From 904f908752b11899f1b9c3d8fddaac3948ef4d39 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 19 Apr 2024 09:32:10 +0000 Subject: [PATCH] Publish Advisories GHSA-3787-6prv-h9w3 GHSA-9f24-jqhm-jfcw GHSA-xfg6-62px-cxc2 GHSA-f3jh-qvm4-mg39 GHSA-4v7x-pqxf-cx7m GHSA-h76p-mprh-fvmv GHSA-5355-6wp2-29w4 GHSA-7m48-vw34-vw84 GHSA-8xxh-r5gq-2wxg GHSA-j347-m6ww-35jg GHSA-qg2q-3q8w-8v7r GHSA-c2pq-wjfc-hxwr GHSA-jhp9-93xh-vh3m --- .../GHSA-3787-6prv-h9w3.json | 6 +++- .../GHSA-9f24-jqhm-jfcw.json | 6 +++- .../GHSA-xfg6-62px-cxc2.json | 6 +++- .../GHSA-f3jh-qvm4-mg39.json | 6 +++- .../GHSA-4v7x-pqxf-cx7m.json | 6 +++- .../GHSA-h76p-mprh-fvmv.json | 6 +++- .../GHSA-5355-6wp2-29w4.json | 6 +++- .../GHSA-7m48-vw34-vw84.json | 6 +++- .../GHSA-8xxh-r5gq-2wxg.json | 6 +++- .../GHSA-j347-m6ww-35jg.json | 6 +++- .../GHSA-qg2q-3q8w-8v7r.json | 6 +++- .../GHSA-c2pq-wjfc-hxwr.json | 35 +++++++++++++++++++ .../GHSA-jhp9-93xh-vh3m.json | 35 +++++++++++++++++++ 13 files changed, 125 insertions(+), 11 deletions(-) create mode 100644 advisories/unreviewed/2024/04/GHSA-c2pq-wjfc-hxwr/GHSA-c2pq-wjfc-hxwr.json create mode 100644 advisories/unreviewed/2024/04/GHSA-jhp9-93xh-vh3m/GHSA-jhp9-93xh-vh3m.json diff --git a/advisories/github-reviewed/2024/02/GHSA-3787-6prv-h9w3/GHSA-3787-6prv-h9w3.json b/advisories/github-reviewed/2024/02/GHSA-3787-6prv-h9w3/GHSA-3787-6prv-h9w3.json index ff7fe78d520..ce98c8339be 100644 --- a/advisories/github-reviewed/2024/02/GHSA-3787-6prv-h9w3/GHSA-3787-6prv-h9w3.json +++ b/advisories/github-reviewed/2024/02/GHSA-3787-6prv-h9w3/GHSA-3787-6prv-h9w3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3787-6prv-h9w3", - "modified": "2024-02-20T18:12:01Z", + "modified": "2024-04-19T09:30:47Z", "published": "2024-02-16T16:02:52Z", "aliases": [ "CVE-2024-24758" @@ -88,6 +88,10 @@ { "type": "WEB", "url": "https://github.com/nodejs/undici/releases/tag/v6.6.1" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240419-0007" } ], "database_specific": { diff --git a/advisories/github-reviewed/2024/02/GHSA-9f24-jqhm-jfcw/GHSA-9f24-jqhm-jfcw.json b/advisories/github-reviewed/2024/02/GHSA-9f24-jqhm-jfcw/GHSA-9f24-jqhm-jfcw.json index b4591a72fa2..fffca1b08e2 100644 --- a/advisories/github-reviewed/2024/02/GHSA-9f24-jqhm-jfcw/GHSA-9f24-jqhm-jfcw.json +++ b/advisories/github-reviewed/2024/02/GHSA-9f24-jqhm-jfcw/GHSA-9f24-jqhm-jfcw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9f24-jqhm-jfcw", - "modified": "2024-02-20T18:11:58Z", + "modified": "2024-04-19T09:30:47Z", "published": "2024-02-16T15:59:38Z", "aliases": [ "CVE-2024-24750" @@ -63,6 +63,10 @@ { "type": "WEB", "url": "https://github.com/nodejs/undici/releases/tag/v6.6.1" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240419-0006" } ], "database_specific": { diff --git a/advisories/github-reviewed/2024/02/GHSA-xfg6-62px-cxc2/GHSA-xfg6-62px-cxc2.json b/advisories/github-reviewed/2024/02/GHSA-xfg6-62px-cxc2/GHSA-xfg6-62px-cxc2.json index 0fc4ee88b59..e4bb41323e9 100644 --- a/advisories/github-reviewed/2024/02/GHSA-xfg6-62px-cxc2/GHSA-xfg6-62px-cxc2.json +++ b/advisories/github-reviewed/2024/02/GHSA-xfg6-62px-cxc2/GHSA-xfg6-62px-cxc2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xfg6-62px-cxc2", - "modified": "2024-04-18T21:31:57Z", + "modified": "2024-04-19T09:30:47Z", "published": "2024-02-19T15:30:38Z", "withdrawn": "2024-02-21T23:18:25Z", "aliases": [ @@ -156,6 +156,10 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TZQTSMESZD2RJ5XBPSXH3TIQVUW5DIUU" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240419-0008" + }, { "type": "WEB", "url": "https://www.enterprisedb.com/docs/jdbc_connector/latest/01_jdbc_rel_notes" diff --git a/advisories/github-reviewed/2024/03/GHSA-f3jh-qvm4-mg39/GHSA-f3jh-qvm4-mg39.json b/advisories/github-reviewed/2024/03/GHSA-f3jh-qvm4-mg39/GHSA-f3jh-qvm4-mg39.json index 143807901bb..40287c9ea29 100644 --- a/advisories/github-reviewed/2024/03/GHSA-f3jh-qvm4-mg39/GHSA-f3jh-qvm4-mg39.json +++ b/advisories/github-reviewed/2024/03/GHSA-f3jh-qvm4-mg39/GHSA-f3jh-qvm4-mg39.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f3jh-qvm4-mg39", - "modified": "2024-03-18T20:10:28Z", + "modified": "2024-04-19T09:30:47Z", "published": "2024-03-18T15:30:51Z", "aliases": [ "CVE-2024-22257" @@ -105,6 +105,10 @@ "type": "PACKAGE", "url": "https://github.com/spring-projects/spring-security" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240419-0005" + }, { "type": "WEB", "url": "https://spring.io/security/cve-2024-22257" diff --git a/advisories/github-reviewed/2024/04/GHSA-4v7x-pqxf-cx7m/GHSA-4v7x-pqxf-cx7m.json b/advisories/github-reviewed/2024/04/GHSA-4v7x-pqxf-cx7m/GHSA-4v7x-pqxf-cx7m.json index 73f40bb566d..8afba60bf00 100644 --- a/advisories/github-reviewed/2024/04/GHSA-4v7x-pqxf-cx7m/GHSA-4v7x-pqxf-cx7m.json +++ b/advisories/github-reviewed/2024/04/GHSA-4v7x-pqxf-cx7m/GHSA-4v7x-pqxf-cx7m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4v7x-pqxf-cx7m", - "modified": "2024-04-17T17:08:46Z", + "modified": "2024-04-19T09:30:47Z", "published": "2024-04-04T21:30:32Z", "aliases": [ "CVE-2023-45288" @@ -116,6 +116,10 @@ { "type": "WEB", "url": "https://pkg.go.dev/vuln/GO-2024-2687" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240419-0009" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/01/GHSA-h76p-mprh-fvmv/GHSA-h76p-mprh-fvmv.json b/advisories/unreviewed/2024/01/GHSA-h76p-mprh-fvmv/GHSA-h76p-mprh-fvmv.json index be8c90a0081..2ecf0bdb917 100644 --- a/advisories/unreviewed/2024/01/GHSA-h76p-mprh-fvmv/GHSA-h76p-mprh-fvmv.json +++ b/advisories/unreviewed/2024/01/GHSA-h76p-mprh-fvmv/GHSA-h76p-mprh-fvmv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h76p-mprh-fvmv", - "modified": "2024-01-18T21:30:27Z", + "modified": "2024-04-19T09:30:46Z", "published": "2024-01-11T21:31:19Z", "aliases": [ "CVE-2023-51780" @@ -36,6 +36,10 @@ { "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2024/01/msg00005.html" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240419-0001" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/02/GHSA-5355-6wp2-29w4/GHSA-5355-6wp2-29w4.json b/advisories/unreviewed/2024/02/GHSA-5355-6wp2-29w4/GHSA-5355-6wp2-29w4.json index b222e8833ea..f3e05ad2f64 100644 --- a/advisories/unreviewed/2024/02/GHSA-5355-6wp2-29w4/GHSA-5355-6wp2-29w4.json +++ b/advisories/unreviewed/2024/02/GHSA-5355-6wp2-29w4/GHSA-5355-6wp2-29w4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5355-6wp2-29w4", - "modified": "2024-02-19T06:30:33Z", + "modified": "2024-04-19T09:30:47Z", "published": "2024-02-19T06:30:33Z", "aliases": [ "CVE-2024-26328" @@ -21,6 +21,10 @@ { "type": "WEB", "url": "https://lore.kernel.org/all/20240213055345-mutt-send-email-mst%40kernel.org" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240419-0010" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/02/GHSA-7m48-vw34-vw84/GHSA-7m48-vw34-vw84.json b/advisories/unreviewed/2024/02/GHSA-7m48-vw34-vw84/GHSA-7m48-vw34-vw84.json index c7880ba7122..1ebbaa6f65a 100644 --- a/advisories/unreviewed/2024/02/GHSA-7m48-vw34-vw84/GHSA-7m48-vw34-vw84.json +++ b/advisories/unreviewed/2024/02/GHSA-7m48-vw34-vw84/GHSA-7m48-vw34-vw84.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7m48-vw34-vw84", - "modified": "2024-02-19T06:30:33Z", + "modified": "2024-04-19T09:30:47Z", "published": "2024-02-19T06:30:33Z", "aliases": [ "CVE-2024-26327" @@ -21,6 +21,10 @@ { "type": "WEB", "url": "https://lore.kernel.org/all/20240214-reuse-v4-5-89ad093a07f4%40daynix.com" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240419-0010" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/02/GHSA-8xxh-r5gq-2wxg/GHSA-8xxh-r5gq-2wxg.json b/advisories/unreviewed/2024/02/GHSA-8xxh-r5gq-2wxg/GHSA-8xxh-r5gq-2wxg.json index 58671e53da0..223ea115259 100644 --- a/advisories/unreviewed/2024/02/GHSA-8xxh-r5gq-2wxg/GHSA-8xxh-r5gq-2wxg.json +++ b/advisories/unreviewed/2024/02/GHSA-8xxh-r5gq-2wxg/GHSA-8xxh-r5gq-2wxg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8xxh-r5gq-2wxg", - "modified": "2024-02-15T06:31:35Z", + "modified": "2024-04-19T09:30:46Z", "published": "2024-02-15T06:31:35Z", "aliases": [ "CVE-2022-23086" @@ -21,6 +21,10 @@ { "type": "WEB", "url": "https://security.freebsd.org/advisories/FreeBSD-SA-22:06.ioctl.asc" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240419-0002" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/02/GHSA-j347-m6ww-35jg/GHSA-j347-m6ww-35jg.json b/advisories/unreviewed/2024/02/GHSA-j347-m6ww-35jg/GHSA-j347-m6ww-35jg.json index 4bbcb7ceaab..306959b7662 100644 --- a/advisories/unreviewed/2024/02/GHSA-j347-m6ww-35jg/GHSA-j347-m6ww-35jg.json +++ b/advisories/unreviewed/2024/02/GHSA-j347-m6ww-35jg/GHSA-j347-m6ww-35jg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j347-m6ww-35jg", - "modified": "2024-02-15T06:31:36Z", + "modified": "2024-04-19T09:30:47Z", "published": "2024-02-15T06:31:35Z", "aliases": [ "CVE-2024-25940" @@ -21,6 +21,10 @@ { "type": "WEB", "url": "https://security.freebsd.org/advisories/FreeBSD-SA-24:01.bhyveload.asc" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240419-0004" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/02/GHSA-qg2q-3q8w-8v7r/GHSA-qg2q-3q8w-8v7r.json b/advisories/unreviewed/2024/02/GHSA-qg2q-3q8w-8v7r/GHSA-qg2q-3q8w-8v7r.json index fc8968ca5b8..2e46ba36dca 100644 --- a/advisories/unreviewed/2024/02/GHSA-qg2q-3q8w-8v7r/GHSA-qg2q-3q8w-8v7r.json +++ b/advisories/unreviewed/2024/02/GHSA-qg2q-3q8w-8v7r/GHSA-qg2q-3q8w-8v7r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qg2q-3q8w-8v7r", - "modified": "2024-02-15T06:31:35Z", + "modified": "2024-04-19T09:30:46Z", "published": "2024-02-15T06:31:35Z", "aliases": [ "CVE-2022-23084" @@ -21,6 +21,10 @@ { "type": "WEB", "url": "https://security.freebsd.org/advisories/FreeBSD-SA-22:04.netmap.asc" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240419-0003" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/04/GHSA-c2pq-wjfc-hxwr/GHSA-c2pq-wjfc-hxwr.json b/advisories/unreviewed/2024/04/GHSA-c2pq-wjfc-hxwr/GHSA-c2pq-wjfc-hxwr.json new file mode 100644 index 00000000000..32e3a84c78a --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-c2pq-wjfc-hxwr/GHSA-c2pq-wjfc-hxwr.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c2pq-wjfc-hxwr", + "modified": "2024-04-19T09:30:47Z", + "published": "2024-04-19T09:30:47Z", + "aliases": [ + "CVE-2024-0671" + ], + "details": "Use After Free vulnerability in Arm Ltd Midgard GPU Kernel Driver, Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to make improper GPU memory processing operations to gain access to already freed memory.This issue affects Midgard GPU Kernel Driver: from r19p0 through r32p0; Bifrost GPU Kernel Driver: from r7p0 through r48p0; Valhall GPU Kernel Driver: from r19p0 through r48p0; Arm 5th Gen GPU Architecture Kernel Driver: from r41p0 through r48p0.\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0671" + }, + { + "type": "WEB", + "url": "https://developer.arm.com/Arm%20Security%20Center/Mali%20GPU%20Driver%20Vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T09:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-jhp9-93xh-vh3m/GHSA-jhp9-93xh-vh3m.json b/advisories/unreviewed/2024/04/GHSA-jhp9-93xh-vh3m/GHSA-jhp9-93xh-vh3m.json new file mode 100644 index 00000000000..e0a97f03396 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-jhp9-93xh-vh3m/GHSA-jhp9-93xh-vh3m.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jhp9-93xh-vh3m", + "modified": "2024-04-19T09:30:47Z", + "published": "2024-04-19T09:30:47Z", + "aliases": [ + "CVE-2024-1065" + ], + "details": "Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to make improper GPU memory processing operations to gain access to already freed memory.This issue affects Bifrost GPU Kernel Driver: from r45p0 through r48p0; Valhall GPU Kernel Driver: from r45p0 through r48p0; Arm 5th Gen GPU Architecture Kernel Driver: from r45p0 through r48p0.\n\n", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1065" + }, + { + "type": "WEB", + "url": "https://developer.arm.com/Arm%20Security%20Center/Mali%20GPU%20Driver%20Vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-19T09:15:46Z" + } +} \ No newline at end of file