From 9d378ea80d8b1cc92577cae89618f8f94899f265 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 21 Oct 2024 18:32:43 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-2gxx-vxp2-c52q.json | 7 ++- .../GHSA-533f-24pj-cvj8.json | 9 ++- .../GHSA-5pwp-v5cx-v53w.json | 9 ++- .../GHSA-74r2-qf2j-vm8r.json | 7 ++- .../GHSA-8h3g-5w8f-55gv.json | 9 ++- .../GHSA-f74f-9cfw-p3xj.json | 9 ++- .../GHSA-f9vw-75cc-w892.json | 7 ++- .../GHSA-h99v-p65j-fpx4.json | 10 +++- .../GHSA-hrmj-vxfx-2vq3.json | 7 ++- .../GHSA-jjvg-65v4-v3cq.json | 9 ++- .../GHSA-p9r7-8rjp-gmw3.json | 9 ++- .../GHSA-r97j-8742-f767.json | 7 ++- .../GHSA-vqxq-fjhv-69jf.json | 8 ++- .../GHSA-wm54-3xjp-vjmc.json | 7 ++- .../GHSA-q56j-8x89-gvgg.json | 2 +- .../GHSA-rwg2-cqg5-rjm4.json | 2 +- .../GHSA-4f5g-h3x2-8v9x.json | 2 +- .../GHSA-3v76-qg7g-rx9c.json | 2 +- .../GHSA-hchc-m7jw-6mhm.json | 2 +- .../GHSA-22wr-xr3p-42c4.json | 43 ++++++++++++++ .../GHSA-23px-9798-3x5c.json | 59 +++++++++++++++++++ .../GHSA-24gv-qfv8-v7f5.json | 59 +++++++++++++++++++ .../GHSA-24vf-v4v3-xgmr.json | 59 +++++++++++++++++++ .../GHSA-26q7-wp6g-349w.json | 47 +++++++++++++++ .../GHSA-276c-3gx4-x9pr.json | 47 +++++++++++++++ .../GHSA-2gvh-vj62-qjmp.json | 43 ++++++++++++++ .../GHSA-2h84-jhpc-6px2.json | 43 ++++++++++++++ .../GHSA-2h93-g5hm-9qcv.json | 43 ++++++++++++++ .../GHSA-2m92-hrph-h3f7.json | 43 ++++++++++++++ .../GHSA-3cmg-5p27-qj6j.json | 47 +++++++++++++++ .../GHSA-3rvw-7pxp-g8xm.json | 59 +++++++++++++++++++ .../GHSA-3xm8-389p-x4rm.json | 43 ++++++++++++++ .../GHSA-44g4-9qvp-9723.json | 43 ++++++++++++++ .../GHSA-4c63-26fj-6f7h.json | 51 ++++++++++++++++ .../GHSA-4f6f-gr2g-x76p.json | 59 +++++++++++++++++++ .../GHSA-4rgx-hjqw-p9f3.json | 59 +++++++++++++++++++ .../GHSA-4vhm-95hf-qf25.json | 55 +++++++++++++++++ .../GHSA-4wjx-5h7f-wqhw.json | 59 +++++++++++++++++++ .../GHSA-4x74-8q36-fc3h.json | 59 +++++++++++++++++++ .../GHSA-4xwj-gw53-4w3v.json | 43 ++++++++++++++ .../GHSA-533j-v9v8-3c94.json | 39 ++++++++++++ .../GHSA-57xc-4245-hh9c.json | 35 +++++++++++ .../GHSA-5frw-42jx-47v6.json | 59 +++++++++++++++++++ .../GHSA-5mqf-fxgc-8r6w.json | 43 ++++++++++++++ .../GHSA-5rwv-chpw-9fvf.json | 51 ++++++++++++++++ .../GHSA-5wgv-v8w4-hvpr.json | 47 +++++++++++++++ .../GHSA-64qp-9xf4-2pch.json | 51 ++++++++++++++++ .../GHSA-66x6-php2-c8mm.json | 59 +++++++++++++++++++ .../GHSA-6g7j-p2cm-w265.json | 39 ++++++++++++ .../GHSA-6ppv-9jp4-gprm.json | 43 ++++++++++++++ .../GHSA-6pw8-39hw-qcp8.json | 59 +++++++++++++++++++ .../GHSA-74qf-4594-qx2m.json | 47 +++++++++++++++ .../GHSA-74w9-c64j-qmcw.json | 39 ++++++++++++ .../GHSA-7797-cc95-p257.json | 43 ++++++++++++++ .../GHSA-7f96-m827-q2r2.json | 43 ++++++++++++++ .../GHSA-7jfp-wvrj-m47g.json | 59 +++++++++++++++++++ .../GHSA-7pj6-rq69-3m65.json | 59 +++++++++++++++++++ .../GHSA-858g-q943-3jmm.json | 39 ++++++++++++ .../GHSA-88g6-52pm-gr2w.json | 51 ++++++++++++++++ .../GHSA-8cpm-hmp4-fcm6.json | 59 +++++++++++++++++++ .../GHSA-8h6q-7wvm-5w36.json | 59 +++++++++++++++++++ .../GHSA-8j66-8f4j-h263.json | 47 +++++++++++++++ .../GHSA-8qrg-fxff-9fcm.json | 47 +++++++++++++++ .../GHSA-8r4r-8c3p-6r95.json | 55 +++++++++++++++++ .../GHSA-8r8w-7pvp-9gqf.json | 55 +++++++++++++++++ .../GHSA-8w32-7xxp-mvxc.json | 43 ++++++++++++++ .../GHSA-9354-rmch-rmj8.json | 59 +++++++++++++++++++ .../GHSA-94p2-m4qf-5m97.json | 47 +++++++++++++++ .../GHSA-9gj6-xqgx-pv89.json | 43 ++++++++++++++ .../GHSA-9jhx-gr45-29p7.json | 43 ++++++++++++++ .../GHSA-9r6q-3r52-hh42.json | 43 ++++++++++++++ .../GHSA-9x5x-jw3v-frfw.json | 59 +++++++++++++++++++ .../GHSA-9xrj-2966-hg7q.json | 59 +++++++++++++++++++ .../GHSA-c3cx-mm7p-wgj8.json | 43 ++++++++++++++ .../GHSA-c4vm-rj4p-m3c8.json | 43 ++++++++++++++ .../GHSA-c8jq-9f5m-r697.json | 59 +++++++++++++++++++ .../GHSA-cjwf-5vh9-w48g.json | 59 +++++++++++++++++++ .../GHSA-cpwp-j2f3-rxq9.json | 39 ++++++++++++ .../GHSA-cx67-p8xc-qwg4.json | 47 +++++++++++++++ .../GHSA-cxw3-2f59-5p7f.json | 55 +++++++++++++++++ .../GHSA-f3gg-6f8f-39gh.json | 59 +++++++++++++++++++ .../GHSA-f3xx-63r9-v2cp.json | 59 +++++++++++++++++++ .../GHSA-f7v4-xw4v-h9wq.json | 39 ++++++++++++ .../GHSA-ffhg-6h3q-652p.json | 2 +- .../GHSA-ffxc-rwg8-qgjw.json | 39 ++++++++++++ .../GHSA-fh5r-24qv-66r9.json | 43 ++++++++++++++ .../GHSA-fh83-rw64-jhh7.json | 59 +++++++++++++++++++ .../GHSA-fppc-fjqw-6gx5.json | 43 ++++++++++++++ .../GHSA-frr9-gqr3-75hc.json | 59 +++++++++++++++++++ .../GHSA-g9fr-wfpx-28xj.json | 59 +++++++++++++++++++ .../GHSA-g9mh-3crx-2qvf.json | 39 ++++++++++++ .../GHSA-gcv4-6hmh-xhwc.json | 39 ++++++++++++ .../GHSA-ggxf-hwrw-c5q2.json | 39 ++++++++++++ .../GHSA-gj49-2hq5-g5h7.json | 47 +++++++++++++++ .../GHSA-gr6g-pg36-368m.json | 59 +++++++++++++++++++ .../GHSA-gxhw-gx89-g9ch.json | 6 +- .../GHSA-h72j-469c-c787.json | 47 +++++++++++++++ .../GHSA-h7p9-f9r3-6533.json | 59 +++++++++++++++++++ .../GHSA-h7r9-ffqq-5r47.json | 47 +++++++++++++++ .../GHSA-h9jc-p2cr-c4rx.json | 39 ++++++++++++ .../GHSA-h9pq-rfrf-6f7p.json | 55 +++++++++++++++++ .../GHSA-hm9p-89r4-c9g7.json | 6 +- .../GHSA-hpqg-3xxv-rhj6.json | 59 +++++++++++++++++++ .../GHSA-hr6h-7jqj-mx8j.json | 55 +++++++++++++++++ .../GHSA-hxxw-vvrc-qrx3.json | 59 +++++++++++++++++++ .../GHSA-j2cc-c4fg-77cq.json | 39 ++++++++++++ .../GHSA-j4xv-h5fv-6v4m.json | 43 ++++++++++++++ .../GHSA-j994-f74j-cwf3.json | 43 ++++++++++++++ .../GHSA-jmxw-f4w9-294j.json | 47 +++++++++++++++ .../GHSA-jq7w-hcx7-gm2r.json | 55 +++++++++++++++++ .../GHSA-jww8-jcqp-pmjm.json | 59 +++++++++++++++++++ .../GHSA-m236-cj4j-935h.json | 59 +++++++++++++++++++ .../GHSA-m3fc-5gx3-j98r.json | 55 +++++++++++++++++ .../GHSA-m5m5-6fc4-ph6r.json | 47 +++++++++++++++ .../GHSA-m7hg-2r4m-qcxr.json | 51 ++++++++++++++++ .../GHSA-m8rm-pc2x-rqv9.json | 59 +++++++++++++++++++ .../GHSA-mc6w-w4fp-fg4v.json | 39 ++++++++++++ .../GHSA-mf62-gm5r-38wj.json | 39 ++++++++++++ .../GHSA-p237-mjc7-7qqj.json | 59 +++++++++++++++++++ .../GHSA-p8wj-q5fw-6q9q.json | 55 +++++++++++++++++ .../GHSA-pgcr-7vhj-26w2.json | 39 ++++++++++++ .../GHSA-pgjc-h8g4-v6j2.json | 43 ++++++++++++++ .../GHSA-pm28-gfv5-pj4g.json | 47 +++++++++++++++ .../GHSA-ppw5-g3vp-9xx2.json | 59 +++++++++++++++++++ .../GHSA-pvgc-vpgw-88mq.json | 59 +++++++++++++++++++ .../GHSA-q2x4-35qf-p4qw.json | 59 +++++++++++++++++++ .../GHSA-q43m-8jgc-g8w7.json | 59 +++++++++++++++++++ .../GHSA-q7pc-7wvx-9qcx.json | 59 +++++++++++++++++++ .../GHSA-q823-fhxh-997g.json | 59 +++++++++++++++++++ .../GHSA-q8m3-vwhc-qqmc.json | 43 ++++++++++++++ .../GHSA-qf5q-fm5c-hc2p.json | 47 +++++++++++++++ .../GHSA-qfhj-q535-jf9w.json | 59 +++++++++++++++++++ .../GHSA-qgr6-hgc6-qm52.json | 59 +++++++++++++++++++ .../GHSA-qjpg-5hx2-g69j.json | 47 +++++++++++++++ .../GHSA-qjwp-794r-6x7v.json | 6 +- .../GHSA-qm34-9r78-66cq.json | 6 +- .../GHSA-qm4c-x73m-f8mf.json | 59 +++++++++++++++++++ .../GHSA-qqcr-57gp-2jmq.json | 43 ++++++++++++++ .../GHSA-qrr4-q9rq-pfvg.json | 6 +- .../GHSA-qwr8-frg5-xvvr.json | 59 +++++++++++++++++++ .../GHSA-r5f6-w2pg-mf93.json | 39 ++++++++++++ .../GHSA-rcg3-vwp6-7grp.json | 59 +++++++++++++++++++ .../GHSA-rf58-pp6r-5653.json | 51 ++++++++++++++++ .../GHSA-rgx3-g7m3-gj3j.json | 59 +++++++++++++++++++ .../GHSA-rqg9-48mq-4pm8.json | 39 ++++++++++++ .../GHSA-rrh5-rfhq-mff2.json | 39 ++++++++++++ .../GHSA-rvgw-688x-x595.json | 51 ++++++++++++++++ .../GHSA-rxhv-mw63-w89c.json | 59 +++++++++++++++++++ .../GHSA-v3jw-p9pj-m453.json | 43 ++++++++++++++ .../GHSA-v5pw-w6w2-2r5q.json | 39 ++++++++++++ .../GHSA-v9vq-7m9c-h738.json | 39 ++++++++++++ .../GHSA-vcrj-5576-fc99.json | 59 +++++++++++++++++++ .../GHSA-vfmw-mcw8-m32f.json | 6 +- .../GHSA-vp2p-wqj6-25wf.json | 59 +++++++++++++++++++ .../GHSA-vw3v-9427-r3gf.json | 39 ++++++++++++ .../GHSA-w38v-phv7-fjq8.json | 59 +++++++++++++++++++ .../GHSA-w7r5-57r3-mcrc.json | 47 +++++++++++++++ .../GHSA-w7w7-6353-385q.json | 39 ++++++++++++ .../GHSA-w89v-9wr9-8jx2.json | 59 +++++++++++++++++++ .../GHSA-w8mx-fc3q-r9qv.json | 59 +++++++++++++++++++ .../GHSA-wchf-3rq4-vh73.json | 2 +- .../GHSA-wg4j-4q4f-6cfc.json | 47 +++++++++++++++ .../GHSA-wh99-hh68-w2m5.json | 43 ++++++++++++++ .../GHSA-x3rh-vhj8-7wq6.json | 43 ++++++++++++++ .../GHSA-x5vx-qmf9-2r9v.json | 59 +++++++++++++++++++ .../GHSA-x652-w4xg-69jh.json | 47 +++++++++++++++ .../GHSA-x75j-gc7f-rqjc.json | 39 ++++++++++++ .../GHSA-xrhf-cccw-cpm8.json | 47 +++++++++++++++ 168 files changed, 7159 insertions(+), 48 deletions(-) create mode 100644 advisories/unreviewed/2024/10/GHSA-22wr-xr3p-42c4/GHSA-22wr-xr3p-42c4.json create mode 100644 advisories/unreviewed/2024/10/GHSA-23px-9798-3x5c/GHSA-23px-9798-3x5c.json create mode 100644 advisories/unreviewed/2024/10/GHSA-24gv-qfv8-v7f5/GHSA-24gv-qfv8-v7f5.json create mode 100644 advisories/unreviewed/2024/10/GHSA-24vf-v4v3-xgmr/GHSA-24vf-v4v3-xgmr.json create mode 100644 advisories/unreviewed/2024/10/GHSA-26q7-wp6g-349w/GHSA-26q7-wp6g-349w.json create mode 100644 advisories/unreviewed/2024/10/GHSA-276c-3gx4-x9pr/GHSA-276c-3gx4-x9pr.json create mode 100644 advisories/unreviewed/2024/10/GHSA-2gvh-vj62-qjmp/GHSA-2gvh-vj62-qjmp.json create mode 100644 advisories/unreviewed/2024/10/GHSA-2h84-jhpc-6px2/GHSA-2h84-jhpc-6px2.json create mode 100644 advisories/unreviewed/2024/10/GHSA-2h93-g5hm-9qcv/GHSA-2h93-g5hm-9qcv.json create mode 100644 advisories/unreviewed/2024/10/GHSA-2m92-hrph-h3f7/GHSA-2m92-hrph-h3f7.json create mode 100644 advisories/unreviewed/2024/10/GHSA-3cmg-5p27-qj6j/GHSA-3cmg-5p27-qj6j.json create mode 100644 advisories/unreviewed/2024/10/GHSA-3rvw-7pxp-g8xm/GHSA-3rvw-7pxp-g8xm.json create mode 100644 advisories/unreviewed/2024/10/GHSA-3xm8-389p-x4rm/GHSA-3xm8-389p-x4rm.json create mode 100644 advisories/unreviewed/2024/10/GHSA-44g4-9qvp-9723/GHSA-44g4-9qvp-9723.json create mode 100644 advisories/unreviewed/2024/10/GHSA-4c63-26fj-6f7h/GHSA-4c63-26fj-6f7h.json create mode 100644 advisories/unreviewed/2024/10/GHSA-4f6f-gr2g-x76p/GHSA-4f6f-gr2g-x76p.json create mode 100644 advisories/unreviewed/2024/10/GHSA-4rgx-hjqw-p9f3/GHSA-4rgx-hjqw-p9f3.json create mode 100644 advisories/unreviewed/2024/10/GHSA-4vhm-95hf-qf25/GHSA-4vhm-95hf-qf25.json create mode 100644 advisories/unreviewed/2024/10/GHSA-4wjx-5h7f-wqhw/GHSA-4wjx-5h7f-wqhw.json create mode 100644 advisories/unreviewed/2024/10/GHSA-4x74-8q36-fc3h/GHSA-4x74-8q36-fc3h.json create mode 100644 advisories/unreviewed/2024/10/GHSA-4xwj-gw53-4w3v/GHSA-4xwj-gw53-4w3v.json create mode 100644 advisories/unreviewed/2024/10/GHSA-533j-v9v8-3c94/GHSA-533j-v9v8-3c94.json create mode 100644 advisories/unreviewed/2024/10/GHSA-57xc-4245-hh9c/GHSA-57xc-4245-hh9c.json create mode 100644 advisories/unreviewed/2024/10/GHSA-5frw-42jx-47v6/GHSA-5frw-42jx-47v6.json create mode 100644 advisories/unreviewed/2024/10/GHSA-5mqf-fxgc-8r6w/GHSA-5mqf-fxgc-8r6w.json create mode 100644 advisories/unreviewed/2024/10/GHSA-5rwv-chpw-9fvf/GHSA-5rwv-chpw-9fvf.json create mode 100644 advisories/unreviewed/2024/10/GHSA-5wgv-v8w4-hvpr/GHSA-5wgv-v8w4-hvpr.json create mode 100644 advisories/unreviewed/2024/10/GHSA-64qp-9xf4-2pch/GHSA-64qp-9xf4-2pch.json create mode 100644 advisories/unreviewed/2024/10/GHSA-66x6-php2-c8mm/GHSA-66x6-php2-c8mm.json create mode 100644 advisories/unreviewed/2024/10/GHSA-6g7j-p2cm-w265/GHSA-6g7j-p2cm-w265.json create mode 100644 advisories/unreviewed/2024/10/GHSA-6ppv-9jp4-gprm/GHSA-6ppv-9jp4-gprm.json create mode 100644 advisories/unreviewed/2024/10/GHSA-6pw8-39hw-qcp8/GHSA-6pw8-39hw-qcp8.json create mode 100644 advisories/unreviewed/2024/10/GHSA-74qf-4594-qx2m/GHSA-74qf-4594-qx2m.json create mode 100644 advisories/unreviewed/2024/10/GHSA-74w9-c64j-qmcw/GHSA-74w9-c64j-qmcw.json create mode 100644 advisories/unreviewed/2024/10/GHSA-7797-cc95-p257/GHSA-7797-cc95-p257.json create mode 100644 advisories/unreviewed/2024/10/GHSA-7f96-m827-q2r2/GHSA-7f96-m827-q2r2.json create mode 100644 advisories/unreviewed/2024/10/GHSA-7jfp-wvrj-m47g/GHSA-7jfp-wvrj-m47g.json create mode 100644 advisories/unreviewed/2024/10/GHSA-7pj6-rq69-3m65/GHSA-7pj6-rq69-3m65.json create mode 100644 advisories/unreviewed/2024/10/GHSA-858g-q943-3jmm/GHSA-858g-q943-3jmm.json create mode 100644 advisories/unreviewed/2024/10/GHSA-88g6-52pm-gr2w/GHSA-88g6-52pm-gr2w.json create mode 100644 advisories/unreviewed/2024/10/GHSA-8cpm-hmp4-fcm6/GHSA-8cpm-hmp4-fcm6.json create mode 100644 advisories/unreviewed/2024/10/GHSA-8h6q-7wvm-5w36/GHSA-8h6q-7wvm-5w36.json create mode 100644 advisories/unreviewed/2024/10/GHSA-8j66-8f4j-h263/GHSA-8j66-8f4j-h263.json create mode 100644 advisories/unreviewed/2024/10/GHSA-8qrg-fxff-9fcm/GHSA-8qrg-fxff-9fcm.json create mode 100644 advisories/unreviewed/2024/10/GHSA-8r4r-8c3p-6r95/GHSA-8r4r-8c3p-6r95.json create mode 100644 advisories/unreviewed/2024/10/GHSA-8r8w-7pvp-9gqf/GHSA-8r8w-7pvp-9gqf.json create mode 100644 advisories/unreviewed/2024/10/GHSA-8w32-7xxp-mvxc/GHSA-8w32-7xxp-mvxc.json create mode 100644 advisories/unreviewed/2024/10/GHSA-9354-rmch-rmj8/GHSA-9354-rmch-rmj8.json create mode 100644 advisories/unreviewed/2024/10/GHSA-94p2-m4qf-5m97/GHSA-94p2-m4qf-5m97.json create mode 100644 advisories/unreviewed/2024/10/GHSA-9gj6-xqgx-pv89/GHSA-9gj6-xqgx-pv89.json create mode 100644 advisories/unreviewed/2024/10/GHSA-9jhx-gr45-29p7/GHSA-9jhx-gr45-29p7.json create mode 100644 advisories/unreviewed/2024/10/GHSA-9r6q-3r52-hh42/GHSA-9r6q-3r52-hh42.json create mode 100644 advisories/unreviewed/2024/10/GHSA-9x5x-jw3v-frfw/GHSA-9x5x-jw3v-frfw.json create mode 100644 advisories/unreviewed/2024/10/GHSA-9xrj-2966-hg7q/GHSA-9xrj-2966-hg7q.json create mode 100644 advisories/unreviewed/2024/10/GHSA-c3cx-mm7p-wgj8/GHSA-c3cx-mm7p-wgj8.json create mode 100644 advisories/unreviewed/2024/10/GHSA-c4vm-rj4p-m3c8/GHSA-c4vm-rj4p-m3c8.json create mode 100644 advisories/unreviewed/2024/10/GHSA-c8jq-9f5m-r697/GHSA-c8jq-9f5m-r697.json create mode 100644 advisories/unreviewed/2024/10/GHSA-cjwf-5vh9-w48g/GHSA-cjwf-5vh9-w48g.json create mode 100644 advisories/unreviewed/2024/10/GHSA-cpwp-j2f3-rxq9/GHSA-cpwp-j2f3-rxq9.json create mode 100644 advisories/unreviewed/2024/10/GHSA-cx67-p8xc-qwg4/GHSA-cx67-p8xc-qwg4.json create mode 100644 advisories/unreviewed/2024/10/GHSA-cxw3-2f59-5p7f/GHSA-cxw3-2f59-5p7f.json create mode 100644 advisories/unreviewed/2024/10/GHSA-f3gg-6f8f-39gh/GHSA-f3gg-6f8f-39gh.json create mode 100644 advisories/unreviewed/2024/10/GHSA-f3xx-63r9-v2cp/GHSA-f3xx-63r9-v2cp.json create mode 100644 advisories/unreviewed/2024/10/GHSA-f7v4-xw4v-h9wq/GHSA-f7v4-xw4v-h9wq.json create mode 100644 advisories/unreviewed/2024/10/GHSA-ffxc-rwg8-qgjw/GHSA-ffxc-rwg8-qgjw.json create mode 100644 advisories/unreviewed/2024/10/GHSA-fh5r-24qv-66r9/GHSA-fh5r-24qv-66r9.json create mode 100644 advisories/unreviewed/2024/10/GHSA-fh83-rw64-jhh7/GHSA-fh83-rw64-jhh7.json create mode 100644 advisories/unreviewed/2024/10/GHSA-fppc-fjqw-6gx5/GHSA-fppc-fjqw-6gx5.json create mode 100644 advisories/unreviewed/2024/10/GHSA-frr9-gqr3-75hc/GHSA-frr9-gqr3-75hc.json create mode 100644 advisories/unreviewed/2024/10/GHSA-g9fr-wfpx-28xj/GHSA-g9fr-wfpx-28xj.json create mode 100644 advisories/unreviewed/2024/10/GHSA-g9mh-3crx-2qvf/GHSA-g9mh-3crx-2qvf.json create mode 100644 advisories/unreviewed/2024/10/GHSA-gcv4-6hmh-xhwc/GHSA-gcv4-6hmh-xhwc.json create mode 100644 advisories/unreviewed/2024/10/GHSA-ggxf-hwrw-c5q2/GHSA-ggxf-hwrw-c5q2.json create mode 100644 advisories/unreviewed/2024/10/GHSA-gj49-2hq5-g5h7/GHSA-gj49-2hq5-g5h7.json create mode 100644 advisories/unreviewed/2024/10/GHSA-gr6g-pg36-368m/GHSA-gr6g-pg36-368m.json create mode 100644 advisories/unreviewed/2024/10/GHSA-h72j-469c-c787/GHSA-h72j-469c-c787.json create mode 100644 advisories/unreviewed/2024/10/GHSA-h7p9-f9r3-6533/GHSA-h7p9-f9r3-6533.json create mode 100644 advisories/unreviewed/2024/10/GHSA-h7r9-ffqq-5r47/GHSA-h7r9-ffqq-5r47.json create mode 100644 advisories/unreviewed/2024/10/GHSA-h9jc-p2cr-c4rx/GHSA-h9jc-p2cr-c4rx.json create mode 100644 advisories/unreviewed/2024/10/GHSA-h9pq-rfrf-6f7p/GHSA-h9pq-rfrf-6f7p.json create mode 100644 advisories/unreviewed/2024/10/GHSA-hpqg-3xxv-rhj6/GHSA-hpqg-3xxv-rhj6.json create mode 100644 advisories/unreviewed/2024/10/GHSA-hr6h-7jqj-mx8j/GHSA-hr6h-7jqj-mx8j.json create mode 100644 advisories/unreviewed/2024/10/GHSA-hxxw-vvrc-qrx3/GHSA-hxxw-vvrc-qrx3.json create mode 100644 advisories/unreviewed/2024/10/GHSA-j2cc-c4fg-77cq/GHSA-j2cc-c4fg-77cq.json create mode 100644 advisories/unreviewed/2024/10/GHSA-j4xv-h5fv-6v4m/GHSA-j4xv-h5fv-6v4m.json create mode 100644 advisories/unreviewed/2024/10/GHSA-j994-f74j-cwf3/GHSA-j994-f74j-cwf3.json create mode 100644 advisories/unreviewed/2024/10/GHSA-jmxw-f4w9-294j/GHSA-jmxw-f4w9-294j.json create mode 100644 advisories/unreviewed/2024/10/GHSA-jq7w-hcx7-gm2r/GHSA-jq7w-hcx7-gm2r.json create mode 100644 advisories/unreviewed/2024/10/GHSA-jww8-jcqp-pmjm/GHSA-jww8-jcqp-pmjm.json create mode 100644 advisories/unreviewed/2024/10/GHSA-m236-cj4j-935h/GHSA-m236-cj4j-935h.json create mode 100644 advisories/unreviewed/2024/10/GHSA-m3fc-5gx3-j98r/GHSA-m3fc-5gx3-j98r.json create mode 100644 advisories/unreviewed/2024/10/GHSA-m5m5-6fc4-ph6r/GHSA-m5m5-6fc4-ph6r.json create mode 100644 advisories/unreviewed/2024/10/GHSA-m7hg-2r4m-qcxr/GHSA-m7hg-2r4m-qcxr.json create mode 100644 advisories/unreviewed/2024/10/GHSA-m8rm-pc2x-rqv9/GHSA-m8rm-pc2x-rqv9.json create mode 100644 advisories/unreviewed/2024/10/GHSA-mc6w-w4fp-fg4v/GHSA-mc6w-w4fp-fg4v.json create mode 100644 advisories/unreviewed/2024/10/GHSA-mf62-gm5r-38wj/GHSA-mf62-gm5r-38wj.json create mode 100644 advisories/unreviewed/2024/10/GHSA-p237-mjc7-7qqj/GHSA-p237-mjc7-7qqj.json create mode 100644 advisories/unreviewed/2024/10/GHSA-p8wj-q5fw-6q9q/GHSA-p8wj-q5fw-6q9q.json create mode 100644 advisories/unreviewed/2024/10/GHSA-pgcr-7vhj-26w2/GHSA-pgcr-7vhj-26w2.json create mode 100644 advisories/unreviewed/2024/10/GHSA-pgjc-h8g4-v6j2/GHSA-pgjc-h8g4-v6j2.json create mode 100644 advisories/unreviewed/2024/10/GHSA-pm28-gfv5-pj4g/GHSA-pm28-gfv5-pj4g.json create mode 100644 advisories/unreviewed/2024/10/GHSA-ppw5-g3vp-9xx2/GHSA-ppw5-g3vp-9xx2.json create mode 100644 advisories/unreviewed/2024/10/GHSA-pvgc-vpgw-88mq/GHSA-pvgc-vpgw-88mq.json create mode 100644 advisories/unreviewed/2024/10/GHSA-q2x4-35qf-p4qw/GHSA-q2x4-35qf-p4qw.json create mode 100644 advisories/unreviewed/2024/10/GHSA-q43m-8jgc-g8w7/GHSA-q43m-8jgc-g8w7.json create mode 100644 advisories/unreviewed/2024/10/GHSA-q7pc-7wvx-9qcx/GHSA-q7pc-7wvx-9qcx.json create mode 100644 advisories/unreviewed/2024/10/GHSA-q823-fhxh-997g/GHSA-q823-fhxh-997g.json create mode 100644 advisories/unreviewed/2024/10/GHSA-q8m3-vwhc-qqmc/GHSA-q8m3-vwhc-qqmc.json create mode 100644 advisories/unreviewed/2024/10/GHSA-qf5q-fm5c-hc2p/GHSA-qf5q-fm5c-hc2p.json create mode 100644 advisories/unreviewed/2024/10/GHSA-qfhj-q535-jf9w/GHSA-qfhj-q535-jf9w.json create mode 100644 advisories/unreviewed/2024/10/GHSA-qgr6-hgc6-qm52/GHSA-qgr6-hgc6-qm52.json create mode 100644 advisories/unreviewed/2024/10/GHSA-qjpg-5hx2-g69j/GHSA-qjpg-5hx2-g69j.json create mode 100644 advisories/unreviewed/2024/10/GHSA-qm4c-x73m-f8mf/GHSA-qm4c-x73m-f8mf.json create mode 100644 advisories/unreviewed/2024/10/GHSA-qqcr-57gp-2jmq/GHSA-qqcr-57gp-2jmq.json create mode 100644 advisories/unreviewed/2024/10/GHSA-qwr8-frg5-xvvr/GHSA-qwr8-frg5-xvvr.json create mode 100644 advisories/unreviewed/2024/10/GHSA-r5f6-w2pg-mf93/GHSA-r5f6-w2pg-mf93.json create mode 100644 advisories/unreviewed/2024/10/GHSA-rcg3-vwp6-7grp/GHSA-rcg3-vwp6-7grp.json create mode 100644 advisories/unreviewed/2024/10/GHSA-rf58-pp6r-5653/GHSA-rf58-pp6r-5653.json create mode 100644 advisories/unreviewed/2024/10/GHSA-rgx3-g7m3-gj3j/GHSA-rgx3-g7m3-gj3j.json create mode 100644 advisories/unreviewed/2024/10/GHSA-rqg9-48mq-4pm8/GHSA-rqg9-48mq-4pm8.json create mode 100644 advisories/unreviewed/2024/10/GHSA-rrh5-rfhq-mff2/GHSA-rrh5-rfhq-mff2.json create mode 100644 advisories/unreviewed/2024/10/GHSA-rvgw-688x-x595/GHSA-rvgw-688x-x595.json create mode 100644 advisories/unreviewed/2024/10/GHSA-rxhv-mw63-w89c/GHSA-rxhv-mw63-w89c.json create mode 100644 advisories/unreviewed/2024/10/GHSA-v3jw-p9pj-m453/GHSA-v3jw-p9pj-m453.json create mode 100644 advisories/unreviewed/2024/10/GHSA-v5pw-w6w2-2r5q/GHSA-v5pw-w6w2-2r5q.json create mode 100644 advisories/unreviewed/2024/10/GHSA-v9vq-7m9c-h738/GHSA-v9vq-7m9c-h738.json create mode 100644 advisories/unreviewed/2024/10/GHSA-vcrj-5576-fc99/GHSA-vcrj-5576-fc99.json create mode 100644 advisories/unreviewed/2024/10/GHSA-vp2p-wqj6-25wf/GHSA-vp2p-wqj6-25wf.json create mode 100644 advisories/unreviewed/2024/10/GHSA-vw3v-9427-r3gf/GHSA-vw3v-9427-r3gf.json create mode 100644 advisories/unreviewed/2024/10/GHSA-w38v-phv7-fjq8/GHSA-w38v-phv7-fjq8.json create mode 100644 advisories/unreviewed/2024/10/GHSA-w7r5-57r3-mcrc/GHSA-w7r5-57r3-mcrc.json create mode 100644 advisories/unreviewed/2024/10/GHSA-w7w7-6353-385q/GHSA-w7w7-6353-385q.json create mode 100644 advisories/unreviewed/2024/10/GHSA-w89v-9wr9-8jx2/GHSA-w89v-9wr9-8jx2.json create mode 100644 advisories/unreviewed/2024/10/GHSA-w8mx-fc3q-r9qv/GHSA-w8mx-fc3q-r9qv.json create mode 100644 advisories/unreviewed/2024/10/GHSA-wg4j-4q4f-6cfc/GHSA-wg4j-4q4f-6cfc.json create mode 100644 advisories/unreviewed/2024/10/GHSA-wh99-hh68-w2m5/GHSA-wh99-hh68-w2m5.json create mode 100644 advisories/unreviewed/2024/10/GHSA-x3rh-vhj8-7wq6/GHSA-x3rh-vhj8-7wq6.json create mode 100644 advisories/unreviewed/2024/10/GHSA-x5vx-qmf9-2r9v/GHSA-x5vx-qmf9-2r9v.json create mode 100644 advisories/unreviewed/2024/10/GHSA-x652-w4xg-69jh/GHSA-x652-w4xg-69jh.json create mode 100644 advisories/unreviewed/2024/10/GHSA-x75j-gc7f-rqjc/GHSA-x75j-gc7f-rqjc.json create mode 100644 advisories/unreviewed/2024/10/GHSA-xrhf-cccw-cpm8/GHSA-xrhf-cccw-cpm8.json diff --git a/advisories/unreviewed/2022/05/GHSA-2gxx-vxp2-c52q/GHSA-2gxx-vxp2-c52q.json b/advisories/unreviewed/2022/05/GHSA-2gxx-vxp2-c52q/GHSA-2gxx-vxp2-c52q.json index e54d19ed722..0daa38fa379 100644 --- a/advisories/unreviewed/2022/05/GHSA-2gxx-vxp2-c52q/GHSA-2gxx-vxp2-c52q.json +++ b/advisories/unreviewed/2022/05/GHSA-2gxx-vxp2-c52q/GHSA-2gxx-vxp2-c52q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-2gxx-vxp2-c52q", - "modified": "2022-05-02T03:16:35Z", + "modified": "2024-10-21T18:30:41Z", "published": "2022-05-02T03:16:35Z", "aliases": [ "CVE-2009-0551" ], "details": "Microsoft Internet Explorer 6 SP1, 6 and 7 on Windows XP SP2 and SP3, 6 and 7 on Windows Server 2003 SP1 and SP2, 7 on Windows Vista Gold and SP1, and 7 on Windows Server 2008 does not properly handle transition errors in a request for one HTTP document followed by a request for a second HTTP document, which allows remote attackers to execute arbitrary code via vectors involving (1) multiple crafted pages on a web site or (2) a web page with crafted inline content such as banner advertisements, aka \"Page Transition Memory Corruption Vulnerability.\"", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-533f-24pj-cvj8/GHSA-533f-24pj-cvj8.json b/advisories/unreviewed/2022/05/GHSA-533f-24pj-cvj8/GHSA-533f-24pj-cvj8.json index 09224c19530..85b6cf01548 100644 --- a/advisories/unreviewed/2022/05/GHSA-533f-24pj-cvj8/GHSA-533f-24pj-cvj8.json +++ b/advisories/unreviewed/2022/05/GHSA-533f-24pj-cvj8/GHSA-533f-24pj-cvj8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-533f-24pj-cvj8", - "modified": "2022-05-02T03:47:36Z", + "modified": "2024-10-21T18:30:42Z", "published": "2022-05-02T03:47:36Z", "aliases": [ "CVE-2009-3671" ], "details": "Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka \"Uninitialized Memory Corruption Vulnerability,\" a different vulnerability than CVE-2009-3674.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,7 +40,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-5pwp-v5cx-v53w/GHSA-5pwp-v5cx-v53w.json b/advisories/unreviewed/2022/05/GHSA-5pwp-v5cx-v53w/GHSA-5pwp-v5cx-v53w.json index cea3e080a83..47bf40a7593 100644 --- a/advisories/unreviewed/2022/05/GHSA-5pwp-v5cx-v53w/GHSA-5pwp-v5cx-v53w.json +++ b/advisories/unreviewed/2022/05/GHSA-5pwp-v5cx-v53w/GHSA-5pwp-v5cx-v53w.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5pwp-v5cx-v53w", - "modified": "2022-05-02T03:26:06Z", + "modified": "2024-10-21T18:30:41Z", "published": "2022-05-02T03:26:06Z", "aliases": [ "CVE-2009-1529" ], "details": "Microsoft Internet Explorer 7 for Windows XP SP2 and SP3; 7 for Server 2003 SP2; 7 for Vista Gold, SP1, and SP2; and 7 for Server 2008 SP2 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by calling the setCapture method on a collection of crafted objects, aka \"Uninitialized Memory Corruption Vulnerability.\"", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -57,7 +60,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-908" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-74r2-qf2j-vm8r/GHSA-74r2-qf2j-vm8r.json b/advisories/unreviewed/2022/05/GHSA-74r2-qf2j-vm8r/GHSA-74r2-qf2j-vm8r.json index 8585175ff4c..c83079ceb45 100644 --- a/advisories/unreviewed/2022/05/GHSA-74r2-qf2j-vm8r/GHSA-74r2-qf2j-vm8r.json +++ b/advisories/unreviewed/2022/05/GHSA-74r2-qf2j-vm8r/GHSA-74r2-qf2j-vm8r.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-74r2-qf2j-vm8r", - "modified": "2022-05-17T01:01:53Z", + "modified": "2024-10-21T18:30:42Z", "published": "2022-05-17T01:01:53Z", "aliases": [ "CVE-2011-1142" ], "details": "Stack consumption vulnerability in the dissect_ber_choice function in the BER dissector in Wireshark 1.2.x through 1.2.15 and 1.4.x through 1.4.4 might allow remote attackers to cause a denial of service (infinite loop) via vectors involving self-referential ASN.1 CHOICE values.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-8h3g-5w8f-55gv/GHSA-8h3g-5w8f-55gv.json b/advisories/unreviewed/2022/05/GHSA-8h3g-5w8f-55gv/GHSA-8h3g-5w8f-55gv.json index 3628f7423d1..8f314cb5619 100644 --- a/advisories/unreviewed/2022/05/GHSA-8h3g-5w8f-55gv/GHSA-8h3g-5w8f-55gv.json +++ b/advisories/unreviewed/2022/05/GHSA-8h3g-5w8f-55gv/GHSA-8h3g-5w8f-55gv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8h3g-5w8f-55gv", - "modified": "2022-05-13T01:15:38Z", + "modified": "2024-10-21T18:30:43Z", "published": "2022-05-13T01:15:38Z", "aliases": [ "CVE-2012-1539" ], "details": "Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code via a crafted web site, aka \"CTreePos Use After Free Vulnerability.\"", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -45,7 +48,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-f74f-9cfw-p3xj/GHSA-f74f-9cfw-p3xj.json b/advisories/unreviewed/2022/05/GHSA-f74f-9cfw-p3xj/GHSA-f74f-9cfw-p3xj.json index 09a96688e3a..df548438fcf 100644 --- a/advisories/unreviewed/2022/05/GHSA-f74f-9cfw-p3xj/GHSA-f74f-9cfw-p3xj.json +++ b/advisories/unreviewed/2022/05/GHSA-f74f-9cfw-p3xj/GHSA-f74f-9cfw-p3xj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f74f-9cfw-p3xj", - "modified": "2022-05-02T03:26:11Z", + "modified": "2024-10-21T18:30:41Z", "published": "2022-05-02T03:26:11Z", "aliases": [ "CVE-2009-1544" ], "details": "Double free vulnerability in the Workstation service in Microsoft Windows allows remote authenticated users to gain privileges via a crafted RPC message to a Windows XP SP2 or SP3 or Server 2003 SP2 system, or cause a denial of service via a crafted RPC message to a Vista Gold, SP1, or SP2 or Server 2008 Gold or SP2 system, aka \"Workstation Service Memory Corruption Vulnerability.\"", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-415" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-f9vw-75cc-w892/GHSA-f9vw-75cc-w892.json b/advisories/unreviewed/2022/05/GHSA-f9vw-75cc-w892/GHSA-f9vw-75cc-w892.json index 1caa7dbdf5b..0df451d3b34 100644 --- a/advisories/unreviewed/2022/05/GHSA-f9vw-75cc-w892/GHSA-f9vw-75cc-w892.json +++ b/advisories/unreviewed/2022/05/GHSA-f9vw-75cc-w892/GHSA-f9vw-75cc-w892.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f9vw-75cc-w892", - "modified": "2022-05-02T06:20:45Z", + "modified": "2024-10-21T18:30:42Z", "published": "2022-05-02T06:20:45Z", "aliases": [ "CVE-2010-1260" ], "details": "The IE8 Developer Toolbar in Microsoft Internet Explorer 8 SP1, SP2, and SP3 allows user-assisted remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka \"HTML Element Memory Corruption Vulnerability.\"", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-h99v-p65j-fpx4/GHSA-h99v-p65j-fpx4.json b/advisories/unreviewed/2022/05/GHSA-h99v-p65j-fpx4/GHSA-h99v-p65j-fpx4.json index 20b729be087..6206c2f5d86 100644 --- a/advisories/unreviewed/2022/05/GHSA-h99v-p65j-fpx4/GHSA-h99v-p65j-fpx4.json +++ b/advisories/unreviewed/2022/05/GHSA-h99v-p65j-fpx4/GHSA-h99v-p65j-fpx4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-h99v-p65j-fpx4", - "modified": "2022-05-02T03:35:50Z", + "modified": "2024-10-21T18:30:41Z", "published": "2022-05-02T03:35:50Z", "aliases": [ "CVE-2009-2502" ], "details": "Buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003 Gold and SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1, and SP2, Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2, Expression Web, Expression Web 2, Groove 2007 Gold and SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 and SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold and SP1, and Forefront Client Security 1.0 allows remote attackers to execute arbitrary code via a crafted TIFF image file, aka \"GDI+ TIFF Buffer Overflow Vulnerability.\"", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,7 +36,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-hrmj-vxfx-2vq3/GHSA-hrmj-vxfx-2vq3.json b/advisories/unreviewed/2022/05/GHSA-hrmj-vxfx-2vq3/GHSA-hrmj-vxfx-2vq3.json index f1525867460..c71fb482762 100644 --- a/advisories/unreviewed/2022/05/GHSA-hrmj-vxfx-2vq3/GHSA-hrmj-vxfx-2vq3.json +++ b/advisories/unreviewed/2022/05/GHSA-hrmj-vxfx-2vq3/GHSA-hrmj-vxfx-2vq3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hrmj-vxfx-2vq3", - "modified": "2022-05-14T01:32:15Z", + "modified": "2024-10-21T18:30:43Z", "published": "2022-05-14T01:32:15Z", "aliases": [ "CVE-2013-0810" ], "details": "Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, and Windows Server 2008 SP2 allow remote attackers to execute arbitrary code via a crafted screensaver in a theme file, aka \"Windows Theme File Remote Code Execution Vulnerability.\"", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-jjvg-65v4-v3cq/GHSA-jjvg-65v4-v3cq.json b/advisories/unreviewed/2022/05/GHSA-jjvg-65v4-v3cq/GHSA-jjvg-65v4-v3cq.json index c0268a3e3b2..96e3e155931 100644 --- a/advisories/unreviewed/2022/05/GHSA-jjvg-65v4-v3cq/GHSA-jjvg-65v4-v3cq.json +++ b/advisories/unreviewed/2022/05/GHSA-jjvg-65v4-v3cq/GHSA-jjvg-65v4-v3cq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jjvg-65v4-v3cq", - "modified": "2022-05-14T02:47:10Z", + "modified": "2024-10-21T18:30:44Z", "published": "2022-05-14T02:47:10Z", "aliases": [ "CVE-2015-8370" ], "details": "Multiple integer underflows in Grub2 1.98 through 2.02 allow physically proximate attackers to bypass authentication, obtain sensitive information, or cause a denial of service (disk corruption) via backspace characters in the (1) grub_username_get function in grub-core/normal/auth.c or the (2) grub_password_get function in lib/crypto.c, which trigger an \"Off-by-two\" or \"Out of bounds overwrite\" memory error.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -113,7 +116,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-191" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-p9r7-8rjp-gmw3/GHSA-p9r7-8rjp-gmw3.json b/advisories/unreviewed/2022/05/GHSA-p9r7-8rjp-gmw3/GHSA-p9r7-8rjp-gmw3.json index 67a9b2a5b4f..7a2b8426688 100644 --- a/advisories/unreviewed/2022/05/GHSA-p9r7-8rjp-gmw3/GHSA-p9r7-8rjp-gmw3.json +++ b/advisories/unreviewed/2022/05/GHSA-p9r7-8rjp-gmw3/GHSA-p9r7-8rjp-gmw3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p9r7-8rjp-gmw3", - "modified": "2022-05-13T01:07:45Z", + "modified": "2024-10-21T18:30:43Z", "published": "2022-05-13T01:07:45Z", "aliases": [ "CVE-2011-0346" ], "details": "Use-after-free vulnerability in the ReleaseInterface function in MSHTML.DLL in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to the DOM implementation and the BreakAASpecial and BreakCircularMemoryReferences functions, as demonstrated by cross_fuzz, aka \"MSHTML Memory Corruption Vulnerability.\"", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -81,7 +84,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-r97j-8742-f767/GHSA-r97j-8742-f767.json b/advisories/unreviewed/2022/05/GHSA-r97j-8742-f767/GHSA-r97j-8742-f767.json index 3dbad55bca9..ee2c5a8b853 100644 --- a/advisories/unreviewed/2022/05/GHSA-r97j-8742-f767/GHSA-r97j-8742-f767.json +++ b/advisories/unreviewed/2022/05/GHSA-r97j-8742-f767/GHSA-r97j-8742-f767.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r97j-8742-f767", - "modified": "2022-05-02T06:13:05Z", + "modified": "2024-10-21T18:30:42Z", "published": "2022-05-02T06:13:05Z", "aliases": [ "CVE-2010-0492" ], "details": "Use-after-free vulnerability in mstime.dll in Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code via vectors related to the TIME2 behavior, the CTimeAction object, and destruction of markup, leading to memory corruption, aka \"HTML Object Memory Corruption Vulnerability.\"", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2022/05/GHSA-vqxq-fjhv-69jf/GHSA-vqxq-fjhv-69jf.json b/advisories/unreviewed/2022/05/GHSA-vqxq-fjhv-69jf/GHSA-vqxq-fjhv-69jf.json index debc7a31392..d82638aa53b 100644 --- a/advisories/unreviewed/2022/05/GHSA-vqxq-fjhv-69jf/GHSA-vqxq-fjhv-69jf.json +++ b/advisories/unreviewed/2022/05/GHSA-vqxq-fjhv-69jf/GHSA-vqxq-fjhv-69jf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vqxq-fjhv-69jf", - "modified": "2022-05-02T06:11:14Z", + "modified": "2024-10-21T18:30:42Z", "published": "2022-05-02T06:11:14Z", "aliases": [ "CVE-2010-0248" ], "details": "Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka \"HTML Object Memory Corruption Vulnerability.\"", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -33,6 +36,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-416", "CWE-94" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/05/GHSA-wm54-3xjp-vjmc/GHSA-wm54-3xjp-vjmc.json b/advisories/unreviewed/2022/05/GHSA-wm54-3xjp-vjmc/GHSA-wm54-3xjp-vjmc.json index 695bc8a232b..10783cf46a8 100644 --- a/advisories/unreviewed/2022/05/GHSA-wm54-3xjp-vjmc/GHSA-wm54-3xjp-vjmc.json +++ b/advisories/unreviewed/2022/05/GHSA-wm54-3xjp-vjmc/GHSA-wm54-3xjp-vjmc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wm54-3xjp-vjmc", - "modified": "2022-05-02T03:36:08Z", + "modified": "2024-10-21T18:30:41Z", "published": "2022-05-02T03:36:08Z", "aliases": [ "CVE-2009-2529" ], "details": "Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, 7, and 8 does not properly handle argument validation for unspecified variables, which allows remote attackers to execute arbitrary code via a crafted HTML document, aka \"HTML Component Handling Vulnerability.\"", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ diff --git a/advisories/unreviewed/2023/03/GHSA-q56j-8x89-gvgg/GHSA-q56j-8x89-gvgg.json b/advisories/unreviewed/2023/03/GHSA-q56j-8x89-gvgg/GHSA-q56j-8x89-gvgg.json index dbe6b3389b0..188e4fcd2a0 100644 --- a/advisories/unreviewed/2023/03/GHSA-q56j-8x89-gvgg/GHSA-q56j-8x89-gvgg.json +++ b/advisories/unreviewed/2023/03/GHSA-q56j-8x89-gvgg/GHSA-q56j-8x89-gvgg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q56j-8x89-gvgg", - "modified": "2023-04-05T18:30:16Z", + "modified": "2024-10-21T18:30:45Z", "published": "2023-03-29T18:30:29Z", "aliases": [ "CVE-2022-48434" diff --git a/advisories/unreviewed/2023/04/GHSA-rwg2-cqg5-rjm4/GHSA-rwg2-cqg5-rjm4.json b/advisories/unreviewed/2023/04/GHSA-rwg2-cqg5-rjm4/GHSA-rwg2-cqg5-rjm4.json index 7a1b334ee6e..29db4bc6b32 100644 --- a/advisories/unreviewed/2023/04/GHSA-rwg2-cqg5-rjm4/GHSA-rwg2-cqg5-rjm4.json +++ b/advisories/unreviewed/2023/04/GHSA-rwg2-cqg5-rjm4/GHSA-rwg2-cqg5-rjm4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rwg2-cqg5-rjm4", - "modified": "2023-11-29T15:30:20Z", + "modified": "2024-10-21T18:30:45Z", "published": "2023-04-28T03:30:16Z", "aliases": [ "CVE-2023-31436" diff --git a/advisories/unreviewed/2023/06/GHSA-4f5g-h3x2-8v9x/GHSA-4f5g-h3x2-8v9x.json b/advisories/unreviewed/2023/06/GHSA-4f5g-h3x2-8v9x/GHSA-4f5g-h3x2-8v9x.json index 46630f3740f..b8f6e6d25fc 100644 --- a/advisories/unreviewed/2023/06/GHSA-4f5g-h3x2-8v9x/GHSA-4f5g-h3x2-8v9x.json +++ b/advisories/unreviewed/2023/06/GHSA-4f5g-h3x2-8v9x/GHSA-4f5g-h3x2-8v9x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4f5g-h3x2-8v9x", - "modified": "2023-12-04T15:31:54Z", + "modified": "2024-10-21T18:30:45Z", "published": "2023-06-19T00:30:19Z", "aliases": [ "CVE-2023-35828" diff --git a/advisories/unreviewed/2023/11/GHSA-3v76-qg7g-rx9c/GHSA-3v76-qg7g-rx9c.json b/advisories/unreviewed/2023/11/GHSA-3v76-qg7g-rx9c/GHSA-3v76-qg7g-rx9c.json index 63ac757cd1e..c933cec68c4 100644 --- a/advisories/unreviewed/2023/11/GHSA-3v76-qg7g-rx9c/GHSA-3v76-qg7g-rx9c.json +++ b/advisories/unreviewed/2023/11/GHSA-3v76-qg7g-rx9c/GHSA-3v76-qg7g-rx9c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3v76-qg7g-rx9c", - "modified": "2023-11-30T15:30:22Z", + "modified": "2024-10-21T18:30:45Z", "published": "2023-11-20T21:31:02Z", "aliases": [ "CVE-2023-38885" diff --git a/advisories/unreviewed/2023/11/GHSA-hchc-m7jw-6mhm/GHSA-hchc-m7jw-6mhm.json b/advisories/unreviewed/2023/11/GHSA-hchc-m7jw-6mhm/GHSA-hchc-m7jw-6mhm.json index 7cf8db0edbf..7e7c66e9c2f 100644 --- a/advisories/unreviewed/2023/11/GHSA-hchc-m7jw-6mhm/GHSA-hchc-m7jw-6mhm.json +++ b/advisories/unreviewed/2023/11/GHSA-hchc-m7jw-6mhm/GHSA-hchc-m7jw-6mhm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hchc-m7jw-6mhm", - "modified": "2023-12-05T21:31:00Z", + "modified": "2024-10-21T18:30:45Z", "published": "2023-11-16T09:30:24Z", "aliases": [ "CVE-2023-47213" diff --git a/advisories/unreviewed/2024/10/GHSA-22wr-xr3p-42c4/GHSA-22wr-xr3p-42c4.json b/advisories/unreviewed/2024/10/GHSA-22wr-xr3p-42c4/GHSA-22wr-xr3p-42c4.json new file mode 100644 index 00000000000..1b4a9c28d92 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-22wr-xr3p-42c4/GHSA-22wr-xr3p-42c4.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-22wr-xr3p-42c4", + "modified": "2024-10-21T18:30:57Z", + "published": "2024-10-21T18:30:57Z", + "aliases": [ + "CVE-2024-49897" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Check phantom_stream before it is used\n\ndcn32_enable_phantom_stream can return null, so returned value\nmust be checked before used.\n\nThis fixes 1 NULL_RETURNS issue reported by Coverity.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49897" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1decf695ce08e23d9ded6ce83d121b2282ce9899" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3718a619a8c0a53152e76bb6769b6c414e1e83f4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3ba1219e299ab5462b5cb374c2fa2a67af0ea190" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-23px-9798-3x5c/GHSA-23px-9798-3x5c.json b/advisories/unreviewed/2024/10/GHSA-23px-9798-3x5c/GHSA-23px-9798-3x5c.json new file mode 100644 index 00000000000..01e3946c695 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-23px-9798-3x5c/GHSA-23px-9798-3x5c.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-23px-9798-3x5c", + "modified": "2024-10-21T18:30:59Z", + "published": "2024-10-21T18:30:59Z", + "aliases": [ + "CVE-2024-49965" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: remove unreasonable unlock in ocfs2_read_blocks\n\nPatch series \"Misc fixes for ocfs2_read_blocks\", v5.\n\nThis series contains 2 fixes for ocfs2_read_blocks(). The first patch fix\nthe issue reported by syzbot, which detects bad unlock balance in\nocfs2_read_blocks(). The second patch fixes an issue reported by Heming\nZhao when reviewing above fix.\n\n\nThis patch (of 2):\n\nThere was a lock release before exiting, so remove the unreasonable unlock.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49965" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/39a88623af3f1c686bf6db1e677ed865ffe6fccc" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3f1ca6ba5452d53c598a45d21267a2c0c221eef3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/81aba693b129e82e11bb54f569504d943d018de9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/84543da867c967edffd5065fa910ebf56aaae49d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c03a82b4a0c935774afa01fd6d128b444fd930a1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/df4f20fc3673cee11abf2c571987a95733cb638d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f55a33fe0fb5274ef185fd61947cf142138958af" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-24gv-qfv8-v7f5/GHSA-24gv-qfv8-v7f5.json b/advisories/unreviewed/2024/10/GHSA-24gv-qfv8-v7f5/GHSA-24gv-qfv8-v7f5.json new file mode 100644 index 00000000000..9d5f6612243 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-24gv-qfv8-v7f5/GHSA-24gv-qfv8-v7f5.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-24gv-qfv8-v7f5", + "modified": "2024-10-21T18:30:59Z", + "published": "2024-10-21T18:30:59Z", + "aliases": [ + "CVE-2024-49983" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\next4: drop ppath from ext4_ext_replay_update_ex() to avoid double-free\n\nWhen calling ext4_force_split_extent_at() in ext4_ext_replay_update_ex(),\nthe 'ppath' is updated but it is the 'path' that is freed, thus potentially\ntriggering a double-free in the following process:\n\next4_ext_replay_update_ex\n ppath = path\n ext4_force_split_extent_at(&ppath)\n ext4_split_extent_at\n ext4_ext_insert_extent\n ext4_ext_create_new_leaf\n ext4_ext_grow_indepth\n ext4_find_extent\n if (depth > path[0].p_maxdepth)\n kfree(path) ---> path First freed\n *orig_path = path = NULL ---> null ppath\n kfree(path) ---> path double-free !!!\n\nSo drop the unnecessary ppath and use path directly to avoid this problem.\nAnd use ext4_find_extent() directly to update path, avoiding unnecessary\nmemory allocation and freeing. Also, propagate the error returned by\next4_find_extent() instead of using strange error codes.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49983" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1b558006d98b7b0b730027be0ee98973dd10ee0d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3ff710662e8d86a63a39b334e9ca0cb10e5c14b0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5c0f4cc84d3a601c99bc5e6e6eb1cbda542cce95" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6367d3f04c69e2b8770b8137bd800e0784b0abbc" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/63adc9016917e6970fb0104ee5fd6770f02b2d80" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8c26d9e53e5fbacda0732a577e97c5a5b7882aaf" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a34bed978364114390162c27e50fca50791c568d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-24vf-v4v3-xgmr/GHSA-24vf-v4v3-xgmr.json b/advisories/unreviewed/2024/10/GHSA-24vf-v4v3-xgmr/GHSA-24vf-v4v3-xgmr.json new file mode 100644 index 00000000000..848ccdd9d30 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-24vf-v4v3-xgmr/GHSA-24vf-v4v3-xgmr.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-24vf-v4v3-xgmr", + "modified": "2024-10-21T18:30:59Z", + "published": "2024-10-21T18:30:59Z", + "aliases": [ + "CVE-2024-49975" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nuprobes: fix kernel info leak via \"[uprobes]\" vma\n\nxol_add_vma() maps the uninitialized page allocated by __create_xol_area()\ninto userspace. On some architectures (x86) this memory is readable even\nwithout VM_READ, VM_EXEC results in the same pgprot_t as VM_EXEC|VM_READ,\nalthough this doesn't really matter, debugger can read this memory anyway.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49975" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/21cb47db1ec9765f91304763a24565ddc22d2492" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/24141df5a8615790950deedd926a44ddf1dfd6d8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2aa45f43709ba2082917bd2973d02687075b6eee" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/34820304cc2cd1804ee1f8f3504ec77813d29c8e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5b981d8335e18aef7908a068529a3287258ff6d8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9634e8dc964a4adafa7e1535147abd7ec29441a6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f561b48d633ac2e7d0d667020fc634a96ade33a0" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-26q7-wp6g-349w/GHSA-26q7-wp6g-349w.json b/advisories/unreviewed/2024/10/GHSA-26q7-wp6g-349w/GHSA-26q7-wp6g-349w.json new file mode 100644 index 00000000000..19ef931ea59 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-26q7-wp6g-349w/GHSA-26q7-wp6g-349w.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-26q7-wp6g-349w", + "modified": "2024-10-21T18:30:58Z", + "published": "2024-10-21T18:30:58Z", + "aliases": [ + "CVE-2024-49931" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath12k: fix array out-of-bound access in SoC stats\n\nCurrently, the ath12k_soc_dp_stats::hal_reo_error array is defined with a\nmaximum size of DP_REO_DST_RING_MAX. However, the ath12k_dp_rx_process()\nfunction access ath12k_soc_dp_stats::hal_reo_error using the REO\ndestination SRNG ring ID, which is incorrect. SRNG ring ID differ from\nnormal ring ID, and this usage leads to out-of-bounds array access. To\nfix this issue, modify ath12k_dp_rx_process() to use the normal ring ID\ndirectly instead of the SRNG ring ID to avoid out-of-bounds array access.\n\nTested-on: QCN9274 hw2.0 PCI WLAN.WBE.1.0.1-00029-QCAHKSWPL_SILICONZ-1", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49931" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a4aef827a41cdaf6201bbaf773c1eae4e20e967b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ad791e3ec60cb66c1e4dc121ffbf872df312427d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d0e4274d9dc9f8409d56d622cd3ecf7b6fd49e2f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e106b7ad13c1d246adaa57df73edb8f8b8acb240" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-276c-3gx4-x9pr/GHSA-276c-3gx4-x9pr.json b/advisories/unreviewed/2024/10/GHSA-276c-3gx4-x9pr/GHSA-276c-3gx4-x9pr.json new file mode 100644 index 00000000000..9850f23706e --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-276c-3gx4-x9pr/GHSA-276c-3gx4-x9pr.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-276c-3gx4-x9pr", + "modified": "2024-10-21T18:31:00Z", + "published": "2024-10-21T18:30:59Z", + "aliases": [ + "CVE-2024-49996" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncifs: Fix buffer overflow when parsing NFS reparse points\n\nReparseDataLength is sum of the InodeType size and DataBuffer size.\nSo to get DataBuffer size it is needed to subtract InodeType's size from\nReparseDataLength.\n\nFunction cifs_strndup_from_utf16() is currentlly accessing buf->DataBuffer\nat position after the end of the buffer because it does not subtract\nInodeType size from the length. Fix this problem and correctly subtract\nvariable len.\n\nMember InodeType is present only when reparse buffer is large enough. Check\nfor ReparseDataLength before accessing InodeType to prevent another invalid\nmemory access.\n\nMajor and minor rdev values are present also only when reparse buffer is\nlarge enough. Check for reparse buffer size before calling reparse_mkdev().", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49996" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/803b3a39cb096d8718c0aebc03fd19f11c7dc919" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c173d47b69f07cd7ca08efb4e458adbd4725d8e9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c6db81c550cea0c73bd72ef55f579991e0e4ba07" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e2a8910af01653c1c268984855629d71fb81f404" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-2gvh-vj62-qjmp/GHSA-2gvh-vj62-qjmp.json b/advisories/unreviewed/2024/10/GHSA-2gvh-vj62-qjmp/GHSA-2gvh-vj62-qjmp.json new file mode 100644 index 00000000000..49571b68cb8 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-2gvh-vj62-qjmp/GHSA-2gvh-vj62-qjmp.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2gvh-vj62-qjmp", + "modified": "2024-10-21T18:30:58Z", + "published": "2024-10-21T18:30:58Z", + "aliases": [ + "CVE-2024-49926" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nrcu-tasks: Fix access non-existent percpu rtpcp variable in rcu_tasks_need_gpcb()\n\nFor kernels built with CONFIG_FORCE_NR_CPUS=y, the nr_cpu_ids is\ndefined as NR_CPUS instead of the number of possible cpus, this\nwill cause the following system panic:\n\nsmpboot: Allowing 4 CPUs, 0 hotplug CPUs\n...\nsetup_percpu: NR_CPUS:512 nr_cpumask_bits:512 nr_cpu_ids:512 nr_node_ids:1\n...\nBUG: unable to handle page fault for address: ffffffff9911c8c8\nOops: 0000 [#1] PREEMPT SMP PTI\nCPU: 0 PID: 15 Comm: rcu_tasks_trace Tainted: G W\n6.6.21 #1 5dc7acf91a5e8e9ac9dcfc35bee0245691283ea6\nRIP: 0010:rcu_tasks_need_gpcb+0x25d/0x2c0\nRSP: 0018:ffffa371c00a3e60 EFLAGS: 00010082\nCR2: ffffffff9911c8c8 CR3: 000000040fa20005 CR4: 00000000001706f0\nCall Trace:\n\n? __die+0x23/0x80\n? page_fault_oops+0xa4/0x180\n? exc_page_fault+0x152/0x180\n? asm_exc_page_fault+0x26/0x40\n? rcu_tasks_need_gpcb+0x25d/0x2c0\n? __pfx_rcu_tasks_kthread+0x40/0x40\nrcu_tasks_one_gp+0x69/0x180\nrcu_tasks_kthread+0x94/0xc0\nkthread+0xe8/0x140\n? __pfx_kthread+0x40/0x40\nret_from_fork+0x34/0x80\n? __pfx_kthread+0x40/0x40\nret_from_fork_asm+0x1b/0x80\n\n\nConsidering that there may be holes in the CPU numbers, use the\nmaximum possible cpu number, instead of nr_cpu_ids, for configuring\nenqueue and dequeue limits.\n\n[ neeraj.upadhyay: Fix htmldocs build error reported by Stephen Rothwell ]", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49926" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/05095271a4fb0f6497121a057f9a2edf386d5d96" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3104bddc666ff64b90491868bbc4c7ebdd90aedf" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fd70e9f1d85f5323096ad313ba73f5fe3d15ea41" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-2h84-jhpc-6px2/GHSA-2h84-jhpc-6px2.json b/advisories/unreviewed/2024/10/GHSA-2h84-jhpc-6px2/GHSA-2h84-jhpc-6px2.json new file mode 100644 index 00000000000..c068e1d5c40 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-2h84-jhpc-6px2/GHSA-2h84-jhpc-6px2.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2h84-jhpc-6px2", + "modified": "2024-10-21T18:30:57Z", + "published": "2024-10-21T18:30:57Z", + "aliases": [ + "CVE-2024-49915" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Add NULL check for clk_mgr in dcn32_init_hw\n\nThis commit addresses a potential null pointer dereference issue in the\n`dcn32_init_hw` function. The issue could occur when `dc->clk_mgr` is\nnull.\n\nThe fix adds a check to ensure `dc->clk_mgr` is not null before\naccessing its functions. This prevents a potential null pointer\ndereference.\n\nReported by smatch:\ndrivers/gpu/drm/amd/amdgpu/../display/dc/hwss/dcn32/dcn32_hwseq.c:961 dcn32_init_hw() error: we previously assumed 'dc->clk_mgr' could be null (see line 782)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49915" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7d1854c86d02cea8f8a0c0ca05f4ab14292baf3d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c395fd47d1565bd67671f45cca281b3acc2c31ef" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f0454b3cb0584a6bf275aeb49be61a760fd546a2" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-2h93-g5hm-9qcv/GHSA-2h93-g5hm-9qcv.json b/advisories/unreviewed/2024/10/GHSA-2h93-g5hm-9qcv/GHSA-2h93-g5hm-9qcv.json new file mode 100644 index 00000000000..dfb93f09b57 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-2h93-g5hm-9qcv/GHSA-2h93-g5hm-9qcv.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2h93-g5hm-9qcv", + "modified": "2024-10-21T18:30:57Z", + "published": "2024-10-21T18:30:56Z", + "aliases": [ + "CVE-2024-49885" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm, slub: avoid zeroing kmalloc redzone\n\nSince commit 946fa0dbf2d8 (\"mm/slub: extend redzone check to extra\nallocated kmalloc space than requested\"), setting orig_size treats\nthe wasted space (object_size - orig_size) as a redzone. However with\ninit_on_free=1 we clear the full object->size, including the redzone.\n\nAdditionally we clear the object metadata, including the stored orig_size,\nmaking it zero, which makes check_object() treat the whole object as a\nredzone.\n\nThese issues lead to the following BUG report with \"slub_debug=FUZ\ninit_on_free=1\":\n\n[ 0.000000] =============================================================================\n[ 0.000000] BUG kmalloc-8 (Not tainted): kmalloc Redzone overwritten\n[ 0.000000] -----------------------------------------------------------------------------\n[ 0.000000]\n[ 0.000000] 0xffff000010032858-0xffff00001003285f @offset=2136. First byte 0x0 instead of 0xcc\n[ 0.000000] FIX kmalloc-8: Restoring kmalloc Redzone 0xffff000010032858-0xffff00001003285f=0xcc\n[ 0.000000] Slab 0xfffffdffc0400c80 objects=36 used=23 fp=0xffff000010032a18 flags=0x3fffe0000000200(workingset|node=0|zone=0|lastcpupid=0x1ffff)\n[ 0.000000] Object 0xffff000010032858 @offset=2136 fp=0xffff0000100328c8\n[ 0.000000]\n[ 0.000000] Redzone ffff000010032850: cc cc cc cc cc cc cc cc ........\n[ 0.000000] Object ffff000010032858: cc cc cc cc cc cc cc cc ........\n[ 0.000000] Redzone ffff000010032860: cc cc cc cc cc cc cc cc ........\n[ 0.000000] Padding ffff0000100328b4: 00 00 00 00 00 00 00 00 00 00 00 00 ............\n[ 0.000000] CPU: 0 UID: 0 PID: 0 Comm: swapper/0 Not tainted 6.11.0-rc3-next-20240814-00004-g61844c55c3f4 #144\n[ 0.000000] Hardware name: NXP i.MX95 19X19 board (DT)\n[ 0.000000] Call trace:\n[ 0.000000] dump_backtrace+0x90/0xe8\n[ 0.000000] show_stack+0x18/0x24\n[ 0.000000] dump_stack_lvl+0x74/0x8c\n[ 0.000000] dump_stack+0x18/0x24\n[ 0.000000] print_trailer+0x150/0x218\n[ 0.000000] check_object+0xe4/0x454\n[ 0.000000] free_to_partial_list+0x2f8/0x5ec\n\nTo address the issue, use orig_size to clear the used area. And restore\nthe value of orig_size after clear the remaining area.\n\nWhen CONFIG_SLUB_DEBUG not defined, (get_orig_size()' directly returns\ns->object_size. So when using memset to init the area, the size can simply\nbe orig_size, as orig_size returns object_size when CONFIG_SLUB_DEBUG not\nenabled. And orig_size can never be bigger than object_size.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49885" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/59090e479ac78ae18facd4c58eb332562a23020e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7a2e823a19746d54052c625faecf0d2d6c52ee0a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/83f0440b2f92227fcce9898118ca7fe7e0d64b1f" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-2m92-hrph-h3f7/GHSA-2m92-hrph-h3f7.json b/advisories/unreviewed/2024/10/GHSA-2m92-hrph-h3f7/GHSA-2m92-hrph-h3f7.json new file mode 100644 index 00000000000..1bfa3b1004b --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-2m92-hrph-h3f7/GHSA-2m92-hrph-h3f7.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2m92-hrph-h3f7", + "modified": "2024-10-21T18:30:57Z", + "published": "2024-10-21T18:30:57Z", + "aliases": [ + "CVE-2024-49909" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Add NULL check for function pointer in dcn32_set_output_transfer_func\n\nThis commit adds a null check for the set_output_gamma function pointer\nin the dcn32_set_output_transfer_func function. Previously,\nset_output_gamma was being checked for null, but then it was being\ndereferenced without any null check. This could lead to a null pointer\ndereference if set_output_gamma is null.\n\nTo fix this, we now ensure that set_output_gamma is not null before\ndereferencing it. We do this by adding a null check for set_output_gamma\nbefore the call to set_output_gamma.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49909" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/28574b08c70e56d34d6f6379326a860b96749051" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/496486950c3d2aebf46a3be300296ac091da7a2d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5298270bdabe97be5b8236e544c9e936415fe1f2" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-3cmg-5p27-qj6j/GHSA-3cmg-5p27-qj6j.json b/advisories/unreviewed/2024/10/GHSA-3cmg-5p27-qj6j/GHSA-3cmg-5p27-qj6j.json new file mode 100644 index 00000000000..db38b0789aa --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-3cmg-5p27-qj6j/GHSA-3cmg-5p27-qj6j.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3cmg-5p27-qj6j", + "modified": "2024-10-21T18:30:59Z", + "published": "2024-10-21T18:30:59Z", + "aliases": [ + "CVE-2024-49986" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86: x86-android-tablets: Fix use after free on platform_device_register() errors\n\nx86_android_tablet_remove() frees the pdevs[] array, so it should not\nbe used after calling x86_android_tablet_remove().\n\nWhen platform_device_register() fails, store the pdevs[x] PTR_ERR() value\ninto the local ret variable before calling x86_android_tablet_remove()\nto avoid using pdevs[] after it has been freed.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49986" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2fae3129c0c08e72b1fe93e61fd8fd203252094a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/73a98cf79e4dbfa3d0c363e826c65aae089b313c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/aac871e493fc8809e60209d9899b1af07e9dbfc8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f08adc5177bd4343df09033f62ab562c09ba7f7d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-3rvw-7pxp-g8xm/GHSA-3rvw-7pxp-g8xm.json b/advisories/unreviewed/2024/10/GHSA-3rvw-7pxp-g8xm/GHSA-3rvw-7pxp-g8xm.json new file mode 100644 index 00000000000..6bbcc6d4471 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-3rvw-7pxp-g8xm/GHSA-3rvw-7pxp-g8xm.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3rvw-7pxp-g8xm", + "modified": "2024-10-21T18:30:58Z", + "published": "2024-10-21T18:30:58Z", + "aliases": [ + "CVE-2024-49924" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: pxafb: Fix possible use after free in pxafb_task()\n\nIn the pxafb_probe function, it calls the pxafb_init_fbinfo function,\nafter which &fbi->task is associated with pxafb_task. Moreover,\nwithin this pxafb_init_fbinfo function, the pxafb_blank function\nwithin the &pxafb_ops struct is capable of scheduling work.\n\nIf we remove the module which will call pxafb_remove to make cleanup,\nit will call unregister_framebuffer function which can call\ndo_unregister_framebuffer to free fbi->fb through\nput_fb_info(fb_info), while the work mentioned above will be used.\nThe sequence of operations that may lead to a UAF bug is as follows:\n\nCPU0 CPU1\n\n | pxafb_task\npxafb_remove |\nunregister_framebuffer(info) |\ndo_unregister_framebuffer(fb_info) |\nput_fb_info(fb_info) |\n// free fbi->fb | set_ctrlr_state(fbi, state)\n | __pxafb_lcd_power(fbi, 0)\n | fbi->lcd_power(on, &fbi->fb.var)\n | //use fbi->fb\n\nFix it by ensuring that the work is canceled before proceeding\nwith the cleanup in pxafb_remove.\n\nNote that only root user can remove the driver at runtime.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49924" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3c0d416eb4bef705f699213cee94bf54b6acdacd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4a6921095eb04a900e0000da83d9475eb958e61e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4cda484e584be34d55ee17436ebf7ad11922b97a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a3a855764dbacbdb1cc51e15dc588f2d21c93e0e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/aaadc0cb05c999ccd8898a03298b7e5c31509b08" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e6897e299f57b103e999e62010b88e363b3eebae" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fdda354f60a576d52dcf90351254714681df4370" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-3xm8-389p-x4rm/GHSA-3xm8-389p-x4rm.json b/advisories/unreviewed/2024/10/GHSA-3xm8-389p-x4rm/GHSA-3xm8-389p-x4rm.json new file mode 100644 index 00000000000..53a67ecc113 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-3xm8-389p-x4rm/GHSA-3xm8-389p-x4rm.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3xm8-389p-x4rm", + "modified": "2024-10-21T18:30:59Z", + "published": "2024-10-21T18:30:59Z", + "aliases": [ + "CVE-2024-49998" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: dsa: improve shutdown sequence\n\nAlexander Sverdlin presents 2 problems during shutdown with the\nlan9303 driver. One is specific to lan9303 and the other just happens\nto reproduce there.\n\nThe first problem is that lan9303 is unique among DSA drivers in that it\ncalls dev_get_drvdata() at \"arbitrary runtime\" (not probe, not shutdown,\nnot remove):\n\nphy_state_machine()\n-> ...\n -> dsa_user_phy_read()\n -> ds->ops->phy_read()\n -> lan9303_phy_read()\n -> chip->ops->phy_read()\n -> lan9303_mdio_phy_read()\n -> dev_get_drvdata()\n\nBut we never stop the phy_state_machine(), so it may continue to run\nafter dsa_switch_shutdown(). Our common pattern in all DSA drivers is\nto set drvdata to NULL to suppress the remove() method that may come\nafterwards. But in this case it will result in an NPD.\n\nThe second problem is that the way in which we set\ndp->conduit->dsa_ptr = NULL; is concurrent with receive packet\nprocessing. dsa_switch_rcv() checks once whether dev->dsa_ptr is NULL,\nbut afterwards, rather than continuing to use that non-NULL value,\ndev->dsa_ptr is dereferenced again and again without NULL checks:\ndsa_conduit_find_user() and many other places. In between dereferences,\nthere is no locking to ensure that what was valid once continues to be\nvalid.\n\nBoth problems have the common aspect that closing the conduit interface\nsolves them.\n\nIn the first case, dev_close(conduit) triggers the NETDEV_GOING_DOWN\nevent in dsa_user_netdevice_event() which closes user ports as well.\ndsa_port_disable_rt() calls phylink_stop(), which synchronously stops\nthe phylink state machine, and ds->ops->phy_read() will thus no longer\ncall into the driver after this point.\n\nIn the second case, dev_close(conduit) should do this, as per\nDocumentation/networking/driver.rst:\n\n| Quiescence\n| ----------\n|\n| After the ndo_stop routine has been called, the hardware must\n| not receive or transmit any data. All in flight packets must\n| be aborted. If necessary, poll or wait for completion of\n| any reset commands.\n\nSo it should be sufficient to ensure that later, when we zeroize\nconduit->dsa_ptr, there will be no concurrent dsa_switch_rcv() call\non this conduit.\n\nThe addition of the netif_device_detach() function is to ensure that\nioctls, rtnetlinks and ethtool requests on the user ports no longer\npropagate down to the driver - we're no longer prepared to handle them.\n\nThe race condition actually did not exist when commit 0650bf52b31f\n(\"net: dsa: be compatible with masters which unregister on shutdown\")\nfirst introduced dsa_switch_shutdown(). It was created later, when we\nstopped unregistering the user interfaces from a bad spot, and we just\nreplaced that sequence with a racy zeroization of conduit->dsa_ptr\n(one which doesn't ensure that the interfaces aren't up).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49998" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6c24a03a61a245fe34d47582898331fa034b6ccd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ab5d3420a1120950703dbdc33698b28a6ebc3d23" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b4a65d479213fe84ecb14e328271251eebe69492" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-44g4-9qvp-9723/GHSA-44g4-9qvp-9723.json b/advisories/unreviewed/2024/10/GHSA-44g4-9qvp-9723/GHSA-44g4-9qvp-9723.json new file mode 100644 index 00000000000..5f822e885ec --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-44g4-9qvp-9723/GHSA-44g4-9qvp-9723.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-44g4-9qvp-9723", + "modified": "2024-10-21T18:30:58Z", + "published": "2024-10-21T18:30:58Z", + "aliases": [ + "CVE-2024-49945" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/ncsi: Disable the ncsi work before freeing the associated structure\n\nThe work function can run after the ncsi device is freed, resulting\nin use-after-free bugs or kernel panic.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49945" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a0ffa68c70b367358b2672cdab6fa5bc4c40de2c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/dd41dab62f32d9e9e0669af8459d12a93834b238" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f6ca58696749268181f43150b3553f2bafd71e42" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-4c63-26fj-6f7h/GHSA-4c63-26fj-6f7h.json b/advisories/unreviewed/2024/10/GHSA-4c63-26fj-6f7h/GHSA-4c63-26fj-6f7h.json new file mode 100644 index 00000000000..91dc6d52087 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-4c63-26fj-6f7h/GHSA-4c63-26fj-6f7h.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4c63-26fj-6f7h", + "modified": "2024-10-21T18:30:58Z", + "published": "2024-10-21T18:30:58Z", + "aliases": [ + "CVE-2024-49961" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: i2c: ar0521: Use cansleep version of gpiod_set_value()\n\nIf we use GPIO reset from I2C port expander, we must use *_cansleep()\nvariant of GPIO functions.\nThis was not done in ar0521_power_on()/ar0521_power_off() functions.\nLet's fix that.\n\n------------[ cut here ]------------\nWARNING: CPU: 0 PID: 11 at drivers/gpio/gpiolib.c:3496 gpiod_set_value+0x74/0x7c\nModules linked in:\nCPU: 0 PID: 11 Comm: kworker/u16:0 Not tainted 6.10.0 #53\nHardware name: Diasom DS-RK3568-SOM-EVB (DT)\nWorkqueue: events_unbound deferred_probe_work_func\npstate: 80400009 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)\npc : gpiod_set_value+0x74/0x7c\nlr : ar0521_power_on+0xcc/0x290\nsp : ffffff8001d7ab70\nx29: ffffff8001d7ab70 x28: ffffff80027dcc90 x27: ffffff8003c82000\nx26: ffffff8003ca9250 x25: ffffffc080a39c60 x24: ffffff8003ca9088\nx23: ffffff8002402720 x22: ffffff8003ca9080 x21: ffffff8003ca9088\nx20: 0000000000000000 x19: ffffff8001eb2a00 x18: ffffff80efeeac80\nx17: 756d2d6332692f30 x16: 0000000000000000 x15: 0000000000000000\nx14: ffffff8001d91d40 x13: 0000000000000016 x12: ffffffc080e98930\nx11: ffffff8001eb2880 x10: 0000000000000890 x9 : ffffff8001d7a9f0\nx8 : ffffff8001d92570 x7 : ffffff80efeeac80 x6 : 000000003fc6e780\nx5 : ffffff8001d91c80 x4 : 0000000000000002 x3 : 0000000000000000\nx2 : 0000000000000000 x1 : 0000000000000000 x0 : 0000000000000001\nCall trace:\n gpiod_set_value+0x74/0x7c\n ar0521_power_on+0xcc/0x290\n...", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49961" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2423b60a2d6d27e5f66c5021b494463aef2db212" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3cf00ecfbf11ee8e6afff306a5bdcff4bf95d2cf" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/625a77b68c96349c16fcc1faa42784313e0b1a85" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9f08876d766755a92f1b9543ae3ee21bfc596fb8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bee1aed819a8cda47927436685d216906ed17f62" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-4f6f-gr2g-x76p/GHSA-4f6f-gr2g-x76p.json b/advisories/unreviewed/2024/10/GHSA-4f6f-gr2g-x76p/GHSA-4f6f-gr2g-x76p.json new file mode 100644 index 00000000000..18551671515 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-4f6f-gr2g-x76p/GHSA-4f6f-gr2g-x76p.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4f6f-gr2g-x76p", + "modified": "2024-10-21T18:30:57Z", + "published": "2024-10-21T18:30:57Z", + "aliases": [ + "CVE-2024-49907" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Check null pointers before using dc->clk_mgr\n\n[WHY & HOW]\ndc->clk_mgr is null checked previously in the same function, indicating\nit might be null.\n\nPassing \"dc\" to \"dc->hwss.apply_idle_power_optimizations\", which\ndereferences null \"dc->clk_mgr\". (The function pointer resolves to\n\"dcn35_apply_idle_power_optimizations\".)\n\nThis fixes 1 FORWARD_NULL issue reported by Coverity.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49907" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3f7e533c10db3d0158709a99e2129ff63add6bcd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5ba3fbf75b243b2863a8be9e7c393e003d3b88f3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8d54001f8dccd56146973f23f3ab2ba037a21251" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/95d9e0803e51d5a24276b7643b244c7477daf463" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9641bc4adf8446034e490ed543ae7e9833cfbdf5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a2773e0a4b79e7a6463abdffaf8cc4f24428ba18" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a545a9403e04c6e17fdc04a26a61d9feebbba106" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-4rgx-hjqw-p9f3/GHSA-4rgx-hjqw-p9f3.json b/advisories/unreviewed/2024/10/GHSA-4rgx-hjqw-p9f3/GHSA-4rgx-hjqw-p9f3.json new file mode 100644 index 00000000000..b0f496e92fc --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-4rgx-hjqw-p9f3/GHSA-4rgx-hjqw-p9f3.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4rgx-hjqw-p9f3", + "modified": "2024-10-21T18:30:57Z", + "published": "2024-10-21T18:30:57Z", + "aliases": [ + "CVE-2024-49890" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/pm: ensure the fw_info is not null before using it\n\nThis resolves the dereference null return value warning\nreported by Coverity.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49890" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/016bf0294b401246471c6710c6bf9251616228b6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/186fb12e7a7b038c2710ceb2fb74068f1b5d55a4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/29f388945770bd0a6c82711436b2bc98b0dfac92" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8adf4408d482faa51b2c14e60bfd9946ec1911a4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9550d8d6f19fac7623f044ae8d9503825b325497" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b511474f49588cdca355ebfce54e7eddbf7b75a5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fd5f4ac1a986f0e7e9fa019201b5890554f87bcf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-4vhm-95hf-qf25/GHSA-4vhm-95hf-qf25.json b/advisories/unreviewed/2024/10/GHSA-4vhm-95hf-qf25/GHSA-4vhm-95hf-qf25.json new file mode 100644 index 00000000000..fb2818c335e --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-4vhm-95hf-qf25/GHSA-4vhm-95hf-qf25.json @@ -0,0 +1,55 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4vhm-95hf-qf25", + "modified": "2024-10-21T18:31:00Z", + "published": "2024-10-21T18:31:00Z", + "aliases": [ + "CVE-2024-50000" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: Fix NULL deref in mlx5e_tir_builder_alloc()\n\nIn mlx5e_tir_builder_alloc() kvzalloc() may return NULL\nwhich is dereferenced on the next line in a reference\nto the modify field.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50000" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0168ab6fbd9e50d20b97486168b604b2ab28a2ca" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1bcc86cc721bea68980098f51f102aa2c2b9d932" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4655456a64a0f936098c8432bac64e7176bd2aff" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4d80dde26d7bab1320210279483ac854dcb274b2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b48ee5bb25c02ca2b81e0d16bf8af17ab6ed3f8b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f25389e779500cf4a59ef9804534237841bce536" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-4wjx-5h7f-wqhw/GHSA-4wjx-5h7f-wqhw.json b/advisories/unreviewed/2024/10/GHSA-4wjx-5h7f-wqhw/GHSA-4wjx-5h7f-wqhw.json new file mode 100644 index 00000000000..734f7c86664 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-4wjx-5h7f-wqhw/GHSA-4wjx-5h7f-wqhw.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4wjx-5h7f-wqhw", + "modified": "2024-10-21T18:30:56Z", + "published": "2024-10-21T18:30:56Z", + "aliases": [ + "CVE-2024-49879" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm: omapdrm: Add missing check for alloc_ordered_workqueue\n\nAs it may return NULL pointer and cause NULL pointer dereference. Add check\nfor the return value of alloc_ordered_workqueue.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49879" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0d71916694aceb207fefecf62dfa811ec1108bbd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2bda89735199683b03f55b807bd1e31a3857520b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/334de68eda2b99892ba869c15cb59bc956fd9f42" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b57b53e8ffcdfda87d954fc4187426a54fe75a3d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e60b0d3b5aa2e8d934deca9e11215af84e632bc9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e794b7b9b92977365c693760a259f8eef940c536" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f37a1d9e5e22d5489309c3cd2db476dcdcc6530c" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-4x74-8q36-fc3h/GHSA-4x74-8q36-fc3h.json b/advisories/unreviewed/2024/10/GHSA-4x74-8q36-fc3h/GHSA-4x74-8q36-fc3h.json new file mode 100644 index 00000000000..644600e5654 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-4x74-8q36-fc3h/GHSA-4x74-8q36-fc3h.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4x74-8q36-fc3h", + "modified": "2024-10-21T18:30:58Z", + "published": "2024-10-21T18:30:58Z", + "aliases": [ + "CVE-2024-49949" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: avoid potential underflow in qdisc_pkt_len_init() with UFO\n\nAfter commit 7c6d2ecbda83 (\"net: be more gentle about silly gso\nrequests coming from user\") virtio_net_hdr_to_skb() had sanity check\nto detect malicious attempts from user space to cook a bad GSO packet.\n\nThen commit cf9acc90c80ec (\"net: virtio_net_hdr_to_skb: count\ntransport header in UFO\") while fixing one issue, allowed user space\nto cook a GSO packet with the following characteristic :\n\nIPv4 SKB_GSO_UDP, gso_size=3, skb->len = 28.\n\nWhen this packet arrives in qdisc_pkt_len_init(), we end up\nwith hdr_len = 28 (IPv4 header + UDP header), matching skb->len\n\nThen the following sets gso_segs to 0 :\n\ngso_segs = DIV_ROUND_UP(skb->len - hdr_len,\n shinfo->gso_size);\n\nThen later we set qdisc_skb_cb(skb)->pkt_len to back to zero :/\n\nqdisc_skb_cb(skb)->pkt_len += (gso_segs - 1) * hdr_len;\n\nThis leads to the following crash in fq_codel [1]\n\nqdisc_pkt_len_init() is best effort, we only want an estimation\nof the bytes sent on the wire, not crashing the kernel.\n\nThis patch is fixing this particular issue, a following one\nadds more sanity checks for another potential bug.\n\n[1]\n[ 70.724101] BUG: kernel NULL pointer dereference, address: 0000000000000000\n[ 70.724561] #PF: supervisor read access in kernel mode\n[ 70.724561] #PF: error_code(0x0000) - not-present page\n[ 70.724561] PGD 10ac61067 P4D 10ac61067 PUD 107ee2067 PMD 0\n[ 70.724561] Oops: Oops: 0000 [#1] SMP NOPTI\n[ 70.724561] CPU: 11 UID: 0 PID: 2163 Comm: b358537762 Not tainted 6.11.0-virtme #991\n[ 70.724561] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014\n[ 70.724561] RIP: 0010:fq_codel_enqueue (net/sched/sch_fq_codel.c:120 net/sched/sch_fq_codel.c:168 net/sched/sch_fq_codel.c:230) sch_fq_codel\n[ 70.724561] Code: 24 08 49 c1 e1 06 44 89 7c 24 18 45 31 ed 45 31 c0 31 ff 89 44 24 14 4c 03 8b 90 01 00 00 eb 04 39 ca 73 37 4d 8b 39 83 c7 01 <49> 8b 17 49 89 11 41 8b 57 28 45 8b 5f 34 49 c7 07 00 00 00 00 49\nAll code\n========\n 0:\t24 08 \tand $0x8,%al\n 2:\t49 c1 e1 06 \tshl $0x6,%r9\n 6:\t44 89 7c 24 18 \tmov %r15d,0x18(%rsp)\n b:\t45 31 ed \txor %r13d,%r13d\n e:\t45 31 c0 \txor %r8d,%r8d\n 11:\t31 ff \txor %edi,%edi\n 13:\t89 44 24 14 \tmov %eax,0x14(%rsp)\n 17:\t4c 03 8b 90 01 00 00 \tadd 0x190(%rbx),%r9\n 1e:\teb 04 \tjmp 0x24\n 20:\t39 ca \tcmp %ecx,%edx\n 22:\t73 37 \tjae 0x5b\n 24:\t4d 8b 39 \tmov (%r9),%r15\n 27:\t83 c7 01 \tadd $0x1,%edi\n 2a:*\t49 8b 17 \tmov (%r15),%rdx\t\t<-- trapping instruction\n 2d:\t49 89 11 \tmov %rdx,(%r9)\n 30:\t41 8b 57 28 \tmov 0x28(%r15),%edx\n 34:\t45 8b 5f 34 \tmov 0x34(%r15),%r11d\n 38:\t49 c7 07 00 00 00 00 \tmovq $0x0,(%r15)\n 3f:\t49 \trex.WB\n\nCode starting with the faulting instruction\n===========================================\n 0:\t49 8b 17 \tmov (%r15),%rdx\n 3:\t49 89 11 \tmov %rdx,(%r9)\n 6:\t41 8b 57 28 \tmov 0x28(%r15),%edx\n a:\t45 8b 5f 34 \tmov 0x34(%r15),%r11d\n e:\t49 c7 07 00 00 00 00 \tmovq $0x0,(%r15)\n 15:\t49 \trex.WB\n[ 70.724561] RSP: 0018:ffff95ae85e6fb90 EFLAGS: 00000202\n[ 70.724561] RAX: 0000000002000000 RBX: ffff95ae841de000 RCX: 0000000000000000\n[ 70.724561] RDX: 0000000000000000 RSI: 0000000000000001 RDI: 0000000000000001\n[ 70.724561] RBP: ffff95ae85e6fbf8 R08: 0000000000000000 R09: ffff95b710a30000\n[ 70.724561] R10: 0000000000000000 R11: bdf289445ce31881 R12: ffff95ae85e6fc58\n[ 70.724561] R13: 0000000000000000 R14: 0000000000000040 R15: 0000000000000000\n[ 70.724561] FS: 000000002c5c1380(0000) GS:ffff95bd7fcc0000(0000) knlGS:0000000000000000\n[ 70.724561] CS: 0010 DS: 0000 ES: 0000 C\n---truncated---", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49949" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/25ab0b87dbd89cecef8a9c60a02bb97832e471d1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/81fd007dcd47c34471766249853e4d4bce8eea4b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/939c88cbdc668dadd8cfa7a35d9066331239041c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ba26060a29d3ca1bfc737aa79f7125128f35147c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c20029db28399ecc50e556964eaba75c43b1e2f1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d6114993e0a89fde84a60a60a8329a571580b174" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f959cce8a2a04ce776aa8b78e83ce339e0d7fbac" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-4xwj-gw53-4w3v/GHSA-4xwj-gw53-4w3v.json b/advisories/unreviewed/2024/10/GHSA-4xwj-gw53-4w3v/GHSA-4xwj-gw53-4w3v.json new file mode 100644 index 00000000000..896b5588683 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-4xwj-gw53-4w3v/GHSA-4xwj-gw53-4w3v.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4xwj-gw53-4w3v", + "modified": "2024-10-21T18:30:59Z", + "published": "2024-10-21T18:30:59Z", + "aliases": [ + "CVE-2024-49974" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nNFSD: Limit the number of concurrent async COPY operations\n\nNothing appears to limit the number of concurrent async COPY\noperations that clients can start. In addition, AFAICT each async\nCOPY can copy an unlimited number of 4MB chunks, so can run for a\nlong time. Thus IMO async COPY can become a DoS vector.\n\nAdd a restriction mechanism that bounds the number of concurrent\nbackground COPY operations. Start simple and try to be fair -- this\npatch implements a per-namespace limit.\n\nAn async COPY request that occurs while this limit is exceeded gets\nNFS4ERR_DELAY. The requesting client can choose to send the request\nagain after a delay or fall back to a traditional read/write style\ncopy.\n\nIf there is need to make the mechanism more sophisticated, we can\nvisit that in future patches.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49974" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6a488ad7745b8f64625c6d3a24ce7e448e83f11b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/aadc3bbea163b6caaaebfdd2b6c4667fbc726752" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b4e21431a0db4854b5023cd5af001be557e6c3db" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-533j-v9v8-3c94/GHSA-533j-v9v8-3c94.json b/advisories/unreviewed/2024/10/GHSA-533j-v9v8-3c94/GHSA-533j-v9v8-3c94.json new file mode 100644 index 00000000000..c1b900fd7ea --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-533j-v9v8-3c94/GHSA-533j-v9v8-3c94.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-533j-v9v8-3c94", + "modified": "2024-10-21T18:30:56Z", + "published": "2024-10-21T18:30:56Z", + "aliases": [ + "CVE-2024-49865" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe/vm: move xa_alloc to prevent UAF\n\nEvil user can guess the next id of the vm before the ioctl completes and\nthen call vm destroy ioctl to trigger UAF since create ioctl is still\nreferencing the same vm. Move the xa_alloc all the way to the end to\nprevent this.\n\nv2:\n - Rebase\n\n(cherry picked from commit dcfd3971327f3ee92765154baebbaece833d3ca9)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49865" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/09cf8901fc0225898311b375cfcc67bae37ed5da" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/74231870cf4976f69e83aa24f48edb16619f652f" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-57xc-4245-hh9c/GHSA-57xc-4245-hh9c.json b/advisories/unreviewed/2024/10/GHSA-57xc-4245-hh9c/GHSA-57xc-4245-hh9c.json new file mode 100644 index 00000000000..bf7ff3e8158 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-57xc-4245-hh9c/GHSA-57xc-4245-hh9c.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-57xc-4245-hh9c", + "modified": "2024-10-21T18:30:56Z", + "published": "2024-10-21T18:30:56Z", + "aliases": [ + "CVE-2024-40746" + ], + "details": "A stored cross-site scripting (XSS) vulnerability in HikaShop Joomla Component < 5.1.1 allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload in the `description` parameter of any product. The `description `parameter is not sanitised in the backend.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40746" + }, + { + "type": "WEB", + "url": "https://www.hikashop.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T17:15:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-5frw-42jx-47v6/GHSA-5frw-42jx-47v6.json b/advisories/unreviewed/2024/10/GHSA-5frw-42jx-47v6/GHSA-5frw-42jx-47v6.json new file mode 100644 index 00000000000..efd472e075c --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-5frw-42jx-47v6/GHSA-5frw-42jx-47v6.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5frw-42jx-47v6", + "modified": "2024-10-21T18:30:59Z", + "published": "2024-10-21T18:30:59Z", + "aliases": [ + "CVE-2024-49981" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: venus: fix use after free bug in venus_remove due to race condition\n\nin venus_probe, core->work is bound with venus_sys_error_handler, which is\nused to handle error. The code use core->sys_err_done to make sync work.\nThe core->work is started in venus_event_notify.\n\nIf we call venus_remove, there might be an unfished work. The possible\nsequence is as follows:\n\nCPU0 CPU1\n\n |venus_sys_error_handler\nvenus_remove |\nhfi_destroy\t \t\t |\nvenus_hfi_destroy\t |\nkfree(hdev);\t |\n |hfi_reinit\n\t\t\t\t\t |venus_hfi_queues_reinit\n |//use hdev\n\nFix it by canceling the work in venus_remove.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49981" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/10941d4f99a5a34999121b314afcd9c0a1c14f15" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2a541fcc0bd2b05a458e9613376df1289ec11621" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/60b6968341a6dd5353554f3e72db554693a128a5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b0686aedc5f1343442d044bd64eeac7e7a391f4e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bf6be32e2d39f6301ff1831e249d32a8744ab28a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c5a85ed88e043474161bbfe54002c89c1cb50ee2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d925e9f7fb5a2dbefd1a73fc01061f38c7becd4c" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-5mqf-fxgc-8r6w/GHSA-5mqf-fxgc-8r6w.json b/advisories/unreviewed/2024/10/GHSA-5mqf-fxgc-8r6w/GHSA-5mqf-fxgc-8r6w.json new file mode 100644 index 00000000000..dbed0a7ab96 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-5mqf-fxgc-8r6w/GHSA-5mqf-fxgc-8r6w.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5mqf-fxgc-8r6w", + "modified": "2024-10-21T18:31:00Z", + "published": "2024-10-21T18:31:00Z", + "aliases": [ + "CVE-2024-49999" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nafs: Fix the setting of the server responding flag\n\nIn afs_wait_for_operation(), we set transcribe the call responded flag to\nthe server record that we used after doing the fileserver iteration loop -\nbut it's possible to exit the loop having had a response from the server\nthat we've discarded (e.g. it returned an abort or we started receiving\ndata, but the call didn't complete).\n\nThis means that op->server might be NULL, but we don't check that before\nattempting to set the server flag.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49999" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3d51ab44123f35dd1d646d99a15ebef10f55e263" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/97c953572d98080c5f1486155350bb688041747a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ff98751bae40faed1ba9c6a7287e84430f7dec64" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-5rwv-chpw-9fvf/GHSA-5rwv-chpw-9fvf.json b/advisories/unreviewed/2024/10/GHSA-5rwv-chpw-9fvf/GHSA-5rwv-chpw-9fvf.json new file mode 100644 index 00000000000..7e42b775ac1 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-5rwv-chpw-9fvf/GHSA-5rwv-chpw-9fvf.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5rwv-chpw-9fvf", + "modified": "2024-10-21T18:30:57Z", + "published": "2024-10-21T18:30:57Z", + "aliases": [ + "CVE-2024-49912" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Handle null 'stream_status' in 'planes_changed_for_existing_stream'\n\nThis commit adds a null check for 'stream_status' in the function\n'planes_changed_for_existing_stream'. Previously, the code assumed\n'stream_status' could be null, but did not handle the case where it was\nactually null. This could lead to a null pointer dereference.\n\nReported by smatch:\ndrivers/gpu/drm/amd/amdgpu/../display/dc/core/dc_resource.c:3784 planes_changed_for_existing_stream() error: we previously assumed 'stream_status' could be null (see line 3774)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49912" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0ffd9fb03bbc99ed1eb5dc989d5c7da2faac0659" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4778982c73d6c9f3fdbdbc6b6c8aa18df98251af" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8141f21b941710ecebe49220b69822cab3abd23d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c4b699b93496c423b0e5b584d4eb4ab849313bcf" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ec6c32b58e6c4e87760e797c525e99a460c82bcb" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-5wgv-v8w4-hvpr/GHSA-5wgv-v8w4-hvpr.json b/advisories/unreviewed/2024/10/GHSA-5wgv-v8w4-hvpr/GHSA-5wgv-v8w4-hvpr.json new file mode 100644 index 00000000000..7975387c2c0 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-5wgv-v8w4-hvpr/GHSA-5wgv-v8w4-hvpr.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5wgv-v8w4-hvpr", + "modified": "2024-10-21T18:30:57Z", + "published": "2024-10-21T18:30:57Z", + "aliases": [ + "CVE-2024-49901" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/msm/adreno: Assign msm_gpu->pdev earlier to avoid nullptrs\n\nThere are some cases, such as the one uncovered by Commit 46d4efcccc68\n(\"drm/msm/a6xx: Avoid a nullptr dereference when speedbin setting fails\")\nwhere\n\nmsm_gpu_cleanup() : platform_set_drvdata(gpu->pdev, NULL);\n\nis called on gpu->pdev == NULL, as the GPU device has not been fully\ninitialized yet.\n\nTurns out that there's more than just the aforementioned path that\ncauses this to happen (e.g. the case when there's speedbin data in the\ncatalog, but opp-supported-hw is missing in DT).\n\nAssigning msm_gpu->pdev earlier seems like the least painful solution\nto this, therefore do so.\n\nPatchwork: https://patchwork.freedesktop.org/patch/602742/", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49901" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/16007768551d5bfe53426645401435ca8d2ef54f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9288a9676c529ad9c856096db68fad812499bc4a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9773737375b20070ea935203fd66cb9fa17c5acb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e8ac2060597a5768e4699bb61d604b4c09927b85" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-64qp-9xf4-2pch/GHSA-64qp-9xf4-2pch.json b/advisories/unreviewed/2024/10/GHSA-64qp-9xf4-2pch/GHSA-64qp-9xf4-2pch.json new file mode 100644 index 00000000000..a21830edb6b --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-64qp-9xf4-2pch/GHSA-64qp-9xf4-2pch.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-64qp-9xf4-2pch", + "modified": "2024-10-21T18:30:58Z", + "published": "2024-10-21T18:30:58Z", + "aliases": [ + "CVE-2024-49937" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: cfg80211: Set correct chandef when starting CAC\n\nWhen starting CAC in a mode other than AP mode, it return a\n\"WARNING: CPU: 0 PID: 63 at cfg80211_chandef_dfs_usable+0x20/0xaf [cfg80211]\"\ncaused by the chandef.chan being null at the end of CAC.\n\nSolution: Ensure the channel definition is set for the different modes\nwhen starting CAC to avoid getting a NULL 'chan' at the end of CAC.\n\n Call Trace:\n ? show_regs.part.0+0x14/0x16\n ? __warn+0x67/0xc0\n ? cfg80211_chandef_dfs_usable+0x20/0xaf [cfg80211]\n ? report_bug+0xa7/0x130\n ? exc_overflow+0x30/0x30\n ? handle_bug+0x27/0x50\n ? exc_invalid_op+0x18/0x60\n ? handle_exception+0xf6/0xf6\n ? exc_overflow+0x30/0x30\n ? cfg80211_chandef_dfs_usable+0x20/0xaf [cfg80211]\n ? exc_overflow+0x30/0x30\n ? cfg80211_chandef_dfs_usable+0x20/0xaf [cfg80211]\n ? regulatory_propagate_dfs_state.cold+0x1b/0x4c [cfg80211]\n ? cfg80211_propagate_cac_done_wk+0x1a/0x30 [cfg80211]\n ? process_one_work+0x165/0x280\n ? worker_thread+0x120/0x3f0\n ? kthread+0xc2/0xf0\n ? process_one_work+0x280/0x280\n ? kthread_complete_and_exit+0x20/0x20\n ? ret_from_fork+0x19/0x24\n\n[shorten subject, remove OCB, reorder cases to match previous list]", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49937" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/04053e55dd50741cf6c59b9bbaa4238218c05c70" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/20361712880396e44ce80aaeec2d93d182035651" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/95f32191e50b75e0f75fae1bb925cdf51d8df0a3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c628026563f4ea9e0413dd4b69429e4a1db240b1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f4dbfda159e43d49b43003cc3c2914751939035f" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-66x6-php2-c8mm/GHSA-66x6-php2-c8mm.json b/advisories/unreviewed/2024/10/GHSA-66x6-php2-c8mm/GHSA-66x6-php2-c8mm.json new file mode 100644 index 00000000000..ce195467de8 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-66x6-php2-c8mm/GHSA-66x6-php2-c8mm.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-66x6-php2-c8mm", + "modified": "2024-10-21T18:30:58Z", + "published": "2024-10-21T18:30:58Z", + "aliases": [ + "CVE-2024-49933" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nblk_iocost: fix more out of bound shifts\n\nRecently running UBSAN caught few out of bound shifts in the\nioc_forgive_debts() function:\n\nUBSAN: shift-out-of-bounds in block/blk-iocost.c:2142:38\nshift exponent 80 is too large for 64-bit type 'u64' (aka 'unsigned long\nlong')\n...\nUBSAN: shift-out-of-bounds in block/blk-iocost.c:2144:30\nshift exponent 80 is too large for 64-bit type 'u64' (aka 'unsigned long\nlong')\n...\nCall Trace:\n\ndump_stack_lvl+0xca/0x130\n__ubsan_handle_shift_out_of_bounds+0x22c/0x280\n? __lock_acquire+0x6441/0x7c10\nioc_timer_fn+0x6cec/0x7750\n? blk_iocost_init+0x720/0x720\n? call_timer_fn+0x5d/0x470\ncall_timer_fn+0xfa/0x470\n? blk_iocost_init+0x720/0x720\n__run_timer_base+0x519/0x700\n...\n\nActual impact of this issue was not identified but I propose to fix the\nundefined behaviour.\nThe proposed fix to prevent those out of bound shifts consist of\nprecalculating exponent before using it the shift operations by taking\nmin value from the actual exponent and maximum possible number of bits.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49933" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1ab2cfe19700fb3dde4c7dfec392acff34db3120" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1b120f151871eb47ce9f283c007af3f8ae1d990e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1f61d509257d6a05763d05bf37943b35306522b1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/364022095bdd4108efdaaa68576afa4712a5d085" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/59121bb38fdc01434ea3fe361ee02b59f036227f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9bce8005ec0dcb23a58300e8522fe4a31da606fa" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f4ef9bef023d5c543cb0f3194ecacfd47ef590ec" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-6g7j-p2cm-w265/GHSA-6g7j-p2cm-w265.json b/advisories/unreviewed/2024/10/GHSA-6g7j-p2cm-w265/GHSA-6g7j-p2cm-w265.json new file mode 100644 index 00000000000..590cb450975 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-6g7j-p2cm-w265/GHSA-6g7j-p2cm-w265.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6g7j-p2cm-w265", + "modified": "2024-10-21T18:30:57Z", + "published": "2024-10-21T18:30:57Z", + "aliases": [ + "CVE-2024-49908" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Add null check for 'afb' in amdgpu_dm_update_cursor (v2)\n\nThis commit adds a null check for the 'afb' variable in the\namdgpu_dm_update_cursor function. Previously, 'afb' was assumed to be\nnull at line 8388, but was used later in the code without a null check.\nThis could potentially lead to a null pointer dereference.\n\nChanges since v1:\n- Moved the null check for 'afb' to the line where 'afb' is used. (Alex)\n\nFixes the below:\ndrivers/gpu/drm/amd/amdgpu/../display/amdgpu_dm/amdgpu_dm.c:8433 amdgpu_dm_update_cursor()\n\terror: we previously assumed 'afb' could be null (see line 8388)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49908" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0fe20258b4989b9112b5e9470df33a0939403fd4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a742168b6a39ead257da53bcbe472384d6e14a1b" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-6ppv-9jp4-gprm/GHSA-6ppv-9jp4-gprm.json b/advisories/unreviewed/2024/10/GHSA-6ppv-9jp4-gprm/GHSA-6ppv-9jp4-gprm.json new file mode 100644 index 00000000000..32bb09396ab --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-6ppv-9jp4-gprm/GHSA-6ppv-9jp4-gprm.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6ppv-9jp4-gprm", + "modified": "2024-10-21T18:30:57Z", + "published": "2024-10-21T18:30:57Z", + "aliases": [ + "CVE-2024-49923" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Pass non-null to dcn20_validate_apply_pipe_split_flags\n\n[WHAT & HOW]\n\"dcn20_validate_apply_pipe_split_flags\" dereferences merge, and thus it\ncannot be a null pointer. Let's pass a valid pointer to avoid null\ndereference.\n\nThis fixes 2 FORWARD_NULL issues reported by Coverity.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49923" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5559598742fb4538e4c51c48ef70563c49c2af23" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/85aa996ecfaa95d1e922867390502d23ce21b905" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9a05270869f40c89f8d184fe2d37cb86e0d7e5f5" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-6pw8-39hw-qcp8/GHSA-6pw8-39hw-qcp8.json b/advisories/unreviewed/2024/10/GHSA-6pw8-39hw-qcp8/GHSA-6pw8-39hw-qcp8.json new file mode 100644 index 00000000000..def43eadb65 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-6pw8-39hw-qcp8/GHSA-6pw8-39hw-qcp8.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6pw8-39hw-qcp8", + "modified": "2024-10-21T18:30:56Z", + "published": "2024-10-21T18:30:56Z", + "aliases": [ + "CVE-2024-49868" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix a NULL pointer dereference when failed to start a new trasacntion\n\n[BUG]\nSyzbot reported a NULL pointer dereference with the following crash:\n\n FAULT_INJECTION: forcing a failure.\n start_transaction+0x830/0x1670 fs/btrfs/transaction.c:676\n prepare_to_relocate+0x31f/0x4c0 fs/btrfs/relocation.c:3642\n relocate_block_group+0x169/0xd20 fs/btrfs/relocation.c:3678\n ...\n BTRFS info (device loop0): balance: ended with status: -12\n Oops: general protection fault, probably for non-canonical address 0xdffffc00000000cc: 0000 [#1] PREEMPT SMP KASAN NOPTI\n KASAN: null-ptr-deref in range [0x0000000000000660-0x0000000000000667]\n RIP: 0010:btrfs_update_reloc_root+0x362/0xa80 fs/btrfs/relocation.c:926\n Call Trace:\n \n commit_fs_roots+0x2ee/0x720 fs/btrfs/transaction.c:1496\n btrfs_commit_transaction+0xfaf/0x3740 fs/btrfs/transaction.c:2430\n del_balance_item fs/btrfs/volumes.c:3678 [inline]\n reset_balance_state+0x25e/0x3c0 fs/btrfs/volumes.c:3742\n btrfs_balance+0xead/0x10c0 fs/btrfs/volumes.c:4574\n btrfs_ioctl_balance+0x493/0x7c0 fs/btrfs/ioctl.c:3673\n vfs_ioctl fs/ioctl.c:51 [inline]\n __do_sys_ioctl fs/ioctl.c:907 [inline]\n __se_sys_ioctl+0xf9/0x170 fs/ioctl.c:893\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\n[CAUSE]\nThe allocation failure happens at the start_transaction() inside\nprepare_to_relocate(), and during the error handling we call\nunset_reloc_control(), which makes fs_info->balance_ctl to be NULL.\n\nThen we continue the error path cleanup in btrfs_balance() by calling\nreset_balance_state() which will call del_balance_item() to fully delete\nthe balance item in the root tree.\n\nHowever during the small window between set_reloc_contrl() and\nunset_reloc_control(), we can have a subvolume tree update and created a\nreloc_root for that subvolume.\n\nThen we go into the final btrfs_commit_transaction() of\ndel_balance_item(), and into btrfs_update_reloc_root() inside\ncommit_fs_roots().\n\nThat function checks if fs_info->reloc_ctl is in the merge_reloc_tree\nstage, but since fs_info->reloc_ctl is NULL, it results a NULL pointer\ndereference.\n\n[FIX]\nJust add extra check on fs_info->reloc_ctl inside\nbtrfs_update_reloc_root(), before checking\nfs_info->reloc_ctl->merge_reloc_tree.\n\nThat DEAD_RELOC_TREE handling is to prevent further modification to the\nreloc tree during merge stage, but since there is no reloc_ctl at all,\nwe do not need to bother that.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49868" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/37fee9c220b92c3b7bf22b51c51dde5364e7590b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/39356ec0e319ed07627b3a0f402d0608546509e6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7ad0c5868f2f0418619089513d95230c66cb7eb4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c3b47f49e83197e8dffd023ec568403bcdbb774b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d13249c0df7aab885acb149695f82c54c0822a70" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d73d48acf36f57362df7e4f9d76568168bf5e944" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/dc02c1440705e3451abd1c2c8114a5c1bb188e9f" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-74qf-4594-qx2m/GHSA-74qf-4594-qx2m.json b/advisories/unreviewed/2024/10/GHSA-74qf-4594-qx2m/GHSA-74qf-4594-qx2m.json new file mode 100644 index 00000000000..f75318d3e32 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-74qf-4594-qx2m/GHSA-74qf-4594-qx2m.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-74qf-4594-qx2m", + "modified": "2024-10-21T18:30:58Z", + "published": "2024-10-21T18:30:58Z", + "aliases": [ + "CVE-2024-49929" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: iwlwifi: mvm: avoid NULL pointer dereference\n\niwl_mvm_tx_skb_sta() and iwl_mvm_tx_mpdu() verify that the mvmvsta\npointer is not NULL.\nIt retrieves this pointer using iwl_mvm_sta_from_mac80211, which is\ndereferencing the ieee80211_sta pointer.\nIf sta is NULL, iwl_mvm_sta_from_mac80211 will dereference a NULL\npointer.\nFix this by checking the sta pointer before retrieving the mvmsta\nfrom it. If sta is not NULL, then mvmsta isn't either.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49929" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/557a6cd847645e667f3b362560bd7e7c09aac284" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6dcadb2ed3b76623ab96e3e7fbeda1a374d01c28" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c0b4f5d94934c290479180868a32c15ba36a6d9e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cdbf51bfa4b0411820806777da36d93d49bc49a1" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-74w9-c64j-qmcw/GHSA-74w9-c64j-qmcw.json b/advisories/unreviewed/2024/10/GHSA-74w9-c64j-qmcw/GHSA-74w9-c64j-qmcw.json new file mode 100644 index 00000000000..ad1ca858e25 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-74w9-c64j-qmcw/GHSA-74w9-c64j-qmcw.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-74w9-c64j-qmcw", + "modified": "2024-10-21T18:30:57Z", + "published": "2024-10-21T18:30:57Z", + "aliases": [ + "CVE-2024-49893" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Check stream_status before it is used\n\n[WHAT & HOW]\ndc_state_get_stream_status can return null, and therefore null must be\nchecked before stream_status is used.\n\nThis fixes 1 NULL_RETURNS issue reported by Coverity.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49893" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4914c8bfee1843fae046a12970b6f178e6642659" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/58a8ee96f84d2c21abb85ad8c22d2bbdf59bd7a9" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-7797-cc95-p257/GHSA-7797-cc95-p257.json b/advisories/unreviewed/2024/10/GHSA-7797-cc95-p257/GHSA-7797-cc95-p257.json new file mode 100644 index 00000000000..1cb0f0aca2b --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-7797-cc95-p257/GHSA-7797-cc95-p257.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7797-cc95-p257", + "modified": "2024-10-21T18:30:57Z", + "published": "2024-10-21T18:30:57Z", + "aliases": [ + "CVE-2024-49917" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Add NULL check for clk_mgr and clk_mgr->funcs in dcn30_init_hw\n\nThis commit addresses a potential null pointer dereference issue in the\n`dcn30_init_hw` function. The issue could occur when `dc->clk_mgr` or\n`dc->clk_mgr->funcs` is null.\n\nThe fix adds a check to ensure `dc->clk_mgr` and `dc->clk_mgr->funcs` is\nnot null before accessing its functions. This prevents a potential null\npointer dereference.\n\nReported by smatch:\ndrivers/gpu/drm/amd/amdgpu/../display/dc/hwss/dcn30/dcn30_hwseq.c:789 dcn30_init_hw() error: we previously assumed 'dc->clk_mgr' could be null (see line 628)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49917" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5443c83eb8fd2f88c71ced38848fbf744d6206a2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/56c326577971adc3a230f29dfd3aa3abdd505f5d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cba7fec864172dadd953daefdd26e01742b71a6a" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-7f96-m827-q2r2/GHSA-7f96-m827-q2r2.json b/advisories/unreviewed/2024/10/GHSA-7f96-m827-q2r2/GHSA-7f96-m827-q2r2.json new file mode 100644 index 00000000000..139114d0e31 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-7f96-m827-q2r2/GHSA-7f96-m827-q2r2.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7f96-m827-q2r2", + "modified": "2024-10-21T18:30:57Z", + "published": "2024-10-21T18:30:57Z", + "aliases": [ + "CVE-2024-49911" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Add NULL check for function pointer in dcn20_set_output_transfer_func\n\nThis commit adds a null check for the set_output_gamma function pointer\nin the dcn20_set_output_transfer_func function. Previously,\nset_output_gamma was being checked for null at line 1030, but then it\nwas being dereferenced without any null check at line 1048. This could\npotentially lead to a null pointer dereference error if set_output_gamma\nis null.\n\nTo fix this, we now ensure that set_output_gamma is not null before\ndereferencing it. We do this by adding a null check for set_output_gamma\nbefore the call to set_output_gamma at line 1048.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49911" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/02411e9359297512946705b1cd8cf5e6b0806fa0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/62ed6f0f198da04e884062264df308277628004f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/827380b114f83c30b3e56d1a675980b6d65f7c88" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-7jfp-wvrj-m47g/GHSA-7jfp-wvrj-m47g.json b/advisories/unreviewed/2024/10/GHSA-7jfp-wvrj-m47g/GHSA-7jfp-wvrj-m47g.json new file mode 100644 index 00000000000..a402f263f95 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-7jfp-wvrj-m47g/GHSA-7jfp-wvrj-m47g.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7jfp-wvrj-m47g", + "modified": "2024-10-21T18:30:56Z", + "published": "2024-10-21T18:30:56Z", + "aliases": [ + "CVE-2024-49877" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: fix possible null-ptr-deref in ocfs2_set_buffer_uptodate\n\nWhen doing cleanup, if flags without OCFS2_BH_READAHEAD, it may trigger\nNULL pointer dereference in the following ocfs2_set_buffer_uptodate() if\nbh is NULL.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49877" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/01cb2e751cc61ade454c9bc1aaa2eac1f8197112" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/33b525cef4cff49e216e4133cc48452e11c0391e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/46b1edf0536a5291a8ad2337f88c926214b209d9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4846e72ab5a0726e49ad4188b9d9df091ae78c64" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/61b84013e560382cbe7dd56758be3154d43a3988" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d52c5652e7dcb7a0648bbb8642cc3e617070ab49" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/df944dc46d06af65a75191183d52be017e6b9dbe" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-7pj6-rq69-3m65/GHSA-7pj6-rq69-3m65.json b/advisories/unreviewed/2024/10/GHSA-7pj6-rq69-3m65/GHSA-7pj6-rq69-3m65.json new file mode 100644 index 00000000000..734bcb3a81c --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-7pj6-rq69-3m65/GHSA-7pj6-rq69-3m65.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7pj6-rq69-3m65", + "modified": "2024-10-21T18:30:58Z", + "published": "2024-10-21T18:30:58Z", + "aliases": [ + "CVE-2024-49957" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: fix null-ptr-deref when journal load failed.\n\nDuring the mounting process, if journal_reset() fails because of too short\njournal, then lead to jbd2_journal_load() fails with NULL j_sb_buffer. \nSubsequently, ocfs2_journal_shutdown() calls\njbd2_journal_flush()->jbd2_cleanup_journal_tail()->\n__jbd2_update_log_tail()->jbd2_journal_update_sb_log_tail()\n->lock_buffer(journal->j_sb_buffer), resulting in a null-pointer\ndereference error.\n\nTo resolve this issue, we should check the JBD2_LOADED flag to ensure the\njournal was properly loaded. Additionally, use journal instead of\nosb->journal directly to simplify the code.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49957" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/387bf565cc03e2e8c720b8b4798efea4aacb6962" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5784d9fcfd43bd853654bb80c87ef293b9e8e80a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/82dfdd1e31e774578f76ce6dc90c834f96403a0f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/86a89e75e9e4dfa768b97db466ad6bedf2e7ea5b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bf605ae98dab5c15c5b631d4d7f88898cb41b649" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f60e94a83db799bde625ac8671a5b4a6354e7120" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ff55291fb36779819211b596da703389135f5b05" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-858g-q943-3jmm/GHSA-858g-q943-3jmm.json b/advisories/unreviewed/2024/10/GHSA-858g-q943-3jmm/GHSA-858g-q943-3jmm.json new file mode 100644 index 00000000000..34913d75910 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-858g-q943-3jmm/GHSA-858g-q943-3jmm.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-858g-q943-3jmm", + "modified": "2024-10-21T18:30:58Z", + "published": "2024-10-21T18:30:57Z", + "aliases": [ + "CVE-2024-49920" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Check null pointers before multiple uses\n\n[WHAT & HOW]\nPoniters, such as stream_enc and dc->bw_vbios, are null checked previously\nin the same function, so Coverity warns \"implies that stream_enc and\ndc->bw_vbios might be null\". They are used multiple times in the\nsubsequent code and need to be checked.\n\nThis fixes 10 FORWARD_NULL issues reported by Coverity.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49920" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/26787fb6c2b2ee0d1a7e1574b36f4711ae40fe27" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fdd5ecbbff751c3b9061d8ebb08e5c96119915b4" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-88g6-52pm-gr2w/GHSA-88g6-52pm-gr2w.json b/advisories/unreviewed/2024/10/GHSA-88g6-52pm-gr2w/GHSA-88g6-52pm-gr2w.json new file mode 100644 index 00000000000..392d96855a3 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-88g6-52pm-gr2w/GHSA-88g6-52pm-gr2w.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-88g6-52pm-gr2w", + "modified": "2024-10-21T18:30:57Z", + "published": "2024-10-21T18:30:57Z", + "aliases": [ + "CVE-2024-49905" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Add null check for 'afb' in amdgpu_dm_plane_handle_cursor_update (v2)\n\nThis commit adds a null check for the 'afb' variable in the\namdgpu_dm_plane_handle_cursor_update function. Previously, 'afb' was\nassumed to be null, but was used later in the code without a null check.\nThis could potentially lead to a null pointer dereference.\n\nChanges since v1:\n- Moved the null check for 'afb' to the line where 'afb' is used. (Alex)\n\nFixes the below:\ndrivers/gpu/drm/amd/amdgpu/../display/amdgpu_dm/amdgpu_dm_plane.c:1298 amdgpu_dm_plane_handle_cursor_update() error: we previously assumed 'afb' could be null (see line 1252)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49905" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/75839e2365b666ff4e1b9047e442cab138eac4f6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9132882eaae4d21d2fc5843b3308379a481ebdf0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bd0e24e5e608ccb9fdda300bb974496d6d8cf57d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cd9e9e0852d501f169aa3bb34e4b413d2eb48c37" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e4e26cbe34d7c1c1db5fb7b3101573c29866439f" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-8cpm-hmp4-fcm6/GHSA-8cpm-hmp4-fcm6.json b/advisories/unreviewed/2024/10/GHSA-8cpm-hmp4-fcm6/GHSA-8cpm-hmp4-fcm6.json new file mode 100644 index 00000000000..25bb25927f6 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-8cpm-hmp4-fcm6/GHSA-8cpm-hmp4-fcm6.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8cpm-hmp4-fcm6", + "modified": "2024-10-21T18:30:59Z", + "published": "2024-10-21T18:30:59Z", + "aliases": [ + "CVE-2024-49977" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: stmmac: Fix zero-division error when disabling tc cbs\n\nThe commit b8c43360f6e4 (\"net: stmmac: No need to calculate speed divider\nwhen offload is disabled\") allows the \"port_transmit_rate_kbps\" to be\nset to a value of 0, which is then passed to the \"div_s64\" function when\ntc-cbs is disabled. This leads to a zero-division error.\n\nWhen tc-cbs is disabled, the idleslope, sendslope, and credit values the\ncredit values are not required to be configured. Therefore, adding a return\nstatement after setting the txQ mode to DCB when tc-cbs is disabled would\nprevent a zero-division error.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49977" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/03582f4752427f60817d896f1a827aff772bd31e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5d43e1ad4567d67af2b42d3ab7c14152ffed25c6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/675faf5a14c14a2be0b870db30a70764df81e2df" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/837d9df9c0792902710149d1a5e0991520af0f93" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b0da9504a528f05f97d926b4db74ff21917a33e9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e297a2bf56d12fd7f91a0c209eb6ea84361f3368" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e33fe25b1efe4f2e6a5858786dbc82ae4c44ed4c" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-8h6q-7wvm-5w36/GHSA-8h6q-7wvm-5w36.json b/advisories/unreviewed/2024/10/GHSA-8h6q-7wvm-5w36/GHSA-8h6q-7wvm-5w36.json new file mode 100644 index 00000000000..13a2158b7db --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-8h6q-7wvm-5w36/GHSA-8h6q-7wvm-5w36.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8h6q-7wvm-5w36", + "modified": "2024-10-21T18:30:58Z", + "published": "2024-10-21T18:30:58Z", + "aliases": [ + "CVE-2024-49955" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nACPI: battery: Fix possible crash when unregistering a battery hook\n\nWhen a battery hook returns an error when adding a new battery, then\nthe battery hook is automatically unregistered.\nHowever the battery hook provider cannot know that, so it will later\ncall battery_hook_unregister() on the already unregistered battery\nhook, resulting in a crash.\n\nFix this by using the list head to mark already unregistered battery\nhooks as already being unregistered so that they can be ignored by\nbattery_hook_unregister().", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49955" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/07b98400cb0285a6348188aa8c5ec6a2ae0551f7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/76959aff14a0012ad6b984ec7686d163deccdc16" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9f469ef1c79dac7f9ac1518643a33703918f7e13" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ca1fb7942a287b40659cc79551a1de54a2c2e7d5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ca26e8eed9c1c6651f51f7fa38fe444f8573cd1b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ce31847f109c3a5b2abdd19d7bcaafaacfde53de" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/da964de4c18199e14b961b5b2e5e6570552a313c" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-8j66-8f4j-h263/GHSA-8j66-8f4j-h263.json b/advisories/unreviewed/2024/10/GHSA-8j66-8f4j-h263/GHSA-8j66-8f4j-h263.json new file mode 100644 index 00000000000..6d295ca29d7 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-8j66-8f4j-h263/GHSA-8j66-8f4j-h263.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8j66-8f4j-h263", + "modified": "2024-10-21T18:30:59Z", + "published": "2024-10-21T18:30:59Z", + "aliases": [ + "CVE-2024-49976" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntracing/timerlat: Drop interface_lock in stop_kthread()\n\nstop_kthread() is the offline callback for \"trace/osnoise:online\", since\ncommit 5bfbcd1ee57b (\"tracing/timerlat: Add interface_lock around clearing\nof kthread in stop_kthread()\"), the following ABBA deadlock scenario is\nintroduced:\n\nT1 | T2 [BP] | T3 [AP]\nosnoise_hotplug_workfn() | work_for_cpu_fn() | cpuhp_thread_fun()\n | _cpu_down() | osnoise_cpu_die()\n mutex_lock(&interface_lock) | | stop_kthread()\n | cpus_write_lock() | mutex_lock(&interface_lock)\n cpus_read_lock() | cpuhp_kick_ap() |\n\nAs the interface_lock here in just for protecting the \"kthread\" field of\nthe osn_var, use xchg() instead to fix this issue. Also use\nfor_each_online_cpu() back in stop_per_cpu_kthreads() as it can take\ncpu_read_lock() again.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49976" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/09cb44cc3d3df7ade2cebc939d6257a2fa8afc7a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a4a05ceffe8fad68b45de38fe2311bda619e76e2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b484a02c9cedf8703eff8f0756f94618004bd165" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/db8571a9a098086608c11a15856ff585789e67e8" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-8qrg-fxff-9fcm/GHSA-8qrg-fxff-9fcm.json b/advisories/unreviewed/2024/10/GHSA-8qrg-fxff-9fcm/GHSA-8qrg-fxff-9fcm.json new file mode 100644 index 00000000000..9f5e139a2dd --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-8qrg-fxff-9fcm/GHSA-8qrg-fxff-9fcm.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8qrg-fxff-9fcm", + "modified": "2024-10-21T18:30:58Z", + "published": "2024-10-21T18:30:58Z", + "aliases": [ + "CVE-2024-49953" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: Fix crash caused by calling __xfrm_state_delete() twice\n\nThe km.state is not checked in driver's delayed work. When\nxfrm_state_check_expire() is called, the state can be reset to\nXFRM_STATE_EXPIRED, even if it is XFRM_STATE_DEAD already. This\nhappens when xfrm state is deleted, but not freed yet. As\n__xfrm_state_delete() is called again in xfrm timer, the following\ncrash occurs.\n\nTo fix this issue, skip xfrm_state_check_expire() if km.state is not\nXFRM_STATE_VALID.\n\n Oops: general protection fault, probably for non-canonical address 0xdead000000000108: 0000 [#1] SMP\n CPU: 5 UID: 0 PID: 7448 Comm: kworker/u102:2 Not tainted 6.11.0-rc2+ #1\n Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014\n Workqueue: mlx5e_ipsec: eth%d mlx5e_ipsec_handle_sw_limits [mlx5_core]\n RIP: 0010:__xfrm_state_delete+0x3d/0x1b0\n Code: 0f 84 8b 01 00 00 48 89 fd c6 87 c8 00 00 00 05 48 8d bb 40 10 00 00 e8 11 04 1a 00 48 8b 95 b8 00 00 00 48 8b 85 c0 00 00 00 <48> 89 42 08 48 89 10 48 8b 55 10 48 b8 00 01 00 00 00 00 ad de 48\n RSP: 0018:ffff88885f945ec8 EFLAGS: 00010246\n RAX: dead000000000122 RBX: ffffffff82afa940 RCX: 0000000000000036\n RDX: dead000000000100 RSI: 0000000000000000 RDI: ffffffff82afb980\n RBP: ffff888109a20340 R08: ffff88885f945ea0 R09: 0000000000000000\n R10: 0000000000000000 R11: ffff88885f945ff8 R12: 0000000000000246\n R13: ffff888109a20340 R14: ffff88885f95f420 R15: ffff88885f95f400\n FS: 0000000000000000(0000) GS:ffff88885f940000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 00007f2163102430 CR3: 00000001128d6001 CR4: 0000000000370eb0\n DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n Call Trace:\n \n ? die_addr+0x33/0x90\n ? exc_general_protection+0x1a2/0x390\n ? asm_exc_general_protection+0x22/0x30\n ? __xfrm_state_delete+0x3d/0x1b0\n ? __xfrm_state_delete+0x2f/0x1b0\n xfrm_timer_handler+0x174/0x350\n ? __xfrm_state_delete+0x1b0/0x1b0\n __hrtimer_run_queues+0x121/0x270\n hrtimer_run_softirq+0x88/0xd0\n handle_softirqs+0xcc/0x270\n do_softirq+0x3c/0x50\n \n \n __local_bh_enable_ip+0x47/0x50\n mlx5e_ipsec_handle_sw_limits+0x7d/0x90 [mlx5_core]\n process_one_work+0x137/0x2d0\n worker_thread+0x28d/0x3a0\n ? rescuer_thread+0x480/0x480\n kthread+0xb8/0xe0\n ? kthread_park+0x80/0x80\n ret_from_fork+0x2d/0x50\n ? kthread_park+0x80/0x80\n ret_from_fork_asm+0x11/0x20\n ", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49953" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0b1672834634df9ac9cedf856db9fc36d92c50ef" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/151e7dead1f5399a73c19c4b50307ea48aff1dc0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7b124695db40d5c9c5295a94ae928a8d67a01c3d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fab615ac9fcb8589222303099975d464d8857527" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-8r4r-8c3p-6r95/GHSA-8r4r-8c3p-6r95.json b/advisories/unreviewed/2024/10/GHSA-8r4r-8c3p-6r95/GHSA-8r4r-8c3p-6r95.json new file mode 100644 index 00000000000..ec5c5377671 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-8r4r-8c3p-6r95/GHSA-8r4r-8c3p-6r95.json @@ -0,0 +1,55 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8r4r-8c3p-6r95", + "modified": "2024-10-21T18:30:56Z", + "published": "2024-10-21T18:30:56Z", + "aliases": [ + "CVE-2024-49866" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntracing/timerlat: Fix a race during cpuhp processing\n\nThere is another found exception that the \"timerlat/1\" thread was\nscheduled on CPU0, and lead to timer corruption finally:\n\n```\nODEBUG: init active (active state 0) object: ffff888237c2e108 object type: hrtimer hint: timerlat_irq+0x0/0x220\nWARNING: CPU: 0 PID: 426 at lib/debugobjects.c:518 debug_print_object+0x7d/0xb0\nModules linked in:\nCPU: 0 UID: 0 PID: 426 Comm: timerlat/1 Not tainted 6.11.0-rc7+ #45\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.13.0-1ubuntu1.1 04/01/2014\nRIP: 0010:debug_print_object+0x7d/0xb0\n...\nCall Trace:\n \n ? __warn+0x7c/0x110\n ? debug_print_object+0x7d/0xb0\n ? report_bug+0xf1/0x1d0\n ? prb_read_valid+0x17/0x20\n ? handle_bug+0x3f/0x70\n ? exc_invalid_op+0x13/0x60\n ? asm_exc_invalid_op+0x16/0x20\n ? debug_print_object+0x7d/0xb0\n ? debug_print_object+0x7d/0xb0\n ? __pfx_timerlat_irq+0x10/0x10\n __debug_object_init+0x110/0x150\n hrtimer_init+0x1d/0x60\n timerlat_main+0xab/0x2d0\n ? __pfx_timerlat_main+0x10/0x10\n kthread+0xb7/0xe0\n ? __pfx_kthread+0x10/0x10\n ret_from_fork+0x2d/0x40\n ? __pfx_kthread+0x10/0x10\n ret_from_fork_asm+0x1a/0x30\n \n```\n\nAfter tracing the scheduling event, it was discovered that the migration\nof the \"timerlat/1\" thread was performed during thread creation. Further\nanalysis confirmed that it is because the CPU online processing for\nosnoise is implemented through workers, which is asynchronous with the\noffline processing. When the worker was scheduled to create a thread, the\nCPU may has already been removed from the cpu_online_mask during the offline\nprocess, resulting in the inability to select the right CPU:\n\nT1 | T2\n[CPUHP_ONLINE] | cpu_device_down()\nosnoise_hotplug_workfn() |\n | cpus_write_lock()\n | takedown_cpu(1)\n | cpus_write_unlock()\n[CPUHP_OFFLINE] |\n cpus_read_lock() |\n start_kthread(1) |\n cpus_read_unlock() |\n\nTo fix this, skip online processing if the CPU is already offline.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49866" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/322920b53dc11f9c2b33397eb3ae5bc6a175b60d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/829e0c9f0855f26b3ae830d17b24aec103f7e915" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a0d9c0cd5856191e095cf43a2e141b73945b7716" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a6e9849063a6c8f4cb2f652a437e44e3ed24356c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ce25f33ba89d6eefef64157655d318444580fa14" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f72b451dc75578f644a3019c1489e9ae2c14e6c4" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-8r8w-7pvp-9gqf/GHSA-8r8w-7pvp-9gqf.json b/advisories/unreviewed/2024/10/GHSA-8r8w-7pvp-9gqf/GHSA-8r8w-7pvp-9gqf.json new file mode 100644 index 00000000000..23745dcc45d --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-8r8w-7pvp-9gqf/GHSA-8r8w-7pvp-9gqf.json @@ -0,0 +1,55 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8r8w-7pvp-9gqf", + "modified": "2024-10-21T18:30:58Z", + "published": "2024-10-21T18:30:58Z", + "aliases": [ + "CVE-2024-49927" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/ioapic: Handle allocation failures gracefully\n\nBreno observed panics when using failslab under certain conditions during\nruntime:\n\n can not alloc irq_pin_list (-1,0,20)\n Kernel panic - not syncing: IO-APIC: failed to add irq-pin. Can not proceed\n\n panic+0x4e9/0x590\n mp_irqdomain_alloc+0x9ab/0xa80\n irq_domain_alloc_irqs_locked+0x25d/0x8d0\n __irq_domain_alloc_irqs+0x80/0x110\n mp_map_pin_to_irq+0x645/0x890\n acpi_register_gsi_ioapic+0xe6/0x150\n hpet_open+0x313/0x480\n\nThat's a pointless panic which is a leftover of the historic IO/APIC code\nwhich panic'ed during early boot when the interrupt allocation failed.\n\nThe only place which might justify panic is the PIT/HPET timer_check() code\nwhich tries to figure out whether the timer interrupt is delivered through\nthe IO/APIC. But that code does not require to handle interrupt allocation\nfailures. If the interrupt cannot be allocated then timer delivery fails\nand it either panics due to that or falls back to legacy mode.\n\nCure this by removing the panic wrapper around __add_pin_to_irq_node() and\nmaking mp_irqdomain_alloc() aware of the failure condition and handle it as\nany other failure in this function gracefully.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49927" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/077e1b7cd521163ded545987bbbd389519aeed71" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/649a5c2ffae797ce792023a70e84c7fe4b6fb8e0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/830802a0fea8fb39d3dc9fb7d6b5581e1343eb1f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e479cb835feeb2abff97f25766e23b96a6eabe28" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ec862cd843faa6f0e84a7a07362f2786446bf697" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f17efbeb2922327ea01a9efa8829fea9a30e547d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-8w32-7xxp-mvxc/GHSA-8w32-7xxp-mvxc.json b/advisories/unreviewed/2024/10/GHSA-8w32-7xxp-mvxc/GHSA-8w32-7xxp-mvxc.json new file mode 100644 index 00000000000..d535963bb9e --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-8w32-7xxp-mvxc/GHSA-8w32-7xxp-mvxc.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8w32-7xxp-mvxc", + "modified": "2024-10-21T18:30:58Z", + "published": "2024-10-21T18:30:58Z", + "aliases": [ + "CVE-2024-49928" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: rtw89: avoid reading out of bounds when loading TX power FW elements\n\nBecause the loop-expression will do one more time before getting false from\ncond-expression, the original code copied one more entry size beyond valid\nregion.\n\nFix it by moving the entry copy to loop-body.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49928" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4007c3d2da31d0c755ea3fcf55e395118e5d5621" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/83c84cdb75572048b67d6a3916283aeac865996e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ed2e4bb17a4884cf29c3347353d8aabb7265b46c" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-9354-rmch-rmj8/GHSA-9354-rmch-rmj8.json b/advisories/unreviewed/2024/10/GHSA-9354-rmch-rmj8/GHSA-9354-rmch-rmj8.json new file mode 100644 index 00000000000..1350d76fe99 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-9354-rmch-rmj8/GHSA-9354-rmch-rmj8.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9354-rmch-rmj8", + "modified": "2024-10-21T18:30:58Z", + "published": "2024-10-21T18:30:58Z", + "aliases": [ + "CVE-2024-49930" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath11k: fix array out-of-bound access in SoC stats\n\nCurrently, the ath11k_soc_dp_stats::hal_reo_error array is defined with a\nmaximum size of DP_REO_DST_RING_MAX. However, the ath11k_dp_process_rx()\nfunction access ath11k_soc_dp_stats::hal_reo_error using the REO\ndestination SRNG ring ID, which is incorrect. SRNG ring ID differ from\nnormal ring ID, and this usage leads to out-of-bounds array access. To fix\nthis issue, modify ath11k_dp_process_rx() to use the normal ring ID\ndirectly instead of the SRNG ring ID to avoid out-of-bounds array access.\n\nTested-on: QCN9074 hw1.0 PCI WLAN.HK.2.7.0.1-01744-QCAHKSWPL_SILICONZ-1", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49930" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/01b77f5ee11c89754fb836af8f76799d3b72ae2f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0f26f26944035ec67546a944f182cbad6577a9c0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4dd732893bd38cec51f887244314e2b47f0d658f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6045ef5b4b00fee3629689f791992900a1c94009" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/69f253e46af98af17e3efa3e5dfa72fcb7d1983d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/73e235728e515faccc104b0153b47d0f263b3344" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7a552bc2f3efe2aaf77a85cb34cdf4a63d81a1a7" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-94p2-m4qf-5m97/GHSA-94p2-m4qf-5m97.json b/advisories/unreviewed/2024/10/GHSA-94p2-m4qf-5m97/GHSA-94p2-m4qf-5m97.json new file mode 100644 index 00000000000..c450f8ad4fa --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-94p2-m4qf-5m97/GHSA-94p2-m4qf-5m97.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-94p2-m4qf-5m97", + "modified": "2024-10-21T18:30:59Z", + "published": "2024-10-21T18:30:59Z", + "aliases": [ + "CVE-2024-49988" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: add refcnt to ksmbd_conn struct\n\nWhen sending an oplock break request, opinfo->conn is used,\nBut freed ->conn can be used on multichannel.\nThis patch add a reference count to the ksmbd_conn struct\nso that it can be freed when it is no longer used.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49988" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/18f06bacc197d4ac9b518ad1c69999bc3d83e7aa" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9fd3cde4628bcd3549ab95061f2bab74d2ed4f3b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e9dac92f4482a382e8c0fe1bc243da5fc3526b0c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ee426bfb9d09b29987369b897fe9b6485ac2be27" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-9gj6-xqgx-pv89/GHSA-9gj6-xqgx-pv89.json b/advisories/unreviewed/2024/10/GHSA-9gj6-xqgx-pv89/GHSA-9gj6-xqgx-pv89.json new file mode 100644 index 00000000000..fa1cb8c7b30 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-9gj6-xqgx-pv89/GHSA-9gj6-xqgx-pv89.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9gj6-xqgx-pv89", + "modified": "2024-10-21T18:30:58Z", + "published": "2024-10-21T18:30:58Z", + "aliases": [ + "CVE-2024-49942" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe: Prevent null pointer access in xe_migrate_copy\n\nxe_migrate_copy designed to copy content of TTM resources. When source\nresource is null, it will trigger a NULL pointer dereference in\nxe_migrate_copy. To avoid this situation, update lacks source flag to\ntrue for this case, the flag will trigger xe_migrate_clear rather than\nxe_migrate_copy.\n\nIssue trace:\n<7> [317.089847] xe 0000:00:02.0: [drm:xe_migrate_copy [xe]] Pass 14,\n sizes: 4194304 & 4194304\n<7> [317.089945] xe 0000:00:02.0: [drm:xe_migrate_copy [xe]] Pass 15,\n sizes: 4194304 & 4194304\n<1> [317.128055] BUG: kernel NULL pointer dereference, address:\n 0000000000000010\n<1> [317.128064] #PF: supervisor read access in kernel mode\n<1> [317.128066] #PF: error_code(0x0000) - not-present page\n<6> [317.128069] PGD 0 P4D 0\n<4> [317.128071] Oops: Oops: 0000 [#1] PREEMPT SMP NOPTI\n<4> [317.128074] CPU: 1 UID: 0 PID: 1440 Comm: kunit_try_catch Tainted:\n G U N 6.11.0-rc7-xe #1\n<4> [317.128078] Tainted: [U]=USER, [N]=TEST\n<4> [317.128080] Hardware name: Intel Corporation Lunar Lake Client\n Platform/LNL-M LP5 RVP1, BIOS LNLMFWI1.R00.3221.D80.2407291239 07/29/2024\n<4> [317.128082] RIP: 0010:xe_migrate_copy+0x66/0x13e0 [xe]\n<4> [317.128158] Code: 00 00 48 89 8d e0 fe ff ff 48 8b 40 10 4c 89 85 c8\n fe ff ff 44 88 8d bd fe ff ff 65 48 8b 3c 25 28 00 00 00 48 89 7d d0 31\n ff <8b> 79 10 48 89 85 a0 fe ff ff 48 8b 00 48 89 b5 d8 fe ff ff 83 ff\n<4> [317.128162] RSP: 0018:ffffc9000167f9f0 EFLAGS: 00010246\n<4> [317.128164] RAX: ffff8881120d8028 RBX: ffff88814d070428 RCX:\n 0000000000000000\n<4> [317.128166] RDX: ffff88813cb99c00 RSI: 0000000004000000 RDI:\n 0000000000000000\n<4> [317.128168] RBP: ffffc9000167fbb8 R08: ffff88814e7b1f08 R09:\n 0000000000000001\n<4> [317.128170] R10: 0000000000000001 R11: 0000000000000001 R12:\n ffff88814e7b1f08\n<4> [317.128172] R13: ffff88814e7b1f08 R14: ffff88813cb99c00 R15:\n 0000000000000001\n<4> [317.128174] FS: 0000000000000000(0000) GS:ffff88846f280000(0000)\n knlGS:0000000000000000\n<4> [317.128176] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n<4> [317.128178] CR2: 0000000000000010 CR3: 000000011f676004 CR4:\n 0000000000770ef0\n<4> [317.128180] DR0: 0000000000000000 DR1: 0000000000000000 DR2:\n 0000000000000000\n<4> [317.128182] DR3: 0000000000000000 DR6: 00000000ffff07f0 DR7:\n 0000000000000400\n<4> [317.128184] PKRU: 55555554\n<4> [317.128185] Call Trace:\n<4> [317.128187] \n<4> [317.128189] ? show_regs+0x67/0x70\n<4> [317.128194] ? __die_body+0x20/0x70\n<4> [317.128196] ? __die+0x2b/0x40\n<4> [317.128198] ? page_fault_oops+0x15f/0x4e0\n<4> [317.128203] ? do_user_addr_fault+0x3fb/0x970\n<4> [317.128205] ? lock_acquire+0xc7/0x2e0\n<4> [317.128209] ? exc_page_fault+0x87/0x2b0\n<4> [317.128212] ? asm_exc_page_fault+0x27/0x30\n<4> [317.128216] ? xe_migrate_copy+0x66/0x13e0 [xe]\n<4> [317.128263] ? __lock_acquire+0xb9d/0x26f0\n<4> [317.128265] ? __lock_acquire+0xb9d/0x26f0\n<4> [317.128267] ? sg_free_append_table+0x20/0x80\n<4> [317.128271] ? lock_acquire+0xc7/0x2e0\n<4> [317.128273] ? mark_held_locks+0x4d/0x80\n<4> [317.128275] ? trace_hardirqs_on+0x1e/0xd0\n<4> [317.128278] ? _raw_spin_unlock_irqrestore+0x31/0x60\n<4> [317.128281] ? __pm_runtime_resume+0x60/0xa0\n<4> [317.128284] xe_bo_move+0x682/0xc50 [xe]\n<4> [317.128315] ? lock_is_held_type+0xaa/0x120\n<4> [317.128318] ttm_bo_handle_move_mem+0xe5/0x1a0 [ttm]\n<4> [317.128324] ttm_bo_validate+0xd1/0x1a0 [ttm]\n<4> [317.128328] shrink_test_run_device+0x721/0xc10 [xe]\n<4> [317.128360] ? find_held_lock+0x31/0x90\n<4> [317.128363] ? lock_release+0xd1/0x2a0\n<4> [317.128365] ? __pfx_kunit_generic_run_threadfn_adapter+0x10/0x10\n [kunit]\n<4> [317.128370] xe_bo_shrink_kunit+0x11/0x20 [xe]\n<4> [317.128397] kunit_try_run_case+0x6e/0x150 [kunit]\n<4> [317.128400] ? trace_hardirqs_on+0x1e/0xd0\n<4> [317.128402] ? _raw_spin_unlock_irqrestore+0x31/0x60\n<4> [317.128404] kunit_generic_run_threadfn_adapter+0x1e/0x40 [ku\n---truncated---", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49942" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/16e0267db156f8a4ea16bfb3ac3f5743c9698df3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7257d9c9a3c6cfe26c428e9b7ae21d61f2f55a79" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8f5199b6971f0717c2d31685953971fa2e1b9e1a" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-9jhx-gr45-29p7/GHSA-9jhx-gr45-29p7.json b/advisories/unreviewed/2024/10/GHSA-9jhx-gr45-29p7/GHSA-9jhx-gr45-29p7.json new file mode 100644 index 00000000000..be5fb6b6628 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-9jhx-gr45-29p7/GHSA-9jhx-gr45-29p7.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9jhx-gr45-29p7", + "modified": "2024-10-21T18:30:59Z", + "published": "2024-10-21T18:30:59Z", + "aliases": [ + "CVE-2024-49990" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe/hdcp: Check GSC structure validity\n\nSometimes xe_gsc is not initialized when checked at HDCP capability\ncheck. Add gsc structure check to avoid null pointer error.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49990" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7266a424b1e502745170322e3c27f697d12de627" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b4224f6bae3801d589f815672ec62800a1501b0d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c940627857eedca8407b84b40ceb4252b100d291" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-9r6q-3r52-hh42/GHSA-9r6q-3r52-hh42.json b/advisories/unreviewed/2024/10/GHSA-9r6q-3r52-hh42/GHSA-9r6q-3r52-hh42.json new file mode 100644 index 00000000000..e728c23251f --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-9r6q-3r52-hh42/GHSA-9r6q-3r52-hh42.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9r6q-3r52-hh42", + "modified": "2024-10-21T18:30:56Z", + "published": "2024-10-21T18:30:56Z", + "aliases": [ + "CVE-2024-49880" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\next4: fix off by one issue in alloc_flex_gd()\n\nWesley reported an issue:\n\n==================================================================\nEXT4-fs (dm-5): resizing filesystem from 7168 to 786432 blocks\n------------[ cut here ]------------\nkernel BUG at fs/ext4/resize.c:324!\nCPU: 9 UID: 0 PID: 3576 Comm: resize2fs Not tainted 6.11.0+ #27\nRIP: 0010:ext4_resize_fs+0x1212/0x12d0\nCall Trace:\n __ext4_ioctl+0x4e0/0x1800\n ext4_ioctl+0x12/0x20\n __x64_sys_ioctl+0x99/0xd0\n x64_sys_call+0x1206/0x20d0\n do_syscall_64+0x72/0x110\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n==================================================================\n\nWhile reviewing the patch, Honza found that when adjusting resize_bg in\nalloc_flex_gd(), it was possible for flex_gd->resize_bg to be bigger than\nflexbg_size.\n\nThe reproduction of the problem requires the following:\n\n o_group = flexbg_size * 2 * n;\n o_size = (o_group + 1) * group_size;\n n_group: [o_group + flexbg_size, o_group + flexbg_size * 2)\n o_size = (n_group + 1) * group_size;\n\nTake n=0,flexbg_size=16 as an example:\n\n last:15\n|o---------------|--------------n-|\no_group:0 resize to n_group:30\n\nThe corresponding reproducer is:\n\nimg=test.img\nrm -f $img\ntruncate -s 600M $img\nmkfs.ext4 -F $img -b 1024 -G 16 8M\ndev=`losetup -f --show $img`\nmkdir -p /tmp/test\nmount $dev /tmp/test\nresize2fs $dev 248M\n\nDelete the problematic plus 1 to fix the issue, and add a WARN_ON_ONCE()\nto prevent the issue from happening again.\n\n[ Note: another reproucer which this commit fixes is:\n\n img=test.img\n rm -f $img\n truncate -s 25MiB $img\n mkfs.ext4 -b 4096 -E nodiscard,lazy_itable_init=0,lazy_journal_init=0 $img\n truncate -s 3GiB $img\n dev=`losetup -f --show $img`\n mkdir -p /tmp/test\n mount $dev /tmp/test\n resize2fs $dev 3G\n umount $dev\n losetup -d $dev\n\n -- TYT ]", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49880" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0d80d2b8bf613398baf7185009e35f9d0459ecb0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6121258c2b33ceac3d21f6a221452692c465df88" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/acb559d6826116cc113598640d105094620c2526" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-9x5x-jw3v-frfw/GHSA-9x5x-jw3v-frfw.json b/advisories/unreviewed/2024/10/GHSA-9x5x-jw3v-frfw/GHSA-9x5x-jw3v-frfw.json new file mode 100644 index 00000000000..a852fb13936 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-9x5x-jw3v-frfw/GHSA-9x5x-jw3v-frfw.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9x5x-jw3v-frfw", + "modified": "2024-10-21T18:30:58Z", + "published": "2024-10-21T18:30:58Z", + "aliases": [ + "CVE-2024-49958" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: reserve space for inline xattr before attaching reflink tree\n\nOne of our customers reported a crash and a corrupted ocfs2 filesystem. \nThe crash was due to the detection of corruption. Upon troubleshooting,\nthe fsck -fn output showed the below corruption\n\n[EXTENT_LIST_FREE] Extent list in owner 33080590 claims 230 as the next free chain record,\nbut fsck believes the largest valid value is 227. Clamp the next record value? n\n\nThe stat output from the debugfs.ocfs2 showed the following corruption\nwhere the \"Next Free Rec:\" had overshot the \"Count:\" in the root metadata\nblock.\n\n Inode: 33080590 Mode: 0640 Generation: 2619713622 (0x9c25a856)\n FS Generation: 904309833 (0x35e6ac49)\n CRC32: 00000000 ECC: 0000\n Type: Regular Attr: 0x0 Flags: Valid\n Dynamic Features: (0x16) HasXattr InlineXattr Refcounted\n Extended Attributes Block: 0 Extended Attributes Inline Size: 256\n User: 0 (root) Group: 0 (root) Size: 281320357888\n Links: 1 Clusters: 141738\n ctime: 0x66911b56 0x316edcb8 -- Fri Jul 12 06:02:30.829349048 2024\n atime: 0x66911d6b 0x7f7a28d -- Fri Jul 12 06:11:23.133669517 2024\n mtime: 0x66911b56 0x12ed75d7 -- Fri Jul 12 06:02:30.317552087 2024\n dtime: 0x0 -- Wed Dec 31 17:00:00 1969\n Refcount Block: 2777346\n Last Extblk: 2886943 Orphan Slot: 0\n Sub Alloc Slot: 0 Sub Alloc Bit: 14\n Tree Depth: 1 Count: 227 Next Free Rec: 230\n ## Offset Clusters Block#\n 0 0 2310 2776351\n 1 2310 2139 2777375\n 2 4449 1221 2778399\n 3 5670 731 2779423\n 4 6401 566 2780447\n ....... .... .......\n ....... .... .......\n\nThe issue was in the reflink workfow while reserving space for inline\nxattr. The problematic function is ocfs2_reflink_xattr_inline(). By the\ntime this function is called the reflink tree is already recreated at the\ndestination inode from the source inode. At this point, this function\nreserves space for inline xattrs at the destination inode without even\nchecking if there is space at the root metadata block. It simply reduces\nthe l_count from 243 to 227 thereby making space of 256 bytes for inline\nxattr whereas the inode already has extents beyond this index (in this\ncase up to 230), thereby causing corruption.\n\nThe fix for this is to reserve space for inline metadata at the destination\ninode before the reflink tree gets recreated. The customer has verified the\nfix.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49958" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/020f5c53c17f66c0a8f2d37dad27ace301b8d8a1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5c2072f02c0d75802ec28ec703b7d43a0dd008b5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5ca60b86f57a4d9648f68418a725b3a7de2816b0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/637c00e06564a945e9d0edb3d78d362d64935f9f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/96ce4c3537114d1698be635f5e36c62dc49df7a4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9f9a8f3ac65b4147f1a7b6c05fad5192c0e3c3d9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/aac31d654a0a31cb0d2fa36ae694f4e164a52707" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-9xrj-2966-hg7q/GHSA-9xrj-2966-hg7q.json b/advisories/unreviewed/2024/10/GHSA-9xrj-2966-hg7q/GHSA-9xrj-2966-hg7q.json new file mode 100644 index 00000000000..8b079d0ad9a --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-9xrj-2966-hg7q/GHSA-9xrj-2966-hg7q.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9xrj-2966-hg7q", + "modified": "2024-10-21T18:31:00Z", + "published": "2024-10-21T18:31:00Z", + "aliases": [ + "CVE-2024-49997" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ethernet: lantiq_etop: fix memory disclosure\n\nWhen applying padding, the buffer is not zeroed, which results in memory\ndisclosure. The mentioned data is observed on the wire. This patch uses\nskb_put_padto() to pad Ethernet frames properly. The mentioned function\nzeroes the expanded buffer.\n\nIn case the packet cannot be padded it is silently dropped. Statistics\nare also not incremented. This driver does not support statistics in the\nold 32-bit format or the new 64-bit format. These will be added in the\nfuture. In its current form, the patch should be easily backported to\nstable versions.\n\nEthernet MACs on Amazon-SE and Danube cannot do padding of the packets\nin hardware, so software padding must be applied.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49997" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1097bf16501ed5e35358d848b0a94ad2830b0f65" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/185df159843d30fb71f821e7ea4368c2a3bfcd36" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2bf4c101d7c99483b8b15a0c8f881e3f399f7e18" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/431b122933b197820d319eb3987a67d04346ce9e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/45c0de18ff2dc9af01236380404bbd6a46502c69" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/469856f76f4802c5d7e3d20e343185188de1e2db" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e66e38d07b31e177ca430758ed97fbc79f27d966" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-c3cx-mm7p-wgj8/GHSA-c3cx-mm7p-wgj8.json b/advisories/unreviewed/2024/10/GHSA-c3cx-mm7p-wgj8/GHSA-c3cx-mm7p-wgj8.json new file mode 100644 index 00000000000..67a531660e2 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-c3cx-mm7p-wgj8/GHSA-c3cx-mm7p-wgj8.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c3cx-mm7p-wgj8", + "modified": "2024-10-21T18:30:57Z", + "published": "2024-10-21T18:30:57Z", + "aliases": [ + "CVE-2024-49887" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to don't panic system for no free segment fault injection\n\nf2fs: fix to don't panic system for no free segment fault injection\n\nsyzbot reports a f2fs bug as below:\n\nF2FS-fs (loop0): inject no free segment in get_new_segment of __allocate_new_segment+0x1ce/0x940 fs/f2fs/segment.c:3167\nF2FS-fs (loop0): Stopped filesystem due to reason: 7\n------------[ cut here ]------------\nkernel BUG at fs/f2fs/segment.c:2748!\nCPU: 0 UID: 0 PID: 5109 Comm: syz-executor304 Not tainted 6.11.0-rc6-syzkaller-00363-g89f5e14d05b4 #0\nRIP: 0010:get_new_segment fs/f2fs/segment.c:2748 [inline]\nRIP: 0010:new_curseg+0x1f61/0x1f70 fs/f2fs/segment.c:2836\nCall Trace:\n __allocate_new_segment+0x1ce/0x940 fs/f2fs/segment.c:3167\n f2fs_allocate_new_section fs/f2fs/segment.c:3181 [inline]\n f2fs_allocate_pinning_section+0xfa/0x4e0 fs/f2fs/segment.c:3195\n f2fs_expand_inode_data+0x5d6/0xbb0 fs/f2fs/file.c:1799\n f2fs_fallocate+0x448/0x960 fs/f2fs/file.c:1903\n vfs_fallocate+0x553/0x6c0 fs/open.c:334\n do_vfs_ioctl+0x2592/0x2e50 fs/ioctl.c:886\n __do_sys_ioctl fs/ioctl.c:905 [inline]\n __se_sys_ioctl+0x81/0x170 fs/ioctl.c:893\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\nRIP: 0010:get_new_segment fs/f2fs/segment.c:2748 [inline]\nRIP: 0010:new_curseg+0x1f61/0x1f70 fs/f2fs/segment.c:2836\n\nThe root cause is when we inject no free segment fault into f2fs,\nwe should not panic system, fix it.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49887" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/645ec43760e86d3079fee2e8b51fde7060a540d0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/65a6ce4726c27b45600303f06496fef46d00b57f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9f6e7a0512a57387d36f5e9e9635d6668cac13dd" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-c4vm-rj4p-m3c8/GHSA-c4vm-rj4p-m3c8.json b/advisories/unreviewed/2024/10/GHSA-c4vm-rj4p-m3c8/GHSA-c4vm-rj4p-m3c8.json new file mode 100644 index 00000000000..9b6ff373f52 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-c4vm-rj4p-m3c8/GHSA-c4vm-rj4p-m3c8.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c4vm-rj4p-m3c8", + "modified": "2024-10-21T18:30:57Z", + "published": "2024-10-21T18:30:57Z", + "aliases": [ + "CVE-2024-49888" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix a sdiv overflow issue\n\nZac Ecob reported a problem where a bpf program may cause kernel crash due\nto the following error:\n Oops: divide error: 0000 [#1] PREEMPT SMP KASAN PTI\n\nThe failure is due to the below signed divide:\n LLONG_MIN/-1 where LLONG_MIN equals to -9,223,372,036,854,775,808.\nLLONG_MIN/-1 is supposed to give a positive number 9,223,372,036,854,775,808,\nbut it is impossible since for 64-bit system, the maximum positive\nnumber is 9,223,372,036,854,775,807. On x86_64, LLONG_MIN/-1 will\ncause a kernel exception. On arm64, the result for LLONG_MIN/-1 is\nLLONG_MIN.\n\nFurther investigation found all the following sdiv/smod cases may trigger\nan exception when bpf program is running on x86_64 platform:\n - LLONG_MIN/-1 for 64bit operation\n - INT_MIN/-1 for 32bit operation\n - LLONG_MIN%-1 for 64bit operation\n - INT_MIN%-1 for 32bit operation\nwhere -1 can be an immediate or in a register.\n\nOn arm64, there are no exceptions:\n - LLONG_MIN/-1 = LLONG_MIN\n - INT_MIN/-1 = INT_MIN\n - LLONG_MIN%-1 = 0\n - INT_MIN%-1 = 0\nwhere -1 can be an immediate or in a register.\n\nInsn patching is needed to handle the above cases and the patched codes\nproduced results aligned with above arm64 result. The below are pseudo\ncodes to handle sdiv/smod exceptions including both divisor -1 and divisor 0\nand the divisor is stored in a register.\n\nsdiv:\n tmp = rX\n tmp += 1 /* [-1, 0] -> [0, 1]\n if tmp >(unsigned) 1 goto L2\n if tmp == 0 goto L1\n rY = 0\n L1:\n rY = -rY;\n goto L3\n L2:\n rY /= rX\n L3:\n\nsmod:\n tmp = rX\n tmp += 1 /* [-1, 0] -> [0, 1]\n if tmp >(unsigned) 1 goto L1\n if tmp == 1 (is64 ? goto L2 : goto L3)\n rY = 0;\n goto L2\n L1:\n rY %= rX\n L2:\n goto L4 // only when !is64\n L3:\n wY = wY // only when !is64\n L4:\n\n [1] https://lore.kernel.org/bpf/tPJLTEh7S_DxFEqAI2Ji5MBSoZVg7_G-Py2iaZpAaWtM961fFTWtsnlzwvTbzBzaUzwQAoNATXKUlt0LZOFgnDcIyKCswAnAGdUF3LBrhGQ=@protonmail.com/", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49888" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4902a6a0dc593c82055fc8c9ada371bafe26c9cc" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7dd34d7b7dcf9309fc6224caf4dd5b35bedddcb7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d22e45a369afc7c28f11acfa5b5e8e478227ca5d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-c8jq-9f5m-r697/GHSA-c8jq-9f5m-r697.json b/advisories/unreviewed/2024/10/GHSA-c8jq-9f5m-r697/GHSA-c8jq-9f5m-r697.json new file mode 100644 index 00000000000..0d01828f8fb --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-c8jq-9f5m-r697/GHSA-c8jq-9f5m-r697.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c8jq-9f5m-r697", + "modified": "2024-10-21T18:30:59Z", + "published": "2024-10-21T18:30:59Z", + "aliases": [ + "CVE-2024-49995" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: guard against string buffer overrun\n\nSmatch reports that copying media_name and if_name to name_parts may\noverwrite the destination.\n\n .../bearer.c:166 bearer_name_validate() error: strcpy() 'media_name' too large for 'name_parts->media_name' (32 vs 16)\n .../bearer.c:167 bearer_name_validate() error: strcpy() 'if_name' too large for 'name_parts->if_name' (1010102 vs 16)\n\nThis does seem to be the case so guard against this possibility by using\nstrscpy() and failing if truncation occurs.\n\nIntroduced by commit b97bf3fd8f6a (\"[TIPC] Initial merge\")\n\nCompile tested only.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49995" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/12d26aa7fd3cbdbc5149b6e516563478d575026e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2ed7f42dfd3edb387034128ca5b0f639836d4ddd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/54dae0e9063ed23c9acf8d5ab9b18d3426a8ac18" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6555a2a9212be6983d2319d65276484f7c5f431a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/80c0be7bcf940ce9308311575c3aff8983c9b97a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a18c7b239d02aafb791ae2c45226f6bb40641792" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e2b2558971e02ca33eb637a8350d68a48b3e8e46" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-cjwf-5vh9-w48g/GHSA-cjwf-5vh9-w48g.json b/advisories/unreviewed/2024/10/GHSA-cjwf-5vh9-w48g/GHSA-cjwf-5vh9-w48g.json new file mode 100644 index 00000000000..aeceab73627 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-cjwf-5vh9-w48g/GHSA-cjwf-5vh9-w48g.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cjwf-5vh9-w48g", + "modified": "2024-10-21T18:30:59Z", + "published": "2024-10-21T18:30:59Z", + "aliases": [ + "CVE-2024-49993" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\niommu/vt-d: Fix potential lockup if qi_submit_sync called with 0 count\n\nIf qi_submit_sync() is invoked with 0 invalidation descriptors (for\ninstance, for DMA draining purposes), we can run into a bug where a\nsubmitting thread fails to detect the completion of invalidation_wait.\nSubsequently, this led to a soft lockup. Currently, there is no impact\nby this bug on the existing users because no callers are submitting\ninvalidations with 0 descriptors. This fix will enable future users\n(such as DMA drain) calling qi_submit_sync() with 0 count.\n\nSuppose thread T1 invokes qi_submit_sync() with non-zero descriptors, while\nconcurrently, thread T2 calls qi_submit_sync() with zero descriptors. Both\nthreads then enter a while loop, waiting for their respective descriptors\nto complete. T1 detects its completion (i.e., T1's invalidation_wait status\nchanges to QI_DONE by HW) and proceeds to call reclaim_free_desc() to\nreclaim all descriptors, potentially including adjacent ones of other\nthreads that are also marked as QI_DONE.\n\nDuring this time, while T2 is waiting to acquire the qi->q_lock, the IOMMU\nhardware may complete the invalidation for T2, setting its status to\nQI_DONE. However, if T1's execution of reclaim_free_desc() frees T2's\ninvalidation_wait descriptor and changes its status to QI_FREE, T2 will\nnot observe the QI_DONE status for its invalidation_wait and will\nindefinitely remain stuck.\n\nThis soft lockup does not occur when only non-zero descriptors are\nsubmitted.In such cases, invalidation descriptors are interspersed among\nwait descriptors with the status QI_IN_USE, acting as barriers. These\nbarriers prevent the reclaim code from mistakenly freeing descriptors\nbelonging to other submitters.\n\nConsidered the following example timeline:\n\tT1\t\t\tT2\n========================================\n\tID1\n\tWD1\n\twhile(WD1!=QI_DONE)\n\tunlock\n\t\t\t\tlock\n\tWD1=QI_DONE*\t\tWD2\n\t\t\t\twhile(WD2!=QI_DONE)\n\t\t\t\tunlock\n\tlock\n\tWD1==QI_DONE?\n\tID1=QI_DONE\t\tWD2=DONE*\n\treclaim()\n\tID1=FREE\n\tWD1=FREE\n\tWD2=FREE\n\tunlock\n\t\t\t\tsoft lockup! T2 never sees QI_DONE in WD2\n\nWhere:\nID = invalidation descriptor\nWD = wait descriptor\n* Written by hardware\n\nThe root of the problem is that the descriptor status QI_DONE flag is used\nfor two conflicting purposes:\n1. signal a descriptor is ready for reclaim (to be freed)\n2. signal by the hardware that a wait descriptor is complete\n\nThe solution (in this patch) is state separation by using QI_FREE flag\nfor #1.\n\nOnce a thread's invalidation descriptors are complete, their status would\nbe set to QI_FREE. The reclaim_free_desc() function would then only\nfree descriptors marked as QI_FREE instead of those marked as\nQI_DONE. This change ensures that T2 (from the previous example) will\ncorrectly observe the completion of its invalidation_wait (marked as\nQI_DONE).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49993" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/07e4e92f84b7d3018b7064ef8d8438aeb54a2ca5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3cf74230c139f208b7fb313ae0054386eee31a81" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8840dc73ac9e1028291458ef1429ec3c2524ffec" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/92ba5b014d5435dd7a1ee02a2c7f2a0e8fe06c36" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/de9e7f68762585f7532de8a06de9485bf39dbd38" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/dfdbc5ba10fb792c9d6d12ba8cb6e465f97365ed" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e03f00aa4a6c0c49c17857a4048f586636abdc32" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-cpwp-j2f3-rxq9/GHSA-cpwp-j2f3-rxq9.json b/advisories/unreviewed/2024/10/GHSA-cpwp-j2f3-rxq9/GHSA-cpwp-j2f3-rxq9.json new file mode 100644 index 00000000000..bd152aeb4d1 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-cpwp-j2f3-rxq9/GHSA-cpwp-j2f3-rxq9.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cpwp-j2f3-rxq9", + "modified": "2024-10-21T18:30:58Z", + "published": "2024-10-21T18:30:58Z", + "aliases": [ + "CVE-2024-49956" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ngfs2: fix double destroy_workqueue error\n\nWhen gfs2_fill_super() fails, destroy_workqueue() is called within\ngfs2_gl_hash_clear(), and the subsequent code path calls\ndestroy_workqueue() on the same work queue again.\n\nThis issue can be fixed by setting the work queue pointer to NULL after\nthe first destroy_workqueue() call and checking for a NULL pointer\nbefore attempting to destroy the work queue again.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49956" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6cb9df81a2c462b89d2f9611009ab43ae8717841" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a5336035728d77efd76306940d742a6f23debe68" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-cx67-p8xc-qwg4/GHSA-cx67-p8xc-qwg4.json b/advisories/unreviewed/2024/10/GHSA-cx67-p8xc-qwg4/GHSA-cx67-p8xc-qwg4.json new file mode 100644 index 00000000000..be0646597af --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-cx67-p8xc-qwg4/GHSA-cx67-p8xc-qwg4.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cx67-p8xc-qwg4", + "modified": "2024-10-21T18:30:56Z", + "published": "2024-10-21T18:30:56Z", + "aliases": [ + "CVE-2024-49864" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nrxrpc: Fix a race between socket set up and I/O thread creation\n\nIn rxrpc_open_socket(), it sets up the socket and then sets up the I/O\nthread that will handle it. This is a problem, however, as there's a gap\nbetween the two phases in which a packet may come into rxrpc_encap_rcv()\nfrom the UDP packet but we oops when trying to wake the not-yet created I/O\nthread.\n\nAs a quick fix, just make rxrpc_encap_rcv() discard the packet if there's\nno I/O thread yet.\n\nA better, but more intrusive fix would perhaps be to rearrange things such\nthat the socket creation is done by the I/O thread.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49864" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/56e415202b8a17de6496f4023e545fcb66f118ec" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bc212465326e8587325f520a052346f0b57360e6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c64f5fc95e9612fdf75587c8e21e494e614c18e2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cdf4bbbdb956d7426f687f38757ebca2a2759a0f" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-cxw3-2f59-5p7f/GHSA-cxw3-2f59-5p7f.json b/advisories/unreviewed/2024/10/GHSA-cxw3-2f59-5p7f/GHSA-cxw3-2f59-5p7f.json new file mode 100644 index 00000000000..3a2248d3f1d --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-cxw3-2f59-5p7f/GHSA-cxw3-2f59-5p7f.json @@ -0,0 +1,55 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cxw3-2f59-5p7f", + "modified": "2024-10-21T18:31:00Z", + "published": "2024-10-21T18:31:00Z", + "aliases": [ + "CVE-2024-50002" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nstatic_call: Handle module init failure correctly in static_call_del_module()\n\nModule insertion invokes static_call_add_module() to initialize the static\ncalls in a module. static_call_add_module() invokes __static_call_init(),\nwhich allocates a struct static_call_mod to either encapsulate the built-in\nstatic call sites of the associated key into it so further modules can be\nadded or to append the module to the module chain.\n\nIf that allocation fails the function returns with an error code and the\nmodule core invokes static_call_del_module() to clean up eventually added\nstatic_call_mod entries.\n\nThis works correctly, when all keys used by the module were converted over\nto a module chain before the failure. If not then static_call_del_module()\ncauses a #GP as it blindly assumes that key::mods points to a valid struct\nstatic_call_mod.\n\nThe problem is that key::mods is not a individual struct member of struct\nstatic_call_key, it's part of a union to save space:\n\n union {\n /* bit 0: 0 = mods, 1 = sites */\n unsigned long type;\n struct static_call_mod *mods;\n struct static_call_site *sites;\n\t};\n\nkey::sites is a pointer to the list of built-in usage sites of the static\ncall. The type of the pointer is differentiated by bit 0. A mods pointer\nhas the bit clear, the sites pointer has the bit set.\n\nAs static_call_del_module() blidly assumes that the pointer is a valid\nstatic_call_mod type, it fails to check for this failure case and\ndereferences the pointer to the list of built-in call sites, which is\nobviously bogus.\n\nCure it by checking whether the key has a sites or a mods pointer.\n\nIf it's a sites pointer then the key is not to be touched. As the sites are\nwalked in the same order as in __static_call_init() the site walk can be\nterminated because all subsequent sites have not been touched by the init\ncode due to the error exit.\n\nIf it was converted before the allocation fail, then the inner loop which\nsearches for a module match will find nothing.\n\nA fail in the second allocation in __static_call_init() is harmless and\ndoes not require special treatment. The first allocation succeeded and\nconverted the key to a module chain. That first entry has mod::mod == NULL\nand mod::next == NULL, so the inner loop of static_call_del_module() will\nneither find a module match nor a module chain. The next site in the walk\nwas either already converted, but can't match the module, or it will exit\nthe outer loop because it has a static_call_site pointer and not a\nstatic_call_mod pointer.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50002" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2b494471797bff3d257e99dc0a7abb0c5ff3b4cd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4b30051c4864234ec57290c3d142db7c88f10d8a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9c48c2b53191bf991361998f5bb97b8f2fc5a89c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b566c7d8a2de403ccc9d8a06195e19bbb386d0e4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c0abbbe8c98c077292221ec7e2baa667c9f0974c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ed4c8ce0f307f2ab8778aeb40a8866d171e8f128" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-f3gg-6f8f-39gh/GHSA-f3gg-6f8f-39gh.json b/advisories/unreviewed/2024/10/GHSA-f3gg-6f8f-39gh/GHSA-f3gg-6f8f-39gh.json new file mode 100644 index 00000000000..078ca18e406 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-f3gg-6f8f-39gh/GHSA-f3gg-6f8f-39gh.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f3gg-6f8f-39gh", + "modified": "2024-10-21T18:30:56Z", + "published": "2024-10-21T18:30:56Z", + "aliases": [ + "CVE-2024-49863" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nvhost/scsi: null-ptr-dereference in vhost_scsi_get_req()\n\nSince commit 3f8ca2e115e5 (\"vhost/scsi: Extract common handling code\nfrom control queue handler\") a null pointer dereference bug can be\ntriggered when guest sends an SCSI AN request.\n\nIn vhost_scsi_ctl_handle_vq(), `vc.target` is assigned with\n`&v_req.tmf.lun[1]` within a switch-case block and is then passed to\nvhost_scsi_get_req() which extracts `vc->req` and `tpg`. However, for\na `VIRTIO_SCSI_T_AN_*` request, tpg is not required, so `vc.target` is\nset to NULL in this branch. Later, in vhost_scsi_get_req(),\n`vc->target` is dereferenced without being checked, leading to a null\npointer dereference bug. This bug can be triggered from guest.\n\nWhen this bug occurs, the vhost_worker process is killed while holding\n`vq->mutex` and the corresponding tpg will remain occupied\nindefinitely.\n\nBelow is the KASAN report:\nOops: general protection fault, probably for non-canonical address\n0xdffffc0000000000: 0000 [#1] PREEMPT SMP KASAN NOPTI\nKASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]\nCPU: 1 PID: 840 Comm: poc Not tainted 6.10.0+ #1\nHardware name: QEMU Ubuntu 24.04 PC (i440FX + PIIX, 1996), BIOS\n1.16.3-debian-1.16.3-2 04/01/2014\nRIP: 0010:vhost_scsi_get_req+0x165/0x3a0\nCode: 00 fc ff df 48 89 fa 48 c1 ea 03 80 3c 02 00 0f 85 2b 02 00 00\n48 b8 00 00 00 00 00 fc ff df 4d 8b 65 30 4c 89 e2 48 c1 ea 03 <0f> b6\n04 02 4c 89 e2 83 e2 07 38 d0 7f 08 84 c0 0f 85 be 01 00 00\nRSP: 0018:ffff888017affb50 EFLAGS: 00010246\nRAX: dffffc0000000000 RBX: ffff88801b000000 RCX: 0000000000000000\nRDX: 0000000000000000 RSI: 0000000000000000 RDI: ffff888017affcb8\nRBP: ffff888017affb80 R08: 0000000000000000 R09: 0000000000000000\nR10: 0000000000000000 R11: 0000000000000000 R12: 0000000000000000\nR13: ffff888017affc88 R14: ffff888017affd1c R15: ffff888017993000\nFS: 000055556e076500(0000) GS:ffff88806b100000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00000000200027c0 CR3: 0000000010ed0004 CR4: 0000000000370ef0\nCall Trace:\n \n ? show_regs+0x86/0xa0\n ? die_addr+0x4b/0xd0\n ? exc_general_protection+0x163/0x260\n ? asm_exc_general_protection+0x27/0x30\n ? vhost_scsi_get_req+0x165/0x3a0\n vhost_scsi_ctl_handle_vq+0x2a4/0xca0\n ? __pfx_vhost_scsi_ctl_handle_vq+0x10/0x10\n ? __switch_to+0x721/0xeb0\n ? __schedule+0xda5/0x5710\n ? __kasan_check_write+0x14/0x30\n ? _raw_spin_lock+0x82/0xf0\n vhost_scsi_ctl_handle_kick+0x52/0x90\n vhost_run_work_list+0x134/0x1b0\n vhost_task_fn+0x121/0x350\n...\n \n---[ end trace 0000000000000000 ]---\n\nLet's add a check in vhost_scsi_get_req.\n\n[whitespace fixes]", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49863" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/00fb5b23e1c9cdbe496f5cd6b40367cb895f6c93" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/221af82f606d928ccef19a16d35633c63026f1be" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/25613e6d9841a1f9fb985be90df921fa99f800de" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/46128370a72c431df733af5ebb065c4d48c9ad39" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/61517f33e76d2c5247c1e61e668693afe5b67e6f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6592347f06e2b19a624270a85ad4b3ae48c3b241" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ace9c778a214da9c98d7b69d904d1b0816f4f681" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-f3xx-63r9-v2cp/GHSA-f3xx-63r9-v2cp.json b/advisories/unreviewed/2024/10/GHSA-f3xx-63r9-v2cp/GHSA-f3xx-63r9-v2cp.json new file mode 100644 index 00000000000..b8773cfaee5 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-f3xx-63r9-v2cp/GHSA-f3xx-63r9-v2cp.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f3xx-63r9-v2cp", + "modified": "2024-10-21T18:30:56Z", + "published": "2024-10-21T18:30:56Z", + "aliases": [ + "CVE-2024-49878" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nresource: fix region_intersects() vs add_memory_driver_managed()\n\nOn a system with CXL memory, the resource tree (/proc/iomem) related to\nCXL memory may look like something as follows.\n\n490000000-50fffffff : CXL Window 0\n 490000000-50fffffff : region0\n 490000000-50fffffff : dax0.0\n 490000000-50fffffff : System RAM (kmem)\n\nBecause drivers/dax/kmem.c calls add_memory_driver_managed() during\nonlining CXL memory, which makes \"System RAM (kmem)\" a descendant of \"CXL\nWindow X\". This confuses region_intersects(), which expects all \"System\nRAM\" resources to be at the top level of iomem_resource. This can lead to\nbugs.\n\nFor example, when the following command line is executed to write some\nmemory in CXL memory range via /dev/mem,\n\n $ dd if=data of=/dev/mem bs=$((1 << 10)) seek=$((0x490000000 >> 10)) count=1\n dd: error writing '/dev/mem': Bad address\n 1+0 records in\n 0+0 records out\n 0 bytes copied, 0.0283507 s, 0.0 kB/s\n\nthe command fails as expected. However, the error code is wrong. It\nshould be \"Operation not permitted\" instead of \"Bad address\". More\nseriously, the /dev/mem permission checking in devmem_is_allowed() passes\nincorrectly. Although the accessing is prevented later because ioremap()\nisn't allowed to map system RAM, it is a potential security issue. During\ncommand executing, the following warning is reported in the kernel log for\ncalling ioremap() on system RAM.\n\n ioremap on RAM at 0x0000000490000000 - 0x0000000490000fff\n WARNING: CPU: 2 PID: 416 at arch/x86/mm/ioremap.c:216 __ioremap_caller.constprop.0+0x131/0x35d\n Call Trace:\n memremap+0xcb/0x184\n xlate_dev_mem_ptr+0x25/0x2f\n write_mem+0x94/0xfb\n vfs_write+0x128/0x26d\n ksys_write+0xac/0xfe\n do_syscall_64+0x9a/0xfd\n entry_SYSCALL_64_after_hwframe+0x4b/0x53\n\nThe details of command execution process are as follows. In the above\nresource tree, \"System RAM\" is a descendant of \"CXL Window 0\" instead of a\ntop level resource. So, region_intersects() will report no System RAM\nresources in the CXL memory region incorrectly, because it only checks the\ntop level resources. Consequently, devmem_is_allowed() will return 1\n(allow access via /dev/mem) for CXL memory region incorrectly. \nFortunately, ioremap() doesn't allow to map System RAM and reject the\naccess.\n\nSo, region_intersects() needs to be fixed to work correctly with the\nresource tree with \"System RAM\" not at top level as above. To fix it, if\nwe found a unmatched resource in the top level, we will continue to search\nmatched resources in its descendant resources. So, we will not miss any\nmatched resources in resource tree anymore.\n\nIn the new implementation, an example resource tree\n\n|------------- \"CXL Window 0\" ------------|\n|-- \"System RAM\" --|\n\nwill behave similar as the following fake resource tree for\nregion_intersects(, IORESOURCE_SYSTEM_RAM, ),\n\n|-- \"System RAM\" --||-- \"CXL Window 0a\" --|\n\nWhere \"CXL Window 0a\" is part of the original \"CXL Window 0\" that\nisn't covered by \"System RAM\".", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49878" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/06ff97a20b8c9e9d256b0d2c3e87f78f8ccea3de" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1d5f85f1b7db79c75c9e07d6571ce2a7bdf725c4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/393331e16ce205e036e58b3d8ca4ee2e635f21d9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4b90d2eb451b357681063ba4552b10b39d7ad885" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8a6fef7d22a1d952aed68584d3fcc0d018d2bdc3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/927abc5b7d6d2c2e936bec5a2f71d9512c5e72f7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b4afe4183ec77f230851ea139d91e5cf2644c68b" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-f7v4-xw4v-h9wq/GHSA-f7v4-xw4v-h9wq.json b/advisories/unreviewed/2024/10/GHSA-f7v4-xw4v-h9wq/GHSA-f7v4-xw4v-h9wq.json new file mode 100644 index 00000000000..ef81da065a2 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-f7v4-xw4v-h9wq/GHSA-f7v4-xw4v-h9wq.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f7v4-xw4v-h9wq", + "modified": "2024-10-21T18:30:59Z", + "published": "2024-10-21T18:30:59Z", + "aliases": [ + "CVE-2024-49971" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Increase array size of dummy_boolean\n\n[WHY]\ndml2_core_shared_mode_support and dml_core_mode_support access the third\nelement of dummy_boolean, i.e. hw_debug5 = &s->dummy_boolean[2], when\ndummy_boolean has size of 2. Any assignment to hw_debug5 causes an\nOVERRUN.\n\n[HOW]\nIncrease dummy_boolean's array size to 3.\n\nThis fixes 2 OVERRUN issues reported by Coverity.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49971" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6d64d39486197083497a01b39e23f2f8474b35d3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e9e48b7bb9cf3b78f0305ef0144aaf61da0a83d8" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-ffhg-6h3q-652p/GHSA-ffhg-6h3q-652p.json b/advisories/unreviewed/2024/10/GHSA-ffhg-6h3q-652p/GHSA-ffhg-6h3q-652p.json index 77226a7e1b6..3dec83e92c2 100644 --- a/advisories/unreviewed/2024/10/GHSA-ffhg-6h3q-652p/GHSA-ffhg-6h3q-652p.json +++ b/advisories/unreviewed/2024/10/GHSA-ffhg-6h3q-652p/GHSA-ffhg-6h3q-652p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ffhg-6h3q-652p", - "modified": "2024-10-16T18:31:47Z", + "modified": "2024-10-21T18:30:45Z", "published": "2024-10-16T18:31:47Z", "aliases": [ "CVE-2024-38814" diff --git a/advisories/unreviewed/2024/10/GHSA-ffxc-rwg8-qgjw/GHSA-ffxc-rwg8-qgjw.json b/advisories/unreviewed/2024/10/GHSA-ffxc-rwg8-qgjw/GHSA-ffxc-rwg8-qgjw.json new file mode 100644 index 00000000000..fdb52be27c2 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-ffxc-rwg8-qgjw/GHSA-ffxc-rwg8-qgjw.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ffxc-rwg8-qgjw", + "modified": "2024-10-21T18:30:57Z", + "published": "2024-10-21T18:30:57Z", + "aliases": [ + "CVE-2024-49906" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Check null pointer before try to access it\n\n[why & how]\nChange the order of the pipe_ctx->plane_state check to ensure that\nplane_state is not null before accessing it.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49906" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1b686053c06ffb9f4524b288110cf2a831ff7a25" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2002ccb93004e76a471b180560accb2c1f850f35" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-fh5r-24qv-66r9/GHSA-fh5r-24qv-66r9.json b/advisories/unreviewed/2024/10/GHSA-fh5r-24qv-66r9/GHSA-fh5r-24qv-66r9.json new file mode 100644 index 00000000000..daf3f7155f7 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-fh5r-24qv-66r9/GHSA-fh5r-24qv-66r9.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fh5r-24qv-66r9", + "modified": "2024-10-21T18:30:57Z", + "published": "2024-10-21T18:30:57Z", + "aliases": [ + "CVE-2024-49904" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: add list empty check to avoid null pointer issue\n\nAdd list empty check to avoid null pointer issues in some corner cases.\n- list_for_each_entry_safe()", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49904" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4416377ae1fdc41a90b665943152ccd7ff61d3c5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5ec731ef47f1dba34daad3e51a93de793f9319ac" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8e87763946f708063d7e5303339598abbb8c5aac" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-fh83-rw64-jhh7/GHSA-fh83-rw64-jhh7.json b/advisories/unreviewed/2024/10/GHSA-fh83-rw64-jhh7/GHSA-fh83-rw64-jhh7.json new file mode 100644 index 00000000000..09a0a1d18a2 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-fh83-rw64-jhh7/GHSA-fh83-rw64-jhh7.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fh83-rw64-jhh7", + "modified": "2024-10-21T18:30:59Z", + "published": "2024-10-21T18:30:59Z", + "aliases": [ + "CVE-2024-49973" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nr8169: add tally counter fields added with RTL8125\n\nRTL8125 added fields to the tally counter, what may result in the chip\ndma'ing these new fields to unallocated memory. Therefore make sure\nthat the allocated memory area is big enough to hold all of the\ntally counter values, even if we use only parts of it.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49973" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1c723d785adb711496bc64c24240f952f4faaabf" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/21950321ad33d7613b1453f4c503d7b1871deb61" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/585c048d15ed559f20cb94c8fa2f30077efa4fbc" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/92bc8647b4d65f4d4bf8afdb206321c1bc55a486" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/991e8b0bab669b7d06927c3e442b3352532e8581" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ced8e8b8f40accfcce4a2bbd8b150aa76d5eff9a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fe44b3bfbf0c74df5712f44458689d0eccccf47d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-fppc-fjqw-6gx5/GHSA-fppc-fjqw-6gx5.json b/advisories/unreviewed/2024/10/GHSA-fppc-fjqw-6gx5/GHSA-fppc-fjqw-6gx5.json new file mode 100644 index 00000000000..a96d18f75f1 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-fppc-fjqw-6gx5/GHSA-fppc-fjqw-6gx5.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fppc-fjqw-6gx5", + "modified": "2024-10-21T18:30:57Z", + "published": "2024-10-21T18:30:57Z", + "aliases": [ + "CVE-2024-49922" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Check null pointers before using them\n\n[WHAT & HOW]\nThese pointers are null checked previously in the same function,\nindicating they might be null as reported by Coverity. As a result,\nthey need to be checked when used again.\n\nThis fixes 3 FORWARD_NULL issue reported by Coverity.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49922" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1ff12bcd7deaeed25efb5120433c6a45dd5504a8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5e9386baa3033c369564d55de4bab62423e8a1d3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/65e1d2c291553ef3f433a0b7109cc3002a5f40ae" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-frr9-gqr3-75hc/GHSA-frr9-gqr3-75hc.json b/advisories/unreviewed/2024/10/GHSA-frr9-gqr3-75hc/GHSA-frr9-gqr3-75hc.json new file mode 100644 index 00000000000..ee6fb36bb59 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-frr9-gqr3-75hc/GHSA-frr9-gqr3-75hc.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-frr9-gqr3-75hc", + "modified": "2024-10-21T18:30:57Z", + "published": "2024-10-21T18:30:57Z", + "aliases": [ + "CVE-2024-49882" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\next4: fix double brelse() the buffer of the extents path\n\nIn ext4_ext_try_to_merge_up(), set path[1].p_bh to NULL after it has been\nreleased, otherwise it may be released twice. An example of what triggers\nthis is as follows:\n\n split2 map split1\n|--------|-------|--------|\n\next4_ext_map_blocks\n ext4_ext_handle_unwritten_extents\n ext4_split_convert_extents\n // path->p_depth == 0\n ext4_split_extent\n // 1. do split1\n ext4_split_extent_at\n |ext4_ext_insert_extent\n | ext4_ext_create_new_leaf\n | ext4_ext_grow_indepth\n | le16_add_cpu(&neh->eh_depth, 1)\n | ext4_find_extent\n | // return -ENOMEM\n |// get error and try zeroout\n |path = ext4_find_extent\n | path->p_depth = 1\n |ext4_ext_try_to_merge\n | ext4_ext_try_to_merge_up\n | path->p_depth = 0\n | brelse(path[1].p_bh) ---> not set to NULL here\n |// zeroout success\n // 2. update path\n ext4_find_extent\n // 3. do split2\n ext4_split_extent_at\n ext4_ext_insert_extent\n ext4_ext_create_new_leaf\n ext4_ext_grow_indepth\n le16_add_cpu(&neh->eh_depth, 1)\n ext4_find_extent\n path[0].p_bh = NULL;\n path->p_depth = 1\n read_extent_tree_block ---> return err\n // path[1].p_bh is still the old value\n ext4_free_ext_path\n ext4_ext_drop_refs\n // path->p_depth == 1\n brelse(path[1].p_bh) ---> brelse a buffer twice\n\nFinally got the following WARRNING when removing the buffer from lru:\n\n============================================\nVFS: brelse: Trying to free free buffer\nWARNING: CPU: 2 PID: 72 at fs/buffer.c:1241 __brelse+0x58/0x90\nCPU: 2 PID: 72 Comm: kworker/u19:1 Not tainted 6.9.0-dirty #716\nRIP: 0010:__brelse+0x58/0x90\nCall Trace:\n \n __find_get_block+0x6e7/0x810\n bdev_getblk+0x2b/0x480\n __ext4_get_inode_loc+0x48a/0x1240\n ext4_get_inode_loc+0xb2/0x150\n ext4_reserve_inode_write+0xb7/0x230\n __ext4_mark_inode_dirty+0x144/0x6a0\n ext4_ext_insert_extent+0x9c8/0x3230\n ext4_ext_map_blocks+0xf45/0x2dc0\n ext4_map_blocks+0x724/0x1700\n ext4_do_writepages+0x12d6/0x2a70\n[...]\n============================================", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49882" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/230ee0535d01478bad9a3037292043f39b9be10b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/32bbb59e3f18facd7201bef110010bf35819b8c3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/68a69cf60660c73990c1875f94a5551600b04775" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7633407ca4ab8be2916ab214eb44ccebc6a50e1a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/78bbc3d15b6f443acb26e94418c445bac940d414" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b6c29c8f3d7cb67b505f3b2f6c242d52298d1f2e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/dcaa6c31134c0f515600111c38ed7750003e1b9c" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-g9fr-wfpx-28xj/GHSA-g9fr-wfpx-28xj.json b/advisories/unreviewed/2024/10/GHSA-g9fr-wfpx-28xj/GHSA-g9fr-wfpx-28xj.json new file mode 100644 index 00000000000..176d07c5339 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-g9fr-wfpx-28xj/GHSA-g9fr-wfpx-28xj.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g9fr-wfpx-28xj", + "modified": "2024-10-21T18:30:59Z", + "published": "2024-10-21T18:30:59Z", + "aliases": [ + "CVE-2024-49982" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\naoe: fix the potential use-after-free problem in more places\n\nFor fixing CVE-2023-6270, f98364e92662 (\"aoe: fix the potential\nuse-after-free problem in aoecmd_cfg_pkts\") makes tx() calling dev_put()\ninstead of doing in aoecmd_cfg_pkts(). It avoids that the tx() runs\ninto use-after-free.\n\nThen Nicolai Stange found more places in aoe have potential use-after-free\nproblem with tx(). e.g. revalidate(), aoecmd_ata_rw(), resend(), probe()\nand aoecmd_cfg_rsp(). Those functions also use aoenet_xmit() to push\npacket to tx queue. So they should also use dev_hold() to increase the\nrefcnt of skb->dev.\n\nOn the other hand, moving dev_put() to tx() causes that the refcnt of\nskb->dev be reduced to a negative value, because corresponding\ndev_hold() are not called in revalidate(), aoecmd_ata_rw(), resend(),\nprobe(), and aoecmd_cfg_rsp(). This patch fixed this issue.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49982" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/07b418d50ccbbca7e5d87a3a0d41d436cefebf79" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6d6e54fc71ad1ab0a87047fd9c211e75d86084a3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8253a60c89ec35c8f36fb2cc08cdf854c7a3eb58" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/89d9a69ae0c667e4d9d028028e2dcc837bae626f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/acc5103a0a8c200a52af7d732c36a8477436a3d3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bc2cbf7525ac288e07d465f5a1d8cb8fb9599254" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f63461af2c1a86af4217910e47a5c46e3372e645" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-g9mh-3crx-2qvf/GHSA-g9mh-3crx-2qvf.json b/advisories/unreviewed/2024/10/GHSA-g9mh-3crx-2qvf/GHSA-g9mh-3crx-2qvf.json new file mode 100644 index 00000000000..b4c4513a4b7 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-g9mh-3crx-2qvf/GHSA-g9mh-3crx-2qvf.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g9mh-3crx-2qvf", + "modified": "2024-10-21T18:30:57Z", + "published": "2024-10-21T18:30:57Z", + "aliases": [ + "CVE-2024-49914" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Add null check for pipe_ctx->plane_state in dcn20_program_pipe\n\nThis commit addresses a null pointer dereference issue in the\n`dcn20_program_pipe` function. The issue could occur when\n`pipe_ctx->plane_state` is null.\n\nThe fix adds a check to ensure `pipe_ctx->plane_state` is not null\nbefore accessing. This prevents a null pointer dereference.\n\nReported by smatch:\ndrivers/gpu/drm/amd/amdgpu/../display/dc/hwss/dcn20/dcn20_hwseq.c:1925 dcn20_program_pipe() error: we previously assumed 'pipe_ctx->plane_state' could be null (see line 1877)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49914" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/65a6fee22d5cfa645cb05489892dc9cd3d142fc2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8e4ed3cf1642df0c4456443d865cff61a9598aa8" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-gcv4-6hmh-xhwc/GHSA-gcv4-6hmh-xhwc.json b/advisories/unreviewed/2024/10/GHSA-gcv4-6hmh-xhwc/GHSA-gcv4-6hmh-xhwc.json new file mode 100644 index 00000000000..f8e8b0578f0 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-gcv4-6hmh-xhwc/GHSA-gcv4-6hmh-xhwc.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gcv4-6hmh-xhwc", + "modified": "2024-10-21T18:30:56Z", + "published": "2024-10-21T18:30:56Z", + "aliases": [ + "CVE-2024-49869" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: send: fix buffer overflow detection when copying path to cache entry\n\nStarting with commit c0247d289e73 (\"btrfs: send: annotate struct\nname_cache_entry with __counted_by()\") we annotated the variable length\narray \"name\" from the name_cache_entry structure with __counted_by() to\nimprove overflow detection. However that alone was not correct, because\nthe length of that array does not match the \"name_len\" field - it matches\nthat plus 1 to include the NUL string terminator, so that makes a\nfortified kernel think there's an overflow and report a splat like this:\n\n strcpy: detected buffer overflow: 20 byte write of buffer size 19\n WARNING: CPU: 3 PID: 3310 at __fortify_report+0x45/0x50\n CPU: 3 UID: 0 PID: 3310 Comm: btrfs Not tainted 6.11.0-prnet #1\n Hardware name: CompuLab Ltd. sbc-ihsw/Intense-PC2 (IPC2), BIOS IPC2_3.330.7 X64 03/15/2018\n RIP: 0010:__fortify_report+0x45/0x50\n Code: 48 8b 34 (...)\n RSP: 0018:ffff97ebc0d6f650 EFLAGS: 00010246\n RAX: 7749924ef60fa600 RBX: ffff8bf5446a521a RCX: 0000000000000027\n RDX: 00000000ffffdfff RSI: ffff97ebc0d6f548 RDI: ffff8bf84e7a1cc8\n RBP: ffff8bf548574080 R08: ffffffffa8c40e10 R09: 0000000000005ffd\n R10: 0000000000000004 R11: ffffffffa8c70e10 R12: ffff8bf551eef400\n R13: 0000000000000000 R14: 0000000000000013 R15: 00000000000003a8\n FS: 00007fae144de8c0(0000) GS:ffff8bf84e780000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 00007fae14691690 CR3: 00000001027a2003 CR4: 00000000001706f0\n Call Trace:\n \n ? __warn+0x12a/0x1d0\n ? __fortify_report+0x45/0x50\n ? report_bug+0x154/0x1c0\n ? handle_bug+0x42/0x70\n ? exc_invalid_op+0x1a/0x50\n ? asm_exc_invalid_op+0x1a/0x20\n ? __fortify_report+0x45/0x50\n __fortify_panic+0x9/0x10\n __get_cur_name_and_parent+0x3bc/0x3c0\n get_cur_path+0x207/0x3b0\n send_extent_data+0x709/0x10d0\n ? find_parent_nodes+0x22df/0x25d0\n ? mas_nomem+0x13/0x90\n ? mtree_insert_range+0xa5/0x110\n ? btrfs_lru_cache_store+0x5f/0x1e0\n ? iterate_extent_inodes+0x52d/0x5a0\n process_extent+0xa96/0x11a0\n ? __pfx_lookup_backref_cache+0x10/0x10\n ? __pfx_store_backref_cache+0x10/0x10\n ? __pfx_iterate_backrefs+0x10/0x10\n ? __pfx_check_extent_item+0x10/0x10\n changed_cb+0x6fa/0x930\n ? tree_advance+0x362/0x390\n ? memcmp_extent_buffer+0xd7/0x160\n send_subvol+0xf0a/0x1520\n btrfs_ioctl_send+0x106b/0x11d0\n ? __pfx___clone_root_cmp_sort+0x10/0x10\n _btrfs_ioctl_send+0x1ac/0x240\n btrfs_ioctl+0x75b/0x850\n __se_sys_ioctl+0xca/0x150\n do_syscall_64+0x85/0x160\n ? __count_memcg_events+0x69/0x100\n ? handle_mm_fault+0x1327/0x15c0\n ? __se_sys_rt_sigprocmask+0xf1/0x180\n ? syscall_exit_to_user_mode+0x75/0xa0\n ? do_syscall_64+0x91/0x160\n ? do_user_addr_fault+0x21d/0x630\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n RIP: 0033:0x7fae145eeb4f\n Code: 00 48 89 (...)\n RSP: 002b:00007ffdf1cb09b0 EFLAGS: 00000246 ORIG_RAX: 0000000000000010\n RAX: ffffffffffffffda RBX: 0000000000000004 RCX: 00007fae145eeb4f\n RDX: 00007ffdf1cb0ad0 RSI: 0000000040489426 RDI: 0000000000000004\n RBP: 00000000000078fe R08: 00007fae144006c0 R09: 00007ffdf1cb0927\n R10: 0000000000000008 R11: 0000000000000246 R12: 00007ffdf1cb1ce8\n R13: 0000000000000003 R14: 000055c499fab2e0 R15: 0000000000000004\n \n\nFix this by not storing the NUL string terminator since we don't actually\nneed it for name cache entries, this way \"name_len\" corresponds to the\nactual size of the \"name\" array. This requires marking the \"name\" array\nfield with __nonstring and using memcpy() instead of strcpy() as\nrecommended by the guidelines at:\n\n https://github.com/KSPP/linux/issues/90", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49869" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/843738ede6cb8b959fb22591fcbabe8b456d7216" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/96c6ca71572a3556ed0c37237305657ff47174b7" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-ggxf-hwrw-c5q2/GHSA-ggxf-hwrw-c5q2.json b/advisories/unreviewed/2024/10/GHSA-ggxf-hwrw-c5q2/GHSA-ggxf-hwrw-c5q2.json new file mode 100644 index 00000000000..a29cb144fa7 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-ggxf-hwrw-c5q2/GHSA-ggxf-hwrw-c5q2.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ggxf-hwrw-c5q2", + "modified": "2024-10-21T18:30:58Z", + "published": "2024-10-21T18:30:58Z", + "aliases": [ + "CVE-2024-49932" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: don't readahead the relocation inode on RST\n\nOn relocation we're doing readahead on the relocation inode, but if the\nfilesystem is backed by a RAID stripe tree we can get ENOENT (e.g. due to\npreallocated extents not being mapped in the RST) from the lookup.\n\nBut readahead doesn't handle the error and submits invalid reads to the\ndevice, causing an assertion in the scatter-gather list code:\n\n BTRFS info (device nvme1n1): balance: start -d -m -s\n BTRFS info (device nvme1n1): relocating block group 6480920576 flags data|raid0\n BTRFS error (device nvme1n1): cannot find raid-stripe for logical [6481928192, 6481969152] devid 2, profile raid0\n ------------[ cut here ]------------\n kernel BUG at include/linux/scatterlist.h:115!\n Oops: invalid opcode: 0000 [#1] PREEMPT SMP PTI\n CPU: 0 PID: 1012 Comm: btrfs Not tainted 6.10.0-rc7+ #567\n RIP: 0010:__blk_rq_map_sg+0x339/0x4a0\n RSP: 0018:ffffc90001a43820 EFLAGS: 00010202\n RAX: 0000000000000000 RBX: 0000000000000000 RCX: ffffea00045d4802\n RDX: 0000000117520000 RSI: 0000000000000000 RDI: ffff8881027d1000\n RBP: 0000000000003000 R08: ffffea00045d4902 R09: 0000000000000000\n R10: 0000000000000000 R11: 0000000000001000 R12: ffff8881003d10b8\n R13: ffffc90001a438f0 R14: 0000000000000000 R15: 0000000000003000\n FS: 00007fcc048a6900(0000) GS:ffff88813bc00000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 000000002cd11000 CR3: 00000001109ea001 CR4: 0000000000370eb0\n Call Trace:\n \n ? __die_body.cold+0x14/0x25\n ? die+0x2e/0x50\n ? do_trap+0xca/0x110\n ? do_error_trap+0x65/0x80\n ? __blk_rq_map_sg+0x339/0x4a0\n ? exc_invalid_op+0x50/0x70\n ? __blk_rq_map_sg+0x339/0x4a0\n ? asm_exc_invalid_op+0x1a/0x20\n ? __blk_rq_map_sg+0x339/0x4a0\n nvme_prep_rq.part.0+0x9d/0x770\n nvme_queue_rq+0x7d/0x1e0\n __blk_mq_issue_directly+0x2a/0x90\n ? blk_mq_get_budget_and_tag+0x61/0x90\n blk_mq_try_issue_list_directly+0x56/0xf0\n blk_mq_flush_plug_list.part.0+0x52b/0x5d0\n __blk_flush_plug+0xc6/0x110\n blk_finish_plug+0x28/0x40\n read_pages+0x160/0x1c0\n page_cache_ra_unbounded+0x109/0x180\n relocate_file_extent_cluster+0x611/0x6a0\n ? btrfs_search_slot+0xba4/0xd20\n ? balance_dirty_pages_ratelimited_flags+0x26/0xb00\n relocate_data_extent.constprop.0+0x134/0x160\n relocate_block_group+0x3f2/0x500\n btrfs_relocate_block_group+0x250/0x430\n btrfs_relocate_chunk+0x3f/0x130\n btrfs_balance+0x71b/0xef0\n ? kmalloc_trace_noprof+0x13b/0x280\n btrfs_ioctl+0x2c2e/0x3030\n ? kvfree_call_rcu+0x1e6/0x340\n ? list_lru_add_obj+0x66/0x80\n ? mntput_no_expire+0x3a/0x220\n __x64_sys_ioctl+0x96/0xc0\n do_syscall_64+0x54/0x110\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n RIP: 0033:0x7fcc04514f9b\n Code: Unable to access opcode bytes at 0x7fcc04514f71.\n RSP: 002b:00007ffeba923370 EFLAGS: 00000246 ORIG_RAX: 0000000000000010\n RAX: ffffffffffffffda RBX: 0000000000000003 RCX: 00007fcc04514f9b\n RDX: 00007ffeba923460 RSI: 00000000c4009420 RDI: 0000000000000003\n RBP: 0000000000000000 R08: 0000000000000013 R09: 0000000000000001\n R10: 00007fcc043fbba8 R11: 0000000000000246 R12: 00007ffeba924fc5\n R13: 00007ffeba923460 R14: 0000000000000002 R15: 00000000004d4bb0\n \n Modules linked in:\n ---[ end trace 0000000000000000 ]---\n RIP: 0010:__blk_rq_map_sg+0x339/0x4a0\n RSP: 0018:ffffc90001a43820 EFLAGS: 00010202\n RAX: 0000000000000000 RBX: 0000000000000000 RCX: ffffea00045d4802\n RDX: 0000000117520000 RSI: 0000000000000000 RDI: ffff8881027d1000\n RBP: 0000000000003000 R08: ffffea00045d4902 R09: 0000000000000000\n R10: 0000000000000000 R11: 0000000000001000 R12: ffff8881003d10b8\n R13: ffffc90001a438f0 R14: 0000000000000000 R15: 0000000000003000\n FS: 00007fcc048a6900(0000) GS:ffff88813bc00000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 00007fcc04514f71 CR3: 00000001109ea001 CR4: 0000000000370eb0\n Kernel p\n---truncated---", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49932" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/04915240e2c3a018e4c7f23418478d27226c8957" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f7a1218a983ab98aba140dc20b25f60b39ee4033" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-gj49-2hq5-g5h7/GHSA-gj49-2hq5-g5h7.json b/advisories/unreviewed/2024/10/GHSA-gj49-2hq5-g5h7/GHSA-gj49-2hq5-g5h7.json new file mode 100644 index 00000000000..72a3e4bc9d4 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-gj49-2hq5-g5h7/GHSA-gj49-2hq5-g5h7.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gj49-2hq5-g5h7", + "modified": "2024-10-21T18:30:59Z", + "published": "2024-10-21T18:30:59Z", + "aliases": [ + "CVE-2024-49991" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdkfd: amdkfd_free_gtt_mem clear the correct pointer\n\nPass pointer reference to amdgpu_bo_unref to clear the correct pointer,\notherwise amdgpu_bo_unref clear the local variable, the original pointer\nnot set to NULL, this could cause use-after-free bug.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49991" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/30ceb873cc2e97348d9da2265b2d1ddf07f682e1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6c9289806591807e4e3be9a23df8ee2069180055" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/71f3240f82987f0f070ea5bed559033de7d4c0e1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c86ad39140bbcb9dc75a10046c2221f657e8083b" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-gr6g-pg36-368m/GHSA-gr6g-pg36-368m.json b/advisories/unreviewed/2024/10/GHSA-gr6g-pg36-368m/GHSA-gr6g-pg36-368m.json new file mode 100644 index 00000000000..9385f86fdb4 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-gr6g-pg36-368m/GHSA-gr6g-pg36-368m.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gr6g-pg36-368m", + "modified": "2024-10-21T18:30:57Z", + "published": "2024-10-21T18:30:57Z", + "aliases": [ + "CVE-2024-49884" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\next4: fix slab-use-after-free in ext4_split_extent_at()\n\nWe hit the following use-after-free:\n\n==================================================================\nBUG: KASAN: slab-use-after-free in ext4_split_extent_at+0xba8/0xcc0\nRead of size 2 at addr ffff88810548ed08 by task kworker/u20:0/40\nCPU: 0 PID: 40 Comm: kworker/u20:0 Not tainted 6.9.0-dirty #724\nCall Trace:\n \n kasan_report+0x93/0xc0\n ext4_split_extent_at+0xba8/0xcc0\n ext4_split_extent.isra.0+0x18f/0x500\n ext4_split_convert_extents+0x275/0x750\n ext4_ext_handle_unwritten_extents+0x73e/0x1580\n ext4_ext_map_blocks+0xe20/0x2dc0\n ext4_map_blocks+0x724/0x1700\n ext4_do_writepages+0x12d6/0x2a70\n[...]\n\nAllocated by task 40:\n __kmalloc_noprof+0x1ac/0x480\n ext4_find_extent+0xf3b/0x1e70\n ext4_ext_map_blocks+0x188/0x2dc0\n ext4_map_blocks+0x724/0x1700\n ext4_do_writepages+0x12d6/0x2a70\n[...]\n\nFreed by task 40:\n kfree+0xf1/0x2b0\n ext4_find_extent+0xa71/0x1e70\n ext4_ext_insert_extent+0xa22/0x3260\n ext4_split_extent_at+0x3ef/0xcc0\n ext4_split_extent.isra.0+0x18f/0x500\n ext4_split_convert_extents+0x275/0x750\n ext4_ext_handle_unwritten_extents+0x73e/0x1580\n ext4_ext_map_blocks+0xe20/0x2dc0\n ext4_map_blocks+0x724/0x1700\n ext4_do_writepages+0x12d6/0x2a70\n[...]\n==================================================================\n\nThe flow of issue triggering is as follows:\n\next4_split_extent_at\n path = *ppath\n ext4_ext_insert_extent(ppath)\n ext4_ext_create_new_leaf(ppath)\n ext4_find_extent(orig_path)\n path = *orig_path\n read_extent_tree_block\n // return -ENOMEM or -EIO\n ext4_free_ext_path(path)\n kfree(path)\n *orig_path = NULL\n a. If err is -ENOMEM:\n ext4_ext_dirty(path + path->p_depth)\n // path use-after-free !!!\n b. If err is -EIO and we have EXT_DEBUG defined:\n ext4_ext_show_leaf(path)\n eh = path[depth].p_hdr\n // path also use-after-free !!!\n\nSo when trying to zeroout or fix the extent length, call ext4_find_extent()\nto update the path.\n\nIn addition we use *ppath directly as an ext4_ext_show_leaf() input to\navoid possible use-after-free when EXT_DEBUG is defined, and to avoid\nunnecessary path updates.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49884" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5d949ea75bb529ea6342e83465938a3b0ac51238" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8fe117790b37c84c651e2bad9efc0e7fda73c0e3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/915ac3630488af0ca194dc63b86d99802b4f6e18" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a5401d4c3e2a3d25643c567d26e6de327774a2c9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c26ab35702f8cd0cdc78f96aa5856bfb77be798f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cafcc1bd62934547c76abf46c6d0d54f135006fe" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e52f933598b781d291b9297e39c463536da0e185" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-gxhw-gx89-g9ch/GHSA-gxhw-gx89-g9ch.json b/advisories/unreviewed/2024/10/GHSA-gxhw-gx89-g9ch/GHSA-gxhw-gx89-g9ch.json index da4ea4e813e..670cf2f046a 100644 --- a/advisories/unreviewed/2024/10/GHSA-gxhw-gx89-g9ch/GHSA-gxhw-gx89-g9ch.json +++ b/advisories/unreviewed/2024/10/GHSA-gxhw-gx89-g9ch/GHSA-gxhw-gx89-g9ch.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gxhw-gx89-g9ch", - "modified": "2024-10-16T18:31:47Z", + "modified": "2024-10-21T18:30:46Z", "published": "2024-10-16T18:31:47Z", "aliases": [ "CVE-2024-4692" ], "details": "Improper Validation of Specified Quantity in Input vulnerability in OpenText OpenText Application Automation Tools allows Exploiting Incorrectly Configured Access Control Security Levels.\n\n\nMultiple missing permission checks - Service Virtualization config has been discovered in in OpenText Application Automation Tools. The vulnerability could allow users with Overall/Read permission to enumerate Service Virtualization server names.\n\nThis issue affects OpenText Application Automation Tools: 24.1.0 and below.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:X/V:X/RE:L/U:Clear" diff --git a/advisories/unreviewed/2024/10/GHSA-h72j-469c-c787/GHSA-h72j-469c-c787.json b/advisories/unreviewed/2024/10/GHSA-h72j-469c-c787/GHSA-h72j-469c-c787.json new file mode 100644 index 00000000000..417e05cb6d1 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-h72j-469c-c787/GHSA-h72j-469c-c787.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h72j-469c-c787", + "modified": "2024-10-21T18:30:59Z", + "published": "2024-10-21T18:30:59Z", + "aliases": [ + "CVE-2024-49980" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nvrf: revert \"vrf: Remove unnecessary RCU-bh critical section\"\n\nThis reverts commit 504fc6f4f7f681d2a03aa5f68aad549d90eab853.\n\ndev_queue_xmit_nit is expected to be called with BH disabled.\n__dev_queue_xmit has the following:\n\n /* Disable soft irqs for various locks below. Also\n * stops preemption for RCU.\n */\n rcu_read_lock_bh();\n\nVRF must follow this invariant. The referenced commit removed this\nprotection. Which triggered a lockdep warning:\n\n\t================================\n\tWARNING: inconsistent lock state\n\t6.11.0 #1 Tainted: G W\n\t--------------------------------\n\tinconsistent {IN-SOFTIRQ-W} -> {SOFTIRQ-ON-W} usage.\n\tbtserver/134819 [HC0[0]:SC0[0]:HE1:SE1] takes:\n\tffff8882da30c118 (rlock-AF_PACKET){+.?.}-{2:2}, at: tpacket_rcv+0x863/0x3b30\n\t{IN-SOFTIRQ-W} state was registered at:\n\t lock_acquire+0x19a/0x4f0\n\t _raw_spin_lock+0x27/0x40\n\t packet_rcv+0xa33/0x1320\n\t __netif_receive_skb_core.constprop.0+0xcb0/0x3a90\n\t __netif_receive_skb_list_core+0x2c9/0x890\n\t netif_receive_skb_list_internal+0x610/0xcc0\n [...]\n\n\tother info that might help us debug this:\n\t Possible unsafe locking scenario:\n\n\t CPU0\n\t ----\n\t lock(rlock-AF_PACKET);\n\t \n\t lock(rlock-AF_PACKET);\n\n\t *** DEADLOCK ***\n\n\tCall Trace:\n\t \n\t dump_stack_lvl+0x73/0xa0\n\t mark_lock+0x102e/0x16b0\n\t __lock_acquire+0x9ae/0x6170\n\t lock_acquire+0x19a/0x4f0\n\t _raw_spin_lock+0x27/0x40\n\t tpacket_rcv+0x863/0x3b30\n\t dev_queue_xmit_nit+0x709/0xa40\n\t vrf_finish_direct+0x26e/0x340 [vrf]\n\t vrf_l3_out+0x5f4/0xe80 [vrf]\n\t __ip_local_out+0x51e/0x7a0\n [...]", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49980" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/718a752bd746b3f4dd62516bb437baf73d548415" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8c9381b3138246d46536db93ed696832abd70204" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b04c4d9eb4f25b950b33218e33b04c94e7445e51" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e61f8c4d179b2ffc0d3b7f821c3734be738643d0" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-h7p9-f9r3-6533/GHSA-h7p9-f9r3-6533.json b/advisories/unreviewed/2024/10/GHSA-h7p9-f9r3-6533/GHSA-h7p9-f9r3-6533.json new file mode 100644 index 00000000000..1f3ff2ab790 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-h7p9-f9r3-6533/GHSA-h7p9-f9r3-6533.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h7p9-f9r3-6533", + "modified": "2024-10-21T18:30:56Z", + "published": "2024-10-21T18:30:56Z", + "aliases": [ + "CVE-2024-49867" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: wait for fixup workers before stopping cleaner kthread during umount\n\nDuring unmount, at close_ctree(), we have the following steps in this order:\n\n1) Park the cleaner kthread - this doesn't destroy the kthread, it basically\n halts its execution (wake ups against it work but do nothing);\n\n2) We stop the cleaner kthread - this results in freeing the respective\n struct task_struct;\n\n3) We call btrfs_stop_all_workers() which waits for any jobs running in all\n the work queues and then free the work queues.\n\nSyzbot reported a case where a fixup worker resulted in a crash when doing\na delayed iput on its inode while attempting to wake up the cleaner at\nbtrfs_add_delayed_iput(), because the task_struct of the cleaner kthread\nwas already freed. This can happen during unmount because we don't wait\nfor any fixup workers still running before we call kthread_stop() against\nthe cleaner kthread, which stops and free all its resources.\n\nFix this by waiting for any fixup workers at close_ctree() before we call\nkthread_stop() against the cleaner and run pending delayed iputs.\n\nThe stack traces reported by syzbot were the following:\n\n BUG: KASAN: slab-use-after-free in __lock_acquire+0x77/0x2050 kernel/locking/lockdep.c:5065\n Read of size 8 at addr ffff8880272a8a18 by task kworker/u8:3/52\n\n CPU: 1 UID: 0 PID: 52 Comm: kworker/u8:3 Not tainted 6.12.0-rc1-syzkaller #0\n Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024\n Workqueue: btrfs-fixup btrfs_work_helper\n Call Trace:\n \n __dump_stack lib/dump_stack.c:94 [inline]\n dump_stack_lvl+0x241/0x360 lib/dump_stack.c:120\n print_address_description mm/kasan/report.c:377 [inline]\n print_report+0x169/0x550 mm/kasan/report.c:488\n kasan_report+0x143/0x180 mm/kasan/report.c:601\n __lock_acquire+0x77/0x2050 kernel/locking/lockdep.c:5065\n lock_acquire+0x1ed/0x550 kernel/locking/lockdep.c:5825\n __raw_spin_lock_irqsave include/linux/spinlock_api_smp.h:110 [inline]\n _raw_spin_lock_irqsave+0xd5/0x120 kernel/locking/spinlock.c:162\n class_raw_spinlock_irqsave_constructor include/linux/spinlock.h:551 [inline]\n try_to_wake_up+0xb0/0x1480 kernel/sched/core.c:4154\n btrfs_writepage_fixup_worker+0xc16/0xdf0 fs/btrfs/inode.c:2842\n btrfs_work_helper+0x390/0xc50 fs/btrfs/async-thread.c:314\n process_one_work kernel/workqueue.c:3229 [inline]\n process_scheduled_works+0xa63/0x1850 kernel/workqueue.c:3310\n worker_thread+0x870/0xd30 kernel/workqueue.c:3391\n kthread+0x2f0/0x390 kernel/kthread.c:389\n ret_from_fork+0x4b/0x80 arch/x86/kernel/process.c:147\n ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:244\n \n\n Allocated by task 2:\n kasan_save_stack mm/kasan/common.c:47 [inline]\n kasan_save_track+0x3f/0x80 mm/kasan/common.c:68\n unpoison_slab_object mm/kasan/common.c:319 [inline]\n __kasan_slab_alloc+0x66/0x80 mm/kasan/common.c:345\n kasan_slab_alloc include/linux/kasan.h:247 [inline]\n slab_post_alloc_hook mm/slub.c:4086 [inline]\n slab_alloc_node mm/slub.c:4135 [inline]\n kmem_cache_alloc_node_noprof+0x16b/0x320 mm/slub.c:4187\n alloc_task_struct_node kernel/fork.c:180 [inline]\n dup_task_struct+0x57/0x8c0 kernel/fork.c:1107\n copy_process+0x5d1/0x3d50 kernel/fork.c:2206\n kernel_clone+0x223/0x880 kernel/fork.c:2787\n kernel_thread+0x1bc/0x240 kernel/fork.c:2849\n create_kthread kernel/kthread.c:412 [inline]\n kthreadd+0x60d/0x810 kernel/kthread.c:765\n ret_from_fork+0x4b/0x80 arch/x86/kernel/process.c:147\n ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:244\n\n Freed by task 61:\n kasan_save_stack mm/kasan/common.c:47 [inline]\n kasan_save_track+0x3f/0x80 mm/kasan/common.c:68\n kasan_save_free_info+0x40/0x50 mm/kasan/generic.c:579\n poison_slab_object mm/kasan/common.c:247 [inline]\n __kasan_slab_free+0x59/0x70 mm/kasan/common.c:264\n kasan_slab_free include/linux/kasan.h:230 [inline]\n slab_free_h\n---truncated---", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49867" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/41fd1e94066a815a7ab0a7025359e9b40e4b3576" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4c98fe0dfa2ae83c4631699695506d8941db4bfe" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/65d11eb276836d49003a8060cf31fa2284ad1047" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/70b60c8d9b42763d6629e44f448aa5d8ae477d61" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9da40aea63f8769f28afb91aea0fac4cf6fbbb65" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bf0de0f9a0544c11f96f93206da04ab87dcea1f4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ed87190e9d9c80aad220fb6b0b03a84d22e2c95b" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-h7r9-ffqq-5r47/GHSA-h7r9-ffqq-5r47.json b/advisories/unreviewed/2024/10/GHSA-h7r9-ffqq-5r47/GHSA-h7r9-ffqq-5r47.json new file mode 100644 index 00000000000..fdc65791fdb --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-h7r9-ffqq-5r47/GHSA-h7r9-ffqq-5r47.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h7r9-ffqq-5r47", + "modified": "2024-10-21T18:30:58Z", + "published": "2024-10-21T18:30:58Z", + "aliases": [ + "CVE-2024-49925" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfbdev: efifb: Register sysfs groups through driver core\n\nThe driver core can register and cleanup sysfs groups already.\nMake use of that functionality to simplify the error handling and\ncleanup.\n\nAlso avoid a UAF race during unregistering where the sysctl attributes\nwere usable after the info struct was freed.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49925" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/36bfefb6baaa8e46de44f4fd919ce4347337620f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4684d69b9670a83992189f6271dc0fcdec4ed0d7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/872cd2d029d2c970a8a1eea88b48dab2b3f2e93a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/95cdd538e0e5677efbdf8aade04ec098ab98f457" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-h9jc-p2cr-c4rx/GHSA-h9jc-p2cr-c4rx.json b/advisories/unreviewed/2024/10/GHSA-h9jc-p2cr-c4rx/GHSA-h9jc-p2cr-c4rx.json new file mode 100644 index 00000000000..b14bac35456 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-h9jc-p2cr-c4rx/GHSA-h9jc-p2cr-c4rx.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h9jc-p2cr-c4rx", + "modified": "2024-10-21T18:30:58Z", + "published": "2024-10-21T18:30:58Z", + "aliases": [ + "CVE-2024-49940" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nl2tp: prevent possible tunnel refcount underflow\n\nWhen a session is created, it sets a backpointer to its tunnel. When\nthe session refcount drops to 0, l2tp_session_free drops the tunnel\nrefcount if session->tunnel is non-NULL. However, session->tunnel is\nset in l2tp_session_create, before the tunnel refcount is incremented\nby l2tp_session_register, which leaves a small window where\nsession->tunnel is non-NULL when the tunnel refcount hasn't been\nbumped.\n\nMoving the assignment to l2tp_session_register is trivial but\nl2tp_session_create calls l2tp_session_set_header_len which uses\nsession->tunnel to get the tunnel's encap. Add an encap arg to\nl2tp_session_set_header_len to avoid using session->tunnel.\n\nIf l2tpv3 sessions have colliding IDs, it is possible for\nl2tp_v3_session_get to race with l2tp_session_register and fetch a\nsession which doesn't yet have session->tunnel set. Add a check for\nthis case.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49940" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/24256415d18695b46da06c93135f5b51c548b950" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f7415e60c25a6108cd7955a20b2e66b6251ffe02" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-h9pq-rfrf-6f7p/GHSA-h9pq-rfrf-6f7p.json b/advisories/unreviewed/2024/10/GHSA-h9pq-rfrf-6f7p/GHSA-h9pq-rfrf-6f7p.json new file mode 100644 index 00000000000..0149801d01d --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-h9pq-rfrf-6f7p/GHSA-h9pq-rfrf-6f7p.json @@ -0,0 +1,55 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h9pq-rfrf-6f7p", + "modified": "2024-10-21T18:30:57Z", + "published": "2024-10-21T18:30:57Z", + "aliases": [ + "CVE-2024-49886" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86: ISST: Fix the KASAN report slab-out-of-bounds bug\n\nAttaching SST PCI device to VM causes \"BUG: KASAN: slab-out-of-bounds\".\nkasan report:\n[ 19.411889] ==================================================================\n[ 19.413702] BUG: KASAN: slab-out-of-bounds in _isst_if_get_pci_dev+0x3d5/0x400 [isst_if_common]\n[ 19.415634] Read of size 8 at addr ffff888829e65200 by task cpuhp/16/113\n[ 19.417368]\n[ 19.418627] CPU: 16 PID: 113 Comm: cpuhp/16 Tainted: G E 6.9.0 #10\n[ 19.420435] Hardware name: VMware, Inc. VMware20,1/440BX Desktop Reference Platform, BIOS VMW201.00V.20192059.B64.2207280713 07/28/2022\n[ 19.422687] Call Trace:\n[ 19.424091] \n[ 19.425448] dump_stack_lvl+0x5d/0x80\n[ 19.426963] ? _isst_if_get_pci_dev+0x3d5/0x400 [isst_if_common]\n[ 19.428694] print_report+0x19d/0x52e\n[ 19.430206] ? __pfx__raw_spin_lock_irqsave+0x10/0x10\n[ 19.431837] ? _isst_if_get_pci_dev+0x3d5/0x400 [isst_if_common]\n[ 19.433539] kasan_report+0xf0/0x170\n[ 19.435019] ? _isst_if_get_pci_dev+0x3d5/0x400 [isst_if_common]\n[ 19.436709] _isst_if_get_pci_dev+0x3d5/0x400 [isst_if_common]\n[ 19.438379] ? __pfx_sched_clock_cpu+0x10/0x10\n[ 19.439910] isst_if_cpu_online+0x406/0x58f [isst_if_common]\n[ 19.441573] ? __pfx_isst_if_cpu_online+0x10/0x10 [isst_if_common]\n[ 19.443263] ? ttwu_queue_wakelist+0x2c1/0x360\n[ 19.444797] cpuhp_invoke_callback+0x221/0xec0\n[ 19.446337] cpuhp_thread_fun+0x21b/0x610\n[ 19.447814] ? __pfx_cpuhp_thread_fun+0x10/0x10\n[ 19.449354] smpboot_thread_fn+0x2e7/0x6e0\n[ 19.450859] ? __pfx_smpboot_thread_fn+0x10/0x10\n[ 19.452405] kthread+0x29c/0x350\n[ 19.453817] ? __pfx_kthread+0x10/0x10\n[ 19.455253] ret_from_fork+0x31/0x70\n[ 19.456685] ? __pfx_kthread+0x10/0x10\n[ 19.458114] ret_from_fork_asm+0x1a/0x30\n[ 19.459573] \n[ 19.460853]\n[ 19.462055] Allocated by task 1198:\n[ 19.463410] kasan_save_stack+0x30/0x50\n[ 19.464788] kasan_save_track+0x14/0x30\n[ 19.466139] __kasan_kmalloc+0xaa/0xb0\n[ 19.467465] __kmalloc+0x1cd/0x470\n[ 19.468748] isst_if_cdev_register+0x1da/0x350 [isst_if_common]\n[ 19.470233] isst_if_mbox_init+0x108/0xff0 [isst_if_mbox_msr]\n[ 19.471670] do_one_initcall+0xa4/0x380\n[ 19.472903] do_init_module+0x238/0x760\n[ 19.474105] load_module+0x5239/0x6f00\n[ 19.475285] init_module_from_file+0xd1/0x130\n[ 19.476506] idempotent_init_module+0x23b/0x650\n[ 19.477725] __x64_sys_finit_module+0xbe/0x130\n[ 19.476506] idempotent_init_module+0x23b/0x650\n[ 19.477725] __x64_sys_finit_module+0xbe/0x130\n[ 19.478920] do_syscall_64+0x82/0x160\n[ 19.480036] entry_SYSCALL_64_after_hwframe+0x76/0x7e\n[ 19.481292]\n[ 19.482205] The buggy address belongs to the object at ffff888829e65000\n which belongs to the cache kmalloc-512 of size 512\n[ 19.484818] The buggy address is located 0 bytes to the right of\n allocated 512-byte region [ffff888829e65000, ffff888829e65200)\n[ 19.487447]\n[ 19.488328] The buggy address belongs to the physical page:\n[ 19.489569] page: refcount:1 mapcount:0 mapping:0000000000000000 index:0xffff888829e60c00 pfn:0x829e60\n[ 19.491140] head: order:3 entire_mapcount:0 nr_pages_mapped:0 pincount:0\n[ 19.492466] anon flags: 0x57ffffc0000840(slab|head|node=1|zone=2|lastcpupid=0x1fffff)\n[ 19.493914] page_type: 0xffffffff()\n[ 19.494988] raw: 0057ffffc0000840 ffff88810004cc80 0000000000000000 0000000000000001\n[ 19.496451] raw: ffff888829e60c00 0000000080200018 00000001ffffffff 0000000000000000\n[ 19.497906] head: 0057ffffc0000840 ffff88810004cc80 0000000000000000 0000000000000001\n[ 19.499379] head: ffff888829e60c00 0000000080200018 00000001ffffffff 0000000000000000\n[ 19.500844] head: 0057ffffc0000003 ffffea0020a79801 ffffea0020a79848 00000000ffffffff\n[ 19.502316] head: 0000000800000000 0000000000000000 00000000ffffffff 0000000000000000\n[ 19.503784] page dumped because: k\n---truncated---", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49886" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1973c4d8ee0782a808303d75e3be9c12baaacd97" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7d59ac07ccb58f8f604f8057db63b8efcebeb3de" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8176d4878ed2af5d93ddd0e971e24c412124d38b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/afa7f78d9a907cfded6c98c91aae2bf7b3b56e51" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cdd03afcb6eda3103da5a0948d3db12372f62910" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cebc705b097d5c16469b141a25e840161d1c517a" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-hm9p-89r4-c9g7/GHSA-hm9p-89r4-c9g7.json b/advisories/unreviewed/2024/10/GHSA-hm9p-89r4-c9g7/GHSA-hm9p-89r4-c9g7.json index f1e1edbb3ce..62dedac19f5 100644 --- a/advisories/unreviewed/2024/10/GHSA-hm9p-89r4-c9g7/GHSA-hm9p-89r4-c9g7.json +++ b/advisories/unreviewed/2024/10/GHSA-hm9p-89r4-c9g7/GHSA-hm9p-89r4-c9g7.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hm9p-89r4-c9g7", - "modified": "2024-10-18T09:31:25Z", + "modified": "2024-10-21T18:30:46Z", "published": "2024-10-18T09:31:25Z", "aliases": [ "CVE-2023-6057" ], "details": "A vulnerability has been discovered in Bitdefender Total Security HTTPS scanning functionality that results in the improper trust of certificates issued using the DSA signature algorithm. The product does not properly check the certificate chain, allowing an attacker to establish MITM SSL connections to arbitrary sites using a DSA-signed certificate.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2024/10/GHSA-hpqg-3xxv-rhj6/GHSA-hpqg-3xxv-rhj6.json b/advisories/unreviewed/2024/10/GHSA-hpqg-3xxv-rhj6/GHSA-hpqg-3xxv-rhj6.json new file mode 100644 index 00000000000..94f20a937a2 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-hpqg-3xxv-rhj6/GHSA-hpqg-3xxv-rhj6.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hpqg-3xxv-rhj6", + "modified": "2024-10-21T18:30:58Z", + "published": "2024-10-21T18:30:58Z", + "aliases": [ + "CVE-2024-49938" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath9k_htc: Use __skb_set_length() for resetting urb before resubmit\n\nSyzbot points out that skb_trim() has a sanity check on the existing length of\nthe skb, which can be uninitialised in some error paths. The intent here is\nclearly just to reset the length to zero before resubmitting, so switch to\ncalling __skb_set_length(skb, 0) directly. In addition, __skb_set_length()\nalready contains a call to skb_reset_tail_pointer(), so remove the redundant\ncall.\n\nThe syzbot report came from ath9k_hif_usb_reg_in_cb(), but there's a similar\nusage of skb_trim() in ath9k_hif_usb_rx_cb(), change both while we're at it.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49938" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/012ae530afa0785102360de452745d33c99a321b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2c230210ec0ae6ed08306ac70dc21c24b817bb95" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6a875220670475d9247e576c15dc29823100a4e4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/94745807f3ebd379f23865e6dab196f220664179" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a9f4e28e8adaf0715bd4e01462af0a52ee46b01f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b02eb7c86ff2ef1411c3095ec8a52b13f68db04f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e37e348835032d6940ec89308cc8996ded691d2d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-hr6h-7jqj-mx8j/GHSA-hr6h-7jqj-mx8j.json b/advisories/unreviewed/2024/10/GHSA-hr6h-7jqj-mx8j/GHSA-hr6h-7jqj-mx8j.json new file mode 100644 index 00000000000..7ff6988774d --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-hr6h-7jqj-mx8j/GHSA-hr6h-7jqj-mx8j.json @@ -0,0 +1,55 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hr6h-7jqj-mx8j", + "modified": "2024-10-21T18:30:58Z", + "published": "2024-10-21T18:30:58Z", + "aliases": [ + "CVE-2024-49954" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nstatic_call: Replace pointless WARN_ON() in static_call_module_notify()\n\nstatic_call_module_notify() triggers a WARN_ON(), when memory allocation\nfails in __static_call_add_module().\n\nThat's not really justified, because the failure case must be correctly\nhandled by the well known call chain and the error code is passed\nthrough to the initiating userspace application.\n\nA memory allocation fail is not a fatal problem, but the WARN_ON() takes\nthe machine out when panic_on_warn is set.\n\nReplace it with a pr_warn().", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49954" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/85a104aaef1f56623acc10ba4c42d5f046ba65b7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b83bef74c121a3311240fc4002d23486b85355e4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bc9356513d56b688775497b7ac6f2b967f46a80c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e67534bd31d79952b50e791e92adf0b3e6c13b8c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ea2cdf4da093d0482f0ef36ba971e2e0c7673425" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fe513c2ef0a172a58f158e2e70465c4317f0a9a2" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-hxxw-vvrc-qrx3/GHSA-hxxw-vvrc-qrx3.json b/advisories/unreviewed/2024/10/GHSA-hxxw-vvrc-qrx3/GHSA-hxxw-vvrc-qrx3.json new file mode 100644 index 00000000000..b8e49f4b681 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-hxxw-vvrc-qrx3/GHSA-hxxw-vvrc-qrx3.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hxxw-vvrc-qrx3", + "modified": "2024-10-21T18:30:59Z", + "published": "2024-10-21T18:30:59Z", + "aliases": [ + "CVE-2024-49969" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Fix index out of bounds in DCN30 color transformation\n\nThis commit addresses a potential index out of bounds issue in the\n`cm3_helper_translate_curve_to_hw_format` function in the DCN30 color\nmanagement module. The issue could occur when the index 'i' exceeds the\nnumber of transfer function points (TRANSFER_FUNC_POINTS).\n\nThe fix adds a check to ensure 'i' is within bounds before accessing the\ntransfer function points. If 'i' is out of bounds, the function returns\nfalse to indicate an error.\n\ndrivers/gpu/drm/amd/amdgpu/../display/dc/dcn30/dcn30_cm_common.c:180 cm3_helper_translate_curve_to_hw_format() error: buffer overflow 'output_tf->tf_pts.red' 1025 <= s32max\ndrivers/gpu/drm/amd/amdgpu/../display/dc/dcn30/dcn30_cm_common.c:181 cm3_helper_translate_curve_to_hw_format() error: buffer overflow 'output_tf->tf_pts.green' 1025 <= s32max\ndrivers/gpu/drm/amd/amdgpu/../display/dc/dcn30/dcn30_cm_common.c:182 cm3_helper_translate_curve_to_hw_format() error: buffer overflow 'output_tf->tf_pts.blue' 1025 <= s32max", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49969" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0f1e222a4b41d77c442901d166fbdca967af0d86" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/578422ddae3d13362b64e77ef9bab98780641631" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7ab69af56a23859b647dee69fa1052c689343621" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/929506d5671419cffd8d01e9a7f5eae53682a838" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b9d8b94ec7e67f0cae228c054f77b73967c389a3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c13f9c62015c56a938304cef6d507227ea3e0039" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d81873f9e715b72d4f8d391c8eb243946f784dfc" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-j2cc-c4fg-77cq/GHSA-j2cc-c4fg-77cq.json b/advisories/unreviewed/2024/10/GHSA-j2cc-c4fg-77cq/GHSA-j2cc-c4fg-77cq.json new file mode 100644 index 00000000000..76c867f963f --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-j2cc-c4fg-77cq/GHSA-j2cc-c4fg-77cq.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j2cc-c4fg-77cq", + "modified": "2024-10-21T18:30:56Z", + "published": "2024-10-21T18:30:56Z", + "aliases": [ + "CVE-2024-49873" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/filemap: fix filemap_get_folios_contig THP panic\n\nPatch series \"memfd-pin huge page fixes\".\n\nFix multiple bugs that occur when using memfd_pin_folios with hugetlb\npages and THP. The hugetlb bugs only bite when the page is not yet\nfaulted in when memfd_pin_folios is called. The THP bug bites when the\nstarting offset passed to memfd_pin_folios is not huge page aligned. See\nthe commit messages for details.\n\n\nThis patch (of 5):\n\nmemfd_pin_folios on memory backed by THP panics if the requested start\noffset is not huge page aligned:\n\nBUG: kernel NULL pointer dereference, address: 0000000000000036\nRIP: 0010:filemap_get_folios_contig+0xdf/0x290\nRSP: 0018:ffffc9002092fbe8 EFLAGS: 00010202\nRAX: 0000000000000002 RBX: 0000000000000002 RCX: 0000000000000002\n\nThe fault occurs here, because xas_load returns a folio with value 2:\n\n filemap_get_folios_contig()\n for (folio = xas_load(&xas); folio && xas.xa_index <= end;\n folio = xas_next(&xas)) {\n ...\n if (!folio_try_get(folio)) <-- BOOM\n\n\"2\" is an xarray sibling entry. We get it because memfd_pin_folios does\nnot round the indices passed to filemap_get_folios_contig to huge page\nboundaries for THP, so we load from the middle of a huge page range see a\nsibling. (It does round for hugetlbfs, at the is_file_hugepages test).\n\nTo fix, if the folio is a sibling, then return the next index as the\nstarting point for the next call to filemap_get_folios_contig.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49873" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/570dd14bfecf281fa467c80f8ec92b26370ee36a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c225c4f6056b46a8a5bf2ed35abf17a2d6887691" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-j4xv-h5fv-6v4m/GHSA-j4xv-h5fv-6v4m.json b/advisories/unreviewed/2024/10/GHSA-j4xv-h5fv-6v4m/GHSA-j4xv-h5fv-6v4m.json new file mode 100644 index 00000000000..c5e1a9489fe --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-j4xv-h5fv-6v4m/GHSA-j4xv-h5fv-6v4m.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j4xv-h5fv-6v4m", + "modified": "2024-10-21T18:30:59Z", + "published": "2024-10-21T18:30:59Z", + "aliases": [ + "CVE-2024-49979" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: gso: fix tcp fraglist segmentation after pull from frag_list\n\nDetect tcp gso fraglist skbs with corrupted geometry (see below) and\npass these to skb_segment instead of skb_segment_list, as the first\ncan segment them correctly.\n\nValid SKB_GSO_FRAGLIST skbs\n- consist of two or more segments\n- the head_skb holds the protocol headers plus first gso_size\n- one or more frag_list skbs hold exactly one segment\n- all but the last must be gso_size\n\nOptional datapath hooks such as NAT and BPF (bpf_skb_pull_data) can\nmodify these skbs, breaking these invariants.\n\nIn extreme cases they pull all data into skb linear. For TCP, this\ncauses a NULL ptr deref in __tcpv4_gso_segment_list_csum at\ntcp_hdr(seg->next).\n\nDetect invalid geometry due to pull, by checking head_skb size.\nDon't just drop, as this may blackhole a destination. Convert to be\nable to pass to regular skb_segment.\n\nApproach and description based on a patch by Willem de Bruijn.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49979" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/17bd3bd82f9f79f3feba15476c2b2c95a9b11ff8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2d4a83a44428de45bfe9dccb0192a3711d1097e0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3fdd8c83e83fa5e82f1b5585245c51e0355c9f46" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-j994-f74j-cwf3/GHSA-j994-f74j-cwf3.json b/advisories/unreviewed/2024/10/GHSA-j994-f74j-cwf3/GHSA-j994-f74j-cwf3.json new file mode 100644 index 00000000000..311edfb0570 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-j994-f74j-cwf3/GHSA-j994-f74j-cwf3.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j994-f74j-cwf3", + "modified": "2024-10-21T18:30:56Z", + "published": "2024-10-21T18:30:56Z", + "aliases": [ + "CVE-2024-49876" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe: fix UAF around queue destruction\n\nWe currently do stuff like queuing the final destruction step on a\nrandom system wq, which will outlive the driver instance. With bad\ntiming we can teardown the driver with one or more work workqueue still\nbeing alive leading to various UAF splats. Add a fini step to ensure\nuser queues are properly torn down. At this point GuC should already be\nnuked so queue itself should no longer be referenced from hw pov.\n\nv2 (Matt B)\n - Looks much safer to use a waitqueue and then just wait for the\n xa_array to become empty before triggering the drain.\n\n(cherry picked from commit 861108666cc0e999cffeab6aff17b662e68774e3)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49876" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/272b0e78874586d6ccae04079d75b27b47705544" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2d2be279f1ca9e7288282d4214f16eea8a727cdb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/421c74670b0f9d5c007f1276d3647aa58f407fde" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-jmxw-f4w9-294j/GHSA-jmxw-f4w9-294j.json b/advisories/unreviewed/2024/10/GHSA-jmxw-f4w9-294j/GHSA-jmxw-f4w9-294j.json new file mode 100644 index 00000000000..537006072ff --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-jmxw-f4w9-294j/GHSA-jmxw-f4w9-294j.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jmxw-f4w9-294j", + "modified": "2024-10-21T18:30:59Z", + "published": "2024-10-21T18:30:59Z", + "aliases": [ + "CVE-2024-49989" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: fix double free issue during amdgpu module unload\n\nFlexible endpoints use DIGs from available inflexible endpoints,\nso only the encoders of inflexible links need to be freed.\nOtherwise, a double free issue may occur when unloading the\namdgpu module.\n\n[ 279.190523] RIP: 0010:__slab_free+0x152/0x2f0\n[ 279.190577] Call Trace:\n[ 279.190580] \n[ 279.190582] ? show_regs+0x69/0x80\n[ 279.190590] ? die+0x3b/0x90\n[ 279.190595] ? do_trap+0xc8/0xe0\n[ 279.190601] ? do_error_trap+0x73/0xa0\n[ 279.190605] ? __slab_free+0x152/0x2f0\n[ 279.190609] ? exc_invalid_op+0x56/0x70\n[ 279.190616] ? __slab_free+0x152/0x2f0\n[ 279.190642] ? asm_exc_invalid_op+0x1f/0x30\n[ 279.190648] ? dcn10_link_encoder_destroy+0x19/0x30 [amdgpu]\n[ 279.191096] ? __slab_free+0x152/0x2f0\n[ 279.191102] ? dcn10_link_encoder_destroy+0x19/0x30 [amdgpu]\n[ 279.191469] kfree+0x260/0x2b0\n[ 279.191474] dcn10_link_encoder_destroy+0x19/0x30 [amdgpu]\n[ 279.191821] link_destroy+0xd7/0x130 [amdgpu]\n[ 279.192248] dc_destruct+0x90/0x270 [amdgpu]\n[ 279.192666] dc_destroy+0x19/0x40 [amdgpu]\n[ 279.193020] amdgpu_dm_fini+0x16e/0x200 [amdgpu]\n[ 279.193432] dm_hw_fini+0x26/0x40 [amdgpu]\n[ 279.193795] amdgpu_device_fini_hw+0x24c/0x400 [amdgpu]\n[ 279.194108] amdgpu_driver_unload_kms+0x4f/0x70 [amdgpu]\n[ 279.194436] amdgpu_pci_remove+0x40/0x80 [amdgpu]\n[ 279.194632] pci_device_remove+0x3a/0xa0\n[ 279.194638] device_remove+0x40/0x70\n[ 279.194642] device_release_driver_internal+0x1ad/0x210\n[ 279.194647] driver_detach+0x4e/0xa0\n[ 279.194650] bus_remove_driver+0x6f/0xf0\n[ 279.194653] driver_unregister+0x33/0x60\n[ 279.194657] pci_unregister_driver+0x44/0x90\n[ 279.194662] amdgpu_exit+0x19/0x1f0 [amdgpu]\n[ 279.194939] __do_sys_delete_module.isra.0+0x198/0x2f0\n[ 279.194946] __x64_sys_delete_module+0x16/0x20\n[ 279.194950] do_syscall_64+0x58/0x120\n[ 279.194954] entry_SYSCALL_64_after_hwframe+0x6e/0x76\n[ 279.194980] ", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49989" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/20b5a8f9f4670a8503aa9fa95ca632e77c6bf55d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3c0ff4de45ce2c5f7997a1ffa6eefee4b79e6b58" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7af9e6fa63dbd43a61d4ecc8f59426596a75e507" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cf6f3ebd6312d465fee096d1f58089b177c7c67f" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-jq7w-hcx7-gm2r/GHSA-jq7w-hcx7-gm2r.json b/advisories/unreviewed/2024/10/GHSA-jq7w-hcx7-gm2r/GHSA-jq7w-hcx7-gm2r.json new file mode 100644 index 00000000000..3066b114ff2 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-jq7w-hcx7-gm2r/GHSA-jq7w-hcx7-gm2r.json @@ -0,0 +1,55 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jq7w-hcx7-gm2r", + "modified": "2024-10-21T18:30:58Z", + "published": "2024-10-21T18:30:58Z", + "aliases": [ + "CVE-2024-49946" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nppp: do not assume bh is held in ppp_channel_bridge_input()\n\nNetworking receive path is usually handled from BH handler.\nHowever, some protocols need to acquire the socket lock, and\npackets might be stored in the socket backlog is the socket was\nowned by a user process.\n\nIn this case, release_sock(), __release_sock(), and sk_backlog_rcv()\nmight call the sk->sk_backlog_rcv() handler in process context.\n\nsybot caught ppp was not considering this case in\nppp_channel_bridge_input() :\n\nWARNING: inconsistent lock state\n6.11.0-rc7-syzkaller-g5f5673607153 #0 Not tainted\n--------------------------------\ninconsistent {SOFTIRQ-ON-W} -> {IN-SOFTIRQ-W} usage.\nksoftirqd/1/24 [HC0[0]:SC1[1]:HE1:SE0] takes:\n ffff0000db7f11e0 (&pch->downl){+.?.}-{2:2}, at: spin_lock include/linux/spinlock.h:351 [inline]\n ffff0000db7f11e0 (&pch->downl){+.?.}-{2:2}, at: ppp_channel_bridge_input drivers/net/ppp/ppp_generic.c:2272 [inline]\n ffff0000db7f11e0 (&pch->downl){+.?.}-{2:2}, at: ppp_input+0x16c/0x854 drivers/net/ppp/ppp_generic.c:2304\n{SOFTIRQ-ON-W} state was registered at:\n lock_acquire+0x240/0x728 kernel/locking/lockdep.c:5759\n __raw_spin_lock include/linux/spinlock_api_smp.h:133 [inline]\n _raw_spin_lock+0x48/0x60 kernel/locking/spinlock.c:154\n spin_lock include/linux/spinlock.h:351 [inline]\n ppp_channel_bridge_input drivers/net/ppp/ppp_generic.c:2272 [inline]\n ppp_input+0x16c/0x854 drivers/net/ppp/ppp_generic.c:2304\n pppoe_rcv_core+0xfc/0x314 drivers/net/ppp/pppoe.c:379\n sk_backlog_rcv include/net/sock.h:1111 [inline]\n __release_sock+0x1a8/0x3d8 net/core/sock.c:3004\n release_sock+0x68/0x1b8 net/core/sock.c:3558\n pppoe_sendmsg+0xc8/0x5d8 drivers/net/ppp/pppoe.c:903\n sock_sendmsg_nosec net/socket.c:730 [inline]\n __sock_sendmsg net/socket.c:745 [inline]\n __sys_sendto+0x374/0x4f4 net/socket.c:2204\n __do_sys_sendto net/socket.c:2216 [inline]\n __se_sys_sendto net/socket.c:2212 [inline]\n __arm64_sys_sendto+0xd8/0xf8 net/socket.c:2212\n __invoke_syscall arch/arm64/kernel/syscall.c:35 [inline]\n invoke_syscall+0x98/0x2b8 arch/arm64/kernel/syscall.c:49\n el0_svc_common+0x130/0x23c arch/arm64/kernel/syscall.c:132\n do_el0_svc+0x48/0x58 arch/arm64/kernel/syscall.c:151\n el0_svc+0x54/0x168 arch/arm64/kernel/entry-common.c:712\n el0t_64_sync_handler+0x84/0xfc arch/arm64/kernel/entry-common.c:730\n el0t_64_sync+0x190/0x194 arch/arm64/kernel/entry.S:598\nirq event stamp: 282914\n hardirqs last enabled at (282914): [] __raw_spin_unlock_irqrestore include/linux/spinlock_api_smp.h:151 [inline]\n hardirqs last enabled at (282914): [] _raw_spin_unlock_irqrestore+0x38/0x98 kernel/locking/spinlock.c:194\n hardirqs last disabled at (282913): [] __raw_spin_lock_irqsave include/linux/spinlock_api_smp.h:108 [inline]\n hardirqs last disabled at (282913): [] _raw_spin_lock_irqsave+0x2c/0x7c kernel/locking/spinlock.c:162\n softirqs last enabled at (282904): [] softirq_handle_end kernel/softirq.c:400 [inline]\n softirqs last enabled at (282904): [] handle_softirqs+0xa3c/0xbfc kernel/softirq.c:582\n softirqs last disabled at (282909): [] run_ksoftirqd+0x70/0x158 kernel/softirq.c:928\n\nother info that might help us debug this:\n Possible unsafe locking scenario:\n\n CPU0\n ----\n lock(&pch->downl);\n \n lock(&pch->downl);\n\n *** DEADLOCK ***\n\n1 lock held by ksoftirqd/1/24:\n #0: ffff80008f74dfa0 (rcu_read_lock){....}-{1:2}, at: rcu_lock_acquire+0x10/0x4c include/linux/rcupdate.h:325\n\nstack backtrace:\nCPU: 1 UID: 0 PID: 24 Comm: ksoftirqd/1 Not tainted 6.11.0-rc7-syzkaller-g5f5673607153 #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 08/06/2024\nCall trace:\n dump_backtrace+0x1b8/0x1e4 arch/arm64/kernel/stacktrace.c:319\n show_stack+0x2c/0x3c arch/arm64/kernel/stacktrace.c:326\n __dump_sta\n---truncated---", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49946" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/176dd41e8c2bd997ed3d66568a3362e69ecce99b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/635deca1800a68624f185dc1e04a8495b48cf185" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/aec7291003df78cb71fd461d7b672912bde55807" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c837f8583535f094a39386308c2ccfd92c8596cd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/efe9cc0f7c0279216a5522271ec675b8288602e4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f9620e2a665aa642625bd2501282bbddff556bd7" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-jww8-jcqp-pmjm/GHSA-jww8-jcqp-pmjm.json b/advisories/unreviewed/2024/10/GHSA-jww8-jcqp-pmjm/GHSA-jww8-jcqp-pmjm.json new file mode 100644 index 00000000000..8d3224cf2a6 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-jww8-jcqp-pmjm/GHSA-jww8-jcqp-pmjm.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jww8-jcqp-pmjm", + "modified": "2024-10-21T18:30:58Z", + "published": "2024-10-21T18:30:58Z", + "aliases": [ + "CVE-2024-49944" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: set sk_state back to CLOSED if autobind fails in sctp_listen_start\n\nIn sctp_listen_start() invoked by sctp_inet_listen(), it should set the\nsk_state back to CLOSED if sctp_autobind() fails due to whatever reason.\n\nOtherwise, next time when calling sctp_inet_listen(), if sctp_sk(sk)->reuse\nis already set via setsockopt(SCTP_REUSE_PORT), sctp_sk(sk)->bind_hash will\nbe dereferenced as sk_state is LISTENING, which causes a crash as bind_hash\nis NULL.\n\n KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]\n RIP: 0010:sctp_inet_listen+0x7f0/0xa20 net/sctp/socket.c:8617\n Call Trace:\n \n __sys_listen_socket net/socket.c:1883 [inline]\n __sys_listen+0x1b7/0x230 net/socket.c:1894\n __do_sys_listen net/socket.c:1902 [inline]", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49944" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7f64cb5b4d8c872296eda0fdce3bcf099eec7aa7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8beee4d8dee76b67c75dc91fd8185d91e845c160" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9230a59eda0878d7ecaa901d876aec76f57bd455" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/dd70c8a89ef99c3d53127fe19e51ef47c3f860fa" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e7a8442195e8ebd97df467ce4742980ab57edcce" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e914bf68dab88815a7ae7b7a3a5e8913c8ff14a5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f032e1dac30b3376c7d6026fb01a8c403c47a80d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-m236-cj4j-935h/GHSA-m236-cj4j-935h.json b/advisories/unreviewed/2024/10/GHSA-m236-cj4j-935h/GHSA-m236-cj4j-935h.json new file mode 100644 index 00000000000..78974c947da --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-m236-cj4j-935h/GHSA-m236-cj4j-935h.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m236-cj4j-935h", + "modified": "2024-10-21T18:30:59Z", + "published": "2024-10-21T18:30:59Z", + "aliases": [ + "CVE-2024-49963" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmailbox: bcm2835: Fix timeout during suspend mode\n\nDuring noirq suspend phase the Raspberry Pi power driver suffer of\nfirmware property timeouts. The reason is that the IRQ of the underlying\nBCM2835 mailbox is disabled and rpi_firmware_property_list() will always\nrun into a timeout [1].\n\nSince the VideoCore side isn't consider as a wakeup source, set the\nIRQF_NO_SUSPEND flag for the mailbox IRQ in order to keep it enabled\nduring suspend-resume cycle.\n\n[1]\nPM: late suspend of devices complete after 1.754 msecs\nWARNING: CPU: 0 PID: 438 at drivers/firmware/raspberrypi.c:128\n rpi_firmware_property_list+0x204/0x22c\nFirmware transaction 0x00028001 timeout\nModules linked in:\nCPU: 0 PID: 438 Comm: bash Tainted: G C 6.9.3-dirty #17\nHardware name: BCM2835\nCall trace:\nunwind_backtrace from show_stack+0x18/0x1c\nshow_stack from dump_stack_lvl+0x34/0x44\ndump_stack_lvl from __warn+0x88/0xec\n__warn from warn_slowpath_fmt+0x7c/0xb0\nwarn_slowpath_fmt from rpi_firmware_property_list+0x204/0x22c\nrpi_firmware_property_list from rpi_firmware_property+0x68/0x8c\nrpi_firmware_property from rpi_firmware_set_power+0x54/0xc0\nrpi_firmware_set_power from _genpd_power_off+0xe4/0x148\n_genpd_power_off from genpd_sync_power_off+0x7c/0x11c\ngenpd_sync_power_off from genpd_finish_suspend+0xcc/0xe0\ngenpd_finish_suspend from dpm_run_callback+0x78/0xd0\ndpm_run_callback from device_suspend_noirq+0xc0/0x238\ndevice_suspend_noirq from dpm_suspend_noirq+0xb0/0x168\ndpm_suspend_noirq from suspend_devices_and_enter+0x1b8/0x5ac\nsuspend_devices_and_enter from pm_suspend+0x254/0x2e4\npm_suspend from state_store+0xa8/0xd4\nstate_store from kernfs_fop_write_iter+0x154/0x1a0\nkernfs_fop_write_iter from vfs_write+0x12c/0x184\nvfs_write from ksys_write+0x78/0xc0\nksys_write from ret_fast_syscall+0x0/0x54\nException stack(0xcc93dfa8 to 0xcc93dff0)\n[...]\nPM: noirq suspend of devices complete after 3095.584 msecs", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49963" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/10a58555e0bb5cc4673c8bb73b8afc5fa651f0ac" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/32ee78823dea2d54adaf6e05f86622eba359e091" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/90320cfc07b7d6e7a58fd8168f6380ec52ff0251" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/dc09f007caed3b2f6a3b6bd7e13777557ae22bfd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/df293ea78740a41384d648041f38f645700288e1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/dfeb67b2194ecc55ef8065468c5adda3cdf59114" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e65a9af05a0b59ebeba28e5e82265a233db7bc27" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-m3fc-5gx3-j98r/GHSA-m3fc-5gx3-j98r.json b/advisories/unreviewed/2024/10/GHSA-m3fc-5gx3-j98r/GHSA-m3fc-5gx3-j98r.json new file mode 100644 index 00000000000..238c556c631 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-m3fc-5gx3-j98r/GHSA-m3fc-5gx3-j98r.json @@ -0,0 +1,55 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m3fc-5gx3-j98r", + "modified": "2024-10-21T18:30:56Z", + "published": "2024-10-21T18:30:56Z", + "aliases": [ + "CVE-2024-49871" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nInput: adp5589-keys - fix NULL pointer dereference\n\nWe register a devm action to call adp5589_clear_config() and then pass\nthe i2c client as argument so that we can call i2c_get_clientdata() in\norder to get our device object. However, i2c_set_clientdata() is only\nbeing set at the end of the probe function which means that we'll get a\nNULL pointer dereference in case the probe function fails early.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49871" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/122b160561f6429701a0559a0f39b0ae309488c6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/34e304cc53ae5d3c8e3f08b41dd11e0d4f3e01ed" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4449fedb8a710043fc0925409eba844c192d4337" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7c3f04223aaf82489472d614c6decee5a1ce8d7f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9a38791ee79bd17d225c15a6d1479448be127a59" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fb5cc65f973661241e4a2b7390b429aa7b330c69" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-m5m5-6fc4-ph6r/GHSA-m5m5-6fc4-ph6r.json b/advisories/unreviewed/2024/10/GHSA-m5m5-6fc4-ph6r/GHSA-m5m5-6fc4-ph6r.json new file mode 100644 index 00000000000..b1604bb942f --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-m5m5-6fc4-ph6r/GHSA-m5m5-6fc4-ph6r.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m5m5-6fc4-ph6r", + "modified": "2024-10-21T18:30:58Z", + "published": "2024-10-21T18:30:58Z", + "aliases": [ + "CVE-2024-49947" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: test for not too small csum_start in virtio_net_hdr_to_skb()\n\nsyzbot was able to trigger this warning [1], after injecting a\nmalicious packet through af_packet, setting skb->csum_start and thus\nthe transport header to an incorrect value.\n\nWe can at least make sure the transport header is after\nthe end of the network header (with a estimated minimal size).\n\n[1]\n[ 67.873027] skb len=4096 headroom=16 headlen=14 tailroom=0\nmac=(-1,-1) mac_len=0 net=(16,-6) trans=10\nshinfo(txflags=0 nr_frags=1 gso(size=0 type=0 segs=0))\ncsum(0xa start=10 offset=0 ip_summed=3 complete_sw=0 valid=0 level=0)\nhash(0x0 sw=0 l4=0) proto=0x0800 pkttype=0 iif=0\npriority=0x0 mark=0x0 alloc_cpu=10 vlan_all=0x0\nencapsulation=0 inner(proto=0x0000, mac=0, net=0, trans=0)\n[ 67.877172] dev name=veth0_vlan feat=0x000061164fdd09e9\n[ 67.877764] sk family=17 type=3 proto=0\n[ 67.878279] skb linear: 00000000: 00 00 10 00 00 00 00 00 0f 00 00 00 08 00\n[ 67.879128] skb frag: 00000000: 0e 00 07 00 00 00 28 00 08 80 1c 00 04 00 00 02\n[ 67.879877] skb frag: 00000010: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\n[ 67.880647] skb frag: 00000020: 00 00 02 00 00 00 08 00 1b 00 00 00 00 00 00 00\n[ 67.881156] skb frag: 00000030: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\n[ 67.881753] skb frag: 00000040: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\n[ 67.882173] skb frag: 00000050: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\n[ 67.882790] skb frag: 00000060: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\n[ 67.883171] skb frag: 00000070: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\n[ 67.883733] skb frag: 00000080: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\n[ 67.884206] skb frag: 00000090: 00 00 00 00 00 00 00 00 00 00 69 70 76 6c 61 6e\n[ 67.884704] skb frag: 000000a0: 31 00 00 00 00 00 00 00 00 00 2b 00 00 00 00 00\n[ 67.885139] skb frag: 000000b0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\n[ 67.885677] skb frag: 000000c0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\n[ 67.886042] skb frag: 000000d0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\n[ 67.886408] skb frag: 000000e0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\n[ 67.887020] skb frag: 000000f0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\n[ 67.887384] skb frag: 00000100: 00 00\n[ 67.887878] ------------[ cut here ]------------\n[ 67.887908] offset (-6) >= skb_headlen() (14)\n[ 67.888445] WARNING: CPU: 10 PID: 2088 at net/core/dev.c:3332 skb_checksum_help (net/core/dev.c:3332 (discriminator 2))\n[ 67.889353] Modules linked in: macsec macvtap macvlan hsr wireguard curve25519_x86_64 libcurve25519_generic libchacha20poly1305 chacha_x86_64 libchacha poly1305_x86_64 dummy bridge sr_mod cdrom evdev pcspkr i2c_piix4 9pnet_virtio 9p 9pnet netfs\n[ 67.890111] CPU: 10 UID: 0 PID: 2088 Comm: b363492833 Not tainted 6.11.0-virtme #1011\n[ 67.890183] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014\n[ 67.890309] RIP: 0010:skb_checksum_help (net/core/dev.c:3332 (discriminator 2))\n[ 67.891043] Call Trace:\n[ 67.891173] \n[ 67.891274] ? __warn (kernel/panic.c:741)\n[ 67.891320] ? skb_checksum_help (net/core/dev.c:3332 (discriminator 2))\n[ 67.891333] ? report_bug (lib/bug.c:180 lib/bug.c:219)\n[ 67.891348] ? handle_bug (arch/x86/kernel/traps.c:239)\n[ 67.891363] ? exc_invalid_op (arch/x86/kernel/traps.c:260 (discriminator 1))\n[ 67.891372] ? asm_exc_invalid_op (./arch/x86/include/asm/idtentry.h:621)\n[ 67.891388] ? skb_checksum_help (net/core/dev.c:3332 (discriminator 2))\n[ 67.891399] ? skb_checksum_help (net/core/dev.c:3332 (discriminator 2))\n[ 67.891416] ip_do_fragment (net/ipv4/ip_output.c:777 (discriminator 1))\n[ 67.891448] ? __ip_local_out (./include/linux/skbuff.h:1146 ./include/net/l3mdev.h:196 ./include/net/l3mdev.h:213 ne\n---truncated---", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49947" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/49d14b54a527289d09a9480f214b8c586322310a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4cc0648e9e3240496835dc698ace1d046d8d57ea" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7711c419a915ee0dd91c125d2b967bbf2a72e9ac" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d9dfd41e32ccc5198033ddd1ff1516822dfefa5a" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-m7hg-2r4m-qcxr/GHSA-m7hg-2r4m-qcxr.json b/advisories/unreviewed/2024/10/GHSA-m7hg-2r4m-qcxr/GHSA-m7hg-2r4m-qcxr.json new file mode 100644 index 00000000000..aa6b56bd9f0 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-m7hg-2r4m-qcxr/GHSA-m7hg-2r4m-qcxr.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m7hg-2r4m-qcxr", + "modified": "2024-10-21T18:30:59Z", + "published": "2024-10-21T18:30:59Z", + "aliases": [ + "CVE-2024-49992" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/stm: Avoid use-after-free issues with crtc and plane\n\nltdc_load() calls functions drm_crtc_init_with_planes(),\ndrm_universal_plane_init() and drm_encoder_init(). These functions\nshould not be called with parameters allocated with devm_kzalloc()\nto avoid use-after-free issues [1].\n\nUse allocations managed by the DRM framework.\n\nFound by Linux Verification Center (linuxtesting.org).\n\n[1]\nhttps://lore.kernel.org/lkml/u366i76e3qhh3ra5oxrtngjtm2u5lterkekcz6y2jkndhuxzli@diujon4h7qwb/", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49992" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0a1741d10da29aa84955ef89ae9a03c4b6038657" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/19dd9780b7ac673be95bf6fd6892a184c9db611f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/454e5d7e671946698af0f201e48469e5ddb42851" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b22eec4b57d04befa90e8554ede34e6c67257606" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d02611ff001454358be6910cb926799e2d818716" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-m8rm-pc2x-rqv9/GHSA-m8rm-pc2x-rqv9.json b/advisories/unreviewed/2024/10/GHSA-m8rm-pc2x-rqv9/GHSA-m8rm-pc2x-rqv9.json new file mode 100644 index 00000000000..4ab244edf17 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-m8rm-pc2x-rqv9/GHSA-m8rm-pc2x-rqv9.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m8rm-pc2x-rqv9", + "modified": "2024-10-21T18:31:00Z", + "published": "2024-10-21T18:31:00Z", + "aliases": [ + "CVE-2024-50001" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: Fix error path in multi-packet WQE transmit\n\nRemove the erroneous unmap in case no DMA mapping was established\n\nThe multi-packet WQE transmit code attempts to obtain a DMA mapping for\nthe skb. This could fail, e.g. under memory pressure, when the IOMMU\ndriver just can't allocate more memory for page tables. While the code\ntries to handle this in the path below the err_unmap label it erroneously\nunmaps one entry from the sq's FIFO list of active mappings. Since the\ncurrent map attempt failed this unmap is removing some random DMA mapping\nthat might still be required. If the PCI function now presents that IOVA,\nthe IOMMU may assumes a rogue DMA access and e.g. on s390 puts the PCI\nfunction in error state.\n\nThe erroneous behavior was seen in a stress-test environment that created\nmemory pressure.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50001" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/26fad69b34fcba80d5c7d9e651f628e6ac927754" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2bcae12c795f32ddfbf8c80d1b5f1d3286341c32" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8bb8c12fb5e2b1f03d603d493c92941676f109b5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ca36d6c1a49b6965c86dd528a73f38bc62d9c625" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ce828b347cf1b3c1b12b091d02463c35ce5097f5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ecf310aaf256acbc8182189fe0aa1021c3ddef72" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fc357e78176945ca7bcacf92ab794b9ccd41b4f4" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-mc6w-w4fp-fg4v/GHSA-mc6w-w4fp-fg4v.json b/advisories/unreviewed/2024/10/GHSA-mc6w-w4fp-fg4v/GHSA-mc6w-w4fp-fg4v.json new file mode 100644 index 00000000000..98dc8c0bb3e --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-mc6w-w4fp-fg4v/GHSA-mc6w-w4fp-fg4v.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mc6w-w4fp-fg4v", + "modified": "2024-10-21T18:30:59Z", + "published": "2024-10-21T18:30:59Z", + "aliases": [ + "CVE-2024-49972" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Deallocate DML memory if allocation fails\n\n[Why]\nWhen DC state create DML memory allocation fails, memory is not\ndeallocated subsequently, resulting in uninitialized structure\nthat is not NULL.\n\n[How]\nDeallocate memory if DML memory allocation fails.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49972" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/80345daa5746184195f2d383a2f1bad058f0f94c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/892abca6877a96c9123bb1c010cafccdf8ca1b75" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-mf62-gm5r-38wj/GHSA-mf62-gm5r-38wj.json b/advisories/unreviewed/2024/10/GHSA-mf62-gm5r-38wj/GHSA-mf62-gm5r-38wj.json new file mode 100644 index 00000000000..ca2bf1b756f --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-mf62-gm5r-38wj/GHSA-mf62-gm5r-38wj.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mf62-gm5r-38wj", + "modified": "2024-10-21T18:30:57Z", + "published": "2024-10-21T18:30:57Z", + "aliases": [ + "CVE-2024-49899" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Initialize denominators' default to 1\n\n[WHAT & HOW]\nVariables used as denominators and maybe not assigned to other values,\nshould not be 0. Change their default to 1 so they are never 0.\n\nThis fixes 10 DIVIDE_BY_ZERO issues reported by Coverity.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49899" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7f8e93b862aba08d540f1e9e03e0ceb4d0cfd5fb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b995c0a6de6c74656a0c39cd57a0626351b13e3c" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-p237-mjc7-7qqj/GHSA-p237-mjc7-7qqj.json b/advisories/unreviewed/2024/10/GHSA-p237-mjc7-7qqj/GHSA-p237-mjc7-7qqj.json new file mode 100644 index 00000000000..9a56ae6556e --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-p237-mjc7-7qqj/GHSA-p237-mjc7-7qqj.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p237-mjc7-7qqj", + "modified": "2024-10-21T18:30:59Z", + "published": "2024-10-21T18:30:59Z", + "aliases": [ + "CVE-2024-49962" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nACPICA: check null return of ACPI_ALLOCATE_ZEROED() in acpi_db_convert_to_package()\n\nACPICA commit 4d4547cf13cca820ff7e0f859ba83e1a610b9fd0\n\nACPI_ALLOCATE_ZEROED() may fail, elements might be NULL and will cause\nNULL pointer dereference later.\n\n[ rjw: Subject and changelog edits ]", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49962" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1c9b8775062f8d854a80caf186af57fc617d454c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4588ea78d3904bebb613b0bb025669e75800f546" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a5242874488eba2b9062985bf13743c029821330" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a907c113a8b66972f15f084d7dff960207b1f71d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ae5d4c7e76ba393d20366dfea1f39f24560ffb1d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cbb67e245dacd02b5e1d82733892647df1523982" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f282db38953ad71dd4f3f8877a4e1d37e580e30a" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-p8wj-q5fw-6q9q/GHSA-p8wj-q5fw-6q9q.json b/advisories/unreviewed/2024/10/GHSA-p8wj-q5fw-6q9q/GHSA-p8wj-q5fw-6q9q.json new file mode 100644 index 00000000000..3a08eae9b51 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-p8wj-q5fw-6q9q/GHSA-p8wj-q5fw-6q9q.json @@ -0,0 +1,55 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p8wj-q5fw-6q9q", + "modified": "2024-10-21T18:30:58Z", + "published": "2024-10-21T18:30:58Z", + "aliases": [ + "CVE-2024-49935" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nACPI: PAD: fix crash in exit_round_robin()\n\nThe kernel occasionally crashes in cpumask_clear_cpu(), which is called\nwithin exit_round_robin(), because when executing clear_bit(nr, addr) with\nnr set to 0xffffffff, the address calculation may cause misalignment within\nthe memory, leading to access to an invalid memory address.\n\n----------\nBUG: unable to handle kernel paging request at ffffffffe0740618\n ...\nCPU: 3 PID: 2919323 Comm: acpi_pad/14 Kdump: loaded Tainted: G OE X --------- - - 4.18.0-425.19.2.el8_7.x86_64 #1\n ...\nRIP: 0010:power_saving_thread+0x313/0x411 [acpi_pad]\nCode: 89 cd 48 89 d3 eb d1 48 c7 c7 55 70 72 c0 e8 64 86 b0 e4 c6 05 0d a1 02 00 01 e9 bc fd ff ff 45 89 e4 42 8b 04 a5 20 82 72 c0 48 0f b3 05 f4 9c 01 00 42 c7 04 a5 20 82 72 c0 ff ff ff ff 31\nRSP: 0018:ff72a5d51fa77ec8 EFLAGS: 00010202\nRAX: 00000000ffffffff RBX: ff462981e5d8cb80 RCX: 0000000000000000\nRDX: 0000000000000000 RSI: 0000000000000246 RDI: 0000000000000246\nRBP: ff46297556959d80 R08: 0000000000000382 R09: ff46297c8d0f38d8\nR10: 0000000000000000 R11: 0000000000000001 R12: 000000000000000e\nR13: 0000000000000000 R14: ffffffffffffffff R15: 000000000000000e\nFS: 0000000000000000(0000) GS:ff46297a800c0000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: ffffffffe0740618 CR3: 0000007e20410004 CR4: 0000000000771ee0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nPKRU: 55555554\nCall Trace:\n ? acpi_pad_add+0x120/0x120 [acpi_pad]\n kthread+0x10b/0x130\n ? set_kthread_struct+0x50/0x50\n ret_from_fork+0x1f/0x40\n ...\nCR2: ffffffffe0740618\n\ncrash> dis -lr ffffffffc0726923\n ...\n/usr/src/debug/kernel-4.18.0-425.19.2.el8_7/linux-4.18.0-425.19.2.el8_7.x86_64/./include/linux/cpumask.h: 114\n0xffffffffc0726918 :\tmov %r12d,%r12d\n/usr/src/debug/kernel-4.18.0-425.19.2.el8_7/linux-4.18.0-425.19.2.el8_7.x86_64/./include/linux/cpumask.h: 325\n0xffffffffc072691b :\tmov -0x3f8d7de0(,%r12,4),%eax\n/usr/src/debug/kernel-4.18.0-425.19.2.el8_7/linux-4.18.0-425.19.2.el8_7.x86_64/./arch/x86/include/asm/bitops.h: 80\n0xffffffffc0726923 :\tlock btr %rax,0x19cf4(%rip) # 0xffffffffc0740620 \n\ncrash> px tsk_in_cpu[14]\n$66 = 0xffffffff\n\ncrash> px 0xffffffffc072692c+0x19cf4\n$99 = 0xffffffffc0740620\n\ncrash> sym 0xffffffffc0740620\nffffffffc0740620 (b) pad_busy_cpus_bits [acpi_pad]\n\ncrash> px pad_busy_cpus_bits[0]\n$42 = 0xfffc0\n----------\n\nTo fix this, ensure that tsk_in_cpu[tsk_index] != -1 before calling\ncpumask_clear_cpu() in exit_round_robin(), just as it is done in\nround_robin_cpu().\n\n[ rjw: Subject edit, avoid updates to the same value ]", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49935" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/03593dbb0b272ef7b0358b099841e65735422aca" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0a2ed70a549e61c5181bad5db418d223b68ae932" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/27c045f868f0e5052c6b532868a65e0cd250c8fc" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/68a599da16ebad442ce295d8d2d5c488e3992822" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/68a8e45743d6a120f863fb14b72dc59616597019" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/92e5661b7d0727ab912b76625a88b33fdb9b609a" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-pgcr-7vhj-26w2/GHSA-pgcr-7vhj-26w2.json b/advisories/unreviewed/2024/10/GHSA-pgcr-7vhj-26w2/GHSA-pgcr-7vhj-26w2.json new file mode 100644 index 00000000000..2ea06832136 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-pgcr-7vhj-26w2/GHSA-pgcr-7vhj-26w2.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pgcr-7vhj-26w2", + "modified": "2024-10-21T18:30:58Z", + "published": "2024-10-21T18:30:58Z", + "aliases": [ + "CVE-2024-49941" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ngpiolib: Fix potential NULL pointer dereference in gpiod_get_label()\n\nIn `gpiod_get_label()`, it is possible that `srcu_dereference_check()` may\nreturn a NULL pointer, leading to a scenario where `label->str` is accessed\nwithout verifying if `label` itself is NULL.\n\nThis patch adds a proper NULL check for `label` before accessing\n`label->str`. The check for `label->str != NULL` is removed because\n`label->str` can never be NULL if `label` is not NULL.\n\nThis fixes the issue where the label name was being printed as `(efault)`\nwhen dumping the sysfs GPIO file when `label == NULL`.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49941" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7b99b5ab885993bff010ebcd93be5e511c56e28a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9ee4b907d7a5d7a53b4ff7727c371ff3d44ccbbb" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-pgjc-h8g4-v6j2/GHSA-pgjc-h8g4-v6j2.json b/advisories/unreviewed/2024/10/GHSA-pgjc-h8g4-v6j2/GHSA-pgjc-h8g4-v6j2.json new file mode 100644 index 00000000000..021a1bb25bc --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-pgjc-h8g4-v6j2/GHSA-pgjc-h8g4-v6j2.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pgjc-h8g4-v6j2", + "modified": "2024-10-21T18:30:57Z", + "published": "2024-10-21T18:30:57Z", + "aliases": [ + "CVE-2024-49918" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Add null check for head_pipe in dcn32_acquire_idle_pipe_for_head_pipe_in_layer\n\nThis commit addresses a potential null pointer dereference issue in the\n`dcn32_acquire_idle_pipe_for_head_pipe_in_layer` function. The issue\ncould occur when `head_pipe` is null.\n\nThe fix adds a check to ensure `head_pipe` is not null before asserting\nit. If `head_pipe` is null, the function returns NULL to prevent a\npotential null pointer dereference.\n\nReported by smatch:\ndrivers/gpu/drm/amd/amdgpu/../display/dc/resource/dcn32/dcn32_resource.c:2690 dcn32_acquire_idle_pipe_for_head_pipe_in_layer() error: we previously assumed 'head_pipe' could be null (see line 2681)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49918" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4f47292f488fa7041284dca1f1244116c18721f1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/96d4c2ee18d732a248d053aae8c4a27cb1d68d1c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ac2140449184a26eac99585b7f69814bd3ba8f2d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-pm28-gfv5-pj4g/GHSA-pm28-gfv5-pj4g.json b/advisories/unreviewed/2024/10/GHSA-pm28-gfv5-pj4g/GHSA-pm28-gfv5-pj4g.json new file mode 100644 index 00000000000..e53fa81c6b8 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-pm28-gfv5-pj4g/GHSA-pm28-gfv5-pj4g.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pm28-gfv5-pj4g", + "modified": "2024-10-21T18:30:58Z", + "published": "2024-10-21T18:30:58Z", + "aliases": [ + "CVE-2024-49950" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: Fix uaf in l2cap_connect\n\n[Syzbot reported]\nBUG: KASAN: slab-use-after-free in l2cap_connect.constprop.0+0x10d8/0x1270 net/bluetooth/l2cap_core.c:3949\nRead of size 8 at addr ffff8880241e9800 by task kworker/u9:0/54\n\nCPU: 0 UID: 0 PID: 54 Comm: kworker/u9:0 Not tainted 6.11.0-rc6-syzkaller-00268-g788220eee30d #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 08/06/2024\nWorkqueue: hci2 hci_rx_work\nCall Trace:\n \n __dump_stack lib/dump_stack.c:93 [inline]\n dump_stack_lvl+0x116/0x1f0 lib/dump_stack.c:119\n print_address_description mm/kasan/report.c:377 [inline]\n print_report+0xc3/0x620 mm/kasan/report.c:488\n kasan_report+0xd9/0x110 mm/kasan/report.c:601\n l2cap_connect.constprop.0+0x10d8/0x1270 net/bluetooth/l2cap_core.c:3949\n l2cap_connect_req net/bluetooth/l2cap_core.c:4080 [inline]\n l2cap_bredr_sig_cmd net/bluetooth/l2cap_core.c:4772 [inline]\n l2cap_sig_channel net/bluetooth/l2cap_core.c:5543 [inline]\n l2cap_recv_frame+0xf0b/0x8eb0 net/bluetooth/l2cap_core.c:6825\n l2cap_recv_acldata+0x9b4/0xb70 net/bluetooth/l2cap_core.c:7514\n hci_acldata_packet net/bluetooth/hci_core.c:3791 [inline]\n hci_rx_work+0xaab/0x1610 net/bluetooth/hci_core.c:4028\n process_one_work+0x9c5/0x1b40 kernel/workqueue.c:3231\n process_scheduled_works kernel/workqueue.c:3312 [inline]\n worker_thread+0x6c8/0xed0 kernel/workqueue.c:3389\n kthread+0x2c1/0x3a0 kernel/kthread.c:389\n ret_from_fork+0x45/0x80 arch/x86/kernel/process.c:147\n ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:244\n...\n\nFreed by task 5245:\n kasan_save_stack+0x33/0x60 mm/kasan/common.c:47\n kasan_save_track+0x14/0x30 mm/kasan/common.c:68\n kasan_save_free_info+0x3b/0x60 mm/kasan/generic.c:579\n poison_slab_object+0xf7/0x160 mm/kasan/common.c:240\n __kasan_slab_free+0x32/0x50 mm/kasan/common.c:256\n kasan_slab_free include/linux/kasan.h:184 [inline]\n slab_free_hook mm/slub.c:2256 [inline]\n slab_free mm/slub.c:4477 [inline]\n kfree+0x12a/0x3b0 mm/slub.c:4598\n l2cap_conn_free net/bluetooth/l2cap_core.c:1810 [inline]\n kref_put include/linux/kref.h:65 [inline]\n l2cap_conn_put net/bluetooth/l2cap_core.c:1822 [inline]\n l2cap_conn_del+0x59d/0x730 net/bluetooth/l2cap_core.c:1802\n l2cap_connect_cfm+0x9e6/0xf80 net/bluetooth/l2cap_core.c:7241\n hci_connect_cfm include/net/bluetooth/hci_core.h:1960 [inline]\n hci_conn_failed+0x1c3/0x370 net/bluetooth/hci_conn.c:1265\n hci_abort_conn_sync+0x75a/0xb50 net/bluetooth/hci_sync.c:5583\n abort_conn_sync+0x197/0x360 net/bluetooth/hci_conn.c:2917\n hci_cmd_sync_work+0x1a4/0x410 net/bluetooth/hci_sync.c:328\n process_one_work+0x9c5/0x1b40 kernel/workqueue.c:3231\n process_scheduled_works kernel/workqueue.c:3312 [inline]\n worker_thread+0x6c8/0xed0 kernel/workqueue.c:3389\n kthread+0x2c1/0x3a0 kernel/kthread.c:389\n ret_from_fork+0x45/0x80 arch/x86/kernel/process.c:147\n ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:244", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49950" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/333b4fd11e89b29c84c269123f871883a30be586" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/78d30ce16fdf9c301bcd8b83ce613cea079cea83" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a1c6174e23df10b8e5770e82d63bc6e2118a3dc7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b90907696c30172b809aa3dd2f0caffae761e4c6" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-ppw5-g3vp-9xx2/GHSA-ppw5-g3vp-9xx2.json b/advisories/unreviewed/2024/10/GHSA-ppw5-g3vp-9xx2/GHSA-ppw5-g3vp-9xx2.json new file mode 100644 index 00000000000..dcb0be6b21c --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-ppw5-g3vp-9xx2/GHSA-ppw5-g3vp-9xx2.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ppw5-g3vp-9xx2", + "modified": "2024-10-21T18:30:57Z", + "published": "2024-10-21T18:30:57Z", + "aliases": [ + "CVE-2024-49900" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\njfs: Fix uninit-value access of new_ea in ea_buffer\n\nsyzbot reports that lzo1x_1_do_compress is using uninit-value:\n\n=====================================================\nBUG: KMSAN: uninit-value in lzo1x_1_do_compress+0x19f9/0x2510 lib/lzo/lzo1x_compress.c:178\n\n...\n\nUninit was stored to memory at:\n ea_put fs/jfs/xattr.c:639 [inline]\n\n...\n\nLocal variable ea_buf created at:\n __jfs_setxattr+0x5d/0x1ae0 fs/jfs/xattr.c:662\n __jfs_xattr_set+0xe6/0x1f0 fs/jfs/xattr.c:934\n\n=====================================================\n\nThe reason is ea_buf->new_ea is not initialized properly.\n\nFix this by using memset to empty its content at the beginning\nin ea_get().", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49900" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2b59ffad47db1c46af25ccad157bb3b25147c35c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6041536d18c5f51a84bc37cd568cbab61870031e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7c244d5b48284a770d96ff703df2dfeadf804a73" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8ad8b531de79c348bcb8133e7f5e827b884226af" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8b1dcf25c26d42e4a68c4725ce52a0543c7878cc" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c076b3746224982eebdba5c9e4b1467e146c0d64" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d7444f91a9f93eaa48827087ed0f3381c194181d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-pvgc-vpgw-88mq/GHSA-pvgc-vpgw-88mq.json b/advisories/unreviewed/2024/10/GHSA-pvgc-vpgw-88mq/GHSA-pvgc-vpgw-88mq.json new file mode 100644 index 00000000000..38b798118f9 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-pvgc-vpgw-88mq/GHSA-pvgc-vpgw-88mq.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pvgc-vpgw-88mq", + "modified": "2024-10-21T18:30:57Z", + "published": "2024-10-21T18:30:56Z", + "aliases": [ + "CVE-2024-49881" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\next4: update orig_path in ext4_find_extent()\n\nIn ext4_find_extent(), if the path is not big enough, we free it and set\n*orig_path to NULL. But after reallocating and successfully initializing\nthe path, we don't update *orig_path, in which case the caller gets a\nvalid path but a NULL ppath, and this may cause a NULL pointer dereference\nor a path memory leak. For example:\n\next4_split_extent\n path = *ppath = 2000\n ext4_find_extent\n if (depth > path[0].p_maxdepth)\n kfree(path = 2000);\n *orig_path = path = NULL;\n path = kcalloc() = 3000\n ext4_split_extent_at(*ppath = NULL)\n path = *ppath;\n ex = path[depth].p_ext;\n // NULL pointer dereference!\n\n==================================================================\nBUG: kernel NULL pointer dereference, address: 0000000000000010\nCPU: 6 UID: 0 PID: 576 Comm: fsstress Not tainted 6.11.0-rc2-dirty #847\nRIP: 0010:ext4_split_extent_at+0x6d/0x560\nCall Trace:\n \n ext4_split_extent.isra.0+0xcb/0x1b0\n ext4_ext_convert_to_initialized+0x168/0x6c0\n ext4_ext_handle_unwritten_extents+0x325/0x4d0\n ext4_ext_map_blocks+0x520/0xdb0\n ext4_map_blocks+0x2b0/0x690\n ext4_iomap_begin+0x20e/0x2c0\n[...]\n==================================================================\n\nTherefore, *orig_path is updated when the extent lookup succeeds, so that\nthe caller can safely use path or *ppath.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49881" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/11b230100d6801c014fab2afabc8bdea304c1b96" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5b4b2dcace35f618fe361a87bae6f0d13af31bc1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6766937d0327000ac1b87c97bbecdd28b0dd6599" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6801ed1298204d16a38571091e31178bfdc3c679" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a9fcb1717d75061d3653ed69365c8d45331815cd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b63481b3a388ee2df9e295f97273226140422a42" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f55ecc58d07a6c1f6d6d5b5af125c25f8da0bda2" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-q2x4-35qf-p4qw/GHSA-q2x4-35qf-p4qw.json b/advisories/unreviewed/2024/10/GHSA-q2x4-35qf-p4qw/GHSA-q2x4-35qf-p4qw.json new file mode 100644 index 00000000000..652d7869a3d --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-q2x4-35qf-p4qw/GHSA-q2x4-35qf-p4qw.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q2x4-35qf-p4qw", + "modified": "2024-10-21T18:30:57Z", + "published": "2024-10-21T18:30:57Z", + "aliases": [ + "CVE-2024-49902" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\njfs: check if leafidx greater than num leaves per dmap tree\n\nsyzbot report a out of bounds in dbSplit, it because dmt_leafidx greater\nthan num leaves per dmap tree, add a checking for dmt_leafidx in dbFindLeaf.\n\nShaggy:\nModified sanity check to apply to control pages as well as leaf pages.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49902" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/058aa89b3318be3d66a103ba7c68d717561e1dc6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2451e5917c56be45d4add786e2a059dd9c2c37c4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/25d2a3ff02f22e215ce53355619df10cc5faa7ab" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4a7bf6a01fb441009a6698179a739957efd88e38" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7fff9a9f866e99931cf6fa260288e55d01626582" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cb0eb10558802764f07de1dc439c4609e27cb4f0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d64ff0d2306713ff084d4b09f84ed1a8c75ecc32" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-q43m-8jgc-g8w7/GHSA-q43m-8jgc-g8w7.json b/advisories/unreviewed/2024/10/GHSA-q43m-8jgc-g8w7/GHSA-q43m-8jgc-g8w7.json new file mode 100644 index 00000000000..42bc70901a2 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-q43m-8jgc-g8w7/GHSA-q43m-8jgc-g8w7.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q43m-8jgc-g8w7", + "modified": "2024-10-21T18:30:57Z", + "published": "2024-10-21T18:30:57Z", + "aliases": [ + "CVE-2024-49913" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Add null check for top_pipe_to_program in commit_planes_for_stream\n\nThis commit addresses a null pointer dereference issue in the\n`commit_planes_for_stream` function at line 4140. The issue could occur\nwhen `top_pipe_to_program` is null.\n\nThe fix adds a check to ensure `top_pipe_to_program` is not null before\naccessing its stream_res. This prevents a null pointer dereference.\n\nReported by smatch:\ndrivers/gpu/drm/amd/amdgpu/../display/dc/core/dc.c:4140 commit_planes_for_stream() error: we previously assumed 'top_pipe_to_program' could be null (see line 3906)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49913" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1ebfa6663807c144be8c8b6727375012409d2356" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3929e382e4758aff42da0102a60d13337c99d3b8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/40193ff73630adf76bc0d82398f7d90fb576dba4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/66d71a72539e173a9b00ca0b1852cbaa5f5bf1ad" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/73efd2a611b62fee71a7b7f27d9d08bb60da8a72" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8ab59527852a6f7780aad6185729550ca0569122" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e47e563c6f0db7d792a559301862c19ead0dfc2f" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-q7pc-7wvx-9qcx/GHSA-q7pc-7wvx-9qcx.json b/advisories/unreviewed/2024/10/GHSA-q7pc-7wvx-9qcx/GHSA-q7pc-7wvx-9qcx.json new file mode 100644 index 00000000000..24783b31e53 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-q7pc-7wvx-9qcx/GHSA-q7pc-7wvx-9qcx.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q7pc-7wvx-9qcx", + "modified": "2024-10-21T18:30:59Z", + "published": "2024-10-21T18:30:59Z", + "aliases": [ + "CVE-2024-49959" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\njbd2: stop waiting for space when jbd2_cleanup_journal_tail() returns error\n\nIn __jbd2_log_wait_for_space(), we might call jbd2_cleanup_journal_tail()\nto recover some journal space. But if an error occurs while executing\njbd2_cleanup_journal_tail() (e.g., an EIO), we don't stop waiting for free\nspace right away, we try other branches, and if j_committing_transaction\nis NULL (i.e., the tid is 0), we will get the following complain:\n\n============================================\nJBD2: I/O error when updating journal superblock for sdd-8.\n__jbd2_log_wait_for_space: needed 256 blocks and only had 217 space available\n__jbd2_log_wait_for_space: no way to get more journal space in sdd-8\n------------[ cut here ]------------\nWARNING: CPU: 2 PID: 139804 at fs/jbd2/checkpoint.c:109 __jbd2_log_wait_for_space+0x251/0x2e0\nModules linked in:\nCPU: 2 PID: 139804 Comm: kworker/u8:3 Not tainted 6.6.0+ #1\nRIP: 0010:__jbd2_log_wait_for_space+0x251/0x2e0\nCall Trace:\n \n add_transaction_credits+0x5d1/0x5e0\n start_this_handle+0x1ef/0x6a0\n jbd2__journal_start+0x18b/0x340\n ext4_dirty_inode+0x5d/0xb0\n __mark_inode_dirty+0xe4/0x5d0\n generic_update_time+0x60/0x70\n[...]\n============================================\n\nSo only if jbd2_cleanup_journal_tail() returns 1, i.e., there is nothing to\nclean up at the moment, continue to try to reclaim free space in other ways.\n\nNote that this fix relies on commit 6f6a6fda2945 (\"jbd2: fix ocfs2 corrupt\nwhen updating journal superblock fails\") to make jbd2_cleanup_journal_tail\nreturn the correct error code.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49959" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1c62dc0d82c62f0dc8fcdc4843208e522acccaf5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3ced0fe6c0eff032733ea8b38778b34707270138" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/481e8f18a290e39e04ddb7feb2bb2a2cc3b213ed" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/70bae48377a2c4296fd3caf4caf8f11079111019" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c6bf043b210eac67d35a114e345c4e5585672913" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ec7f8337c98ad281020ad1f11ba492462d80737a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f5cacdc6f2bb2a9bf214469dd7112b43dd2dd68a" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-q823-fhxh-997g/GHSA-q823-fhxh-997g.json b/advisories/unreviewed/2024/10/GHSA-q823-fhxh-997g/GHSA-q823-fhxh-997g.json new file mode 100644 index 00000000000..961f1aba919 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-q823-fhxh-997g/GHSA-q823-fhxh-997g.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q823-fhxh-997g", + "modified": "2024-10-21T18:30:57Z", + "published": "2024-10-21T18:30:57Z", + "aliases": [ + "CVE-2024-49894" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Fix index out of bounds in degamma hardware format translation\n\nFixes index out of bounds issue in\n`cm_helper_translate_curve_to_degamma_hw_format` function. The issue\ncould occur when the index 'i' exceeds the number of transfer function\npoints (TRANSFER_FUNC_POINTS).\n\nThe fix adds a check to ensure 'i' is within bounds before accessing the\ntransfer function points. If 'i' is out of bounds the function returns\nfalse to indicate an error.\n\nReported by smatch:\ndrivers/gpu/drm/amd/amdgpu/../display/dc/dcn10/dcn10_cm_common.c:594 cm_helper_translate_curve_to_degamma_hw_format() error: buffer overflow 'output_tf->tf_pts.red' 1025 <= s32max\ndrivers/gpu/drm/amd/amdgpu/../display/dc/dcn10/dcn10_cm_common.c:595 cm_helper_translate_curve_to_degamma_hw_format() error: buffer overflow 'output_tf->tf_pts.green' 1025 <= s32max\ndrivers/gpu/drm/amd/amdgpu/../display/dc/dcn10/dcn10_cm_common.c:596 cm_helper_translate_curve_to_degamma_hw_format() error: buffer overflow 'output_tf->tf_pts.blue' 1025 <= s32max", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49894" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/07078fa5d589a7fbce8f81ea8acf7aa0021ab38e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/122e3a7a8c7bcbe3aacddd6103f67f9f36bed473" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2495c8e272d84685403506833a664fad932e453a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2f5da549535be8ccd2ab7c9abac8562ad370b181" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b7e99058eb2e86aabd7a10761e76cae33d22b49f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c130a3c09e3746c1a09ce26c20d21d449d039b1d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c6979719012a90e5b8e3bc31725fbfdd0b9b2b79" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-q8m3-vwhc-qqmc/GHSA-q8m3-vwhc-qqmc.json b/advisories/unreviewed/2024/10/GHSA-q8m3-vwhc-qqmc/GHSA-q8m3-vwhc-qqmc.json new file mode 100644 index 00000000000..30dff1028c4 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-q8m3-vwhc-qqmc/GHSA-q8m3-vwhc-qqmc.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q8m3-vwhc-qqmc", + "modified": "2024-10-21T18:30:57Z", + "published": "2024-10-21T18:30:57Z", + "aliases": [ + "CVE-2024-49891" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: lpfc: Validate hdwq pointers before dereferencing in reset/errata paths\n\nWhen the HBA is undergoing a reset or is handling an errata event, NULL ptr\ndereference crashes may occur in routines such as\nlpfc_sli_flush_io_rings(), lpfc_dev_loss_tmo_callbk(), or\nlpfc_abort_handler().\n\nAdd NULL ptr checks before dereferencing hdwq pointers that may have been\nfreed due to operations colliding with a reset or errata event handler.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49891" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2be1d4f11944cd6283cb97268b3e17c4424945ca" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/99a801e2fca39a6f31e543fc3383058a8955896f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fd665c8dbdb19548965b0ae80c490de00e906366" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-qf5q-fm5c-hc2p/GHSA-qf5q-fm5c-hc2p.json b/advisories/unreviewed/2024/10/GHSA-qf5q-fm5c-hc2p/GHSA-qf5q-fm5c-hc2p.json new file mode 100644 index 00000000000..2ea8a380425 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-qf5q-fm5c-hc2p/GHSA-qf5q-fm5c-hc2p.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qf5q-fm5c-hc2p", + "modified": "2024-10-21T18:30:59Z", + "published": "2024-10-21T18:30:59Z", + "aliases": [ + "CVE-2024-49987" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpftool: Fix undefined behavior in qsort(NULL, 0, ...)\n\nWhen netfilter has no entry to display, qsort is called with\nqsort(NULL, 0, ...). This results in undefined behavior, as UBSan\nreports:\n\nnet.c:827:2: runtime error: null pointer passed as argument 1, which is declared to never be null\n\nAlthough the C standard does not explicitly state whether calling qsort\nwith a NULL pointer when the size is 0 constitutes undefined behavior,\nSection 7.1.4 of the C standard (Use of library functions) mentions:\n\n\"Each of the following statements applies unless explicitly stated\notherwise in the detailed descriptions that follow: If an argument to a\nfunction has an invalid value (such as a value outside the domain of\nthe function, or a pointer outside the address space of the program, or\na null pointer, or a pointer to non-modifiable storage when the\ncorresponding parameter is not const-qualified) or a type (after\npromotion) not expected by a function with variable number of\narguments, the behavior is undefined.\"\n\nTo avoid this, add an early return when nf_link_info is NULL to prevent\ncalling qsort with a NULL pointer.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49987" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2e0f6f33f2aa87493b365a38a8fd87b8854b7734" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c208b02827eb642758cef65641995fd3f38c89af" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c2d9f9a7837ab29ccae0c42252f17d436bf0a501" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f04e2ad394e2755d0bb2d858ecb5598718bf00d5" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-qfhj-q535-jf9w/GHSA-qfhj-q535-jf9w.json b/advisories/unreviewed/2024/10/GHSA-qfhj-q535-jf9w/GHSA-qfhj-q535-jf9w.json new file mode 100644 index 00000000000..635eb0e7347 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-qfhj-q535-jf9w/GHSA-qfhj-q535-jf9w.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qfhj-q535-jf9w", + "modified": "2024-10-21T18:30:59Z", + "published": "2024-10-21T18:30:59Z", + "aliases": [ + "CVE-2024-49985" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ni2c: stm32f7: Do not prepare/unprepare clock during runtime suspend/resume\n\nIn case there is any sort of clock controller attached to this I2C bus\ncontroller, for example Versaclock or even an AIC32x4 I2C codec, then\nan I2C transfer triggered from the clock controller clk_ops .prepare\ncallback may trigger a deadlock on drivers/clk/clk.c prepare_lock mutex.\n\nThis is because the clock controller first grabs the prepare_lock mutex\nand then performs the prepare operation, including its I2C access. The\nI2C access resumes this I2C bus controller via .runtime_resume callback,\nwhich calls clk_prepare_enable(), which attempts to grab the prepare_lock\nmutex again and deadlocks.\n\nSince the clock are already prepared since probe() and unprepared in\nremove(), use simple clk_enable()/clk_disable() calls to enable and\ndisable the clock on runtime suspend and resume, to avoid hitting the\nprepare_lock mutex.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49985" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/048bbbdbf85e5e00258dfb12f5e368f908801d7b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1883cad2cc629ded4a3556c0bbb8b42533ad8764" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/22a1f8a5b56ba93d3e8b7a1dafa24e01c8bb48ba" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/894cd5f5fd9061983445bbd1fa3d81be43095344" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9b8bc33ad64192f54142396470cc34ce539a8940" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c2024b1a583ab9176c797ea1e5f57baf8d5e2682" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fac3c9f7784e8184c0338e9f0877b81e55d3ef1c" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-qgr6-hgc6-qm52/GHSA-qgr6-hgc6-qm52.json b/advisories/unreviewed/2024/10/GHSA-qgr6-hgc6-qm52/GHSA-qgr6-hgc6-qm52.json new file mode 100644 index 00000000000..3a989edb20d --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-qgr6-hgc6-qm52/GHSA-qgr6-hgc6-qm52.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qgr6-hgc6-qm52", + "modified": "2024-10-21T18:30:57Z", + "published": "2024-10-21T18:30:57Z", + "aliases": [ + "CVE-2024-49896" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Check stream before comparing them\n\n[WHAT & HOW]\namdgpu_dm can pass a null stream to dc_is_stream_unchanged. It is\nnecessary to check for null before dereferencing them.\n\nThis fixes 1 FORWARD_NULL issue reported by Coverity.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49896" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0167d570f6a0b38689c4a0e50bf79c518d827500" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/14db8692afe1aa2143b673856bb603713d8ea93f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/35ff747c86767937ee1e0ca987545b7eed7a0810" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/42d31a33643813cce55ee1ebbad3a2d0d24a08e0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5b4b13e678b15975055f4ff1ce4cf0ce4c19b6c4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e41a291e1bef1153bba091b6580ecc7affc53c82" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e8da54b7f8a17e44e67ea6d1037f35450af28115" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-qjpg-5hx2-g69j/GHSA-qjpg-5hx2-g69j.json b/advisories/unreviewed/2024/10/GHSA-qjpg-5hx2-g69j/GHSA-qjpg-5hx2-g69j.json new file mode 100644 index 00000000000..ee1f3569180 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-qjpg-5hx2-g69j/GHSA-qjpg-5hx2-g69j.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qjpg-5hx2-g69j", + "modified": "2024-10-21T18:30:59Z", + "published": "2024-10-21T18:30:59Z", + "aliases": [ + "CVE-2024-49984" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/v3d: Prevent out of bounds access in performance query extensions\n\nCheck that the number of perfmons userspace is passing in the copy and\nreset extensions is not greater than the internal kernel storage where\nthe ids will be copied into.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49984" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3e50d72abe50204c7b19784a66e86da29dde32c2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/73ad583bd4938bf37d2709fc36901eb6f22f2722" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d9536f16be3970c170571efa707c13cd089c774e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f32b5128d2c440368b5bf3a7a356823e235caabb" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-qjwp-794r-6x7v/GHSA-qjwp-794r-6x7v.json b/advisories/unreviewed/2024/10/GHSA-qjwp-794r-6x7v/GHSA-qjwp-794r-6x7v.json index 721e205c2bf..b1c63d57b21 100644 --- a/advisories/unreviewed/2024/10/GHSA-qjwp-794r-6x7v/GHSA-qjwp-794r-6x7v.json +++ b/advisories/unreviewed/2024/10/GHSA-qjwp-794r-6x7v/GHSA-qjwp-794r-6x7v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qjwp-794r-6x7v", - "modified": "2024-10-18T15:31:11Z", + "modified": "2024-10-21T18:30:45Z", "published": "2024-10-15T12:30:37Z", "aliases": [ "CVE-2024-47674" @@ -40,6 +40,10 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/a95a24fcaee1b892e47d5e6dcc403f713874ee80" + }, + { + "type": "WEB", + "url": "https://project-zero.issues.chromium.org/issues/366053091" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/10/GHSA-qm34-9r78-66cq/GHSA-qm34-9r78-66cq.json b/advisories/unreviewed/2024/10/GHSA-qm34-9r78-66cq/GHSA-qm34-9r78-66cq.json index b12d6efb5d9..3760a27b413 100644 --- a/advisories/unreviewed/2024/10/GHSA-qm34-9r78-66cq/GHSA-qm34-9r78-66cq.json +++ b/advisories/unreviewed/2024/10/GHSA-qm34-9r78-66cq/GHSA-qm34-9r78-66cq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qm34-9r78-66cq", - "modified": "2024-10-18T21:32:18Z", + "modified": "2024-10-21T18:30:46Z", "published": "2024-10-18T15:31:20Z", "aliases": [ "CVE-2024-9537" @@ -53,6 +53,10 @@ "type": "WEB", "url": "https://www.bleepingcomputer.com/news/security/rackspace-monitoring-data-stolen-in-sciencelogic-zero-day-attack" }, + { + "type": "WEB", + "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2024-9537" + }, { "type": "WEB", "url": "https://www.theregister.com/2024/09/30/rackspace_zero_day_attack" diff --git a/advisories/unreviewed/2024/10/GHSA-qm4c-x73m-f8mf/GHSA-qm4c-x73m-f8mf.json b/advisories/unreviewed/2024/10/GHSA-qm4c-x73m-f8mf/GHSA-qm4c-x73m-f8mf.json new file mode 100644 index 00000000000..8c864a8d29b --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-qm4c-x73m-f8mf/GHSA-qm4c-x73m-f8mf.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qm4c-x73m-f8mf", + "modified": "2024-10-21T18:30:58Z", + "published": "2024-10-21T18:30:58Z", + "aliases": [ + "CVE-2024-49952" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: prevent nf_skb_duplicated corruption\n\nsyzbot found that nf_dup_ipv4() or nf_dup_ipv6() could write\nper-cpu variable nf_skb_duplicated in an unsafe way [1].\n\nDisabling preemption as hinted by the splat is not enough,\nwe have to disable soft interrupts as well.\n\n[1]\nBUG: using __this_cpu_write() in preemptible [00000000] code: syz.4.282/6316\n caller is nf_dup_ipv4+0x651/0x8f0 net/ipv4/netfilter/nf_dup_ipv4.c:87\nCPU: 0 UID: 0 PID: 6316 Comm: syz.4.282 Not tainted 6.11.0-rc7-syzkaller-00104-g7052622fccb1 #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 08/06/2024\nCall Trace:\n \n __dump_stack lib/dump_stack.c:93 [inline]\n dump_stack_lvl+0x241/0x360 lib/dump_stack.c:119\n check_preemption_disabled+0x10e/0x120 lib/smp_processor_id.c:49\n nf_dup_ipv4+0x651/0x8f0 net/ipv4/netfilter/nf_dup_ipv4.c:87\n nft_dup_ipv4_eval+0x1db/0x300 net/ipv4/netfilter/nft_dup_ipv4.c:30\n expr_call_ops_eval net/netfilter/nf_tables_core.c:240 [inline]\n nft_do_chain+0x4ad/0x1da0 net/netfilter/nf_tables_core.c:288\n nft_do_chain_ipv4+0x202/0x320 net/netfilter/nft_chain_filter.c:23\n nf_hook_entry_hookfn include/linux/netfilter.h:154 [inline]\n nf_hook_slow+0xc3/0x220 net/netfilter/core.c:626\n nf_hook+0x2c4/0x450 include/linux/netfilter.h:269\n NF_HOOK_COND include/linux/netfilter.h:302 [inline]\n ip_output+0x185/0x230 net/ipv4/ip_output.c:433\n ip_local_out net/ipv4/ip_output.c:129 [inline]\n ip_send_skb+0x74/0x100 net/ipv4/ip_output.c:1495\n udp_send_skb+0xacf/0x1650 net/ipv4/udp.c:981\n udp_sendmsg+0x1c21/0x2a60 net/ipv4/udp.c:1269\n sock_sendmsg_nosec net/socket.c:730 [inline]\n __sock_sendmsg+0x1a6/0x270 net/socket.c:745\n ____sys_sendmsg+0x525/0x7d0 net/socket.c:2597\n ___sys_sendmsg net/socket.c:2651 [inline]\n __sys_sendmmsg+0x3b2/0x740 net/socket.c:2737\n __do_sys_sendmmsg net/socket.c:2766 [inline]\n __se_sys_sendmmsg net/socket.c:2763 [inline]\n __x64_sys_sendmmsg+0xa0/0xb0 net/socket.c:2763\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\nRIP: 0033:0x7f4ce4f7def9\nCode: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48\nRSP: 002b:00007f4ce5d4a038 EFLAGS: 00000246 ORIG_RAX: 0000000000000133\nRAX: ffffffffffffffda RBX: 00007f4ce5135f80 RCX: 00007f4ce4f7def9\nRDX: 0000000000000001 RSI: 0000000020005d40 RDI: 0000000000000006\nRBP: 00007f4ce4ff0b76 R08: 0000000000000000 R09: 0000000000000000\nR10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000\nR13: 0000000000000000 R14: 00007f4ce5135f80 R15: 00007ffd4cbc6d68\n ", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49952" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/38e3fd0c4a2616052eb3c8f4e6f32d1ff47cd663" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4e3542f40f3a94efa59ea328e307c50601ed7065" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/531754952f5dfc4b141523088147071d6e6112c4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/752e1924604254f1708f3e3700283a86ebdd325d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/92ceba94de6fb4cee2bf40b485979c342f44a492" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b40b027a0c0cc1cb9471a13f9730bb2fff12a15b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f839c5cd348201fec440d987cbca9b979bdb4fa7" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-qqcr-57gp-2jmq/GHSA-qqcr-57gp-2jmq.json b/advisories/unreviewed/2024/10/GHSA-qqcr-57gp-2jmq/GHSA-qqcr-57gp-2jmq.json new file mode 100644 index 00000000000..1be39f3aa46 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-qqcr-57gp-2jmq/GHSA-qqcr-57gp-2jmq.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qqcr-57gp-2jmq", + "modified": "2024-10-21T18:30:59Z", + "published": "2024-10-21T18:30:59Z", + "aliases": [ + "CVE-2024-49994" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nblock: fix integer overflow in BLKSECDISCARD\n\nI independently rediscovered\n\n\tcommit 22d24a544b0d49bbcbd61c8c0eaf77d3c9297155\n\tblock: fix overflow in blk_ioctl_discard()\n\nbut for secure erase.\n\nSame problem:\n\n\tuint64_t r[2] = {512, 18446744073709551104ULL};\n\tioctl(fd, BLKSECDISCARD, r);\n\nwill enter near infinite loop inside blkdev_issue_secure_erase():\n\n\ta.out: attempt to access beyond end of device\n\tloop0: rw=5, sector=3399043073, nr_sectors = 1024 limit=2048\n\tbio_check_eod: 3286214 callbacks suppressed", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49994" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0842ddd83939eb4db940b9af7d39e79722bc41aa" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/697ba0b6ec4ae04afb67d3911799b5e2043b4455" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6c9915fa9410cbb9bd75ee283c03120046c56d3d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-qrr4-q9rq-pfvg/GHSA-qrr4-q9rq-pfvg.json b/advisories/unreviewed/2024/10/GHSA-qrr4-q9rq-pfvg/GHSA-qrr4-q9rq-pfvg.json index 4916319c124..3ad57922876 100644 --- a/advisories/unreviewed/2024/10/GHSA-qrr4-q9rq-pfvg/GHSA-qrr4-q9rq-pfvg.json +++ b/advisories/unreviewed/2024/10/GHSA-qrr4-q9rq-pfvg/GHSA-qrr4-q9rq-pfvg.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qrr4-q9rq-pfvg", - "modified": "2024-10-16T18:31:47Z", + "modified": "2024-10-21T18:30:46Z", "published": "2024-10-16T18:31:47Z", "aliases": [ "CVE-2024-4211" ], "details": "Improper Validation of Specified Quantity in Input vulnerability in OpenText OpenText Application Automation Tools allows Exploiting Incorrectly Configured Access Control Security Levels.\n\n\nMultiple missing permission checks - ALM job config has been discovered in OpenText Application Automation Tools. The vulnerability could allow users with Overall/Read permission to enumerate ALM server names, usernames and client IDs configured to be used with ALM servers.\n\n\nThis issue affects OpenText Application Automation Tools: 24.1.0 and below.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:X/V:X/RE:L/U:Clear" diff --git a/advisories/unreviewed/2024/10/GHSA-qwr8-frg5-xvvr/GHSA-qwr8-frg5-xvvr.json b/advisories/unreviewed/2024/10/GHSA-qwr8-frg5-xvvr/GHSA-qwr8-frg5-xvvr.json new file mode 100644 index 00000000000..2968bae40fd --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-qwr8-frg5-xvvr/GHSA-qwr8-frg5-xvvr.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qwr8-frg5-xvvr", + "modified": "2024-10-21T18:30:57Z", + "published": "2024-10-21T18:30:57Z", + "aliases": [ + "CVE-2024-49895" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Fix index out of bounds in DCN30 degamma hardware format translation\n\nThis commit addresses a potential index out of bounds issue in the\n`cm3_helper_translate_curve_to_degamma_hw_format` function in the DCN30\ncolor management module. The issue could occur when the index 'i'\nexceeds the number of transfer function points (TRANSFER_FUNC_POINTS).\n\nThe fix adds a check to ensure 'i' is within bounds before accessing the\ntransfer function points. If 'i' is out of bounds, the function returns\nfalse to indicate an error.\n\nReported by smatch:\ndrivers/gpu/drm/amd/amdgpu/../display/dc/dcn30/dcn30_cm_common.c:338 cm3_helper_translate_curve_to_degamma_hw_format() error: buffer overflow 'output_tf->tf_pts.red' 1025 <= s32max\ndrivers/gpu/drm/amd/amdgpu/../display/dc/dcn30/dcn30_cm_common.c:339 cm3_helper_translate_curve_to_degamma_hw_format() error: buffer overflow 'output_tf->tf_pts.green' 1025 <= s32max\ndrivers/gpu/drm/amd/amdgpu/../display/dc/dcn30/dcn30_cm_common.c:340 cm3_helper_translate_curve_to_degamma_hw_format() error: buffer overflow 'output_tf->tf_pts.blue' 1025 <= s32max", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49895" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0d38a0751143afc03faef02d55d31f70374ff843" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ad89f83343a501890cf082c8a584e96b59fe4015" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bc50b614d59990747dd5aeced9ec22f9258991ff" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c4fdc2d6fea129684b82bab90bb52fbace494a58" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/de6ee4f9e6b1c36b4fdc7c345c1a6de9e246093e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f3ccd855b4395ce65f10dd37847167f52e122b70" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f5c3d306de91a4b69cfe3eedb72b42d452593e42" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-r5f6-w2pg-mf93/GHSA-r5f6-w2pg-mf93.json b/advisories/unreviewed/2024/10/GHSA-r5f6-w2pg-mf93/GHSA-r5f6-w2pg-mf93.json new file mode 100644 index 00000000000..c12c2b1b249 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-r5f6-w2pg-mf93/GHSA-r5f6-w2pg-mf93.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r5f6-w2pg-mf93", + "modified": "2024-10-21T18:30:59Z", + "published": "2024-10-21T18:30:58Z", + "aliases": [ + "CVE-2024-49964" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/hugetlb: fix memfd_pin_folios free_huge_pages leak\n\nmemfd_pin_folios followed by unpin_folios fails to restore free_huge_pages\nif the pages were not already faulted in, because the folio refcount for\npages created by memfd_alloc_folio never goes to 0. memfd_pin_folios\nneeds another folio_put to undo the folio_try_get below:\n\nmemfd_alloc_folio()\n alloc_hugetlb_folio_nodemask()\n dequeue_hugetlb_folio_nodemask()\n dequeue_hugetlb_folio_node_exact()\n folio_ref_unfreeze(folio, 1); ; adds 1 refcount\n folio_try_get() ; adds 1 refcount\n hugetlb_add_to_page_cache() ; adds 512 refcount (on x86)\n\nWith the fix, after memfd_pin_folios + unpin_folios, the refcount for the\n(unfaulted) page is 512, which is correct, as the refcount for a faulted\nunpinned page is 513.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49964" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/59e081ff2e91bbf19b8c1ecb75b031f778858383" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c56b6f3d801d7ec8965993342bdd9e2972b6cb8e" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-rcg3-vwp6-7grp/GHSA-rcg3-vwp6-7grp.json b/advisories/unreviewed/2024/10/GHSA-rcg3-vwp6-7grp/GHSA-rcg3-vwp6-7grp.json new file mode 100644 index 00000000000..9b5f76e7164 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-rcg3-vwp6-7grp/GHSA-rcg3-vwp6-7grp.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rcg3-vwp6-7grp", + "modified": "2024-10-21T18:30:57Z", + "published": "2024-10-21T18:30:57Z", + "aliases": [ + "CVE-2024-49889" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\next4: avoid use-after-free in ext4_ext_show_leaf()\n\nIn ext4_find_extent(), path may be freed by error or be reallocated, so\nusing a previously saved *ppath may have been freed and thus may trigger\nuse-after-free, as follows:\n\next4_split_extent\n path = *ppath;\n ext4_split_extent_at(ppath)\n path = ext4_find_extent(ppath)\n ext4_split_extent_at(ppath)\n // ext4_find_extent fails to free path\n // but zeroout succeeds\n ext4_ext_show_leaf(inode, path)\n eh = path[depth].p_hdr\n // path use-after-free !!!\n\nSimilar to ext4_split_extent_at(), we use *ppath directly as an input to\next4_ext_show_leaf(). Fix a spelling error by the way.\n\nSame problem in ext4_ext_handle_unwritten_extents(). Since 'path' is only\nused in ext4_ext_show_leaf(), remove 'path' and use *ppath directly.\n\nThis issue is triggered only when EXT_DEBUG is defined and therefore does\nnot affect functionality.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49889" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2eba3b0cc5b8de624918d21f32b5b8db59a90b39" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/34b2096380ba475771971a778a478661a791aa15" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4999fed877bb64e3e7f9ab9996de2ca983c41928" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4e2524ba2ca5f54bdbb9e5153bea00421ef653f5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8b114f2cc7dd5d36729d040b68432fbd0f0a8868" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b0cb4561fc4284d04e69c8a66c8504928ab2484e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d483c7cc1796bd6a80e7b3a8fd494996260f6b67" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-rf58-pp6r-5653/GHSA-rf58-pp6r-5653.json b/advisories/unreviewed/2024/10/GHSA-rf58-pp6r-5653/GHSA-rf58-pp6r-5653.json new file mode 100644 index 00000000000..d5a40eec856 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-rf58-pp6r-5653/GHSA-rf58-pp6r-5653.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rf58-pp6r-5653", + "modified": "2024-10-21T18:30:59Z", + "published": "2024-10-21T18:30:59Z", + "aliases": [ + "CVE-2024-49978" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ngso: fix udp gso fraglist segmentation after pull from frag_list\n\nDetect gso fraglist skbs with corrupted geometry (see below) and\npass these to skb_segment instead of skb_segment_list, as the first\ncan segment them correctly.\n\nValid SKB_GSO_FRAGLIST skbs\n- consist of two or more segments\n- the head_skb holds the protocol headers plus first gso_size\n- one or more frag_list skbs hold exactly one segment\n- all but the last must be gso_size\n\nOptional datapath hooks such as NAT and BPF (bpf_skb_pull_data) can\nmodify these skbs, breaking these invariants.\n\nIn extreme cases they pull all data into skb linear. For UDP, this\ncauses a NULL ptr deref in __udpv4_gso_segment_list_csum at\nudp_hdr(seg->next)->dest.\n\nDetect invalid geometry due to pull, by checking head_skb size.\nDon't just drop, as this may blackhole a destination. Convert to be\nable to pass to regular skb_segment.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49978" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/080e6c9a3908de193a48f646c5ce1bfb15676ffc" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/33e28acf42ee863f332a958bfc2f1a284a3659df" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3cd00d2e3655fad3bda96dc1ebf17b6495f86fea" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a1e40ac5b5e9077fe1f7ae0eb88034db0f9ae1ab" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/af3122f5fdc0d00581d6e598a668df6bf54c9daa" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-rgx3-g7m3-gj3j/GHSA-rgx3-g7m3-gj3j.json b/advisories/unreviewed/2024/10/GHSA-rgx3-g7m3-gj3j/GHSA-rgx3-g7m3-gj3j.json new file mode 100644 index 00000000000..b49641376f4 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-rgx3-g7m3-gj3j/GHSA-rgx3-g7m3-gj3j.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rgx3-g7m3-gj3j", + "modified": "2024-10-21T18:30:57Z", + "published": "2024-10-21T18:30:57Z", + "aliases": [ + "CVE-2024-49903" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\njfs: Fix uaf in dbFreeBits\n\n[syzbot reported]\n==================================================================\nBUG: KASAN: slab-use-after-free in __mutex_lock_common kernel/locking/mutex.c:587 [inline]\nBUG: KASAN: slab-use-after-free in __mutex_lock+0xfe/0xd70 kernel/locking/mutex.c:752\nRead of size 8 at addr ffff8880229254b0 by task syz-executor357/5216\n\nCPU: 0 UID: 0 PID: 5216 Comm: syz-executor357 Not tainted 6.11.0-rc3-syzkaller-00156-gd7a5aa4b3c00 #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 06/27/2024\nCall Trace:\n \n __dump_stack lib/dump_stack.c:93 [inline]\n dump_stack_lvl+0x241/0x360 lib/dump_stack.c:119\n print_address_description mm/kasan/report.c:377 [inline]\n print_report+0x169/0x550 mm/kasan/report.c:488\n kasan_report+0x143/0x180 mm/kasan/report.c:601\n __mutex_lock_common kernel/locking/mutex.c:587 [inline]\n __mutex_lock+0xfe/0xd70 kernel/locking/mutex.c:752\n dbFreeBits+0x7ea/0xd90 fs/jfs/jfs_dmap.c:2390\n dbFreeDmap fs/jfs/jfs_dmap.c:2089 [inline]\n dbFree+0x35b/0x680 fs/jfs/jfs_dmap.c:409\n dbDiscardAG+0x8a9/0xa20 fs/jfs/jfs_dmap.c:1650\n jfs_ioc_trim+0x433/0x670 fs/jfs/jfs_discard.c:100\n jfs_ioctl+0x2d0/0x3e0 fs/jfs/ioctl.c:131\n vfs_ioctl fs/ioctl.c:51 [inline]\n __do_sys_ioctl fs/ioctl.c:907 [inline]\n __se_sys_ioctl+0xfc/0x170 fs/ioctl.c:893\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83\n\nFreed by task 5218:\n kasan_save_stack mm/kasan/common.c:47 [inline]\n kasan_save_track+0x3f/0x80 mm/kasan/common.c:68\n kasan_save_free_info+0x40/0x50 mm/kasan/generic.c:579\n poison_slab_object+0xe0/0x150 mm/kasan/common.c:240\n __kasan_slab_free+0x37/0x60 mm/kasan/common.c:256\n kasan_slab_free include/linux/kasan.h:184 [inline]\n slab_free_hook mm/slub.c:2252 [inline]\n slab_free mm/slub.c:4473 [inline]\n kfree+0x149/0x360 mm/slub.c:4594\n dbUnmount+0x11d/0x190 fs/jfs/jfs_dmap.c:278\n jfs_mount_rw+0x4ac/0x6a0 fs/jfs/jfs_mount.c:247\n jfs_remount+0x3d1/0x6b0 fs/jfs/super.c:454\n reconfigure_super+0x445/0x880 fs/super.c:1083\n vfs_cmd_reconfigure fs/fsopen.c:263 [inline]\n vfs_fsconfig_locked fs/fsopen.c:292 [inline]\n __do_sys_fsconfig fs/fsopen.c:473 [inline]\n __se_sys_fsconfig+0xb6e/0xf80 fs/fsopen.c:345\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\n[Analysis]\nThere are two paths (dbUnmount and jfs_ioc_trim) that generate race\ncondition when accessing bmap, which leads to the occurrence of uaf.\n\nUse the lock s_umount to synchronize them, in order to avoid uaf caused\nby race condition.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49903" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0c238da83f56bb895cab1e5851d034ac45b158d1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4218b31ecc7af7e191768d32e32ed4386d8f9b76" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/95accb7183badca387f7a8d19a2475cf3089f148" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a9603a6f75df2fd8125cd208c98cfaa0fe3f7505" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d6c1b3599b2feb5c7291f5ac3a36e5fa7cedb234" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e7ae14f7ee76c6ef5a48aebab1a278ad78f42619" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fd026b6b6758d5569705c02540b40f3bbf822b9a" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-rqg9-48mq-4pm8/GHSA-rqg9-48mq-4pm8.json b/advisories/unreviewed/2024/10/GHSA-rqg9-48mq-4pm8/GHSA-rqg9-48mq-4pm8.json new file mode 100644 index 00000000000..11a2486d68d --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-rqg9-48mq-4pm8/GHSA-rqg9-48mq-4pm8.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rqg9-48mq-4pm8", + "modified": "2024-10-21T18:30:57Z", + "published": "2024-10-21T18:30:57Z", + "aliases": [ + "CVE-2024-49916" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Add NULL check for clk_mgr and clk_mgr->funcs in dcn401_init_hw\n\nThis commit addresses a potential null pointer dereference issue in the\n`dcn401_init_hw` function. The issue could occur when `dc->clk_mgr` or\n`dc->clk_mgr->funcs` is null.\n\nThe fix adds a check to ensure `dc->clk_mgr` and `dc->clk_mgr->funcs` is\nnot null before accessing its functions. This prevents a potential null\npointer dereference.\n\nReported by smatch:\ndrivers/gpu/drm/amd/amdgpu/../display/dc/hwss/dcn401/dcn401_hwseq.c:416 dcn401_init_hw() error: we previously assumed 'dc->clk_mgr' could be null (see line 225)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49916" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4b6377f0e96085cbec96eb7f0b282430ccdd3d75" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ac1c41e318074d8a9ea925787e366be15d7645e8" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-rrh5-rfhq-mff2/GHSA-rrh5-rfhq-mff2.json b/advisories/unreviewed/2024/10/GHSA-rrh5-rfhq-mff2/GHSA-rrh5-rfhq-mff2.json new file mode 100644 index 00000000000..24fabcd2323 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-rrh5-rfhq-mff2/GHSA-rrh5-rfhq-mff2.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rrh5-rfhq-mff2", + "modified": "2024-10-21T18:30:56Z", + "published": "2024-10-21T18:30:56Z", + "aliases": [ + "CVE-2024-49872" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/gup: fix memfd_pin_folios alloc race panic\n\nIf memfd_pin_folios tries to create a hugetlb page, but someone else\nalready did, then folio gets the value -EEXIST here:\n\n folio = memfd_alloc_folio(memfd, start_idx);\n if (IS_ERR(folio)) {\n ret = PTR_ERR(folio);\n if (ret != -EEXIST)\n goto err;\n\nthen on the next trip through the \"while start_idx\" loop we panic here:\n\n if (folio) {\n folio_put(folio);\n\nTo fix, set the folio to NULL on error.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49872" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ce645b9fdc78ec5d28067286e92871ddae6817d5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e28f39b359c0cfdcc011603e51187085a5f1e5e3" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-rvgw-688x-x595/GHSA-rvgw-688x-x595.json b/advisories/unreviewed/2024/10/GHSA-rvgw-688x-x595/GHSA-rvgw-688x-x595.json new file mode 100644 index 00000000000..ab98d5429de --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-rvgw-688x-x595/GHSA-rvgw-688x-x595.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rvgw-688x-x595", + "modified": "2024-10-21T18:30:56Z", + "published": "2024-10-21T18:30:56Z", + "aliases": [ + "CVE-2024-49870" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncachefiles: fix dentry leak in cachefiles_open_file()\n\nA dentry leak may be caused when a lookup cookie and a cull are concurrent:\n\n P1 | P2\n-----------------------------------------------------------\ncachefiles_lookup_cookie\n cachefiles_look_up_object\n lookup_one_positive_unlocked\n // get dentry\n cachefiles_cull\n inode->i_flags |= S_KERNEL_FILE;\n cachefiles_open_file\n cachefiles_mark_inode_in_use\n __cachefiles_mark_inode_in_use\n can_use = false\n if (!(inode->i_flags & S_KERNEL_FILE))\n can_use = true\n\t return false\n return false\n // Returns an error but doesn't put dentry\n\nAfter that the following WARNING will be triggered when the backend folder\nis umounted:\n\n==================================================================\nBUG: Dentry 000000008ad87947{i=7a,n=Dx_1_1.img} still in use (1) [unmount of ext4 sda]\nWARNING: CPU: 4 PID: 359261 at fs/dcache.c:1767 umount_check+0x5d/0x70\nCPU: 4 PID: 359261 Comm: umount Not tainted 6.6.0-dirty #25\nRIP: 0010:umount_check+0x5d/0x70\nCall Trace:\n \n d_walk+0xda/0x2b0\n do_one_tree+0x20/0x40\n shrink_dcache_for_umount+0x2c/0x90\n generic_shutdown_super+0x20/0x160\n kill_block_super+0x1a/0x40\n ext4_kill_sb+0x22/0x40\n deactivate_locked_super+0x35/0x80\n cleanup_mnt+0x104/0x160\n==================================================================\n\nWhether cachefiles_open_file() returns true or false, the reference count\nobtained by lookup_positive_unlocked() in cachefiles_look_up_object()\nshould be released.\n\nTherefore release that reference count in cachefiles_look_up_object() to\nfix the above issue and simplify the code.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49870" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7fa2382f97421978514a419c93054eca69f5247b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c7d10fa7d7691558ff967668494672415f5fa151" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d32ff64c872d7e08e893c32ba6a2374583444410" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/da6ef2dffe6056aad3435e6cf7c6471c2a62187c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e4a28489b310339b2b8187bec0a437709be551c1" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-rxhv-mw63-w89c/GHSA-rxhv-mw63-w89c.json b/advisories/unreviewed/2024/10/GHSA-rxhv-mw63-w89c/GHSA-rxhv-mw63-w89c.json new file mode 100644 index 00000000000..bc7aae2ac84 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-rxhv-mw63-w89c/GHSA-rxhv-mw63-w89c.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rxhv-mw63-w89c", + "modified": "2024-10-21T18:30:58Z", + "published": "2024-10-21T18:30:58Z", + "aliases": [ + "CVE-2024-49948" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: add more sanity checks to qdisc_pkt_len_init()\n\nOne path takes care of SKB_GSO_DODGY, assuming\nskb->len is bigger than hdr_len.\n\nvirtio_net_hdr_to_skb() does not fully dissect TCP headers,\nit only make sure it is at least 20 bytes.\n\nIt is possible for an user to provide a malicious 'GSO' packet,\ntotal length of 80 bytes.\n\n- 20 bytes of IPv4 header\n- 60 bytes TCP header\n- a small gso_size like 8\n\nvirtio_net_hdr_to_skb() would declare this packet as a normal\nGSO packet, because it would see 40 bytes of payload,\nbigger than gso_size.\n\nWe need to make detect this case to not underflow\nqdisc_skb_cb(skb)->pkt_len.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49948" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1eebe602a8d8264a12e35e39d0645fa88dbbacdd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2415f465730e48b6e38da1c7c097317bf5dd2d20" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/27a8fabc54d2f960d47bdfbebf2bdc6e8a92a4c4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/566a931a1436d0e0ad13708ea55479b95426213c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9b0ee571d20a238a22722126abdfde61f1b2bdd0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ab9a9a9e9647392a19e7a885b08000e89c86b535" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ff1c3cadcf405ab37dd91418a62a7acecf3bc5e2" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-v3jw-p9pj-m453/GHSA-v3jw-p9pj-m453.json b/advisories/unreviewed/2024/10/GHSA-v3jw-p9pj-m453/GHSA-v3jw-p9pj-m453.json new file mode 100644 index 00000000000..576f54618a6 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-v3jw-p9pj-m453/GHSA-v3jw-p9pj-m453.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v3jw-p9pj-m453", + "modified": "2024-10-21T18:30:58Z", + "published": "2024-10-21T18:30:58Z", + "aliases": [ + "CVE-2024-49934" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfs/inode: Prevent dump_mapping() accessing invalid dentry.d_name.name\n\nIt's observed that a crash occurs during hot-remove a memory device,\nin which user is accessing the hugetlb. See calltrace as following:\n\n------------[ cut here ]------------\nWARNING: CPU: 1 PID: 14045 at arch/x86/mm/fault.c:1278 do_user_addr_fault+0x2a0/0x790\nModules linked in: kmem device_dax cxl_mem cxl_pmem cxl_port cxl_pci dax_hmem dax_pmem nd_pmem cxl_acpi nd_btt cxl_core crc32c_intel nvme virtiofs fuse nvme_core nfit libnvdimm dm_multipath scsi_dh_rdac scsi_dh_emc s\nmirror dm_region_hash dm_log dm_mod\nCPU: 1 PID: 14045 Comm: daxctl Not tainted 6.10.0-rc2-lizhijian+ #492\nHardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014\nRIP: 0010:do_user_addr_fault+0x2a0/0x790\nCode: 48 8b 00 a8 04 0f 84 b5 fe ff ff e9 1c ff ff ff 4c 89 e9 4c 89 e2 be 01 00 00 00 bf 02 00 00 00 e8 b5 ef 24 00 e9 42 fe ff ff <0f> 0b 48 83 c4 08 4c 89 ea 48 89 ee 4c 89 e7 5b 5d 41 5c 41 5d 41\nRSP: 0000:ffffc90000a575f0 EFLAGS: 00010046\nRAX: ffff88800c303600 RBX: 0000000000000000 RCX: 0000000000000000\nRDX: 0000000000001000 RSI: ffffffff82504162 RDI: ffffffff824b2c36\nRBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000000000\nR10: 0000000000000000 R11: 0000000000000000 R12: ffffc90000a57658\nR13: 0000000000001000 R14: ffff88800bc2e040 R15: 0000000000000000\nFS: 00007f51cb57d880(0000) GS:ffff88807fd00000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000000000001000 CR3: 00000000072e2004 CR4: 00000000001706f0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nCall Trace:\n \n ? __warn+0x8d/0x190\n ? do_user_addr_fault+0x2a0/0x790\n ? report_bug+0x1c3/0x1d0\n ? handle_bug+0x3c/0x70\n ? exc_invalid_op+0x14/0x70\n ? asm_exc_invalid_op+0x16/0x20\n ? do_user_addr_fault+0x2a0/0x790\n ? exc_page_fault+0x31/0x200\n exc_page_fault+0x68/0x200\n<...snip...>\nBUG: unable to handle page fault for address: 0000000000001000\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\n PGD 800000000ad92067 P4D 800000000ad92067 PUD 7677067 PMD 0\n Oops: Oops: 0000 [#1] PREEMPT SMP PTI\n ---[ end trace 0000000000000000 ]---\n BUG: unable to handle page fault for address: 0000000000001000\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\n PGD 800000000ad92067 P4D 800000000ad92067 PUD 7677067 PMD 0\n Oops: Oops: 0000 [#1] PREEMPT SMP PTI\n CPU: 1 PID: 14045 Comm: daxctl Kdump: loaded Tainted: G W 6.10.0-rc2-lizhijian+ #492\n Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014\n RIP: 0010:dentry_name+0x1f4/0x440\n<...snip...>\n? dentry_name+0x2fa/0x440\nvsnprintf+0x1f3/0x4f0\nvprintk_store+0x23a/0x540\nvprintk_emit+0x6d/0x330\n_printk+0x58/0x80\ndump_mapping+0x10b/0x1a0\n? __pfx_free_object_rcu+0x10/0x10\n__dump_page+0x26b/0x3e0\n? vprintk_emit+0xe0/0x330\n? _printk+0x58/0x80\n? dump_page+0x17/0x50\ndump_page+0x17/0x50\ndo_migrate_range+0x2f7/0x7f0\n? do_migrate_range+0x42/0x7f0\n? offline_pages+0x2f4/0x8c0\noffline_pages+0x60a/0x8c0\nmemory_subsys_offline+0x9f/0x1c0\n? lockdep_hardirqs_on+0x77/0x100\n? _raw_spin_unlock_irqrestore+0x38/0x60\ndevice_offline+0xe3/0x110\nstate_store+0x6e/0xc0\nkernfs_fop_write_iter+0x143/0x200\nvfs_write+0x39f/0x560\nksys_write+0x65/0xf0\ndo_syscall_64+0x62/0x130\n\nPreviously, some sanity check have been done in dump_mapping() before\nthe print facility parsing '%pd' though, it's still possible to run into\nan invalid dentry.d_name.name.\n\nSince dump_mapping() only needs to dump the filename only, retrieve it\nby itself in a safer way to prevent an unnecessary crash.\n\nNote that either retrieving the filename with '%pd' or\nstrncpy_from_kernel_nofault(), the filename could be unreliable.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49934" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7f7b850689ac06a62befe26e1fd1806799e7f152" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ef921bc72328b577cb45772ff7921cba4773b74a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f92b8829c6e75632de4e2b9f70e7a7e6c5c2ba98" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-v5pw-w6w2-2r5q/GHSA-v5pw-w6w2-2r5q.json b/advisories/unreviewed/2024/10/GHSA-v5pw-w6w2-2r5q/GHSA-v5pw-w6w2-2r5q.json new file mode 100644 index 00000000000..22c425f0fe1 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-v5pw-w6w2-2r5q/GHSA-v5pw-w6w2-2r5q.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v5pw-w6w2-2r5q", + "modified": "2024-10-21T18:30:58Z", + "published": "2024-10-21T18:30:58Z", + "aliases": [ + "CVE-2024-49943" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe/guc_submit: add missing locking in wedged_fini\n\nAny non-wedged queue can have a zero refcount here and can be running\nconcurrently with an async queue destroy, therefore dereferencing the\nqueue ptr to check wedge status after the lookup can trigger UAF if\nqueue is not wedged. Fix this by keeping the submission_state lock held\naround the check to postpone the free and make the check safe, before\ndropping again around the put() to avoid the deadlock.\n\n(cherry picked from commit d28af0b6b9580b9f90c265a7da0315b0ad20bbfd)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49943" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/790533e44bfc7af929842fccd9674c9f424d4627" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d88f9bab7e62dd0dbe983fa70cf040042a60cc84" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-v9vq-7m9c-h738/GHSA-v9vq-7m9c-h738.json b/advisories/unreviewed/2024/10/GHSA-v9vq-7m9c-h738/GHSA-v9vq-7m9c-h738.json new file mode 100644 index 00000000000..dc7615d244f --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-v9vq-7m9c-h738/GHSA-v9vq-7m9c-h738.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v9vq-7m9c-h738", + "modified": "2024-10-21T18:30:57Z", + "published": "2024-10-21T18:30:57Z", + "aliases": [ + "CVE-2024-49910" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Add NULL check for function pointer in dcn401_set_output_transfer_func\n\nThis commit adds a null check for the set_output_gamma function pointer\nin the dcn401_set_output_transfer_func function. Previously,\nset_output_gamma was being checked for null, but then it was being\ndereferenced without any null check. This could lead to a null pointer\ndereference if set_output_gamma is null.\n\nTo fix this, we now ensure that set_output_gamma is not null before\ndereferencing it. We do this by adding a null check for set_output_gamma\nbefore the call to set_output_gamma.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49910" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d8ee900b92b6526cf84275b49a473155ad75c70e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/dd340acd42c24a3f28dd22fae6bf38662334264c" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-vcrj-5576-fc99/GHSA-vcrj-5576-fc99.json b/advisories/unreviewed/2024/10/GHSA-vcrj-5576-fc99/GHSA-vcrj-5576-fc99.json new file mode 100644 index 00000000000..44b66975472 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-vcrj-5576-fc99/GHSA-vcrj-5576-fc99.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vcrj-5576-fc99", + "modified": "2024-10-21T18:30:57Z", + "published": "2024-10-21T18:30:56Z", + "aliases": [ + "CVE-2024-49875" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: map the EBADMSG to nfserr_io to avoid warning\n\nExt4 will throw -EBADMSG through ext4_readdir when a checksum error\noccurs, resulting in the following WARNING.\n\nFix it by mapping EBADMSG to nfserr_io.\n\nnfsd_buffered_readdir\n iterate_dir // -EBADMSG -74\n ext4_readdir // .iterate_shared\n ext4_dx_readdir\n ext4_htree_fill_tree\n htree_dirblock_to_tree\n ext4_read_dirblock\n __ext4_read_dirblock\n ext4_dirblock_csum_verify\n warn_no_space_for_csum\n __warn_no_space_for_csum\n return ERR_PTR(-EFSBADCRC) // -EBADMSG -74\n nfserrno // WARNING\n\n[ 161.115610] ------------[ cut here ]------------\n[ 161.116465] nfsd: non-standard errno: -74\n[ 161.117315] WARNING: CPU: 1 PID: 780 at fs/nfsd/nfsproc.c:878 nfserrno+0x9d/0xd0\n[ 161.118596] Modules linked in:\n[ 161.119243] CPU: 1 PID: 780 Comm: nfsd Not tainted 5.10.0-00014-g79679361fd5d #138\n[ 161.120684] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.14.0-0-g155821a1990b-prebuilt.qe\nmu.org 04/01/2014\n[ 161.123601] RIP: 0010:nfserrno+0x9d/0xd0\n[ 161.124676] Code: 0f 87 da 30 dd 00 83 e3 01 b8 00 00 00 05 75 d7 44 89 ee 48 c7 c7 c0 57 24 98 89 44 24 04 c6\n 05 ce 2b 61 03 01 e8 99 20 d8 00 <0f> 0b 8b 44 24 04 eb b5 4c 89 e6 48 c7 c7 a0 6d a4 99 e8 cc 15 33\n[ 161.127797] RSP: 0018:ffffc90000e2f9c0 EFLAGS: 00010286\n[ 161.128794] RAX: 0000000000000000 RBX: 0000000000000000 RCX: 0000000000000000\n[ 161.130089] RDX: 1ffff1103ee16f6d RSI: 0000000000000008 RDI: fffff520001c5f2a\n[ 161.131379] RBP: 0000000000000022 R08: 0000000000000001 R09: ffff8881f70c1827\n[ 161.132664] R10: ffffed103ee18304 R11: 0000000000000001 R12: 0000000000000021\n[ 161.133949] R13: 00000000ffffffb6 R14: ffff8881317c0000 R15: ffffc90000e2fbd8\n[ 161.135244] FS: 0000000000000000(0000) GS:ffff8881f7080000(0000) knlGS:0000000000000000\n[ 161.136695] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 161.137761] CR2: 00007fcaad70b348 CR3: 0000000144256006 CR4: 0000000000770ee0\n[ 161.139041] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n[ 161.140291] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n[ 161.141519] PKRU: 55555554\n[ 161.142076] Call Trace:\n[ 161.142575] ? __warn+0x9b/0x140\n[ 161.143229] ? nfserrno+0x9d/0xd0\n[ 161.143872] ? report_bug+0x125/0x150\n[ 161.144595] ? handle_bug+0x41/0x90\n[ 161.145284] ? exc_invalid_op+0x14/0x70\n[ 161.146009] ? asm_exc_invalid_op+0x12/0x20\n[ 161.146816] ? nfserrno+0x9d/0xd0\n[ 161.147487] nfsd_buffered_readdir+0x28b/0x2b0\n[ 161.148333] ? nfsd4_encode_dirent_fattr+0x380/0x380\n[ 161.149258] ? nfsd_buffered_filldir+0xf0/0xf0\n[ 161.150093] ? wait_for_concurrent_writes+0x170/0x170\n[ 161.151004] ? generic_file_llseek_size+0x48/0x160\n[ 161.151895] nfsd_readdir+0x132/0x190\n[ 161.152606] ? nfsd4_encode_dirent_fattr+0x380/0x380\n[ 161.153516] ? nfsd_unlink+0x380/0x380\n[ 161.154256] ? override_creds+0x45/0x60\n[ 161.155006] nfsd4_encode_readdir+0x21a/0x3d0\n[ 161.155850] ? nfsd4_encode_readlink+0x210/0x210\n[ 161.156731] ? write_bytes_to_xdr_buf+0x97/0xe0\n[ 161.157598] ? __write_bytes_to_xdr_buf+0xd0/0xd0\n[ 161.158494] ? lock_downgrade+0x90/0x90\n[ 161.159232] ? nfs4svc_decode_voidarg+0x10/0x10\n[ 161.160092] nfsd4_encode_operation+0x15a/0x440\n[ 161.160959] nfsd4_proc_compound+0x718/0xe90\n[ 161.161818] nfsd_dispatch+0x18e/0x2c0\n[ 161.162586] svc_process_common+0x786/0xc50\n[ 161.163403] ? nfsd_svc+0x380/0x380\n[ 161.164137] ? svc_printk+0x160/0x160\n[ 161.164846] ? svc_xprt_do_enqueue.part.0+0x365/0x380\n[ 161.165808] ? nfsd_svc+0x380/0x380\n[ 161.166523] ? rcu_is_watching+0x23/0x40\n[ 161.167309] svc_process+0x1a5/0x200\n[ 161.168019] nfsd+0x1f5/0x380\n[ 161.168663] ? nfsd_shutdown_threads+0x260/0x260\n[ 161.169554] kthread+0x1c4/0x210\n[ 161.170224] ? kthread_insert_work_sanity_check+0x80/0x80\n[ 161.171246] ret_from_fork+0x1f/0x30", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49875" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0ea4333c679f333e23956de743ad17387819d3f2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/340e61e44c1d2a15c42ec72ade9195ad525fd048" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6fe058502f8864649c3d614b06b2235223798f48" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/825789ca94602543101045ad3aad19b2b60c6b2a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c76005adfa93d1a027433331252422078750321f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e9cfecca22a36b927a440abc6307efb9e138fed5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f7d8ee9db94372b8235f5f22bb24381891594c42" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-vfmw-mcw8-m32f/GHSA-vfmw-mcw8-m32f.json b/advisories/unreviewed/2024/10/GHSA-vfmw-mcw8-m32f/GHSA-vfmw-mcw8-m32f.json index 438b434f848..87ecc1b8354 100644 --- a/advisories/unreviewed/2024/10/GHSA-vfmw-mcw8-m32f/GHSA-vfmw-mcw8-m32f.json +++ b/advisories/unreviewed/2024/10/GHSA-vfmw-mcw8-m32f/GHSA-vfmw-mcw8-m32f.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vfmw-mcw8-m32f", - "modified": "2024-10-16T18:31:47Z", + "modified": "2024-10-21T18:30:45Z", "published": "2024-10-16T18:31:47Z", "aliases": [ "CVE-2024-4690" ], "details": "Improper Restriction of XML External Entity Reference vulnerability in OpenText Application Automation Tools allows DTD Injection.This issue affects OpenText Application Automation Tools: 24.1.0 and below.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:U/V:D/RE:L/U:Green" diff --git a/advisories/unreviewed/2024/10/GHSA-vp2p-wqj6-25wf/GHSA-vp2p-wqj6-25wf.json b/advisories/unreviewed/2024/10/GHSA-vp2p-wqj6-25wf/GHSA-vp2p-wqj6-25wf.json new file mode 100644 index 00000000000..f629a59b4d8 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-vp2p-wqj6-25wf/GHSA-vp2p-wqj6-25wf.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vp2p-wqj6-25wf", + "modified": "2024-10-21T18:30:58Z", + "published": "2024-10-21T18:30:58Z", + "aliases": [ + "CVE-2024-49936" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/xen-netback: prevent UAF in xenvif_flush_hash()\n\nDuring the list_for_each_entry_rcu iteration call of xenvif_flush_hash,\nkfree_rcu does not exist inside the rcu read critical section, so if\nkfree_rcu is called when the rcu grace period ends during the iteration,\nUAF occurs when accessing head->next after the entry becomes free.\n\nTherefore, to solve this, you need to change it to list_for_each_entry_safe.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49936" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0fa5e94a1811d68fbffa0725efe6d4ca62c03d12" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/143edf098b80669d05245b2f2367dd156a83a2c5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/54d8639af5568fc41c0e274fc3ec9cf86c59fcbb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a0465723b8581cad27164c9073fd780904cd22d4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a7f0073fcd12ed7de185ef2c0af9d0fa1ddef22c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d408889d4b54f5501e4becc4dbbb9065143fbf4e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/efcff6ce7467f01f0753609f420333f3f2ceceda" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-vw3v-9427-r3gf/GHSA-vw3v-9427-r3gf.json b/advisories/unreviewed/2024/10/GHSA-vw3v-9427-r3gf/GHSA-vw3v-9427-r3gf.json new file mode 100644 index 00000000000..a166441af7e --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-vw3v-9427-r3gf/GHSA-vw3v-9427-r3gf.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vw3v-9427-r3gf", + "modified": "2024-10-21T18:30:57Z", + "published": "2024-10-21T18:30:57Z", + "aliases": [ + "CVE-2024-49921" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Check null pointers before used\n\n[WHAT & HOW]\nPoniters, such as dc->clk_mgr, are null checked previously in the same\nfunction, so Coverity warns \"implies that \"dc->clk_mgr\" might be null\".\nAs a result, these pointers need to be checked when used again.\n\nThis fixes 10 FORWARD_NULL issues reported by Coverity.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49921" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5b35bf1a82eb29841b67ff5643ba83762250fc24" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/be1fb44389ca3038ad2430dac4234669bc177ee3" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-w38v-phv7-fjq8/GHSA-w38v-phv7-fjq8.json b/advisories/unreviewed/2024/10/GHSA-w38v-phv7-fjq8/GHSA-w38v-phv7-fjq8.json new file mode 100644 index 00000000000..6a6ee83941e --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-w38v-phv7-fjq8/GHSA-w38v-phv7-fjq8.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w38v-phv7-fjq8", + "modified": "2024-10-21T18:30:57Z", + "published": "2024-10-21T18:30:57Z", + "aliases": [ + "CVE-2024-49883" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\next4: aovid use-after-free in ext4_ext_insert_extent()\n\nAs Ojaswin mentioned in Link, in ext4_ext_insert_extent(), if the path is\nreallocated in ext4_ext_create_new_leaf(), we'll use the stale path and\ncause UAF. Below is a sample trace with dummy values:\n\next4_ext_insert_extent\n path = *ppath = 2000\n ext4_ext_create_new_leaf(ppath)\n ext4_find_extent(ppath)\n path = *ppath = 2000\n if (depth > path[0].p_maxdepth)\n kfree(path = 2000);\n *ppath = path = NULL;\n path = kcalloc() = 3000\n *ppath = 3000;\n return path;\n /* here path is still 2000, UAF! */\n eh = path[depth].p_hdr\n\n==================================================================\nBUG: KASAN: slab-use-after-free in ext4_ext_insert_extent+0x26d4/0x3330\nRead of size 8 at addr ffff8881027bf7d0 by task kworker/u36:1/179\nCPU: 3 UID: 0 PID: 179 Comm: kworker/u6:1 Not tainted 6.11.0-rc2-dirty #866\nCall Trace:\n \n ext4_ext_insert_extent+0x26d4/0x3330\n ext4_ext_map_blocks+0xe22/0x2d40\n ext4_map_blocks+0x71e/0x1700\n ext4_do_writepages+0x1290/0x2800\n[...]\n\nAllocated by task 179:\n ext4_find_extent+0x81c/0x1f70\n ext4_ext_map_blocks+0x146/0x2d40\n ext4_map_blocks+0x71e/0x1700\n ext4_do_writepages+0x1290/0x2800\n ext4_writepages+0x26d/0x4e0\n do_writepages+0x175/0x700\n[...]\n\nFreed by task 179:\n kfree+0xcb/0x240\n ext4_find_extent+0x7c0/0x1f70\n ext4_ext_insert_extent+0xa26/0x3330\n ext4_ext_map_blocks+0xe22/0x2d40\n ext4_map_blocks+0x71e/0x1700\n ext4_do_writepages+0x1290/0x2800\n ext4_writepages+0x26d/0x4e0\n do_writepages+0x175/0x700\n[...]\n==================================================================\n\nSo use *ppath to update the path to avoid the above problem.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49883" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/51db04892a993cace63415be99848970a0f15ef2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5e811066c5ab709b070659197dccfb80ab650ddd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8162ee5d94b8c0351be0a9321be134872a7654a1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9df59009dfc6d9fc1bd9ddf6c5ab6e56d6ed887a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a164f3a432aae62ca23d03e6d926b122ee5b860d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/beb7b66fb489041c50c6473100b383f7a51648fc" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bfed082ce4b1ce6349b05c09a0fa4f3da35ecb1b" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-w7r5-57r3-mcrc/GHSA-w7r5-57r3-mcrc.json b/advisories/unreviewed/2024/10/GHSA-w7r5-57r3-mcrc/GHSA-w7r5-57r3-mcrc.json new file mode 100644 index 00000000000..b5853abb73a --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-w7r5-57r3-mcrc/GHSA-w7r5-57r3-mcrc.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w7r5-57r3-mcrc", + "modified": "2024-10-21T18:30:58Z", + "published": "2024-10-21T18:30:58Z", + "aliases": [ + "CVE-2024-49939" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: rtw89: avoid to add interface to list twice when SER\n\nIf SER L2 occurs during the WoWLAN resume flow, the add interface flow\nis triggered by ieee80211_reconfig(). However, due to\nrtw89_wow_resume() return failure, it will cause the add interface flow\nto be executed again, resulting in a double add list and causing a kernel\npanic. Therefore, we have added a check to prevent double adding of the\nlist.\n\nlist_add double add: new=ffff99d6992e2010, prev=ffff99d6992e2010, next=ffff99d695302628.\n------------[ cut here ]------------\nkernel BUG at lib/list_debug.c:37!\ninvalid opcode: 0000 [#1] PREEMPT SMP NOPTI\nCPU: 0 PID: 9 Comm: kworker/0:1 Tainted: G W O 6.6.30-02659-gc18865c4dfbd #1 770df2933251a0e3c888ba69d1053a817a6376a7\nHardware name: HP Grunt/Grunt, BIOS Google_Grunt.11031.169.0 06/24/2021\nWorkqueue: events_freezable ieee80211_restart_work [mac80211]\nRIP: 0010:__list_add_valid_or_report+0x5e/0xb0\nCode: c7 74 18 48 39 ce 74 13 b0 01 59 5a 5e 5f 41 58 41 59 41 5a 5d e9 e2 d6 03 00 cc 48 c7 c7 8d 4f 17 83 48 89 c2 e8 02 c0 00 00 <0f> 0b 48 c7 c7 aa 8c 1c 83 e8 f4 bf 00 00 0f 0b 48 c7 c7 c8 bc 12\nRSP: 0018:ffffa91b8007bc50 EFLAGS: 00010246\nRAX: 0000000000000058 RBX: ffff99d6992e0900 RCX: a014d76c70ef3900\nRDX: ffffa91b8007bae8 RSI: 00000000ffffdfff RDI: 0000000000000001\nRBP: ffffa91b8007bc88 R08: 0000000000000000 R09: ffffa91b8007bae0\nR10: 00000000ffffdfff R11: ffffffff83a79800 R12: ffff99d695302060\nR13: ffff99d695300900 R14: ffff99d6992e1be0 R15: ffff99d6992e2010\nFS: 0000000000000000(0000) GS:ffff99d6aac00000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 000078fbdba43480 CR3: 000000010e464000 CR4: 00000000001506f0\nCall Trace:\n \n ? __die_body+0x1f/0x70\n ? die+0x3d/0x60\n ? do_trap+0xa4/0x110\n ? __list_add_valid_or_report+0x5e/0xb0\n ? do_error_trap+0x6d/0x90\n ? __list_add_valid_or_report+0x5e/0xb0\n ? handle_invalid_op+0x30/0x40\n ? __list_add_valid_or_report+0x5e/0xb0\n ? exc_invalid_op+0x3c/0x50\n ? asm_exc_invalid_op+0x16/0x20\n ? __list_add_valid_or_report+0x5e/0xb0\n rtw89_ops_add_interface+0x309/0x310 [rtw89_core 7c32b1ee6854761c0321027c8a58c5160e41f48f]\n drv_add_interface+0x5c/0x130 [mac80211 83e989e6e616bd5b4b8a2b0a9f9352a2c385a3bc]\n ieee80211_reconfig+0x241/0x13d0 [mac80211 83e989e6e616bd5b4b8a2b0a9f9352a2c385a3bc]\n ? finish_wait+0x3e/0x90\n ? synchronize_rcu_expedited+0x174/0x260\n ? sync_rcu_exp_done_unlocked+0x50/0x50\n ? wake_bit_function+0x40/0x40\n ieee80211_restart_work+0xf0/0x140 [mac80211 83e989e6e616bd5b4b8a2b0a9f9352a2c385a3bc]\n process_scheduled_works+0x1e5/0x480\n worker_thread+0xea/0x1e0\n kthread+0xdb/0x110\n ? move_linked_works+0x90/0x90\n ? kthread_associate_blkcg+0xa0/0xa0\n ret_from_fork+0x3b/0x50\n ? kthread_associate_blkcg+0xa0/0xa0\n ret_from_fork_asm+0x11/0x20\n \nModules linked in: dm_integrity async_xor xor async_tx lz4 lz4_compress zstd zstd_compress zram zsmalloc rfcomm cmac uinput algif_hash algif_skcipher af_alg btusb btrtl iio_trig_hrtimer industrialio_sw_trigger btmtk industrialio_configfs btbcm btintel uvcvideo videobuf2_vmalloc iio_trig_sysfs videobuf2_memops videobuf2_v4l2 videobuf2_common uvc snd_hda_codec_hdmi veth snd_hda_intel snd_intel_dspcfg acpi_als snd_hda_codec industrialio_triggered_buffer kfifo_buf snd_hwdep industrialio i2c_piix4 snd_hda_core designware_i2s ip6table_nat snd_soc_max98357a xt_MASQUERADE xt_cgroup snd_soc_acp_rt5682_mach fuse rtw89_8922ae(O) rtw89_8922a(O) rtw89_pci(O) rtw89_core(O) 8021q mac80211(O) bluetooth ecdh_generic ecc cfg80211 r8152 mii joydev\ngsmi: Log Shutdown Reason 0x03\n---[ end trace 0000000000000000 ]---", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49939" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/37c319503023de49a4c87301c8998c8d928112cb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/490eddc836b2a6ec286e5df14bed4c7cf5e1f475" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7dd5d2514a8ea58f12096e888b0bd050d7eae20a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fdc73f2cfbe897f4733156df211d79ced649b23c" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-w7w7-6353-385q/GHSA-w7w7-6353-385q.json b/advisories/unreviewed/2024/10/GHSA-w7w7-6353-385q/GHSA-w7w7-6353-385q.json new file mode 100644 index 00000000000..2e9ae306394 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-w7w7-6353-385q/GHSA-w7w7-6353-385q.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w7w7-6353-385q", + "modified": "2024-10-21T18:30:59Z", + "published": "2024-10-21T18:30:59Z", + "aliases": [ + "CVE-2024-49970" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Implement bounds check for stream encoder creation in DCN401\n\n'stream_enc_regs' array is an array of dcn10_stream_enc_registers\nstructures. The array is initialized with four elements, corresponding\nto the four calls to stream_enc_regs() in the array initializer. This\nmeans that valid indices for this array are 0, 1, 2, and 3.\n\nThe error message 'stream_enc_regs' 4 <= 5 below, is indicating that\nthere is an attempt to access this array with an index of 5, which is\nout of bounds. This could lead to undefined behavior\n\nHere, eng_id is used as an index to access the stream_enc_regs array. If\neng_id is 5, this would result in an out-of-bounds access on the\nstream_enc_regs array.\n\nThus fixing Buffer overflow error in dcn401_stream_encoder_create\n\nFound by smatch:\ndrivers/gpu/drm/amd/amdgpu/../display/dc/resource/dcn401/dcn401_resource.c:1209 dcn401_stream_encoder_create() error: buffer overflow 'stream_enc_regs' 4 <= 5", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49970" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b219b46ad42df1dea9258788bcfea37181f3ccb2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bdf606810210e8e07a0cdf1af3c467291363b295" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-w89v-9wr9-8jx2/GHSA-w89v-9wr9-8jx2.json b/advisories/unreviewed/2024/10/GHSA-w89v-9wr9-8jx2/GHSA-w89v-9wr9-8jx2.json new file mode 100644 index 00000000000..90801013e18 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-w89v-9wr9-8jx2/GHSA-w89v-9wr9-8jx2.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w89v-9wr9-8jx2", + "modified": "2024-10-21T18:30:59Z", + "published": "2024-10-21T18:30:59Z", + "aliases": [ + "CVE-2024-49967" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\next4: no need to continue when the number of entries is 1", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49967" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/133ff0d78f1b160de011647bb65807195ca5d1ca" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1a00a393d6a7fb1e745a41edd09019bd6a0ad64c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2d64e7dada22ab589d1ac216a3661074d027f25e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9d4b2e4c36bb88d57018c1cbc8b6a0c4b44a7f42" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a02d7f5b24193aed451ac67aad3453472e79dc78" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/aca593e6070e21979430c344e9cb0b272a9e7e10" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fe192515d2937b8ed2d21921b558a06dd2031d21" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-w8mx-fc3q-r9qv/GHSA-w8mx-fc3q-r9qv.json b/advisories/unreviewed/2024/10/GHSA-w8mx-fc3q-r9qv/GHSA-w8mx-fc3q-r9qv.json new file mode 100644 index 00000000000..885e8510cf9 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-w8mx-fc3q-r9qv/GHSA-w8mx-fc3q-r9qv.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w8mx-fc3q-r9qv", + "modified": "2024-10-21T18:30:59Z", + "published": "2024-10-21T18:30:59Z", + "aliases": [ + "CVE-2024-49966" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: cancel dqi_sync_work before freeing oinfo\n\nocfs2_global_read_info() will initialize and schedule dqi_sync_work at the\nend, if error occurs after successfully reading global quota, it will\ntrigger the following warning with CONFIG_DEBUG_OBJECTS_* enabled:\n\nODEBUG: free active (active state 0) object: 00000000d8b0ce28 object type: timer_list hint: qsync_work_fn+0x0/0x16c\n\nThis reports that there is an active delayed work when freeing oinfo in\nerror handling, so cancel dqi_sync_work first. BTW, return status instead\nof -1 when .read_file_info fails.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49966" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0d707a33c84b371cb66120e198eed3374726ddd8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/14114d8148db07e7946fb06b56a50cfa425e26c7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/35fccce29feb3706f649726d410122dd81b92c18" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4173d1277c00baeedaaca76783e98b8fd0e3c08d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a4346c04d055bf7e184c18a73dbd23b6a9811118" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bbf41277df8b33fbedf4750a9300c147e8f104eb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ef768020366f47d23f39c4f57bcb03af6d1e24b3" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-wchf-3rq4-vh73/GHSA-wchf-3rq4-vh73.json b/advisories/unreviewed/2024/10/GHSA-wchf-3rq4-vh73/GHSA-wchf-3rq4-vh73.json index aa8eafe3304..4ea1ddc4469 100644 --- a/advisories/unreviewed/2024/10/GHSA-wchf-3rq4-vh73/GHSA-wchf-3rq4-vh73.json +++ b/advisories/unreviewed/2024/10/GHSA-wchf-3rq4-vh73/GHSA-wchf-3rq4-vh73.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wchf-3rq4-vh73", - "modified": "2024-10-21T12:30:55Z", + "modified": "2024-10-21T18:30:51Z", "published": "2024-10-21T12:30:55Z", "aliases": [ "CVE-2024-47706" diff --git a/advisories/unreviewed/2024/10/GHSA-wg4j-4q4f-6cfc/GHSA-wg4j-4q4f-6cfc.json b/advisories/unreviewed/2024/10/GHSA-wg4j-4q4f-6cfc/GHSA-wg4j-4q4f-6cfc.json new file mode 100644 index 00000000000..328bc7a2499 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-wg4j-4q4f-6cfc/GHSA-wg4j-4q4f-6cfc.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wg4j-4q4f-6cfc", + "modified": "2024-10-21T18:30:56Z", + "published": "2024-10-21T18:30:56Z", + "aliases": [ + "CVE-2024-49874" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ni3c: master: svc: Fix use after free vulnerability in svc_i3c_master Driver Due to Race Condition\n\nIn the svc_i3c_master_probe function, &master->hj_work is bound with\nsvc_i3c_master_hj_work, &master->ibi_work is bound with\nsvc_i3c_master_ibi_work. And svc_i3c_master_ibi_work can start the\nhj_work, svc_i3c_master_irq_handler can start the ibi_work.\n\nIf we remove the module which will call svc_i3c_master_remove to\nmake cleanup, it will free master->base through i3c_master_unregister\nwhile the work mentioned above will be used. The sequence of operations\nthat may lead to a UAF bug is as follows:\n\nCPU0 CPU1\n\n | svc_i3c_master_hj_work\nsvc_i3c_master_remove |\ni3c_master_unregister(&master->base)|\ndevice_unregister(&master->dev) |\ndevice_release |\n//free master->base |\n | i3c_master_do_daa(&master->base)\n | //use master->base\n\nFix it by ensuring that the work is canceled before proceeding with the\ncleanup in svc_i3c_master_remove.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49874" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/27b55724d3f781dd6e635e89dc6e2fd78fa81a00" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4318998892bf8fe99f97bea18c37ae7b685af75a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4ac637122930cc4ab7e2c22e364cf3aaf96b05b1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/61850725779709369c7e907ae8c7c75dc7cec4f3" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-wh99-hh68-w2m5/GHSA-wh99-hh68-w2m5.json b/advisories/unreviewed/2024/10/GHSA-wh99-hh68-w2m5/GHSA-wh99-hh68-w2m5.json new file mode 100644 index 00000000000..fb89c89547d --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-wh99-hh68-w2m5/GHSA-wh99-hh68-w2m5.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wh99-hh68-w2m5", + "modified": "2024-10-21T18:30:58Z", + "published": "2024-10-21T18:30:57Z", + "aliases": [ + "CVE-2024-49919" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Add null check for head_pipe in dcn201_acquire_free_pipe_for_layer\n\nThis commit addresses a potential null pointer dereference issue in the\n`dcn201_acquire_free_pipe_for_layer` function. The issue could occur\nwhen `head_pipe` is null.\n\nThe fix adds a check to ensure `head_pipe` is not null before asserting\nit. If `head_pipe` is null, the function returns NULL to prevent a\npotential null pointer dereference.\n\nReported by smatch:\ndrivers/gpu/drm/amd/amdgpu/../display/dc/resource/dcn201/dcn201_resource.c:1016 dcn201_acquire_free_pipe_for_layer() error: we previously assumed 'head_pipe' could be null (see line 1010)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49919" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/390d757621f5f35d11a63ed7d9d3262ead240064" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8a1b1655a490a492a5a6987254c935ecce4eb9de" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f22f4754aaa47d8c59f166ba3042182859e5dff7" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-x3rh-vhj8-7wq6/GHSA-x3rh-vhj8-7wq6.json b/advisories/unreviewed/2024/10/GHSA-x3rh-vhj8-7wq6/GHSA-x3rh-vhj8-7wq6.json new file mode 100644 index 00000000000..d4f6faac2f5 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-x3rh-vhj8-7wq6/GHSA-x3rh-vhj8-7wq6.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x3rh-vhj8-7wq6", + "modified": "2024-10-21T18:30:57Z", + "published": "2024-10-21T18:30:57Z", + "aliases": [ + "CVE-2024-49898" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Check null-initialized variables\n\n[WHAT & HOW]\ndrr_timing and subvp_pipe are initialized to null and they are not\nalways assigned new values. It is necessary to check for null before\ndereferencing.\n\nThis fixes 2 FORWARD_NULL issues reported by Coverity.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49898" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/115b1a3b0944b4d8ef0b4b0c5a625bdd9474131f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/367cd9ceba1933b63bc1d87d967baf6d9fd241d2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3fc70ae048fe0936761b73b50700a810ff61e853" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-x5vx-qmf9-2r9v/GHSA-x5vx-qmf9-2r9v.json b/advisories/unreviewed/2024/10/GHSA-x5vx-qmf9-2r9v/GHSA-x5vx-qmf9-2r9v.json new file mode 100644 index 00000000000..50ce060cec1 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-x5vx-qmf9-2r9v/GHSA-x5vx-qmf9-2r9v.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x5vx-qmf9-2r9v", + "modified": "2024-10-21T18:30:57Z", + "published": "2024-10-21T18:30:57Z", + "aliases": [ + "CVE-2024-49892" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Initialize get_bytes_per_element's default to 1\n\nVariables, used as denominators and maybe not assigned to other values,\nshould not be 0. bytes_per_element_y & bytes_per_element_c are\ninitialized by get_bytes_per_element() which should never return 0.\n\nThis fixes 10 DIVIDE_BY_ZERO issues reported by Coverity.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49892" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1f9f8186e239222f1c8d3dd73bf3bc6ae86c5e76" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3334ab72cbba55a632f24579cd47c4a4e5e69cda" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4067f4fa0423a89fb19a30b57231b384d77d2610" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a23d6029e730f8a151b1a34afb169baac1274583" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bc00d211da4ffad5314a2043b50bdc8ff8a33724" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c7630935d9a4986e8c0ed91658a781b7a77d73f7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f921335123f6620c3dce5c96fbb95f18524a021c" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-x652-w4xg-69jh/GHSA-x652-w4xg-69jh.json b/advisories/unreviewed/2024/10/GHSA-x652-w4xg-69jh/GHSA-x652-w4xg-69jh.json new file mode 100644 index 00000000000..975a92ab071 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-x652-w4xg-69jh/GHSA-x652-w4xg-69jh.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x652-w4xg-69jh", + "modified": "2024-10-21T18:30:58Z", + "published": "2024-10-21T18:30:58Z", + "aliases": [ + "CVE-2024-49951" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: MGMT: Fix possible crash on mgmt_index_removed\n\nIf mgmt_index_removed is called while there are commands queued on\ncmd_sync it could lead to crashes like the bellow trace:\n\n0x0000053D: __list_del_entry_valid_or_report+0x98/0xdc\n0x0000053D: mgmt_pending_remove+0x18/0x58 [bluetooth]\n0x0000053E: mgmt_remove_adv_monitor_complete+0x80/0x108 [bluetooth]\n0x0000053E: hci_cmd_sync_work+0xbc/0x164 [bluetooth]\n\nSo while handling mgmt_index_removed this attempts to dequeue\ncommands passed as user_data to cmd_sync.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49951" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0cc47233af35fb5f10b5e6a027cb4ccd480caf9a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4883296505aa7e4863c6869b689afb6005633b23" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8c3f7943a29145d8a2d8e24893762f7673323eae" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f53e1c9c726d83092167f2226f32bd3b73f26c21" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-x75j-gc7f-rqjc/GHSA-x75j-gc7f-rqjc.json b/advisories/unreviewed/2024/10/GHSA-x75j-gc7f-rqjc/GHSA-x75j-gc7f-rqjc.json new file mode 100644 index 00000000000..11db23ff88c --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-x75j-gc7f-rqjc/GHSA-x75j-gc7f-rqjc.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x75j-gc7f-rqjc", + "modified": "2024-10-21T18:30:59Z", + "published": "2024-10-21T18:30:59Z", + "aliases": [ + "CVE-2024-49968" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\next4: filesystems without casefold feature cannot be mounted with siphash\n\nWhen mounting the ext4 filesystem, if the default hash version is set to\nDX_HASH_SIPHASH but the casefold feature is not set, exit the mounting.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49968" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/985b67cd86392310d9e9326de941c22fc9340eec" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e1373903db6c4ac994de0d18076280ad88e12dee" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-xrhf-cccw-cpm8/GHSA-xrhf-cccw-cpm8.json b/advisories/unreviewed/2024/10/GHSA-xrhf-cccw-cpm8/GHSA-xrhf-cccw-cpm8.json new file mode 100644 index 00000000000..4d2dadc7263 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-xrhf-cccw-cpm8/GHSA-xrhf-cccw-cpm8.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xrhf-cccw-cpm8", + "modified": "2024-10-21T18:30:59Z", + "published": "2024-10-21T18:30:58Z", + "aliases": [ + "CVE-2024-49960" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\next4: fix timer use-after-free on failed mount\n\nSyzbot has found an ODEBUG bug in ext4_fill_super\n\nThe del_timer_sync function cancels the s_err_report timer,\nwhich reminds about filesystem errors daily. We should\nguarantee the timer is no longer active before kfree(sbi).\n\nWhen filesystem mounting fails, the flow goes to failed_mount3,\nwhere an error occurs when ext4_stop_mmpd is called, causing\na read I/O failure. This triggers the ext4_handle_error function\nthat ultimately re-arms the timer,\nleaving the s_err_report timer active before kfree(sbi) is called.\n\nFix the issue by canceling the s_err_report timer after calling ext4_stop_mmpd.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49960" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0ce160c5bdb67081a62293028dc85758a8efb22a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9203817ba46ebba7c865c8de2aba399537b6e891" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b85569585d0154d4db1e4f9e3e6a4731d407feb0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fa78fb51d396f4f2f80f8e96a3b1516f394258be" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-21T18:15:17Z" + } +} \ No newline at end of file