diff --git a/advisories/unreviewed/2024/06/GHSA-24vr-m38m-hw6f/GHSA-24vr-m38m-hw6f.json b/advisories/unreviewed/2024/06/GHSA-24vr-m38m-hw6f/GHSA-24vr-m38m-hw6f.json
new file mode 100644
index 00000000000..0c3d798d21b
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-24vr-m38m-hw6f/GHSA-24vr-m38m-hw6f.json
@@ -0,0 +1,47 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-24vr-m38m-hw6f",
+ "modified": "2024-06-20T12:31:20Z",
+ "published": "2024-06-20T12:31:20Z",
+ "aliases": [
+ "CVE-2022-48720"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: macsec: Fix offload support for NETDEV_UNREGISTER event\n\nCurrent macsec netdev notify handler handles NETDEV_UNREGISTER event by\nreleasing relevant SW resources only, this causes resources leak in case\nof macsec HW offload, as the underlay driver was not notified to clean\nit's macsec offload resources.\n\nFix by calling the underlay driver to clean it's relevant resources\nby moving offload handling from macsec_dellink() to macsec_common_dellink()\nwhen handling NETDEV_UNREGISTER event.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48720"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/2e7f5b6ee1a7a2c628253a95b0a95b582901ef1b"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/8299be160aad8548071d080518712dec0df92bd5"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/9cef24c8b76c1f6effe499d2f131807c90f7ce9a"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/e7a0b3a0806dae3cc81931f0e83055ca2ac6f455"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T11:15:55Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-26jw-cv8r-w4pr/GHSA-26jw-cv8r-w4pr.json b/advisories/unreviewed/2024/06/GHSA-26jw-cv8r-w4pr/GHSA-26jw-cv8r-w4pr.json
new file mode 100644
index 00000000000..24fae6cda6a
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-26jw-cv8r-w4pr/GHSA-26jw-cv8r-w4pr.json
@@ -0,0 +1,47 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-26jw-cv8r-w4pr",
+ "modified": "2024-06-20T12:31:22Z",
+ "published": "2024-06-20T12:31:22Z",
+ "aliases": [
+ "CVE-2022-48767"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nceph: properly put ceph_string reference after async create attempt\n\nThe reference acquired by try_prep_async_create is currently leaked.\nEnsure we put it.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48767"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/36d433ae3242aa714176378850e6d1a5a3e78f18"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/932a9b5870d38b87ba0a9923c804b1af7d3605b9"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/a0c22e970cd78b81c94691e6cb09713e8074d580"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/e7be12ca7d3947765b0d7c1c7e0537e748da993a"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T12:15:14Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-2f9c-gcww-48v7/GHSA-2f9c-gcww-48v7.json b/advisories/unreviewed/2024/06/GHSA-2f9c-gcww-48v7/GHSA-2f9c-gcww-48v7.json
new file mode 100644
index 00000000000..6c73c2a6d8c
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-2f9c-gcww-48v7/GHSA-2f9c-gcww-48v7.json
@@ -0,0 +1,47 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-2f9c-gcww-48v7",
+ "modified": "2024-06-20T12:31:22Z",
+ "published": "2024-06-20T12:31:22Z",
+ "aliases": [
+ "CVE-2022-48763"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: x86: Forcibly leave nested virt when SMM state is toggled\n\nForcibly leave nested virtualization operation if userspace toggles SMM\nstate via KVM_SET_VCPU_EVENTS or KVM_SYNC_X86_EVENTS. If userspace\nforces the vCPU out of SMM while it's post-VMXON and then injects an SMI,\nvmx_enter_smm() will overwrite vmx->nested.smm.vmxon and end up with both\nvmxon=false and smm.vmxon=false, but all other nVMX state allocated.\n\nDon't attempt to gracefully handle the transition as (a) most transitions\nare nonsencial, e.g. forcing SMM while L2 is running, (b) there isn't\nsufficient information to handle all transitions, e.g. SVM wants access\nto the SMRAM save state, and (c) KVM_SET_VCPU_EVENTS must precede\nKVM_SET_NESTED_STATE during state restore as the latter disallows putting\nthe vCPU into L2 if SMM is active, and disallows tagging the vCPU as\nbeing post-VMXON in SMM if SMM is not active.\n\nAbuse of KVM_SET_VCPU_EVENTS manifests as a WARN and memory leak in nVMX\ndue to failure to free vmcs01's shadow VMCS, but the bug goes far beyond\njust a memory leak, e.g. toggling SMM on while L2 is active puts the vCPU\nin an architecturally impossible state.\n\n WARNING: CPU: 0 PID: 3606 at free_loaded_vmcs arch/x86/kvm/vmx/vmx.c:2665 [inline]\n WARNING: CPU: 0 PID: 3606 at free_loaded_vmcs+0x158/0x1a0 arch/x86/kvm/vmx/vmx.c:2656\n Modules linked in:\n CPU: 1 PID: 3606 Comm: syz-executor725 Not tainted 5.17.0-rc1-syzkaller #0\n Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011\n RIP: 0010:free_loaded_vmcs arch/x86/kvm/vmx/vmx.c:2665 [inline]\n RIP: 0010:free_loaded_vmcs+0x158/0x1a0 arch/x86/kvm/vmx/vmx.c:2656\n Code: <0f> 0b eb b3 e8 8f 4d 9f 00 e9 f7 fe ff ff 48 89 df e8 92 4d 9f 00\n Call Trace:\n \n kvm_arch_vcpu_destroy+0x72/0x2f0 arch/x86/kvm/x86.c:11123\n kvm_vcpu_destroy arch/x86/kvm/../../../virt/kvm/kvm_main.c:441 [inline]\n kvm_destroy_vcpus+0x11f/0x290 arch/x86/kvm/../../../virt/kvm/kvm_main.c:460\n kvm_free_vcpus arch/x86/kvm/x86.c:11564 [inline]\n kvm_arch_destroy_vm+0x2e8/0x470 arch/x86/kvm/x86.c:11676\n kvm_destroy_vm arch/x86/kvm/../../../virt/kvm/kvm_main.c:1217 [inline]\n kvm_put_kvm+0x4fa/0xb00 arch/x86/kvm/../../../virt/kvm/kvm_main.c:1250\n kvm_vm_release+0x3f/0x50 arch/x86/kvm/../../../virt/kvm/kvm_main.c:1273\n __fput+0x286/0x9f0 fs/file_table.c:311\n task_work_run+0xdd/0x1a0 kernel/task_work.c:164\n exit_task_work include/linux/task_work.h:32 [inline]\n do_exit+0xb29/0x2a30 kernel/exit.c:806\n do_group_exit+0xd2/0x2f0 kernel/exit.c:935\n get_signal+0x4b0/0x28c0 kernel/signal.c:2862\n arch_do_signal_or_restart+0x2a9/0x1c40 arch/x86/kernel/signal.c:868\n handle_signal_work kernel/entry/common.c:148 [inline]\n exit_to_user_mode_loop kernel/entry/common.c:172 [inline]\n exit_to_user_mode_prepare+0x17d/0x290 kernel/entry/common.c:207\n __syscall_exit_to_user_mode_work kernel/entry/common.c:289 [inline]\n syscall_exit_to_user_mode+0x19/0x60 kernel/entry/common.c:300\n do_syscall_64+0x42/0xb0 arch/x86/entry/common.c:86\n entry_SYSCALL_64_after_hwframe+0x44/0xae\n ",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48763"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/080dbe7e9b86a0392d8dffc00d9971792afc121f"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/b4c0d89c92e957ecccce12e66b63875d0cc7af7e"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/e302786233e6bc512986d007c96458ccf5ca21c7"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/f7e570780efc5cec9b2ed1e0472a7da14e864fdb"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T12:15:14Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-2g7v-9r87-x6xh/GHSA-2g7v-9r87-x6xh.json b/advisories/unreviewed/2024/06/GHSA-2g7v-9r87-x6xh/GHSA-2g7v-9r87-x6xh.json
new file mode 100644
index 00000000000..364b15bf416
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-2g7v-9r87-x6xh/GHSA-2g7v-9r87-x6xh.json
@@ -0,0 +1,39 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-2g7v-9r87-x6xh",
+ "modified": "2024-06-20T12:31:22Z",
+ "published": "2024-06-20T12:31:22Z",
+ "aliases": [
+ "CVE-2022-48766"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Wrap dcn301_calculate_wm_and_dlg for FPU.\n\nMirrors the logic for dcn30. Cue lots of WARNs and some\nkernel panics without this fix.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48766"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/25f1488bdbba63415239ff301fe61a8546140d9f"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/456ba2433844a6483cc4c933aa8f43d24575e341"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T12:15:14Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-2pg7-r8hw-8m7v/GHSA-2pg7-r8hw-8m7v.json b/advisories/unreviewed/2024/06/GHSA-2pg7-r8hw-8m7v/GHSA-2pg7-r8hw-8m7v.json
new file mode 100644
index 00000000000..967ee54b797
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-2pg7-r8hw-8m7v/GHSA-2pg7-r8hw-8m7v.json
@@ -0,0 +1,47 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-2pg7-r8hw-8m7v",
+ "modified": "2024-06-20T12:31:20Z",
+ "published": "2024-06-20T12:31:20Z",
+ "aliases": [
+ "CVE-2022-48726"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/ucma: Protect mc during concurrent multicast leaves\n\nPartially revert the commit mentioned in the Fixes line to make sure that\nallocation and erasing multicast struct are locked.\n\n BUG: KASAN: use-after-free in ucma_cleanup_multicast drivers/infiniband/core/ucma.c:491 [inline]\n BUG: KASAN: use-after-free in ucma_destroy_private_ctx+0x914/0xb70 drivers/infiniband/core/ucma.c:579\n Read of size 8 at addr ffff88801bb74b00 by task syz-executor.1/25529\n CPU: 0 PID: 25529 Comm: syz-executor.1 Not tainted 5.16.0-rc7-syzkaller #0\n Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011\n Call Trace:\n __dump_stack lib/dump_stack.c:88 [inline]\n dump_stack_lvl+0xcd/0x134 lib/dump_stack.c:106\n print_address_description.constprop.0.cold+0x8d/0x320 mm/kasan/report.c:247\n __kasan_report mm/kasan/report.c:433 [inline]\n kasan_report.cold+0x83/0xdf mm/kasan/report.c:450\n ucma_cleanup_multicast drivers/infiniband/core/ucma.c:491 [inline]\n ucma_destroy_private_ctx+0x914/0xb70 drivers/infiniband/core/ucma.c:579\n ucma_destroy_id+0x1e6/0x280 drivers/infiniband/core/ucma.c:614\n ucma_write+0x25c/0x350 drivers/infiniband/core/ucma.c:1732\n vfs_write+0x28e/0xae0 fs/read_write.c:588\n ksys_write+0x1ee/0x250 fs/read_write.c:643\n do_syscall_x64 arch/x86/entry/common.c:50 [inline]\n do_syscall_64+0x35/0xb0 arch/x86/entry/common.c:80\n entry_SYSCALL_64_after_hwframe+0x44/0xae\n\nCurrently the xarray search can touch a concurrently freeing mc as the\nxa_for_each() is not surrounded by any lock. Rather than hold the lock for\na full scan hold it only for the effected items, which is usually an empty\nlist.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48726"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/2923948ffe0835f7114e948b35bcc42bc9b3baa1"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/36e8169ec973359f671f9ec7213547059cae972e"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/75c610212b9f1756b9384911d3a2c347eee8031c"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/ee2477e8ccd3d978eeac0dc5a981b286d9bb7b0a"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T12:15:11Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-2x6c-642q-vfcc/GHSA-2x6c-642q-vfcc.json b/advisories/unreviewed/2024/06/GHSA-2x6c-642q-vfcc/GHSA-2x6c-642q-vfcc.json
new file mode 100644
index 00000000000..361ea125f53
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-2x6c-642q-vfcc/GHSA-2x6c-642q-vfcc.json
@@ -0,0 +1,67 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-2x6c-642q-vfcc",
+ "modified": "2024-06-20T12:31:22Z",
+ "published": "2024-06-20T12:31:22Z",
+ "aliases": [
+ "CVE-2022-48758"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: bnx2fc: Flush destroy_work queue before calling bnx2fc_interface_put()\n\nThe bnx2fc_destroy() functions are removing the interface before calling\ndestroy_work. This results multiple WARNings from sysfs_remove_group() as\nthe controller rport device attributes are removed too early.\n\nReplace the fcoe_port's destroy_work queue. It's not needed.\n\nThe problem is easily reproducible with the following steps.\n\nExample:\n\n $ dmesg -w &\n $ systemctl enable --now fcoe\n $ fipvlan -s -c ens2f1\n $ fcoeadm -d ens2f1.802\n [ 583.464488] host2: libfc: Link down on port (7500a1)\n [ 583.472651] bnx2fc: 7500a1 - rport not created Yet!!\n [ 583.490468] ------------[ cut here ]------------\n [ 583.538725] sysfs group 'power' not found for kobject 'rport-2:0-0'\n [ 583.568814] WARNING: CPU: 3 PID: 192 at fs/sysfs/group.c:279 sysfs_remove_group+0x6f/0x80\n [ 583.607130] Modules linked in: dm_service_time 8021q garp mrp stp llc bnx2fc cnic uio rpcsec_gss_krb5 auth_rpcgss nfsv4 ...\n [ 583.942994] CPU: 3 PID: 192 Comm: kworker/3:2 Kdump: loaded Not tainted 5.14.0-39.el9.x86_64 #1\n [ 583.984105] Hardware name: HP ProLiant DL120 G7, BIOS J01 07/01/2013\n [ 584.016535] Workqueue: fc_wq_2 fc_rport_final_delete [scsi_transport_fc]\n [ 584.050691] RIP: 0010:sysfs_remove_group+0x6f/0x80\n [ 584.074725] Code: ff 5b 48 89 ef 5d 41 5c e9 ee c0 ff ff 48 89 ef e8 f6 b8 ff ff eb d1 49 8b 14 24 48 8b 33 48 c7 c7 ...\n [ 584.162586] RSP: 0018:ffffb567c15afdc0 EFLAGS: 00010282\n [ 584.188225] RAX: 0000000000000000 RBX: ffffffff8eec4220 RCX: 0000000000000000\n [ 584.221053] RDX: ffff8c1586ce84c0 RSI: ffff8c1586cd7cc0 RDI: ffff8c1586cd7cc0\n [ 584.255089] RBP: 0000000000000000 R08: 0000000000000000 R09: ffffb567c15afc00\n [ 584.287954] R10: ffffb567c15afbf8 R11: ffffffff8fbe7f28 R12: ffff8c1486326400\n [ 584.322356] R13: ffff8c1486326480 R14: ffff8c1483a4a000 R15: 0000000000000004\n [ 584.355379] FS: 0000000000000000(0000) GS:ffff8c1586cc0000(0000) knlGS:0000000000000000\n [ 584.394419] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n [ 584.421123] CR2: 00007fe95a6f7840 CR3: 0000000107674002 CR4: 00000000000606e0\n [ 584.454888] Call Trace:\n [ 584.466108] device_del+0xb2/0x3e0\n [ 584.481701] device_unregister+0x13/0x60\n [ 584.501306] bsg_unregister_queue+0x5b/0x80\n [ 584.522029] bsg_remove_queue+0x1c/0x40\n [ 584.541884] fc_rport_final_delete+0xf3/0x1d0 [scsi_transport_fc]\n [ 584.573823] process_one_work+0x1e3/0x3b0\n [ 584.592396] worker_thread+0x50/0x3b0\n [ 584.609256] ? rescuer_thread+0x370/0x370\n [ 584.628877] kthread+0x149/0x170\n [ 584.643673] ? set_kthread_struct+0x40/0x40\n [ 584.662909] ret_from_fork+0x22/0x30\n [ 584.680002] ---[ end trace 53575ecefa942ece ]---",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48758"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/00849de10f798a9538242824a51b1756e7110754"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/262550f29c750f7876b6ed1244281e72b64ebffb"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/2a12fe8248a38437b95b942bbe85aced72e6e2eb"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/847f9ea4c5186fdb7b84297e3eeed9e340e83fce"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/ace7b6ef41251c5fe47f629a9a922382fb7b0a6b"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/b11e34f7bab21df36f02a5e54fb69e858c09a65d"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/bf2bd892a0cb14dd2d21f2c658f4b747813be311"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/c93a290c862ccfa404e42d7420565730d67cbff9"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/de6336b17a1376db1c0f7a528cce8783db0881c0"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T12:15:13Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-33xv-g39w-2g66/GHSA-33xv-g39w-2g66.json b/advisories/unreviewed/2024/06/GHSA-33xv-g39w-2g66/GHSA-33xv-g39w-2g66.json
new file mode 100644
index 00000000000..68de60f1368
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-33xv-g39w-2g66/GHSA-33xv-g39w-2g66.json
@@ -0,0 +1,39 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-33xv-g39w-2g66",
+ "modified": "2024-06-20T12:31:22Z",
+ "published": "2024-06-20T12:31:22Z",
+ "aliases": [
+ "CVE-2022-48753"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nblock: fix memory leak in disk_register_independent_access_ranges\n\nkobject_init_and_add() takes reference even when it fails.\nAccording to the doc of kobject_init_and_add()\n\n If this function returns an error, kobject_put() must be called to\n properly clean up the memory associated with the object.\n\nFix this issue by adding kobject_put().\nCallback function blk_ia_ranges_sysfs_release() in kobject_put()\ncan handle the pointer \"iars\" properly.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48753"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/83114df32ae779df57e0af99a8ba6c3968b2ba3d"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/fe4214a07e0b53d2af711f57519e33739c5df23f"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T12:15:13Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-36cj-8xp6-3cv8/GHSA-36cj-8xp6-3cv8.json b/advisories/unreviewed/2024/06/GHSA-36cj-8xp6-3cv8/GHSA-36cj-8xp6-3cv8.json
new file mode 100644
index 00000000000..697b7abc5b5
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-36cj-8xp6-3cv8/GHSA-36cj-8xp6-3cv8.json
@@ -0,0 +1,47 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-36cj-8xp6-3cv8",
+ "modified": "2024-06-20T12:31:22Z",
+ "published": "2024-06-20T12:31:22Z",
+ "aliases": [
+ "CVE-2022-48752"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\npowerpc/perf: Fix power_pmu_disable to call clear_pmi_irq_pending only if PMI is pending\n\nRunning selftest with CONFIG_PPC_IRQ_SOFT_MASK_DEBUG enabled in kernel\ntriggered below warning:\n\n[ 172.851380] ------------[ cut here ]------------\n[ 172.851391] WARNING: CPU: 8 PID: 2901 at arch/powerpc/include/asm/hw_irq.h:246 power_pmu_disable+0x270/0x280\n[ 172.851402] Modules linked in: dm_mod bonding nft_ct nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 ip_set nf_tables rfkill nfnetlink sunrpc xfs libcrc32c pseries_rng xts vmx_crypto uio_pdrv_genirq uio sch_fq_codel ip_tables ext4 mbcache jbd2 sd_mod t10_pi sg ibmvscsi ibmveth scsi_transport_srp fuse\n[ 172.851442] CPU: 8 PID: 2901 Comm: lost_exception_ Not tainted 5.16.0-rc5-03218-g798527287598 #2\n[ 172.851451] NIP: c00000000013d600 LR: c00000000013d5a4 CTR: c00000000013b180\n[ 172.851458] REGS: c000000017687860 TRAP: 0700 Not tainted (5.16.0-rc5-03218-g798527287598)\n[ 172.851465] MSR: 8000000000029033 CR: 48004884 XER: 20040000\n[ 172.851482] CFAR: c00000000013d5b4 IRQMASK: 1\n[ 172.851482] GPR00: c00000000013d5a4 c000000017687b00 c000000002a10600 0000000000000004\n[ 172.851482] GPR04: 0000000082004000 c0000008ba08f0a8 0000000000000000 00000008b7ed0000\n[ 172.851482] GPR08: 00000000446194f6 0000000000008000 c00000000013b118 c000000000d58e68\n[ 172.851482] GPR12: c00000000013d390 c00000001ec54a80 0000000000000000 0000000000000000\n[ 172.851482] GPR16: 0000000000000000 0000000000000000 c000000015d5c708 c0000000025396d0\n[ 172.851482] GPR20: 0000000000000000 0000000000000000 c00000000a3bbf40 0000000000000003\n[ 172.851482] GPR24: 0000000000000000 c0000008ba097400 c0000000161e0d00 c00000000a3bb600\n[ 172.851482] GPR28: c000000015d5c700 0000000000000001 0000000082384090 c0000008ba0020d8\n[ 172.851549] NIP [c00000000013d600] power_pmu_disable+0x270/0x280\n[ 172.851557] LR [c00000000013d5a4] power_pmu_disable+0x214/0x280\n[ 172.851565] Call Trace:\n[ 172.851568] [c000000017687b00] [c00000000013d5a4] power_pmu_disable+0x214/0x280 (unreliable)\n[ 172.851579] [c000000017687b40] [c0000000003403ac] perf_pmu_disable+0x4c/0x60\n[ 172.851588] [c000000017687b60] [c0000000003445e4] __perf_event_task_sched_out+0x1d4/0x660\n[ 172.851596] [c000000017687c50] [c000000000d1175c] __schedule+0xbcc/0x12a0\n[ 172.851602] [c000000017687d60] [c000000000d11ea8] schedule+0x78/0x140\n[ 172.851608] [c000000017687d90] [c0000000001a8080] sys_sched_yield+0x20/0x40\n[ 172.851615] [c000000017687db0] [c0000000000334dc] system_call_exception+0x18c/0x380\n[ 172.851622] [c000000017687e10] [c00000000000c74c] system_call_common+0xec/0x268\n\nThe warning indicates that MSR_EE being set(interrupt enabled) when\nthere was an overflown PMC detected. This could happen in\npower_pmu_disable since it runs under interrupt soft disable\ncondition ( local_irq_save ) and not with interrupts hard disabled.\ncommit 2c9ac51b850d (\"powerpc/perf: Fix PMU callbacks to clear\npending PMI before resetting an overflown PMC\") intended to clear\nPMI pending bit in Paca when disabling the PMU. It could happen\nthat PMC gets overflown while code is in power_pmu_disable\ncallback function. Hence add a check to see if PMI pending bit\nis set in Paca before clearing it via clear_pmi_pending.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48752"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/28aaed966e76807a71de79dd40a8eee9042374dd"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/55402a4618721f350a9ab660bb42717d8aa18e7c"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/fa4ad064a6bd49208221df5e62adf27b426d1720"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/fb6433b48a178d4672cb26632454ee0b21056eaa"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T12:15:13Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-37rf-gf26-33r7/GHSA-37rf-gf26-33r7.json b/advisories/unreviewed/2024/06/GHSA-37rf-gf26-33r7/GHSA-37rf-gf26-33r7.json
new file mode 100644
index 00000000000..8dd629d026d
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-37rf-gf26-33r7/GHSA-37rf-gf26-33r7.json
@@ -0,0 +1,43 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-37rf-gf26-33r7",
+ "modified": "2024-06-20T12:31:20Z",
+ "published": "2024-06-20T12:31:20Z",
+ "aliases": [
+ "CVE-2022-48718"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm: mxsfb: Fix NULL pointer dereference\n\nmxsfb should not ever dereference the NULL pointer which\ndrm_atomic_get_new_bridge_state is allowed to return.\nAssume a fixed format instead.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48718"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/622c9a3a7868e1eeca39c55305ca3ebec4742b64"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/6f9267e01cca749137349d8ffb0d0ebbadf567f4"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/86a337bb803040e4401b87c974a7fb92efe3d0e1"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T11:15:55Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-38c9-5x95-x8fq/GHSA-38c9-5x95-x8fq.json b/advisories/unreviewed/2024/06/GHSA-38c9-5x95-x8fq/GHSA-38c9-5x95-x8fq.json
new file mode 100644
index 00000000000..54ea69a179c
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-38c9-5x95-x8fq/GHSA-38c9-5x95-x8fq.json
@@ -0,0 +1,47 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-38c9-5x95-x8fq",
+ "modified": "2024-06-20T12:31:20Z",
+ "published": "2024-06-20T12:31:20Z",
+ "aliases": [
+ "CVE-2022-48723"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nspi: uniphier: fix reference count leak in uniphier_spi_probe()\n\nThe issue happens in several error paths in uniphier_spi_probe().\nWhen either dma_get_slave_caps() or devm_spi_register_master() returns\nan error code, the function forgets to decrease the refcount of both\n`dma_rx` and `dma_tx` objects, which may lead to refcount leaks.\n\nFix it by decrementing the reference count of specific objects in\nthose error paths.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48723"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/37c2c83ca4f1ef4b6908181ac98e18360af89b42"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/447c3d4046d7b54052d07d8b27e15e6edea5662c"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/dd00b4f8f768d81c3788a8ac88fdb3d745e55ea3"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/e895e067d73e154b1ebc84a124e00831e311d9b0"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T11:15:55Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-38w9-7cc9-2cwv/GHSA-38w9-7cc9-2cwv.json b/advisories/unreviewed/2024/06/GHSA-38w9-7cc9-2cwv/GHSA-38w9-7cc9-2cwv.json
new file mode 100644
index 00000000000..9fc87ad41b4
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-38w9-7cc9-2cwv/GHSA-38w9-7cc9-2cwv.json
@@ -0,0 +1,47 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-38w9-7cc9-2cwv",
+ "modified": "2024-06-20T12:31:22Z",
+ "published": "2024-06-20T12:31:22Z",
+ "aliases": [
+ "CVE-2022-48755"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\npowerpc64/bpf: Limit 'ldbrx' to processors compliant with ISA v2.06\n\nJohan reported the below crash with test_bpf on ppc64 e5500:\n\n test_bpf: #296 ALU_END_FROM_LE 64: 0x0123456789abcdef -> 0x67452301 jited:1\n Oops: Exception in kernel mode, sig: 4 [#1]\n BE PAGE_SIZE=4K SMP NR_CPUS=24 QEMU e500\n Modules linked in: test_bpf(+)\n CPU: 0 PID: 76 Comm: insmod Not tainted 5.14.0-03771-g98c2059e008a-dirty #1\n NIP: 8000000000061c3c LR: 80000000006dea64 CTR: 8000000000061c18\n REGS: c0000000032d3420 TRAP: 0700 Not tainted (5.14.0-03771-g98c2059e008a-dirty)\n MSR: 0000000080089000 CR: 88002822 XER: 20000000 IRQMASK: 0\n <...>\n NIP [8000000000061c3c] 0x8000000000061c3c\n LR [80000000006dea64] .__run_one+0x104/0x17c [test_bpf]\n Call Trace:\n .__run_one+0x60/0x17c [test_bpf] (unreliable)\n .test_bpf_init+0x6a8/0xdc8 [test_bpf]\n .do_one_initcall+0x6c/0x28c\n .do_init_module+0x68/0x28c\n .load_module+0x2460/0x2abc\n .__do_sys_init_module+0x120/0x18c\n .system_call_exception+0x110/0x1b8\n system_call_common+0xf0/0x210\n --- interrupt: c00 at 0x101d0acc\n <...>\n ---[ end trace 47b2bf19090bb3d0 ]---\n\n Illegal instruction\n\nThe illegal instruction turned out to be 'ldbrx' emitted for\nBPF_FROM_[L|B]E, which was only introduced in ISA v2.06. Guard use of\nthe same and implement an alternative approach for older processors.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48755"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/129c71829d7f46423d95c19e8d87ce956d4c6e1c"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/3bfbc00587dc883eaed383558ae512a351c2cd09"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/3f5f766d5f7f95a69a630da3544a1a0cee1cdddf"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/aaccfeeee1630b155e8ff0d6c449d3de1ef86e73"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T12:15:13Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-3963-94c4-r6r8/GHSA-3963-94c4-r6r8.json b/advisories/unreviewed/2024/06/GHSA-3963-94c4-r6r8/GHSA-3963-94c4-r6r8.json
new file mode 100644
index 00000000000..bd4f8ef6edb
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-3963-94c4-r6r8/GHSA-3963-94c4-r6r8.json
@@ -0,0 +1,63 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-3963-94c4-r6r8",
+ "modified": "2024-06-20T12:31:21Z",
+ "published": "2024-06-20T12:31:21Z",
+ "aliases": [
+ "CVE-2022-48737"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: ops: Reject out of bounds values in snd_soc_put_volsw_sx()\n\nWe don't currently validate that the values being set are within the range\nwe advertised to userspace as being valid, do so and reject any values\nthat are out of range.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48737"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/038f8b7caa74d29e020949a43ca368c93f6b29b9"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/4977491e4b3aad8567f57e2a9992d251410c1db3"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/4f1e50d6a9cf9c1b8c859d449b5031cacfa8404e"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/9a12fcbf3c622f9bf6b110a873d62b0cba93972e"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/9e5c40b5706d8aae2cf70bd7e01f0b4575a642d0"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/c33402b056de61104b6146dedbe138ca8d7ec62b"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/e8e07c5e25a29e2a6f119fd947f55d7a55eb8a13"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/ef6cd9eeb38062a145802b7b56be7ae1090e165e"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T12:15:12Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-3wjp-7h53-cfv8/GHSA-3wjp-7h53-cfv8.json b/advisories/unreviewed/2024/06/GHSA-3wjp-7h53-cfv8/GHSA-3wjp-7h53-cfv8.json
new file mode 100644
index 00000000000..57c206dbb0c
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-3wjp-7h53-cfv8/GHSA-3wjp-7h53-cfv8.json
@@ -0,0 +1,67 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-3wjp-7h53-cfv8",
+ "modified": "2024-06-20T12:31:22Z",
+ "published": "2024-06-20T12:31:22Z",
+ "aliases": [
+ "CVE-2022-48760"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: core: Fix hang in usb_kill_urb by adding memory barriers\n\nThe syzbot fuzzer has identified a bug in which processes hang waiting\nfor usb_kill_urb() to return. It turns out the issue is not unlinking\nthe URB; that works just fine. Rather, the problem arises when the\nwakeup notification that the URB has completed is not received.\n\nThe reason is memory-access ordering on SMP systems. In outline form,\nusb_kill_urb() and __usb_hcd_giveback_urb() operating concurrently on\ndifferent CPUs perform the following actions:\n\nCPU 0\t\t\t\t\tCPU 1\n----------------------------\t\t---------------------------------\nusb_kill_urb():\t\t\t\t__usb_hcd_giveback_urb():\n ...\t\t\t\t\t ...\n atomic_inc(&urb->reject);\t\t atomic_dec(&urb->use_count);\n ...\t\t\t\t\t ...\n wait_event(usb_kill_urb_queue,\n\tatomic_read(&urb->use_count) == 0);\n\t\t\t\t\t if (atomic_read(&urb->reject))\n\t\t\t\t\t\twake_up(&usb_kill_urb_queue);\n\nConfining your attention to urb->reject and urb->use_count, you can\nsee that the overall pattern of accesses on CPU 0 is:\n\n\twrite urb->reject, then read urb->use_count;\n\nwhereas the overall pattern of accesses on CPU 1 is:\n\n\twrite urb->use_count, then read urb->reject.\n\nThis pattern is referred to in memory-model circles as SB (for \"Store\nBuffering\"), and it is well known that without suitable enforcement of\nthe desired order of accesses -- in the form of memory barriers -- it\nis entirely possible for one or both CPUs to execute their reads ahead\nof their writes. The end result will be that sometimes CPU 0 sees the\nold un-decremented value of urb->use_count while CPU 1 sees the old\nun-incremented value of urb->reject. Consequently CPU 0 ends up on\nthe wait queue and never gets woken up, leading to the observed hang\nin usb_kill_urb().\n\nThe same pattern of accesses occurs in usb_poison_urb() and the\nfailure pathway of usb_hcd_submit_urb().\n\nThe problem is fixed by adding suitable memory barriers. To provide\nproper memory-access ordering in the SB pattern, a full barrier is\nrequired on both CPUs. The atomic_inc() and atomic_dec() accesses\nthemselves don't provide any memory ordering, but since they are\npresent, we can use the optimized smp_mb__after_atomic() memory\nbarrier in the various routines to obtain the desired effect.\n\nThis patch adds the necessary memory barriers.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48760"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/26fbe9772b8c459687930511444ce443011f86bf"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/546ba238535d925254e0b3f12012a5c55801e2f3"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/5904dfd3ddaff3bf4a41c3baf0a8e8f31ed4599b"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/5f138ef224dffd15d5e5c5b095859719e0038427"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/9340226388c66a7e090ebb00e91ed64a753b6c26"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/9c61fce322ac2ef7fecf025285353570d60e41d6"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/b50f5ca60475710bbc9a3af32fbfc17b1e69c2f0"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/c9a18f7c5b071dce5e6939568829d40994866ab0"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/e3b131e30e612ff0e32de6c1cb4f69f89db29193"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T12:15:14Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-5jhp-6hhp-5q5g/GHSA-5jhp-6hhp-5q5g.json b/advisories/unreviewed/2024/06/GHSA-5jhp-6hhp-5q5g/GHSA-5jhp-6hhp-5q5g.json
new file mode 100644
index 00000000000..96bc86ba6de
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-5jhp-6hhp-5q5g/GHSA-5jhp-6hhp-5q5g.json
@@ -0,0 +1,59 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-5jhp-6hhp-5q5g",
+ "modified": "2024-06-20T12:31:20Z",
+ "published": "2024-06-20T12:31:20Z",
+ "aliases": [
+ "CVE-2022-48724"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\niommu/vt-d: Fix potential memory leak in intel_setup_irq_remapping()\n\nAfter commit e3beca48a45b (\"irqdomain/treewide: Keep firmware node\nunconditionally allocated\"). For tear down scenario, fn is only freed\nafter fail to allocate ir_domain, though it also should be freed in case\ndmar_enable_qi returns error.\n\nBesides free fn, irq_domain and ir_msi_domain need to be removed as well\nif intel_setup_irq_remapping fails to enable queued invalidation.\n\nImprove the rewinding path by add out_free_ir_domain and out_free_fwnode\nlables per Baolu's suggestion.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48724"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/336d096b62bdc673e852b6b80d5072d7888ce85d"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/5c43d46daa0d2928234dd2792ebebc35d29ee2d1"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/99e675d473eb8cf2deac1376a0f840222fc1adcf"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/9d9995b0371e4e8c18d4f955479e5d47efe7b2d4"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/a0c685ba99961b1dd894b2e470e692a539770f6d"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/a31cb1f0fb6caf46ffe88c41252b6b7a4ee062d9"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/b62eceb5f8f08815fe3f945fc55bbf997c344ecd"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T12:15:10Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-675x-jh39-gvrq/GHSA-675x-jh39-gvrq.json b/advisories/unreviewed/2024/06/GHSA-675x-jh39-gvrq/GHSA-675x-jh39-gvrq.json
new file mode 100644
index 00000000000..5b44b7c47d0
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-675x-jh39-gvrq/GHSA-675x-jh39-gvrq.json
@@ -0,0 +1,59 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-675x-jh39-gvrq",
+ "modified": "2024-06-20T12:31:20Z",
+ "published": "2024-06-20T12:31:20Z",
+ "aliases": [
+ "CVE-2022-48722"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ieee802154: ca8210: Stop leaking skb's\n\nUpon error the ieee802154_xmit_complete() helper is not called. Only\nieee802154_wake_queue() is called manually. We then leak the skb\nstructure.\n\nFree the skb structure upon error before returning.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48722"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/21feb6df3967541931242c427fe0958276af81cc"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/621b24b09eb61c63f262da0c9c5f0e93348897e5"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/6f38d3a6ec11c2733b1c641a46a2a2ecec57be08"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/78b3f20c17cbcb7645bfa63f2ca0e11b53c09d56"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/94cd597e20ed4acedb8f15f029d92998b011cb1a"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/a1c277b0ed2a13e7de923b5f03bc23586eceb851"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/d6a44feb2f28d71a7e725f72d09c97c81561cd9a"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T11:15:55Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-6hw2-3r9f-pmmj/GHSA-6hw2-3r9f-pmmj.json b/advisories/unreviewed/2024/06/GHSA-6hw2-3r9f-pmmj/GHSA-6hw2-3r9f-pmmj.json
new file mode 100644
index 00000000000..dc5d3d142fa
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-6hw2-3r9f-pmmj/GHSA-6hw2-3r9f-pmmj.json
@@ -0,0 +1,43 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-6hw2-3r9f-pmmj",
+ "modified": "2024-06-20T12:31:22Z",
+ "published": "2024-06-20T12:31:22Z",
+ "aliases": [
+ "CVE-2022-48765"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: LAPIC: Also cancel preemption timer during SET_LAPIC\n\nThe below warning is splatting during guest reboot.\n\n ------------[ cut here ]------------\n WARNING: CPU: 0 PID: 1931 at arch/x86/kvm/x86.c:10322 kvm_arch_vcpu_ioctl_run+0x874/0x880 [kvm]\n CPU: 0 PID: 1931 Comm: qemu-system-x86 Tainted: G I 5.17.0-rc1+ #5\n RIP: 0010:kvm_arch_vcpu_ioctl_run+0x874/0x880 [kvm]\n Call Trace:\n \n kvm_vcpu_ioctl+0x279/0x710 [kvm]\n __x64_sys_ioctl+0x83/0xb0\n do_syscall_64+0x3b/0xc0\n entry_SYSCALL_64_after_hwframe+0x44/0xae\n RIP: 0033:0x7fd39797350b\n\nThis can be triggered by not exposing tsc-deadline mode and doing a reboot in\nthe guest. The lapic_shutdown() function which is called in sys_reboot path\nwill not disarm the flying timer, it just masks LVTT. lapic_shutdown() clears\nAPIC state w/ LVT_MASKED and timer-mode bit is 0, this can trigger timer-mode\nswitch between tsc-deadline and oneshot/periodic, which can result in preemption\ntimer be cancelled in apic_update_lvtt(). However, We can't depend on this when\nnot exposing tsc-deadline mode and oneshot/periodic modes emulated by preemption\ntimer. Qemu will synchronise states around reset, let's cancel preemption timer\nunder KVM_SET_LAPIC.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48765"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/35fe7cfbab2e81f1afb23fc4212210b1de6d9633"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/54b3439c8e70e0bcfea59aeef9dd98908cbbf655"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/ce55f63f6cea4cab8ae9212f73285648a5baa30d"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T12:15:14Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-6j4r-jvg8-v6gc/GHSA-6j4r-jvg8-v6gc.json b/advisories/unreviewed/2024/06/GHSA-6j4r-jvg8-v6gc/GHSA-6j4r-jvg8-v6gc.json
new file mode 100644
index 00000000000..98ce4793b24
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-6j4r-jvg8-v6gc/GHSA-6j4r-jvg8-v6gc.json
@@ -0,0 +1,39 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-6j4r-jvg8-v6gc",
+ "modified": "2024-06-20T12:31:20Z",
+ "published": "2024-06-20T12:31:20Z",
+ "aliases": [
+ "CVE-2022-48719"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet, neigh: Do not trigger immediate probes on NUD_FAILED from neigh_managed_work\n\nsyzkaller was able to trigger a deadlock for NTF_MANAGED entries [0]:\n\n kworker/0:16/14617 is trying to acquire lock:\n ffffffff8d4dd370 (&tbl->lock){++-.}-{2:2}, at: ___neigh_create+0x9e1/0x2990 net/core/neighbour.c:652\n [...]\n but task is already holding lock:\n ffffffff8d4dd370 (&tbl->lock){++-.}-{2:2}, at: neigh_managed_work+0x35/0x250 net/core/neighbour.c:1572\n\nThe neighbor entry turned to NUD_FAILED state, where __neigh_event_send()\ntriggered an immediate probe as per commit cd28ca0a3dd1 (\"neigh: reduce\narp latency\") via neigh_probe() given table lock was held.\n\nOne option to fix this situation is to defer the neigh_probe() back to\nthe neigh_timer_handler() similarly as pre cd28ca0a3dd1. For the case\nof NTF_MANAGED, this deferral is acceptable given this only happens on\nactual failure state and regular / expected state is NUD_VALID with the\nentry already present.\n\nThe fix adds a parameter to __neigh_event_send() in order to communicate\nwhether immediate probe is allowed or disallowed. Existing call-sites\nof neigh_event_send() default as-is to immediate probe. However, the\nneigh_managed_work() disables it via use of neigh_event_send_probe().\n\n[0] \n __dump_stack lib/dump_stack.c:88 [inline]\n dump_stack_lvl+0xcd/0x134 lib/dump_stack.c:106\n print_deadlock_bug kernel/locking/lockdep.c:2956 [inline]\n check_deadlock kernel/locking/lockdep.c:2999 [inline]\n validate_chain kernel/locking/lockdep.c:3788 [inline]\n __lock_acquire.cold+0x149/0x3ab kernel/locking/lockdep.c:5027\n lock_acquire kernel/locking/lockdep.c:5639 [inline]\n lock_acquire+0x1ab/0x510 kernel/locking/lockdep.c:5604\n __raw_write_lock_bh include/linux/rwlock_api_smp.h:202 [inline]\n _raw_write_lock_bh+0x2f/0x40 kernel/locking/spinlock.c:334\n ___neigh_create+0x9e1/0x2990 net/core/neighbour.c:652\n ip6_finish_output2+0x1070/0x14f0 net/ipv6/ip6_output.c:123\n __ip6_finish_output net/ipv6/ip6_output.c:191 [inline]\n __ip6_finish_output+0x61e/0xe90 net/ipv6/ip6_output.c:170\n ip6_finish_output+0x32/0x200 net/ipv6/ip6_output.c:201\n NF_HOOK_COND include/linux/netfilter.h:296 [inline]\n ip6_output+0x1e4/0x530 net/ipv6/ip6_output.c:224\n dst_output include/net/dst.h:451 [inline]\n NF_HOOK include/linux/netfilter.h:307 [inline]\n ndisc_send_skb+0xa99/0x17f0 net/ipv6/ndisc.c:508\n ndisc_send_ns+0x3a9/0x840 net/ipv6/ndisc.c:650\n ndisc_solicit+0x2cd/0x4f0 net/ipv6/ndisc.c:742\n neigh_probe+0xc2/0x110 net/core/neighbour.c:1040\n __neigh_event_send+0x37d/0x1570 net/core/neighbour.c:1201\n neigh_event_send include/net/neighbour.h:470 [inline]\n neigh_managed_work+0x162/0x250 net/core/neighbour.c:1574\n process_one_work+0x9ac/0x1650 kernel/workqueue.c:2307\n worker_thread+0x657/0x1110 kernel/workqueue.c:2454\n kthread+0x2e9/0x3a0 kernel/kthread.c:377\n ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:295\n ",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48719"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/203a35ebb49cdce377416b0690215d3ce090d364"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/4a81f6da9cb2d1ef911131a6fd8bd15cb61fc772"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T11:15:55Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-6p2j-4rfr-64h6/GHSA-6p2j-4rfr-64h6.json b/advisories/unreviewed/2024/06/GHSA-6p2j-4rfr-64h6/GHSA-6p2j-4rfr-64h6.json
new file mode 100644
index 00000000000..3680ab0daac
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-6p2j-4rfr-64h6/GHSA-6p2j-4rfr-64h6.json
@@ -0,0 +1,63 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-6p2j-4rfr-64h6",
+ "modified": "2024-06-20T12:31:20Z",
+ "published": "2024-06-20T12:31:20Z",
+ "aliases": [
+ "CVE-2022-48715"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: bnx2fc: Make bnx2fc_recv_frame() mp safe\n\nRunning tests with a debug kernel shows that bnx2fc_recv_frame() is\nmodifying the per_cpu lport stats counters in a non-mpsafe way. Just boot\na debug kernel and run the bnx2fc driver with the hardware enabled.\n\n[ 1391.699147] BUG: using smp_processor_id() in preemptible [00000000] code: bnx2fc_\n[ 1391.699160] caller is bnx2fc_recv_frame+0xbf9/0x1760 [bnx2fc]\n[ 1391.699174] CPU: 2 PID: 4355 Comm: bnx2fc_l2_threa Kdump: loaded Tainted: G B\n[ 1391.699180] Hardware name: HP ProLiant DL120 G7, BIOS J01 07/01/2013\n[ 1391.699183] Call Trace:\n[ 1391.699188] dump_stack_lvl+0x57/0x7d\n[ 1391.699198] check_preemption_disabled+0xc8/0xd0\n[ 1391.699205] bnx2fc_recv_frame+0xbf9/0x1760 [bnx2fc]\n[ 1391.699215] ? do_raw_spin_trylock+0xb5/0x180\n[ 1391.699221] ? bnx2fc_npiv_create_vports.isra.0+0x4e0/0x4e0 [bnx2fc]\n[ 1391.699229] ? bnx2fc_l2_rcv_thread+0xb7/0x3a0 [bnx2fc]\n[ 1391.699240] bnx2fc_l2_rcv_thread+0x1af/0x3a0 [bnx2fc]\n[ 1391.699250] ? bnx2fc_ulp_init+0xc0/0xc0 [bnx2fc]\n[ 1391.699258] kthread+0x364/0x420\n[ 1391.699263] ? _raw_spin_unlock_irq+0x24/0x50\n[ 1391.699268] ? set_kthread_struct+0x100/0x100\n[ 1391.699273] ret_from_fork+0x22/0x30\n\nRestore the old get_cpu/put_cpu code with some modifications to reduce the\nsize of the critical section.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48715"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/003bcee66a8f0e76157eb3af369c173151901d97"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/2d24336c7214b281b51860e54783dfc65f1248df"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/2f5a1ac68bdf2899ce822ab845081922ea8c588e"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/3a345198a7c2d1db2526dc60b77052f75de019d3"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/471085571f926a1fe6b1bed095638994dbf23990"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/53e4f71763c61a557283eb43301efd671922d1e8"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/936bd03405fc83ba039d42bc93ffd4b88418f1d3"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/ec4334152dae175dbd8fd5bde1d2139bbe7b42d0"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T11:15:55Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-79gf-6cwh-vc6m/GHSA-79gf-6cwh-vc6m.json b/advisories/unreviewed/2024/06/GHSA-79gf-6cwh-vc6m/GHSA-79gf-6cwh-vc6m.json
new file mode 100644
index 00000000000..389ec4a495f
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-79gf-6cwh-vc6m/GHSA-79gf-6cwh-vc6m.json
@@ -0,0 +1,50 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-79gf-6cwh-vc6m",
+ "modified": "2024-06-20T12:31:20Z",
+ "published": "2024-06-20T12:31:20Z",
+ "aliases": [
+ "CVE-2024-6182"
+ ],
+ "details": "A vulnerability was found in LabVantage LIMS 2017. It has been rated as problematic. This issue affects some unknown processing of the file /labvantage/rc?command=page&page=LV_ViewSampleSpec&oosonly=Y&_sdialog=Y. The manipulation of the argument sdcid/keyid1 leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-269153 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6182"
+ },
+ {
+ "type": "WEB",
+ "url": "https://gentle-khaan-c53.notion.site/Reflected-XSS-in-Labvantage-LIMS-95e338b6f9ea45db9a6c635c3c1ff3b8"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?ctiid.269153"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?id.269153"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?submit.354361"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T11:15:57Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-86c2-5gmm-pc5g/GHSA-86c2-5gmm-pc5g.json b/advisories/unreviewed/2024/06/GHSA-86c2-5gmm-pc5g/GHSA-86c2-5gmm-pc5g.json
new file mode 100644
index 00000000000..abfa01a21c1
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-86c2-5gmm-pc5g/GHSA-86c2-5gmm-pc5g.json
@@ -0,0 +1,43 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-86c2-5gmm-pc5g",
+ "modified": "2024-06-20T12:31:21Z",
+ "published": "2024-06-20T12:31:21Z",
+ "aliases": [
+ "CVE-2022-48739"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: hdmi-codec: Fix OOB memory accesses\n\nCorrect size of iec_status array by changing it to the size of status\narray of the struct snd_aes_iec958. This fixes out-of-bounds slab\nread accesses made by memcpy() of the hdmi-codec driver. This problem\nis reported by KASAN.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48739"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/06feec6005c9d9500cd286ec440aabf8b2ddd94d"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/10007bd96b6c4c3cfaea9e76c311b06a07a5e260"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/1552e66be325a21d7eff49f46013fb402165a0ac"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T12:15:12Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-88rc-96xj-2mvh/GHSA-88rc-96xj-2mvh.json b/advisories/unreviewed/2024/06/GHSA-88rc-96xj-2mvh/GHSA-88rc-96xj-2mvh.json
new file mode 100644
index 00000000000..5a75cee73bc
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-88rc-96xj-2mvh/GHSA-88rc-96xj-2mvh.json
@@ -0,0 +1,47 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-88rc-96xj-2mvh",
+ "modified": "2024-06-20T12:31:21Z",
+ "published": "2024-06-20T12:31:21Z",
+ "aliases": [
+ "CVE-2022-48730"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndma-buf: heaps: Fix potential spectre v1 gadget\n\nIt appears like nr could be a Spectre v1 gadget as it's supplied by a\nuser and used as an array index. Prevent the contents\nof kernel memory from being leaked to userspace via speculative\nexecution by using array_index_nospec.\n\n [sumits: added fixes and cc: stable tags]",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48730"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/24f8e12d965b24f8aea762589e0e9fe2025c005e"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/5d40f1bdad3dd1a177f21a90ad4353c1ed40ba3a"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/92c4cfaee6872038563c5b6f2e8e613f9d84d47d"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/cc8f7940d9c2d45f67b3d1a2f2b7a829ca561bed"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T12:15:11Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-8w39-2g8c-h8rg/GHSA-8w39-2g8c-h8rg.json b/advisories/unreviewed/2024/06/GHSA-8w39-2g8c-h8rg/GHSA-8w39-2g8c-h8rg.json
new file mode 100644
index 00000000000..af65b79e6a0
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-8w39-2g8c-h8rg/GHSA-8w39-2g8c-h8rg.json
@@ -0,0 +1,55 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-8w39-2g8c-h8rg",
+ "modified": "2024-06-20T12:31:20Z",
+ "published": "2024-06-20T12:31:20Z",
+ "aliases": [
+ "CVE-2022-48717"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: max9759: fix underflow in speaker_gain_control_put()\n\nCheck for negative values of \"priv->gain\" to prevent an out of bounds\naccess. The concern is that these might come from the user via:\n -> snd_ctl_elem_write_user()\n -> snd_ctl_elem_write()\n -> kctl->put()",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48717"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/4c907bcd9dcd233da6707059d777ab389dcbd964"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/5a45448ac95b715173edb1cd090ff24b6586d921"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/71e60c170105d153e34d01766c1e4db26a4b24cc"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/a0f49d12547d45ea8b0f356a96632dd503941c1e"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/baead410e5db49e962a67fffc17ac30e44b50b7c"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/f114fd6165dfb52520755cc4d1c1dfbd447b88b6"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T11:15:55Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-932h-84vw-p6cw/GHSA-932h-84vw-p6cw.json b/advisories/unreviewed/2024/06/GHSA-932h-84vw-p6cw/GHSA-932h-84vw-p6cw.json
new file mode 100644
index 00000000000..c5952a5d06b
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-932h-84vw-p6cw/GHSA-932h-84vw-p6cw.json
@@ -0,0 +1,39 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-932h-84vw-p6cw",
+ "modified": "2024-06-20T12:31:21Z",
+ "published": "2024-06-20T12:31:21Z",
+ "aliases": [
+ "CVE-2022-48744"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: Avoid field-overflowing memcpy()\n\nIn preparation for FORTIFY_SOURCE performing compile-time and run-time\nfield bounds checking for memcpy(), memmove(), and memset(), avoid\nintentionally writing across neighboring fields.\n\nUse flexible arrays instead of zero-element arrays (which look like they\nare always overflowing) and split the cross-field memcpy() into two halves\nthat can be appropriately bounds-checked by the compiler.\n\nWe were doing:\n\n\t#define ETH_HLEN 14\n\t#define VLAN_HLEN 4\n\t...\n\t#define MLX5E_XDP_MIN_INLINE (ETH_HLEN + VLAN_HLEN)\n\t...\n struct mlx5e_tx_wqe *wqe = mlx5_wq_cyc_get_wqe(wq, pi);\n\t...\n struct mlx5_wqe_eth_seg *eseg = &wqe->eth;\n struct mlx5_wqe_data_seg *dseg = wqe->data;\n\t...\n\tmemcpy(eseg->inline_hdr.start, xdptxd->data, MLX5E_XDP_MIN_INLINE);\n\ntarget is wqe->eth.inline_hdr.start (which the compiler sees as being\n2 bytes in size), but copying 18, intending to write across start\n(really vlan_tci, 2 bytes). The remaining 16 bytes get written into\nwqe->data[0], covering byte_count (4 bytes), lkey (4 bytes), and addr\n(8 bytes).\n\nstruct mlx5e_tx_wqe {\n struct mlx5_wqe_ctrl_seg ctrl; /* 0 16 */\n struct mlx5_wqe_eth_seg eth; /* 16 16 */\n struct mlx5_wqe_data_seg data[]; /* 32 0 */\n\n /* size: 32, cachelines: 1, members: 3 */\n /* last cacheline: 32 bytes */\n};\n\nstruct mlx5_wqe_eth_seg {\n u8 swp_outer_l4_offset; /* 0 1 */\n u8 swp_outer_l3_offset; /* 1 1 */\n u8 swp_inner_l4_offset; /* 2 1 */\n u8 swp_inner_l3_offset; /* 3 1 */\n u8 cs_flags; /* 4 1 */\n u8 swp_flags; /* 5 1 */\n __be16 mss; /* 6 2 */\n __be32 flow_table_metadata; /* 8 4 */\n union {\n struct {\n __be16 sz; /* 12 2 */\n u8 start[2]; /* 14 2 */\n } inline_hdr; /* 12 4 */\n struct {\n __be16 type; /* 12 2 */\n __be16 vlan_tci; /* 14 2 */\n } insert; /* 12 4 */\n __be32 trailer; /* 12 4 */\n }; /* 12 4 */\n\n /* size: 16, cachelines: 1, members: 9 */\n /* last cacheline: 16 bytes */\n};\n\nstruct mlx5_wqe_data_seg {\n __be32 byte_count; /* 0 4 */\n __be32 lkey; /* 4 4 */\n __be64 addr; /* 8 8 */\n\n /* size: 16, cachelines: 1, members: 3 */\n /* last cacheline: 16 bytes */\n};\n\nSo, split the memcpy() so the compiler can reason about the buffer\nsizes.\n\n\"pahole\" shows no size nor member offset changes to struct mlx5e_tx_wqe\nnor struct mlx5e_umr_wqe. \"objdump -d\" shows no meaningful object\ncode changes (i.e. only source line number induced differences and\noptimizations).",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48744"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/8fbdf8c8b8ab82beab882175157650452c46493e"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/ad5185735f7dab342fdd0dd41044da4c9ccfef67"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T12:15:12Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-9533-j5r3-r25x/GHSA-9533-j5r3-r25x.json b/advisories/unreviewed/2024/06/GHSA-9533-j5r3-r25x/GHSA-9533-j5r3-r25x.json
new file mode 100644
index 00000000000..9aa6c11fdab
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-9533-j5r3-r25x/GHSA-9533-j5r3-r25x.json
@@ -0,0 +1,46 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-9533-j5r3-r25x",
+ "modified": "2024-06-20T12:31:20Z",
+ "published": "2024-06-20T12:31:20Z",
+ "aliases": [
+ "CVE-2024-5036"
+ ],
+ "details": "The Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Elementor Widgets & Elementor Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 3.5.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5036"
+ },
+ {
+ "type": "WEB",
+ "url": "https://plugins.trac.wordpress.org/browser/sina-extension-for-elementor/trunk/widgets/basic/sina-counter.php#L687"
+ },
+ {
+ "type": "WEB",
+ "url": "https://plugins.trac.wordpress.org/changeset/3104601"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/64f11bc9-88b5-43d5-bc76-129dc5909210?source=cve"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T11:15:56Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-9wpf-m764-qmf8/GHSA-9wpf-m764-qmf8.json b/advisories/unreviewed/2024/06/GHSA-9wpf-m764-qmf8/GHSA-9wpf-m764-qmf8.json
new file mode 100644
index 00000000000..336d39a4a27
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-9wpf-m764-qmf8/GHSA-9wpf-m764-qmf8.json
@@ -0,0 +1,55 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-9wpf-m764-qmf8",
+ "modified": "2024-06-20T12:31:22Z",
+ "published": "2024-06-20T12:31:22Z",
+ "aliases": [
+ "CVE-2022-48754"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nphylib: fix potential use-after-free\n\nCommit bafbdd527d56 (\"phylib: Add device reset GPIO support\") added call\nto phy_device_reset(phydev) after the put_device() call in phy_detach().\n\nThe comment before the put_device() call says that the phydev might go\naway with put_device().\n\nFix potential use-after-free by calling phy_device_reset() before\nput_device().",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48754"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/67d271760b037ce0806d687ee6057edc8afd4205"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/aefaccd19379d6c4620269a162bfb88ff687f289"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/bd024e36f68174b1793906c39ca16cee0c9295c2"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/cb2fab10fc5e7a3aa1bb0a68a3abdcf3e37852af"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/cbda1b16687580d5beee38273f6241ae3725960c"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/f39027cbada43b33566c312e6be3db654ca3ad17"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T12:15:13Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-c4jc-f237-c7h5/GHSA-c4jc-f237-c7h5.json b/advisories/unreviewed/2024/06/GHSA-c4jc-f237-c7h5/GHSA-c4jc-f237-c7h5.json
new file mode 100644
index 00000000000..6bb2589c82f
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-c4jc-f237-c7h5/GHSA-c4jc-f237-c7h5.json
@@ -0,0 +1,59 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-c4jc-f237-c7h5",
+ "modified": "2024-06-20T12:31:22Z",
+ "published": "2024-06-20T12:31:22Z",
+ "aliases": [
+ "CVE-2022-48756"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/msm/dsi: invalid parameter check in msm_dsi_phy_enable\n\nThe function performs a check on the \"phy\" input parameter, however, it\nis used before the check.\n\nInitialize the \"dev\" variable after the sanity check to avoid a possible\nNULL pointer dereference.\n\nAddresses-Coverity-ID: 1493860 (\"Null pointer dereference\")",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48756"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/2b7e7df1eacd280e561ede3e977853606871c951"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/56480fb10b976581a363fd168dc2e4fbee87a1a7"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/581317b1f001b7509041544d7019b75571daa100"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/5e761a2287234bc402ba7ef07129f5103bcd775c"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/6d9f8ba28f3747ca0f910a363e46f1114856dbbe"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/79c0b5287ded74f4eacde4dfd8aa0a76cbd853b5"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/ca63eeb70fcb53c42e1fe54e1735a54d8e7759fd"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T12:15:13Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-c864-85xv-823c/GHSA-c864-85xv-823c.json b/advisories/unreviewed/2024/06/GHSA-c864-85xv-823c/GHSA-c864-85xv-823c.json
new file mode 100644
index 00000000000..f4cf99c91b8
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-c864-85xv-823c/GHSA-c864-85xv-823c.json
@@ -0,0 +1,51 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-c864-85xv-823c",
+ "modified": "2024-06-20T12:31:21Z",
+ "published": "2024-06-20T12:31:21Z",
+ "aliases": [
+ "CVE-2022-48731"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/kmemleak: avoid scanning potential huge holes\n\nWhen using devm_request_free_mem_region() and devm_memremap_pages() to\nadd ZONE_DEVICE memory, if requested free mem region's end pfn were\nhuge(e.g., 0x400000000), the node_end_pfn() will be also huge (see\nmove_pfn_range_to_zone()). Thus it creates a huge hole between\nnode_start_pfn() and node_end_pfn().\n\nWe found on some AMD APUs, amdkfd requested such a free mem region and\ncreated a huge hole. In such a case, following code snippet was just\ndoing busy test_bit() looping on the huge hole.\n\n for (pfn = start_pfn; pfn < end_pfn; pfn++) {\n\tstruct page *page = pfn_to_online_page(pfn);\n\t\tif (!page)\n\t\t\tcontinue;\n\t...\n }\n\nSo we got a soft lockup:\n\n watchdog: BUG: soft lockup - CPU#6 stuck for 26s! [bash:1221]\n CPU: 6 PID: 1221 Comm: bash Not tainted 5.15.0-custom #1\n RIP: 0010:pfn_to_online_page+0x5/0xd0\n Call Trace:\n ? kmemleak_scan+0x16a/0x440\n kmemleak_write+0x306/0x3a0\n ? common_file_perm+0x72/0x170\n full_proxy_write+0x5c/0x90\n vfs_write+0xb9/0x260\n ksys_write+0x67/0xe0\n __x64_sys_write+0x1a/0x20\n do_syscall_64+0x3b/0xc0\n entry_SYSCALL_64_after_hwframe+0x44/0xae\n\nI did some tests with the patch.\n\n(1) amdgpu module unloaded\n\nbefore the patch:\n\n real 0m0.976s\n user 0m0.000s\n sys 0m0.968s\n\nafter the patch:\n\n real 0m0.981s\n user 0m0.000s\n sys 0m0.973s\n\n(2) amdgpu module loaded\n\nbefore the patch:\n\n real 0m35.365s\n user 0m0.000s\n sys 0m35.354s\n\nafter the patch:\n\n real 0m1.049s\n user 0m0.000s\n sys 0m1.042s",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48731"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/352715593e81b917ce1b321e794549815b850134"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/a5389c80992f0001ee505838fe6a8b20897ce96e"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/c10a0f877fe007021d70f9cada240f42adc2b5db"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/cebb0aceb21ad91429617a40e3a17444fabf1529"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/d3533ee20e9a0e2e8f60384da7450d43d1c63d1a"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T12:15:11Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-c87f-rj58-gx9p/GHSA-c87f-rj58-gx9p.json b/advisories/unreviewed/2024/06/GHSA-c87f-rj58-gx9p/GHSA-c87f-rj58-gx9p.json
new file mode 100644
index 00000000000..d542c8fab14
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-c87f-rj58-gx9p/GHSA-c87f-rj58-gx9p.json
@@ -0,0 +1,35 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-c87f-rj58-gx9p",
+ "modified": "2024-06-20T12:31:20Z",
+ "published": "2024-06-20T12:31:20Z",
+ "aliases": [
+ "CVE-2024-28147"
+ ],
+ "details": "An authenticated user can upload arbitrary files in the upload \nfunction for collection preview images. An attacker may upload an HTML \nfile that includes malicious JavaScript code which will be executed if a\n user visits the direct URL of the collection preview image (Stored \nCross Site Scripting). It is also possible to upload SVG files that \ninclude nested XML entities. Those are parsed when a user visits the \ndirect URL of the collection preview image, which may be utilized for a \nDenial of Service attack.\n\nThis issue affects edu-sharing: <8.0.8-RC2, <8.1.4-RC0, <9.0.0-RC19.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28147"
+ },
+ {
+ "type": "WEB",
+ "url": "https://r.sec-consult.com/metaventis"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-434"
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T11:15:55Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-c956-68gp-vrv2/GHSA-c956-68gp-vrv2.json b/advisories/unreviewed/2024/06/GHSA-c956-68gp-vrv2/GHSA-c956-68gp-vrv2.json
new file mode 100644
index 00000000000..a5fcb9b4d55
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-c956-68gp-vrv2/GHSA-c956-68gp-vrv2.json
@@ -0,0 +1,50 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-c956-68gp-vrv2",
+ "modified": "2024-06-20T12:31:22Z",
+ "published": "2024-06-20T12:31:22Z",
+ "aliases": [
+ "CVE-2024-6185"
+ ],
+ "details": "A vulnerability, which was classified as critical, has been found in Ruijie RG-UAC 1.0. Affected by this issue is the function get_ip_addr_details of the file /view/dhcp/dhcpConfig/commit.php. The manipulation of the argument ethname leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-269156. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6185"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/L1OudFd8cl09/CVE/blob/main/11_06_2024_b.md"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?ctiid.269156"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?id.269156"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?submit.354121"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-78"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T12:15:15Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-cfrf-95q8-jrvm/GHSA-cfrf-95q8-jrvm.json b/advisories/unreviewed/2024/06/GHSA-cfrf-95q8-jrvm/GHSA-cfrf-95q8-jrvm.json
new file mode 100644
index 00000000000..405b9e04f6f
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-cfrf-95q8-jrvm/GHSA-cfrf-95q8-jrvm.json
@@ -0,0 +1,47 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-cfrf-95q8-jrvm",
+ "modified": "2024-06-20T12:31:20Z",
+ "published": "2024-06-20T12:31:20Z",
+ "aliases": [
+ "CVE-2022-48713"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nperf/x86/intel/pt: Fix crash with stop filters in single-range mode\n\nAdd a check for !buf->single before calling pt_buffer_region_size in a\nplace where a missing check can cause a kernel crash.\n\nFixes a bug introduced by commit 670638477aed (\"perf/x86/intel/pt:\nOpportunistically use single range output mode\"), which added a\nsupport for PT single-range output mode. Since that commit if a PT\nstop filter range is hit while tracing, the kernel will crash because\nof a null pointer dereference in pt_handle_status due to calling\npt_buffer_region_size without a ToPA configured.\n\nThe commit which introduced single-range mode guarded almost all uses of\nthe ToPA buffer variables with checks of the buf->single variable, but\nmissed the case where tracing was stopped by the PT hardware, which\nhappens when execution hits a configured stop filter.\n\nTested that hitting a stop filter while PT recording successfully\nrecords a trace with this patch but crashes without this patch.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48713"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/1d9093457b243061a9bba23543c38726e864a643"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/456f041e035913fcedb275aff6f8a71dfebcd394"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/e83d941fd3445f660d2f43647c580a320cc384f6"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/feffb6ae2c80b9a8206450cdef90f5943baced99"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T11:15:54Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-cq4f-h5g8-8r5h/GHSA-cq4f-h5g8-8r5h.json b/advisories/unreviewed/2024/06/GHSA-cq4f-h5g8-8r5h/GHSA-cq4f-h5g8-8r5h.json
new file mode 100644
index 00000000000..350651b178f
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-cq4f-h5g8-8r5h/GHSA-cq4f-h5g8-8r5h.json
@@ -0,0 +1,47 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-cq4f-h5g8-8r5h",
+ "modified": "2024-06-20T12:31:21Z",
+ "published": "2024-06-20T12:31:21Z",
+ "aliases": [
+ "CVE-2022-48735"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: hda: Fix UAF of leds class devs at unbinding\n\nThe LED class devices that are created by HD-audio codec drivers are\nregistered via devm_led_classdev_register() and associated with the\nHD-audio codec device. Unfortunately, it turned out that the devres\nrelease doesn't work for this case; namely, since the codec resource\nrelease happens before the devm call chain, it triggers a NULL\ndereference or a UAF for a stale set_brightness_delay callback.\n\nFor fixing the bug, this patch changes the LED class device register\nand unregister in a manual manner without devres, keeping the\ninstances in hda_gen_spec.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48735"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/0e629052f013eeb61494d4df2f1f647c2a9aef47"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/549f8ffc7b2f7561bea7f90930b6c5104318e87b"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/813e9f3e06d22e29872d4fd51b54992d89cf66c8"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/a7de1002135cf94367748ffc695a29812d7633b5"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T12:15:11Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-cw86-cw6h-wc44/GHSA-cw86-cw6h-wc44.json b/advisories/unreviewed/2024/06/GHSA-cw86-cw6h-wc44/GHSA-cw86-cw6h-wc44.json
new file mode 100644
index 00000000000..8126e56bf1e
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-cw86-cw6h-wc44/GHSA-cw86-cw6h-wc44.json
@@ -0,0 +1,55 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-cw86-cw6h-wc44",
+ "modified": "2024-06-20T12:31:20Z",
+ "published": "2024-06-20T12:31:20Z",
+ "aliases": [
+ "CVE-2021-47619"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ni40e: Fix queues reservation for XDP\n\nWhen XDP was configured on a system with large number of CPUs\nand X722 NIC there was a call trace with NULL pointer dereference.\n\ni40e 0000:87:00.0: failed to get tracking for 256 queues for VSI 0 err -12\ni40e 0000:87:00.0: setup of MAIN VSI failed\n\nBUG: kernel NULL pointer dereference, address: 0000000000000000\nRIP: 0010:i40e_xdp+0xea/0x1b0 [i40e]\nCall Trace:\n? i40e_reconfig_rss_queues+0x130/0x130 [i40e]\ndev_xdp_install+0x61/0xe0\ndev_xdp_attach+0x18a/0x4c0\ndev_change_xdp_fd+0x1e6/0x220\ndo_setlink+0x616/0x1030\n? ahci_port_stop+0x80/0x80\n? ata_qc_issue+0x107/0x1e0\n? lock_timer_base+0x61/0x80\n? __mod_timer+0x202/0x380\nrtnl_setlink+0xe5/0x170\n? bpf_lsm_binder_transaction+0x10/0x10\n? security_capable+0x36/0x50\nrtnetlink_rcv_msg+0x121/0x350\n? rtnl_calcit.isra.0+0x100/0x100\nnetlink_rcv_skb+0x50/0xf0\nnetlink_unicast+0x1d3/0x2a0\nnetlink_sendmsg+0x22a/0x440\nsock_sendmsg+0x5e/0x60\n__sys_sendto+0xf0/0x160\n? __sys_getsockname+0x7e/0xc0\n? _copy_from_user+0x3c/0x80\n? __sys_setsockopt+0xc8/0x1a0\n__x64_sys_sendto+0x20/0x30\ndo_syscall_64+0x33/0x40\nentry_SYSCALL_64_after_hwframe+0x44/0xae\nRIP: 0033:0x7f83fa7a39e0\n\nThis was caused by PF queue pile fragmentation due to\nflow director VSI queue being placed right after main VSI.\nBecause of this main VSI was not able to resize its\nqueue allocation for XDP resulting in no queues allocated\nfor main VSI when XDP was turned on.\n\nFix this by always allocating last queue in PF queue pile\nfor a flow director VSI.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47619"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/00eddb0e4ea115154581d1049507a996acfc2d3e"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/4b3aa858268b7b9aeef02e5f9c4cd8f8fac101c8"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/768eb705e6381f0c70ca29d4e66f19790d5d19a1"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/92947844b8beee988c0ce17082b705c2f75f0742"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/be6998f232b8e4ca8225029e305b8329d89bfd59"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/d46fa4ea9756ef6cbcf9752d0832cc66e2d7121b"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T11:15:54Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-cw8x-f629-7c3v/GHSA-cw8x-f629-7c3v.json b/advisories/unreviewed/2024/06/GHSA-cw8x-f629-7c3v/GHSA-cw8x-f629-7c3v.json
new file mode 100644
index 00000000000..dbd98a33b4a
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-cw8x-f629-7c3v/GHSA-cw8x-f629-7c3v.json
@@ -0,0 +1,43 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-cw8x-f629-7c3v",
+ "modified": "2024-06-20T12:31:20Z",
+ "published": "2024-06-20T12:31:20Z",
+ "aliases": [
+ "CVE-2022-48721"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/smc: Forward wakeup to smc socket waitqueue after fallback\n\nWhen we replace TCP with SMC and a fallback occurs, there may be\nsome socket waitqueue entries remaining in smc socket->wq, such\nas eppoll_entries inserted by userspace applications.\n\nAfter the fallback, data flows over TCP/IP and only clcsocket->wq\nwill be woken up. Applications can't be notified by the entries\nwhich were inserted in smc socket->wq before fallback. So we need\na mechanism to wake up smc socket->wq at the same time if some\nentries remaining in it.\n\nThe current workaround is to transfer the entries from smc socket->wq\nto clcsock->wq during the fallback. But this may cause a crash\nlike this:\n\n general protection fault, probably for non-canonical address 0xdead000000000100: 0000 [#1] PREEMPT SMP PTI\n CPU: 3 PID: 0 Comm: swapper/3 Kdump: loaded Tainted: G E 5.16.0+ #107\n RIP: 0010:__wake_up_common+0x65/0x170\n Call Trace:\n \n __wake_up_common_lock+0x7a/0xc0\n sock_def_readable+0x3c/0x70\n tcp_data_queue+0x4a7/0xc40\n tcp_rcv_established+0x32f/0x660\n ? sk_filter_trim_cap+0xcb/0x2e0\n tcp_v4_do_rcv+0x10b/0x260\n tcp_v4_rcv+0xd2a/0xde0\n ip_protocol_deliver_rcu+0x3b/0x1d0\n ip_local_deliver_finish+0x54/0x60\n ip_local_deliver+0x6a/0x110\n ? tcp_v4_early_demux+0xa2/0x140\n ? tcp_v4_early_demux+0x10d/0x140\n ip_sublist_rcv_finish+0x49/0x60\n ip_sublist_rcv+0x19d/0x230\n ip_list_rcv+0x13e/0x170\n __netif_receive_skb_list_core+0x1c2/0x240\n netif_receive_skb_list_internal+0x1e6/0x320\n napi_complete_done+0x11d/0x190\n mlx5e_napi_poll+0x163/0x6b0 [mlx5_core]\n __napi_poll+0x3c/0x1b0\n net_rx_action+0x27c/0x300\n __do_softirq+0x114/0x2d2\n irq_exit_rcu+0xb4/0xe0\n common_interrupt+0xba/0xe0\n \n \n\nThe crash is caused by privately transferring waitqueue entries from\nsmc socket->wq to clcsock->wq. The owners of these entries, such as\nepoll, have no idea that the entries have been transferred to a\ndifferent socket wait queue and still use original waitqueue spinlock\n(smc socket->wq.wait.lock) to make the entries operation exclusive,\nbut it doesn't work. The operations to the entries, such as removing\nfrom the waitqueue (now is clcsock->wq after fallback), may cause a\ncrash when clcsock waitqueue is being iterated over at the moment.\n\nThis patch tries to fix this by no longer transferring wait queue\nentries privately, but introducing own implementations of clcsock's\ncallback functions in fallback situation. The callback functions will\nforward the wakeup to smc socket->wq if clcsock->wq is actually woken\nup and smc socket->wq has remaining entries.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48721"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/0ef6049f664941bc0f75828b3a61877635048b27"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/341adeec9adad0874f29a0a1af35638207352a39"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/504078fbe9dd570d685361b57784a6050bc40aaa"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T11:15:55Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-f558-fw4f-vm2c/GHSA-f558-fw4f-vm2c.json b/advisories/unreviewed/2024/06/GHSA-f558-fw4f-vm2c/GHSA-f558-fw4f-vm2c.json
new file mode 100644
index 00000000000..cc4fe62aa0d
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-f558-fw4f-vm2c/GHSA-f558-fw4f-vm2c.json
@@ -0,0 +1,47 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-f558-fw4f-vm2c",
+ "modified": "2024-06-20T12:31:21Z",
+ "published": "2024-06-20T12:31:21Z",
+ "aliases": [
+ "CVE-2022-48740"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nselinux: fix double free of cond_list on error paths\n\nOn error path from cond_read_list() and duplicate_policydb_cond_list()\nthe cond_list_destroy() gets called a second time in caller functions,\nresulting in NULL pointer deref. Fix this by resetting the\ncond_list_len to 0 in cond_list_destroy(), making subsequent calls a\nnoop.\n\nAlso consistently reset the cond_list pointer to NULL after freeing.\n\n[PM: fix line lengths in the description]",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48740"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/186edf7e368c40d06cf727a1ad14698ea67b74ad"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/70caa32e6d81f45f0702070c0e4dfe945e92fbd7"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/7ed9cbf7ac0d4ed86b356e1b944304ae9ee450d4"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/f446089a268c8fc6908488e991d28a9b936293db"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T12:15:12Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-f975-vjfw-7f99/GHSA-f975-vjfw-7f99.json b/advisories/unreviewed/2024/06/GHSA-f975-vjfw-7f99/GHSA-f975-vjfw-7f99.json
new file mode 100644
index 00000000000..06cbbc7699c
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-f975-vjfw-7f99/GHSA-f975-vjfw-7f99.json
@@ -0,0 +1,47 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-f975-vjfw-7f99",
+ "modified": "2024-06-20T12:31:22Z",
+ "published": "2024-06-20T12:31:22Z",
+ "aliases": [
+ "CVE-2022-48761"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: xhci-plat: fix crash when suspend if remote wake enable\n\nCrashed at i.mx8qm platform when suspend if enable remote wakeup\n\nInternal error: synchronous external abort: 96000210 [#1] PREEMPT SMP\nModules linked in:\nCPU: 2 PID: 244 Comm: kworker/u12:6 Not tainted 5.15.5-dirty #12\nHardware name: Freescale i.MX8QM MEK (DT)\nWorkqueue: events_unbound async_run_entry_fn\npstate: 600000c5 (nZCv daIF -PAN -UAO -TCO -DIT -SSBS BTYPE=--)\npc : xhci_disable_hub_port_wake.isra.62+0x60/0xf8\nlr : xhci_disable_hub_port_wake.isra.62+0x34/0xf8\nsp : ffff80001394bbf0\nx29: ffff80001394bbf0 x28: 0000000000000000 x27: ffff00081193b578\nx26: ffff00081193b570 x25: 0000000000000000 x24: 0000000000000000\nx23: ffff00081193a29c x22: 0000000000020001 x21: 0000000000000001\nx20: 0000000000000000 x19: ffff800014e90490 x18: 0000000000000000\nx17: 0000000000000000 x16: 0000000000000000 x15: 0000000000000000\nx14: 0000000000000000 x13: 0000000000000002 x12: 0000000000000000\nx11: 0000000000000000 x10: 0000000000000960 x9 : ffff80001394baa0\nx8 : ffff0008145d1780 x7 : ffff0008f95b8e80 x6 : 000000001853b453\nx5 : 0000000000000496 x4 : 0000000000000000 x3 : ffff00081193a29c\nx2 : 0000000000000001 x1 : 0000000000000000 x0 : ffff000814591620\nCall trace:\n xhci_disable_hub_port_wake.isra.62+0x60/0xf8\n xhci_suspend+0x58/0x510\n xhci_plat_suspend+0x50/0x78\n platform_pm_suspend+0x2c/0x78\n dpm_run_callback.isra.25+0x50/0xe8\n __device_suspend+0x108/0x3c0\n\nThe basic flow:\n\t1. run time suspend call xhci_suspend, xhci parent devices gate the clock.\n 2. echo mem >/sys/power/state, system _device_suspend call xhci_suspend\n 3. xhci_suspend call xhci_disable_hub_port_wake, which access register,\n\t but clock already gated by run time suspend.\n\nThis problem was hidden by power domain driver, which call run time resume before it.\n\nBut the below commit remove it and make this issue happen.\n\tcommit c1df456d0f06e (\"PM: domains: Don't runtime resume devices at genpd_prepare()\")\n\nThis patch call run time resume before suspend to make sure clock is on\nbefore access register.\n\nTesteb-by: Abel Vesa ",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48761"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/20c51a4c52208f98e27308c456a1951778f41fa5"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/8b05ad29acb972850ad795fa850e814b2e758b83"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/9df478463d9feb90dae24f183383961cf123a0ec"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/d5755832a1e47f5d8773f0776e211ecd4e02da72"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T12:15:14Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-g2r9-fvrv-f652/GHSA-g2r9-fvrv-f652.json b/advisories/unreviewed/2024/06/GHSA-g2r9-fvrv-f652/GHSA-g2r9-fvrv-f652.json
new file mode 100644
index 00000000000..975a5c0b03b
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-g2r9-fvrv-f652/GHSA-g2r9-fvrv-f652.json
@@ -0,0 +1,67 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-g2r9-fvrv-f652",
+ "modified": "2024-06-20T12:31:20Z",
+ "published": "2024-06-20T12:31:20Z",
+ "aliases": [
+ "CVE-2021-47620"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: refactor malicious adv data check\n\nCheck for out-of-bound read was being performed at the end of while\nnum_reports loop, and would fill journal with false positives. Added\ncheck to beginning of loop processing so that it doesn't get checked\nafter ptr has been advanced.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47620"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/305e92f525450f3e1b5f5c9dc7eadb152d66a082"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/5a539c08d743d9910631448da78af5e961664c0e"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/5c968affa804ba98c3c603f37ffea6fba618025e"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/7889b38a7f21ed19314f83194622b195d328465c"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/835d3706852537bf92eb23eb8635b8dee0c0aa67"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/83d5196b65d1b29e27d7dd16a3b9b439fb1d2dba"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/8819f93cd4a443dfe547aa622b21f723757df3fb"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/899663be5e75dc0174dc8bda0b5e6826edf0b29a"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/bcea886771c3f22a590c8c8b9139a107bd7f1e1c"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T11:15:54Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-gcrq-r544-wxfh/GHSA-gcrq-r544-wxfh.json b/advisories/unreviewed/2024/06/GHSA-gcrq-r544-wxfh/GHSA-gcrq-r544-wxfh.json
new file mode 100644
index 00000000000..81ce1ea4a4a
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-gcrq-r544-wxfh/GHSA-gcrq-r544-wxfh.json
@@ -0,0 +1,63 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-gcrq-r544-wxfh",
+ "modified": "2024-06-20T12:31:20Z",
+ "published": "2024-06-20T12:31:20Z",
+ "aliases": [
+ "CVE-2021-4439"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nisdn: cpai: check ctr->cnr to avoid array index out of bound\n\nThe cmtp_add_connection() would add a cmtp session to a controller\nand run a kernel thread to process cmtp.\n\n\t__module_get(THIS_MODULE);\n\tsession->task = kthread_run(cmtp_session, session, \"kcmtpd_ctr_%d\",\n\t\t\t\t\t\t\t\tsession->num);\n\nDuring this process, the kernel thread would call detach_capi_ctr()\nto detach a register controller. if the controller\nwas not attached yet, detach_capi_ctr() would\ntrigger an array-index-out-bounds bug.\n\n[ 46.866069][ T6479] UBSAN: array-index-out-of-bounds in\ndrivers/isdn/capi/kcapi.c:483:21\n[ 46.867196][ T6479] index -1 is out of range for type 'capi_ctr *[32]'\n[ 46.867982][ T6479] CPU: 1 PID: 6479 Comm: kcmtpd_ctr_0 Not tainted\n5.15.0-rc2+ #8\n[ 46.869002][ T6479] Hardware name: QEMU Standard PC (i440FX + PIIX,\n1996), BIOS 1.14.0-2 04/01/2014\n[ 46.870107][ T6479] Call Trace:\n[ 46.870473][ T6479] dump_stack_lvl+0x57/0x7d\n[ 46.870974][ T6479] ubsan_epilogue+0x5/0x40\n[ 46.871458][ T6479] __ubsan_handle_out_of_bounds.cold+0x43/0x48\n[ 46.872135][ T6479] detach_capi_ctr+0x64/0xc0\n[ 46.872639][ T6479] cmtp_session+0x5c8/0x5d0\n[ 46.873131][ T6479] ? __init_waitqueue_head+0x60/0x60\n[ 46.873712][ T6479] ? cmtp_add_msgpart+0x120/0x120\n[ 46.874256][ T6479] kthread+0x147/0x170\n[ 46.874709][ T6479] ? set_kthread_struct+0x40/0x40\n[ 46.875248][ T6479] ret_from_fork+0x1f/0x30\n[ 46.875773][ T6479]",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-4439"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/1f3e2e97c003f80c4b087092b225c8787ff91e4d"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/24219a977bfe3d658687e45615c70998acdbac5a"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/285e9210b1fab96a11c0be3ed5cea9dd48b6ac54"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/7d91adc0ccb060ce564103315189466eb822cc6a"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/7f221ccbee4ec662e2292d490a43ce6c314c4594"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/9b6b2db77bc3121fe435f1d4b56e34de443bec75"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/cc20226e218a2375d50dd9ac14fb4121b43375ff"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/e8b8de17e164c9f1b7777f1c6f99d05539000036"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T12:15:10Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-gpr7-jpmr-pqcr/GHSA-gpr7-jpmr-pqcr.json b/advisories/unreviewed/2024/06/GHSA-gpr7-jpmr-pqcr/GHSA-gpr7-jpmr-pqcr.json
new file mode 100644
index 00000000000..fc746059a2d
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-gpr7-jpmr-pqcr/GHSA-gpr7-jpmr-pqcr.json
@@ -0,0 +1,47 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-gpr7-jpmr-pqcr",
+ "modified": "2024-06-20T12:31:21Z",
+ "published": "2024-06-20T12:31:21Z",
+ "aliases": [
+ "CVE-2022-48745"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: Use del_timer_sync in fw reset flow of halting poll\n\nSubstitute del_timer() with del_timer_sync() in fw reset polling\ndeactivation flow, in order to prevent a race condition which occurs\nwhen del_timer() is called and timer is deactivated while another\nprocess is handling the timer interrupt. A situation that led to\nthe following call trace:\n\tRIP: 0010:run_timer_softirq+0x137/0x420\n\t\n\trecalibrate_cpu_khz+0x10/0x10\n\tktime_get+0x3e/0xa0\n\t? sched_clock_cpu+0xb/0xc0\n\t__do_softirq+0xf5/0x2ea\n\tirq_exit_rcu+0xc1/0xf0\n\tsysvec_apic_timer_interrupt+0x9e/0xc0\n\tasm_sysvec_apic_timer_interrupt+0x12/0x20\n\t",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48745"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/2a038dd1d942f8fbc495c58fa592ff24af05f1c2"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/3c5193a87b0fea090aa3f769d020337662d87b5e"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/502c37b033fab7cde3e95a570af4f073306be45e"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/f895ebeb44d09d02674cfdd0cfc2bf687603918c"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T12:15:12Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-grhv-62hf-9jg3/GHSA-grhv-62hf-9jg3.json b/advisories/unreviewed/2024/06/GHSA-grhv-62hf-9jg3/GHSA-grhv-62hf-9jg3.json
new file mode 100644
index 00000000000..ea6654c795d
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-grhv-62hf-9jg3/GHSA-grhv-62hf-9jg3.json
@@ -0,0 +1,43 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-grhv-62hf-9jg3",
+ "modified": "2024-06-20T12:31:21Z",
+ "published": "2024-06-20T12:31:21Z",
+ "aliases": [
+ "CVE-2022-48733"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix use-after-free after failure to create a snapshot\n\nAt ioctl.c:create_snapshot(), we allocate a pending snapshot structure and\nthen attach it to the transaction's list of pending snapshots. After that\nwe call btrfs_commit_transaction(), and if that returns an error we jump\nto 'fail' label, where we kfree() the pending snapshot structure. This can\nresult in a later use-after-free of the pending snapshot:\n\n1) We allocated the pending snapshot and added it to the transaction's\n list of pending snapshots;\n\n2) We call btrfs_commit_transaction(), and it fails either at the first\n call to btrfs_run_delayed_refs() or btrfs_start_dirty_block_groups().\n In both cases, we don't abort the transaction and we release our\n transaction handle. We jump to the 'fail' label and free the pending\n snapshot structure. We return with the pending snapshot still in the\n transaction's list;\n\n3) Another task commits the transaction. This time there's no error at\n all, and then during the transaction commit it accesses a pointer\n to the pending snapshot structure that the snapshot creation task\n has already freed, resulting in a user-after-free.\n\nThis issue could actually be detected by smatch, which produced the\nfollowing warning:\n\n fs/btrfs/ioctl.c:843 create_snapshot() warn: '&pending_snapshot->list' not removed from list\n\nSo fix this by not having the snapshot creation ioctl directly add the\npending snapshot to the transaction's list. Instead add the pending\nsnapshot to the transaction handle, and then at btrfs_commit_transaction()\nwe add the snapshot to the list only when we can guarantee that any error\nreturned after that point will result in a transaction abort, in which\ncase the ioctl code can safely free the pending snapshot and no one can\naccess it anymore.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48733"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/28b21c558a3753171097193b6f6602a94169093a"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/9372fa1d73da5f1673921e365d0cd2c27ec7adc2"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/a7b717fa15165d3d9245614680bebc48a52ac05d"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T12:15:11Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-gw48-9prx-v2xx/GHSA-gw48-9prx-v2xx.json b/advisories/unreviewed/2024/06/GHSA-gw48-9prx-v2xx/GHSA-gw48-9prx-v2xx.json
new file mode 100644
index 00000000000..7394b3f8ac3
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-gw48-9prx-v2xx/GHSA-gw48-9prx-v2xx.json
@@ -0,0 +1,31 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-gw48-9prx-v2xx",
+ "modified": "2024-06-20T12:31:20Z",
+ "published": "2024-06-20T12:31:20Z",
+ "aliases": [
+ "CVE-2024-5886"
+ ],
+ "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5886"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T11:15:56Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-h9h2-6w4q-6c52/GHSA-h9h2-6w4q-6c52.json b/advisories/unreviewed/2024/06/GHSA-h9h2-6w4q-6c52/GHSA-h9h2-6w4q-6c52.json
new file mode 100644
index 00000000000..8c0b1dc7e69
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-h9h2-6w4q-6c52/GHSA-h9h2-6w4q-6c52.json
@@ -0,0 +1,47 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-h9h2-6w4q-6c52",
+ "modified": "2024-06-20T12:31:21Z",
+ "published": "2024-06-20T12:31:21Z",
+ "aliases": [
+ "CVE-2022-48748"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: bridge: vlan: fix memory leak in __allowed_ingress\n\nWhen using per-vlan state, if vlan snooping and stats are disabled,\nuntagged or priority-tagged ingress frame will go to check pvid state.\nIf the port state is forwarding and the pvid state is not\nlearning/forwarding, untagged or priority-tagged frame will be dropped\nbut skb memory is not freed.\nShould free skb when __allowed_ingress returns false.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48748"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/14be8d448fca6fe7b2a413831eedd55aef6c6511"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/446ff1fc37c74093e81db40811a07b5a19f1d797"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/c5e216e880fa6f2cd9d4a6541269377657163098"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/fd20d9738395cf8e27d0a17eba34169699fccdff"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T12:15:13Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-hcr7-cqwc-q5gq/GHSA-hcr7-cqwc-q5gq.json b/advisories/unreviewed/2024/06/GHSA-hcr7-cqwc-q5gq/GHSA-hcr7-cqwc-q5gq.json
index c76a0e9530c..79705e66fa2 100644
--- a/advisories/unreviewed/2024/06/GHSA-hcr7-cqwc-q5gq/GHSA-hcr7-cqwc-q5gq.json
+++ b/advisories/unreviewed/2024/06/GHSA-hcr7-cqwc-q5gq/GHSA-hcr7-cqwc-q5gq.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hcr7-cqwc-q5gq",
- "modified": "2024-06-20T09:30:59Z",
+ "modified": "2024-06-20T12:31:19Z",
"published": "2024-06-20T09:30:59Z",
"aliases": [
"CVE-2024-34693"
@@ -24,6 +24,10 @@
{
"type": "WEB",
"url": "https://lists.apache.org/thread/1803x1s34m7r71h1k0q1njol8k6fmyon"
+ },
+ {
+ "type": "WEB",
+ "url": "http://www.openwall.com/lists/oss-security/2024/06/20/1"
}
],
"database_specific": {
diff --git a/advisories/unreviewed/2024/06/GHSA-hhpm-mjg9-jj2m/GHSA-hhpm-mjg9-jj2m.json b/advisories/unreviewed/2024/06/GHSA-hhpm-mjg9-jj2m/GHSA-hhpm-mjg9-jj2m.json
new file mode 100644
index 00000000000..0e3ebdbc59b
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-hhpm-mjg9-jj2m/GHSA-hhpm-mjg9-jj2m.json
@@ -0,0 +1,43 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-hhpm-mjg9-jj2m",
+ "modified": "2024-06-20T12:31:21Z",
+ "published": "2024-06-20T12:31:20Z",
+ "aliases": [
+ "CVE-2022-48727"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: arm64: Avoid consuming a stale esr value when SError occur\n\nWhen any exception other than an IRQ occurs, the CPU updates the ESR_EL2\nregister with the exception syndrome. An SError may also become pending,\nand will be synchronised by KVM. KVM notes the exception type, and whether\nan SError was synchronised in exit_code.\n\nWhen an exception other than an IRQ occurs, fixup_guest_exit() updates\nvcpu->arch.fault.esr_el2 from the hardware register. When an SError was\nsynchronised, the vcpu esr value is used to determine if the exception\nwas due to an HVC. If so, ELR_EL2 is moved back one instruction. This\nis so that KVM can process the SError first, and re-execute the HVC if\nthe guest survives the SError.\n\nBut if an IRQ synchronises an SError, the vcpu's esr value is stale.\nIf the previous non-IRQ exception was an HVC, KVM will corrupt ELR_EL2,\ncausing an unrelated guest instruction to be executed twice.\n\nCheck ARM_EXCEPTION_CODE() before messing with ELR_EL2, IRQs don't\nupdate this register so don't need to check.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48727"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/1c71dbc8a179d99dd9bb7e7fc1888db613cf85de"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/57e2986c3b25092691a6e3d6ee9168caf8978932"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/e1e852746997500f1873f60b954da5f02cc2dba3"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T12:15:11Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-hj37-jcv3-rcw4/GHSA-hj37-jcv3-rcw4.json b/advisories/unreviewed/2024/06/GHSA-hj37-jcv3-rcw4/GHSA-hj37-jcv3-rcw4.json
new file mode 100644
index 00000000000..8307bf513ba
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-hj37-jcv3-rcw4/GHSA-hj37-jcv3-rcw4.json
@@ -0,0 +1,63 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-hj37-jcv3-rcw4",
+ "modified": "2024-06-20T12:31:21Z",
+ "published": "2024-06-20T12:31:21Z",
+ "aliases": [
+ "CVE-2022-48743"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: amd-xgbe: Fix skb data length underflow\n\nThere will be BUG_ON() triggered in include/linux/skbuff.h leading to\nintermittent kernel panic, when the skb length underflow is detected.\n\nFix this by dropping the packet if such length underflows are seen\nbecause of inconsistencies in the hardware descriptors.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48743"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/34aeb4da20f93ac80a6291a2dbe7b9c6460e9b26"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/4d3fcfe8464838b3920bc2b939d888e0b792934e"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/5aac9108a180fc06e28d4e7fb00247ce603b72ee"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/617f9934bb37993b9813832516f318ba874bcb7d"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/9892742f035f7aa7dcd2bb0750effa486db89576"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/9924c80bd484340191e586110ca22bff23a49f2e"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/db6fd92316a254be2097556f01bccecf560e53ce"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/e8f73f620fee5f52653ed2da360121e4446575c5"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T12:15:12Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-hmp7-pqw6-66rw/GHSA-hmp7-pqw6-66rw.json b/advisories/unreviewed/2024/06/GHSA-hmp7-pqw6-66rw/GHSA-hmp7-pqw6-66rw.json
new file mode 100644
index 00000000000..f6e6509b734
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-hmp7-pqw6-66rw/GHSA-hmp7-pqw6-66rw.json
@@ -0,0 +1,39 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-hmp7-pqw6-66rw",
+ "modified": "2024-06-20T12:31:22Z",
+ "published": "2024-06-20T12:31:22Z",
+ "aliases": [
+ "CVE-2022-48750"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (nct6775) Fix crash in clear_caseopen\n\nPaweł Marciniak reports the following crash, observed when clearing\nthe chassis intrusion alarm.\n\nBUG: kernel NULL pointer dereference, address: 0000000000000028\nPGD 0 P4D 0\nOops: 0000 [#1] PREEMPT SMP PTI\nCPU: 3 PID: 4815 Comm: bash Tainted: G S 5.16.2-200.fc35.x86_64 #1\nHardware name: To Be Filled By O.E.M. To Be Filled By O.E.M./Z97 Extreme4, BIOS P2.60A 05/03/2018\nRIP: 0010:clear_caseopen+0x5a/0x120 [nct6775]\nCode: 68 70 e8 e9 32 b1 e3 85 c0 0f 85 d2 00 00 00 48 83 7c 24 ...\nRSP: 0018:ffffabcb02803dd8 EFLAGS: 00010246\nRAX: 0000000000000000 RBX: 0000000000000002 RCX: 0000000000000000\nRDX: ffff8e8808192880 RSI: 0000000000000000 RDI: ffff8e87c7509a68\nRBP: 0000000000000000 R08: 0000000000000001 R09: 000000000000000a\nR10: 000000000000000a R11: f000000000000000 R12: 000000000000001f\nR13: ffff8e87c7509828 R14: ffff8e87c7509a68 R15: ffff8e88494527a0\nFS: 00007f4db9151740(0000) GS:ffff8e8ebfec0000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000000000000028 CR3: 0000000166b66001 CR4: 00000000001706e0\nCall Trace:\n \n kernfs_fop_write_iter+0x11c/0x1b0\n new_sync_write+0x10b/0x180\n vfs_write+0x209/0x2a0\n ksys_write+0x4f/0xc0\n do_syscall_64+0x3b/0x90\n entry_SYSCALL_64_after_hwframe+0x44/0xae\n\nThe problem is that the device passed to clear_caseopen() is the hwmon\ndevice, not the platform device, and the platform data is not set in the\nhwmon device. Store the pointer to sio_data in struct nct6775_data and\nget if from there if needed.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48750"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/79da533d3cc717ccc05ddbd3190da8a72bc2408b"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/cfb7d12f2e4a4d694f49e9b4ebb352f7b67cdfbb"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T12:15:13Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-j2qm-vfcf-p3gj/GHSA-j2qm-vfcf-p3gj.json b/advisories/unreviewed/2024/06/GHSA-j2qm-vfcf-p3gj/GHSA-j2qm-vfcf-p3gj.json
new file mode 100644
index 00000000000..8e702c3f093
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-j2qm-vfcf-p3gj/GHSA-j2qm-vfcf-p3gj.json
@@ -0,0 +1,59 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-j2qm-vfcf-p3gj",
+ "modified": "2024-06-20T12:31:22Z",
+ "published": "2024-06-20T12:31:22Z",
+ "aliases": [
+ "CVE-2022-48771"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/vmwgfx: Fix stale file descriptors on failed usercopy\n\nA failing usercopy of the fence_rep object will lead to a stale entry in\nthe file descriptor table as put_unused_fd() won't release it. This\nenables userland to refer to a dangling 'file' object through that still\nvalid file descriptor, leading to all kinds of use-after-free\nexploitation scenarios.\n\nFix this by deferring the call to fd_install() until after the usercopy\nhas succeeded.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48771"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/0008a0c78fc33a84e2212a7c04e6b21a36ca6f4d"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/1d833b27fb708d6fdf5de9f6b3a8be4bd4321565"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/6066977961fc6f437bc064f628cf9b0e4571c56c"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/84b1259fe36ae0915f3d6ddcea6377779de48b82"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/a0f90c8815706981c483a652a6aefca51a5e191c"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/ae2b20f27732fe92055d9e7b350abc5cdf3e2414"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/e8d092a62449dcfc73517ca43963d2b8f44d0516"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T12:15:15Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-j385-2ppr-7766/GHSA-j385-2ppr-7766.json b/advisories/unreviewed/2024/06/GHSA-j385-2ppr-7766/GHSA-j385-2ppr-7766.json
new file mode 100644
index 00000000000..8a3f71420f0
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-j385-2ppr-7766/GHSA-j385-2ppr-7766.json
@@ -0,0 +1,43 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-j385-2ppr-7766",
+ "modified": "2024-06-20T12:31:22Z",
+ "published": "2024-06-20T12:31:22Z",
+ "aliases": [
+ "CVE-2022-48751"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/smc: Transitional solution for clcsock race issue\n\nWe encountered a crash in smc_setsockopt() and it is caused by\naccessing smc->clcsock after clcsock was released.\n\n BUG: kernel NULL pointer dereference, address: 0000000000000020\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\n PGD 0 P4D 0\n Oops: 0000 [#1] PREEMPT SMP PTI\n CPU: 1 PID: 50309 Comm: nginx Kdump: loaded Tainted: G E 5.16.0-rc4+ #53\n RIP: 0010:smc_setsockopt+0x59/0x280 [smc]\n Call Trace:\n \n __sys_setsockopt+0xfc/0x190\n __x64_sys_setsockopt+0x20/0x30\n do_syscall_64+0x34/0x90\n entry_SYSCALL_64_after_hwframe+0x44/0xae\n RIP: 0033:0x7f16ba83918e\n \n\nThis patch tries to fix it by holding clcsock_release_lock and\nchecking whether clcsock has already been released before access.\n\nIn case that a crash of the same reason happens in smc_getsockopt()\nor smc_switch_to_fallback(), this patch also checkes smc->clcsock\nin them too. And the caller of smc_switch_to_fallback() will identify\nwhether fallback succeeds according to the return value.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48751"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/38f0bdd548fd2ef5d481b88d8a2bfef968452e34"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/4284225cd8001e134f5cf533a7cd244bbb654d0f"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/c0bf3d8a943b6f2e912b7c1de03e2ef28e76f760"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T12:15:13Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-j52p-q7q4-9vwc/GHSA-j52p-q7q4-9vwc.json b/advisories/unreviewed/2024/06/GHSA-j52p-q7q4-9vwc/GHSA-j52p-q7q4-9vwc.json
new file mode 100644
index 00000000000..c74cd0a20b5
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-j52p-q7q4-9vwc/GHSA-j52p-q7q4-9vwc.json
@@ -0,0 +1,47 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-j52p-q7q4-9vwc",
+ "modified": "2024-06-20T12:31:21Z",
+ "published": "2024-06-20T12:31:21Z",
+ "aliases": [
+ "CVE-2022-48746"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: Fix handling of wrong devices during bond netevent\n\nCurrent implementation of bond netevent handler only check if\nthe handled netdev is VF representor and it missing a check if\nthe VF representor is on the same phys device of the bond handling\nthe netevent.\n\nFix by adding the missing check and optimizing the check if\nthe netdev is VF representor so it will not access uninitialized\nprivate data and crashes.\n\nBUG: kernel NULL pointer dereference, address: 000000000000036c\nPGD 0 P4D 0\nOops: 0000 [#1] SMP NOPTI\nWorkqueue: eth3bond0 bond_mii_monitor [bonding]\nRIP: 0010:mlx5e_is_uplink_rep+0xc/0x50 [mlx5_core]\nRSP: 0018:ffff88812d69fd60 EFLAGS: 00010282\nRAX: 0000000000000000 RBX: ffff8881cf800000 RCX: 0000000000000000\nRDX: ffff88812d69fe10 RSI: 000000000000001b RDI: ffff8881cf800880\nRBP: ffff8881cf800000 R08: 00000445cabccf2b R09: 0000000000000008\nR10: 0000000000000004 R11: 0000000000000008 R12: ffff88812d69fe10\nR13: 00000000fffffffe R14: ffff88820c0f9000 R15: 0000000000000000\nFS: 0000000000000000(0000) GS:ffff88846fb00000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 000000000000036c CR3: 0000000103d80006 CR4: 0000000000370ea0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nCall Trace:\n mlx5e_eswitch_uplink_rep+0x31/0x40 [mlx5_core]\n mlx5e_rep_is_lag_netdev+0x94/0xc0 [mlx5_core]\n mlx5e_rep_esw_bond_netevent+0xeb/0x3d0 [mlx5_core]\n raw_notifier_call_chain+0x41/0x60\n call_netdevice_notifiers_info+0x34/0x80\n netdev_lower_state_changed+0x4e/0xa0\n bond_mii_monitor+0x56b/0x640 [bonding]\n process_one_work+0x1b9/0x390\n worker_thread+0x4d/0x3d0\n ? rescuer_thread+0x350/0x350\n kthread+0x124/0x150\n ? set_kthread_struct+0x40/0x40\n ret_from_fork+0x1f/0x30",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48746"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/4fad499d7fece448e7230d5e5b92f6d8a073e0bb"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/a01ee1b8165f4161459b5ec4e728bc7130fe8cd4"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/ec41332e02bd0acf1f24206867bb6a02f5877a62"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/fe70126da6063c29ca161cdec7ad1dae9af836b3"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T12:15:12Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-mfmr-68wm-65f9/GHSA-mfmr-68wm-65f9.json b/advisories/unreviewed/2024/06/GHSA-mfmr-68wm-65f9/GHSA-mfmr-68wm-65f9.json
new file mode 100644
index 00000000000..939b4d4772d
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-mfmr-68wm-65f9/GHSA-mfmr-68wm-65f9.json
@@ -0,0 +1,47 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-mfmr-68wm-65f9",
+ "modified": "2024-06-20T12:31:21Z",
+ "published": "2024-06-20T12:31:21Z",
+ "aliases": [
+ "CVE-2022-48728"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nIB/hfi1: Fix AIP early init panic\n\nAn early failure in hfi1_ipoib_setup_rn() can lead to the following panic:\n\n BUG: unable to handle kernel NULL pointer dereference at 00000000000001b0\n PGD 0 P4D 0\n Oops: 0002 [#1] SMP NOPTI\n Workqueue: events work_for_cpu_fn\n RIP: 0010:try_to_grab_pending+0x2b/0x140\n Code: 1f 44 00 00 41 55 41 54 55 48 89 d5 53 48 89 fb 9c 58 0f 1f 44 00 00 48 89 c2 fa 66 0f 1f 44 00 00 48 89 55 00 40 84 f6 75 77 48 0f ba 2b 00 72 09 31 c0 5b 5d 41 5c 41 5d c3 48 89 df e8 6c\n RSP: 0018:ffffb6b3cf7cfa48 EFLAGS: 00010046\n RAX: 0000000000000246 RBX: 00000000000001b0 RCX: 0000000000000000\n RDX: 0000000000000246 RSI: 0000000000000000 RDI: 00000000000001b0\n RBP: ffffb6b3cf7cfa70 R08: 0000000000000f09 R09: 0000000000000001\n R10: 0000000000000000 R11: 0000000000000001 R12: 0000000000000000\n R13: ffffb6b3cf7cfa90 R14: ffffffff9b2fbfc0 R15: ffff8a4fdf244690\n FS: 0000000000000000(0000) GS:ffff8a527f400000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 00000000000001b0 CR3: 00000017e2410003 CR4: 00000000007706f0\n DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n PKRU: 55555554\n Call Trace:\n __cancel_work_timer+0x42/0x190\n ? dev_printk_emit+0x4e/0x70\n iowait_cancel_work+0x15/0x30 [hfi1]\n hfi1_ipoib_txreq_deinit+0x5a/0x220 [hfi1]\n ? dev_err+0x6c/0x90\n hfi1_ipoib_netdev_dtor+0x15/0x30 [hfi1]\n hfi1_ipoib_setup_rn+0x10e/0x150 [hfi1]\n rdma_init_netdev+0x5a/0x80 [ib_core]\n ? hfi1_ipoib_free_rdma_netdev+0x20/0x20 [hfi1]\n ipoib_intf_init+0x6c/0x350 [ib_ipoib]\n ipoib_intf_alloc+0x5c/0xc0 [ib_ipoib]\n ipoib_add_one+0xbe/0x300 [ib_ipoib]\n add_client_context+0x12c/0x1a0 [ib_core]\n enable_device_and_get+0xdc/0x1d0 [ib_core]\n ib_register_device+0x572/0x6b0 [ib_core]\n rvt_register_device+0x11b/0x220 [rdmavt]\n hfi1_register_ib_device+0x6b4/0x770 [hfi1]\n do_init_one.isra.20+0x3e3/0x680 [hfi1]\n local_pci_probe+0x41/0x90\n work_for_cpu_fn+0x16/0x20\n process_one_work+0x1a7/0x360\n ? create_worker+0x1a0/0x1a0\n worker_thread+0x1cf/0x390\n ? create_worker+0x1a0/0x1a0\n kthread+0x116/0x130\n ? kthread_flush_work_fn+0x10/0x10\n ret_from_fork+0x1f/0x40\n\nThe panic happens in hfi1_ipoib_txreq_deinit() because there is a NULL\nderef when hfi1_ipoib_netdev_dtor() is called in this error case.\n\nhfi1_ipoib_txreq_init() and hfi1_ipoib_rxq_init() are self unwinding so\nfix by adjusting the error paths accordingly.\n\nOther changes:\n- hfi1_ipoib_free_rdma_netdev() is deleted including the free_netdev()\n since the netdev core code deletes calls free_netdev()\n- The switch to the accelerated entrances is moved to the success path.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48728"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/1899c3cad265c4583658aed5293d02e8af84276b"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/4a9bd1e6780fc59f81466ec3489d5ad535a37190"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/5f8f55b92edd621f056bdf09e572092849fabd83"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/a3dd4d2682f2a796121609e5f3bbeb1243198c53"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T12:15:11Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-p546-cwvc-mhpj/GHSA-p546-cwvc-mhpj.json b/advisories/unreviewed/2024/06/GHSA-p546-cwvc-mhpj/GHSA-p546-cwvc-mhpj.json
new file mode 100644
index 00000000000..11e088e1454
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-p546-cwvc-mhpj/GHSA-p546-cwvc-mhpj.json
@@ -0,0 +1,39 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-p546-cwvc-mhpj",
+ "modified": "2024-06-20T12:31:22Z",
+ "published": "2024-06-20T12:31:22Z",
+ "aliases": [
+ "CVE-2023-52883"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: Fix possible null pointer dereference\n\nabo->tbo.resource may be NULL in amdgpu_vm_bo_update.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52883"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/51b79f33817544e3b4df838d86e8e8e4388ff684"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/fefac8c4686fd81fde6830c6dae32f9001d2ac28"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T12:15:15Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-pwf7-jc5h-rr33/GHSA-pwf7-jc5h-rr33.json b/advisories/unreviewed/2024/06/GHSA-pwf7-jc5h-rr33/GHSA-pwf7-jc5h-rr33.json
new file mode 100644
index 00000000000..2c3b0afe57e
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-pwf7-jc5h-rr33/GHSA-pwf7-jc5h-rr33.json
@@ -0,0 +1,51 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-pwf7-jc5h-rr33",
+ "modified": "2024-06-20T12:31:22Z",
+ "published": "2024-06-20T12:31:22Z",
+ "aliases": [
+ "CVE-2022-48768"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntracing/histogram: Fix a potential memory leak for kstrdup()\n\nkfree() is missing on an error path to free the memory allocated by\nkstrdup():\n\n p = param = kstrdup(data->params[i], GFP_KERNEL);\n\nSo it is better to free it via kfree(p).",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48768"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/8a8878ebb596281f50fc0b9a6e1f23f0d7f154e8"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/d71b06aa995007eafd247626d0669b9364c42ad7"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/df86e2fe808c3536a9dba353cc2bebdfea00d0cf"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/e33fa4a46ee22de88a700e2e3d033da8214a5175"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/e629e7b525a179e29d53463d992bdee759c950fb"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T12:15:14Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-q3wh-8888-5hjg/GHSA-q3wh-8888-5hjg.json b/advisories/unreviewed/2024/06/GHSA-q3wh-8888-5hjg/GHSA-q3wh-8888-5hjg.json
new file mode 100644
index 00000000000..5390eabcfe0
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-q3wh-8888-5hjg/GHSA-q3wh-8888-5hjg.json
@@ -0,0 +1,39 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-q3wh-8888-5hjg",
+ "modified": "2024-06-20T12:31:21Z",
+ "published": "2024-06-20T12:31:21Z",
+ "aliases": [
+ "CVE-2022-48729"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nIB/hfi1: Fix panic with larger ipoib send_queue_size\n\nWhen the ipoib send_queue_size is increased from the default the following\npanic happens:\n\n RIP: 0010:hfi1_ipoib_drain_tx_ring+0x45/0xf0 [hfi1]\n Code: 31 e4 eb 0f 8b 85 c8 02 00 00 41 83 c4 01 44 39 e0 76 60 8b 8d cc 02 00 00 44 89 e3 be 01 00 00 00 d3 e3 48 03 9d c0 02 00 00 83 18 01 00 00 00 00 00 00 48 8b bb 30 01 00 00 e8 25 af a7 e0\n RSP: 0018:ffffc9000798f4a0 EFLAGS: 00010286\n RAX: 0000000000008000 RBX: ffffc9000aa0f000 RCX: 000000000000000f\n RDX: 0000000000000000 RSI: 0000000000000001 RDI: 0000000000000000\n RBP: ffff88810ff08000 R08: ffff88889476d900 R09: 0000000000000101\n R10: 0000000000000000 R11: ffffc90006590ff8 R12: 0000000000000200\n R13: ffffc9000798fba8 R14: 0000000000000000 R15: 0000000000000001\n FS: 00007fd0f79cc3c0(0000) GS:ffff88885fb00000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: ffffc9000aa0f118 CR3: 0000000889c84001 CR4: 00000000001706e0\n Call Trace:\n \n hfi1_ipoib_napi_tx_disable+0x45/0x60 [hfi1]\n hfi1_ipoib_dev_stop+0x18/0x80 [hfi1]\n ipoib_ib_dev_stop+0x1d/0x40 [ib_ipoib]\n ipoib_stop+0x48/0xc0 [ib_ipoib]\n __dev_close_many+0x9e/0x110\n __dev_change_flags+0xd9/0x210\n dev_change_flags+0x21/0x60\n do_setlink+0x31c/0x10f0\n ? __nla_validate_parse+0x12d/0x1a0\n ? __nla_parse+0x21/0x30\n ? inet6_validate_link_af+0x5e/0xf0\n ? cpumask_next+0x1f/0x20\n ? __snmp6_fill_stats64.isra.53+0xbb/0x140\n ? __nla_validate_parse+0x47/0x1a0\n __rtnl_newlink+0x530/0x910\n ? pskb_expand_head+0x73/0x300\n ? __kmalloc_node_track_caller+0x109/0x280\n ? __nla_put+0xc/0x20\n ? cpumask_next_and+0x20/0x30\n ? update_sd_lb_stats.constprop.144+0xd3/0x820\n ? _raw_spin_unlock_irqrestore+0x25/0x37\n ? __wake_up_common_lock+0x87/0xc0\n ? kmem_cache_alloc_trace+0x3d/0x3d0\n rtnl_newlink+0x43/0x60\n\nThe issue happens when the shift that should have been a function of the\ntxq item size mistakenly used the ring size.\n\nFix by using the item size.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48729"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/1530d84fba1e459ba55f46aa42649b88773210e7"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/8c83d39cc730378bbac64d67a551897b203a606e"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T12:15:11Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-qc27-qr34-95w5/GHSA-qc27-qr34-95w5.json b/advisories/unreviewed/2024/06/GHSA-qc27-qr34-95w5/GHSA-qc27-qr34-95w5.json
new file mode 100644
index 00000000000..b15328d7672
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-qc27-qr34-95w5/GHSA-qc27-qr34-95w5.json
@@ -0,0 +1,43 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-qc27-qr34-95w5",
+ "modified": "2024-06-20T12:31:20Z",
+ "published": "2024-06-20T12:31:20Z",
+ "aliases": [
+ "CVE-2022-48716"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: codecs: wcd938x: fix incorrect used of portid\n\nMixer controls have the channel id in mixer->reg, which is not same\nas port id. port id should be derived from chan_info array.\nSo fix this. Without this, its possible that we could corrupt\nstruct wcd938x_sdw_priv by accessing port_map array out of range\nwith channel id instead of port id.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48716"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/9167f2712dc8c24964840a4d1e2ebf130e846b95"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/aa7152f9f117b3e66b3c0d4158ca4c6d46ab229f"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/c5c1546a654f613e291a7c5d6f3660fc1eb6d0c7"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T11:15:55Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-qg8q-9c83-3485/GHSA-qg8q-9c83-3485.json b/advisories/unreviewed/2024/06/GHSA-qg8q-9c83-3485/GHSA-qg8q-9c83-3485.json
new file mode 100644
index 00000000000..feeafb19f76
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-qg8q-9c83-3485/GHSA-qg8q-9c83-3485.json
@@ -0,0 +1,63 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-qg8q-9c83-3485",
+ "modified": "2024-06-20T12:31:21Z",
+ "published": "2024-06-20T12:31:21Z",
+ "aliases": [
+ "CVE-2022-48742"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nrtnetlink: make sure to refresh master_dev/m_ops in __rtnl_newlink()\n\nWhile looking at one unrelated syzbot bug, I found the replay logic\nin __rtnl_newlink() to potentially trigger use-after-free.\n\nIt is better to clear master_dev and m_ops inside the loop,\nin case we have to replay it.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48742"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/2cf180360d66bd657e606c1217e0e668e6faa303"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/36a9a0aee881940476b254e0352581401b23f210"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/3bbe2019dd12b8d13671ee6cda055d49637b4c39"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/7d9211678c0f0624f74cdff36117ab8316697bb8"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/a01e60a1ec6bef9be471fb7182a33c6d6f124e93"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/bd43771ee9759dd9dfae946bff190e2c5a120de5"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/c6f6f2444bdbe0079e41914a35081530d0409963"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/def5e7070079b2a214b3b1a2fbec623e6fbfe34a"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T12:15:12Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-qpxp-m569-qp25/GHSA-qpxp-m569-qp25.json b/advisories/unreviewed/2024/06/GHSA-qpxp-m569-qp25/GHSA-qpxp-m569-qp25.json
new file mode 100644
index 00000000000..7d744df6f4a
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-qpxp-m569-qp25/GHSA-qpxp-m569-qp25.json
@@ -0,0 +1,51 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-qpxp-m569-qp25",
+ "modified": "2024-06-20T12:31:21Z",
+ "published": "2024-06-20T12:31:21Z",
+ "aliases": [
+ "CVE-2022-48747"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nblock: Fix wrong offset in bio_truncate()\n\nbio_truncate() clears the buffer outside of last block of bdev, however\ncurrent bio_truncate() is using the wrong offset of page. So it can\nreturn the uninitialized data.\n\nThis happened when both of truncated/corrupted FS and userspace (via\nbdev) are trying to read the last of bdev.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48747"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/3ee859e384d453d6ac68bfd5971f630d9fa46ad3"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/4633a79ff8bc82770486a063a08b55e5162521d8"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/6cbf4c731d7812518cd857c2cfc3da9fd120f6ae"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/941d5180c430ce5b0f7a3622ef9b76077bfa3d82"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/b63e120189fd92aff00096d11e2fc5253f60248b"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T12:15:12Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-qx5f-76wj-2xm5/GHSA-qx5f-76wj-2xm5.json b/advisories/unreviewed/2024/06/GHSA-qx5f-76wj-2xm5/GHSA-qx5f-76wj-2xm5.json
new file mode 100644
index 00000000000..4081fd72a32
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-qx5f-76wj-2xm5/GHSA-qx5f-76wj-2xm5.json
@@ -0,0 +1,47 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-qx5f-76wj-2xm5",
+ "modified": "2024-06-20T12:31:22Z",
+ "published": "2024-06-20T12:31:22Z",
+ "aliases": [
+ "CVE-2022-48770"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Guard against accessing NULL pt_regs in bpf_get_task_stack()\n\ntask_pt_regs() can return NULL on powerpc for kernel threads. This is\nthen used in __bpf_get_stack() to check for user mode, resulting in a\nkernel oops. Guard against this by checking return value of\ntask_pt_regs() before trying to obtain the call chain.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48770"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/0bcd484587b3b3092e448d27dc369e347e1810c3"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/b82ef4985a6d05e80f604624332430351df7b79a"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/b992f01e66150fc5e90be4a96f5eb8e634c8249e"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/ff6bdc205fd0a83bd365405d4e31fb5905826996"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T12:15:14Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-r68c-p976-5jmg/GHSA-r68c-p976-5jmg.json b/advisories/unreviewed/2024/06/GHSA-r68c-p976-5jmg/GHSA-r68c-p976-5jmg.json
new file mode 100644
index 00000000000..cd318ac8bb6
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-r68c-p976-5jmg/GHSA-r68c-p976-5jmg.json
@@ -0,0 +1,55 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-r68c-p976-5jmg",
+ "modified": "2024-06-20T12:31:19Z",
+ "published": "2024-06-20T12:31:19Z",
+ "aliases": [
+ "CVE-2021-47617"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nPCI: pciehp: Fix infinite loop in IRQ handler upon power fault\n\nThe Power Fault Detected bit in the Slot Status register differs from\nall other hotplug events in that it is sticky: It can only be cleared\nafter turning off slot power. Per PCIe r5.0, sec. 6.7.1.8:\n\n If a power controller detects a main power fault on the hot-plug slot,\n it must automatically set its internal main power fault latch [...].\n The main power fault latch is cleared when software turns off power to\n the hot-plug slot.\n\nThe stickiness used to cause interrupt storms and infinite loops which\nwere fixed in 2009 by commits 5651c48cfafe (\"PCI pciehp: fix power fault\ninterrupt storm problem\") and 99f0169c17f3 (\"PCI: pciehp: enable\nsoftware notification on empty slots\").\n\nUnfortunately in 2020 the infinite loop issue was inadvertently\nreintroduced by commit 8edf5332c393 (\"PCI: pciehp: Fix MSI interrupt\nrace\"): The hardirq handler pciehp_isr() clears the PFD bit until\npciehp's power_fault_detected flag is set. That happens in the IRQ\nthread pciehp_ist(), which never learns of the event because the hardirq\nhandler is stuck in an infinite loop. Fix by setting the\npower_fault_detected flag already in the hardirq handler.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47617"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/1db58c6584a72102e98af2e600ea184ddaf2b8af"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/23584c1ed3e15a6f4bfab8dc5a88d94ab929ee12"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/3b4c966fb156ff3e70b2526d964952ff7c1574d9"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/464da38ba827f670deac6500a1de9a4f0f44c41d"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/6d6f1f0dac3e3441ecdb1103d4efb11b9ed24dd5"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/ff27f7d0333cff89ec85c419f431aca1b38fb16a"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T11:15:54Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-rfp5-p8gj-qx34/GHSA-rfp5-p8gj-qx34.json b/advisories/unreviewed/2024/06/GHSA-rfp5-p8gj-qx34/GHSA-rfp5-p8gj-qx34.json
new file mode 100644
index 00000000000..53a7b246b31
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-rfp5-p8gj-qx34/GHSA-rfp5-p8gj-qx34.json
@@ -0,0 +1,59 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-rfp5-p8gj-qx34",
+ "modified": "2024-06-20T12:31:22Z",
+ "published": "2024-06-20T12:31:22Z",
+ "aliases": [
+ "CVE-2022-48759"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nrpmsg: char: Fix race between the release of rpmsg_ctrldev and cdev\n\nstruct rpmsg_ctrldev contains a struct cdev. The current code frees\nthe rpmsg_ctrldev struct in rpmsg_ctrldev_release_device(), but the\ncdev is a managed object, therefore its release is not predictable\nand the rpmsg_ctrldev could be freed before the cdev is entirely\nreleased, as in the backtrace below.\n\n[ 93.625603] ODEBUG: free active (active state 0) object type: timer_list hint: delayed_work_timer_fn+0x0/0x7c\n[ 93.636115] WARNING: CPU: 0 PID: 12 at lib/debugobjects.c:488 debug_print_object+0x13c/0x1b0\n[ 93.644799] Modules linked in: veth xt_cgroup xt_MASQUERADE rfcomm algif_hash algif_skcipher af_alg uinput ip6table_nat fuse uvcvideo videobuf2_vmalloc venus_enc venus_dec videobuf2_dma_contig hci_uart btandroid btqca snd_soc_rt5682_i2c bluetooth qcom_spmi_temp_alarm snd_soc_rt5682v\n[ 93.715175] CPU: 0 PID: 12 Comm: kworker/0:1 Tainted: G B 5.4.163-lockdep #26\n[ 93.723855] Hardware name: Google Lazor (rev3 - 8) with LTE (DT)\n[ 93.730055] Workqueue: events kobject_delayed_cleanup\n[ 93.735271] pstate: 60c00009 (nZCv daif +PAN +UAO)\n[ 93.740216] pc : debug_print_object+0x13c/0x1b0\n[ 93.744890] lr : debug_print_object+0x13c/0x1b0\n[ 93.749555] sp : ffffffacf5bc7940\n[ 93.752978] x29: ffffffacf5bc7940 x28: dfffffd000000000\n[ 93.758448] x27: ffffffacdb11a800 x26: dfffffd000000000\n[ 93.763916] x25: ffffffd0734f856c x24: dfffffd000000000\n[ 93.769389] x23: 0000000000000000 x22: ffffffd0733c35b0\n[ 93.774860] x21: ffffffd0751994a0 x20: ffffffd075ec27c0\n[ 93.780338] x19: ffffffd075199100 x18: 00000000000276e0\n[ 93.785814] x17: 0000000000000000 x16: dfffffd000000000\n[ 93.791291] x15: ffffffffffffffff x14: 6e6968207473696c\n[ 93.796768] x13: 0000000000000000 x12: ffffffd075e2b000\n[ 93.802244] x11: 0000000000000001 x10: 0000000000000000\n[ 93.807723] x9 : d13400dff1921900 x8 : d13400dff1921900\n[ 93.813200] x7 : 0000000000000000 x6 : 0000000000000000\n[ 93.818676] x5 : 0000000000000080 x4 : 0000000000000000\n[ 93.824152] x3 : ffffffd0732a0fa4 x2 : 0000000000000001\n[ 93.829628] x1 : ffffffacf5bc7580 x0 : 0000000000000061\n[ 93.835104] Call trace:\n[ 93.837644] debug_print_object+0x13c/0x1b0\n[ 93.841963] __debug_check_no_obj_freed+0x25c/0x3c0\n[ 93.846987] debug_check_no_obj_freed+0x18/0x20\n[ 93.851669] slab_free_freelist_hook+0xbc/0x1e4\n[ 93.856346] kfree+0xfc/0x2f4\n[ 93.859416] rpmsg_ctrldev_release_device+0x78/0xb8\n[ 93.864445] device_release+0x84/0x168\n[ 93.868310] kobject_cleanup+0x12c/0x298\n[ 93.872356] kobject_delayed_cleanup+0x10/0x18\n[ 93.876948] process_one_work+0x578/0x92c\n[ 93.881086] worker_thread+0x804/0xcf8\n[ 93.884963] kthread+0x2a8/0x314\n[ 93.888303] ret_from_fork+0x10/0x18\n\nThe cdev_device_add/del() API was created to address this issue (see\ncommit '233ed09d7fda (\"chardev: add helper function to register char\ndevs with a struct device\")'), use it instead of cdev add/del().",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48759"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/1dbb206730f3e5ce90014ad569ddf8167ec4124a"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/70cb4295ec806b663665e1d2ed15caab6159880e"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/74d85e9fbc7022a4011102c7474a9c7aeb704a35"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/85aba11a8ea92a8eef2de95ebbe063086fd62d9c"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/b7fb2dad571d1e21173c06cef0bced77b323990a"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/d6cdc6ae542845d4d0ac8b6d99362bde7042a3c7"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/da27b834c1e0222e149e06caddf7718478086d1b"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T12:15:14Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-v47w-h9mw-wj4f/GHSA-v47w-h9mw-wj4f.json b/advisories/unreviewed/2024/06/GHSA-v47w-h9mw-wj4f/GHSA-v47w-h9mw-wj4f.json
new file mode 100644
index 00000000000..f0b97bcb42e
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-v47w-h9mw-wj4f/GHSA-v47w-h9mw-wj4f.json
@@ -0,0 +1,43 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-v47w-h9mw-wj4f",
+ "modified": "2024-06-20T12:31:21Z",
+ "published": "2024-06-20T12:31:21Z",
+ "aliases": [
+ "CVE-2022-48741"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\novl: fix NULL pointer dereference in copy up warning\n\nThis patch is fixing a NULL pointer dereference to get a recently\nintroduced warning message working.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48741"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/4ee7e4a6c9b298da44029ed9ec8ed23ae49cc209"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/9c7f8a35c5a83740c0e3ea540b6ad145c50d79aa"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/e6b678c1a3673de6a5d2f4e22bb725a086a0701a"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T12:15:12Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-v7qr-4h7w-77cm/GHSA-v7qr-4h7w-77cm.json b/advisories/unreviewed/2024/06/GHSA-v7qr-4h7w-77cm/GHSA-v7qr-4h7w-77cm.json
new file mode 100644
index 00000000000..662ece77b7d
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-v7qr-4h7w-77cm/GHSA-v7qr-4h7w-77cm.json
@@ -0,0 +1,39 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-v7qr-4h7w-77cm",
+ "modified": "2024-06-20T12:31:22Z",
+ "published": "2024-06-20T12:31:22Z",
+ "aliases": [
+ "CVE-2022-48764"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: x86: Free kvm_cpuid_entry2 array on post-KVM_RUN KVM_SET_CPUID{,2}\n\nFree the \"struct kvm_cpuid_entry2\" array on successful post-KVM_RUN\nKVM_SET_CPUID{,2} to fix a memory leak, the callers of kvm_set_cpuid()\nfree the array only on failure.\n\n BUG: memory leak\n unreferenced object 0xffff88810963a800 (size 2048):\n comm \"syz-executor025\", pid 3610, jiffies 4294944928 (age 8.080s)\n hex dump (first 32 bytes):\n 00 00 00 00 00 00 00 00 00 00 00 00 0d 00 00 00 ................\n 47 65 6e 75 6e 74 65 6c 69 6e 65 49 00 00 00 00 GenuntelineI....\n backtrace:\n [] kmalloc_node include/linux/slab.h:604 [inline]\n [] kvmalloc_node+0x3e/0x100 mm/util.c:580\n [] kvmalloc include/linux/slab.h:732 [inline]\n [] vmemdup_user+0x22/0x100 mm/util.c:199\n [] kvm_vcpu_ioctl_set_cpuid2+0x8f/0xf0 arch/x86/kvm/cpuid.c:423\n [] kvm_arch_vcpu_ioctl+0xb99/0x1e60 arch/x86/kvm/x86.c:5251\n [] kvm_vcpu_ioctl+0x4ad/0x950 arch/x86/kvm/../../../virt/kvm/kvm_main.c:4066\n [] vfs_ioctl fs/ioctl.c:51 [inline]\n [] __do_sys_ioctl fs/ioctl.c:874 [inline]\n [] __se_sys_ioctl fs/ioctl.c:860 [inline]\n [] __x64_sys_ioctl+0xfc/0x140 fs/ioctl.c:860\n [] do_syscall_x64 arch/x86/entry/common.c:50 [inline]\n [] do_syscall_64+0x35/0xb0 arch/x86/entry/common.c:80\n [] entry_SYSCALL_64_after_hwframe+0x44/0xae",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48764"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/811f95ff95270e6048197821434d9301e3d7f07c"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/b9ee734a14bb685b2088f2176d82b34cb4e30dbc"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T12:15:14Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-vccq-5j26-h8w6/GHSA-vccq-5j26-h8w6.json b/advisories/unreviewed/2024/06/GHSA-vccq-5j26-h8w6/GHSA-vccq-5j26-h8w6.json
new file mode 100644
index 00000000000..eb383ce1599
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-vccq-5j26-h8w6/GHSA-vccq-5j26-h8w6.json
@@ -0,0 +1,63 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-vccq-5j26-h8w6",
+ "modified": "2024-06-20T12:31:21Z",
+ "published": "2024-06-20T12:31:21Z",
+ "aliases": [
+ "CVE-2022-48736"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: ops: Reject out of bounds values in snd_soc_put_xr_sx()\n\nWe don't currently validate that the values being set are within the range\nwe advertised to userspace as being valid, do so and reject any values\nthat are out of range.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48736"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/17e16a66b4f9a310713d8599e6e1ca4a0c9fd28c"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/4cf28e9ae6e2e11a044be1bcbcfa1b0d8675fe4d"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/54abca038e287d3746dd40016514670a7f654c5c"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/6877f87579ed830f9ff6d478539074f035d04bfb"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/7659f25a80e6affb784b690df8994b79b4212fd4"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/b0a7836ecf1345814a7d8ef748fb797c520dad18"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/e09cf398e8c6db69c620b6d8073abc4377a07af5"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/fd9a23319f16e7031f0d8c98eed6e093c2927229"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T12:15:11Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-vcpc-x3pw-9whm/GHSA-vcpc-x3pw-9whm.json b/advisories/unreviewed/2024/06/GHSA-vcpc-x3pw-9whm/GHSA-vcpc-x3pw-9whm.json
new file mode 100644
index 00000000000..74933b2b247
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-vcpc-x3pw-9whm/GHSA-vcpc-x3pw-9whm.json
@@ -0,0 +1,50 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-vcpc-x3pw-9whm",
+ "modified": "2024-06-20T12:31:20Z",
+ "published": "2024-06-20T12:31:20Z",
+ "aliases": [
+ "CVE-2024-6181"
+ ],
+ "details": "A vulnerability was found in LabVantage LIMS 2017. It has been declared as problematic. This vulnerability affects unknown code of the file /labvantage/rc?command=file&file=WEB-CORE/elements/files/filesembedded.jsp&size=32. The manipulation of the argument height/width leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-269152. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6181"
+ },
+ {
+ "type": "WEB",
+ "url": "https://gentle-khaan-c53.notion.site/Reflected-XSS-in-Labvantage-LIMS-9531d77dce984d4da2ddcab863962e9c?pvs=4"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?ctiid.269152"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?id.269152"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?submit.353709"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T11:15:56Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-vfq8-59v7-rr9v/GHSA-vfq8-59v7-rr9v.json b/advisories/unreviewed/2024/06/GHSA-vfq8-59v7-rr9v/GHSA-vfq8-59v7-rr9v.json
new file mode 100644
index 00000000000..6e136d0618d
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-vfq8-59v7-rr9v/GHSA-vfq8-59v7-rr9v.json
@@ -0,0 +1,47 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-vfq8-59v7-rr9v",
+ "modified": "2024-06-20T12:31:20Z",
+ "published": "2024-06-20T12:31:20Z",
+ "aliases": [
+ "CVE-2022-48714"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Use VM_MAP instead of VM_ALLOC for ringbuf\n\nAfter commit 2fd3fb0be1d1 (\"kasan, vmalloc: unpoison VM_ALLOC pages\nafter mapping\"), non-VM_ALLOC mappings will be marked as accessible\nin __get_vm_area_node() when KASAN is enabled. But now the flag for\nringbuf area is VM_ALLOC, so KASAN will complain out-of-bound access\nafter vmap() returns. Because the ringbuf area is created by mapping\nallocated pages, so use VM_MAP instead.\n\nAfter the change, info in /proc/vmallocinfo also changes from\n [start]-[end] 24576 ringbuf_map_alloc+0x171/0x290 vmalloc user\nto\n [start]-[end] 24576 ringbuf_map_alloc+0x171/0x290 vmap user",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48714"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/5e457aeab52a5947619e1f18047f4d2f3212b3eb"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/6304a613a97d6dcd49b93fbad31e9f39d1e138d6"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/b293dcc473d22a62dc6d78de2b15e4f49515db56"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/d578933f6226d5419af9306746efa1c693cbaf9c"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T11:15:55Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-vj7w-cq55-7h2m/GHSA-vj7w-cq55-7h2m.json b/advisories/unreviewed/2024/06/GHSA-vj7w-cq55-7h2m/GHSA-vj7w-cq55-7h2m.json
new file mode 100644
index 00000000000..ef63df23252
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-vj7w-cq55-7h2m/GHSA-vj7w-cq55-7h2m.json
@@ -0,0 +1,39 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-vj7w-cq55-7h2m",
+ "modified": "2024-06-20T12:31:22Z",
+ "published": "2024-06-20T12:31:22Z",
+ "aliases": [
+ "CVE-2022-48762"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\narm64: extable: fix load_unaligned_zeropad() reg indices\n\nIn ex_handler_load_unaligned_zeropad() we erroneously extract the data and\naddr register indices from ex->type rather than ex->data. As ex->type will\ncontain EX_TYPE_LOAD_UNALIGNED_ZEROPAD (i.e. 4):\n * We'll always treat X0 as the address register, since EX_DATA_REG_ADDR is\n extracted from bits [9:5]. Thus, we may attempt to dereference an\n arbitrary address as X0 may hold an arbitrary value.\n * We'll always treat X4 as the data register, since EX_DATA_REG_DATA is\n extracted from bits [4:0]. Thus we will corrupt X4 and cause arbitrary\n behaviour within load_unaligned_zeropad() and its caller.\n\nFix this by extracting both values from ex->data as originally intended.\n\nOn an MTE-enabled QEMU image we are hitting the following crash:\n Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000\n Call trace:\n fixup_exception+0xc4/0x108\n __do_kernel_fault+0x3c/0x268\n do_tag_check_fault+0x3c/0x104\n do_mem_abort+0x44/0xf4\n el1_abort+0x40/0x64\n el1h_64_sync_handler+0x60/0xa0\n el1h_64_sync+0x7c/0x80\n link_path_walk+0x150/0x344\n path_openat+0xa0/0x7dc\n do_filp_open+0xb8/0x168\n do_sys_openat2+0x88/0x17c\n __arm64_sys_openat+0x74/0xa0\n invoke_syscall+0x48/0x148\n el0_svc_common+0xb8/0xf8\n do_el0_svc+0x28/0x88\n el0_svc+0x24/0x84\n el0t_64_sync_handler+0x88/0xec\n el0t_64_sync+0x1b4/0x1b8\n Code: f8695a69 71007d1f 540000e0 927df12a (f940014a)",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48762"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/3758a6c74e08bdc15ccccd6872a6ad37d165239a"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/47fe7a1c5e3e011eeb4ab79f2d54a794fdd1c3eb"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T12:15:14Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-vjh8-wgcx-46j4/GHSA-vjh8-wgcx-46j4.json b/advisories/unreviewed/2024/06/GHSA-vjh8-wgcx-46j4/GHSA-vjh8-wgcx-46j4.json
new file mode 100644
index 00000000000..93de922c58e
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-vjh8-wgcx-46j4/GHSA-vjh8-wgcx-46j4.json
@@ -0,0 +1,63 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-vjh8-wgcx-46j4",
+ "modified": "2024-06-20T12:31:21Z",
+ "published": "2024-06-20T12:31:21Z",
+ "aliases": [
+ "CVE-2022-48732"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/nouveau: fix off by one in BIOS boundary checking\n\nBounds checking when parsing init scripts embedded in the BIOS reject\naccess to the last byte. This causes driver initialization to fail on\nApple eMac's with GeForce 2 MX GPUs, leaving the system with no working\nconsole.\n\nThis is probably only seen on OpenFirmware machines like PowerPC Macs\nbecause the BIOS image provided by OF is only the used parts of the ROM,\nnot a power-of-two blocks read from PCI directly so PCs always have\nempty bytes at the end that are never accessed.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48732"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/1b777d4d9e383d2744fc9b3a09af6ec1893c8b1a"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/909d3ec1bf9f0ec534bfc081b77c0836fea7b0e2"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/acc887ba88333f5fec49631f12d8cc7ebd95781c"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/b2a21669ee98aafc41c6d42ef15af4dab9e6e882"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/d4b746e60fd8eaa8016e144223abe91158edcdad"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/d877e814a62b7de9069aeff8bc1d979dfc996e06"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/e7c36fa8a1e63b08312162179c78a0c7795ea369"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/f071d9fa857582d7bd77f4906691f73d3edeab73"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T12:15:11Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-vvvp-c6hw-m8pj/GHSA-vvvp-c6hw-m8pj.json b/advisories/unreviewed/2024/06/GHSA-vvvp-c6hw-m8pj/GHSA-vvvp-c6hw-m8pj.json
new file mode 100644
index 00000000000..e5d97ff61b3
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-vvvp-c6hw-m8pj/GHSA-vvvp-c6hw-m8pj.json
@@ -0,0 +1,67 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-vvvp-c6hw-m8pj",
+ "modified": "2024-06-20T12:31:22Z",
+ "published": "2024-06-20T12:31:22Z",
+ "aliases": [
+ "CVE-2022-48757"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: fix information leakage in /proc/net/ptype\n\nIn one net namespace, after creating a packet socket without binding\nit to a device, users in other net namespaces can observe the new\n`packet_type` added by this packet socket by reading `/proc/net/ptype`\nfile. This is minor information leakage as packet socket is\nnamespace aware.\n\nAdd a net pointer in `packet_type` to keep the net namespace of\nof corresponding packet socket. In `ptype_seq_show`, this net pointer\nmust be checked when it is not NULL.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48757"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/47934e06b65637c88a762d9c98329ae6e3238888"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/839ec7039513a4f84bfbaff953a9393471176bee"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/8f88c78d24f6f346919007cd459fd7e51a8c7779"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/b67ad6170c0ea87391bb253f35d1f78857736e54"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/be1ca30331c7923c6f376610c1bd6059be9b1908"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/c38023032a598ec6263e008d62c7f02def72d5c7"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/db044d97460ea792110eb8b971e82569ded536c6"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/e372ecd455b6ebc7720f52bf4b5f5d44d02f2092"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/e43669c77cb3a742b7d84ecdc7c68c4167a7709b"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T12:15:13Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-w48q-m5vp-9pqr/GHSA-w48q-m5vp-9pqr.json b/advisories/unreviewed/2024/06/GHSA-w48q-m5vp-9pqr/GHSA-w48q-m5vp-9pqr.json
new file mode 100644
index 00000000000..be64f297ce2
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-w48q-m5vp-9pqr/GHSA-w48q-m5vp-9pqr.json
@@ -0,0 +1,47 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-w48q-m5vp-9pqr",
+ "modified": "2024-06-20T12:31:20Z",
+ "published": "2024-06-20T12:31:20Z",
+ "aliases": [
+ "CVE-2022-48712"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\next4: fix error handling in ext4_fc_record_modified_inode()\n\nCurrent code does not fully takes care of krealloc() error case, which\ncould lead to silent memory corruption or a kernel bug. This patch\nfixes that.\n\nAlso it cleans up some duplicated error handling logic from various\nfunctions in fast_commit.c file.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48712"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/14aa3f49c7fc6424763f4323bfbc3a807b0727dc"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/1b6762ecdf3cf12113772427c904aa3c420a1802"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/62e46e0ffc02daa8fcfc02f7a932cc8a19601b19"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/cdce59a1549190b66f8e3fe465c2b2f714b98a94"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T11:15:54Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-w8pj-f2rr-pxw2/GHSA-w8pj-f2rr-pxw2.json b/advisories/unreviewed/2024/06/GHSA-w8pj-f2rr-pxw2/GHSA-w8pj-f2rr-pxw2.json
new file mode 100644
index 00000000000..a70b8b461e1
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-w8pj-f2rr-pxw2/GHSA-w8pj-f2rr-pxw2.json
@@ -0,0 +1,50 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-w8pj-f2rr-pxw2",
+ "modified": "2024-06-20T12:31:22Z",
+ "published": "2024-06-20T12:31:22Z",
+ "aliases": [
+ "CVE-2024-6184"
+ ],
+ "details": "A vulnerability classified as critical was found in Ruijie RG-UAC 1.0. Affected by this vulnerability is an unknown functionality of the file /view/systemConfig/reboot/reboot_commit.php. The manipulation of the argument servicename leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-269155. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6184"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/L1OudFd8cl09/CVE/blob/main/11_06_2024_a.md"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?ctiid.269155"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?id.269155"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?submit.354119"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-78"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T12:15:15Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-wfmj-q8m4-96gm/GHSA-wfmj-q8m4-96gm.json b/advisories/unreviewed/2024/06/GHSA-wfmj-q8m4-96gm/GHSA-wfmj-q8m4-96gm.json
new file mode 100644
index 00000000000..8d0488aa0cb
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-wfmj-q8m4-96gm/GHSA-wfmj-q8m4-96gm.json
@@ -0,0 +1,47 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-wfmj-q8m4-96gm",
+ "modified": "2024-06-20T12:31:22Z",
+ "published": "2024-06-20T12:31:22Z",
+ "aliases": [
+ "CVE-2022-48749"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/msm/dpu: invalid parameter check in dpu_setup_dspp_pcc\n\nThe function performs a check on the \"ctx\" input parameter, however, it\nis used before the check.\n\nInitialize the \"base\" variable after the sanity check to avoid a\npossible NULL pointer dereference.\n\nAddresses-Coverity-ID: 1493866 (\"Null pointer dereference\")",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48749"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/170b22234d5495f5e0844246e23f004639ee89ba"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/1ebc18836d5df09061657f8c548e594cbb519476"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/8f069f6dde518dfebe86e848508c07e497bd9298"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/93a6e920d8ccb4df846c03b6e72f7e08843d294c"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T12:15:13Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-wp88-9pj8-x522/GHSA-wp88-9pj8-x522.json b/advisories/unreviewed/2024/06/GHSA-wp88-9pj8-x522/GHSA-wp88-9pj8-x522.json
new file mode 100644
index 00000000000..fc9307a263a
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-wp88-9pj8-x522/GHSA-wp88-9pj8-x522.json
@@ -0,0 +1,46 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-wp88-9pj8-x522",
+ "modified": "2024-06-20T12:31:22Z",
+ "published": "2024-06-20T12:31:22Z",
+ "aliases": [
+ "CVE-2024-6183"
+ ],
+ "details": "A vulnerability classified as problematic has been found in EZ-Suite EZ-Partner 5. Affected is an unknown function of the component Forgot Password Handler. The manipulation leads to basic cross site scripting. It is possible to launch the attack remotely. VDB-269154 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"
+ }
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6183"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?ctiid.269154"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?id.269154"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?submit.353713"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-80"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T12:15:15Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-wpx5-jrwp-94gj/GHSA-wpx5-jrwp-94gj.json b/advisories/unreviewed/2024/06/GHSA-wpx5-jrwp-94gj/GHSA-wpx5-jrwp-94gj.json
new file mode 100644
index 00000000000..30b34b0c31d
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-wpx5-jrwp-94gj/GHSA-wpx5-jrwp-94gj.json
@@ -0,0 +1,63 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-wpx5-jrwp-94gj",
+ "modified": "2024-06-20T12:31:21Z",
+ "published": "2024-06-20T12:31:21Z",
+ "aliases": [
+ "CVE-2022-48738"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: ops: Reject out of bounds values in snd_soc_put_volsw()\n\nWe don't currently validate that the values being set are within the range\nwe advertised to userspace as being valid, do so and reject any values\nthat are out of range.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48738"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/40f598698129b5ceaf31012f9501b775c7b6e57d"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/586ef863c94354a7e00e5ae5ef01443d1dc99bc7"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/65a61b1f56f5386486757930069fbdce94af08bf"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/68fd718724284788fc5f379e0b7cac541429ece7"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/817f7c9335ec01e0f5e8caffc4f1dcd5e458a4c0"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/9e8895f1b3d4433f6d78aa6578e9db61ca6e6830"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/a9394f21fba027147bf275b083c77955864c366a"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/bb72d2dda85564c66d909108ea6903937a41679d"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T12:15:12Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-wrfr-rmr8-j7gx/GHSA-wrfr-rmr8-j7gx.json b/advisories/unreviewed/2024/06/GHSA-wrfr-rmr8-j7gx/GHSA-wrfr-rmr8-j7gx.json
new file mode 100644
index 00000000000..e181c219c1c
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-wrfr-rmr8-j7gx/GHSA-wrfr-rmr8-j7gx.json
@@ -0,0 +1,51 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-wrfr-rmr8-j7gx",
+ "modified": "2024-06-20T12:31:21Z",
+ "published": "2024-06-20T12:31:21Z",
+ "aliases": [
+ "CVE-2022-48734"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix deadlock between quota disable and qgroup rescan worker\n\nQuota disable ioctl starts a transaction before waiting for the qgroup\nrescan worker completes. However, this wait can be infinite and results\nin deadlock because of circular dependency among the quota disable\nioctl, the qgroup rescan worker and the other task with transaction such\nas block group relocation task.\n\nThe deadlock happens with the steps following:\n\n1) Task A calls ioctl to disable quota. It starts a transaction and\n waits for qgroup rescan worker completes.\n2) Task B such as block group relocation task starts a transaction and\n joins to the transaction that task A started. Then task B commits to\n the transaction. In this commit, task B waits for a commit by task A.\n3) Task C as the qgroup rescan worker starts its job and starts a\n transaction. In this transaction start, task C waits for completion\n of the transaction that task A started and task B committed.\n\nThis deadlock was found with fstests test case btrfs/115 and a zoned\nnull_blk device. The test case enables and disables quota, and the\nblock group reclaim was triggered during the quota disable by chance.\nThe deadlock was also observed by running quota enable and disable in\nparallel with 'btrfs balance' command on regular null_blk devices.\n\nAn example report of the deadlock:\n\n [372.469894] INFO: task kworker/u16:6:103 blocked for more than 122 seconds.\n [372.479944] Not tainted 5.16.0-rc8 #7\n [372.485067] \"echo 0 > /proc/sys/kernel/hung_task_timeout_secs\" disables this message.\n [372.493898] task:kworker/u16:6 state:D stack: 0 pid: 103 ppid: 2 flags:0x00004000\n [372.503285] Workqueue: btrfs-qgroup-rescan btrfs_work_helper [btrfs]\n [372.510782] Call Trace:\n [372.514092] \n [372.521684] __schedule+0xb56/0x4850\n [372.530104] ? io_schedule_timeout+0x190/0x190\n [372.538842] ? lockdep_hardirqs_on+0x7e/0x100\n [372.547092] ? _raw_spin_unlock_irqrestore+0x3e/0x60\n [372.555591] schedule+0xe0/0x270\n [372.561894] btrfs_commit_transaction+0x18bb/0x2610 [btrfs]\n [372.570506] ? btrfs_apply_pending_changes+0x50/0x50 [btrfs]\n [372.578875] ? free_unref_page+0x3f2/0x650\n [372.585484] ? finish_wait+0x270/0x270\n [372.591594] ? release_extent_buffer+0x224/0x420 [btrfs]\n [372.599264] btrfs_qgroup_rescan_worker+0xc13/0x10c0 [btrfs]\n [372.607157] ? lock_release+0x3a9/0x6d0\n [372.613054] ? btrfs_qgroup_account_extent+0xda0/0xda0 [btrfs]\n [372.620960] ? do_raw_spin_lock+0x11e/0x250\n [372.627137] ? rwlock_bug.part.0+0x90/0x90\n [372.633215] ? lock_is_held_type+0xe4/0x140\n [372.639404] btrfs_work_helper+0x1ae/0xa90 [btrfs]\n [372.646268] process_one_work+0x7e9/0x1320\n [372.652321] ? lock_release+0x6d0/0x6d0\n [372.658081] ? pwq_dec_nr_in_flight+0x230/0x230\n [372.664513] ? rwlock_bug.part.0+0x90/0x90\n [372.670529] worker_thread+0x59e/0xf90\n [372.676172] ? process_one_work+0x1320/0x1320\n [372.682440] kthread+0x3b9/0x490\n [372.687550] ? _raw_spin_unlock_irq+0x24/0x50\n [372.693811] ? set_kthread_struct+0x100/0x100\n [372.700052] ret_from_fork+0x22/0x30\n [372.705517] \n [372.709747] INFO: task btrfs-transacti:2347 blocked for more than 123 seconds.\n [372.729827] Not tainted 5.16.0-rc8 #7\n [372.745907] \"echo 0 > /proc/sys/kernel/hung_task_timeout_secs\" disables this message.\n [372.767106] task:btrfs-transacti state:D stack: 0 pid: 2347 ppid: 2 flags:0x00004000\n [372.787776] Call Trace:\n [372.801652] \n [372.812961] __schedule+0xb56/0x4850\n [372.830011] ? io_schedule_timeout+0x190/0x190\n [372.852547] ? lockdep_hardirqs_on+0x7e/0x100\n [372.871761] ? _raw_spin_unlock_irqrestore+0x3e/0x60\n [372.886792] schedule+0xe0/0x270\n [372.901685] wait_current_trans+0x22c/0x310 [btrfs]\n [372.919743] ? btrfs_put_transaction+0x3d0/0x3d0 [btrfs]\n [372.938923] ? finish_wait+0x270/0x270\n [372.959085] ? join_transaction+0xc7\n---truncated---",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48734"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/26b3901d20bf9da2c6a00cb1fb48932166f80a45"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/31198e58c09e21d4f65c49d2361f76b87aca4c3f"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/32747e01436aac8ef93fe85b5b523b4f3b52f040"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/89d4cca583fc9594ee7d1a0bc986886d6fb587e6"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/e804861bd4e69cc5fe1053eedcb024982dde8e48"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T12:15:11Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-wvrm-qgrr-87qr/GHSA-wvrm-qgrr-87qr.json b/advisories/unreviewed/2024/06/GHSA-wvrm-qgrr-87qr/GHSA-wvrm-qgrr-87qr.json
new file mode 100644
index 00000000000..e5fb1a18e22
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-wvrm-qgrr-87qr/GHSA-wvrm-qgrr-87qr.json
@@ -0,0 +1,43 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-wvrm-qgrr-87qr",
+ "modified": "2024-06-20T12:31:19Z",
+ "published": "2024-06-20T12:31:19Z",
+ "aliases": [
+ "CVE-2021-47618"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nARM: 9170/1: fix panic when kasan and kprobe are enabled\n\narm32 uses software to simulate the instruction replaced\nby kprobe. some instructions may be simulated by constructing\nassembly functions. therefore, before executing instruction\nsimulation, it is necessary to construct assembly function\nexecution environment in C language through binding registers.\nafter kasan is enabled, the register binding relationship will\nbe destroyed, resulting in instruction simulation errors and\ncausing kernel panic.\n\nthe kprobe emulate instruction function is distributed in three\nfiles: actions-common.c actions-arm.c actions-thumb.c, so disable\nKASAN when compiling these files.\n\nfor example, use kprobe insert on cap_capable+20 after kasan\nenabled, the cap_capable assembly code is as follows:\n:\ne92d47f0\tpush\t{r4, r5, r6, r7, r8, r9, sl, lr}\ne1a05000\tmov\tr5, r0\ne280006c\tadd\tr0, r0, #108 ; 0x6c\ne1a04001\tmov\tr4, r1\ne1a06002\tmov\tr6, r2\ne59fa090\tldr\tsl, [pc, #144] ;\nebfc7bf8\tbl\tc03aa4b4 <__asan_load4>\ne595706c\tldr\tr7, [r5, #108] ; 0x6c\ne2859014\tadd\tr9, r5, #20\n......\nThe emulate_ldr assembly code after enabling kasan is as follows:\nc06f1384 :\ne92d47f0\tpush\t{r4, r5, r6, r7, r8, r9, sl, lr}\ne282803c\tadd\tr8, r2, #60 ; 0x3c\ne1a05000\tmov\tr5, r0\ne7e37855\tubfx\tr7, r5, #16, #4\ne1a00008\tmov\tr0, r8\ne1a09001\tmov\tr9, r1\ne1a04002\tmov\tr4, r2\nebf35462\tbl\tc03c6530 <__asan_load4>\ne357000f\tcmp\tr7, #15\ne7e36655\tubfx\tr6, r5, #12, #4\ne205a00f\tand\tsl, r5, #15\n0a000001\tbeq\tc06f13bc \ne0840107\tadd\tr0, r4, r7, lsl #2\nebf3545c\tbl\tc03c6530 <__asan_load4>\ne084010a\tadd\tr0, r4, sl, lsl #2\nebf3545a\tbl\tc03c6530 <__asan_load4>\ne2890010\tadd\tr0, r9, #16\nebf35458\tbl\tc03c6530 <__asan_load4>\ne5990010\tldr\tr0, [r9, #16]\ne12fff30\tblx\tr0\ne356000f\tcm\tr6, #15\n1a000014\tbne\tc06f1430 \ne1a06000\tmov\tr6, r0\ne2840040\tadd\tr0, r4, #64 ; 0x40\n......\n\nwhen running in emulate_ldr to simulate the ldr instruction, panic\noccurred, and the log is as follows:\nUnable to handle kernel NULL pointer dereference at virtual address\n00000090\npgd = ecb46400\n[00000090] *pgd=2e0fa003, *pmd=00000000\nInternal error: Oops: 206 [#1] SMP ARM\nPC is at cap_capable+0x14/0xb0\nLR is at emulate_ldr+0x50/0xc0\npsr: 600d0293 sp : ecd63af8 ip : 00000004 fp : c0a7c30c\nr10: 00000000 r9 : c30897f4 r8 : ecd63cd4\nr7 : 0000000f r6 : 0000000a r5 : e59fa090 r4 : ecd63c98\nr3 : c06ae294 r2 : 00000000 r1 : b7611300 r0 : bf4ec008\nFlags: nZCv IRQs off FIQs on Mode SVC_32 ISA ARM Segment user\nControl: 32c5387d Table: 2d546400 DAC: 55555555\nProcess bash (pid: 1643, stack limit = 0xecd60190)\n(cap_capable) from (kprobe_handler+0x218/0x340)\n(kprobe_handler) from (kprobe_trap_handler+0x24/0x48)\n(kprobe_trap_handler) from (do_undefinstr+0x13c/0x364)\n(do_undefinstr) from (__und_svc_finish+0x0/0x30)\n(__und_svc_finish) from (cap_capable+0x18/0xb0)\n(cap_capable) from (cap_vm_enough_memory+0x38/0x48)\n(cap_vm_enough_memory) from\n(security_vm_enough_memory_mm+0x48/0x6c)\n(security_vm_enough_memory_mm) from\n(copy_process.constprop.5+0x16b4/0x25c8)\n(copy_process.constprop.5) from (_do_fork+0xe8/0x55c)\n(_do_fork) from (SyS_clone+0x1c/0x24)\n(SyS_clone) from (__sys_trace_return+0x0/0x10)\nCode: 0050a0e1 6c0080e2 0140a0e1 0260a0e1 (f801f0e7)",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47618"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/1515e72aae803fc6b466adf918e71c4e4c9d5b3d"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/8b59b0a53c840921b625378f137e88adfa87647e"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/ba1863be105b06e10d0e2f6b1b8a0570801cfc71"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T11:15:54Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-xc27-896v-44wp/GHSA-xc27-896v-44wp.json b/advisories/unreviewed/2024/06/GHSA-xc27-896v-44wp/GHSA-xc27-896v-44wp.json
new file mode 100644
index 00000000000..f2cead7a95d
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-xc27-896v-44wp/GHSA-xc27-896v-44wp.json
@@ -0,0 +1,43 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-xc27-896v-44wp",
+ "modified": "2024-06-20T12:31:20Z",
+ "published": "2024-06-20T12:31:20Z",
+ "aliases": [
+ "CVE-2022-48725"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/siw: Fix refcounting leak in siw_create_qp()\n\nThe atomic_inc() needs to be paired with an atomic_dec() on the error\npath.",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48725"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/2989ba9532babac66e79997ccff73c015b69700c"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/a75badebfdc0b3823054bedf112edb54d6357c75"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/fa3b844a50845c817660146c27c0fc29b08d3116"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T12:15:10Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-xprq-wxmv-vch9/GHSA-xprq-wxmv-vch9.json b/advisories/unreviewed/2024/06/GHSA-xprq-wxmv-vch9/GHSA-xprq-wxmv-vch9.json
new file mode 100644
index 00000000000..85edc8fc70e
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-xprq-wxmv-vch9/GHSA-xprq-wxmv-vch9.json
@@ -0,0 +1,47 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-xprq-wxmv-vch9",
+ "modified": "2024-06-20T12:31:22Z",
+ "published": "2024-06-20T12:31:22Z",
+ "aliases": [
+ "CVE-2022-48769"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nefi: runtime: avoid EFIv2 runtime services on Apple x86 machines\n\nAditya reports [0] that his recent MacbookPro crashes in the firmware\nwhen using the variable services at runtime. The culprit appears to be a\ncall to QueryVariableInfo(), which we did not use to call on Apple x86\nmachines in the past as they only upgraded from EFI v1.10 to EFI v2.40\nfirmware fairly recently, and QueryVariableInfo() (along with\nUpdateCapsule() et al) was added in EFI v2.00.\n\nThe only runtime service introduced in EFI v2.00 that we actually use in\nLinux is QueryVariableInfo(), as the capsule based ones are optional,\ngenerally not used at runtime (all the LVFS/fwupd firmware update\ninfrastructure uses helper EFI programs that invoke capsule update at\nboot time, not runtime), and not implemented by Apple machines in the\nfirst place. QueryVariableInfo() is used to 'safely' set variables,\ni.e., only when there is enough space. This prevents machines with buggy\nfirmwares from corrupting their NVRAMs when they run out of space.\n\nGiven that Apple machines have been using EFI v1.10 services only for\nthe longest time (the EFI v2.0 spec was released in 2006, and Linux\nsupport for the newly introduced runtime services was added in 2011, but\nthe MacbookPro12,1 released in 2015 still claims to be EFI v1.10 only),\nlet's avoid the EFI v2.0 ones on all Apple x86 machines.\n\n[0] https://lore.kernel.org/all/6D757C75-65B1-468B-842D-10410081A8E4@live.com/",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48769"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/3df52448978802ae15dcebf66beba1029df957b4"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/a4085859411c825c321c9b55b8a9dc5a128a6684"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/b0f1cc093bc2493ac259c53766fd2b800e085807"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/f5390cd0b43c2e54c7cf5506c7da4a37c5cef746"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T12:15:14Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2024/06/GHSA-xwqp-6c5w-h6q9/GHSA-xwqp-6c5w-h6q9.json b/advisories/unreviewed/2024/06/GHSA-xwqp-6c5w-h6q9/GHSA-xwqp-6c5w-h6q9.json
new file mode 100644
index 00000000000..d5eec257e1c
--- /dev/null
+++ b/advisories/unreviewed/2024/06/GHSA-xwqp-6c5w-h6q9/GHSA-xwqp-6c5w-h6q9.json
@@ -0,0 +1,63 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-xwqp-6c5w-h6q9",
+ "modified": "2024-06-20T12:31:20Z",
+ "published": "2024-06-20T12:31:20Z",
+ "aliases": [
+ "CVE-2022-48711"
+ ],
+ "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: improve size validations for received domain records\n\nThe function tipc_mon_rcv() allows a node to receive and process\ndomain_record structs from peer nodes to track their views of the\nnetwork topology.\n\nThis patch verifies that the number of members in a received domain\nrecord does not exceed the limit defined by MAX_MON_DOMAIN, something\nthat may otherwise lead to a stack overflow.\n\ntipc_mon_rcv() is called from the function tipc_link_proto_rcv(), where\nwe are reading a 32 bit message data length field into a uint16. To\navert any risk of bit overflow, we add an extra sanity check for this in\nthat function. We cannot see that happen with the current code, but\nfuture designers being unaware of this risk, may introduce it by\nallowing delivery of very large (> 64k) sk buffers from the bearer\nlayer. This potential problem was identified by Eric Dumazet.\n\nThis fixes CVE-2022-0435",
+ "severity": [
+
+ ],
+ "affected": [
+
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48711"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/175db196e45d6f0e6047eccd09c8ba55465eb131"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/1f1788616157b0222b0c2153828b475d95e374a7"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/3c7e5943553594f68bbc070683db6bb6f6e9e78e"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/59ff7514f8c56f166aadca49bcecfa028e0ad50f"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/9aa422ad326634b76309e8ff342c246800621216"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/d692e3406e052dbf9f6d9da0cba36cb763272529"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/f1af11edd08dd8376f7a84487cbb0ea8203e3a1d"
+ },
+ {
+ "type": "WEB",
+ "url": "https://git.kernel.org/stable/c/fde4ddeadd099bf9fbb9ccbee8e1b5c20d530a2d"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+
+ ],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2024-06-20T11:15:54Z"
+ }
+}
\ No newline at end of file