diff --git a/advisories/unreviewed/2022/11/GHSA-3mh4-fcx6-w55m/GHSA-3mh4-fcx6-w55m.json b/advisories/unreviewed/2022/11/GHSA-3mh4-fcx6-w55m/GHSA-3mh4-fcx6-w55m.json index bb71033f8de..db5cd6db186 100644 --- a/advisories/unreviewed/2022/11/GHSA-3mh4-fcx6-w55m/GHSA-3mh4-fcx6-w55m.json +++ b/advisories/unreviewed/2022/11/GHSA-3mh4-fcx6-w55m/GHSA-3mh4-fcx6-w55m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3mh4-fcx6-w55m", - "modified": "2022-11-23T21:30:33Z", + "modified": "2025-04-29T21:31:29Z", "published": "2022-11-22T15:30:25Z", "aliases": [ "CVE-2022-44804" diff --git a/advisories/unreviewed/2022/11/GHSA-5q2f-65mc-6jvf/GHSA-5q2f-65mc-6jvf.json b/advisories/unreviewed/2022/11/GHSA-5q2f-65mc-6jvf/GHSA-5q2f-65mc-6jvf.json index 05994f9b063..77ce41d8e4e 100644 --- a/advisories/unreviewed/2022/11/GHSA-5q2f-65mc-6jvf/GHSA-5q2f-65mc-6jvf.json +++ b/advisories/unreviewed/2022/11/GHSA-5q2f-65mc-6jvf/GHSA-5q2f-65mc-6jvf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5q2f-65mc-6jvf", - "modified": "2022-11-22T21:30:17Z", + "modified": "2025-04-29T21:31:25Z", "published": "2022-11-19T00:30:55Z", "aliases": [ "CVE-2021-31739" diff --git a/advisories/unreviewed/2022/11/GHSA-5w9h-x2v4-5xm7/GHSA-5w9h-x2v4-5xm7.json b/advisories/unreviewed/2022/11/GHSA-5w9h-x2v4-5xm7/GHSA-5w9h-x2v4-5xm7.json index 62fdad13a37..5b96aa758e2 100644 --- a/advisories/unreviewed/2022/11/GHSA-5w9h-x2v4-5xm7/GHSA-5w9h-x2v4-5xm7.json +++ b/advisories/unreviewed/2022/11/GHSA-5w9h-x2v4-5xm7/GHSA-5w9h-x2v4-5xm7.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-284", "CWE-863" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2022/11/GHSA-69f3-xjq9-mwxg/GHSA-69f3-xjq9-mwxg.json b/advisories/unreviewed/2022/11/GHSA-69f3-xjq9-mwxg/GHSA-69f3-xjq9-mwxg.json index 8786b4428e9..2b9bb12af68 100644 --- a/advisories/unreviewed/2022/11/GHSA-69f3-xjq9-mwxg/GHSA-69f3-xjq9-mwxg.json +++ b/advisories/unreviewed/2022/11/GHSA-69f3-xjq9-mwxg/GHSA-69f3-xjq9-mwxg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-69f3-xjq9-mwxg", - "modified": "2022-11-23T21:30:33Z", + "modified": "2025-04-29T21:31:27Z", "published": "2022-11-22T15:30:25Z", "aliases": [ "CVE-2022-44202" diff --git a/advisories/unreviewed/2022/11/GHSA-f6qg-mvmh-xgxv/GHSA-f6qg-mvmh-xgxv.json b/advisories/unreviewed/2022/11/GHSA-f6qg-mvmh-xgxv/GHSA-f6qg-mvmh-xgxv.json index 9a3e151f389..cc1f87dfb87 100644 --- a/advisories/unreviewed/2022/11/GHSA-f6qg-mvmh-xgxv/GHSA-f6qg-mvmh-xgxv.json +++ b/advisories/unreviewed/2022/11/GHSA-f6qg-mvmh-xgxv/GHSA-f6qg-mvmh-xgxv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f6qg-mvmh-xgxv", - "modified": "2022-11-23T21:30:33Z", + "modified": "2025-04-29T21:31:28Z", "published": "2022-11-22T15:30:25Z", "aliases": [ "CVE-2022-44801" diff --git a/advisories/unreviewed/2022/11/GHSA-h558-w3qm-gvh7/GHSA-h558-w3qm-gvh7.json b/advisories/unreviewed/2022/11/GHSA-h558-w3qm-gvh7/GHSA-h558-w3qm-gvh7.json index 49092686baa..b10cb036a62 100644 --- a/advisories/unreviewed/2022/11/GHSA-h558-w3qm-gvh7/GHSA-h558-w3qm-gvh7.json +++ b/advisories/unreviewed/2022/11/GHSA-h558-w3qm-gvh7/GHSA-h558-w3qm-gvh7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h558-w3qm-gvh7", - "modified": "2022-11-23T21:30:33Z", + "modified": "2025-04-29T21:31:29Z", "published": "2022-11-22T15:30:25Z", "aliases": [ "CVE-2022-44806" diff --git a/advisories/unreviewed/2022/11/GHSA-hj7c-g88c-mq5v/GHSA-hj7c-g88c-mq5v.json b/advisories/unreviewed/2022/11/GHSA-hj7c-g88c-mq5v/GHSA-hj7c-g88c-mq5v.json index a8e7272c32c..1bd4ef4a700 100644 --- a/advisories/unreviewed/2022/11/GHSA-hj7c-g88c-mq5v/GHSA-hj7c-g88c-mq5v.json +++ b/advisories/unreviewed/2022/11/GHSA-hj7c-g88c-mq5v/GHSA-hj7c-g88c-mq5v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hj7c-g88c-mq5v", - "modified": "2022-11-22T21:30:17Z", + "modified": "2025-04-29T21:31:25Z", "published": "2022-11-18T21:30:16Z", "aliases": [ "CVE-2022-44641" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2023/01/msg00016.html" }, + { + "type": "WEB", + "url": "https://lists.lavasoftware.org/archives/list/lava-announce%40lists.lavasoftware.org/thread/WHXGQMIZAPW3GCQEXYHC32N2ZAAAIYCY" + }, { "type": "WEB", "url": "https://lists.lavasoftware.org/archives/list/lava-announce@lists.lavasoftware.org/thread/WHXGQMIZAPW3GCQEXYHC32N2ZAAAIYCY" diff --git a/advisories/unreviewed/2022/11/GHSA-rxv7-j96r-9mj5/GHSA-rxv7-j96r-9mj5.json b/advisories/unreviewed/2022/11/GHSA-rxv7-j96r-9mj5/GHSA-rxv7-j96r-9mj5.json index c0d094335f3..7c1441d11a6 100644 --- a/advisories/unreviewed/2022/11/GHSA-rxv7-j96r-9mj5/GHSA-rxv7-j96r-9mj5.json +++ b/advisories/unreviewed/2022/11/GHSA-rxv7-j96r-9mj5/GHSA-rxv7-j96r-9mj5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rxv7-j96r-9mj5", - "modified": "2022-11-23T21:30:33Z", + "modified": "2025-04-29T21:31:30Z", "published": "2022-11-22T15:30:25Z", "aliases": [ "CVE-2022-44807" diff --git a/advisories/unreviewed/2022/11/GHSA-whx6-754g-3x5v/GHSA-whx6-754g-3x5v.json b/advisories/unreviewed/2022/11/GHSA-whx6-754g-3x5v/GHSA-whx6-754g-3x5v.json index 038a5480d7d..cc96168b2e5 100644 --- a/advisories/unreviewed/2022/11/GHSA-whx6-754g-3x5v/GHSA-whx6-754g-3x5v.json +++ b/advisories/unreviewed/2022/11/GHSA-whx6-754g-3x5v/GHSA-whx6-754g-3x5v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-whx6-754g-3x5v", - "modified": "2022-11-22T21:30:17Z", + "modified": "2025-04-29T21:31:25Z", "published": "2022-11-19T00:30:55Z", "aliases": [ "CVE-2021-22141" diff --git a/advisories/unreviewed/2022/12/GHSA-m3j7-gp78-ggjf/GHSA-m3j7-gp78-ggjf.json b/advisories/unreviewed/2022/12/GHSA-m3j7-gp78-ggjf/GHSA-m3j7-gp78-ggjf.json index 380b3a065c0..10c111cedb6 100644 --- a/advisories/unreviewed/2022/12/GHSA-m3j7-gp78-ggjf/GHSA-m3j7-gp78-ggjf.json +++ b/advisories/unreviewed/2022/12/GHSA-m3j7-gp78-ggjf/GHSA-m3j7-gp78-ggjf.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/10/GHSA-3856-cjch-9cv8/GHSA-3856-cjch-9cv8.json b/advisories/unreviewed/2023/10/GHSA-3856-cjch-9cv8/GHSA-3856-cjch-9cv8.json index d5f53cde011..6b8ec6bd35c 100644 --- a/advisories/unreviewed/2023/10/GHSA-3856-cjch-9cv8/GHSA-3856-cjch-9cv8.json +++ b/advisories/unreviewed/2023/10/GHSA-3856-cjch-9cv8/GHSA-3856-cjch-9cv8.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/11/GHSA-3wwg-wvhq-f8q7/GHSA-3wwg-wvhq-f8q7.json b/advisories/unreviewed/2023/11/GHSA-3wwg-wvhq-f8q7/GHSA-3wwg-wvhq-f8q7.json index ba6b1fbcb30..efe863ea57c 100644 --- a/advisories/unreviewed/2023/11/GHSA-3wwg-wvhq-f8q7/GHSA-3wwg-wvhq-f8q7.json +++ b/advisories/unreviewed/2023/11/GHSA-3wwg-wvhq-f8q7/GHSA-3wwg-wvhq-f8q7.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-120", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/11/GHSA-7cjp-92p9-vr97/GHSA-7cjp-92p9-vr97.json b/advisories/unreviewed/2023/11/GHSA-7cjp-92p9-vr97/GHSA-7cjp-92p9-vr97.json index 29157298f00..af8b0cf8364 100644 --- a/advisories/unreviewed/2023/11/GHSA-7cjp-92p9-vr97/GHSA-7cjp-92p9-vr97.json +++ b/advisories/unreviewed/2023/11/GHSA-7cjp-92p9-vr97/GHSA-7cjp-92p9-vr97.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7cjp-92p9-vr97", - "modified": "2023-11-08T21:30:36Z", + "modified": "2025-04-29T21:31:30Z", "published": "2023-11-01T18:30:33Z", "aliases": [ "CVE-2023-5849" diff --git a/advisories/unreviewed/2023/11/GHSA-c46p-5pq2-qpcg/GHSA-c46p-5pq2-qpcg.json b/advisories/unreviewed/2023/11/GHSA-c46p-5pq2-qpcg/GHSA-c46p-5pq2-qpcg.json index 1f018fa1fed..93897ffc657 100644 --- a/advisories/unreviewed/2023/11/GHSA-c46p-5pq2-qpcg/GHSA-c46p-5pq2-qpcg.json +++ b/advisories/unreviewed/2023/11/GHSA-c46p-5pq2-qpcg/GHSA-c46p-5pq2-qpcg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c46p-5pq2-qpcg", - "modified": "2023-11-08T21:30:36Z", + "modified": "2025-04-29T21:31:30Z", "published": "2023-11-01T18:30:33Z", "aliases": [ "CVE-2023-5854" diff --git a/advisories/unreviewed/2023/11/GHSA-jwj7-8489-4jqm/GHSA-jwj7-8489-4jqm.json b/advisories/unreviewed/2023/11/GHSA-jwj7-8489-4jqm/GHSA-jwj7-8489-4jqm.json index 3ec36cccd09..86fb8f4f122 100644 --- a/advisories/unreviewed/2023/11/GHSA-jwj7-8489-4jqm/GHSA-jwj7-8489-4jqm.json +++ b/advisories/unreviewed/2023/11/GHSA-jwj7-8489-4jqm/GHSA-jwj7-8489-4jqm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jwj7-8489-4jqm", - "modified": "2023-11-08T21:30:36Z", + "modified": "2025-04-29T21:31:30Z", "published": "2023-11-01T18:30:33Z", "aliases": [ "CVE-2023-5855" diff --git a/advisories/unreviewed/2023/11/GHSA-qfx8-xprj-wvh4/GHSA-qfx8-xprj-wvh4.json b/advisories/unreviewed/2023/11/GHSA-qfx8-xprj-wvh4/GHSA-qfx8-xprj-wvh4.json index b600a479f08..dd91e0664b7 100644 --- a/advisories/unreviewed/2023/11/GHSA-qfx8-xprj-wvh4/GHSA-qfx8-xprj-wvh4.json +++ b/advisories/unreviewed/2023/11/GHSA-qfx8-xprj-wvh4/GHSA-qfx8-xprj-wvh4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qfx8-xprj-wvh4", - "modified": "2023-11-08T21:30:36Z", + "modified": "2025-04-29T21:31:30Z", "published": "2023-11-01T18:30:33Z", "aliases": [ "CVE-2023-5852" diff --git a/advisories/unreviewed/2023/11/GHSA-xmhq-fw78-wjxr/GHSA-xmhq-fw78-wjxr.json b/advisories/unreviewed/2023/11/GHSA-xmhq-fw78-wjxr/GHSA-xmhq-fw78-wjxr.json index 24d725b74eb..68e1854e92e 100644 --- a/advisories/unreviewed/2023/11/GHSA-xmhq-fw78-wjxr/GHSA-xmhq-fw78-wjxr.json +++ b/advisories/unreviewed/2023/11/GHSA-xmhq-fw78-wjxr/GHSA-xmhq-fw78-wjxr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xmhq-fw78-wjxr", - "modified": "2023-11-08T21:30:36Z", + "modified": "2025-04-29T21:31:31Z", "published": "2023-11-01T18:30:34Z", "aliases": [ "CVE-2023-5856" diff --git a/advisories/unreviewed/2024/05/GHSA-3c4w-p6cr-wgq6/GHSA-3c4w-p6cr-wgq6.json b/advisories/unreviewed/2024/05/GHSA-3c4w-p6cr-wgq6/GHSA-3c4w-p6cr-wgq6.json index 196b1b4233d..26ceccbb8f3 100644 --- a/advisories/unreviewed/2024/05/GHSA-3c4w-p6cr-wgq6/GHSA-3c4w-p6cr-wgq6.json +++ b/advisories/unreviewed/2024/05/GHSA-3c4w-p6cr-wgq6/GHSA-3c4w-p6cr-wgq6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3c4w-p6cr-wgq6", - "modified": "2024-05-21T15:31:39Z", + "modified": "2025-04-29T21:31:31Z", "published": "2024-05-21T15:31:39Z", "aliases": [ "CVE-2021-47221" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/slub: actually fix freelist pointer vs redzoning\n\nIt turns out that SLUB redzoning (\"slub_debug=Z\") checks from\ns->object_size rather than from s->inuse (which is normally bumped to\nmake room for the freelist pointer), so a cache created with an object\nsize less than 24 would have the freelist pointer written beyond\ns->object_size, causing the redzone to be corrupted by the freelist\npointer. This was very visible with \"slub_debug=ZF\":\n\n BUG test (Tainted: G B ): Right Redzone overwritten\n -----------------------------------------------------------------------------\n\n INFO: 0xffff957ead1c05de-0xffff957ead1c05df @offset=1502. First byte 0x1a instead of 0xbb\n INFO: Slab 0xffffef3950b47000 objects=170 used=170 fp=0x0000000000000000 flags=0x8000000000000200\n INFO: Object 0xffff957ead1c05d8 @offset=1496 fp=0xffff957ead1c0620\n\n Redzone (____ptrval____): bb bb bb bb bb bb bb bb ........\n Object (____ptrval____): 00 00 00 00 00 f6 f4 a5 ........\n Redzone (____ptrval____): 40 1d e8 1a aa @....\n Padding (____ptrval____): 00 00 00 00 00 00 00 00 ........\n\nAdjust the offset to stay within s->object_size.\n\n(Note that no caches of in this size range are known to exist in the\nkernel currently.)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-763" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T15:15:11Z" diff --git a/advisories/unreviewed/2024/05/GHSA-3w59-vx6f-4274/GHSA-3w59-vx6f-4274.json b/advisories/unreviewed/2024/05/GHSA-3w59-vx6f-4274/GHSA-3w59-vx6f-4274.json index 05147836ba1..5ee7fa56219 100644 --- a/advisories/unreviewed/2024/05/GHSA-3w59-vx6f-4274/GHSA-3w59-vx6f-4274.json +++ b/advisories/unreviewed/2024/05/GHSA-3w59-vx6f-4274/GHSA-3w59-vx6f-4274.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3w59-vx6f-4274", - "modified": "2024-05-21T15:31:40Z", + "modified": "2025-04-29T21:31:35Z", "published": "2024-05-21T15:31:40Z", "aliases": [ "CVE-2021-47236" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: cdc_eem: fix tx fixup skb leak\n\nwhen usbnet transmit a skb, eem fixup it in eem_tx_fixup(),\nif skb_copy_expand() failed, it return NULL,\nusbnet_start_xmit() will have no chance to free original skb.\n\nfix it by free orginal skb in eem_tx_fixup() first,\nthen check skb clone status, if failed, return NULL to usbnet.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T15:15:12Z" diff --git a/advisories/unreviewed/2024/05/GHSA-4jxh-jrgp-4422/GHSA-4jxh-jrgp-4422.json b/advisories/unreviewed/2024/05/GHSA-4jxh-jrgp-4422/GHSA-4jxh-jrgp-4422.json index f190b55505c..eaf1e6428ec 100644 --- a/advisories/unreviewed/2024/05/GHSA-4jxh-jrgp-4422/GHSA-4jxh-jrgp-4422.json +++ b/advisories/unreviewed/2024/05/GHSA-4jxh-jrgp-4422/GHSA-4jxh-jrgp-4422.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4jxh-jrgp-4422", - "modified": "2024-05-21T15:31:39Z", + "modified": "2025-04-29T21:31:32Z", "published": "2024-05-21T15:31:39Z", "aliases": [ "CVE-2021-47226" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/fpu: Invalidate FPU state after a failed XRSTOR from a user buffer\n\nBoth Intel and AMD consider it to be architecturally valid for XRSTOR to\nfail with #PF but nonetheless change the register state. The actual\nconditions under which this might occur are unclear [1], but it seems\nplausible that this might be triggered if one sibling thread unmaps a page\nand invalidates the shared TLB while another sibling thread is executing\nXRSTOR on the page in question.\n\n__fpu__restore_sig() can execute XRSTOR while the hardware registers\nare preserved on behalf of a different victim task (using the\nfpu_fpregs_owner_ctx mechanism), and, in theory, XRSTOR could fail but\nmodify the registers.\n\nIf this happens, then there is a window in which __fpu__restore_sig()\ncould schedule out and the victim task could schedule back in without\nreloading its own FPU registers. This would result in part of the FPU\nstate that __fpu__restore_sig() was attempting to load leaking into the\nvictim task's user-visible state.\n\nInvalidate preserved FPU registers on XRSTOR failure to prevent this\nsituation from corrupting any state.\n\n[1] Frequent readers of the errata lists might imagine \"complex\n microarchitectural conditions\".", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-203" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T15:15:11Z" diff --git a/advisories/unreviewed/2024/05/GHSA-74hg-7r85-vvw3/GHSA-74hg-7r85-vvw3.json b/advisories/unreviewed/2024/05/GHSA-74hg-7r85-vvw3/GHSA-74hg-7r85-vvw3.json index 230ca67277e..153c22059a8 100644 --- a/advisories/unreviewed/2024/05/GHSA-74hg-7r85-vvw3/GHSA-74hg-7r85-vvw3.json +++ b/advisories/unreviewed/2024/05/GHSA-74hg-7r85-vvw3/GHSA-74hg-7r85-vvw3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-74hg-7r85-vvw3", - "modified": "2024-05-21T15:31:39Z", + "modified": "2025-04-29T21:31:34Z", "published": "2024-05-21T15:31:39Z", "aliases": [ "CVE-2021-47229" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nPCI: aardvark: Fix kernel panic during PIO transfer\n\nTrying to start a new PIO transfer by writing value 0 in PIO_START register\nwhen previous transfer has not yet completed (which is indicated by value 1\nin PIO_START) causes an External Abort on CPU, which results in kernel\npanic:\n\n SError Interrupt on CPU0, code 0xbf000002 -- SError\n Kernel panic - not syncing: Asynchronous SError Interrupt\n\nTo prevent kernel panic, it is required to reject a new PIO transfer when\nprevious one has not finished yet.\n\nIf previous PIO transfer is not finished yet, the kernel may issue a new\nPIO request only if the previous PIO transfer timed out.\n\nIn the past the root cause of this issue was incorrectly identified (as it\noften happens during link retraining or after link down event) and special\nhack was implemented in Trusted Firmware to catch all SError events in EL3,\nto ignore errors with code 0xbf000002 and not forwarding any other errors\nto kernel and instead throw panic from EL3 Trusted Firmware handler.\n\nLinks to discussion and patches about this issue:\nhttps://git.trustedfirmware.org/TF-A/trusted-firmware-a.git/commit/?id=3c7dcdac5c50\nhttps://lore.kernel.org/linux-pci/20190316161243.29517-1-repk@triplefau.lt/\nhttps://lore.kernel.org/linux-pci/971be151d24312cc533989a64bd454b4@www.loen.fr/\nhttps://review.trustedfirmware.org/c/TF-A/trusted-firmware-a/+/1541\n\nBut the real cause was the fact that during link retraining or after link\ndown event the PIO transfer may take longer time, up to the 1.44s until it\ntimes out. This increased probability that a new PIO transfer would be\nissued by kernel while previous one has not finished yet.\n\nAfter applying this change into the kernel, it is possible to revert the\nmentioned TF-A hack and SError events do not have to be caught in TF-A EL3.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -41,7 +46,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T15:15:12Z" diff --git a/advisories/unreviewed/2024/05/GHSA-c655-qwvw-wfqm/GHSA-c655-qwvw-wfqm.json b/advisories/unreviewed/2024/05/GHSA-c655-qwvw-wfqm/GHSA-c655-qwvw-wfqm.json index 593ab1988fa..288a15a0801 100644 --- a/advisories/unreviewed/2024/05/GHSA-c655-qwvw-wfqm/GHSA-c655-qwvw-wfqm.json +++ b/advisories/unreviewed/2024/05/GHSA-c655-qwvw-wfqm/GHSA-c655-qwvw-wfqm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c655-qwvw-wfqm", - "modified": "2024-05-21T15:31:40Z", + "modified": "2025-04-29T21:31:35Z", "published": "2024-05-21T15:31:40Z", "aliases": [ "CVE-2021-47246" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: Fix page reclaim for dead peer hairpin\n\nWhen adding a hairpin flow, a firmware-side send queue is created for\nthe peer net device, which claims some host memory pages for its\ninternal ring buffer. If the peer net device is removed/unbound before\nthe hairpin flow is deleted, then the send queue is not destroyed which\nleads to a stack trace on pci device remove:\n\n[ 748.005230] mlx5_core 0000:08:00.2: wait_func:1094:(pid 12985): MANAGE_PAGES(0x108) timeout. Will cause a leak of a command resource\n[ 748.005231] mlx5_core 0000:08:00.2: reclaim_pages:514:(pid 12985): failed reclaiming pages: err -110\n[ 748.001835] mlx5_core 0000:08:00.2: mlx5_reclaim_root_pages:653:(pid 12985): failed reclaiming pages (-110) for func id 0x0\n[ 748.002171] ------------[ cut here ]------------\n[ 748.001177] FW pages counter is 4 after reclaiming all pages\n[ 748.001186] WARNING: CPU: 1 PID: 12985 at drivers/net/ethernet/mellanox/mlx5/core/pagealloc.c:685 mlx5_reclaim_startup_pages+0x34b/0x460 [mlx5_core] [ +0.002771] Modules linked in: cls_flower mlx5_ib mlx5_core ptp pps_core act_mirred sch_ingress openvswitch nsh xt_conntrack xt_MASQUERADE nf_conntrack_netlink nfnetlink xt_addrtype iptable_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 br_netfilter rpcrdma rdma_ucm ib_iser libiscsi scsi_transport_iscsi rdma_cm ib_umad ib_ipoib iw_cm ib_cm ib_uverbs ib_core overlay fuse [last unloaded: pps_core]\n[ 748.007225] CPU: 1 PID: 12985 Comm: tee Not tainted 5.12.0+ #1\n[ 748.001376] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014\n[ 748.002315] RIP: 0010:mlx5_reclaim_startup_pages+0x34b/0x460 [mlx5_core]\n[ 748.001679] Code: 28 00 00 00 0f 85 22 01 00 00 48 81 c4 b0 00 00 00 31 c0 5b 5d 41 5c 41 5d 41 5e 41 5f c3 48 c7 c7 40 cc 19 a1 e8 9f 71 0e e2 <0f> 0b e9 30 ff ff ff 48 c7 c7 a0 cc 19 a1 e8 8c 71 0e e2 0f 0b e9\n[ 748.003781] RSP: 0018:ffff88815220faf8 EFLAGS: 00010286\n[ 748.001149] RAX: 0000000000000000 RBX: ffff8881b4900280 RCX: 0000000000000000\n[ 748.001445] RDX: 0000000000000027 RSI: 0000000000000004 RDI: ffffed102a441f51\n[ 748.001614] RBP: 00000000000032b9 R08: 0000000000000001 R09: ffffed1054a15ee8\n[ 748.001446] R10: ffff8882a50af73b R11: ffffed1054a15ee7 R12: fffffbfff07c1e30\n[ 748.001447] R13: dffffc0000000000 R14: ffff8881b492cba8 R15: 0000000000000000\n[ 748.001429] FS: 00007f58bd08b580(0000) GS:ffff8882a5080000(0000) knlGS:0000000000000000\n[ 748.001695] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 748.001309] CR2: 000055a026351740 CR3: 00000001d3b48006 CR4: 0000000000370ea0\n[ 748.001506] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n[ 748.001483] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n[ 748.001654] Call Trace:\n[ 748.000576] ? mlx5_satisfy_startup_pages+0x290/0x290 [mlx5_core]\n[ 748.001416] ? mlx5_cmd_teardown_hca+0xa2/0xd0 [mlx5_core]\n[ 748.001354] ? mlx5_cmd_init_hca+0x280/0x280 [mlx5_core]\n[ 748.001203] mlx5_function_teardown+0x30/0x60 [mlx5_core]\n[ 748.001275] mlx5_uninit_one+0xa7/0xc0 [mlx5_core]\n[ 748.001200] remove_one+0x5f/0xc0 [mlx5_core]\n[ 748.001075] pci_device_remove+0x9f/0x1d0\n[ 748.000833] device_release_driver_internal+0x1e0/0x490\n[ 748.001207] unbind_store+0x19f/0x200\n[ 748.000942] ? sysfs_file_ops+0x170/0x170\n[ 748.001000] kernfs_fop_write_iter+0x2bc/0x450\n[ 748.000970] new_sync_write+0x373/0x610\n[ 748.001124] ? new_sync_read+0x600/0x600\n[ 748.001057] ? lock_acquire+0x4d6/0x700\n[ 748.000908] ? lockdep_hardirqs_on_prepare+0x400/0x400\n[ 748.001126] ? fd_install+0x1c9/0x4d0\n[ 748.000951] vfs_write+0x4d0/0x800\n[ 748.000804] ksys_write+0xf9/0x1d0\n[ 748.000868] ? __x64_sys_read+0xb0/0xb0\n[ 748.000811] ? filp_open+0x50/0x50\n[ 748.000919] ? syscall_enter_from_user_mode+0x1d/0x50\n[ 748.001223] do_syscall_64+0x3f/0x80\n[ 748.000892] entry_SYSCALL_64_after_hwframe+0x44/0xae\n[ 748.00\n---truncated---", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T15:15:13Z" diff --git a/advisories/unreviewed/2024/05/GHSA-cjw7-m4qf-xc59/GHSA-cjw7-m4qf-xc59.json b/advisories/unreviewed/2024/05/GHSA-cjw7-m4qf-xc59/GHSA-cjw7-m4qf-xc59.json index 96aa81aa38f..4b8438d299c 100644 --- a/advisories/unreviewed/2024/05/GHSA-cjw7-m4qf-xc59/GHSA-cjw7-m4qf-xc59.json +++ b/advisories/unreviewed/2024/05/GHSA-cjw7-m4qf-xc59/GHSA-cjw7-m4qf-xc59.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cjw7-m4qf-xc59", - "modified": "2024-05-21T15:31:39Z", + "modified": "2025-04-29T21:31:33Z", "published": "2024-05-21T15:31:39Z", "aliases": [ "CVE-2021-47227" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/fpu: Prevent state corruption in __fpu__restore_sig()\n\nThe non-compacted slowpath uses __copy_from_user() and copies the entire\nuser buffer into the kernel buffer, verbatim. This means that the kernel\nbuffer may now contain entirely invalid state on which XRSTOR will #GP.\nvalidate_user_xstate_header() can detect some of that corruption, but that\nleaves the onus on callers to clear the buffer.\n\nPrior to XSAVES support, it was possible just to reinitialize the buffer,\ncompletely, but with supervisor states that is not longer possible as the\nbuffer clearing code split got it backwards. Fixing that is possible but\nnot corrupting the state in the first place is more robust.\n\nAvoid corruption of the kernel XSAVE buffer by using copy_user_to_xstate()\nwhich validates the XSAVE header contents before copying the actual states\nto the kernel. copy_user_to_xstate() was previously only called for\ncompacted-format kernel buffers, but it works for both compacted and\nnon-compacted forms.\n\nUsing it for the non-compacted form is slower because of multiple\n__copy_from_user() operations, but that cost is less important than robust\ncode in an already slow path.\n\n[ Changelog polished by Dave Hansen ]", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-754" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T15:15:11Z" diff --git a/advisories/unreviewed/2024/05/GHSA-h423-6g7m-qpqq/GHSA-h423-6g7m-qpqq.json b/advisories/unreviewed/2024/05/GHSA-h423-6g7m-qpqq/GHSA-h423-6g7m-qpqq.json index b9bd2398b2a..4a6263c8f62 100644 --- a/advisories/unreviewed/2024/05/GHSA-h423-6g7m-qpqq/GHSA-h423-6g7m-qpqq.json +++ b/advisories/unreviewed/2024/05/GHSA-h423-6g7m-qpqq/GHSA-h423-6g7m-qpqq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h423-6g7m-qpqq", - "modified": "2024-05-21T15:31:39Z", + "modified": "2025-04-29T21:31:32Z", "published": "2024-05-21T15:31:39Z", "aliases": [ "CVE-2021-47222" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: bridge: fix vlan tunnel dst refcnt when egressing\n\nThe egress tunnel code uses dst_clone() and directly sets the result\nwhich is wrong because the entry might have 0 refcnt or be already deleted,\ncausing number of problems. It also triggers the WARN_ON() in dst_hold()[1]\nwhen a refcnt couldn't be taken. Fix it by using dst_hold_safe() and\nchecking if a reference was actually taken before setting the dst.\n\n[1] dmesg WARN_ON log and following refcnt errors\n WARNING: CPU: 5 PID: 38 at include/net/dst.h:230 br_handle_egress_vlan_tunnel+0x10b/0x134 [bridge]\n Modules linked in: 8021q garp mrp bridge stp llc bonding ipv6 virtio_net\n CPU: 5 PID: 38 Comm: ksoftirqd/5 Kdump: loaded Tainted: G W 5.13.0-rc3+ #360\n Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.14.0-1.fc33 04/01/2014\n RIP: 0010:br_handle_egress_vlan_tunnel+0x10b/0x134 [bridge]\n Code: e8 85 bc 01 e1 45 84 f6 74 90 45 31 f6 85 db 48 c7 c7 a0 02 19 a0 41 0f 94 c6 31 c9 31 d2 44 89 f6 e8 64 bc 01 e1 85 db 75 02 <0f> 0b 31 c9 31 d2 44 89 f6 48 c7 c7 70 02 19 a0 e8 4b bc 01 e1 49\n RSP: 0018:ffff8881003d39e8 EFLAGS: 00010246\n RAX: 0000000000000000 RBX: 0000000000000000 RCX: 0000000000000000\n RDX: 0000000000000000 RSI: 0000000000000001 RDI: ffffffffa01902a0\n RBP: ffff8881040c6700 R08: 0000000000000000 R09: 0000000000000001\n R10: 2ce93d0054fe0d00 R11: 54fe0d00000e0000 R12: ffff888109515000\n R13: 0000000000000000 R14: 0000000000000001 R15: 0000000000000401\n FS: 0000000000000000(0000) GS:ffff88822bf40000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 00007f42ba70f030 CR3: 0000000109926000 CR4: 00000000000006e0\n Call Trace:\n br_handle_vlan+0xbc/0xca [bridge]\n __br_forward+0x23/0x164 [bridge]\n deliver_clone+0x41/0x48 [bridge]\n br_handle_frame_finish+0x36f/0x3aa [bridge]\n ? skb_dst+0x2e/0x38 [bridge]\n ? br_handle_ingress_vlan_tunnel+0x3e/0x1c8 [bridge]\n ? br_handle_frame_finish+0x3aa/0x3aa [bridge]\n br_handle_frame+0x2c3/0x377 [bridge]\n ? __skb_pull+0x33/0x51\n ? vlan_do_receive+0x4f/0x36a\n ? br_handle_frame_finish+0x3aa/0x3aa [bridge]\n __netif_receive_skb_core+0x539/0x7c6\n ? __list_del_entry_valid+0x16e/0x1c2\n __netif_receive_skb_list_core+0x6d/0xd6\n netif_receive_skb_list_internal+0x1d9/0x1fa\n gro_normal_list+0x22/0x3e\n dev_gro_receive+0x55b/0x600\n ? detach_buf_split+0x58/0x140\n napi_gro_receive+0x94/0x12e\n virtnet_poll+0x15d/0x315 [virtio_net]\n __napi_poll+0x2c/0x1c9\n net_rx_action+0xe6/0x1fb\n __do_softirq+0x115/0x2d8\n run_ksoftirqd+0x18/0x20\n smpboot_thread_fn+0x183/0x19c\n ? smpboot_unregister_percpu_thread+0x66/0x66\n kthread+0x10a/0x10f\n ? kthread_mod_delayed_work+0xb6/0xb6\n ret_from_fork+0x22/0x30\n ---[ end trace 49f61b07f775fd2b ]---\n dst_release: dst:00000000c02d677a refcnt:-1\n dst_release underflow", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T15:15:11Z" diff --git a/advisories/unreviewed/2024/05/GHSA-mv9f-845w-2cgm/GHSA-mv9f-845w-2cgm.json b/advisories/unreviewed/2024/05/GHSA-mv9f-845w-2cgm/GHSA-mv9f-845w-2cgm.json index 5fe99d09389..5f92334fe15 100644 --- a/advisories/unreviewed/2024/05/GHSA-mv9f-845w-2cgm/GHSA-mv9f-845w-2cgm.json +++ b/advisories/unreviewed/2024/05/GHSA-mv9f-845w-2cgm/GHSA-mv9f-845w-2cgm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mv9f-845w-2cgm", - "modified": "2024-05-21T15:31:40Z", + "modified": "2025-04-29T21:31:34Z", "published": "2024-05-21T15:31:40Z", "aliases": [ "CVE-2021-47234" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nphy: phy-mtk-tphy: Fix some resource leaks in mtk_phy_init()\n\nUse clk_disable_unprepare() in the error path of mtk_phy_init() to fix\nsome resource leaks.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T15:15:12Z" diff --git a/advisories/unreviewed/2025/01/GHSA-4m2r-43mh-wr82/GHSA-4m2r-43mh-wr82.json b/advisories/unreviewed/2025/01/GHSA-4m2r-43mh-wr82/GHSA-4m2r-43mh-wr82.json index 7fc4e07578f..c2c14c36e73 100644 --- a/advisories/unreviewed/2025/01/GHSA-4m2r-43mh-wr82/GHSA-4m2r-43mh-wr82.json +++ b/advisories/unreviewed/2025/01/GHSA-4m2r-43mh-wr82/GHSA-4m2r-43mh-wr82.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-xxj4-cj4p-x2c6/GHSA-xxj4-cj4p-x2c6.json b/advisories/unreviewed/2025/01/GHSA-xxj4-cj4p-x2c6/GHSA-xxj4-cj4p-x2c6.json index 7b659f66c1f..f65af5f6d08 100644 --- a/advisories/unreviewed/2025/01/GHSA-xxj4-cj4p-x2c6/GHSA-xxj4-cj4p-x2c6.json +++ b/advisories/unreviewed/2025/01/GHSA-xxj4-cj4p-x2c6/GHSA-xxj4-cj4p-x2c6.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-24cr-7gmf-xxwh/GHSA-24cr-7gmf-xxwh.json b/advisories/unreviewed/2025/04/GHSA-24cr-7gmf-xxwh/GHSA-24cr-7gmf-xxwh.json index d4af65ec72c..df39efa67d5 100644 --- a/advisories/unreviewed/2025/04/GHSA-24cr-7gmf-xxwh/GHSA-24cr-7gmf-xxwh.json +++ b/advisories/unreviewed/2025/04/GHSA-24cr-7gmf-xxwh/GHSA-24cr-7gmf-xxwh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-24cr-7gmf-xxwh", - "modified": "2025-04-16T15:34:39Z", + "modified": "2025-04-29T21:31:46Z", "published": "2025-04-16T15:34:39Z", "aliases": [ "CVE-2025-22032" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: mt7921: fix kernel panic due to null pointer dereference\n\nAddress a kernel panic caused by a null pointer dereference in the\n`mt792x_rx_get_wcid` function. The issue arises because the `deflink` structure\nis not properly initialized with the `sta` context. This patch ensures that the\n`deflink` structure is correctly linked to the `sta` context, preventing the\nnull pointer dereference.\n\n BUG: kernel NULL pointer dereference, address: 0000000000000400\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\n PGD 0 P4D 0\n Oops: Oops: 0000 [#1] PREEMPT SMP NOPTI\n CPU: 0 UID: 0 PID: 470 Comm: mt76-usb-rx phy Not tainted 6.12.13-gentoo-dist #1\n Hardware name: /AMD HUDSON-M1, BIOS 4.6.4 11/15/2011\n RIP: 0010:mt792x_rx_get_wcid+0x48/0x140 [mt792x_lib]\n RSP: 0018:ffffa147c055fd98 EFLAGS: 00010202\n RAX: 0000000000000000 RBX: ffff8e9ecb652000 RCX: 0000000000000000\n RDX: 0000000000000000 RSI: 0000000000000001 RDI: ffff8e9ecb652000\n RBP: 0000000000000685 R08: ffff8e9ec6570000 R09: 0000000000000000\n R10: ffff8e9ecd2ca000 R11: ffff8e9f22a217c0 R12: 0000000038010119\n R13: 0000000080843801 R14: ffff8e9ec6570000 R15: ffff8e9ecb652000\n FS: 0000000000000000(0000) GS:ffff8e9f22a00000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 0000000000000400 CR3: 000000000d2ea000 CR4: 00000000000006f0\n Call Trace:\n \n ? __die_body.cold+0x19/0x27\n ? page_fault_oops+0x15a/0x2f0\n ? search_module_extables+0x19/0x60\n ? search_bpf_extables+0x5f/0x80\n ? exc_page_fault+0x7e/0x180\n ? asm_exc_page_fault+0x26/0x30\n ? mt792x_rx_get_wcid+0x48/0x140 [mt792x_lib]\n mt7921_queue_rx_skb+0x1c6/0xaa0 [mt7921_common]\n mt76u_alloc_queues+0x784/0x810 [mt76_usb]\n ? __pfx___mt76_worker_fn+0x10/0x10 [mt76]\n __mt76_worker_fn+0x4f/0x80 [mt76]\n kthread+0xd2/0x100\n ? __pfx_kthread+0x10/0x10\n ret_from_fork+0x34/0x50\n ? __pfx_kthread+0x10/0x10\n ret_from_fork_asm+0x1a/0x30\n \n ---[ end trace 0000000000000000 ]---", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-16T15:15:55Z" diff --git a/advisories/unreviewed/2025/04/GHSA-24vc-7q35-w5rv/GHSA-24vc-7q35-w5rv.json b/advisories/unreviewed/2025/04/GHSA-24vc-7q35-w5rv/GHSA-24vc-7q35-w5rv.json index 7fc2541d9db..761d3ce5e17 100644 --- a/advisories/unreviewed/2025/04/GHSA-24vc-7q35-w5rv/GHSA-24vc-7q35-w5rv.json +++ b/advisories/unreviewed/2025/04/GHSA-24vc-7q35-w5rv/GHSA-24vc-7q35-w5rv.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-2788-7prj-r2qv/GHSA-2788-7prj-r2qv.json b/advisories/unreviewed/2025/04/GHSA-2788-7prj-r2qv/GHSA-2788-7prj-r2qv.json index 7bafee6dd1e..2c1b46aef28 100644 --- a/advisories/unreviewed/2025/04/GHSA-2788-7prj-r2qv/GHSA-2788-7prj-r2qv.json +++ b/advisories/unreviewed/2025/04/GHSA-2788-7prj-r2qv/GHSA-2788-7prj-r2qv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2788-7prj-r2qv", - "modified": "2025-04-16T15:34:39Z", + "modified": "2025-04-29T21:31:46Z", "published": "2025-04-16T15:34:39Z", "aliases": [ "CVE-2025-22031" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nPCI/bwctrl: Fix NULL pointer dereference on bus number exhaustion\n\nWhen BIOS neglects to assign bus numbers to PCI bridges, the kernel\nattempts to correct that during PCI device enumeration. If it runs out\nof bus numbers, no pci_bus is allocated and the \"subordinate\" pointer in\nthe bridge's pci_dev remains NULL.\n\nThe PCIe bandwidth controller erroneously does not check for a NULL\nsubordinate pointer and dereferences it on probe.\n\nBandwidth control of unusable devices below the bridge is of questionable\nutility, so simply error out instead. This mirrors what PCIe hotplug does\nsince commit 62e4492c3063 (\"PCI: Prevent NULL dereference during pciehp\nprobe\").\n\nThe PCI core emits a message with KERN_INFO severity if it has run out of\nbus numbers. PCIe hotplug emits an additional message with KERN_ERR\nseverity to inform the user that hotplug functionality is disabled at the\nbridge. A similar message for bandwidth control does not seem merited,\ngiven that its only purpose so far is to expose an up-to-date link speed\nin sysfs and throttle the link speed on certain laptops with limited\nThermal Design Power. So error out silently.\n\nUser-visible messages:\n\n pci 0000:16:02.0: bridge configuration invalid ([bus 00-00]), reconfiguring\n [...]\n pci_bus 0000:45: busn_res: [bus 45-74] end is updated to 74\n pci 0000:16:02.0: devices behind bridge are unusable because [bus 45-74] cannot be assigned for them\n [...]\n pcieport 0000:16:02.0: pciehp: Hotplug bridge without secondary bus, ignoring\n [...]\n BUG: kernel NULL pointer dereference\n RIP: pcie_update_link_speed\n pcie_bwnotif_enable\n pcie_bwnotif_probe\n pcie_port_probe_service\n really_probe", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-16T15:15:55Z" diff --git a/advisories/unreviewed/2025/04/GHSA-2wwh-pgrr-63c8/GHSA-2wwh-pgrr-63c8.json b/advisories/unreviewed/2025/04/GHSA-2wwh-pgrr-63c8/GHSA-2wwh-pgrr-63c8.json index 344214cf065..8a31d684ab4 100644 --- a/advisories/unreviewed/2025/04/GHSA-2wwh-pgrr-63c8/GHSA-2wwh-pgrr-63c8.json +++ b/advisories/unreviewed/2025/04/GHSA-2wwh-pgrr-63c8/GHSA-2wwh-pgrr-63c8.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-32fp-f974-p3vf/GHSA-32fp-f974-p3vf.json b/advisories/unreviewed/2025/04/GHSA-32fp-f974-p3vf/GHSA-32fp-f974-p3vf.json new file mode 100644 index 00000000000..a511cb676d9 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-32fp-f974-p3vf/GHSA-32fp-f974-p3vf.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-32fp-f974-p3vf", + "modified": "2025-04-29T21:31:54Z", + "published": "2025-04-29T21:31:54Z", + "aliases": [ + "CVE-2024-57698" + ], + "details": "An issue in modernwms v.1.0 allows an attacker view the MD5 hash of the administrator password and other attributes without authentication, even after initial configuration and password change. This happens due to excessive exposure of information and the lack of adequate access control on the /user/list?culture=en-us endpoint.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57698" + }, + { + "type": "WEB", + "url": "https://github.com/rodolfomarianocy/xpl-ModernWMS" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-29T20:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4c3f-c9v6-jqxm/GHSA-4c3f-c9v6-jqxm.json b/advisories/unreviewed/2025/04/GHSA-4c3f-c9v6-jqxm/GHSA-4c3f-c9v6-jqxm.json index 1af6475b785..14814883de9 100644 --- a/advisories/unreviewed/2025/04/GHSA-4c3f-c9v6-jqxm/GHSA-4c3f-c9v6-jqxm.json +++ b/advisories/unreviewed/2025/04/GHSA-4c3f-c9v6-jqxm/GHSA-4c3f-c9v6-jqxm.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-4fx4-vxg4-984r/GHSA-4fx4-vxg4-984r.json b/advisories/unreviewed/2025/04/GHSA-4fx4-vxg4-984r/GHSA-4fx4-vxg4-984r.json index 4b2dd680f19..6803ea2526d 100644 --- a/advisories/unreviewed/2025/04/GHSA-4fx4-vxg4-984r/GHSA-4fx4-vxg4-984r.json +++ b/advisories/unreviewed/2025/04/GHSA-4fx4-vxg4-984r/GHSA-4fx4-vxg4-984r.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-4hwj-3ppp-cx8v/GHSA-4hwj-3ppp-cx8v.json b/advisories/unreviewed/2025/04/GHSA-4hwj-3ppp-cx8v/GHSA-4hwj-3ppp-cx8v.json index cc864ccdf3d..9cdefb79eb5 100644 --- a/advisories/unreviewed/2025/04/GHSA-4hwj-3ppp-cx8v/GHSA-4hwj-3ppp-cx8v.json +++ b/advisories/unreviewed/2025/04/GHSA-4hwj-3ppp-cx8v/GHSA-4hwj-3ppp-cx8v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4hwj-3ppp-cx8v", - "modified": "2025-04-16T15:34:40Z", + "modified": "2025-04-29T21:31:47Z", "published": "2025-04-16T15:34:40Z", "aliases": [ "CVE-2025-22036" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nexfat: fix random stack corruption after get_block\n\nWhen get_block is called with a buffer_head allocated on the stack, such\nas do_mpage_readpage, stack corruption due to buffer_head UAF may occur in\nthe following race condition situation.\n\n \nmpage_read_folio\n <>\n do_mpage_readpage\n exfat_get_block\n bh_read\n __bh_read\n\t get_bh(bh)\n submit_bh\n wait_on_buffer\n ...\n end_buffer_read_sync\n __end_buffer_read_notouch\n unlock_buffer\n <>\n ...\n ...\n ...\n ...\n<>\n .\n .\nanother_function\n <>\n put_bh(bh)\n atomic_dec(bh->b_count)\n * stack corruption here *\n\nThis patch returns -EAGAIN if a folio does not have buffers when bh_read\nneeds to be called. By doing this, the caller can fallback to functions\nlike block_read_full_folio(), create a buffer_head in the folio, and then\ncall get_block again.\n\nLet's do not call bh_read() with on-stack buffer_head.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-362" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-16T15:15:56Z" diff --git a/advisories/unreviewed/2025/04/GHSA-4mpp-jp65-h4rw/GHSA-4mpp-jp65-h4rw.json b/advisories/unreviewed/2025/04/GHSA-4mpp-jp65-h4rw/GHSA-4mpp-jp65-h4rw.json index a9012c24023..b6549ec34c0 100644 --- a/advisories/unreviewed/2025/04/GHSA-4mpp-jp65-h4rw/GHSA-4mpp-jp65-h4rw.json +++ b/advisories/unreviewed/2025/04/GHSA-4mpp-jp65-h4rw/GHSA-4mpp-jp65-h4rw.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-4p64-m7fw-73rf/GHSA-4p64-m7fw-73rf.json b/advisories/unreviewed/2025/04/GHSA-4p64-m7fw-73rf/GHSA-4p64-m7fw-73rf.json index 25cfd536bc0..09fdccde4fd 100644 --- a/advisories/unreviewed/2025/04/GHSA-4p64-m7fw-73rf/GHSA-4p64-m7fw-73rf.json +++ b/advisories/unreviewed/2025/04/GHSA-4p64-m7fw-73rf/GHSA-4p64-m7fw-73rf.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-5659-626r-mfvx/GHSA-5659-626r-mfvx.json b/advisories/unreviewed/2025/04/GHSA-5659-626r-mfvx/GHSA-5659-626r-mfvx.json index 1bb1b50f7a2..28f242af981 100644 --- a/advisories/unreviewed/2025/04/GHSA-5659-626r-mfvx/GHSA-5659-626r-mfvx.json +++ b/advisories/unreviewed/2025/04/GHSA-5659-626r-mfvx/GHSA-5659-626r-mfvx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5659-626r-mfvx", - "modified": "2025-04-16T15:34:47Z", + "modified": "2025-04-29T21:31:48Z", "published": "2025-04-16T15:34:46Z", "aliases": [ "CVE-2025-23136" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nthermal: int340x: Add NULL check for adev\n\nNot all devices have an ACPI companion fwnode, so adev might be NULL.\nThis is similar to the commit cd2fd6eab480\n(\"platform/x86: int3472: Check for adev == NULL\").\n\nAdd a check for adev not being set and return -ENODEV in that case to\navoid a possible NULL pointer deref in int3402_thermal_probe().\n\nNote, under the same directory, int3400_thermal_probe() has such a\ncheck.\n\n[ rjw: Subject edit, added Fixes: ]", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -52,8 +57,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-16T15:16:07Z" diff --git a/advisories/unreviewed/2025/04/GHSA-5974-c6r6-2pv9/GHSA-5974-c6r6-2pv9.json b/advisories/unreviewed/2025/04/GHSA-5974-c6r6-2pv9/GHSA-5974-c6r6-2pv9.json index f1d2b535995..6d0830c91a9 100644 --- a/advisories/unreviewed/2025/04/GHSA-5974-c6r6-2pv9/GHSA-5974-c6r6-2pv9.json +++ b/advisories/unreviewed/2025/04/GHSA-5974-c6r6-2pv9/GHSA-5974-c6r6-2pv9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5974-c6r6-2pv9", - "modified": "2025-04-17T18:31:22Z", + "modified": "2025-04-29T21:31:50Z", "published": "2025-04-17T18:31:22Z", "aliases": [ "CVE-2020-36789" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: dev: can_get_echo_skb(): prevent call to kfree_skb() in hard IRQ context\n\nIf a driver calls can_get_echo_skb() during a hardware IRQ (which is often, but\nnot always, the case), the 'WARN_ON(in_irq)' in\nnet/core/skbuff.c#skb_release_head_state() might be triggered, under network\ncongestion circumstances, together with the potential risk of a NULL pointer\ndereference.\n\nThe root cause of this issue is the call to kfree_skb() instead of\ndev_kfree_skb_irq() in net/core/dev.c#enqueue_to_backlog().\n\nThis patch prevents the skb to be freed within the call to netif_rx() by\nincrementing its reference count with skb_get(). The skb is finally freed by\none of the in-irq-context safe functions: dev_consume_skb_any() or\ndev_kfree_skb_any(). The \"any\" version is used because some drivers might call\ncan_get_echo_skb() in a normal context.\n\nThe reason for this issue to occur is that initially, in the core network\nstack, loopback skb were not supposed to be received in hardware IRQ context.\nThe CAN stack is an exeption.\n\nThis bug was previously reported back in 2017 in [1] but the proposed patch\nnever got accepted.\n\nWhile [1] directly modifies net/core/dev.c, we try to propose here a\nsmoother modification local to CAN network stack (the assumption\nbehind is that only CAN devices are affected by this issue).\n\n[1] http://lore.kernel.org/r/57a3ffb6-3309-3ad5-5a34-e93c3fe3614d@cetitec.com", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-17T18:15:42Z" diff --git a/advisories/unreviewed/2025/04/GHSA-5q67-5hpv-7q5r/GHSA-5q67-5hpv-7q5r.json b/advisories/unreviewed/2025/04/GHSA-5q67-5hpv-7q5r/GHSA-5q67-5hpv-7q5r.json index 994aecec222..c8d02ac1470 100644 --- a/advisories/unreviewed/2025/04/GHSA-5q67-5hpv-7q5r/GHSA-5q67-5hpv-7q5r.json +++ b/advisories/unreviewed/2025/04/GHSA-5q67-5hpv-7q5r/GHSA-5q67-5hpv-7q5r.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-5v57-87fw-9gxc/GHSA-5v57-87fw-9gxc.json b/advisories/unreviewed/2025/04/GHSA-5v57-87fw-9gxc/GHSA-5v57-87fw-9gxc.json index dfbb4fd9756..0fa8af90d92 100644 --- a/advisories/unreviewed/2025/04/GHSA-5v57-87fw-9gxc/GHSA-5v57-87fw-9gxc.json +++ b/advisories/unreviewed/2025/04/GHSA-5v57-87fw-9gxc/GHSA-5v57-87fw-9gxc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5v57-87fw-9gxc", - "modified": "2025-04-16T15:34:39Z", + "modified": "2025-04-29T21:31:46Z", "published": "2025-04-16T15:34:39Z", "aliases": [ "CVE-2025-22033" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\narm64: Don't call NULL in do_compat_alignment_fixup()\n\ndo_alignment_t32_to_handler() only fixes up alignment faults for\nspecific instructions; it returns NULL otherwise (e.g. LDREX). When\nthat's the case, signal to the caller that it needs to proceed with the\nregular alignment fault handling (i.e. SIGBUS). Without this patch, the\nkernel panics:\n\n Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000\n Mem abort info:\n ESR = 0x0000000086000006\n EC = 0x21: IABT (current EL), IL = 32 bits\n SET = 0, FnV = 0\n EA = 0, S1PTW = 0\n FSC = 0x06: level 2 translation fault\n user pgtable: 4k pages, 48-bit VAs, pgdp=00000800164aa000\n [0000000000000000] pgd=0800081fdbd22003, p4d=0800081fdbd22003, pud=08000815d51c6003, pmd=0000000000000000\n Internal error: Oops: 0000000086000006 [#1] SMP\n Modules linked in: cfg80211 rfkill xt_nat xt_tcpudp xt_conntrack nft_chain_nat xt_MASQUERADE nf_nat nf_conntrack_netlink nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 xfrm_user xfrm_algo xt_addrtype nft_compat br_netfilter veth nvme_fa>\n libcrc32c crc32c_generic raid0 multipath linear dm_mod dax raid1 md_mod xhci_pci nvme xhci_hcd nvme_core t10_pi usbcore igb crc64_rocksoft crc64 crc_t10dif crct10dif_generic crct10dif_ce crct10dif_common usb_common i2c_algo_bit i2c>\n CPU: 2 PID: 3932954 Comm: WPEWebProcess Not tainted 6.1.0-31-arm64 #1 Debian 6.1.128-1\n Hardware name: GIGABYTE MP32-AR1-00/MP32-AR1-00, BIOS F18v (SCP: 1.08.20211002) 12/01/2021\n pstate: 80400009 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n pc : 0x0\n lr : do_compat_alignment_fixup+0xd8/0x3dc\n sp : ffff80000f973dd0\n x29: ffff80000f973dd0 x28: ffff081b42526180 x27: 0000000000000000\n x26: 0000000000000000 x25: 0000000000000000 x24: 0000000000000000\n x23: 0000000000000004 x22: 0000000000000000 x21: 0000000000000001\n x20: 00000000e8551f00 x19: ffff80000f973eb0 x18: 0000000000000000\n x17: 0000000000000000 x16: 0000000000000000 x15: 0000000000000000\n x14: 0000000000000000 x13: 0000000000000000 x12: 0000000000000000\n x11: 0000000000000000 x10: 0000000000000000 x9 : ffffaebc949bc488\n x8 : 0000000000000000 x7 : 0000000000000000 x6 : 0000000000000000\n x5 : 0000000000400000 x4 : 0000fffffffffffe x3 : 0000000000000000\n x2 : ffff80000f973eb0 x1 : 00000000e8551f00 x0 : 0000000000000001\n Call trace:\n 0x0\n do_alignment_fault+0x40/0x50\n do_mem_abort+0x4c/0xa0\n el0_da+0x48/0xf0\n el0t_32_sync_handler+0x110/0x140\n el0t_32_sync+0x190/0x194\n Code: bad PC value\n ---[ end trace 0000000000000000 ]---", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-16T15:15:55Z" diff --git a/advisories/unreviewed/2025/04/GHSA-65vr-4gg3-qw3m/GHSA-65vr-4gg3-qw3m.json b/advisories/unreviewed/2025/04/GHSA-65vr-4gg3-qw3m/GHSA-65vr-4gg3-qw3m.json index 13fbcc40b50..5a60d86515c 100644 --- a/advisories/unreviewed/2025/04/GHSA-65vr-4gg3-qw3m/GHSA-65vr-4gg3-qw3m.json +++ b/advisories/unreviewed/2025/04/GHSA-65vr-4gg3-qw3m/GHSA-65vr-4gg3-qw3m.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-6jmr-r7p6-f5wr/GHSA-6jmr-r7p6-f5wr.json b/advisories/unreviewed/2025/04/GHSA-6jmr-r7p6-f5wr/GHSA-6jmr-r7p6-f5wr.json new file mode 100644 index 00000000000..3361c8005b7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6jmr-r7p6-f5wr/GHSA-6jmr-r7p6-f5wr.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6jmr-r7p6-f5wr", + "modified": "2025-04-29T21:31:55Z", + "published": "2025-04-29T21:31:55Z", + "aliases": [ + "CVE-2025-0520" + ], + "details": "An unrestricted file upload vulnerability in ShowDoc caused by improper validation of file extension allows execution of arbitrary PHP, leading to remote code execution.This issue affects ShowDoc: before 2.8.7.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0520" + }, + { + "type": "WEB", + "url": "https://github.com/star7th/showdoc/pull/1059" + }, + { + "type": "WEB", + "url": "https://github.com/vulhub/vulhub/tree/master/showdoc/CNVD-2020-26585" + }, + { + "type": "WEB", + "url": "https://www.cnvd.org.cn/flaw/show/CNVD-2020-26585" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-29T20:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6pg5-wf6r-xvh8/GHSA-6pg5-wf6r-xvh8.json b/advisories/unreviewed/2025/04/GHSA-6pg5-wf6r-xvh8/GHSA-6pg5-wf6r-xvh8.json index 3bd1399a829..e6dbad87e62 100644 --- a/advisories/unreviewed/2025/04/GHSA-6pg5-wf6r-xvh8/GHSA-6pg5-wf6r-xvh8.json +++ b/advisories/unreviewed/2025/04/GHSA-6pg5-wf6r-xvh8/GHSA-6pg5-wf6r-xvh8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6pg5-wf6r-xvh8", - "modified": "2025-04-16T15:34:41Z", + "modified": "2025-04-29T21:31:47Z", "published": "2025-04-16T15:34:41Z", "aliases": [ "CVE-2025-22054" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\narcnet: Add NULL check in com20020pci_probe()\n\ndevm_kasprintf() returns NULL when memory allocation fails. Currently,\ncom20020pci_probe() does not check for this case, which results in a\nNULL pointer dereference.\n\nAdd NULL check after devm_kasprintf() to prevent this issue and ensure\nno resources are left allocated.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -52,8 +57,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-16T15:15:58Z" diff --git a/advisories/unreviewed/2025/04/GHSA-73hp-3m9v-h54h/GHSA-73hp-3m9v-h54h.json b/advisories/unreviewed/2025/04/GHSA-73hp-3m9v-h54h/GHSA-73hp-3m9v-h54h.json index 5d40fd61908..ff64ccc8f61 100644 --- a/advisories/unreviewed/2025/04/GHSA-73hp-3m9v-h54h/GHSA-73hp-3m9v-h54h.json +++ b/advisories/unreviewed/2025/04/GHSA-73hp-3m9v-h54h/GHSA-73hp-3m9v-h54h.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-73hp-3m9v-h54h", - "modified": "2025-04-24T03:31:32Z", + "modified": "2025-04-29T21:31:52Z", "published": "2025-04-24T03:31:32Z", "aliases": [ "CVE-2025-1976" ], "details": "Brocade Fabric OS versions starting with 9.1.0 have root access removed, however, a local user with admin privilege can potentially execute arbitrary code with full root privileges on Fabric OS versions 9.1.0 through 9.1.1d6.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" @@ -26,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-78", "CWE-94" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2025/04/GHSA-7mx5-64fm-676w/GHSA-7mx5-64fm-676w.json b/advisories/unreviewed/2025/04/GHSA-7mx5-64fm-676w/GHSA-7mx5-64fm-676w.json index 9d31da339a0..8b9f6c4dea8 100644 --- a/advisories/unreviewed/2025/04/GHSA-7mx5-64fm-676w/GHSA-7mx5-64fm-676w.json +++ b/advisories/unreviewed/2025/04/GHSA-7mx5-64fm-676w/GHSA-7mx5-64fm-676w.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7mx5-64fm-676w", - "modified": "2025-04-16T15:34:41Z", + "modified": "2025-04-29T21:31:48Z", "published": "2025-04-16T15:34:41Z", "aliases": [ "CVE-2025-22056" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_tunnel: fix geneve_opt type confusion addition\n\nWhen handling multiple NFTA_TUNNEL_KEY_OPTS_GENEVE attributes, the\nparsing logic should place every geneve_opt structure one by one\ncompactly. Hence, when deciding the next geneve_opt position, the\npointer addition should be in units of char *.\n\nHowever, the current implementation erroneously does type conversion\nbefore the addition, which will lead to heap out-of-bounds write.\n\n[ 6.989857] ==================================================================\n[ 6.990293] BUG: KASAN: slab-out-of-bounds in nft_tunnel_obj_init+0x977/0xa70\n[ 6.990725] Write of size 124 at addr ffff888005f18974 by task poc/178\n[ 6.991162]\n[ 6.991259] CPU: 0 PID: 178 Comm: poc-oob-write Not tainted 6.1.132 #1\n[ 6.991655] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.0-0-gd239552ce722-prebuilt.qemu.org 04/01/2014\n[ 6.992281] Call Trace:\n[ 6.992423] \n[ 6.992586] dump_stack_lvl+0x44/0x5c\n[ 6.992801] print_report+0x184/0x4be\n[ 6.993790] kasan_report+0xc5/0x100\n[ 6.994252] kasan_check_range+0xf3/0x1a0\n[ 6.994486] memcpy+0x38/0x60\n[ 6.994692] nft_tunnel_obj_init+0x977/0xa70\n[ 6.995677] nft_obj_init+0x10c/0x1b0\n[ 6.995891] nf_tables_newobj+0x585/0x950\n[ 6.996922] nfnetlink_rcv_batch+0xdf9/0x1020\n[ 6.998997] nfnetlink_rcv+0x1df/0x220\n[ 6.999537] netlink_unicast+0x395/0x530\n[ 7.000771] netlink_sendmsg+0x3d0/0x6d0\n[ 7.001462] __sock_sendmsg+0x99/0xa0\n[ 7.001707] ____sys_sendmsg+0x409/0x450\n[ 7.002391] ___sys_sendmsg+0xfd/0x170\n[ 7.003145] __sys_sendmsg+0xea/0x170\n[ 7.004359] do_syscall_64+0x5e/0x90\n[ 7.005817] entry_SYSCALL_64_after_hwframe+0x6e/0xd8\n[ 7.006127] RIP: 0033:0x7ec756d4e407\n[ 7.006339] Code: 48 89 fa 4c 89 df e8 38 aa 00 00 8b 93 08 03 00 00 59 5e 48 83 f8 fc 74 1a 5b c3 0f 1f 84 00 00 00 00 00 48 8b 44 24 10 0f 05 <5b> c3 0f 1f 80 00 00 00 00 83 e2 39 83 faf\n[ 7.007364] RSP: 002b:00007ffed5d46760 EFLAGS: 00000202 ORIG_RAX: 000000000000002e\n[ 7.007827] RAX: ffffffffffffffda RBX: 00007ec756cc4740 RCX: 00007ec756d4e407\n[ 7.008223] RDX: 0000000000000000 RSI: 00007ffed5d467f0 RDI: 0000000000000003\n[ 7.008620] RBP: 00007ffed5d468a0 R08: 0000000000000000 R09: 0000000000000000\n[ 7.009039] R10: 0000000000000000 R11: 0000000000000202 R12: 0000000000000000\n[ 7.009429] R13: 00007ffed5d478b0 R14: 00007ec756ee5000 R15: 00005cbd4e655cb8\n\nFix this bug with correct pointer addition and conversion in parse\nand dump code.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-16T15:15:59Z" diff --git a/advisories/unreviewed/2025/04/GHSA-7p3g-jgfx-frjh/GHSA-7p3g-jgfx-frjh.json b/advisories/unreviewed/2025/04/GHSA-7p3g-jgfx-frjh/GHSA-7p3g-jgfx-frjh.json index 79c9a24e338..02af72c19e6 100644 --- a/advisories/unreviewed/2025/04/GHSA-7p3g-jgfx-frjh/GHSA-7p3g-jgfx-frjh.json +++ b/advisories/unreviewed/2025/04/GHSA-7p3g-jgfx-frjh/GHSA-7p3g-jgfx-frjh.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-94" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-843p-6jf4-c3r6/GHSA-843p-6jf4-c3r6.json b/advisories/unreviewed/2025/04/GHSA-843p-6jf4-c3r6/GHSA-843p-6jf4-c3r6.json index e4c624c8e34..06b6558bbcd 100644 --- a/advisories/unreviewed/2025/04/GHSA-843p-6jf4-c3r6/GHSA-843p-6jf4-c3r6.json +++ b/advisories/unreviewed/2025/04/GHSA-843p-6jf4-c3r6/GHSA-843p-6jf4-c3r6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-843p-6jf4-c3r6", - "modified": "2025-04-16T15:34:46Z", + "modified": "2025-04-29T21:31:48Z", "published": "2025-04-16T15:34:46Z", "aliases": [ "CVE-2025-23137" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncpufreq/amd-pstate: Add missing NULL ptr check in amd_pstate_update\n\nCheck if policy is NULL before dereferencing it in amd_pstate_update.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-16T15:16:08Z" diff --git a/advisories/unreviewed/2025/04/GHSA-8xw7-j864-h87q/GHSA-8xw7-j864-h87q.json b/advisories/unreviewed/2025/04/GHSA-8xw7-j864-h87q/GHSA-8xw7-j864-h87q.json index 3010f429aae..aca0fbeb96a 100644 --- a/advisories/unreviewed/2025/04/GHSA-8xw7-j864-h87q/GHSA-8xw7-j864-h87q.json +++ b/advisories/unreviewed/2025/04/GHSA-8xw7-j864-h87q/GHSA-8xw7-j864-h87q.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8xw7-j864-h87q", - "modified": "2025-04-16T15:34:40Z", + "modified": "2025-04-29T21:31:47Z", "published": "2025-04-16T15:34:40Z", "aliases": [ "CVE-2025-22038" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: validate zero num_subauth before sub_auth is accessed\n\nAccess psid->sub_auth[psid->num_subauth - 1] without checking\nif num_subauth is non-zero leads to an out-of-bounds read.\nThis patch adds a validation step to ensure num_subauth != 0\nbefore sub_auth is accessed.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-16T15:15:56Z" diff --git a/advisories/unreviewed/2025/04/GHSA-9867-8p52-837m/GHSA-9867-8p52-837m.json b/advisories/unreviewed/2025/04/GHSA-9867-8p52-837m/GHSA-9867-8p52-837m.json index a9208ae6d93..46764f0ff2b 100644 --- a/advisories/unreviewed/2025/04/GHSA-9867-8p52-837m/GHSA-9867-8p52-837m.json +++ b/advisories/unreviewed/2025/04/GHSA-9867-8p52-837m/GHSA-9867-8p52-837m.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-9wr5-868p-4jmw/GHSA-9wr5-868p-4jmw.json b/advisories/unreviewed/2025/04/GHSA-9wr5-868p-4jmw/GHSA-9wr5-868p-4jmw.json index c976af59fad..2304204f17b 100644 --- a/advisories/unreviewed/2025/04/GHSA-9wr5-868p-4jmw/GHSA-9wr5-868p-4jmw.json +++ b/advisories/unreviewed/2025/04/GHSA-9wr5-868p-4jmw/GHSA-9wr5-868p-4jmw.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-9xq3-wmwq-jv6r/GHSA-9xq3-wmwq-jv6r.json b/advisories/unreviewed/2025/04/GHSA-9xq3-wmwq-jv6r/GHSA-9xq3-wmwq-jv6r.json new file mode 100644 index 00000000000..2b07d52814f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9xq3-wmwq-jv6r/GHSA-9xq3-wmwq-jv6r.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9xq3-wmwq-jv6r", + "modified": "2025-04-29T21:31:54Z", + "published": "2025-04-29T21:31:54Z", + "aliases": [ + "CVE-2025-4079" + ], + "details": "A vulnerability, which was classified as critical, was found in PCMan FTP Server up to 2.0.7. Affected is an unknown function of the component RENAME Command Handler. The manipulation leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4079" + }, + { + "type": "WEB", + "url": "https://fitoxs.com/exploit/exploit-9e107d9d372bb6826bd81d3542a419d6.txt" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.306516" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.306516" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.560541" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-29T19:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-c8pq-47pf-5pgc/GHSA-c8pq-47pf-5pgc.json b/advisories/unreviewed/2025/04/GHSA-c8pq-47pf-5pgc/GHSA-c8pq-47pf-5pgc.json index 4e1afde0cfa..e6a4470e153 100644 --- a/advisories/unreviewed/2025/04/GHSA-c8pq-47pf-5pgc/GHSA-c8pq-47pf-5pgc.json +++ b/advisories/unreviewed/2025/04/GHSA-c8pq-47pf-5pgc/GHSA-c8pq-47pf-5pgc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c8pq-47pf-5pgc", - "modified": "2025-04-16T15:34:40Z", + "modified": "2025-04-29T21:31:47Z", "published": "2025-04-16T15:34:40Z", "aliases": [ "CVE-2025-22051" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: gpib: Fix Oops after disconnect in agilent usb\n\nIf the agilent usb dongle is disconnected subsequent calls to the\ndriver cause a NULL dereference Oops as the bus_interface\nis set to NULL on disconnect.\n\nThis problem was introduced by setting usb_dev from the bus_interface\nfor dev_xxx messages.\n\nPreviously bus_interface was checked for NULL only in the functions\ndirectly calling usb_fill_bulk_urb or usb_control_msg.\n\nCheck for valid bus_interface on all interface entry points\nand return -ENODEV if it is NULL.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-16T15:15:58Z" diff --git a/advisories/unreviewed/2025/04/GHSA-fx44-2wx5-5fvp/GHSA-fx44-2wx5-5fvp.json b/advisories/unreviewed/2025/04/GHSA-fx44-2wx5-5fvp/GHSA-fx44-2wx5-5fvp.json new file mode 100644 index 00000000000..1b85d3d86a4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fx44-2wx5-5fvp/GHSA-fx44-2wx5-5fvp.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fx44-2wx5-5fvp", + "modified": "2025-04-29T21:31:56Z", + "published": "2025-04-29T21:31:56Z", + "aliases": [ + "CVE-2025-3910" + ], + "details": "A flaw was found in Keycloak. The org.keycloak.authorization package may be vulnerable to circumventing required actions, allowing users to circumvent requirements such as setting up two-factor authentication.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3910" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2025-3910" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2361923" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-29T21:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fx6v-2fj6-rmxx/GHSA-fx6v-2fj6-rmxx.json b/advisories/unreviewed/2025/04/GHSA-fx6v-2fj6-rmxx/GHSA-fx6v-2fj6-rmxx.json index 5ed8cc471bc..6aa89de17b1 100644 --- a/advisories/unreviewed/2025/04/GHSA-fx6v-2fj6-rmxx/GHSA-fx6v-2fj6-rmxx.json +++ b/advisories/unreviewed/2025/04/GHSA-fx6v-2fj6-rmxx/GHSA-fx6v-2fj6-rmxx.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-gjvw-2pj9-fgr6/GHSA-gjvw-2pj9-fgr6.json b/advisories/unreviewed/2025/04/GHSA-gjvw-2pj9-fgr6/GHSA-gjvw-2pj9-fgr6.json index 9b4c1e147d5..ffeac8287e7 100644 --- a/advisories/unreviewed/2025/04/GHSA-gjvw-2pj9-fgr6/GHSA-gjvw-2pj9-fgr6.json +++ b/advisories/unreviewed/2025/04/GHSA-gjvw-2pj9-fgr6/GHSA-gjvw-2pj9-fgr6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gjvw-2pj9-fgr6", - "modified": "2025-04-16T15:34:40Z", + "modified": "2025-04-29T21:31:47Z", "published": "2025-04-16T15:34:40Z", "aliases": [ "CVE-2025-22052" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: gpib: Fix Oops after disconnect in ni_usb\n\nIf the usb dongle is disconnected subsequent calls to the\ndriver cause a NULL dereference Oops as the bus_interface\nis set to NULL on disconnect.\n\nThis problem was introduced by setting usb_dev from the bus_interface\nfor dev_xxx messages.\n\nPreviously bus_interface was checked for NULL only in the the functions\ndirectly calling usb_fill_bulk_urb or usb_control_msg.\n\nCheck for valid bus_interface on all interface entry points\nand return -ENODEV if it is NULL.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-16T15:15:58Z" diff --git a/advisories/unreviewed/2025/04/GHSA-gmvc-v65c-677x/GHSA-gmvc-v65c-677x.json b/advisories/unreviewed/2025/04/GHSA-gmvc-v65c-677x/GHSA-gmvc-v65c-677x.json index a61d11fc4b5..88799248174 100644 --- a/advisories/unreviewed/2025/04/GHSA-gmvc-v65c-677x/GHSA-gmvc-v65c-677x.json +++ b/advisories/unreviewed/2025/04/GHSA-gmvc-v65c-677x/GHSA-gmvc-v65c-677x.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-gvg4-xh6r-ggrp/GHSA-gvg4-xh6r-ggrp.json b/advisories/unreviewed/2025/04/GHSA-gvg4-xh6r-ggrp/GHSA-gvg4-xh6r-ggrp.json index be6b8431753..ed1141c5da8 100644 --- a/advisories/unreviewed/2025/04/GHSA-gvg4-xh6r-ggrp/GHSA-gvg4-xh6r-ggrp.json +++ b/advisories/unreviewed/2025/04/GHSA-gvg4-xh6r-ggrp/GHSA-gvg4-xh6r-ggrp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gvg4-xh6r-ggrp", - "modified": "2025-04-16T15:34:40Z", + "modified": "2025-04-29T21:31:47Z", "published": "2025-04-16T15:34:40Z", "aliases": [ "CVE-2025-22037" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix null pointer dereference in alloc_preauth_hash()\n\nThe Client send malformed smb2 negotiate request. ksmbd return error\nresponse. Subsequently, the client can send smb2 session setup even\nthought conn->preauth_info is not allocated.\nThis patch add KSMBD_SESS_NEED_SETUP status of connection to ignore\nsession setup request if smb2 negotiate phase is not complete.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-16T15:15:56Z" diff --git a/advisories/unreviewed/2025/04/GHSA-gxg5-6xg7-gc7q/GHSA-gxg5-6xg7-gc7q.json b/advisories/unreviewed/2025/04/GHSA-gxg5-6xg7-gc7q/GHSA-gxg5-6xg7-gc7q.json index c9db4a3764f..49b39eb3962 100644 --- a/advisories/unreviewed/2025/04/GHSA-gxg5-6xg7-gc7q/GHSA-gxg5-6xg7-gc7q.json +++ b/advisories/unreviewed/2025/04/GHSA-gxg5-6xg7-gc7q/GHSA-gxg5-6xg7-gc7q.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gxg5-6xg7-gc7q", - "modified": "2025-04-16T15:34:46Z", + "modified": "2025-04-29T21:31:48Z", "published": "2025-04-16T15:34:46Z", "aliases": [ "CVE-2025-23134" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: timer: Don't take register_mutex with copy_from/to_user()\n\nThe infamous mmap_lock taken in copy_from/to_user() can be often\nproblematic when it's called inside another mutex, as they might lead\nto deadlocks.\n\nIn the case of ALSA timer code, the bad pattern is with\nguard(mutex)(®ister_mutex) that covers copy_from/to_user() -- which\nwas mistakenly introduced at converting to guard(), and it had been\ncarefully worked around in the past.\n\nThis patch fixes those pieces simply by moving copy_from/to_user() out\nof the register mutex lock again.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-667" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-16T15:16:07Z" diff --git a/advisories/unreviewed/2025/04/GHSA-j2gf-g3mw-7r5v/GHSA-j2gf-g3mw-7r5v.json b/advisories/unreviewed/2025/04/GHSA-j2gf-g3mw-7r5v/GHSA-j2gf-g3mw-7r5v.json index 2a2a85c39a0..8e3e7b707cc 100644 --- a/advisories/unreviewed/2025/04/GHSA-j2gf-g3mw-7r5v/GHSA-j2gf-g3mw-7r5v.json +++ b/advisories/unreviewed/2025/04/GHSA-j2gf-g3mw-7r5v/GHSA-j2gf-g3mw-7r5v.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-jcc3-vmjf-jfhj/GHSA-jcc3-vmjf-jfhj.json b/advisories/unreviewed/2025/04/GHSA-jcc3-vmjf-jfhj/GHSA-jcc3-vmjf-jfhj.json index 6b4d0c29194..3ada73b0de2 100644 --- a/advisories/unreviewed/2025/04/GHSA-jcc3-vmjf-jfhj/GHSA-jcc3-vmjf-jfhj.json +++ b/advisories/unreviewed/2025/04/GHSA-jcc3-vmjf-jfhj/GHSA-jcc3-vmjf-jfhj.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-p345-jmhp-7wg2/GHSA-p345-jmhp-7wg2.json b/advisories/unreviewed/2025/04/GHSA-p345-jmhp-7wg2/GHSA-p345-jmhp-7wg2.json index f299ed968b0..b205c3598d8 100644 --- a/advisories/unreviewed/2025/04/GHSA-p345-jmhp-7wg2/GHSA-p345-jmhp-7wg2.json +++ b/advisories/unreviewed/2025/04/GHSA-p345-jmhp-7wg2/GHSA-p345-jmhp-7wg2.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-p8jc-2h55-7w89/GHSA-p8jc-2h55-7w89.json b/advisories/unreviewed/2025/04/GHSA-p8jc-2h55-7w89/GHSA-p8jc-2h55-7w89.json new file mode 100644 index 00000000000..8959099b335 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-p8jc-2h55-7w89/GHSA-p8jc-2h55-7w89.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p8jc-2h55-7w89", + "modified": "2025-04-29T21:31:55Z", + "published": "2025-04-29T21:31:55Z", + "aliases": [ + "CVE-2025-4078" + ], + "details": "A vulnerability, which was classified as problematic, has been found in Wangshen SecGate 3600 2400. This issue affects some unknown processing of the file ?g=log_export_file. The manipulation of the argument file_name leads to path traversal. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4078" + }, + { + "type": "WEB", + "url": "https://flowus.cn/share/f5c70c53-737b-470b-aa2e-6d5524f849fb?code=G8A6P3" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.306515" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.306515" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.560540" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-29T20:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-pg7p-xxvc-73xx/GHSA-pg7p-xxvc-73xx.json b/advisories/unreviewed/2025/04/GHSA-pg7p-xxvc-73xx/GHSA-pg7p-xxvc-73xx.json index df7b01471af..7dea923ff2e 100644 --- a/advisories/unreviewed/2025/04/GHSA-pg7p-xxvc-73xx/GHSA-pg7p-xxvc-73xx.json +++ b/advisories/unreviewed/2025/04/GHSA-pg7p-xxvc-73xx/GHSA-pg7p-xxvc-73xx.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-pxcm-247j-vw9j/GHSA-pxcm-247j-vw9j.json b/advisories/unreviewed/2025/04/GHSA-pxcm-247j-vw9j/GHSA-pxcm-247j-vw9j.json index 454c431e995..8235fa877a7 100644 --- a/advisories/unreviewed/2025/04/GHSA-pxcm-247j-vw9j/GHSA-pxcm-247j-vw9j.json +++ b/advisories/unreviewed/2025/04/GHSA-pxcm-247j-vw9j/GHSA-pxcm-247j-vw9j.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-qffm-wchf-95hp/GHSA-qffm-wchf-95hp.json b/advisories/unreviewed/2025/04/GHSA-qffm-wchf-95hp/GHSA-qffm-wchf-95hp.json new file mode 100644 index 00000000000..0c19a26d490 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qffm-wchf-95hp/GHSA-qffm-wchf-95hp.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qffm-wchf-95hp", + "modified": "2025-04-29T21:31:56Z", + "published": "2025-04-29T21:31:56Z", + "aliases": [ + "CVE-2025-4080" + ], + "details": "A vulnerability has been found in PHPGurukul Online Nurse Hiring System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/view-request.php. The manipulation of the argument viewid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4080" + }, + { + "type": "WEB", + "url": "https://github.com/Iandweb/CVE/issues/2" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.306517" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.306517" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.560558" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-29T20:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-r764-27jf-q424/GHSA-r764-27jf-q424.json b/advisories/unreviewed/2025/04/GHSA-r764-27jf-q424/GHSA-r764-27jf-q424.json index 0b48d50c28d..711342f5027 100644 --- a/advisories/unreviewed/2025/04/GHSA-r764-27jf-q424/GHSA-r764-27jf-q424.json +++ b/advisories/unreviewed/2025/04/GHSA-r764-27jf-q424/GHSA-r764-27jf-q424.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-r764-27jf-q424", - "modified": "2025-04-16T15:34:41Z", + "modified": "2025-04-29T21:31:48Z", "published": "2025-04-16T15:34:41Z", "aliases": [ "CVE-2025-22063" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetlabel: Fix NULL pointer exception caused by CALIPSO on IPv4 sockets\n\nWhen calling netlbl_conn_setattr(), addr->sa_family is used\nto determine the function behavior. If sk is an IPv4 socket,\nbut the connect function is called with an IPv6 address,\nthe function calipso_sock_setattr() is triggered.\nInside this function, the following code is executed:\n\nsk_fullsock(__sk) ? inet_sk(__sk)->pinet6 : NULL;\n\nSince sk is an IPv4 socket, pinet6 is NULL, leading to a\nnull pointer dereference.\n\nThis patch fixes the issue by checking if inet6_sk(sk)\nreturns a NULL pointer before accessing pinet6.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -52,8 +57,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-16T15:15:59Z" diff --git a/advisories/unreviewed/2025/04/GHSA-r934-w73g-v4p8/GHSA-r934-w73g-v4p8.json b/advisories/unreviewed/2025/04/GHSA-r934-w73g-v4p8/GHSA-r934-w73g-v4p8.json new file mode 100644 index 00000000000..b49ab4c9383 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-r934-w73g-v4p8/GHSA-r934-w73g-v4p8.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r934-w73g-v4p8", + "modified": "2025-04-29T21:31:56Z", + "published": "2025-04-29T21:31:56Z", + "aliases": [ + "CVE-2025-3501" + ], + "details": "A flaw was found in Keycloak. By setting a verification policy to 'ALL', the trust store certificate verification is skipped, which is unintended.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3501" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2025-3501" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2358834" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-297" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-29T21:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vhg6-m6c8-39c2/GHSA-vhg6-m6c8-39c2.json b/advisories/unreviewed/2025/04/GHSA-vhg6-m6c8-39c2/GHSA-vhg6-m6c8-39c2.json index b74c918f4a5..ea16cbc03f7 100644 --- a/advisories/unreviewed/2025/04/GHSA-vhg6-m6c8-39c2/GHSA-vhg6-m6c8-39c2.json +++ b/advisories/unreviewed/2025/04/GHSA-vhg6-m6c8-39c2/GHSA-vhg6-m6c8-39c2.json @@ -42,6 +42,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-79", "CWE-80" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2025/04/GHSA-wh3v-xmpm-9x73/GHSA-wh3v-xmpm-9x73.json b/advisories/unreviewed/2025/04/GHSA-wh3v-xmpm-9x73/GHSA-wh3v-xmpm-9x73.json index 0a83fabd1b6..938868a1f34 100644 --- a/advisories/unreviewed/2025/04/GHSA-wh3v-xmpm-9x73/GHSA-wh3v-xmpm-9x73.json +++ b/advisories/unreviewed/2025/04/GHSA-wh3v-xmpm-9x73/GHSA-wh3v-xmpm-9x73.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null,