From 7b8f2a0a7214ba42b032ea21090e18f3ad426eb5 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 20 Feb 2024 21:31:50 +0000 Subject: [PATCH] Publish Advisories GHSA-p86h-23p7-v2rx GHSA-276r-vcw2-xfq4 GHSA-45hh-rj6v-548f GHSA-25g3-q597-79m8 GHSA-372x-c6rw-v8f9 GHSA-42p9-m692-hxrc GHSA-45hq-rg54-63ww GHSA-62vc-2f72-vcj3 GHSA-6vr7-3j3q-8546 GHSA-74mg-f7w3-pcrr GHSA-7gq6-cq6r-rrpx GHSA-8q5j-74vg-j4hr GHSA-9m3j-vpcw-4f37 GHSA-cq85-4f5h-qqc4 GHSA-gcc7-m89j-w3pq GHSA-hmqj-rccj-3q53 GHSA-mf2m-vhfh-2qjv GHSA-vgjv-qpvm-qjx7 GHSA-w267-2gcr-ggcp GHSA-x5pm-h33q-cjrw --- .../GHSA-p86h-23p7-v2rx.json | 11 ++-- .../GHSA-276r-vcw2-xfq4.json | 2 +- .../GHSA-45hh-rj6v-548f.json | 6 +- .../GHSA-25g3-q597-79m8.json | 59 +++++++++++++++++ .../GHSA-372x-c6rw-v8f9.json | 6 +- .../GHSA-42p9-m692-hxrc.json | 63 +++++++++++++++++++ .../GHSA-45hq-rg54-63ww.json | 35 +++++++++++ .../GHSA-62vc-2f72-vcj3.json | 6 +- .../GHSA-6vr7-3j3q-8546.json | 39 ++++++++++++ .../GHSA-74mg-f7w3-pcrr.json | 63 +++++++++++++++++++ .../GHSA-7gq6-cq6r-rrpx.json | 63 +++++++++++++++++++ .../GHSA-8q5j-74vg-j4hr.json | 6 +- .../GHSA-9m3j-vpcw-4f37.json | 6 +- .../GHSA-cq85-4f5h-qqc4.json | 6 +- .../GHSA-gcc7-m89j-w3pq.json | 2 +- .../GHSA-hmqj-rccj-3q53.json | 6 +- .../GHSA-mf2m-vhfh-2qjv.json | 6 +- .../GHSA-vgjv-qpvm-qjx7.json | 35 +++++++++++ .../GHSA-w267-2gcr-ggcp.json | 6 +- .../GHSA-x5pm-h33q-cjrw.json | 39 ++++++++++++ 20 files changed, 448 insertions(+), 17 deletions(-) create mode 100644 advisories/unreviewed/2024/02/GHSA-25g3-q597-79m8/GHSA-25g3-q597-79m8.json create mode 100644 advisories/unreviewed/2024/02/GHSA-42p9-m692-hxrc/GHSA-42p9-m692-hxrc.json create mode 100644 advisories/unreviewed/2024/02/GHSA-45hq-rg54-63ww/GHSA-45hq-rg54-63ww.json create mode 100644 advisories/unreviewed/2024/02/GHSA-6vr7-3j3q-8546/GHSA-6vr7-3j3q-8546.json create mode 100644 advisories/unreviewed/2024/02/GHSA-74mg-f7w3-pcrr/GHSA-74mg-f7w3-pcrr.json create mode 100644 advisories/unreviewed/2024/02/GHSA-7gq6-cq6r-rrpx/GHSA-7gq6-cq6r-rrpx.json create mode 100644 advisories/unreviewed/2024/02/GHSA-vgjv-qpvm-qjx7/GHSA-vgjv-qpvm-qjx7.json create mode 100644 advisories/unreviewed/2024/02/GHSA-x5pm-h33q-cjrw/GHSA-x5pm-h33q-cjrw.json diff --git a/advisories/unreviewed/2023/10/GHSA-p86h-23p7-v2rx/GHSA-p86h-23p7-v2rx.json b/advisories/unreviewed/2023/10/GHSA-p86h-23p7-v2rx/GHSA-p86h-23p7-v2rx.json index 191f7105385..bcdd4af14d1 100644 --- a/advisories/unreviewed/2023/10/GHSA-p86h-23p7-v2rx/GHSA-p86h-23p7-v2rx.json +++ b/advisories/unreviewed/2023/10/GHSA-p86h-23p7-v2rx/GHSA-p86h-23p7-v2rx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p86h-23p7-v2rx", - "modified": "2023-10-16T06:32:23Z", + "modified": "2024-02-20T21:30:19Z", "published": "2023-10-16T06:32:23Z", "aliases": [ "CVE-2023-45572" ], "details": "Buffer Overflow vulnerability in DI-7003GV2.D1 v.23.08.25D1 and before, DI-7100G+V2.D1 v.23.08.23D1 and before, DI-7100GV2.D1 v.23.08.23D1, DI-7200G+V2.D1 v.23.08.23D1 and before, DI-7200GV2.E1 v.23.08.23E1 and before, DI-7300G+V2.D1 v.23.08.23D1, and DI-7400G+V2.D1 v.23.08.23D1 and before allows a remote attacker to execute arbitrary code via the fn parameter of the tgfile.htm function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-10-16T06:15:12Z" diff --git a/advisories/unreviewed/2023/12/GHSA-276r-vcw2-xfq4/GHSA-276r-vcw2-xfq4.json b/advisories/unreviewed/2023/12/GHSA-276r-vcw2-xfq4/GHSA-276r-vcw2-xfq4.json index e67546004a1..16a9810ce7a 100644 --- a/advisories/unreviewed/2023/12/GHSA-276r-vcw2-xfq4/GHSA-276r-vcw2-xfq4.json +++ b/advisories/unreviewed/2023/12/GHSA-276r-vcw2-xfq4/GHSA-276r-vcw2-xfq4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-276r-vcw2-xfq4", - "modified": "2024-01-03T21:30:31Z", + "modified": "2024-02-20T21:30:19Z", "published": "2023-12-26T09:30:20Z", "aliases": [ "CVE-2023-51363" diff --git a/advisories/unreviewed/2024/01/GHSA-45hh-rj6v-548f/GHSA-45hh-rj6v-548f.json b/advisories/unreviewed/2024/01/GHSA-45hh-rj6v-548f/GHSA-45hh-rj6v-548f.json index 27ad68b28bf..748ffe85ef5 100644 --- a/advisories/unreviewed/2024/01/GHSA-45hh-rj6v-548f/GHSA-45hh-rj6v-548f.json +++ b/advisories/unreviewed/2024/01/GHSA-45hh-rj6v-548f/GHSA-45hh-rj6v-548f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-45hh-rj6v-548f", - "modified": "2024-01-10T15:30:19Z", + "modified": "2024-02-20T21:30:20Z", "published": "2024-01-10T15:30:19Z", "aliases": [ "CVE-2023-5455" @@ -71,11 +71,11 @@ }, { "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/U76DAZZVY7V4XQBOOV5ETPTHW3A6MW5O/" + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/U76DAZZVY7V4XQBOOV5ETPTHW3A6MW5O" }, { "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UFNUQH7IOHTKCTKQWFHONWGUBOUANL6I/" + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UFNUQH7IOHTKCTKQWFHONWGUBOUANL6I" }, { "type": "WEB", diff --git a/advisories/unreviewed/2024/02/GHSA-25g3-q597-79m8/GHSA-25g3-q597-79m8.json b/advisories/unreviewed/2024/02/GHSA-25g3-q597-79m8/GHSA-25g3-q597-79m8.json new file mode 100644 index 00000000000..3743af99365 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-25g3-q597-79m8/GHSA-25g3-q597-79m8.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-25g3-q597-79m8", + "modified": "2024-02-20T21:30:26Z", + "published": "2024-02-20T21:30:26Z", + "aliases": [ + "CVE-2023-52438" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbinder: fix use-after-free in shinker's callback\n\nThe mmap read lock is used during the shrinker's callback, which means\nthat using alloc->vma pointer isn't safe as it can race with munmap().\nAs of commit dd2283f2605e (\"mm: mmap: zap pages with read mmap_sem in\nmunmap\") the mmap lock is downgraded after the vma has been isolated.\n\nI was able to reproduce this issue by manually adding some delays and\ntriggering page reclaiming through the shrinker's debug sysfs. The\nfollowing KASAN report confirms the UAF:\n\n ==================================================================\n BUG: KASAN: slab-use-after-free in zap_page_range_single+0x470/0x4b8\n Read of size 8 at addr ffff356ed50e50f0 by task bash/478\n\n CPU: 1 PID: 478 Comm: bash Not tainted 6.6.0-rc5-00055-g1c8b86a3799f-dirty #70\n Hardware name: linux,dummy-virt (DT)\n Call trace:\n zap_page_range_single+0x470/0x4b8\n binder_alloc_free_page+0x608/0xadc\n __list_lru_walk_one+0x130/0x3b0\n list_lru_walk_node+0xc4/0x22c\n binder_shrink_scan+0x108/0x1dc\n shrinker_debugfs_scan_write+0x2b4/0x500\n full_proxy_write+0xd4/0x140\n vfs_write+0x1ac/0x758\n ksys_write+0xf0/0x1dc\n __arm64_sys_write+0x6c/0x9c\n\n Allocated by task 492:\n kmem_cache_alloc+0x130/0x368\n vm_area_alloc+0x2c/0x190\n mmap_region+0x258/0x18bc\n do_mmap+0x694/0xa60\n vm_mmap_pgoff+0x170/0x29c\n ksys_mmap_pgoff+0x290/0x3a0\n __arm64_sys_mmap+0xcc/0x144\n\n Freed by task 491:\n kmem_cache_free+0x17c/0x3c8\n vm_area_free_rcu_cb+0x74/0x98\n rcu_core+0xa38/0x26d4\n rcu_core_si+0x10/0x1c\n __do_softirq+0x2fc/0xd24\n\n Last potentially related work creation:\n __call_rcu_common.constprop.0+0x6c/0xba0\n call_rcu+0x10/0x1c\n vm_area_free+0x18/0x24\n remove_vma+0xe4/0x118\n do_vmi_align_munmap.isra.0+0x718/0xb5c\n do_vmi_munmap+0xdc/0x1fc\n __vm_munmap+0x10c/0x278\n __arm64_sys_munmap+0x58/0x7c\n\nFix this issue by performing instead a vma_lookup() which will fail to\nfind the vma that was isolated before the mmap lock downgrade. Note that\nthis option has better performance than upgrading to a mmap write lock\nwhich would increase contention. Plus, mmap_write_trylock() has been\nrecently removed anyway.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52438" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3f489c2067c5824528212b0fc18b28d51332d906" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8ad4d580e8aff8de2a4d57c5930fcc29f1ffd4a6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9fa04c93f24138747807fe75b5591bb680098f56" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a49087ab93508b60d9b8add91707a22dda832869" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a53e15e592b4dcc91c3a3b8514e484a0bdbc53a3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c8c1158ffb007197f31f9d9170cf13e4f34cbb5c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e074686e993ff1be5f21b085a3b1b4275ccd5727" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-20T21:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-372x-c6rw-v8f9/GHSA-372x-c6rw-v8f9.json b/advisories/unreviewed/2024/02/GHSA-372x-c6rw-v8f9/GHSA-372x-c6rw-v8f9.json index 6842857c58d..28b7cf7118e 100644 --- a/advisories/unreviewed/2024/02/GHSA-372x-c6rw-v8f9/GHSA-372x-c6rw-v8f9.json +++ b/advisories/unreviewed/2024/02/GHSA-372x-c6rw-v8f9/GHSA-372x-c6rw-v8f9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-372x-c6rw-v8f9", - "modified": "2024-02-20T15:31:05Z", + "modified": "2024-02-20T21:30:24Z", "published": "2024-02-20T15:31:05Z", "aliases": [ "CVE-2024-1552" @@ -29,6 +29,10 @@ { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2024-06" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-07" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/02/GHSA-42p9-m692-hxrc/GHSA-42p9-m692-hxrc.json b/advisories/unreviewed/2024/02/GHSA-42p9-m692-hxrc/GHSA-42p9-m692-hxrc.json new file mode 100644 index 00000000000..fe0de0c3ffb --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-42p9-m692-hxrc/GHSA-42p9-m692-hxrc.json @@ -0,0 +1,63 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-42p9-m692-hxrc", + "modified": "2024-02-20T21:30:26Z", + "published": "2024-02-20T21:30:26Z", + "aliases": [ + "CVE-2023-52437" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRevert \"md/raid5: Wait for MD_SB_CHANGE_PENDING in raid5d\"\n\nThis reverts commit 5e2cf333b7bd5d3e62595a44d598a254c697cd74.\n\nThat commit introduced the following race and can cause system hung.\n\n md_write_start: raid5d:\n // mddev->in_sync == 1\n set \"MD_SB_CHANGE_PENDING\"\n // running before md_write_start wakeup it\n waiting \"MD_SB_CHANGE_PENDING\" cleared\n >>>>>>>>> hung\n wakeup mddev->thread\n ...\n waiting \"MD_SB_CHANGE_PENDING\" cleared\n >>>> hung, raid5d should clear this flag\n but get hung by same flag.\n\nThe issue reverted commit fixing is fixed by last patch in a new way.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52437" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0de40f76d567133b871cd6ad46bb87afbce46983" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/84c39986fe6dd77aa15f08712339f5d4eb7dbe27" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/87165c64fe1a98bbab7280c58df3c83be2c98478" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/aab69ef769707ad987ff905d79e0bd6591812580" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bed0acf330b2c50c688f6d9cfbcac2aa57a8e613" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bed9e27baf52a09b7ba2a3714f1e24e17ced386d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cfa46838285814c3a27faacf7357f0a65bb5d152" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e16a0bbdb7e590a6607b0d82915add738c03c069" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-20T21:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-45hq-rg54-63ww/GHSA-45hq-rg54-63ww.json b/advisories/unreviewed/2024/02/GHSA-45hq-rg54-63ww/GHSA-45hq-rg54-63ww.json new file mode 100644 index 00000000000..b8710d76f8f --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-45hq-rg54-63ww/GHSA-45hq-rg54-63ww.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-45hq-rg54-63ww", + "modified": "2024-02-20T21:30:25Z", + "published": "2024-02-20T21:30:25Z", + "aliases": [ + "CVE-2023-49034" + ], + "details": "Cross Site Scripting (XSS) vulnerability in ProjeQtOr 11.0.2 allows a remote attacker to execute arbitrary code via a crafted script to thecheckvalidHtmlText function in the ack.php and security.php files.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49034" + }, + { + "type": "WEB", + "url": "https://gist.github.com/thedroidgeek/0a9b8189b74f968b5d7b84ec12b8f8f5" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-20T21:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-62vc-2f72-vcj3/GHSA-62vc-2f72-vcj3.json b/advisories/unreviewed/2024/02/GHSA-62vc-2f72-vcj3/GHSA-62vc-2f72-vcj3.json index 49ba7f6c765..a58ebbb09de 100644 --- a/advisories/unreviewed/2024/02/GHSA-62vc-2f72-vcj3/GHSA-62vc-2f72-vcj3.json +++ b/advisories/unreviewed/2024/02/GHSA-62vc-2f72-vcj3/GHSA-62vc-2f72-vcj3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-62vc-2f72-vcj3", - "modified": "2024-02-20T15:31:05Z", + "modified": "2024-02-20T21:30:24Z", "published": "2024-02-20T15:31:05Z", "aliases": [ "CVE-2024-1553" @@ -29,6 +29,10 @@ { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2024-06" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-07" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/02/GHSA-6vr7-3j3q-8546/GHSA-6vr7-3j3q-8546.json b/advisories/unreviewed/2024/02/GHSA-6vr7-3j3q-8546/GHSA-6vr7-3j3q-8546.json new file mode 100644 index 00000000000..275dfbc95e1 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-6vr7-3j3q-8546/GHSA-6vr7-3j3q-8546.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6vr7-3j3q-8546", + "modified": "2024-02-20T21:30:25Z", + "published": "2024-02-20T21:30:25Z", + "aliases": [ + "CVE-2023-52435" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: prevent mss overflow in skb_segment()\n\nOnce again syzbot is able to crash the kernel in skb_segment() [1]\n\nGSO_BY_FRAGS is a forbidden value, but unfortunately the following\ncomputation in skb_segment() can reach it quite easily :\n\n\tmss = mss * partial_segs;\n\n65535 = 3 * 5 * 17 * 257, so many initial values of mss can lead to\na bad final result.\n\nMake sure to limit segmentation so that the new mss value is smaller\nthan GSO_BY_FRAGS.\n\n[1]\n\ngeneral protection fault, probably for non-canonical address 0xdffffc000000000e: 0000 [#1] PREEMPT SMP KASAN\nKASAN: null-ptr-deref in range [0x0000000000000070-0x0000000000000077]\nCPU: 1 PID: 5079 Comm: syz-executor993 Not tainted 6.7.0-rc4-syzkaller-00141-g1ae4cd3cbdd0 #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 11/10/2023\nRIP: 0010:skb_segment+0x181d/0x3f30 net/core/skbuff.c:4551\nCode: 83 e3 02 e9 fb ed ff ff e8 90 68 1c f9 48 8b 84 24 f8 00 00 00 48 8d 78 70 48 b8 00 00 00 00 00 fc ff df 48 89 fa 48 c1 ea 03 <0f> b6 04 02 84 c0 74 08 3c 03 0f 8e 8a 21 00 00 48 8b 84 24 f8 00\nRSP: 0018:ffffc900043473d0 EFLAGS: 00010202\nRAX: dffffc0000000000 RBX: 0000000000010046 RCX: ffffffff886b1597\nRDX: 000000000000000e RSI: ffffffff886b2520 RDI: 0000000000000070\nRBP: ffffc90004347578 R08: 0000000000000005 R09: 000000000000ffff\nR10: 000000000000ffff R11: 0000000000000002 R12: ffff888063202ac0\nR13: 0000000000010000 R14: 000000000000ffff R15: 0000000000000046\nFS: 0000555556e7e380(0000) GS:ffff8880b9900000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000000020010000 CR3: 0000000027ee2000 CR4: 00000000003506f0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nCall Trace:\n\nudp6_ufo_fragment+0xa0e/0xd00 net/ipv6/udp_offload.c:109\nipv6_gso_segment+0x534/0x17e0 net/ipv6/ip6_offload.c:120\nskb_mac_gso_segment+0x290/0x610 net/core/gso.c:53\n__skb_gso_segment+0x339/0x710 net/core/gso.c:124\nskb_gso_segment include/net/gso.h:83 [inline]\nvalidate_xmit_skb+0x36c/0xeb0 net/core/dev.c:3626\n__dev_queue_xmit+0x6f3/0x3d60 net/core/dev.c:4338\ndev_queue_xmit include/linux/netdevice.h:3134 [inline]\npacket_xmit+0x257/0x380 net/packet/af_packet.c:276\npacket_snd net/packet/af_packet.c:3087 [inline]\npacket_sendmsg+0x24c6/0x5220 net/packet/af_packet.c:3119\nsock_sendmsg_nosec net/socket.c:730 [inline]\n__sock_sendmsg+0xd5/0x180 net/socket.c:745\n__sys_sendto+0x255/0x340 net/socket.c:2190\n__do_sys_sendto net/socket.c:2202 [inline]\n__se_sys_sendto net/socket.c:2198 [inline]\n__x64_sys_sendto+0xe0/0x1b0 net/socket.c:2198\ndo_syscall_x64 arch/x86/entry/common.c:52 [inline]\ndo_syscall_64+0x40/0x110 arch/x86/entry/common.c:83\nentry_SYSCALL_64_after_hwframe+0x63/0x6b\nRIP: 0033:0x7f8692032aa9\nCode: 28 00 00 00 75 05 48 83 c4 28 c3 e8 d1 19 00 00 90 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b8 ff ff ff f7 d8 64 89 01 48\nRSP: 002b:00007fff8d685418 EFLAGS: 00000246 ORIG_RAX: 000000000000002c\nRAX: ffffffffffffffda RBX: 0000000000000003 RCX: 00007f8692032aa9\nRDX: 0000000000010048 RSI: 00000000200000c0 RDI: 0000000000000003\nRBP: 00000000000f4240 R08: 0000000020000540 R09: 0000000000000014\nR10: 0000000000000000 R11: 0000000000000246 R12: 00007fff8d685480\nR13: 0000000000000001 R14: 00007fff8d685480 R15: 0000000000000003\n\nModules linked in:\n---[ end trace 0000000000000000 ]---\nRIP: 0010:skb_segment+0x181d/0x3f30 net/core/skbuff.c:4551\nCode: 83 e3 02 e9 fb ed ff ff e8 90 68 1c f9 48 8b 84 24 f8 00 00 00 48 8d 78 70 48 b8 00 00 00 00 00 fc ff df 48 89 fa 48 c1 ea 03 <0f> b6 04 02 84 c0 74 08 3c 03 0f 8e 8a 21 00 00 48 8b 84 24 f8 00\nRSP: 0018:ffffc900043473d0 EFLAGS: 00010202\nRAX: dffffc0000000000 RBX: 0000000000010046 RCX: ffffffff886b1597\nRDX: 000000000000000e RSI: ffffffff886b2520 RDI: 0000000000000070\nRBP: ffffc90004347578 R0\n---truncated---", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52435" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/23d05d563b7e7b0314e65c8e882bc27eac2da8e7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/95b3904a261a9f810205da560e802cc326f50d77" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-20T20:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-74mg-f7w3-pcrr/GHSA-74mg-f7w3-pcrr.json b/advisories/unreviewed/2024/02/GHSA-74mg-f7w3-pcrr/GHSA-74mg-f7w3-pcrr.json new file mode 100644 index 00000000000..3079e08b2f7 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-74mg-f7w3-pcrr/GHSA-74mg-f7w3-pcrr.json @@ -0,0 +1,63 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-74mg-f7w3-pcrr", + "modified": "2024-02-20T21:30:26Z", + "published": "2024-02-20T21:30:26Z", + "aliases": [ + "CVE-2023-52436" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: explicitly null-terminate the xattr list\n\nWhen setting an xattr, explicitly null-terminate the xattr list. This\neliminates the fragile assumption that the unused xattr space is always\nzeroed.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52436" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/12cf91e23b126718a96b914f949f2cdfeadc7b2a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/16ae3132ff7746894894927c1892493693b89135" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2525d1ba225b5c167162fa344013c408e8b4de36" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/32a6cfc67675ee96fe107aeed5af9776fec63f11" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3e47740091b05ac8d7836a33afd8646b6863ca52" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5de9e9dd1828db9b8b962f7ca42548bd596deb8a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e26b6d39270f5eab0087453d9b544189a38c8564" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f6c30bfe5a49bc38cae985083a11016800708fea" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-20T21:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-7gq6-cq6r-rrpx/GHSA-7gq6-cq6r-rrpx.json b/advisories/unreviewed/2024/02/GHSA-7gq6-cq6r-rrpx/GHSA-7gq6-cq6r-rrpx.json new file mode 100644 index 00000000000..1dc21aad398 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-7gq6-cq6r-rrpx/GHSA-7gq6-cq6r-rrpx.json @@ -0,0 +1,63 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7gq6-cq6r-rrpx", + "modified": "2024-02-20T21:30:26Z", + "published": "2024-02-20T21:30:26Z", + "aliases": [ + "CVE-2023-52439" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nuio: Fix use-after-free in uio_open\n\ncore-1\t\t\t\tcore-2\n-------------------------------------------------------\nuio_unregister_device\t\tuio_open\n\t\t\t\tidev = idr_find()\ndevice_unregister(&idev->dev)\nput_device(&idev->dev)\nuio_device_release\n\t\t\t\tget_device(&idev->dev)\nkfree(idev)\nuio_free_minor(minor)\n\t\t\t\tuio_release\n\t\t\t\tput_device(&idev->dev)\n\t\t\t\tkfree(idev)\n-------------------------------------------------------\n\nIn the core-1 uio_unregister_device(), the device_unregister will kfree\nidev when the idev->dev kobject ref is 1. But after core-1\ndevice_unregister, put_device and before doing kfree, the core-2 may\nget_device. Then:\n1. After core-1 kfree idev, the core-2 will do use-after-free for idev.\n2. When core-2 do uio_release and put_device, the idev will be double\n freed.\n\nTo address this issue, we can get idev atomic & inc idev reference with\nminor_lock.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52439" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0c9ae0b8605078eafc3bea053cc78791e97ba2e2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/17a8519cb359c3b483fb5c7367efa9a8a508bdea" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3174e0f7de1ba392dc191625da83df02d695b60c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/35f102607054faafe78d2a6994b18d5d9d6e92ad" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5cf604ee538ed0c467abe3b4cda5308a6398f0f7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5e0be1229ae199ebb90b33102f74a0f22d152570" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/913205930da6213305616ac539447702eaa85e41" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e93da893d52d82d57fc0db2ca566024e0f26ff50" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-20T21:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-8q5j-74vg-j4hr/GHSA-8q5j-74vg-j4hr.json b/advisories/unreviewed/2024/02/GHSA-8q5j-74vg-j4hr/GHSA-8q5j-74vg-j4hr.json index ba8724cd862..437112f0aec 100644 --- a/advisories/unreviewed/2024/02/GHSA-8q5j-74vg-j4hr/GHSA-8q5j-74vg-j4hr.json +++ b/advisories/unreviewed/2024/02/GHSA-8q5j-74vg-j4hr/GHSA-8q5j-74vg-j4hr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8q5j-74vg-j4hr", - "modified": "2024-02-20T15:31:05Z", + "modified": "2024-02-20T21:30:24Z", "published": "2024-02-20T15:31:05Z", "aliases": [ "CVE-2024-1550" @@ -29,6 +29,10 @@ { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2024-06" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-07" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/02/GHSA-9m3j-vpcw-4f37/GHSA-9m3j-vpcw-4f37.json b/advisories/unreviewed/2024/02/GHSA-9m3j-vpcw-4f37/GHSA-9m3j-vpcw-4f37.json index 9a4990a10d0..1b19fe0f9c7 100644 --- a/advisories/unreviewed/2024/02/GHSA-9m3j-vpcw-4f37/GHSA-9m3j-vpcw-4f37.json +++ b/advisories/unreviewed/2024/02/GHSA-9m3j-vpcw-4f37/GHSA-9m3j-vpcw-4f37.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9m3j-vpcw-4f37", - "modified": "2024-02-20T15:31:04Z", + "modified": "2024-02-20T21:30:24Z", "published": "2024-02-20T15:31:04Z", "aliases": [ "CVE-2024-1548" @@ -29,6 +29,10 @@ { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2024-06" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-07" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/02/GHSA-cq85-4f5h-qqc4/GHSA-cq85-4f5h-qqc4.json b/advisories/unreviewed/2024/02/GHSA-cq85-4f5h-qqc4/GHSA-cq85-4f5h-qqc4.json index d71ee63208e..1f45d3a354b 100644 --- a/advisories/unreviewed/2024/02/GHSA-cq85-4f5h-qqc4/GHSA-cq85-4f5h-qqc4.json +++ b/advisories/unreviewed/2024/02/GHSA-cq85-4f5h-qqc4/GHSA-cq85-4f5h-qqc4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cq85-4f5h-qqc4", - "modified": "2024-02-20T15:31:05Z", + "modified": "2024-02-20T21:30:24Z", "published": "2024-02-20T15:31:05Z", "aliases": [ "CVE-2024-1551" @@ -29,6 +29,10 @@ { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2024-06" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-07" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/02/GHSA-gcc7-m89j-w3pq/GHSA-gcc7-m89j-w3pq.json b/advisories/unreviewed/2024/02/GHSA-gcc7-m89j-w3pq/GHSA-gcc7-m89j-w3pq.json index 0fc3b0e1d8d..d8f2cb63253 100644 --- a/advisories/unreviewed/2024/02/GHSA-gcc7-m89j-w3pq/GHSA-gcc7-m89j-w3pq.json +++ b/advisories/unreviewed/2024/02/GHSA-gcc7-m89j-w3pq/GHSA-gcc7-m89j-w3pq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gcc7-m89j-w3pq", - "modified": "2024-02-15T15:30:28Z", + "modified": "2024-02-20T21:30:20Z", "published": "2024-02-15T15:30:28Z", "aliases": [ "CVE-2023-45581" diff --git a/advisories/unreviewed/2024/02/GHSA-hmqj-rccj-3q53/GHSA-hmqj-rccj-3q53.json b/advisories/unreviewed/2024/02/GHSA-hmqj-rccj-3q53/GHSA-hmqj-rccj-3q53.json index 6671edc36ce..a2a58607c7e 100644 --- a/advisories/unreviewed/2024/02/GHSA-hmqj-rccj-3q53/GHSA-hmqj-rccj-3q53.json +++ b/advisories/unreviewed/2024/02/GHSA-hmqj-rccj-3q53/GHSA-hmqj-rccj-3q53.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hmqj-rccj-3q53", - "modified": "2024-02-20T15:31:04Z", + "modified": "2024-02-20T21:30:23Z", "published": "2024-02-20T15:31:04Z", "aliases": [ "CVE-2024-1547" @@ -29,6 +29,10 @@ { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2024-06" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-07" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/02/GHSA-mf2m-vhfh-2qjv/GHSA-mf2m-vhfh-2qjv.json b/advisories/unreviewed/2024/02/GHSA-mf2m-vhfh-2qjv/GHSA-mf2m-vhfh-2qjv.json index 72fb5081e11..0e567017a68 100644 --- a/advisories/unreviewed/2024/02/GHSA-mf2m-vhfh-2qjv/GHSA-mf2m-vhfh-2qjv.json +++ b/advisories/unreviewed/2024/02/GHSA-mf2m-vhfh-2qjv/GHSA-mf2m-vhfh-2qjv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mf2m-vhfh-2qjv", - "modified": "2024-02-20T15:31:05Z", + "modified": "2024-02-20T21:30:24Z", "published": "2024-02-20T15:31:05Z", "aliases": [ "CVE-2024-1549" @@ -29,6 +29,10 @@ { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2024-06" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-07" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/02/GHSA-vgjv-qpvm-qjx7/GHSA-vgjv-qpvm-qjx7.json b/advisories/unreviewed/2024/02/GHSA-vgjv-qpvm-qjx7/GHSA-vgjv-qpvm-qjx7.json new file mode 100644 index 00000000000..2821d82f68d --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-vgjv-qpvm-qjx7/GHSA-vgjv-qpvm-qjx7.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vgjv-qpvm-qjx7", + "modified": "2024-02-20T21:30:25Z", + "published": "2024-02-20T21:30:25Z", + "aliases": [ + "CVE-2023-46967" + ], + "details": "Cross Site Scripting vulnerability in the sanitize function in Enhancesoft osTicket 1.18.0 allows a remote attacker to escalate privileges via a crafted support ticket.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46967" + }, + { + "type": "WEB", + "url": "https://www.sonarsource.com/blog/pitfalls-of-desanitization-leaking-customer-data-from-osticket" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-20T21:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-w267-2gcr-ggcp/GHSA-w267-2gcr-ggcp.json b/advisories/unreviewed/2024/02/GHSA-w267-2gcr-ggcp/GHSA-w267-2gcr-ggcp.json index bd5f9628dc2..d9128f93ac2 100644 --- a/advisories/unreviewed/2024/02/GHSA-w267-2gcr-ggcp/GHSA-w267-2gcr-ggcp.json +++ b/advisories/unreviewed/2024/02/GHSA-w267-2gcr-ggcp/GHSA-w267-2gcr-ggcp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w267-2gcr-ggcp", - "modified": "2024-02-20T15:31:04Z", + "modified": "2024-02-20T21:30:23Z", "published": "2024-02-20T15:31:04Z", "aliases": [ "CVE-2024-1546" @@ -29,6 +29,10 @@ { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2024-06" + }, + { + "type": "WEB", + "url": "https://www.mozilla.org/security/advisories/mfsa2024-07" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/02/GHSA-x5pm-h33q-cjrw/GHSA-x5pm-h33q-cjrw.json b/advisories/unreviewed/2024/02/GHSA-x5pm-h33q-cjrw/GHSA-x5pm-h33q-cjrw.json new file mode 100644 index 00000000000..c3462eed4b0 --- /dev/null +++ b/advisories/unreviewed/2024/02/GHSA-x5pm-h33q-cjrw/GHSA-x5pm-h33q-cjrw.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x5pm-h33q-cjrw", + "modified": "2024-02-20T21:30:26Z", + "published": "2024-02-20T21:30:26Z", + "aliases": [ + "CVE-2024-25141" + ], + "details": "When ssl was enabled for Mongo Hook, default settings included \"allow_insecure\" which caused that certificates were not validated. This was unexpected and undocumented.\nUsers are recommended to upgrade to version 4.0.0, which fixes this issue.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25141" + }, + { + "type": "WEB", + "url": "https://github.com/apache/airflow/pull/37214" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/sqgbfqngjmn45ommmrgj7hvs7fgspsgm" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-295" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-02-20T21:15:08Z" + } +} \ No newline at end of file