From 744f97f82c328913c463fa37c70b310f471bfd00 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 11 Dec 2024 15:32:38 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-cxc6-784q-9f49.json | 11 +++-- .../GHSA-gmfg-g4f3-5fg9.json | 15 +++++-- .../GHSA-hmp8-5wq6-v727.json | 11 +++-- .../GHSA-p2qc-mv5g-9gcr.json | 11 +++-- .../GHSA-2292-859m-6prp.json | 15 +++++-- .../GHSA-2m3h-p692-qjp7.json | 15 +++++-- .../GHSA-59mx-6m8m-c99j.json | 15 +++++-- .../GHSA-65mj-5f83-m897.json | 15 +++++-- .../GHSA-6vm2-4jg8-fq6m.json | 15 +++++-- .../GHSA-9jv3-jc56-rv4g.json | 15 +++++-- .../GHSA-gfh2-325r-ffgp.json | 15 +++++-- .../GHSA-gg3p-v52w-p6fr.json | 15 +++++-- .../GHSA-mvcc-fjcm-33jm.json | 15 +++++-- .../GHSA-pcxc-636v-74pc.json | 15 +++++-- .../GHSA-w2cg-jcf6-hrgr.json | 11 +++-- .../GHSA-wgvh-m7hp-9m4m.json | 15 +++++-- .../GHSA-xc3g-cm27-mcmg.json | 15 +++++-- .../GHSA-3q8w-82vq-p7rq.json | 15 +++++-- .../GHSA-45vq-73jx-ggvm.json | 15 +++++-- .../GHSA-6j8r-9fpw-hmxp.json | 15 +++++-- .../GHSA-7vmw-m77g-4fxf.json | 11 +++-- .../GHSA-8qf2-p2j7-qp5x.json | 15 +++++-- .../GHSA-g4cc-x94v-f3gm.json | 15 +++++-- .../GHSA-m87g-gjm6-7c8j.json | 11 +++-- .../GHSA-wx45-rr53-j6w8.json | 11 +++-- .../GHSA-28pg-93m7-9jmx.json | 1 + .../GHSA-p346-px87-vf2h.json | 3 +- .../GHSA-4p29-qp7w-5p8p.json | 15 +++++-- .../GHSA-5684-4xfg-mxj4.json | 2 +- .../GHSA-56gp-6mw9-wpfj.json | 15 +++++-- .../GHSA-9w6j-hvpp-85hf.json | 3 +- .../GHSA-r79x-wgrg-2v77.json | 15 +++++-- .../GHSA-362j-p2h8-qq8p.json | 15 +++++-- .../GHSA-46mh-fqpf-6685.json | 15 +++++-- .../GHSA-4c8h-4mm2-mm5g.json | 15 +++++-- .../GHSA-4gff-x4ff-9qq7.json | 31 ++++++++++++++ .../GHSA-8q4m-8m4v-c2rm.json | 36 +++++++++++++++++ .../GHSA-8q75-6f6h-8grp.json | 4 +- .../GHSA-c52g-v6h9-jghm.json | 15 +++++-- .../GHSA-c5j4-2m6v-w9gr.json | 6 ++- .../GHSA-cjh5-vw7v-698x.json | 15 +++++-- .../GHSA-fg92-6xpx-v2x4.json | 15 +++++-- .../GHSA-h288-5fq8-5pfw.json | 11 +++-- .../GHSA-hqgr-6w6j-4xpp.json | 40 +++++++++++++++++++ .../GHSA-hwfm-86r3-467v.json | 15 +++++-- .../GHSA-p28q-ghm8-cw23.json | 15 +++++-- .../GHSA-p85v-4hp9-vq4r.json | 15 +++++-- .../GHSA-prj7-gm8m-736f.json | 15 +++++-- .../GHSA-px72-8g3v-62xm.json | 6 ++- .../GHSA-v8rw-4jh7-4cx9.json | 15 +++++-- .../GHSA-w6fv-cg9x-p5jx.json | 15 +++++-- .../GHSA-x486-v4r3-8xm3.json | 36 +++++++++++++++++ 52 files changed, 589 insertions(+), 162 deletions(-) create mode 100644 advisories/unreviewed/2024/12/GHSA-4gff-x4ff-9qq7/GHSA-4gff-x4ff-9qq7.json create mode 100644 advisories/unreviewed/2024/12/GHSA-8q4m-8m4v-c2rm/GHSA-8q4m-8m4v-c2rm.json create mode 100644 advisories/unreviewed/2024/12/GHSA-hqgr-6w6j-4xpp/GHSA-hqgr-6w6j-4xpp.json create mode 100644 advisories/unreviewed/2024/12/GHSA-x486-v4r3-8xm3/GHSA-x486-v4r3-8xm3.json diff --git a/advisories/unreviewed/2024/02/GHSA-cxc6-784q-9f49/GHSA-cxc6-784q-9f49.json b/advisories/unreviewed/2024/02/GHSA-cxc6-784q-9f49/GHSA-cxc6-784q-9f49.json index e83b5113c4e..2176777b3be 100644 --- a/advisories/unreviewed/2024/02/GHSA-cxc6-784q-9f49/GHSA-cxc6-784q-9f49.json +++ b/advisories/unreviewed/2024/02/GHSA-cxc6-784q-9f49/GHSA-cxc6-784q-9f49.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cxc6-784q-9f49", - "modified": "2024-02-27T21:31:27Z", + "modified": "2024-12-11T15:31:13Z", "published": "2024-02-27T21:31:27Z", "aliases": [ "CVE-2021-46960" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncifs: Return correct error code from smb2_get_enc_key\n\nAvoid a warning if the error percolates back up:\n\n[440700.376476] CIFS VFS: \\\\otters.example.com crypt_message: Could not get encryption key\n[440700.386947] ------------[ cut here ]------------\n[440700.386948] err = 1\n[440700.386977] WARNING: CPU: 11 PID: 2733 at /build/linux-hwe-5.4-p6lk6L/linux-hwe-5.4-5.4.0/lib/errseq.c:74 errseq_set+0x5c/0x70\n...\n[440700.397304] CPU: 11 PID: 2733 Comm: tar Tainted: G OE 5.4.0-70-generic #78~18.04.1-Ubuntu\n...\n[440700.397334] Call Trace:\n[440700.397346] __filemap_set_wb_err+0x1a/0x70\n[440700.397419] cifs_writepages+0x9c7/0xb30 [cifs]\n[440700.397426] do_writepages+0x4b/0xe0\n[440700.397444] __filemap_fdatawrite_range+0xcb/0x100\n[440700.397455] filemap_write_and_wait+0x42/0xa0\n[440700.397486] cifs_setattr+0x68b/0xf30 [cifs]\n[440700.397493] notify_change+0x358/0x4a0\n[440700.397500] utimes_common+0xe9/0x1c0\n[440700.397510] do_utimes+0xc5/0x150\n[440700.397520] __x64_sys_utimensat+0x88/0xd0", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -45,7 +50,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-27T19:04:06Z" diff --git a/advisories/unreviewed/2024/02/GHSA-gmfg-g4f3-5fg9/GHSA-gmfg-g4f3-5fg9.json b/advisories/unreviewed/2024/02/GHSA-gmfg-g4f3-5fg9/GHSA-gmfg-g4f3-5fg9.json index d7bbde3e5ea..2b39821fe3d 100644 --- a/advisories/unreviewed/2024/02/GHSA-gmfg-g4f3-5fg9/GHSA-gmfg-g4f3-5fg9.json +++ b/advisories/unreviewed/2024/02/GHSA-gmfg-g4f3-5fg9/GHSA-gmfg-g4f3-5fg9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gmfg-g4f3-5fg9", - "modified": "2024-02-27T21:31:27Z", + "modified": "2024-12-11T15:31:13Z", "published": "2024-02-27T21:31:27Z", "aliases": [ "CVE-2021-46958" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix race between transaction aborts and fsyncs leading to use-after-free\n\nThere is a race between a task aborting a transaction during a commit,\na task doing an fsync and the transaction kthread, which leads to an\nuse-after-free of the log root tree. When this happens, it results in a\nstack trace like the following:\n\n BTRFS info (device dm-0): forced readonly\n BTRFS warning (device dm-0): Skipping commit of aborted transaction.\n BTRFS: error (device dm-0) in cleanup_transaction:1958: errno=-5 IO failure\n BTRFS warning (device dm-0): lost page write due to IO error on /dev/mapper/error-test (-5)\n BTRFS warning (device dm-0): Skipping commit of aborted transaction.\n BTRFS warning (device dm-0): direct IO failed ino 261 rw 0,0 sector 0xa4e8 len 4096 err no 10\n BTRFS error (device dm-0): error writing primary super block to device 1\n BTRFS warning (device dm-0): direct IO failed ino 261 rw 0,0 sector 0x12e000 len 4096 err no 10\n BTRFS warning (device dm-0): direct IO failed ino 261 rw 0,0 sector 0x12e008 len 4096 err no 10\n BTRFS warning (device dm-0): direct IO failed ino 261 rw 0,0 sector 0x12e010 len 4096 err no 10\n BTRFS: error (device dm-0) in write_all_supers:4110: errno=-5 IO failure (1 errors while writing supers)\n BTRFS: error (device dm-0) in btrfs_sync_log:3308: errno=-5 IO failure\n general protection fault, probably for non-canonical address 0x6b6b6b6b6b6b6b68: 0000 [#1] PREEMPT SMP DEBUG_PAGEALLOC PTI\n CPU: 2 PID: 2458471 Comm: fsstress Not tainted 5.12.0-rc5-btrfs-next-84 #1\n Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.14.0-0-g155821a1990b-prebuilt.qemu.org 04/01/2014\n RIP: 0010:__mutex_lock+0x139/0xa40\n Code: c0 74 19 (...)\n RSP: 0018:ffff9f18830d7b00 EFLAGS: 00010202\n RAX: 6b6b6b6b6b6b6b68 RBX: 0000000000000001 RCX: 0000000000000002\n RDX: ffffffffb9c54d13 RSI: 0000000000000000 RDI: 0000000000000000\n RBP: ffff9f18830d7bc0 R08: 0000000000000000 R09: 0000000000000000\n R10: ffff9f18830d7be0 R11: 0000000000000001 R12: ffff8c6cd199c040\n R13: ffff8c6c95821358 R14: 00000000fffffffb R15: ffff8c6cbcf01358\n FS: 00007fa9140c2b80(0000) GS:ffff8c6fac600000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 00007fa913d52000 CR3: 000000013d2b4003 CR4: 0000000000370ee0\n DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n Call Trace:\n ? __btrfs_handle_fs_error+0xde/0x146 [btrfs]\n ? btrfs_sync_log+0x7c1/0xf20 [btrfs]\n ? btrfs_sync_log+0x7c1/0xf20 [btrfs]\n btrfs_sync_log+0x7c1/0xf20 [btrfs]\n btrfs_sync_file+0x40c/0x580 [btrfs]\n do_fsync+0x38/0x70\n __x64_sys_fsync+0x10/0x20\n do_syscall_64+0x33/0x80\n entry_SYSCALL_64_after_hwframe+0x44/0xae\n RIP: 0033:0x7fa9142a55c3\n Code: 8b 15 09 (...)\n RSP: 002b:00007fff26278d48 EFLAGS: 00000246 ORIG_RAX: 000000000000004a\n RAX: ffffffffffffffda RBX: 0000563c83cb4560 RCX: 00007fa9142a55c3\n RDX: 00007fff26278cb0 RSI: 00007fff26278cb0 RDI: 0000000000000005\n RBP: 0000000000000005 R08: 0000000000000001 R09: 00007fff26278d5c\n R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000340\n R13: 00007fff26278de0 R14: 00007fff26278d96 R15: 0000563c83ca57c0\n Modules linked in: btrfs dm_zero dm_snapshot dm_thin_pool (...)\n ---[ end trace ee2f1b19327d791d ]---\n\nThe steps that lead to this crash are the following:\n\n1) We are at transaction N;\n\n2) We have two tasks with a transaction handle attached to transaction N.\n Task A and Task B. Task B is doing an fsync;\n\n3) Task B is at btrfs_sync_log(), and has saved fs_info->log_root_tree\n into a local variable named 'log_root_tree' at the top of\n btrfs_sync_log(). Task B is about to call write_all_supers(), but\n before that...\n\n4) Task A calls btrfs_commit_transaction(), and after it sets the\n transaction state to TRANS_STATE_COMMIT_START, an error happens before\n it w\n---truncated---", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-27T19:04:06Z" diff --git a/advisories/unreviewed/2024/02/GHSA-hmp8-5wq6-v727/GHSA-hmp8-5wq6-v727.json b/advisories/unreviewed/2024/02/GHSA-hmp8-5wq6-v727/GHSA-hmp8-5wq6-v727.json index 4390d9a710f..a7e75be3ed1 100644 --- a/advisories/unreviewed/2024/02/GHSA-hmp8-5wq6-v727/GHSA-hmp8-5wq6-v727.json +++ b/advisories/unreviewed/2024/02/GHSA-hmp8-5wq6-v727/GHSA-hmp8-5wq6-v727.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hmp8-5wq6-v727", - "modified": "2024-02-27T21:31:27Z", + "modified": "2024-12-11T15:31:14Z", "published": "2024-02-27T21:31:27Z", "aliases": [ "CVE-2021-46962" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmmc: uniphier-sd: Fix a resource leak in the remove function\n\nA 'tmio_mmc_host_free()' call is missing in the remove function, in order\nto balance a 'tmio_mmc_host_alloc()' call in the probe.\nThis is done in the error handling path of the probe, but not in the remove\nfunction.\n\nAdd the missing call.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -37,7 +42,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-27T19:04:06Z" diff --git a/advisories/unreviewed/2024/02/GHSA-p2qc-mv5g-9gcr/GHSA-p2qc-mv5g-9gcr.json b/advisories/unreviewed/2024/02/GHSA-p2qc-mv5g-9gcr/GHSA-p2qc-mv5g-9gcr.json index 080df34da7c..4d42f1d6a61 100644 --- a/advisories/unreviewed/2024/02/GHSA-p2qc-mv5g-9gcr/GHSA-p2qc-mv5g-9gcr.json +++ b/advisories/unreviewed/2024/02/GHSA-p2qc-mv5g-9gcr/GHSA-p2qc-mv5g-9gcr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p2qc-mv5g-9gcr", - "modified": "2024-02-27T21:31:27Z", + "modified": "2024-12-11T15:31:14Z", "published": "2024-02-27T21:31:27Z", "aliases": [ "CVE-2021-46961" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nirqchip/gic-v3: Do not enable irqs when handling spurious interrups\n\nWe triggered the following error while running our 4.19 kernel\nwith the pseudo-NMI patches backported to it:\n\n[ 14.816231] ------------[ cut here ]------------\n[ 14.816231] kernel BUG at irq.c:99!\n[ 14.816232] Internal error: Oops - BUG: 0 [#1] SMP\n[ 14.816232] Process swapper/0 (pid: 0, stack limit = 0x(____ptrval____))\n[ 14.816233] CPU: 0 PID: 0 Comm: swapper/0 Tainted: G O 4.19.95.aarch64 #14\n[ 14.816233] Hardware name: evb (DT)\n[ 14.816234] pstate: 80400085 (Nzcv daIf +PAN -UAO)\n[ 14.816234] pc : asm_nmi_enter+0x94/0x98\n[ 14.816235] lr : asm_nmi_enter+0x18/0x98\n[ 14.816235] sp : ffff000008003c50\n[ 14.816235] pmr_save: 00000070\n[ 14.816237] x29: ffff000008003c50 x28: ffff0000095f56c0\n[ 14.816238] x27: 0000000000000000 x26: ffff000008004000\n[ 14.816239] x25: 00000000015e0000 x24: ffff8008fb916000\n[ 14.816240] x23: 0000000020400005 x22: ffff0000080817cc\n[ 14.816241] x21: ffff000008003da0 x20: 0000000000000060\n[ 14.816242] x19: 00000000000003ff x18: ffffffffffffffff\n[ 14.816243] x17: 0000000000000008 x16: 003d090000000000\n[ 14.816244] x15: ffff0000095ea6c8 x14: ffff8008fff5ab40\n[ 14.816244] x13: ffff8008fff58b9d x12: 0000000000000000\n[ 14.816245] x11: ffff000008c8a200 x10: 000000008e31fca5\n[ 14.816246] x9 : ffff000008c8a208 x8 : 000000000000000f\n[ 14.816247] x7 : 0000000000000004 x6 : ffff8008fff58b9e\n[ 14.816248] x5 : 0000000000000000 x4 : 0000000080000000\n[ 14.816249] x3 : 0000000000000000 x2 : 0000000080000000\n[ 14.816250] x1 : 0000000000120000 x0 : ffff0000095f56c0\n[ 14.816251] Call trace:\n[ 14.816251] asm_nmi_enter+0x94/0x98\n[ 14.816251] el1_irq+0x8c/0x180 (IRQ C)\n[ 14.816252] gic_handle_irq+0xbc/0x2e4\n[ 14.816252] el1_irq+0xcc/0x180 (IRQ B)\n[ 14.816253] arch_timer_handler_virt+0x38/0x58\n[ 14.816253] handle_percpu_devid_irq+0x90/0x240\n[ 14.816253] generic_handle_irq+0x34/0x50\n[ 14.816254] __handle_domain_irq+0x68/0xc0\n[ 14.816254] gic_handle_irq+0xf8/0x2e4\n[ 14.816255] el1_irq+0xcc/0x180 (IRQ A)\n[ 14.816255] arch_cpu_idle+0x34/0x1c8\n[ 14.816255] default_idle_call+0x24/0x44\n[ 14.816256] do_idle+0x1d0/0x2c8\n[ 14.816256] cpu_startup_entry+0x28/0x30\n[ 14.816256] rest_init+0xb8/0xc8\n[ 14.816257] start_kernel+0x4c8/0x4f4\n[ 14.816257] Code: 940587f1 d5384100 b9401001 36a7fd01 (d4210000)\n[ 14.816258] Modules linked in: start_dp(O) smeth(O)\n[ 15.103092] ---[ end trace 701753956cb14aa8 ]---\n[ 15.103093] Kernel panic - not syncing: Fatal exception in interrupt\n[ 15.103099] SMP: stopping secondary CPUs\n[ 15.103100] Kernel Offset: disabled\n[ 15.103100] CPU features: 0x36,a2400218\n[ 15.103100] Memory Limit: none\n\nwhich is cause by a 'BUG_ON(in_nmi())' in nmi_enter().\n\nFrom the call trace, we can find three interrupts (noted A, B, C above):\ninterrupt (A) is preempted by (B), which is further interrupted by (C).\n\nSubsequent investigations show that (B) results in nmi_enter() being\ncalled, but that it actually is a spurious interrupt. Furthermore,\ninterrupts are reenabled in the context of (B), and (C) fires with\nNMI priority. We end-up with a nested NMI situation, something\nwe definitely do not want to (and cannot) handle.\n\nThe bug here is that spurious interrupts should never result in any\nstate change, and we should just return to the interrupted context.\nMoving the handling of spurious interrupts as early as possible in\nthe GICv3 handler fixes this issue.\n\n[maz: rewrote commit message, corrected Fixes: tag]", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -37,7 +42,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-27T19:04:06Z" diff --git a/advisories/unreviewed/2024/03/GHSA-2292-859m-6prp/GHSA-2292-859m-6prp.json b/advisories/unreviewed/2024/03/GHSA-2292-859m-6prp/GHSA-2292-859m-6prp.json index e4da651d667..2e98ed80bf4 100644 --- a/advisories/unreviewed/2024/03/GHSA-2292-859m-6prp/GHSA-2292-859m-6prp.json +++ b/advisories/unreviewed/2024/03/GHSA-2292-859m-6prp/GHSA-2292-859m-6prp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2292-859m-6prp", - "modified": "2024-03-03T00:30:31Z", + "modified": "2024-12-11T15:31:14Z", "published": "2024-03-03T00:30:31Z", "aliases": [ "CVE-2023-52510" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nieee802154: ca8210: Fix a potential UAF in ca8210_probe\n\nIf of_clk_add_provider() fails in ca8210_register_ext_clock(),\nit calls clk_unregister() to release priv->clk and returns an\nerror. However, the caller ca8210_probe() then calls ca8210_remove(),\nwhere priv->clk is freed again in ca8210_unregister_ext_clock(). In\nthis case, a use-after-free may happen in the second time we call\nclk_unregister().\n\nFix this by removing the first clk_unregister(). Also, priv->clk could\nbe an error code on failure of clk_register_fixed_rate(). Use\nIS_ERR_OR_NULL to catch this case in ca8210_unregister_ext_clock().", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-02T22:15:47Z" diff --git a/advisories/unreviewed/2024/03/GHSA-2m3h-p692-qjp7/GHSA-2m3h-p692-qjp7.json b/advisories/unreviewed/2024/03/GHSA-2m3h-p692-qjp7/GHSA-2m3h-p692-qjp7.json index b4307a45c94..0ee0b16dacb 100644 --- a/advisories/unreviewed/2024/03/GHSA-2m3h-p692-qjp7/GHSA-2m3h-p692-qjp7.json +++ b/advisories/unreviewed/2024/03/GHSA-2m3h-p692-qjp7/GHSA-2m3h-p692-qjp7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2m3h-p692-qjp7", - "modified": "2024-03-03T00:30:31Z", + "modified": "2024-12-11T15:31:14Z", "published": "2024-03-03T00:30:31Z", "aliases": [ "CVE-2023-52513" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/siw: Fix connection failure handling\n\nIn case immediate MPA request processing fails, the newly\ncreated endpoint unlinks the listening endpoint and is\nready to be dropped. This special case was not handled\ncorrectly by the code handling the later TCP socket close,\ncausing a NULL dereference crash in siw_cm_work_handler()\nwhen dereferencing a NULL listener. We now also cancel\nthe useless MPA timeout, if immediate MPA request\nprocessing fails.\n\nThis patch furthermore simplifies MPA processing in general:\nScheduling a useless TCP socket read in sk_data_ready() upcall\nis now surpressed, if the socket is already moved out of\nTCP_ESTABLISHED state.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-02T22:15:47Z" diff --git a/advisories/unreviewed/2024/03/GHSA-59mx-6m8m-c99j/GHSA-59mx-6m8m-c99j.json b/advisories/unreviewed/2024/03/GHSA-59mx-6m8m-c99j/GHSA-59mx-6m8m-c99j.json index 24ef3e77b71..adaa9eb3395 100644 --- a/advisories/unreviewed/2024/03/GHSA-59mx-6m8m-c99j/GHSA-59mx-6m8m-c99j.json +++ b/advisories/unreviewed/2024/03/GHSA-59mx-6m8m-c99j/GHSA-59mx-6m8m-c99j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-59mx-6m8m-c99j", - "modified": "2024-03-03T00:30:31Z", + "modified": "2024-12-11T15:31:14Z", "published": "2024-03-03T00:30:30Z", "aliases": [ "CVE-2023-52504" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/alternatives: Disable KASAN in apply_alternatives()\n\nFei has reported that KASAN triggers during apply_alternatives() on\na 5-level paging machine:\n\n\tBUG: KASAN: out-of-bounds in rcu_is_watching()\n\tRead of size 4 at addr ff110003ee6419a0 by task swapper/0/0\n\t...\n\t__asan_load4()\n\trcu_is_watching()\n\ttrace_hardirqs_on()\n\ttext_poke_early()\n\tapply_alternatives()\n\t...\n\nOn machines with 5-level paging, cpu_feature_enabled(X86_FEATURE_LA57)\ngets patched. It includes KASAN code, where KASAN_SHADOW_START depends on\n__VIRTUAL_MASK_SHIFT, which is defined with cpu_feature_enabled().\n\nKASAN gets confused when apply_alternatives() patches the\nKASAN_SHADOW_START users. A test patch that makes KASAN_SHADOW_START\nstatic, by replacing __VIRTUAL_MASK_SHIFT with 56, works around the issue.\n\nFix it for real by disabling KASAN while the kernel is patching alternatives.\n\n[ mingo: updated the changelog ]", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-02T22:15:47Z" diff --git a/advisories/unreviewed/2024/03/GHSA-65mj-5f83-m897/GHSA-65mj-5f83-m897.json b/advisories/unreviewed/2024/03/GHSA-65mj-5f83-m897/GHSA-65mj-5f83-m897.json index 1089a74ead5..f5b69c37427 100644 --- a/advisories/unreviewed/2024/03/GHSA-65mj-5f83-m897/GHSA-65mj-5f83-m897.json +++ b/advisories/unreviewed/2024/03/GHSA-65mj-5f83-m897/GHSA-65mj-5f83-m897.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-65mj-5f83-m897", - "modified": "2024-03-03T00:30:32Z", + "modified": "2024-12-11T15:31:14Z", "published": "2024-03-03T00:30:32Z", "aliases": [ "CVE-2023-52560" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/damon/vaddr-test: fix memory leak in damon_do_test_apply_three_regions()\n\nWhen CONFIG_DAMON_VADDR_KUNIT_TEST=y and making CONFIG_DEBUG_KMEMLEAK=y\nand CONFIG_DEBUG_KMEMLEAK_AUTO_SCAN=y, the below memory leak is detected.\n\nSince commit 9f86d624292c (\"mm/damon/vaddr-test: remove unnecessary\nvariables\"), the damon_destroy_ctx() is removed, but still call\ndamon_new_target() and damon_new_region(), the damon_region which is\nallocated by kmem_cache_alloc() in damon_new_region() and the damon_target\nwhich is allocated by kmalloc in damon_new_target() are not freed. And\nthe damon_region which is allocated in damon_new_region() in\ndamon_set_regions() is also not freed.\n\nSo use damon_destroy_target to free all the damon_regions and damon_target.\n\n unreferenced object 0xffff888107c9a940 (size 64):\n comm \"kunit_try_catch\", pid 1069, jiffies 4294670592 (age 732.761s)\n hex dump (first 32 bytes):\n 00 00 00 00 00 00 00 00 06 00 00 00 6b 6b 6b 6b ............kkkk\n 60 c7 9c 07 81 88 ff ff f8 cb 9c 07 81 88 ff ff `...............\n backtrace:\n [] kmalloc_trace+0x27/0xa0\n [] damon_new_target+0x3f/0x1b0\n [] damon_do_test_apply_three_regions.constprop.0+0x95/0x3e0\n [] damon_test_apply_three_regions1+0x21e/0x260\n [] kunit_generic_run_threadfn_adapter+0x4a/0x90\n [] kthread+0x2b6/0x380\n [] ret_from_fork+0x2d/0x70\n [] ret_from_fork_asm+0x11/0x20\n unreferenced object 0xffff8881079cc740 (size 56):\n comm \"kunit_try_catch\", pid 1069, jiffies 4294670592 (age 732.761s)\n hex dump (first 32 bytes):\n 05 00 00 00 00 00 00 00 14 00 00 00 00 00 00 00 ................\n 6b 6b 6b 6b 6b 6b 6b 6b 00 00 00 00 6b 6b 6b 6b kkkkkkkk....kkkk\n backtrace:\n [] damon_new_region+0x22/0x1c0\n [] damon_do_test_apply_three_regions.constprop.0+0xd1/0x3e0\n [] damon_test_apply_three_regions1+0x21e/0x260\n [] kunit_generic_run_threadfn_adapter+0x4a/0x90\n [] kthread+0x2b6/0x380\n [] ret_from_fork+0x2d/0x70\n [] ret_from_fork_asm+0x11/0x20\n unreferenced object 0xffff888107c9ac40 (size 64):\n comm \"kunit_try_catch\", pid 1071, jiffies 4294670595 (age 732.843s)\n hex dump (first 32 bytes):\n 00 00 00 00 00 00 00 00 06 00 00 00 6b 6b 6b 6b ............kkkk\n a0 cc 9c 07 81 88 ff ff 78 a1 76 07 81 88 ff ff ........x.v.....\n backtrace:\n [] kmalloc_trace+0x27/0xa0\n [] damon_new_target+0x3f/0x1b0\n [] damon_do_test_apply_three_regions.constprop.0+0x95/0x3e0\n [] damon_test_apply_three_regions2+0x21e/0x260\n [] kunit_generic_run_threadfn_adapter+0x4a/0x90\n [] kthread+0x2b6/0x380\n [] ret_from_fork+0x2d/0x70\n [] ret_from_fork_asm+0x11/0x20\n unreferenced object 0xffff8881079ccc80 (size 56):\n comm \"kunit_try_catch\", pid 1071, jiffies 4294670595 (age 732.843s)\n hex dump (first 32 bytes):\n 05 00 00 00 00 00 00 00 14 00 00 00 00 00 00 00 ................\n 6b 6b 6b 6b 6b 6b 6b 6b 00 00 00 00 6b 6b 6b 6b kkkkkkkk....kkkk\n backtrace:\n [] damon_new_region+0x22/0x1c0\n [] damon_do_test_apply_three_regions.constprop.0+0xd1/0x3e0\n [] damon_test_apply_three_regions2+0x21e/0x260\n [] kunit_generic_run_threadfn_adapter+0x4a/0x90\n [] kthread+0x2b6/0x380\n [] ret_from_fork+0x2d/0x70\n [\n ? __die+0x24/0x70\n ? page_fault_oops+0x82/0x150\n ? exc_page_fault+0x69/0x150\n ? asm_exc_page_fault+0x26/0x30\n ? vlan_dev_hard_header+0x35/0x140 [8021q]\n ? vlan_dev_hard_header+0x8e/0x140 [8021q]\n neigh_connected_output+0xb2/0x100\n ip6_finish_output2+0x1cb/0x520\n ? nf_hook_slow+0x43/0xc0\n ? ip6_mtu+0x46/0x80\n ip6_finish_output+0x2a/0xb0\n mld_sendpack+0x18f/0x250\n mld_ifc_work+0x39/0x160\n process_one_work+0x1e6/0x3f0\n worker_thread+0x4d/0x2f0\n ? __pfx_worker_thread+0x10/0x10\n kthread+0xe5/0x120\n ? __pfx_kthread+0x10/0x10\n ret_from_fork+0x34/0x50\n ? __pfx_kthread+0x10/0x10\n ret_from_fork_asm+0x1b/0x30\n\n[1]\n$ teamd -t team0 -d -c '{\"runner\": {\"name\": \"loadbalance\"}}'\n$ ip link add name t-dummy type dummy\n$ ip link add link t-dummy name t-dummy.100 type vlan id 100\n$ ip link add name t-nlmon type nlmon\n$ ip link set t-nlmon master team0\n$ ip link set t-nlmon nomaster\n$ ip link set t-dummy up\n$ ip link set team0 up\n$ ip link set t-dummy.100 down\n$ ip link set t-dummy.100 master team0\n\nWhen enslave a vlan device to team device and team device type is changed\nfrom non-ether to ether, header_ops of team device is changed to\nvlan_header_ops. That is incorrect and will trigger null-ptr-deref\nfor vlan->real_dev in vlan_dev_hard_header() because team device is not\na vlan device.\n\nCache eth_header_ops in team_setup(), then assign cached header_ops to\nheader_ops of team net device when its type is changed from non-ether\nto ether to fix the bug.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-02T22:15:49Z" diff --git a/advisories/unreviewed/2024/03/GHSA-9jv3-jc56-rv4g/GHSA-9jv3-jc56-rv4g.json b/advisories/unreviewed/2024/03/GHSA-9jv3-jc56-rv4g/GHSA-9jv3-jc56-rv4g.json index 32bc6294900..bf682fa167d 100644 --- a/advisories/unreviewed/2024/03/GHSA-9jv3-jc56-rv4g/GHSA-9jv3-jc56-rv4g.json +++ b/advisories/unreviewed/2024/03/GHSA-9jv3-jc56-rv4g/GHSA-9jv3-jc56-rv4g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9jv3-jc56-rv4g", - "modified": "2024-03-03T00:30:32Z", + "modified": "2024-12-11T15:31:15Z", "published": "2024-03-03T00:30:32Z", "aliases": [ "CVE-2023-52573" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: rds: Fix possible NULL-pointer dereference\n\nIn rds_rdma_cm_event_handler_cmn() check, if conn pointer exists\nbefore dereferencing it as rdma_set_service_type() argument\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-02T22:15:49Z" diff --git a/advisories/unreviewed/2024/03/GHSA-gfh2-325r-ffgp/GHSA-gfh2-325r-ffgp.json b/advisories/unreviewed/2024/03/GHSA-gfh2-325r-ffgp/GHSA-gfh2-325r-ffgp.json index 8c72f30cc75..4740ce2ce7b 100644 --- a/advisories/unreviewed/2024/03/GHSA-gfh2-325r-ffgp/GHSA-gfh2-325r-ffgp.json +++ b/advisories/unreviewed/2024/03/GHSA-gfh2-325r-ffgp/GHSA-gfh2-325r-ffgp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gfh2-325r-ffgp", - "modified": "2024-03-03T00:30:32Z", + "modified": "2024-12-11T15:31:15Z", "published": "2024-03-03T00:30:32Z", "aliases": [ "CVE-2023-52570" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nvfio/mdev: Fix a null-ptr-deref bug for mdev_unregister_parent()\n\nInject fault while probing mdpy.ko, if kstrdup() of create_dir() fails in\nkobject_add_internal() in kobject_init_and_add() in mdev_type_add()\nin parent_create_sysfs_files(), it will return 0 and probe successfully.\nAnd when rmmod mdpy.ko, the mdpy_dev_exit() will call\nmdev_unregister_parent(), the mdev_type_remove() may traverse uninitialized\nparent->types[i] in parent_remove_sysfs_files(), and it will cause\nbelow null-ptr-deref.\n\nIf mdev_type_add() fails, return the error code and kset_unregister()\nto fix the issue.\n\n general protection fault, probably for non-canonical address 0xdffffc0000000002: 0000 [#1] PREEMPT SMP KASAN\n KASAN: null-ptr-deref in range [0x0000000000000010-0x0000000000000017]\n CPU: 2 PID: 10215 Comm: rmmod Tainted: G W N 6.6.0-rc2+ #20\n Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014\n RIP: 0010:__kobject_del+0x62/0x1c0\n Code: 48 89 fa 48 c1 ea 03 80 3c 02 00 0f 85 51 01 00 00 48 b8 00 00 00 00 00 fc ff df 48 8b 6b 28 48 8d 7d 10 48 89 fa 48 c1 ea 03 <80> 3c 02 00 0f 85 24 01 00 00 48 8b 75 10 48 89 df 48 8d 6b 3c e8\n RSP: 0018:ffff88810695fd30 EFLAGS: 00010202\n RAX: dffffc0000000000 RBX: ffffffffa0270268 RCX: 0000000000000000\n RDX: 0000000000000002 RSI: 0000000000000004 RDI: 0000000000000010\n RBP: 0000000000000000 R08: 0000000000000001 R09: ffffed10233a4ef1\n R10: ffff888119d2778b R11: 0000000063666572 R12: 0000000000000000\n R13: fffffbfff404e2d4 R14: dffffc0000000000 R15: ffffffffa0271660\n FS: 00007fbc81981540(0000) GS:ffff888119d00000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 00007fc14a142dc0 CR3: 0000000110a62003 CR4: 0000000000770ee0\n DR0: ffffffff8fb0bce8 DR1: ffffffff8fb0bce9 DR2: ffffffff8fb0bcea\n DR3: ffffffff8fb0bceb DR6: 00000000fffe0ff0 DR7: 0000000000000600\n PKRU: 55555554\n Call Trace:\n \n ? die_addr+0x3d/0xa0\n ? exc_general_protection+0x144/0x220\n ? asm_exc_general_protection+0x22/0x30\n ? __kobject_del+0x62/0x1c0\n kobject_del+0x32/0x50\n parent_remove_sysfs_files+0xd6/0x170 [mdev]\n mdev_unregister_parent+0xfb/0x190 [mdev]\n ? mdev_register_parent+0x270/0x270 [mdev]\n ? find_module_all+0x9d/0xe0\n mdpy_dev_exit+0x17/0x63 [mdpy]\n __do_sys_delete_module.constprop.0+0x2fa/0x4b0\n ? module_flags+0x300/0x300\n ? __fput+0x4e7/0xa00\n do_syscall_64+0x35/0x80\n entry_SYSCALL_64_after_hwframe+0x46/0xb0\n RIP: 0033:0x7fbc813221b7\n Code: 73 01 c3 48 8b 0d d1 8c 2c 00 f7 d8 64 89 01 48 83 c8 ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 b8 b0 00 00 00 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 8b 0d a1 8c 2c 00 f7 d8 64 89 01 48\n RSP: 002b:00007ffe780e0648 EFLAGS: 00000206 ORIG_RAX: 00000000000000b0\n RAX: ffffffffffffffda RBX: 00007ffe780e06a8 RCX: 00007fbc813221b7\n RDX: 000000000000000a RSI: 0000000000000800 RDI: 000055e214df9b58\n RBP: 000055e214df9af0 R08: 00007ffe780df5c1 R09: 0000000000000000\n R10: 00007fbc8139ecc0 R11: 0000000000000206 R12: 00007ffe780e0870\n R13: 00007ffe780e0ed0 R14: 000055e214df9260 R15: 000055e214df9af0\n \n Modules linked in: mdpy(-) mdev vfio_iommu_type1 vfio [last unloaded: mdpy]\n Dumping ftrace buffer:\n (ftrace buffer empty)\n ---[ end trace 0000000000000000 ]---\n RIP: 0010:__kobject_del+0x62/0x1c0\n Code: 48 89 fa 48 c1 ea 03 80 3c 02 00 0f 85 51 01 00 00 48 b8 00 00 00 00 00 fc ff df 48 8b 6b 28 48 8d 7d 10 48 89 fa 48 c1 ea 03 <80> 3c 02 00 0f 85 24 01 00 00 48 8b 75 10 48 89 df 48 8d 6b 3c e8\n RSP: 0018:ffff88810695fd30 EFLAGS: 00010202\n RAX: dffffc0000000000 RBX: ffffffffa0270268 RCX: 0000000000000000\n RDX: 0000000000000002 RSI: 0000000000000004 RDI: 0000000000000010\n RBP: 0000000000000000 R08: 0000000000000001 R09: ffffed10233a4ef1\n R10: ffff888119d2778b R11: 0000000063666572 R12: 0000000000000000\n R13: fffffbfff404e2d4 R14: dffffc0000000000 R15: ffffffffa0271660\n FS: 00007fbc81981540(0000) GS:ffff888119d00000(000\n---truncated---", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-02T22:15:49Z" diff --git a/advisories/unreviewed/2024/03/GHSA-gg3p-v52w-p6fr/GHSA-gg3p-v52w-p6fr.json b/advisories/unreviewed/2024/03/GHSA-gg3p-v52w-p6fr/GHSA-gg3p-v52w-p6fr.json index aaeb64a0797..d200062a82c 100644 --- a/advisories/unreviewed/2024/03/GHSA-gg3p-v52w-p6fr/GHSA-gg3p-v52w-p6fr.json +++ b/advisories/unreviewed/2024/03/GHSA-gg3p-v52w-p6fr/GHSA-gg3p-v52w-p6fr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gg3p-v52w-p6fr", - "modified": "2024-03-03T00:30:32Z", + "modified": "2024-12-11T15:31:14Z", "published": "2024-03-03T00:30:32Z", "aliases": [ "CVE-2023-52563" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/meson: fix memory leak on ->hpd_notify callback\n\nThe EDID returned by drm_bridge_get_edid() needs to be freed.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-02T22:15:48Z" diff --git a/advisories/unreviewed/2024/03/GHSA-mvcc-fjcm-33jm/GHSA-mvcc-fjcm-33jm.json b/advisories/unreviewed/2024/03/GHSA-mvcc-fjcm-33jm/GHSA-mvcc-fjcm-33jm.json index 05a6c2016e7..bb52d3922f6 100644 --- a/advisories/unreviewed/2024/03/GHSA-mvcc-fjcm-33jm/GHSA-mvcc-fjcm-33jm.json +++ b/advisories/unreviewed/2024/03/GHSA-mvcc-fjcm-33jm/GHSA-mvcc-fjcm-33jm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mvcc-fjcm-33jm", - "modified": "2024-03-03T00:30:32Z", + "modified": "2024-12-11T15:31:14Z", "published": "2024-03-03T00:30:32Z", "aliases": [ "CVE-2023-52531" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: iwlwifi: mvm: Fix a memory corruption issue\n\nA few lines above, space is kzalloc()'ed for:\n\tsizeof(struct iwl_nvm_data) +\n\tsizeof(struct ieee80211_channel) +\n\tsizeof(struct ieee80211_rate)\n\n'mvm->nvm_data' is a 'struct iwl_nvm_data', so it is fine.\n\nAt the end of this structure, there is the 'channels' flex array.\nEach element is of type 'struct ieee80211_channel'.\nSo only 1 element is allocated in this array.\n\nWhen doing:\n mvm->nvm_data->bands[0].channels = mvm->nvm_data->channels;\nWe point at the first element of the 'channels' flex array.\nSo this is fine.\n\nHowever, when doing:\n mvm->nvm_data->bands[0].bitrates =\n\t\t\t(void *)((u8 *)mvm->nvm_data->channels + 1);\nbecause of the \"(u8 *)\" cast, we add only 1 to the address of the beginning\nof the flex array.\n\nIt is likely that we want point at the 'struct ieee80211_rate' allocated\njust after.\n\nRemove the spurious casting so that the pointer arithmetic works as\nexpected.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-02T22:15:48Z" diff --git a/advisories/unreviewed/2024/03/GHSA-pcxc-636v-74pc/GHSA-pcxc-636v-74pc.json b/advisories/unreviewed/2024/03/GHSA-pcxc-636v-74pc/GHSA-pcxc-636v-74pc.json index 41c438c0ca4..f5ead7b2dcc 100644 --- a/advisories/unreviewed/2024/03/GHSA-pcxc-636v-74pc/GHSA-pcxc-636v-74pc.json +++ b/advisories/unreviewed/2024/03/GHSA-pcxc-636v-74pc/GHSA-pcxc-636v-74pc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pcxc-636v-74pc", - "modified": "2024-03-03T00:30:32Z", + "modified": "2024-12-11T15:31:15Z", "published": "2024-03-03T00:30:32Z", "aliases": [ "CVE-2023-52565" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: uvcvideo: Fix OOB read\n\nIf the index provided by the user is bigger than the mask size, we might do\nan out of bound read.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-02T22:15:48Z" diff --git a/advisories/unreviewed/2024/03/GHSA-w2cg-jcf6-hrgr/GHSA-w2cg-jcf6-hrgr.json b/advisories/unreviewed/2024/03/GHSA-w2cg-jcf6-hrgr/GHSA-w2cg-jcf6-hrgr.json index 9b8818b3742..467e728be97 100644 --- a/advisories/unreviewed/2024/03/GHSA-w2cg-jcf6-hrgr/GHSA-w2cg-jcf6-hrgr.json +++ b/advisories/unreviewed/2024/03/GHSA-w2cg-jcf6-hrgr/GHSA-w2cg-jcf6-hrgr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-w2cg-jcf6-hrgr", - "modified": "2024-03-03T00:30:32Z", + "modified": "2024-12-11T15:31:14Z", "published": "2024-03-03T00:30:32Z", "aliases": [ "CVE-2023-52520" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86: think-lmi: Fix reference leak\n\nIf a duplicate attribute is found using kset_find_obj(), a reference\nto that attribute is returned which needs to be disposed accordingly\nusing kobject_put(). Move the setting name validation into a separate\nfunction to allow for this change without having to duplicate the\ncleanup code for this setting.\nAs a side note, a very similar bug was fixed in\ncommit 7295a996fdab (\"platform/x86: dell-sysman: Fix reference leak\"),\nso it seems that the bug was copied from that driver.\n\nCompile-tested only.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -33,7 +38,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-02T22:15:48Z" diff --git a/advisories/unreviewed/2024/03/GHSA-wgvh-m7hp-9m4m/GHSA-wgvh-m7hp-9m4m.json b/advisories/unreviewed/2024/03/GHSA-wgvh-m7hp-9m4m/GHSA-wgvh-m7hp-9m4m.json index b554bfcfc9f..0f9aaa8c267 100644 --- a/advisories/unreviewed/2024/03/GHSA-wgvh-m7hp-9m4m/GHSA-wgvh-m7hp-9m4m.json +++ b/advisories/unreviewed/2024/03/GHSA-wgvh-m7hp-9m4m/GHSA-wgvh-m7hp-9m4m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wgvh-m7hp-9m4m", - "modified": "2024-03-03T00:30:31Z", + "modified": "2024-12-11T15:31:14Z", "published": "2024-03-03T00:30:31Z", "aliases": [ "CVE-2023-52509" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nravb: Fix use-after-free issue in ravb_tx_timeout_work()\n\nThe ravb_stop() should call cancel_work_sync(). Otherwise,\nravb_tx_timeout_work() is possible to use the freed priv after\nravb_remove() was called like below:\n\nCPU0\t\t\tCPU1\n\t\t\travb_tx_timeout()\nravb_remove()\nunregister_netdev()\nfree_netdev(ndev)\n// free priv\n\t\t\travb_tx_timeout_work()\n\t\t\t// use priv\n\nunregister_netdev() will call .ndo_stop() so that ravb_stop() is\ncalled. And, after phy_stop() is called, netif_carrier_off()\nis also called. So that .ndo_tx_timeout() will not be called\nafter phy_stop().", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-02T22:15:47Z" diff --git a/advisories/unreviewed/2024/03/GHSA-xc3g-cm27-mcmg/GHSA-xc3g-cm27-mcmg.json b/advisories/unreviewed/2024/03/GHSA-xc3g-cm27-mcmg/GHSA-xc3g-cm27-mcmg.json index a6efdd517e2..732eb9b38b2 100644 --- a/advisories/unreviewed/2024/03/GHSA-xc3g-cm27-mcmg/GHSA-xc3g-cm27-mcmg.json +++ b/advisories/unreviewed/2024/03/GHSA-xc3g-cm27-mcmg/GHSA-xc3g-cm27-mcmg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xc3g-cm27-mcmg", - "modified": "2024-03-03T00:30:32Z", + "modified": "2024-12-11T15:31:14Z", "published": "2024-03-03T00:30:32Z", "aliases": [ "CVE-2023-52526" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nerofs: fix memory leak of LZMA global compressed deduplication\n\nWhen stressing microLZMA EROFS images with the new global compressed\ndeduplication feature enabled (`-Ededupe`), I found some short-lived\ntemporary pages weren't properly released, which could slowly cause\nunexpected OOMs hours later.\n\nLet's fix it now (LZ4 and DEFLATE don't have this issue.)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-02T22:15:48Z" diff --git a/advisories/unreviewed/2024/07/GHSA-3q8w-82vq-p7rq/GHSA-3q8w-82vq-p7rq.json b/advisories/unreviewed/2024/07/GHSA-3q8w-82vq-p7rq/GHSA-3q8w-82vq-p7rq.json index 5a0554e8470..c1bc635d115 100644 --- a/advisories/unreviewed/2024/07/GHSA-3q8w-82vq-p7rq/GHSA-3q8w-82vq-p7rq.json +++ b/advisories/unreviewed/2024/07/GHSA-3q8w-82vq-p7rq/GHSA-3q8w-82vq-p7rq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3q8w-82vq-p7rq", - "modified": "2024-07-30T09:32:02Z", + "modified": "2024-12-11T15:31:15Z", "published": "2024-07-30T09:32:02Z", "aliases": [ "CVE-2024-42141" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: ISO: Check socket flag instead of hcon\n\nThis fixes the following Smatch static checker warning:\n\nnet/bluetooth/iso.c:1364 iso_sock_recvmsg()\nerror: we previously assumed 'pi->conn->hcon' could be null (line 1359)\n\nnet/bluetooth/iso.c\n1347 static int iso_sock_recvmsg(struct socket *sock, struct msghdr *msg,\n1348 size_t len, int flags)\n1349 {\n1350 struct sock *sk = sock->sk;\n1351 struct iso_pinfo *pi = iso_pi(sk);\n1352\n1353 BT_DBG(\"sk %p\", sk);\n1354\n1355 if (test_and_clear_bit(BT_SK_DEFER_SETUP,\n &bt_sk(sk)->flags)) {\n1356 lock_sock(sk);\n1357 switch (sk->sk_state) {\n1358 case BT_CONNECT2:\n1359 if (pi->conn->hcon &&\n ^^^^^^^^^^^^^^ If ->hcon is NULL\n\n1360 test_bit(HCI_CONN_PA_SYNC,\n &pi->conn->hcon->flags)) {\n1361 iso_conn_big_sync(sk);\n1362 sk->sk_state = BT_LISTEN;\n1363 } else {\n--> 1364 iso_conn_defer_accept(pi->conn->hcon);\n ^^^^^^^^^^^^^^\n then we're toast\n\n1365 sk->sk_state = BT_CONFIG;\n1366 }\n1367 release_sock(sk);\n1368 return 0;\n1369 case BT_CONNECTED:\n1370 if (test_bit(BT_SK_PA_SYNC,", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-30T08:15:05Z" diff --git a/advisories/unreviewed/2024/07/GHSA-45vq-73jx-ggvm/GHSA-45vq-73jx-ggvm.json b/advisories/unreviewed/2024/07/GHSA-45vq-73jx-ggvm/GHSA-45vq-73jx-ggvm.json index c7084737da4..d24ab13d405 100644 --- a/advisories/unreviewed/2024/07/GHSA-45vq-73jx-ggvm/GHSA-45vq-73jx-ggvm.json +++ b/advisories/unreviewed/2024/07/GHSA-45vq-73jx-ggvm/GHSA-45vq-73jx-ggvm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-45vq-73jx-ggvm", - "modified": "2024-07-30T09:32:02Z", + "modified": "2024-12-11T15:31:15Z", "published": "2024-07-30T09:32:02Z", "aliases": [ "CVE-2024-42145" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nIB/core: Implement a limit on UMAD receive List\n\nThe existing behavior of ib_umad, which maintains received MAD\npackets in an unbounded list, poses a risk of uncontrolled growth.\nAs user-space applications extract packets from this list, the rate\nof extraction may not match the rate of incoming packets, leading\nto potential list overflow.\n\nTo address this, we introduce a limit to the size of the list. After\nconsidering typical scenarios, such as OpenSM processing, which can\nhandle approximately 100k packets per second, and the 1-second retry\ntimeout for most packets, we set the list size limit to 200k. Packets\nreceived beyond this limit are dropped, assuming they are likely timed\nout by the time they are handled by user-space.\n\nNotably, packets queued on the receive list due to reasons like\ntimed-out sends are preserved even when the list is full.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-770" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-30T08:15:06Z" diff --git a/advisories/unreviewed/2024/07/GHSA-6j8r-9fpw-hmxp/GHSA-6j8r-9fpw-hmxp.json b/advisories/unreviewed/2024/07/GHSA-6j8r-9fpw-hmxp/GHSA-6j8r-9fpw-hmxp.json index 3e9f4198217..175b8512fc8 100644 --- a/advisories/unreviewed/2024/07/GHSA-6j8r-9fpw-hmxp/GHSA-6j8r-9fpw-hmxp.json +++ b/advisories/unreviewed/2024/07/GHSA-6j8r-9fpw-hmxp/GHSA-6j8r-9fpw-hmxp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6j8r-9fpw-hmxp", - "modified": "2024-07-30T09:32:02Z", + "modified": "2024-12-11T15:31:15Z", "published": "2024-07-30T09:32:02Z", "aliases": [ "CVE-2024-42138" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmlxsw: core_linecards: Fix double memory deallocation in case of invalid INI file\n\nIn case of invalid INI file mlxsw_linecard_types_init() deallocates memory\nbut doesn't reset pointer to NULL and returns 0. In case of any error\noccurred after mlxsw_linecard_types_init() call, mlxsw_linecards_init()\ncalls mlxsw_linecard_types_fini() which performs memory deallocation again.\n\nAdd pointer reset to NULL.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-415" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-30T08:15:05Z" diff --git a/advisories/unreviewed/2024/07/GHSA-7vmw-m77g-4fxf/GHSA-7vmw-m77g-4fxf.json b/advisories/unreviewed/2024/07/GHSA-7vmw-m77g-4fxf/GHSA-7vmw-m77g-4fxf.json index 5ee829680c9..2479a332e6a 100644 --- a/advisories/unreviewed/2024/07/GHSA-7vmw-m77g-4fxf/GHSA-7vmw-m77g-4fxf.json +++ b/advisories/unreviewed/2024/07/GHSA-7vmw-m77g-4fxf/GHSA-7vmw-m77g-4fxf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7vmw-m77g-4fxf", - "modified": "2024-07-30T09:32:02Z", + "modified": "2024-12-11T15:31:15Z", "published": "2024-07-30T09:32:02Z", "aliases": [ "CVE-2024-42135" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nvhost_task: Handle SIGKILL by flushing work and exiting\n\nInstead of lingering until the device is closed, this has us handle\nSIGKILL by:\n\n1. marking the worker as killed so we no longer try to use it with\n new virtqueues and new flush operations.\n2. setting the virtqueue to worker mapping so no new works are queued.\n3. running all the exiting works.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -29,7 +34,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-30T08:15:05Z" diff --git a/advisories/unreviewed/2024/07/GHSA-8qf2-p2j7-qp5x/GHSA-8qf2-p2j7-qp5x.json b/advisories/unreviewed/2024/07/GHSA-8qf2-p2j7-qp5x/GHSA-8qf2-p2j7-qp5x.json index 1ff5287eb3e..91f6211fffc 100644 --- a/advisories/unreviewed/2024/07/GHSA-8qf2-p2j7-qp5x/GHSA-8qf2-p2j7-qp5x.json +++ b/advisories/unreviewed/2024/07/GHSA-8qf2-p2j7-qp5x/GHSA-8qf2-p2j7-qp5x.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8qf2-p2j7-qp5x", - "modified": "2024-07-30T09:32:02Z", + "modified": "2024-12-11T15:31:15Z", "published": "2024-07-30T09:32:02Z", "aliases": [ "CVE-2024-42139" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nice: Fix improper extts handling\n\nExtts events are disabled and enabled by the application ts2phc.\nHowever, in case where the driver is removed when the application is\nrunning, a specific extts event remains enabled and can cause a kernel\ncrash.\nAs a side effect, when the driver is reloaded and application is started\nagain, remaining extts event for the channel from a previous run will\nkeep firing and the message \"extts on unexpected channel\" might be\nprinted to the user.\n\nTo avoid that, extts events shall be disabled when PTP is released.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-754" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-30T08:15:05Z" diff --git a/advisories/unreviewed/2024/07/GHSA-g4cc-x94v-f3gm/GHSA-g4cc-x94v-f3gm.json b/advisories/unreviewed/2024/07/GHSA-g4cc-x94v-f3gm/GHSA-g4cc-x94v-f3gm.json index 448c862df12..7268ad17227 100644 --- a/advisories/unreviewed/2024/07/GHSA-g4cc-x94v-f3gm/GHSA-g4cc-x94v-f3gm.json +++ b/advisories/unreviewed/2024/07/GHSA-g4cc-x94v-f3gm/GHSA-g4cc-x94v-f3gm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-g4cc-x94v-f3gm", - "modified": "2024-07-30T09:32:02Z", + "modified": "2024-12-11T15:31:15Z", "published": "2024-07-30T09:32:02Z", "aliases": [ "CVE-2024-42147" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: hisilicon/debugfs - Fix debugfs uninit process issue\n\nDuring the zip probe process, the debugfs failure does not stop\nthe probe. When debugfs initialization fails, jumping to the\nerror branch will also release regs, in addition to its own\nrollback operation.\n\nAs a result, it may be released repeatedly during the regs\nuninit process. Therefore, the null check needs to be added to\nthe regs uninit process.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-415" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-30T08:15:06Z" diff --git a/advisories/unreviewed/2024/07/GHSA-m87g-gjm6-7c8j/GHSA-m87g-gjm6-7c8j.json b/advisories/unreviewed/2024/07/GHSA-m87g-gjm6-7c8j/GHSA-m87g-gjm6-7c8j.json index 309cc61e5c0..60e4279f54f 100644 --- a/advisories/unreviewed/2024/07/GHSA-m87g-gjm6-7c8j/GHSA-m87g-gjm6-7c8j.json +++ b/advisories/unreviewed/2024/07/GHSA-m87g-gjm6-7c8j/GHSA-m87g-gjm6-7c8j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-m87g-gjm6-7c8j", - "modified": "2024-07-30T09:32:02Z", + "modified": "2024-12-11T15:31:15Z", "published": "2024-07-30T09:32:02Z", "aliases": [ "CVE-2024-42142" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: E-switch, Create ingress ACL when needed\n\nCurrently, ingress acl is used for three features. It is created only\nwhen vport metadata match and prio tag are enabled. But active-backup\nlag mode also uses it. It is independent of vport metadata match and\nprio tag. And vport metadata match can be disabled using the\nfollowing devlink command:\n\n # devlink dev param set pci/0000:08:00.0 name esw_port_metadata \\\n\tvalue false cmode runtime\n\nIf ingress acl is not created, will hit panic when creating drop rule\nfor active-backup lag mode. If always create it, there will be about\n5% performance degradation.\n\nFix it by creating ingress acl when needed. If esw_port_metadata is\ntrue, ingress acl exists, then create drop rule using existing\ningress acl. If esw_port_metadata is false, create ingress acl and\nthen create drop rule.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -33,7 +38,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-30T08:15:05Z" diff --git a/advisories/unreviewed/2024/07/GHSA-wx45-rr53-j6w8/GHSA-wx45-rr53-j6w8.json b/advisories/unreviewed/2024/07/GHSA-wx45-rr53-j6w8/GHSA-wx45-rr53-j6w8.json index 448dabed3ad..c80aca1e633 100644 --- a/advisories/unreviewed/2024/07/GHSA-wx45-rr53-j6w8/GHSA-wx45-rr53-j6w8.json +++ b/advisories/unreviewed/2024/07/GHSA-wx45-rr53-j6w8/GHSA-wx45-rr53-j6w8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wx45-rr53-j6w8", - "modified": "2024-07-30T09:32:02Z", + "modified": "2024-12-11T15:31:15Z", "published": "2024-07-30T09:32:02Z", "aliases": [ "CVE-2024-42146" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe: Add outer runtime_pm protection to xe_live_ktest@xe_dma_buf\n\nAny kunit doing any memory access should get their own runtime_pm\nouter references since they don't use the standard driver API\nentries. In special this dma_buf from the same driver.\n\nFound by pre-merge CI on adding WARN calls for unprotected\ninner callers:\n\n<6> [318.639739] # xe_dma_buf_kunit: running xe_test_dmabuf_import_same_driver\n<4> [318.639957] ------------[ cut here ]------------\n<4> [318.639967] xe 0000:4d:00.0: Missing outer runtime PM protection\n<4> [318.640049] WARNING: CPU: 117 PID: 3832 at drivers/gpu/drm/xe/xe_pm.c:533 xe_pm_runtime_get_noresume+0x48/0x60 [xe]", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -25,7 +30,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-30T08:15:06Z" diff --git a/advisories/unreviewed/2024/10/GHSA-28pg-93m7-9jmx/GHSA-28pg-93m7-9jmx.json b/advisories/unreviewed/2024/10/GHSA-28pg-93m7-9jmx/GHSA-28pg-93m7-9jmx.json index e7ce13ec9e3..1623340551f 100644 --- a/advisories/unreviewed/2024/10/GHSA-28pg-93m7-9jmx/GHSA-28pg-93m7-9jmx.json +++ b/advisories/unreviewed/2024/10/GHSA-28pg-93m7-9jmx/GHSA-28pg-93m7-9jmx.json @@ -38,6 +38,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-416", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/10/GHSA-p346-px87-vf2h/GHSA-p346-px87-vf2h.json b/advisories/unreviewed/2024/10/GHSA-p346-px87-vf2h/GHSA-p346-px87-vf2h.json index 525cbc99f76..4b095d159ef 100644 --- a/advisories/unreviewed/2024/10/GHSA-p346-px87-vf2h/GHSA-p346-px87-vf2h.json +++ b/advisories/unreviewed/2024/10/GHSA-p346-px87-vf2h/GHSA-p346-px87-vf2h.json @@ -34,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-401" + "CWE-401", + "CWE-416" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-4p29-qp7w-5p8p/GHSA-4p29-qp7w-5p8p.json b/advisories/unreviewed/2024/11/GHSA-4p29-qp7w-5p8p/GHSA-4p29-qp7w-5p8p.json index cf2f4377fff..68e1660f781 100644 --- a/advisories/unreviewed/2024/11/GHSA-4p29-qp7w-5p8p/GHSA-4p29-qp7w-5p8p.json +++ b/advisories/unreviewed/2024/11/GHSA-4p29-qp7w-5p8p/GHSA-4p29-qp7w-5p8p.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4p29-qp7w-5p8p", - "modified": "2024-11-21T21:33:32Z", + "modified": "2024-12-11T15:31:16Z", "published": "2024-11-21T21:33:32Z", "aliases": [ "CVE-2024-53095" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: Fix use-after-free of network namespace.\n\nRecently, we got a customer report that CIFS triggers oops while\nreconnecting to a server. [0]\n\nThe workload runs on Kubernetes, and some pods mount CIFS servers\nin non-root network namespaces. The problem rarely happened, but\nit was always while the pod was dying.\n\nThe root cause is wrong reference counting for network namespace.\n\nCIFS uses kernel sockets, which do not hold refcnt of the netns that\nthe socket belongs to. That means CIFS must ensure the socket is\nalways freed before its netns; otherwise, use-after-free happens.\n\nThe repro steps are roughly:\n\n 1. mount CIFS in a non-root netns\n 2. drop packets from the netns\n 3. destroy the netns\n 4. unmount CIFS\n\nWe can reproduce the issue quickly with the script [1] below and see\nthe splat [2] if CONFIG_NET_NS_REFCNT_TRACKER is enabled.\n\nWhen the socket is TCP, it is hard to guarantee the netns lifetime\nwithout holding refcnt due to async timers.\n\nLet's hold netns refcnt for each socket as done for SMC in commit\n9744d2bf1976 (\"smc: Fix use-after-free in tcp_write_timer_handler().\").\n\nNote that we need to move put_net() from cifs_put_tcp_session() to\nclean_demultiplex_info(); otherwise, __sock_create() still could touch a\nfreed netns while cifsd tries to reconnect from cifs_demultiplex_thread().\n\nAlso, maybe_get_net() cannot be put just before __sock_create() because\nthe code is not under RCU and there is a small chance that the same\naddress happened to be reallocated to another netns.\n\n[0]:\nCIFS: VFS: \\\\XXXXXXXXXXX has not responded in 15 seconds. Reconnecting...\nCIFS: Serverclose failed 4 times, giving up\nUnable to handle kernel paging request at virtual address 14de99e461f84a07\nMem abort info:\n ESR = 0x0000000096000004\n EC = 0x25: DABT (current EL), IL = 32 bits\n SET = 0, FnV = 0\n EA = 0, S1PTW = 0\n FSC = 0x04: level 0 translation fault\nData abort info:\n ISV = 0, ISS = 0x00000004\n CM = 0, WnR = 0\n[14de99e461f84a07] address between user and kernel address ranges\nInternal error: Oops: 0000000096000004 [#1] SMP\nModules linked in: cls_bpf sch_ingress nls_utf8 cifs cifs_arc4 cifs_md4 dns_resolver tcp_diag inet_diag veth xt_state xt_connmark nf_conntrack_netlink xt_nat xt_statistic xt_MASQUERADE xt_mark xt_addrtype ipt_REJECT nf_reject_ipv4 nft_chain_nat nf_nat xt_conntrack nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 xt_comment nft_compat nf_tables nfnetlink overlay nls_ascii nls_cp437 sunrpc vfat fat aes_ce_blk aes_ce_cipher ghash_ce sm4_ce_cipher sm4 sm3_ce sm3 sha3_ce sha512_ce sha512_arm64 sha1_ce ena button sch_fq_codel loop fuse configfs dmi_sysfs sha2_ce sha256_arm64 dm_mirror dm_region_hash dm_log dm_mod dax efivarfs\nCPU: 5 PID: 2690970 Comm: cifsd Not tainted 6.1.103-109.184.amzn2023.aarch64 #1\nHardware name: Amazon EC2 r7g.4xlarge/, BIOS 1.0 11/1/2018\npstate: 00400005 (nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)\npc : fib_rules_lookup+0x44/0x238\nlr : __fib_lookup+0x64/0xbc\nsp : ffff8000265db790\nx29: ffff8000265db790 x28: 0000000000000000 x27: 000000000000bd01\nx26: 0000000000000000 x25: ffff000b4baf8000 x24: ffff00047b5e4580\nx23: ffff8000265db7e0 x22: 0000000000000000 x21: ffff00047b5e4500\nx20: ffff0010e3f694f8 x19: 14de99e461f849f7 x18: 0000000000000000\nx17: 0000000000000000 x16: 0000000000000000 x15: 0000000000000000\nx14: 0000000000000000 x13: 0000000000000000 x12: 3f92800abd010002\nx11: 0000000000000001 x10: ffff0010e3f69420 x9 : ffff800008a6f294\nx8 : 0000000000000000 x7 : 0000000000000006 x6 : 0000000000000000\nx5 : 0000000000000001 x4 : ffff001924354280 x3 : ffff8000265db7e0\nx2 : 0000000000000000 x1 : ffff0010e3f694f8 x0 : ffff00047b5e4500\nCall trace:\n fib_rules_lookup+0x44/0x238\n __fib_lookup+0x64/0xbc\n ip_route_output_key_hash_rcu+0x2c4/0x398\n ip_route_output_key_hash+0x60/0x8c\n tcp_v4_connect+0x290/0x488\n __inet_stream_connect+0x108/0x3d0\n inet_stream_connect+0x50/0x78\n kernel_connect+0x6c/0xac\n generic_ip_conne\n---truncated---", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-21T19:15:12Z" diff --git a/advisories/unreviewed/2024/11/GHSA-5684-4xfg-mxj4/GHSA-5684-4xfg-mxj4.json b/advisories/unreviewed/2024/11/GHSA-5684-4xfg-mxj4/GHSA-5684-4xfg-mxj4.json index 5095623f9bc..d99aeb2769c 100644 --- a/advisories/unreviewed/2024/11/GHSA-5684-4xfg-mxj4/GHSA-5684-4xfg-mxj4.json +++ b/advisories/unreviewed/2024/11/GHSA-5684-4xfg-mxj4/GHSA-5684-4xfg-mxj4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5684-4xfg-mxj4", - "modified": "2024-11-13T21:30:32Z", + "modified": "2024-12-11T15:31:15Z", "published": "2024-11-09T12:30:47Z", "aliases": [ "CVE-2024-50217" diff --git a/advisories/unreviewed/2024/11/GHSA-56gp-6mw9-wpfj/GHSA-56gp-6mw9-wpfj.json b/advisories/unreviewed/2024/11/GHSA-56gp-6mw9-wpfj/GHSA-56gp-6mw9-wpfj.json index 0d7d309f19d..543fb9c64e9 100644 --- a/advisories/unreviewed/2024/11/GHSA-56gp-6mw9-wpfj/GHSA-56gp-6mw9-wpfj.json +++ b/advisories/unreviewed/2024/11/GHSA-56gp-6mw9-wpfj/GHSA-56gp-6mw9-wpfj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-56gp-6mw9-wpfj", - "modified": "2024-11-28T18:38:37Z", + "modified": "2024-12-11T15:31:16Z", "published": "2024-11-28T18:38:37Z", "aliases": [ "CVE-2023-52922" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: bcm: Fix UAF in bcm_proc_show()\n\nBUG: KASAN: slab-use-after-free in bcm_proc_show+0x969/0xa80\nRead of size 8 at addr ffff888155846230 by task cat/7862\n\nCPU: 1 PID: 7862 Comm: cat Not tainted 6.5.0-rc1-00153-gc8746099c197 #230\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014\nCall Trace:\n \n dump_stack_lvl+0xd5/0x150\n print_report+0xc1/0x5e0\n kasan_report+0xba/0xf0\n bcm_proc_show+0x969/0xa80\n seq_read_iter+0x4f6/0x1260\n seq_read+0x165/0x210\n proc_reg_read+0x227/0x300\n vfs_read+0x1d5/0x8d0\n ksys_read+0x11e/0x240\n do_syscall_64+0x35/0xb0\n entry_SYSCALL_64_after_hwframe+0x63/0xcd\n\nAllocated by task 7846:\n kasan_save_stack+0x1e/0x40\n kasan_set_track+0x21/0x30\n __kasan_kmalloc+0x9e/0xa0\n bcm_sendmsg+0x264b/0x44e0\n sock_sendmsg+0xda/0x180\n ____sys_sendmsg+0x735/0x920\n ___sys_sendmsg+0x11d/0x1b0\n __sys_sendmsg+0xfa/0x1d0\n do_syscall_64+0x35/0xb0\n entry_SYSCALL_64_after_hwframe+0x63/0xcd\n\nFreed by task 7846:\n kasan_save_stack+0x1e/0x40\n kasan_set_track+0x21/0x30\n kasan_save_free_info+0x27/0x40\n ____kasan_slab_free+0x161/0x1c0\n slab_free_freelist_hook+0x119/0x220\n __kmem_cache_free+0xb4/0x2e0\n rcu_core+0x809/0x1bd0\n\nbcm_op is freed before procfs entry be removed in bcm_release(),\nthis lead to bcm_proc_show() may read the freed bcm_op.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-28T15:15:17Z" diff --git a/advisories/unreviewed/2024/11/GHSA-9w6j-hvpp-85hf/GHSA-9w6j-hvpp-85hf.json b/advisories/unreviewed/2024/11/GHSA-9w6j-hvpp-85hf/GHSA-9w6j-hvpp-85hf.json index 7ebb3b27a42..6f953c09875 100644 --- a/advisories/unreviewed/2024/11/GHSA-9w6j-hvpp-85hf/GHSA-9w6j-hvpp-85hf.json +++ b/advisories/unreviewed/2024/11/GHSA-9w6j-hvpp-85hf/GHSA-9w6j-hvpp-85hf.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-r79x-wgrg-2v77/GHSA-r79x-wgrg-2v77.json b/advisories/unreviewed/2024/11/GHSA-r79x-wgrg-2v77/GHSA-r79x-wgrg-2v77.json index 66b604161b6..41c8fac2284 100644 --- a/advisories/unreviewed/2024/11/GHSA-r79x-wgrg-2v77/GHSA-r79x-wgrg-2v77.json +++ b/advisories/unreviewed/2024/11/GHSA-r79x-wgrg-2v77/GHSA-r79x-wgrg-2v77.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-r79x-wgrg-2v77", - "modified": "2024-11-19T03:31:08Z", + "modified": "2024-12-11T15:31:16Z", "published": "2024-11-19T03:31:08Z", "aliases": [ "CVE-2024-50280" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndm cache: fix flushing uninitialized delayed_work on cache_ctr error\n\nAn unexpected WARN_ON from flush_work() may occur when cache creation\nfails, caused by destroying the uninitialized delayed_work waker in the\nerror path of cache_create(). For example, the warning appears on the\nsuperblock checksum error.\n\nReproduce steps:\n\ndmsetup create cmeta --table \"0 8192 linear /dev/sdc 0\"\ndmsetup create cdata --table \"0 65536 linear /dev/sdc 8192\"\ndmsetup create corig --table \"0 524288 linear /dev/sdc 262144\"\ndd if=/dev/urandom of=/dev/mapper/cmeta bs=4k count=1 oflag=direct\ndmsetup create cache --table \"0 524288 cache /dev/mapper/cmeta \\\n/dev/mapper/cdata /dev/mapper/corig 128 2 metadata2 writethrough smq 0\"\n\nKernel logs:\n\n(snip)\nWARNING: CPU: 0 PID: 84 at kernel/workqueue.c:4178 __flush_work+0x5d4/0x890\n\nFix by pulling out the cancel_delayed_work_sync() from the constructor's\nerror path. This patch doesn't affect the use-after-free fix for\nconcurrent dm_resume and dm_destroy (commit 6a459d8edbdb (\"dm cache: Fix\nUAF in destroy()\")) as cache_dtr is not changed.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-19T02:16:30Z" diff --git a/advisories/unreviewed/2024/12/GHSA-362j-p2h8-qq8p/GHSA-362j-p2h8-qq8p.json b/advisories/unreviewed/2024/12/GHSA-362j-p2h8-qq8p/GHSA-362j-p2h8-qq8p.json index 53e71ad02bc..ed52404072b 100644 --- a/advisories/unreviewed/2024/12/GHSA-362j-p2h8-qq8p/GHSA-362j-p2h8-qq8p.json +++ b/advisories/unreviewed/2024/12/GHSA-362j-p2h8-qq8p/GHSA-362j-p2h8-qq8p.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-362j-p2h8-qq8p", - "modified": "2024-12-10T21:30:52Z", + "modified": "2024-12-11T15:31:16Z", "published": "2024-12-10T21:30:52Z", "aliases": [ "CVE-2024-46341" ], "details": "TP-Link TL-WR845N(UN)_V4_190219 was discovered to transmit credentials in base64 encoded form, which can be easily decoded by an attacker executing a man-in-the-middle attack.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-522" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-10T20:15:15Z" diff --git a/advisories/unreviewed/2024/12/GHSA-46mh-fqpf-6685/GHSA-46mh-fqpf-6685.json b/advisories/unreviewed/2024/12/GHSA-46mh-fqpf-6685/GHSA-46mh-fqpf-6685.json index 599963494b1..e4af558f0f6 100644 --- a/advisories/unreviewed/2024/12/GHSA-46mh-fqpf-6685/GHSA-46mh-fqpf-6685.json +++ b/advisories/unreviewed/2024/12/GHSA-46mh-fqpf-6685/GHSA-46mh-fqpf-6685.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-46mh-fqpf-6685", - "modified": "2024-12-10T21:30:52Z", + "modified": "2024-12-11T15:31:16Z", "published": "2024-12-10T21:30:52Z", "aliases": [ "CVE-2024-46442" ], "details": "An issue in the BYD Dilink Headunit System v3.0 to v4.0 allows attackers to bypass authentication via a bruteforce attack.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-307" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-10T19:15:27Z" diff --git a/advisories/unreviewed/2024/12/GHSA-4c8h-4mm2-mm5g/GHSA-4c8h-4mm2-mm5g.json b/advisories/unreviewed/2024/12/GHSA-4c8h-4mm2-mm5g/GHSA-4c8h-4mm2-mm5g.json index 9f23bbb7927..63ff0645fff 100644 --- a/advisories/unreviewed/2024/12/GHSA-4c8h-4mm2-mm5g/GHSA-4c8h-4mm2-mm5g.json +++ b/advisories/unreviewed/2024/12/GHSA-4c8h-4mm2-mm5g/GHSA-4c8h-4mm2-mm5g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4c8h-4mm2-mm5g", - "modified": "2024-12-10T21:30:52Z", + "modified": "2024-12-11T15:31:16Z", "published": "2024-12-10T21:30:52Z", "aliases": [ "CVE-2024-55550" ], "details": "Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sanitization. A successful exploit could allow the authenticated admin attacker to access resources that are constrained to the admin access level, and the disclosure is limited to non-sensitive system information. This vulnerability does not allow file modification or privilege escalation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-10T19:15:31Z" diff --git a/advisories/unreviewed/2024/12/GHSA-4gff-x4ff-9qq7/GHSA-4gff-x4ff-9qq7.json b/advisories/unreviewed/2024/12/GHSA-4gff-x4ff-9qq7/GHSA-4gff-x4ff-9qq7.json new file mode 100644 index 00000000000..8025ae5d9e6 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-4gff-x4ff-9qq7/GHSA-4gff-x4ff-9qq7.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4gff-x4ff-9qq7", + "modified": "2024-12-11T15:31:16Z", + "published": "2024-12-11T15:31:16Z", + "aliases": [ + "CVE-2024-50585" + ], + "details": "Users who click on a malicious link or visit a website under the control of an attacker can be infected with arbitrary JavaScript which is running in the context of the \"Numerix License Server Administration System Login\" (nlslogin.jsp) page. The vulnerability can be triggered by sending a specially crafted HTTP POST request. \n\n\n\nThe vendor was unresponsive during multiple attempts to contact them via various channels, hence there is no solution available. In case you are using this software, be sure to restrict access and monitor logs. Try to reach out to your contact person for this vendor and request a patch.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50585" + }, + { + "type": "WEB", + "url": "https://r.sec-consult.com/numerix" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-11T15:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-8q4m-8m4v-c2rm/GHSA-8q4m-8m4v-c2rm.json b/advisories/unreviewed/2024/12/GHSA-8q4m-8m4v-c2rm/GHSA-8q4m-8m4v-c2rm.json new file mode 100644 index 00000000000..756508c106b --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-8q4m-8m4v-c2rm/GHSA-8q4m-8m4v-c2rm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8q4m-8m4v-c2rm", + "modified": "2024-12-11T15:31:16Z", + "published": "2024-12-11T15:31:16Z", + "aliases": [ + "CVE-2023-23472" + ], + "details": "IBM InfoSphere DataStage Flow Designer (InfoSphere Information Server 11.7) could allow an authenticated user to obtain sensitive information that could aid in further attacks against the system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23472" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/6988167" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-497" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-11T13:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-8q75-6f6h-8grp/GHSA-8q75-6f6h-8grp.json b/advisories/unreviewed/2024/12/GHSA-8q75-6f6h-8grp/GHSA-8q75-6f6h-8grp.json index ff57d87f1d6..3bc93796289 100644 --- a/advisories/unreviewed/2024/12/GHSA-8q75-6f6h-8grp/GHSA-8q75-6f6h-8grp.json +++ b/advisories/unreviewed/2024/12/GHSA-8q75-6f6h-8grp/GHSA-8q75-6f6h-8grp.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-78" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/12/GHSA-c52g-v6h9-jghm/GHSA-c52g-v6h9-jghm.json b/advisories/unreviewed/2024/12/GHSA-c52g-v6h9-jghm/GHSA-c52g-v6h9-jghm.json index 8050ee13059..c0a5215c226 100644 --- a/advisories/unreviewed/2024/12/GHSA-c52g-v6h9-jghm/GHSA-c52g-v6h9-jghm.json +++ b/advisories/unreviewed/2024/12/GHSA-c52g-v6h9-jghm/GHSA-c52g-v6h9-jghm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c52g-v6h9-jghm", - "modified": "2024-12-05T12:31:28Z", + "modified": "2024-12-11T15:31:16Z", "published": "2024-12-04T15:31:52Z", "aliases": [ "CVE-2024-53130" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: fix null-ptr-deref in block_dirty_buffer tracepoint\n\nWhen using the \"block:block_dirty_buffer\" tracepoint, mark_buffer_dirty()\nmay cause a NULL pointer dereference, or a general protection fault when\nKASAN is enabled.\n\nThis happens because, since the tracepoint was added in\nmark_buffer_dirty(), it references the dev_t member bh->b_bdev->bd_dev\nregardless of whether the buffer head has a pointer to a block_device\nstructure.\n\nIn the current implementation, nilfs_grab_buffer(), which grabs a buffer\nto read (or create) a block of metadata, including b-tree node blocks,\ndoes not set the block device, but instead does so only if the buffer is\nnot in the \"uptodate\" state for each of its caller block reading\nfunctions. However, if the uptodate flag is set on a folio/page, and the\nbuffer heads are detached from it by try_to_free_buffers(), and new buffer\nheads are then attached by create_empty_buffers(), the uptodate flag may\nbe restored to each buffer without the block device being set to\nbh->b_bdev, and mark_buffer_dirty() may be called later in that state,\nresulting in the bug mentioned above.\n\nFix this issue by making nilfs_grab_buffer() always set the block device\nof the super block structure to the buffer head, regardless of the state\nof the buffer's uptodate flag.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-04T15:15:12Z" diff --git a/advisories/unreviewed/2024/12/GHSA-c5j4-2m6v-w9gr/GHSA-c5j4-2m6v-w9gr.json b/advisories/unreviewed/2024/12/GHSA-c5j4-2m6v-w9gr/GHSA-c5j4-2m6v-w9gr.json index 519e48d5049..f6f26258517 100644 --- a/advisories/unreviewed/2024/12/GHSA-c5j4-2m6v-w9gr/GHSA-c5j4-2m6v-w9gr.json +++ b/advisories/unreviewed/2024/12/GHSA-c5j4-2m6v-w9gr/GHSA-c5j4-2m6v-w9gr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c5j4-2m6v-w9gr", - "modified": "2024-12-10T21:30:52Z", + "modified": "2024-12-11T15:31:16Z", "published": "2024-12-10T21:30:52Z", "aliases": [ "CVE-2024-49533" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://helpx.adobe.com/security/products/acrobat/apsb24-92.html" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2070" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/12/GHSA-cjh5-vw7v-698x/GHSA-cjh5-vw7v-698x.json b/advisories/unreviewed/2024/12/GHSA-cjh5-vw7v-698x/GHSA-cjh5-vw7v-698x.json index 1b6072d7590..d5cebc059ad 100644 --- a/advisories/unreviewed/2024/12/GHSA-cjh5-vw7v-698x/GHSA-cjh5-vw7v-698x.json +++ b/advisories/unreviewed/2024/12/GHSA-cjh5-vw7v-698x/GHSA-cjh5-vw7v-698x.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cjh5-vw7v-698x", - "modified": "2024-12-04T00:31:32Z", + "modified": "2024-12-11T15:31:16Z", "published": "2024-12-04T00:31:32Z", "aliases": [ "CVE-2024-51363" ], "details": "Insecure deserialization in Hodoku v2.3.0 to v2.3.2 allows attackers to execute arbitrary code.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-03T22:15:05Z" diff --git a/advisories/unreviewed/2024/12/GHSA-fg92-6xpx-v2x4/GHSA-fg92-6xpx-v2x4.json b/advisories/unreviewed/2024/12/GHSA-fg92-6xpx-v2x4/GHSA-fg92-6xpx-v2x4.json index 0b365a3c460..2356136d1c2 100644 --- a/advisories/unreviewed/2024/12/GHSA-fg92-6xpx-v2x4/GHSA-fg92-6xpx-v2x4.json +++ b/advisories/unreviewed/2024/12/GHSA-fg92-6xpx-v2x4/GHSA-fg92-6xpx-v2x4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fg92-6xpx-v2x4", - "modified": "2024-12-02T09:39:12Z", + "modified": "2024-12-11T15:31:16Z", "published": "2024-12-02T09:39:12Z", "aliases": [ "CVE-2024-53104" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format\n\nThis can lead to out of bounds writes since frames of this type were not\ntaken into account when calculating the size of the frames buffer in\nuvc_parse_streaming.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -52,8 +57,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-02T08:15:08Z" diff --git a/advisories/unreviewed/2024/12/GHSA-h288-5fq8-5pfw/GHSA-h288-5fq8-5pfw.json b/advisories/unreviewed/2024/12/GHSA-h288-5fq8-5pfw/GHSA-h288-5fq8-5pfw.json index 0c1b599f00a..8edc6581704 100644 --- a/advisories/unreviewed/2024/12/GHSA-h288-5fq8-5pfw/GHSA-h288-5fq8-5pfw.json +++ b/advisories/unreviewed/2024/12/GHSA-h288-5fq8-5pfw/GHSA-h288-5fq8-5pfw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h288-5fq8-5pfw", - "modified": "2024-12-11T12:32:26Z", + "modified": "2024-12-11T15:31:16Z", "published": "2024-12-11T09:32:03Z", "aliases": [ "CVE-2024-11053" ], "details": "When asked to both use a `.netrc` file for credentials and to follow HTTP\nredirects, curl could leak the password used for the first host to the\nfollowed-to host under certain circumstances.\n\nThis flaw only manifests itself if the netrc file has an entry that matches\nthe redirect target hostname but the entry either omits just the password or\nomits both login and password.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -33,7 +38,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-11T08:15:05Z" diff --git a/advisories/unreviewed/2024/12/GHSA-hqgr-6w6j-4xpp/GHSA-hqgr-6w6j-4xpp.json b/advisories/unreviewed/2024/12/GHSA-hqgr-6w6j-4xpp/GHSA-hqgr-6w6j-4xpp.json new file mode 100644 index 00000000000..e8197b5cb1e --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-hqgr-6w6j-4xpp/GHSA-hqgr-6w6j-4xpp.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hqgr-6w6j-4xpp", + "modified": "2024-12-11T15:31:16Z", + "published": "2024-12-11T15:31:16Z", + "aliases": [ + "CVE-2024-11351" + ], + "details": "The Restrict – membership, site, content and user access restrictions for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.8 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restricted to higher-level roles such as administrator.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11351" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3201494/restricted-content" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/de982653-26b4-4a7b-a391-373362bcb834?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-11T13:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-hwfm-86r3-467v/GHSA-hwfm-86r3-467v.json b/advisories/unreviewed/2024/12/GHSA-hwfm-86r3-467v/GHSA-hwfm-86r3-467v.json index 76a0c6a8dc9..ca45ad4a544 100644 --- a/advisories/unreviewed/2024/12/GHSA-hwfm-86r3-467v/GHSA-hwfm-86r3-467v.json +++ b/advisories/unreviewed/2024/12/GHSA-hwfm-86r3-467v/GHSA-hwfm-86r3-467v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hwfm-86r3-467v", - "modified": "2024-12-10T18:31:07Z", + "modified": "2024-12-11T15:31:16Z", "published": "2024-12-10T18:31:07Z", "aliases": [ "CVE-2024-45494" ], "details": "An issue was discovered in MSA Safety FieldServer Gateways and Embedded Modules with build revisions before 7.0.0. The FieldServer Gateway has an internally used shared administrative user account on all devices. The authentication for this user is implemented through an unsafe shared secret that is static in all affected firmware versions.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-276" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-10T17:15:10Z" diff --git a/advisories/unreviewed/2024/12/GHSA-p28q-ghm8-cw23/GHSA-p28q-ghm8-cw23.json b/advisories/unreviewed/2024/12/GHSA-p28q-ghm8-cw23/GHSA-p28q-ghm8-cw23.json index 9e81ba287e3..ca6d071154b 100644 --- a/advisories/unreviewed/2024/12/GHSA-p28q-ghm8-cw23/GHSA-p28q-ghm8-cw23.json +++ b/advisories/unreviewed/2024/12/GHSA-p28q-ghm8-cw23/GHSA-p28q-ghm8-cw23.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p28q-ghm8-cw23", - "modified": "2024-12-04T15:31:53Z", + "modified": "2024-12-11T15:31:16Z", "published": "2024-12-04T15:31:53Z", "aliases": [ "CVE-2024-53139" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: fix possible UAF in sctp_v6_available()\n\nA lockdep report [1] with CONFIG_PROVE_RCU_LIST=y hints\nthat sctp_v6_available() is calling dev_get_by_index_rcu()\nand ipv6_chk_addr() without holding rcu.\n\n[1]\n =============================\n WARNING: suspicious RCU usage\n 6.12.0-rc5-virtme #1216 Tainted: G W\n -----------------------------\n net/core/dev.c:876 RCU-list traversed in non-reader section!!\n\nother info that might help us debug this:\n\nrcu_scheduler_active = 2, debug_locks = 1\n 1 lock held by sctp_hello/31495:\n #0: ffff9f1ebbdb7418 (sk_lock-AF_INET6){+.+.}-{0:0}, at: sctp_bind (./arch/x86/include/asm/jump_label.h:27 net/sctp/socket.c:315) sctp\n\nstack backtrace:\n CPU: 7 UID: 0 PID: 31495 Comm: sctp_hello Tainted: G W 6.12.0-rc5-virtme #1216\n Tainted: [W]=WARN\n Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014\n Call Trace:\n \n dump_stack_lvl (lib/dump_stack.c:123)\n lockdep_rcu_suspicious (kernel/locking/lockdep.c:6822)\n dev_get_by_index_rcu (net/core/dev.c:876 (discriminator 7))\n sctp_v6_available (net/sctp/ipv6.c:701) sctp\n sctp_do_bind (net/sctp/socket.c:400 (discriminator 1)) sctp\n sctp_bind (net/sctp/socket.c:320) sctp\n inet6_bind_sk (net/ipv6/af_inet6.c:465)\n ? security_socket_bind (security/security.c:4581 (discriminator 1))\n __sys_bind (net/socket.c:1848 net/socket.c:1869)\n ? do_user_addr_fault (./include/linux/rcupdate.h:347 ./include/linux/rcupdate.h:880 ./include/linux/mm.h:729 arch/x86/mm/fault.c:1340)\n ? do_user_addr_fault (./arch/x86/include/asm/preempt.h:84 (discriminator 13) ./include/linux/rcupdate.h:98 (discriminator 13) ./include/linux/rcupdate.h:882 (discriminator 13) ./include/linux/mm.h:729 (discriminator 13) arch/x86/mm/fault.c:1340 (discriminator 13))\n __x64_sys_bind (net/socket.c:1877 (discriminator 1) net/socket.c:1875 (discriminator 1) net/socket.c:1875 (discriminator 1))\n do_syscall_64 (arch/x86/entry/common.c:52 (discriminator 1) arch/x86/entry/common.c:83 (discriminator 1))\n entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130)\n RIP: 0033:0x7f59b934a1e7\n Code: 44 00 00 48 8b 15 39 8c 0c 00 f7 d8 64 89 02 b8 ff ff ff ff eb bd 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 00 b8 31 00 00 00 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 8b 0d 09 8c 0c 00 f7 d8 64 89 01 48\nAll code\n========\n 0:\t44 00 00 \tadd %r8b,(%rax)\n 3:\t48 8b 15 39 8c 0c 00 \tmov 0xc8c39(%rip),%rdx # 0xc8c43\n a:\tf7 d8 \tneg %eax\n c:\t64 89 02 \tmov %eax,%fs:(%rdx)\n f:\tb8 ff ff ff ff \tmov $0xffffffff,%eax\n 14:\teb bd \tjmp 0xffffffffffffffd3\n 16:\t66 2e 0f 1f 84 00 00 \tcs nopw 0x0(%rax,%rax,1)\n 1d:\t00 00 00\n 20:\t0f 1f 00 \tnopl (%rax)\n 23:\tb8 31 00 00 00 \tmov $0x31,%eax\n 28:\t0f 05 \tsyscall\n 2a:*\t48 3d 01 f0 ff ff \tcmp $0xfffffffffffff001,%rax\t\t<-- trapping instruction\n 30:\t73 01 \tjae 0x33\n 32:\tc3 \tret\n 33:\t48 8b 0d 09 8c 0c 00 \tmov 0xc8c09(%rip),%rcx # 0xc8c43\n 3a:\tf7 d8 \tneg %eax\n 3c:\t64 89 01 \tmov %eax,%fs:(%rcx)\n 3f:\t48 \trex.W\n\nCode starting with the faulting instruction\n===========================================\n 0:\t48 3d 01 f0 ff ff \tcmp $0xfffffffffffff001,%rax\n 6:\t73 01 \tjae 0x9\n 8:\tc3 \tret\n 9:\t48 8b 0d 09 8c 0c 00 \tmov 0xc8c09(%rip),%rcx # 0xc8c19\n 10:\tf7 d8 \tneg %eax\n 12:\t64 89 01 \tmov %eax,%fs:(%rcx)\n 15:\t48 \trex.W\n RSP: 002b:00007ffe2d0ad398 EFLAGS: 00000202 ORIG_RAX: 0000000000000031\n RAX: ffffffffffffffda RBX: 00007ffe2d0ad3d0 RCX: 00007f59b934a1e7\n RDX: 000000000000001c RSI: 00007ffe2d0ad3d0 RDI: 0000000000000005\n RBP: 0000000000000005 R08: 1999999999999999 R09: 0000000000000000\n R10: 00007f59b9253298 R11: 000000000000\n---truncated---", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-04T15:15:15Z" diff --git a/advisories/unreviewed/2024/12/GHSA-p85v-4hp9-vq4r/GHSA-p85v-4hp9-vq4r.json b/advisories/unreviewed/2024/12/GHSA-p85v-4hp9-vq4r/GHSA-p85v-4hp9-vq4r.json index 77698e27f90..382f3d33951 100644 --- a/advisories/unreviewed/2024/12/GHSA-p85v-4hp9-vq4r/GHSA-p85v-4hp9-vq4r.json +++ b/advisories/unreviewed/2024/12/GHSA-p85v-4hp9-vq4r/GHSA-p85v-4hp9-vq4r.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p85v-4hp9-vq4r", - "modified": "2024-12-05T12:31:28Z", + "modified": "2024-12-11T15:31:16Z", "published": "2024-12-04T15:31:52Z", "aliases": [ "CVE-2024-53131" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: fix null-ptr-deref in block_touch_buffer tracepoint\n\nPatch series \"nilfs2: fix null-ptr-deref bugs on block tracepoints\".\n\nThis series fixes null pointer dereference bugs that occur when using\nnilfs2 and two block-related tracepoints.\n\n\nThis patch (of 2):\n\nIt has been reported that when using \"block:block_touch_buffer\"\ntracepoint, touch_buffer() called from __nilfs_get_folio_block() causes a\nNULL pointer dereference, or a general protection fault when KASAN is\nenabled.\n\nThis happens because since the tracepoint was added in touch_buffer(), it\nreferences the dev_t member bh->b_bdev->bd_dev regardless of whether the\nbuffer head has a pointer to a block_device structure. In the current\nimplementation, the block_device structure is set after the function\nreturns to the caller.\n\nHere, touch_buffer() is used to mark the folio/page that owns the buffer\nhead as accessed, but the common search helper for folio/page used by the\ncaller function was optimized to mark the folio/page as accessed when it\nwas reimplemented a long time ago, eliminating the need to call\ntouch_buffer() here in the first place.\n\nSo this solves the issue by eliminating the touch_buffer() call itself.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-04T15:15:13Z" diff --git a/advisories/unreviewed/2024/12/GHSA-prj7-gm8m-736f/GHSA-prj7-gm8m-736f.json b/advisories/unreviewed/2024/12/GHSA-prj7-gm8m-736f/GHSA-prj7-gm8m-736f.json index 273e1a1c7c1..d19196b17d1 100644 --- a/advisories/unreviewed/2024/12/GHSA-prj7-gm8m-736f/GHSA-prj7-gm8m-736f.json +++ b/advisories/unreviewed/2024/12/GHSA-prj7-gm8m-736f/GHSA-prj7-gm8m-736f.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-prj7-gm8m-736f", - "modified": "2024-12-04T00:31:32Z", + "modified": "2024-12-11T15:31:16Z", "published": "2024-12-04T00:31:32Z", "aliases": [ "CVE-2024-46625" ], "details": "An authenticated arbitrary file upload vulnerability in the /documentCache/upload endpoint of InfoDom Performa 365 v4.0.1 allows attackers to execute arbitrary code via uploading a crafted SVG file.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-434" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-03T22:15:04Z" diff --git a/advisories/unreviewed/2024/12/GHSA-px72-8g3v-62xm/GHSA-px72-8g3v-62xm.json b/advisories/unreviewed/2024/12/GHSA-px72-8g3v-62xm/GHSA-px72-8g3v-62xm.json index 42208c8f773..61dba3d781a 100644 --- a/advisories/unreviewed/2024/12/GHSA-px72-8g3v-62xm/GHSA-px72-8g3v-62xm.json +++ b/advisories/unreviewed/2024/12/GHSA-px72-8g3v-62xm/GHSA-px72-8g3v-62xm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-px72-8g3v-62xm", - "modified": "2024-12-10T21:30:52Z", + "modified": "2024-12-11T15:31:16Z", "published": "2024-12-10T21:30:52Z", "aliases": [ "CVE-2024-49534" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://helpx.adobe.com/security/products/acrobat/apsb24-92.html" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2076" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/12/GHSA-v8rw-4jh7-4cx9/GHSA-v8rw-4jh7-4cx9.json b/advisories/unreviewed/2024/12/GHSA-v8rw-4jh7-4cx9/GHSA-v8rw-4jh7-4cx9.json index af733f02a2b..f9abfbee4e2 100644 --- a/advisories/unreviewed/2024/12/GHSA-v8rw-4jh7-4cx9/GHSA-v8rw-4jh7-4cx9.json +++ b/advisories/unreviewed/2024/12/GHSA-v8rw-4jh7-4cx9/GHSA-v8rw-4jh7-4cx9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-v8rw-4jh7-4cx9", - "modified": "2024-12-10T21:30:52Z", + "modified": "2024-12-11T15:31:16Z", "published": "2024-12-10T21:30:52Z", "aliases": [ "CVE-2024-46340" ], "details": "TP-Link TL-WR845N(UN)_V4_200909 and TL-WR845N(UN)_V4_190219 was discovered to transmit user credentials in plaintext after executing a factory reset.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-312" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-10T20:15:15Z" diff --git a/advisories/unreviewed/2024/12/GHSA-w6fv-cg9x-p5jx/GHSA-w6fv-cg9x-p5jx.json b/advisories/unreviewed/2024/12/GHSA-w6fv-cg9x-p5jx/GHSA-w6fv-cg9x-p5jx.json index 88a313f7611..3cb152aed2d 100644 --- a/advisories/unreviewed/2024/12/GHSA-w6fv-cg9x-p5jx/GHSA-w6fv-cg9x-p5jx.json +++ b/advisories/unreviewed/2024/12/GHSA-w6fv-cg9x-p5jx/GHSA-w6fv-cg9x-p5jx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-w6fv-cg9x-p5jx", - "modified": "2024-12-10T21:30:53Z", + "modified": "2024-12-11T15:31:16Z", "published": "2024-12-10T21:30:53Z", "aliases": [ "CVE-2024-51165" ], "details": "SQL injection vulnerability in JEPAAS7.2.8, via /je/rbac/rbac/loadLoginCount in the dateVal parameter, which could allow a remote user to submit a specially crafted query, allowing an attacker to retrieve all the information stored in the DB.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-10T20:15:20Z" diff --git a/advisories/unreviewed/2024/12/GHSA-x486-v4r3-8xm3/GHSA-x486-v4r3-8xm3.json b/advisories/unreviewed/2024/12/GHSA-x486-v4r3-8xm3/GHSA-x486-v4r3-8xm3.json new file mode 100644 index 00000000000..1e37cbffc7a --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-x486-v4r3-8xm3/GHSA-x486-v4r3-8xm3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x486-v4r3-8xm3", + "modified": "2024-12-11T15:31:16Z", + "published": "2024-12-11T15:31:16Z", + "aliases": [ + "CVE-2024-51460" + ], + "details": "IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information when a detailed technical error message is returned in a stack trace. This information could be used in further attacks against the system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51460" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7177698" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-209" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-11T13:15:06Z" + } +} \ No newline at end of file