From 9394569fe8c36f9017d4c1b2e4f12bca137570bc Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 16 Jul 2024 15:32:14 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-2m3m-4f43-3vh4.json | 11 ++-- .../GHSA-72mh-pf6c-wq87.json | 9 ++- .../GHSA-f7m8-7gw9-4gf3.json | 11 ++-- .../GHSA-fg5v-f56h-7qqv.json | 11 ++-- .../GHSA-h33q-qggg-pqmj.json | 11 ++-- .../GHSA-m576-86pq-hpp4.json | 11 ++-- .../GHSA-mx74-c2vm-7fgr.json | 2 +- .../GHSA-pgf2-jh8p-r4gg.json | 9 ++- .../GHSA-pqhj-hg4g-hg2v.json | 2 +- .../GHSA-2cmx-hh49-m5qp.json | 63 +++++++++++++++++++ .../GHSA-2mxj-r96x-vpcm.json | 43 +++++++++++++ .../GHSA-2q6j-vpvr-6pvj.json | 6 +- .../GHSA-3vcc-f634-j924.json | 63 +++++++++++++++++++ .../GHSA-48mq-mj2m-9cjq.json | 42 +++++++++++++ .../GHSA-55x8-qm73-mrfg.json | 38 +++++++++++ .../GHSA-59f9-39vx-2r92.json | 1 + .../GHSA-5gg7-q62c-m2hp.json | 47 ++++++++++++++ .../GHSA-697g-g69g-85cq.json | 63 +++++++++++++++++++ .../GHSA-6g4r-v8v9-hj9h.json | 43 +++++++++++++ .../GHSA-6gcc-c84m-wqv4.json | 39 ++++++++++++ .../GHSA-73j8-r39c-jxp6.json | 43 +++++++++++++ .../GHSA-74mq-wr7w-wwvw.json | 63 +++++++++++++++++++ .../GHSA-7hc6-qhpj-2x7q.json | 51 +++++++++++++++ .../GHSA-7pgp-w5jc-4xjm.json | 39 ++++++++++++ .../GHSA-7vfx-qp7p-vwcw.json | 43 +++++++++++++ .../GHSA-8hqr-2pq7-7gv3.json | 51 +++++++++++++++ .../GHSA-8rjj-j4hj-jc98.json | 43 +++++++++++++ .../GHSA-97c5-prqj-77gq.json | 47 ++++++++++++++ .../GHSA-9c8v-c8p9-2pjh.json | 43 +++++++++++++ .../GHSA-9j87-4jmc-mrvg.json | 51 +++++++++++++++ .../GHSA-9pfw-fqv3-483p.json | 43 +++++++++++++ .../GHSA-cqc3-8mfm-84p4.json | 43 +++++++++++++ .../GHSA-f2xw-g7hm-66qr.json | 63 +++++++++++++++++++ .../GHSA-f9vw-2hpv-h272.json | 43 +++++++++++++ .../GHSA-fcw4-rj76-q6cg.json | 38 +++++++++++ .../GHSA-gq7q-6p5c-gpcc.json | 63 +++++++++++++++++++ .../GHSA-hg7f-jj55-6xcf.json | 43 +++++++++++++ .../GHSA-mr3g-8vqm-6mhq.json | 47 ++++++++++++++ .../GHSA-p622-mwq3-26f2.json | 63 +++++++++++++++++++ .../GHSA-pvw6-xmpp-3h64.json | 39 ++++++++++++ .../GHSA-qc77-c9gc-j3x6.json | 63 +++++++++++++++++++ .../GHSA-qvwc-r3r6-hq25.json | 63 +++++++++++++++++++ .../GHSA-r6gj-cppw-666p.json | 55 ++++++++++++++++ .../GHSA-r7cx-6c4p-88r8.json | 63 +++++++++++++++++++ .../GHSA-v9xm-vjq4-6r8q.json | 46 ++++++++++++++ .../GHSA-vp69-366h-2hqh.json | 43 +++++++++++++ .../GHSA-w7jq-wm3w-xhpq.json | 43 +++++++++++++ .../GHSA-wgcq-m83r-f344.json | 47 ++++++++++++++ .../GHSA-wrch-9585-fw25.json | 63 +++++++++++++++++++ .../GHSA-x27m-p9c5-jvf7.json | 2 +- 50 files changed, 1942 insertions(+), 30 deletions(-) create mode 100644 advisories/unreviewed/2024/07/GHSA-2cmx-hh49-m5qp/GHSA-2cmx-hh49-m5qp.json create mode 100644 advisories/unreviewed/2024/07/GHSA-2mxj-r96x-vpcm/GHSA-2mxj-r96x-vpcm.json create mode 100644 advisories/unreviewed/2024/07/GHSA-3vcc-f634-j924/GHSA-3vcc-f634-j924.json create mode 100644 advisories/unreviewed/2024/07/GHSA-48mq-mj2m-9cjq/GHSA-48mq-mj2m-9cjq.json create mode 100644 advisories/unreviewed/2024/07/GHSA-55x8-qm73-mrfg/GHSA-55x8-qm73-mrfg.json create mode 100644 advisories/unreviewed/2024/07/GHSA-5gg7-q62c-m2hp/GHSA-5gg7-q62c-m2hp.json create mode 100644 advisories/unreviewed/2024/07/GHSA-697g-g69g-85cq/GHSA-697g-g69g-85cq.json create mode 100644 advisories/unreviewed/2024/07/GHSA-6g4r-v8v9-hj9h/GHSA-6g4r-v8v9-hj9h.json create mode 100644 advisories/unreviewed/2024/07/GHSA-6gcc-c84m-wqv4/GHSA-6gcc-c84m-wqv4.json create mode 100644 advisories/unreviewed/2024/07/GHSA-73j8-r39c-jxp6/GHSA-73j8-r39c-jxp6.json create mode 100644 advisories/unreviewed/2024/07/GHSA-74mq-wr7w-wwvw/GHSA-74mq-wr7w-wwvw.json create mode 100644 advisories/unreviewed/2024/07/GHSA-7hc6-qhpj-2x7q/GHSA-7hc6-qhpj-2x7q.json create mode 100644 advisories/unreviewed/2024/07/GHSA-7pgp-w5jc-4xjm/GHSA-7pgp-w5jc-4xjm.json create mode 100644 advisories/unreviewed/2024/07/GHSA-7vfx-qp7p-vwcw/GHSA-7vfx-qp7p-vwcw.json create mode 100644 advisories/unreviewed/2024/07/GHSA-8hqr-2pq7-7gv3/GHSA-8hqr-2pq7-7gv3.json create mode 100644 advisories/unreviewed/2024/07/GHSA-8rjj-j4hj-jc98/GHSA-8rjj-j4hj-jc98.json create mode 100644 advisories/unreviewed/2024/07/GHSA-97c5-prqj-77gq/GHSA-97c5-prqj-77gq.json create mode 100644 advisories/unreviewed/2024/07/GHSA-9c8v-c8p9-2pjh/GHSA-9c8v-c8p9-2pjh.json create mode 100644 advisories/unreviewed/2024/07/GHSA-9j87-4jmc-mrvg/GHSA-9j87-4jmc-mrvg.json create mode 100644 advisories/unreviewed/2024/07/GHSA-9pfw-fqv3-483p/GHSA-9pfw-fqv3-483p.json create mode 100644 advisories/unreviewed/2024/07/GHSA-cqc3-8mfm-84p4/GHSA-cqc3-8mfm-84p4.json create mode 100644 advisories/unreviewed/2024/07/GHSA-f2xw-g7hm-66qr/GHSA-f2xw-g7hm-66qr.json create mode 100644 advisories/unreviewed/2024/07/GHSA-f9vw-2hpv-h272/GHSA-f9vw-2hpv-h272.json create mode 100644 advisories/unreviewed/2024/07/GHSA-fcw4-rj76-q6cg/GHSA-fcw4-rj76-q6cg.json create mode 100644 advisories/unreviewed/2024/07/GHSA-gq7q-6p5c-gpcc/GHSA-gq7q-6p5c-gpcc.json create mode 100644 advisories/unreviewed/2024/07/GHSA-hg7f-jj55-6xcf/GHSA-hg7f-jj55-6xcf.json create mode 100644 advisories/unreviewed/2024/07/GHSA-mr3g-8vqm-6mhq/GHSA-mr3g-8vqm-6mhq.json create mode 100644 advisories/unreviewed/2024/07/GHSA-p622-mwq3-26f2/GHSA-p622-mwq3-26f2.json create mode 100644 advisories/unreviewed/2024/07/GHSA-pvw6-xmpp-3h64/GHSA-pvw6-xmpp-3h64.json create mode 100644 advisories/unreviewed/2024/07/GHSA-qc77-c9gc-j3x6/GHSA-qc77-c9gc-j3x6.json create mode 100644 advisories/unreviewed/2024/07/GHSA-qvwc-r3r6-hq25/GHSA-qvwc-r3r6-hq25.json create mode 100644 advisories/unreviewed/2024/07/GHSA-r6gj-cppw-666p/GHSA-r6gj-cppw-666p.json create mode 100644 advisories/unreviewed/2024/07/GHSA-r7cx-6c4p-88r8/GHSA-r7cx-6c4p-88r8.json create mode 100644 advisories/unreviewed/2024/07/GHSA-v9xm-vjq4-6r8q/GHSA-v9xm-vjq4-6r8q.json create mode 100644 advisories/unreviewed/2024/07/GHSA-vp69-366h-2hqh/GHSA-vp69-366h-2hqh.json create mode 100644 advisories/unreviewed/2024/07/GHSA-w7jq-wm3w-xhpq/GHSA-w7jq-wm3w-xhpq.json create mode 100644 advisories/unreviewed/2024/07/GHSA-wgcq-m83r-f344/GHSA-wgcq-m83r-f344.json create mode 100644 advisories/unreviewed/2024/07/GHSA-wrch-9585-fw25/GHSA-wrch-9585-fw25.json diff --git a/advisories/unreviewed/2024/06/GHSA-2m3m-4f43-3vh4/GHSA-2m3m-4f43-3vh4.json b/advisories/unreviewed/2024/06/GHSA-2m3m-4f43-3vh4/GHSA-2m3m-4f43-3vh4.json index fc608467cd7..09434925920 100644 --- a/advisories/unreviewed/2024/06/GHSA-2m3m-4f43-3vh4/GHSA-2m3m-4f43-3vh4.json +++ b/advisories/unreviewed/2024/06/GHSA-2m3m-4f43-3vh4/GHSA-2m3m-4f43-3vh4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2m3m-4f43-3vh4", - "modified": "2024-06-13T21:30:55Z", + "modified": "2024-07-16T15:30:44Z", "published": "2024-06-13T21:30:55Z", "aliases": [ "CVE-2024-32913" ], "details": "In wl_notify_rx_mgmt_frame of wl_cfg80211.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-190" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-13T21:15:55Z" diff --git a/advisories/unreviewed/2024/06/GHSA-72mh-pf6c-wq87/GHSA-72mh-pf6c-wq87.json b/advisories/unreviewed/2024/06/GHSA-72mh-pf6c-wq87/GHSA-72mh-pf6c-wq87.json index 5018e2179ab..6b7bb700ac5 100644 --- a/advisories/unreviewed/2024/06/GHSA-72mh-pf6c-wq87/GHSA-72mh-pf6c-wq87.json +++ b/advisories/unreviewed/2024/06/GHSA-72mh-pf6c-wq87/GHSA-72mh-pf6c-wq87.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-72mh-pf6c-wq87", - "modified": "2024-06-13T21:30:55Z", + "modified": "2024-07-16T15:30:44Z", "published": "2024-06-13T21:30:55Z", "aliases": [ "CVE-2024-32912" ], "details": "there is a possible persistent Denial of Service due to test/debugging code left in a production build. This could lead to local denial of service of impaired use of the device with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-13T21:15:55Z" diff --git a/advisories/unreviewed/2024/06/GHSA-f7m8-7gw9-4gf3/GHSA-f7m8-7gw9-4gf3.json b/advisories/unreviewed/2024/06/GHSA-f7m8-7gw9-4gf3/GHSA-f7m8-7gw9-4gf3.json index c4dc449a88e..9128384ff19 100644 --- a/advisories/unreviewed/2024/06/GHSA-f7m8-7gw9-4gf3/GHSA-f7m8-7gw9-4gf3.json +++ b/advisories/unreviewed/2024/06/GHSA-f7m8-7gw9-4gf3/GHSA-f7m8-7gw9-4gf3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f7m8-7gw9-4gf3", - "modified": "2024-06-13T21:30:55Z", + "modified": "2024-07-16T15:30:44Z", "published": "2024-06-13T21:30:55Z", "aliases": [ "CVE-2024-32910" ], "details": "In handle_msg_shm_map_req of trusty/user/base/lib/spi/srv/tipc/tipc.c, there is a possible stack data disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-908" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-13T21:15:55Z" diff --git a/advisories/unreviewed/2024/06/GHSA-fg5v-f56h-7qqv/GHSA-fg5v-f56h-7qqv.json b/advisories/unreviewed/2024/06/GHSA-fg5v-f56h-7qqv/GHSA-fg5v-f56h-7qqv.json index 0a208803437..64aac0772a0 100644 --- a/advisories/unreviewed/2024/06/GHSA-fg5v-f56h-7qqv/GHSA-fg5v-f56h-7qqv.json +++ b/advisories/unreviewed/2024/06/GHSA-fg5v-f56h-7qqv/GHSA-fg5v-f56h-7qqv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fg5v-f56h-7qqv", - "modified": "2024-06-07T00:30:37Z", + "modified": "2024-07-16T15:30:44Z", "published": "2024-06-07T00:30:37Z", "aliases": [ "CVE-2024-36774" ], "details": "An arbitrary file upload vulnerability in Monstra CMS v3.0.4 allows attackers to execute arbitrary code via uploading a crafted PHP file.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-06T22:15:10Z" diff --git a/advisories/unreviewed/2024/06/GHSA-h33q-qggg-pqmj/GHSA-h33q-qggg-pqmj.json b/advisories/unreviewed/2024/06/GHSA-h33q-qggg-pqmj/GHSA-h33q-qggg-pqmj.json index 9b48bf3b207..4b7e30954ff 100644 --- a/advisories/unreviewed/2024/06/GHSA-h33q-qggg-pqmj/GHSA-h33q-qggg-pqmj.json +++ b/advisories/unreviewed/2024/06/GHSA-h33q-qggg-pqmj/GHSA-h33q-qggg-pqmj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h33q-qggg-pqmj", - "modified": "2024-06-13T21:30:55Z", + "modified": "2024-07-16T15:30:44Z", "published": "2024-06-13T21:30:55Z", "aliases": [ "CVE-2024-32911" ], "details": "There is a possible escalation of privilege due to improperly used crypto. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-327" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-13T21:15:55Z" diff --git a/advisories/unreviewed/2024/06/GHSA-m576-86pq-hpp4/GHSA-m576-86pq-hpp4.json b/advisories/unreviewed/2024/06/GHSA-m576-86pq-hpp4/GHSA-m576-86pq-hpp4.json index 04571dfeea3..0da3bf80a30 100644 --- a/advisories/unreviewed/2024/06/GHSA-m576-86pq-hpp4/GHSA-m576-86pq-hpp4.json +++ b/advisories/unreviewed/2024/06/GHSA-m576-86pq-hpp4/GHSA-m576-86pq-hpp4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m576-86pq-hpp4", - "modified": "2024-06-07T00:30:37Z", + "modified": "2024-07-16T15:30:44Z", "published": "2024-06-07T00:30:37Z", "aliases": [ "CVE-2024-36775" ], "details": "A cross-site scripting (XSS) vulnerability in Monstra CMS v3.0.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the About Me parameter in the Edit Profile page.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-06T22:15:10Z" diff --git a/advisories/unreviewed/2024/06/GHSA-mx74-c2vm-7fgr/GHSA-mx74-c2vm-7fgr.json b/advisories/unreviewed/2024/06/GHSA-mx74-c2vm-7fgr/GHSA-mx74-c2vm-7fgr.json index 7b4c7dc5dd0..e2d4a122762 100644 --- a/advisories/unreviewed/2024/06/GHSA-mx74-c2vm-7fgr/GHSA-mx74-c2vm-7fgr.json +++ b/advisories/unreviewed/2024/06/GHSA-mx74-c2vm-7fgr/GHSA-mx74-c2vm-7fgr.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-pgf2-jh8p-r4gg/GHSA-pgf2-jh8p-r4gg.json b/advisories/unreviewed/2024/06/GHSA-pgf2-jh8p-r4gg/GHSA-pgf2-jh8p-r4gg.json index 526be1af5ba..9c612abfe73 100644 --- a/advisories/unreviewed/2024/06/GHSA-pgf2-jh8p-r4gg/GHSA-pgf2-jh8p-r4gg.json +++ b/advisories/unreviewed/2024/06/GHSA-pgf2-jh8p-r4gg/GHSA-pgf2-jh8p-r4gg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pgf2-jh8p-r4gg", - "modified": "2024-06-13T21:30:55Z", + "modified": "2024-07-16T15:30:44Z", "published": "2024-06-13T21:30:55Z", "aliases": [ "CVE-2024-32902" ], "details": "Remote prevention of access to cellular service with no user interaction (for example, crashing the cellular radio service with a malformed packet)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-13T21:15:54Z" diff --git a/advisories/unreviewed/2024/06/GHSA-pqhj-hg4g-hg2v/GHSA-pqhj-hg4g-hg2v.json b/advisories/unreviewed/2024/06/GHSA-pqhj-hg4g-hg2v/GHSA-pqhj-hg4g-hg2v.json index e676cca17b7..a24f2f7e8ce 100644 --- a/advisories/unreviewed/2024/06/GHSA-pqhj-hg4g-hg2v/GHSA-pqhj-hg4g-hg2v.json +++ b/advisories/unreviewed/2024/06/GHSA-pqhj-hg4g-hg2v/GHSA-pqhj-hg4g-hg2v.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-2cmx-hh49-m5qp/GHSA-2cmx-hh49-m5qp.json b/advisories/unreviewed/2024/07/GHSA-2cmx-hh49-m5qp/GHSA-2cmx-hh49-m5qp.json new file mode 100644 index 00000000000..de5e04ede27 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-2cmx-hh49-m5qp/GHSA-2cmx-hh49-m5qp.json @@ -0,0 +1,63 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2cmx-hh49-m5qp", + "modified": "2024-07-16T15:30:47Z", + "published": "2024-07-16T15:30:47Z", + "aliases": [ + "CVE-2022-48836" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nInput: aiptek - properly check endpoint type\n\nSyzbot reported warning in usb_submit_urb() which is caused by wrong\nendpoint type. There was a check for the number of endpoints, but not\nfor the type of endpoint.\n\nFix it by replacing old desc.bNumEndpoints check with\nusb_find_common_endpoints() helper for finding endpoints\n\nFail log:\n\nusb 5-1: BOGUS urb xfer, pipe 1 != type 3\nWARNING: CPU: 2 PID: 48 at drivers/usb/core/urb.c:502 usb_submit_urb+0xed2/0x18a0 drivers/usb/core/urb.c:502\nModules linked in:\nCPU: 2 PID: 48 Comm: kworker/2:2 Not tainted 5.17.0-rc6-syzkaller-00226-g07ebd38a0da2 #0\nHardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.14.0-2 04/01/2014\nWorkqueue: usb_hub_wq hub_event\n...\nCall Trace:\n \n aiptek_open+0xd5/0x130 drivers/input/tablet/aiptek.c:830\n input_open_device+0x1bb/0x320 drivers/input/input.c:629\n kbd_connect+0xfe/0x160 drivers/tty/vt/keyboard.c:1593", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48836" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/35069e654bcab567ff8b9f0e68e1caf82c15dcd7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5600f6986628dde8881734090588474f54a540a8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/57277a8b5d881e02051ba9d7f6cb3f915c229821" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6de20111cd0bb7da9b2294073ba00c7d2a6c1c4f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e732b0412f8c603d1e998f3bff41b5e7d5c3914c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e762f57ff255af28236cd02ca9fc5c7e5a089d31" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f0d43d22d24182b94d7eb78a2bf6ae7e2b33204a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fc8033a55e2796d21e370260a784ac9fbb8305a6" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-16T13:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-2mxj-r96x-vpcm/GHSA-2mxj-r96x-vpcm.json b/advisories/unreviewed/2024/07/GHSA-2mxj-r96x-vpcm/GHSA-2mxj-r96x-vpcm.json new file mode 100644 index 00000000000..a41676a1369 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-2mxj-r96x-vpcm/GHSA-2mxj-r96x-vpcm.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2mxj-r96x-vpcm", + "modified": "2024-07-16T15:30:50Z", + "published": "2024-07-16T15:30:50Z", + "aliases": [ + "CVE-2022-48866" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: hid-thrustmaster: fix OOB read in thrustmaster_interrupts\n\nSyzbot reported an slab-out-of-bounds Read in thrustmaster_probe() bug.\nThe root case is in missing validation check of actual number of endpoints.\n\nCode should not blindly access usb_host_interface::endpoint array, since\nit may contain less endpoints than code expects.\n\nFix it by adding missing validaion check and print an error if\nnumber of endpoints do not match expected number", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48866" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3ffbe85cda7f523dad896bae08cecd8db8b555ab" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/56185434e1e50acecee56d8f5850135009b87947" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fc3ef2e3297b3c0e2006b5d7b3d66965e3392036" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-16T13:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-2q6j-vpvr-6pvj/GHSA-2q6j-vpvr-6pvj.json b/advisories/unreviewed/2024/07/GHSA-2q6j-vpvr-6pvj/GHSA-2q6j-vpvr-6pvj.json index 87c8c2e8987..0521f01d32a 100644 --- a/advisories/unreviewed/2024/07/GHSA-2q6j-vpvr-6pvj/GHSA-2q6j-vpvr-6pvj.json +++ b/advisories/unreviewed/2024/07/GHSA-2q6j-vpvr-6pvj/GHSA-2q6j-vpvr-6pvj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2q6j-vpvr-6pvj", - "modified": "2024-07-16T12:30:38Z", + "modified": "2024-07-16T15:30:46Z", "published": "2024-07-16T12:30:37Z", "aliases": [ "CVE-2024-39887" @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://lists.apache.org/thread/j55vm41jg3l0x6w49zrmvbf3k0ts5fqz" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/07/16/5" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/07/GHSA-3vcc-f634-j924/GHSA-3vcc-f634-j924.json b/advisories/unreviewed/2024/07/GHSA-3vcc-f634-j924/GHSA-3vcc-f634-j924.json new file mode 100644 index 00000000000..5677bd711ee --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-3vcc-f634-j924/GHSA-3vcc-f634-j924.json @@ -0,0 +1,63 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3vcc-f634-j924", + "modified": "2024-07-16T15:30:49Z", + "published": "2024-07-16T15:30:49Z", + "aliases": [ + "CVE-2022-48850" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet-sysfs: add check for netdevice being present to speed_show\n\nWhen bringing down the netdevice or system shutdown, a panic can be\ntriggered while accessing the sysfs path because the device is already\nremoved.\n\n [ 755.549084] mlx5_core 0000:12:00.1: Shutdown was called\n [ 756.404455] mlx5_core 0000:12:00.0: Shutdown was called\n ...\n [ 757.937260] BUG: unable to handle kernel NULL pointer dereference at (null)\n [ 758.031397] IP: [] dma_pool_alloc+0x1ab/0x280\n\n crash> bt\n ...\n PID: 12649 TASK: ffff8924108f2100 CPU: 1 COMMAND: \"amsd\"\n ...\n #9 [ffff89240e1a38b0] page_fault at ffffffff8f38c778\n [exception RIP: dma_pool_alloc+0x1ab]\n RIP: ffffffff8ee11acb RSP: ffff89240e1a3968 RFLAGS: 00010046\n RAX: 0000000000000246 RBX: ffff89243d874100 RCX: 0000000000001000\n RDX: 0000000000000000 RSI: 0000000000000246 RDI: ffff89243d874090\n RBP: ffff89240e1a39c0 R8: 000000000001f080 R9: ffff8905ffc03c00\n R10: ffffffffc04680d4 R11: ffffffff8edde9fd R12: 00000000000080d0\n R13: ffff89243d874090 R14: ffff89243d874080 R15: 0000000000000000\n ORIG_RAX: ffffffffffffffff CS: 0010 SS: 0018\n #10 [ffff89240e1a39c8] mlx5_alloc_cmd_msg at ffffffffc04680f3 [mlx5_core]\n #11 [ffff89240e1a3a18] cmd_exec at ffffffffc046ad62 [mlx5_core]\n #12 [ffff89240e1a3ab8] mlx5_cmd_exec at ffffffffc046b4fb [mlx5_core]\n #13 [ffff89240e1a3ae8] mlx5_core_access_reg at ffffffffc0475434 [mlx5_core]\n #14 [ffff89240e1a3b40] mlx5e_get_fec_caps at ffffffffc04a7348 [mlx5_core]\n #15 [ffff89240e1a3bb0] get_fec_supported_advertised at ffffffffc04992bf [mlx5_core]\n #16 [ffff89240e1a3c08] mlx5e_get_link_ksettings at ffffffffc049ab36 [mlx5_core]\n #17 [ffff89240e1a3ce8] __ethtool_get_link_ksettings at ffffffff8f25db46\n #18 [ffff89240e1a3d48] speed_show at ffffffff8f277208\n #19 [ffff89240e1a3dd8] dev_attr_show at ffffffff8f0b70e3\n #20 [ffff89240e1a3df8] sysfs_kf_seq_show at ffffffff8eedbedf\n #21 [ffff89240e1a3e18] kernfs_seq_show at ffffffff8eeda596\n #22 [ffff89240e1a3e28] seq_read at ffffffff8ee76d10\n #23 [ffff89240e1a3e98] kernfs_fop_read at ffffffff8eedaef5\n #24 [ffff89240e1a3ed8] vfs_read at ffffffff8ee4e3ff\n #25 [ffff89240e1a3f08] sys_read at ffffffff8ee4f27f\n #26 [ffff89240e1a3f50] system_call_fastpath at ffffffff8f395f92\n\n crash> net_device.state ffff89443b0c0000\n state = 0x5 (__LINK_STATE_START| __LINK_STATE_NOCARRIER)\n\nTo prevent this scenario, we also make sure that the netdevice is present.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48850" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/081369ad088a76429984483b8a5f7e967a125aad" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3a79f380b3e10edf6caa9aac90163a5d7a282204" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4224cfd7fb6523f7a9d1c8bb91bb5df1e38eb624" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/75fc8363227a999e8f3d17e2eb28dce5600dcd3f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8879b5313e9fa5e0c6d6812a0d25d83aed0110e2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8d5e69d8fbf3a35ab4fbe56b8f092802b43f3ef6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a7b9ab04c5932dee7ec95e0abc58b0df350c0dd2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d15c9f6e3335002fea1c33bc8f71a705fa96976c" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-16T13:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-48mq-mj2m-9cjq/GHSA-48mq-mj2m-9cjq.json b/advisories/unreviewed/2024/07/GHSA-48mq-mj2m-9cjq/GHSA-48mq-mj2m-9cjq.json new file mode 100644 index 00000000000..e045526b5ca --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-48mq-mj2m-9cjq/GHSA-48mq-mj2m-9cjq.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-48mq-mj2m-9cjq", + "modified": "2024-07-16T15:30:50Z", + "published": "2024-07-16T15:30:50Z", + "aliases": [ + "CVE-2024-32861" + ], + "details": "Under certain circumstances the Software House C●CURE 9000 Site Server provides insufficient protection of directories containing executables.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32861" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/ICSA-24-191-05" + }, + { + "type": "WEB", + "url": "https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-276" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-16T15:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-55x8-qm73-mrfg/GHSA-55x8-qm73-mrfg.json b/advisories/unreviewed/2024/07/GHSA-55x8-qm73-mrfg/GHSA-55x8-qm73-mrfg.json new file mode 100644 index 00000000000..2c0f3d4b484 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-55x8-qm73-mrfg/GHSA-55x8-qm73-mrfg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-55x8-qm73-mrfg", + "modified": "2024-07-16T15:30:50Z", + "published": "2024-07-16T15:30:50Z", + "aliases": [ + "CVE-2024-6435" + ], + "details": "A privilege escalation vulnerability exists in the affected products which could allow a malicious user with basic privileges to access functions which should only be available to users with administrative level privileges. If exploited, an attacker could read sensitive data, and create users. For example, a malicious user with basic privileges could perform critical functions such as creating a user with elevated privileges and reading sensitive information in the “views” section.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6435" + }, + { + "type": "WEB", + "url": "https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1681.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-732" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-16T13:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-59f9-39vx-2r92/GHSA-59f9-39vx-2r92.json b/advisories/unreviewed/2024/07/GHSA-59f9-39vx-2r92/GHSA-59f9-39vx-2r92.json index f346a71e607..e217a8088bb 100644 --- a/advisories/unreviewed/2024/07/GHSA-59f9-39vx-2r92/GHSA-59f9-39vx-2r92.json +++ b/advisories/unreviewed/2024/07/GHSA-59f9-39vx-2r92/GHSA-59f9-39vx-2r92.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-116", "CWE-644" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/07/GHSA-5gg7-q62c-m2hp/GHSA-5gg7-q62c-m2hp.json b/advisories/unreviewed/2024/07/GHSA-5gg7-q62c-m2hp/GHSA-5gg7-q62c-m2hp.json new file mode 100644 index 00000000000..b96c1967f54 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-5gg7-q62c-m2hp/GHSA-5gg7-q62c-m2hp.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5gg7-q62c-m2hp", + "modified": "2024-07-16T15:30:47Z", + "published": "2024-07-16T15:30:47Z", + "aliases": [ + "CVE-2022-48835" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: mpt3sas: Page fault in reply q processing\n\nA page fault was encountered in mpt3sas on a LUN reset error path:\n\n[ 145.763216] mpt3sas_cm1: Task abort tm failed: handle(0x0002),timeout(30) tr_method(0x0) smid(3) msix_index(0)\n[ 145.778932] scsi 1:0:0:0: task abort: FAILED scmd(0x0000000024ba29a2)\n[ 145.817307] scsi 1:0:0:0: attempting device reset! scmd(0x0000000024ba29a2)\n[ 145.827253] scsi 1:0:0:0: [sg1] tag#2 CDB: Receive Diagnostic 1c 01 01 ff fc 00\n[ 145.837617] scsi target1:0:0: handle(0x0002), sas_address(0x500605b0000272b9), phy(0)\n[ 145.848598] scsi target1:0:0: enclosure logical id(0x500605b0000272b8), slot(0)\n[ 149.858378] mpt3sas_cm1: Poll ReplyDescriptor queues for completion of smid(0), task_type(0x05), handle(0x0002)\n[ 149.875202] BUG: unable to handle page fault for address: 00000007fffc445d\n[ 149.885617] #PF: supervisor read access in kernel mode\n[ 149.894346] #PF: error_code(0x0000) - not-present page\n[ 149.903123] PGD 0 P4D 0\n[ 149.909387] Oops: 0000 [#1] PREEMPT SMP NOPTI\n[ 149.917417] CPU: 24 PID: 3512 Comm: scsi_eh_1 Kdump: loaded Tainted: G S O 5.10.89-altav-1 #1\n[ 149.934327] Hardware name: DDN 200NVX2 /200NVX2-MB , BIOS ATHG2.2.02.01 09/10/2021\n[ 149.951871] RIP: 0010:_base_process_reply_queue+0x4b/0x900 [mpt3sas]\n[ 149.961889] Code: 0f 84 22 02 00 00 8d 48 01 49 89 fd 48 8d 57 38 f0 0f b1 4f 38 0f 85 d8 01 00 00 49 8b 45 10 45 31 e4 41 8b 55 0c 48 8d 1c d0 <0f> b6 03 83 e0 0f 3c 0f 0f 85 a2 00 00 00 e9 e6 01 00 00 0f b7 ee\n[ 149.991952] RSP: 0018:ffffc9000f1ebcb8 EFLAGS: 00010246\n[ 150.000937] RAX: 0000000000000055 RBX: 00000007fffc445d RCX: 000000002548f071\n[ 150.011841] RDX: 00000000ffff8881 RSI: 0000000000000001 RDI: ffff888125ed50d8\n[ 150.022670] RBP: 0000000000000000 R08: 0000000000000000 R09: c0000000ffff7fff\n[ 150.033445] R10: ffffc9000f1ebb68 R11: ffffc9000f1ebb60 R12: 0000000000000000\n[ 150.044204] R13: ffff888125ed50d8 R14: 0000000000000080 R15: 34cdc00034cdea80\n[ 150.054963] FS: 0000000000000000(0000) GS:ffff88dfaf200000(0000) knlGS:0000000000000000\n[ 150.066715] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 150.076078] CR2: 00000007fffc445d CR3: 000000012448a006 CR4: 0000000000770ee0\n[ 150.086887] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n[ 150.097670] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n[ 150.108323] PKRU: 55555554\n[ 150.114690] Call Trace:\n[ 150.120497] ? printk+0x48/0x4a\n[ 150.127049] mpt3sas_scsih_issue_tm.cold.114+0x2e/0x2b3 [mpt3sas]\n[ 150.136453] mpt3sas_scsih_issue_locked_tm+0x86/0xb0 [mpt3sas]\n[ 150.145759] scsih_dev_reset+0xea/0x300 [mpt3sas]\n[ 150.153891] scsi_eh_ready_devs+0x541/0x9e0 [scsi_mod]\n[ 150.162206] ? __scsi_host_match+0x20/0x20 [scsi_mod]\n[ 150.170406] ? scsi_try_target_reset+0x90/0x90 [scsi_mod]\n[ 150.178925] ? blk_mq_tagset_busy_iter+0x45/0x60\n[ 150.186638] ? scsi_try_target_reset+0x90/0x90 [scsi_mod]\n[ 150.195087] scsi_error_handler+0x3a5/0x4a0 [scsi_mod]\n[ 150.203206] ? __schedule+0x1e9/0x610\n[ 150.209783] ? scsi_eh_get_sense+0x210/0x210 [scsi_mod]\n[ 150.217924] kthread+0x12e/0x150\n[ 150.224041] ? kthread_worker_fn+0x130/0x130\n[ 150.231206] ret_from_fork+0x1f/0x30\n\nThis is caused by mpt3sas_base_sync_reply_irqs() using an invalid reply_q\npointer outside of the list_for_each_entry() loop. At the end of the full\nlist traversal the pointer is invalid.\n\nMove the _base_process_reply_queue() call inside of the loop.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48835" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0cd2dd4bcf4abc812148c4943f966a3c8dccb00f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3916e33b917581e2b2086e856c291cb86ea98a05" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/69ad4ef868c1fc7609daa235dfa46d28ba7a3ba3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/98e7a654a5bebaf1a28e987af5e44c002544a413" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-16T13:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-697g-g69g-85cq/GHSA-697g-g69g-85cq.json b/advisories/unreviewed/2024/07/GHSA-697g-g69g-85cq/GHSA-697g-g69g-85cq.json new file mode 100644 index 00000000000..69638a53c05 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-697g-g69g-85cq/GHSA-697g-g69g-85cq.json @@ -0,0 +1,63 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-697g-g69g-85cq", + "modified": "2024-07-16T15:30:47Z", + "published": "2024-07-16T15:30:47Z", + "aliases": [ + "CVE-2022-48838" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: Fix use-after-free bug by not setting udc->dev.driver\n\nThe syzbot fuzzer found a use-after-free bug:\n\nBUG: KASAN: use-after-free in dev_uevent+0x712/0x780 drivers/base/core.c:2320\nRead of size 8 at addr ffff88802b934098 by task udevd/3689\n\nCPU: 2 PID: 3689 Comm: udevd Not tainted 5.17.0-rc4-syzkaller-00229-g4f12b742eb2b #0\nHardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.14.0-2 04/01/2014\nCall Trace:\n \n __dump_stack lib/dump_stack.c:88 [inline]\n dump_stack_lvl+0xcd/0x134 lib/dump_stack.c:106\n print_address_description.constprop.0.cold+0x8d/0x303 mm/kasan/report.c:255\n __kasan_report mm/kasan/report.c:442 [inline]\n kasan_report.cold+0x83/0xdf mm/kasan/report.c:459\n dev_uevent+0x712/0x780 drivers/base/core.c:2320\n uevent_show+0x1b8/0x380 drivers/base/core.c:2391\n dev_attr_show+0x4b/0x90 drivers/base/core.c:2094\n\nAlthough the bug manifested in the driver core, the real cause was a\nrace with the gadget core. dev_uevent() does:\n\n\tif (dev->driver)\n\t\tadd_uevent_var(env, \"DRIVER=%s\", dev->driver->name);\n\nand between the test and the dereference of dev->driver, the gadget\ncore sets dev->driver to NULL.\n\nThe race wouldn't occur if the gadget core registered its devices on\na real bus, using the standard synchronization techniques of the\ndriver core. However, it's not necessary to make such a large change\nin order to fix this bug; all we need to do is make sure that\nudc->dev.driver is always NULL.\n\nIn fact, there is no reason for udc->dev.driver ever to be set to\nanything, let alone to the value it currently gets: the address of the\ngadget's driver. After all, a gadget driver only knows how to manage\na gadget, not how to manage a UDC.\n\nThis patch simply removes the statements in the gadget core that touch\nudc->dev.driver.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48838" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/00bdd9bf1ac6d401ad926d3d8df41b9f1399f646" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/16b1941eac2bd499f065a6739a40ce0011a3d740" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2015c23610cd0efadaeca4d3a8d1dae9a45aa35a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2282a6eb6d4e118e294e43dcc421e0e0fe4040b5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/27d64436984fb8835a8b7e95993193cc478b162e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4325124dde6726267813c736fee61226f1d38f0b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/609a7119bffe3ddd7c93f2fa65be8917e02a0b7e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e2d3a7009e505e120805f449c832942660f3f7f3" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-16T13:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-6g4r-v8v9-hj9h/GHSA-6g4r-v8v9-hj9h.json b/advisories/unreviewed/2024/07/GHSA-6g4r-v8v9-hj9h/GHSA-6g4r-v8v9-hj9h.json new file mode 100644 index 00000000000..b3de04771f9 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-6g4r-v8v9-hj9h/GHSA-6g4r-v8v9-hj9h.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6g4r-v8v9-hj9h", + "modified": "2024-07-16T15:30:50Z", + "published": "2024-07-16T15:30:50Z", + "aliases": [ + "CVE-2022-48864" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nvdpa/mlx5: add validation for VIRTIO_NET_CTRL_MQ_VQ_PAIRS_SET command\n\nWhen control vq receives a VIRTIO_NET_CTRL_MQ_VQ_PAIRS_SET command\nrequest from the driver, presently there is no validation against the\nnumber of queue pairs to configure, or even if multiqueue had been\nnegotiated or not is unverified. This may lead to kernel panic due to\nuninitialized resource for the queues were there any bogus request\nsent down by untrusted driver. Tie up the loose ends there.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48864" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9f6effca75626c7a7c7620dabcb1a254ca530230" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e7e118416465f2ba8b55007e5b789823e101421e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ed0f849fc3a63ed2ddf5e72cdb1de3bdbbb0f8eb" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-16T13:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-6gcc-c84m-wqv4/GHSA-6gcc-c84m-wqv4.json b/advisories/unreviewed/2024/07/GHSA-6gcc-c84m-wqv4/GHSA-6gcc-c84m-wqv4.json new file mode 100644 index 00000000000..13f55389330 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-6gcc-c84m-wqv4/GHSA-6gcc-c84m-wqv4.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6gcc-c84m-wqv4", + "modified": "2024-07-16T15:30:49Z", + "published": "2024-07-16T15:30:49Z", + "aliases": [ + "CVE-2022-48848" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntracing/osnoise: Do not unregister events twice\n\nNicolas reported that using:\n\n # trace-cmd record -e all -M 10 -p osnoise --poll\n\nResulted in the following kernel warning:\n\n ------------[ cut here ]------------\n WARNING: CPU: 0 PID: 1217 at kernel/tracepoint.c:404 tracepoint_probe_unregister+0x280/0x370\n [...]\n CPU: 0 PID: 1217 Comm: trace-cmd Not tainted 5.17.0-rc6-next-20220307-nico+ #19\n RIP: 0010:tracepoint_probe_unregister+0x280/0x370\n [...]\n CR2: 00007ff919b29497 CR3: 0000000109da4005 CR4: 0000000000170ef0\n Call Trace:\n \n osnoise_workload_stop+0x36/0x90\n tracing_set_tracer+0x108/0x260\n tracing_set_trace_write+0x94/0xd0\n ? __check_object_size.part.0+0x10a/0x150\n ? selinux_file_permission+0x104/0x150\n vfs_write+0xb5/0x290\n ksys_write+0x5f/0xe0\n do_syscall_64+0x3b/0x90\n entry_SYSCALL_64_after_hwframe+0x44/0xae\n RIP: 0033:0x7ff919a18127\n [...]\n ---[ end trace 0000000000000000 ]---\n\nThe warning complains about an attempt to unregister an\nunregistered tracepoint.\n\nThis happens on trace-cmd because it first stops tracing, and\nthen switches the tracer to nop. Which is equivalent to:\n\n # cd /sys/kernel/tracing/\n # echo osnoise > current_tracer\n # echo 0 > tracing_on\n # echo nop > current_tracer\n\nThe osnoise tracer stops the workload when no trace instance\nis actually collecting data. This can be caused both by\ndisabling tracing or disabling the tracer itself.\n\nTo avoid unregistering events twice, use the existing\ntrace_osnoise_callback_enabled variable to check if the events\n(and the workload) are actually active before trying to\ndeactivate them.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48848" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4e10787d18379d9b296290c2288097feddef16d4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f0cfe17bcc1dd2f0872966b554a148e888833ee9" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-16T13:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-73j8-r39c-jxp6/GHSA-73j8-r39c-jxp6.json b/advisories/unreviewed/2024/07/GHSA-73j8-r39c-jxp6/GHSA-73j8-r39c-jxp6.json new file mode 100644 index 00000000000..5214fc2a750 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-73j8-r39c-jxp6/GHSA-73j8-r39c-jxp6.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-73j8-r39c-jxp6", + "modified": "2024-07-16T15:30:49Z", + "published": "2024-07-16T15:30:49Z", + "aliases": [ + "CVE-2022-48846" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nblock: release rq qos structures for queue without disk\n\nblkcg_init_queue() may add rq qos structures to request queue, previously\nblk_cleanup_queue() calls rq_qos_exit() to release them, but commit\n8e141f9eb803 (\"block: drain file system I/O on del_gendisk\")\nmoves rq_qos_exit() into del_gendisk(), so memory leak is caused\nbecause queues may not have disk, such as un-present scsi luns, nvme\nadmin queue, ...\n\nFixes the issue by adding rq_qos_exit() to blk_cleanup_queue() back.\n\nBTW, v5.18 won't need this patch any more since we move\nblkcg_init_queue()/blkcg_exit_queue() into disk allocation/release\nhandler, and patches have been in for-5.18/block.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48846" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/60c2c8e2ef3a3ec79de8cbc80a06ca0c21df8c29" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d4ad8736ac982111bb0be8306bf19c8207f6600e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/daaca3522a8e67c46e39ef09c1d542e866f85f3b" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-16T13:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-74mq-wr7w-wwvw/GHSA-74mq-wr7w-wwvw.json b/advisories/unreviewed/2024/07/GHSA-74mq-wr7w-wwvw/GHSA-74mq-wr7w-wwvw.json new file mode 100644 index 00000000000..f69b2e7ad7e --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-74mq-wr7w-wwvw/GHSA-74mq-wr7w-wwvw.json @@ -0,0 +1,63 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-74mq-wr7w-wwvw", + "modified": "2024-07-16T15:30:50Z", + "published": "2024-07-16T15:30:50Z", + "aliases": [ + "CVE-2022-48855" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: fix kernel-infoleak for SCTP sockets\n\nsyzbot reported a kernel infoleak [1] of 4 bytes.\n\nAfter analysis, it turned out r->idiag_expires is not initialized\nif inet_sctp_diag_fill() calls inet_diag_msg_common_fill()\n\nMake sure to clear idiag_timer/idiag_retrans/idiag_expires\nand let inet_diag_msg_sctpasoc_fill() fill them again if needed.\n\n[1]\n\nBUG: KMSAN: kernel-infoleak in instrument_copy_to_user include/linux/instrumented.h:121 [inline]\nBUG: KMSAN: kernel-infoleak in copyout lib/iov_iter.c:154 [inline]\nBUG: KMSAN: kernel-infoleak in _copy_to_iter+0x6ef/0x25a0 lib/iov_iter.c:668\n instrument_copy_to_user include/linux/instrumented.h:121 [inline]\n copyout lib/iov_iter.c:154 [inline]\n _copy_to_iter+0x6ef/0x25a0 lib/iov_iter.c:668\n copy_to_iter include/linux/uio.h:162 [inline]\n simple_copy_to_iter+0xf3/0x140 net/core/datagram.c:519\n __skb_datagram_iter+0x2d5/0x11b0 net/core/datagram.c:425\n skb_copy_datagram_iter+0xdc/0x270 net/core/datagram.c:533\n skb_copy_datagram_msg include/linux/skbuff.h:3696 [inline]\n netlink_recvmsg+0x669/0x1c80 net/netlink/af_netlink.c:1977\n sock_recvmsg_nosec net/socket.c:948 [inline]\n sock_recvmsg net/socket.c:966 [inline]\n __sys_recvfrom+0x795/0xa10 net/socket.c:2097\n __do_sys_recvfrom net/socket.c:2115 [inline]\n __se_sys_recvfrom net/socket.c:2111 [inline]\n __x64_sys_recvfrom+0x19d/0x210 net/socket.c:2111\n do_syscall_x64 arch/x86/entry/common.c:51 [inline]\n do_syscall_64+0x54/0xd0 arch/x86/entry/common.c:82\n entry_SYSCALL_64_after_hwframe+0x44/0xae\n\nUninit was created at:\n slab_post_alloc_hook mm/slab.h:737 [inline]\n slab_alloc_node mm/slub.c:3247 [inline]\n __kmalloc_node_track_caller+0xe0c/0x1510 mm/slub.c:4975\n kmalloc_reserve net/core/skbuff.c:354 [inline]\n __alloc_skb+0x545/0xf90 net/core/skbuff.c:426\n alloc_skb include/linux/skbuff.h:1158 [inline]\n netlink_dump+0x3e5/0x16c0 net/netlink/af_netlink.c:2248\n __netlink_dump_start+0xcf8/0xe90 net/netlink/af_netlink.c:2373\n netlink_dump_start include/linux/netlink.h:254 [inline]\n inet_diag_handler_cmd+0x2e7/0x400 net/ipv4/inet_diag.c:1341\n sock_diag_rcv_msg+0x24a/0x620\n netlink_rcv_skb+0x40c/0x7e0 net/netlink/af_netlink.c:2494\n sock_diag_rcv+0x63/0x80 net/core/sock_diag.c:277\n netlink_unicast_kernel net/netlink/af_netlink.c:1317 [inline]\n netlink_unicast+0x1093/0x1360 net/netlink/af_netlink.c:1343\n netlink_sendmsg+0x14d9/0x1720 net/netlink/af_netlink.c:1919\n sock_sendmsg_nosec net/socket.c:705 [inline]\n sock_sendmsg net/socket.c:725 [inline]\n sock_write_iter+0x594/0x690 net/socket.c:1061\n do_iter_readv_writev+0xa7f/0xc70\n do_iter_write+0x52c/0x1500 fs/read_write.c:851\n vfs_writev fs/read_write.c:924 [inline]\n do_writev+0x645/0xe00 fs/read_write.c:967\n __do_sys_writev fs/read_write.c:1040 [inline]\n __se_sys_writev fs/read_write.c:1037 [inline]\n __x64_sys_writev+0xe5/0x120 fs/read_write.c:1037\n do_syscall_x64 arch/x86/entry/common.c:51 [inline]\n do_syscall_64+0x54/0xd0 arch/x86/entry/common.c:82\n entry_SYSCALL_64_after_hwframe+0x44/0xae\n\nBytes 68-71 of 2508 are uninitialized\nMemory access of size 2508 starts at ffff888114f9b000\nData copied to user address 00007f7fe09ff2e0\n\nCPU: 1 PID: 3478 Comm: syz-executor306 Not tainted 5.17.0-rc4-syzkaller #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48855" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1502f15b9f29c41883a6139f2923523873282a83" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2d8fa3fdf4542a2174a72d92018f488d65d848c5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3fc0fd724d199e061432b66a8d85b7d48fe485f7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/41a2864cf719c17294f417726edd411643462ab8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/633593a808980f82d251d0ca89730d8bb8b0220c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b7e4d9ba2ddb78801488b4c623875b81fb46b545" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bbf59d7ae558940cfa2b36a287fd1e88d83f89f8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d828b0fe6631f3ae8709ac9a10c77c5836c76a08" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-16T13:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-7hc6-qhpj-2x7q/GHSA-7hc6-qhpj-2x7q.json b/advisories/unreviewed/2024/07/GHSA-7hc6-qhpj-2x7q/GHSA-7hc6-qhpj-2x7q.json new file mode 100644 index 00000000000..63a85bb262c --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-7hc6-qhpj-2x7q/GHSA-7hc6-qhpj-2x7q.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7hc6-qhpj-2x7q", + "modified": "2024-07-16T15:30:47Z", + "published": "2024-07-16T15:30:47Z", + "aliases": [ + "CVE-2022-48834" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: usbtmc: Fix bug in pipe direction for control transfers\n\nThe syzbot fuzzer reported a minor bug in the usbtmc driver:\n\nusb 5-1: BOGUS control dir, pipe 80001e80 doesn't match bRequestType 0\nWARNING: CPU: 0 PID: 3813 at drivers/usb/core/urb.c:412\nusb_submit_urb+0x13a5/0x1970 drivers/usb/core/urb.c:410\nModules linked in:\nCPU: 0 PID: 3813 Comm: syz-executor122 Not tainted\n5.17.0-rc5-syzkaller-00306-g2293be58d6a1 #0\n...\nCall Trace:\n \n usb_start_wait_urb+0x113/0x530 drivers/usb/core/message.c:58\n usb_internal_control_msg drivers/usb/core/message.c:102 [inline]\n usb_control_msg+0x2a5/0x4b0 drivers/usb/core/message.c:153\n usbtmc_ioctl_request drivers/usb/class/usbtmc.c:1947 [inline]\n\nThe problem is that usbtmc_ioctl_request() uses usb_rcvctrlpipe() for\nall of its transfers, whether they are in or out. It's easy to fix.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48834" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/10a805334a11acd547602d6c4cf540a0f6ab5c6e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5f6a2d63c68c12cf61259df7c3527a0e05dce952" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/700a0715854c1e79a73341724ce4f5bb01abc016" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c69aef9db878ab277068a8cc1b4bf0cf309dc2b7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e9b667a82cdcfe21d590344447d65daed52b353b" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-16T13:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-7pgp-w5jc-4xjm/GHSA-7pgp-w5jc-4xjm.json b/advisories/unreviewed/2024/07/GHSA-7pgp-w5jc-4xjm/GHSA-7pgp-w5jc-4xjm.json new file mode 100644 index 00000000000..22fb2104dc6 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-7pgp-w5jc-4xjm/GHSA-7pgp-w5jc-4xjm.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7pgp-w5jc-4xjm", + "modified": "2024-07-16T15:30:48Z", + "published": "2024-07-16T15:30:48Z", + "aliases": [ + "CVE-2022-48841" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nice: fix NULL pointer dereference in ice_update_vsi_tx_ring_stats()\n\nIt is possible to do NULL pointer dereference in routine that updates\nTx ring stats. Currently only stats and bytes are updated when ring\npointer is valid, but later on ring is accessed to propagate gathered Tx\nstats onto VSI stats.\n\nChange the existing logic to move to next ring when ring is NULL.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48841" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2397270ec97c5e3009a58ac110a25e1869e9d6ff" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f153546913bada41a811722f2c6d17c3243a0333" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-16T13:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-7vfx-qp7p-vwcw/GHSA-7vfx-qp7p-vwcw.json b/advisories/unreviewed/2024/07/GHSA-7vfx-qp7p-vwcw/GHSA-7vfx-qp7p-vwcw.json new file mode 100644 index 00000000000..6ec08c227a3 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-7vfx-qp7p-vwcw/GHSA-7vfx-qp7p-vwcw.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7vfx-qp7p-vwcw", + "modified": "2024-07-16T15:30:49Z", + "published": "2024-07-16T15:30:49Z", + "aliases": [ + "CVE-2022-48849" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: bypass tiling flag check in virtual display case (v2)\n\nvkms leverages common amdgpu framebuffer creation, and\nalso as it does not support FB modifier, there is no need\nto check tiling flags when initing framebuffer when virtual\ndisplay is enabled.\n\nThis can fix below calltrace:\n\namdgpu 0000:00:08.0: GFX9+ requires FB check based on format modifier\nWARNING: CPU: 0 PID: 1023 at drivers/gpu/drm/amd/amdgpu/amdgpu_display.c:1150 amdgpu_display_framebuffer_init+0x8e7/0xb40 [amdgpu]\n\nv2: check adev->enable_virtual_display instead as vkms can be\n\tenabled in bare metal as well.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48849" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cb29021be49858059138f75d6311a7c35a9379b2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e2b993302f40c4eb714ecf896dd9e1c5be7d4cd7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fcd1d79aa943fff4fbaa0cce1d576995a7960699" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-16T13:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-8hqr-2pq7-7gv3/GHSA-8hqr-2pq7-7gv3.json b/advisories/unreviewed/2024/07/GHSA-8hqr-2pq7-7gv3/GHSA-8hqr-2pq7-7gv3.json new file mode 100644 index 00000000000..d83bc4ae3e4 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-8hqr-2pq7-7gv3/GHSA-8hqr-2pq7-7gv3.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8hqr-2pq7-7gv3", + "modified": "2024-07-16T15:30:50Z", + "published": "2024-07-16T15:30:50Z", + "aliases": [ + "CVE-2022-48858" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: Fix a race on command flush flow\n\nFix a refcount use after free warning due to a race on command entry.\nSuch race occurs when one of the commands releases its last refcount and\nfrees its index and entry while another process running command flush\nflow takes refcount to this command entry. The process which handles\ncommands flush may see this command as needed to be flushed if the other\nprocess released its refcount but didn't release the index yet. Fix it\nby adding the needed spin lock.\n\nIt fixes the following warning trace:\n\nrefcount_t: addition on 0; use-after-free.\nWARNING: CPU: 11 PID: 540311 at lib/refcount.c:25 refcount_warn_saturate+0x80/0xe0\n...\nRIP: 0010:refcount_warn_saturate+0x80/0xe0\n...\nCall Trace:\n \n mlx5_cmd_trigger_completions+0x293/0x340 [mlx5_core]\n mlx5_cmd_flush+0x3a/0xf0 [mlx5_core]\n enter_error_state+0x44/0x80 [mlx5_core]\n mlx5_fw_fatal_reporter_err_work+0x37/0xe0 [mlx5_core]\n process_one_work+0x1be/0x390\n worker_thread+0x4d/0x3d0\n ? rescuer_thread+0x350/0x350\n kthread+0x141/0x160\n ? set_kthread_struct+0x40/0x40\n ret_from_fork+0x1f/0x30\n ", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48858" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0401bfb27a91d7bdd74b1635c1aae57cbb128da6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/063bd355595428750803d8736a9bb7c8db67d42d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1a4017926eeea56c7540cc41b42106746ee8a0ee" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7c519f769f555ff7d9d4ccba3497bbb589df360a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f3331bc17449f15832c31823f27573f4c0e13e5f" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-16T13:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-8rjj-j4hj-jc98/GHSA-8rjj-j4hj-jc98.json b/advisories/unreviewed/2024/07/GHSA-8rjj-j4hj-jc98/GHSA-8rjj-j4hj-jc98.json new file mode 100644 index 00000000000..4761d9d7c06 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-8rjj-j4hj-jc98/GHSA-8rjj-j4hj-jc98.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8rjj-j4hj-jc98", + "modified": "2024-07-16T15:30:50Z", + "published": "2024-07-16T15:30:50Z", + "aliases": [ + "CVE-2022-48859" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: marvell: prestera: Add missing of_node_put() in prestera_switch_set_base_mac_addr\n\nThis node pointer is returned by of_find_compatible_node() with\nrefcount incremented. Calling of_node_put() to aovid the refcount leak.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48859" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4cc66bf17220ff9631f9fa99b02a872e0ad5a08b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b7c2fd1d126329340639adfb8dd2938fe4b65df7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c9ffa3e2bc451816ce0295e40063514fabf2bd36" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-16T13:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-97c5-prqj-77gq/GHSA-97c5-prqj-77gq.json b/advisories/unreviewed/2024/07/GHSA-97c5-prqj-77gq/GHSA-97c5-prqj-77gq.json new file mode 100644 index 00000000000..b15bdfb9385 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-97c5-prqj-77gq/GHSA-97c5-prqj-77gq.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-97c5-prqj-77gq", + "modified": "2024-07-16T15:30:50Z", + "published": "2024-07-16T15:30:50Z", + "aliases": [ + "CVE-2022-48865" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: fix kernel panic when enabling bearer\n\nWhen enabling a bearer on a node, a kernel panic is observed:\n\n[ 4.498085] RIP: 0010:tipc_mon_prep+0x4e/0x130 [tipc]\n...\n[ 4.520030] Call Trace:\n[ 4.520689] \n[ 4.521236] tipc_link_build_proto_msg+0x375/0x750 [tipc]\n[ 4.522654] tipc_link_build_state_msg+0x48/0xc0 [tipc]\n[ 4.524034] __tipc_node_link_up+0xd7/0x290 [tipc]\n[ 4.525292] tipc_rcv+0x5da/0x730 [tipc]\n[ 4.526346] ? __netif_receive_skb_core+0xb7/0xfc0\n[ 4.527601] tipc_l2_rcv_msg+0x5e/0x90 [tipc]\n[ 4.528737] __netif_receive_skb_list_core+0x20b/0x260\n[ 4.530068] netif_receive_skb_list_internal+0x1bf/0x2e0\n[ 4.531450] ? dev_gro_receive+0x4c2/0x680\n[ 4.532512] napi_complete_done+0x6f/0x180\n[ 4.533570] virtnet_poll+0x29c/0x42e [virtio_net]\n...\n\nThe node in question is receiving activate messages in another\nthread after changing bearer status to allow message sending/\nreceiving in current thread:\n\n thread 1 | thread 2\n -------- | --------\n |\ntipc_enable_bearer() |\n test_and_set_bit_lock() |\n tipc_bearer_xmit_skb() |\n | tipc_l2_rcv_msg()\n | tipc_rcv()\n | __tipc_node_link_up()\n | tipc_link_build_state_msg()\n | tipc_link_build_proto_msg()\n | tipc_mon_prep()\n | {\n | ...\n | // null-pointer dereference\n | u16 gen = mon->dom_gen;\n | ...\n | }\n // Not being executed yet |\n tipc_mon_create() |\n { |\n ... |\n // allocate |\n mon = kzalloc(); |\n ... |\n } |\n\nMonitoring pointer in thread 2 is dereferenced before monitoring data\nis allocated in thread 1. This causes kernel panic.\n\nThis commit fixes it by allocating the monitoring data before enabling\nthe bearer to receive messages.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48865" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2de76d37d4a6dca9b96ea51da24d4290e6cfa1a5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/be4977b847f5d5cedb64d50eaaf2218c3a55a3a3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f4f59fdbc748805b08c13dae14c01f0518c77c94" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f96dc3adb9a97b8f3dfdb88796483491a3006b71" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-16T13:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-9c8v-c8p9-2pjh/GHSA-9c8v-c8p9-2pjh.json b/advisories/unreviewed/2024/07/GHSA-9c8v-c8p9-2pjh/GHSA-9c8v-c8p9-2pjh.json new file mode 100644 index 00000000000..c3b6d6aab99 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-9c8v-c8p9-2pjh/GHSA-9c8v-c8p9-2pjh.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9c8v-c8p9-2pjh", + "modified": "2024-07-16T15:30:50Z", + "published": "2024-07-16T15:30:50Z", + "aliases": [ + "CVE-2022-48861" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nvdpa: fix use-after-free on vp_vdpa_remove\n\nWhen vp_vdpa driver is unbind, vp_vdpa is freed in vdpa_unregister_device\nand then vp_vdpa->mdev.pci_dev is dereferenced in vp_modern_remove,\ntriggering use-after-free.\n\nCall Trace of unbinding driver free vp_vdpa :\ndo_syscall_64\n vfs_write\n kernfs_fop_write_iter\n device_release_driver_internal\n pci_device_remove\n vp_vdpa_remove\n vdpa_unregister_device\n kobject_release\n device_release\n kfree\n\nCall Trace of dereference vp_vdpa->mdev.pci_dev:\nvp_modern_remove\n pci_release_selected_regions\n pci_release_region\n pci_resource_len\n pci_resource_end\n (dev)->resource[(bar)].end", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48861" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4b1743bc715a3691a63ac21b349079b07bf1b19e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/dc54ba9932aeaaa1a21fe214af1f446593a78274" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/eb057b44dbe35ae14527830236a92f51de8f9184" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-16T13:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-9j87-4jmc-mrvg/GHSA-9j87-4jmc-mrvg.json b/advisories/unreviewed/2024/07/GHSA-9j87-4jmc-mrvg/GHSA-9j87-4jmc-mrvg.json new file mode 100644 index 00000000000..671f6677d74 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-9j87-4jmc-mrvg/GHSA-9j87-4jmc-mrvg.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9j87-4jmc-mrvg", + "modified": "2024-07-16T15:30:48Z", + "published": "2024-07-16T15:30:48Z", + "aliases": [ + "CVE-2022-48843" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/vrr: Set VRR capable prop only if it is attached to connector\n\nVRR capable property is not attached by default to the connector\nIt is attached only if VRR is supported.\nSo if the driver tries to call drm core set prop function without\nit being attached that causes NULL dereference.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48843" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0ba557d330946c23559aaea2d51ea649fdeca98a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3534c5c005ef99a1804ed50b8a72cdae254cabb5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/62929726ef0ec72cbbe9440c5d125d4278b99894" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/85271e92ae4f13aa679acaa6cf76b3c36bcb7bab" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/941e8bcd2b2ba95490738e33dfeca27168452779" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-16T13:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-9pfw-fqv3-483p/GHSA-9pfw-fqv3-483p.json b/advisories/unreviewed/2024/07/GHSA-9pfw-fqv3-483p/GHSA-9pfw-fqv3-483p.json new file mode 100644 index 00000000000..2d214694109 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-9pfw-fqv3-483p/GHSA-9pfw-fqv3-483p.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9pfw-fqv3-483p", + "modified": "2024-07-16T15:30:48Z", + "published": "2024-07-16T15:30:48Z", + "aliases": [ + "CVE-2022-48842" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nice: Fix race condition during interface enslave\n\nCommit 5dbbbd01cbba83 (\"ice: Avoid RTNL lock when re-creating\nauxiliary device\") changes a process of re-creation of aux device\nso ice_plug_aux_dev() is called from ice_service_task() context.\nThis unfortunately opens a race window that can result in dead-lock\nwhen interface has left LAG and immediately enters LAG again.\n\nReproducer:\n```\n#!/bin/sh\n\nip link add lag0 type bond mode 1 miimon 100\nip link set lag0\n\nfor n in {1..10}; do\n echo Cycle: $n\n ip link set ens7f0 master lag0\n sleep 1\n ip link set ens7f0 nomaster\ndone\n```\n\nThis results in:\n[20976.208697] Workqueue: ice ice_service_task [ice]\n[20976.213422] Call Trace:\n[20976.215871] __schedule+0x2d1/0x830\n[20976.219364] schedule+0x35/0xa0\n[20976.222510] schedule_preempt_disabled+0xa/0x10\n[20976.227043] __mutex_lock.isra.7+0x310/0x420\n[20976.235071] enum_all_gids_of_dev_cb+0x1c/0x100 [ib_core]\n[20976.251215] ib_enum_roce_netdev+0xa4/0xe0 [ib_core]\n[20976.256192] ib_cache_setup_one+0x33/0xa0 [ib_core]\n[20976.261079] ib_register_device+0x40d/0x580 [ib_core]\n[20976.266139] irdma_ib_register_device+0x129/0x250 [irdma]\n[20976.281409] irdma_probe+0x2c1/0x360 [irdma]\n[20976.285691] auxiliary_bus_probe+0x45/0x70\n[20976.289790] really_probe+0x1f2/0x480\n[20976.298509] driver_probe_device+0x49/0xc0\n[20976.302609] bus_for_each_drv+0x79/0xc0\n[20976.306448] __device_attach+0xdc/0x160\n[20976.310286] bus_probe_device+0x9d/0xb0\n[20976.314128] device_add+0x43c/0x890\n[20976.321287] __auxiliary_device_add+0x43/0x60\n[20976.325644] ice_plug_aux_dev+0xb2/0x100 [ice]\n[20976.330109] ice_service_task+0xd0c/0xed0 [ice]\n[20976.342591] process_one_work+0x1a7/0x360\n[20976.350536] worker_thread+0x30/0x390\n[20976.358128] kthread+0x10a/0x120\n[20976.365547] ret_from_fork+0x1f/0x40\n...\n[20976.438030] task:ip state:D stack: 0 pid:213658 ppid:213627 flags:0x00004084\n[20976.446469] Call Trace:\n[20976.448921] __schedule+0x2d1/0x830\n[20976.452414] schedule+0x35/0xa0\n[20976.455559] schedule_preempt_disabled+0xa/0x10\n[20976.460090] __mutex_lock.isra.7+0x310/0x420\n[20976.464364] device_del+0x36/0x3c0\n[20976.467772] ice_unplug_aux_dev+0x1a/0x40 [ice]\n[20976.472313] ice_lag_event_handler+0x2a2/0x520 [ice]\n[20976.477288] notifier_call_chain+0x47/0x70\n[20976.481386] __netdev_upper_dev_link+0x18b/0x280\n[20976.489845] bond_enslave+0xe05/0x1790 [bonding]\n[20976.494475] do_setlink+0x336/0xf50\n[20976.502517] __rtnl_newlink+0x529/0x8b0\n[20976.543441] rtnl_newlink+0x43/0x60\n[20976.546934] rtnetlink_rcv_msg+0x2b1/0x360\n[20976.559238] netlink_rcv_skb+0x4c/0x120\n[20976.563079] netlink_unicast+0x196/0x230\n[20976.567005] netlink_sendmsg+0x204/0x3d0\n[20976.570930] sock_sendmsg+0x4c/0x50\n[20976.574423] ____sys_sendmsg+0x1eb/0x250\n[20976.586807] ___sys_sendmsg+0x7c/0xc0\n[20976.606353] __sys_sendmsg+0x57/0xa0\n[20976.609930] do_syscall_64+0x5b/0x1a0\n[20976.613598] entry_SYSCALL_64_after_hwframe+0x65/0xca\n\n1. Command 'ip link ... set nomaster' causes that ice_plug_aux_dev()\n is called from ice_service_task() context, aux device is created\n and associated device->lock is taken.\n2. Command 'ip link ... set master...' calls ice's notifier under\n RTNL lock and that notifier calls ice_unplug_aux_dev(). That\n function tries to take aux device->lock but this is already taken\n by ice_plug_aux_dev() in step 1\n3. Later ice_plug_aux_dev() tries to take RTNL lock but this is already\n taken in step 2\n4. Dead-lock\n\nThe patch fixes this issue by following changes:\n- Bit ICE_FLAG_PLUG_AUX_DEV is kept to be set during ice_plug_aux_dev()\n call in ice_service_task()\n- The bit is checked in ice_clear_rdma_cap() and only if it is not set\n then ice_unplug_aux_dev() is called. If it is set (in other words\n plugging of aux device was requested and ice_plug_aux_dev() is\n potentially running) then the function only clears the\n---truncated---", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48842" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5cb1ebdbc4342b1c2ce89516e19808d64417bdbc" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a9bbacc53d1f5ed8febbfdf31401d20e005f49ef" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e1014fc5572375658fa421531cedb6e084f477dc" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-16T13:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-cqc3-8mfm-84p4/GHSA-cqc3-8mfm-84p4.json b/advisories/unreviewed/2024/07/GHSA-cqc3-8mfm-84p4/GHSA-cqc3-8mfm-84p4.json new file mode 100644 index 00000000000..c54e5f95c03 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-cqc3-8mfm-84p4/GHSA-cqc3-8mfm-84p4.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cqc3-8mfm-84p4", + "modified": "2024-07-16T15:30:50Z", + "published": "2024-07-16T15:30:50Z", + "aliases": [ + "CVE-2022-48862" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nvhost: fix hung thread due to erroneous iotlb entries\n\nIn vhost_iotlb_add_range_ctx(), range size can overflow to 0 when\nstart is 0 and last is ULONG_MAX. One instance where it can happen\nis when userspace sends an IOTLB message with iova=size=uaddr=0\n(vhost_process_iotlb_msg). So, an entry with size = 0, start = 0,\nlast = ULONG_MAX ends up in the iotlb. Next time a packet is sent,\niotlb_access_ok() loops indefinitely due to that erroneous entry.\n\n\tCall Trace:\n\t \n\t iotlb_access_ok+0x21b/0x3e0 drivers/vhost/vhost.c:1340\n\t vq_meta_prefetch+0xbc/0x280 drivers/vhost/vhost.c:1366\n\t vhost_transport_do_send_pkt+0xe0/0xfd0 drivers/vhost/vsock.c:104\n\t vhost_worker+0x23d/0x3d0 drivers/vhost/vhost.c:372\n\t kthread+0x2e9/0x3a0 kernel/kthread.c:377\n\t ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:295\n\t \n\nReported by syzbot at:\n\thttps://syzkaller.appspot.com/bug?extid=0abd373e2e50d704db87\n\nTo fix this, do two things:\n\n1. Return -EINVAL in vhost_chr_write_iter() when userspace asks to map\n a range with size 0.\n2. Fix vhost_iotlb_add_range_ctx() to handle the range [0, ULONG_MAX]\n by splitting it into two entries.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48862" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d9a747e6b6561280bf1791bb24c5e9e082193dad" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e2ae38cf3d91837a493cb2093c87700ff3cbe667" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f8d88e86e90ea1002226d7ac2430152bfea003d1" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-16T13:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-f2xw-g7hm-66qr/GHSA-f2xw-g7hm-66qr.json b/advisories/unreviewed/2024/07/GHSA-f2xw-g7hm-66qr/GHSA-f2xw-g7hm-66qr.json new file mode 100644 index 00000000000..982bd6e8755 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-f2xw-g7hm-66qr/GHSA-f2xw-g7hm-66qr.json @@ -0,0 +1,63 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f2xw-g7hm-66qr", + "modified": "2024-07-16T15:30:49Z", + "published": "2024-07-16T15:30:49Z", + "aliases": [ + "CVE-2022-48851" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: gdm724x: fix use after free in gdm_lte_rx()\n\nThe netif_rx_ni() function frees the skb so we can't dereference it to\nsave the skb->len.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48851" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1fb9dd3787495b4deb0efe66c58306b65691a48f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/403e3afe241b62401de1f8629c9c6b9b3d69dbff" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/48ecdf3e29a6e514e8196691589c7dfc6c4ac169" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6d9700b445098dbbce0caff4b8cfca214cf1e757" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6dc7b87c62423bfa68139fe95e85028aab584c9a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/83a9c886c2b5a0d28c0b37e1736b47f38d61332a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d39dc79513e99147b4c158a8a9e46743e23944f5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fc7f750dc9d102c1ed7bbe4591f991e770c99033" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-16T13:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-f9vw-2hpv-h272/GHSA-f9vw-2hpv-h272.json b/advisories/unreviewed/2024/07/GHSA-f9vw-2hpv-h272/GHSA-f9vw-2hpv-h272.json new file mode 100644 index 00000000000..0c4db01aa74 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-f9vw-2hpv-h272/GHSA-f9vw-2hpv-h272.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f9vw-2hpv-h272", + "modified": "2024-07-16T15:30:48Z", + "published": "2024-07-16T15:30:48Z", + "aliases": [ + "CVE-2022-48840" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\niavf: Fix hang during reboot/shutdown\n\nRecent commit 974578017fc1 (\"iavf: Add waiting so the port is\ninitialized in remove\") adds a wait-loop at the beginning of\niavf_remove() to ensure that port initialization is finished\nprior unregistering net device. This causes a regression\nin reboot/shutdown scenario because in this case callback\niavf_shutdown() is called and this callback detaches the device,\nmakes it down if it is running and sets its state to __IAVF_REMOVE.\nLater shutdown callback of associated PF driver (e.g. ice_shutdown)\nis called. That callback calls among other things sriov_disable()\nthat calls indirectly iavf_remove() (see stack trace below).\nAs the adapter state is already __IAVF_REMOVE then the mentioned\nloop is end-less and shutdown process hangs.\n\nThe patch fixes this by checking adapter's state at the beginning\nof iavf_remove() and skips the rest of the function if the adapter\nis already in remove state (shutdown is in progress).\n\nReproducer:\n1. Create VF on PF driven by ice or i40e driver\n2. Ensure that the VF is bound to iavf driver\n3. Reboot\n\n[52625.981294] sysrq: SysRq : Show Blocked State\n[52625.988377] task:reboot state:D stack: 0 pid:17359 ppid: 1 f2\n[52625.996732] Call Trace:\n[52625.999187] __schedule+0x2d1/0x830\n[52626.007400] schedule+0x35/0xa0\n[52626.010545] schedule_hrtimeout_range_clock+0x83/0x100\n[52626.020046] usleep_range+0x5b/0x80\n[52626.023540] iavf_remove+0x63/0x5b0 [iavf]\n[52626.027645] pci_device_remove+0x3b/0xc0\n[52626.031572] device_release_driver_internal+0x103/0x1f0\n[52626.036805] pci_stop_bus_device+0x72/0xa0\n[52626.040904] pci_stop_and_remove_bus_device+0xe/0x20\n[52626.045870] pci_iov_remove_virtfn+0xba/0x120\n[52626.050232] sriov_disable+0x2f/0xe0\n[52626.053813] ice_free_vfs+0x7c/0x340 [ice]\n[52626.057946] ice_remove+0x220/0x240 [ice]\n[52626.061967] ice_shutdown+0x16/0x50 [ice]\n[52626.065987] pci_device_shutdown+0x34/0x60\n[52626.070086] device_shutdown+0x165/0x1c5\n[52626.074011] kernel_restart+0xe/0x30\n[52626.077593] __do_sys_reboot+0x1d2/0x210\n[52626.093815] do_syscall_64+0x5b/0x1a0\n[52626.097483] entry_SYSCALL_64_after_hwframe+0x65/0xca", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48840" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4477b9a4193b35eb3a8afd2adf2d42add2f88d57" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/80974bb730270199c6fcb189af04d5945b87e813" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b04683ff8f0823b869c219c78ba0d974bddea0b5" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-16T13:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-fcw4-rj76-q6cg/GHSA-fcw4-rj76-q6cg.json b/advisories/unreviewed/2024/07/GHSA-fcw4-rj76-q6cg/GHSA-fcw4-rj76-q6cg.json new file mode 100644 index 00000000000..1b1f0f619a4 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-fcw4-rj76-q6cg/GHSA-fcw4-rj76-q6cg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fcw4-rj76-q6cg", + "modified": "2024-07-16T15:30:50Z", + "published": "2024-07-16T15:30:50Z", + "aliases": [ + "CVE-2022-45449" + ], + "details": "Sensitive information disclosure due to excessive privileges assigned to Acronis Agent. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 30984.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45449" + }, + { + "type": "WEB", + "url": "https://security-advisory.acronis.com/advisories/SEC-5279" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-16T15:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-gq7q-6p5c-gpcc/GHSA-gq7q-6p5c-gpcc.json b/advisories/unreviewed/2024/07/GHSA-gq7q-6p5c-gpcc/GHSA-gq7q-6p5c-gpcc.json new file mode 100644 index 00000000000..1d411d762b5 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-gq7q-6p5c-gpcc/GHSA-gq7q-6p5c-gpcc.json @@ -0,0 +1,63 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gq7q-6p5c-gpcc", + "modified": "2024-07-16T15:30:47Z", + "published": "2024-07-16T15:30:47Z", + "aliases": [ + "CVE-2022-48837" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: rndis: prevent integer overflow in rndis_set_response()\n\nIf \"BufOffset\" is very large the \"BufOffset + 8\" operation can have an\ninteger overflow.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48837" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/138d4f739b35dfb40438a0d5d7054965763bfbe7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/21829376268397f9fd2c35cfa9135937b6aa3a1e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/28bc0267399f42f987916a7174e2e32f0833cc65" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/56b38e3ca4064041d93c1ca18828c8cedad2e16c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/65f3324f4b6fed78b8761c3b74615ecf0ffa81fa" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8b3e4d26bc9cd0f6373d0095b9ffd99e7da8006b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c7953cf03a26876d676145ce5d2ae6d8c9630b90" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/df7e088d51cdf78b1a0bf1f3d405c2593295c7b0" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-16T13:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-hg7f-jj55-6xcf/GHSA-hg7f-jj55-6xcf.json b/advisories/unreviewed/2024/07/GHSA-hg7f-jj55-6xcf/GHSA-hg7f-jj55-6xcf.json new file mode 100644 index 00000000000..f263a965efb --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-hg7f-jj55-6xcf/GHSA-hg7f-jj55-6xcf.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hg7f-jj55-6xcf", + "modified": "2024-07-16T15:30:48Z", + "published": "2024-07-16T15:30:48Z", + "aliases": [ + "CVE-2022-48844" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_core: Fix leaking sent_cmd skb\n\nsent_cmd memory is not freed before freeing hci_dev causing it to leak\nit contents.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48844" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3679ccc09d8806686d579095ed504e045af7f7d6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9473d06bd1c8da49eafb685aa95a290290c672dd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/dd3b1dc3dd050f1f47cd13e300732852414270f8" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-16T13:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-mr3g-8vqm-6mhq/GHSA-mr3g-8vqm-6mhq.json b/advisories/unreviewed/2024/07/GHSA-mr3g-8vqm-6mhq/GHSA-mr3g-8vqm-6mhq.json new file mode 100644 index 00000000000..e9860090a00 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-mr3g-8vqm-6mhq/GHSA-mr3g-8vqm-6mhq.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mr3g-8vqm-6mhq", + "modified": "2024-07-16T15:30:50Z", + "published": "2024-07-16T15:30:50Z", + "aliases": [ + "CVE-2022-48863" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmISDN: Fix memory leak in dsp_pipeline_build()\n\ndsp_pipeline_build() allocates dup pointer by kstrdup(cfg),\nbut then it updates dup variable by strsep(&dup, \"|\").\nAs a result when it calls kfree(dup), the dup variable contains NULL.\n\nFound by Linux Driver Verification project (linuxtesting.org) with SVACE.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48863" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/640445d6fc059d4514ffea79eb4196299e0e2d0f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7777b1f795af1bb43867375d8a776080111aae1b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a3d5fcc6cf2ecbba5a269631092570aa285a24cb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c6a502c2299941c8326d029cfc8a3bc8a4607ad5" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-16T13:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-p622-mwq3-26f2/GHSA-p622-mwq3-26f2.json b/advisories/unreviewed/2024/07/GHSA-p622-mwq3-26f2/GHSA-p622-mwq3-26f2.json new file mode 100644 index 00000000000..3a0b30f48b1 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-p622-mwq3-26f2/GHSA-p622-mwq3-26f2.json @@ -0,0 +1,63 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p622-mwq3-26f2", + "modified": "2024-07-16T15:30:50Z", + "published": "2024-07-16T15:30:49Z", + "aliases": [ + "CVE-2022-48853" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nswiotlb: fix info leak with DMA_FROM_DEVICE\n\nThe problem I'm addressing was discovered by the LTP test covering\ncve-2018-1000204.\n\nA short description of what happens follows:\n1) The test case issues a command code 00 (TEST UNIT READY) via the SG_IO\n interface with: dxfer_len == 524288, dxdfer_dir == SG_DXFER_FROM_DEV\n and a corresponding dxferp. The peculiar thing about this is that TUR\n is not reading from the device.\n2) In sg_start_req() the invocation of blk_rq_map_user() effectively\n bounces the user-space buffer. As if the device was to transfer into\n it. Since commit a45b599ad808 (\"scsi: sg: allocate with __GFP_ZERO in\n sg_build_indirect()\") we make sure this first bounce buffer is\n allocated with GFP_ZERO.\n3) For the rest of the story we keep ignoring that we have a TUR, so the\n device won't touch the buffer we prepare as if the we had a\n DMA_FROM_DEVICE type of situation. My setup uses a virtio-scsi device\n and the buffer allocated by SG is mapped by the function\n virtqueue_add_split() which uses DMA_FROM_DEVICE for the \"in\" sgs (here\n scatter-gather and not scsi generics). This mapping involves bouncing\n via the swiotlb (we need swiotlb to do virtio in protected guest like\n s390 Secure Execution, or AMD SEV).\n4) When the SCSI TUR is done, we first copy back the content of the second\n (that is swiotlb) bounce buffer (which most likely contains some\n previous IO data), to the first bounce buffer, which contains all\n zeros. Then we copy back the content of the first bounce buffer to\n the user-space buffer.\n5) The test case detects that the buffer, which it zero-initialized,\n ain't all zeros and fails.\n\nOne can argue that this is an swiotlb problem, because without swiotlb\nwe leak all zeros, and the swiotlb should be transparent in a sense that\nit does not affect the outcome (if all other participants are well\nbehaved).\n\nCopying the content of the original buffer into the swiotlb buffer is\nthe only way I can think of to make swiotlb transparent in such\nscenarios. So let's do just that if in doubt, but allow the driver\nto tell us that the whole mapped buffer is going to be overwritten,\nin which case we can preserve the old behavior and avoid the performance\nimpact of the extra bounce.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48853" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/270475d6d2410ec66e971bf181afe1958dad565e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6bfc5377a210dbda2a237f16d94d1bd4f1335026" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7403f4118ab94be837ab9d770507537a8057bc63" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8d9ac1b6665c73f23e963775f85d99679fd8e192" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/971e5dadffd02beba1063e7dd9c3a82de17cf534" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c132f2ba716b5ee6b35f82226a6e5417d013d753" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d4d975e7921079f877f828099bb8260af335508f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ddbd89deb7d32b1fbb879f48d68fda1a8ac58e8e" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-16T13:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-pvw6-xmpp-3h64/GHSA-pvw6-xmpp-3h64.json b/advisories/unreviewed/2024/07/GHSA-pvw6-xmpp-3h64/GHSA-pvw6-xmpp-3h64.json new file mode 100644 index 00000000000..9735726133a --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-pvw6-xmpp-3h64/GHSA-pvw6-xmpp-3h64.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pvw6-xmpp-3h64", + "modified": "2024-07-16T15:30:49Z", + "published": "2024-07-16T15:30:49Z", + "aliases": [ + "CVE-2022-48854" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: arc_emac: Fix use after free in arc_mdio_probe()\n\nIf bus->state is equal to MDIOBUS_ALLOCATED, mdiobus_free(bus) will free\nthe \"bus\". But bus->name is still used in the next line, which will lead\nto a use after free.\n\nWe can fix it by putting the name in a local variable and make the\nbus->name point to the rodata section \"name\",then use the name in the\nerror message without referring to bus to avoid the uaf.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48854" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/84c831803785c2c3bec5c28c0e8a0b72f6b41d4d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bc0e610a6eb0d46e4123fafdbe5e6141d9fff3be" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-16T13:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-qc77-c9gc-j3x6/GHSA-qc77-c9gc-j3x6.json b/advisories/unreviewed/2024/07/GHSA-qc77-c9gc-j3x6/GHSA-qc77-c9gc-j3x6.json new file mode 100644 index 00000000000..7e1a13782c4 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-qc77-c9gc-j3x6/GHSA-qc77-c9gc-j3x6.json @@ -0,0 +1,63 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qc77-c9gc-j3x6", + "modified": "2024-07-16T15:30:50Z", + "published": "2024-07-16T15:30:50Z", + "aliases": [ + "CVE-2022-48860" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nethernet: Fix error handling in xemaclite_of_probe\n\nThis node pointer is returned by of_parse_phandle() with refcount\nincremented in this function. Calling of_node_put() to avoid the\nrefcount leak. As the remove function do.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48860" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1852854ee349881efb78ccdbbb237838975902e4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5e7c402892e189a7bc152b125e72261154aa585d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/669172ce976608b25a2f76f3c65d47f042d125c9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8609e29611befc4bfbe7a91bb50fc65ae72ff549" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8ee065a7a9b6a3976c16340503677efc4d8351f6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/979b418b96e35f07136f77962ccfaa54cf3e30e1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b19ab4b38b06aae12442b2de95ccf58b5dc53584" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b7220f8e9d6c6b9594ddfb3125dad938cd478b1f" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-16T13:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-qvwc-r3r6-hq25/GHSA-qvwc-r3r6-hq25.json b/advisories/unreviewed/2024/07/GHSA-qvwc-r3r6-hq25/GHSA-qvwc-r3r6-hq25.json new file mode 100644 index 00000000000..57603e391b0 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-qvwc-r3r6-hq25/GHSA-qvwc-r3r6-hq25.json @@ -0,0 +1,63 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qvwc-r3r6-hq25", + "modified": "2024-07-16T15:30:48Z", + "published": "2024-07-16T15:30:48Z", + "aliases": [ + "CVE-2022-48839" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/packet: fix slab-out-of-bounds access in packet_recvmsg()\n\nsyzbot found that when an AF_PACKET socket is using PACKET_COPY_THRESH\nand mmap operations, tpacket_rcv() is queueing skbs with\ngarbage in skb->cb[], triggering a too big copy [1]\n\nPresumably, users of af_packet using mmap() already gets correct\nmetadata from the mapped buffer, we can simply make sure\nto clear 12 bytes that might be copied to user space later.\n\nBUG: KASAN: stack-out-of-bounds in memcpy include/linux/fortify-string.h:225 [inline]\nBUG: KASAN: stack-out-of-bounds in packet_recvmsg+0x56c/0x1150 net/packet/af_packet.c:3489\nWrite of size 165 at addr ffffc9000385fb78 by task syz-executor233/3631\n\nCPU: 0 PID: 3631 Comm: syz-executor233 Not tainted 5.17.0-rc7-syzkaller-02396-g0b3660695e80 #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011\nCall Trace:\n \n __dump_stack lib/dump_stack.c:88 [inline]\n dump_stack_lvl+0xcd/0x134 lib/dump_stack.c:106\n print_address_description.constprop.0.cold+0xf/0x336 mm/kasan/report.c:255\n __kasan_report mm/kasan/report.c:442 [inline]\n kasan_report.cold+0x83/0xdf mm/kasan/report.c:459\n check_region_inline mm/kasan/generic.c:183 [inline]\n kasan_check_range+0x13d/0x180 mm/kasan/generic.c:189\n memcpy+0x39/0x60 mm/kasan/shadow.c:66\n memcpy include/linux/fortify-string.h:225 [inline]\n packet_recvmsg+0x56c/0x1150 net/packet/af_packet.c:3489\n sock_recvmsg_nosec net/socket.c:948 [inline]\n sock_recvmsg net/socket.c:966 [inline]\n sock_recvmsg net/socket.c:962 [inline]\n ____sys_recvmsg+0x2c4/0x600 net/socket.c:2632\n ___sys_recvmsg+0x127/0x200 net/socket.c:2674\n __sys_recvmsg+0xe2/0x1a0 net/socket.c:2704\n do_syscall_x64 arch/x86/entry/common.c:50 [inline]\n do_syscall_64+0x35/0xb0 arch/x86/entry/common.c:80\n entry_SYSCALL_64_after_hwframe+0x44/0xae\nRIP: 0033:0x7fdfd5954c29\nCode: 28 00 00 00 75 05 48 83 c4 28 c3 e8 41 15 00 00 90 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 c0 ff ff ff f7 d8 64 89 01 48\nRSP: 002b:00007ffcf8e71e48 EFLAGS: 00000246 ORIG_RAX: 000000000000002f\nRAX: ffffffffffffffda RBX: 0000000000000003 RCX: 00007fdfd5954c29\nRDX: 0000000000000000 RSI: 0000000020000500 RDI: 0000000000000005\nRBP: 0000000000000000 R08: 000000000000000d R09: 000000000000000d\nR10: 0000000000000000 R11: 0000000000000246 R12: 00007ffcf8e71e60\nR13: 00000000000f4240 R14: 000000000000c1ff R15: 00007ffcf8e71e54\n \n\naddr ffffc9000385fb78 is located in stack of task syz-executor233/3631 at offset 32 in frame:\n ____sys_recvmsg+0x0/0x600 include/linux/uio.h:246\n\nthis frame has 1 object:\n [32, 160) 'addr'\n\nMemory state around the buggy address:\n ffffc9000385fa80: 00 04 f3 f3 f3 f3 f3 00 00 00 00 00 00 00 00 00\n ffffc9000385fb00: 00 00 00 00 00 00 00 00 00 00 00 f1 f1 f1 f1 00\n>ffffc9000385fb80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 f3\n ^\n ffffc9000385fc00: f3 f3 f3 00 00 00 00 00 00 00 00 00 00 00 00 f1\n ffffc9000385fc80: f1 f1 f1 00 f2 f2 f2 00 f2 f2 f2 00 00 00 00 00\n==================================================================", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48839" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/268dcf1f7b3193bc446ec3d14e08a240e9561e4d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/70b7b3c055fd4a464da8da55ff4c1f84269f9b02" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a055f5f2841f7522b44a2b1eccb1951b4b03d51a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a33dd1e6693f80d805155b3f69c18c2f642915da" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b1e27cda1e3c12b705875bb7e247a97168580e33" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b9d5772d60f8e7ef34e290f72fc20e3a4883e7d0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c700525fcc06b05adfea78039de02628af79e07a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ef591b35176029fdefea38e8388ffa371e18f4b2" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-16T13:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-r6gj-cppw-666p/GHSA-r6gj-cppw-666p.json b/advisories/unreviewed/2024/07/GHSA-r6gj-cppw-666p/GHSA-r6gj-cppw-666p.json new file mode 100644 index 00000000000..8dbecc53e89 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-r6gj-cppw-666p/GHSA-r6gj-cppw-666p.json @@ -0,0 +1,55 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r6gj-cppw-666p", + "modified": "2024-07-16T15:30:50Z", + "published": "2024-07-16T15:30:50Z", + "aliases": [ + "CVE-2022-48856" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ngianfar: ethtool: Fix refcount leak in gfar_get_ts_info\n\nThe of_find_compatible_node() function returns a node pointer with\nrefcount incremented, We should use of_node_put() on it when done\nAdd the missing of_node_put() to release the refcount.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48856" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0e1b9a2078e07fb1e6e91bf8badfd89ecab1e848" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/21044e679ed535345042d2023f7df0ca8e897e2a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2ac5b58e645c66932438bb021cb5b52097ce70b0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6263f2eb93a85ad7df504daf0c341a7fb6bbe8a6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f49f646f9ec296fc0afe7ae92c2bb47f23e3846c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f7b3b520349193f8a82cca74daf366199e06add9" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-16T13:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-r7cx-6c4p-88r8/GHSA-r7cx-6c4p-88r8.json b/advisories/unreviewed/2024/07/GHSA-r7cx-6c4p-88r8/GHSA-r7cx-6c4p-88r8.json new file mode 100644 index 00000000000..c4623592a6c --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-r7cx-6c4p-88r8/GHSA-r7cx-6c4p-88r8.json @@ -0,0 +1,63 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r7cx-6c4p-88r8", + "modified": "2024-07-16T15:30:49Z", + "published": "2024-07-16T15:30:49Z", + "aliases": [ + "CVE-2022-48845" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nMIPS: smp: fill in sibling and core maps earlier\n\nAfter enabling CONFIG_SCHED_CORE (landed during 5.14 cycle),\n2-core 2-thread-per-core interAptiv (CPS-driven) started emitting\nthe following:\n\n[ 0.025698] CPU1 revision is: 0001a120 (MIPS interAptiv (multi))\n[ 0.048183] ------------[ cut here ]------------\n[ 0.048187] WARNING: CPU: 1 PID: 0 at kernel/sched/core.c:6025 sched_core_cpu_starting+0x198/0x240\n[ 0.048220] Modules linked in:\n[ 0.048233] CPU: 1 PID: 0 Comm: swapper/1 Not tainted 5.17.0-rc3+ #35 b7b319f24073fd9a3c2aa7ad15fb7993eec0b26f\n[ 0.048247] Stack : 817f0000 00000004 327804c8 810eb050 00000000 00000004 00000000 c314fdd1\n[ 0.048278] 830cbd64 819c0000 81800000 817f0000 83070bf4 00000001 830cbd08 00000000\n[ 0.048307] 00000000 00000000 815fcbc4 00000000 00000000 00000000 00000000 00000000\n[ 0.048334] 00000000 00000000 00000000 00000000 817f0000 00000000 00000000 817f6f34\n[ 0.048361] 817f0000 818a3c00 817f0000 00000004 00000000 00000000 4dc33260 0018c933\n[ 0.048389] ...\n[ 0.048396] Call Trace:\n[ 0.048399] [<8105a7bc>] show_stack+0x3c/0x140\n[ 0.048424] [<8131c2a0>] dump_stack_lvl+0x60/0x80\n[ 0.048440] [<8108b5c0>] __warn+0xc0/0xf4\n[ 0.048454] [<8108b658>] warn_slowpath_fmt+0x64/0x10c\n[ 0.048467] [<810bd418>] sched_core_cpu_starting+0x198/0x240\n[ 0.048483] [<810c6514>] sched_cpu_starting+0x14/0x80\n[ 0.048497] [<8108c0f8>] cpuhp_invoke_callback_range+0x78/0x140\n[ 0.048510] [<8108d914>] notify_cpu_starting+0x94/0x140\n[ 0.048523] [<8106593c>] start_secondary+0xbc/0x280\n[ 0.048539]\n[ 0.048543] ---[ end trace 0000000000000000 ]---\n[ 0.048636] Synchronize counters for CPU 1: done.\n\n...for each but CPU 0/boot.\nBasic debug printks right before the mentioned line say:\n\n[ 0.048170] CPU: 1, smt_mask:\n\nSo smt_mask, which is sibling mask obviously, is empty when entering\nthe function.\nThis is critical, as sched_core_cpu_starting() calculates\ncore-scheduling parameters only once per CPU start, and it's crucial\nto have all the parameters filled in at that moment (at least it\nuses cpu_smt_mask() which in fact is `&cpu_sibling_map[cpu]` on\nMIPS).\n\nA bit of debugging led me to that set_cpu_sibling_map() performing\nthe actual map calculation, was being invocated after\nnotify_cpu_start(), and exactly the latter function starts CPU HP\ncallback round (sched_core_cpu_starting() is basically a CPU HP\ncallback).\nWhile the flow is same on ARM64 (maps after the notifier, although\nbefore calling set_cpu_online()), x86 started calculating sibling\nmaps earlier than starting the CPU HP callbacks in Linux 4.14 (see\n[0] for the reference). Neither me nor my brief tests couldn't find\nany potential caveats in calculating the maps right after performing\ndelay calibration, but the WARN splat is now gone.\nThe very same debug prints now yield exactly what I expected from\nthem:\n\n[ 0.048433] CPU: 1, smt_mask: 0-1\n\n[0] https://git.kernel.org/pub/scm/linux/kernel/git/mips/linux.git/commit/?id=76ce7cfe35ef", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48845" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/32813321f18d5432cec1b1a6ecc964f9ea26d565" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/56eaacb8137ba2071ce48d4e3d91979270e139a7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7315f8538db009605ffba00370678142ef00ac98" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/94647aec80d03d6914aa664b7b8e103cd9d63239" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/be538b764a46be1d0700fd3b6e82fb76bd17f13a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c2420bc3333111184cdcb112282d13afe1338dd7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e8ad9ecc406974deb5e7c070f51cc1d09d21dc4b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f2703def339c793674010cc9f01bfe4980231808" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-16T13:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-v9xm-vjq4-6r8q/GHSA-v9xm-vjq4-6r8q.json b/advisories/unreviewed/2024/07/GHSA-v9xm-vjq4-6r8q/GHSA-v9xm-vjq4-6r8q.json new file mode 100644 index 00000000000..65be1c7331f --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-v9xm-vjq4-6r8q/GHSA-v9xm-vjq4-6r8q.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v9xm-vjq4-6r8q", + "modified": "2024-07-16T15:30:50Z", + "published": "2024-07-16T15:30:50Z", + "aliases": [ + "CVE-2024-6655" + ], + "details": "A flaw was found in the GTK library. Under certain conditions, it is possible for a library to be injected into a GTK application from the current working directory.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6655" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-6655" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2297098" + }, + { + "type": "WEB", + "url": "https://gitlab.gnome.org/GNOME/gtk/-/merge_requests/7361/diffs?commit_id=3bbf0b6176d42836d23c36a6ac410e807ec0a7a7#diff-content-e3fbe6480add9420b69f82374fb26ccac2c015a0" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-16T15:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-vp69-366h-2hqh/GHSA-vp69-366h-2hqh.json b/advisories/unreviewed/2024/07/GHSA-vp69-366h-2hqh/GHSA-vp69-366h-2hqh.json new file mode 100644 index 00000000000..26efca32d35 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-vp69-366h-2hqh/GHSA-vp69-366h-2hqh.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vp69-366h-2hqh", + "modified": "2024-07-16T15:30:47Z", + "published": "2024-07-16T15:30:47Z", + "aliases": [ + "CVE-2022-48833" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: skip reserved bytes warning on unmount after log cleanup failure\n\nAfter the recent changes made by commit c2e39305299f01 (\"btrfs: clear\nextent buffer uptodate when we fail to write it\") and its followup fix,\ncommit 651740a5024117 (\"btrfs: check WRITE_ERR when trying to read an\nextent buffer\"), we can now end up not cleaning up space reservations of\nlog tree extent buffers after a transaction abort happens, as well as not\ncleaning up still dirty extent buffers.\n\nThis happens because if writeback for a log tree extent buffer failed,\nthen we have cleared the bit EXTENT_BUFFER_UPTODATE from the extent buffer\nand we have also set the bit EXTENT_BUFFER_WRITE_ERR on it. Later on,\nwhen trying to free the log tree with free_log_tree(), which iterates\nover the tree, we can end up getting an -EIO error when trying to read\na node or a leaf, since read_extent_buffer_pages() returns -EIO if an\nextent buffer does not have EXTENT_BUFFER_UPTODATE set and has the\nEXTENT_BUFFER_WRITE_ERR bit set. Getting that -EIO means that we return\nimmediately as we can not iterate over the entire tree.\n\nIn that case we never update the reserved space for an extent buffer in\nthe respective block group and space_info object.\n\nWhen this happens we get the following traces when unmounting the fs:\n\n[174957.284509] BTRFS: error (device dm-0) in cleanup_transaction:1913: errno=-5 IO failure\n[174957.286497] BTRFS: error (device dm-0) in free_log_tree:3420: errno=-5 IO failure\n[174957.399379] ------------[ cut here ]------------\n[174957.402497] WARNING: CPU: 2 PID: 3206883 at fs/btrfs/block-group.c:127 btrfs_put_block_group+0x77/0xb0 [btrfs]\n[174957.407523] Modules linked in: btrfs overlay dm_zero (...)\n[174957.424917] CPU: 2 PID: 3206883 Comm: umount Tainted: G W 5.16.0-rc5-btrfs-next-109 #1\n[174957.426689] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.14.0-0-g155821a1990b-prebuilt.qemu.org 04/01/2014\n[174957.428716] RIP: 0010:btrfs_put_block_group+0x77/0xb0 [btrfs]\n[174957.429717] Code: 21 48 8b bd (...)\n[174957.432867] RSP: 0018:ffffb70d41cffdd0 EFLAGS: 00010206\n[174957.433632] RAX: 0000000000000001 RBX: ffff8b09c3848000 RCX: ffff8b0758edd1c8\n[174957.434689] RDX: 0000000000000001 RSI: ffffffffc0b467e7 RDI: ffff8b0758edd000\n[174957.436068] RBP: ffff8b0758edd000 R08: 0000000000000000 R09: 0000000000000000\n[174957.437114] R10: 0000000000000246 R11: 0000000000000000 R12: ffff8b09c3848148\n[174957.438140] R13: ffff8b09c3848198 R14: ffff8b0758edd188 R15: dead000000000100\n[174957.439317] FS: 00007f328fb82800(0000) GS:ffff8b0a2d200000(0000) knlGS:0000000000000000\n[174957.440402] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[174957.441164] CR2: 00007fff13563e98 CR3: 0000000404f4e005 CR4: 0000000000370ee0\n[174957.442117] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n[174957.443076] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n[174957.443948] Call Trace:\n[174957.444264] \n[174957.444538] btrfs_free_block_groups+0x255/0x3c0 [btrfs]\n[174957.445238] close_ctree+0x301/0x357 [btrfs]\n[174957.445803] ? call_rcu+0x16c/0x290\n[174957.446250] generic_shutdown_super+0x74/0x120\n[174957.446832] kill_anon_super+0x14/0x30\n[174957.447305] btrfs_kill_super+0x12/0x20 [btrfs]\n[174957.447890] deactivate_locked_super+0x31/0xa0\n[174957.448440] cleanup_mnt+0x147/0x1c0\n[174957.448888] task_work_run+0x5c/0xa0\n[174957.449336] exit_to_user_mode_prepare+0x1e5/0x1f0\n[174957.449934] syscall_exit_to_user_mode+0x16/0x40\n[174957.450512] do_syscall_64+0x48/0xc0\n[174957.450980] entry_SYSCALL_64_after_hwframe+0x44/0xae\n[174957.451605] RIP: 0033:0x7f328fdc4a97\n[174957.452059] Code: 03 0c 00 f7 (...)\n[174957.454320] RSP: 002b:00007fff13564ec8 EFLAGS: 00000246 ORIG_RAX: 00000000000000a6\n[174957.455262] RAX: 0000000000000000 RBX: 00007f328feea264 RCX: 00007f328fdc4a97\n[174957.456131] RDX: 0000000000000000 RSI: 00000000000000\n---truncated---", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48833" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/40cdc509877bacb438213b83c7541c5e24a1d9ec" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/44557a8f539a822c91238c1f95a95f98a5093d82" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4c5d94990fa2fd609360ecd0f7e183212a7d115c" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-16T13:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-w7jq-wm3w-xhpq/GHSA-w7jq-wm3w-xhpq.json b/advisories/unreviewed/2024/07/GHSA-w7jq-wm3w-xhpq/GHSA-w7jq-wm3w-xhpq.json new file mode 100644 index 00000000000..63f51e7ef87 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-w7jq-wm3w-xhpq/GHSA-w7jq-wm3w-xhpq.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w7jq-wm3w-xhpq", + "modified": "2024-07-16T15:30:49Z", + "published": "2024-07-16T15:30:49Z", + "aliases": [ + "CVE-2022-48852" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/vc4: hdmi: Unregister codec device on unbind\n\nOn bind we will register the HDMI codec device but we don't unregister\nit on unbind, leading to a device leakage. Unregister our device at\nunbind.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48852" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1ed68d776246f167aee9cd79f63f089c40a5e2a3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e40945ab7c7f966d0c37b7bd7b0596497dfe228d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ee22082c3e2f230028afa0e22aa8773b1de3c919" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-16T13:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-wgcq-m83r-f344/GHSA-wgcq-m83r-f344.json b/advisories/unreviewed/2024/07/GHSA-wgcq-m83r-f344/GHSA-wgcq-m83r-f344.json new file mode 100644 index 00000000000..45af005fa6a --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-wgcq-m83r-f344/GHSA-wgcq-m83r-f344.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wgcq-m83r-f344", + "modified": "2024-07-16T15:30:49Z", + "published": "2024-07-16T15:30:49Z", + "aliases": [ + "CVE-2022-48847" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwatch_queue: Fix filter limit check\n\nIn watch_queue_set_filter(), there are a couple of places where we check\nthat the filter type value does not exceed what the type_filter bitmap\ncan hold. One place calculates the number of bits by:\n\n if (tf[i].type >= sizeof(wfilter->type_filter) * 8)\n\nwhich is fine, but the second does:\n\n if (tf[i].type >= sizeof(wfilter->type_filter) * BITS_PER_LONG)\n\nwhich is not. This can lead to a couple of out-of-bounds writes due to\na too-large type:\n\n (1) __set_bit() on wfilter->type_filter\n (2) Writing more elements in wfilter->filters[] than we allocated.\n\nFix this by just using the proper WATCH_TYPE__NR instead, which is the\nnumber of types we actually know about.\n\nThe bug may cause an oops looking something like:\n\n BUG: KASAN: slab-out-of-bounds in watch_queue_set_filter+0x659/0x740\n Write of size 4 at addr ffff88800d2c66bc by task watch_queue_oob/611\n ...\n Call Trace:\n \n dump_stack_lvl+0x45/0x59\n print_address_description.constprop.0+0x1f/0x150\n ...\n kasan_report.cold+0x7f/0x11b\n ...\n watch_queue_set_filter+0x659/0x740\n ...\n __x64_sys_ioctl+0x127/0x190\n do_syscall_64+0x43/0x90\n entry_SYSCALL_64_after_hwframe+0x44/0xae\n\n Allocated by task 611:\n kasan_save_stack+0x1e/0x40\n __kasan_kmalloc+0x81/0xa0\n watch_queue_set_filter+0x23a/0x740\n __x64_sys_ioctl+0x127/0x190\n do_syscall_64+0x43/0x90\n entry_SYSCALL_64_after_hwframe+0x44/0xae\n\n The buggy address belongs to the object at ffff88800d2c66a0\n which belongs to the cache kmalloc-32 of size 32\n The buggy address is located 28 bytes inside of\n 32-byte region [ffff88800d2c66a0, ffff88800d2c66c0)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48847" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1b09f28f70a5046acd64138075ae3f095238b045" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/648895da69ced90ca770fd941c3d9479a9d72c16" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b36588ebbcef74583824c08352e75838d6fb4ff2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c993ee0f9f81caf5767a50d1faeba39a0dc82af2" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-16T13:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-wrch-9585-fw25/GHSA-wrch-9585-fw25.json b/advisories/unreviewed/2024/07/GHSA-wrch-9585-fw25/GHSA-wrch-9585-fw25.json new file mode 100644 index 00000000000..03155329b22 --- /dev/null +++ b/advisories/unreviewed/2024/07/GHSA-wrch-9585-fw25/GHSA-wrch-9585-fw25.json @@ -0,0 +1,63 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wrch-9585-fw25", + "modified": "2024-07-16T15:30:50Z", + "published": "2024-07-16T15:30:50Z", + "aliases": [ + "CVE-2022-48857" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nNFC: port100: fix use-after-free in port100_send_complete\n\nSyzbot reported UAF in port100_send_complete(). The root case is in\nmissing usb_kill_urb() calls on error handling path of ->probe function.\n\nport100_send_complete() accesses devm allocated memory which will be\nfreed on probe failure. We should kill this urbs before returning an\nerror from probe function to prevent reported use-after-free\n\nFail log:\n\nBUG: KASAN: use-after-free in port100_send_complete+0x16e/0x1a0 drivers/nfc/port100.c:935\nRead of size 1 at addr ffff88801bb59540 by task ksoftirqd/2/26\n...\nCall Trace:\n \n __dump_stack lib/dump_stack.c:88 [inline]\n dump_stack_lvl+0xcd/0x134 lib/dump_stack.c:106\n print_address_description.constprop.0.cold+0x8d/0x303 mm/kasan/report.c:255\n __kasan_report mm/kasan/report.c:442 [inline]\n kasan_report.cold+0x83/0xdf mm/kasan/report.c:459\n port100_send_complete+0x16e/0x1a0 drivers/nfc/port100.c:935\n __usb_hcd_giveback_urb+0x2b0/0x5c0 drivers/usb/core/hcd.c:1670\n\n...\n\nAllocated by task 1255:\n kasan_save_stack+0x1e/0x40 mm/kasan/common.c:38\n kasan_set_track mm/kasan/common.c:45 [inline]\n set_alloc_info mm/kasan/common.c:436 [inline]\n ____kasan_kmalloc mm/kasan/common.c:515 [inline]\n ____kasan_kmalloc mm/kasan/common.c:474 [inline]\n __kasan_kmalloc+0xa6/0xd0 mm/kasan/common.c:524\n alloc_dr drivers/base/devres.c:116 [inline]\n devm_kmalloc+0x96/0x1d0 drivers/base/devres.c:823\n devm_kzalloc include/linux/device.h:209 [inline]\n port100_probe+0x8a/0x1320 drivers/nfc/port100.c:1502\n\nFreed by task 1255:\n kasan_save_stack+0x1e/0x40 mm/kasan/common.c:38\n kasan_set_track+0x21/0x30 mm/kasan/common.c:45\n kasan_set_free_info+0x20/0x30 mm/kasan/generic.c:370\n ____kasan_slab_free mm/kasan/common.c:366 [inline]\n ____kasan_slab_free+0xff/0x140 mm/kasan/common.c:328\n kasan_slab_free include/linux/kasan.h:236 [inline]\n __cache_free mm/slab.c:3437 [inline]\n kfree+0xf8/0x2b0 mm/slab.c:3794\n release_nodes+0x112/0x1a0 drivers/base/devres.c:501\n devres_release_all+0x114/0x190 drivers/base/devres.c:530\n really_probe+0x626/0xcc0 drivers/base/dd.c:670", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48857" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0e721b8f2ee5e11376dd55363f9ccb539d754b8a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/205c4ec78e71cbf561794e6043da80e7bae6790f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2b1c85f56512d49e43bc53741fce2f508cd90029" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/32e866ae5a7af590597ef4bcff8451bf96d5f980" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7194737e1be8fdc89d2a9382bd2f371f7ee2eda8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b1db33d4e54bc35d8db96ce143ea0ef92e23d58e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cd2a5c0da0d1ddf11d1f84e9c9b1949f50f6e161" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f80cfe2f26581f188429c12bd937eb905ad3ac7b" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-07-16T13:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-x27m-p9c5-jvf7/GHSA-x27m-p9c5-jvf7.json b/advisories/unreviewed/2024/07/GHSA-x27m-p9c5-jvf7/GHSA-x27m-p9c5-jvf7.json index 7eb44415f00..888f008eb4c 100644 --- a/advisories/unreviewed/2024/07/GHSA-x27m-p9c5-jvf7/GHSA-x27m-p9c5-jvf7.json +++ b/advisories/unreviewed/2024/07/GHSA-x27m-p9c5-jvf7/GHSA-x27m-p9c5-jvf7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x27m-p9c5-jvf7", - "modified": "2024-07-16T12:30:38Z", + "modified": "2024-07-16T15:30:46Z", "published": "2024-07-16T12:30:38Z", "aliases": [ "CVE-2022-48775"