Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2024-02-26 18:31:49 +00:00
parent 5e3c89cf88
commit 7ec3db23cc
112 changed files with 4035 additions and 21 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3h6x-952r-xr8p",
"modified": "2024-02-11T09:30:18Z",
"modified": "2024-02-26T18:30:27Z",
"published": "2024-01-23T03:31:08Z",
"aliases": [
"CVE-2024-23213"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-554m-v42f-hcq9",
"modified": "2024-01-31T15:30:20Z",
"modified": "2024-02-26T18:30:27Z",
"published": "2024-01-31T15:30:20Z",
"aliases": [
"CVE-2023-5992"
@@ -21,6 +21,14 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5992"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:0966"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:0967"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2023-5992"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-73m5-j333-fcwc",
"modified": "2024-02-11T09:30:18Z",
"modified": "2024-02-26T18:30:27Z",
"published": "2024-01-23T03:31:08Z",
"aliases": [
"CVE-2024-23206"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x697-v25m-6phv",
"modified": "2024-02-13T09:30:31Z",
"modified": "2024-02-26T18:30:27Z",
"published": "2024-01-16T12:30:26Z",
"aliases": [
"CVE-2024-0553"
@@ -45,6 +45,10 @@
"type": "WEB",
"url": "https://gitlab.com/gnutls/gnutls/-/issues/1522"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2024/02/msg00010.html"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7ZEIOLORQ7N6WRPFXZSYDL2MC4LP7VFV"
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-246p-56fr-j339",
"modified": "2024-02-26T18:30:31Z",
"published": "2024-02-26T18:30:31Z",
"aliases": [
"CVE-2024-25909"
],
"details": "Unrestricted Upload of File with Dangerous Type vulnerability in JoomUnited WP Media folder.This issue affects WP Media folder: from n/a through 5.7.2.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25909"
},
{
"type": "WEB",
"url": "https://patchstack.com/database/vulnerability/wp-media-folder/wordpress-wp-media-folder-plugin-5-7-2-subscriber-arbitrary-file-upload-vulnerability?_s_id=cve"
}
],
"database_specific": {
"cwe_ids": [
"CWE-434"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-26T16:27:59Z"
}
}
@@ -0,0 +1,55 @@
{
"schema_version": "1.4.0",
"id": "GHSA-25vh-f6xx-mfc3",
"modified": "2024-02-26T18:30:28Z",
"published": "2024-02-26T18:30:28Z",
"aliases": [
"CVE-2023-52467"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmfd: syscon: Fix null pointer dereference in of_syscon_register()\n\nkasprintf() returns a pointer to dynamically allocated memory\nwhich can be NULL upon failure.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52467"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/3ef1130deee98997275904d9bfc37af75e1e906c"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/41673c66b3d0c09915698fec5c13b24336f18dd1"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/527e8c5f3d00299822612c495d5adf1f8f43c001"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/7f2c410ac470959b88e03dadd94b7a0b71df7973"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/927626a2073887ee30ba00633260d4d203f8e875"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/c3e3a2144bf50877551138ffce9f7aa6ddfe385b"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-26T16:27:48Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-273x-mxvr-9vx2",
"modified": "2024-02-26T18:30:28Z",
"published": "2024-02-26T18:30:28Z",
"aliases": [
"CVE-2022-34357"
],
"details": "IBM Cognos Analytics Mobile Server 11.1.7, 11.2.4, and 12.0.0 is vulnerable to Denial of Service due to due to weak or absence of rate limiting. By making unlimited http requests, it is possible for a single user to exhaust server resources over a period of time making service unavailable for other legitimate users. IBM X-Force ID: 230510.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-34357"
},
{
"type": "WEB",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/230510"
},
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/7123154"
}
],
"database_specific": {
"cwe_ids": [
"CWE-770"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-26T16:27:45Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-29vg-wcmp-5fp9",
"modified": "2024-02-23T03:30:39Z",
"modified": "2024-02-26T18:30:28Z",
"published": "2024-02-21T06:30:32Z",
"aliases": [
"CVE-2024-1674"
@@ -26,6 +26,10 @@
"type": "WEB",
"url": "https://issues.chromium.org/issues/40095183"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PWWBMVQTSERVBXSXCZVUKIMEDNQUQ7O3"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QDCMYQ3J45NHQ4EJREM3BJNNKB5BK4Y7"
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2j3h-j2q3-wxp3",
"modified": "2024-02-26T18:30:31Z",
"published": "2024-02-26T18:30:31Z",
"aliases": [
"CVE-2024-25082"
],
"details": "Splinefont in FontForge through 20230101 allows command injection via crafted archives or compressed files.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25082"
},
{
"type": "WEB",
"url": "https://github.com/fontforge/fontforge/pull/5367"
},
{
"type": "WEB",
"url": "https://fontforge.org/en-US/downloads"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-26T16:27:58Z"
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-32rv-jjcf-cmrm",
"modified": "2024-02-26T18:30:29Z",
"published": "2024-02-26T18:30:29Z",
"aliases": [
"CVE-2024-0455"
],
"details": "The inclusion of the web scraper for AnythingLLM means that any user with the proper authorization level (manager, admin, and when in single user) could put in the URL\n```\nhttp://169.254.169.254/latest/meta-data/identity-credentials/ec2/security-credentials/ec2-instance\n```\nwhich is a special IP and URL that resolves only when the request comes from within an EC2 instance. This would allow the user to see the connection/secret credentials for their specific instance and be able to manage it regardless of who deployed it.\n\nThe user would have to have pre-existing knowledge of the hosting infra which the target instance is deployed on, but if sent - would resolve if on EC2 and the proper `iptable` or firewall rule is not configured for their setup.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0455"
},
{
"type": "WEB",
"url": "https://github.com/mintplex-labs/anything-llm/commit/b2b2c2afe15c48952d57b4d01e7108f9515c5f55"
},
{
"type": "WEB",
"url": "https://huntr.com/bounties/07d83b49-7ebb-40d2-83fc-78381e3c5c9c"
}
],
"database_specific": {
"cwe_ids": [
"CWE-918"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-26T16:27:50Z"
}
}
@@ -0,0 +1,47 @@
{
"schema_version": "1.4.0",
"id": "GHSA-35j4-pxc2-3gcf",
"modified": "2024-02-26T18:30:31Z",
"published": "2024-02-26T18:30:31Z",
"aliases": [
"CVE-2024-25344"
],
"details": "Cross Site Scripting vulnerability in ITFlow.org before commit v.432488eca3998c5be6b6b9e8f8ba01f54bc12378 allows a remtoe attacker to execute arbitrary code and obtain sensitive information via the settings.php, settings+company.php, settings_defaults.php,settings_integrations.php, settings_invoice.php, settings_localization.php, settings_mail.php components.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25344"
},
{
"type": "WEB",
"url": "https://github.com/itflow-org/itflow/commit/432488eca3998c5be6b6b9e8f8ba01f54bc12378"
},
{
"type": "WEB",
"url": "https://github.com/itflow-org/itflow/commit/8068cb6081e4760860a634c1066b2c64d0ee2d46"
},
{
"type": "WEB",
"url": "https://itflow.org"
},
{
"type": "WEB",
"url": "https://packetstormsecurity.com/files/177224/ITFlow-Cross-Site-Request-Forgery.html"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-26T16:27:58Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-36cg-qj95-mq7x",
"modified": "2024-02-26T18:30:31Z",
"published": "2024-02-26T18:30:31Z",
"aliases": [
"CVE-2019-25161"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: prevent memory leak\n\nIn dcn*_create_resource_pool the allocated memory should be released if\nconstruct pool fails.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2019-25161"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/104c307147ad379617472dd91a5bcb368d72bd6d"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/60e1b411bf0fd9fda2d2de7f45dc3b1d9960b85e"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-26T18:15:06Z"
}
}
@@ -0,0 +1,47 @@
{
"schema_version": "1.4.0",
"id": "GHSA-38g6-vx2q-23wm",
"modified": "2024-02-26T18:30:31Z",
"published": "2024-02-26T18:30:31Z",
"aliases": [
"CVE-2024-26601"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\next4: regenerate buddy after block freeing failed if under fc replay\n\nThis mostly reverts commit 6bd97bf273bd (\"ext4: remove redundant\nmb_regenerate_buddy()\") and reintroduces mb_regenerate_buddy(). Based on\ncode in mb_free_blocks(), fast commit replay can end up marking as free\nblocks that are already marked as such. This causes corruption of the\nbuddy bitmap so we need to regenerate it in that case.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26601"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/6b0d48647935e4b8c7b75d1eccb9043fcd4ee581"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/78327acd4cdc4a1601af718b781eece577b6b7d4"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/c9b528c35795b711331ed36dc3dbee90d5812d4e"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/ea42d6cffb0dd27a417f410b9d0011e9859328cb"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-26T16:27:59Z"
}
}
@@ -0,0 +1,43 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3fmx-gx73-5jg7",
"modified": "2024-02-26T18:30:28Z",
"published": "2024-02-26T18:30:28Z",
"aliases": [
"CVE-2023-52466"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nPCI: Avoid potential out-of-bounds read in pci_dev_for_each_resource()\n\nCoverity complains that pointer in the pci_dev_for_each_resource() may be\nwrong, i.e., might be used for the out-of-bounds read.\n\nThere is no actual issue right now because we have another check afterwards\nand the out-of-bounds read is not being performed. In any case it's better\ncode with this fixed, hence the proposed change.\n\nAs Jonas pointed out \"It probably makes the code slightly less performant\nas res will now be checked for being not NULL (which will always be true),\nbut I doubt it will be significant (or in any hot paths).\"",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52466"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/3171e46d677a668eed3086da78671f1e4f5b8405"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/5b3e25efe16e06779a9a7c7610217c1b921ec179"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/bd26159dcaaa3e9a927070efd348e7ce7e5ee933"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-26T16:27:48Z"
}
}
@@ -0,0 +1,35 @@
{
"schema_version": "1.4.0",
"id": "GHSA-42c4-hvg2-mp96",
"modified": "2024-02-26T18:30:31Z",
"published": "2024-02-26T18:30:31Z",
"aliases": [
"CVE-2024-24402"
],
"details": "An issue in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted script to the /usr/local/nagios/bin/npcd component.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24402"
},
{
"type": "WEB",
"url": "https://www.nagios.com/changelog"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-26T17:15:10Z"
}
}
@@ -0,0 +1,43 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4473-972q-596c",
"modified": "2024-02-26T18:30:29Z",
"published": "2024-02-26T18:30:29Z",
"aliases": [
"CVE-2023-52473"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nthermal: core: Fix NULL pointer dereference in zone registration error path\n\nIf device_register() in thermal_zone_device_register_with_trips()\nreturns an error, the tz variable is set to NULL and subsequently\ndereferenced in kfree(tz->tzp).\n\nCommit adc8749b150c (\"thermal/drivers/core: Use put_device() if\ndevice_register() fails\") added the tz = NULL assignment in question to\navoid a possible double-free after dropping the reference to the zone\ndevice. However, after commit 4649620d9404 (\"thermal: core: Make\nthermal_zone_device_unregister() return after freeing the zone\"), that\nassignment has become redundant, because dropping the reference to the\nzone device does not cause the zone object to be freed any more.\n\nDrop it to address the NULL pointer dereference.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52473"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/02871710b93058eb1249d5847c0b2d1c2c3c98ae"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/04e6ccfc93c5a1aa1d75a537cf27e418895e20ea"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/335176dd8ebaca6493807dceea33c478305667fa"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-26T16:27:48Z"
}
}
@@ -0,0 +1,63 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4pqp-3cv2-mm87",
"modified": "2024-02-26T18:30:28Z",
"published": "2024-02-26T18:30:28Z",
"aliases": [
"CVE-2022-48626"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmoxart: fix potential use-after-free on remove path\n\nIt was reported that the mmc host structure could be accessed after it\nwas freed in moxart_remove(), so fix this by saving the base register of\nthe device and using it instead of the pointer dereference.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48626"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/3a0a7ec5574b510b067cfc734b8bdb6564b31d4e"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/7f901d53f120d1921f84f7b9b118e87e94b403c5"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/9c25d5ff1856b91bd4365e813f566cb59aaa9552"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/af0e6c49438b1596e4be8a267d218a0c88a42323"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/bd2db32e7c3e35bd4d9b8bbff689434a50893546"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/be93028d306dac9f5b59ebebd9ec7abcfc69c156"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/e6f580d0b3349646d4ee1ce0057eb273e8fb7e2e"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/f5dc193167591e88797262ec78515a0cbe79ff5f"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-26T16:27:45Z"
}
}
@@ -0,0 +1,38 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5998-89hj-xhfc",
"modified": "2024-02-26T18:30:30Z",
"published": "2024-02-26T18:30:30Z",
"aliases": [
"CVE-2024-21825"
],
"details": "A heap-based buffer overflow vulnerability exists in the GGUF library GGUF_TYPE_ARRAY/GGUF_TYPE_STRING parsing functionality of llama.cpp Commit 18c2e17. A specially crafted .gguf file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21825"
},
{
"type": "WEB",
"url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-1912"
}
],
"database_specific": {
"cwe_ids": [
"CWE-190"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-26T16:27:55Z"
}
}
@@ -0,0 +1,47 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5m9g-hh42-2p58",
"modified": "2024-02-26T18:30:30Z",
"published": "2024-02-26T18:30:30Z",
"aliases": [
"CVE-2024-22873"
],
"details": "Tencent Blueking CMDB v3.2.x to v3.9.x was discovered to contain a Server-Side Request Forgery (SSRF) via the event subscription function (/service/subscription.go). This vulnerability allows attackers to access internal requests via a crafted POST request.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22873"
},
{
"type": "WEB",
"url": "https://gist.github.com/exp1orer/0f190c6a64b668a9b1c4c47789affa09"
},
{
"type": "WEB",
"url": "https://sphenoid-enquiry-9be.notion.site/BK-CMDB-SSRF-ba21e94f4976460188fa52d26c15a6ae?pvs=4"
},
{
"type": "WEB",
"url": "http://blueking.com"
},
{
"type": "WEB",
"url": "http://tencent.com"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-26T16:27:56Z"
}
}
@@ -0,0 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5p3m-pw6j-5jwm",
"modified": "2024-02-26T18:30:31Z",
"published": "2024-02-26T18:30:31Z",
"aliases": [
"CVE-2024-26605"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nPCI/ASPM: Fix deadlock when enabling ASPM\n\nA last minute revert in 6.7-final introduced a potential deadlock when\nenabling ASPM during probe of Qualcomm PCIe controllers as reported by\nlockdep:\n\n ============================================\n WARNING: possible recursive locking detected\n 6.7.0 #40 Not tainted\n --------------------------------------------\n kworker/u16:5/90 is trying to acquire lock:\n ffffacfa78ced000 (pci_bus_sem){++++}-{3:3}, at: pcie_aspm_pm_state_change+0x58/0xdc\n\n but task is already holding lock:\n ffffacfa78ced000 (pci_bus_sem){++++}-{3:3}, at: pci_walk_bus+0x34/0xbc\n\n other info that might help us debug this:\n Possible unsafe locking scenario:\n\n CPU0\n ----\n lock(pci_bus_sem);\n lock(pci_bus_sem);\n\n *** DEADLOCK ***\n\n Call trace:\n print_deadlock_bug+0x25c/0x348\n __lock_acquire+0x10a4/0x2064\n lock_acquire+0x1e8/0x318\n down_read+0x60/0x184\n pcie_aspm_pm_state_change+0x58/0xdc\n pci_set_full_power_state+0xa8/0x114\n pci_set_power_state+0xc4/0x120\n qcom_pcie_enable_aspm+0x1c/0x3c [pcie_qcom]\n pci_walk_bus+0x64/0xbc\n qcom_pcie_host_post_init_2_7_0+0x28/0x34 [pcie_qcom]\n\nThe deadlock can easily be reproduced on machines like the Lenovo ThinkPad\nX13s by adding a delay to increase the race window during asynchronous\nprobe where another thread can take a write lock.\n\nAdd a new pci_set_power_state_locked() and associated helper functions that\ncan be called with the PCI bus semaphore held to avoid taking the read lock\ntwice.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26605"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/1e560864159d002b453da42bd2c13a1805515a20"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/ef90508574d7af48420bdc5f7b9a4f1cdd26bc70"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-26T16:28:00Z"
}
}

Some files were not shown because too many files have changed in this diff Show More