA-w77p-v2rp-vmv8.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w77p-v2rp-vmv8", + "modified": "2025-05-01T15:31:51Z", + "published": "2025-05-01T15:31:51Z", + "aliases": [ + "CVE-2022-49888" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\narm64: entry: avoid kprobe recursion\n\nThe cortex_a76_erratum_1463225_debug_handler() function is called when\nhandling debug exceptions (and synchronous exceptions from BRK\ninstructions), and so is called when a probed function executes. If the\ncompiler does not inline cortex_a76_erratum_1463225_debug_handler(), it\ncan be probed.\n\nIf cortex_a76_erratum_1463225_debug_handler() is probed, any debug\nexception or software breakpoint exception will result in recursive\nexceptions leading to a stack overflow. This can be triggered with the\nftrace multiple_probes selftest, and as per the example splat below.\n\nThis is a regression caused by commit:\n\n 6459b8469753e9fe (\"arm64: entry: consolidate Cortex-A76 erratum 1463225 workaround\")\n\n... which removed the NOKPROBE_SYMBOL() annotation associated with the\nfunction.\n\nMy intent was that cortex_a76_erratum_1463225_debug_handler() would be\ninlined into its caller, el1_dbg(), which is marked noinstr and cannot\nbe probed. Mark cortex_a76_erratum_1463225_debug_handler() as\n__always_inline to ensure this.\n\nExample splat prior to this patch (with recursive entries elided):\n\n| # echo p cortex_a76_erratum_1463225_debug_handler > /sys/kernel/debug/tracing/kprobe_events\n| # echo p do_el0_svc >> /sys/kernel/debug/tracing/kprobe_events\n| # echo 1 > /sys/kernel/debug/tracing/events/kprobes/enable\n| Insufficient stack space to handle exception!\n| ESR: 0x0000000096000047 -- DABT (current EL)\n| FAR: 0xffff800009cefff0\n| Task stack: [0xffff800009cf0000..0xffff800009cf4000]\n| IRQ stack: [0xffff800008000000..0xffff800008004000]\n| Overflow stack: [0xffff00007fbc00f0..0xffff00007fbc10f0]\n| CPU: 0 PID: 145 Comm: sh Not tainted 6.0.0 #2\n| Hardware name: linux,dummy-virt (DT)\n| pstate: 604003c5 (nZCv DAIF +PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n| pc : arm64_enter_el1_dbg+0x4/0x20\n| lr : el1_dbg+0x24/0x5c\n| sp : ffff800009cf0000\n| x29: ffff800009cf0000 x28: ffff000002c74740 x27: 0000000000000000\n| x26: 0000000000000000 x25: 0000000000000000 x24: 0000000000000000\n| x23: 00000000604003c5 x22: ffff80000801745c x21: 0000aaaac95ac068\n| x20: 00000000f2000004 x19: ffff800009cf0040 x18: 0000000000000000\n| x17: 0000000000000000 x16: 0000000000000000 x15: 0000000000000000\n| x14: 0000000000000000 x13: 0000000000000000 x12: 0000000000000000\n| x11: 0000000000000010 x10: ffff800008c87190 x9 : ffff800008ca00d0\n| x8 : 000000000000003c x7 : 0000000000000000 x6 : 0000000000000000\n| x5 : 0000000000000000 x4 : 0000000000000000 x3 : 00000000000043a4\n| x2 : 00000000f2000004 x1 : 00000000f2000004 x0 : ffff800009cf0040\n| Kernel panic - not syncing: kernel stack overflow\n| CPU: 0 PID: 145 Comm: sh Not tainted 6.0.0 #2\n| Hardware name: linux,dummy-virt (DT)\n| Call trace:\n| dump_backtrace+0xe4/0x104\n| show_stack+0x18/0x4c\n| dump_stack_lvl+0x64/0x7c\n| dump_stack+0x18/0x38\n| panic+0x14c/0x338\n| test_taint+0x0/0x2c\n| panic_bad_stack+0x104/0x118\n| handle_bad_stack+0x34/0x48\n| __bad_stack+0x78/0x7c\n| arm64_enter_el1_dbg+0x4/0x20\n| el1h_64_sync_handler+0x40/0x98\n| el1h_64_sync+0x64/0x68\n| cortex_a76_erratum_1463225_debug_handler+0x0/0x34\n...\n| el1h_64_sync_handler+0x40/0x98\n| el1h_64_sync+0x64/0x68\n| cortex_a76_erratum_1463225_debug_handler+0x0/0x34\n...\n| el1h_64_sync_handler+0x40/0x98\n| el1h_64_sync+0x64/0x68\n| cortex_a76_erratum_1463225_debug_handler+0x0/0x34\n| el1h_64_sync_handler+0x40/0x98\n| el1h_64_sync+0x64/0x68\n| do_el0_svc+0x0/0x28\n| el0t_64_sync_handler+0x84/0xf0\n| el0t_64_sync+0x18c/0x190\n| Kernel Offset: disabled\n| CPU features: 0x0080,00005021,19001080\n| Memory Limit: none\n| ---[ end Kernel panic - not syncing: kernel stack overflow ]---\n\nWith this patch, cortex_a76_erratum_1463225_debug_handler() is inlined\ninto el1_dbg(), and el1_dbg() cannot be probed:\n\n| # echo p cortex_a76_erratum_1463225_debug_handler > /sys/kernel/debug/tracing/kprobe_events\n| sh: write error: No such file or directory\n| # grep -w cortex_a76_errat\n---truncated---", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49888" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/024f4b2e1f874934943eb2d3d288ebc52c79f55c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/71d6c33fe223255f4416a01514da2c0bc3e283e7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/db66629d43b2d12cb43b004a4ca6be1d03228e97" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-w8jp-xg39-86rf/GHSA-w8jp-xg39-86rf.json b/advisories/unreviewed/2025/05/GHSA-w8jp-xg39-86rf/GHSA-w8jp-xg39-86rf.json new file mode 100644 index 00000000000..c23f7c76438 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-w8jp-xg39-86rf/GHSA-w8jp-xg39-86rf.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w8jp-xg39-86rf", + "modified": "2025-05-01T15:31:42Z", + "published": "2025-05-01T15:31:42Z", + "aliases": [ + "CVE-2025-37751" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/cpu: Avoid running off the end of an AMD erratum table\n\nThe NULL array terminator at the end of erratum_1386_microcode was\nremoved during the switch from x86_cpu_desc to x86_cpu_id. This\ncauses readers to run off the end of the array.\n\nReplace the NULL.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37751" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1b518f73f1b6f59e083ec33dea22d9a1a275a970" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f0df00ebc57f803603f2a2e0df197e51f06fbe90" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T13:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-w983-x7cf-qq48/GHSA-w983-x7cf-qq48.json b/advisories/unreviewed/2025/05/GHSA-w983-x7cf-qq48/GHSA-w983-x7cf-qq48.json new file mode 100644 index 00000000000..ab2c986938f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-w983-x7cf-qq48/GHSA-w983-x7cf-qq48.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w983-x7cf-qq48", + "modified": "2025-05-01T15:31:52Z", + "published": "2025-05-01T15:31:51Z", + "aliases": [ + "CVE-2022-49892" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nftrace: Fix use-after-free for dynamic ftrace_ops\n\nKASAN reported a use-after-free with ftrace ops [1]. It was found from\nvmcore that perf had registered two ops with the same content\nsuccessively, both dynamic. After unregistering the second ops, a\nuse-after-free occurred.\n\nIn ftrace_shutdown(), when the second ops is unregistered, the\nFTRACE_UPDATE_CALLS command is not set because there is another enabled\nops with the same content. Also, both ops are dynamic and the ftrace\ncallback function is ftrace_ops_list_func, so the\nFTRACE_UPDATE_TRACE_FUNC command will not be set. Eventually the value\nof 'command' will be 0 and ftrace_shutdown() will skip the rcu\nsynchronization.\n\nHowever, ftrace may be activated. When the ops is released, another CPU\nmay be accessing the ops. Add the missing synchronization to fix this\nproblem.\n\n[1]\nBUG: KASAN: use-after-free in __ftrace_ops_list_func kernel/trace/ftrace.c:7020 [inline]\nBUG: KASAN: use-after-free in ftrace_ops_list_func+0x2b0/0x31c kernel/trace/ftrace.c:7049\nRead of size 8 at addr ffff56551965bbc8 by task syz-executor.2/14468\n\nCPU: 1 PID: 14468 Comm: syz-executor.2 Not tainted 5.10.0 #7\nHardware name: linux,dummy-virt (DT)\nCall trace:\n dump_backtrace+0x0/0x40c arch/arm64/kernel/stacktrace.c:132\n show_stack+0x30/0x40 arch/arm64/kernel/stacktrace.c:196\n __dump_stack lib/dump_stack.c:77 [inline]\n dump_stack+0x1b4/0x248 lib/dump_stack.c:118\n print_address_description.constprop.0+0x28/0x48c mm/kasan/report.c:387\n __kasan_report mm/kasan/report.c:547 [inline]\n kasan_report+0x118/0x210 mm/kasan/report.c:564\n check_memory_region_inline mm/kasan/generic.c:187 [inline]\n __asan_load8+0x98/0xc0 mm/kasan/generic.c:253\n __ftrace_ops_list_func kernel/trace/ftrace.c:7020 [inline]\n ftrace_ops_list_func+0x2b0/0x31c kernel/trace/ftrace.c:7049\n ftrace_graph_call+0x0/0x4\n __might_sleep+0x8/0x100 include/linux/perf_event.h:1170\n __might_fault mm/memory.c:5183 [inline]\n __might_fault+0x58/0x70 mm/memory.c:5171\n do_strncpy_from_user lib/strncpy_from_user.c:41 [inline]\n strncpy_from_user+0x1f4/0x4b0 lib/strncpy_from_user.c:139\n getname_flags+0xb0/0x31c fs/namei.c:149\n getname+0x2c/0x40 fs/namei.c:209\n [...]\n\nAllocated by task 14445:\n kasan_save_stack+0x24/0x50 mm/kasan/common.c:48\n kasan_set_track mm/kasan/common.c:56 [inline]\n __kasan_kmalloc mm/kasan/common.c:479 [inline]\n __kasan_kmalloc.constprop.0+0x110/0x13c mm/kasan/common.c:449\n kasan_kmalloc+0xc/0x14 mm/kasan/common.c:493\n kmem_cache_alloc_trace+0x440/0x924 mm/slub.c:2950\n kmalloc include/linux/slab.h:563 [inline]\n kzalloc include/linux/slab.h:675 [inline]\n perf_event_alloc.part.0+0xb4/0x1350 kernel/events/core.c:11230\n perf_event_alloc kernel/events/core.c:11733 [inline]\n __do_sys_perf_event_open kernel/events/core.c:11831 [inline]\n __se_sys_perf_event_open+0x550/0x15f4 kernel/events/core.c:11723\n __arm64_sys_perf_event_open+0x6c/0x80 kernel/events/core.c:11723\n [...]\n\nFreed by task 14445:\n kasan_save_stack+0x24/0x50 mm/kasan/common.c:48\n kasan_set_track+0x24/0x34 mm/kasan/common.c:56\n kasan_set_free_info+0x20/0x40 mm/kasan/generic.c:358\n __kasan_slab_free.part.0+0x11c/0x1b0 mm/kasan/common.c:437\n __kasan_slab_free mm/kasan/common.c:445 [inline]\n kasan_slab_free+0x2c/0x40 mm/kasan/common.c:446\n slab_free_hook mm/slub.c:1569 [inline]\n slab_free_freelist_hook mm/slub.c:1608 [inline]\n slab_free mm/slub.c:3179 [inline]\n kfree+0x12c/0xc10 mm/slub.c:4176\n perf_event_alloc.part.0+0xa0c/0x1350 kernel/events/core.c:11434\n perf_event_alloc kernel/events/core.c:11733 [inline]\n __do_sys_perf_event_open kernel/events/core.c:11831 [inline]\n __se_sys_perf_event_open+0x550/0x15f4 kernel/events/core.c:11723\n [...]", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49892" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0e792b89e6800cd9cb4757a76a96f7ef3e8b6294" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/88561a66777e7a2fe06638c6dcb22a9fae0b6733" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cc1b9961a0ceb70f6ca4e2f4b8bb71c87c7a495c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ea5f2fd4640ecbb9df969bf8bb27733ae2183169" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-w9wh-q8v9-3rwf/GHSA-w9wh-q8v9-3rwf.json b/advisories/unreviewed/2025/05/GHSA-w9wh-q8v9-3rwf/GHSA-w9wh-q8v9-3rwf.json new file mode 100644 index 00000000000..21bdd237275 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-w9wh-q8v9-3rwf/GHSA-w9wh-q8v9-3rwf.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w9wh-q8v9-3rwf", + "modified": "2025-05-01T15:31:51Z", + "published": "2025-05-01T15:31:51Z", + "aliases": [ + "CVE-2022-49889" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nring-buffer: Check for NULL cpu_buffer in ring_buffer_wake_waiters()\n\nOn some machines the number of listed CPUs may be bigger than the actual\nCPUs that exist. The tracing subsystem allocates a per_cpu directory with\naccess to the per CPU ring buffer via a cpuX file. But to save space, the\nring buffer will only allocate buffers for online CPUs, even though the\nCPU array will be as big as the nr_cpu_ids.\n\nWith the addition of waking waiters on the ring buffer when closing the\nfile, the ring_buffer_wake_waiters() now needs to make sure that the\nbuffer is allocated (with the irq_work allocated with it) before trying to\nwake waiters, as it will cause a NULL pointer dereference.\n\nWhile debugging this, I added a NULL check for the buffer itself (which is\nOK to do), and also NULL pointer checks against buffer->buffers (which is\nnot fine, and will WARN) as well as making sure the CPU number passed in\nis within the nr_cpu_ids (which is also not fine if it isn't).\n\n\nBugzilla: https://bugzilla.opensuse.org/show_bug.cgi?id=1204705", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49889" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/49ca992f6e50d0f46ec9608f44e011cf3121f389" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7433632c9ff68a991bd0bc38cabf354e9d2de410" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b5074df412bf3df9d6ce096b6fa03eb1082d05c9" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-wcv7-qxr2-whrg/GHSA-wcv7-qxr2-whrg.json b/advisories/unreviewed/2025/05/GHSA-wcv7-qxr2-whrg/GHSA-wcv7-qxr2-whrg.json new file mode 100644 index 00000000000..8bbb95e067b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-wcv7-qxr2-whrg/GHSA-wcv7-qxr2-whrg.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wcv7-qxr2-whrg", + "modified": "2025-05-01T15:31:42Z", + "published": "2025-05-01T15:31:42Z", + "aliases": [ + "CVE-2025-37753" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ns390/cpumf: Fix double free on error in cpumf_pmu_event_init()\n\nIn PMU event initialization functions\n - cpumsf_pmu_event_init()\n - cpumf_pmu_event_init()\n - cfdiag_event_init()\nthe partially created event had to be removed when an error was detected.\nThe event::event_init() member function had to release all resources\nit allocated in case of error. event::destroy() had to be called\non freeing an event after it was successfully created and\nevent::event_init() returned success.\n\nWith\n\ncommit c70ca298036c (\"perf/core: Simplify the perf_event_alloc() error path\")\n\nthis is not necessary anymore. The performance subsystem common\ncode now always calls event::destroy() to clean up the allocated\nresources created during event initialization.\n\nRemove the event::destroy() invocation in PMU event initialization\nor that function is called twice for each event that runs into an\nerror condition in event creation.\n\nThis is the kernel log entry which shows up without the fix:\n\n------------[ cut here ]------------\nrefcount_t: underflow; use-after-free.\nWARNING: CPU: 0 PID: 43388 at lib/refcount.c:87\trefcount_dec_not_one+0x74/0x90\nCPU: 0 UID: 0 PID: 43388 Comm: perf Not tainted 6.15.0-20250407.rc1.git0.300.fc41.s390x+git #1 NONE\nHardware name: IBM 3931 A01 704 (LPAR)\nKrnl PSW : 0704c00180000000 00000209cb2c1b88 (refcount_dec_not_one+0x78/0x90)\n R:0 T:1 IO:1 EX:1 Key:0 M:1 W:0 P:0 AS:3 CC:0 PM:0 RI:0 EA:3\nKrnl GPRS: 0000020900000027 0000020900000023 0000000000000026 0000018900000000\n 00000004a2200a00 0000000000000000 0000000000000057 ffffffffffffffea\n 00000002b386c600 00000002b3f5b3e0 00000209cc51f140 00000209cc7fc550\n 0000000001449d38 ffffffffffffffff 00000209cb2c1b84 00000189d67dfb80\nKrnl Code: 00000209cb2c1b78: c02000506727\tlarl\t%r2,00000209cbcce9c6\n 00000209cb2c1b7e: c0e5ffbd4431\tbrasl\t%r14,00000209caa6a3e0\n #00000209cb2c1b84: af000000\t\tmc\t0,0\n >00000209cb2c1b88: a7480001\t\tlhi\t%r4,1\n 00000209cb2c1b8c: ebeff0a00004\tlmg\t%r14,%r15,160(%r15)\n 00000209cb2c1b92: ec243fbf0055\trisbg\t%r2,%r4,63,191,0\n 00000209cb2c1b98: 07fe\t\tbcr\t15,%r14\n 00000209cb2c1b9a: 47000700\t\tbc\t0,1792\nCall Trace:\n [<00000209cb2c1b88>] refcount_dec_not_one+0x78/0x90\n [<00000209cb2c1dc4>] refcount_dec_and_mutex_lock+0x24/0x90\n [<00000209caa3c29e>] hw_perf_event_destroy+0x2e/0x80\n [<00000209cacaf8b4>] __free_event+0x74/0x270\n [<00000209cacb47c4>] perf_event_alloc.part.0+0x4a4/0x730\n [<00000209cacbf3e8>] __do_sys_perf_event_open+0x248/0xc20\n [<00000209cacc14a4>] __s390x_sys_perf_event_open+0x44/0x50\n [<00000209cb8114de>] __do_syscall+0x12e/0x260\n [<00000209cb81ce34>] system_call+0x74/0x98\nLast Breaking-Event-Address:\n [<00000209caa6a4d2>] __warn_printk+0xf2/0x100\n---[ end trace 0000000000000000 ]---", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37753" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3a3faf873db5dcd5d2622d8e2accb90af0a86c2d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/aa1ac98268cd1f380c713f07e39b1fa1d5c7650c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bdbecb2bf531fadbbc9347a79009f7a58ea7eb03" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ddf60c1491102dab04491481bc3376d3e9cd139d" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T13:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-whm8-436x-pvrj/GHSA-whm8-436x-pvrj.json b/advisories/unreviewed/2025/05/GHSA-whm8-436x-pvrj/GHSA-whm8-436x-pvrj.json new file mode 100644 index 00000000000..d4a56bfe8c2 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-whm8-436x-pvrj/GHSA-whm8-436x-pvrj.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-whm8-436x-pvrj", + "modified": "2025-05-01T15:31:50Z", + "published": "2025-05-01T15:31:50Z", + "aliases": [ + "CVE-2022-49852" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nriscv: process: fix kernel info leakage\n\nthread_struct's s[12] may contain random kernel memory content, which\nmay be finally leaked to userspace. This is a security hole. Fix it\nby clearing the s[12] array in thread_struct when fork.\n\nAs for kthread case, it's better to clear the s[12] array as well.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49852" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/358a68f98304b40b201ba5afe94c20355aa3dc68" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6510c78490c490a6636e48b61eeaa6fb65981f4b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c4601d30f7d989b4f354df899ab85b5f7a750d30" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c5c0b3167537793a7cf936fb240366eefd2fc7fb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cc36c7fa5d9384602529ba3eea8c5daee7be4dbc" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e56d18a976dda653194218df6d40d8122c775712" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-whp8-mg46-9399/GHSA-whp8-mg46-9399.json b/advisories/unreviewed/2025/05/GHSA-whp8-mg46-9399/GHSA-whp8-mg46-9399.json new file mode 100644 index 00000000000..0beaad24ad6 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-whp8-mg46-9399/GHSA-whp8-mg46-9399.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-whp8-mg46-9399", + "modified": "2025-05-01T15:31:48Z", + "published": "2025-05-01T15:31:48Z", + "aliases": [ + "CVE-2022-49820" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmctp i2c: don't count unused / invalid keys for flow release\n\nWe're currently hitting the WARN_ON in mctp_i2c_flow_release:\n\n if (midev->release_count > midev->i2c_lock_count) {\n WARN_ONCE(1, \"release count overflow\");\n\nThis may be hit if we expire a flow before sending the first packet it\ncontains - as we will not be pairing the increment of release_count\n(performed on flow release) with the i2c lock operation (only\nperformed on actual TX).\n\nTo fix this, only release a flow if we've encountered it previously (ie,\ndev_flow_state does not indicate NEW), as we will mark the flow as\nACTIVE at the same time as accounting for the i2c lock operation. We\nalso need to add an INVALID flow state, to indicate when we've done the\nrelease.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49820" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9cbd48d5fa14e4c65f8580de16686077f7cea02b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a5915a9a3ab4067ef8996a57738d156eabeb3a12" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-whrx-8qvw-6p89/GHSA-whrx-8qvw-6p89.json b/advisories/unreviewed/2025/05/GHSA-whrx-8qvw-6p89/GHSA-whrx-8qvw-6p89.json new file mode 100644 index 00000000000..1a7723f1dbc --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-whrx-8qvw-6p89/GHSA-whrx-8qvw-6p89.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-whrx-8qvw-6p89", + "modified": "2025-05-01T15:31:47Z", + "published": "2025-05-01T15:31:47Z", + "aliases": [ + "CVE-2022-49803" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetdevsim: Fix memory leak of nsim_dev->fa_cookie\n\nkmemleak reports this issue:\n\nunreferenced object 0xffff8881bac872d0 (size 8):\n comm \"sh\", pid 58603, jiffies 4481524462 (age 68.065s)\n hex dump (first 8 bytes):\n 04 00 00 00 de ad be ef ........\n backtrace:\n [<00000000c80b8577>] __kmalloc+0x49/0x150\n [<000000005292b8c6>] nsim_dev_trap_fa_cookie_write+0xc1/0x210 [netdevsim]\n [<0000000093d78e77>] full_proxy_write+0xf3/0x180\n [<000000005a662c16>] vfs_write+0x1c5/0xaf0\n [<000000007aabf84a>] ksys_write+0xed/0x1c0\n [<000000005f1d2e47>] do_syscall_64+0x3b/0x90\n [<000000006001c6ec>] entry_SYSCALL_64_after_hwframe+0x63/0xcd\n\nThe issue occurs in the following scenarios:\n\nnsim_dev_trap_fa_cookie_write()\n kmalloc() fa_cookie\n nsim_dev->fa_cookie = fa_cookie\n..\nnsim_drv_remove()\n\nThe fa_cookie allocked in nsim_dev_trap_fa_cookie_write() is not freed. To\nfix, add kfree(nsim_dev->fa_cookie) to nsim_drv_remove().", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49803" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/064bc7312bd09a48798418663090be0c776183db" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/207edad5717e0a5709ce8467f0eff41c607835c9" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-wmr5-8rgc-r7p9/GHSA-wmr5-8rgc-r7p9.json b/advisories/unreviewed/2025/05/GHSA-wmr5-8rgc-r7p9/GHSA-wmr5-8rgc-r7p9.json new file mode 100644 index 00000000000..6ddfbbbd70a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-wmr5-8rgc-r7p9/GHSA-wmr5-8rgc-r7p9.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wmr5-8rgc-r7p9", + "modified": "2025-05-01T15:31:43Z", + "published": "2025-05-01T15:31:43Z", + "aliases": [ + "CVE-2025-37759" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nublk: fix handling recovery & reissue in ublk_abort_queue()\n\nCommit 8284066946e6 (\"ublk: grab request reference when the request is handled\nby userspace\") doesn't grab request reference in case of recovery reissue.\nThen the request can be requeued & re-dispatch & failed when canceling\nuring command.\n\nIf it is one zc request, the request can be freed before io_uring\nreturns the zc buffer back, then cause kernel panic:\n\n[ 126.773061] BUG: kernel NULL pointer dereference, address: 00000000000000c8\n[ 126.773657] #PF: supervisor read access in kernel mode\n[ 126.774052] #PF: error_code(0x0000) - not-present page\n[ 126.774455] PGD 0 P4D 0\n[ 126.774698] Oops: Oops: 0000 [#1] SMP NOPTI\n[ 126.775034] CPU: 13 UID: 0 PID: 1612 Comm: kworker/u64:55 Not tainted 6.14.0_blk+ #182 PREEMPT(full)\n[ 126.775676] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-1.fc39 04/01/2014\n[ 126.776275] Workqueue: iou_exit io_ring_exit_work\n[ 126.776651] RIP: 0010:ublk_io_release+0x14/0x130 [ublk_drv]\n\nFixes it by always grabbing request reference for aborting the request.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37759" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0a21d259ca4d6310fdfcc0284ebbc000e66cbf70" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5d34a30efac9c9c93e150130caa940c0df6053c1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6ee6bd5d4fce502a5b5a2ea805e9ff16e6aa890f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/caa5c8a2358604f38bf0a4afaa5eacda13763067" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T13:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-wqr7-3rhv-2c6r/GHSA-wqr7-3rhv-2c6r.json b/advisories/unreviewed/2025/05/GHSA-wqr7-3rhv-2c6r/GHSA-wqr7-3rhv-2c6r.json new file mode 100644 index 00000000000..7a4aa8b12d2 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-wqr7-3rhv-2c6r/GHSA-wqr7-3rhv-2c6r.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wqr7-3rhv-2c6r", + "modified": "2025-05-01T15:31:47Z", + "published": "2025-05-01T15:31:47Z", + "aliases": [ + "CVE-2022-49795" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nrethook: fix a potential memleak in rethook_alloc()\n\nIn rethook_alloc(), the variable rh is not freed or passed out\nif handler is NULL, which could lead to a memleak, fix it.\n\n[Masami: Add \"rethook:\" tag to the title.]\n\nAcke-by: Masami Hiramatsu (Google) ", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49795" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0a1ebe35cb3b7aa1f4b26b37e2a0b9ae68dc4ffb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cbc5d1f9a8cc40ba2bc6779b36d2ea1f65bc027c" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-wx6j-jwh7-wq64/GHSA-wx6j-jwh7-wq64.json b/advisories/unreviewed/2025/05/GHSA-wx6j-jwh7-wq64/GHSA-wx6j-jwh7-wq64.json new file mode 100644 index 00000000000..e2cb309c488 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-wx6j-jwh7-wq64/GHSA-wx6j-jwh7-wq64.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wx6j-jwh7-wq64", + "modified": "2025-05-01T15:31:47Z", + "published": "2025-05-01T15:31:47Z", + "aliases": [ + "CVE-2022-49807" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet: fix a memory leak in nvmet_auth_set_key\n\nWhen changing dhchap secrets we need to release the old\nsecrets as well.\n\nkmemleak complaint:\n--\nunreferenced object 0xffff8c7f44ed8180 (size 64):\n comm \"check\", pid 7304, jiffies 4295686133 (age 72034.246s)\n hex dump (first 32 bytes):\n 44 48 48 43 2d 31 3a 30 30 3a 4c 64 4c 4f 64 71 DHHC-1:00:LdLOdq\n 79 56 69 67 77 48 55 32 6d 5a 59 4c 7a 35 59 38 yVigwHU2mZYLz5Y8\n backtrace:\n [<00000000b6fc5071>] kstrdup+0x2e/0x60\n [<00000000f0f4633f>] 0xffffffffc0e07ee6\n [<0000000053006c05>] 0xffffffffc0dff783\n [<00000000419ae922>] configfs_write_iter+0xb1/0x120\n [<000000008183c424>] vfs_write+0x2be/0x3c0\n [<000000009005a2a5>] ksys_write+0x5f/0xe0\n [<00000000cd495c89>] do_syscall_64+0x38/0x90\n [<00000000f2a84ac5>] entry_SYSCALL_64_after_hwframe+0x63/0xcd", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49807" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0a52566279b4ee65ecd2503d7b7342851f84755c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/65710ea51d4a185592c7b14c9e33d0c4a364f074" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-wx74-4w24-9hwf/GHSA-wx74-4w24-9hwf.json b/advisories/unreviewed/2025/05/GHSA-wx74-4w24-9hwf/GHSA-wx74-4w24-9hwf.json new file mode 100644 index 00000000000..083dc928970 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-wx74-4w24-9hwf/GHSA-wx74-4w24-9hwf.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wx74-4w24-9hwf", + "modified": "2025-05-01T15:31:52Z", + "published": "2025-05-01T15:31:52Z", + "aliases": [ + "CVE-2022-49911" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: ipset: enforce documented limit to prevent allocating huge memory\n\nDaniel Xu reported that the hash:net,iface type of the ipset subsystem does\nnot limit adding the same network with different interfaces to a set, which\ncan lead to huge memory usage or allocation failure.\n\nThe quick reproducer is\n\n$ ipset create ACL.IN.ALL_PERMIT hash:net,iface hashsize 1048576 timeout 0\n$ for i in $(seq 0 100); do /sbin/ipset add ACL.IN.ALL_PERMIT 0.0.0.0/0,kaf_$i timeout 0 -exist; done\n\nThe backtrace when vmalloc fails:\n\n [Tue Oct 25 00:13:08 2022] ipset: vmalloc error: size 1073741848, exceeds total pages\n <...>\n [Tue Oct 25 00:13:08 2022] Call Trace:\n [Tue Oct 25 00:13:08 2022] \n [Tue Oct 25 00:13:08 2022] dump_stack_lvl+0x48/0x60\n [Tue Oct 25 00:13:08 2022] warn_alloc+0x155/0x180\n [Tue Oct 25 00:13:08 2022] __vmalloc_node_range+0x72a/0x760\n [Tue Oct 25 00:13:08 2022] ? hash_netiface4_add+0x7c0/0xb20\n [Tue Oct 25 00:13:08 2022] ? __kmalloc_large_node+0x4a/0x90\n [Tue Oct 25 00:13:08 2022] kvmalloc_node+0xa6/0xd0\n [Tue Oct 25 00:13:08 2022] ? hash_netiface4_resize+0x99/0x710\n <...>\n\nThe fix is to enforce the limit documented in the ipset(8) manpage:\n\n> The internal restriction of the hash:net,iface set type is that the same\n> network prefix cannot be stored with more than 64 different interfaces\n> in a single set.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49911" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/42d20d5e24575c9afa2d66d9a51e7386db9514f5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/510841da1fcc16f702440ab58ef0b4d82a9056b7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a37ef32fe5956fe9248df68f6a61997845ba047e" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-wxgf-7f8j-hr6j/GHSA-wxgf-7f8j-hr6j.json b/advisories/unreviewed/2025/05/GHSA-wxgf-7f8j-hr6j/GHSA-wxgf-7f8j-hr6j.json new file mode 100644 index 00000000000..a8b2b2be810 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-wxgf-7f8j-hr6j/GHSA-wxgf-7f8j-hr6j.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wxgf-7f8j-hr6j", + "modified": "2025-05-01T15:31:51Z", + "published": "2025-05-01T15:31:51Z", + "aliases": [ + "CVE-2022-49890" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncapabilities: fix potential memleak on error path from vfs_getxattr_alloc()\n\nIn cap_inode_getsecurity(), we will use vfs_getxattr_alloc() to\ncomplete the memory allocation of tmpbuf, if we have completed\nthe memory allocation of tmpbuf, but failed to call handler->get(...),\nthere will be a memleak in below logic:\n\n |-- ret = (int)vfs_getxattr_alloc(mnt_userns, ...)\n | /* ^^^ alloc for tmpbuf */\n |-- value = krealloc(*xattr_value, error + 1, flags)\n | /* ^^^ alloc memory */\n |-- error = handler->get(handler, ...)\n | /* error! */\n |-- *xattr_value = value\n | /* xattr_value is &tmpbuf (memory leak!) */\n\nSo we will try to free(tmpbuf) after vfs_getxattr_alloc() fails to fix it.\n\n[PM: subject line and backtrace tweaks]", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49890" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0c3e6288da650d1ec911a259c77bc2d88e498603" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2de8eec8afb75792440b8900a01d52b8f6742fd1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6bb00eb21c0fbf18e5d3538c9ff0cf63fd0ace85" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7480aeff0093d8c54377553ec6b31110bea37b4d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8cf0a1bc12870d148ae830a4ba88cfdf0e879cee" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/90577bcc01c4188416a47269f8433f70502abe98" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cdf01c807e974048c43c7fd3ca574f6086a57906" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-x2w3-4grf-5r9f/GHSA-x2w3-4grf-5r9f.json b/advisories/unreviewed/2025/05/GHSA-x2w3-4grf-5r9f/GHSA-x2w3-4grf-5r9f.json new file mode 100644 index 00000000000..fb656026988 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-x2w3-4grf-5r9f/GHSA-x2w3-4grf-5r9f.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x2w3-4grf-5r9f", + "modified": "2025-05-01T15:31:46Z", + "published": "2025-05-01T15:31:46Z", + "aliases": [ + "CVE-2022-49772" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: usb-audio: Drop snd_BUG_ON() from snd_usbmidi_output_open()\n\nsnd_usbmidi_output_open() has a check of the NULL port with\nsnd_BUG_ON(). snd_BUG_ON() was used as this shouldn't have happened,\nbut in reality, the NULL port may be seen when the device gives an\ninvalid endpoint setup at the descriptor, hence the driver skips the\nallocation. That is, the check itself is valid and snd_BUG_ON()\nshould be dropped from there. Otherwise it's confusing as if it were\na real bug, as recently syzbot stumbled on it.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49772" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/00f5f1bbf815a39e9eecb468d12ca55d3360eb10" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/02b94885b2fdf1808b1874e009bfb90753f8f4db" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/368a01e5064c13946d032ab1d65ba95020a39cc5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/872c9314769e89d8bda74ff3ac584756a45ee752" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a80369c8ca50bc885d14386087a834659ec54a54" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ad72c3c3f6eb81d2cb189ec71e888316adada5df" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c43991065f36f7628cd124e037b8750c4617a7a7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e7dc436aea80308a9268e6d2d85f910ff107de9b" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-x3xp-7x67-4cx9/GHSA-x3xp-7x67-4cx9.json b/advisories/unreviewed/2025/05/GHSA-x3xp-7x67-4cx9/GHSA-x3xp-7x67-4cx9.json new file mode 100644 index 00000000000..4131b6286ca --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-x3xp-7x67-4cx9/GHSA-x3xp-7x67-4cx9.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x3xp-7x67-4cx9", + "modified": "2025-05-01T15:31:42Z", + "published": "2025-05-01T15:31:42Z", + "aliases": [ + "CVE-2025-37745" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nPM: hibernate: Avoid deadlock in hibernate_compressor_param_set()\n\nsyzbot reported a deadlock in lock_system_sleep() (see below).\n\nThe write operation to \"/sys/module/hibernate/parameters/compressor\"\nconflicts with the registration of ieee80211 device, resulting in a deadlock\nwhen attempting to acquire system_transition_mutex under param_lock.\n\nTo avoid this deadlock, change hibernate_compressor_param_set() to use\nmutex_trylock() for attempting to acquire system_transition_mutex and\nreturn -EBUSY when it fails.\n\nTask flags need not be saved or adjusted before calling\nmutex_trylock(&system_transition_mutex) because the caller is not going\nto end up waiting for this mutex and if it runs concurrently with system\nsuspend in progress, it will be frozen properly when it returns to user\nspace.\n\nsyzbot report:\n\nsyz-executor895/5833 is trying to acquire lock:\nffffffff8e0828c8 (system_transition_mutex){+.+.}-{4:4}, at: lock_system_sleep+0x87/0xa0 kernel/power/main.c:56\n\nbut task is already holding lock:\nffffffff8e07dc68 (param_lock){+.+.}-{4:4}, at: kernel_param_lock kernel/params.c:607 [inline]\nffffffff8e07dc68 (param_lock){+.+.}-{4:4}, at: param_attr_store+0xe6/0x300 kernel/params.c:586\n\nwhich lock already depends on the new lock.\n\nthe existing dependency chain (in reverse order) is:\n\n-> #3 (param_lock){+.+.}-{4:4}:\n __mutex_lock_common kernel/locking/mutex.c:585 [inline]\n __mutex_lock+0x19b/0xb10 kernel/locking/mutex.c:730\n ieee80211_rate_control_ops_get net/mac80211/rate.c:220 [inline]\n rate_control_alloc net/mac80211/rate.c:266 [inline]\n ieee80211_init_rate_ctrl_alg+0x18d/0x6b0 net/mac80211/rate.c:1015\n ieee80211_register_hw+0x20cd/0x4060 net/mac80211/main.c:1531\n mac80211_hwsim_new_radio+0x304e/0x54e0 drivers/net/wireless/virtual/mac80211_hwsim.c:5558\n init_mac80211_hwsim+0x432/0x8c0 drivers/net/wireless/virtual/mac80211_hwsim.c:6910\n do_one_initcall+0x128/0x700 init/main.c:1257\n do_initcall_level init/main.c:1319 [inline]\n do_initcalls init/main.c:1335 [inline]\n do_basic_setup init/main.c:1354 [inline]\n kernel_init_freeable+0x5c7/0x900 init/main.c:1568\n kernel_init+0x1c/0x2b0 init/main.c:1457\n ret_from_fork+0x45/0x80 arch/x86/kernel/process.c:148\n ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:244\n\n-> #2 (rtnl_mutex){+.+.}-{4:4}:\n __mutex_lock_common kernel/locking/mutex.c:585 [inline]\n __mutex_lock+0x19b/0xb10 kernel/locking/mutex.c:730\n wg_pm_notification drivers/net/wireguard/device.c:80 [inline]\n wg_pm_notification+0x49/0x180 drivers/net/wireguard/device.c:64\n notifier_call_chain+0xb7/0x410 kernel/notifier.c:85\n notifier_call_chain_robust kernel/notifier.c:120 [inline]\n blocking_notifier_call_chain_robust kernel/notifier.c:345 [inline]\n blocking_notifier_call_chain_robust+0xc9/0x170 kernel/notifier.c:333\n pm_notifier_call_chain_robust+0x27/0x60 kernel/power/main.c:102\n snapshot_open+0x189/0x2b0 kernel/power/user.c:77\n misc_open+0x35a/0x420 drivers/char/misc.c:179\n chrdev_open+0x237/0x6a0 fs/char_dev.c:414\n do_dentry_open+0x735/0x1c40 fs/open.c:956\n vfs_open+0x82/0x3f0 fs/open.c:1086\n do_open fs/namei.c:3830 [inline]\n path_openat+0x1e88/0x2d80 fs/namei.c:3989\n do_filp_open+0x20c/0x470 fs/namei.c:4016\n do_sys_openat2+0x17a/0x1e0 fs/open.c:1428\n do_sys_open fs/open.c:1443 [inline]\n __do_sys_openat fs/open.c:1459 [inline]\n __se_sys_openat fs/open.c:1454 [inline]\n __x64_sys_openat+0x175/0x210 fs/open.c:1454\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xcd/0x250 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\n-> #1 ((pm_chain_head).rwsem){++++}-{4:4}:\n down_read+0x9a/0x330 kernel/locking/rwsem.c:1524\n blocking_notifier_call_chain_robust kerne\n---truncated---", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37745" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/11ae4fec1f4b4ee06770a572c37d89cbaecbf66e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3b2c3806ef4253595dfcb8b58352cfab55c9bfb0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/52323ed1444ea5c2a5f1754ea0a2d9c8c216ccdf" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6dbaa8583af74814a5aae03a337cb1722c414808" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T13:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-x3xw-8j27-57gc/GHSA-x3xw-8j27-57gc.json b/advisories/unreviewed/2025/05/GHSA-x3xw-8j27-57gc/GHSA-x3xw-8j27-57gc.json new file mode 100644 index 00000000000..eba3eebe397 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-x3xw-8j27-57gc/GHSA-x3xw-8j27-57gc.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x3xw-8j27-57gc", + "modified": "2025-05-01T15:31:50Z", + "published": "2025-05-01T15:31:49Z", + "aliases": [ + "CVE-2022-49857" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: marvell: prestera: fix memory leak in prestera_rxtx_switch_init()\n\nWhen prestera_sdma_switch_init() failed, the memory pointed to by\nsw->rxtx isn't released. Fix it. Only be compiled, not be tested.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49857" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/31e5084ac6876e52dbb0a1cc4fc18b6c79979f31" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/409731df6310a33f4d0a3ef594d2410cdcd637f2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/519b58bbfa825f042fcf80261cc18e1e35f85ffd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5333cf1b7f6861912aff6263978d4781f9858e47" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-x496-m67p-rgph/GHSA-x496-m67p-rgph.json b/advisories/unreviewed/2025/05/GHSA-x496-m67p-rgph/GHSA-x496-m67p-rgph.json new file mode 100644 index 00000000000..bb567da7258 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-x496-m67p-rgph/GHSA-x496-m67p-rgph.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x496-m67p-rgph", + "modified": "2025-05-01T15:31:43Z", + "published": "2025-05-01T15:31:43Z", + "aliases": [ + "CVE-2025-25016" + ], + "details": "Unrestricted file upload in Kibana allows an authenticated attacker to compromise software integrity by uploading a crafted malicious file due to insufficient server-side validation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25016" + }, + { + "type": "WEB", + "url": "https://discuss.elastic.co/t/kibana-7-17-19-and-8-13-0-security-update-esa-2024-47/377711" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T14:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-x65r-3hpg-f998/GHSA-x65r-3hpg-f998.json b/advisories/unreviewed/2025/05/GHSA-x65r-3hpg-f998/GHSA-x65r-3hpg-f998.json new file mode 100644 index 00000000000..9167922ff87 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-x65r-3hpg-f998/GHSA-x65r-3hpg-f998.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x65r-3hpg-f998", + "modified": "2025-05-01T15:31:44Z", + "published": "2025-05-01T15:31:44Z", + "aliases": [ + "CVE-2025-37769" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/pm/smu11: Prevent division by zero\n\nThe user can set any speed value.\nIf speed is greater than UINT_MAX/8, division by zero is possible.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.\n\n(cherry picked from commit da7dc714a8f8e1c9fc33c57cd63583779a3bef71)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37769" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/63a150400194592206817124268ff6f43947e8c9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7ba88b5cccc1a99c1afb96e31e7eedac9907704c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/de2cba068c9c648503973b57696d035cfe58a9f6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/de6f8e0534cfabc528c969d453150ca90b24fb01" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fc9d55377353321e78f9e108d15f72a17e8c6ee2" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T14:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-xffq-295c-gmg5/GHSA-xffq-295c-gmg5.json b/advisories/unreviewed/2025/05/GHSA-xffq-295c-gmg5/GHSA-xffq-295c-gmg5.json new file mode 100644 index 00000000000..92d1a1e2a9b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-xffq-295c-gmg5/GHSA-xffq-295c-gmg5.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xffq-295c-gmg5", + "modified": "2025-05-01T15:31:42Z", + "published": "2025-05-01T15:31:42Z", + "aliases": [ + "CVE-2025-37744" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath12k: fix memory leak in ath12k_pci_remove()\n\nKmemleak reported this error:\n\n unreferenced object 0xffff1c165cec3060 (size 32):\n comm \"insmod\", pid 560, jiffies 4296964570 (age 235.596s)\n backtrace:\n [<000000005434db68>] __kmem_cache_alloc_node+0x1f4/0x2c0\n [<000000001203b155>] kmalloc_trace+0x40/0x88\n [<0000000028adc9c8>] _request_firmware+0xb8/0x608\n [<00000000cad1aef7>] firmware_request_nowarn+0x50/0x80\n [<000000005011a682>] local_pci_probe+0x48/0xd0\n [<00000000077cd295>] pci_device_probe+0xb4/0x200\n [<0000000087184c94>] really_probe+0x150/0x2c0\n\nThe firmware memory was allocated in ath12k_pci_probe(), but not\nfreed in ath12k_pci_remove() in case ATH12K_FLAG_QMI_FAIL bit is\nset. So call ath12k_fw_unmap() to free the memory.\n\nTested-on: WCN7850 hw2.0 PCI WLAN.HMT.2.0-02280-QCAHMTSWPL_V1.0_V2.0_SILICONZ-1", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37744" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1b24394ed5c8a8d8f7b9e3aa9044c31495d46f2e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3cb47b50926a5b9eef8c06506a14cdc0f3d95c53" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/52e3132e62c31b5ade43dc4495fa81175e6e8398" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cb8f4c5f9c487d82a566672b5ed0c9f05e40659b" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T13:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-xgcc-8xxp-phhm/GHSA-xgcc-8xxp-phhm.json b/advisories/unreviewed/2025/05/GHSA-xgcc-8xxp-phhm/GHSA-xgcc-8xxp-phhm.json new file mode 100644 index 00000000000..9ac4023bb3a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-xgcc-8xxp-phhm/GHSA-xgcc-8xxp-phhm.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xgcc-8xxp-phhm", + "modified": "2025-05-01T15:31:45Z", + "published": "2025-05-01T15:31:45Z", + "aliases": [ + "CVE-2025-37792" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: btrtl: Prevent potential NULL dereference\n\nThe btrtl_initialize() function checks that rtl_load_file() either\nhad an error or it loaded a zero length file. However, if it loaded\na zero length file then the error code is not set correctly. It\nresults in an error pointer vs NULL bug, followed by a NULL pointer\ndereference. This was detected by Smatch:\n\ndrivers/bluetooth/btrtl.c:592 btrtl_initialize() warn: passing zero to 'ERR_PTR'", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37792" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/324dddea321078a6eeb535c2bff5257be74c9799" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3db6605043b50c8bb768547b23e0222f67ceef3e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/53ceef799dcfc22c734d600811bfc9dd32eaea0a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/aaf356f872a60db1e96fb762a62c4607fd22741f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d8441818690d795232331bd8358545c5c95b6b72" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T14:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-xh29-jpw9-pv7c/GHSA-xh29-jpw9-pv7c.json b/advisories/unreviewed/2025/05/GHSA-xh29-jpw9-pv7c/GHSA-xh29-jpw9-pv7c.json new file mode 100644 index 00000000000..4a51d5e1bb3 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-xh29-jpw9-pv7c/GHSA-xh29-jpw9-pv7c.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xh29-jpw9-pv7c", + "modified": "2025-05-01T15:31:47Z", + "published": "2025-05-01T15:31:47Z", + "aliases": [ + "CVE-2022-49794" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\niio: adc: at91_adc: fix possible memory leak in at91_adc_allocate_trigger()\n\nIf iio_trigger_register() returns error, it should call iio_trigger_free()\nto give up the reference that hold in iio_trigger_alloc(), so that it can\ncall iio_trig_release() to free memory when the refcount hit to 0.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49794" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1bf8c0aff8fb5c4edf3ba6728e6bedbd610d7f4b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2b29a7f2d52fb5281b30cf61c947d88bab18a29b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/65f20301607d07ee279b0804d11a05a62a6c1a1c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7b75515728b628a9a7540f201efdeb8ca7299385" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/85d2a8b287a89853c0dcfc5a97b5e9d36376fe37" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a0d98ae5a62a7bbad8fcf9fa22e0a1274197bbc4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c27a3b6ba23350708cf5ab9962337447b51eb76d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c3ce73f60599a483dca7becd4112508833a40ef9" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-xq94-j9xm-j8mp/GHSA-xq94-j9xm-j8mp.json b/advisories/unreviewed/2025/05/GHSA-xq94-j9xm-j8mp/GHSA-xq94-j9xm-j8mp.json new file mode 100644 index 00000000000..db5ee3fc5e9 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-xq94-j9xm-j8mp/GHSA-xq94-j9xm-j8mp.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xq94-j9xm-j8mp", + "modified": "2025-05-01T15:31:50Z", + "published": "2025-05-01T15:31:50Z", + "aliases": [ + "CVE-2022-49864" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdkfd: Fix NULL pointer dereference in svm_migrate_to_ram()\n\n./drivers/gpu/drm/amd/amdkfd/kfd_migrate.c:985:58-62: ERROR: p is NULL but dereferenced.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49864" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3c1bb6187e566143f15dbf0367ae671584aead5b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5b994354af3cab770bf13386469c5725713679af" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/613d5a9a440828970f1543b962779401ac2c9c62" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-xr86-xwvg-mq5q/GHSA-xr86-xwvg-mq5q.json b/advisories/unreviewed/2025/05/GHSA-xr86-xwvg-mq5q/GHSA-xr86-xwvg-mq5q.json new file mode 100644 index 00000000000..93a9d72ee7c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-xr86-xwvg-mq5q/GHSA-xr86-xwvg-mq5q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xr86-xwvg-mq5q", + "modified": "2025-05-01T15:31:39Z", + "published": "2025-05-01T15:31:39Z", + "aliases": [ + "CVE-2023-46669" + ], + "details": "Exposure of sensitive information to local unauthorized actors in Elastic Agent and Elastic Security Endpoint can lead to loss of confidentiality and impersonation of Endpoint to the Elastic Stack. This issue was identified by Elastic engineers and Elastic has no indication that it is known or has been exploited by malicious actors.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46669" + }, + { + "type": "WEB", + "url": "https://discuss.elastic.co/t/elastic-agent-elastic-endpoint-security-security-update-esa-2025-03/377706" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T13:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-xx2h-qwcv-vv5w/GHSA-xx2h-qwcv-vv5w.json b/advisories/unreviewed/2025/05/GHSA-xx2h-qwcv-vv5w/GHSA-xx2h-qwcv-vv5w.json new file mode 100644 index 00000000000..3c4ef8be0d3 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-xx2h-qwcv-vv5w/GHSA-xx2h-qwcv-vv5w.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xx2h-qwcv-vv5w", + "modified": "2025-05-01T15:31:40Z", + "published": "2025-05-01T15:31:40Z", + "aliases": [ + "CVE-2025-23152" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\narm64/crc-t10dif: fix use of out-of-scope array in crc_t10dif_arch()\n\nFix a silly bug where an array was used outside of its scope.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23152" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bd9e1a03e579a01dfa66dbaa53d0219c33cbc463" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d48b663f410f8b35b8ba9bd597bafaa00f53293b" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T13:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-xxc5-272v-5wc3/GHSA-xxc5-272v-5wc3.json b/advisories/unreviewed/2025/05/GHSA-xxc5-272v-5wc3/GHSA-xxc5-272v-5wc3.json new file mode 100644 index 00000000000..ed6e4406694 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-xxc5-272v-5wc3/GHSA-xxc5-272v-5wc3.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xxc5-272v-5wc3", + "modified": "2025-05-01T15:31:48Z", + "published": "2025-05-01T15:31:48Z", + "aliases": [ + "CVE-2022-49819" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nocteon_ep: fix potential memory leak in octep_device_setup()\n\nWhen occur unsupported_dev and mbox init errors, it did not free oct->conf\nand iounmap() oct->mmio[i].hw_addr. That would trigger memory leak problem.\nAdd kfree() for oct->conf and iounmap() for oct->mmio[i].hw_addr under\nunsupported_dev and mbox init errors to fix the problem.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49819" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/67b65a0db8a7fdad43159819f41335497a4bb04f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e4041be97b15302ebfffda8bbd45f3b2d096048f" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-xxgf-mjgq-w636/GHSA-xxgf-mjgq-w636.json b/advisories/unreviewed/2025/05/GHSA-xxgf-mjgq-w636/GHSA-xxgf-mjgq-w636.json new file mode 100644 index 00000000000..d6dc2de0f34 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-xxgf-mjgq-w636/GHSA-xxgf-mjgq-w636.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xxgf-mjgq-w636", + "modified": "2025-05-01T15:31:51Z", + "published": "2025-05-01T15:31:51Z", + "aliases": [ + "CVE-2022-49887" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: meson: vdec: fix possible refcount leak in vdec_probe()\n\nv4l2_device_unregister need to be called to put the refcount got by\nv4l2_device_register when vdec_probe fails or vdec_remove is called.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49887" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0457e7b12ece1a7e41fa0ae8b7e47c0a72a83bef" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/70119756311a0be3b95bec2e1ba714673e90feba" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7718999356234d9cc6a11b4641bb773928f1390f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/be6e22f54623d8a856a4f167b25be73c2ff1ff80" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f96ad391d054bd5c36994f98afd6a12cbb5600bf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T15:16:13Z" + } +} \ No newline at end of file