diff --git a/advisories/unreviewed/2023/02/GHSA-3gxg-hfhr-6g9x/GHSA-3gxg-hfhr-6g9x.json b/advisories/unreviewed/2023/02/GHSA-3gxg-hfhr-6g9x/GHSA-3gxg-hfhr-6g9x.json index 4fed331bb32..74c42589ac9 100644 --- a/advisories/unreviewed/2023/02/GHSA-3gxg-hfhr-6g9x/GHSA-3gxg-hfhr-6g9x.json +++ b/advisories/unreviewed/2023/02/GHSA-3gxg-hfhr-6g9x/GHSA-3gxg-hfhr-6g9x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3gxg-hfhr-6g9x", - "modified": "2023-03-02T18:30:30Z", + "modified": "2025-03-17T18:31:33Z", "published": "2023-02-21T18:30:25Z", "aliases": [ "CVE-2023-23009" @@ -23,6 +23,14 @@ "type": "WEB", "url": "https://github.com/libreswan/libreswan/issues/954" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2MFOIQX2LRL43P3GJT33DE7G7COHNXDN" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CSMYJH7MC2FZGCY5NH5AXULO3ISXIHOF" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2MFOIQX2LRL43P3GJT33DE7G7COHNXDN" diff --git a/advisories/unreviewed/2024/01/GHSA-x83f-9m8f-428q/GHSA-x83f-9m8f-428q.json b/advisories/unreviewed/2024/01/GHSA-x83f-9m8f-428q/GHSA-x83f-9m8f-428q.json index ba4c766619c..97201837450 100644 --- a/advisories/unreviewed/2024/01/GHSA-x83f-9m8f-428q/GHSA-x83f-9m8f-428q.json +++ b/advisories/unreviewed/2024/01/GHSA-x83f-9m8f-428q/GHSA-x83f-9m8f-428q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x83f-9m8f-428q", - "modified": "2024-01-29T15:30:24Z", + "modified": "2025-03-17T18:31:36Z", "published": "2024-01-24T00:30:32Z", "aliases": [ "CVE-2024-0808" diff --git a/advisories/unreviewed/2024/02/GHSA-ggv6-7vfj-r2fw/GHSA-ggv6-7vfj-r2fw.json b/advisories/unreviewed/2024/02/GHSA-ggv6-7vfj-r2fw/GHSA-ggv6-7vfj-r2fw.json index 1b972b15c63..1d73553e5e6 100644 --- a/advisories/unreviewed/2024/02/GHSA-ggv6-7vfj-r2fw/GHSA-ggv6-7vfj-r2fw.json +++ b/advisories/unreviewed/2024/02/GHSA-ggv6-7vfj-r2fw/GHSA-ggv6-7vfj-r2fw.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-ggv6-7vfj-r2fw", - "modified": "2024-10-22T18:32:04Z", + "modified": "2025-03-17T18:31:37Z", "published": "2024-02-13T21:30:30Z", "aliases": [ "CVE-2023-31347" ], - "details": "Due to a code bug in\nSecure_TSC, SEV firmware may allow an attacker with high privileges to cause a\nguest to observe an incorrect TSC when Secure TSC is enabled potentially\nresulting in a loss of guest integrity.  \n\n\n\n\n", + "details": "Due to a code bug in\nSecure_TSC, SEV firmware may allow an attacker with high privileges to cause a\nguest to observe an incorrect TSC when Secure TSC is enabled potentially\nresulting in a loss of guest integrity.  ", "severity": [ { "type": "CVSS_V3", @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-682" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-mcfm-j6mc-82gv/GHSA-mcfm-j6mc-82gv.json b/advisories/unreviewed/2024/02/GHSA-mcfm-j6mc-82gv/GHSA-mcfm-j6mc-82gv.json index 99b6ff64998..4342b7166b2 100644 --- a/advisories/unreviewed/2024/02/GHSA-mcfm-j6mc-82gv/GHSA-mcfm-j6mc-82gv.json +++ b/advisories/unreviewed/2024/02/GHSA-mcfm-j6mc-82gv/GHSA-mcfm-j6mc-82gv.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-v9x5-9rj9-j343/GHSA-v9x5-9rj9-j343.json b/advisories/unreviewed/2024/02/GHSA-v9x5-9rj9-j343/GHSA-v9x5-9rj9-j343.json index 4063d2837b0..78879ae6155 100644 --- a/advisories/unreviewed/2024/02/GHSA-v9x5-9rj9-j343/GHSA-v9x5-9rj9-j343.json +++ b/advisories/unreviewed/2024/02/GHSA-v9x5-9rj9-j343/GHSA-v9x5-9rj9-j343.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-395" + "CWE-395", + "CWE-755" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-mwm3-q3pf-fp7v/GHSA-mwm3-q3pf-fp7v.json b/advisories/unreviewed/2024/03/GHSA-mwm3-q3pf-fp7v/GHSA-mwm3-q3pf-fp7v.json index e6d091043a2..bdca481847c 100644 --- a/advisories/unreviewed/2024/03/GHSA-mwm3-q3pf-fp7v/GHSA-mwm3-q3pf-fp7v.json +++ b/advisories/unreviewed/2024/03/GHSA-mwm3-q3pf-fp7v/GHSA-mwm3-q3pf-fp7v.json @@ -49,7 +49,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-2h64-rqxh-72wj/GHSA-2h64-rqxh-72wj.json b/advisories/unreviewed/2024/04/GHSA-2h64-rqxh-72wj/GHSA-2h64-rqxh-72wj.json index 462d106a369..d1267c5b1c1 100644 --- a/advisories/unreviewed/2024/04/GHSA-2h64-rqxh-72wj/GHSA-2h64-rqxh-72wj.json +++ b/advisories/unreviewed/2024/04/GHSA-2h64-rqxh-72wj/GHSA-2h64-rqxh-72wj.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-79", "CWE-94" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/04/GHSA-2vp9-gjfg-fmgw/GHSA-2vp9-gjfg-fmgw.json b/advisories/unreviewed/2024/04/GHSA-2vp9-gjfg-fmgw/GHSA-2vp9-gjfg-fmgw.json index 2258bce3559..599ea09a9cf 100644 --- a/advisories/unreviewed/2024/04/GHSA-2vp9-gjfg-fmgw/GHSA-2vp9-gjfg-fmgw.json +++ b/advisories/unreviewed/2024/04/GHSA-2vp9-gjfg-fmgw/GHSA-2vp9-gjfg-fmgw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2vp9-gjfg-fmgw", - "modified": "2024-04-04T15:30:33Z", + "modified": "2025-03-17T18:31:38Z", "published": "2024-04-03T15:30:43Z", "aliases": [ "CVE-2024-26710" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\npowerpc/kasan: Limit KASAN thread size increase to 32KB\n\nKASAN is seen to increase stack usage, to the point that it was reported\nto lead to stack overflow on some 32-bit machines (see link).\n\nTo avoid overflows the stack size was doubled for KASAN builds in\ncommit 3e8635fb2e07 (\"powerpc/kasan: Force thread size increase with\nKASAN\").\n\nHowever with a 32KB stack size to begin with, the doubling leads to a\n64KB stack, which causes build errors:\n arch/powerpc/kernel/switch.S:249: Error: operand out of range (0x000000000000fe50 is not between 0xffffffffffff8000 and 0x0000000000007fff)\n\nAlthough the asm could be reworked, in practice a 32KB stack seems\nsufficient even for KASAN builds - the additional usage seems to be in\nthe 2-3KB range for a 64-bit KASAN build.\n\nSo only increase the stack for KASAN if the stack size is < 32KB.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-770" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T15:15:53Z" diff --git a/advisories/unreviewed/2024/04/GHSA-2vqj-rxh7-chjw/GHSA-2vqj-rxh7-chjw.json b/advisories/unreviewed/2024/04/GHSA-2vqj-rxh7-chjw/GHSA-2vqj-rxh7-chjw.json index a2ee07a4b5e..ee1bd406be3 100644 --- a/advisories/unreviewed/2024/04/GHSA-2vqj-rxh7-chjw/GHSA-2vqj-rxh7-chjw.json +++ b/advisories/unreviewed/2024/04/GHSA-2vqj-rxh7-chjw/GHSA-2vqj-rxh7-chjw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2vqj-rxh7-chjw", - "modified": "2024-06-27T12:30:44Z", + "modified": "2025-03-17T18:31:38Z", "published": "2024-04-02T09:30:41Z", "aliases": [ "CVE-2024-26679" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ninet: read sk->sk_family once in inet_recv_error()\n\ninet_recv_error() is called without holding the socket lock.\n\nIPv6 socket could mutate to IPv4 with IPV6_ADDRFORM\nsocket option and trigger a KCSAN warning.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -56,8 +61,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-667" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-02T07:15:44Z" diff --git a/advisories/unreviewed/2024/04/GHSA-37h8-63p8-qhhg/GHSA-37h8-63p8-qhhg.json b/advisories/unreviewed/2024/04/GHSA-37h8-63p8-qhhg/GHSA-37h8-63p8-qhhg.json index aa24fa0d204..64075be1a3e 100644 --- a/advisories/unreviewed/2024/04/GHSA-37h8-63p8-qhhg/GHSA-37h8-63p8-qhhg.json +++ b/advisories/unreviewed/2024/04/GHSA-37h8-63p8-qhhg/GHSA-37h8-63p8-qhhg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-37h8-63p8-qhhg", - "modified": "2024-04-03T18:30:42Z", + "modified": "2025-03-17T18:31:40Z", "published": "2024-04-03T18:30:42Z", "aliases": [ "CVE-2024-26740" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: act_mirred: use the backlog for mirred ingress\n\nThe test Davide added in commit ca22da2fbd69 (\"act_mirred: use the backlog\nfor nested calls to mirred ingress\") hangs our testing VMs every 10 or so\nruns, with the familiar tcp_v4_rcv -> tcp_v4_rcv deadlock reported by\nlockdep.\n\nThe problem as previously described by Davide (see Link) is that\nif we reverse flow of traffic with the redirect (egress -> ingress)\nwe may reach the same socket which generated the packet. And we may\nstill be holding its socket lock. The common solution to such deadlocks\nis to put the packet in the Rx backlog, rather than run the Rx path\ninline. Do that for all egress -> ingress reversals, not just once\nwe started to nest mirred calls.\n\nIn the past there was a concern that the backlog indirection will\nlead to loss of error reporting / less accurate stats. But the current\nworkaround does not seem to address the issue.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-667" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T17:15:51Z" diff --git a/advisories/unreviewed/2024/04/GHSA-3w39-v724-v74w/GHSA-3w39-v724-v74w.json b/advisories/unreviewed/2024/04/GHSA-3w39-v724-v74w/GHSA-3w39-v724-v74w.json index 2bf3a942daa..7c99990a285 100644 --- a/advisories/unreviewed/2024/04/GHSA-3w39-v724-v74w/GHSA-3w39-v724-v74w.json +++ b/advisories/unreviewed/2024/04/GHSA-3w39-v724-v74w/GHSA-3w39-v724-v74w.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3w39-v724-v74w", - "modified": "2024-04-03T15:30:42Z", + "modified": "2025-03-17T18:31:38Z", "published": "2024-04-03T15:30:42Z", "aliases": [ "CVE-2024-26693" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: iwlwifi: mvm: fix a crash when we run out of stations\n\nA DoS tool that injects loads of authentication frames made our AP\ncrash. The iwl_mvm_is_dup() function couldn't find the per-queue\ndup_data which was not allocated.\n\nThe root cause for that is that we ran out of stations in the firmware\nand we didn't really add the station to the firmware, yet we didn't\nreturn an error to mac80211.\nMac80211 was thinking that we have the station and because of that,\nsta_info::uploaded was set to 1. This allowed\nieee80211_find_sta_by_ifaddr() to return a valid station object, but\nthat ieee80211_sta didn't have any iwl_mvm_sta object initialized and\nthat caused the crash mentioned earlier when we got Rx on that station.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -29,7 +34,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T15:15:52Z" diff --git a/advisories/unreviewed/2024/04/GHSA-4fj7-85cf-9m8p/GHSA-4fj7-85cf-9m8p.json b/advisories/unreviewed/2024/04/GHSA-4fj7-85cf-9m8p/GHSA-4fj7-85cf-9m8p.json index 9d658c3d41d..df5b2a7c32b 100644 --- a/advisories/unreviewed/2024/04/GHSA-4fj7-85cf-9m8p/GHSA-4fj7-85cf-9m8p.json +++ b/advisories/unreviewed/2024/04/GHSA-4fj7-85cf-9m8p/GHSA-4fj7-85cf-9m8p.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4fj7-85cf-9m8p", - "modified": "2024-04-03T15:30:43Z", + "modified": "2025-03-17T18:31:38Z", "published": "2024-04-03T15:30:43Z", "aliases": [ "CVE-2024-26706" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nparisc: Fix random data corruption from exception handler\n\nThe current exception handler implementation, which assists when accessing\nuser space memory, may exhibit random data corruption if the compiler decides\nto use a different register than the specified register %r29 (defined in\nASM_EXCEPTIONTABLE_REG) for the error code. If the compiler choose another\nregister, the fault handler will nevertheless store -EFAULT into %r29 and thus\ntrash whatever this register is used for.\nLooking at the assembly I found that this happens sometimes in emulate_ldd().\n\nTo solve the issue, the easiest solution would be if it somehow is\npossible to tell the fault handler which register is used to hold the error\ncode. Using %0 or %1 in the inline assembly is not posssible as it will show\nup as e.g. %r29 (with the \"%r\" prefix), which the GNU assembler can not\nconvert to an integer.\n\nThis patch takes another, better and more flexible approach:\nWe extend the __ex_table (which is out of the execution path) by one 32-word.\nIn this word we tell the compiler to insert the assembler instruction\n\"or %r0,%r0,%reg\", where %reg references the register which the compiler\nchoosed for the error return code.\nIn case of an access failure, the fault handler finds the __ex_table entry and\ncan examine the opcode. The used register is encoded in the lowest 5 bits, and\nthe fault handler can then store -EFAULT into this register.\n\nSince we extend the __ex_table to 3 words we can't use the BUILDTIME_TABLE_SORT\nconfig option any longer.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T15:15:53Z" diff --git a/advisories/unreviewed/2024/04/GHSA-5g26-fc68-x9f2/GHSA-5g26-fc68-x9f2.json b/advisories/unreviewed/2024/04/GHSA-5g26-fc68-x9f2/GHSA-5g26-fc68-x9f2.json index 91690b71e33..9cc04189bb3 100644 --- a/advisories/unreviewed/2024/04/GHSA-5g26-fc68-x9f2/GHSA-5g26-fc68-x9f2.json +++ b/advisories/unreviewed/2024/04/GHSA-5g26-fc68-x9f2/GHSA-5g26-fc68-x9f2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5g26-fc68-x9f2", - "modified": "2024-04-28T12:30:27Z", + "modified": "2025-03-17T18:31:38Z", "published": "2024-04-02T09:30:41Z", "aliases": [ "CVE-2024-26678" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/efistub: Use 1:1 file:memory mapping for PE/COFF .compat section\n\nThe .compat section is a dummy PE section that contains the address of\nthe 32-bit entrypoint of the 64-bit kernel image if it is bootable from\n32-bit firmware (i.e., CONFIG_EFI_MIXED=y)\n\nThis section is only 8 bytes in size and is only referenced from the\nloader, and so it is placed at the end of the memory view of the image,\nto avoid the need for padding it to 4k, which is required for sections\nappearing in the middle of the image.\n\nUnfortunately, this violates the PE/COFF spec, and even if most EFI\nloaders will work correctly (including the Tianocore reference\nimplementation), PE loaders do exist that reject such images, on the\nbasis that both the file and memory views of the file contents should be\ndescribed by the section headers in a monotonically increasing manner\nwithout leaving any gaps.\n\nSo reorganize the sections to avoid this issue. This results in a slight\npadding overhead (< 4k) which can be avoided if desired by disabling\nCONFIG_EFI_MIXED (which is only needed in rare cases these days)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-02T07:15:44Z" diff --git a/advisories/unreviewed/2024/04/GHSA-5qvv-jjxx-82r8/GHSA-5qvv-jjxx-82r8.json b/advisories/unreviewed/2024/04/GHSA-5qvv-jjxx-82r8/GHSA-5qvv-jjxx-82r8.json index b50b783f22b..4982e40169c 100644 --- a/advisories/unreviewed/2024/04/GHSA-5qvv-jjxx-82r8/GHSA-5qvv-jjxx-82r8.json +++ b/advisories/unreviewed/2024/04/GHSA-5qvv-jjxx-82r8/GHSA-5qvv-jjxx-82r8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5qvv-jjxx-82r8", - "modified": "2024-10-22T18:32:04Z", + "modified": "2025-03-17T18:31:39Z", "published": "2024-04-03T15:30:43Z", "aliases": [ "CVE-2024-26718" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndm-crypt, dm-verity: disable tasklets\n\nTasklets have an inherent problem with memory corruption. The function\ntasklet_action_common calls tasklet_trylock, then it calls the tasklet\ncallback and then it calls tasklet_unlock. If the tasklet callback frees\nthe structure that contains the tasklet or if it calls some code that may\nfree it, tasklet_unlock will write into free memory.\n\nThe commits 8e14f610159d and d9a02e016aaf try to fix it for dm-crypt, but\nit is not a sufficient fix and the data corruption can still happen [1].\nThere is no fix for dm-verity and dm-verity will write into free memory\nwith every tasklet-processed bio.\n\nThere will be atomic workqueues implemented in the kernel 6.9 [2]. They\nwill have better interface and they will not suffer from the memory\ncorruption problem.\n\nBut we need something that stops the memory corruption now and that can be\nbackported to the stable kernels. So, I'm proposing this commit that\ndisables tasklets in both dm-crypt and dm-verity. This commit doesn't\nremove the tasklet support, because the tasklet code will be reused when\natomic workqueues will be implemented.\n\n[1] https://lore.kernel.org/all/d390d7ee-f142-44d3-822a-87949e14608b@suse.de/T/\n[2] https://lore.kernel.org/lkml/20240130091300.2968534-1-tj@kernel.org/", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T15:15:53Z" diff --git a/advisories/unreviewed/2024/04/GHSA-68mg-2p5r-x33h/GHSA-68mg-2p5r-x33h.json b/advisories/unreviewed/2024/04/GHSA-68mg-2p5r-x33h/GHSA-68mg-2p5r-x33h.json index 06543814d7b..9635a38949e 100644 --- a/advisories/unreviewed/2024/04/GHSA-68mg-2p5r-x33h/GHSA-68mg-2p5r-x33h.json +++ b/advisories/unreviewed/2024/04/GHSA-68mg-2p5r-x33h/GHSA-68mg-2p5r-x33h.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-68mg-2p5r-x33h", - "modified": "2024-06-26T00:31:36Z", + "modified": "2025-03-17T18:31:41Z", "published": "2024-04-03T18:30:42Z", "aliases": [ "CVE-2024-26743" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/qedr: Fix qedr_create_user_qp error flow\n\nAvoid the following warning by making sure to free the allocated\nresources in case that qedr_init_user_queue() fail.\n\n-----------[ cut here ]-----------\nWARNING: CPU: 0 PID: 143192 at drivers/infiniband/core/rdma_core.c:874 uverbs_destroy_ufile_hw+0xcf/0xf0 [ib_uverbs]\nModules linked in: tls target_core_user uio target_core_pscsi target_core_file target_core_iblock ib_srpt ib_srp scsi_transport_srp nfsd nfs_acl rpcsec_gss_krb5 auth_rpcgss nfsv4 dns_resolver nfs lockd grace fscache netfs 8021q garp mrp stp llc ext4 mbcache jbd2 opa_vnic ib_umad ib_ipoib sunrpc rdma_ucm ib_isert iscsi_target_mod target_core_mod ib_iser libiscsi scsi_transport_iscsi rdma_cm iw_cm ib_cm hfi1 intel_rapl_msr intel_rapl_common mgag200 qedr sb_edac drm_shmem_helper rdmavt x86_pkg_temp_thermal drm_kms_helper intel_powerclamp ib_uverbs coretemp i2c_algo_bit kvm_intel dell_wmi_descriptor ipmi_ssif sparse_keymap kvm ib_core rfkill syscopyarea sysfillrect video sysimgblt irqbypass ipmi_si ipmi_devintf fb_sys_fops rapl iTCO_wdt mxm_wmi iTCO_vendor_support intel_cstate pcspkr dcdbas intel_uncore ipmi_msghandler lpc_ich acpi_power_meter mei_me mei fuse drm xfs libcrc32c qede sd_mod ahci libahci t10_pi sg crct10dif_pclmul crc32_pclmul crc32c_intel qed libata tg3\nghash_clmulni_intel megaraid_sas crc8 wmi [last unloaded: ib_srpt]\nCPU: 0 PID: 143192 Comm: fi_rdm_tagged_p Kdump: loaded Not tainted 5.14.0-408.el9.x86_64 #1\nHardware name: Dell Inc. PowerEdge R430/03XKDV, BIOS 2.14.0 01/25/2022\nRIP: 0010:uverbs_destroy_ufile_hw+0xcf/0xf0 [ib_uverbs]\nCode: 5d 41 5c 41 5d 41 5e e9 0f 26 1b dd 48 89 df e8 67 6a ff ff 49 8b 86 10 01 00 00 48 85 c0 74 9c 4c 89 e7 e8 83 c0 cb dd eb 92 <0f> 0b eb be 0f 0b be 04 00 00 00 48 89 df e8 8e f5 ff ff e9 6d ff\nRSP: 0018:ffffb7c6cadfbc60 EFLAGS: 00010286\nRAX: ffff8f0889ee3f60 RBX: ffff8f088c1a5200 RCX: 00000000802a0016\nRDX: 00000000802a0017 RSI: 0000000000000001 RDI: ffff8f0880042600\nRBP: 0000000000000001 R08: 0000000000000001 R09: 0000000000000000\nR10: ffff8f11fffd5000 R11: 0000000000039000 R12: ffff8f0d5b36cd80\nR13: ffff8f088c1a5250 R14: ffff8f1206d91000 R15: 0000000000000000\nFS: 0000000000000000(0000) GS:ffff8f11d7c00000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000147069200e20 CR3: 00000001c7210002 CR4: 00000000001706f0\nCall Trace:\n\n? show_trace_log_lvl+0x1c4/0x2df\n? show_trace_log_lvl+0x1c4/0x2df\n? ib_uverbs_close+0x1f/0xb0 [ib_uverbs]\n? uverbs_destroy_ufile_hw+0xcf/0xf0 [ib_uverbs]\n? __warn+0x81/0x110\n? uverbs_destroy_ufile_hw+0xcf/0xf0 [ib_uverbs]\n? report_bug+0x10a/0x140\n? handle_bug+0x3c/0x70\n? exc_invalid_op+0x14/0x70\n? asm_exc_invalid_op+0x16/0x20\n? uverbs_destroy_ufile_hw+0xcf/0xf0 [ib_uverbs]\nib_uverbs_close+0x1f/0xb0 [ib_uverbs]\n__fput+0x94/0x250\ntask_work_run+0x5c/0x90\ndo_exit+0x270/0x4a0\ndo_group_exit+0x2d/0x90\nget_signal+0x87c/0x8c0\narch_do_signal_or_restart+0x25/0x100\n? ib_uverbs_ioctl+0xc2/0x110 [ib_uverbs]\nexit_to_user_mode_loop+0x9c/0x130\nexit_to_user_mode_prepare+0xb6/0x100\nsyscall_exit_to_user_mode+0x12/0x40\ndo_syscall_64+0x69/0x90\n? syscall_exit_work+0x103/0x130\n? syscall_exit_to_user_mode+0x22/0x40\n? do_syscall_64+0x69/0x90\n? syscall_exit_work+0x103/0x130\n? syscall_exit_to_user_mode+0x22/0x40\n? do_syscall_64+0x69/0x90\n? do_syscall_64+0x69/0x90\n? common_interrupt+0x43/0xa0\nentry_SYSCALL_64_after_hwframe+0x72/0xdc\nRIP: 0033:0x1470abe3ec6b\nCode: Unable to access opcode bytes at RIP 0x1470abe3ec41.\nRSP: 002b:00007fff13ce9108 EFLAGS: 00000246 ORIG_RAX: 0000000000000010\nRAX: fffffffffffffffc RBX: 00007fff13ce9218 RCX: 00001470abe3ec6b\nRDX: 00007fff13ce9200 RSI: 00000000c0181b01 RDI: 0000000000000004\nRBP: 00007fff13ce91e0 R08: 0000558d9655da10 R09: 0000558d9655dd00\nR10: 00007fff13ce95c0 R11: 0000000000000246 R12: 00007fff13ce9358\nR13: 0000000000000013 R14: 0000558d9655db50 R15: 00007fff13ce9470\n\n--[ end trace 888a9b92e04c5c97 ]--", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-770" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T17:15:51Z" diff --git a/advisories/unreviewed/2024/04/GHSA-782j-786c-25hh/GHSA-782j-786c-25hh.json b/advisories/unreviewed/2024/04/GHSA-782j-786c-25hh/GHSA-782j-786c-25hh.json index d2b927ad70e..f09cb4deb4f 100644 --- a/advisories/unreviewed/2024/04/GHSA-782j-786c-25hh/GHSA-782j-786c-25hh.json +++ b/advisories/unreviewed/2024/04/GHSA-782j-786c-25hh/GHSA-782j-786c-25hh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-782j-786c-25hh", - "modified": "2024-06-27T15:30:38Z", + "modified": "2025-03-17T18:31:38Z", "published": "2024-04-02T09:30:41Z", "aliases": [ "CVE-2024-26675" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nppp_async: limit MRU to 64K\n\nsyzbot triggered a warning [1] in __alloc_pages():\n\nWARN_ON_ONCE_GFP(order > MAX_PAGE_ORDER, gfp)\n\nWillem fixed a similar issue in commit c0a2a1b0d631 (\"ppp: limit MRU to 64K\")\n\nAdopt the same sanity check for ppp_async_ioctl(PPPIOCSMRU)\n\n[1]:\n\n WARNING: CPU: 1 PID: 11 at mm/page_alloc.c:4543 __alloc_pages+0x308/0x698 mm/page_alloc.c:4543\nModules linked in:\nCPU: 1 PID: 11 Comm: kworker/u4:0 Not tainted 6.8.0-rc2-syzkaller-g41bccc98fb79 #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 11/17/2023\nWorkqueue: events_unbound flush_to_ldisc\npstate: 204000c5 (nzCv daIF +PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n pc : __alloc_pages+0x308/0x698 mm/page_alloc.c:4543\n lr : __alloc_pages+0xc8/0x698 mm/page_alloc.c:4537\nsp : ffff800093967580\nx29: ffff800093967660 x28: ffff8000939675a0 x27: dfff800000000000\nx26: ffff70001272ceb4 x25: 0000000000000000 x24: ffff8000939675c0\nx23: 0000000000000000 x22: 0000000000060820 x21: 1ffff0001272ceb8\nx20: ffff8000939675e0 x19: 0000000000000010 x18: ffff800093967120\nx17: ffff800083bded5c x16: ffff80008ac97500 x15: 0000000000000005\nx14: 1ffff0001272cebc x13: 0000000000000000 x12: 0000000000000000\nx11: ffff70001272cec1 x10: 1ffff0001272cec0 x9 : 0000000000000001\nx8 : ffff800091c91000 x7 : 0000000000000000 x6 : 000000000000003f\nx5 : 00000000ffffffff x4 : 0000000000000000 x3 : 0000000000000020\nx2 : 0000000000000008 x1 : 0000000000000000 x0 : ffff8000939675e0\nCall trace:\n __alloc_pages+0x308/0x698 mm/page_alloc.c:4543\n __alloc_pages_node include/linux/gfp.h:238 [inline]\n alloc_pages_node include/linux/gfp.h:261 [inline]\n __kmalloc_large_node+0xbc/0x1fc mm/slub.c:3926\n __do_kmalloc_node mm/slub.c:3969 [inline]\n __kmalloc_node_track_caller+0x418/0x620 mm/slub.c:4001\n kmalloc_reserve+0x17c/0x23c net/core/skbuff.c:590\n __alloc_skb+0x1c8/0x3d8 net/core/skbuff.c:651\n __netdev_alloc_skb+0xb8/0x3e8 net/core/skbuff.c:715\n netdev_alloc_skb include/linux/skbuff.h:3235 [inline]\n dev_alloc_skb include/linux/skbuff.h:3248 [inline]\n ppp_async_input drivers/net/ppp/ppp_async.c:863 [inline]\n ppp_asynctty_receive+0x588/0x186c drivers/net/ppp/ppp_async.c:341\n tty_ldisc_receive_buf+0x12c/0x15c drivers/tty/tty_buffer.c:390\n tty_port_default_receive_buf+0x74/0xac drivers/tty/tty_port.c:37\n receive_buf drivers/tty/tty_buffer.c:444 [inline]\n flush_to_ldisc+0x284/0x6e4 drivers/tty/tty_buffer.c:494\n process_one_work+0x694/0x1204 kernel/workqueue.c:2633\n process_scheduled_works kernel/workqueue.c:2706 [inline]\n worker_thread+0x938/0xef4 kernel/workqueue.c:2787\n kthread+0x288/0x310 kernel/kthread.c:388\n ret_from_fork+0x10/0x20 arch/arm64/kernel/entry.S:860", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -56,8 +61,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-770" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-02T07:15:44Z" diff --git a/advisories/unreviewed/2024/04/GHSA-798v-p58f-mw7j/GHSA-798v-p58f-mw7j.json b/advisories/unreviewed/2024/04/GHSA-798v-p58f-mw7j/GHSA-798v-p58f-mw7j.json index fbb4479bd79..99ef760b14d 100644 --- a/advisories/unreviewed/2024/04/GHSA-798v-p58f-mw7j/GHSA-798v-p58f-mw7j.json +++ b/advisories/unreviewed/2024/04/GHSA-798v-p58f-mw7j/GHSA-798v-p58f-mw7j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-798v-p58f-mw7j", - "modified": "2024-04-03T15:30:43Z", + "modified": "2025-03-17T18:31:39Z", "published": "2024-04-03T15:30:43Z", "aliases": [ "CVE-2024-26726" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: don't drop extent_map for free space inode on write error\n\nWhile running the CI for an unrelated change I hit the following panic\nwith generic/648 on btrfs_holes_spacecache.\n\nassertion failed: block_start != EXTENT_MAP_HOLE, in fs/btrfs/extent_io.c:1385\n------------[ cut here ]------------\nkernel BUG at fs/btrfs/extent_io.c:1385!\ninvalid opcode: 0000 [#1] PREEMPT SMP NOPTI\nCPU: 1 PID: 2695096 Comm: fsstress Kdump: loaded Tainted: G W 6.8.0-rc2+ #1\nRIP: 0010:__extent_writepage_io.constprop.0+0x4c1/0x5c0\nCall Trace:\n \n extent_write_cache_pages+0x2ac/0x8f0\n extent_writepages+0x87/0x110\n do_writepages+0xd5/0x1f0\n filemap_fdatawrite_wbc+0x63/0x90\n __filemap_fdatawrite_range+0x5c/0x80\n btrfs_fdatawrite_range+0x1f/0x50\n btrfs_write_out_cache+0x507/0x560\n btrfs_write_dirty_block_groups+0x32a/0x420\n commit_cowonly_roots+0x21b/0x290\n btrfs_commit_transaction+0x813/0x1360\n btrfs_sync_file+0x51a/0x640\n __x64_sys_fdatasync+0x52/0x90\n do_syscall_64+0x9c/0x190\n entry_SYSCALL_64_after_hwframe+0x6e/0x76\n\nThis happens because we fail to write out the free space cache in one\ninstance, come back around and attempt to write it again. However on\nthe second pass through we go to call btrfs_get_extent() on the inode to\nget the extent mapping. Because this is a new block group, and with the\nfree space inode we always search the commit root to avoid deadlocking\nwith the tree, we find nothing and return a EXTENT_MAP_HOLE for the\nrequested range.\n\nThis happens because the first time we try to write the space cache out\nwe hit an error, and on an error we drop the extent mapping. This is\nnormal for normal files, but the free space cache inode is special. We\nalways expect the extent map to be correct. Thus the second time\nthrough we end up with a bogus extent map.\n\nSince we're deprecating this feature, the most straightforward way to\nfix this is to simply skip dropping the extent map range for this failed\nrange.\n\nI shortened the test by using error injection to stress the area to make\nit easier to reproduce. With this patch in place we no longer panic\nwith my error injection test.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-617" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T15:15:54Z" diff --git a/advisories/unreviewed/2024/04/GHSA-7g56-3wmh-7x3p/GHSA-7g56-3wmh-7x3p.json b/advisories/unreviewed/2024/04/GHSA-7g56-3wmh-7x3p/GHSA-7g56-3wmh-7x3p.json index 82db3cfa9ea..3949f4ddc67 100644 --- a/advisories/unreviewed/2024/04/GHSA-7g56-3wmh-7x3p/GHSA-7g56-3wmh-7x3p.json +++ b/advisories/unreviewed/2024/04/GHSA-7g56-3wmh-7x3p/GHSA-7g56-3wmh-7x3p.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7g56-3wmh-7x3p", - "modified": "2024-06-26T00:31:36Z", + "modified": "2025-03-17T18:31:38Z", "published": "2024-04-03T15:30:42Z", "aliases": [ "CVE-2024-26698" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nhv_netvsc: Fix race condition between netvsc_probe and netvsc_remove\n\nIn commit ac5047671758 (\"hv_netvsc: Disable NAPI before closing the\nVMBus channel\"), napi_disable was getting called for all channels,\nincluding all subchannels without confirming if they are enabled or not.\n\nThis caused hv_netvsc getting hung at napi_disable, when netvsc_probe()\nhas finished running but nvdev->subchan_work has not started yet.\nnetvsc_subchan_work() -> rndis_set_subchannel() has not created the\nsub-channels and because of that netvsc_sc_open() is not running.\nnetvsc_remove() calls cancel_work_sync(&nvdev->subchan_work), for which\nnetvsc_subchan_work did not run.\n\nnetif_napi_add() sets the bit NAPI_STATE_SCHED because it ensures NAPI\ncannot be scheduled. Then netvsc_sc_open() -> napi_enable will clear the\nNAPIF_STATE_SCHED bit, so it can be scheduled. napi_disable() does the\nopposite.\n\nNow during netvsc_device_remove(), when napi_disable is called for those\nsubchannels, napi_disable gets stuck on infinite msleep.\n\nThis fix addresses this problem by ensuring that napi_disable() is not\ngetting called for non-enabled NAPI struct.\nBut netif_napi_del() is still necessary for these non-enabled NAPI struct\nfor cleanup purpose.\n\nCall trace:\n[ 654.559417] task:modprobe state:D stack: 0 pid: 2321 ppid: 1091 flags:0x00004002\n[ 654.568030] Call Trace:\n[ 654.571221] \n[ 654.573790] __schedule+0x2d6/0x960\n[ 654.577733] schedule+0x69/0xf0\n[ 654.581214] schedule_timeout+0x87/0x140\n[ 654.585463] ? __bpf_trace_tick_stop+0x20/0x20\n[ 654.590291] msleep+0x2d/0x40\n[ 654.593625] napi_disable+0x2b/0x80\n[ 654.597437] netvsc_device_remove+0x8a/0x1f0 [hv_netvsc]\n[ 654.603935] rndis_filter_device_remove+0x194/0x1c0 [hv_netvsc]\n[ 654.611101] ? do_wait_intr+0xb0/0xb0\n[ 654.615753] netvsc_remove+0x7c/0x120 [hv_netvsc]\n[ 654.621675] vmbus_remove+0x27/0x40 [hv_vmbus]", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-362" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T15:15:52Z" diff --git a/advisories/unreviewed/2024/04/GHSA-7xq6-jm62-ww8g/GHSA-7xq6-jm62-ww8g.json b/advisories/unreviewed/2024/04/GHSA-7xq6-jm62-ww8g/GHSA-7xq6-jm62-ww8g.json index 84d23b36dbe..778a81582b6 100644 --- a/advisories/unreviewed/2024/04/GHSA-7xq6-jm62-ww8g/GHSA-7xq6-jm62-ww8g.json +++ b/advisories/unreviewed/2024/04/GHSA-7xq6-jm62-ww8g/GHSA-7xq6-jm62-ww8g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7xq6-jm62-ww8g", - "modified": "2024-06-26T00:31:36Z", + "modified": "2025-03-17T18:31:38Z", "published": "2024-04-03T15:30:42Z", "aliases": [ "CVE-2024-26687" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nxen/events: close evtchn after mapping cleanup\n\nshutdown_pirq and startup_pirq are not taking the\nirq_mapping_update_lock because they can't due to lock inversion. Both\nare called with the irq_desc->lock being taking. The lock order,\nhowever, is first irq_mapping_update_lock and then irq_desc->lock.\n\nThis opens multiple races:\n- shutdown_pirq can be interrupted by a function that allocates an event\n channel:\n\n CPU0 CPU1\n shutdown_pirq {\n xen_evtchn_close(e)\n __startup_pirq {\n EVTCHNOP_bind_pirq\n -> returns just freed evtchn e\n set_evtchn_to_irq(e, irq)\n }\n xen_irq_info_cleanup() {\n set_evtchn_to_irq(e, -1)\n }\n }\n\n Assume here event channel e refers here to the same event channel\n number.\n After this race the evtchn_to_irq mapping for e is invalid (-1).\n\n- __startup_pirq races with __unbind_from_irq in a similar way. Because\n __startup_pirq doesn't take irq_mapping_update_lock it can grab the\n evtchn that __unbind_from_irq is currently freeing and cleaning up. In\n this case even though the event channel is allocated, its mapping can\n be unset in evtchn_to_irq.\n\nThe fix is to first cleanup the mappings and then close the event\nchannel. In this way, when an event channel gets allocated it's\npotential previous evtchn_to_irq mappings are guaranteed to be unset already.\nThis is also the reverse order of the allocation where first the event\nchannel is allocated and then the mappings are setup.\n\nOn a 5.10 kernel prior to commit 3fcdaf3d7634 (\"xen/events: modify internal\n[un]bind interfaces\"), we hit a BUG like the following during probing of NVMe\ndevices. The issue is that during nvme_setup_io_queues, pci_free_irq\nis called for every device which results in a call to shutdown_pirq.\nWith many nvme devices it's therefore likely to hit this race during\nboot because there will be multiple calls to shutdown_pirq and\nstartup_pirq are running potentially in parallel.\n\n ------------[ cut here ]------------\n blkfront: xvda: barrier or flush: disabled; persistent grants: enabled; indirect descriptors: enabled; bounce buffer: enabled\n kernel BUG at drivers/xen/events/events_base.c:499!\n invalid opcode: 0000 [#1] SMP PTI\n CPU: 44 PID: 375 Comm: kworker/u257:23 Not tainted 5.10.201-191.748.amzn2.x86_64 #1\n Hardware name: Xen HVM domU, BIOS 4.11.amazon 08/24/2006\n Workqueue: nvme-reset-wq nvme_reset_work\n RIP: 0010:bind_evtchn_to_cpu+0xdf/0xf0\n Code: 5d 41 5e c3 cc cc cc cc 44 89 f7 e8 2b 55 ad ff 49 89 c5 48 85 c0 0f 84 64 ff ff ff 4c 8b 68 30 41 83 fe ff 0f 85 60 ff ff ff <0f> 0b 66 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 0f 1f 44 00 00\n RSP: 0000:ffffc9000d533b08 EFLAGS: 00010046\n RAX: 0000000000000000 RBX: 0000000000000000 RCX: 0000000000000006\n RDX: 0000000000000028 RSI: 00000000ffffffff RDI: 00000000ffffffff\n RBP: ffff888107419680 R08: 0000000000000000 R09: ffffffff82d72b00\n R10: 0000000000000000 R11: 0000000000000000 R12: 00000000000001ed\n R13: 0000000000000000 R14: 00000000ffffffff R15: 0000000000000002\n FS: 0000000000000000(0000) GS:ffff88bc8b500000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 0000000000000000 CR3: 0000000002610001 CR4: 00000000001706e0\n DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n Call Trace:\n ? show_trace_log_lvl+0x1c1/0x2d9\n ? show_trace_log_lvl+0x1c1/0x2d9\n ? set_affinity_irq+0xdc/0x1c0\n ? __die_body.cold+0x8/0xd\n ? die+0x2b/0x50\n ? do_trap+0x90/0x110\n ? bind_evtchn_to_cpu+0xdf/0xf0\n ? do_error_trap+0x65/0x80\n ? bind_evtchn_to_cpu+0xdf/0xf0\n ? exc_invalid_op+0x4e/0x70\n ? bind_evtchn_to_cpu+0xdf/0xf0\n ? asm_exc_invalid_op+0x12/0x20\n ? bind_evtchn_to_cpu+0xdf/0x\n---truncated---", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-459" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T15:15:52Z" diff --git a/advisories/unreviewed/2024/04/GHSA-82mq-c3x3-cpp9/GHSA-82mq-c3x3-cpp9.json b/advisories/unreviewed/2024/04/GHSA-82mq-c3x3-cpp9/GHSA-82mq-c3x3-cpp9.json index e1879ef2698..cd6fc859187 100644 --- a/advisories/unreviewed/2024/04/GHSA-82mq-c3x3-cpp9/GHSA-82mq-c3x3-cpp9.json +++ b/advisories/unreviewed/2024/04/GHSA-82mq-c3x3-cpp9/GHSA-82mq-c3x3-cpp9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-82mq-c3x3-cpp9", - "modified": "2024-04-03T15:30:42Z", + "modified": "2025-03-17T18:31:38Z", "published": "2024-04-03T15:30:42Z", "aliases": [ "CVE-2023-52639" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: s390: vsie: fix race during shadow creation\n\nRight now it is possible to see gmap->private being zero in\nkvm_s390_vsie_gmap_notifier resulting in a crash. This is due to the\nfact that we add gmap->private == kvm after creation:\n\nstatic int acquire_gmap_shadow(struct kvm_vcpu *vcpu,\n struct vsie_page *vsie_page)\n{\n[...]\n gmap = gmap_shadow(vcpu->arch.gmap, asce, edat);\n if (IS_ERR(gmap))\n return PTR_ERR(gmap);\n gmap->private = vcpu->kvm;\n\nLet children inherit the private field of the parent.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-362" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T15:15:51Z" diff --git a/advisories/unreviewed/2024/04/GHSA-85g7-5359-r834/GHSA-85g7-5359-r834.json b/advisories/unreviewed/2024/04/GHSA-85g7-5359-r834/GHSA-85g7-5359-r834.json index ff3837e31b8..c0d1620ef2c 100644 --- a/advisories/unreviewed/2024/04/GHSA-85g7-5359-r834/GHSA-85g7-5359-r834.json +++ b/advisories/unreviewed/2024/04/GHSA-85g7-5359-r834/GHSA-85g7-5359-r834.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-85g7-5359-r834", - "modified": "2024-04-03T18:30:42Z", + "modified": "2025-03-17T18:31:41Z", "published": "2024-04-03T18:30:42Z", "aliases": [ "CVE-2024-26756" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmd: Don't register sync_thread for reshape directly\n\nCurrently, if reshape is interrupted, then reassemble the array will\nregister sync_thread directly from pers->run(), in this case\n'MD_RECOVERY_RUNNING' is set directly, however, there is no guarantee\nthat md_do_sync() will be executed, hence stop_sync_thread() will hang\nbecause 'MD_RECOVERY_RUNNING' can't be cleared.\n\nLast patch make sure that md_do_sync() will set MD_RECOVERY_DONE,\nhowever, following hang can still be triggered by dm-raid test\nshell/lvconvert-raid-reshape.sh occasionally:\n\n[root@fedora ~]# cat /proc/1982/stack\n[<0>] stop_sync_thread+0x1ab/0x270 [md_mod]\n[<0>] md_frozen_sync_thread+0x5c/0xa0 [md_mod]\n[<0>] raid_presuspend+0x1e/0x70 [dm_raid]\n[<0>] dm_table_presuspend_targets+0x40/0xb0 [dm_mod]\n[<0>] __dm_destroy+0x2a5/0x310 [dm_mod]\n[<0>] dm_destroy+0x16/0x30 [dm_mod]\n[<0>] dev_remove+0x165/0x290 [dm_mod]\n[<0>] ctl_ioctl+0x4bb/0x7b0 [dm_mod]\n[<0>] dm_ctl_ioctl+0x11/0x20 [dm_mod]\n[<0>] vfs_ioctl+0x21/0x60\n[<0>] __x64_sys_ioctl+0xb9/0xe0\n[<0>] do_syscall_64+0xc6/0x230\n[<0>] entry_SYSCALL_64_after_hwframe+0x6c/0x74\n\nMeanwhile mddev->recovery is:\nMD_RECOVERY_RUNNING |\nMD_RECOVERY_INTR |\nMD_RECOVERY_RESHAPE |\nMD_RECOVERY_FROZEN\n\nFix this problem by remove the code to register sync_thread directly\nfrom raid10 and raid5. And let md_check_recovery() to register\nsync_thread.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-459" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T17:15:52Z" diff --git a/advisories/unreviewed/2024/04/GHSA-968x-w27q-c8fx/GHSA-968x-w27q-c8fx.json b/advisories/unreviewed/2024/04/GHSA-968x-w27q-c8fx/GHSA-968x-w27q-c8fx.json index a38d37180c1..fb58f6fb54c 100644 --- a/advisories/unreviewed/2024/04/GHSA-968x-w27q-c8fx/GHSA-968x-w27q-c8fx.json +++ b/advisories/unreviewed/2024/04/GHSA-968x-w27q-c8fx/GHSA-968x-w27q-c8fx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-968x-w27q-c8fx", - "modified": "2024-04-02T09:30:41Z", + "modified": "2025-03-17T18:31:38Z", "published": "2024-04-02T09:30:41Z", "aliases": [ "CVE-2024-26681" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetdevsim: avoid potential loop in nsim_dev_trap_report_work()\n\nMany syzbot reports include the following trace [1]\n\nIf nsim_dev_trap_report_work() can not grab the mutex,\nit should rearm itself at least one jiffie later.\n\n[1]\nSending NMI from CPU 1 to CPUs 0:\nNMI backtrace for cpu 0\nCPU: 0 PID: 32383 Comm: kworker/0:2 Not tainted 6.8.0-rc2-syzkaller-00031-g861c0981648f #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 11/17/2023\nWorkqueue: events nsim_dev_trap_report_work\n RIP: 0010:bytes_is_nonzero mm/kasan/generic.c:89 [inline]\n RIP: 0010:memory_is_nonzero mm/kasan/generic.c:104 [inline]\n RIP: 0010:memory_is_poisoned_n mm/kasan/generic.c:129 [inline]\n RIP: 0010:memory_is_poisoned mm/kasan/generic.c:161 [inline]\n RIP: 0010:check_region_inline mm/kasan/generic.c:180 [inline]\n RIP: 0010:kasan_check_range+0x101/0x190 mm/kasan/generic.c:189\nCode: 07 49 39 d1 75 0a 45 3a 11 b8 01 00 00 00 7c 0b 44 89 c2 e8 21 ed ff ff 83 f0 01 5b 5d 41 5c c3 48 85 d2 74 4f 48 01 ea eb 09 <48> 83 c0 01 48 39 d0 74 41 80 38 00 74 f2 eb b6 41 bc 08 00 00 00\nRSP: 0018:ffffc90012dcf998 EFLAGS: 00000046\nRAX: fffffbfff258af1e RBX: fffffbfff258af1f RCX: ffffffff8168eda3\nRDX: fffffbfff258af1f RSI: 0000000000000004 RDI: ffffffff92c578f0\nRBP: fffffbfff258af1e R08: 0000000000000000 R09: fffffbfff258af1e\nR10: ffffffff92c578f3 R11: ffffffff8acbcbc0 R12: 0000000000000002\nR13: ffff88806db38400 R14: 1ffff920025b9f42 R15: ffffffff92c578e8\nFS: 0000000000000000(0000) GS:ffff8880b9800000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 000000c00994e078 CR3: 000000002c250000 CR4: 00000000003506f0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nCall Trace:\n \n \n \n instrument_atomic_read include/linux/instrumented.h:68 [inline]\n atomic_read include/linux/atomic/atomic-instrumented.h:32 [inline]\n queued_spin_is_locked include/asm-generic/qspinlock.h:57 [inline]\n debug_spin_unlock kernel/locking/spinlock_debug.c:101 [inline]\n do_raw_spin_unlock+0x53/0x230 kernel/locking/spinlock_debug.c:141\n __raw_spin_unlock_irqrestore include/linux/spinlock_api_smp.h:150 [inline]\n _raw_spin_unlock_irqrestore+0x22/0x70 kernel/locking/spinlock.c:194\n debug_object_activate+0x349/0x540 lib/debugobjects.c:726\n debug_work_activate kernel/workqueue.c:578 [inline]\n insert_work+0x30/0x230 kernel/workqueue.c:1650\n __queue_work+0x62e/0x11d0 kernel/workqueue.c:1802\n __queue_delayed_work+0x1bf/0x270 kernel/workqueue.c:1953\n queue_delayed_work_on+0x106/0x130 kernel/workqueue.c:1989\n queue_delayed_work include/linux/workqueue.h:563 [inline]\n schedule_delayed_work include/linux/workqueue.h:677 [inline]\n nsim_dev_trap_report_work+0x9c0/0xc80 drivers/net/netdevsim/dev.c:842\n process_one_work+0x886/0x15d0 kernel/workqueue.c:2633\n process_scheduled_works kernel/workqueue.c:2706 [inline]\n worker_thread+0x8b9/0x1290 kernel/workqueue.c:2787\n kthread+0x2c6/0x3a0 kernel/kthread.c:388\n ret_from_fork+0x45/0x80 arch/x86/kernel/process.c:147\n ret_from_fork_asm+0x11/0x20 arch/x86/entry/entry_64.S:242\n ", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-835" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-02T07:15:44Z" diff --git a/advisories/unreviewed/2024/04/GHSA-9gh2-p9fc-q3cr/GHSA-9gh2-p9fc-q3cr.json b/advisories/unreviewed/2024/04/GHSA-9gh2-p9fc-q3cr/GHSA-9gh2-p9fc-q3cr.json index cd5317ff6e0..d1e3e7665c7 100644 --- a/advisories/unreviewed/2024/04/GHSA-9gh2-p9fc-q3cr/GHSA-9gh2-p9fc-q3cr.json +++ b/advisories/unreviewed/2024/04/GHSA-9gh2-p9fc-q3cr/GHSA-9gh2-p9fc-q3cr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9gh2-p9fc-q3cr", - "modified": "2024-04-02T09:30:41Z", + "modified": "2025-03-17T18:31:38Z", "published": "2024-04-02T09:30:41Z", "aliases": [ "CVE-2024-26677" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nrxrpc: Fix delayed ACKs to not set the reference serial number\n\nFix the construction of delayed ACKs to not set the reference serial number\nas they can't be used as an RTT reference.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-02T07:15:44Z" diff --git a/advisories/unreviewed/2024/04/GHSA-c8f2-2f6p-gpgc/GHSA-c8f2-2f6p-gpgc.json b/advisories/unreviewed/2024/04/GHSA-c8f2-2f6p-gpgc/GHSA-c8f2-2f6p-gpgc.json index 7aeb2197c8b..7bf30664b05 100644 --- a/advisories/unreviewed/2024/04/GHSA-c8f2-2f6p-gpgc/GHSA-c8f2-2f6p-gpgc.json +++ b/advisories/unreviewed/2024/04/GHSA-c8f2-2f6p-gpgc/GHSA-c8f2-2f6p-gpgc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c8f2-2f6p-gpgc", - "modified": "2024-06-26T00:31:36Z", + "modified": "2025-03-17T18:31:38Z", "published": "2024-04-03T15:30:43Z", "aliases": [ "CVE-2024-26707" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: hsr: remove WARN_ONCE() in send_hsr_supervision_frame()\n\nSyzkaller reported [1] hitting a warning after failing to allocate\nresources for skb in hsr_init_skb(). Since a WARN_ONCE() call will\nnot help much in this case, it might be prudent to switch to\nnetdev_warn_once(). At the very least it will suppress syzkaller\nreports such as [1].\n\nJust in case, use netdev_warn_once() in send_prp_supervision_frame()\nfor similar reasons.\n\n[1]\nHSR: Could not send supervision frame\nWARNING: CPU: 1 PID: 85 at net/hsr/hsr_device.c:294 send_hsr_supervision_frame+0x60a/0x810 net/hsr/hsr_device.c:294\nRIP: 0010:send_hsr_supervision_frame+0x60a/0x810 net/hsr/hsr_device.c:294\n...\nCall Trace:\n \n hsr_announce+0x114/0x370 net/hsr/hsr_device.c:382\n call_timer_fn+0x193/0x590 kernel/time/timer.c:1700\n expire_timers kernel/time/timer.c:1751 [inline]\n __run_timers+0x764/0xb20 kernel/time/timer.c:2022\n run_timer_softirq+0x58/0xd0 kernel/time/timer.c:2035\n __do_softirq+0x21a/0x8de kernel/softirq.c:553\n invoke_softirq kernel/softirq.c:427 [inline]\n __irq_exit_rcu kernel/softirq.c:632 [inline]\n irq_exit_rcu+0xb7/0x120 kernel/softirq.c:644\n sysvec_apic_timer_interrupt+0x95/0xb0 arch/x86/kernel/apic/apic.c:1076\n \n \n asm_sysvec_apic_timer_interrupt+0x1a/0x20 arch/x86/include/asm/idtentry.h:649\n...\n\nThis issue is also found in older kernels (at least up to 5.10).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-770" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T15:15:53Z" diff --git a/advisories/unreviewed/2024/04/GHSA-cwpj-wxfp-crc5/GHSA-cwpj-wxfp-crc5.json b/advisories/unreviewed/2024/04/GHSA-cwpj-wxfp-crc5/GHSA-cwpj-wxfp-crc5.json index cf3ce48ee18..174016bc571 100644 --- a/advisories/unreviewed/2024/04/GHSA-cwpj-wxfp-crc5/GHSA-cwpj-wxfp-crc5.json +++ b/advisories/unreviewed/2024/04/GHSA-cwpj-wxfp-crc5/GHSA-cwpj-wxfp-crc5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cwpj-wxfp-crc5", - "modified": "2024-04-02T09:30:41Z", + "modified": "2025-03-17T18:31:38Z", "published": "2024-04-02T09:30:41Z", "aliases": [ "CVE-2024-26674" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/lib: Revert to _ASM_EXTABLE_UA() for {get,put}_user() fixups\n\nDuring memory error injection test on kernels >= v6.4, the kernel panics\nlike below. However, this issue couldn't be reproduced on kernels <= v6.3.\n\n mce: [Hardware Error]: CPU 296: Machine Check Exception: f Bank 1: bd80000000100134\n mce: [Hardware Error]: RIP 10: {__get_user_nocheck_4+0x6/0x20}\n mce: [Hardware Error]: TSC 411a93533ed ADDR 346a8730040 MISC 86\n mce: [Hardware Error]: PROCESSOR 0:a06d0 TIME 1706000767 SOCKET 1 APIC 211 microcode 80001490\n mce: [Hardware Error]: Run the above through 'mcelog --ascii'\n mce: [Hardware Error]: Machine check: Data load in unrecoverable area of kernel\n Kernel panic - not syncing: Fatal local machine check\n\nThe MCA code can recover from an in-kernel #MC if the fixup type is\nEX_TYPE_UACCESS, explicitly indicating that the kernel is attempting to\naccess userspace memory. However, if the fixup type is EX_TYPE_DEFAULT\nthe only thing that is raised for an in-kernel #MC is a panic.\n\nex_handler_uaccess() would warn if users gave a non-canonical addresses\n(with bit 63 clear) to {get, put}_user(), which was unexpected.\n\nTherefore, commit\n\n b19b74bc99b1 (\"x86/mm: Rework address range check in get_user() and put_user()\")\n\nreplaced _ASM_EXTABLE_UA() with _ASM_EXTABLE() for {get, put}_user()\nfixups. However, the new fixup type EX_TYPE_DEFAULT results in a panic.\n\nCommit\n\n 6014bc27561f (\"x86-64: make access_ok() independent of LAM\")\n\nadded the check gp_fault_address_ok() right before the WARN_ONCE() in\nex_handler_uaccess() to not warn about non-canonical user addresses due\nto LAM.\n\nWith that in place, revert back to _ASM_EXTABLE_UA() for {get,put}_user()\nexception fixups in order to be able to handle in-kernel MCEs correctly\nagain.\n\n [ bp: Massage commit message. ]", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-02T07:15:44Z" diff --git a/advisories/unreviewed/2024/04/GHSA-cwr2-26gq-v2xr/GHSA-cwr2-26gq-v2xr.json b/advisories/unreviewed/2024/04/GHSA-cwr2-26gq-v2xr/GHSA-cwr2-26gq-v2xr.json index b1af9fba818..9d3c4082aa3 100644 --- a/advisories/unreviewed/2024/04/GHSA-cwr2-26gq-v2xr/GHSA-cwr2-26gq-v2xr.json +++ b/advisories/unreviewed/2024/04/GHSA-cwr2-26gq-v2xr/GHSA-cwr2-26gq-v2xr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cwr2-26gq-v2xr", - "modified": "2024-06-27T15:30:38Z", + "modified": "2025-03-17T18:31:38Z", "published": "2024-04-03T15:30:42Z", "aliases": [ "CVE-2024-26696" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: fix hang in nilfs_lookup_dirty_data_buffers()\n\nSyzbot reported a hang issue in migrate_pages_batch() called by mbind()\nand nilfs_lookup_dirty_data_buffers() called in the log writer of nilfs2.\n\nWhile migrate_pages_batch() locks a folio and waits for the writeback to\ncomplete, the log writer thread that should bring the writeback to\ncompletion picks up the folio being written back in\nnilfs_lookup_dirty_data_buffers() that it calls for subsequent log\ncreation and was trying to lock the folio. Thus causing a deadlock.\n\nIn the first place, it is unexpected that folios/pages in the middle of\nwriteback will be updated and become dirty. Nilfs2 adds a checksum to\nverify the validity of the log being written and uses it for recovery at\nmount, so data changes during writeback are suppressed. Since this is\nbroken, an unclean shutdown could potentially cause recovery to fail.\n\nInvestigation revealed that the root cause is that the wait for writeback\ncompletion in nilfs_page_mkwrite() is conditional, and if the backing\ndevice does not require stable writes, data may be modified without\nwaiting.\n\nFix these issues by making nilfs_page_mkwrite() wait for writeback to\nfinish regardless of the stable write requirement of the backing device.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -56,8 +61,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-667" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T15:15:52Z" diff --git a/advisories/unreviewed/2024/04/GHSA-jc4v-c4mw-rmf8/GHSA-jc4v-c4mw-rmf8.json b/advisories/unreviewed/2024/04/GHSA-jc4v-c4mw-rmf8/GHSA-jc4v-c4mw-rmf8.json index dbc01744190..49fb24ab968 100644 --- a/advisories/unreviewed/2024/04/GHSA-jc4v-c4mw-rmf8/GHSA-jc4v-c4mw-rmf8.json +++ b/advisories/unreviewed/2024/04/GHSA-jc4v-c4mw-rmf8/GHSA-jc4v-c4mw-rmf8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jc4v-c4mw-rmf8", - "modified": "2024-04-03T15:30:42Z", + "modified": "2025-03-17T18:31:38Z", "published": "2024-04-03T15:30:42Z", "aliases": [ "CVE-2024-26692" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: Fix regression in writes when non-standard maximum write size negotiated\n\nThe conversion to netfs in the 6.3 kernel caused a regression when\nmaximum write size is set by the server to an unexpected value which is\nnot a multiple of 4096 (similarly if the user overrides the maximum\nwrite size by setting mount parm \"wsize\", but sets it to a value that\nis not a multiple of 4096). When negotiated write size is not a\nmultiple of 4096 the netfs code can skip the end of the final\npage when doing large sequential writes, causing data corruption.\n\nThis section of code is being rewritten/removed due to a large\nnetfs change, but until that point (ie for the 6.3 kernel until now)\nwe can not support non-standard maximum write sizes.\n\nAdd a warning if a user specifies a wsize on mount that is not\na multiple of 4096 (and round down), also add a change where we\nround down the maximum write size if the server negotiates a value\nthat is not a multiple of 4096 (we also have to check to make sure that\nwe do not round it down to zero).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T15:15:52Z" diff --git a/advisories/unreviewed/2024/04/GHSA-mgx5-jrhq-g7rg/GHSA-mgx5-jrhq-g7rg.json b/advisories/unreviewed/2024/04/GHSA-mgx5-jrhq-g7rg/GHSA-mgx5-jrhq-g7rg.json index f00ed96d83e..3332b1816ed 100644 --- a/advisories/unreviewed/2024/04/GHSA-mgx5-jrhq-g7rg/GHSA-mgx5-jrhq-g7rg.json +++ b/advisories/unreviewed/2024/04/GHSA-mgx5-jrhq-g7rg/GHSA-mgx5-jrhq-g7rg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mgx5-jrhq-g7rg", - "modified": "2024-12-09T15:31:32Z", + "modified": "2025-03-17T18:31:38Z", "published": "2024-04-03T15:30:42Z", "aliases": [ "CVE-2024-26686" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfs/proc: do_task_stat: use sig->stats_lock to gather the threads/children stats\n\nlock_task_sighand() can trigger a hard lockup. If NR_CPUS threads call\ndo_task_stat() at the same time and the process has NR_THREADS, it will\nspin with irqs disabled O(NR_CPUS * NR_THREADS) time.\n\nChange do_task_stat() to use sig->stats_lock to gather the statistics\noutside of ->siglock protected section, in the likely case this code will\nrun lockless.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-667" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T15:15:52Z" diff --git a/advisories/unreviewed/2024/04/GHSA-mw2r-2h6j-6g7v/GHSA-mw2r-2h6j-6g7v.json b/advisories/unreviewed/2024/04/GHSA-mw2r-2h6j-6g7v/GHSA-mw2r-2h6j-6g7v.json index 46fefa1678d..401171a02a7 100644 --- a/advisories/unreviewed/2024/04/GHSA-mw2r-2h6j-6g7v/GHSA-mw2r-2h6j-6g7v.json +++ b/advisories/unreviewed/2024/04/GHSA-mw2r-2h6j-6g7v/GHSA-mw2r-2h6j-6g7v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mw2r-2h6j-6g7v", - "modified": "2024-06-26T00:31:36Z", + "modified": "2025-03-17T18:31:41Z", "published": "2024-04-03T18:30:42Z", "aliases": [ "CVE-2024-26751" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nARM: ep93xx: Add terminator to gpiod_lookup_table\n\nWithout the terminator, if a con_id is passed to gpio_find() that\ndoes not exist in the lookup table the function will not stop looping\ncorrectly, and eventually cause an oops.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -53,7 +58,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T17:15:51Z" diff --git a/advisories/unreviewed/2024/04/GHSA-p22p-8399-qrmf/GHSA-p22p-8399-qrmf.json b/advisories/unreviewed/2024/04/GHSA-p22p-8399-qrmf/GHSA-p22p-8399-qrmf.json index 38a21dcf2ca..0a14e12ac3b 100644 --- a/advisories/unreviewed/2024/04/GHSA-p22p-8399-qrmf/GHSA-p22p-8399-qrmf.json +++ b/advisories/unreviewed/2024/04/GHSA-p22p-8399-qrmf/GHSA-p22p-8399-qrmf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p22p-8399-qrmf", - "modified": "2024-04-03T18:30:42Z", + "modified": "2025-03-17T18:31:41Z", "published": "2024-04-03T18:30:42Z", "aliases": [ "CVE-2024-26759" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/swap: fix race when skipping swapcache\n\nWhen skipping swapcache for SWP_SYNCHRONOUS_IO, if two or more threads\nswapin the same entry at the same time, they get different pages (A, B). \nBefore one thread (T0) finishes the swapin and installs page (A) to the\nPTE, another thread (T1) could finish swapin of page (B), swap_free the\nentry, then swap out the possibly modified page reusing the same entry. \nIt breaks the pte_same check in (T0) because PTE value is unchanged,\ncausing ABA problem. Thread (T0) will install a stalled page (A) into the\nPTE and cause data corruption.\n\nOne possible callstack is like this:\n\nCPU0 CPU1\n---- ----\ndo_swap_page() do_swap_page() with same entry\n \n \nswap_read_folio() <- read to page A swap_read_folio() <- read to page B\n \n... set_pte_at()\n swap_free() <- entry is free\n \n \npte_same() <- Check pass, PTE seems\n unchanged, but page A\n is stalled!\nswap_free() <- page B content lost!\nset_pte_at() <- staled page A installed!\n\nAnd besides, for ZRAM, swap_free() allows the swap device to discard the\nentry content, so even if page (B) is not modified, if swap_read_folio()\non CPU0 happens later than swap_free() on CPU1, it may also cause data\nloss.\n\nTo fix this, reuse swapcache_prepare which will pin the swap entry using\nthe cache flag, and allow only one thread to swap it in, also prevent any\nparallel code from putting the entry in the cache. Release the pin after\nPT unlocked.\n\nRacers just loop and wait since it's a rare and very short event. A\nschedule_timeout_uninterruptible(1) call is added to avoid repeated page\nfaults wasting too much CPU, causing livelock or adding too much noise to\nperf statistics. A similar livelock issue was described in commit\n029c4628b2eb (\"mm: swap: get rid of livelock in swapin readahead\")\n\nReproducer:\n\nThis race issue can be triggered easily using a well constructed\nreproducer and patched brd (with a delay in read path) [1]:\n\nWith latest 6.8 mainline, race caused data loss can be observed easily:\n$ gcc -g -lpthread test-thread-swap-race.c && ./a.out\n Polulating 32MB of memory region...\n Keep swapping out...\n Starting round 0...\n Spawning 65536 workers...\n 32746 workers spawned, wait for done...\n Round 0: Error on 0x5aa00, expected 32746, got 32743, 3 data loss!\n Round 0: Error on 0x395200, expected 32746, got 32743, 3 data loss!\n Round 0: Error on 0x3fd000, expected 32746, got 32737, 9 data loss!\n Round 0 Failed, 15 data loss!\n\nThis reproducer spawns multiple threads sharing the same memory region\nusing a small swap device. Every two threads updates mapped pages one by\none in opposite direction trying to create a race, with one dedicated\nthread keep swapping out the data out using madvise.\n\nThe reproducer created a reproduce rate of about once every 5 minutes, so\nthe race should be totally possible in production.\n\nAfter this patch, I ran the reproducer for over a few hundred rounds and\nno data loss observed.\n\nPerformance overhead is minimal, microbenchmark swapin 10G from 32G\nzram:\n\nBefore: 10934698 us\nAfter: 11157121 us\nCached: 13155355 us (Dropping SWP_SYNCHRONOUS_IO flag)\n\n[kasong@tencent.com: v4]\n Link: https://lkml.kernel.org/r/20240219082040.7495-1-ryncsn@gmail.com", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T17:15:52Z" diff --git a/advisories/unreviewed/2024/04/GHSA-q3x9-cqxj-2x38/GHSA-q3x9-cqxj-2x38.json b/advisories/unreviewed/2024/04/GHSA-q3x9-cqxj-2x38/GHSA-q3x9-cqxj-2x38.json index 44e15c1decd..429a14a9b25 100644 --- a/advisories/unreviewed/2024/04/GHSA-q3x9-cqxj-2x38/GHSA-q3x9-cqxj-2x38.json +++ b/advisories/unreviewed/2024/04/GHSA-q3x9-cqxj-2x38/GHSA-q3x9-cqxj-2x38.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-306" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-q4mr-gm7x-h58f/GHSA-q4mr-gm7x-h58f.json b/advisories/unreviewed/2024/04/GHSA-q4mr-gm7x-h58f/GHSA-q4mr-gm7x-h58f.json index b4c998d9be8..4d3e5c1ecca 100644 --- a/advisories/unreviewed/2024/04/GHSA-q4mr-gm7x-h58f/GHSA-q4mr-gm7x-h58f.json +++ b/advisories/unreviewed/2024/04/GHSA-q4mr-gm7x-h58f/GHSA-q4mr-gm7x-h58f.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-q4mr-gm7x-h58f", - "modified": "2024-04-03T18:30:41Z", + "modified": "2025-03-17T18:31:39Z", "published": "2024-04-03T18:30:41Z", "aliases": [ "CVE-2024-26730" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (nct6775) Fix access to temperature configuration registers\n\nThe number of temperature configuration registers does\nnot always match the total number of temperature registers.\nThis can result in access errors reported if KASAN is enabled.\n\nBUG: KASAN: global-out-of-bounds in nct6775_probe+0x5654/0x6fe9 nct6775_core", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T17:15:50Z" diff --git a/advisories/unreviewed/2024/04/GHSA-q5qj-w2hw-fr2c/GHSA-q5qj-w2hw-fr2c.json b/advisories/unreviewed/2024/04/GHSA-q5qj-w2hw-fr2c/GHSA-q5qj-w2hw-fr2c.json index 0a39e092380..33f7a6c6ccd 100644 --- a/advisories/unreviewed/2024/04/GHSA-q5qj-w2hw-fr2c/GHSA-q5qj-w2hw-fr2c.json +++ b/advisories/unreviewed/2024/04/GHSA-q5qj-w2hw-fr2c/GHSA-q5qj-w2hw-fr2c.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-q5qj-w2hw-fr2c", - "modified": "2024-04-03T18:30:42Z", + "modified": "2025-03-17T18:31:40Z", "published": "2024-04-03T18:30:42Z", "aliases": [ "CVE-2024-26742" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: smartpqi: Fix disable_managed_interrupts\n\nCorrect blk-mq registration issue with module parameter\ndisable_managed_interrupts enabled.\n\nWhen we turn off the default PCI_IRQ_AFFINITY flag, the driver needs to\nregister with blk-mq using blk_mq_map_queues(). The driver is currently\ncalling blk_mq_pci_map_queues() which results in a stack trace and possibly\nundefined behavior.\n\nStack Trace:\n[ 7.860089] scsi host2: smartpqi\n[ 7.871934] WARNING: CPU: 0 PID: 238 at block/blk-mq-pci.c:52 blk_mq_pci_map_queues+0xca/0xd0\n[ 7.889231] Modules linked in: sd_mod t10_pi sg uas smartpqi(+) crc32c_intel scsi_transport_sas usb_storage dm_mirror dm_region_hash dm_log dm_mod ipmi_devintf ipmi_msghandler fuse\n[ 7.924755] CPU: 0 PID: 238 Comm: kworker/0:3 Not tainted 4.18.0-372.88.1.el8_6_smartpqi_test.x86_64 #1\n[ 7.944336] Hardware name: HPE ProLiant DL380 Gen10/ProLiant DL380 Gen10, BIOS U30 03/08/2022\n[ 7.963026] Workqueue: events work_for_cpu_fn\n[ 7.978275] RIP: 0010:blk_mq_pci_map_queues+0xca/0xd0\n[ 7.978278] Code: 48 89 de 89 c7 e8 f6 0f 4f 00 3b 05 c4 b7 8e 01 72 e1 5b 31 c0 5d 41 5c 41 5d 41 5e 41 5f e9 7d df 73 00 31 c0 e9 76 df 73 00 <0f> 0b eb bc 90 90 0f 1f 44 00 00 41 57 49 89 ff 41 56 41 55 41 54\n[ 7.978280] RSP: 0018:ffffa95fc3707d50 EFLAGS: 00010216\n[ 7.978283] RAX: 00000000ffffffff RBX: 0000000000000000 RCX: 0000000000000010\n[ 7.978284] RDX: 0000000000000004 RSI: 0000000000000000 RDI: ffff9190c32d4310\n[ 7.978286] RBP: 0000000000000000 R08: ffffa95fc3707d38 R09: ffff91929b81ac00\n[ 7.978287] R10: 0000000000000001 R11: ffffa95fc3707ac0 R12: 0000000000000000\n[ 7.978288] R13: ffff9190c32d4000 R14: 00000000ffffffff R15: ffff9190c4c950a8\n[ 7.978290] FS: 0000000000000000(0000) GS:ffff9193efc00000(0000) knlGS:0000000000000000\n[ 7.978292] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 8.172814] CR2: 000055d11166c000 CR3: 00000002dae10002 CR4: 00000000007706f0\n[ 8.172816] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n[ 8.172817] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n[ 8.172818] PKRU: 55555554\n[ 8.172819] Call Trace:\n[ 8.172823] blk_mq_alloc_tag_set+0x12e/0x310\n[ 8.264339] scsi_add_host_with_dma.cold.9+0x30/0x245\n[ 8.279302] pqi_ctrl_init+0xacf/0xc8e [smartpqi]\n[ 8.294085] ? pqi_pci_probe+0x480/0x4c8 [smartpqi]\n[ 8.309015] pqi_pci_probe+0x480/0x4c8 [smartpqi]\n[ 8.323286] local_pci_probe+0x42/0x80\n[ 8.337855] work_for_cpu_fn+0x16/0x20\n[ 8.351193] process_one_work+0x1a7/0x360\n[ 8.364462] ? create_worker+0x1a0/0x1a0\n[ 8.379252] worker_thread+0x1ce/0x390\n[ 8.392623] ? create_worker+0x1a0/0x1a0\n[ 8.406295] kthread+0x10a/0x120\n[ 8.418428] ? set_kthread_struct+0x50/0x50\n[ 8.431532] ret_from_fork+0x1f/0x40\n[ 8.444137] ---[ end trace 1bf0173d39354506 ]---", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T17:15:51Z" diff --git a/advisories/unreviewed/2024/04/GHSA-qxg5-g69m-9vxh/GHSA-qxg5-g69m-9vxh.json b/advisories/unreviewed/2024/04/GHSA-qxg5-g69m-9vxh/GHSA-qxg5-g69m-9vxh.json index 1a5fb1984a5..83d6931f05b 100644 --- a/advisories/unreviewed/2024/04/GHSA-qxg5-g69m-9vxh/GHSA-qxg5-g69m-9vxh.json +++ b/advisories/unreviewed/2024/04/GHSA-qxg5-g69m-9vxh/GHSA-qxg5-g69m-9vxh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qxg5-g69m-9vxh", - "modified": "2024-04-02T09:30:41Z", + "modified": "2025-03-17T18:31:38Z", "published": "2024-04-02T09:30:41Z", "aliases": [ "CVE-2024-26682" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: improve CSA/ECSA connection refusal\n\nAs mentioned in the previous commit, we pretty quickly found\nthat some APs have ECSA elements stuck in their probe response,\nso using that to not attempt to connect while CSA is happening\nwe never connect to such an AP.\n\nImprove this situation by checking more carefully and ignoring\nthe ECSA if cfg80211 has previously detected the ECSA element\nbeing stuck in the probe response.\n\nAdditionally, allow connecting to an AP that's switching to a\nchannel it's already using, unless it's using quiet mode. In\nthis case, we may just have to adjust bandwidth later. If it's\nactually switching channels, it's better not to try to connect\nin the middle of that.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -25,7 +30,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-02T07:15:44Z" diff --git a/advisories/unreviewed/2024/04/GHSA-v854-7g2j-4x32/GHSA-v854-7g2j-4x32.json b/advisories/unreviewed/2024/04/GHSA-v854-7g2j-4x32/GHSA-v854-7g2j-4x32.json index fae8ef78723..6903e524afb 100644 --- a/advisories/unreviewed/2024/04/GHSA-v854-7g2j-4x32/GHSA-v854-7g2j-4x32.json +++ b/advisories/unreviewed/2024/04/GHSA-v854-7g2j-4x32/GHSA-v854-7g2j-4x32.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-v854-7g2j-4x32", - "modified": "2024-06-26T00:31:36Z", + "modified": "2025-03-17T18:31:38Z", "published": "2024-04-02T09:30:41Z", "aliases": [ "CVE-2024-26673" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_ct: sanitize layer 3 and 4 protocol number in custom expectations\n\n- Disallow families other than NFPROTO_{IPV4,IPV6,INET}.\n- Disallow layer 4 protocol with no ports, since destination port is a\n mandatory attribute for this object.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -49,7 +54,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-02T07:15:43Z" diff --git a/advisories/unreviewed/2024/04/GHSA-vfpm-jx2c-63hf/GHSA-vfpm-jx2c-63hf.json b/advisories/unreviewed/2024/04/GHSA-vfpm-jx2c-63hf/GHSA-vfpm-jx2c-63hf.json index e2cc949200a..97b0a4afd41 100644 --- a/advisories/unreviewed/2024/04/GHSA-vfpm-jx2c-63hf/GHSA-vfpm-jx2c-63hf.json +++ b/advisories/unreviewed/2024/04/GHSA-vfpm-jx2c-63hf/GHSA-vfpm-jx2c-63hf.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-20" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-vfrw-8352-324f/GHSA-vfrw-8352-324f.json b/advisories/unreviewed/2024/04/GHSA-vfrw-8352-324f/GHSA-vfrw-8352-324f.json index 8c5071aa0e6..99f84ee6afc 100644 --- a/advisories/unreviewed/2024/04/GHSA-vfrw-8352-324f/GHSA-vfrw-8352-324f.json +++ b/advisories/unreviewed/2024/04/GHSA-vfrw-8352-324f/GHSA-vfrw-8352-324f.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vfrw-8352-324f", - "modified": "2024-04-03T15:30:43Z", + "modified": "2025-03-17T18:31:38Z", "published": "2024-04-03T15:30:43Z", "aliases": [ "CVE-2024-26714" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ninterconnect: qcom: sc8180x: Mark CO0 BCM keepalive\n\nThe CO0 BCM needs to be up at all times, otherwise some hardware (like\nthe UFS controller) loses its connection to the rest of the SoC,\nresulting in a hang of the platform, accompanied by a spectacular\nlogspam.\n\nMark it as keepalive to prevent such cases.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -33,7 +38,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T15:15:53Z" diff --git a/advisories/unreviewed/2024/04/GHSA-vrrq-3f8j-8672/GHSA-vrrq-3f8j-8672.json b/advisories/unreviewed/2024/04/GHSA-vrrq-3f8j-8672/GHSA-vrrq-3f8j-8672.json index 7e80a82645b..4fbb06d9609 100644 --- a/advisories/unreviewed/2024/04/GHSA-vrrq-3f8j-8672/GHSA-vrrq-3f8j-8672.json +++ b/advisories/unreviewed/2024/04/GHSA-vrrq-3f8j-8672/GHSA-vrrq-3f8j-8672.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vrrq-3f8j-8672", - "modified": "2024-06-26T00:31:36Z", + "modified": "2025-03-17T18:31:40Z", "published": "2024-04-03T18:30:42Z", "aliases": [ "CVE-2024-26736" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nafs: Increase buffer size in afs_update_volume_status()\n\nThe max length of volume->vid value is 20 characters.\nSo increase idbuf[] size up to 24 to avoid overflow.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.\n\n[DH: Actually, it's 20 + NUL, so increase it to 24 and use snprintf()]", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T17:15:51Z" diff --git a/advisories/unreviewed/2024/04/GHSA-vx76-2j88-69mq/GHSA-vx76-2j88-69mq.json b/advisories/unreviewed/2024/04/GHSA-vx76-2j88-69mq/GHSA-vx76-2j88-69mq.json index 2847080a293..a4475f0cced 100644 --- a/advisories/unreviewed/2024/04/GHSA-vx76-2j88-69mq/GHSA-vx76-2j88-69mq.json +++ b/advisories/unreviewed/2024/04/GHSA-vx76-2j88-69mq/GHSA-vx76-2j88-69mq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vx76-2j88-69mq", - "modified": "2024-06-26T00:31:36Z", + "modified": "2025-03-17T18:31:38Z", "published": "2024-04-02T09:30:42Z", "aliases": [ "CVE-2024-26684" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: stmmac: xgmac: fix handling of DPP safety error for DMA channels\n\nCommit 56e58d6c8a56 (\"net: stmmac: Implement Safety Features in\nXGMAC core\") checks and reports safety errors, but leaves the\nData Path Parity Errors for each channel in DMA unhandled at all, lead to\na storm of interrupt.\nFix it by checking and clearing the DMA_DPP_Interrupt_Status register.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -49,7 +54,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-02T07:15:44Z" diff --git a/advisories/unreviewed/2024/04/GHSA-w9mj-34hr-82rj/GHSA-w9mj-34hr-82rj.json b/advisories/unreviewed/2024/04/GHSA-w9mj-34hr-82rj/GHSA-w9mj-34hr-82rj.json index 106aca5b217..f2ece6926cf 100644 --- a/advisories/unreviewed/2024/04/GHSA-w9mj-34hr-82rj/GHSA-w9mj-34hr-82rj.json +++ b/advisories/unreviewed/2024/04/GHSA-w9mj-34hr-82rj/GHSA-w9mj-34hr-82rj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-w9mj-34hr-82rj", - "modified": "2024-06-25T21:31:12Z", + "modified": "2025-03-17T18:31:39Z", "published": "2024-04-03T15:30:44Z", "aliases": [ "CVE-2024-26727" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: do not ASSERT() if the newly created subvolume already got read\n\n[BUG]\nThere is a syzbot crash, triggered by the ASSERT() during subvolume\ncreation:\n\n assertion failed: !anon_dev, in fs/btrfs/disk-io.c:1319\n ------------[ cut here ]------------\n kernel BUG at fs/btrfs/disk-io.c:1319!\n invalid opcode: 0000 [#1] PREEMPT SMP KASAN\n RIP: 0010:btrfs_get_root_ref.part.0+0x9aa/0xa60\n \n btrfs_get_new_fs_root+0xd3/0xf0\n create_subvol+0xd02/0x1650\n btrfs_mksubvol+0xe95/0x12b0\n __btrfs_ioctl_snap_create+0x2f9/0x4f0\n btrfs_ioctl_snap_create+0x16b/0x200\n btrfs_ioctl+0x35f0/0x5cf0\n __x64_sys_ioctl+0x19d/0x210\n do_syscall_64+0x3f/0xe0\n entry_SYSCALL_64_after_hwframe+0x63/0x6b\n ---[ end trace 0000000000000000 ]---\n\n[CAUSE]\nDuring create_subvol(), after inserting root item for the newly created\nsubvolume, we would trigger btrfs_get_new_fs_root() to get the\nbtrfs_root of that subvolume.\n\nThe idea here is, we have preallocated an anonymous device number for\nthe subvolume, thus we can assign it to the new subvolume.\n\nBut there is really nothing preventing things like backref walk to read\nthe new subvolume.\nIf that happens before we call btrfs_get_new_fs_root(), the subvolume\nwould be read out, with a new anonymous device number assigned already.\n\nIn that case, we would trigger ASSERT(), as we really expect no one to\nread out that subvolume (which is not yet accessible from the fs).\nBut things like backref walk is still possible to trigger the read on\nthe subvolume.\n\nThus our assumption on the ASSERT() is not correct in the first place.\n\n[FIX]\nFix it by removing the ASSERT(), and just free the @anon_dev, reset it\nto 0, and continue.\n\nIf the subvolume tree is read out by something else, it should have\nalready get a new anon_dev assigned thus we only need to free the\npreallocated one.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-617" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T15:15:54Z" diff --git a/advisories/unreviewed/2024/04/GHSA-whqc-wjjv-fvgg/GHSA-whqc-wjjv-fvgg.json b/advisories/unreviewed/2024/04/GHSA-whqc-wjjv-fvgg/GHSA-whqc-wjjv-fvgg.json index 4cc12a52ab8..79709945e97 100644 --- a/advisories/unreviewed/2024/04/GHSA-whqc-wjjv-fvgg/GHSA-whqc-wjjv-fvgg.json +++ b/advisories/unreviewed/2024/04/GHSA-whqc-wjjv-fvgg/GHSA-whqc-wjjv-fvgg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-whqc-wjjv-fvgg", - "modified": "2024-04-02T09:30:41Z", + "modified": "2025-03-17T18:31:38Z", "published": "2024-04-02T09:30:41Z", "aliases": [ "CVE-2024-26683" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: cfg80211: detect stuck ECSA element in probe resp\n\nWe recently added some validation that we don't try to\nconnect to an AP that is currently in a channel switch\nprocess, since that might want the channel to be quiet\nor we might not be able to connect in time to hear the\nswitching in a beacon. This was in commit c09c4f31998b\n(\"wifi: mac80211: don't connect to an AP while it's in\na CSA process\").\n\nHowever, we promptly got a report that this caused new\nconnection failures, and it turns out that the AP that\nwe now cannot connect to is permanently advertising an\nextended channel switch announcement, even with quiet.\nThe AP in question was an Asus RT-AC53, with firmware\n3.0.0.4.380_10760-g21a5898.\n\nAs a first step, attempt to detect that we're dealing\nwith such a situation, so mac80211 can use this later.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -25,7 +30,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-02T07:15:44Z" diff --git a/advisories/unreviewed/2024/04/GHSA-wr7h-84qc-v963/GHSA-wr7h-84qc-v963.json b/advisories/unreviewed/2024/04/GHSA-wr7h-84qc-v963/GHSA-wr7h-84qc-v963.json index f0ee707c286..a76446037ea 100644 --- a/advisories/unreviewed/2024/04/GHSA-wr7h-84qc-v963/GHSA-wr7h-84qc-v963.json +++ b/advisories/unreviewed/2024/04/GHSA-wr7h-84qc-v963/GHSA-wr7h-84qc-v963.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wr7h-84qc-v963", - "modified": "2024-04-03T15:30:43Z", + "modified": "2025-03-17T18:31:39Z", "published": "2024-04-03T15:30:43Z", "aliases": [ "CVE-2024-26721" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/i915/dsc: Fix the macro that calculates DSCC_/DSCA_ PPS reg address\n\nCommit bd077259d0a9 (\"drm/i915/vdsc: Add function to read any PPS\nregister\") defines a new macro to calculate the DSC PPS register\naddresses with PPS number as an input. This macro correctly calculates\nthe addresses till PPS 11 since the addresses increment by 4. So in that\ncase the following macro works correctly to give correct register\naddress:\n\n_MMIO(_DSCA_PPS_0 + (pps) * 4)\n\nHowever after PPS 11, the register address for PPS 12 increments by 12\nbecause of RC Buffer memory allocation in between. Because of this\ndiscontinuity in the address space, the macro calculates wrong addresses\nfor PPS 12 - 16 resulting into incorrect DSC PPS parameter value\nread/writes causing DSC corruption.\n\nThis fixes it by correcting this macro to add the offset of 12 for PPS\n>=12.\n\nv3: Add correct paranthesis for pps argument (Jani Nikula)\n\n(cherry picked from commit 6074be620c31dc2ae11af96a1a5ea95580976fb5)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-131" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T15:15:54Z" diff --git a/advisories/unreviewed/2024/04/GHSA-wxj8-5gp5-wmxf/GHSA-wxj8-5gp5-wmxf.json b/advisories/unreviewed/2024/04/GHSA-wxj8-5gp5-wmxf/GHSA-wxj8-5gp5-wmxf.json index 9a9f5e221a8..b0196b4657f 100644 --- a/advisories/unreviewed/2024/04/GHSA-wxj8-5gp5-wmxf/GHSA-wxj8-5gp5-wmxf.json +++ b/advisories/unreviewed/2024/04/GHSA-wxj8-5gp5-wmxf/GHSA-wxj8-5gp5-wmxf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wxj8-5gp5-wmxf", - "modified": "2024-04-03T18:30:42Z", + "modified": "2025-03-17T18:31:42Z", "published": "2024-04-03T18:30:42Z", "aliases": [ "CVE-2024-26761" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncxl/pci: Fix disabling memory if DVSEC CXL Range does not match a CFMWS window\n\nThe Linux CXL subsystem is built on the assumption that HPA == SPA.\nThat is, the host physical address (HPA) the HDM decoder registers are\nprogrammed with are system physical addresses (SPA).\n\nDuring HDM decoder setup, the DVSEC CXL range registers (cxl-3.1,\n8.1.3.8) are checked if the memory is enabled and the CXL range is in\na HPA window that is described in a CFMWS structure of the CXL host\nbridge (cxl-3.1, 9.18.1.3).\n\nNow, if the HPA is not an SPA, the CXL range does not match a CFMWS\nwindow and the CXL memory range will be disabled then. The HDM decoder\nstops working which causes system memory being disabled and further a\nsystem hang during HDM decoder initialization, typically when a CXL\nenabled kernel boots.\n\nPrevent a system hang and do not disable the HDM decoder if the\ndecoder's CXL range is not found in a CFMWS window.\n\nNote the change only fixes a hardware hang, but does not implement\nHPA/SPA translation. Support for this can be added in a follow on\npatch series.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -33,7 +38,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T17:15:52Z" diff --git a/advisories/unreviewed/2024/04/GHSA-x4x7-9mj3-h6gw/GHSA-x4x7-9mj3-h6gw.json b/advisories/unreviewed/2024/04/GHSA-x4x7-9mj3-h6gw/GHSA-x4x7-9mj3-h6gw.json index 80af35ded93..a24fe56ce51 100644 --- a/advisories/unreviewed/2024/04/GHSA-x4x7-9mj3-h6gw/GHSA-x4x7-9mj3-h6gw.json +++ b/advisories/unreviewed/2024/04/GHSA-x4x7-9mj3-h6gw/GHSA-x4x7-9mj3-h6gw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x4x7-9mj3-h6gw", - "modified": "2024-04-03T18:30:42Z", + "modified": "2025-03-17T18:31:40Z", "published": "2024-04-03T18:30:42Z", "aliases": [ "CVE-2024-26741" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndccp/tcp: Unhash sk from ehash for tb2 alloc failure after check_estalblished().\n\nsyzkaller reported a warning [0] in inet_csk_destroy_sock() with no\nrepro.\n\n WARN_ON(inet_sk(sk)->inet_num && !inet_csk(sk)->icsk_bind_hash);\n\nHowever, the syzkaller's log hinted that connect() failed just before\nthe warning due to FAULT_INJECTION. [1]\n\nWhen connect() is called for an unbound socket, we search for an\navailable ephemeral port. If a bhash bucket exists for the port, we\ncall __inet_check_established() or __inet6_check_established() to check\nif the bucket is reusable.\n\nIf reusable, we add the socket into ehash and set inet_sk(sk)->inet_num.\n\nLater, we look up the corresponding bhash2 bucket and try to allocate\nit if it does not exist.\n\nAlthough it rarely occurs in real use, if the allocation fails, we must\nrevert the changes by check_established(). Otherwise, an unconnected\nsocket could illegally occupy an ehash entry.\n\nNote that we do not put tw back into ehash because sk might have\nalready responded to a packet for tw and it would be better to free\ntw earlier under such memory presure.\n\n[0]:\nWARNING: CPU: 0 PID: 350830 at net/ipv4/inet_connection_sock.c:1193 inet_csk_destroy_sock (net/ipv4/inet_connection_sock.c:1193)\nModules linked in:\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.0-0-gd239552ce722-prebuilt.qemu.org 04/01/2014\nRIP: 0010:inet_csk_destroy_sock (net/ipv4/inet_connection_sock.c:1193)\nCode: 41 5c 41 5d 41 5e e9 2d 4a 3d fd e8 28 4a 3d fd 48 89 ef e8 f0 cd 7d ff 5b 5d 41 5c 41 5d 41 5e e9 13 4a 3d fd e8 0e 4a 3d fd <0f> 0b e9 61 fe ff ff e8 02 4a 3d fd 4c 89 e7 be 03 00 00 00 e8 05\nRSP: 0018:ffffc9000b21fd38 EFLAGS: 00010293\nRAX: 0000000000000000 RBX: 0000000000009e78 RCX: ffffffff840bae40\nRDX: ffff88806e46c600 RSI: ffffffff840bb012 RDI: ffff88811755cca8\nRBP: ffff88811755c880 R08: 0000000000000003 R09: 0000000000000000\nR10: 0000000000009e78 R11: 0000000000000000 R12: ffff88811755c8e0\nR13: ffff88811755c892 R14: ffff88811755c918 R15: 0000000000000000\nFS: 00007f03e5243800(0000) GS:ffff88811ae00000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000001b32f21000 CR3: 0000000112ffe001 CR4: 0000000000770ef0\nPKRU: 55555554\nCall Trace:\n \n ? inet_csk_destroy_sock (net/ipv4/inet_connection_sock.c:1193)\n dccp_close (net/dccp/proto.c:1078)\n inet_release (net/ipv4/af_inet.c:434)\n __sock_release (net/socket.c:660)\n sock_close (net/socket.c:1423)\n __fput (fs/file_table.c:377)\n __fput_sync (fs/file_table.c:462)\n __x64_sys_close (fs/open.c:1557 fs/open.c:1539 fs/open.c:1539)\n do_syscall_64 (arch/x86/entry/common.c:52 arch/x86/entry/common.c:83)\n entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:129)\nRIP: 0033:0x7f03e53852bb\nCode: 03 00 00 00 0f 05 48 3d 00 f0 ff ff 77 41 c3 48 83 ec 18 89 7c 24 0c e8 43 c9 f5 ff 8b 7c 24 0c 41 89 c0 b8 03 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 35 44 89 c7 89 44 24 0c e8 a1 c9 f5 ff 8b 44\nRSP: 002b:00000000005dfba0 EFLAGS: 00000293 ORIG_RAX: 0000000000000003\nRAX: ffffffffffffffda RBX: 0000000000000004 RCX: 00007f03e53852bb\nRDX: 0000000000000002 RSI: 0000000000000002 RDI: 0000000000000003\nRBP: 0000000000000000 R08: 0000000000000000 R09: 000000000000167c\nR10: 0000000008a79680 R11: 0000000000000293 R12: 00007f03e4e43000\nR13: 00007f03e4e43170 R14: 00007f03e4e43178 R15: 00007f03e4e43170\n \n\n[1]:\nFAULT_INJECTION: forcing a failure.\nname failslab, interval 1, probability 0, space 0, times 0\nCPU: 0 PID: 350833 Comm: syz-executor.1 Not tainted 6.7.0-12272-g2121c43f88f5 #9\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.0-0-gd239552ce722-prebuilt.qemu.org 04/01/2014\nCall Trace:\n \n dump_stack_lvl (lib/dump_stack.c:107 (discriminator 1))\n should_fail_ex (lib/fault-inject.c:52 lib/fault-inject.c:153)\n should_failslab (mm/slub.c:3748)\n kmem_cache_alloc (mm/slub.c:3763 mm/slub.c:3842 mm/slub.c:3867)\n inet_bind2_bucket_create \n---truncated---", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-770" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T17:15:51Z" diff --git a/advisories/unreviewed/2024/04/GHSA-xg7r-7865-v6c7/GHSA-xg7r-7865-v6c7.json b/advisories/unreviewed/2024/04/GHSA-xg7r-7865-v6c7/GHSA-xg7r-7865-v6c7.json index f4fd92f1488..bec79b3ff9f 100644 --- a/advisories/unreviewed/2024/04/GHSA-xg7r-7865-v6c7/GHSA-xg7r-7865-v6c7.json +++ b/advisories/unreviewed/2024/04/GHSA-xg7r-7865-v6c7/GHSA-xg7r-7865-v6c7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xg7r-7865-v6c7", - "modified": "2024-06-27T12:30:44Z", + "modified": "2025-03-17T18:31:38Z", "published": "2024-04-03T15:30:42Z", "aliases": [ "CVE-2024-26697" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: fix data corruption in dsync block recovery for small block sizes\n\nThe helper function nilfs_recovery_copy_block() of\nnilfs_recovery_dsync_blocks(), which recovers data from logs created by\ndata sync writes during a mount after an unclean shutdown, incorrectly\ncalculates the on-page offset when copying repair data to the file's page\ncache. In environments where the block size is smaller than the page\nsize, this flaw can cause data corruption and leak uninitialized memory\nbytes during the recovery process.\n\nFix these issues by correcting this byte offset calculation on the page.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -56,8 +61,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T15:15:52Z" diff --git a/advisories/unreviewed/2024/04/GHSA-xhhv-7xxm-fwgf/GHSA-xhhv-7xxm-fwgf.json b/advisories/unreviewed/2024/04/GHSA-xhhv-7xxm-fwgf/GHSA-xhhv-7xxm-fwgf.json index c16f1067390..d270edb802f 100644 --- a/advisories/unreviewed/2024/04/GHSA-xhhv-7xxm-fwgf/GHSA-xhhv-7xxm-fwgf.json +++ b/advisories/unreviewed/2024/04/GHSA-xhhv-7xxm-fwgf/GHSA-xhhv-7xxm-fwgf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xhhv-7xxm-fwgf", - "modified": "2024-04-02T09:30:41Z", + "modified": "2025-03-17T18:31:38Z", "published": "2024-04-02T09:30:41Z", "aliases": [ "CVE-2024-26680" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: atlantic: Fix DMA mapping for PTP hwts ring\n\nFunction aq_ring_hwts_rx_alloc() maps extra AQ_CFG_RXDS_DEF bytes\nfor PTP HWTS ring but then generic aq_ring_free() does not take this\ninto account.\nCreate and use a specific function to free HWTS ring to fix this\nissue.\n\nTrace:\n[ 215.351607] ------------[ cut here ]------------\n[ 215.351612] DMA-API: atlantic 0000:4b:00.0: device driver frees DMA memory with different size [device address=0x00000000fbdd0000] [map size=34816 bytes] [unmap size=32768 bytes]\n[ 215.351635] WARNING: CPU: 33 PID: 10759 at kernel/dma/debug.c:988 check_unmap+0xa6f/0x2360\n...\n[ 215.581176] Call Trace:\n[ 215.583632] \n[ 215.585745] ? show_trace_log_lvl+0x1c4/0x2df\n[ 215.590114] ? show_trace_log_lvl+0x1c4/0x2df\n[ 215.594497] ? debug_dma_free_coherent+0x196/0x210\n[ 215.599305] ? check_unmap+0xa6f/0x2360\n[ 215.603147] ? __warn+0xca/0x1d0\n[ 215.606391] ? check_unmap+0xa6f/0x2360\n[ 215.610237] ? report_bug+0x1ef/0x370\n[ 215.613921] ? handle_bug+0x3c/0x70\n[ 215.617423] ? exc_invalid_op+0x14/0x50\n[ 215.621269] ? asm_exc_invalid_op+0x16/0x20\n[ 215.625480] ? check_unmap+0xa6f/0x2360\n[ 215.629331] ? mark_lock.part.0+0xca/0xa40\n[ 215.633445] debug_dma_free_coherent+0x196/0x210\n[ 215.638079] ? __pfx_debug_dma_free_coherent+0x10/0x10\n[ 215.643242] ? slab_free_freelist_hook+0x11d/0x1d0\n[ 215.648060] dma_free_attrs+0x6d/0x130\n[ 215.651834] aq_ring_free+0x193/0x290 [atlantic]\n[ 215.656487] aq_ptp_ring_free+0x67/0x110 [atlantic]\n...\n[ 216.127540] ---[ end trace 6467e5964dd2640b ]---\n[ 216.132160] DMA-API: Mapped at:\n[ 216.132162] debug_dma_alloc_coherent+0x66/0x2f0\n[ 216.132165] dma_alloc_attrs+0xf5/0x1b0\n[ 216.132168] aq_ring_hwts_rx_alloc+0x150/0x1f0 [atlantic]\n[ 216.132193] aq_ptp_ring_alloc+0x1bb/0x540 [atlantic]\n[ 216.132213] aq_nic_init+0x4a1/0x760 [atlantic]", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-02T07:15:44Z" diff --git a/advisories/unreviewed/2024/04/GHSA-xhj3-2vvm-6mr5/GHSA-xhj3-2vvm-6mr5.json b/advisories/unreviewed/2024/04/GHSA-xhj3-2vvm-6mr5/GHSA-xhj3-2vvm-6mr5.json index fdd83d49150..5d936c35005 100644 --- a/advisories/unreviewed/2024/04/GHSA-xhj3-2vvm-6mr5/GHSA-xhj3-2vvm-6mr5.json +++ b/advisories/unreviewed/2024/04/GHSA-xhj3-2vvm-6mr5/GHSA-xhj3-2vvm-6mr5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xhj3-2vvm-6mr5", - "modified": "2024-06-27T12:30:44Z", + "modified": "2025-03-17T18:31:41Z", "published": "2024-04-03T18:30:42Z", "aliases": [ "CVE-2024-26752" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nl2tp: pass correct message length to ip6_append_data\n\nl2tp_ip6_sendmsg needs to avoid accounting for the transport header\ntwice when splicing more data into an already partially-occupied skbuff.\n\nTo manage this, we check whether the skbuff contains data using\nskb_queue_empty when deciding how much data to append using\nip6_append_data.\n\nHowever, the code which performed the calculation was incorrect:\n\n ulen = len + skb_queue_empty(&sk->sk_write_queue) ? transhdrlen : 0;\n\n...due to C operator precedence, this ends up setting ulen to\ntranshdrlen for messages with a non-zero length, which results in\ncorrupted packets on the wire.\n\nAdd parentheses to correct the calculation in line with the original\nintent.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -56,8 +61,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-131" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T17:15:51Z" diff --git a/advisories/unreviewed/2024/04/GHSA-xqrq-q336-f78g/GHSA-xqrq-q336-f78g.json b/advisories/unreviewed/2024/04/GHSA-xqrq-q336-f78g/GHSA-xqrq-q336-f78g.json index 4947703c7b4..8cc970b5364 100644 --- a/advisories/unreviewed/2024/04/GHSA-xqrq-q336-f78g/GHSA-xqrq-q336-f78g.json +++ b/advisories/unreviewed/2024/04/GHSA-xqrq-q336-f78g/GHSA-xqrq-q336-f78g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xqrq-q336-f78g", - "modified": "2024-06-26T00:31:36Z", + "modified": "2025-03-17T18:31:40Z", "published": "2024-04-03T18:30:41Z", "aliases": [ "CVE-2024-26733" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\narp: Prevent overflow in arp_req_get().\n\nsyzkaller reported an overflown write in arp_req_get(). [0]\n\nWhen ioctl(SIOCGARP) is issued, arp_req_get() looks up an neighbour\nentry and copies neigh->ha to struct arpreq.arp_ha.sa_data.\n\nThe arp_ha here is struct sockaddr, not struct sockaddr_storage, so\nthe sa_data buffer is just 14 bytes.\n\nIn the splat below, 2 bytes are overflown to the next int field,\narp_flags. We initialise the field just after the memcpy(), so it's\nnot a problem.\n\nHowever, when dev->addr_len is greater than 22 (e.g. MAX_ADDR_LEN),\narp_netmask is overwritten, which could be set as htonl(0xFFFFFFFFUL)\nin arp_ioctl() before calling arp_req_get().\n\nTo avoid the overflow, let's limit the max length of memcpy().\n\nNote that commit b5f0de6df6dc (\"net: dev: Convert sa_data to flexible\narray in struct sockaddr\") just silenced syzkaller.\n\n[0]:\nmemcpy: detected field-spanning write (size 16) of single field \"r->arp_ha.sa_data\" at net/ipv4/arp.c:1128 (size 14)\nWARNING: CPU: 0 PID: 144638 at net/ipv4/arp.c:1128 arp_req_get+0x411/0x4a0 net/ipv4/arp.c:1128\nModules linked in:\nCPU: 0 PID: 144638 Comm: syz-executor.4 Not tainted 6.1.74 #31\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.0-debian-1.16.0-5 04/01/2014\nRIP: 0010:arp_req_get+0x411/0x4a0 net/ipv4/arp.c:1128\nCode: fd ff ff e8 41 42 de fb b9 0e 00 00 00 4c 89 fe 48 c7 c2 20 6d ab 87 48 c7 c7 80 6d ab 87 c6 05 25 af 72 04 01 e8 5f 8d ad fb <0f> 0b e9 6c fd ff ff e8 13 42 de fb be 03 00 00 00 4c 89 e7 e8 a6\nRSP: 0018:ffffc900050b7998 EFLAGS: 00010286\nRAX: 0000000000000000 RBX: ffff88803a815000 RCX: 0000000000000000\nRDX: 0000000000000000 RSI: ffffffff8641a44a RDI: 0000000000000001\nRBP: ffffc900050b7a98 R08: 0000000000000001 R09: 0000000000000000\nR10: 0000000000000000 R11: 203a7970636d656d R12: ffff888039c54000\nR13: 1ffff92000a16f37 R14: ffff88803a815084 R15: 0000000000000010\nFS: 00007f172bf306c0(0000) GS:ffff88805aa00000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007f172b3569f0 CR3: 0000000057f12005 CR4: 0000000000770ef0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nPKRU: 55555554\nCall Trace:\n \n arp_ioctl+0x33f/0x4b0 net/ipv4/arp.c:1261\n inet_ioctl+0x314/0x3a0 net/ipv4/af_inet.c:981\n sock_do_ioctl+0xdf/0x260 net/socket.c:1204\n sock_ioctl+0x3ef/0x650 net/socket.c:1321\n vfs_ioctl fs/ioctl.c:51 [inline]\n __do_sys_ioctl fs/ioctl.c:870 [inline]\n __se_sys_ioctl fs/ioctl.c:856 [inline]\n __x64_sys_ioctl+0x18e/0x220 fs/ioctl.c:856\n do_syscall_x64 arch/x86/entry/common.c:51 [inline]\n do_syscall_64+0x37/0x90 arch/x86/entry/common.c:81\n entry_SYSCALL_64_after_hwframe+0x64/0xce\nRIP: 0033:0x7f172b262b8d\nCode: 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 00 f3 0f 1e fa 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b8 ff ff ff f7 d8 64 89 01 48\nRSP: 002b:00007f172bf300b8 EFLAGS: 00000246 ORIG_RAX: 0000000000000010\nRAX: ffffffffffffffda RBX: 00007f172b3abf80 RCX: 00007f172b262b8d\nRDX: 0000000020000000 RSI: 0000000000008954 RDI: 0000000000000003\nRBP: 00007f172b2d3493 R08: 0000000000000000 R09: 0000000000000000\nR10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000\nR13: 000000000000000b R14: 00007f172b3abf80 R15: 00007f172bf10000\n ", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -41,11 +46,17 @@ { "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20241101-0013" } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T17:15:51Z" diff --git a/advisories/unreviewed/2024/04/GHSA-xv6f-4q9w-8q96/GHSA-xv6f-4q9w-8q96.json b/advisories/unreviewed/2024/04/GHSA-xv6f-4q9w-8q96/GHSA-xv6f-4q9w-8q96.json index b528aa6c25e..98ca5661875 100644 --- a/advisories/unreviewed/2024/04/GHSA-xv6f-4q9w-8q96/GHSA-xv6f-4q9w-8q96.json +++ b/advisories/unreviewed/2024/04/GHSA-xv6f-4q9w-8q96/GHSA-xv6f-4q9w-8q96.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xv6f-4q9w-8q96", - "modified": "2024-04-03T15:30:43Z", + "modified": "2025-03-17T18:31:38Z", "published": "2024-04-03T15:30:43Z", "aliases": [ "CVE-2024-26705" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nparisc: BTLB: Fix crash when setting up BTLB at CPU bringup\n\nWhen using hotplug and bringing up a 32-bit CPU, ask the firmware about the\nBTLB information to set up the static (block) TLB entries.\n\nFor that write access to the static btlb_info struct is needed, but\nsince it is marked __ro_after_init the kernel segfaults with missing\nwrite permissions.\n\nFix the crash by dropping the __ro_after_init annotation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T15:15:53Z" diff --git a/advisories/unreviewed/2024/05/GHSA-2893-xwgh-4qj6/GHSA-2893-xwgh-4qj6.json b/advisories/unreviewed/2024/05/GHSA-2893-xwgh-4qj6/GHSA-2893-xwgh-4qj6.json index c36d0836fed..c62390deb0b 100644 --- a/advisories/unreviewed/2024/05/GHSA-2893-xwgh-4qj6/GHSA-2893-xwgh-4qj6.json +++ b/advisories/unreviewed/2024/05/GHSA-2893-xwgh-4qj6/GHSA-2893-xwgh-4qj6.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-122" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-qgc7-3qhr-fr4g/GHSA-qgc7-3qhr-fr4g.json b/advisories/unreviewed/2024/05/GHSA-qgc7-3qhr-fr4g/GHSA-qgc7-3qhr-fr4g.json index 09d809fbc94..2feb5adf9c4 100644 --- a/advisories/unreviewed/2024/05/GHSA-qgc7-3qhr-fr4g/GHSA-qgc7-3qhr-fr4g.json +++ b/advisories/unreviewed/2024/05/GHSA-qgc7-3qhr-fr4g/GHSA-qgc7-3qhr-fr4g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qgc7-3qhr-fr4g", - "modified": "2024-05-06T03:30:47Z", + "modified": "2025-03-17T18:31:43Z", "published": "2024-05-06T03:30:47Z", "aliases": [ "CVE-2023-32871" ], "details": "In DA, there is a possible permission bypass due to an incorrect status check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08355514; Issue ID: ALPS08355514.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-391" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-06T03:15:09Z" diff --git a/advisories/unreviewed/2024/05/GHSA-vq69-6gcm-2ff7/GHSA-vq69-6gcm-2ff7.json b/advisories/unreviewed/2024/05/GHSA-vq69-6gcm-2ff7/GHSA-vq69-6gcm-2ff7.json index cea35f2e170..b8eee82cdc9 100644 --- a/advisories/unreviewed/2024/05/GHSA-vq69-6gcm-2ff7/GHSA-vq69-6gcm-2ff7.json +++ b/advisories/unreviewed/2024/05/GHSA-vq69-6gcm-2ff7/GHSA-vq69-6gcm-2ff7.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-p66q-q6cx-6j4r/GHSA-p66q-q6cx-6j4r.json b/advisories/unreviewed/2024/07/GHSA-p66q-q6cx-6j4r/GHSA-p66q-q6cx-6j4r.json index 3811c31b818..b3bc356ea71 100644 --- a/advisories/unreviewed/2024/07/GHSA-p66q-q6cx-6j4r/GHSA-p66q-q6cx-6j4r.json +++ b/advisories/unreviewed/2024/07/GHSA-p66q-q6cx-6j4r/GHSA-p66q-q6cx-6j4r.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-125" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-prvp-xgc5-f378/GHSA-prvp-xgc5-f378.json b/advisories/unreviewed/2024/07/GHSA-prvp-xgc5-f378/GHSA-prvp-xgc5-f378.json index a1fb921cf67..14f460d783f 100644 --- a/advisories/unreviewed/2024/07/GHSA-prvp-xgc5-f378/GHSA-prvp-xgc5-f378.json +++ b/advisories/unreviewed/2024/07/GHSA-prvp-xgc5-f378/GHSA-prvp-xgc5-f378.json @@ -45,7 +45,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-287" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/09/GHSA-473p-xqgv-xxw3/GHSA-473p-xqgv-xxw3.json b/advisories/unreviewed/2024/09/GHSA-473p-xqgv-xxw3/GHSA-473p-xqgv-xxw3.json index 20028e86a2c..c33efdc598b 100644 --- a/advisories/unreviewed/2024/09/GHSA-473p-xqgv-xxw3/GHSA-473p-xqgv-xxw3.json +++ b/advisories/unreviewed/2024/09/GHSA-473p-xqgv-xxw3/GHSA-473p-xqgv-xxw3.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-451" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/09/GHSA-74p7-53wh-h625/GHSA-74p7-53wh-h625.json b/advisories/unreviewed/2024/09/GHSA-74p7-53wh-h625/GHSA-74p7-53wh-h625.json index c84b1ee28fc..1326fa9c6f6 100644 --- a/advisories/unreviewed/2024/09/GHSA-74p7-53wh-h625/GHSA-74p7-53wh-h625.json +++ b/advisories/unreviewed/2024/09/GHSA-74p7-53wh-h625/GHSA-74p7-53wh-h625.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/09/GHSA-7v3f-jf4x-gj99/GHSA-7v3f-jf4x-gj99.json b/advisories/unreviewed/2024/09/GHSA-7v3f-jf4x-gj99/GHSA-7v3f-jf4x-gj99.json index 97d03ae212e..dd4a1de6c1c 100644 --- a/advisories/unreviewed/2024/09/GHSA-7v3f-jf4x-gj99/GHSA-7v3f-jf4x-gj99.json +++ b/advisories/unreviewed/2024/09/GHSA-7v3f-jf4x-gj99/GHSA-7v3f-jf4x-gj99.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/09/GHSA-v64w-2rh7-3gvr/GHSA-v64w-2rh7-3gvr.json b/advisories/unreviewed/2024/09/GHSA-v64w-2rh7-3gvr/GHSA-v64w-2rh7-3gvr.json index 26e991fce33..3d1c062b2a8 100644 --- a/advisories/unreviewed/2024/09/GHSA-v64w-2rh7-3gvr/GHSA-v64w-2rh7-3gvr.json +++ b/advisories/unreviewed/2024/09/GHSA-v64w-2rh7-3gvr/GHSA-v64w-2rh7-3gvr.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/10/GHSA-3ggr-5p57-2xgh/GHSA-3ggr-5p57-2xgh.json b/advisories/unreviewed/2024/10/GHSA-3ggr-5p57-2xgh/GHSA-3ggr-5p57-2xgh.json index 5c255ac6451..473d67f9c86 100644 --- a/advisories/unreviewed/2024/10/GHSA-3ggr-5p57-2xgh/GHSA-3ggr-5p57-2xgh.json +++ b/advisories/unreviewed/2024/10/GHSA-3ggr-5p57-2xgh/GHSA-3ggr-5p57-2xgh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3ggr-5p57-2xgh", - "modified": "2024-10-15T09:30:31Z", + "modified": "2025-03-17T18:31:44Z", "published": "2024-10-15T09:30:31Z", "aliases": [ "CVE-2024-47943" ], "details": "The firmware upgrade function in the admin web interface of the Rittal IoT Interface & CMC III Processing Unit devices checks if \nthe patch files are signed before executing the containing run.sh \nscript. The signing process is kind of an HMAC with a long string as key\n which is hard-coded in the firmware and is freely available for \ndownload. This allows crafting malicious \"signed\" .patch files in order \nto compromise the device and execute arbitrary code.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -27,7 +32,7 @@ "cwe_ids": [ "CWE-347" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-15T09:15:03Z" diff --git a/advisories/unreviewed/2024/10/GHSA-6vmj-9xjc-fxmr/GHSA-6vmj-9xjc-fxmr.json b/advisories/unreviewed/2024/10/GHSA-6vmj-9xjc-fxmr/GHSA-6vmj-9xjc-fxmr.json index 42751d6c06c..99367a9eb62 100644 --- a/advisories/unreviewed/2024/10/GHSA-6vmj-9xjc-fxmr/GHSA-6vmj-9xjc-fxmr.json +++ b/advisories/unreviewed/2024/10/GHSA-6vmj-9xjc-fxmr/GHSA-6vmj-9xjc-fxmr.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-mw3w-3jx9-mhff/GHSA-mw3w-3jx9-mhff.json b/advisories/unreviewed/2024/11/GHSA-mw3w-3jx9-mhff/GHSA-mw3w-3jx9-mhff.json index e7a6af466e5..9276587bf9c 100644 --- a/advisories/unreviewed/2024/11/GHSA-mw3w-3jx9-mhff/GHSA-mw3w-3jx9-mhff.json +++ b/advisories/unreviewed/2024/11/GHSA-mw3w-3jx9-mhff/GHSA-mw3w-3jx9-mhff.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-5rjv-47jf-7h66/GHSA-5rjv-47jf-7h66.json b/advisories/unreviewed/2025/01/GHSA-5rjv-47jf-7h66/GHSA-5rjv-47jf-7h66.json index 0d7c38f0b10..8d0aca0cc65 100644 --- a/advisories/unreviewed/2025/01/GHSA-5rjv-47jf-7h66/GHSA-5rjv-47jf-7h66.json +++ b/advisories/unreviewed/2025/01/GHSA-5rjv-47jf-7h66/GHSA-5rjv-47jf-7h66.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-203" + "CWE-203", + "CWE-400" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-mh68-7cw5-7m9v/GHSA-mh68-7cw5-7m9v.json b/advisories/unreviewed/2025/01/GHSA-mh68-7cw5-7m9v/GHSA-mh68-7cw5-7m9v.json index 7c3760cd016..212f5e52832 100644 --- a/advisories/unreviewed/2025/01/GHSA-mh68-7cw5-7m9v/GHSA-mh68-7cw5-7m9v.json +++ b/advisories/unreviewed/2025/01/GHSA-mh68-7cw5-7m9v/GHSA-mh68-7cw5-7m9v.json @@ -41,7 +41,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-xpjh-vmfm-8qmf/GHSA-xpjh-vmfm-8qmf.json b/advisories/unreviewed/2025/01/GHSA-xpjh-vmfm-8qmf/GHSA-xpjh-vmfm-8qmf.json index 5b4569692fc..c5fd1ba8651 100644 --- a/advisories/unreviewed/2025/01/GHSA-xpjh-vmfm-8qmf/GHSA-xpjh-vmfm-8qmf.json +++ b/advisories/unreviewed/2025/01/GHSA-xpjh-vmfm-8qmf/GHSA-xpjh-vmfm-8qmf.json @@ -38,6 +38,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-862", "CWE-863" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2025/02/GHSA-cqhq-5mcx-c3m9/GHSA-cqhq-5mcx-c3m9.json b/advisories/unreviewed/2025/02/GHSA-cqhq-5mcx-c3m9/GHSA-cqhq-5mcx-c3m9.json index 621892b5cf2..22f69c8114b 100644 --- a/advisories/unreviewed/2025/02/GHSA-cqhq-5mcx-c3m9/GHSA-cqhq-5mcx-c3m9.json +++ b/advisories/unreviewed/2025/02/GHSA-cqhq-5mcx-c3m9/GHSA-cqhq-5mcx-c3m9.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-400", "CWE-770" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2025/02/GHSA-wcpp-7r83-v4gc/GHSA-wcpp-7r83-v4gc.json b/advisories/unreviewed/2025/02/GHSA-wcpp-7r83-v4gc/GHSA-wcpp-7r83-v4gc.json index 7a5cf8f82e3..9ea41f68ab8 100644 --- a/advisories/unreviewed/2025/02/GHSA-wcpp-7r83-v4gc/GHSA-wcpp-7r83-v4gc.json +++ b/advisories/unreviewed/2025/02/GHSA-wcpp-7r83-v4gc/GHSA-wcpp-7r83-v4gc.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-287" + "CWE-287", + "CWE-319" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-23g7-m523-p43j/GHSA-23g7-m523-p43j.json b/advisories/unreviewed/2025/03/GHSA-23g7-m523-p43j/GHSA-23g7-m523-p43j.json index 8771564ea2c..704a42603cf 100644 --- a/advisories/unreviewed/2025/03/GHSA-23g7-m523-p43j/GHSA-23g7-m523-p43j.json +++ b/advisories/unreviewed/2025/03/GHSA-23g7-m523-p43j/GHSA-23g7-m523-p43j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-23g7-m523-p43j", - "modified": "2025-03-16T06:30:24Z", + "modified": "2025-03-17T18:31:52Z", "published": "2025-03-16T06:30:23Z", "aliases": [ "CVE-2025-1619" ], "details": "The GDPR Cookie Compliance WordPress plugin before 4.15.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-16T06:15:12Z" diff --git a/advisories/unreviewed/2025/03/GHSA-24gm-rc6w-r33q/GHSA-24gm-rc6w-r33q.json b/advisories/unreviewed/2025/03/GHSA-24gm-rc6w-r33q/GHSA-24gm-rc6w-r33q.json new file mode 100644 index 00000000000..0fbfd6c994d --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-24gm-rc6w-r33q/GHSA-24gm-rc6w-r33q.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-24gm-rc6w-r33q", + "modified": "2025-03-17T18:31:51Z", + "published": "2025-03-17T18:31:50Z", + "aliases": [ + "CVE-2022-49477" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: samsung: Fix refcount leak in aries_audio_probe\n\nof_parse_phandle() returns a node pointer with refcount\nincremented, we should use of_node_put() on it when done.\nIf extcon_find_edev_by_node() fails, it doesn't call of_node_put()\nCalling of_node_put() after extcon_find_edev_by_node() to fix this.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49477" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/46d1b310a2d571811c4e08041ce287babb60b86a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/70130bde3457d28c02c76b6cacc5d40a72dd6e17" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/85d899f396622d3034643bf89615a78f9be7c91a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bf4a9b2467b775717d0e9034ad916888e19713a3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cacea459f95be22b3750f3b25b7a1c5897a68206" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-2vp4-6vg4-qh8r/GHSA-2vp4-6vg4-qh8r.json b/advisories/unreviewed/2025/03/GHSA-2vp4-6vg4-qh8r/GHSA-2vp4-6vg4-qh8r.json new file mode 100644 index 00000000000..85c8b37595e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-2vp4-6vg4-qh8r/GHSA-2vp4-6vg4-qh8r.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2vp4-6vg4-qh8r", + "modified": "2025-03-17T18:31:50Z", + "published": "2025-03-17T18:31:50Z", + "aliases": [ + "CVE-2022-49468" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nthermal/core: Fix memory leak in __thermal_cooling_device_register()\n\nI got memory leak as follows when doing fault injection test:\n\nunreferenced object 0xffff888010080000 (size 264312):\n comm \"182\", pid 102533, jiffies 4296434960 (age 10.100s)\n hex dump (first 32 bytes):\n 00 00 00 00 ad 4e ad de ff ff ff ff 00 00 00 00 .....N..........\n ff ff ff ff ff ff ff ff 40 7f 1f b9 ff ff ff ff ........@.......\n backtrace:\n [<0000000038b2f4fc>] kmalloc_order_trace+0x1d/0x110 mm/slab_common.c:969\n [<00000000ebcb8da5>] __kmalloc+0x373/0x420 include/linux/slab.h:510\n [<0000000084137f13>] thermal_cooling_device_setup_sysfs+0x15d/0x2d0 include/linux/slab.h:586\n [<00000000352b8755>] __thermal_cooling_device_register+0x332/0xa60 drivers/thermal/thermal_core.c:927\n [<00000000fb9f331b>] devm_thermal_of_cooling_device_register+0x6b/0xf0 drivers/thermal/thermal_core.c:1041\n [<000000009b8012d2>] max6650_probe.cold+0x557/0x6aa drivers/hwmon/max6650.c:211\n [<00000000da0b7e04>] i2c_device_probe+0x472/0xac0 drivers/i2c/i2c-core-base.c:561\n\nIf device_register() fails, thermal_cooling_device_destroy_sysfs() need be called\nto free the memory allocated in thermal_cooling_device_setup_sysfs().", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49468" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/18530bedd221160823f63ccc20dd55c7a03edbcf" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/21ccc58b671aea924f2481cf5c1cf0ebbfd3552d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3802171f0b5b8b831f4ade5c827547cb323a5bb2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/98a160e898c0f4a979af9de3ab48b4b1d42d1dbb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9abdf0c0184230f0cb5c6685aabf33dda89aa9fb" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-3675-4584-vjwg/GHSA-3675-4584-vjwg.json b/advisories/unreviewed/2025/03/GHSA-3675-4584-vjwg/GHSA-3675-4584-vjwg.json new file mode 100644 index 00000000000..de18d54f040 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3675-4584-vjwg/GHSA-3675-4584-vjwg.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3675-4584-vjwg", + "modified": "2025-03-17T18:31:53Z", + "published": "2025-03-17T18:31:53Z", + "aliases": [ + "CVE-2024-48828" + ], + "details": "Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Privilege Management vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48828" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000289970/dsa-2025-070-security-update-for-dell-networking-os10-vulnerabilities" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000293638/dsa-2025-069-security-update-for-dell-networking-os10-vulnerabilities" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000294091/dsa-2025-079-security-update-for-dell-networking-os10-vulnerabilities" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000295014/dsa-2025-068-security-update-for-dell-networking-os10-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T18:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-3c5h-34ff-q9qh/GHSA-3c5h-34ff-q9qh.json b/advisories/unreviewed/2025/03/GHSA-3c5h-34ff-q9qh/GHSA-3c5h-34ff-q9qh.json new file mode 100644 index 00000000000..854cd617322 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3c5h-34ff-q9qh/GHSA-3c5h-34ff-q9qh.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3c5h-34ff-q9qh", + "modified": "2025-03-17T18:31:53Z", + "published": "2025-03-17T18:31:53Z", + "aliases": [ + "CVE-2024-49561" + ], + "details": "Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Incorrect Privilege Assignment vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49561" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000289970/dsa-2025-070-security-update-for-dell-networking-os10-vulnerabilities" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000293638/dsa-2025-069-security-update-for-dell-networking-os10-vulnerabilities" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000294091/dsa-2025-079-security-update-for-dell-networking-os10-vulnerabilities" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000295014/dsa-2025-068-security-update-for-dell-networking-os10-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T18:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-3mr7-v482-7rj9/GHSA-3mr7-v482-7rj9.json b/advisories/unreviewed/2025/03/GHSA-3mr7-v482-7rj9/GHSA-3mr7-v482-7rj9.json new file mode 100644 index 00000000000..7b389af5fa3 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3mr7-v482-7rj9/GHSA-3mr7-v482-7rj9.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3mr7-v482-7rj9", + "modified": "2025-03-17T18:31:50Z", + "published": "2025-03-17T18:31:50Z", + "aliases": [ + "CVE-2022-49485" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/v3d: Fix null pointer dereference of pointer perfmon\n\nIn the unlikely event that pointer perfmon is null the WARN_ON return path\noccurs after the pointer has already been deferenced. Fix this by only\ndereferencing perfmon after it has been null checked.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49485" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1df8f8901babcc8c8eea2c067179e455b5c828fd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3b72deb784a7d4ae8519a5c584cd87c4b57aa6c8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4be045434923e549a50846a066a04b7b6c1d6d33" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ce7a1ecf3f9f1fccaf67295307614511d8e11b13" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-3ph6-cjjg-96q6/GHSA-3ph6-cjjg-96q6.json b/advisories/unreviewed/2025/03/GHSA-3ph6-cjjg-96q6/GHSA-3ph6-cjjg-96q6.json index c4c796b0990..a7681973b36 100644 --- a/advisories/unreviewed/2025/03/GHSA-3ph6-cjjg-96q6/GHSA-3ph6-cjjg-96q6.json +++ b/advisories/unreviewed/2025/03/GHSA-3ph6-cjjg-96q6/GHSA-3ph6-cjjg-96q6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3ph6-cjjg-96q6", - "modified": "2025-03-16T06:30:24Z", + "modified": "2025-03-17T18:31:51Z", "published": "2025-03-16T06:30:24Z", "aliases": [ "CVE-2025-1620" ], "details": "The GDPR Cookie Compliance WordPress plugin before 4.15.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-16T06:15:12Z" diff --git a/advisories/unreviewed/2025/03/GHSA-427q-63q6-ggx8/GHSA-427q-63q6-ggx8.json b/advisories/unreviewed/2025/03/GHSA-427q-63q6-ggx8/GHSA-427q-63q6-ggx8.json new file mode 100644 index 00000000000..b8eeca3fa1a --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-427q-63q6-ggx8/GHSA-427q-63q6-ggx8.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-427q-63q6-ggx8", + "modified": "2025-03-17T18:31:48Z", + "published": "2025-03-17T18:31:48Z", + "aliases": [ + "CVE-2022-49448" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsoc: bcm: Check for NULL return of devm_kzalloc()\n\nAs the potential failure of allocation, devm_kzalloc() may return NULL. Then\nthe 'pd->pmb' and the follow lines of code may bring null pointer dereference.\n\nTherefore, it is better to check the return value of devm_kzalloc() to avoid\nthis confusion.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49448" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/36339ea7bae4943be01c8e9545e46e334591fecd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5650e103bfc70156001615861fb8aafb3947da6e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b48b98743b568bb219152ba2e15af6ef0d3d8a9b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b4bd2aafacce48db26b0a213d849818d940556dd" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-42x2-72v8-6q9v/GHSA-42x2-72v8-6q9v.json b/advisories/unreviewed/2025/03/GHSA-42x2-72v8-6q9v/GHSA-42x2-72v8-6q9v.json new file mode 100644 index 00000000000..fff54765e72 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-42x2-72v8-6q9v/GHSA-42x2-72v8-6q9v.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-42x2-72v8-6q9v", + "modified": "2025-03-17T18:31:51Z", + "published": "2025-03-17T18:31:51Z", + "aliases": [ + "CVE-2022-49507" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nregulator: da9121: Fix uninit-value in da9121_assign_chip_model()\n\nKASAN report slab-out-of-bounds in __regmap_init as follows:\n\nBUG: KASAN: slab-out-of-bounds in __regmap_init drivers/base/regmap/regmap.c:841\nRead of size 1 at addr ffff88803678cdf1 by task xrun/9137\n\nCPU: 0 PID: 9137 Comm: xrun Tainted: G W 5.18.0-rc2\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.13.0-1ubuntu1.1 04/01/2014\nCall Trace:\n \n dump_stack_lvl+0xe8/0x15a lib/dump_stack.c:88\n print_report.cold+0xcd/0x69b mm/kasan/report.c:313\n kasan_report+0x8e/0xc0 mm/kasan/report.c:491\n __regmap_init+0x4540/0x4ba0 drivers/base/regmap/regmap.c:841\n __devm_regmap_init+0x7a/0x100 drivers/base/regmap/regmap.c:1266\n __devm_regmap_init_i2c+0x65/0x80 drivers/base/regmap/regmap-i2c.c:394\n da9121_i2c_probe+0x386/0x6d1 drivers/regulator/da9121-regulator.c:1039\n i2c_device_probe+0x959/0xac0 drivers/i2c/i2c-core-base.c:563\n\nThis happend when da9121 device is probe by da9121_i2c_id, but with\ninvalid dts. Thus, chip->subvariant_id is set to -EINVAL, and later\nda9121_assign_chip_model() will access 'regmap' without init it.\n\nFix it by return -EINVAL from da9121_assign_chip_model() if\n'chip->subvariant_id' is invalid.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49507" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/60f21eda69f1b5727a97d2077da766eb27fcc21f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7da64c7c82c9b29b628a62c88a8c2fb06990563d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bab76514aca36bc513224525d5598da676938218" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/be96baa0c79588084e0d7a4fa21c574cec9a57f4" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-908" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-439f-2pm4-424q/GHSA-439f-2pm4-424q.json b/advisories/unreviewed/2025/03/GHSA-439f-2pm4-424q/GHSA-439f-2pm4-424q.json new file mode 100644 index 00000000000..a78dc419980 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-439f-2pm4-424q/GHSA-439f-2pm4-424q.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-439f-2pm4-424q", + "modified": "2025-03-17T18:31:49Z", + "published": "2025-03-17T18:31:49Z", + "aliases": [ + "CVE-2022-49449" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\npinctrl: renesas: rzn1: Fix possible null-ptr-deref in sh_pfc_map_resources()\n\nIt will cause null-ptr-deref when using 'res', if platform_get_resource()\nreturns NULL, so move using 'res' after devm_ioremap_resource() that\nwill check it to avoid null-ptr-deref.\nAnd use devm_platform_get_and_ioremap_resource() to simplify code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49449" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/01f9e02e0f13df3fd291676dc80054e977be1601" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2f661477c2bb8068194dbba9738d05219f111c6e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/34c719b8fdfbd0c7c54cae56e6b0f16e9f8bf03e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b646e0cfeb38bf5f1944fd548f1dfa9b129fa00c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c16b59d445135c8026a04e388d8b2762feaa3b3b" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-4w8m-wcw8-4mmj/GHSA-4w8m-wcw8-4mmj.json b/advisories/unreviewed/2025/03/GHSA-4w8m-wcw8-4mmj/GHSA-4w8m-wcw8-4mmj.json new file mode 100644 index 00000000000..876cb6e3b5a --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4w8m-wcw8-4mmj/GHSA-4w8m-wcw8-4mmj.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4w8m-wcw8-4mmj", + "modified": "2025-03-17T18:31:51Z", + "published": "2025-03-17T18:31:51Z", + "aliases": [ + "CVE-2022-49499" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/msm: Fix null pointer dereferences without iommu\n\nCheck if 'aspace' is set before using it as it will stay null without\nIOMMU, such as on msm8974.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49499" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/36a1d1bda77e1851bddfa9cf4e8ada94476dbaff" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f09937e80f9bc792965476c9a528f26c8fdc9179" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-547x-8cmf-v92w/GHSA-547x-8cmf-v92w.json b/advisories/unreviewed/2025/03/GHSA-547x-8cmf-v92w/GHSA-547x-8cmf-v92w.json new file mode 100644 index 00000000000..cd13a8217dd --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-547x-8cmf-v92w/GHSA-547x-8cmf-v92w.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-547x-8cmf-v92w", + "modified": "2025-03-17T18:31:47Z", + "published": "2025-03-17T18:31:47Z", + "aliases": [ + "CVE-2022-49443" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nlist: fix a data-race around ep->rdllist\n\nep_poll() first calls ep_events_available() with no lock held and checks\nif ep->rdllist is empty by list_empty_careful(), which reads\nrdllist->prev. Thus all accesses to it need some protection to avoid\nstore/load-tearing.\n\nNote INIT_LIST_HEAD_RCU() already has the annotation for both prev\nand next.\n\nCommit bf3b9f6372c4 (\"epoll: Add busy poll support to epoll with socket\nfds.\") added the first lockless ep_events_available(), and commit\nc5a282e9635e (\"fs/epoll: reduce the scope of wq lock in epoll_wait()\")\nmade some ep_events_available() calls lockless and added single call under\na lock, finally commit e59d3c64cba6 (\"epoll: eliminate unnecessary lock\nfor zero timeout\") made the last ep_events_available() lockless.\n\nBUG: KCSAN: data-race in do_epoll_wait / do_epoll_wait\n\nwrite to 0xffff88810480c7d8 of 8 bytes by task 1802 on cpu 0:\n INIT_LIST_HEAD include/linux/list.h:38 [inline]\n list_splice_init include/linux/list.h:492 [inline]\n ep_start_scan fs/eventpoll.c:622 [inline]\n ep_send_events fs/eventpoll.c:1656 [inline]\n ep_poll fs/eventpoll.c:1806 [inline]\n do_epoll_wait+0x4eb/0xf40 fs/eventpoll.c:2234\n do_epoll_pwait fs/eventpoll.c:2268 [inline]\n __do_sys_epoll_pwait fs/eventpoll.c:2281 [inline]\n __se_sys_epoll_pwait+0x12b/0x240 fs/eventpoll.c:2275\n __x64_sys_epoll_pwait+0x74/0x80 fs/eventpoll.c:2275\n do_syscall_x64 arch/x86/entry/common.c:50 [inline]\n do_syscall_64+0x44/0xd0 arch/x86/entry/common.c:80\n entry_SYSCALL_64_after_hwframe+0x44/0xae\n\nread to 0xffff88810480c7d8 of 8 bytes by task 1799 on cpu 1:\n list_empty_careful include/linux/list.h:329 [inline]\n ep_events_available fs/eventpoll.c:381 [inline]\n ep_poll fs/eventpoll.c:1797 [inline]\n do_epoll_wait+0x279/0xf40 fs/eventpoll.c:2234\n do_epoll_pwait fs/eventpoll.c:2268 [inline]\n __do_sys_epoll_pwait fs/eventpoll.c:2281 [inline]\n __se_sys_epoll_pwait+0x12b/0x240 fs/eventpoll.c:2275\n __x64_sys_epoll_pwait+0x74/0x80 fs/eventpoll.c:2275\n do_syscall_x64 arch/x86/entry/common.c:50 [inline]\n do_syscall_64+0x44/0xd0 arch/x86/entry/common.c:80\n entry_SYSCALL_64_after_hwframe+0x44/0xae\n\nvalue changed: 0xffff88810480c7d0 -> 0xffff888103c15098\n\nReported by Kernel Concurrency Sanitizer on:\nCPU: 1 PID: 1799 Comm: syz-fuzzer Tainted: G W 5.17.0-rc7-syzkaller-dirty #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49443" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5d5d993f16be15d124be7b8ec71b28ef7b7dc3af" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cb3e48f7a35033deb9455abe3932e63cb500b9eb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d679ae94fdd5d3ab00c35078f5af5f37e068b03d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e039c0b5985999b150594126225e1ee51df7b4c9" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-362" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-57m4-7g8p-fcrj/GHSA-57m4-7g8p-fcrj.json b/advisories/unreviewed/2025/03/GHSA-57m4-7g8p-fcrj/GHSA-57m4-7g8p-fcrj.json new file mode 100644 index 00000000000..0071ea0bcdc --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-57m4-7g8p-fcrj/GHSA-57m4-7g8p-fcrj.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-57m4-7g8p-fcrj", + "modified": "2025-03-17T18:31:52Z", + "published": "2025-03-17T18:31:52Z", + "aliases": [ + "CVE-2025-2386" + ], + "details": "A vulnerability was found in PHPGurukul Local Services Search Engine Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /serviceman-search.php. The manipulation of the argument location leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2386" + }, + { + "type": "WEB", + "url": "https://github.com/aionman/cve/issues/7" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.299885" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.299885" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.516546" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T17:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5mpr-r2xv-9qfh/GHSA-5mpr-r2xv-9qfh.json b/advisories/unreviewed/2025/03/GHSA-5mpr-r2xv-9qfh/GHSA-5mpr-r2xv-9qfh.json new file mode 100644 index 00000000000..a378a814d92 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5mpr-r2xv-9qfh/GHSA-5mpr-r2xv-9qfh.json @@ -0,0 +1,60 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5mpr-r2xv-9qfh", + "modified": "2025-03-17T18:31:50Z", + "published": "2025-03-17T18:31:50Z", + "aliases": [ + "CVE-2022-49467" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm: msm: fix possible memory leak in mdp5_crtc_cursor_set()\n\ndrm_gem_object_lookup will call drm_gem_object_get inside. So cursor_bo\nneeds to be put when msm_gem_get_and_pin_iova fails.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49467" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/33546183c16c7b9650682dc610bedd732d9c6919" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/449374565f349d4233beec811d4286fdfe5de44b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/656aa3c51fc662064f17179b38ec3ce43af53bca" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/947a844bb3ebff0f4736d244d792ce129f6700d7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d544880482a5558ec06393b1b3d5dc9275b7a32b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d63ffe3fb3f8327ca21cf91b6a14a2961bc629b4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f8cd192752a1f613b14eee77783c6f0aebb49691" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5wh6-378g-4ggp/GHSA-5wh6-378g-4ggp.json b/advisories/unreviewed/2025/03/GHSA-5wh6-378g-4ggp/GHSA-5wh6-378g-4ggp.json new file mode 100644 index 00000000000..1f130a52bd7 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5wh6-378g-4ggp/GHSA-5wh6-378g-4ggp.json @@ -0,0 +1,66 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5wh6-378g-4ggp", + "modified": "2025-03-17T18:31:51Z", + "published": "2025-03-17T18:31:51Z", + "aliases": [ + "CVE-2022-49481" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nregulator: pfuze100: Fix refcount leak in pfuze_parse_regulators_dt\n\nof_node_get() returns a node with refcount incremented.\nCalling of_node_put() to drop the reference when not needed anymore.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49481" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0be5d9da5743b9825a95baec85a67500b2c1d362" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/49d785baeb91568332197be356d138e5e59c7ddb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/56ab0c01027492cd161c64148e1dc892c56887ad" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/671be14fc31374b1a10a3abd93db6a8480838fc9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6ca675f4abbc74bc991d154a1ecc8b384dc2aae4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/984cfef0675ed7398814e14af2c5323911723e1c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9f564e29a51210a49df3d925117777c157a17d6d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/afaa7b933ef00a2d3262f4d1252087613fb5c06d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b74c0dd9179d21b7260260e075d597b23970100c" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6246-v5x4-r68f/GHSA-6246-v5x4-r68f.json b/advisories/unreviewed/2025/03/GHSA-6246-v5x4-r68f/GHSA-6246-v5x4-r68f.json new file mode 100644 index 00000000000..ceb0991055a --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6246-v5x4-r68f/GHSA-6246-v5x4-r68f.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6246-v5x4-r68f", + "modified": "2025-03-17T18:31:51Z", + "published": "2025-03-17T18:31:51Z", + "aliases": [ + "CVE-2022-49516" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nice: always check VF VSI pointer values\n\nThe ice_get_vf_vsi function can return NULL in some cases, such as if\nhandling messages during a reset where the VSI is being removed and\nrecreated.\n\nSeveral places throughout the driver do not bother to check whether this\nVSI pointer is valid. Static analysis tools maybe report issues because\nthey detect paths where a potentially NULL pointer could be dereferenced.\n\nFix this by checking the return value of ice_get_vf_vsi everywhere.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49516" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/baeb705fd6a7245cc1fa69ed991a9cffdf44a174" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e7be3877589d539c52e5d1d23a625f889b541b9d" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6vvr-74xr-p579/GHSA-6vvr-74xr-p579.json b/advisories/unreviewed/2025/03/GHSA-6vvr-74xr-p579/GHSA-6vvr-74xr-p579.json new file mode 100644 index 00000000000..56d034c476a --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6vvr-74xr-p579/GHSA-6vvr-74xr-p579.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6vvr-74xr-p579", + "modified": "2025-03-17T18:31:52Z", + "published": "2025-03-17T18:31:52Z", + "aliases": [ + "CVE-2024-48013" + ], + "details": "Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Execution with Unnecessary Privileges vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48013" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000289970/dsa-2025-070-security-update-for-dell-networking-os10-vulnerabilities" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000293638/dsa-2025-069-security-update-for-dell-networking-os10-vulnerabilities" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000294091/dsa-2025-079-security-update-for-dell-networking-os10-vulnerabilities" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000295014/dsa-2025-068-security-update-for-dell-networking-os10-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-250" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T17:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-7rvj-6cpm-cm89/GHSA-7rvj-6cpm-cm89.json b/advisories/unreviewed/2025/03/GHSA-7rvj-6cpm-cm89/GHSA-7rvj-6cpm-cm89.json new file mode 100644 index 00000000000..c065d5d18f3 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-7rvj-6cpm-cm89/GHSA-7rvj-6cpm-cm89.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7rvj-6cpm-cm89", + "modified": "2025-03-17T18:31:50Z", + "published": "2025-03-17T18:31:49Z", + "aliases": [ + "CVE-2022-49454" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nPCI: mediatek: Fix refcount leak in mtk_pcie_subsys_powerup()\n\nThe of_find_compatible_node() function returns a node pointer with\nrefcount incremented, We should use of_node_put() on it when done\nAdd the missing of_node_put() to release the refcount.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49454" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/09b2d906d78ddf5042b1f3e0091835fc6997e8a4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/214e0d8fe4a813ae6ffd62bc2dfe7544c20914f4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4cef4237d6c37257cb6ddc397723e9c0dded0efe" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ad1c9d13e04509ae24fae8dd2897148657323519" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-7xj2-3647-rgjf/GHSA-7xj2-3647-rgjf.json b/advisories/unreviewed/2025/03/GHSA-7xj2-3647-rgjf/GHSA-7xj2-3647-rgjf.json new file mode 100644 index 00000000000..9a285b9aefb --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-7xj2-3647-rgjf/GHSA-7xj2-3647-rgjf.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7xj2-3647-rgjf", + "modified": "2025-03-17T18:31:52Z", + "published": "2025-03-17T18:31:52Z", + "aliases": [ + "CVE-2025-22474" + ], + "details": "Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) a Server-Side Request Forgery (SSRF) vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22474" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000289970/dsa-2025-070-security-update-for-dell-networking-os10-vulnerabilities" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000293638/dsa-2025-069-security-update-for-dell-networking-os10-vulnerabilities" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000294091/dsa-2025-079-security-update-for-dell-networking-os10-vulnerabilities" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000295014/dsa-2025-068-security-update-for-dell-networking-os10-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T17:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-83q9-29r8-r4qx/GHSA-83q9-29r8-r4qx.json b/advisories/unreviewed/2025/03/GHSA-83q9-29r8-r4qx/GHSA-83q9-29r8-r4qx.json new file mode 100644 index 00000000000..413d48fce85 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-83q9-29r8-r4qx/GHSA-83q9-29r8-r4qx.json @@ -0,0 +1,66 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-83q9-29r8-r4qx", + "modified": "2025-03-17T18:31:52Z", + "published": "2025-03-17T18:31:52Z", + "aliases": [ + "CVE-2022-49514" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: mediatek: Fix error handling in mt8173_max98090_dev_probe\n\nCall of_node_put(platform_node) to avoid refcount leak in\nthe error path.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49514" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0a1901f34f775b83ea4b8dbb5ed992147b9b8531" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1e932aba3c7628c9f880ee9c2cfcc2ae3ba0c01e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/23f340ed906c758cec6527376768e3bc1474ac30" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/48889eb3cce91d7f58e02bc07277b7f724b7a54a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4f4e0454e226de3bf4efd7e7924d1edc571c52d5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/98d5afe868df998b0244f4c229ab758b4083684a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cc43b9fdca519c5b13be6a717bacbebccd628cf6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ebd5cb4f1f3f10b839e7575219e0f17b60c23113" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fb66e0512e5ccc093070e21cf88cce8d98c181b5" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-8wr8-fqcf-723v/GHSA-8wr8-fqcf-723v.json b/advisories/unreviewed/2025/03/GHSA-8wr8-fqcf-723v/GHSA-8wr8-fqcf-723v.json new file mode 100644 index 00000000000..ddfb68cd1b9 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-8wr8-fqcf-723v/GHSA-8wr8-fqcf-723v.json @@ -0,0 +1,68 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8wr8-fqcf-723v", + "modified": "2025-03-17T18:31:51Z", + "published": "2025-03-17T18:31:51Z", + "aliases": [ + "CVE-2022-49495" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/msm/hdmi: check return value after calling platform_get_resource_byname()\n\nIt will cause null-ptr-deref if platform_get_resource_byname() returns NULL,\nwe need check the return value.\n\nPatchwork: https://patchwork.freedesktop.org/patch/482992/", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49495" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0978fcce91b90b561b8c82e7c492ba9fc8440eef" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2b3ed7547b1a052209da6c4ab886ffe0eed88c42" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4cd66a8016b872a153bf892fe4258cbc0dacf5b1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6369dda4a2209142ab819f01d3d2076d81e3ebdd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9cb1ee33efccb8b107ee04b7b3441820de3fd2da" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9f5495a5c51c1d11c6ffc13aa2befffec0c2651a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a36e506711548df923ceb7ec9f6001375be799a5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c1bfacf0daf25a5fc7d667399d6ff2dffda84cd8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d9cb951d11a4ace4de5c50b1178ad211de17079e" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9262-x6ph-8rp3/GHSA-9262-x6ph-8rp3.json b/advisories/unreviewed/2025/03/GHSA-9262-x6ph-8rp3/GHSA-9262-x6ph-8rp3.json new file mode 100644 index 00000000000..e14ac5c0668 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-9262-x6ph-8rp3/GHSA-9262-x6ph-8rp3.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9262-x6ph-8rp3", + "modified": "2025-03-17T18:31:50Z", + "published": "2025-03-17T18:31:50Z", + "aliases": [ + "CVE-2022-49471" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nrtw89: cfo: check mac_id to avoid out-of-bounds\n\nSomehow, hardware reports incorrect mac_id and pollute memory. Check index\nbefore we access the array.\n\n UBSAN: array-index-out-of-bounds in rtw89/phy.c:2517:23\n index 188 is out of range for type 's32 [64]'\n CPU: 1 PID: 51550 Comm: irq/35-rtw89_pc Tainted: G OE\n Call Trace:\n \n show_stack+0x52/0x58\n dump_stack_lvl+0x4c/0x63\n dump_stack+0x10/0x12\n ubsan_epilogue+0x9/0x45\n __ubsan_handle_out_of_bounds.cold+0x44/0x49\n ? __alloc_skb+0x92/0x1d0\n rtw89_phy_cfo_parse+0x44/0x7f [rtw89_core]\n rtw89_core_rx+0x261/0x871 [rtw89_core]\n ? __alloc_skb+0xee/0x1d0\n rtw89_pci_napi_poll+0x3fa/0x4ea [rtw89_pci]\n __napi_poll+0x33/0x1a0\n net_rx_action+0x126/0x260\n ? __queue_work+0x217/0x4c0\n __do_softirq+0xd9/0x315\n ? disable_irq_nosync+0x10/0x10\n do_softirq.part.0+0x6d/0x90\n \n \n __local_bh_enable_ip+0x62/0x70\n rtw89_pci_interrupt_threadfn+0x182/0x1a6 [rtw89_pci]\n irq_thread_fn+0x28/0x60\n irq_thread+0xc8/0x190\n ? irq_thread_fn+0x60/0x60\n kthread+0x16b/0x190\n ? irq_thread_check_affinity+0xe0/0xe0\n ? set_kthread_struct+0x50/0x50\n ret_from_fork+0x22/0x30\n ", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49471" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/03ed236480aeec8c2fd327a1ea6d711364c495e3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/97df85871a5b187609d30fca6d85b912d9e02f29" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c32fafe68298bb599e825c298e1d0ba30186f0a5" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-129" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9598-v3j2-4mpr/GHSA-9598-v3j2-4mpr.json b/advisories/unreviewed/2025/03/GHSA-9598-v3j2-4mpr/GHSA-9598-v3j2-4mpr.json new file mode 100644 index 00000000000..8bb9984a25f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-9598-v3j2-4mpr/GHSA-9598-v3j2-4mpr.json @@ -0,0 +1,66 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9598-v3j2-4mpr", + "modified": "2025-03-17T18:31:49Z", + "published": "2025-03-17T18:31:49Z", + "aliases": [ + "CVE-2022-49457" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nARM: versatile: Add missing of_node_put in dcscb_init\n\nThe device_node pointer is returned by of_find_compatible_node\nwith refcount incremented. We should use of_node_put() to avoid\nthe refcount leak.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49457" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/23b44f9c649bbef10b45fa33080cd8b4166800ae" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2d7b23db35254b7d46e852967090c64cdccf24da" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3c6006faed9aba5144b33176d061031a9be66954" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/83c329b980bddbc8c6a3d287d91f2103a4d4a860" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a0fc05cd17617e63fc13ad0c01f3f0afd890d8ec" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bbdfb7d4f036118d36415a2575efa6f5246505ae" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d146e2a9864ade19914494de3fb520390b415d58" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d6de7b181c29cd4578ec139aafb5eac062abbe1b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fcd1999ba97445a12cc394f5f42ffd9116bf0185" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-972p-cf2j-j59m/GHSA-972p-cf2j-j59m.json b/advisories/unreviewed/2025/03/GHSA-972p-cf2j-j59m/GHSA-972p-cf2j-j59m.json new file mode 100644 index 00000000000..bf7361c3615 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-972p-cf2j-j59m/GHSA-972p-cf2j-j59m.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-972p-cf2j-j59m", + "modified": "2025-03-17T18:31:50Z", + "published": "2025-03-17T18:31:50Z", + "aliases": [ + "CVE-2022-49483" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/msm/disp/dpu1: avoid clearing hw interrupts if hw_intr is null during drm uninit\n\nIf edp modeset init is failed due to panel being not ready and\nprobe defers during drm bind, avoid clearing irqs and dereference\nhw_intr when hw_intr is null.\n\nBUG: Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000\n\nCall trace:\n dpu_core_irq_uninstall+0x50/0xb0\n dpu_irq_uninstall+0x18/0x24\n msm_drm_uninit+0xd8/0x16c\n msm_drm_bind+0x580/0x5fc\n try_to_bring_up_master+0x168/0x1c0\n __component_add+0xb4/0x178\n component_add+0x1c/0x28\n dp_display_probe+0x38c/0x400\n platform_probe+0xb0/0xd0\n really_probe+0xcc/0x2c8\n __driver_probe_device+0xbc/0xe8\n driver_probe_device+0x48/0xf0\n __device_attach_driver+0xa0/0xc8\n bus_for_each_drv+0x8c/0xd8\n __device_attach+0xc4/0x150\n device_initial_probe+0x1c/0x28\n\nChanges in V2:\n- Update commit message and coreect fixes tag.\n\nPatchwork: https://patchwork.freedesktop.org/patch/484430/", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49483" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/01013ba9bbddc62f7d011163cebfd7ed06bb698b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a7ca30c3a8b2e8bda65f2b922d382ac056be8aa4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a800701429313149afde18d98821554fbfcb3164" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-97v8-9w8c-8wvm/GHSA-97v8-9w8c-8wvm.json b/advisories/unreviewed/2025/03/GHSA-97v8-9w8c-8wvm/GHSA-97v8-9w8c-8wvm.json new file mode 100644 index 00000000000..c1cea8ab730 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-97v8-9w8c-8wvm/GHSA-97v8-9w8c-8wvm.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-97v8-9w8c-8wvm", + "modified": "2025-03-17T18:31:51Z", + "published": "2025-03-17T18:31:51Z", + "aliases": [ + "CVE-2022-49498" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: pcm: Check for null pointer of pointer substream before dereferencing it\n\nPointer substream is being dereferenced on the assignment of pointer card\nbefore substream is being null checked with the macro PCM_RUNTIME_CHECK.\nAlthough PCM_RUNTIME_CHECK calls BUG_ON, it still is useful to perform the\nthe pointer check before card is assigned.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49498" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/011b559be832194f992f73d6c0d5485f5925a10b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1f2e28857be1e5c7db39bbc221332215fc5467e3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7784d22f81a29df2ec57ca90d54f93a35cbcd1a2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b2421a196cb0911ea95aec1050a0b830464c8fa6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b41ef7ad9238c22aa2e142f5ce4ce1a1a0d48123" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f2c68c52898f623fe84518da4606538d193b0cca" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-998v-m47j-cqm8/GHSA-998v-m47j-cqm8.json b/advisories/unreviewed/2025/03/GHSA-998v-m47j-cqm8/GHSA-998v-m47j-cqm8.json new file mode 100644 index 00000000000..3c1d8f2dc4f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-998v-m47j-cqm8/GHSA-998v-m47j-cqm8.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-998v-m47j-cqm8", + "modified": "2025-03-17T18:31:53Z", + "published": "2025-03-17T18:31:52Z", + "aliases": [ + "CVE-2024-48017" + ], + "details": "Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48017" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000289970/dsa-2025-070-security-update-for-dell-networking-os10-vulnerabilities" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000293638/dsa-2025-069-security-update-for-dell-networking-os10-vulnerabilities" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000294091/dsa-2025-079-security-update-for-dell-networking-os10-vulnerabilities" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000295014/dsa-2025-068-security-update-for-dell-networking-os10-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T18:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9hcv-xw76-m4h6/GHSA-9hcv-xw76-m4h6.json b/advisories/unreviewed/2025/03/GHSA-9hcv-xw76-m4h6/GHSA-9hcv-xw76-m4h6.json index 098e5dcab27..ef7619946b7 100644 --- a/advisories/unreviewed/2025/03/GHSA-9hcv-xw76-m4h6/GHSA-9hcv-xw76-m4h6.json +++ b/advisories/unreviewed/2025/03/GHSA-9hcv-xw76-m4h6/GHSA-9hcv-xw76-m4h6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9hcv-xw76-m4h6", - "modified": "2025-03-15T21:30:28Z", + "modified": "2025-03-17T18:31:52Z", "published": "2025-03-14T09:34:06Z", "aliases": [ "CVE-2024-8176" @@ -27,10 +27,34 @@ "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-8176" }, + { + "type": "WEB", + "url": "https://blog.hartwork.org/posts/expat-2-7-0-released" + }, { "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2310137" }, + { + "type": "WEB", + "url": "https://bugzilla.suse.com/show_bug.cgi?id=1239618" + }, + { + "type": "WEB", + "url": "https://github.com/libexpat/libexpat/blob/R_2_7_0/expat/Changes#L40-L52" + }, + { + "type": "WEB", + "url": "https://gitlab.alpinelinux.org/alpine/aports/-/commit/d068c3ff36fc6f4789988a09c69b434db757db53" + }, + { + "type": "WEB", + "url": "https://security-tracker.debian.org/tracker/CVE-2024-8176" + }, + { + "type": "WEB", + "url": "https://ubuntu.com/security/CVE-2024-8176" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2025/03/15/1" diff --git a/advisories/unreviewed/2025/03/GHSA-9hwv-rwqx-f5cv/GHSA-9hwv-rwqx-f5cv.json b/advisories/unreviewed/2025/03/GHSA-9hwv-rwqx-f5cv/GHSA-9hwv-rwqx-f5cv.json new file mode 100644 index 00000000000..5826b12de17 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-9hwv-rwqx-f5cv/GHSA-9hwv-rwqx-f5cv.json @@ -0,0 +1,68 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9hwv-rwqx-f5cv", + "modified": "2025-03-17T18:31:51Z", + "published": "2025-03-17T18:31:51Z", + "aliases": [ + "CVE-2022-49492" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnvme-pci: fix a NULL pointer dereference in nvme_alloc_admin_tags\n\nIn nvme_alloc_admin_tags, the admin_q can be set to an error (typically\n-ENOMEM) if the blk_mq_init_queue call fails to set up the queue, which\nis checked immediately after the call. However, when we return the error\nmessage up the stack, to nvme_reset_work the error takes us to\nnvme_remove_dead_ctrl()\n nvme_dev_disable()\n nvme_suspend_queue(&dev->queues[0]).\n\nHere, we only check that the admin_q is non-NULL, rather than not\nan error or NULL, and begin quiescing a queue that never existed, leading\nto bad / NULL pointer dereference.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49492" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/54a4c1e47d1b2585e74920399455bd9abbfb2bd7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7a28556082d1fbcbc599baf1c24252dfc73efefc" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8321b17789f614414206af07e17ce4751c95dc76" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8da2b7bdb47e94bbc4062a3978c708926bcb022c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/906c81dba8ee8057523859b5e1a2479e9fd34860" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9e649471b396fa0139d53919354ce1eace9b9a24" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/af98940dd33c9f9e1beb4f71c0a39260100e2a65" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/da42761181627e9bdc37d18368b827948a583929" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f76729662650cd7bc8f8194e057af381370349a7" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9jwp-f88q-j572/GHSA-9jwp-f88q-j572.json b/advisories/unreviewed/2025/03/GHSA-9jwp-f88q-j572/GHSA-9jwp-f88q-j572.json new file mode 100644 index 00000000000..3f8bd2b4a1d --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-9jwp-f88q-j572/GHSA-9jwp-f88q-j572.json @@ -0,0 +1,60 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9jwp-f88q-j572", + "modified": "2025-03-17T18:31:51Z", + "published": "2025-03-17T18:31:51Z", + "aliases": [ + "CVE-2022-49508" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: elan: Fix potential double free in elan_input_configured\n\n'input' is a managed resource allocated with devm_input_allocate_device(),\nso there is no need to call input_free_device() explicitly or\nthere will be a double free.\n\nAccording to the doc of devm_input_allocate_device():\n * Managed input devices do not need to be explicitly unregistered or\n * freed as it will be done automatically when owner device unbinds from\n * its driver (or binding fails).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49508" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1af20714fedad238362571620be0bd690ded05b6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/24f9dfdaece9bd75bb8dbfdba83eddeefdf7dc47" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5291451851feeb66fd4bf0826710f482f3b1ab38" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6d0726725c7c560495f5ff364862a2cefea542e3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8bb1716507ebf12d50bbf181764481de3b6bc7fd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c92ec22a991778a096342cf1a917ae36c5c86a90" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f1d4f19a796551edc6679a681ea1756b8c578c08" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-415" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9x7w-p6r9-4xp9/GHSA-9x7w-p6r9-4xp9.json b/advisories/unreviewed/2025/03/GHSA-9x7w-p6r9-4xp9/GHSA-9x7w-p6r9-4xp9.json index 40ddb126d63..731ef16d401 100644 --- a/advisories/unreviewed/2025/03/GHSA-9x7w-p6r9-4xp9/GHSA-9x7w-p6r9-4xp9.json +++ b/advisories/unreviewed/2025/03/GHSA-9x7w-p6r9-4xp9/GHSA-9x7w-p6r9-4xp9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9x7w-p6r9-4xp9", - "modified": "2025-03-17T15:31:50Z", + "modified": "2025-03-17T18:31:52Z", "published": "2025-03-17T15:31:50Z", "aliases": [ "CVE-2025-25618" ], "details": "Incorrect Access Control in Unifiedtransform 2.0 leads to Privilege Escalation allowing the change of Section Name and Room Number by Teachers.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-17T15:15:44Z" diff --git a/advisories/unreviewed/2025/03/GHSA-c339-mwfc-fmr2/GHSA-c339-mwfc-fmr2.json b/advisories/unreviewed/2025/03/GHSA-c339-mwfc-fmr2/GHSA-c339-mwfc-fmr2.json new file mode 100644 index 00000000000..96c778732ce --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-c339-mwfc-fmr2/GHSA-c339-mwfc-fmr2.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c339-mwfc-fmr2", + "modified": "2025-03-17T18:31:53Z", + "published": "2025-03-17T18:31:53Z", + "aliases": [ + "CVE-2025-2241" + ], + "details": "A flaw was found in Hive, a component of Multicluster Engine (MCE) and Advanced Cluster Management (ACM). This vulnerability causes VCenter credentials to be exposed in the ClusterProvision object after provisioning a VSphere cluster. Users with read access to ClusterProvision objects can extract sensitive credentials even if they do not have direct access to Kubernetes Secrets. This issue can lead to unauthorized VCenter access, cluster management, and privilege escalation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2241" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2025-2241" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2351350" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-922" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T17:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-c56g-23r8-83xm/GHSA-c56g-23r8-83xm.json b/advisories/unreviewed/2025/03/GHSA-c56g-23r8-83xm/GHSA-c56g-23r8-83xm.json new file mode 100644 index 00000000000..7064be9ba0d --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-c56g-23r8-83xm/GHSA-c56g-23r8-83xm.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c56g-23r8-83xm", + "modified": "2025-03-17T18:31:51Z", + "published": "2025-03-17T18:31:51Z", + "aliases": [ + "CVE-2022-49497" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: remove two BUG() from skb_checksum_help()\n\nI have a syzbot report that managed to get a crash in skb_checksum_help()\n\nIf syzbot can trigger these BUG(), it makes sense to replace\nthem with more friendly WARN_ON_ONCE() since skb_checksum_help()\ncan instead return an error code.\n\nNote that syzbot will still crash there, until real bug is fixed.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49497" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/312c43e98ed190bd8fd7a71a0addf9539d5b8ab1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6320ae1b5876c30bf98203b6a5abe8b5c45e6a04" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b1320c9a4d30ff54b824a8ad6036e0b5fb4c5e73" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d5281245f3502e960cb6b89348767b935379cee3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d7ea0d9df2a6265b2b180d17ebc64b38105968fc" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-c7gr-crgh-pwcp/GHSA-c7gr-crgh-pwcp.json b/advisories/unreviewed/2025/03/GHSA-c7gr-crgh-pwcp/GHSA-c7gr-crgh-pwcp.json new file mode 100644 index 00000000000..9faaddc03fd --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-c7gr-crgh-pwcp/GHSA-c7gr-crgh-pwcp.json @@ -0,0 +1,68 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c7gr-crgh-pwcp", + "modified": "2025-03-17T18:31:47Z", + "published": "2025-03-17T18:31:46Z", + "aliases": [ + "CVE-2022-49441" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntty: fix deadlock caused by calling printk() under tty_port->lock\n\npty_write() invokes kmalloc() which may invoke a normal printk() to print\nfailure message. This can cause a deadlock in the scenario reported by\nsyz-bot below:\n\n CPU0 CPU1 CPU2\n ---- ---- ----\n lock(console_owner);\n lock(&port_lock_key);\n lock(&port->lock);\n lock(&port_lock_key);\n lock(&port->lock);\n lock(console_owner);\n\nAs commit dbdda842fe96 (\"printk: Add console owner and waiter logic to\nload balance console writes\") said, such deadlock can be prevented by\nusing printk_deferred() in kmalloc() (which is invoked in the section\nguarded by the port->lock). But there are too many printk() on the\nkmalloc() path, and kmalloc() can be called from anywhere, so changing\nprintk() to printk_deferred() is too complicated and inelegant.\n\nTherefore, this patch chooses to specify __GFP_NOWARN to kmalloc(), so\nthat printk() will not be called, and this deadlock problem can be\navoided.\n\nSyzbot reported the following lockdep error:\n\n======================================================\nWARNING: possible circular locking dependency detected\n5.4.143-00237-g08ccc19a-dirty #10 Not tainted\n------------------------------------------------------\nsyz-executor.4/29420 is trying to acquire lock:\nffffffff8aedb2a0 (console_owner){....}-{0:0}, at: console_trylock_spinning kernel/printk/printk.c:1752 [inline]\nffffffff8aedb2a0 (console_owner){....}-{0:0}, at: vprintk_emit+0x2ca/0x470 kernel/printk/printk.c:2023\n\nbut task is already holding lock:\nffff8880119c9158 (&port->lock){-.-.}-{2:2}, at: pty_write+0xf4/0x1f0 drivers/tty/pty.c:120\n\nwhich lock already depends on the new lock.\n\nthe existing dependency chain (in reverse order) is:\n\n-> #2 (&port->lock){-.-.}-{2:2}:\n __raw_spin_lock_irqsave include/linux/spinlock_api_smp.h:110 [inline]\n _raw_spin_lock_irqsave+0x35/0x50 kernel/locking/spinlock.c:159\n tty_port_tty_get drivers/tty/tty_port.c:288 [inline] \t\t<-- lock(&port->lock);\n tty_port_default_wakeup+0x1d/0xb0 drivers/tty/tty_port.c:47\n serial8250_tx_chars+0x530/0xa80 drivers/tty/serial/8250/8250_port.c:1767\n serial8250_handle_irq.part.0+0x31f/0x3d0 drivers/tty/serial/8250/8250_port.c:1854\n serial8250_handle_irq drivers/tty/serial/8250/8250_port.c:1827 [inline] \t<-- lock(&port_lock_key);\n serial8250_default_handle_irq+0xb2/0x220 drivers/tty/serial/8250/8250_port.c:1870\n serial8250_interrupt+0xfd/0x200 drivers/tty/serial/8250/8250_core.c:126\n __handle_irq_event_percpu+0x109/0xa50 kernel/irq/handle.c:156\n [...]\n\n-> #1 (&port_lock_key){-.-.}-{2:2}:\n __raw_spin_lock_irqsave include/linux/spinlock_api_smp.h:110 [inline]\n _raw_spin_lock_irqsave+0x35/0x50 kernel/locking/spinlock.c:159\n serial8250_console_write+0x184/0xa40 drivers/tty/serial/8250/8250_port.c:3198\n\t\t\t\t\t\t\t\t\t\t<-- lock(&port_lock_key);\n call_console_drivers kernel/printk/printk.c:1819 [inline]\n console_unlock+0x8cb/0xd00 kernel/printk/printk.c:2504\n vprintk_emit+0x1b5/0x470 kernel/printk/printk.c:2024\t\t\t<-- lock(console_owner);\n vprintk_func+0x8d/0x250 kernel/printk/printk_safe.c:394\n printk+0xba/0xed kernel/printk/printk.c:2084\n register_console+0x8b3/0xc10 kernel/printk/printk.c:2829\n univ8250_console_init+0x3a/0x46 drivers/tty/serial/8250/8250_core.c:681\n console_init+0x49d/0x6d3 kernel/printk/printk.c:2915\n start_kernel+0x5e9/0x879 init/main.c:713\n secondary_startup_64+0xa4/0xb0 arch/x86/kernel/head_64.S:241\n\n-> #0 (console_owner){....}-{0:0}:\n [...]\n lock_acquire+0x127/0x340 kernel/locking/lockdep.c:4734\n console_trylock_spinning kernel/printk/printk.c:1773 \n---truncated---", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49441" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/04ee31678c128a6cc7bb057ea189a8624ba5a314" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0bcf44903ef4df742dcada86ccaedd25374ffb50" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/18ca0d55e8639b911df8aae1b47598b13f9acded" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3219ac364ac3d8d30771612a6010f1e0b7fa0a28" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4af21b12a60ed2d3642284f4f85b42d7dc6ac246" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4c253caf9264d2aa47ee806a87986dd8eb91a5d9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6b9dbedbe3499fef862c4dff5217cf91f34e43b3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9834b13e8b962caa28fbcf1f422dd82413da4ede" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b3c974501d0c32258ae0e04e5cc3fb92383b40f6" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-667" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-chr8-rg8g-rv24/GHSA-chr8-rg8g-rv24.json b/advisories/unreviewed/2025/03/GHSA-chr8-rg8g-rv24/GHSA-chr8-rg8g-rv24.json new file mode 100644 index 00000000000..fdb9d0105c7 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-chr8-rg8g-rv24/GHSA-chr8-rg8g-rv24.json @@ -0,0 +1,62 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-chr8-rg8g-rv24", + "modified": "2025-03-17T18:31:51Z", + "published": "2025-03-17T18:31:51Z", + "aliases": [ + "CVE-2022-49517" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: mediatek: Fix missing of_node_put in mt2701_wm8960_machine_probe\n\nThis node pointer is returned by of_parse_phandle() with\nrefcount incremented in this function.\nCalling of_node_put() to avoid the refcount leak.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49517" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/05654431a18fe24e5e46a375d98904134628a102" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/318afb1442eeef089fe7f8a8297d97c0302ff6f6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/61a85a20e8df5e0a92cfe169c92425c7bae0753b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9345122f5fb9f97a206f440f38bb656e53f46912" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/94587aa17abf8b26f543d2b29c44abc21bc36836" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bc2afecaabd2a2c9f17e43b4793a30e3461bfb29" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c71494f5f2b444adfd992a7359a0d2a791642b39" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f279c49f17ce10866087ea6c0c57382158974b63" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-f7xm-7mw8-vghc/GHSA-f7xm-7mw8-vghc.json b/advisories/unreviewed/2025/03/GHSA-f7xm-7mw8-vghc/GHSA-f7xm-7mw8-vghc.json new file mode 100644 index 00000000000..e43ebd86d06 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-f7xm-7mw8-vghc/GHSA-f7xm-7mw8-vghc.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f7xm-7mw8-vghc", + "modified": "2025-03-17T18:31:50Z", + "published": "2025-03-17T18:31:49Z", + "aliases": [ + "CVE-2022-49461" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\namt: fix memory leak for advertisement message\n\nWhen a gateway receives an advertisement message, it extracts relay\ninformation and then it should be freed.\nBut the advertisement handler doesn't free it.\nSo, memory leak would occur.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49461" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/19bb2d57eac86a368839a92117d8a10ab7183623" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e7322da399fb86a2072f008b56f7160afa1b2051" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fe29794c3585d039fefebaa2b5a4932a627ad4fd" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-f83p-7qxr-cxpg/GHSA-f83p-7qxr-cxpg.json b/advisories/unreviewed/2025/03/GHSA-f83p-7qxr-cxpg/GHSA-f83p-7qxr-cxpg.json new file mode 100644 index 00000000000..e518583375a --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-f83p-7qxr-cxpg/GHSA-f83p-7qxr-cxpg.json @@ -0,0 +1,68 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f83p-7qxr-cxpg", + "modified": "2025-03-17T18:31:51Z", + "published": "2025-03-17T18:31:51Z", + "aliases": [ + "CVE-2022-49491" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/rockchip: vop: fix possible null-ptr-deref in vop_bind()\n\nIt will cause null-ptr-deref in resource_size(), if platform_get_resource()\nreturns NULL, move calling resource_size() after devm_ioremap_resource() that\nwill check 'res' to avoid null-ptr-deref.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49491" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3451852312303d54a003c73bd0ae39cebb960bd5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/452922955df215a417c80d09dab72bbc667a1861" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6ff986e057bf28e2f7690dad410768b2270f9453" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/769c53bb6116d0eaec0f1fe4ec4b27a74465cad1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a9b4599665e437de8a1152799c34841b799a2e1c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b54926bd558d97c888c3d2d87886f3c159d3254a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ecfa52654d0c9c333c1fe1611f47105f6bce9591" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f8c242908ad15bbd604d3bcb54961b7d454c43f8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fcd6a886443730c39170b8383411e52118aec0a3" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-fcw8-q8jr-pq38/GHSA-fcw8-q8jr-pq38.json b/advisories/unreviewed/2025/03/GHSA-fcw8-q8jr-pq38/GHSA-fcw8-q8jr-pq38.json new file mode 100644 index 00000000000..dc8b797ba1a --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-fcw8-q8jr-pq38/GHSA-fcw8-q8jr-pq38.json @@ -0,0 +1,68 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fcw8-q8jr-pq38", + "modified": "2025-03-17T18:31:49Z", + "published": "2025-03-17T18:31:49Z", + "aliases": [ + "CVE-2022-49450" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nrxrpc: Fix listen() setting the bar too high for the prealloc rings\n\nAF_RXRPC's listen() handler lets you set the backlog up to 32 (if you bump\nup the sysctl), but whilst the preallocation circular buffers have 32 slots\nin them, one of them has to be a dead slot because we're using CIRC_CNT().\n\nThis means that listen(rxrpc_sock, 32) will cause an oops when the socket\nis closed because rxrpc_service_prealloc_one() allocated one too many calls\nand rxrpc_discard_prealloc() won't then be able to get rid of them because\nit'll think the ring is empty. rxrpc_release_calls_on_socket() then tries\nto abort them, but oopses because call->peer isn't yet set.\n\nFix this by setting the maximum backlog to RXRPC_BACKLOG_MAX - 1 to match\nthe ring capacity.\n\n BUG: kernel NULL pointer dereference, address: 0000000000000086\n ...\n RIP: 0010:rxrpc_send_abort_packet+0x73/0x240 [rxrpc]\n Call Trace:\n \n ? __wake_up_common_lock+0x7a/0x90\n ? rxrpc_notify_socket+0x8e/0x140 [rxrpc]\n ? rxrpc_abort_call+0x4c/0x60 [rxrpc]\n rxrpc_release_calls_on_socket+0x107/0x1a0 [rxrpc]\n rxrpc_release+0xc9/0x1c0 [rxrpc]\n __sock_release+0x37/0xa0\n sock_close+0x11/0x20\n __fput+0x89/0x240\n task_work_run+0x59/0x90\n do_exit+0x319/0xaa0", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49450" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/369de57492c4f1a42563c5a3bd365822ca3bfc79" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4a3a78b7918bdd723d8c7c9786522ca969bffcc4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5b4826657d36c218e9f08e8d3223b0edce3de88f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/616f76498d5ddf26b997caf64a95cda3c8a55533" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/61fb38cfbb1d54d3dafd0c25752f684b3cd00b32" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/88e22159750b0d55793302eeed8ee603f5c1a95c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/91b34bf0409f43bb60453bab23c5beadd726d022" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b3a9b227d5e7467b8518160ff034ea22bb9de573" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e198f1930050e3115c80b67d9249f80f98a27c67" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-ffm8-j238-56p4/GHSA-ffm8-j238-56p4.json b/advisories/unreviewed/2025/03/GHSA-ffm8-j238-56p4/GHSA-ffm8-j238-56p4.json index 234a7e3651b..e32e028486a 100644 --- a/advisories/unreviewed/2025/03/GHSA-ffm8-j238-56p4/GHSA-ffm8-j238-56p4.json +++ b/advisories/unreviewed/2025/03/GHSA-ffm8-j238-56p4/GHSA-ffm8-j238-56p4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-ffm8-j238-56p4", - "modified": "2025-03-17T15:31:50Z", + "modified": "2025-03-17T18:31:52Z", "published": "2025-03-17T15:31:50Z", "aliases": [ "CVE-2025-25612" ], "details": "FS Inc S3150-8T2F prior to version S3150-8T2F_2.2.0D_135103 is vulnerable to Cross Site Scripting (XSS) in the Time Range Configuration functionality of the administration interface. An attacker can inject malicious JavaScript into the \"Time Range Name\" field, which is improperly sanitized. When this input is saved, it is later executed in the browser of any user accessing the affected page, including administrators, resulting in arbitrary script execution in the user's browser.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-17T15:15:43Z" diff --git a/advisories/unreviewed/2025/03/GHSA-fr3p-cqxv-rxf4/GHSA-fr3p-cqxv-rxf4.json b/advisories/unreviewed/2025/03/GHSA-fr3p-cqxv-rxf4/GHSA-fr3p-cqxv-rxf4.json new file mode 100644 index 00000000000..1de41b78050 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-fr3p-cqxv-rxf4/GHSA-fr3p-cqxv-rxf4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fr3p-cqxv-rxf4", + "modified": "2025-03-17T18:31:53Z", + "published": "2025-03-17T18:31:53Z", + "aliases": [ + "CVE-2024-48831" + ], + "details": "Dell SmartFabric OS10 Software, version(s) 10.5.6.x, contain(s) a Use of Hard-coded Password vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48831" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000295014/dsa-2025-068-security-update-for-dell-networking-os10-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-259" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T18:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-fvcj-669r-qvmx/GHSA-fvcj-669r-qvmx.json b/advisories/unreviewed/2025/03/GHSA-fvcj-669r-qvmx/GHSA-fvcj-669r-qvmx.json new file mode 100644 index 00000000000..cd606f75bd6 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-fvcj-669r-qvmx/GHSA-fvcj-669r-qvmx.json @@ -0,0 +1,66 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fvcj-669r-qvmx", + "modified": "2025-03-17T18:31:48Z", + "published": "2025-03-17T18:31:48Z", + "aliases": [ + "CVE-2022-49447" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nARM: hisi: Add missing of_node_put after of_find_compatible_node\n\nof_find_compatible_node will increment the refcount of the returned\ndevice_node. Calling of_node_put() to avoid the refcount leak", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49447" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/21a3effe446dd6dc5eed7fe897c2f9b88c9a5d6d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/45d211668d33c49d73f5213e8c2b58468108647c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/46cb7868811d025c3d29c10d18b3422db1cf20d5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9bc72e47d4630d58a840a66a869c56b29554cfe4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a3265a9440030068547a20dfee646666f3ca5278" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cafaaae4bb9ce84a2791fa29bf6907a9466c3883" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/dd4be8ecfb41a29e7c4e551b4e866157ce4a3429" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e109058165137ef42841abd989f080adfefa14fa" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f8da78b2bae1f54746647a2bb44f8bd6025c57af" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-g2fv-f8fc-6w96/GHSA-g2fv-f8fc-6w96.json b/advisories/unreviewed/2025/03/GHSA-g2fv-f8fc-6w96/GHSA-g2fv-f8fc-6w96.json new file mode 100644 index 00000000000..278c886f5d6 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-g2fv-f8fc-6w96/GHSA-g2fv-f8fc-6w96.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g2fv-f8fc-6w96", + "modified": "2025-03-17T18:31:53Z", + "published": "2025-03-17T18:31:52Z", + "aliases": [ + "CVE-2024-48015" + ], + "details": "Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48015" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000289970/dsa-2025-070-security-update-for-dell-networking-os10-vulnerabilities" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000293638/dsa-2025-069-security-update-for-dell-networking-os10-vulnerabilities" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000294091/dsa-2025-079-security-update-for-dell-networking-os10-vulnerabilities" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000295014/dsa-2025-068-security-update-for-dell-networking-os10-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T18:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-gg7j-j8vg-xr4r/GHSA-gg7j-j8vg-xr4r.json b/advisories/unreviewed/2025/03/GHSA-gg7j-j8vg-xr4r/GHSA-gg7j-j8vg-xr4r.json new file mode 100644 index 00000000000..524ab696221 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-gg7j-j8vg-xr4r/GHSA-gg7j-j8vg-xr4r.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gg7j-j8vg-xr4r", + "modified": "2025-03-17T18:31:51Z", + "published": "2025-03-17T18:31:51Z", + "aliases": [ + "CVE-2022-49487" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmtd: rawnand: intel: fix possible null-ptr-deref in ebu_nand_probe()\n\nIt will cause null-ptr-deref when using 'res', if platform_get_resource()\nreturns NULL, so move using 'res' after devm_ioremap_resource() that\nwill check it to avoid null-ptr-deref.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49487" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/daa5166450b447415aeeaac0199e445bae7bd0f2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ddf66aefd685fd46500b9917333e1b1e118276dc" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e5b1e419cdb6dd8709eb05ed34039a3ded8e6003" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f8e262eb7575a4a2412f30f7a1b293875aceba80" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-h2ww-68w4-vxxq/GHSA-h2ww-68w4-vxxq.json b/advisories/unreviewed/2025/03/GHSA-h2ww-68w4-vxxq/GHSA-h2ww-68w4-vxxq.json new file mode 100644 index 00000000000..1eaa7cb91c2 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-h2ww-68w4-vxxq/GHSA-h2ww-68w4-vxxq.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h2ww-68w4-vxxq", + "modified": "2025-03-17T18:31:50Z", + "published": "2025-03-17T18:31:50Z", + "aliases": [ + "CVE-2022-49459" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nthermal/drivers/broadcom: Fix potential NULL dereference in sr_thermal_probe\n\nplatform_get_resource() may return NULL, add proper check to\navoid potential NULL dereferencing.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49459" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/61621e042c22b47d1eadee617bdd26835294b425" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/79098339ac2065f4b4352ef5921628970b6f47e6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b3461ccaa5d2588568d865faee285512ad448049" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e20d136ec7d6f309989c447638365840d3424c8e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ee9b6b02e8c140323ed46d6602d805ea735c7719" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ef1235c6514a58f274246cf4a2d5f4e40af539ce" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-h347-fx62-m8r9/GHSA-h347-fx62-m8r9.json b/advisories/unreviewed/2025/03/GHSA-h347-fx62-m8r9/GHSA-h347-fx62-m8r9.json new file mode 100644 index 00000000000..ad8126bf3d5 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-h347-fx62-m8r9/GHSA-h347-fx62-m8r9.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h347-fx62-m8r9", + "modified": "2025-03-17T18:31:50Z", + "published": "2025-03-17T18:31:50Z", + "aliases": [ + "CVE-2022-49480" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: imx-hdmi: Fix refcount leak in imx_hdmi_probe\n\nof_find_device_by_node() takes reference, we should use put_device()\nto release it. when devm_kzalloc() fails, it doesn't have a\nput_device(), it will cause refcount leak.\nAdd missing put_device() to fix this.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49480" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/81b7edaabd44ba133006ad72056914eb36828d60" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8205a0114db10ec41bd2b748cdd7528632082eca" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cf760e494ee5fa6bc2dc222f0098c741ad460801" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ed46731d8e86c8d65f5fc717671e1f1f6c3146d2" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-h35h-f387-6vv4/GHSA-h35h-f387-6vv4.json b/advisories/unreviewed/2025/03/GHSA-h35h-f387-6vv4/GHSA-h35h-f387-6vv4.json index c523a0591ab..20b0dbd1560 100644 --- a/advisories/unreviewed/2025/03/GHSA-h35h-f387-6vv4/GHSA-h35h-f387-6vv4.json +++ b/advisories/unreviewed/2025/03/GHSA-h35h-f387-6vv4/GHSA-h35h-f387-6vv4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h35h-f387-6vv4", - "modified": "2025-03-03T15:31:33Z", + "modified": "2025-03-17T18:31:51Z", "published": "2025-03-03T15:31:33Z", "aliases": [ "CVE-2025-26918" diff --git a/advisories/unreviewed/2025/03/GHSA-h9m4-2235-4mrh/GHSA-h9m4-2235-4mrh.json b/advisories/unreviewed/2025/03/GHSA-h9m4-2235-4mrh/GHSA-h9m4-2235-4mrh.json new file mode 100644 index 00000000000..f7e7ffbb277 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-h9m4-2235-4mrh/GHSA-h9m4-2235-4mrh.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h9m4-2235-4mrh", + "modified": "2025-03-17T18:31:50Z", + "published": "2025-03-17T18:31:50Z", + "aliases": [ + "CVE-2022-49476" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmt76: mt7921: fix kernel crash at mt7921_pci_remove\n\nThe crash log shown it is possible that mt7921_irq_handler is called while\ndevm_free_irq is being handled so mt76_free_device need to be postponed\nuntil devm_free_irq is completed to solve the crash we free the mt76 device\ntoo early.\n\n[ 9299.339655] BUG: kernel NULL pointer dereference, address: 0000000000000008\n[ 9299.339705] #PF: supervisor read access in kernel mode\n[ 9299.339735] #PF: error_code(0x0000) - not-present page\n[ 9299.339768] PGD 0 P4D 0\n[ 9299.339786] Oops: 0000 [#1] SMP PTI\n[ 9299.339812] CPU: 1 PID: 1624 Comm: prepare-suspend Not tainted 5.15.14-1.fc32.qubes.x86_64 #1\n[ 9299.339863] Hardware name: Xen HVM domU, BIOS 4.14.3 01/20/2022\n[ 9299.339901] RIP: 0010:mt7921_irq_handler+0x1e/0x70 [mt7921e]\n[ 9299.340048] RSP: 0018:ffffa81b80c27cb0 EFLAGS: 00010082\n[ 9299.340081] RAX: 0000000000000000 RBX: ffff98a4cb752020 RCX: ffffffffa96211c5\n[ 9299.340123] RDX: 0000000000000000 RSI: 00000000000d4204 RDI: ffff98a4cb752020\n[ 9299.340165] RBP: ffff98a4c28a62a4 R08: ffff98a4c37a96c0 R09: 0000000080150011\n[ 9299.340207] R10: 0000000040000000 R11: 0000000000000000 R12: ffff98a4c4eaa080\n[ 9299.340249] R13: ffff98a4c28a6360 R14: ffff98a4cb752020 R15: ffff98a4c28a6228\n[ 9299.340297] FS: 00007260840d3740(0000) GS:ffff98a4ef700000(0000) knlGS:0000000000000000\n[ 9299.340345] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 9299.340383] CR2: 0000000000000008 CR3: 0000000004c56001 CR4: 0000000000770ee0\n[ 9299.340432] PKRU: 55555554\n[ 9299.340449] Call Trace:\n[ 9299.340467] \n[ 9299.340485] __free_irq+0x221/0x350\n[ 9299.340527] free_irq+0x30/0x70\n[ 9299.340553] devm_free_irq+0x55/0x80\n[ 9299.340579] mt7921_pci_remove+0x2f/0x40 [mt7921e]\n[ 9299.340616] pci_device_remove+0x3b/0xa0\n[ 9299.340651] __device_release_driver+0x17a/0x240\n[ 9299.340686] device_driver_detach+0x3c/0xa0\n[ 9299.340714] unbind_store+0x113/0x130\n[ 9299.340740] kernfs_fop_write_iter+0x124/0x1b0\n[ 9299.340775] new_sync_write+0x15c/0x1f0\n[ 9299.340806] vfs_write+0x1d2/0x270\n[ 9299.340831] ksys_write+0x67/0xe0\n[ 9299.340857] do_syscall_64+0x3b/0x90\n[ 9299.340887] entry_SYSCALL_64_after_hwframe+0x44/0xae", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49476" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/09693f5b636fb3f6dd56fd943226fc1bbc600b51" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/677e669973bf5460705bc65033445ea9f6615999" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ad483ed9dd5193a54293269c852a29051813b7bd" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hv6q-2vcj-wx97/GHSA-hv6q-2vcj-wx97.json b/advisories/unreviewed/2025/03/GHSA-hv6q-2vcj-wx97/GHSA-hv6q-2vcj-wx97.json new file mode 100644 index 00000000000..58f004a1b48 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hv6q-2vcj-wx97/GHSA-hv6q-2vcj-wx97.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hv6q-2vcj-wx97", + "modified": "2025-03-17T18:31:53Z", + "published": "2025-03-17T18:31:53Z", + "aliases": [ + "CVE-2025-2387" + ], + "details": "A vulnerability was found in SourceCodester Online Food Ordering System 2.0. It has been classified as critical. Affected is an unknown function of the file /admin/ajax.php?action=add_to_cart. The manipulation of the argument pid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2387" + }, + { + "type": "WEB", + "url": "https://github.com/aionman/cve/issues/9" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.299886" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.299886" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.516681" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T18:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hw3r-gvqg-rmwc/GHSA-hw3r-gvqg-rmwc.json b/advisories/unreviewed/2025/03/GHSA-hw3r-gvqg-rmwc/GHSA-hw3r-gvqg-rmwc.json new file mode 100644 index 00000000000..faee92ec6f6 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hw3r-gvqg-rmwc/GHSA-hw3r-gvqg-rmwc.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hw3r-gvqg-rmwc", + "modified": "2025-03-17T18:31:51Z", + "published": "2025-03-17T18:31:50Z", + "aliases": [ + "CVE-2022-49473" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: ti: j721e-evm: Fix refcount leak in j721e_soc_probe_*\n\nof_parse_phandle() returns a node pointer with refcount\nincremented, we should use of_node_put() on it when not needed anymore.\nAdd missing of_node_put() to avoid refcount leak.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49473" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2a3966b950b37a6f10c5f9caee15b4cdcf5a7413" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/510e879420b410d88c612aecc6ca15dc6fe77473" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/554df0f70bff1ace6d2df2fcaddbc9b7bd509de2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a34840c4eb3278a7c29c9c57a65ce7541c66f9f2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d748ff8fbb3a5296bddd586445dc692b079cbe3d" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hx56-4qgw-5q6r/GHSA-hx56-4qgw-5q6r.json b/advisories/unreviewed/2025/03/GHSA-hx56-4qgw-5q6r/GHSA-hx56-4qgw-5q6r.json new file mode 100644 index 00000000000..2abf049905a --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hx56-4qgw-5q6r/GHSA-hx56-4qgw-5q6r.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hx56-4qgw-5q6r", + "modified": "2025-03-17T18:31:52Z", + "published": "2025-03-17T18:31:52Z", + "aliases": [ + "CVE-2025-25685" + ], + "details": "An issue was discovered in GL-INet Beryl AX GL-MT3000 v4.7.0. Attackers are able to download arbitrary files from the device's file system via adding symbolic links on an external drive used as a samba share.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25685" + }, + { + "type": "WEB", + "url": "https://medium.com/@tfortinsec/multiple-path-traversal-vulnerabilities-in-the-beryl-ax-gl-mt300-router-e7f856d14af9" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T17:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jgh8-6hmw-5f93/GHSA-jgh8-6hmw-5f93.json b/advisories/unreviewed/2025/03/GHSA-jgh8-6hmw-5f93/GHSA-jgh8-6hmw-5f93.json new file mode 100644 index 00000000000..abf47e7d763 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-jgh8-6hmw-5f93/GHSA-jgh8-6hmw-5f93.json @@ -0,0 +1,68 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jgh8-6hmw-5f93", + "modified": "2025-03-17T18:31:50Z", + "published": "2025-03-17T18:31:50Z", + "aliases": [ + "CVE-2022-49478" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: pvrusb2: fix array-index-out-of-bounds in pvr2_i2c_core_init\n\nSyzbot reported that -1 is used as array index. The problem was in\nmissing validation check.\n\nhdw->unit_number is initialized with -1 and then if init table walk fails\nthis value remains unchanged. Since code blindly uses this member for\narray indexing adding sanity check is the easiest fix for that.\n\nhdw->workpoll initialization moved upper to prevent warning in\n__flush_work.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49478" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1310fc3538dcc375a2f46ef0a438512c2ca32827" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/24e807541e4a9263ed928e6ae3498de3ad43bd1e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2e004fe914b243db41fa96f9e583385f360ea58e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3309c2c574e13b21b44729f5bdbf21f60189b79a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4351bfe36aba9fa7dc9d68d498d25d41a0f45e67" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/471bec68457aaf981add77b4f590d65dd7da1059" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a3304766d9384886e6d3092c776273526947a2e9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a3660e06675bccec4bf149c7229ea1d491ba10d7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f99a8b1ec0eddc2931aeaa4f490277a15b39f511" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-129" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jh5p-2xj5-gpc8/GHSA-jh5p-2xj5-gpc8.json b/advisories/unreviewed/2025/03/GHSA-jh5p-2xj5-gpc8/GHSA-jh5p-2xj5-gpc8.json index 529a452ecdb..3d2abbe4041 100644 --- a/advisories/unreviewed/2025/03/GHSA-jh5p-2xj5-gpc8/GHSA-jh5p-2xj5-gpc8.json +++ b/advisories/unreviewed/2025/03/GHSA-jh5p-2xj5-gpc8/GHSA-jh5p-2xj5-gpc8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jh5p-2xj5-gpc8", - "modified": "2025-03-16T06:30:24Z", + "modified": "2025-03-17T18:31:52Z", "published": "2025-03-16T06:30:24Z", "aliases": [ "CVE-2025-1624" ], "details": "The GDPR Cookie Compliance WordPress plugin before 4.15.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-16T06:15:13Z" diff --git a/advisories/unreviewed/2025/03/GHSA-jpj2-8x9f-59j6/GHSA-jpj2-8x9f-59j6.json b/advisories/unreviewed/2025/03/GHSA-jpj2-8x9f-59j6/GHSA-jpj2-8x9f-59j6.json new file mode 100644 index 00000000000..343f3724efc --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-jpj2-8x9f-59j6/GHSA-jpj2-8x9f-59j6.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jpj2-8x9f-59j6", + "modified": "2025-03-17T18:31:49Z", + "published": "2025-03-17T18:31:49Z", + "aliases": [ + "CVE-2022-49455" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmisc: ocxl: fix possible double free in ocxl_file_register_afu\n\ninfo_release() will be called in device_unregister() when info->dev's\nreference count is 0. So there is no need to call ocxl_afu_put() and\nkfree() again.\n\nFix this by adding free_minor() and return to err_unregister error path.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49455" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/252768d32e92c1214aeebb5fec0844ca479bcf5c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8fb674216835e1f0c143762696d645facebb4685" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/950cf957fe34d40d63dfa3bf3968210430b6491e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9e9087cf34ee69f4e95d146ac29385d6e367a97b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/de65c32ace9aa70d51facc61ba986607075e3a25" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ee89d8dee55ab4b3b8ad8b70866b2841ba334767" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-415" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jw2v-8hv4-c26w/GHSA-jw2v-8hv4-c26w.json b/advisories/unreviewed/2025/03/GHSA-jw2v-8hv4-c26w/GHSA-jw2v-8hv4-c26w.json new file mode 100644 index 00000000000..1f7e4f4c67c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-jw2v-8hv4-c26w/GHSA-jw2v-8hv4-c26w.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jw2v-8hv4-c26w", + "modified": "2025-03-17T18:31:52Z", + "published": "2025-03-17T18:31:52Z", + "aliases": [ + "CVE-2024-48830" + ], + "details": "Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48830" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000289970/dsa-2025-070-security-update-for-dell-networking-os10-vulnerabilities" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000293638/dsa-2025-069-security-update-for-dell-networking-os10-vulnerabilities" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000294091/dsa-2025-079-security-update-for-dell-networking-os10-vulnerabilities" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000295014/dsa-2025-068-security-update-for-dell-networking-os10-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T17:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-m2qv-9v9x-x3fp/GHSA-m2qv-9v9x-x3fp.json b/advisories/unreviewed/2025/03/GHSA-m2qv-9v9x-x3fp/GHSA-m2qv-9v9x-x3fp.json new file mode 100644 index 00000000000..00905bd5ce7 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-m2qv-9v9x-x3fp/GHSA-m2qv-9v9x-x3fp.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m2qv-9v9x-x3fp", + "modified": "2025-03-17T18:31:50Z", + "published": "2025-03-17T18:31:50Z", + "aliases": [ + "CVE-2022-49484" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmt76: mt7915: fix possible NULL pointer dereference in mt7915_mac_fill_rx_vector\n\nFix possible NULL pointer dereference in mt7915_mac_fill_rx_vector\nroutine if the chip does not support dbdc and the hw reports band_idx\nset to 1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49484" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/268e8ef187eb8780d021b0e4f5ffa92dee5c4983" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/62fdc974894eec80d678523458cf99bbdb887e22" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-m4xp-3x5f-vcrx/GHSA-m4xp-3x5f-vcrx.json b/advisories/unreviewed/2025/03/GHSA-m4xp-3x5f-vcrx/GHSA-m4xp-3x5f-vcrx.json new file mode 100644 index 00000000000..b0bc6f095b3 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-m4xp-3x5f-vcrx/GHSA-m4xp-3x5f-vcrx.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m4xp-3x5f-vcrx", + "modified": "2025-03-17T18:31:52Z", + "published": "2025-03-17T18:31:52Z", + "aliases": [ + "CVE-2025-29431" + ], + "details": "Code-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting (XSS) in /pages/department.php via the id, code, and name parameters.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29431" + }, + { + "type": "WEB", + "url": "https://github.com/872323857/CVE/blob/main/Online%20Class%20and%20Exam%20Scheduling%20System-department.php.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T17:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-mmcw-cwf5-8442/GHSA-mmcw-cwf5-8442.json b/advisories/unreviewed/2025/03/GHSA-mmcw-cwf5-8442/GHSA-mmcw-cwf5-8442.json index 057b3fd53e8..c547ca3e068 100644 --- a/advisories/unreviewed/2025/03/GHSA-mmcw-cwf5-8442/GHSA-mmcw-cwf5-8442.json +++ b/advisories/unreviewed/2025/03/GHSA-mmcw-cwf5-8442/GHSA-mmcw-cwf5-8442.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mmcw-cwf5-8442", - "modified": "2025-03-16T06:30:24Z", + "modified": "2025-03-17T18:31:52Z", "published": "2025-03-16T06:30:24Z", "aliases": [ "CVE-2025-1623" ], "details": "The GDPR Cookie Compliance WordPress plugin before 4.15.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-16T06:15:13Z" diff --git a/advisories/unreviewed/2025/03/GHSA-mvp7-6jpm-fhmr/GHSA-mvp7-6jpm-fhmr.json b/advisories/unreviewed/2025/03/GHSA-mvp7-6jpm-fhmr/GHSA-mvp7-6jpm-fhmr.json new file mode 100644 index 00000000000..9fa70e07b00 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-mvp7-6jpm-fhmr/GHSA-mvp7-6jpm-fhmr.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mvp7-6jpm-fhmr", + "modified": "2025-03-17T18:31:51Z", + "published": "2025-03-17T18:31:51Z", + "aliases": [ + "CVE-2022-49510" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/omap: fix NULL but dereferenced coccicheck error\n\nFix the following coccicheck warning:\n./drivers/gpu/drm/omapdrm/omap_overlay.c:89:22-25: ERROR: r_ovl is NULL\nbut dereferenced.\n\nHere should be ovl->idx rather than r_ovl->idx.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49510" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/08d9a75eab594ca508a440db7c73064498d26687" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8f2a3970c969d0d8d7289a4c65edcedafc16fd92" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d2507be660310bb9bcca918f81f49b8bba07e462" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-mwxh-v66f-wcq5/GHSA-mwxh-v66f-wcq5.json b/advisories/unreviewed/2025/03/GHSA-mwxh-v66f-wcq5/GHSA-mwxh-v66f-wcq5.json index baaa857a1a6..f5cfb0f819c 100644 --- a/advisories/unreviewed/2025/03/GHSA-mwxh-v66f-wcq5/GHSA-mwxh-v66f-wcq5.json +++ b/advisories/unreviewed/2025/03/GHSA-mwxh-v66f-wcq5/GHSA-mwxh-v66f-wcq5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mwxh-v66f-wcq5", - "modified": "2025-03-17T15:31:50Z", + "modified": "2025-03-17T18:31:52Z", "published": "2025-03-17T15:31:50Z", "aliases": [ "CVE-2025-25621" ], "details": "Unifiedtransform 2.0 is vulnerable to Incorrect Access Control, which allows teachers to take attendance of fellow teachers. This affected endpoint is /courses/teacher/index?teacher_id=2&semester_id=1.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-17T15:15:44Z" diff --git a/advisories/unreviewed/2025/03/GHSA-p345-p4c5-jq38/GHSA-p345-p4c5-jq38.json b/advisories/unreviewed/2025/03/GHSA-p345-p4c5-jq38/GHSA-p345-p4c5-jq38.json new file mode 100644 index 00000000000..a634f199877 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-p345-p4c5-jq38/GHSA-p345-p4c5-jq38.json @@ -0,0 +1,66 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p345-p4c5-jq38", + "modified": "2025-03-17T18:31:51Z", + "published": "2025-03-17T18:31:50Z", + "aliases": [ + "CVE-2022-49482" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: mxs-saif: Fix refcount leak in mxs_saif_probe\n\nof_parse_phandle() returns a node pointer with refcount\nincremented, we should use of_node_put() on it when done.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49482" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/18b907ff0ae4bf20120aae1538f7156b9d08e3a7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/24491124406666bf0dcb9ee10c5575c6ce6a1730" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2a0da7641e1f17a744ac7b3f76471388c97b63dc" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2be84f73785fa9ed6443e3c5b158730266f1c2ee" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/30d110ca703ce60162ec337aa564a3e4da30715f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4e2a1bcc51bdebed48176f6e88c150f175983f9c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c933829cbf3338b684869e6c4c8931abf5d68fbd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d42601e93fce7802bb8d70dd59b60cfeefa20469" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d855505851ee8ba666eb204149b49f906130dc17" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-p44j-49f8-cp36/GHSA-p44j-49f8-cp36.json b/advisories/unreviewed/2025/03/GHSA-p44j-49f8-cp36/GHSA-p44j-49f8-cp36.json new file mode 100644 index 00000000000..233bf8e87f4 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-p44j-49f8-cp36/GHSA-p44j-49f8-cp36.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p44j-49f8-cp36", + "modified": "2025-03-17T18:31:51Z", + "published": "2025-03-17T18:31:51Z", + "aliases": [ + "CVE-2022-49502" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: rga: fix possible memory leak in rga_probe\n\nrga->m2m_dev needs to be freed when rga_probe fails.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49502" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1cdc768468c25d6b10ab83ec1efd4a8554532d69" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8ddc89437ccefa18279918c19a61fd81527f40b9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a71eb6025305192e646040cd76ccacb5bd48a1b5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b7bbca4d08471bc8404a946bab1aa017dd05199b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/eeb4819e94aa69767b9e5591e70c63e8b7c5786a" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-p4v4-q7w4-pw4w/GHSA-p4v4-q7w4-pw4w.json b/advisories/unreviewed/2025/03/GHSA-p4v4-q7w4-pw4w/GHSA-p4v4-q7w4-pw4w.json new file mode 100644 index 00000000000..612072b8d0f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-p4v4-q7w4-pw4w/GHSA-p4v4-q7w4-pw4w.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p4v4-q7w4-pw4w", + "modified": "2025-03-17T18:31:51Z", + "published": "2025-03-17T18:31:51Z", + "aliases": [ + "CVE-2022-49496" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: mediatek: vcodec: prevent kernel crash when rmmod mtk-vcodec-dec.ko\n\nIf the driver support subdev mode, the parameter \"dev->pm.dev\" will be\nNULL in mtk_vcodec_dec_remove. Kernel will crash when try to rmmod\nmtk-vcodec-dec.ko.\n\n[ 4380.702726] pc : do_raw_spin_trylock+0x4/0x80\n[ 4380.707075] lr : _raw_spin_lock_irq+0x90/0x14c\n[ 4380.711509] sp : ffff80000819bc10\n[ 4380.714811] x29: ffff80000819bc10 x28: ffff3600c03e4000 x27: 0000000000000000\n[ 4380.721934] x26: 0000000000000000 x25: 0000000000000000 x24: 0000000000000000\n[ 4380.729057] x23: ffff3600c0f34930 x22: ffffd5e923549000 x21: 0000000000000220\n[ 4380.736179] x20: 0000000000000208 x19: ffffd5e9213e8ebc x18: 0000000000000020\n[ 4380.743298] x17: 0000002000000000 x16: ffffd5e9213e8e90 x15: 696c346f65646976\n[ 4380.750420] x14: 0000000000000000 x13: 0000000000000001 x12: 0000000000000040\n[ 4380.757542] x11: 0000000000000000 x10: 0000000000000000 x9 : 0000000000000000\n[ 4380.764664] x8 : 0000000000000000 x7 : ffff3600c7273ae8 x6 : ffffd5e9213e8ebc\n[ 4380.771786] x5 : 0000000000000000 x4 : 0000000000000001 x3 : 0000000000000000\n[ 4380.778908] x2 : 0000000000000000 x1 : ffff3600c03e4000 x0 : 0000000000000208\n[ 4380.786031] Call trace:\n[ 4380.788465] do_raw_spin_trylock+0x4/0x80\n[ 4380.792462] __pm_runtime_disable+0x2c/0x1b0\n[ 4380.796723] mtk_vcodec_dec_remove+0x5c/0xa0 [mtk_vcodec_dec]\n[ 4380.802466] platform_remove+0x2c/0x60\n[ 4380.806204] __device_release_driver+0x194/0x250\n[ 4380.810810] driver_detach+0xc8/0x15c\n[ 4380.814462] bus_remove_driver+0x5c/0xb0\n[ 4380.818375] driver_unregister+0x34/0x64\n[ 4380.822288] platform_driver_unregister+0x18/0x24\n[ 4380.826979] mtk_vcodec_dec_driver_exit+0x1c/0x888 [mtk_vcodec_dec]\n[ 4380.833240] __arm64_sys_delete_module+0x190/0x224\n[ 4380.838020] invoke_syscall+0x48/0x114\n[ 4380.841760] el0_svc_common.constprop.0+0x60/0x11c\n[ 4380.846540] do_el0_svc+0x28/0x90\n[ 4380.849844] el0_svc+0x4c/0x100\n[ 4380.852975] el0t_64_sync_handler+0xec/0xf0\n[ 4380.857148] el0t_64_sync+0x190/0x194\n[ 4380.860801] Code: 94431515 17ffffca d503201f d503245f (b9400004)", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49496" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1fa37b00dc55a061a3eb82e378849862b4aeca9d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c10c0086db688c95bb4e0e378e523818dff1551d" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-667" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-p4vm-8rvv-j5fx/GHSA-p4vm-8rvv-j5fx.json b/advisories/unreviewed/2025/03/GHSA-p4vm-8rvv-j5fx/GHSA-p4vm-8rvv-j5fx.json new file mode 100644 index 00000000000..ec0ff357179 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-p4vm-8rvv-j5fx/GHSA-p4vm-8rvv-j5fx.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p4vm-8rvv-j5fx", + "modified": "2025-03-17T18:31:53Z", + "published": "2025-03-17T18:31:53Z", + "aliases": [ + "CVE-2024-49559" + ], + "details": "Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Use of Default Password vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49559" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000289970/dsa-2025-070-security-update-for-dell-networking-os10-vulnerabilities" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000293638/dsa-2025-069-security-update-for-dell-networking-os10-vulnerabilities" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000294091/dsa-2025-079-security-update-for-dell-networking-os10-vulnerabilities" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000295014/dsa-2025-068-security-update-for-dell-networking-os10-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1393" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T18:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-pwf4-m8pj-j567/GHSA-pwf4-m8pj-j567.json b/advisories/unreviewed/2025/03/GHSA-pwf4-m8pj-j567/GHSA-pwf4-m8pj-j567.json new file mode 100644 index 00000000000..db240c11de2 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-pwf4-m8pj-j567/GHSA-pwf4-m8pj-j567.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pwf4-m8pj-j567", + "modified": "2025-03-17T18:31:53Z", + "published": "2025-03-17T18:31:53Z", + "aliases": [ + "CVE-2025-2388" + ], + "details": "A vulnerability was found in Keytop 路内停车收费系统 2.7.1. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /saas/commonApi/park/getParks of the component API. The manipulation leads to improper authentication. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2388" + }, + { + "type": "WEB", + "url": "https://github.com/K-mxredo/MXdocument/wiki" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.299887" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.299887" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.516710" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T18:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-q4fr-fxrh-m96v/GHSA-q4fr-fxrh-m96v.json b/advisories/unreviewed/2025/03/GHSA-q4fr-fxrh-m96v/GHSA-q4fr-fxrh-m96v.json new file mode 100644 index 00000000000..9ad7aab4a93 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-q4fr-fxrh-m96v/GHSA-q4fr-fxrh-m96v.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q4fr-fxrh-m96v", + "modified": "2025-03-17T18:31:52Z", + "published": "2025-03-17T18:31:52Z", + "aliases": [ + "CVE-2025-2384" + ], + "details": "A vulnerability, which was classified as critical, was found in code-projects Real Estate Property Management System 1.0. This affects an unknown part of the file /InsertCustomer.php of the component Parameter Handler. The manipulation of the argument txtName/txtAddress/cmbCity/txtEmail/cmbGender/txtBirthDate/txtUserName2/txtPassword2 leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2384" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://github.com/yiijiayan/cve/blob/main/sql-cve.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.299883" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.299883" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.516282" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T16:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-qcff-4j87-mv7g/GHSA-qcff-4j87-mv7g.json b/advisories/unreviewed/2025/03/GHSA-qcff-4j87-mv7g/GHSA-qcff-4j87-mv7g.json new file mode 100644 index 00000000000..32efe2c5743 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-qcff-4j87-mv7g/GHSA-qcff-4j87-mv7g.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qcff-4j87-mv7g", + "modified": "2025-03-17T18:31:47Z", + "published": "2025-03-17T18:31:47Z", + "aliases": [ + "CVE-2022-49445" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\npinctrl: renesas: core: Fix possible null-ptr-deref in sh_pfc_map_resources()\n\nIt will cause null-ptr-deref when using 'res', if platform_get_resource()\nreturns NULL, so move using 'res' after devm_ioremap_resource() that\nwill check it to avoid null-ptr-deref.\nAnd use devm_platform_get_and_ioremap_resource() to simplify code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49445" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5376e3d904532e657fd7ca1a9b1ff3d351527b90" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5ed0519d425619b435150372cce2ffeec71581fa" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e3a1ad8fd0ac11f4fa1260c23b5db71a25473254" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f991879762392c19661af5b722578089a12b305f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fb4f022b3ad1f3ff3cafdbc7d51896090ae17701" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-qh4r-rffh-prr5/GHSA-qh4r-rffh-prr5.json b/advisories/unreviewed/2025/03/GHSA-qh4r-rffh-prr5/GHSA-qh4r-rffh-prr5.json new file mode 100644 index 00000000000..77979a71dc9 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-qh4r-rffh-prr5/GHSA-qh4r-rffh-prr5.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qh4r-rffh-prr5", + "modified": "2025-03-17T18:31:53Z", + "published": "2025-03-17T18:31:53Z", + "aliases": [ + "CVE-2025-29430" + ], + "details": "Code-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting (XSS) in /pages/room.php via the id and rome parameters.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29430" + }, + { + "type": "WEB", + "url": "https://github.com/872323857/CVE/blob/main/Online%20Class%20and%20Exam%20Scheduling%20System-room.php.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T18:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-qjx4-5xpx-3mfc/GHSA-qjx4-5xpx-3mfc.json b/advisories/unreviewed/2025/03/GHSA-qjx4-5xpx-3mfc/GHSA-qjx4-5xpx-3mfc.json index cd5ecb10285..7d94ccd549a 100644 --- a/advisories/unreviewed/2025/03/GHSA-qjx4-5xpx-3mfc/GHSA-qjx4-5xpx-3mfc.json +++ b/advisories/unreviewed/2025/03/GHSA-qjx4-5xpx-3mfc/GHSA-qjx4-5xpx-3mfc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qjx4-5xpx-3mfc", - "modified": "2025-03-16T06:30:23Z", + "modified": "2025-03-17T18:31:52Z", "published": "2025-03-16T06:30:23Z", "aliases": [ "CVE-2024-13602" ], "details": "The Poll Maker WordPress plugin before 5.5.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-16T06:15:12Z" diff --git a/advisories/unreviewed/2025/03/GHSA-qvqc-gf26-cfg3/GHSA-qvqc-gf26-cfg3.json b/advisories/unreviewed/2025/03/GHSA-qvqc-gf26-cfg3/GHSA-qvqc-gf26-cfg3.json new file mode 100644 index 00000000000..194fd55b660 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-qvqc-gf26-cfg3/GHSA-qvqc-gf26-cfg3.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qvqc-gf26-cfg3", + "modified": "2025-03-17T18:31:51Z", + "published": "2025-03-17T18:31:51Z", + "aliases": [ + "CVE-2022-49486" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: fsl: Fix refcount leak in imx_sgtl5000_probe\n\nof_find_i2c_device_by_node() takes a reference,\nIn error paths, we should call put_device() to drop\nthe reference to aviod refount leak.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49486" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/41cd312dfe980af869c3503b4d38e62ed20dd3b7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4bfbbfdb3d761323127a67d7d765abe2f77d7b21" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7f75e9f629ef54a0845b43889d8ab9dd6e280dd5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/922bccdb1796a9e7b989f2bc6d9ada7b499a4329" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/96fc3da6184af5687e153d420cd7dcdeefdd2f9a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e84aaf23ca82753d765bf84d05295d9d9c5fed29" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-r33j-vf7v-cq2v/GHSA-r33j-vf7v-cq2v.json b/advisories/unreviewed/2025/03/GHSA-r33j-vf7v-cq2v/GHSA-r33j-vf7v-cq2v.json new file mode 100644 index 00000000000..20e34850eac --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-r33j-vf7v-cq2v/GHSA-r33j-vf7v-cq2v.json @@ -0,0 +1,64 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r33j-vf7v-cq2v", + "modified": "2025-03-17T18:31:50Z", + "published": "2025-03-17T18:31:50Z", + "aliases": [ + "CVE-2022-49472" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: phy: micrel: Allow probing without .driver_data\n\nCurrently, if the .probe element is present in the phy_driver structure\nand the .driver_data is not, a NULL pointer dereference happens.\n\nAllow passing .probe without .driver_data by inserting NULL checks\nfor priv->type.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49472" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/143878e18001c5a61fcc7ae5c5240323753bb641" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1e5fbfc2a6f384e3195446c14bbd3bc298eb88c2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/660dfa033ccc9afb032015b6dc76e846bba42cfb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7dcb404662839a4ed1a9703658fee979eb894ca4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/91e720b32cba25fa58eaa4c88fe957009cffe9f3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/abb5594ae2ba7b82cce85917cc6337ec5d774837" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bd219273b4e004a3f853da72e111fc8f81357501" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f2ef6f7539c68c6bd6c32323d8845ee102b7c450" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-r4vm-xmvg-644h/GHSA-r4vm-xmvg-644h.json b/advisories/unreviewed/2025/03/GHSA-r4vm-xmvg-644h/GHSA-r4vm-xmvg-644h.json index bc839d493bb..f91822a26df 100644 --- a/advisories/unreviewed/2025/03/GHSA-r4vm-xmvg-644h/GHSA-r4vm-xmvg-644h.json +++ b/advisories/unreviewed/2025/03/GHSA-r4vm-xmvg-644h/GHSA-r4vm-xmvg-644h.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-r4vm-xmvg-644h", - "modified": "2025-03-17T15:31:50Z", + "modified": "2025-03-17T18:31:52Z", "published": "2025-03-17T15:31:50Z", "aliases": [ "CVE-2025-26127" ], "details": "A stored cross-site scripting (XSS) vulnerability in the Send for Approval function of FileCloud v23.241.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-17T15:15:44Z" diff --git a/advisories/unreviewed/2025/03/GHSA-r8c7-cxqw-v5hj/GHSA-r8c7-cxqw-v5hj.json b/advisories/unreviewed/2025/03/GHSA-r8c7-cxqw-v5hj/GHSA-r8c7-cxqw-v5hj.json new file mode 100644 index 00000000000..8e903d59bc7 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-r8c7-cxqw-v5hj/GHSA-r8c7-cxqw-v5hj.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r8c7-cxqw-v5hj", + "modified": "2025-03-17T18:31:51Z", + "published": "2025-03-17T18:31:51Z", + "aliases": [ + "CVE-2022-49494" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmtd: rawnand: cadence: fix possible null-ptr-deref in cadence_nand_dt_probe()\n\nIt will cause null-ptr-deref when using 'res', if platform_get_resource()\nreturns NULL, so move using 'res' after devm_ioremap_resource() that\nwill check it to avoid null-ptr-deref.\nAnd use devm_platform_get_and_ioremap_resource() to simplify code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49494" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/069af5e27c1b0f7677ef76d8d3102e503ca4f80b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0cfee868b89ffa945f3d535ee5c985cb40c5a0f8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/13b60d3dc84b47307669edb66b633b18466014b4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/81f1ddffdc22ca5789e33b9d4712914e302090c1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a28ed09dafee20da51eb26452950839633afd824" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-rmhf-8c8c-36j6/GHSA-rmhf-8c8c-36j6.json b/advisories/unreviewed/2025/03/GHSA-rmhf-8c8c-36j6/GHSA-rmhf-8c8c-36j6.json new file mode 100644 index 00000000000..675b176bd3b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-rmhf-8c8c-36j6/GHSA-rmhf-8c8c-36j6.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rmhf-8c8c-36j6", + "modified": "2025-03-17T18:31:52Z", + "published": "2025-03-17T18:31:52Z", + "aliases": [ + "CVE-2025-30143" + ], + "details": "Rule 3000216 (before version 2) in Akamai App & API Protector (with Akamai ASE) before 2024-12-10 does not properly consider JavaScript variable assignment to built-in functions and properties.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30143" + }, + { + "type": "WEB", + "url": "https://github.com/geo-chen/Akamai/blob/main/README.md#cve-2025-30143---waf-bypass-in-akamai-ase-application-security-edge-due-to-obfuscated-payload-leading-to-reflected-xss" + }, + { + "type": "WEB", + "url": "https://techdocs.akamai.com/app-api-protector/changelog/dec-9-2024-waf-rule-updates" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T16:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-v3p2-rq9p-452w/GHSA-v3p2-rq9p-452w.json b/advisories/unreviewed/2025/03/GHSA-v3p2-rq9p-452w/GHSA-v3p2-rq9p-452w.json new file mode 100644 index 00000000000..e797a523010 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-v3p2-rq9p-452w/GHSA-v3p2-rq9p-452w.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v3p2-rq9p-452w", + "modified": "2025-03-17T18:31:49Z", + "published": "2025-03-17T18:31:49Z", + "aliases": [ + "CVE-2022-49462" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/msm/a6xx: Fix refcount leak in a6xx_gpu_init\n\nof_parse_phandle() returns a node pointer with refcount\nincremented, we should use of_node_put() on it when not need anymore.\n\na6xx_gmu_init() passes the node to of_find_device_by_node()\nand of_dma_configure(), of_find_device_by_node() will takes its\nreference, of_dma_configure() doesn't need the node after usage.\n\nAdd missing of_node_put() to avoid refcount leak.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49462" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/06907a374f1b74f8f2fb30720dc6df81331e4fb5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/48e82ce8cdb19c20a5020fa446b286d6a147450c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/65ddbc0d26824e2a5d6154d01d8cf39344900213" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6832e36f156ea35a6ed74bca72727806116effdd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c56de483093d7ad0782327f95dda7da97bc4c315" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/edff4c1af831d0c02e654eed9da7d74174de49d5" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-vjr9-vrjv-2g4h/GHSA-vjr9-vrjv-2g4h.json b/advisories/unreviewed/2025/03/GHSA-vjr9-vrjv-2g4h/GHSA-vjr9-vrjv-2g4h.json new file mode 100644 index 00000000000..32213a1f371 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-vjr9-vrjv-2g4h/GHSA-vjr9-vrjv-2g4h.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vjr9-vrjv-2g4h", + "modified": "2025-03-17T18:31:53Z", + "published": "2025-03-17T18:31:53Z", + "aliases": [ + "CVE-2025-22473" + ], + "details": "Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22473" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000289970/dsa-2025-070-security-update-for-dell-networking-os10-vulnerabilities" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000293638/dsa-2025-069-security-update-for-dell-networking-os10-vulnerabilities" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000294091/dsa-2025-079-security-update-for-dell-networking-os10-vulnerabilities" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000295014/dsa-2025-068-security-update-for-dell-networking-os10-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T18:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-w277-7jfc-fqc3/GHSA-w277-7jfc-fqc3.json b/advisories/unreviewed/2025/03/GHSA-w277-7jfc-fqc3/GHSA-w277-7jfc-fqc3.json new file mode 100644 index 00000000000..4f7667e31a3 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-w277-7jfc-fqc3/GHSA-w277-7jfc-fqc3.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w277-7jfc-fqc3", + "modified": "2025-03-17T18:31:52Z", + "published": "2025-03-17T18:31:52Z", + "aliases": [ + "CVE-2025-2385" + ], + "details": "A vulnerability has been found in code-projects Modern Bag 1.0 and classified as critical. This vulnerability affects unknown code of the file /login.php. The manipulation of the argument userEmail/userPassword leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2385" + }, + { + "type": "WEB", + "url": "https://github.com/MiniSweetBeen/src/issues/2" + }, + { + "type": "WEB", + "url": "https://code-projects.org" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.299884" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.299884" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.516544" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T17:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-w8fh-vjh9-56p3/GHSA-w8fh-vjh9-56p3.json b/advisories/unreviewed/2025/03/GHSA-w8fh-vjh9-56p3/GHSA-w8fh-vjh9-56p3.json new file mode 100644 index 00000000000..1e2de49f60b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-w8fh-vjh9-56p3/GHSA-w8fh-vjh9-56p3.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w8fh-vjh9-56p3", + "modified": "2025-03-17T18:31:53Z", + "published": "2025-03-17T18:31:53Z", + "aliases": [ + "CVE-2025-22472" + ], + "details": "Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to execution of commands with elevated privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22472" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000289970/dsa-2025-070-security-update-for-dell-networking-os10-vulnerabilities" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000293638/dsa-2025-069-security-update-for-dell-networking-os10-vulnerabilities" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000294091/dsa-2025-079-security-update-for-dell-networking-os10-vulnerabilities" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000295014/dsa-2025-068-security-update-for-dell-networking-os10-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T18:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-w9c3-8j7h-3cq6/GHSA-w9c3-8j7h-3cq6.json b/advisories/unreviewed/2025/03/GHSA-w9c3-8j7h-3cq6/GHSA-w9c3-8j7h-3cq6.json new file mode 100644 index 00000000000..a485ab9b2d6 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-w9c3-8j7h-3cq6/GHSA-w9c3-8j7h-3cq6.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w9c3-8j7h-3cq6", + "modified": "2025-03-17T18:31:52Z", + "published": "2025-03-17T18:31:52Z", + "aliases": [ + "CVE-2025-25684" + ], + "details": "A lack of validation in the path parameter (/download) of GL-INet Beryl AX GL-MT3000 v4.7.0 allows attackers to download arbitrary files from the device's file system via a crafted POST request.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25684" + }, + { + "type": "WEB", + "url": "https://medium.com/@tfortinsec/multiple-path-traversal-vulnerabilities-in-the-beryl-ax-gl-mt300-router-e7f856d14af9" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T17:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-w9g2-vv3j-rp63/GHSA-w9g2-vv3j-rp63.json b/advisories/unreviewed/2025/03/GHSA-w9g2-vv3j-rp63/GHSA-w9g2-vv3j-rp63.json new file mode 100644 index 00000000000..fc36b1c2991 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-w9g2-vv3j-rp63/GHSA-w9g2-vv3j-rp63.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w9g2-vv3j-rp63", + "modified": "2025-03-17T18:31:53Z", + "published": "2025-03-17T18:31:53Z", + "aliases": [ + "CVE-2025-29429" + ], + "details": "Code-projects Online Class and Exam Scheduling System V1.0 is vulnerable to Cross Site Scripting (XSS) in /pages/program.php via the id, code, and name parameters.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29429" + }, + { + "type": "WEB", + "url": "https://github.com/872323857/CVE/blob/main/Online%20Class%20and%20Exam%20Scheduling%20System-program.php.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T18:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-wmq7-vc7f-g5r2/GHSA-wmq7-vc7f-g5r2.json b/advisories/unreviewed/2025/03/GHSA-wmq7-vc7f-g5r2/GHSA-wmq7-vc7f-g5r2.json index 75505cdbeeb..9e29ef80845 100644 --- a/advisories/unreviewed/2025/03/GHSA-wmq7-vc7f-g5r2/GHSA-wmq7-vc7f-g5r2.json +++ b/advisories/unreviewed/2025/03/GHSA-wmq7-vc7f-g5r2/GHSA-wmq7-vc7f-g5r2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wmq7-vc7f-g5r2", - "modified": "2025-03-16T06:30:24Z", + "modified": "2025-03-17T18:31:52Z", "published": "2025-03-16T06:30:24Z", "aliases": [ "CVE-2025-1621" ], "details": "The GDPR Cookie Compliance WordPress plugin before 4.15.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-16T06:15:12Z" diff --git a/advisories/unreviewed/2025/03/GHSA-wqw7-xgf9-5p2q/GHSA-wqw7-xgf9-5p2q.json b/advisories/unreviewed/2025/03/GHSA-wqw7-xgf9-5p2q/GHSA-wqw7-xgf9-5p2q.json new file mode 100644 index 00000000000..5f03dde15b7 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-wqw7-xgf9-5p2q/GHSA-wqw7-xgf9-5p2q.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wqw7-xgf9-5p2q", + "modified": "2025-03-17T18:31:50Z", + "published": "2025-03-17T18:31:50Z", + "aliases": [ + "CVE-2022-49466" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nregulator: scmi: Fix refcount leak in scmi_regulator_probe\n\nof_find_node_by_name() returns a node pointer with refcount\nincremented, we should use of_node_put() on it when done.\nAdd missing of_node_put() to avoid refcount leak.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49466" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/299a002161c7bfb72e99ba45e5b660aecc344ea0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4a59c763ef9b68c711dc2fd2ef4a6648da5480ee" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/68d6c8476fd4f448e70e0ab31ff972838ac41dae" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9ebbfa73d69909b7c737f599fd4ebd42318fc881" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-wvff-mvg2-8jqh/GHSA-wvff-mvg2-8jqh.json b/advisories/unreviewed/2025/03/GHSA-wvff-mvg2-8jqh/GHSA-wvff-mvg2-8jqh.json new file mode 100644 index 00000000000..743ad5e43a2 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-wvff-mvg2-8jqh/GHSA-wvff-mvg2-8jqh.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wvff-mvg2-8jqh", + "modified": "2025-03-17T18:31:49Z", + "published": "2025-03-17T18:31:49Z", + "aliases": [ + "CVE-2022-49453" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsoc: ti: ti_sci_pm_domains: Check for null return of devm_kcalloc\n\nThe allocation funciton devm_kcalloc may fail and return a null pointer,\nwhich would cause a null-pointer dereference later.\nIt might be better to check it and directly return -ENOMEM just like the\nusage of devm_kcalloc in previous code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49453" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/01ba41a359622ab256ce4d4f8b94c67165ae3daf" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/05efc4591f80582b6fe53366b70b6a35a42fd255" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7cef9274fa1b8506949d74bc45aef072b890824a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ba56291e297d28aa6eb82c5c1964fae2d7594746" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c4e188869406b47ac3350920bf165be303cb1c96" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-wx3r-gcpx-jqq8/GHSA-wx3r-gcpx-jqq8.json b/advisories/unreviewed/2025/03/GHSA-wx3r-gcpx-jqq8/GHSA-wx3r-gcpx-jqq8.json index a27fc556a74..0981b9cf32d 100644 --- a/advisories/unreviewed/2025/03/GHSA-wx3r-gcpx-jqq8/GHSA-wx3r-gcpx-jqq8.json +++ b/advisories/unreviewed/2025/03/GHSA-wx3r-gcpx-jqq8/GHSA-wx3r-gcpx-jqq8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wx3r-gcpx-jqq8", - "modified": "2025-03-14T18:30:51Z", + "modified": "2025-03-17T18:31:52Z", "published": "2025-03-14T18:30:51Z", "aliases": [ "CVE-2025-26312" ], "details": "SendQuick Entera devices before 11HF5 are vulnerable to CAPTCHA bypass via the captcha parameter", - "severity": [], + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], "affected": [], "references": [ { @@ -18,14 +23,20 @@ "type": "WEB", "url": "https://medium.com/@retro.metro/cve-2025-26312-captcha-bypass-vulnerability-in-sendquick-entera-devices-68708e203216" }, + { + "type": "WEB", + "url": "https://www.sendquick.com/products/sendquick-entera" + }, { "type": "WEB", "url": "http://sendquick.com" } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-472" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-14T18:15:31Z" diff --git a/advisories/unreviewed/2025/03/GHSA-wx8p-85p4-gfr8/GHSA-wx8p-85p4-gfr8.json b/advisories/unreviewed/2025/03/GHSA-wx8p-85p4-gfr8/GHSA-wx8p-85p4-gfr8.json new file mode 100644 index 00000000000..d6a65947f70 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-wx8p-85p4-gfr8/GHSA-wx8p-85p4-gfr8.json @@ -0,0 +1,60 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wx8p-85p4-gfr8", + "modified": "2025-03-17T18:31:49Z", + "published": "2025-03-17T18:31:49Z", + "aliases": [ + "CVE-2022-49451" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware: arm_scmi: Fix list protocols enumeration in the base protocol\n\nWhile enumerating protocols implemented by the SCMI platform using\nBASE_DISCOVER_LIST_PROTOCOLS, the number of returned protocols is\ncurrently validated in an improper way since the check employs a sum\nbetween unsigned integers that could overflow and cause the check itself\nto be silently bypassed if the returned value 'loop_num_ret' is big\nenough.\n\nFix the validation avoiding the addition.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49451" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1052f22e127d0c34c3387bb389424ba1c61491ff" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2ccfcd7a09c826516edcfe464b05071961aada3f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/444a2d27fe9867d0da4b28fc45b793f32e099ab8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6e7978695f4a6cbd83616b5a702b77fa2087b247" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8009120e0354a67068e920eb10dce532391361d0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/98342148a8cd242855d7e257f298c966c96dba9f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b0e4bafac8963c2d85ee18d3d01f393735acceec" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-190" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-x7qp-h9pf-wpv9/GHSA-x7qp-h9pf-wpv9.json b/advisories/unreviewed/2025/03/GHSA-x7qp-h9pf-wpv9/GHSA-x7qp-h9pf-wpv9.json new file mode 100644 index 00000000000..1c2af5562d7 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-x7qp-h9pf-wpv9/GHSA-x7qp-h9pf-wpv9.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x7qp-h9pf-wpv9", + "modified": "2025-03-17T18:31:52Z", + "published": "2025-03-17T18:31:52Z", + "aliases": [ + "CVE-2025-2383" + ], + "details": "A vulnerability, which was classified as critical, has been found in PHPGurukul Doctor Appointment Management System 1.0. Affected by this issue is some unknown functionality of the file /doctor/search.php. The manipulation of the argument searchdata leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2383" + }, + { + "type": "WEB", + "url": "https://github.com/aionman/cve/issues/6" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.299882" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.299882" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.515913" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T16:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-xcxv-mc83-gmw5/GHSA-xcxv-mc83-gmw5.json b/advisories/unreviewed/2025/03/GHSA-xcxv-mc83-gmw5/GHSA-xcxv-mc83-gmw5.json new file mode 100644 index 00000000000..17237eb6dfa --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-xcxv-mc83-gmw5/GHSA-xcxv-mc83-gmw5.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xcxv-mc83-gmw5", + "modified": "2025-03-17T18:31:53Z", + "published": "2025-03-17T18:31:53Z", + "aliases": [ + "CVE-2025-26125" + ], + "details": "An exposed ioctl in the IMFForceDelete driver of IObit Malware Fighter v12.1.0 allows attackers to arbitrarily delete files and escalate privileges.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26125" + }, + { + "type": "WEB", + "url": "https://github.com/ZeroMemoryEx/CVE-2025-26125" + }, + { + "type": "WEB", + "url": "https://github.com/ZeroMemoryEx/IObit-EoP" + }, + { + "type": "WEB", + "url": "https://x.com/zeromemoryex/status/1876878269200449819" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T18:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-xf2q-qg27-ggxv/GHSA-xf2q-qg27-ggxv.json b/advisories/unreviewed/2025/03/GHSA-xf2q-qg27-ggxv/GHSA-xf2q-qg27-ggxv.json new file mode 100644 index 00000000000..afefb8df309 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-xf2q-qg27-ggxv/GHSA-xf2q-qg27-ggxv.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xf2q-qg27-ggxv", + "modified": "2025-03-17T18:31:50Z", + "published": "2025-03-17T18:31:50Z", + "aliases": [ + "CVE-2022-49475" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nspi: spi-fsl-qspi: check return value after calling platform_get_resource_byname()\n\nIt will cause null-ptr-deref if platform_get_resource_byname() returns NULL,\nwe need check the return value.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49475" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/10f537219629769498ecb8515e096be213224c24" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/33dda87d04598ac5d9a849218a373443f7d3de66" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/560dcbe1c7a78f597f2167371ebdbe2bca3d0735" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9d9c84825c3ec359b165c762a424cfdefe87fdd7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a2b331ac11e1cac56f5b7d367e9f3c5796deaaed" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-xrfw-g6fh-r7xc/GHSA-xrfw-g6fh-r7xc.json b/advisories/unreviewed/2025/03/GHSA-xrfw-g6fh-r7xc/GHSA-xrfw-g6fh-r7xc.json new file mode 100644 index 00000000000..4863dafa7a6 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-xrfw-g6fh-r7xc/GHSA-xrfw-g6fh-r7xc.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xrfw-g6fh-r7xc", + "modified": "2025-03-17T18:31:50Z", + "published": "2025-03-17T18:31:50Z", + "aliases": [ + "CVE-2022-49463" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nthermal/drivers/imx_sc_thermal: Fix refcount leak in imx_sc_thermal_probe\n\nof_find_node_by_name() returns a node pointer with refcount\nincremented, we should use of_node_put() on it when done.\nAdd missing of_node_put() to avoid refcount leak.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49463" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/09700c504d8e63faffd2a2235074e8c5d130cb8f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0ec10303c10833c1bcba7a1bde2f297e494d5464" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3ade442ea5d3512a3c67984489ab4d8a6fb3b29f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8bbf522a2c51ef939d0e8835e236bfcd252193af" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ec0925b731697db7cab5944a3e55d2d58bb3d075" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-xrg9-xjhp-934h/GHSA-xrg9-xjhp-934h.json b/advisories/unreviewed/2025/03/GHSA-xrg9-xjhp-934h/GHSA-xrg9-xjhp-934h.json new file mode 100644 index 00000000000..d84c3cc1fc4 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-xrg9-xjhp-934h/GHSA-xrg9-xjhp-934h.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xrg9-xjhp-934h", + "modified": "2025-03-17T18:31:47Z", + "published": "2025-03-17T18:31:47Z", + "aliases": [ + "CVE-2022-49446" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnvdimm: Fix firmware activation deadlock scenarios\n\nLockdep reports the following deadlock scenarios for CXL root device\npower-management, device_prepare(), operations, and device_shutdown()\noperations for 'nd_region' devices:\n\n Chain exists of:\n &nvdimm_region_key --> &nvdimm_bus->reconfig_mutex --> system_transition_mutex\n\n Possible unsafe locking scenario:\n\n CPU0 CPU1\n ---- ----\n lock(system_transition_mutex);\n lock(&nvdimm_bus->reconfig_mutex);\n lock(system_transition_mutex);\n lock(&nvdimm_region_key);\n\n Chain exists of:\n &cxl_nvdimm_bridge_key --> acpi_scan_lock --> &cxl_root_key\n\n Possible unsafe locking scenario:\n\n CPU0 CPU1\n ---- ----\n lock(&cxl_root_key);\n lock(acpi_scan_lock);\n lock(&cxl_root_key);\n lock(&cxl_nvdimm_bridge_key);\n\nThese stem from holding nvdimm_bus_lock() over hibernate_quiet_exec()\nwhich walks the entire system device topology taking device_lock() along\nthe way. The nvdimm_bus_lock() is protecting against unregistration,\nmultiple simultaneous ops callers, and preventing activate_show() from\nracing activate_store(). For the first 2, the lock is redundant.\nUnregistration already flushes all ops users, and sysfs already prevents\nmultiple threads to be active in an ops handler at the same time. For\nthe last userspace should already be waiting for its last\nactivate_store() to complete, and does not need activate_show() to flush\nthe write side, so this lock usage can be deleted in these attributes.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-49446" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2f97ebc58d5fc83ca1528cd553fa725472ab3ca8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2fd853fdb40afc052de338693df1372f2ead7be7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/641649f31e20df630310f5c22f26c071acc676d4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ceb924ee16b2c8e48dcac3d9ad6be01c40b5a228" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e6829d1bd3c4b58296ee9e412f7ed4d6cb390192" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-667" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T07:01:21Z" + } +} \ No newline at end of file