diff --git a/advisories/unreviewed/2023/01/GHSA-2347-hhxr-8hg9/GHSA-2347-hhxr-8hg9.json b/advisories/unreviewed/2023/01/GHSA-2347-hhxr-8hg9/GHSA-2347-hhxr-8hg9.json index 7143718990f..dc5fbf2f2b1 100644 --- a/advisories/unreviewed/2023/01/GHSA-2347-hhxr-8hg9/GHSA-2347-hhxr-8hg9.json +++ b/advisories/unreviewed/2023/01/GHSA-2347-hhxr-8hg9/GHSA-2347-hhxr-8hg9.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-74", "CWE-79" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2023/01/GHSA-9w89-223r-7hm3/GHSA-9w89-223r-7hm3.json b/advisories/unreviewed/2023/01/GHSA-9w89-223r-7hm3/GHSA-9w89-223r-7hm3.json index 02398bbbb51..13547d3dce2 100644 --- a/advisories/unreviewed/2023/01/GHSA-9w89-223r-7hm3/GHSA-9w89-223r-7hm3.json +++ b/advisories/unreviewed/2023/01/GHSA-9w89-223r-7hm3/GHSA-9w89-223r-7hm3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9w89-223r-7hm3", - "modified": "2023-02-06T18:30:31Z", + "modified": "2025-04-01T18:30:31Z", "published": "2023-01-26T21:30:21Z", "aliases": [ "CVE-2022-43997" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-269" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/01/GHSA-cxjq-5xjf-cmp7/GHSA-cxjq-5xjf-cmp7.json b/advisories/unreviewed/2023/01/GHSA-cxjq-5xjf-cmp7/GHSA-cxjq-5xjf-cmp7.json index 219b2ef6c3c..5d82afbdf24 100644 --- a/advisories/unreviewed/2023/01/GHSA-cxjq-5xjf-cmp7/GHSA-cxjq-5xjf-cmp7.json +++ b/advisories/unreviewed/2023/01/GHSA-cxjq-5xjf-cmp7/GHSA-cxjq-5xjf-cmp7.json @@ -34,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-79" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/01/GHSA-qcxf-3r2g-vpvx/GHSA-qcxf-3r2g-vpvx.json b/advisories/unreviewed/2023/01/GHSA-qcxf-3r2g-vpvx/GHSA-qcxf-3r2g-vpvx.json index 6235d9f3f4c..bc1aa137ac8 100644 --- a/advisories/unreviewed/2023/01/GHSA-qcxf-3r2g-vpvx/GHSA-qcxf-3r2g-vpvx.json +++ b/advisories/unreviewed/2023/01/GHSA-qcxf-3r2g-vpvx/GHSA-qcxf-3r2g-vpvx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qcxf-3r2g-vpvx", - "modified": "2023-02-01T21:30:22Z", + "modified": "2025-04-01T18:30:32Z", "published": "2023-01-26T21:30:20Z", "aliases": [ "CVE-2022-47073" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-47073" }, + { + "type": "WEB", + "url": "https://medium.com/%40shiva.infocop/stored-xss-found-in-small-crm-phpgurukul-7890ea3c04df" + }, { "type": "WEB", "url": "https://medium.com/@shiva.infocop/stored-xss-found-in-small-crm-phpgurukul-7890ea3c04df" diff --git a/advisories/unreviewed/2023/01/GHSA-rwm6-p7m2-82w7/GHSA-rwm6-p7m2-82w7.json b/advisories/unreviewed/2023/01/GHSA-rwm6-p7m2-82w7/GHSA-rwm6-p7m2-82w7.json index 2dce7fe6ae2..91bf5e46afe 100644 --- a/advisories/unreviewed/2023/01/GHSA-rwm6-p7m2-82w7/GHSA-rwm6-p7m2-82w7.json +++ b/advisories/unreviewed/2023/01/GHSA-rwm6-p7m2-82w7/GHSA-rwm6-p7m2-82w7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rwm6-p7m2-82w7", - "modified": "2023-02-01T15:30:20Z", + "modified": "2025-04-01T18:30:32Z", "published": "2023-01-26T21:30:21Z", "aliases": [ "CVE-2022-45730" diff --git a/advisories/unreviewed/2024/02/GHSA-4rvh-837w-4r69/GHSA-4rvh-837w-4r69.json b/advisories/unreviewed/2024/02/GHSA-4rvh-837w-4r69/GHSA-4rvh-837w-4r69.json index f5a12f428d9..6dbe2c5e7d4 100644 --- a/advisories/unreviewed/2024/02/GHSA-4rvh-837w-4r69/GHSA-4rvh-837w-4r69.json +++ b/advisories/unreviewed/2024/02/GHSA-4rvh-837w-4r69/GHSA-4rvh-837w-4r69.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-4rvh-837w-4r69", - "modified": "2024-02-28T18:30:32Z", + "modified": "2025-04-01T18:30:33Z", "published": "2024-02-28T18:30:32Z", "aliases": [ "CVE-2023-51683" ], - "details": "Cross-Site Request Forgery (CSRF) vulnerability in Scott Paterson Easy PayPal & Stripe Buy Now Button.This issue affects Easy PayPal & Stripe Buy Now Button: from n/a through 1.8.1.\n\n", + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Scott Paterson Easy PayPal & Stripe Buy Now Button.This issue affects Easy PayPal & Stripe Buy Now Button: from n/a through 1.8.1.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/02/GHSA-fwfw-qq2h-g6g5/GHSA-fwfw-qq2h-g6g5.json b/advisories/unreviewed/2024/02/GHSA-fwfw-qq2h-g6g5/GHSA-fwfw-qq2h-g6g5.json index d52cfddf2a3..80b56f0e367 100644 --- a/advisories/unreviewed/2024/02/GHSA-fwfw-qq2h-g6g5/GHSA-fwfw-qq2h-g6g5.json +++ b/advisories/unreviewed/2024/02/GHSA-fwfw-qq2h-g6g5/GHSA-fwfw-qq2h-g6g5.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-fwfw-qq2h-g6g5", - "modified": "2024-02-28T15:30:57Z", + "modified": "2025-04-01T18:30:33Z", "published": "2024-02-28T15:30:57Z", "aliases": [ "CVE-2024-24702" ], - "details": "Cross-Site Request Forgery (CSRF) vulnerability in Matt Martz & Andy Stratton Page Restrict.This issue affects Page Restrict: from n/a through 2.5.5.\n\n", + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Matt Martz & Andy Stratton Page Restrict.This issue affects Page Restrict: from n/a through 2.5.5.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/02/GHSA-p56p-x426-8q87/GHSA-p56p-x426-8q87.json b/advisories/unreviewed/2024/02/GHSA-p56p-x426-8q87/GHSA-p56p-x426-8q87.json index 15f84d60ec9..b5b96bff577 100644 --- a/advisories/unreviewed/2024/02/GHSA-p56p-x426-8q87/GHSA-p56p-x426-8q87.json +++ b/advisories/unreviewed/2024/02/GHSA-p56p-x426-8q87/GHSA-p56p-x426-8q87.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-p56p-x426-8q87", - "modified": "2024-02-21T15:30:44Z", + "modified": "2025-04-01T18:30:33Z", "published": "2024-02-20T00:30:34Z", "aliases": [ "CVE-2023-6259" ], - "details": "Insufficiently Protected Credentials, : Improper Access Control vulnerability in Brivo ACS100, ACS300 allows Password Recovery Exploitation, Bypassing Physical Security.This issue affects ACS100, ACS300: from 5.2.4 before 6.2.4.3.\n\n", + "details": "Insufficiently Protected Credentials, : Improper Access Control vulnerability in Brivo ACS100, ACS300 allows Password Recovery Exploitation, Bypassing Physical Security.This issue affects ACS100, ACS300: from 5.2.4 before 6.2.4.3.", "severity": [ { "type": "CVSS_V3", @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-522" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-37x3-hqf8-5w7p/GHSA-37x3-hqf8-5w7p.json b/advisories/unreviewed/2024/03/GHSA-37x3-hqf8-5w7p/GHSA-37x3-hqf8-5w7p.json index 43352fe6e6d..52f8b8af920 100644 --- a/advisories/unreviewed/2024/03/GHSA-37x3-hqf8-5w7p/GHSA-37x3-hqf8-5w7p.json +++ b/advisories/unreviewed/2024/03/GHSA-37x3-hqf8-5w7p/GHSA-37x3-hqf8-5w7p.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-59gg-h898-v8m7/GHSA-59gg-h898-v8m7.json b/advisories/unreviewed/2024/03/GHSA-59gg-h898-v8m7/GHSA-59gg-h898-v8m7.json index cfad6ebed5f..a69e28c2654 100644 --- a/advisories/unreviewed/2024/03/GHSA-59gg-h898-v8m7/GHSA-59gg-h898-v8m7.json +++ b/advisories/unreviewed/2024/03/GHSA-59gg-h898-v8m7/GHSA-59gg-h898-v8m7.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-59gg-h898-v8m7", - "modified": "2024-03-25T09:32:34Z", + "modified": "2025-04-01T18:30:38Z", "published": "2024-03-25T09:32:34Z", "aliases": [ "CVE-2024-2862" ], - "details": "\nThis vulnerability allows remote attackers to reset the password of anonymous users without authorization on the affected LG LED Assistant.\n\n", + "details": "This vulnerability allows remote attackers to reset the password of anonymous users without authorization on the affected LG LED Assistant.", "severity": [ { "type": "CVSS_V3", @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-287" + "CWE-287", + "CWE-640" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-5xcj-6x8h-ff6h/GHSA-5xcj-6x8h-ff6h.json b/advisories/unreviewed/2024/03/GHSA-5xcj-6x8h-ff6h/GHSA-5xcj-6x8h-ff6h.json index b02163d0000..42be1cd060b 100644 --- a/advisories/unreviewed/2024/03/GHSA-5xcj-6x8h-ff6h/GHSA-5xcj-6x8h-ff6h.json +++ b/advisories/unreviewed/2024/03/GHSA-5xcj-6x8h-ff6h/GHSA-5xcj-6x8h-ff6h.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-6fc3-8g79-3f39/GHSA-6fc3-8g79-3f39.json b/advisories/unreviewed/2024/03/GHSA-6fc3-8g79-3f39/GHSA-6fc3-8g79-3f39.json index b1bf96a554a..ff9c9e3d6c3 100644 --- a/advisories/unreviewed/2024/03/GHSA-6fc3-8g79-3f39/GHSA-6fc3-8g79-3f39.json +++ b/advisories/unreviewed/2024/03/GHSA-6fc3-8g79-3f39/GHSA-6fc3-8g79-3f39.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-6pcg-34vx-3h95/GHSA-6pcg-34vx-3h95.json b/advisories/unreviewed/2024/03/GHSA-6pcg-34vx-3h95/GHSA-6pcg-34vx-3h95.json index e2f6ecaf85b..c5d2154dc6c 100644 --- a/advisories/unreviewed/2024/03/GHSA-6pcg-34vx-3h95/GHSA-6pcg-34vx-3h95.json +++ b/advisories/unreviewed/2024/03/GHSA-6pcg-34vx-3h95/GHSA-6pcg-34vx-3h95.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-9q54-pg8p-25cg/GHSA-9q54-pg8p-25cg.json b/advisories/unreviewed/2024/03/GHSA-9q54-pg8p-25cg/GHSA-9q54-pg8p-25cg.json index 8731897e34b..98753a6598a 100644 --- a/advisories/unreviewed/2024/03/GHSA-9q54-pg8p-25cg/GHSA-9q54-pg8p-25cg.json +++ b/advisories/unreviewed/2024/03/GHSA-9q54-pg8p-25cg/GHSA-9q54-pg8p-25cg.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-918" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-fpr2-hvvq-5xh8/GHSA-fpr2-hvvq-5xh8.json b/advisories/unreviewed/2024/03/GHSA-fpr2-hvvq-5xh8/GHSA-fpr2-hvvq-5xh8.json index fa83959bd5c..9b20b1ea262 100644 --- a/advisories/unreviewed/2024/03/GHSA-fpr2-hvvq-5xh8/GHSA-fpr2-hvvq-5xh8.json +++ b/advisories/unreviewed/2024/03/GHSA-fpr2-hvvq-5xh8/GHSA-fpr2-hvvq-5xh8.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-wvw8-hcw4-jwqp/GHSA-wvw8-hcw4-jwqp.json b/advisories/unreviewed/2024/03/GHSA-wvw8-hcw4-jwqp/GHSA-wvw8-hcw4-jwqp.json index f4cf4f42c13..9e08b38d29e 100644 --- a/advisories/unreviewed/2024/03/GHSA-wvw8-hcw4-jwqp/GHSA-wvw8-hcw4-jwqp.json +++ b/advisories/unreviewed/2024/03/GHSA-wvw8-hcw4-jwqp/GHSA-wvw8-hcw4-jwqp.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-ww69-c6p5-r54m/GHSA-ww69-c6p5-r54m.json b/advisories/unreviewed/2024/03/GHSA-ww69-c6p5-r54m/GHSA-ww69-c6p5-r54m.json index 6fc4fd9cd04..aa8aac99478 100644 --- a/advisories/unreviewed/2024/03/GHSA-ww69-c6p5-r54m/GHSA-ww69-c6p5-r54m.json +++ b/advisories/unreviewed/2024/03/GHSA-ww69-c6p5-r54m/GHSA-ww69-c6p5-r54m.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-704" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-2fg8-6ggf-j2jg/GHSA-2fg8-6ggf-j2jg.json b/advisories/unreviewed/2024/05/GHSA-2fg8-6ggf-j2jg/GHSA-2fg8-6ggf-j2jg.json index 42de66247d7..a6e6a9910f6 100644 --- a/advisories/unreviewed/2024/05/GHSA-2fg8-6ggf-j2jg/GHSA-2fg8-6ggf-j2jg.json +++ b/advisories/unreviewed/2024/05/GHSA-2fg8-6ggf-j2jg/GHSA-2fg8-6ggf-j2jg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2fg8-6ggf-j2jg", - "modified": "2024-06-10T18:31:01Z", + "modified": "2025-04-01T18:30:39Z", "published": "2024-05-14T18:31:05Z", "aliases": [ "CVE-2024-4768" ], "details": "A bug in popup notifications' interaction with WebAuthn made it easier for an attacker to trick a user into granting permissions. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-281" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T18:15:14Z" diff --git a/advisories/unreviewed/2024/05/GHSA-fffc-4hjp-2r9v/GHSA-fffc-4hjp-2r9v.json b/advisories/unreviewed/2024/05/GHSA-fffc-4hjp-2r9v/GHSA-fffc-4hjp-2r9v.json index cb9199e3e99..fd3f6eeee67 100644 --- a/advisories/unreviewed/2024/05/GHSA-fffc-4hjp-2r9v/GHSA-fffc-4hjp-2r9v.json +++ b/advisories/unreviewed/2024/05/GHSA-fffc-4hjp-2r9v/GHSA-fffc-4hjp-2r9v.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-359" + "CWE-359", + "CWE-459" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-c864-85xv-823c/GHSA-c864-85xv-823c.json b/advisories/unreviewed/2024/06/GHSA-c864-85xv-823c/GHSA-c864-85xv-823c.json index b186bb15a52..643b7015da1 100644 --- a/advisories/unreviewed/2024/06/GHSA-c864-85xv-823c/GHSA-c864-85xv-823c.json +++ b/advisories/unreviewed/2024/06/GHSA-c864-85xv-823c/GHSA-c864-85xv-823c.json @@ -41,7 +41,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-667" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-g9c8-phh2-8fqc/GHSA-g9c8-phh2-8fqc.json b/advisories/unreviewed/2024/06/GHSA-g9c8-phh2-8fqc/GHSA-g9c8-phh2-8fqc.json index 7c63c6ba0f0..e002f9e5ea3 100644 --- a/advisories/unreviewed/2024/06/GHSA-g9c8-phh2-8fqc/GHSA-g9c8-phh2-8fqc.json +++ b/advisories/unreviewed/2024/06/GHSA-g9c8-phh2-8fqc/GHSA-g9c8-phh2-8fqc.json @@ -61,7 +61,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-667" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-gqvj-vmm6-rx6c/GHSA-gqvj-vmm6-rx6c.json b/advisories/unreviewed/2024/06/GHSA-gqvj-vmm6-rx6c/GHSA-gqvj-vmm6-rx6c.json index 08f78cd0c9f..db02612f30f 100644 --- a/advisories/unreviewed/2024/06/GHSA-gqvj-vmm6-rx6c/GHSA-gqvj-vmm6-rx6c.json +++ b/advisories/unreviewed/2024/06/GHSA-gqvj-vmm6-rx6c/GHSA-gqvj-vmm6-rx6c.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gqvj-vmm6-rx6c", - "modified": "2024-06-21T12:31:20Z", + "modified": "2025-04-01T18:30:40Z", "published": "2024-06-21T12:31:20Z", "aliases": [ "CVE-2024-38388" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: hda/cs_dsp_ctl: Use private_free for control cleanup\n\nUse the control private_free callback to free the associated data\nblock. This ensures that the memory won't leak, whatever way the\ncontrol gets destroyed.\n\nThe original implementation didn't actually remove the ALSA\ncontrols in hda_cs_dsp_control_remove(). It only freed the internal\ntracking structure. This meant it was possible to remove/unload the\namp driver while leaving its ALSA controls still present in the\nsoundcard. Obviously attempting to access them could cause segfaults\nor at least dereferencing stale pointers.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-21T11:15:10Z" diff --git a/advisories/unreviewed/2024/06/GHSA-hfr2-rr32-h89p/GHSA-hfr2-rr32-h89p.json b/advisories/unreviewed/2024/06/GHSA-hfr2-rr32-h89p/GHSA-hfr2-rr32-h89p.json index 99e973aefca..f72db4b513c 100644 --- a/advisories/unreviewed/2024/06/GHSA-hfr2-rr32-h89p/GHSA-hfr2-rr32-h89p.json +++ b/advisories/unreviewed/2024/06/GHSA-hfr2-rr32-h89p/GHSA-hfr2-rr32-h89p.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-xwrr-9h7c-8mxc/GHSA-xwrr-9h7c-8mxc.json b/advisories/unreviewed/2024/06/GHSA-xwrr-9h7c-8mxc/GHSA-xwrr-9h7c-8mxc.json index 7d6ff8eb641..e3f966a9735 100644 --- a/advisories/unreviewed/2024/06/GHSA-xwrr-9h7c-8mxc/GHSA-xwrr-9h7c-8mxc.json +++ b/advisories/unreviewed/2024/06/GHSA-xwrr-9h7c-8mxc/GHSA-xwrr-9h7c-8mxc.json @@ -42,6 +42,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-120", "CWE-121" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2025/03/GHSA-6qrv-h235-q5x7/GHSA-6qrv-h235-q5x7.json b/advisories/unreviewed/2025/03/GHSA-6qrv-h235-q5x7/GHSA-6qrv-h235-q5x7.json index 62a90e4e95a..020dff62ea6 100644 --- a/advisories/unreviewed/2025/03/GHSA-6qrv-h235-q5x7/GHSA-6qrv-h235-q5x7.json +++ b/advisories/unreviewed/2025/03/GHSA-6qrv-h235-q5x7/GHSA-6qrv-h235-q5x7.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-76c9-635j-h2r5/GHSA-76c9-635j-h2r5.json b/advisories/unreviewed/2025/03/GHSA-76c9-635j-h2r5/GHSA-76c9-635j-h2r5.json index 434e7bc34ae..fa6d540b045 100644 --- a/advisories/unreviewed/2025/03/GHSA-76c9-635j-h2r5/GHSA-76c9-635j-h2r5.json +++ b/advisories/unreviewed/2025/03/GHSA-76c9-635j-h2r5/GHSA-76c9-635j-h2r5.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-pq47-r743-hrh5/GHSA-pq47-r743-hrh5.json b/advisories/unreviewed/2025/03/GHSA-pq47-r743-hrh5/GHSA-pq47-r743-hrh5.json index ebdd7821889..4a226991ff0 100644 --- a/advisories/unreviewed/2025/03/GHSA-pq47-r743-hrh5/GHSA-pq47-r743-hrh5.json +++ b/advisories/unreviewed/2025/03/GHSA-pq47-r743-hrh5/GHSA-pq47-r743-hrh5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pq47-r743-hrh5", - "modified": "2025-03-24T15:30:48Z", + "modified": "2025-04-01T18:30:43Z", "published": "2025-03-24T15:30:48Z", "aliases": [ "CVE-2024-55279" ], "details": "Uguu through 1.8.9 allows Cross Site Scripting (XSS) via JavaScript in XML files.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-24T15:15:15Z" diff --git a/advisories/unreviewed/2025/03/GHSA-qqq7-68c5-p37w/GHSA-qqq7-68c5-p37w.json b/advisories/unreviewed/2025/03/GHSA-qqq7-68c5-p37w/GHSA-qqq7-68c5-p37w.json index 5fdee40d3c0..fcbcc1c7190 100644 --- a/advisories/unreviewed/2025/03/GHSA-qqq7-68c5-p37w/GHSA-qqq7-68c5-p37w.json +++ b/advisories/unreviewed/2025/03/GHSA-qqq7-68c5-p37w/GHSA-qqq7-68c5-p37w.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-2qpc-wrp3-2p98/GHSA-2qpc-wrp3-2p98.json b/advisories/unreviewed/2025/04/GHSA-2qpc-wrp3-2p98/GHSA-2qpc-wrp3-2p98.json new file mode 100644 index 00000000000..3ef42d8a204 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2qpc-wrp3-2p98/GHSA-2qpc-wrp3-2p98.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2qpc-wrp3-2p98", + "modified": "2025-04-01T18:30:51Z", + "published": "2025-04-01T18:30:50Z", + "aliases": [ + "CVE-2025-21913" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/amd_nb: Use rdmsr_safe() in amd_get_mmconfig_range()\n\nXen doesn't offer MSR_FAM10H_MMIO_CONF_BASE to all guests. This results\nin the following warning:\n\n unchecked MSR access error: RDMSR from 0xc0010058 at rIP: 0xffffffff8101d19f (xen_do_read_msr+0x7f/0xa0)\n Call Trace:\n xen_read_msr+0x1e/0x30\n amd_get_mmconfig_range+0x2b/0x80\n quirk_amd_mmconfig_area+0x28/0x100\n pnp_fixup_device+0x39/0x50\n __pnp_add_device+0xf/0x150\n pnp_add_device+0x3d/0x100\n pnpacpi_add_device_handler+0x1f9/0x280\n acpi_ns_get_device_callback+0x104/0x1c0\n acpi_ns_walk_namespace+0x1d0/0x260\n acpi_get_devices+0x8a/0xb0\n pnpacpi_init+0x50/0x80\n do_one_initcall+0x46/0x2e0\n kernel_init_freeable+0x1da/0x2f0\n kernel_init+0x16/0x1b0\n ret_from_fork+0x30/0x50\n ret_from_fork_asm+0x1b/0x30\n\nbased on quirks for a \"PNP0c01\" device. Treating MMCFG as disabled is the\nright course of action, so no change is needed there.\n\nThis was most likely exposed by fixing the Xen MSR accessors to not be\nsilently-safe.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21913" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0c65d13bdcc54e5b924ebe790f85a7f01bfe1cb1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/14cb5d83068ecf15d2da6f7d0e9ea9edbcbc0457" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8f43ba5ee498fe037d1570f6868d9aeaf49dda80" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/923fede9eae9865af305bcdf8f111e4b62ae4bda" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ebf6a763904e42dabeb2e270ceb0bbe0f825d7ae" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-32g6-m5fv-fhv6/GHSA-32g6-m5fv-fhv6.json b/advisories/unreviewed/2025/04/GHSA-32g6-m5fv-fhv6/GHSA-32g6-m5fv-fhv6.json new file mode 100644 index 00000000000..056830d5b10 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-32g6-m5fv-fhv6/GHSA-32g6-m5fv-fhv6.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-32g6-m5fv-fhv6", + "modified": "2025-04-01T18:30:50Z", + "published": "2025-04-01T18:30:50Z", + "aliases": [ + "CVE-2025-21897" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsched_ext: Fix pick_task_scx() picking non-queued tasks when it's called without balance()\n\na6250aa251ea (\"sched_ext: Handle cases where pick_task_scx() is called\nwithout preceding balance_scx()\") added a workaround to handle the cases\nwhere pick_task_scx() is called without prececing balance_scx() which is due\nto a fair class bug where pick_taks_fair() may return NULL after a true\nreturn from balance_fair().\n\nThe workaround detects when pick_task_scx() is called without preceding\nbalance_scx() and emulates SCX_RQ_BAL_KEEP and triggers kicking to avoid\nstalling. Unfortunately, the workaround code was testing whether @prev was\non SCX to decide whether to keep the task running. This is incorrect as the\ntask may be on SCX but no longer runnable.\n\nThis could lead to a non-runnable task to be returned from pick_task_scx()\nwhich cause interesting confusions and failures. e.g. A common failure mode\nis the task ending up with (!on_rq && on_cpu) state which can cause\npotential wakers to busy loop, which can easily lead to deadlocks.\n\nFix it by testing whether @prev has SCX_TASK_QUEUED set. This makes\n@prev_on_scx only used in one place. Open code the usage and improve the\ncomment while at it.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21897" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5324c459f90d16b0c43a78b494c598915d782b7a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8fef0a3b17bb258130a4fcbcb5addf94b25e9ec5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/de60a31cb0bcacfaf9487546eac5e70e0a9c66d7" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-37v5-vmq6-f37g/GHSA-37v5-vmq6-f37g.json b/advisories/unreviewed/2025/04/GHSA-37v5-vmq6-f37g/GHSA-37v5-vmq6-f37g.json new file mode 100644 index 00000000000..bc75f94059b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-37v5-vmq6-f37g/GHSA-37v5-vmq6-f37g.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-37v5-vmq6-f37g", + "modified": "2025-04-01T18:30:54Z", + "published": "2025-04-01T18:30:54Z", + "aliases": [ + "CVE-2025-21971" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet_sched: Prevent creation of classes with TC_H_ROOT\n\nThe function qdisc_tree_reduce_backlog() uses TC_H_ROOT as a termination\ncondition when traversing up the qdisc tree to update parent backlog\ncounters. However, if a class is created with classid TC_H_ROOT, the\ntraversal terminates prematurely at this class instead of reaching the\nactual root qdisc, causing parent statistics to be incorrectly maintained.\nIn case of DRR, this could lead to a crash as reported by Mingi Cho.\n\nPrevent the creation of any Qdisc class with classid TC_H_ROOT\n(0xFFFFFFFF) across all qdisc types, as suggested by Jamal.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21971" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0c3057a5a04d07120b3d0ec9c79568fceb9c921e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5c3ca9cb48b51bd72bf76b8b05e24f3cd53db5e7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/78533c4a29ac3aeddce4b481770beaaa4f3bfb67" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/94edfdfb9505ab608e86599d1d1e38c83816fc1c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e5ee00607bbfc97ef1526ea95b6b2458ac9e7cb7" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3cxf-3h44-8cxr/GHSA-3cxf-3h44-8cxr.json b/advisories/unreviewed/2025/04/GHSA-3cxf-3h44-8cxr/GHSA-3cxf-3h44-8cxr.json index 5133f090b27..1a7b486bcda 100644 --- a/advisories/unreviewed/2025/04/GHSA-3cxf-3h44-8cxr/GHSA-3cxf-3h44-8cxr.json +++ b/advisories/unreviewed/2025/04/GHSA-3cxf-3h44-8cxr/GHSA-3cxf-3h44-8cxr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3cxf-3h44-8cxr", - "modified": "2025-04-01T00:30:44Z", + "modified": "2025-04-01T18:30:48Z", "published": "2025-04-01T00:30:44Z", "aliases": [ "CVE-2025-31187" ], "details": "This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to modify protected parts of the file system.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:28Z" diff --git a/advisories/unreviewed/2025/04/GHSA-3rmf-x7h3-c76w/GHSA-3rmf-x7h3-c76w.json b/advisories/unreviewed/2025/04/GHSA-3rmf-x7h3-c76w/GHSA-3rmf-x7h3-c76w.json new file mode 100644 index 00000000000..b534b0172d5 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3rmf-x7h3-c76w/GHSA-3rmf-x7h3-c76w.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3rmf-x7h3-c76w", + "modified": "2025-04-01T18:30:50Z", + "published": "2025-04-01T18:30:50Z", + "aliases": [ + "CVE-2025-21906" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: iwlwifi: mvm: clean up ROC on failure\n\nIf the firmware fails to start the session protection, then we\ndo call iwl_mvm_roc_finished() here, but that won't do anything\nat all because IWL_MVM_STATUS_ROC_P2P_RUNNING was never set.\nSet IWL_MVM_STATUS_ROC_P2P_RUNNING in the failure/stop path.\nIf it started successfully before, it's already set, so that\ndoesn't matter, and if it didn't start it needs to be set to\nclean up.\n\nNot doing so will lead to a WARN_ON() later on a fresh remain-\non-channel, since the link is already active when activated as\nit was never deactivated.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21906" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a88c18409b5d69f426d5acc583c053eac71756a3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d1a12fcb9051bbf38b2e5af310ffb102a0fab6f9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f9751163bffd3fe60794929829f810968c6de73d" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-497m-pmwp-3283/GHSA-497m-pmwp-3283.json b/advisories/unreviewed/2025/04/GHSA-497m-pmwp-3283/GHSA-497m-pmwp-3283.json new file mode 100644 index 00000000000..95762668865 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-497m-pmwp-3283/GHSA-497m-pmwp-3283.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-497m-pmwp-3283", + "modified": "2025-04-01T18:30:50Z", + "published": "2025-04-01T18:30:50Z", + "aliases": [ + "CVE-2025-21907" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm: memory-failure: update ttu flag inside unmap_poisoned_folio\n\nPatch series \"mm: memory_failure: unmap poisoned folio during migrate\nproperly\", v3.\n\nFix two bugs during folio migration if the folio is poisoned.\n\n\nThis patch (of 3):\n\nCommit 6da6b1d4a7df (\"mm/hwpoison: convert TTU_IGNORE_HWPOISON to\nTTU_HWPOISON\") introduce TTU_HWPOISON to replace TTU_IGNORE_HWPOISON in\norder to stop send SIGBUS signal when accessing an error page after a\nmemory error on a clean folio. However during page migration, anon folio\nmust be set with TTU_HWPOISON during unmap_*(). For pagecache we need\nsome policy just like the one in hwpoison_user_mappings to set this flag. \nSo move this policy from hwpoison_user_mappings to unmap_poisoned_folio to\nhandle this warning properly.\n\nWarning will be produced during unamp poison folio with the following log:\n\n ------------[ cut here ]------------\n WARNING: CPU: 1 PID: 365 at mm/rmap.c:1847 try_to_unmap_one+0x8fc/0xd3c\n Modules linked in:\n CPU: 1 UID: 0 PID: 365 Comm: bash Tainted: G W 6.13.0-rc1-00018-gacdb4bbda7ab #42\n Tainted: [W]=WARN\n Hardware name: QEMU QEMU Virtual Machine, BIOS 0.0.0 02/06/2015\n pstate: 20400005 (nzCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n pc : try_to_unmap_one+0x8fc/0xd3c\n lr : try_to_unmap_one+0x3dc/0xd3c\n Call trace:\n try_to_unmap_one+0x8fc/0xd3c (P)\n try_to_unmap_one+0x3dc/0xd3c (L)\n rmap_walk_anon+0xdc/0x1f8\n rmap_walk+0x3c/0x58\n try_to_unmap+0x88/0x90\n unmap_poisoned_folio+0x30/0xa8\n do_migrate_range+0x4a0/0x568\n offline_pages+0x5a4/0x670\n memory_block_action+0x17c/0x374\n memory_subsys_offline+0x3c/0x78\n device_offline+0xa4/0xd0\n state_store+0x8c/0xf0\n dev_attr_store+0x18/0x2c\n sysfs_kf_write+0x44/0x54\n kernfs_fop_write_iter+0x118/0x1a8\n vfs_write+0x3a8/0x4bc\n ksys_write+0x6c/0xf8\n __arm64_sys_write+0x1c/0x28\n invoke_syscall+0x44/0x100\n el0_svc_common.constprop.0+0x40/0xe0\n do_el0_svc+0x1c/0x28\n el0_svc+0x30/0xd0\n el0t_64_sync_handler+0xc8/0xcc\n el0t_64_sync+0x198/0x19c\n ---[ end trace 0000000000000000 ]---\n\n[mawupeng1@huawei.com: unmap_poisoned_folio(): remove shadowed local `mapping', per Miaohe]\n Link: https://lkml.kernel.org/r/20250219060653.3849083-1-mawupeng1@huawei.com", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21907" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/425c12c076e6fc6b2cb04b9f960319d31dcabc76" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/608cc7deb428f1122ed426060233622ebf667b6e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b81679b1633aa43c0d973adfa816d78c1ed0d032" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4hrq-jxxx-hj3h/GHSA-4hrq-jxxx-hj3h.json b/advisories/unreviewed/2025/04/GHSA-4hrq-jxxx-hj3h/GHSA-4hrq-jxxx-hj3h.json new file mode 100644 index 00000000000..685e5e02cc1 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4hrq-jxxx-hj3h/GHSA-4hrq-jxxx-hj3h.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4hrq-jxxx-hj3h", + "modified": "2025-04-01T18:30:54Z", + "published": "2025-04-01T18:30:54Z", + "aliases": [ + "CVE-2025-21979" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: cfg80211: cancel wiphy_work before freeing wiphy\n\nA wiphy_work can be queued from the moment the wiphy is allocated and\ninitialized (i.e. wiphy_new_nm). When a wiphy_work is queued, the\nrdev::wiphy_work is getting queued.\n\nIf wiphy_free is called before the rdev::wiphy_work had a chance to run,\nthe wiphy memory will be freed, and then when it eventally gets to run\nit'll use invalid memory.\n\nFix this by canceling the work before freeing the wiphy.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21979" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0272d4af7f92997541d8bbf4c51918b93ded6ee2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/72d520476a2fab6f3489e8388ab524985d6c4b90" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/75d262ad3c36d52852d764588fcd887f0fcd9138" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a5158d67bff06cb6fea31be39aeb319fd908ed8e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/dea22de162058216a90f2706f0d0b36f0ff309fd" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4m83-xp7j-q4j9/GHSA-4m83-xp7j-q4j9.json b/advisories/unreviewed/2025/04/GHSA-4m83-xp7j-q4j9/GHSA-4m83-xp7j-q4j9.json new file mode 100644 index 00000000000..c81edad3520 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4m83-xp7j-q4j9/GHSA-4m83-xp7j-q4j9.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4m83-xp7j-q4j9", + "modified": "2025-04-01T18:30:51Z", + "published": "2025-04-01T18:30:50Z", + "aliases": [ + "CVE-2025-21909" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: nl80211: reject cooked mode if it is set along with other flags\n\nIt is possible to set both MONITOR_FLAG_COOK_FRAMES and MONITOR_FLAG_ACTIVE\nflags simultaneously on the same monitor interface from the userspace. This\ncauses a sub-interface to be created with no IEEE80211_SDATA_IN_DRIVER bit\nset because the monitor interface is in the cooked state and it takes\nprecedence over all other states. When the interface is then being deleted\nthe kernel calls WARN_ONCE() from check_sdata_in_driver() because of missing\nthat bit.\n\nFix this by rejecting MONITOR_FLAG_COOK_FRAMES if it is set along with\nother flags.\n\nFound by Linux Verification Center (linuxtesting.org) with Syzkaller.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21909" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/236f41ca728f23210b31ed2d1d8a6df575a4b2d6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/351eb7ac53ff1cd94d893c0c4534ced2f36ae7d7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/49f27f29446a5bfe633dd2cc0cfebd48a1a5e77f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/521e55c2b0d6028861ac0a2d06aa57bb0e3ac486" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5ea856d93794c4afa5542defd8c61f2708dc245a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ac4860141300581d3e2f6c6dafa37220f7ea9f65" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cd1bdcb77fdc03c253137e55bae10551b3481461" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ebebbb0eded2ed9a1abfa31962f6fb699e6abce7" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4r9v-r5j3-85m7/GHSA-4r9v-r5j3-85m7.json b/advisories/unreviewed/2025/04/GHSA-4r9v-r5j3-85m7/GHSA-4r9v-r5j3-85m7.json new file mode 100644 index 00000000000..df21e0a2324 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4r9v-r5j3-85m7/GHSA-4r9v-r5j3-85m7.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4r9v-r5j3-85m7", + "modified": "2025-04-01T18:30:49Z", + "published": "2025-04-01T18:30:49Z", + "aliases": [ + "CVE-2025-21896" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfuse: revert back to __readahead_folio() for readahead\n\nIn commit 3eab9d7bc2f4 (\"fuse: convert readahead to use folios\"), the\nlogic was converted to using the new folio readahead code, which drops\nthe reference on the folio once it is locked, using an inferred\nreference on the folio. Previously we held a reference on the folio for\nthe entire duration of the readpages call.\n\nThis is fine, however for the case for splice pipe responses where we\nwill remove the old folio and splice in the new folio (see\nfuse_try_move_page()), we assume that there is a reference held on the\nfolio for ap->folios, which is no longer the case.\n\nTo fix this, revert back to __readahead_folio() which allows us to hold\nthe reference on the folio for the duration of readpages until either we\ndrop the reference ourselves in fuse_readpages_end() or the reference is\ndropped after it's replaced in the page cache in the splice case.\nThis will fix the UAF bug that was reported.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21896" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0c67c37e1710b2a8f61c8a02db95a51fe577e2c1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/60db11f1b7fba4a66b117ea998d965818784a98d" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4v94-f8pq-mj8v/GHSA-4v94-f8pq-mj8v.json b/advisories/unreviewed/2025/04/GHSA-4v94-f8pq-mj8v/GHSA-4v94-f8pq-mj8v.json new file mode 100644 index 00000000000..bf111ab2a1f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4v94-f8pq-mj8v/GHSA-4v94-f8pq-mj8v.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4v94-f8pq-mj8v", + "modified": "2025-04-01T18:30:51Z", + "published": "2025-04-01T18:30:51Z", + "aliases": [ + "CVE-2025-21915" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncdx: Fix possible UAF error in driver_override_show()\n\nFixed a possible UAF problem in driver_override_show() in drivers/cdx/cdx.c\n\nThis function driver_override_show() is part of DEVICE_ATTR_RW, which\nincludes both driver_override_show() and driver_override_store().\nThese functions can be executed concurrently in sysfs.\n\nThe driver_override_store() function uses driver_set_override() to\nupdate the driver_override value, and driver_set_override() internally\nlocks the device (device_lock(dev)). If driver_override_show() reads\ncdx_dev->driver_override without locking, it could potentially access\na freed pointer if driver_override_store() frees the string\nconcurrently. This could lead to printing a kernel address, which is a\nsecurity risk since DEVICE_ATTR can be read by all users.\n\nAdditionally, a similar pattern is used in drivers/amba/bus.c, as well\nas many other bus drivers, where device_lock() is taken in the show\nfunction, and it has been working without issues.\n\nThis potential bug was detected by our experimental static analysis\ntool, which analyzes locking APIs and paired functions to identify\ndata races and atomicity violations.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21915" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0439d541aa8d3444ad41c39e39eb71acb57acde3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8473135f89c0949436a22adb05b8cece2fb3da91" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/91d44c1afc61a2fec37a9c7a3485368309391e0b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d7b339bbc887bcfc1a5b620bfc70c6fbb8f733bf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5f2m-5gjf-8mqg/GHSA-5f2m-5gjf-8mqg.json b/advisories/unreviewed/2025/04/GHSA-5f2m-5gjf-8mqg/GHSA-5f2m-5gjf-8mqg.json new file mode 100644 index 00000000000..410595e97e6 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5f2m-5gjf-8mqg/GHSA-5f2m-5gjf-8mqg.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5f2m-5gjf-8mqg", + "modified": "2025-04-01T18:30:51Z", + "published": "2025-04-01T18:30:51Z", + "aliases": [ + "CVE-2025-21923" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: hid-steam: Fix use-after-free when detaching device\n\nWhen a hid-steam device is removed it must clean up the client_hdev used for\nintercepting hidraw access. This can lead to scheduling deferred work to\nreattach the input device. Though the cleanup cancels the deferred work, this\nwas done before the client_hdev itself is cleaned up, so it gets rescheduled.\nThis patch fixes the ordering to make sure the deferred work is properly\ncanceled.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21923" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/026714ec7546de741826324a6a1914c91024d06c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a899adf7063c6745aaff1ec869f3c7f6329ed0a1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e53fc232a65f7488ab75d03a5b95f06aaada7262" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ea3f18d2f02629653b7bfe42607737ccd1343e54" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5g8p-x9mm-c9vr/GHSA-5g8p-x9mm-c9vr.json b/advisories/unreviewed/2025/04/GHSA-5g8p-x9mm-c9vr/GHSA-5g8p-x9mm-c9vr.json new file mode 100644 index 00000000000..472a55136ea --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5g8p-x9mm-c9vr/GHSA-5g8p-x9mm-c9vr.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5g8p-x9mm-c9vr", + "modified": "2025-04-01T18:30:53Z", + "published": "2025-04-01T18:30:53Z", + "aliases": [ + "CVE-2025-21945" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix use-after-free in smb2_lock\n\nIf smb_lock->zero_len has value, ->llist of smb_lock is not delete and\nflock is old one. It will cause use-after-free on error handling\nroutine.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21945" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/410ce35a2ed6d0e114132bba29af49b69880c8c7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/636e021646cf9b52ddfea7c809b018e91f2188cb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/84d2d1641b71dec326e8736a749b7ee76a9599fc" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8573571060ca466cbef2c6f03306b2cc7b883506" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a0609097fd10d618aed4864038393dd75131289e" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5jw6-g45h-9h97/GHSA-5jw6-g45h-9h97.json b/advisories/unreviewed/2025/04/GHSA-5jw6-g45h-9h97/GHSA-5jw6-g45h-9h97.json new file mode 100644 index 00000000000..c09ac9119a2 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5jw6-g45h-9h97/GHSA-5jw6-g45h-9h97.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5jw6-g45h-9h97", + "modified": "2025-04-01T18:30:52Z", + "published": "2025-04-01T18:30:52Z", + "aliases": [ + "CVE-2025-21939" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe/hmm: Don't dereference struct page pointers without notifier lock\n\nThe pnfs that we obtain from hmm_range_fault() point to pages that\nwe don't have a reference on, and the guarantee that they are still\nin the cpu page-tables is that the notifier lock must be held and the\nnotifier seqno is still valid.\n\nSo while building the sg table and marking the pages accesses / dirty\nwe need to hold this lock with a validated seqno.\n\nHowever, the lock is reclaim tainted which makes\nsg_alloc_table_from_pages_segment() unusable, since it internally\nallocates memory.\n\nInstead build the sg-table manually. For the non-iommu case\nthis might lead to fewer coalesces, but if that's a problem it can\nbe fixed up later in the resource cursor code. For the iommu case,\nthe whole sg-table may still be coalesced to a single contigous\ndevice va region.\n\nThis avoids marking pages that we don't own dirty and accessed, and\nit also avoid dereferencing struct pages that we don't own.\n\nv2:\n- Use assert to check whether hmm pfns are valid (Matthew Auld)\n- Take into account that large pages may cross range boundaries\n (Matthew Auld)\n\nv3:\n- Don't unnecessarily check for a non-freed sg-table. (Matthew Auld)\n- Add a missing up_read() in an error path. (Matthew Auld)\n\n(cherry picked from commit ea3e66d280ce2576664a862693d1da8fd324c317)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21939" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0a98219bcc961edd3388960576e4353e123b4a51" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2a24c98f0e4cc994334598d4f3a851972064809d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f9326f529da7298a95643c3267f1c0fdb0db55eb" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5mxp-4f79-c8g9/GHSA-5mxp-4f79-c8g9.json b/advisories/unreviewed/2025/04/GHSA-5mxp-4f79-c8g9/GHSA-5mxp-4f79-c8g9.json new file mode 100644 index 00000000000..a4716f1ac5f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5mxp-4f79-c8g9/GHSA-5mxp-4f79-c8g9.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5mxp-4f79-c8g9", + "modified": "2025-04-01T18:30:53Z", + "published": "2025-04-01T18:30:53Z", + "aliases": [ + "CVE-2025-21954" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetmem: prevent TX of unreadable skbs\n\nCurrently on stable trees we have support for netmem/devmem RX but not\nTX. It is not safe to forward/redirect an RX unreadable netmem packet\ninto the device's TX path, as the device may call dma-mapping APIs on\ndma addrs that should not be passed to it.\n\nFix this by preventing the xmit of unreadable skbs.\n\nTested by configuring tc redirect:\n\nsudo tc qdisc add dev eth1 ingress\nsudo tc filter add dev eth1 ingress protocol ip prio 1 flower ip_proto \\\n\ttcp src_ip 192.168.1.12 action mirred egress redirect dev eth1\n\nBefore, I see unreadable skbs in the driver's TX path passed to dma\nmapping APIs.\n\nAfter, I don't see unreadable skbs in the driver's TX path passed to dma\nmapping APIs.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21954" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1c17c8ced25c5fbe424c7ad7ea11d33014a986b1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/454825019d2f0c59e5174ece9e713f45ad80beff" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f3600c867c99a2cc8038680ecf211089c50e7971" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5px9-qgxf-p79c/GHSA-5px9-qgxf-p79c.json b/advisories/unreviewed/2025/04/GHSA-5px9-qgxf-p79c/GHSA-5px9-qgxf-p79c.json new file mode 100644 index 00000000000..aae26f1b488 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5px9-qgxf-p79c/GHSA-5px9-qgxf-p79c.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5px9-qgxf-p79c", + "modified": "2025-04-01T18:30:50Z", + "published": "2025-04-01T18:30:50Z", + "aliases": [ + "CVE-2025-21900" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nNFSv4: Fix a deadlock when recovering state on a sillyrenamed file\n\nIf the file is sillyrenamed, and slated for delete on close, it is\npossible for a server reboot to triggeer an open reclaim, with can again\nrace with the application call to close(). When that happens, the call\nto put_nfs_open_context() can trigger a synchronous delegreturn call\nwhich deadlocks because it is not marked as privileged.\n\nInstead, ensure that the call to nfs4_inode_return_delegation_on_close()\ncatches the delegreturn, and schedules it asynchronously.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21900" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4fe4ae6c2e01d028856b73b6328b12b8945df871" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8f8df955f078e1a023ee55161935000a67651f38" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f41a60bc43e7abbc636fee78bed0d74c31e738b0" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5vpp-hj53-v2pr/GHSA-5vpp-hj53-v2pr.json b/advisories/unreviewed/2025/04/GHSA-5vpp-hj53-v2pr/GHSA-5vpp-hj53-v2pr.json new file mode 100644 index 00000000000..a1e98881c18 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5vpp-hj53-v2pr/GHSA-5vpp-hj53-v2pr.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5vpp-hj53-v2pr", + "modified": "2025-04-01T18:30:52Z", + "published": "2025-04-01T18:30:52Z", + "aliases": [ + "CVE-2025-21936" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: Add check for mgmt_alloc_skb() in mgmt_device_connected()\n\nAdd check for the return value of mgmt_alloc_skb() in\nmgmt_device_connected() to prevent null pointer dereference.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21936" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7841180342c9a0fd97d54f3e62c7369309b5cd84" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7d39387886ffe220323cbed5c155233c3276926b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bdb1805c248e9694dbb3ffa8867cef2e52cf7261" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d8df010f72b8a32aaea393e36121738bb53ed905" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/dc516e66fb28c61b248b393e2ddd63bd7f104969" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-64vr-rmgj-v53q/GHSA-64vr-rmgj-v53q.json b/advisories/unreviewed/2025/04/GHSA-64vr-rmgj-v53q/GHSA-64vr-rmgj-v53q.json new file mode 100644 index 00000000000..c4cbfc4c191 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-64vr-rmgj-v53q/GHSA-64vr-rmgj-v53q.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-64vr-rmgj-v53q", + "modified": "2025-04-01T18:30:52Z", + "published": "2025-04-01T18:30:52Z", + "aliases": [ + "CVE-2025-21938" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: fix 'scheduling while atomic' in mptcp_pm_nl_append_new_local_addr\n\nIf multiple connection requests attempt to create an implicit mptcp\nendpoint in parallel, more than one caller may end up in\nmptcp_pm_nl_append_new_local_addr because none found the address in\nlocal_addr_list during their call to mptcp_pm_nl_get_local_id. In this\ncase, the concurrent new_local_addr calls may delete the address entry\ncreated by the previous caller. These deletes use synchronize_rcu, but\nthis is not permitted in some of the contexts where this function may be\ncalled. During packet recv, the caller may be in a rcu read critical\nsection and have preemption disabled.\n\nAn example stack:\n\n BUG: scheduling while atomic: swapper/2/0/0x00000302\n\n Call Trace:\n \n dump_stack_lvl (lib/dump_stack.c:117 (discriminator 1))\n dump_stack (lib/dump_stack.c:124)\n __schedule_bug (kernel/sched/core.c:5943)\n schedule_debug.constprop.0 (arch/x86/include/asm/preempt.h:33 kernel/sched/core.c:5970)\n __schedule (arch/x86/include/asm/jump_label.h:27 include/linux/jump_label.h:207 kernel/sched/features.h:29 kernel/sched/core.c:6621)\n schedule (arch/x86/include/asm/preempt.h:84 kernel/sched/core.c:6804 kernel/sched/core.c:6818)\n schedule_timeout (kernel/time/timer.c:2160)\n wait_for_completion (kernel/sched/completion.c:96 kernel/sched/completion.c:116 kernel/sched/completion.c:127 kernel/sched/completion.c:148)\n __wait_rcu_gp (include/linux/rcupdate.h:311 kernel/rcu/update.c:444)\n synchronize_rcu (kernel/rcu/tree.c:3609)\n mptcp_pm_nl_append_new_local_addr (net/mptcp/pm_netlink.c:966 net/mptcp/pm_netlink.c:1061)\n mptcp_pm_nl_get_local_id (net/mptcp/pm_netlink.c:1164)\n mptcp_pm_get_local_id (net/mptcp/pm.c:420)\n subflow_check_req (net/mptcp/subflow.c:98 net/mptcp/subflow.c:213)\n subflow_v4_route_req (net/mptcp/subflow.c:305)\n tcp_conn_request (net/ipv4/tcp_input.c:7216)\n subflow_v4_conn_request (net/mptcp/subflow.c:651)\n tcp_rcv_state_process (net/ipv4/tcp_input.c:6709)\n tcp_v4_do_rcv (net/ipv4/tcp_ipv4.c:1934)\n tcp_v4_rcv (net/ipv4/tcp_ipv4.c:2334)\n ip_protocol_deliver_rcu (net/ipv4/ip_input.c:205 (discriminator 1))\n ip_local_deliver_finish (include/linux/rcupdate.h:813 net/ipv4/ip_input.c:234)\n ip_local_deliver (include/linux/netfilter.h:314 include/linux/netfilter.h:308 net/ipv4/ip_input.c:254)\n ip_sublist_rcv_finish (include/net/dst.h:461 net/ipv4/ip_input.c:580)\n ip_sublist_rcv (net/ipv4/ip_input.c:640)\n ip_list_rcv (net/ipv4/ip_input.c:675)\n __netif_receive_skb_list_core (net/core/dev.c:5583 net/core/dev.c:5631)\n netif_receive_skb_list_internal (net/core/dev.c:5685 net/core/dev.c:5774)\n napi_complete_done (include/linux/list.h:37 include/net/gro.h:449 include/net/gro.h:444 net/core/dev.c:6114)\n igb_poll (drivers/net/ethernet/intel/igb/igb_main.c:8244) igb\n __napi_poll (net/core/dev.c:6582)\n net_rx_action (net/core/dev.c:6653 net/core/dev.c:6787)\n handle_softirqs (kernel/softirq.c:553)\n __irq_exit_rcu (kernel/softirq.c:588 kernel/softirq.c:427 kernel/softirq.c:636)\n irq_exit_rcu (kernel/softirq.c:651)\n common_interrupt (arch/x86/kernel/irq.c:247 (discriminator 14))\n \n\nThis problem seems particularly prevalent if the user advertises an\nendpoint that has a different external vs internal address. In the case\nwhere the external address is advertised and multiple connections\nalready exist, multiple subflow SYNs arrive in parallel which tends to\ntrigger the race during creation of the first local_addr_list entries\nwhich have the internal address instead.\n\nFix by skipping the replacement of an existing implicit local address if\ncalled via mptcp_pm_nl_get_local_id.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21938" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/022bfe24aad8937705704ff2e414b100cf0f2e1a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/125ccafe6dd062901b5a0c31ee9038740fc8859e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4b228dae3d2cc6d9dce167449cd8fa9f028e9376" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f1404f368c40fc6a068dad72e4ee0824ee6a78ee" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f3fcdb2de9fdbed9d8c6a8eb2c5fbd7d6f54a4d8" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-66cx-2vhc-36f5/GHSA-66cx-2vhc-36f5.json b/advisories/unreviewed/2025/04/GHSA-66cx-2vhc-36f5/GHSA-66cx-2vhc-36f5.json new file mode 100644 index 00000000000..6c1cf288662 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-66cx-2vhc-36f5/GHSA-66cx-2vhc-36f5.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-66cx-2vhc-36f5", + "modified": "2025-04-01T18:30:52Z", + "published": "2025-04-01T18:30:52Z", + "aliases": [ + "CVE-2025-21937" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: Add check for mgmt_alloc_skb() in mgmt_remote_name()\n\nAdd check for the return value of mgmt_alloc_skb() in\nmgmt_remote_name() to prevent null pointer dereference.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21937" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/37785a01040cb5d11ed0ddbcbf78491fcd073161" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/69fb168b88e4d62cb31cdd725b67ccc5216cfcaf" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/88310caff68ae69d0574859f7926a59c1da2d60b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c5845c73cbacf5704169283ef29ca02031a36564" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f2176a07e7b19f73e05c805cf3d130a2999154cb" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6f6m-g7v2-775j/GHSA-6f6m-g7v2-775j.json b/advisories/unreviewed/2025/04/GHSA-6f6m-g7v2-775j/GHSA-6f6m-g7v2-775j.json new file mode 100644 index 00000000000..fe07c2f87a6 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6f6m-g7v2-775j/GHSA-6f6m-g7v2-775j.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6f6m-g7v2-775j", + "modified": "2025-04-01T18:30:54Z", + "published": "2025-04-01T18:30:54Z", + "aliases": [ + "CVE-2025-21982" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\npinctrl: nuvoton: npcm8xx: Add NULL check in npcm8xx_gpio_fw\n\ndevm_kasprintf() calls can return null pointers on failure.\nBut the return values were not checked in npcm8xx_gpio_fw().\nAdd NULL check in npcm8xx_gpio_fw(), to handle kernel NULL\npointer dereference error.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21982" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6a08a86e5aff8e65368ccd463348fdda26100821" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a585f6ea42ec259a9a57e3e2580fa527c92187d0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/acf40ab42799e4ae1397ee6f5c5941092d66f999" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6g9c-7jcv-4g45/GHSA-6g9c-7jcv-4g45.json b/advisories/unreviewed/2025/04/GHSA-6g9c-7jcv-4g45/GHSA-6g9c-7jcv-4g45.json new file mode 100644 index 00000000000..dcfe99df7c0 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6g9c-7jcv-4g45/GHSA-6g9c-7jcv-4g45.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6g9c-7jcv-4g45", + "modified": "2025-04-01T18:30:51Z", + "published": "2025-04-01T18:30:51Z", + "aliases": [ + "CVE-2025-21922" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nppp: Fix KMSAN uninit-value warning with bpf\n\nSyzbot caught an \"KMSAN: uninit-value\" warning [1], which is caused by the\nppp driver not initializing a 2-byte header when using socket filter.\n\nThe following code can generate a PPP filter BPF program:\n'''\nstruct bpf_program fp;\npcap_t *handle;\nhandle = pcap_open_dead(DLT_PPP_PPPD, 65535);\npcap_compile(handle, &fp, \"ip and outbound\", 0, 0);\nbpf_dump(&fp, 1);\n'''\nIts output is:\n'''\n(000) ldh [2]\n(001) jeq #0x21 jt 2 jf 5\n(002) ldb [0]\n(003) jeq #0x1 jt 4 jf 5\n(004) ret #65535\n(005) ret #0\n'''\nWen can find similar code at the following link:\nhttps://github.com/ppp-project/ppp/blob/master/pppd/options.c#L1680\nThe maintainer of this code repository is also the original maintainer\nof the ppp driver.\n\nAs you can see the BPF program skips 2 bytes of data and then reads the\n'Protocol' field to determine if it's an IP packet. Then it read the first\nbyte of the first 2 bytes to determine the direction.\n\nThe issue is that only the first byte indicating direction is initialized\nin current ppp driver code while the second byte is not initialized.\n\nFor normal BPF programs generated by libpcap, uninitialized data won't be\nused, so it's not a problem. However, for carefully crafted BPF programs,\nsuch as those generated by syzkaller [2], which start reading from offset\n0, the uninitialized data will be used and caught by KMSAN.\n\n[1] https://syzkaller.appspot.com/bug?extid=853242d9c9917165d791\n[2] https://syzkaller.appspot.com/text?tag=ReproC&x=11994913980000", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21922" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1eacd47636a9de5bee25d9d5962dc538a82d9f0b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2f591cb158807bdcf424f66f1fbfa6e4e50f3757" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3de809a768464528762757e433cd50de35bcb3c1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4c2d14c40a68678d885eab4008a0129646805bae" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4e2191b0fd0c064d37b0db67396216f2d4787e0f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8aa8a40c766b3945b40565a70349d5581458ff63" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c036f5f2680cbdabdbbace86baee3c83721634d6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d685096c8129c9a92689975193e268945fd21dbf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6hmr-pwgj-w283/GHSA-6hmr-pwgj-w283.json b/advisories/unreviewed/2025/04/GHSA-6hmr-pwgj-w283/GHSA-6hmr-pwgj-w283.json new file mode 100644 index 00000000000..559edfac44a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6hmr-pwgj-w283/GHSA-6hmr-pwgj-w283.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6hmr-pwgj-w283", + "modified": "2025-04-01T18:30:55Z", + "published": "2025-04-01T18:30:55Z", + "aliases": [ + "CVE-2025-21985" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Fix out-of-bound accesses\n\n[WHAT & HOW]\nhpo_stream_to_link_encoder_mapping has size MAX_HPO_DP2_ENCODERS(=4),\nbut location can have size up to 6. As a result, it is necessary to\ncheck location against MAX_HPO_DP2_ENCODERS.\n\nSimiliarly, disp_cfg_stream_location can be used as an array index which\nshould be 0..5, so the ASSERT's conditions should be less without equal.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21985" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/36793d90d76f667d26c6dd025571481ee0c96abc" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8adbb2a98b00926315fd513b5fe2596b5716b82d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9aedc776b11038f04f4641241bb7e877781e4aa4" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6m8x-cvmh-fpwm/GHSA-6m8x-cvmh-fpwm.json b/advisories/unreviewed/2025/04/GHSA-6m8x-cvmh-fpwm/GHSA-6m8x-cvmh-fpwm.json new file mode 100644 index 00000000000..7e8f8d6dabe --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6m8x-cvmh-fpwm/GHSA-6m8x-cvmh-fpwm.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6m8x-cvmh-fpwm", + "modified": "2025-04-01T18:30:50Z", + "published": "2025-04-01T18:30:50Z", + "aliases": [ + "CVE-2025-21908" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nNFS: fix nfs_release_folio() to not deadlock via kcompactd writeback\n\nAdd PF_KCOMPACTD flag and current_is_kcompactd() helper to check for it so\nnfs_release_folio() can skip calling nfs_wb_folio() from kcompactd.\n\nOtherwise NFS can deadlock waiting for kcompactd enduced writeback which\nrecurses back to NFS (which triggers writeback to NFSD via NFS loopback\nmount on the same host, NFSD blocks waiting for XFS's call to\n__filemap_get_folio):\n\n6070.550357] INFO: task kcompactd0:58 blocked for more than 4435 seconds.\n\n{---\n[58] \"kcompactd0\"\n[<0>] folio_wait_bit+0xe8/0x200\n[<0>] folio_wait_writeback+0x2b/0x80\n[<0>] nfs_wb_folio+0x80/0x1b0 [nfs]\n[<0>] nfs_release_folio+0x68/0x130 [nfs]\n[<0>] split_huge_page_to_list_to_order+0x362/0x840\n[<0>] migrate_pages_batch+0x43d/0xb90\n[<0>] migrate_pages_sync+0x9a/0x240\n[<0>] migrate_pages+0x93c/0x9f0\n[<0>] compact_zone+0x8e2/0x1030\n[<0>] compact_node+0xdb/0x120\n[<0>] kcompactd+0x121/0x2e0\n[<0>] kthread+0xcf/0x100\n[<0>] ret_from_fork+0x31/0x40\n[<0>] ret_from_fork_asm+0x1a/0x30\n---}\n\n[akpm@linux-foundation.org: fix build]", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21908" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5ae31c54cff745832b9bd5b32e71f3d1b607cd1e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8253ff29edcb429a9a6c75710941c6a16a9a34b1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ab0727d6e2196682351c25c1dd112136f6991f11" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ce6d9c1c2b5cc785016faa11b48b6cd317eb367e" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6p7v-mm3j-hhhh/GHSA-6p7v-mm3j-hhhh.json b/advisories/unreviewed/2025/04/GHSA-6p7v-mm3j-hhhh/GHSA-6p7v-mm3j-hhhh.json index e0b0ceea186..def591eac16 100644 --- a/advisories/unreviewed/2025/04/GHSA-6p7v-mm3j-hhhh/GHSA-6p7v-mm3j-hhhh.json +++ b/advisories/unreviewed/2025/04/GHSA-6p7v-mm3j-hhhh/GHSA-6p7v-mm3j-hhhh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6p7v-mm3j-hhhh", - "modified": "2025-04-01T00:30:40Z", + "modified": "2025-04-01T18:30:47Z", "published": "2025-04-01T00:30:40Z", "aliases": [ "CVE-2025-24254" ], "details": "This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A user may be able to elevate privileges.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:22Z" diff --git a/advisories/unreviewed/2025/04/GHSA-6w5j-j56x-jmm3/GHSA-6w5j-j56x-jmm3.json b/advisories/unreviewed/2025/04/GHSA-6w5j-j56x-jmm3/GHSA-6w5j-j56x-jmm3.json index d17c1266d01..3db1f531490 100644 --- a/advisories/unreviewed/2025/04/GHSA-6w5j-j56x-jmm3/GHSA-6w5j-j56x-jmm3.json +++ b/advisories/unreviewed/2025/04/GHSA-6w5j-j56x-jmm3/GHSA-6w5j-j56x-jmm3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6w5j-j56x-jmm3", - "modified": "2025-04-01T00:30:45Z", + "modified": "2025-04-01T18:30:48Z", "published": "2025-04-01T00:30:45Z", "aliases": [ "CVE-2025-3062" ], "details": "Vulnerability in Drupal Drupal Admin LTE theme.This issue affects Drupal Admin LTE theme: *.*.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-287" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:30Z" diff --git a/advisories/unreviewed/2025/04/GHSA-6xj5-r9h7-wphq/GHSA-6xj5-r9h7-wphq.json b/advisories/unreviewed/2025/04/GHSA-6xj5-r9h7-wphq/GHSA-6xj5-r9h7-wphq.json new file mode 100644 index 00000000000..df95a37a047 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6xj5-r9h7-wphq/GHSA-6xj5-r9h7-wphq.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6xj5-r9h7-wphq", + "modified": "2025-04-01T18:30:53Z", + "published": "2025-04-01T18:30:53Z", + "aliases": [ + "CVE-2025-21957" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: qla1280: Fix kernel oops when debug level > 2\n\nA null dereference or oops exception will eventually occur when qla1280.c\ndriver is compiled with DEBUG_QLA1280 enabled and ql_debug_level > 2. I\nthink its clear from the code that the intention here is sg_dma_len(s) not\nlength of sg_next(s) when printing the debug info.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21957" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/24602e2664c515a4f2950d7b52c3d5997463418c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5233e3235dec3065ccc632729675575dbe3c6b8a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7ac2473e727d67a38266b2b7e55c752402ab588c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/af71ba921d08c241a817010f96458dc5e5e26762" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ea371d1cdefb0951c7127a33bcd7eb931cf44571" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7c5j-6262-p78w/GHSA-7c5j-6262-p78w.json b/advisories/unreviewed/2025/04/GHSA-7c5j-6262-p78w/GHSA-7c5j-6262-p78w.json new file mode 100644 index 00000000000..340864f044e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7c5j-6262-p78w/GHSA-7c5j-6262-p78w.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7c5j-6262-p78w", + "modified": "2025-04-01T18:30:53Z", + "published": "2025-04-01T18:30:53Z", + "aliases": [ + "CVE-2025-21947" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix type confusion via race condition when using ipc_msg_send_request\n\nreq->handle is allocated using ksmbd_acquire_id(&ipc_ida), based on\nida_alloc. req->handle from ksmbd_ipc_login_request and\nFSCTL_PIPE_TRANSCEIVE ioctl can be same and it could lead to type confusion\nbetween messages, resulting in access to unexpected parts of memory after\nan incorrect delivery. ksmbd check type of ipc response but missing add\ncontinue to check next ipc reponse.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21947" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1e8833c03a38e1d5d5df6484e3f670a2fd38fb76" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3cb2b2e41541fe6f9cc55ca22d4c0bd260498aea" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6321bbda4244b93802d61cfe0887883aae322f4b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/76861630b29e51373e73e7b00ad0d467b6941162" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e2ff19f0b7a30e03516e6eb73b948e27a55bc9d2" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7fc4-8q5h-8mjj/GHSA-7fc4-8q5h-8mjj.json b/advisories/unreviewed/2025/04/GHSA-7fc4-8q5h-8mjj/GHSA-7fc4-8q5h-8mjj.json new file mode 100644 index 00000000000..35d6b446e3b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7fc4-8q5h-8mjj/GHSA-7fc4-8q5h-8mjj.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7fc4-8q5h-8mjj", + "modified": "2025-04-01T18:30:50Z", + "published": "2025-04-01T18:30:50Z", + "aliases": [ + "CVE-2025-21905" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: iwlwifi: limit printed string from FW file\n\nThere's no guarantee here that the file is always with a\nNUL-termination, so reading the string may read beyond the\nend of the TLV. If that's the last TLV in the file, it can\nperhaps even read beyond the end of the file buffer.\n\nFix that by limiting the print format to the size of the\nbuffer we have.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21905" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/38f0d398b6d7640d223db69df022c4a232f24774" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/47616b82f2d42ea2060334746fed9a2988d845c9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/59cdda202829d1d6a095d233386870a59aff986f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/88ed69f924638c7503644e1f8eed1e976f3ffa7a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b02f8d5a71c8571ccf77f285737c566db73ef5e5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c0e626f2b2390472afac52dfe72b29daf9ed8e1d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e0dc2c1bef722cbf16ae557690861e5f91208129" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f265e6031d0bc4fc40c4619cb42466722b46eaa9" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7jcj-vjq7-xp8h/GHSA-7jcj-vjq7-xp8h.json b/advisories/unreviewed/2025/04/GHSA-7jcj-vjq7-xp8h/GHSA-7jcj-vjq7-xp8h.json new file mode 100644 index 00000000000..25129b975ce --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7jcj-vjq7-xp8h/GHSA-7jcj-vjq7-xp8h.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7jcj-vjq7-xp8h", + "modified": "2025-04-01T18:30:55Z", + "published": "2025-04-01T18:30:54Z", + "aliases": [ + "CVE-2025-21981" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nice: fix memory leak in aRFS after reset\n\nFix aRFS (accelerated Receive Flow Steering) structures memory leak by\nadding a checker to verify if aRFS memory is already allocated while\nconfiguring VSI. aRFS objects are allocated in two cases:\n- as part of VSI initialization (at probe), and\n- as part of reset handling\n\nHowever, VSI reconfiguration executed during reset involves memory\nallocation one more time, without prior releasing already allocated\nresources. This led to the memory leak with the following signature:\n\n[root@os-delivery ~]# cat /sys/kernel/debug/kmemleak\nunreferenced object 0xff3c1ca7252e6000 (size 8192):\n comm \"kworker/0:0\", pid 8, jiffies 4296833052\n hex dump (first 32 bytes):\n 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n backtrace (crc 0):\n [] __kmalloc_cache_noprof+0x275/0x340\n [] ice_init_arfs+0x3a/0xe0 [ice]\n [] ice_vsi_cfg_def+0x607/0x850 [ice]\n [] ice_vsi_setup+0x5b/0x130 [ice]\n [] ice_init+0x1c1/0x460 [ice]\n [] ice_probe+0x2af/0x520 [ice]\n [] local_pci_probe+0x43/0xa0\n [] work_for_cpu_fn+0x13/0x20\n [] process_one_work+0x179/0x390\n [] worker_thread+0x239/0x340\n [] kthread+0xcc/0x100\n [] ret_from_fork+0x2d/0x50\n [] ret_from_fork_asm+0x1a/0x30\n ...", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21981" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/23d97f18901ef5e4e264e3b1777fe65c760186b5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3b27e6e10a32589fcd293b8933ab6de9387a460e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5d30d256661fc11b6e73fac6c3783a702e1006a3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/78f3d64b30210c0e521c59357431aca14024cb79" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fcbacc47d16306c87ad1b820b7a575f6e9eae58b" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7qmx-chg2-w65c/GHSA-7qmx-chg2-w65c.json b/advisories/unreviewed/2025/04/GHSA-7qmx-chg2-w65c/GHSA-7qmx-chg2-w65c.json new file mode 100644 index 00000000000..08d9d957c94 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7qmx-chg2-w65c/GHSA-7qmx-chg2-w65c.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7qmx-chg2-w65c", + "modified": "2025-04-01T18:30:53Z", + "published": "2025-04-01T18:30:53Z", + "aliases": [ + "CVE-2025-21946" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix out-of-bounds in parse_sec_desc()\n\nIf osidoffset, gsidoffset and dacloffset could be greater than smb_ntsd\nstruct size. If it is smaller, It could cause slab-out-of-bounds.\nAnd when validating sid, It need to check it included subauth array size.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21946" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/159d059cbcb0e6d0e7a7b34af3862ba09a6b22d1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6a9831180d0b23b5c97e2bd841aefc8f82900172" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c1569dbbe2d43041be9f3fef7ca08bec3b66ad1b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d6e13e19063db24f94b690159d0633aaf72a0f03" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7wv2-745f-m4cr/GHSA-7wv2-745f-m4cr.json b/advisories/unreviewed/2025/04/GHSA-7wv2-745f-m4cr/GHSA-7wv2-745f-m4cr.json new file mode 100644 index 00000000000..b819ec439cf --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7wv2-745f-m4cr/GHSA-7wv2-745f-m4cr.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7wv2-745f-m4cr", + "modified": "2025-04-01T18:30:54Z", + "published": "2025-04-01T18:30:54Z", + "aliases": [ + "CVE-2025-21975" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: handle errors in mlx5_chains_create_table()\n\nIn mlx5_chains_create_table(), the return value of mlx5_get_fdb_sub_ns()\nand mlx5_get_flow_namespace() must be checked to prevent NULL pointer\ndereferences. If either function fails, the function should log error\nmessage with mlx5_core_warn() and return error pointer.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21975" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/093b4aaec97ec048623e3fe1e516fc45a954d412" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1598307c914ba3d2642a2b03d1ff11efbdb7c6c2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1d34296409a519b4027750e3e82d9e19553a7398" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/637105ef0d46fe5beac15aceb431da3ec832bb00" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/eab0396353be1c778eba1c0b5180176f04dd21ce" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7xff-8wqr-949p/GHSA-7xff-8wqr-949p.json b/advisories/unreviewed/2025/04/GHSA-7xff-8wqr-949p/GHSA-7xff-8wqr-949p.json index 8e160bff1f9..42d7896a8a8 100644 --- a/advisories/unreviewed/2025/04/GHSA-7xff-8wqr-949p/GHSA-7xff-8wqr-949p.json +++ b/advisories/unreviewed/2025/04/GHSA-7xff-8wqr-949p/GHSA-7xff-8wqr-949p.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7xff-8wqr-949p", - "modified": "2025-04-01T00:30:40Z", + "modified": "2025-04-01T18:30:47Z", "published": "2025-04-01T00:30:40Z", "aliases": [ "CVE-2025-24255" ], "details": "A file access issue was addressed with improved input validation. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to break out of its sandbox.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:22Z" diff --git a/advisories/unreviewed/2025/04/GHSA-8ff6-v3j2-x264/GHSA-8ff6-v3j2-x264.json b/advisories/unreviewed/2025/04/GHSA-8ff6-v3j2-x264/GHSA-8ff6-v3j2-x264.json new file mode 100644 index 00000000000..c0ed5b1f8c0 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8ff6-v3j2-x264/GHSA-8ff6-v3j2-x264.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8ff6-v3j2-x264", + "modified": "2025-04-01T18:30:55Z", + "published": "2025-04-01T18:30:55Z", + "aliases": [ + "CVE-2025-29208" + ], + "details": "CodeZips Gym Management System v1.0 is vulnerable to SQL injection in the name parameter within /dashboard/admin/deleteroutine.php.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29208" + }, + { + "type": "WEB", + "url": "https://github.com/LLz-7/CVE/blob/main/CVE_1.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T18:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8j66-r7fp-95mx/GHSA-8j66-r7fp-95mx.json b/advisories/unreviewed/2025/04/GHSA-8j66-r7fp-95mx/GHSA-8j66-r7fp-95mx.json new file mode 100644 index 00000000000..a105873708f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8j66-r7fp-95mx/GHSA-8j66-r7fp-95mx.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8j66-r7fp-95mx", + "modified": "2025-04-01T18:30:51Z", + "published": "2025-04-01T18:30:51Z", + "aliases": [ + "CVE-2025-21924" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: hns3: make sure ptp clock is unregister and freed if hclge_ptp_get_cycle returns an error\n\nDuring the initialization of ptp, hclge_ptp_get_cycle might return an error\nand returned directly without unregister clock and free it. To avoid that,\ncall hclge_ptp_destroy_clock to unregist and free clock if\nhclge_ptp_get_cycle failed.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21924" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/21dba813d9821687a7f9aff576798ba21a859a32" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2c04e507f3a5c5dc6e2b9ab37d8cdedee1ef1a37" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/33244e98aa9503585e585335fe2ceb4492630949" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9cfc43c0e6e6a31122b4008d763a2960c206aa2d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b7365eab39831487a84e63a9638209b68dc54008" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b7d8d4529984e2d4a72a6d552fb886233e8e83cb" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8r77-rxc7-qgvv/GHSA-8r77-rxc7-qgvv.json b/advisories/unreviewed/2025/04/GHSA-8r77-rxc7-qgvv/GHSA-8r77-rxc7-qgvv.json index 405bffb139c..8c8b7fba517 100644 --- a/advisories/unreviewed/2025/04/GHSA-8r77-rxc7-qgvv/GHSA-8r77-rxc7-qgvv.json +++ b/advisories/unreviewed/2025/04/GHSA-8r77-rxc7-qgvv/GHSA-8r77-rxc7-qgvv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8r77-rxc7-qgvv", - "modified": "2025-04-01T15:31:36Z", + "modified": "2025-04-01T18:30:48Z", "published": "2025-04-01T15:31:36Z", "aliases": [ "CVE-2025-3030" ], "details": "Memory safety bugs present in Firefox 136, Thunderbird 136, Firefox ESR 128.8, and Thunderbird 128.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 137, Firefox ESR < 128.9, Thunderbird < 137, and Thunderbird ESR < 128.9.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-01T13:15:41Z" diff --git a/advisories/unreviewed/2025/04/GHSA-972j-fxc9-8wqp/GHSA-972j-fxc9-8wqp.json b/advisories/unreviewed/2025/04/GHSA-972j-fxc9-8wqp/GHSA-972j-fxc9-8wqp.json index ea7a09526db..635c8628851 100644 --- a/advisories/unreviewed/2025/04/GHSA-972j-fxc9-8wqp/GHSA-972j-fxc9-8wqp.json +++ b/advisories/unreviewed/2025/04/GHSA-972j-fxc9-8wqp/GHSA-972j-fxc9-8wqp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-972j-fxc9-8wqp", - "modified": "2025-04-01T00:30:37Z", + "modified": "2025-04-01T18:30:46Z", "published": "2025-04-01T00:30:36Z", "aliases": [ "CVE-2025-24193" ], "details": "This issue was addressed with improved authentication. This issue is fixed in iOS 18.4 and iPadOS 18.4. An attacker with a USB-C connection to an unlocked device may be able to programmatically access photos.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:17Z" diff --git a/advisories/unreviewed/2025/04/GHSA-9gr8-3pvc-4w93/GHSA-9gr8-3pvc-4w93.json b/advisories/unreviewed/2025/04/GHSA-9gr8-3pvc-4w93/GHSA-9gr8-3pvc-4w93.json new file mode 100644 index 00000000000..bd530b489d5 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9gr8-3pvc-4w93/GHSA-9gr8-3pvc-4w93.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9gr8-3pvc-4w93", + "modified": "2025-04-01T18:30:53Z", + "published": "2025-04-01T18:30:53Z", + "aliases": [ + "CVE-2025-21965" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsched_ext: Validate prev_cpu in scx_bpf_select_cpu_dfl()\n\nIf a BPF scheduler provides an invalid CPU (outside the nr_cpu_ids\nrange) as prev_cpu to scx_bpf_select_cpu_dfl() it can cause a kernel\ncrash.\n\nTo prevent this, validate prev_cpu in scx_bpf_select_cpu_dfl() and\ntrigger an scx error if an invalid CPU is specified.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21965" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/515680e76c536dd4aa8e2b5d674b0d441baddf5b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/752b56bb76e2471197d25d6948d85753043b10da" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9360dfe4cbd62ff1eb8217b815964931523b75b3" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9r28-p42w-83mg/GHSA-9r28-p42w-83mg.json b/advisories/unreviewed/2025/04/GHSA-9r28-p42w-83mg/GHSA-9r28-p42w-83mg.json index 74053136fde..702b4677502 100644 --- a/advisories/unreviewed/2025/04/GHSA-9r28-p42w-83mg/GHSA-9r28-p42w-83mg.json +++ b/advisories/unreviewed/2025/04/GHSA-9r28-p42w-83mg/GHSA-9r28-p42w-83mg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9r28-p42w-83mg", - "modified": "2025-04-01T00:30:37Z", + "modified": "2025-04-01T18:30:46Z", "published": "2025-04-01T00:30:37Z", "aliases": [ "CVE-2025-24202" ], "details": "A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. An app may be able to access sensitive user data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:18Z" diff --git a/advisories/unreviewed/2025/04/GHSA-9v7h-vc98-97mp/GHSA-9v7h-vc98-97mp.json b/advisories/unreviewed/2025/04/GHSA-9v7h-vc98-97mp/GHSA-9v7h-vc98-97mp.json new file mode 100644 index 00000000000..193b69b3a54 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9v7h-vc98-97mp/GHSA-9v7h-vc98-97mp.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9v7h-vc98-97mp", + "modified": "2025-04-01T18:30:54Z", + "published": "2025-04-01T18:30:54Z", + "aliases": [ + "CVE-2025-21969" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: Fix slab-use-after-free Read in l2cap_send_cmd\n\nAfter the hci sync command releases l2cap_conn, the hci receive data work\nqueue references the released l2cap_conn when sending to the upper layer.\nAdd hci dev lock to the hci receive data work queue to synchronize the two.\n\n[1]\nBUG: KASAN: slab-use-after-free in l2cap_send_cmd+0x187/0x8d0 net/bluetooth/l2cap_core.c:954\nRead of size 8 at addr ffff8880271a4000 by task kworker/u9:2/5837\n\nCPU: 0 UID: 0 PID: 5837 Comm: kworker/u9:2 Not tainted 6.13.0-rc5-syzkaller-00163-gab75170520d4 #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024\nWorkqueue: hci1 hci_rx_work\nCall Trace:\n \n __dump_stack lib/dump_stack.c:94 [inline]\n dump_stack_lvl+0x241/0x360 lib/dump_stack.c:120\n print_address_description mm/kasan/report.c:378 [inline]\n print_report+0x169/0x550 mm/kasan/report.c:489\n kasan_report+0x143/0x180 mm/kasan/report.c:602\n l2cap_build_cmd net/bluetooth/l2cap_core.c:2964 [inline]\n l2cap_send_cmd+0x187/0x8d0 net/bluetooth/l2cap_core.c:954\n l2cap_sig_send_rej net/bluetooth/l2cap_core.c:5502 [inline]\n l2cap_sig_channel net/bluetooth/l2cap_core.c:5538 [inline]\n l2cap_recv_frame+0x221f/0x10db0 net/bluetooth/l2cap_core.c:6817\n hci_acldata_packet net/bluetooth/hci_core.c:3797 [inline]\n hci_rx_work+0x508/0xdb0 net/bluetooth/hci_core.c:4040\n process_one_work kernel/workqueue.c:3229 [inline]\n process_scheduled_works+0xa66/0x1840 kernel/workqueue.c:3310\n worker_thread+0x870/0xd30 kernel/workqueue.c:3391\n kthread+0x2f0/0x390 kernel/kthread.c:389\n ret_from_fork+0x4b/0x80 arch/x86/kernel/process.c:147\n ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:244\n \n\nAllocated by task 5837:\n kasan_save_stack mm/kasan/common.c:47 [inline]\n kasan_save_track+0x3f/0x80 mm/kasan/common.c:68\n poison_kmalloc_redzone mm/kasan/common.c:377 [inline]\n __kasan_kmalloc+0x98/0xb0 mm/kasan/common.c:394\n kasan_kmalloc include/linux/kasan.h:260 [inline]\n __kmalloc_cache_noprof+0x243/0x390 mm/slub.c:4329\n kmalloc_noprof include/linux/slab.h:901 [inline]\n kzalloc_noprof include/linux/slab.h:1037 [inline]\n l2cap_conn_add+0xa9/0x8e0 net/bluetooth/l2cap_core.c:6860\n l2cap_connect_cfm+0x115/0x1090 net/bluetooth/l2cap_core.c:7239\n hci_connect_cfm include/net/bluetooth/hci_core.h:2057 [inline]\n hci_remote_features_evt+0x68e/0xac0 net/bluetooth/hci_event.c:3726\n hci_event_func net/bluetooth/hci_event.c:7473 [inline]\n hci_event_packet+0xac2/0x1540 net/bluetooth/hci_event.c:7525\n hci_rx_work+0x3f3/0xdb0 net/bluetooth/hci_core.c:4035\n process_one_work kernel/workqueue.c:3229 [inline]\n process_scheduled_works+0xa66/0x1840 kernel/workqueue.c:3310\n worker_thread+0x870/0xd30 kernel/workqueue.c:3391\n kthread+0x2f0/0x390 kernel/kthread.c:389\n ret_from_fork+0x4b/0x80 arch/x86/kernel/process.c:147\n ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:244\n\nFreed by task 54:\n kasan_save_stack mm/kasan/common.c:47 [inline]\n kasan_save_track+0x3f/0x80 mm/kasan/common.c:68\n kasan_save_free_info+0x40/0x50 mm/kasan/generic.c:582\n poison_slab_object mm/kasan/common.c:247 [inline]\n __kasan_slab_free+0x59/0x70 mm/kasan/common.c:264\n kasan_slab_free include/linux/kasan.h:233 [inline]\n slab_free_hook mm/slub.c:2353 [inline]\n slab_free mm/slub.c:4613 [inline]\n kfree+0x196/0x430 mm/slub.c:4761\n l2cap_connect_cfm+0xcc/0x1090 net/bluetooth/l2cap_core.c:7235\n hci_connect_cfm include/net/bluetooth/hci_core.h:2057 [inline]\n hci_conn_failed+0x287/0x400 net/bluetooth/hci_conn.c:1266\n hci_abort_conn_sync+0x56c/0x11f0 net/bluetooth/hci_sync.c:5603\n hci_cmd_sync_work+0x22b/0x400 net/bluetooth/hci_sync.c:332\n process_one_work kernel/workqueue.c:3229 [inline]\n process_scheduled_works+0xa66/0x1840 kernel/workqueue.c:3310\n worker_thread+0x870/0xd30 kernel/workqueue.c:3391\n kthread+0x2f0/0x390 kernel/kthread.c:389\n ret_from_fork+0x4b/0x80 arch/x86/kernel/process.c:147\n ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entr\n---truncated---", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21969" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7790a79c6fce8d5d552bc64f5c82819f719e4f28" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b4f82f9ed43aefa79bec2504ae8c29be0c0f5d1d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c96cce853542b3b13da3738f35ef1be8cfcc9d1d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f8094625a591eeb0b75b1bd9e713fac1d93f5ca9" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9vff-p882-x7qp/GHSA-9vff-p882-x7qp.json b/advisories/unreviewed/2025/04/GHSA-9vff-p882-x7qp/GHSA-9vff-p882-x7qp.json new file mode 100644 index 00000000000..e0498690403 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9vff-p882-x7qp/GHSA-9vff-p882-x7qp.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9vff-p882-x7qp", + "modified": "2025-04-01T18:30:54Z", + "published": "2025-04-01T18:30:54Z", + "aliases": [ + "CVE-2025-21976" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: hyperv_fb: Allow graceful removal of framebuffer\n\nWhen a Hyper-V framebuffer device is unbind, hyperv_fb driver tries to\nrelease the framebuffer forcefully. If this framebuffer is in use it\nproduce the following WARN and hence this framebuffer is never released.\n\n[ 44.111220] WARNING: CPU: 35 PID: 1882 at drivers/video/fbdev/core/fb_info.c:70 framebuffer_release+0x2c/0x40\n< snip >\n[ 44.111289] Call Trace:\n[ 44.111290] \n[ 44.111291] ? show_regs+0x6c/0x80\n[ 44.111295] ? __warn+0x8d/0x150\n[ 44.111298] ? framebuffer_release+0x2c/0x40\n[ 44.111300] ? report_bug+0x182/0x1b0\n[ 44.111303] ? handle_bug+0x6e/0xb0\n[ 44.111306] ? exc_invalid_op+0x18/0x80\n[ 44.111308] ? asm_exc_invalid_op+0x1b/0x20\n[ 44.111311] ? framebuffer_release+0x2c/0x40\n[ 44.111313] ? hvfb_remove+0x86/0xa0 [hyperv_fb]\n[ 44.111315] vmbus_remove+0x24/0x40 [hv_vmbus]\n[ 44.111323] device_remove+0x40/0x80\n[ 44.111325] device_release_driver_internal+0x20b/0x270\n[ 44.111327] ? bus_find_device+0xb3/0xf0\n\nFix this by moving the release of framebuffer and assosiated memory\nto fb_ops.fb_destroy function, so that framebuffer framework handles\nit gracefully.\n\nWhile we fix this, also replace manual registrations/unregistration of\nframebuffer with devm_register_framebuffer.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21976" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4545e2aa121aea304d33903099c03e29ed4fe50a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a7b583dc99c6cf4a96877017be1d08247e1ef2c7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ea2f45ab0e53b255f72c85ccd99e2b394fc5fceb" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-c863-9ggg-4m2g/GHSA-c863-9ggg-4m2g.json b/advisories/unreviewed/2025/04/GHSA-c863-9ggg-4m2g/GHSA-c863-9ggg-4m2g.json new file mode 100644 index 00000000000..1e2ce2c1ce5 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-c863-9ggg-4m2g/GHSA-c863-9ggg-4m2g.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c863-9ggg-4m2g", + "modified": "2025-04-01T18:30:54Z", + "published": "2025-04-01T18:30:54Z", + "aliases": [ + "CVE-2025-21974" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\neth: bnxt: return fail if interface is down in bnxt_queue_mem_alloc()\n\nThe bnxt_queue_mem_alloc() is called to allocate new queue memory when\na queue is restarted.\nIt internally accesses rx buffer descriptor corresponding to the index.\nThe rx buffer descriptor is allocated and set when the interface is up\nand it's freed when the interface is down.\nSo, if queue is restarted if interface is down, kernel panic occurs.\n\nSplat looks like:\n BUG: unable to handle page fault for address: 000000000000b240\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\n PGD 0 P4D 0\n Oops: Oops: 0000 [#1] PREEMPT SMP NOPTI\n CPU: 3 UID: 0 PID: 1563 Comm: ncdevmem2 Not tainted 6.14.0-rc2+ #9 844ddba6e7c459cafd0bf4db9a3198e\n Hardware name: ASUS System Product Name/PRIME Z690-P D4, BIOS 0603 11/01/2021\n RIP: 0010:bnxt_queue_mem_alloc+0x3f/0x4e0 [bnxt_en]\n Code: 41 54 4d 89 c4 4d 69 c0 c0 05 00 00 55 48 89 f5 53 48 89 fb 4c 8d b5 40 05 00 00 48 83 ec 15\n RSP: 0018:ffff9dcc83fef9e8 EFLAGS: 00010202\n RAX: ffffffffc0457720 RBX: ffff934ed8d40000 RCX: 0000000000000000\n RDX: 000000000000001f RSI: ffff934ea508f800 RDI: ffff934ea508f808\n RBP: ffff934ea508f800 R08: 000000000000b240 R09: ffff934e84f4b000\n R10: ffff9dcc83fefa30 R11: ffff934e84f4b000 R12: 000000000000001f\n R13: ffff934ed8d40ac0 R14: ffff934ea508fd40 R15: ffff934e84f4b000\n FS: 00007fa73888c740(0000) GS:ffff93559f780000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 000000000000b240 CR3: 0000000145a2e000 CR4: 00000000007506f0\n PKRU: 55555554\n Call Trace:\n \n ? __die+0x20/0x70\n ? page_fault_oops+0x15a/0x460\n ? exc_page_fault+0x6e/0x180\n ? asm_exc_page_fault+0x22/0x30\n ? __pfx_bnxt_queue_mem_alloc+0x10/0x10 [bnxt_en 7f85e76f4d724ba07471d7e39d9e773aea6597b7]\n ? bnxt_queue_mem_alloc+0x3f/0x4e0 [bnxt_en 7f85e76f4d724ba07471d7e39d9e773aea6597b7]\n netdev_rx_queue_restart+0xc5/0x240\n net_devmem_bind_dmabuf_to_queue+0xf8/0x200\n netdev_nl_bind_rx_doit+0x3a7/0x450\n genl_family_rcv_msg_doit+0xd9/0x130\n genl_rcv_msg+0x184/0x2b0\n ? __pfx_netdev_nl_bind_rx_doit+0x10/0x10\n ? __pfx_genl_rcv_msg+0x10/0x10\n netlink_rcv_skb+0x54/0x100\n genl_rcv+0x24/0x40\n...", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21974" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/14eb5f0d6554653f4b159835c2f77b2a9bd7e9be" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ca2456e073957781e1184de68551c65161b2bd30" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d3b8cd8a8a98c7c83a693bd651f1919be36a57f2" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-c924-p67m-48hp/GHSA-c924-p67m-48hp.json b/advisories/unreviewed/2025/04/GHSA-c924-p67m-48hp/GHSA-c924-p67m-48hp.json new file mode 100644 index 00000000000..68f89434cb7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-c924-p67m-48hp/GHSA-c924-p67m-48hp.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c924-p67m-48hp", + "modified": "2025-04-01T18:30:51Z", + "published": "2025-04-01T18:30:51Z", + "aliases": [ + "CVE-2025-21919" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsched/fair: Fix potential memory corruption in child_cfs_rq_on_list\n\nchild_cfs_rq_on_list attempts to convert a 'prev' pointer to a cfs_rq.\nThis 'prev' pointer can originate from struct rq's leaf_cfs_rq_list,\nmaking the conversion invalid and potentially leading to memory\ncorruption. Depending on the relative positions of leaf_cfs_rq_list and\nthe task group (tg) pointer within the struct, this can cause a memory\nfault or access garbage data.\n\nThe issue arises in list_add_leaf_cfs_rq, where both\ncfs_rq->leaf_cfs_rq_list and rq->leaf_cfs_rq_list are added to the same\nleaf list. Also, rq->tmp_alone_branch can be set to rq->leaf_cfs_rq_list.\n\nThis adds a check `if (prev == &rq->leaf_cfs_rq_list)` after the main\nconditional in child_cfs_rq_on_list. This ensures that the container_of\noperation will convert a correct cfs_rq struct.\n\nThis check is sufficient because only cfs_rqs on the same CPU are added\nto the list, so verifying the 'prev' pointer against the current rq's list\nhead is enough.\n\nFixes a potential memory corruption issue that due to current struct\nlayout might not be manifesting as a crash but could lead to unpredictable\nbehavior when the layout changes.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21919" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/000c9ee43928f2ce68a156dd40bab7616256f4dd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3b4035ddbfc8e4521f85569998a7569668cccf51" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5cb300dcdd27e6a351ac02541e0231261c775852" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9cc7f0018609f75a349e42e3aebc3b0e905ba775" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b5741e4b9ef3567613b2351384f91d3f16e59986" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e1dd09df30ba86716cb2ffab97dc35195c01eb8f" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-chr3-3876-prr8/GHSA-chr3-3876-prr8.json b/advisories/unreviewed/2025/04/GHSA-chr3-3876-prr8/GHSA-chr3-3876-prr8.json new file mode 100644 index 00000000000..0157fd2452d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-chr3-3876-prr8/GHSA-chr3-3876-prr8.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-chr3-3876-prr8", + "modified": "2025-04-01T18:30:52Z", + "published": "2025-04-01T18:30:51Z", + "aliases": [ + "CVE-2025-21925" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nllc: do not use skb_get() before dev_queue_xmit()\n\nsyzbot is able to crash hosts [1], using llc and devices\nnot supporting IFF_TX_SKB_SHARING.\n\nIn this case, e1000 driver calls eth_skb_pad(), while\nthe skb is shared.\n\nSimply replace skb_get() by skb_clone() in net/llc/llc_s_ac.c\n\nNote that e1000 driver might have an issue with pktgen,\nbecause it does not clear IFF_TX_SKB_SHARING, this is an\northogonal change.\n\nWe need to audit other skb_get() uses in net/llc.\n\n[1]\n\nkernel BUG at net/core/skbuff.c:2178 !\nOops: invalid opcode: 0000 [#1] PREEMPT SMP KASAN NOPTI\nCPU: 0 UID: 0 PID: 16371 Comm: syz.2.2764 Not tainted 6.14.0-rc4-syzkaller-00052-gac9c34d1e45a #0\nHardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2~bpo12+1 04/01/2014\n RIP: 0010:pskb_expand_head+0x6ce/0x1240 net/core/skbuff.c:2178\nCall Trace:\n \n __skb_pad+0x18a/0x610 net/core/skbuff.c:2466\n __skb_put_padto include/linux/skbuff.h:3843 [inline]\n skb_put_padto include/linux/skbuff.h:3862 [inline]\n eth_skb_pad include/linux/etherdevice.h:656 [inline]\n e1000_xmit_frame+0x2d99/0x5800 drivers/net/ethernet/intel/e1000/e1000_main.c:3128\n __netdev_start_xmit include/linux/netdevice.h:5151 [inline]\n netdev_start_xmit include/linux/netdevice.h:5160 [inline]\n xmit_one net/core/dev.c:3806 [inline]\n dev_hard_start_xmit+0x9a/0x7b0 net/core/dev.c:3822\n sch_direct_xmit+0x1ae/0xc30 net/sched/sch_generic.c:343\n __dev_xmit_skb net/core/dev.c:4045 [inline]\n __dev_queue_xmit+0x13d4/0x43e0 net/core/dev.c:4621\n dev_queue_xmit include/linux/netdevice.h:3313 [inline]\n llc_sap_action_send_test_c+0x268/0x320 net/llc/llc_s_ac.c:144\n llc_exec_sap_trans_actions net/llc/llc_sap.c:153 [inline]\n llc_sap_next_state net/llc/llc_sap.c:182 [inline]\n llc_sap_state_process+0x239/0x510 net/llc/llc_sap.c:209\n llc_ui_sendmsg+0xd0d/0x14e0 net/llc/af_llc.c:993\n sock_sendmsg_nosec net/socket.c:718 [inline]", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21925" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/056e8a46d79e22983bae4267e0d9c52927076f46" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0f764208dc24ea043c3e20194d32aebf94f8459c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/13f3f872627f0f27c31245524fc11367756240ad" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/17f86e25431ebc15aa9245ff156414fdad47822d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/416e8b4c20c6398044e93008deefd563289f477d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/64e6a754d33d31aa844b3ee66fb93ac84ca1565e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9b6f083db141ece0024be01526aa05aa978811cb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cd1c44327bbbd50fc24f2b38892f5f328b784d0f" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-cjrr-3f69-p92j/GHSA-cjrr-3f69-p92j.json b/advisories/unreviewed/2025/04/GHSA-cjrr-3f69-p92j/GHSA-cjrr-3f69-p92j.json new file mode 100644 index 00000000000..875531cb4bf --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-cjrr-3f69-p92j/GHSA-cjrr-3f69-p92j.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cjrr-3f69-p92j", + "modified": "2025-04-01T18:30:50Z", + "published": "2025-04-01T18:30:50Z", + "aliases": [ + "CVE-2025-21898" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nftrace: Avoid potential division by zero in function_stat_show()\n\nCheck whether denominator expression x * (x - 1) * 1000 mod {2^32, 2^64}\nproduce zero and skip stddev computation in that case.\n\nFor now don't care about rec->counter * rec->counter overflow because\nrec->time * rec->time overflow will likely happen earlier.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21898" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3d738b53ed6cddb68e68c9874520a4bf846163b5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5b3d32f607f0478b414b16516cf27f9170cf66c8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/746cc474a95473591853927b3a9792a2d671155b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/992775227843c9376773784b8b362add44592ad7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9cdac46fa7e854e587eb5f393fe491b6d7a9bdf6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a1a7eb89ca0b89dc1c326eeee2596f263291aca3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ca381f60a3bb7cfaa618d73ca411610bd7fc3149" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f58a3f8e284d0bdf94164a8e61cd4e70d337a1a3" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-cqjr-x55g-2j6v/GHSA-cqjr-x55g-2j6v.json b/advisories/unreviewed/2025/04/GHSA-cqjr-x55g-2j6v/GHSA-cqjr-x55g-2j6v.json new file mode 100644 index 00000000000..ad9b31989db --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-cqjr-x55g-2j6v/GHSA-cqjr-x55g-2j6v.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cqjr-x55g-2j6v", + "modified": "2025-04-01T18:30:51Z", + "published": "2025-04-01T18:30:51Z", + "aliases": [ + "CVE-2025-21912" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ngpio: rcar: Use raw_spinlock to protect register access\n\nUse raw_spinlock in order to fix spurious messages about invalid context\nwhen spinlock debugging is enabled. The lock is only used to serialize\nregister access.\n\n [ 4.239592] =============================\n [ 4.239595] [ BUG: Invalid wait context ]\n [ 4.239599] 6.13.0-rc7-arm64-renesas-05496-gd088502a519f #35 Not tainted\n [ 4.239603] -----------------------------\n [ 4.239606] kworker/u8:5/76 is trying to lock:\n [ 4.239609] ffff0000091898a0 (&p->lock){....}-{3:3}, at: gpio_rcar_config_interrupt_input_mode+0x34/0x164\n [ 4.239641] other info that might help us debug this:\n [ 4.239643] context-{5:5}\n [ 4.239646] 5 locks held by kworker/u8:5/76:\n [ 4.239651] #0: ffff0000080fb148 ((wq_completion)async){+.+.}-{0:0}, at: process_one_work+0x190/0x62c\n [ 4.250180] OF: /soc/sound@ec500000/ports/port@0/endpoint: Read of boolean property 'frame-master' with a value.\n [ 4.254094] #1: ffff80008299bd80 ((work_completion)(&entry->work)){+.+.}-{0:0}, at: process_one_work+0x1b8/0x62c\n [ 4.254109] #2: ffff00000920c8f8\n [ 4.258345] OF: /soc/sound@ec500000/ports/port@1/endpoint: Read of boolean property 'bitclock-master' with a value.\n [ 4.264803] (&dev->mutex){....}-{4:4}, at: __device_attach_async_helper+0x3c/0xdc\n [ 4.264820] #3: ffff00000a50ca40 (request_class#2){+.+.}-{4:4}, at: __setup_irq+0xa0/0x690\n [ 4.264840] #4:\n [ 4.268872] OF: /soc/sound@ec500000/ports/port@1/endpoint: Read of boolean property 'frame-master' with a value.\n [ 4.273275] ffff00000a50c8c8 (lock_class){....}-{2:2}, at: __setup_irq+0xc4/0x690\n [ 4.296130] renesas_sdhi_internal_dmac ee100000.mmc: mmc1 base at 0x00000000ee100000, max clock rate 200 MHz\n [ 4.304082] stack backtrace:\n [ 4.304086] CPU: 1 UID: 0 PID: 76 Comm: kworker/u8:5 Not tainted 6.13.0-rc7-arm64-renesas-05496-gd088502a519f #35\n [ 4.304092] Hardware name: Renesas Salvator-X 2nd version board based on r8a77965 (DT)\n [ 4.304097] Workqueue: async async_run_entry_fn\n [ 4.304106] Call trace:\n [ 4.304110] show_stack+0x14/0x20 (C)\n [ 4.304122] dump_stack_lvl+0x6c/0x90\n [ 4.304131] dump_stack+0x14/0x1c\n [ 4.304138] __lock_acquire+0xdfc/0x1584\n [ 4.426274] lock_acquire+0x1c4/0x33c\n [ 4.429942] _raw_spin_lock_irqsave+0x5c/0x80\n [ 4.434307] gpio_rcar_config_interrupt_input_mode+0x34/0x164\n [ 4.440061] gpio_rcar_irq_set_type+0xd4/0xd8\n [ 4.444422] __irq_set_trigger+0x5c/0x178\n [ 4.448435] __setup_irq+0x2e4/0x690\n [ 4.452012] request_threaded_irq+0xc4/0x190\n [ 4.456285] devm_request_threaded_irq+0x7c/0xf4\n [ 4.459398] ata1: link resume succeeded after 1 retries\n [ 4.460902] mmc_gpiod_request_cd_irq+0x68/0xe0\n [ 4.470660] mmc_start_host+0x50/0xac\n [ 4.474327] mmc_add_host+0x80/0xe4\n [ 4.477817] tmio_mmc_host_probe+0x2b0/0x440\n [ 4.482094] renesas_sdhi_probe+0x488/0x6f4\n [ 4.486281] renesas_sdhi_internal_dmac_probe+0x60/0x78\n [ 4.491509] platform_probe+0x64/0xd8\n [ 4.495178] really_probe+0xb8/0x2a8\n [ 4.498756] __driver_probe_device+0x74/0x118\n [ 4.503116] driver_probe_device+0x3c/0x154\n [ 4.507303] __device_attach_driver+0xd4/0x160\n [ 4.511750] bus_for_each_drv+0x84/0xe0\n [ 4.515588] __device_attach_async_helper+0xb0/0xdc\n [ 4.520470] async_run_entry_fn+0x30/0xd8\n [ 4.524481] process_one_work+0x210/0x62c\n [ 4.528494] worker_thread+0x1ac/0x340\n [ 4.532245] kthread+0x10c/0x110\n [ 4.535476] ret_from_fork+0x10/0x20", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21912" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3e300913c42041e81c5b17a970c4e078086ff2d1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/51ef3073493e2a25dced05fdd59dfb059e7e284d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7c1f36f9c9aca507d317479a3d3388150ae40a87" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b42c84f9e4ec5bc2885e7fd80c79ec0352f5d2af" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c10365031f16514a29c812cd909085a6e4ea4b61" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f02c41f87cfe61440c18bf77d1ef0a884b9ee2b5" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-f349-gqv8-wh65/GHSA-f349-gqv8-wh65.json b/advisories/unreviewed/2025/04/GHSA-f349-gqv8-wh65/GHSA-f349-gqv8-wh65.json new file mode 100644 index 00000000000..e56f25bc35e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-f349-gqv8-wh65/GHSA-f349-gqv8-wh65.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f349-gqv8-wh65", + "modified": "2025-04-01T18:30:52Z", + "published": "2025-04-01T18:30:52Z", + "aliases": [ + "CVE-2025-21942" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: zoned: fix extent range end unlock in cow_file_range()\n\nRunning generic/751 on the for-next branch often results in a hang like\nbelow. They are both stack by locking an extent. This suggests someone\nforget to unlock an extent.\n\n INFO: task kworker/u128:1:12 blocked for more than 323 seconds.\n Not tainted 6.13.0-BTRFS-ZNS+ #503\n \"echo 0 > /proc/sys/kernel/hung_task_timeout_secs\" disables this message.\n task:kworker/u128:1 state:D stack:0 pid:12 tgid:12 ppid:2 flags:0x00004000\n Workqueue: btrfs-fixup btrfs_work_helper [btrfs]\n Call Trace:\n \n __schedule+0x534/0xdd0\n schedule+0x39/0x140\n __lock_extent+0x31b/0x380 [btrfs]\n ? __pfx_autoremove_wake_function+0x10/0x10\n btrfs_writepage_fixup_worker+0xf1/0x3a0 [btrfs]\n btrfs_work_helper+0xff/0x480 [btrfs]\n ? lock_release+0x178/0x2c0\n process_one_work+0x1ee/0x570\n ? srso_return_thunk+0x5/0x5f\n worker_thread+0x1d1/0x3b0\n ? __pfx_worker_thread+0x10/0x10\n kthread+0x10b/0x230\n ? __pfx_kthread+0x10/0x10\n ret_from_fork+0x30/0x50\n ? __pfx_kthread+0x10/0x10\n ret_from_fork_asm+0x1a/0x30\n \n INFO: task kworker/u134:0:184 blocked for more than 323 seconds.\n Not tainted 6.13.0-BTRFS-ZNS+ #503\n \"echo 0 > /proc/sys/kernel/hung_task_timeout_secs\" disables this message.\n task:kworker/u134:0 state:D stack:0 pid:184 tgid:184 ppid:2 flags:0x00004000\n Workqueue: writeback wb_workfn (flush-btrfs-4)\n Call Trace:\n \n __schedule+0x534/0xdd0\n schedule+0x39/0x140\n __lock_extent+0x31b/0x380 [btrfs]\n ? __pfx_autoremove_wake_function+0x10/0x10\n find_lock_delalloc_range+0xdb/0x260 [btrfs]\n writepage_delalloc+0x12f/0x500 [btrfs]\n ? srso_return_thunk+0x5/0x5f\n extent_write_cache_pages+0x232/0x840 [btrfs]\n btrfs_writepages+0x72/0x130 [btrfs]\n do_writepages+0xe7/0x260\n ? srso_return_thunk+0x5/0x5f\n ? lock_acquire+0xd2/0x300\n ? srso_return_thunk+0x5/0x5f\n ? find_held_lock+0x2b/0x80\n ? wbc_attach_and_unlock_inode.part.0+0x102/0x250\n ? wbc_attach_and_unlock_inode.part.0+0x102/0x250\n __writeback_single_inode+0x5c/0x4b0\n writeback_sb_inodes+0x22d/0x550\n __writeback_inodes_wb+0x4c/0xe0\n wb_writeback+0x2f6/0x3f0\n wb_workfn+0x32a/0x510\n process_one_work+0x1ee/0x570\n ? srso_return_thunk+0x5/0x5f\n worker_thread+0x1d1/0x3b0\n ? __pfx_worker_thread+0x10/0x10\n kthread+0x10b/0x230\n ? __pfx_kthread+0x10/0x10\n ret_from_fork+0x30/0x50\n ? __pfx_kthread+0x10/0x10\n ret_from_fork_asm+0x1a/0x30\n \n\nThis happens because we have another success path for the zoned mode. When\nthere is no active zone available, btrfs_reserve_extent() returns\n-EAGAIN. In this case, we have two reactions.\n\n(1) If the given range is never allocated, we can only wait for someone\n to finish a zone, so wait on BTRFS_FS_NEED_ZONE_FINISH bit and retry\n afterward.\n\n(2) Or, if some allocations are already done, we must bail out and let\n the caller to send IOs for the allocation. This is because these IOs\n may be necessary to finish a zone.\n\nThe commit 06f364284794 (\"btrfs: do proper folio cleanup when\ncow_file_range() failed\") moved the unlock code from the inside of the\nloop to the outside. So, previously, the allocated extents are unlocked\njust after the allocation and so before returning from the function.\nHowever, they are no longer unlocked on the case (2) above. That caused\nthe hang issue.\n\nFix the issue by modifying the 'end' to the end of the allocated\nrange. Then, we can exit the loop and the same unlock code can properly\nhandle the case.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21942" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3fcff2f55389306482ab049b4321bda49495e546" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5a4041f2c47247575a6c2e53ce14f7b0ac946c33" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-f3mw-fg4x-6x2p/GHSA-f3mw-fg4x-6x2p.json b/advisories/unreviewed/2025/04/GHSA-f3mw-fg4x-6x2p/GHSA-f3mw-fg4x-6x2p.json new file mode 100644 index 00000000000..8b5a1dd67a7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-f3mw-fg4x-6x2p/GHSA-f3mw-fg4x-6x2p.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f3mw-fg4x-6x2p", + "modified": "2025-04-01T18:30:52Z", + "published": "2025-04-01T18:30:52Z", + "aliases": [ + "CVE-2025-21940" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdkfd: Fix NULL Pointer Dereference in KFD queue\n\nThrough KFD IOCTL Fuzzing we encountered a NULL pointer derefrence\nwhen calling kfd_queue_acquire_buffers.\n\n(cherry picked from commit 049e5bf3c8406f87c3d8e1958e0a16804fa1d530)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21940" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/33eb8041c5d6c19d46e7bfd23a031844336afd80" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c3cbeafb4e0001d9146df50b470885e02664f3c7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fd617ea3b79d2116d53f76cdb5a3601c0ba6e42f" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-f46w-cpqw-2pqr/GHSA-f46w-cpqw-2pqr.json b/advisories/unreviewed/2025/04/GHSA-f46w-cpqw-2pqr/GHSA-f46w-cpqw-2pqr.json new file mode 100644 index 00000000000..ea74b719592 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-f46w-cpqw-2pqr/GHSA-f46w-cpqw-2pqr.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f46w-cpqw-2pqr", + "modified": "2025-04-01T18:30:52Z", + "published": "2025-04-01T18:30:52Z", + "aliases": [ + "CVE-2025-21935" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nrapidio: add check for rio_add_net() in rio_scan_alloc_net()\n\nThe return value of rio_add_net() should be checked. If it fails,\nput_device() should be called to free the memory and give up the reference\ninitialized in rio_add_net().", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21935" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/181d4daaefb3bceeb2f2635ba9f3781eeda9e550" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4f3509cfcc02e9d757f2714bb7dbbeec35de6fa7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6d22953c4a183d0b7fdf34d68c5debd16da6edc5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a0d069ccc475abaaa79c6368ee27fc0b5912bea8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ad82be4298a89a9ae46f07128bdf3d8614bce745" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c332f3e2df0fcae5a45fd55cc18902fb1e4825ca" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e6411c3b9512dba09af7d014d474516828c89706" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e842f9a1edf306bf36fe2a4d847a0b0d458770de" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fcgh-gjcg-cmc2/GHSA-fcgh-gjcg-cmc2.json b/advisories/unreviewed/2025/04/GHSA-fcgh-gjcg-cmc2/GHSA-fcgh-gjcg-cmc2.json new file mode 100644 index 00000000000..12de330b859 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fcgh-gjcg-cmc2/GHSA-fcgh-gjcg-cmc2.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fcgh-gjcg-cmc2", + "modified": "2025-04-01T18:30:52Z", + "published": "2025-04-01T18:30:52Z", + "aliases": [ + "CVE-2025-21932" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm: abort vma_modify() on merge out of memory failure\n\nThe remainder of vma_modify() relies upon the vmg state remaining pristine\nafter a merge attempt.\n\nUsually this is the case, however in the one edge case scenario of a merge\nattempt failing not due to the specified range being unmergeable, but\nrather due to an out of memory error arising when attempting to commit the\nmerge, this assumption becomes untrue.\n\nThis results in vmg->start, end being modified, and thus the proceeding\nattempts to split the VMA will be done with invalid start/end values.\n\nThankfully, it is likely practically impossible for us to hit this in\nreality, as it would require a maple tree node pre-allocation failure that\nwould likely never happen due to it being 'too small to fail', i.e. the\nkernel would simply keep retrying reclaim until it succeeded.\n\nHowever, this scenario remains theoretically possible, and what we are\ndoing here is wrong so we must correct it.\n\nThe safest option is, when this scenario occurs, to simply give up the\noperation. If we cannot allocate memory to merge, then we cannot allocate\nmemory to split either (perhaps moreso!).\n\nAny scenario where this would be happening would be under very extreme\n(likely fatal) memory pressure, so it's best we give up early.\n\nSo there is no doubt it is appropriate to simply bail out in this\nscenario.\n\nHowever, in general we must if at all possible never assume VMG state is\nstable after a merge attempt, since merge operations update VMG fields. \nAs a result, additionally also make this clear by storing start, end in\nlocal variables.\n\nThe issue was reported originally by syzkaller, and by Brad Spengler (via\nan off-list discussion), and in both instances it manifested as a\ntriggering of the assert:\n\n\tVM_WARN_ON_VMG(start >= end, vmg);\n\nIn vma_merge_existing_range().\n\nIt seems at least one scenario in which this is occurring is one in which\nthe merge being attempted is due to an madvise() across multiple VMAs\nwhich looks like this:\n\n start end\n |<------>|\n |----------|------|\n | vma | next |\n |----------|------|\n\nWhen madvise_walk_vmas() is invoked, we first find vma in the above\n(determining prev to be equal to vma as we are offset into vma), and then\nenter the loop.\n\nWe determine the end of vma that forms part of the range we are\nmadvise()'ing by setting 'tmp' to this value:\n\n\t\t/* Here vma->vm_start <= start < (end|vma->vm_end) */\n\t\ttmp = vma->vm_end;\n\nWe then invoke the madvise() operation via visit(), letting prev get\nupdated to point to vma as part of the operation:\n\n\t\t/* Here vma->vm_start <= start < tmp <= (end|vma->vm_end). */\n\t\terror = visit(vma, &prev, start, tmp, arg);\n\nWhere the visit() function pointer in this instance is\nmadvise_vma_behavior().\n\nAs observed in syzkaller reports, it is ultimately madvise_update_vma()\nthat is invoked, calling vma_modify_flags_name() and vma_modify() in turn.\n\nThen, in vma_modify(), we attempt the merge:\n\n\tmerged = vma_merge_existing_range(vmg);\n\tif (merged)\n\t\treturn merged;\n\nWe invoke this with vmg->start, end set to start, tmp as such:\n\n start tmp\n |<--->|\n |----------|------|\n | vma | next |\n |----------|------|\n\nWe find ourselves in the merge right scenario, but the one in which we\ncannot remove the middle (we are offset into vma).\n\nHere we have a special case where vmg->start, end get set to perhaps\nunintuitive values - we intended to shrink the middle VMA and expand the\nnext.\n\nThis means vmg->start, end are set to... vma->vm_start, start.\n\nNow the commit_merge() fails, and vmg->start, end are left like this. \nThis means we return to the rest of vma_modify() with vmg->start, end\n(here denoted as start', end') set as:\n\n start' end'\n |<-->|\n |----------|------|\n | vma | next |\n |----------|------|\n\nSo we now erroneously try to split accordingly. This is where the\nunfortunate\n---truncated---", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21932" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/47b16d0462a460000b8f05dfb1292377ac48f3ca" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/53fd215f7886a1e8dea5a9ca1391dbb697fff601" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/79636d2981b066acd945117387a9533f56411f6f" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fcxj-8496-8247/GHSA-fcxj-8496-8247.json b/advisories/unreviewed/2025/04/GHSA-fcxj-8496-8247/GHSA-fcxj-8496-8247.json new file mode 100644 index 00000000000..e7756067869 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fcxj-8496-8247/GHSA-fcxj-8496-8247.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fcxj-8496-8247", + "modified": "2025-04-01T18:30:54Z", + "published": "2025-04-01T18:30:54Z", + "aliases": [ + "CVE-2025-21977" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: hyperv_fb: Fix hang in kdump kernel when on Hyper-V Gen 2 VMs\n\nGen 2 Hyper-V VMs boot via EFI and have a standard EFI framebuffer\ndevice. When the kdump kernel runs in such a VM, loading the efifb\ndriver may hang because of accessing the framebuffer at the wrong\nmemory address.\n\nThe scenario occurs when the hyperv_fb driver in the original kernel\nmoves the framebuffer to a different MMIO address because of conflicts\nwith an already-running efifb or simplefb driver. The hyperv_fb driver\nthen informs Hyper-V of the change, which is allowed by the Hyper-V FB\nVMBus device protocol. However, when the kexec command loads the kdump\nkernel into crash memory via the kexec_file_load() system call, the\nsystem call doesn't know the framebuffer has moved, and it sets up the\nkdump screen_info using the original framebuffer address. The transition\nto the kdump kernel does not go through the Hyper-V host, so Hyper-V\ndoes not reset the framebuffer address like it would do on a reboot.\nWhen efifb tries to run, it accesses a non-existent framebuffer\naddress, which traps to the Hyper-V host. After many such accesses,\nthe Hyper-V host thinks the guest is being malicious, and throttles\nthe guest to the point that it runs very slowly or appears to have hung.\n\nWhen the kdump kernel is loaded into crash memory via the kexec_load()\nsystem call, the problem does not occur. In this case, the kexec command\nbuilds the screen_info table itself in user space from data returned\nby the FBIOGET_FSCREENINFO ioctl against /dev/fb0, which gives it the\nnew framebuffer location.\n\nThis problem was originally reported in 2020 [1], resulting in commit\n3cb73bc3fa2a (\"hyperv_fb: Update screen_info after removing old\nframebuffer\"). This commit solved the problem by setting orig_video_isVGA\nto 0, so the kdump kernel was unaware of the EFI framebuffer. The efifb\ndriver did not try to load, and no hang occurred. But in 2024, commit\nc25a19afb81c (\"fbdev/hyperv_fb: Do not clear global screen_info\")\neffectively reverted 3cb73bc3fa2a. Commit c25a19afb81c has no reference\nto 3cb73bc3fa2a, so perhaps it was done without knowing the implications\nthat were reported with 3cb73bc3fa2a. In any case, as of commit\nc25a19afb81c, the original problem came back again.\n\nInterestingly, the hyperv_drm driver does not have this problem because\nit never moves the framebuffer. The difference is that the hyperv_drm\ndriver removes any conflicting framebuffers *before* allocating an MMIO\naddress, while the hyperv_fb drivers removes conflicting framebuffers\n*after* allocating an MMIO address. With the \"after\" ordering, hyperv_fb\nmay encounter a conflict and move the framebuffer to a different MMIO\naddress. But the conflict is essentially bogus because it is removed\na few lines of code later.\n\nRather than fix the problem with the approach from 2020 in commit\n3cb73bc3fa2a, instead slightly reorder the steps in hyperv_fb so\nconflicting framebuffers are removed before allocating an MMIO address.\nThen the default framebuffer MMIO address should always be available, and\nthere's never any confusion about which framebuffer address the kdump\nkernel should use -- it's always the original address provided by\nthe Hyper-V host. This approach is already used by the hyperv_drm\ndriver, and is consistent with the usage guidelines at the head of\nthe module with the function aperture_remove_conflicting_devices().\n\nThis approach also solves a related minor problem when kexec_load()\nis used to load the kdump kernel. With current code, unbinding and\nrebinding the hyperv_fb driver could result in the framebuffer moving\nback to the default framebuffer address, because on the rebind there\nare no conflicts. If such a move is done after the kdump kernel is\nloaded with the new framebuffer address, at kdump time it could again\nhave the wrong address.\n\nThis problem and fix are described in terms of the kdump kernel, but\nit can also occur\n---truncated---", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21977" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2924802d35e00a36b1503a4e786f1926b2fdc1d0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/304386373007aaca9236a3f36afac0bbedcd2bf0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cfffe46a994ac6d5de3b119917680ea1e9a96125" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fhg3-8v6r-3g42/GHSA-fhg3-8v6r-3g42.json b/advisories/unreviewed/2025/04/GHSA-fhg3-8v6r-3g42/GHSA-fhg3-8v6r-3g42.json new file mode 100644 index 00000000000..4457caaf054 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fhg3-8v6r-3g42/GHSA-fhg3-8v6r-3g42.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fhg3-8v6r-3g42", + "modified": "2025-04-01T18:30:54Z", + "published": "2025-04-01T18:30:54Z", + "aliases": [ + "CVE-2025-21973" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\neth: bnxt: fix kernel panic in the bnxt_get_queue_stats{rx | tx}\n\nWhen qstats-get operation is executed, callbacks of netdev_stats_ops\nare called. The bnxt_get_queue_stats{rx | tx} collect per-queue stats\nfrom sw_stats in the rings.\nBut {rx | tx | cp}_ring are allocated when the interface is up.\nSo, these rings are not allocated when the interface is down.\n\nThe qstats-get is allowed even if the interface is down. However,\nthe bnxt_get_queue_stats{rx | tx}() accesses cp_ring and tx_ring\nwithout null check.\nSo, it needs to avoid accessing rings if the interface is down.\n\nReproducer:\n ip link set $interface down\n ./cli.py --spec netdev.yaml --dump qstats-get\nOR\n ip link set $interface down\n python ./stats.py\n\nSplat looks like:\n BUG: kernel NULL pointer dereference, address: 0000000000000000\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\n PGD 1680fa067 P4D 1680fa067 PUD 16be3b067 PMD 0\n Oops: Oops: 0000 [#1] PREEMPT SMP NOPTI\n CPU: 0 UID: 0 PID: 1495 Comm: python3 Not tainted 6.14.0-rc4+ #32 5cd0f999d5a15c574ac72b3e4b907341\n Hardware name: ASUS System Product Name/PRIME Z690-P D4, BIOS 0603 11/01/2021\n RIP: 0010:bnxt_get_queue_stats_rx+0xf/0x70 [bnxt_en]\n Code: c6 87 b5 18 00 00 02 eb a2 66 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 0f 1f 44 01\n RSP: 0018:ffffabef43cdb7e0 EFLAGS: 00010282\n RAX: 0000000000000000 RBX: ffffffffc04c8710 RCX: 0000000000000000\n RDX: ffffabef43cdb858 RSI: 0000000000000000 RDI: ffff8d504e850000\n RBP: ffff8d506c9f9c00 R08: 0000000000000004 R09: ffff8d506bcd901c\n R10: 0000000000000015 R11: ffff8d506bcd9000 R12: 0000000000000000\n R13: ffffabef43cdb8c0 R14: ffff8d504e850000 R15: 0000000000000000\n FS: 00007f2c5462b080(0000) GS:ffff8d575f600000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 0000000000000000 CR3: 0000000167fd0000 CR4: 00000000007506f0\n PKRU: 55555554\n Call Trace:\n \n ? __die+0x20/0x70\n ? page_fault_oops+0x15a/0x460\n ? sched_balance_find_src_group+0x58d/0xd10\n ? exc_page_fault+0x6e/0x180\n ? asm_exc_page_fault+0x22/0x30\n ? bnxt_get_queue_stats_rx+0xf/0x70 [bnxt_en cdd546fd48563c280cfd30e9647efa420db07bf1]\n netdev_nl_stats_by_netdev+0x2b1/0x4e0\n ? xas_load+0x9/0xb0\n ? xas_find+0x183/0x1d0\n ? xa_find+0x8b/0xe0\n netdev_nl_qstats_get_dumpit+0xbf/0x1e0\n genl_dumpit+0x31/0x90\n netlink_dump+0x1a8/0x360", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21973" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/adb830085f0fc3a09a0fc8b64fed2e7c8d244665" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f059a0fd733078c3832fd0f3a3037aa5975d3d36" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f09af5fdfbd9b0fcee73aab1116904c53b199e97" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-g2g9-6hgr-7f52/GHSA-g2g9-6hgr-7f52.json b/advisories/unreviewed/2025/04/GHSA-g2g9-6hgr-7f52/GHSA-g2g9-6hgr-7f52.json new file mode 100644 index 00000000000..b82ee4e0c04 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-g2g9-6hgr-7f52/GHSA-g2g9-6hgr-7f52.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g2g9-6hgr-7f52", + "modified": "2025-04-01T18:30:52Z", + "published": "2025-04-01T18:30:52Z", + "aliases": [ + "CVE-2025-21931" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nhwpoison, memory_hotplug: lock folio before unmap hwpoisoned folio\n\nCommit b15c87263a69 (\"hwpoison, memory_hotplug: allow hwpoisoned pages to\nbe offlined) add page poison checks in do_migrate_range in order to make\noffline hwpoisoned page possible by introducing isolate_lru_page and\ntry_to_unmap for hwpoisoned page. However folio lock must be held before\ncalling try_to_unmap. Add it to fix this problem.\n\nWarning will be produced if folio is not locked during unmap:\n\n ------------[ cut here ]------------\n kernel BUG at ./include/linux/swapops.h:400!\n Internal error: Oops - BUG: 00000000f2000800 [#1] PREEMPT SMP\n Modules linked in:\n CPU: 4 UID: 0 PID: 411 Comm: bash Tainted: G W 6.13.0-rc1-00016-g3c434c7ee82a-dirty #41\n Tainted: [W]=WARN\n Hardware name: QEMU QEMU Virtual Machine, BIOS 0.0.0 02/06/2015\n pstate: 40400005 (nZcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n pc : try_to_unmap_one+0xb08/0xd3c\n lr : try_to_unmap_one+0x3dc/0xd3c\n Call trace:\n try_to_unmap_one+0xb08/0xd3c (P)\n try_to_unmap_one+0x3dc/0xd3c (L)\n rmap_walk_anon+0xdc/0x1f8\n rmap_walk+0x3c/0x58\n try_to_unmap+0x88/0x90\n unmap_poisoned_folio+0x30/0xa8\n do_migrate_range+0x4a0/0x568\n offline_pages+0x5a4/0x670\n memory_block_action+0x17c/0x374\n memory_subsys_offline+0x3c/0x78\n device_offline+0xa4/0xd0\n state_store+0x8c/0xf0\n dev_attr_store+0x18/0x2c\n sysfs_kf_write+0x44/0x54\n kernfs_fop_write_iter+0x118/0x1a8\n vfs_write+0x3a8/0x4bc\n ksys_write+0x6c/0xf8\n __arm64_sys_write+0x1c/0x28\n invoke_syscall+0x44/0x100\n el0_svc_common.constprop.0+0x40/0xe0\n do_el0_svc+0x1c/0x28\n el0_svc+0x30/0xd0\n el0t_64_sync_handler+0xc8/0xcc\n el0t_64_sync+0x198/0x19c\n Code: f9407be0 b5fff320 d4210000 17ffff97 (d4210000)\n ---[ end trace 0000000000000000 ]---", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21931" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/576a2f4c437c19bec7d05d05b5990f178d2b0f40" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/629dfc6ba5431056701d4e44830f3409b989955a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/af288a426c3e3552b62595c6138ec6371a17dbba" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-g7gr-m9c4-cg88/GHSA-g7gr-m9c4-cg88.json b/advisories/unreviewed/2025/04/GHSA-g7gr-m9c4-cg88/GHSA-g7gr-m9c4-cg88.json new file mode 100644 index 00000000000..98c625f9340 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-g7gr-m9c4-cg88/GHSA-g7gr-m9c4-cg88.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g7gr-m9c4-cg88", + "modified": "2025-04-01T18:30:55Z", + "published": "2025-04-01T18:30:55Z", + "aliases": [ + "CVE-2025-27829" + ], + "details": "An issue was discovered in Stormshield Network Security (SNS) 4.3.x before 4.3.35. If multicast streams are enabled on different interfaces, it may be possible to interrupt multicast traffic on some of these interfaces. That could result in a denial of the multicast routing service on the firewall.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27829" + }, + { + "type": "WEB", + "url": "https://advisories.stormshield.eu/2025-002" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T17:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-h94q-fmqj-xgwh/GHSA-h94q-fmqj-xgwh.json b/advisories/unreviewed/2025/04/GHSA-h94q-fmqj-xgwh/GHSA-h94q-fmqj-xgwh.json index 252d7afbd5f..79f773bb566 100644 --- a/advisories/unreviewed/2025/04/GHSA-h94q-fmqj-xgwh/GHSA-h94q-fmqj-xgwh.json +++ b/advisories/unreviewed/2025/04/GHSA-h94q-fmqj-xgwh/GHSA-h94q-fmqj-xgwh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h94q-fmqj-xgwh", - "modified": "2025-04-01T00:30:42Z", + "modified": "2025-04-01T18:30:48Z", "published": "2025-04-01T00:30:42Z", "aliases": [ "CVE-2025-30450" ], "details": "This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to access sensitive user data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:26Z" diff --git a/advisories/unreviewed/2025/04/GHSA-h9h6-5fw6-j683/GHSA-h9h6-5fw6-j683.json b/advisories/unreviewed/2025/04/GHSA-h9h6-5fw6-j683/GHSA-h9h6-5fw6-j683.json new file mode 100644 index 00000000000..51922bf8793 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-h9h6-5fw6-j683/GHSA-h9h6-5fw6-j683.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h9h6-5fw6-j683", + "modified": "2025-04-01T18:30:54Z", + "published": "2025-04-01T18:30:53Z", + "aliases": [ + "CVE-2025-21963" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncifs: Fix integer overflow while processing acdirmax mount option\n\nUser-provided mount parameter acdirmax of type u32 is intended to have\nan upper limit, but before it is validated, the value is converted from\nseconds to jiffies which can lead to an integer overflow.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21963" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2809a79bc64964ce02e0c5f2d6bd39b9d09bdb3c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/39d086bb3558da9640ef335f97453e01d32578a1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5b29891f91dfb8758baf1e2217bef4b16b2b165b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6124cbf73e3dea7591857dd63b8ccece28952afd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9e438d0410a4002d24f420f2c28897ba2dc0af64" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hc79-964w-vvqg/GHSA-hc79-964w-vvqg.json b/advisories/unreviewed/2025/04/GHSA-hc79-964w-vvqg/GHSA-hc79-964w-vvqg.json new file mode 100644 index 00000000000..c4b18b70d0e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hc79-964w-vvqg/GHSA-hc79-964w-vvqg.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hc79-964w-vvqg", + "modified": "2025-04-01T18:30:55Z", + "published": "2025-04-01T18:30:55Z", + "aliases": [ + "CVE-2025-25041" + ], + "details": "A vulnerability in the HPE Aruba Networking Virtual Intranet Access (VIA) client could allow malicious users to overwrite arbitrary files as NT AUTHORITY\\SYSTEM (root). A successful exploit could allow the creation of a Denial-of-Service (DoS) condition affecting the Microsoft Windows Operating System. This vulnerability does not affect Linux and Android based clients.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25041" + }, + { + "type": "WEB", + "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04841en_us&docLocale=en_US" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T17:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hf5w-7g55-wh36/GHSA-hf5w-7g55-wh36.json b/advisories/unreviewed/2025/04/GHSA-hf5w-7g55-wh36/GHSA-hf5w-7g55-wh36.json new file mode 100644 index 00000000000..865e92305d7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hf5w-7g55-wh36/GHSA-hf5w-7g55-wh36.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hf5w-7g55-wh36", + "modified": "2025-04-01T18:30:51Z", + "published": "2025-04-01T18:30:51Z", + "aliases": [ + "CVE-2025-21917" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: renesas_usbhs: Flush the notify_hotplug_work\n\nWhen performing continuous unbind/bind operations on the USB drivers\navailable on the Renesas RZ/G2L SoC, a kernel crash with the message\n\"Unable to handle kernel NULL pointer dereference at virtual address\"\nmay occur. This issue points to the usbhsc_notify_hotplug() function.\n\nFlush the delayed work to avoid its execution when driver resources are\nunavailable.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21917" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3248c1f833f924246cb98ce7da4569133c1b2292" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/394965f90454d6f00fe11879142b720c6c1a872e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4ca078084cdd5f32d533311d6a0b63a60dcadd41" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4cd847a7b630a85493d0294ad9542c21aafaa246" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/552ca6b87e3778f3dd5b87842f95138162e16c82" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/830818c8e70c0364e377f0c243b28061ef7967eb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d50f5c0cd949593eb9a3d822b34d7b50046a06b7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e5aac1c9b2974636db7ce796ffa6de88fa08335e" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hr95-mwx9-67j6/GHSA-hr95-mwx9-67j6.json b/advisories/unreviewed/2025/04/GHSA-hr95-mwx9-67j6/GHSA-hr95-mwx9-67j6.json new file mode 100644 index 00000000000..1cabce80857 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hr95-mwx9-67j6/GHSA-hr95-mwx9-67j6.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hr95-mwx9-67j6", + "modified": "2025-04-01T18:30:51Z", + "published": "2025-04-01T18:30:51Z", + "aliases": [ + "CVE-2025-21914" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nslimbus: messaging: Free transaction ID in delayed interrupt scenario\n\nIn case of interrupt delay for any reason, slim_do_transfer()\nreturns timeout error but the transaction ID (TID) is not freed.\nThis results into invalid memory access inside\nqcom_slim_ngd_rx_msgq_cb() due to invalid TID.\n\nFix the issue by freeing the TID in slim_do_transfer() before\nreturning timeout error to avoid invalid memory access.\n\nCall trace:\n__memcpy_fromio+0x20/0x190\nqcom_slim_ngd_rx_msgq_cb+0x130/0x290 [slim_qcom_ngd_ctrl]\nvchan_complete+0x2a0/0x4a0\ntasklet_action_common+0x274/0x700\ntasklet_action+0x28/0x3c\n_stext+0x188/0x620\nrun_ksoftirqd+0x34/0x74\nsmpboot_thread_fn+0x1d8/0x464\nkthread+0x178/0x238\nret_from_fork+0x10/0x20\nCode: aa0003e8 91000429 f100044a 3940002b (3800150b)\n---[ end trace 0fe00bec2b975c99 ]---\nKernel panic - not syncing: Oops: Fatal exception in interrupt.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21914" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/09d34c4cbc38485c7514069f25348e439555b282" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0c541c8f6da23e0b92f0a6216d899659a7572074" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/18ae4cee05c310c299ba75d7477dcf34be67aa16" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6abf3d8bb51cbaf886c3f08109a0462890b10db6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a32e5198a9134772eb03f7b72a7849094c55bda9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cec8c0ac173fe5321f03fdb1a09a9cb69bc9a9fe" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/dcb0d43ba8eb9517e70b1a0e4b0ae0ab657a0e5a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/faac8e894014e8167471a8e4a5eb35a8fefbb82a" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hwhh-xm47-jghm/GHSA-hwhh-xm47-jghm.json b/advisories/unreviewed/2025/04/GHSA-hwhh-xm47-jghm/GHSA-hwhh-xm47-jghm.json new file mode 100644 index 00000000000..1008ffeab51 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hwhh-xm47-jghm/GHSA-hwhh-xm47-jghm.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hwhh-xm47-jghm", + "modified": "2025-04-01T18:30:53Z", + "published": "2025-04-01T18:30:53Z", + "aliases": [ + "CVE-2025-21959" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_conncount: Fully initialize struct nf_conncount_tuple in insert_tree()\n\nSince commit b36e4523d4d5 (\"netfilter: nf_conncount: fix garbage\ncollection confirm race\"), `cpu` and `jiffies32` were introduced to\nthe struct nf_conncount_tuple.\n\nThe commit made nf_conncount_add() initialize `conn->cpu` and\n`conn->jiffies32` when allocating the struct.\nIn contrast, count_tree() was not changed to initialize them.\n\nBy commit 34848d5c896e (\"netfilter: nf_conncount: Split insert and\ntraversal\"), count_tree() was split and the relevant allocation\ncode now resides in insert_tree().\nInitialize `conn->cpu` and `conn->jiffies32` in insert_tree().\n\nBUG: KMSAN: uninit-value in find_or_evict net/netfilter/nf_conncount.c:117 [inline]\nBUG: KMSAN: uninit-value in __nf_conncount_add+0xd9c/0x2850 net/netfilter/nf_conncount.c:143\n find_or_evict net/netfilter/nf_conncount.c:117 [inline]\n __nf_conncount_add+0xd9c/0x2850 net/netfilter/nf_conncount.c:143\n count_tree net/netfilter/nf_conncount.c:438 [inline]\n nf_conncount_count+0x82f/0x1e80 net/netfilter/nf_conncount.c:521\n connlimit_mt+0x7f6/0xbd0 net/netfilter/xt_connlimit.c:72\n __nft_match_eval net/netfilter/nft_compat.c:403 [inline]\n nft_match_eval+0x1a5/0x300 net/netfilter/nft_compat.c:433\n expr_call_ops_eval net/netfilter/nf_tables_core.c:240 [inline]\n nft_do_chain+0x426/0x2290 net/netfilter/nf_tables_core.c:288\n nft_do_chain_ipv4+0x1a5/0x230 net/netfilter/nft_chain_filter.c:23\n nf_hook_entry_hookfn include/linux/netfilter.h:154 [inline]\n nf_hook_slow+0xf4/0x400 net/netfilter/core.c:626\n nf_hook_slow_list+0x24d/0x860 net/netfilter/core.c:663\n NF_HOOK_LIST include/linux/netfilter.h:350 [inline]\n ip_sublist_rcv+0x17b7/0x17f0 net/ipv4/ip_input.c:633\n ip_list_rcv+0x9ef/0xa40 net/ipv4/ip_input.c:669\n __netif_receive_skb_list_ptype net/core/dev.c:5936 [inline]\n __netif_receive_skb_list_core+0x15c5/0x1670 net/core/dev.c:5983\n __netif_receive_skb_list net/core/dev.c:6035 [inline]\n netif_receive_skb_list_internal+0x1085/0x1700 net/core/dev.c:6126\n netif_receive_skb_list+0x5a/0x460 net/core/dev.c:6178\n xdp_recv_frames net/bpf/test_run.c:280 [inline]\n xdp_test_run_batch net/bpf/test_run.c:361 [inline]\n bpf_test_run_xdp_live+0x2e86/0x3480 net/bpf/test_run.c:390\n bpf_prog_test_run_xdp+0xf1d/0x1ae0 net/bpf/test_run.c:1316\n bpf_prog_test_run+0x5e5/0xa30 kernel/bpf/syscall.c:4407\n __sys_bpf+0x6aa/0xd90 kernel/bpf/syscall.c:5813\n __do_sys_bpf kernel/bpf/syscall.c:5902 [inline]\n __se_sys_bpf kernel/bpf/syscall.c:5900 [inline]\n __ia32_sys_bpf+0xa0/0xe0 kernel/bpf/syscall.c:5900\n ia32_sys_call+0x394d/0x4180 arch/x86/include/generated/asm/syscalls_32.h:358\n do_syscall_32_irqs_on arch/x86/entry/common.c:165 [inline]\n __do_fast_syscall_32+0xb0/0x110 arch/x86/entry/common.c:387\n do_fast_syscall_32+0x38/0x80 arch/x86/entry/common.c:412\n do_SYSENTER_32+0x1f/0x30 arch/x86/entry/common.c:450\n entry_SYSENTER_compat_after_hwframe+0x84/0x8e\n\nUninit was created at:\n slab_post_alloc_hook mm/slub.c:4121 [inline]\n slab_alloc_node mm/slub.c:4164 [inline]\n kmem_cache_alloc_noprof+0x915/0xe10 mm/slub.c:4171\n insert_tree net/netfilter/nf_conncount.c:372 [inline]\n count_tree net/netfilter/nf_conncount.c:450 [inline]\n nf_conncount_count+0x1415/0x1e80 net/netfilter/nf_conncount.c:521\n connlimit_mt+0x7f6/0xbd0 net/netfilter/xt_connlimit.c:72\n __nft_match_eval net/netfilter/nft_compat.c:403 [inline]\n nft_match_eval+0x1a5/0x300 net/netfilter/nft_compat.c:433\n expr_call_ops_eval net/netfilter/nf_tables_core.c:240 [inline]\n nft_do_chain+0x426/0x2290 net/netfilter/nf_tables_core.c:288\n nft_do_chain_ipv4+0x1a5/0x230 net/netfilter/nft_chain_filter.c:23\n nf_hook_entry_hookfn include/linux/netfilter.h:154 [inline]\n nf_hook_slow+0xf4/0x400 net/netfilter/core.c:626\n nf_hook_slow_list+0x24d/0x860 net/netfilter/core.c:663\n NF_HOOK_LIST include/linux/netfilter.h:350 [inline]\n ip_sublist_rcv+0x17b7/0x17f0 net/ipv4/ip_input.c:633\n ip_list_rcv+0x9ef/0xa40 net/ip\n---truncated---", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21959" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2db5baaf047a7c8d6ed5e2cc657b7854e155b7fc" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a62a25c6ad58fae997f48a0749afeda1c252ae51" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d653bfeb07ebb3499c403404c21ac58a16531607" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/db1e0c0856821c59a32ea3af79476bf20a6beeb2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fda50302a13701d47fbe01e1739c7a51114144fb" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-j57r-qmgx-xp34/GHSA-j57r-qmgx-xp34.json b/advisories/unreviewed/2025/04/GHSA-j57r-qmgx-xp34/GHSA-j57r-qmgx-xp34.json new file mode 100644 index 00000000000..1f7acae6ab4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-j57r-qmgx-xp34/GHSA-j57r-qmgx-xp34.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j57r-qmgx-xp34", + "modified": "2025-04-01T18:30:50Z", + "published": "2025-04-01T18:30:50Z", + "aliases": [ + "CVE-2025-21901" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/bnxt_re: Add sanity checks on rdev validity\n\nThere is a possibility that ulp_irq_stop and ulp_irq_start\ncallbacks will be called when the device is in detached state.\nThis can cause a crash due to NULL pointer dereference as\nthe rdev is already freed.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21901" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8cb0eef46d70a99c88c26a1addb7fd955242e0e6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/aed1bc673907e3df372b317c10ff2f3582f8bf1a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f0df225d12fcb049429fb5bf5122afe143c2dd15" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-j8rw-3x8v-v327/GHSA-j8rw-3x8v-v327.json b/advisories/unreviewed/2025/04/GHSA-j8rw-3x8v-v327/GHSA-j8rw-3x8v-v327.json new file mode 100644 index 00000000000..6c235d6c03e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-j8rw-3x8v-v327/GHSA-j8rw-3x8v-v327.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j8rw-3x8v-v327", + "modified": "2025-04-01T18:30:51Z", + "published": "2025-04-01T18:30:51Z", + "aliases": [ + "CVE-2025-21918" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: typec: ucsi: Fix NULL pointer access\n\nResources should be released only after all threads that utilize them\nhave been destroyed.\nThis commit ensures that resources are not released prematurely by waiting\nfor the associated workqueue to complete before deallocating them.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21918" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/079a3e52f3e751bb8f5937195bdf25c5d14fdff0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/46fba7be161bb89068958138ea64ec33c0b446d4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/592a0327d026a122e97e8e8bb7c60cbbe7697344" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b13abcb7ddd8d38de769486db5bd917537b32ab1" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-j97h-5fwv-4rhj/GHSA-j97h-5fwv-4rhj.json b/advisories/unreviewed/2025/04/GHSA-j97h-5fwv-4rhj/GHSA-j97h-5fwv-4rhj.json new file mode 100644 index 00000000000..bcbd14a4ea4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-j97h-5fwv-4rhj/GHSA-j97h-5fwv-4rhj.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j97h-5fwv-4rhj", + "modified": "2025-04-01T18:30:52Z", + "published": "2025-04-01T18:30:52Z", + "aliases": [ + "CVE-2025-21953" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: mana: cleanup mana struct after debugfs_remove()\n\nWhen on a MANA VM hibernation is triggered, as part of hibernate_snapshot(),\nmana_gd_suspend() and mana_gd_resume() are called. If during this\nmana_gd_resume(), a failure occurs with HWC creation, mana_port_debugfs\npointer does not get reinitialized and ends up pointing to older,\ncleaned-up dentry.\nFurther in the hibernation path, as part of power_down(), mana_gd_shutdown()\nis triggered. This call, unaware of the failures in resume, tries to cleanup\nthe already cleaned up mana_port_debugfs value and hits the following bug:\n\n[ 191.359296] mana 7870:00:00.0: Shutdown was called\n[ 191.359918] BUG: kernel NULL pointer dereference, address: 0000000000000098\n[ 191.360584] #PF: supervisor write access in kernel mode\n[ 191.361125] #PF: error_code(0x0002) - not-present page\n[ 191.361727] PGD 1080ea067 P4D 0\n[ 191.362172] Oops: Oops: 0002 [#1] SMP NOPTI\n[ 191.362606] CPU: 11 UID: 0 PID: 1674 Comm: bash Not tainted 6.14.0-rc5+ #2\n[ 191.363292] Hardware name: Microsoft Corporation Virtual Machine/Virtual Machine, BIOS Hyper-V UEFI Release v4.1 11/21/2024\n[ 191.364124] RIP: 0010:down_write+0x19/0x50\n[ 191.364537] Code: 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 0f 1f 44 00 00 55 48 89 e5 53 48 89 fb e8 de cd ff ff 31 c0 ba 01 00 00 00 48 0f b1 13 75 16 65 48 8b 05 88 24 4c 6a 48 89 43 08 48 8b 5d\n[ 191.365867] RSP: 0000:ff45fbe0c1c037b8 EFLAGS: 00010246\n[ 191.366350] RAX: 0000000000000000 RBX: 0000000000000098 RCX: ffffff8100000000\n[ 191.366951] RDX: 0000000000000001 RSI: 0000000000000064 RDI: 0000000000000098\n[ 191.367600] RBP: ff45fbe0c1c037c0 R08: 0000000000000000 R09: 0000000000000001\n[ 191.368225] R10: ff45fbe0d2b01000 R11: 0000000000000008 R12: 0000000000000000\n[ 191.368874] R13: 000000000000000b R14: ff43dc27509d67c0 R15: 0000000000000020\n[ 191.369549] FS: 00007dbc5001e740(0000) GS:ff43dc663f380000(0000) knlGS:0000000000000000\n[ 191.370213] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 191.370830] CR2: 0000000000000098 CR3: 0000000168e8e002 CR4: 0000000000b73ef0\n[ 191.371557] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n[ 191.372192] DR3: 0000000000000000 DR6: 00000000fffe07f0 DR7: 0000000000000400\n[ 191.372906] Call Trace:\n[ 191.373262] \n[ 191.373621] ? show_regs+0x64/0x70\n[ 191.374040] ? __die+0x24/0x70\n[ 191.374468] ? page_fault_oops+0x290/0x5b0\n[ 191.374875] ? do_user_addr_fault+0x448/0x800\n[ 191.375357] ? exc_page_fault+0x7a/0x160\n[ 191.375971] ? asm_exc_page_fault+0x27/0x30\n[ 191.376416] ? down_write+0x19/0x50\n[ 191.376832] ? down_write+0x12/0x50\n[ 191.377232] simple_recursive_removal+0x4a/0x2a0\n[ 191.377679] ? __pfx_remove_one+0x10/0x10\n[ 191.378088] debugfs_remove+0x44/0x70\n[ 191.378530] mana_detach+0x17c/0x4f0\n[ 191.378950] ? __flush_work+0x1e2/0x3b0\n[ 191.379362] ? __cond_resched+0x1a/0x50\n[ 191.379787] mana_remove+0xf2/0x1a0\n[ 191.380193] mana_gd_shutdown+0x3b/0x70\n[ 191.380642] pci_device_shutdown+0x3a/0x80\n[ 191.381063] device_shutdown+0x13e/0x230\n[ 191.381480] kernel_power_off+0x35/0x80\n[ 191.381890] hibernate+0x3c6/0x470\n[ 191.382312] state_store+0xcb/0xd0\n[ 191.382734] kobj_attr_store+0x12/0x30\n[ 191.383211] sysfs_kf_write+0x3e/0x50\n[ 191.383640] kernfs_fop_write_iter+0x140/0x1d0\n[ 191.384106] vfs_write+0x271/0x440\n[ 191.384521] ksys_write+0x72/0xf0\n[ 191.384924] __x64_sys_write+0x19/0x20\n[ 191.385313] x64_sys_call+0x2b0/0x20b0\n[ 191.385736] do_syscall_64+0x79/0x150\n[ 191.386146] ? __mod_memcg_lruvec_state+0xe7/0x240\n[ 191.386676] ? __lruvec_stat_mod_folio+0x79/0xb0\n[ 191.387124] ? __pfx_lru_add+0x10/0x10\n[ 191.387515] ? queued_spin_unlock+0x9/0x10\n[ 191.387937] ? do_anonymous_page+0x33c/0xa00\n[ 191.388374] ? __handle_mm_fault+0xcf3/0x1210\n[ 191.388805] ? __count_memcg_events+0xbe/0x180\n[ 191.389235] ? handle_mm_fault+0xae/0x300\n[ 19\n---truncated---", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21953" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3e64bb2ae7d9f2b3a8259d4d6b86ed1984d5460a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a1466112fb6e819261272ad75e7db750a43b78bf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-jrg4-7p24-jjmf/GHSA-jrg4-7p24-jjmf.json b/advisories/unreviewed/2025/04/GHSA-jrg4-7p24-jjmf/GHSA-jrg4-7p24-jjmf.json new file mode 100644 index 00000000000..e9e5fc9c0df --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jrg4-7p24-jjmf/GHSA-jrg4-7p24-jjmf.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jrg4-7p24-jjmf", + "modified": "2025-04-01T18:30:55Z", + "published": "2025-04-01T18:30:55Z", + "aliases": [ + "CVE-2025-28131" + ], + "details": "A Broken Access Control vulnerability in Nagios Network Analyzer 2024R1.0.3 allows low-privilege users with \"Read-Only\" access to perform administrative actions, including stopping system services and deleting critical resources. This flaw arises due to improper authorization enforcement, enabling unauthorized modifications that compromise system integrity and availability.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28131" + }, + { + "type": "WEB", + "url": "https://github.com/harshal79/Privilege-Escalation-in-Nagios-Network-Analyzer.git" + }, + { + "type": "WEB", + "url": "https://www.nagios.com/changelog/#network-analyzer" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T17:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-jvvm-77gw-35g5/GHSA-jvvm-77gw-35g5.json b/advisories/unreviewed/2025/04/GHSA-jvvm-77gw-35g5/GHSA-jvvm-77gw-35g5.json new file mode 100644 index 00000000000..c28059c5a96 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jvvm-77gw-35g5/GHSA-jvvm-77gw-35g5.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jvvm-77gw-35g5", + "modified": "2025-04-01T18:30:49Z", + "published": "2025-04-01T18:30:49Z", + "aliases": [ + "CVE-2025-21895" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nperf/core: Order the PMU list to fix warning about unordered pmu_ctx_list\n\nSyskaller triggers a warning due to prev_epc->pmu != next_epc->pmu in\nperf_event_swap_task_ctx_data(). vmcore shows that two lists have the same\nperf_event_pmu_context, but not in the same order.\n\nThe problem is that the order of pmu_ctx_list for the parent is impacted by\nthe time when an event/PMU is added. While the order for a child is\nimpacted by the event order in the pinned_groups and flexible_groups. So\nthe order of pmu_ctx_list in the parent and child may be different.\n\nTo fix this problem, insert the perf_event_pmu_context to its proper place\nafter iteration of the pmu_ctx_list.\n\nThe follow testcase can trigger above warning:\n\n # perf record -e cycles --call-graph lbr -- taskset -c 3 ./a.out &\n # perf stat -e cpu-clock,cs -p xxx // xxx is the pid of a.out\n\n test.c\n\n void main() {\n int count = 0;\n pid_t pid;\n\n printf(\"%d running\\n\", getpid());\n sleep(30);\n printf(\"running\\n\");\n\n pid = fork();\n if (pid == -1) {\n printf(\"fork error\\n\");\n return;\n }\n if (pid == 0) {\n while (1) {\n count++;\n }\n } else {\n while (1) {\n count++;\n }\n }\n }\n\nThe testcase first opens an LBR event, so it will allocate task_ctx_data,\nand then open tracepoint and software events, so the parent context will\nhave 3 different perf_event_pmu_contexts. On inheritance, child ctx will\ninsert the perf_event_pmu_context in another order and the warning will\ntrigger.\n\n[ mingo: Tidied up the changelog. ]", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21895" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2016066c66192a99d9e0ebf433789c490a6785a2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3e812a70732d84b7873cea61a7f6349b9a9dcbf5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7d582eb6e4e100959ba07083d7563453c8c2a343" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f0c3971405cef6892844016aa710121a02da3a23" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-jwp5-c35f-qv38/GHSA-jwp5-c35f-qv38.json b/advisories/unreviewed/2025/04/GHSA-jwp5-c35f-qv38/GHSA-jwp5-c35f-qv38.json new file mode 100644 index 00000000000..838b7c8a179 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jwp5-c35f-qv38/GHSA-jwp5-c35f-qv38.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jwp5-c35f-qv38", + "modified": "2025-04-01T18:30:52Z", + "published": "2025-04-01T18:30:51Z", + "aliases": [ + "CVE-2025-21926" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: gso: fix ownership in __udp_gso_segment\n\nIn __udp_gso_segment the skb destructor is removed before segmenting the\nskb but the socket reference is kept as-is. This is an issue if the\noriginal skb is later orphaned as we can hit the following bug:\n\n kernel BUG at ./include/linux/skbuff.h:3312! (skb_orphan)\n RIP: 0010:ip_rcv_core+0x8b2/0xca0\n Call Trace:\n ip_rcv+0xab/0x6e0\n __netif_receive_skb_one_core+0x168/0x1b0\n process_backlog+0x384/0x1100\n __napi_poll.constprop.0+0xa1/0x370\n net_rx_action+0x925/0xe50\n\nThe above can happen following a sequence of events when using\nOpenVSwitch, when an OVS_ACTION_ATTR_USERSPACE action precedes an\nOVS_ACTION_ATTR_OUTPUT action:\n\n1. OVS_ACTION_ATTR_USERSPACE is handled (in do_execute_actions): the skb\n goes through queue_gso_packets and then __udp_gso_segment, where its\n destructor is removed.\n2. The segments' data are copied and sent to userspace.\n3. OVS_ACTION_ATTR_OUTPUT is handled (in do_execute_actions) and the\n same original skb is sent to its path.\n4. If it later hits skb_orphan, we hit the bug.\n\nFix this by also removing the reference to the socket in\n__udp_gso_segment.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21926" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/01a83237644d6822bc7df2c5564fc81b0df84358" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/084819b0d8b1bd433b90142371eb9450d657f8ca" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/455217ac9db0cf9349b3933664355e907bb1a569" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9f28205ddb76e86cac418332e952241d85fed0dc" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a2d1cca955ed34873e524cc2e6e885450d262f05" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c32da44cc9298eaa6109e3fc2c2b4e07cc4bf11b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e8db70537878e1bb3fd83e5abcc6feefc0587828" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ee01b2f2d7d0010787c2343463965bbc283a497f" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-jx6v-7wmg-pq67/GHSA-jx6v-7wmg-pq67.json b/advisories/unreviewed/2025/04/GHSA-jx6v-7wmg-pq67/GHSA-jx6v-7wmg-pq67.json new file mode 100644 index 00000000000..b8b32783bfb --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jx6v-7wmg-pq67/GHSA-jx6v-7wmg-pq67.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jx6v-7wmg-pq67", + "modified": "2025-04-01T18:30:53Z", + "published": "2025-04-01T18:30:53Z", + "aliases": [ + "CVE-2025-21958" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRevert \"openvswitch: switch to per-action label counting in conntrack\"\n\nCurrently, ovs_ct_set_labels() is only called for confirmed conntrack\nentries (ct) within ovs_ct_commit(). However, if the conntrack entry\ndoes not have the labels_ext extension, attempting to allocate it in\novs_ct_get_conn_labels() for a confirmed entry triggers a warning in\nnf_ct_ext_add():\n\n WARN_ON(nf_ct_is_confirmed(ct));\n\nThis happens when the conntrack entry is created externally before OVS\nincrements net->ct.labels_used. The issue has become more likely since\ncommit fcb1aa5163b1 (\"openvswitch: switch to per-action label counting\nin conntrack\"), which changed to use per-action label counting and\nincrement net->ct.labels_used when a flow with ct action is added.\n\nSince there’s no straightforward way to fully resolve this issue at the\nmoment, this reverts the commit to avoid breaking existing use cases.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21958" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1063ae07383c0ddc5bcce170260c143825846b03" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9e79fdabd52cfce1a021640a81256878a2c516a2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d91bfc64a4886102746e74d2c6f3a61e9a77fd7d" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-jxrr-3gxj-w229/GHSA-jxrr-3gxj-w229.json b/advisories/unreviewed/2025/04/GHSA-jxrr-3gxj-w229/GHSA-jxrr-3gxj-w229.json new file mode 100644 index 00000000000..77ba83bf498 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jxrr-3gxj-w229/GHSA-jxrr-3gxj-w229.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jxrr-3gxj-w229", + "modified": "2025-04-01T18:30:54Z", + "published": "2025-04-01T18:30:54Z", + "aliases": [ + "CVE-2025-21983" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/slab/kvfree_rcu: Switch to WQ_MEM_RECLAIM wq\n\nCurrently kvfree_rcu() APIs use a system workqueue which is\n\"system_unbound_wq\" to driver RCU machinery to reclaim a memory.\n\nRecently, it has been noted that the following kernel warning can\nbe observed:\n\n\nworkqueue: WQ_MEM_RECLAIM nvme-wq:nvme_scan_work is flushing !WQ_MEM_RECLAIM events_unbound:kfree_rcu_work\n WARNING: CPU: 21 PID: 330 at kernel/workqueue.c:3719 check_flush_dependency+0x112/0x120\n Modules linked in: intel_uncore_frequency(E) intel_uncore_frequency_common(E) skx_edac(E) ...\n CPU: 21 UID: 0 PID: 330 Comm: kworker/u144:6 Tainted: G E 6.13.2-0_g925d379822da #1\n Hardware name: Wiwynn Twin Lakes MP/Twin Lakes Passive MP, BIOS YMM20 02/01/2023\n Workqueue: nvme-wq nvme_scan_work\n RIP: 0010:check_flush_dependency+0x112/0x120\n Code: 05 9a 40 14 02 01 48 81 c6 c0 00 00 00 48 8b 50 18 48 81 c7 c0 00 00 00 48 89 f9 48 ...\n RSP: 0018:ffffc90000df7bd8 EFLAGS: 00010082\n RAX: 000000000000006a RBX: ffffffff81622390 RCX: 0000000000000027\n RDX: 00000000fffeffff RSI: 000000000057ffa8 RDI: ffff88907f960c88\n RBP: 0000000000000000 R08: ffffffff83068e50 R09: 000000000002fffd\n R10: 0000000000000004 R11: 0000000000000000 R12: ffff8881001a4400\n R13: 0000000000000000 R14: ffff88907f420fb8 R15: 0000000000000000\n FS: 0000000000000000(0000) GS:ffff88907f940000(0000) knlGS:0000000000000000\n CR2: 00007f60c3001000 CR3: 000000107d010005 CR4: 00000000007726f0\n PKRU: 55555554\n Call Trace:\n \n ? __warn+0xa4/0x140\n ? check_flush_dependency+0x112/0x120\n ? report_bug+0xe1/0x140\n ? check_flush_dependency+0x112/0x120\n ? handle_bug+0x5e/0x90\n ? exc_invalid_op+0x16/0x40\n ? asm_exc_invalid_op+0x16/0x20\n ? timer_recalc_next_expiry+0x190/0x190\n ? check_flush_dependency+0x112/0x120\n ? check_flush_dependency+0x112/0x120\n __flush_work.llvm.1643880146586177030+0x174/0x2c0\n flush_rcu_work+0x28/0x30\n kvfree_rcu_barrier+0x12f/0x160\n kmem_cache_destroy+0x18/0x120\n bioset_exit+0x10c/0x150\n disk_release.llvm.6740012984264378178+0x61/0xd0\n device_release+0x4f/0x90\n kobject_put+0x95/0x180\n nvme_put_ns+0x23/0xc0\n nvme_remove_invalid_namespaces+0xb3/0xd0\n nvme_scan_work+0x342/0x490\n process_scheduled_works+0x1a2/0x370\n worker_thread+0x2ff/0x390\n ? pwq_release_workfn+0x1e0/0x1e0\n kthread+0xb1/0xe0\n ? __kthread_parkme+0x70/0x70\n ret_from_fork+0x30/0x40\n ? __kthread_parkme+0x70/0x70\n ret_from_fork_asm+0x11/0x20\n \n ---[ end trace 0000000000000000 ]---\n\n\nTo address this switch to use of independent WQ_MEM_RECLAIM\nworkqueue, so the rules are not violated from workqueue framework\npoint of view.\n\nApart of that, since kvfree_rcu() does reclaim memory it is worth\nto go with WQ_MEM_RECLAIM type of wq because it is designed for\nthis purpose.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21983" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/656e35bf66a11e1adde44c4c12050086dc39f241" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a74979dce9e9c61f6d797c3761020252c4d8dc63" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/dfd3df31c9db752234d7d2e09bef2aeabb643ce4" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-jxxv-c48x-753p/GHSA-jxxv-c48x-753p.json b/advisories/unreviewed/2025/04/GHSA-jxxv-c48x-753p/GHSA-jxxv-c48x-753p.json new file mode 100644 index 00000000000..d32e03cbddf --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jxxv-c48x-753p/GHSA-jxxv-c48x-753p.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jxxv-c48x-753p", + "modified": "2025-04-01T18:30:53Z", + "published": "2025-04-01T18:30:52Z", + "aliases": [ + "CVE-2025-21948" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: appleir: Fix potential NULL dereference at raw event handle\n\nSyzkaller reports a NULL pointer dereference issue in input_event().\n\nBUG: KASAN: null-ptr-deref in instrument_atomic_read include/linux/instrumented.h:68 [inline]\nBUG: KASAN: null-ptr-deref in _test_bit include/asm-generic/bitops/instrumented-non-atomic.h:141 [inline]\nBUG: KASAN: null-ptr-deref in is_event_supported drivers/input/input.c:67 [inline]\nBUG: KASAN: null-ptr-deref in input_event+0x42/0xa0 drivers/input/input.c:395\nRead of size 8 at addr 0000000000000028 by task syz-executor199/2949\n\nCPU: 0 UID: 0 PID: 2949 Comm: syz-executor199 Not tainted 6.13.0-rc4-syzkaller-00076-gf097a36ef88d #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024\nCall Trace:\n \n __dump_stack lib/dump_stack.c:94 [inline]\n dump_stack_lvl+0x116/0x1f0 lib/dump_stack.c:120\n kasan_report+0xd9/0x110 mm/kasan/report.c:602\n check_region_inline mm/kasan/generic.c:183 [inline]\n kasan_check_range+0xef/0x1a0 mm/kasan/generic.c:189\n instrument_atomic_read include/linux/instrumented.h:68 [inline]\n _test_bit include/asm-generic/bitops/instrumented-non-atomic.h:141 [inline]\n is_event_supported drivers/input/input.c:67 [inline]\n input_event+0x42/0xa0 drivers/input/input.c:395\n input_report_key include/linux/input.h:439 [inline]\n key_down drivers/hid/hid-appleir.c:159 [inline]\n appleir_raw_event+0x3e5/0x5e0 drivers/hid/hid-appleir.c:232\n __hid_input_report.constprop.0+0x312/0x440 drivers/hid/hid-core.c:2111\n hid_ctrl+0x49f/0x550 drivers/hid/usbhid/hid-core.c:484\n __usb_hcd_giveback_urb+0x389/0x6e0 drivers/usb/core/hcd.c:1650\n usb_hcd_giveback_urb+0x396/0x450 drivers/usb/core/hcd.c:1734\n dummy_timer+0x17f7/0x3960 drivers/usb/gadget/udc/dummy_hcd.c:1993\n __run_hrtimer kernel/time/hrtimer.c:1739 [inline]\n __hrtimer_run_queues+0x20a/0xae0 kernel/time/hrtimer.c:1803\n hrtimer_run_softirq+0x17d/0x350 kernel/time/hrtimer.c:1820\n handle_softirqs+0x206/0x8d0 kernel/softirq.c:561\n __do_softirq kernel/softirq.c:595 [inline]\n invoke_softirq kernel/softirq.c:435 [inline]\n __irq_exit_rcu+0xfa/0x160 kernel/softirq.c:662\n irq_exit_rcu+0x9/0x30 kernel/softirq.c:678\n instr_sysvec_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1049 [inline]\n sysvec_apic_timer_interrupt+0x90/0xb0 arch/x86/kernel/apic/apic.c:1049\n \n \n asm_sysvec_apic_timer_interrupt+0x1a/0x20 arch/x86/include/asm/idtentry.h:702\n __mod_timer+0x8f6/0xdc0 kernel/time/timer.c:1185\n add_timer+0x62/0x90 kernel/time/timer.c:1295\n schedule_timeout+0x11f/0x280 kernel/time/sleep_timeout.c:98\n usbhid_wait_io+0x1c7/0x380 drivers/hid/usbhid/hid-core.c:645\n usbhid_init_reports+0x19f/0x390 drivers/hid/usbhid/hid-core.c:784\n hiddev_ioctl+0x1133/0x15b0 drivers/hid/usbhid/hiddev.c:794\n vfs_ioctl fs/ioctl.c:51 [inline]\n __do_sys_ioctl fs/ioctl.c:906 [inline]\n __se_sys_ioctl fs/ioctl.c:892 [inline]\n __x64_sys_ioctl+0x190/0x200 fs/ioctl.c:892\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xcd/0x250 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n \n\nThis happens due to the malformed report items sent by the emulated device\nwhich results in a report, that has no fields, being added to the report list.\nDue to this appleir_input_configured() is never called, hidinput_connect()\nfails which results in the HID_CLAIMED_INPUT flag is not being set. However,\nit does not make appleir_probe() fail and lets the event callback to be\ncalled without the associated input device.\n\nThus, add a check for the HID_CLAIMED_INPUT flag and leave the event hook\nearly if the driver didn't claim any input_dev for some reason. Moreover,\nsome other hid drivers accessing input_dev in their event callbacks do have\nsimilar checks, too.\n\nFound by Linux Verification Center (linuxtesting.org) with Syzkaller.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21948" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0df1ac8ee417ad76760ff076faa4518a4d861894" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2ff5baa9b5275e3acafdf7f2089f74cccb2f38d1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/68cdf6710f228dfd74f66ec61fbe636da2646a73" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6db423b00940b05df2a1265d3c7eabafe9f1734c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8d39eb8c5e14f2f0f441eed832ef8a7b654e6fee" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b1d95d733cd6e74f595653daddcfc357bea461e8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d335fce8b88b2353f4bb20c631698e20384e3610" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fc69e2c3219d433caabba4b5d6371ba726a4b37f" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-m27r-w8g9-3x9h/GHSA-m27r-w8g9-3x9h.json b/advisories/unreviewed/2025/04/GHSA-m27r-w8g9-3x9h/GHSA-m27r-w8g9-3x9h.json new file mode 100644 index 00000000000..7ef75d8ea4b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-m27r-w8g9-3x9h/GHSA-m27r-w8g9-3x9h.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m27r-w8g9-3x9h", + "modified": "2025-04-01T18:30:53Z", + "published": "2025-04-01T18:30:52Z", + "aliases": [ + "CVE-2025-21950" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrivers: virt: acrn: hsm: Use kzalloc to avoid info leak in pmcmd_ioctl\n\nIn the \"pmcmd_ioctl\" function, three memory objects allocated by\nkmalloc are initialized by \"hcall_get_cpu_state\", which are then\ncopied to user space. The initializer is indeed implemented in\n\"acrn_hypercall2\" (arch/x86/include/asm/acrn.h). There is a risk of\ninformation leakage due to uninitialized bytes.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21950" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1b8f7a2caa7f9cdfd135e3f78eb9d7e36fb95083" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4e15cf870d2c748e45d45ffc4d5b1dc1b7d50120" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/524f29d78c9bdeb49f31f5b0376a07d2fc5cf563" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/819cec1dc47cdeac8f5dd6ba81c1dbee2a68c3bb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a4c21b878f0e237f45209a324c903ea7fb05247d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d7e5031fe3f161c8eb5e84db1540bc4373ed861b" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-m5q5-9mr9-g93x/GHSA-m5q5-9mr9-g93x.json b/advisories/unreviewed/2025/04/GHSA-m5q5-9mr9-g93x/GHSA-m5q5-9mr9-g93x.json new file mode 100644 index 00000000000..3eb880c0cad --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-m5q5-9mr9-g93x/GHSA-m5q5-9mr9-g93x.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m5q5-9mr9-g93x", + "modified": "2025-04-01T18:30:54Z", + "published": "2025-04-01T18:30:54Z", + "aliases": [ + "CVE-2025-21970" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: Bridge, fix the crash caused by LAG state check\n\nWhen removing LAG device from bridge, NETDEV_CHANGEUPPER event is\ntriggered. Driver finds the lower devices (PFs) to flush all the\noffloaded entries. And mlx5_lag_is_shared_fdb is checked, it returns\nfalse if one of PF is unloaded. In such case,\nmlx5_esw_bridge_lag_rep_get() and its caller return NULL, instead of\nthe alive PF, and the flush is skipped.\n\nBesides, the bridge fdb entry's lastuse is updated in mlx5 bridge\nevent handler. But this SWITCHDEV_FDB_ADD_TO_BRIDGE event can be\nignored in this case because the upper interface for bond is deleted,\nand the entry will never be aged because lastuse is never updated.\n\nTo make things worse, as the entry is alive, mlx5 bridge workqueue\nkeeps sending that event, which is then handled by kernel bridge\nnotifier. It causes the following crash when accessing the passed bond\nnetdev which is already destroyed.\n\nTo fix this issue, remove such checks. LAG state is already checked in\ncommit 15f8f168952f (\"net/mlx5: Bridge, verify LAG state when adding\nbond to bridge\"), driver still need to skip offload if LAG becomes\ninvalid state after initialization.\n\n Oops: stack segment: 0000 [#1] SMP\n CPU: 3 UID: 0 PID: 23695 Comm: kworker/u40:3 Tainted: G OE 6.11.0_mlnx #1\n Tainted: [O]=OOT_MODULE, [E]=UNSIGNED_MODULE\n Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014\n Workqueue: mlx5_bridge_wq mlx5_esw_bridge_update_work [mlx5_core]\n RIP: 0010:br_switchdev_event+0x2c/0x110 [bridge]\n Code: 44 00 00 48 8b 02 48 f7 00 00 02 00 00 74 69 41 54 55 53 48 83 ec 08 48 8b a8 08 01 00 00 48 85 ed 74 4a 48 83 fe 02 48 89 d3 <4c> 8b 65 00 74 23 76 49 48 83 fe 05 74 7e 48 83 fe 06 75 2f 0f b7\n RSP: 0018:ffffc900092cfda0 EFLAGS: 00010297\n RAX: ffff888123bfe000 RBX: ffffc900092cfe08 RCX: 00000000ffffffff\n RDX: ffffc900092cfe08 RSI: 0000000000000001 RDI: ffffffffa0c585f0\n RBP: 6669746f6e690a30 R08: 0000000000000000 R09: ffff888123ae92c8\n R10: 0000000000000000 R11: fefefefefefefeff R12: ffff888123ae9c60\n R13: 0000000000000001 R14: ffffc900092cfe08 R15: 0000000000000000\n FS: 0000000000000000(0000) GS:ffff88852c980000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 00007f15914c8734 CR3: 0000000002830005 CR4: 0000000000770ef0\n DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n PKRU: 55555554\n Call Trace:\n \n ? __die_body+0x1a/0x60\n ? die+0x38/0x60\n ? do_trap+0x10b/0x120\n ? do_error_trap+0x64/0xa0\n ? exc_stack_segment+0x33/0x50\n ? asm_exc_stack_segment+0x22/0x30\n ? br_switchdev_event+0x2c/0x110 [bridge]\n ? sched_balance_newidle.isra.149+0x248/0x390\n notifier_call_chain+0x4b/0xa0\n atomic_notifier_call_chain+0x16/0x20\n mlx5_esw_bridge_update+0xec/0x170 [mlx5_core]\n mlx5_esw_bridge_update_work+0x19/0x40 [mlx5_core]\n process_scheduled_works+0x81/0x390\n worker_thread+0x106/0x250\n ? bh_worker+0x110/0x110\n kthread+0xb7/0xe0\n ? kthread_park+0x80/0x80\n ret_from_fork+0x2d/0x50\n ? kthread_park+0x80/0x80\n ret_from_fork_asm+0x11/0x20\n ", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21970" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4b8eeed4fb105770ce6dc84a2c6ef953c7b71cbb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5dd8bf6ab1d6db40f5d09603759fa88caec19e7f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/86ff45f5f61ae1d0d17f0f6d8797b052eacfd8f1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bd7e3a42800743a7748c83243e4cafc1b995d4c4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f7bf259a04271165ae667ad21cfc60c6413f25ca" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-m773-p743-chvm/GHSA-m773-p743-chvm.json b/advisories/unreviewed/2025/04/GHSA-m773-p743-chvm/GHSA-m773-p743-chvm.json index eb455b111f9..c601fcba2a5 100644 --- a/advisories/unreviewed/2025/04/GHSA-m773-p743-chvm/GHSA-m773-p743-chvm.json +++ b/advisories/unreviewed/2025/04/GHSA-m773-p743-chvm/GHSA-m773-p743-chvm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-m773-p743-chvm", - "modified": "2025-04-01T00:30:38Z", + "modified": "2025-04-01T18:30:47Z", "published": "2025-04-01T00:30:38Z", "aliases": [ "CVE-2025-24214" ], "details": "A privacy issue was addressed by not logging contents of text fields. This issue is fixed in visionOS 2.4, iOS 18.4 and iPadOS 18.4, tvOS 18.4, macOS Sequoia 15.4. An app may be able to access sensitive user data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:19Z" diff --git a/advisories/unreviewed/2025/04/GHSA-m7gq-vr78-836g/GHSA-m7gq-vr78-836g.json b/advisories/unreviewed/2025/04/GHSA-m7gq-vr78-836g/GHSA-m7gq-vr78-836g.json new file mode 100644 index 00000000000..6f6a621aa03 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-m7gq-vr78-836g/GHSA-m7gq-vr78-836g.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m7gq-vr78-836g", + "modified": "2025-04-01T18:30:49Z", + "published": "2025-04-01T18:30:49Z", + "aliases": [ + "CVE-2025-21894" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: enetc: VFs do not support HWTSTAMP_TX_ONESTEP_SYNC\n\nActually ENETC VFs do not support HWTSTAMP_TX_ONESTEP_SYNC because only\nENETC PF can access PMa_SINGLE_STEP registers. And there will be a crash\nif VFs are used to test one-step timestamp, the crash log as follows.\n\n[ 129.110909] Unable to handle kernel paging request at virtual address 00000000000080c0\n[ 129.287769] Call trace:\n[ 129.290219] enetc_port_mac_wr+0x30/0xec (P)\n[ 129.294504] enetc_start_xmit+0xda4/0xe74\n[ 129.298525] enetc_xmit+0x70/0xec\n[ 129.301848] dev_hard_start_xmit+0x98/0x118", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21894" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1748531839298ab7be682155f6cd98ae04773e6a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3d9634211121700568d0e3635ebdd5df06d20440" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8c393efd7420cc994864d059fcc6219bfd7cb840" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a562d0c4a893eae3ea51d512c4d90ab858a6b7ec" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-m7pp-g2rm-wrcq/GHSA-m7pp-g2rm-wrcq.json b/advisories/unreviewed/2025/04/GHSA-m7pp-g2rm-wrcq/GHSA-m7pp-g2rm-wrcq.json new file mode 100644 index 00000000000..706ec92a9bc --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-m7pp-g2rm-wrcq/GHSA-m7pp-g2rm-wrcq.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m7pp-g2rm-wrcq", + "modified": "2025-04-01T18:30:53Z", + "published": "2025-04-01T18:30:53Z", + "aliases": [ + "CVE-2025-21943" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ngpio: aggregator: protect driver attr handlers against module unload\n\nBoth new_device_store and delete_device_store touch module global\nresources (e.g. gpio_aggregator_lock). To prevent race conditions with\nmodule unload, a reference needs to be held.\n\nAdd try_module_get() in these handlers.\n\nFor new_device_store, this eliminates what appears to be the most dangerous\nscenario: if an id is allocated from gpio_aggregator_idr but\nplatform_device_register has not yet been called or completed, a concurrent\nmodule unload could fail to unregister/delete the device, leaving behind a\ndangling platform device/GPIO forwarder. This can result in various issues.\nThe following simple reproducer demonstrates these problems:\n\n #!/bin/bash\n while :; do\n # note: whether 'gpiochip0 0' exists or not does not matter.\n echo 'gpiochip0 0' > /sys/bus/platform/drivers/gpio-aggregator/new_device\n done &\n while :; do\n modprobe gpio-aggregator\n modprobe -r gpio-aggregator\n done &\n wait\n\n Starting with the following warning, several kinds of warnings will appear\n and the system may become unstable:\n\n ------------[ cut here ]------------\n list_del corruption, ffff888103e2e980->next is LIST_POISON1 (dead000000000100)\n WARNING: CPU: 1 PID: 1327 at lib/list_debug.c:56 __list_del_entry_valid_or_report+0xa3/0x120\n [...]\n RIP: 0010:__list_del_entry_valid_or_report+0xa3/0x120\n [...]\n Call Trace:\n \n ? __list_del_entry_valid_or_report+0xa3/0x120\n ? __warn.cold+0x93/0xf2\n ? __list_del_entry_valid_or_report+0xa3/0x120\n ? report_bug+0xe6/0x170\n ? __irq_work_queue_local+0x39/0xe0\n ? handle_bug+0x58/0x90\n ? exc_invalid_op+0x13/0x60\n ? asm_exc_invalid_op+0x16/0x20\n ? __list_del_entry_valid_or_report+0xa3/0x120\n gpiod_remove_lookup_table+0x22/0x60\n new_device_store+0x315/0x350 [gpio_aggregator]\n kernfs_fop_write_iter+0x137/0x1f0\n vfs_write+0x262/0x430\n ksys_write+0x60/0xd0\n do_syscall_64+0x6c/0x180\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n [...]\n \n ---[ end trace 0000000000000000 ]---", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21943" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/12f65d1203507f7db3ba59930fe29a3b8eee9945" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/56281a76b805b5ac61feb5d580139695a22f87f0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/807789018186cf508ceb3a1f8f02935cd195717b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8fb07fb1bba91d45846ed8605c3097fe67a7d54c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9334c88fc2fbc6836b307d269fcc1744c69701c0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d99dc8f7ea01ee1b21306e0eda8eb18a4af80db6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fd6aa1f8cbe0979eb66ac32ebc231bf0b10a2117" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-mg5c-fjcx-j5g5/GHSA-mg5c-fjcx-j5g5.json b/advisories/unreviewed/2025/04/GHSA-mg5c-fjcx-j5g5/GHSA-mg5c-fjcx-j5g5.json new file mode 100644 index 00000000000..f68f6973052 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-mg5c-fjcx-j5g5/GHSA-mg5c-fjcx-j5g5.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mg5c-fjcx-j5g5", + "modified": "2025-04-01T18:30:53Z", + "published": "2025-04-01T18:30:53Z", + "aliases": [ + "CVE-2025-21962" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncifs: Fix integer overflow while processing closetimeo mount option\n\nUser-provided mount parameter closetimeo of type u32 is intended to have\nan upper limit, but before it is validated, the value is converted from\nseconds to jiffies which can lead to an integer overflow.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21962" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1c46673be93dd2954f44fe370fb4f2b8e6214224" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6c13fcb7cf59ae65940da1dfea80144e42921e53" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9968fcf02cf6b0f78fbacf3f63e782162603855a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b24edd5c191c2689c59d0509f0903f9487eb6317" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d5a30fddfe2f2e540f6c43b59cf701809995faef" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-mp83-3fxr-m45v/GHSA-mp83-3fxr-m45v.json b/advisories/unreviewed/2025/04/GHSA-mp83-3fxr-m45v/GHSA-mp83-3fxr-m45v.json new file mode 100644 index 00000000000..843a90b084e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-mp83-3fxr-m45v/GHSA-mp83-3fxr-m45v.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mp83-3fxr-m45v", + "modified": "2025-04-01T18:30:53Z", + "published": "2025-04-01T18:30:53Z", + "aliases": [ + "CVE-2025-21964" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncifs: Fix integer overflow while processing acregmax mount option\n\nUser-provided mount parameter acregmax of type u32 is intended to have\nan upper limit, but before it is validated, the value is converted from\nseconds to jiffies which can lead to an integer overflow.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21964" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0252c33cc943e9e48ddfafaa6b1eb72adb68a099" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5f500874ab9b3cc8c169c2ab49f00b838520b9c5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7489161b1852390b4413d57f2457cd40b34da6cc" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/833f2903eb8b70faca7967319e580e9ce69729fc" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/dd190168e60ac15408f074a1fe0ce36aff34027b" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-mq3v-g8q8-f78r/GHSA-mq3v-g8q8-f78r.json b/advisories/unreviewed/2025/04/GHSA-mq3v-g8q8-f78r/GHSA-mq3v-g8q8-f78r.json new file mode 100644 index 00000000000..ada81448744 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-mq3v-g8q8-f78r/GHSA-mq3v-g8q8-f78r.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mq3v-g8q8-f78r", + "modified": "2025-04-01T18:30:53Z", + "published": "2025-04-01T18:30:53Z", + "aliases": [ + "CVE-2025-21956" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Assign normalized_pix_clk when color depth = 14\n\n[WHY & HOW]\nA warning message \"WARNING: CPU: 4 PID: 459 at ... /dc_resource.c:3397\ncalculate_phy_pix_clks+0xef/0x100 [amdgpu]\" occurs because the\ndisplay_color_depth == COLOR_DEPTH_141414 is not handled. This is\nobserved in Radeon RX 6600 XT.\n\nIt is fixed by assigning pix_clk * (14 * 3) / 24 - same as the rests.\n\nAlso fixes the indentation in get_norm_pix_clk.\n\n(cherry picked from commit 274a87eb389f58eddcbc5659ab0b180b37e92775)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21956" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/04f90b505ad3a6eed474bbaa03167095fef5203a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/27df30106690969f7d63604f0d49ed8e9bffa2cb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/79e31396fdd7037c503e6add15af7cb00633ea92" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a8f77e1658d78e4a8bb227a83bcee67de97f7634" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/dc831b38680c47d07e425871a9852109183895cf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-mw8g-4mvm-gj4f/GHSA-mw8g-4mvm-gj4f.json b/advisories/unreviewed/2025/04/GHSA-mw8g-4mvm-gj4f/GHSA-mw8g-4mvm-gj4f.json new file mode 100644 index 00000000000..28dc06d0a58 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-mw8g-4mvm-gj4f/GHSA-mw8g-4mvm-gj4f.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mw8g-4mvm-gj4f", + "modified": "2025-04-01T18:30:54Z", + "published": "2025-04-01T18:30:54Z", + "aliases": [ + "CVE-2025-21984" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm: fix kernel BUG when userfaultfd_move encounters swapcache\n\nuserfaultfd_move() checks whether the PTE entry is present or a\nswap entry.\n\n- If the PTE entry is present, move_present_pte() handles folio\n migration by setting:\n\n src_folio->index = linear_page_index(dst_vma, dst_addr);\n\n- If the PTE entry is a swap entry, move_swap_pte() simply copies\n the PTE to the new dst_addr.\n\nThis approach is incorrect because, even if the PTE is a swap entry,\nit can still reference a folio that remains in the swap cache.\n\nThis creates a race window between steps 2 and 4.\n 1. add_to_swap: The folio is added to the swapcache.\n 2. try_to_unmap: PTEs are converted to swap entries.\n 3. pageout: The folio is written back.\n 4. Swapcache is cleared.\nIf userfaultfd_move() occurs in the window between steps 2 and 4,\nafter the swap PTE has been moved to the destination, accessing the\ndestination triggers do_swap_page(), which may locate the folio in\nthe swapcache. However, since the folio's index has not been updated\nto match the destination VMA, do_swap_page() will detect a mismatch.\n\nThis can result in two critical issues depending on the system\nconfiguration.\n\nIf KSM is disabled, both small and large folios can trigger a BUG\nduring the add_rmap operation due to:\n\n page_pgoff(folio, page) != linear_page_index(vma, address)\n\n[ 13.336953] page: refcount:6 mapcount:1 mapping:00000000f43db19c index:0xffffaf150 pfn:0x4667c\n[ 13.337520] head: order:2 mapcount:1 entire_mapcount:0 nr_pages_mapped:1 pincount:0\n[ 13.337716] memcg:ffff00000405f000\n[ 13.337849] anon flags: 0x3fffc0000020459(locked|uptodate|dirty|owner_priv_1|head|swapbacked|node=0|zone=0|lastcpupid=0xffff)\n[ 13.338630] raw: 03fffc0000020459 ffff80008507b538 ffff80008507b538 ffff000006260361\n[ 13.338831] raw: 0000000ffffaf150 0000000000004000 0000000600000000 ffff00000405f000\n[ 13.339031] head: 03fffc0000020459 ffff80008507b538 ffff80008507b538 ffff000006260361\n[ 13.339204] head: 0000000ffffaf150 0000000000004000 0000000600000000 ffff00000405f000\n[ 13.339375] head: 03fffc0000000202 fffffdffc0199f01 ffffffff00000000 0000000000000001\n[ 13.339546] head: 0000000000000004 0000000000000000 00000000ffffffff 0000000000000000\n[ 13.339736] page dumped because: VM_BUG_ON_PAGE(page_pgoff(folio, page) != linear_page_index(vma, address))\n[ 13.340190] ------------[ cut here ]------------\n[ 13.340316] kernel BUG at mm/rmap.c:1380!\n[ 13.340683] Internal error: Oops - BUG: 00000000f2000800 [#1] PREEMPT SMP\n[ 13.340969] Modules linked in:\n[ 13.341257] CPU: 1 UID: 0 PID: 107 Comm: a.out Not tainted 6.14.0-rc3-gcf42737e247a-dirty #299\n[ 13.341470] Hardware name: linux,dummy-virt (DT)\n[ 13.341671] pstate: 60000005 (nZCv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n[ 13.341815] pc : __page_check_anon_rmap+0xa0/0xb0\n[ 13.341920] lr : __page_check_anon_rmap+0xa0/0xb0\n[ 13.342018] sp : ffff80008752bb20\n[ 13.342093] x29: ffff80008752bb20 x28: fffffdffc0199f00 x27: 0000000000000001\n[ 13.342404] x26: 0000000000000000 x25: 0000000000000001 x24: 0000000000000001\n[ 13.342575] x23: 0000ffffaf0d0000 x22: 0000ffffaf0d0000 x21: fffffdffc0199f00\n[ 13.342731] x20: fffffdffc0199f00 x19: ffff000006210700 x18: 00000000ffffffff\n[ 13.342881] x17: 6c203d2120296567 x16: 6170202c6f696c6f x15: 662866666f67705f\n[ 13.343033] x14: 6567617028454741 x13: 2929737365726464 x12: ffff800083728ab0\n[ 13.343183] x11: ffff800082996bf8 x10: 0000000000000fd7 x9 : ffff80008011bc40\n[ 13.343351] x8 : 0000000000017fe8 x7 : 00000000fffff000 x6 : ffff8000829eebf8\n[ 13.343498] x5 : c0000000fffff000 x4 : 0000000000000000 x3 : 0000000000000000\n[ 13.343645] x2 : 0000000000000000 x1 : ffff0000062db980 x0 : 000000000000005f\n[ 13.343876] Call trace:\n[ 13.344045] __page_check_anon_rmap+0xa0/0xb0 (P)\n[ 13.344234] folio_add_anon_rmap_ptes+0x22c/0x320\n[ 13.344333] do_swap_page+0x1060/0x1400\n[ 13.344417] __handl\n---truncated---", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21984" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4e9507246298fd6f1ca7bb42ef01a6e34fb93684" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b1e11bd86c0943bb7624efebdc384340a50ad683" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c50f8e6053b0503375c2975bf47f182445aebb4c" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-mwfv-f593-4f6x/GHSA-mwfv-f593-4f6x.json b/advisories/unreviewed/2025/04/GHSA-mwfv-f593-4f6x/GHSA-mwfv-f593-4f6x.json new file mode 100644 index 00000000000..e3c85763b18 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-mwfv-f593-4f6x/GHSA-mwfv-f593-4f6x.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mwfv-f593-4f6x", + "modified": "2025-04-01T18:30:55Z", + "published": "2025-04-01T18:30:54Z", + "aliases": [ + "CVE-2025-21980" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsched: address a potential NULL pointer dereference in the GRED scheduler.\n\nIf kzalloc in gred_init returns a NULL pointer, the code follows the\nerror handling path, invoking gred_destroy. This, in turn, calls\ngred_offload, where memset could receive a NULL pointer as input,\npotentially leading to a kernel crash.\n\nWhen table->opt is NULL in gred_init(), gred_change_table_def()\nis not called yet, so it is not necessary to call ->ndo_setup_tc()\nin gred_offload().", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21980" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0f0a152957d64ce45b4c27c687e7d087e8f45079" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/115ef44a98220fddfab37a39a19370497cd718b9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5f996b4f80c2cef1f9c77275055e7fcba44c9199" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/68896dd50180b38ea552e49a6a00b685321e5769" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d02c9acd68950a444acda18d514e2b41f846cb7f" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-p2c4-6w6j-w378/GHSA-p2c4-6w6j-w378.json b/advisories/unreviewed/2025/04/GHSA-p2c4-6w6j-w378/GHSA-p2c4-6w6j-w378.json new file mode 100644 index 00000000000..4281a99bd01 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-p2c4-6w6j-w378/GHSA-p2c4-6w6j-w378.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p2c4-6w6j-w378", + "modified": "2025-04-01T18:30:53Z", + "published": "2025-04-01T18:30:53Z", + "aliases": [ + "CVE-2025-21955" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: prevent connection release during oplock break notification\n\nksmbd_work could be freed when after connection release.\nIncrement r_count of ksmbd_conn to indicate that requests\nare not finished yet and to not release the connection.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21955" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/09aeab68033161cb54f194da93e51a11aee6144b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3aa660c059240e0c795217182cf7df32909dd917" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a4261bbc33fbf99b99c80aa3a2c5097611802980" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f17d1c63a76b0fe8e9c78023a86507a3a6d62cfa" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-p2xq-87xh-464r/GHSA-p2xq-87xh-464r.json b/advisories/unreviewed/2025/04/GHSA-p2xq-87xh-464r/GHSA-p2xq-87xh-464r.json new file mode 100644 index 00000000000..34203d66db6 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-p2xq-87xh-464r/GHSA-p2xq-87xh-464r.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p2xq-87xh-464r", + "modified": "2025-04-01T18:30:52Z", + "published": "2025-04-01T18:30:52Z", + "aliases": [ + "CVE-2025-21934" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nrapidio: fix an API misues when rio_add_net() fails\n\nrio_add_net() calls device_register() and fails when device_register()\nfails. Thus, put_device() should be used rather than kfree(). Add\n\"mport->net = NULL;\" to avoid a use after free issue.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21934" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/22e4977141dfc6d109bf29b495bf2187b4250990" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2537f01d57f08c527e40bbb5862aa6ff43344898" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/88ddad53e4cfb6de861c6d4fb7b25427f46baed5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a5f5e520e8fbc6294020ff8afa36f684d92c6e6a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b2ef51c74b0171fde7eb69b6152d3d2f743ef269" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cdd9f58f7fe41a55fae4305ea51fc234769fd466" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d4ec862ce80f64db923a1d942b5d11cf6fc87d36" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f0aa4ee1cbbf7789907e5a3f6810de01c146c211" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-p3jf-39f4-gqr8/GHSA-p3jf-39f4-gqr8.json b/advisories/unreviewed/2025/04/GHSA-p3jf-39f4-gqr8/GHSA-p3jf-39f4-gqr8.json new file mode 100644 index 00000000000..302a7fe9f75 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-p3jf-39f4-gqr8/GHSA-p3jf-39f4-gqr8.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p3jf-39f4-gqr8", + "modified": "2025-04-01T18:30:54Z", + "published": "2025-04-01T18:30:53Z", + "aliases": [ + "CVE-2025-21967" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix use-after-free in ksmbd_free_work_struct\n\n->interim_entry of ksmbd_work could be deleted after oplock is freed.\nWe don't need to manage it with linked list. The interim request could be\nimmediately sent whenever a oplock break wait is needed.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21967" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/62746ae3f5414244a96293e3b017be637b641280" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bb39ed47065455604729404729d9116868638d31" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/eb51f6f59d19b92f6fe84d3873f958495ab32f0a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fb776765bfc21d5e4ed03bb3d4406c2b86ff1ac3" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-p4qc-cp8p-44wh/GHSA-p4qc-cp8p-44wh.json b/advisories/unreviewed/2025/04/GHSA-p4qc-cp8p-44wh/GHSA-p4qc-cp8p-44wh.json new file mode 100644 index 00000000000..a2824c32342 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-p4qc-cp8p-44wh/GHSA-p4qc-cp8p-44wh.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p4qc-cp8p-44wh", + "modified": "2025-04-01T18:30:51Z", + "published": "2025-04-01T18:30:51Z", + "aliases": [ + "CVE-2025-21927" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnvme-tcp: fix potential memory corruption in nvme_tcp_recv_pdu()\n\nnvme_tcp_recv_pdu() doesn't check the validity of the header length.\nWhen header digests are enabled, a target might send a packet with an\ninvalid header length (e.g. 255), causing nvme_tcp_verify_hdgst()\nto access memory outside the allocated area and cause memory corruptions\nby overwriting it with the calculated digest.\n\nFix this by rejecting packets with an unexpected header length.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21927" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/22b06c89aa6b2d1ecb8aea72edfb9d53af8d5126" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9fbc953d6b38bc824392e01850f0aeee3b348722" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ad95bab0cd28ed77c2c0d0b6e76e03e031391064" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-p5qx-8g2f-7jgh/GHSA-p5qx-8g2f-7jgh.json b/advisories/unreviewed/2025/04/GHSA-p5qx-8g2f-7jgh/GHSA-p5qx-8g2f-7jgh.json new file mode 100644 index 00000000000..939d67c8f69 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-p5qx-8g2f-7jgh/GHSA-p5qx-8g2f-7jgh.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p5qx-8g2f-7jgh", + "modified": "2025-04-01T18:30:50Z", + "published": "2025-04-01T18:30:50Z", + "aliases": [ + "CVE-2025-21903" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmctp i3c: handle NULL header address\n\ndaddr can be NULL if there is no neighbour table entry present,\nin that case the tx packet should be dropped.\n\nsaddr will usually be set by MCTP core, but check for NULL in case a\npacket is transmitted by a different protocol.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21903" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/740bf9c9b715cc327d34b1e2d4ee79fcd4c47a56" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cf7ee25e70c6edfac4553d6b671e8b19db1d9573" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d8be54c35aee29d96d1350b1b6f153be4da37c07" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-p79h-jcrm-6qrc/GHSA-p79h-jcrm-6qrc.json b/advisories/unreviewed/2025/04/GHSA-p79h-jcrm-6qrc/GHSA-p79h-jcrm-6qrc.json new file mode 100644 index 00000000000..161c2e698ca --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-p79h-jcrm-6qrc/GHSA-p79h-jcrm-6qrc.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p79h-jcrm-6qrc", + "modified": "2025-04-01T18:30:51Z", + "published": "2025-04-01T18:30:51Z", + "aliases": [ + "CVE-2025-21920" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nvlan: enforce underlying device type\n\nCurrently, VLAN devices can be created on top of non-ethernet devices.\n\nBesides the fact that it doesn't make much sense, this also causes a\nbug which leaks the address of a kernel function to usermode.\n\nWhen creating a VLAN device, we initialize GARP (garp_init_applicant)\nand MRP (mrp_init_applicant) for the underlying device.\n\nAs part of the initialization process, we add the multicast address of\neach applicant to the underlying device, by calling dev_mc_add.\n\n__dev_mc_add uses dev->addr_len to determine the length of the new\nmulticast address.\n\nThis causes an out-of-bounds read if dev->addr_len is greater than 6,\nsince the multicast addresses provided by GARP and MRP are only 6\nbytes long.\n\nThis behaviour can be reproduced using the following commands:\n\nip tunnel add gretest mode ip6gre local ::1 remote ::2 dev lo\nip l set up dev gretest\nip link add link gretest name vlantest type vlan id 100\n\nThen, the following command will display the address of garp_pdu_rcv:\n\nip maddr show | grep 01:80:c2:00:00:21\n\nFix the bug by enforcing the type of the underlying device during VLAN\ndevice initialization.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21920" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0fb7aa04c19eac4417f360a9f7611a60637bdacc" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/30e8aee77899173a82ae5ed89f536c096f20aaeb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3561442599804905c3defca241787cd4546e99a7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5a515d13e15536e82c5c7c83eb6cf5bc4827fee5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7f1564b2b2072b7aa1ac75350e9560a07c7a44fd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b33a534610067ade2bdaf2052900aaad99701353" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b6c72479748b7ea09f53ed64b223cee6463dc278" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fa40ebef69234e39ec2d26930d045f2fb9a8cb2b" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-p8mv-7r9h-cfvf/GHSA-p8mv-7r9h-cfvf.json b/advisories/unreviewed/2025/04/GHSA-p8mv-7r9h-cfvf/GHSA-p8mv-7r9h-cfvf.json new file mode 100644 index 00000000000..27aadc8b87e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-p8mv-7r9h-cfvf/GHSA-p8mv-7r9h-cfvf.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p8mv-7r9h-cfvf", + "modified": "2025-04-01T18:30:53Z", + "published": "2025-04-01T18:30:53Z", + "aliases": [ + "CVE-2025-21952" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: corsair-void: Update power supply values with a unified work handler\n\ncorsair_void_process_receiver can be called from an interrupt context,\nlocking battery_mutex in it was causing a kernel panic.\nFix it by moving the critical section into its own work, sharing this\nwork with battery_add_work and battery_remove_work to remove the need\nfor any locking", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21952" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0c28e4d1e10d2aae608094620bb386e6fd73d55e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/de19c9dfb68f7c5791accc89047f92e952f57996" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-pf4f-8wpm-5vh2/GHSA-pf4f-8wpm-5vh2.json b/advisories/unreviewed/2025/04/GHSA-pf4f-8wpm-5vh2/GHSA-pf4f-8wpm-5vh2.json new file mode 100644 index 00000000000..b90ecbddd2e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-pf4f-8wpm-5vh2/GHSA-pf4f-8wpm-5vh2.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pf4f-8wpm-5vh2", + "modified": "2025-04-01T18:30:53Z", + "published": "2025-04-01T18:30:52Z", + "aliases": [ + "CVE-2025-21951" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbus: mhi: host: pci_generic: Use pci_try_reset_function() to avoid deadlock\n\nThere are multiple places from where the recovery work gets scheduled\nasynchronously. Also, there are multiple places where the caller waits\nsynchronously for the recovery to be completed. One such place is during\nthe PM shutdown() callback.\n\nIf the device is not alive during recovery_work, it will try to reset the\ndevice using pci_reset_function(). This function internally will take the\ndevice_lock() first before resetting the device. By this time, if the lock\nhas already been acquired, then recovery_work will get stalled while\nwaiting for the lock. And if the lock was already acquired by the caller\nwhich waits for the recovery_work to be completed, it will lead to\ndeadlock.\n\nThis is what happened on the X1E80100 CRD device when the device died\nbefore shutdown() callback. Driver core calls the driver's shutdown()\ncallback while holding the device_lock() leading to deadlock.\n\nAnd this deadlock scenario can occur on other paths as well, like during\nthe PM suspend() callback, where the driver core would hold the\ndevice_lock() before calling driver's suspend() callback. And if the\nrecovery_work was already started, it could lead to deadlock. This is also\nobserved on the X1E80100 CRD.\n\nSo to fix both issues, use pci_try_reset_function() in recovery_work. This\nfunction first checks for the availability of the device_lock() before\ntrying to reset the device. If the lock is available, it will acquire it\nand reset the device. Otherwise, it will return -EAGAIN. If that happens,\nrecovery_work will fail with the error message \"Recovery failed\" as not\nmuch could be done.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21951" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1f9eb7078bc6b5fb5cbfbcb37c4bc01685332b95" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/62505657475c245c9cd46e42ac01026d1e61f027" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7746f3bb8917fccb4571a576f3837d80fc513054" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7a5ffadd54fe2662f5c99cdccf30144d060376f7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/985d3cf56d8745ca637deee273929e01df449f85" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a321d163de3d8aa38a6449ab2becf4b1581aed96" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-pm2v-rvr8-mpff/GHSA-pm2v-rvr8-mpff.json b/advisories/unreviewed/2025/04/GHSA-pm2v-rvr8-mpff/GHSA-pm2v-rvr8-mpff.json new file mode 100644 index 00000000000..ce8dcc60552 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-pm2v-rvr8-mpff/GHSA-pm2v-rvr8-mpff.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pm2v-rvr8-mpff", + "modified": "2025-04-01T18:30:52Z", + "published": "2025-04-01T18:30:51Z", + "aliases": [ + "CVE-2025-21930" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: iwlwifi: mvm: don't try to talk to a dead firmware\n\nThis fixes:\n\n bad state = 0\n WARNING: CPU: 10 PID: 702 at drivers/net/wireless/inel/iwlwifi/iwl-trans.c:178 iwl_trans_send_cmd+0xba/0xe0 [iwlwifi]\n Call Trace:\n \n ? __warn+0xca/0x1c0\n ? iwl_trans_send_cmd+0xba/0xe0 [iwlwifi 64fa9ad799a0e0d2ba53d4af93a53ad9a531f8d4]\n iwl_fw_dbg_clear_monitor_buf+0xd7/0x110 [iwlwifi 64fa9ad799a0e0d2ba53d4af93a53ad9a531f8d4]\n _iwl_dbgfs_fw_dbg_clear_write+0xe2/0x120 [iwlmvm 0e8adb18cea92d2c341766bcc10b18699290068a]\n\nAsk whether the firmware is alive before sending a command.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21930" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/437e93ecd40754f9e938d524daf52a10c589e2d4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d73d2c6e3313f0ba60711ab4f4b9044eddca9ca5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e7c31a3f4f27d61b9ccd894a7bf4690f137da0ec" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-q5wj-cxq5-m47h/GHSA-q5wj-cxq5-m47h.json b/advisories/unreviewed/2025/04/GHSA-q5wj-cxq5-m47h/GHSA-q5wj-cxq5-m47h.json new file mode 100644 index 00000000000..7fa91a0d4ec --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-q5wj-cxq5-m47h/GHSA-q5wj-cxq5-m47h.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q5wj-cxq5-m47h", + "modified": "2025-04-01T18:30:52Z", + "published": "2025-04-01T18:30:52Z", + "aliases": [ + "CVE-2025-21933" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\narm: pgtable: fix NULL pointer dereference issue\n\nWhen update_mmu_cache_range() is called by update_mmu_cache(), the vmf\nparameter is NULL, which will cause a NULL pointer dereference issue in\nadjust_pte():\n\nUnable to handle kernel NULL pointer dereference at virtual address 00000030 when read\nHardware name: Atmel AT91SAM9\nPC is at update_mmu_cache_range+0x1e0/0x278\nLR is at pte_offset_map_rw_nolock+0x18/0x2c\nCall trace:\n update_mmu_cache_range from remove_migration_pte+0x29c/0x2ec\n remove_migration_pte from rmap_walk_file+0xcc/0x130\n rmap_walk_file from remove_migration_ptes+0x90/0xa4\n remove_migration_ptes from migrate_pages_batch+0x6d4/0x858\n migrate_pages_batch from migrate_pages+0x188/0x488\n migrate_pages from compact_zone+0x56c/0x954\n compact_zone from compact_node+0x90/0xf0\n compact_node from kcompactd+0x1d4/0x204\n kcompactd from kthread+0x120/0x12c\n kthread from ret_from_fork+0x14/0x38\nException stack(0xc0d8bfb0 to 0xc0d8bff8)\n\nTo fix it, do not rely on whether 'ptl' is equal to decide whether to hold\nthe pte lock, but decide it by whether CONFIG_SPLIT_PTE_PTLOCKS is\nenabled. In addition, if two vmas map to the same PTE page, there is no\nneed to hold the pte lock again, otherwise a deadlock will occur. Just\nadd the need_lock parameter to let adjust_pte() know this information.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21933" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/91d011efe30aedde067ce6d218d521cf99b162e5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a564ccfe300fa6a065beda06ab7f3c140d6b4d63" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-q6h7-hvhw-m2p9/GHSA-q6h7-hvhw-m2p9.json b/advisories/unreviewed/2025/04/GHSA-q6h7-hvhw-m2p9/GHSA-q6h7-hvhw-m2p9.json new file mode 100644 index 00000000000..5f673efd9a1 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-q6h7-hvhw-m2p9/GHSA-q6h7-hvhw-m2p9.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q6h7-hvhw-m2p9", + "modified": "2025-04-01T18:30:51Z", + "published": "2025-04-01T18:30:51Z", + "aliases": [ + "CVE-2025-21916" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: atm: cxacru: fix a flaw in existing endpoint checks\n\nSyzbot once again identified a flaw in usb endpoint checking, see [1].\nThis time the issue stems from a commit authored by me (2eabb655a968\n(\"usb: atm: cxacru: fix endpoint checking in cxacru_bind()\")).\n\nWhile using usb_find_common_endpoints() may usually be enough to\ndiscard devices with wrong endpoints, in this case one needs more\nthan just finding and identifying the sufficient number of endpoints\nof correct types - one needs to check the endpoint's address as well.\n\nSince cxacru_bind() fills URBs with CXACRU_EP_CMD address in mind,\nswitch the endpoint verification approach to usb_check_XXX_endpoints()\ninstead to fix incomplete ep testing.\n\n[1] Syzbot report:\nusb 5-1: BOGUS urb xfer, pipe 3 != type 1\nWARNING: CPU: 0 PID: 1378 at drivers/usb/core/urb.c:504 usb_submit_urb+0xc4e/0x18c0 drivers/usb/core/urb.c:503\n...\nRIP: 0010:usb_submit_urb+0xc4e/0x18c0 drivers/usb/core/urb.c:503\n...\nCall Trace:\n \n cxacru_cm+0x3c8/0xe50 drivers/usb/atm/cxacru.c:649\n cxacru_card_status drivers/usb/atm/cxacru.c:760 [inline]\n cxacru_bind+0xcf9/0x1150 drivers/usb/atm/cxacru.c:1223\n usbatm_usb_probe+0x314/0x1d30 drivers/usb/atm/usbatm.c:1058\n cxacru_usb_probe+0x184/0x220 drivers/usb/atm/cxacru.c:1377\n usb_probe_interface+0x641/0xbb0 drivers/usb/core/driver.c:396\n really_probe+0x2b9/0xad0 drivers/base/dd.c:658\n __driver_probe_device+0x1a2/0x390 drivers/base/dd.c:800\n driver_probe_device+0x50/0x430 drivers/base/dd.c:830\n...", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21916" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/197e78076c5ecd895f109158c4ea2954b9919af6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/319529e0356bd904528c64647725a2272d297c83" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/903b80c21458bb1e34c3a78c5fdc553821e357f8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a0475a885d69849b1ade38add6d64338dfa83a8f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bf4409f84023b52b5e9b36c0a071a121eee42138" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c90aad369899a607cfbc002bebeafd51e31900cd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cfc295f7cccf66cbd5123416bcf1bee2e1bd37de" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/dcd592ab9dd8a2bfc36e75583b9006db2a77ec24" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-q86w-66m5-qpj3/GHSA-q86w-66m5-qpj3.json b/advisories/unreviewed/2025/04/GHSA-q86w-66m5-qpj3/GHSA-q86w-66m5-qpj3.json new file mode 100644 index 00000000000..29c74fe1fdb --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-q86w-66m5-qpj3/GHSA-q86w-66m5-qpj3.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q86w-66m5-qpj3", + "modified": "2025-04-01T18:30:52Z", + "published": "2025-04-01T18:30:52Z", + "aliases": [ + "CVE-2025-21944" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix bug on trap in smb2_lock\n\nIf lock count is greater than 1, flags could be old value.\nIt should be checked with flags of smb_lock, not flags.\nIt will cause bug-on trap from locks_free_lock in error handling\nroutine.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21944" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/11e0e74e14f1832a95092f2c98ed3b99f57797ee" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2b70e3ac79eacbdf32571f7af48dd81cdd957ca8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8994f0ce8259f812b4f4a681d8298c6ff682efaa" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/dbcd7fdd86f77529210fe8978154a81cd479844c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e26e2d2e15daf1ab33e0135caf2304a0cfa2744b" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qc6x-3767-556f/GHSA-qc6x-3767-556f.json b/advisories/unreviewed/2025/04/GHSA-qc6x-3767-556f/GHSA-qc6x-3767-556f.json new file mode 100644 index 00000000000..f41023958b8 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qc6x-3767-556f/GHSA-qc6x-3767-556f.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qc6x-3767-556f", + "modified": "2025-04-01T18:30:51Z", + "published": "2025-04-01T18:30:51Z", + "aliases": [ + "CVE-2025-21921" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ethtool: netlink: Allow NULL nlattrs when getting a phy_device\n\nethnl_req_get_phydev() is used to lookup a phy_device, in the case an\nethtool netlink command targets a specific phydev within a netdev's\ntopology.\n\nIt takes as a parameter a const struct nlattr *header that's used for\nerror handling :\n\n if (!phydev) {\n NL_SET_ERR_MSG_ATTR(extack, header,\n \"no phy matching phyindex\");\n return ERR_PTR(-ENODEV);\n }\n\nIn the notify path after a ->set operation however, there's no request\nattributes available.\n\nThe typical callsite for the above function looks like:\n\n\tphydev = ethnl_req_get_phydev(req_base, tb[ETHTOOL_A_XXX_HEADER],\n\t\t\t\t info->extack);\n\nSo, when tb is NULL (such as in the ethnl notify path), we have a nice\ncrash.\n\nIt turns out that there's only the PLCA command that is in that case, as\nthe other phydev-specific commands don't have a notification.\n\nThis commit fixes the crash by passing the cmd index and the nlattr\narray separately, allowing NULL-checking it directly inside the helper.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21921" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1f458fa42c29144cef280e05bc49fc21b873d897" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/637399bf7e77797811adf340090b561a8f9d1213" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/639c70352958735addbba5ae7dd65985da96e061" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qf9h-wvgw-cqh6/GHSA-qf9h-wvgw-cqh6.json b/advisories/unreviewed/2025/04/GHSA-qf9h-wvgw-cqh6/GHSA-qf9h-wvgw-cqh6.json new file mode 100644 index 00000000000..e34065203f0 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qf9h-wvgw-cqh6/GHSA-qf9h-wvgw-cqh6.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qf9h-wvgw-cqh6", + "modified": "2025-04-01T18:30:52Z", + "published": "2025-04-01T18:30:52Z", + "aliases": [ + "CVE-2025-21941" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Fix null check for pipe_ctx->plane_state in resource_build_scaling_params\n\nNull pointer dereference issue could occur when pipe_ctx->plane_state\nis null. The fix adds a check to ensure 'pipe_ctx->plane_state' is not\nnull before accessing. This prevents a null pointer dereference.\n\nFound by code review.\n\n(cherry picked from commit 63e6a77ccf239337baa9b1e7787cde9fa0462092)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21941" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3748fad09d89e9a5290e1738fd6872a79f794743" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/374c9faac5a763a05bc3f68ad9f73dab3c6aec90" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3b3c2be58d5275aa59d8b4810a59f173f2f5bac1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c1e54752dc12e90305eb0475ca908f42f5b369ca" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e0345c3478f185ca840daac7f08a1fcd4ebec3e9" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qhr5-5m4q-73p8/GHSA-qhr5-5m4q-73p8.json b/advisories/unreviewed/2025/04/GHSA-qhr5-5m4q-73p8/GHSA-qhr5-5m4q-73p8.json new file mode 100644 index 00000000000..91d0af596eb --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qhr5-5m4q-73p8/GHSA-qhr5-5m4q-73p8.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qhr5-5m4q-73p8", + "modified": "2025-04-01T18:30:52Z", + "published": "2025-04-01T18:30:52Z", + "aliases": [ + "CVE-2025-21949" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nLoongArch: Set hugetlb mmap base address aligned with pmd size\n\nWith ltp test case \"testcases/bin/hugefork02\", there is a dmesg error\nreport message such as:\n\n kernel BUG at mm/hugetlb.c:5550!\n Oops - BUG[#1]:\n CPU: 0 UID: 0 PID: 1517 Comm: hugefork02 Not tainted 6.14.0-rc2+ #241\n Hardware name: QEMU QEMU Virtual Machine, BIOS unknown 2/2/2022\n pc 90000000004eaf1c ra 9000000000485538 tp 900000010edbc000 sp 900000010edbf940\n a0 900000010edbfb00 a1 9000000108d20280 a2 00007fffe9474000 a3 00007ffff3474000\n a4 0000000000000000 a5 0000000000000003 a6 00000000003cadd3 a7 0000000000000000\n t0 0000000001ffffff t1 0000000001474000 t2 900000010ecd7900 t3 00007fffe9474000\n t4 00007fffe9474000 t5 0000000000000040 t6 900000010edbfb00 t7 0000000000000001\n t8 0000000000000005 u0 90000000004849d0 s9 900000010edbfa00 s0 9000000108d20280\n s1 00007fffe9474000 s2 0000000002000000 s3 9000000108d20280 s4 9000000002b38b10\n s5 900000010edbfb00 s6 00007ffff3474000 s7 0000000000000406 s8 900000010edbfa08\n ra: 9000000000485538 unmap_vmas+0x130/0x218\n ERA: 90000000004eaf1c __unmap_hugepage_range+0x6f4/0x7d0\n PRMD: 00000004 (PPLV0 +PIE -PWE)\n EUEN: 00000007 (+FPE +SXE +ASXE -BTE)\n ECFG: 00071c1d (LIE=0,2-4,10-12 VS=7)\n ESTAT: 000c0000 [BRK] (IS= ECode=12 EsubCode=0)\n PRID: 0014c010 (Loongson-64bit, Loongson-3A5000)\n Process hugefork02 (pid: 1517, threadinfo=00000000a670eaf4, task=000000007a95fc64)\n Call Trace:\n [<90000000004eaf1c>] __unmap_hugepage_range+0x6f4/0x7d0\n [<9000000000485534>] unmap_vmas+0x12c/0x218\n [<9000000000494068>] exit_mmap+0xe0/0x308\n [<900000000025fdc4>] mmput+0x74/0x180\n [<900000000026a284>] do_exit+0x294/0x898\n [<900000000026aa30>] do_group_exit+0x30/0x98\n [<900000000027bed4>] get_signal+0x83c/0x868\n [<90000000002457b4>] arch_do_signal_or_restart+0x54/0xfa0\n [<90000000015795e8>] irqentry_exit_to_user_mode+0xb8/0x138\n [<90000000002572d0>] tlb_do_page_fault_1+0x114/0x1b4\n\nThe problem is that base address allocated from hugetlbfs is not aligned\nwith pmd size. Here add a checking for hugetlbfs and align base address\nwith pmd size. After this patch the test case \"testcases/bin/hugefork02\"\npasses to run.\n\nThis is similar to the commit 7f24cbc9c4d42db8a3c8484d1 (\"mm/mmap: teach\ngeneric_get_unmapped_area{_topdown} to handle hugetlb mappings\").", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21949" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/242b34f48a377afe4b285b472bd0f17744fca8e8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3109d5ff484b7bc7b955f166974c6776d91f247b" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qrfj-w3wq-p623/GHSA-qrfj-w3wq-p623.json b/advisories/unreviewed/2025/04/GHSA-qrfj-w3wq-p623/GHSA-qrfj-w3wq-p623.json new file mode 100644 index 00000000000..90555785123 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qrfj-w3wq-p623/GHSA-qrfj-w3wq-p623.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qrfj-w3wq-p623", + "modified": "2025-04-01T18:30:55Z", + "published": "2025-04-01T18:30:55Z", + "aliases": [ + "CVE-2025-28132" + ], + "details": "A session management flaw in Nagios Network Analyzer 2024R1.0.3 allows an attacker to reuse session tokens even after a user logs out, leading to unauthorized access and account takeover. This occurs due to insufficient session expiration, where session tokens remain valid beyond logout, allowing an attacker to impersonate users and perform actions on their behalf.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28132" + }, + { + "type": "WEB", + "url": "https://github.com/harshal79/Insufficient-Session-Expiration.git" + }, + { + "type": "WEB", + "url": "https://www.nagios.com/changelog/#network-analyzer" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T17:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qvv4-xwrq-f5qv/GHSA-qvv4-xwrq-f5qv.json b/advisories/unreviewed/2025/04/GHSA-qvv4-xwrq-f5qv/GHSA-qvv4-xwrq-f5qv.json index 44f2a545066..98517c5540c 100644 --- a/advisories/unreviewed/2025/04/GHSA-qvv4-xwrq-f5qv/GHSA-qvv4-xwrq-f5qv.json +++ b/advisories/unreviewed/2025/04/GHSA-qvv4-xwrq-f5qv/GHSA-qvv4-xwrq-f5qv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qvv4-xwrq-f5qv", - "modified": "2025-04-01T15:31:36Z", + "modified": "2025-04-01T18:30:48Z", "published": "2025-04-01T15:31:36Z", "aliases": [ "CVE-2025-22231" @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-269" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-r89f-5fp9-fmg7/GHSA-r89f-5fp9-fmg7.json b/advisories/unreviewed/2025/04/GHSA-r89f-5fp9-fmg7/GHSA-r89f-5fp9-fmg7.json new file mode 100644 index 00000000000..66e294ee834 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-r89f-5fp9-fmg7/GHSA-r89f-5fp9-fmg7.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r89f-5fp9-fmg7", + "modified": "2025-04-01T18:30:52Z", + "published": "2025-04-01T18:30:52Z", + "aliases": [ + "CVE-2025-21929" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: intel-ish-hid: Fix use-after-free issue in hid_ishtp_cl_remove()\n\nDuring the `rmmod` operation for the `intel_ishtp_hid` driver, a\nuse-after-free issue can occur in the hid_ishtp_cl_remove() function.\nThe function hid_ishtp_cl_deinit() is called before ishtp_hid_remove(),\nwhich can lead to accessing freed memory or resources during the\nremoval process.\n\nCall Trace:\n ? ishtp_cl_send+0x168/0x220 [intel_ishtp]\n ? hid_output_report+0xe3/0x150 [hid]\n hid_ishtp_set_feature+0xb5/0x120 [intel_ishtp_hid]\n ishtp_hid_request+0x7b/0xb0 [intel_ishtp_hid]\n hid_hw_request+0x1f/0x40 [hid]\n sensor_hub_set_feature+0x11f/0x190 [hid_sensor_hub]\n _hid_sensor_power_state+0x147/0x1e0 [hid_sensor_trigger]\n hid_sensor_runtime_resume+0x22/0x30 [hid_sensor_trigger]\n sensor_hub_remove+0xa8/0xe0 [hid_sensor_hub]\n hid_device_remove+0x49/0xb0 [hid]\n hid_destroy_device+0x6f/0x90 [hid]\n ishtp_hid_remove+0x42/0x70 [intel_ishtp_hid]\n hid_ishtp_cl_remove+0x6b/0xb0 [intel_ishtp_hid]\n ishtp_cl_device_remove+0x4a/0x60 [intel_ishtp]\n ...\n\nAdditionally, ishtp_hid_remove() is a HID level power off, which should\noccur before the ISHTP level disconnect.\n\nThis patch resolves the issue by reordering the calls in\nhid_ishtp_cl_remove(). The function ishtp_hid_remove() is now\ncalled before hid_ishtp_cl_deinit().", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21929" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/823987841424289339fdb4ba90e6d2c3792836db" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9c677fe859a73f5dd3dd84c27f99e10d28047c73" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e040f11fbca868c6d151e9f2c5730c476abfcf17" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rqhf-vpjr-2pw8/GHSA-rqhf-vpjr-2pw8.json b/advisories/unreviewed/2025/04/GHSA-rqhf-vpjr-2pw8/GHSA-rqhf-vpjr-2pw8.json new file mode 100644 index 00000000000..7c98806791d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rqhf-vpjr-2pw8/GHSA-rqhf-vpjr-2pw8.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rqhf-vpjr-2pw8", + "modified": "2025-04-01T18:30:53Z", + "published": "2025-04-01T18:30:53Z", + "aliases": [ + "CVE-2025-21960" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\neth: bnxt: do not update checksum in bnxt_xdp_build_skb()\n\nThe bnxt_rx_pkt() updates ip_summed value at the end if checksum offload\nis enabled.\nWhen the XDP-MB program is attached and it returns XDP_PASS, the\nbnxt_xdp_build_skb() is called to update skb_shared_info.\nThe main purpose of bnxt_xdp_build_skb() is to update skb_shared_info,\nbut it updates ip_summed value too if checksum offload is enabled.\nThis is actually duplicate work.\n\nWhen the bnxt_rx_pkt() updates ip_summed value, it checks if ip_summed\nis CHECKSUM_NONE or not.\nIt means that ip_summed should be CHECKSUM_NONE at this moment.\nBut ip_summed may already be updated to CHECKSUM_UNNECESSARY in the\nXDP-MB-PASS path.\nSo the by skb_checksum_none_assert() WARNS about it.\n\nThis is duplicate work and updating ip_summed in the\nbnxt_xdp_build_skb() is not needed.\n\nSplat looks like:\nWARNING: CPU: 3 PID: 5782 at ./include/linux/skbuff.h:5155 bnxt_rx_pkt+0x479b/0x7610 [bnxt_en]\nModules linked in: bnxt_re bnxt_en rdma_ucm rdma_cm iw_cm ib_cm ib_uverbs veth xt_nat xt_tcpudp xt_conntrack nft_chain_nat xt_MASQUERADE nf_]\nCPU: 3 UID: 0 PID: 5782 Comm: socat Tainted: G W 6.14.0-rc4+ #27\nTainted: [W]=WARN\nHardware name: ASUS System Product Name/PRIME Z690-P D4, BIOS 0603 11/01/2021\nRIP: 0010:bnxt_rx_pkt+0x479b/0x7610 [bnxt_en]\nCode: 54 24 0c 4c 89 f1 4c 89 ff c1 ea 1f ff d3 0f 1f 00 49 89 c6 48 85 c0 0f 84 4c e5 ff ff 48 89 c7 e8 ca 3d a0 c8 e9 8f f4 ff ff <0f> 0b f\nRSP: 0018:ffff88881ba09928 EFLAGS: 00010202\nRAX: 0000000000000000 RBX: 00000000c7590303 RCX: 0000000000000000\nRDX: 1ffff1104e7d1610 RSI: 0000000000000001 RDI: ffff8881c91300b8\nRBP: ffff88881ba09b28 R08: ffff888273e8b0d0 R09: ffff888273e8b070\nR10: ffff888273e8b010 R11: ffff888278b0f000 R12: ffff888273e8b080\nR13: ffff8881c9130e00 R14: ffff8881505d3800 R15: ffff888273e8b000\nFS: 00007f5a2e7be080(0000) GS:ffff88881ba00000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007fff2e708ff8 CR3: 000000013e3b0000 CR4: 00000000007506f0\nPKRU: 55555554\nCall Trace:\n \n ? __warn+0xcd/0x2f0\n ? bnxt_rx_pkt+0x479b/0x7610\n ? report_bug+0x326/0x3c0\n ? handle_bug+0x53/0xa0\n ? exc_invalid_op+0x14/0x50\n ? asm_exc_invalid_op+0x16/0x20\n ? bnxt_rx_pkt+0x479b/0x7610\n ? bnxt_rx_pkt+0x3e41/0x7610\n ? __pfx_bnxt_rx_pkt+0x10/0x10\n ? napi_complete_done+0x2cf/0x7d0\n __bnxt_poll_work+0x4e8/0x1220\n ? __pfx___bnxt_poll_work+0x10/0x10\n ? __pfx_mark_lock.part.0+0x10/0x10\n bnxt_poll_p5+0x36a/0xfa0\n ? __pfx_bnxt_poll_p5+0x10/0x10\n __napi_poll.constprop.0+0xa0/0x440\n net_rx_action+0x899/0xd00\n...\n\nFollowing ping.py patch adds xdp-mb-pass case. so ping.py is going\nto be able to reproduce this issue.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21960" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/44578bc6460b8fca530fc7bd5897c115d9bd27e2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5b57ed14a1b85e7ab0074d9668a0baa6c94826c7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c03e7d05aa0e2f7e9a9ce5ad8a12471a53f941dc" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e8e3e03d69f2420eaa578199a65d281c58867105" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ee086c8e775f9690282e3d26471dbcfd5dad5a6a" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rvg2-pv9x-xxhg/GHSA-rvg2-pv9x-xxhg.json b/advisories/unreviewed/2025/04/GHSA-rvg2-pv9x-xxhg/GHSA-rvg2-pv9x-xxhg.json new file mode 100644 index 00000000000..925e5d58611 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rvg2-pv9x-xxhg/GHSA-rvg2-pv9x-xxhg.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rvg2-pv9x-xxhg", + "modified": "2025-04-01T18:30:54Z", + "published": "2025-04-01T18:30:54Z", + "aliases": [ + "CVE-2025-21968" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Fix slab-use-after-free on hdcp_work\n\n[Why]\nA slab-use-after-free is reported when HDCP is destroyed but the\nproperty_validate_dwork queue is still running.\n\n[How]\nCancel the delayed work when destroying workqueue.\n\n(cherry picked from commit 725a04ba5a95e89c89633d4322430cfbca7ce128)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21968" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/378b361e2e30e9729f9a7676f7926868d14f4326" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4964dbc4191ab436877a5e3ecd9c67a4e50b7c36" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/93d701064e56788663d7c5918fbe5e060d5df587" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bac7b8b1a3f1a86eeec85835af106cbdc2b9d9f7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e65e7bea220c3ce8c4c793b4ba35557f4994ab2b" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-v244-2mr3-cvh9/GHSA-v244-2mr3-cvh9.json b/advisories/unreviewed/2025/04/GHSA-v244-2mr3-cvh9/GHSA-v244-2mr3-cvh9.json new file mode 100644 index 00000000000..644d3527a1a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-v244-2mr3-cvh9/GHSA-v244-2mr3-cvh9.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v244-2mr3-cvh9", + "modified": "2025-04-01T18:30:55Z", + "published": "2025-04-01T18:30:55Z", + "aliases": [ + "CVE-2018-1472" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it was erroneously associated with an open source vulnerability by another vendor.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-1472" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T18:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-v2qv-44ch-jx7v/GHSA-v2qv-44ch-jx7v.json b/advisories/unreviewed/2025/04/GHSA-v2qv-44ch-jx7v/GHSA-v2qv-44ch-jx7v.json new file mode 100644 index 00000000000..372546c9311 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-v2qv-44ch-jx7v/GHSA-v2qv-44ch-jx7v.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v2qv-44ch-jx7v", + "modified": "2025-04-01T18:30:51Z", + "published": "2025-04-01T18:30:51Z", + "aliases": [ + "CVE-2025-21928" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: intel-ish-hid: Fix use-after-free issue in ishtp_hid_remove()\n\nThe system can experience a random crash a few minutes after the driver is\nremoved. This issue occurs due to improper handling of memory freeing in\nthe ishtp_hid_remove() function.\n\nThe function currently frees the `driver_data` directly within the loop\nthat destroys the HID devices, which can lead to accessing freed memory.\nSpecifically, `hid_destroy_device()` uses `driver_data` when it calls\n`hid_ishtp_set_feature()` to power off the sensor, so freeing\n`driver_data` beforehand can result in accessing invalid memory.\n\nThis patch resolves the issue by storing the `driver_data` in a temporary\nvariable before calling `hid_destroy_device()`, and then freeing the\n`driver_data` after the device is destroyed.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21928" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/01b18a330cda61cc21423a7d1af92cf31ded8f60" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/07583a0010696a17fb0942e0b499a62785c5fc9f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0c1fb475ef999d6c22fc3f963fdf20cb3ed1b03d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/560f4d1299342504a6ab8a47f575b5e6b8345ada" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cf1a6015d2f6b1f0afaa0fd6a0124ff2c7943394" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d3faae7f42181865c799d88c5054176f38ae4625" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/dea6a349bcaf243fff95dfd0428a26be6a0fb44e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/eb0695d87a81e7c1f0509b7d8ee7c65fbc26aec9" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-v974-f78x-v6pq/GHSA-v974-f78x-v6pq.json b/advisories/unreviewed/2025/04/GHSA-v974-f78x-v6pq/GHSA-v974-f78x-v6pq.json new file mode 100644 index 00000000000..93a9779e8ee --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-v974-f78x-v6pq/GHSA-v974-f78x-v6pq.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v974-f78x-v6pq", + "modified": "2025-04-01T18:30:53Z", + "published": "2025-04-01T18:30:53Z", + "aliases": [ + "CVE-2025-21961" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\neth: bnxt: fix truesize for mb-xdp-pass case\n\nWhen mb-xdp is set and return is XDP_PASS, packet is converted from\nxdp_buff to sk_buff with xdp_update_skb_shared_info() in\nbnxt_xdp_build_skb().\nbnxt_xdp_build_skb() passes incorrect truesize argument to\nxdp_update_skb_shared_info().\nThe truesize is calculated as BNXT_RX_PAGE_SIZE * sinfo->nr_frags but\nthe skb_shared_info was wiped by napi_build_skb() before.\nSo it stores sinfo->nr_frags before bnxt_xdp_build_skb() and use it\ninstead of getting skb_shared_info from xdp_get_shared_info_from_buff().\n\nSplat looks like:\n ------------[ cut here ]------------\n WARNING: CPU: 2 PID: 0 at net/core/skbuff.c:6072 skb_try_coalesce+0x504/0x590\n Modules linked in: xt_nat xt_tcpudp veth af_packet xt_conntrack nft_chain_nat xt_MASQUERADE nf_conntrack_netlink xfrm_user xt_addrtype nft_coms\n CPU: 2 UID: 0 PID: 0 Comm: swapper/2 Not tainted 6.14.0-rc2+ #3\n RIP: 0010:skb_try_coalesce+0x504/0x590\n Code: 4b fd ff ff 49 8b 34 24 40 80 e6 40 0f 84 3d fd ff ff 49 8b 74 24 48 40 f6 c6 01 0f 84 2e fd ff ff 48 8d 4e ff e9 25 fd ff ff <0f> 0b e99\n RSP: 0018:ffffb62c4120caa8 EFLAGS: 00010287\n RAX: 0000000000000003 RBX: ffffb62c4120cb14 RCX: 0000000000000ec0\n RDX: 0000000000001000 RSI: ffffa06e5d7dc000 RDI: 0000000000000003\n RBP: ffffa06e5d7ddec0 R08: ffffa06e6120a800 R09: ffffa06e7a119900\n R10: 0000000000002310 R11: ffffa06e5d7dcec0 R12: ffffe4360575f740\n R13: ffffe43600000000 R14: 0000000000000002 R15: 0000000000000002\n FS: 0000000000000000(0000) GS:ffffa0755f700000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 00007f147b76b0f8 CR3: 00000001615d4000 CR4: 00000000007506f0\n PKRU: 55555554\n Call Trace:\n \n ? __warn+0x84/0x130\n ? skb_try_coalesce+0x504/0x590\n ? report_bug+0x18a/0x1a0\n ? handle_bug+0x53/0x90\n ? exc_invalid_op+0x14/0x70\n ? asm_exc_invalid_op+0x16/0x20\n ? skb_try_coalesce+0x504/0x590\n inet_frag_reasm_finish+0x11f/0x2e0\n ip_defrag+0x37a/0x900\n ip_local_deliver+0x51/0x120\n ip_sublist_rcv_finish+0x64/0x70\n ip_sublist_rcv+0x179/0x210\n ip_list_rcv+0xf9/0x130\n\nHow to reproduce:\n\nip link set $interface1 xdp obj xdp_pass.o\nip link set $interface1 mtu 9000 up\nip a a 10.0.0.1/24 dev $interface1\n\nip link set $interfac2 mtu 9000 up\nip a a 10.0.0.2/24 dev $interface2\nping 10.0.0.1 -s 65000\n\nFollowing ping.py patch adds xdp-mb-pass case. so ping.py is going to be\nable to reproduce this issue.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21961" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/19107e71be330dbccb9f8f9f4cf0a9abeadad802" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9f7b2aa5034e24d3c49db73d5f760c0435fe31c2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b4679807c6083ade4d47f03f80da891afcb6ef62" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vcr5-6jvw-92h4/GHSA-vcr5-6jvw-92h4.json b/advisories/unreviewed/2025/04/GHSA-vcr5-6jvw-92h4/GHSA-vcr5-6jvw-92h4.json new file mode 100644 index 00000000000..fa9fdd6c03e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vcr5-6jvw-92h4/GHSA-vcr5-6jvw-92h4.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vcr5-6jvw-92h4", + "modified": "2025-04-01T18:30:55Z", + "published": "2025-04-01T18:30:54Z", + "aliases": [ + "CVE-2025-21986" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: switchdev: Convert blocking notification chain to a raw one\n\nA blocking notification chain uses a read-write semaphore to protect the\nintegrity of the chain. The semaphore is acquired for writing when\nadding / removing notifiers to / from the chain and acquired for reading\nwhen traversing the chain and informing notifiers about an event.\n\nIn case of the blocking switchdev notification chain, recursive\nnotifications are possible which leads to the semaphore being acquired\ntwice for reading and to lockdep warnings being generated [1].\n\nSpecifically, this can happen when the bridge driver processes a\nSWITCHDEV_BRPORT_UNOFFLOADED event which causes it to emit notifications\nabout deferred events when calling switchdev_deferred_process().\n\nFix this by converting the notification chain to a raw notification\nchain in a similar fashion to the netdev notification chain. Protect\nthe chain using the RTNL mutex by acquiring it when modifying the chain.\nEvents are always informed under the RTNL mutex, but add an assertion in\ncall_switchdev_blocking_notifiers() to make sure this is not violated in\nthe future.\n\nMaintain the \"blocking\" prefix as events are always emitted from process\ncontext and listeners are allowed to block.\n\n[1]:\nWARNING: possible recursive locking detected\n6.14.0-rc4-custom-g079270089484 #1 Not tainted\n--------------------------------------------\nip/52731 is trying to acquire lock:\nffffffff850918d8 ((switchdev_blocking_notif_chain).rwsem){++++}-{4:4}, at: blocking_notifier_call_chain+0x58/0xa0\n\nbut task is already holding lock:\nffffffff850918d8 ((switchdev_blocking_notif_chain).rwsem){++++}-{4:4}, at: blocking_notifier_call_chain+0x58/0xa0\n\nother info that might help us debug this:\nPossible unsafe locking scenario:\nCPU0\n----\nlock((switchdev_blocking_notif_chain).rwsem);\nlock((switchdev_blocking_notif_chain).rwsem);\n\n*** DEADLOCK ***\nMay be due to missing lock nesting notation\n3 locks held by ip/52731:\n #0: ffffffff84f795b0 (rtnl_mutex){+.+.}-{4:4}, at: rtnl_newlink+0x727/0x1dc0\n #1: ffffffff8731f628 (&net->rtnl_mutex){+.+.}-{4:4}, at: rtnl_newlink+0x790/0x1dc0\n #2: ffffffff850918d8 ((switchdev_blocking_notif_chain).rwsem){++++}-{4:4}, at: blocking_notifier_call_chain+0x58/0xa0\n\nstack backtrace:\n...\n? __pfx_down_read+0x10/0x10\n? __pfx_mark_lock+0x10/0x10\n? __pfx_switchdev_port_attr_set_deferred+0x10/0x10\nblocking_notifier_call_chain+0x58/0xa0\nswitchdev_port_attr_notify.constprop.0+0xb3/0x1b0\n? __pfx_switchdev_port_attr_notify.constprop.0+0x10/0x10\n? mark_held_locks+0x94/0xe0\n? switchdev_deferred_process+0x11a/0x340\nswitchdev_port_attr_set_deferred+0x27/0xd0\nswitchdev_deferred_process+0x164/0x340\nbr_switchdev_port_unoffload+0xc8/0x100 [bridge]\nbr_switchdev_blocking_event+0x29f/0x580 [bridge]\nnotifier_call_chain+0xa2/0x440\nblocking_notifier_call_chain+0x6e/0xa0\nswitchdev_bridge_port_unoffload+0xde/0x1a0\n...", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21986" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1f7d051814e7a0cb1f0717ed5527c1059992129d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/62531a1effa87bdab12d5104015af72e60d926ff" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a597d4b75669ec82c72cbee9fe75a15d04b35b2b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/af757f5ee3f754c5dceefb05c12ff37cb46fc682" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f9ed3fb50b872bd78bcb01f25087f9e4e25085d8" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vp9f-g82m-h958/GHSA-vp9f-g82m-h958.json b/advisories/unreviewed/2025/04/GHSA-vp9f-g82m-h958/GHSA-vp9f-g82m-h958.json new file mode 100644 index 00000000000..c6c09a7daa0 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vp9f-g82m-h958/GHSA-vp9f-g82m-h958.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vp9f-g82m-h958", + "modified": "2025-04-01T18:30:50Z", + "published": "2025-04-01T18:30:50Z", + "aliases": [ + "CVE-2025-21899" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: Fix bad hist from corrupting named_triggers list\n\nThe following commands causes a crash:\n\n ~# cd /sys/kernel/tracing/events/rcu/rcu_callback\n ~# echo 'hist:name=bad:keys=common_pid:onmax(bogus).save(common_pid)' > trigger\n bash: echo: write error: Invalid argument\n ~# echo 'hist:name=bad:keys=common_pid' > trigger\n\nBecause the following occurs:\n\nevent_trigger_write() {\n trigger_process_regex() {\n event_hist_trigger_parse() {\n\n data = event_trigger_alloc(..);\n\n event_trigger_register(.., data) {\n cmd_ops->reg(.., data, ..) [hist_register_trigger()] {\n data->ops->init() [event_hist_trigger_init()] {\n save_named_trigger(name, data) {\n list_add(&data->named_list, &named_triggers);\n }\n }\n }\n }\n\n ret = create_actions(); (return -EINVAL)\n if (ret)\n goto out_unreg;\n[..]\n ret = hist_trigger_enable(data, ...) {\n list_add_tail_rcu(&data->list, &file->triggers); <<<---- SKIPPED!!! (this is important!)\n[..]\n out_unreg:\n event_hist_unregister(.., data) {\n cmd_ops->unreg(.., data, ..) [hist_unregister_trigger()] {\n list_for_each_entry(iter, &file->triggers, list) {\n if (!hist_trigger_match(data, iter, named_data, false)) <- never matches\n continue;\n [..]\n test = iter;\n }\n if (test && test->ops->free) <<<-- test is NULL\n\n test->ops->free(test) [event_hist_trigger_free()] {\n [..]\n if (data->name)\n del_named_trigger(data) {\n list_del(&data->named_list); <<<<-- NEVER gets removed!\n }\n }\n }\n }\n\n [..]\n kfree(data); <<<-- frees item but it is still on list\n\nThe next time a hist with name is registered, it causes an u-a-f bug and\nthe kernel can crash.\n\nMove the code around such that if event_trigger_register() succeeds, the\nnext thing called is hist_trigger_enable() which adds it to the list.\n\nA bunch of actions is called if get_named_trigger_data() returns false.\nBut that doesn't need to be called after event_trigger_register(), so it\ncan be moved up, allowing event_trigger_register() to be called just\nbefore hist_trigger_enable() keeping them together and allowing the\nfile->triggers to be properly populated.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21899" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/435d2964af815aae456db554c62963b4515f19d0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/43b254d46c740bf9dbe65709afa021dd726dfa99" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5ae1b18f05ee2b849dc03b6c15d7da0c1c6efa77" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6f86bdeab633a56d5c6dccf1a2c5989b6a5e323e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f1ae50cfb818ce1ac7a674406dfadb7653e2552d" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-w66x-hqgr-vfg4/GHSA-w66x-hqgr-vfg4.json b/advisories/unreviewed/2025/04/GHSA-w66x-hqgr-vfg4/GHSA-w66x-hqgr-vfg4.json new file mode 100644 index 00000000000..9de8474fe43 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-w66x-hqgr-vfg4/GHSA-w66x-hqgr-vfg4.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w66x-hqgr-vfg4", + "modified": "2025-04-01T18:30:54Z", + "published": "2025-04-01T18:30:53Z", + "aliases": [ + "CVE-2025-21966" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndm-flakey: Fix memory corruption in optional corrupt_bio_byte feature\n\nFix memory corruption due to incorrect parameter being passed to bio_init", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21966" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/57e9417f69839cb10f7ffca684c38acd28ceb57b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5a87e46da2418c57b445371f5ca0958d5779ba5f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/818330f756f3800c37d738bd36bce60eac949938" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/da070843e153471be4297a12fdaa64023276f40e" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-w69j-ppp7-83pp/GHSA-w69j-ppp7-83pp.json b/advisories/unreviewed/2025/04/GHSA-w69j-ppp7-83pp/GHSA-w69j-ppp7-83pp.json new file mode 100644 index 00000000000..03191bb9dd7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-w69j-ppp7-83pp/GHSA-w69j-ppp7-83pp.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w69j-ppp7-83pp", + "modified": "2025-04-01T18:30:50Z", + "published": "2025-04-01T18:30:50Z", + "aliases": [ + "CVE-2025-21902" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nacpi: typec: ucsi: Introduce a ->poll_cci method\n\nFor the ACPI backend of UCSI the UCSI \"registers\" are just a memory copy\nof the register values in an opregion. The ACPI implementation in the\nBIOS ensures that the opregion contents are synced to the embedded\ncontroller and it ensures that the registers (in particular CCI) are\nsynced back to the opregion on notifications. While there is an ACPI call\nthat syncs the actual registers to the opregion there is rarely a need to\ndo this and on some ACPI implementations it actually breaks in various\ninteresting ways.\n\nThe only reason to force a sync from the embedded controller is to poll\nCCI while notifications are disabled. Only the ucsi core knows if this\nis the case and guessing based on the current command is suboptimal, i.e.\nleading to the following spurious assertion splat:\n\nWARNING: CPU: 3 PID: 76 at drivers/usb/typec/ucsi/ucsi.c:1388 ucsi_reset_ppm+0x1b4/0x1c0 [typec_ucsi]\nCPU: 3 UID: 0 PID: 76 Comm: kworker/3:0 Not tainted 6.12.11-200.fc41.x86_64 #1\nHardware name: LENOVO 21D0/LNVNB161216, BIOS J6CN45WW 03/17/2023\nWorkqueue: events_long ucsi_init_work [typec_ucsi]\nRIP: 0010:ucsi_reset_ppm+0x1b4/0x1c0 [typec_ucsi]\nCall Trace:\n \n ucsi_init_work+0x3c/0xac0 [typec_ucsi]\n process_one_work+0x179/0x330\n worker_thread+0x252/0x390\n kthread+0xd2/0x100\n ret_from_fork+0x34/0x50\n ret_from_fork_asm+0x1a/0x30\n \n\nThus introduce a ->poll_cci() method that works like ->read_cci() with an\nadditional forced sync and document that this should be used when polling\nwith notifications disabled. For all other backends that presumably don't\nhave this issue use the same implementation for both methods.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21902" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/012b98cdb54c7d47743ee7fc402fa23f2d90529a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1aec5c9066965ac0984e385bbc31455ae31cbffc" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/976e7e9bdc7719a023a4ecccd2e3daec9ab20a40" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-w7xc-x24c-mg52/GHSA-w7xc-x24c-mg52.json b/advisories/unreviewed/2025/04/GHSA-w7xc-x24c-mg52/GHSA-w7xc-x24c-mg52.json new file mode 100644 index 00000000000..577baacab56 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-w7xc-x24c-mg52/GHSA-w7xc-x24c-mg52.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w7xc-x24c-mg52", + "modified": "2025-04-01T18:30:54Z", + "published": "2025-04-01T18:30:54Z", + "aliases": [ + "CVE-2025-21972" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: mctp: unshare packets when reassembling\n\nEnsure that the frag_list used for reassembly isn't shared with other\npackets. This avoids incorrect reassembly when packets are cloned, and\nprevents a memory leak due to circular references between fragments and\ntheir skb_shared_info.\n\nThe upcoming MCTP-over-USB driver uses skb_clone which can trigger the\nproblem - other MCTP drivers don't share SKBs.\n\nA kunit test is added to reproduce the issue.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21972" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5c47d5bfa7b096cf8890afac32141c578583f8e0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f44fff3d3c6cd67b6f348b821d73c4d6888c7a6e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f5d83cf0eeb90fade4d5c4d17d24b8bee9ceeecc" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-wxg9-m4pj-6hvr/GHSA-wxg9-m4pj-6hvr.json b/advisories/unreviewed/2025/04/GHSA-wxg9-m4pj-6hvr/GHSA-wxg9-m4pj-6hvr.json index 3eb00e28983..ffbe6fb274d 100644 --- a/advisories/unreviewed/2025/04/GHSA-wxg9-m4pj-6hvr/GHSA-wxg9-m4pj-6hvr.json +++ b/advisories/unreviewed/2025/04/GHSA-wxg9-m4pj-6hvr/GHSA-wxg9-m4pj-6hvr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wxg9-m4pj-6hvr", - "modified": "2025-04-01T00:30:40Z", + "modified": "2025-04-01T18:30:47Z", "published": "2025-04-01T00:30:40Z", "aliases": [ "CVE-2025-24272" ], "details": "The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to modify protected parts of the file system.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:23Z" diff --git a/advisories/unreviewed/2025/04/GHSA-x37f-9gm8-pv63/GHSA-x37f-9gm8-pv63.json b/advisories/unreviewed/2025/04/GHSA-x37f-9gm8-pv63/GHSA-x37f-9gm8-pv63.json new file mode 100644 index 00000000000..b90a7d71798 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-x37f-9gm8-pv63/GHSA-x37f-9gm8-pv63.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x37f-9gm8-pv63", + "modified": "2025-04-01T18:30:54Z", + "published": "2025-04-01T18:30:54Z", + "aliases": [ + "CVE-2025-21978" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/hyperv: Fix address space leak when Hyper-V DRM device is removed\n\nWhen a Hyper-V DRM device is probed, the driver allocates MMIO space for\nthe vram, and maps it cacheable. If the device removed, or in the error\npath for device probing, the MMIO space is released but no unmap is done.\nConsequently the kernel address space for the mapping is leaked.\n\nFix this by adding iounmap() calls in the device removal path, and in the\nerror path during device probing.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21978" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/158242b56bf465a73e1edeac0fe828a8acad4499" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/24f1bbfb2be77dad82489c1468bbb14312aab129" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ad27b4a51495490b815580d9b935e8eee14d1a9c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/aed709355fd05ef747e1af24a1d5d78cd7feb81e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c40cd24bfb9bfbb315c118ca14ebe6cf52e2dd1e" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-x97h-4pwx-3c9h/GHSA-x97h-4pwx-3c9h.json b/advisories/unreviewed/2025/04/GHSA-x97h-4pwx-3c9h/GHSA-x97h-4pwx-3c9h.json new file mode 100644 index 00000000000..9430a66f232 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-x97h-4pwx-3c9h/GHSA-x97h-4pwx-3c9h.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x97h-4pwx-3c9h", + "modified": "2025-04-01T18:30:50Z", + "published": "2025-04-01T18:30:50Z", + "aliases": [ + "CVE-2025-21904" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncaif_virtio: fix wrong pointer check in cfv_probe()\n\ndel_vqs() frees virtqueues, therefore cfv->vq_tx pointer should be checked\nfor NULL before calling it, not cfv->vdev. Also the current implementation\nis redundant because the pointer cfv->vdev is dereferenced before it is\nchecked for NULL.\n\nFix this by checking cfv->vq_tx for NULL instead of cfv->vdev before\ncalling del_vqs().", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21904" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/29e0cd296c87240278e2f7ea4cf3f496b60c03af" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/56cddf71cce3b15b078e937fadab29962b6f6643" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/597c27e5f04cb50e56cc9aeda75d3e42b6b89c3e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7b5fe58959822e6cfa884327cabba6be3b01883d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8e4e08ca4cc634b337bb74bc9a70758fdeda0bcb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/90d302619ee7ce5ed0c69c29c290bdccfde66418" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/990fff6980d0c1693d60a812f58dbf93eab0473f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a466fd7e9fafd975949e5945e2f70c33a94b1a70" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-x9qw-9cw3-55vf/GHSA-x9qw-9cw3-55vf.json b/advisories/unreviewed/2025/04/GHSA-x9qw-9cw3-55vf/GHSA-x9qw-9cw3-55vf.json new file mode 100644 index 00000000000..0e2b7d8df45 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-x9qw-9cw3-55vf/GHSA-x9qw-9cw3-55vf.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x9qw-9cw3-55vf", + "modified": "2025-04-01T18:30:50Z", + "published": "2025-04-01T18:30:50Z", + "aliases": [ + "CVE-2025-21911" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/imagination: avoid deadlock on fence release\n\nDo scheduler queue fence release processing on a workqueue, rather\nthan in the release function itself.\n\nFixes deadlock issues such as the following:\n\n[ 607.400437] ============================================\n[ 607.405755] WARNING: possible recursive locking detected\n[ 607.415500] --------------------------------------------\n[ 607.420817] weston:zfq0/24149 is trying to acquire lock:\n[ 607.426131] ffff000017d041a0 (reservation_ww_class_mutex){+.+.}-{3:3}, at: pvr_gem_object_vunmap+0x40/0xc0 [powervr]\n[ 607.436728]\n but task is already holding lock:\n[ 607.442554] ffff000017d105a0 (reservation_ww_class_mutex){+.+.}-{3:3}, at: dma_buf_ioctl+0x250/0x554\n[ 607.451727]\n other info that might help us debug this:\n[ 607.458245] Possible unsafe locking scenario:\n\n[ 607.464155] CPU0\n[ 607.466601] ----\n[ 607.469044] lock(reservation_ww_class_mutex);\n[ 607.473584] lock(reservation_ww_class_mutex);\n[ 607.478114]\n *** DEADLOCK ***", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21911" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9bd8b8d34cf4efba18766d64f817c819ed1bbde7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d993ae7360923efd6ade43a32043459a121c28c1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/df1a1ed5e1bdd9cc13148e0e5549f5ebcf76cf13" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xq5q-48gp-2pgw/GHSA-xq5q-48gp-2pgw.json b/advisories/unreviewed/2025/04/GHSA-xq5q-48gp-2pgw/GHSA-xq5q-48gp-2pgw.json new file mode 100644 index 00000000000..7f69f55ffb2 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xq5q-48gp-2pgw/GHSA-xq5q-48gp-2pgw.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xq5q-48gp-2pgw", + "modified": "2025-04-01T18:30:50Z", + "published": "2025-04-01T18:30:50Z", + "aliases": [ + "CVE-2025-21910" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: cfg80211: regulatory: improve invalid hints checking\n\nSyzbot keeps reporting an issue [1] that occurs when erroneous symbols\nsent from userspace get through into user_alpha2[] via\nregulatory_hint_user() call. Such invalid regulatory hints should be\nrejected.\n\nWhile a sanity check from commit 47caf685a685 (\"cfg80211: regulatory:\nreject invalid hints\") looks to be enough to deter these very cases,\nthere is a way to get around it due to 2 reasons.\n\n1) The way isalpha() works, symbols other than latin lower and\nupper letters may be used to determine a country/domain.\nFor instance, greek letters will also be considered upper/lower\nletters and for such characters isalpha() will return true as well.\nHowever, ISO-3166-1 alpha2 codes should only hold latin\ncharacters.\n\n2) While processing a user regulatory request, between\nreg_process_hint_user() and regulatory_hint_user() there happens to\nbe a call to queue_regulatory_request() which modifies letters in\nrequest->alpha2[] with toupper(). This works fine for latin symbols,\nless so for weird letter characters from the second part of _ctype[].\n\nSyzbot triggers a warning in is_user_regdom_saved() by first sending\nover an unexpected non-latin letter that gets malformed by toupper()\ninto a character that ends up failing isalpha() check.\n\nPrevent this by enhancing is_an_alpha2() to ensure that incoming\nsymbols are latin letters and nothing else.\n\n[1] Syzbot report:\n------------[ cut here ]------------\nUnexpected user alpha2: A�\nWARNING: CPU: 1 PID: 964 at net/wireless/reg.c:442 is_user_regdom_saved net/wireless/reg.c:440 [inline]\nWARNING: CPU: 1 PID: 964 at net/wireless/reg.c:442 restore_alpha2 net/wireless/reg.c:3424 [inline]\nWARNING: CPU: 1 PID: 964 at net/wireless/reg.c:442 restore_regulatory_settings+0x3c0/0x1e50 net/wireless/reg.c:3516\nModules linked in:\nCPU: 1 UID: 0 PID: 964 Comm: kworker/1:2 Not tainted 6.12.0-rc5-syzkaller-00044-gc1e939a21eb1 #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024\nWorkqueue: events_power_efficient crda_timeout_work\nRIP: 0010:is_user_regdom_saved net/wireless/reg.c:440 [inline]\nRIP: 0010:restore_alpha2 net/wireless/reg.c:3424 [inline]\nRIP: 0010:restore_regulatory_settings+0x3c0/0x1e50 net/wireless/reg.c:3516\n...\nCall Trace:\n \n crda_timeout_work+0x27/0x50 net/wireless/reg.c:542\n process_one_work kernel/workqueue.c:3229 [inline]\n process_scheduled_works+0xa65/0x1850 kernel/workqueue.c:3310\n worker_thread+0x870/0xd30 kernel/workqueue.c:3391\n kthread+0x2f2/0x390 kernel/kthread.c:389\n ret_from_fork+0x4d/0x80 arch/x86/kernel/process.c:147\n ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:244\n ", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21910" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/17aa34c84867f6cd181a5743e1c647e7766962a6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/35ef07112b61b06eb30683a6563c9f6378c02476" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/59b348be7597c4a9903cb003c69e37df20c04a30" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/62b1a9bbfebba4b4c2bb6c1ede9ef7ecee7a9ff6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6a5e3b23054cee3b92683d1467e3fa83921f5622" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/be7c5f00aa7f1344293e4d48d0e12be83a2f223d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/da3f599517ef2ea851208df3229d07728d238dc5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f4112cb477c727a65787a4065a75ca593bb5b2f4" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T16:15:21Z" + } +} \ No newline at end of file