diff --git a/advisories/github-reviewed/2024/02/GHSA-6mx3-9qfh-77gj/GHSA-6mx3-9qfh-77gj.json b/advisories/github-reviewed/2024/02/GHSA-6mx3-9qfh-77gj/GHSA-6mx3-9qfh-77gj.json index 2de77f959ca..f5b61bca30d 100644 --- a/advisories/github-reviewed/2024/02/GHSA-6mx3-9qfh-77gj/GHSA-6mx3-9qfh-77gj.json +++ b/advisories/github-reviewed/2024/02/GHSA-6mx3-9qfh-77gj/GHSA-6mx3-9qfh-77gj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6mx3-9qfh-77gj", - "modified": "2024-07-08T20:28:04Z", + "modified": "2025-01-10T18:32:25Z", "published": "2024-02-29T09:30:34Z", "aliases": [ "CVE-2024-24988" @@ -56,25 +56,6 @@ ] } ] - }, - { - "package": { - "ecosystem": "Go", - "name": "github.com/mattermost/mattermost/server/v8" - }, - "ranges": [ - { - "type": "ECOSYSTEM", - "events": [ - { - "introduced": "0" - }, - { - "fixed": "8.1.9" - } - ] - } - ] } ], "references": [ diff --git a/advisories/github-reviewed/2024/02/GHSA-7v3v-984v-h74r/GHSA-7v3v-984v-h74r.json b/advisories/github-reviewed/2024/02/GHSA-7v3v-984v-h74r/GHSA-7v3v-984v-h74r.json index 712886cd30c..4ab5494b9bd 100644 --- a/advisories/github-reviewed/2024/02/GHSA-7v3v-984v-h74r/GHSA-7v3v-984v-h74r.json +++ b/advisories/github-reviewed/2024/02/GHSA-7v3v-984v-h74r/GHSA-7v3v-984v-h74r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7v3v-984v-h74r", - "modified": "2024-07-08T20:26:46Z", + "modified": "2025-01-10T18:32:12Z", "published": "2024-02-29T09:30:34Z", "aliases": [ "CVE-2024-23493" @@ -75,25 +75,6 @@ ] } ] - }, - { - "package": { - "ecosystem": "Go", - "name": "github.com/mattermost/mattermost/server/v8" - }, - "ranges": [ - { - "type": "ECOSYSTEM", - "events": [ - { - "introduced": "0" - }, - { - "fixed": "8.1.9" - } - ] - } - ] } ], "references": [ @@ -112,7 +93,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-862" ], "severity": "MODERATE", "github_reviewed": true, diff --git a/advisories/unreviewed/2023/06/GHSA-3q42-qm7m-gp8c/GHSA-3q42-qm7m-gp8c.json b/advisories/unreviewed/2023/06/GHSA-3q42-qm7m-gp8c/GHSA-3q42-qm7m-gp8c.json index 2660d174e1d..85e31ee2cbf 100644 --- a/advisories/unreviewed/2023/06/GHSA-3q42-qm7m-gp8c/GHSA-3q42-qm7m-gp8c.json +++ b/advisories/unreviewed/2023/06/GHSA-3q42-qm7m-gp8c/GHSA-3q42-qm7m-gp8c.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-1021" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-3r46-584r-xx8v/GHSA-3r46-584r-xx8v.json b/advisories/unreviewed/2023/06/GHSA-3r46-584r-xx8v/GHSA-3r46-584r-xx8v.json index 932acbcde5d..20f50f89967 100644 --- a/advisories/unreviewed/2023/06/GHSA-3r46-584r-xx8v/GHSA-3r46-584r-xx8v.json +++ b/advisories/unreviewed/2023/06/GHSA-3r46-584r-xx8v/GHSA-3r46-584r-xx8v.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-770" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-5997-5448-jfqf/GHSA-5997-5448-jfqf.json b/advisories/unreviewed/2023/06/GHSA-5997-5448-jfqf/GHSA-5997-5448-jfqf.json index 07b7ec1cb30..83402a49414 100644 --- a/advisories/unreviewed/2023/06/GHSA-5997-5448-jfqf/GHSA-5997-5448-jfqf.json +++ b/advisories/unreviewed/2023/06/GHSA-5997-5448-jfqf/GHSA-5997-5448-jfqf.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-5pj8-c4h5-h95p/GHSA-5pj8-c4h5-h95p.json b/advisories/unreviewed/2023/06/GHSA-5pj8-c4h5-h95p/GHSA-5pj8-c4h5-h95p.json index 778b9080c54..29f29733358 100644 --- a/advisories/unreviewed/2023/06/GHSA-5pj8-c4h5-h95p/GHSA-5pj8-c4h5-h95p.json +++ b/advisories/unreviewed/2023/06/GHSA-5pj8-c4h5-h95p/GHSA-5pj8-c4h5-h95p.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-203" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-v7qx-gcjm-59m5/GHSA-v7qx-gcjm-59m5.json b/advisories/unreviewed/2023/06/GHSA-v7qx-gcjm-59m5/GHSA-v7qx-gcjm-59m5.json index 5df63466980..d5bfa1291bf 100644 --- a/advisories/unreviewed/2023/06/GHSA-v7qx-gcjm-59m5/GHSA-v7qx-gcjm-59m5.json +++ b/advisories/unreviewed/2023/06/GHSA-v7qx-gcjm-59m5/GHSA-v7qx-gcjm-59m5.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-1284" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-vhjv-4vf6-mc9x/GHSA-vhjv-4vf6-mc9x.json b/advisories/unreviewed/2023/06/GHSA-vhjv-4vf6-mc9x/GHSA-vhjv-4vf6-mc9x.json index c7918916efb..998a2ad9c9d 100644 --- a/advisories/unreviewed/2023/06/GHSA-vhjv-4vf6-mc9x/GHSA-vhjv-4vf6-mc9x.json +++ b/advisories/unreviewed/2023/06/GHSA-vhjv-4vf6-mc9x/GHSA-vhjv-4vf6-mc9x.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/07/GHSA-gqg8-5m8q-4j2q/GHSA-gqg8-5m8q-4j2q.json b/advisories/unreviewed/2023/07/GHSA-gqg8-5m8q-4j2q/GHSA-gqg8-5m8q-4j2q.json index 56ec7f1c3b2..d14a9411624 100644 --- a/advisories/unreviewed/2023/07/GHSA-gqg8-5m8q-4j2q/GHSA-gqg8-5m8q-4j2q.json +++ b/advisories/unreviewed/2023/07/GHSA-gqg8-5m8q-4j2q/GHSA-gqg8-5m8q-4j2q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gqg8-5m8q-4j2q", - "modified": "2024-04-04T05:47:47Z", + "modified": "2025-01-10T18:31:30Z", "published": "2023-07-06T21:15:06Z", "aliases": [ "CVE-2023-33509" diff --git a/advisories/unreviewed/2023/07/GHSA-rmp7-8h7w-9h3x/GHSA-rmp7-8h7w-9h3x.json b/advisories/unreviewed/2023/07/GHSA-rmp7-8h7w-9h3x/GHSA-rmp7-8h7w-9h3x.json index 36f79dc61ff..2363c1c4b26 100644 --- a/advisories/unreviewed/2023/07/GHSA-rmp7-8h7w-9h3x/GHSA-rmp7-8h7w-9h3x.json +++ b/advisories/unreviewed/2023/07/GHSA-rmp7-8h7w-9h3x/GHSA-rmp7-8h7w-9h3x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rmp7-8h7w-9h3x", - "modified": "2024-04-04T05:47:54Z", + "modified": "2025-01-10T18:31:30Z", "published": "2023-07-06T21:15:06Z", "aliases": [ "CVE-2023-33508" diff --git a/advisories/unreviewed/2024/02/GHSA-f7hm-xqp4-h2q8/GHSA-f7hm-xqp4-h2q8.json b/advisories/unreviewed/2024/02/GHSA-f7hm-xqp4-h2q8/GHSA-f7hm-xqp4-h2q8.json index 93a84241f72..83761978abc 100644 --- a/advisories/unreviewed/2024/02/GHSA-f7hm-xqp4-h2q8/GHSA-f7hm-xqp4-h2q8.json +++ b/advisories/unreviewed/2024/02/GHSA-f7hm-xqp4-h2q8/GHSA-f7hm-xqp4-h2q8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-f7hm-xqp4-h2q8", - "modified": "2024-02-29T06:30:32Z", + "modified": "2025-01-10T18:31:32Z", "published": "2024-02-29T06:30:32Z", "aliases": [ "CVE-2023-52478" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: logitech-hidpp: Fix kernel crash on receiver USB disconnect\n\nhidpp_connect_event() has *four* time-of-check vs time-of-use (TOCTOU)\nraces when it races with itself.\n\nhidpp_connect_event() primarily runs from a workqueue but it also runs\non probe() and if a \"device-connected\" packet is received by the hw\nwhen the thread running hidpp_connect_event() from probe() is waiting on\nthe hw, then a second thread running hidpp_connect_event() will be\nstarted from the workqueue.\n\nThis opens the following races (note the below code is simplified):\n\n1. Retrieving + printing the protocol (harmless race):\n\n\tif (!hidpp->protocol_major) {\n\t\thidpp_root_get_protocol_version()\n\t\thidpp->protocol_major = response.rap.params[0];\n\t}\n\nWe can actually see this race hit in the dmesg in the abrt output\nattached to rhbz#2227968:\n\n[ 3064.624215] logitech-hidpp-device 0003:046D:4071.0049: HID++ 4.5 device connected.\n[ 3064.658184] logitech-hidpp-device 0003:046D:4071.0049: HID++ 4.5 device connected.\n\nTesting with extra logging added has shown that after this the 2 threads\ntake turn grabbing the hw access mutex (send_mutex) so they ping-pong\nthrough all the other TOCTOU cases managing to hit all of them:\n\n2. Updating the name to the HIDPP name (harmless race):\n\n\tif (hidpp->name == hdev->name) {\n\t\t...\n\t\thidpp->name = new_name;\n\t}\n\n3. Initializing the power_supply class for the battery (problematic!):\n\nhidpp_initialize_battery()\n{\n if (hidpp->battery.ps)\n return 0;\n\n\tprobe_battery(); /* Blocks, threads take turns executing this */\n\n\thidpp->battery.desc.properties =\n\t\tdevm_kmemdup(dev, hidpp_battery_props, cnt, GFP_KERNEL);\n\n\thidpp->battery.ps =\n\t\tdevm_power_supply_register(&hidpp->hid_dev->dev,\n\t\t\t\t\t &hidpp->battery.desc, cfg);\n}\n\n4. Creating delayed input_device (potentially problematic):\n\n\tif (hidpp->delayed_input)\n\t\treturn;\n\n\thidpp->delayed_input = hidpp_allocate_input(hdev);\n\nThe really big problem here is 3. Hitting the race leads to the following\nsequence:\n\n\thidpp->battery.desc.properties =\n\t\tdevm_kmemdup(dev, hidpp_battery_props, cnt, GFP_KERNEL);\n\n\thidpp->battery.ps =\n\t\tdevm_power_supply_register(&hidpp->hid_dev->dev,\n\t\t\t\t\t &hidpp->battery.desc, cfg);\n\n\t...\n\n\thidpp->battery.desc.properties =\n\t\tdevm_kmemdup(dev, hidpp_battery_props, cnt, GFP_KERNEL);\n\n\thidpp->battery.ps =\n\t\tdevm_power_supply_register(&hidpp->hid_dev->dev,\n\t\t\t\t\t &hidpp->battery.desc, cfg);\n\nSo now we have registered 2 power supplies for the same battery,\nwhich looks a bit weird from userspace's pov but this is not even\nthe really big problem.\n\nNotice how:\n\n1. This is all devm-maganaged\n2. The hidpp->battery.desc struct is shared between the 2 power supplies\n3. hidpp->battery.desc.properties points to the result from the second\n devm_kmemdup()\n\nThis causes a use after free scenario on USB disconnect of the receiver:\n1. The last registered power supply class device gets unregistered\n2. The memory from the last devm_kmemdup() call gets freed,\n hidpp->battery.desc.properties now points to freed memory\n3. The first registered power supply class device gets unregistered,\n this involves sending a remove uevent to userspace which invokes\n power_supply_uevent() to fill the uevent data\n4. power_supply_uevent() uses hidpp->battery.desc.properties which\n now points to freed memory leading to backtraces like this one:\n\nSep 22 20:01:35 eric kernel: BUG: unable to handle page fault for address: ffffb2140e017f08\n...\nSep 22 20:01:35 eric kernel: Workqueue: usb_hub_wq hub_event\nSep 22 20:01:35 eric kernel: RIP: 0010:power_supply_uevent+0xee/0x1d0\n...\nSep 22 20:01:35 eric kernel: ? asm_exc_page_fault+0x26/0x30\nSep 22 20:01:35 eric kernel: ? power_supply_uevent+0xee/0x1d0\nSep 22 20:01:35 eric kernel: ? power_supply_uevent+0x10d/0x1d0\nSep 22 20:01:35 eric kernel: dev_uevent+0x10f/0x2d0\nSep 22 20:01:35 eric kernel: kobject_uevent_env+0x291/0x680\nSep 22 20:01:35 eric kernel: \n---truncated---", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-367" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-29T06:15:45Z" diff --git a/advisories/unreviewed/2024/02/GHSA-h958-4cw7-rqgr/GHSA-h958-4cw7-rqgr.json b/advisories/unreviewed/2024/02/GHSA-h958-4cw7-rqgr/GHSA-h958-4cw7-rqgr.json index f70de50dda4..2a139f931aa 100644 --- a/advisories/unreviewed/2024/02/GHSA-h958-4cw7-rqgr/GHSA-h958-4cw7-rqgr.json +++ b/advisories/unreviewed/2024/02/GHSA-h958-4cw7-rqgr/GHSA-h958-4cw7-rqgr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h958-4cw7-rqgr", - "modified": "2024-02-28T09:30:38Z", + "modified": "2025-01-10T18:31:31Z", "published": "2024-02-28T09:30:38Z", "aliases": [ "CVE-2021-47036" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nudp: skip L4 aggregation for UDP tunnel packets\n\nIf NETIF_F_GRO_FRAGLIST or NETIF_F_GRO_UDP_FWD are enabled, and there\nare UDP tunnels available in the system, udp_gro_receive() could end-up\ndoing L4 aggregation (either SKB_GSO_UDP_L4 or SKB_GSO_FRAGLIST) at\nthe outer UDP tunnel level for packets effectively carrying and UDP\ntunnel header.\n\nThat could cause inner protocol corruption. If e.g. the relevant\npackets carry a vxlan header, different vxlan ids will be ignored/\naggregated to the same GSO packet. Inner headers will be ignored, too,\nso that e.g. TCP over vxlan push packets will be held in the GRO\nengine till the next flush, etc.\n\nJust skip the SKB_GSO_UDP_L4 and SKB_GSO_FRAGLIST code path if the\ncurrent packet could land in a UDP tunnel, and let udp_gro_receive()\ndo GRO via udp_sk(sk)->gro_receive.\n\nThe check implemented in this patch is broader than what is strictly\nneeded, as the existing UDP tunnel could be e.g. configured on top of\na different device: we could end-up skipping GRO at-all for some packets.\n\nAnyhow, that is a very thin corner case and covering it will add quite\na bit of complexity.\n\nv1 -> v2:\n - hopefully clarify the commit message", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -25,7 +30,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-28T09:15:39Z" diff --git a/advisories/unreviewed/2024/02/GHSA-m8jx-hpg8-g7ww/GHSA-m8jx-hpg8-g7ww.json b/advisories/unreviewed/2024/02/GHSA-m8jx-hpg8-g7ww/GHSA-m8jx-hpg8-g7ww.json index d94f2f0bc63..eaad74324eb 100644 --- a/advisories/unreviewed/2024/02/GHSA-m8jx-hpg8-g7ww/GHSA-m8jx-hpg8-g7ww.json +++ b/advisories/unreviewed/2024/02/GHSA-m8jx-hpg8-g7ww/GHSA-m8jx-hpg8-g7ww.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-m8jx-hpg8-g7ww", - "modified": "2024-02-28T09:30:38Z", + "modified": "2025-01-10T18:31:31Z", "published": "2024-02-28T09:30:38Z", "aliases": [ "CVE-2021-47027" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmt76: mt7921: fix kernel crash when the firmware fails to download\n\nFix kernel crash when the firmware is missing or fails to download.\n\n[ 9.444758] kernel BUG at drivers/pci/msi.c:375!\n[ 9.449363] Internal error: Oops - BUG: 0 [#1] PREEMPT SMP\n[ 9.501033] pstate: a0400009 (NzCv daif +PAN -UAO)\n[ 9.505814] pc : free_msi_irqs+0x180/0x184\n[ 9.509897] lr : free_msi_irqs+0x40/0x184\n[ 9.513893] sp : ffffffc015193870\n[ 9.517194] x29: ffffffc015193870 x28: 00000000f0e94fa2\n[ 9.522492] x27: 0000000000000acd x26: 000000000000009a\n[ 9.527790] x25: ffffffc0152cee58 x24: ffffffdbb383e0d8\n[ 9.533087] x23: ffffffdbb38628d0 x22: 0000000000040200\n[ 9.538384] x21: ffffff8cf7de7318 x20: ffffff8cd65a2480\n[ 9.543681] x19: ffffff8cf7de7000 x18: 0000000000000000\n[ 9.548979] x17: ffffff8cf9ca03b4 x16: ffffffdc13ad9a34\n[ 9.554277] x15: 0000000000000000 x14: 0000000000080800\n[ 9.559575] x13: ffffff8cd65a2980 x12: 0000000000000000\n[ 9.564873] x11: ffffff8cfa45d820 x10: ffffff8cfa45d6d0\n[ 9.570171] x9 : 0000000000000040 x8 : ffffff8ccef1b780\n[ 9.575469] x7 : aaaaaaaaaaaaaaaa x6 : 0000000000000000\n[ 9.580766] x5 : ffffffdc13824900 x4 : ffffff8ccefe0000\n[ 9.586063] x3 : 0000000000000000 x2 : 0000000000000000\n[ 9.591362] x1 : 0000000000000125 x0 : ffffff8ccefe0000\n[ 9.596660] Call trace:\n[ 9.599095] free_msi_irqs+0x180/0x184\n[ 9.602831] pci_disable_msi+0x100/0x130\n[ 9.606740] pci_free_irq_vectors+0x24/0x30\n[ 9.610915] mt7921_pci_probe+0xbc/0x250 [mt7921e]\n[ 9.615693] pci_device_probe+0xd4/0x14c\n[ 9.619604] really_probe+0x134/0x2ec\n[ 9.623252] driver_probe_device+0x64/0xfc\n[ 9.627335] device_driver_attach+0x4c/0x6c\n[ 9.631506] __driver_attach+0xac/0xc0\n[ 9.635243] bus_for_each_dev+0x8c/0xd4\n[ 9.639066] driver_attach+0x2c/0x38\n[ 9.642628] bus_add_driver+0xfc/0x1d0\n[ 9.646365] driver_register+0x64/0xf8\n[ 9.650101] __pci_register_driver+0x6c/0x7c\n[ 9.654360] init_module+0x28/0xfdc [mt7921e]\n[ 9.658704] do_one_initcall+0x13c/0x2d0\n[ 9.662615] do_init_module+0x58/0x1e8\n[ 9.666351] load_module+0xd80/0xeb4\n[ 9.669912] __arm64_sys_finit_module+0xa8/0xe0\n[ 9.674430] el0_svc_common+0xa4/0x16c\n[ 9.678168] el0_svc_compat_handler+0x2c/0x40\n[ 9.682511] el0_svc_compat+0x8/0x10\n[ 9.686076] Code: a94257f6 f9400bf7 a8c47bfd d65f03c0 (d4210000)\n[ 9.692155] ---[ end trace 7621f966afbf0a29 ]---\n[ 9.697385] Kernel panic - not syncing: Fatal exception\n[ 9.702599] SMP: stopping secondary CPUs\n[ 9.706549] Kernel Offset: 0x1c03600000 from 0xffffffc010000000\n[ 9.712456] PHYS_OFFSET: 0xfffffff440000000\n[ 9.716625] CPU features: 0x080026,2a80aa18\n[ 9.720795] Memory Limit: none", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -25,7 +30,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-28T09:15:39Z" diff --git a/advisories/unreviewed/2024/02/GHSA-p6q6-7q65-mgx6/GHSA-p6q6-7q65-mgx6.json b/advisories/unreviewed/2024/02/GHSA-p6q6-7q65-mgx6/GHSA-p6q6-7q65-mgx6.json index 4c7ae67c80d..d2431553781 100644 --- a/advisories/unreviewed/2024/02/GHSA-p6q6-7q65-mgx6/GHSA-p6q6-7q65-mgx6.json +++ b/advisories/unreviewed/2024/02/GHSA-p6q6-7q65-mgx6/GHSA-p6q6-7q65-mgx6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p6q6-7q65-mgx6", - "modified": "2024-02-29T06:30:32Z", + "modified": "2025-01-10T18:31:32Z", "published": "2024-02-29T06:30:32Z", "aliases": [ "CVE-2023-52476" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nperf/x86/lbr: Filter vsyscall addresses\n\nWe found that a panic can occur when a vsyscall is made while LBR sampling\nis active. If the vsyscall is interrupted (NMI) for perf sampling, this\ncall sequence can occur (most recent at top):\n\n __insn_get_emulate_prefix()\n insn_get_emulate_prefix()\n insn_get_prefixes()\n insn_get_opcode()\n decode_branch_type()\n get_branch_type()\n intel_pmu_lbr_filter()\n intel_pmu_handle_irq()\n perf_event_nmi_handler()\n\nWithin __insn_get_emulate_prefix() at frame 0, a macro is called:\n\n peek_nbyte_next(insn_byte_t, insn, i)\n\nWithin this macro, this dereference occurs:\n\n (insn)->next_byte\n\nInspecting registers at this point, the value of the next_byte field is the\naddress of the vsyscall made, for example the location of the vsyscall\nversion of gettimeofday() at 0xffffffffff600000. The access to an address\nin the vsyscall region will trigger an oops due to an unhandled page fault.\n\nTo fix the bug, filtering for vsyscalls can be done when\ndetermining the branch type. This patch will return\na \"none\" branch if a kernel address if found to lie in the\nvsyscall region.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -33,7 +38,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-29T06:15:45Z" diff --git a/advisories/unreviewed/2024/02/GHSA-w9w6-r588-cpmx/GHSA-w9w6-r588-cpmx.json b/advisories/unreviewed/2024/02/GHSA-w9w6-r588-cpmx/GHSA-w9w6-r588-cpmx.json index bfafe0df603..a9cafba0c5f 100644 --- a/advisories/unreviewed/2024/02/GHSA-w9w6-r588-cpmx/GHSA-w9w6-r588-cpmx.json +++ b/advisories/unreviewed/2024/02/GHSA-w9w6-r588-cpmx/GHSA-w9w6-r588-cpmx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-w9w6-r588-cpmx", - "modified": "2024-02-28T09:30:36Z", + "modified": "2025-01-10T18:31:31Z", "published": "2024-02-28T09:30:36Z", "aliases": [ "CVE-2021-46976" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/i915: Fix crash in auto_retire\n\nThe retire logic uses the 2 lower bits of the pointer to the retire\nfunction to store flags. However, the auto_retire function is not\nguaranteed to be aligned to a multiple of 4, which causes crashes as\nwe jump to the wrong address, for example like this:\n\n2021-04-24T18:03:53.804300Z WARNING kernel: [ 516.876901] invalid opcode: 0000 [#1] PREEMPT SMP NOPTI\n2021-04-24T18:03:53.804310Z WARNING kernel: [ 516.876906] CPU: 7 PID: 146 Comm: kworker/u16:6 Tainted: G U 5.4.105-13595-g3cd84167b2df #1\n2021-04-24T18:03:53.804311Z WARNING kernel: [ 516.876907] Hardware name: Google Volteer2/Volteer2, BIOS Google_Volteer2.13672.76.0 02/22/2021\n2021-04-24T18:03:53.804312Z WARNING kernel: [ 516.876911] Workqueue: events_unbound active_work\n2021-04-24T18:03:53.804313Z WARNING kernel: [ 516.876914] RIP: 0010:auto_retire+0x1/0x20\n2021-04-24T18:03:53.804314Z WARNING kernel: [ 516.876916] Code: e8 01 f2 ff ff eb 02 31 db 48 89 d8 5b 5d c3 0f 1f 44 00 00 55 48 89 e5 f0 ff 87 c8 00 00 00 0f 88 ab 47 4a 00 31 c0 5d c3 0f <1f> 44 00 00 55 48 89 e5 f0 ff 8f c8 00 00 00 0f 88 9a 47 4a 00 74\n2021-04-24T18:03:53.804319Z WARNING kernel: [ 516.876918] RSP: 0018:ffff9b4d809fbe38 EFLAGS: 00010286\n2021-04-24T18:03:53.804320Z WARNING kernel: [ 516.876919] RAX: 0000000000000007 RBX: ffff927915079600 RCX: 0000000000000007\n2021-04-24T18:03:53.804320Z WARNING kernel: [ 516.876921] RDX: ffff9b4d809fbe40 RSI: 0000000000000286 RDI: ffff927915079600\n2021-04-24T18:03:53.804321Z WARNING kernel: [ 516.876922] RBP: ffff9b4d809fbe68 R08: 8080808080808080 R09: fefefefefefefeff\n2021-04-24T18:03:53.804321Z WARNING kernel: [ 516.876924] R10: 0000000000000010 R11: ffffffff92e44bd8 R12: ffff9279150796a0\n2021-04-24T18:03:53.804322Z WARNING kernel: [ 516.876925] R13: ffff92791c368180 R14: ffff927915079640 R15: 000000001c867605\n2021-04-24T18:03:53.804323Z WARNING kernel: [ 516.876926] FS: 0000000000000000(0000) GS:ffff92791ffc0000(0000) knlGS:0000000000000000\n2021-04-24T18:03:53.804323Z WARNING kernel: [ 516.876928] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n2021-04-24T18:03:53.804324Z WARNING kernel: [ 516.876929] CR2: 0000239514955000 CR3: 00000007f82da001 CR4: 0000000000760ee0\n2021-04-24T18:03:53.804325Z WARNING kernel: [ 516.876930] PKRU: 55555554\n2021-04-24T18:03:53.804325Z WARNING kernel: [ 516.876931] Call Trace:\n2021-04-24T18:03:53.804326Z WARNING kernel: [ 516.876935] __active_retire+0x77/0xcf\n2021-04-24T18:03:53.804326Z WARNING kernel: [ 516.876939] process_one_work+0x1da/0x394\n2021-04-24T18:03:53.804327Z WARNING kernel: [ 516.876941] worker_thread+0x216/0x375\n2021-04-24T18:03:53.804327Z WARNING kernel: [ 516.876944] kthread+0x147/0x156\n2021-04-24T18:03:53.804335Z WARNING kernel: [ 516.876946] ? pr_cont_work+0x58/0x58\n2021-04-24T18:03:53.804335Z WARNING kernel: [ 516.876948] ? kthread_blkcg+0x2e/0x2e\n2021-04-24T18:03:53.804336Z WARNING kernel: [ 516.876950] ret_from_fork+0x1f/0x40\n2021-04-24T18:03:53.804336Z WARNING kernel: [ 516.876952] Modules linked in: cdc_mbim cdc_ncm cdc_wdm xt_cgroup rfcomm cmac algif_hash algif_skcipher af_alg xt_MASQUERADE uinput snd_soc_rt5682_sdw snd_soc_rt5682 snd_soc_max98373_sdw snd_soc_max98373 snd_soc_rl6231 regmap_sdw snd_soc_sof_sdw snd_soc_hdac_hdmi snd_soc_dmic snd_hda_codec_hdmi snd_sof_pci snd_sof_intel_hda_common intel_ipu6_psys snd_sof_xtensa_dsp soundwire_intel soundwire_generic_allocation soundwire_cadence snd_sof_intel_hda snd_sof snd_soc_hdac_hda snd_soc_acpi_intel_match snd_soc_acpi snd_hda_ext_core soundwire_bus snd_hda_intel snd_intel_dspcfg snd_hda_codec snd_hwdep snd_hda_core intel_ipu6_isys videobuf2_dma_contig videobuf2_v4l2 videobuf2_common videobuf2_memops mei_hdcp intel_ipu6 ov2740 ov8856 at24 sx9310 dw9768 v4l2_fwnode cros_ec_typec intel_pmc_mux roles acpi_als typec fuse iio_trig_sysfs cros_ec_light_prox cros_ec_lid_angle cros_ec_sensors cros\n---truncated---", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -33,7 +38,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-28T09:15:37Z" diff --git a/advisories/unreviewed/2024/02/GHSA-xppg-r7h5-74wm/GHSA-xppg-r7h5-74wm.json b/advisories/unreviewed/2024/02/GHSA-xppg-r7h5-74wm/GHSA-xppg-r7h5-74wm.json index 43a89647566..a962db62c27 100644 --- a/advisories/unreviewed/2024/02/GHSA-xppg-r7h5-74wm/GHSA-xppg-r7h5-74wm.json +++ b/advisories/unreviewed/2024/02/GHSA-xppg-r7h5-74wm/GHSA-xppg-r7h5-74wm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xppg-r7h5-74wm", - "modified": "2024-02-28T09:30:38Z", + "modified": "2025-01-10T18:31:31Z", "published": "2024-02-28T09:30:38Z", "aliases": [ "CVE-2021-47047" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nspi: spi-zynqmp-gqspi: return -ENOMEM if dma_map_single fails\n\nThe spi controller supports 44-bit address space on AXI in DMA mode,\nso set dma_addr_t width to 44-bit to avoid using a swiotlb mapping.\nIn addition, if dma_map_single fails, it should return immediately\ninstead of continuing doing the DMA operation which bases on invalid\naddress.\n\nThis fixes the following crash which occurs in reading a big block\nfrom flash:\n\n[ 123.633577] zynqmp-qspi ff0f0000.spi: swiotlb buffer is full (sz: 4194304 bytes), total 32768 (slots), used 0 (slots)\n[ 123.644230] zynqmp-qspi ff0f0000.spi: ERR:rxdma:memory not mapped\n[ 123.784625] Unable to handle kernel paging request at virtual address 00000000003fffc0\n[ 123.792536] Mem abort info:\n[ 123.795313] ESR = 0x96000145\n[ 123.798351] EC = 0x25: DABT (current EL), IL = 32 bits\n[ 123.803655] SET = 0, FnV = 0\n[ 123.806693] EA = 0, S1PTW = 0\n[ 123.809818] Data abort info:\n[ 123.812683] ISV = 0, ISS = 0x00000145\n[ 123.816503] CM = 1, WnR = 1\n[ 123.819455] user pgtable: 4k pages, 48-bit VAs, pgdp=0000000805047000\n[ 123.825887] [00000000003fffc0] pgd=0000000803b45003, p4d=0000000803b45003, pud=0000000000000000\n[ 123.834586] Internal error: Oops: 96000145 [#1] PREEMPT SMP", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -33,7 +38,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-28T09:15:40Z" diff --git a/advisories/unreviewed/2024/03/GHSA-6299-m9xc-vxvj/GHSA-6299-m9xc-vxvj.json b/advisories/unreviewed/2024/03/GHSA-6299-m9xc-vxvj/GHSA-6299-m9xc-vxvj.json index 13d86da38ad..646245948fb 100644 --- a/advisories/unreviewed/2024/03/GHSA-6299-m9xc-vxvj/GHSA-6299-m9xc-vxvj.json +++ b/advisories/unreviewed/2024/03/GHSA-6299-m9xc-vxvj/GHSA-6299-m9xc-vxvj.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-120" + "CWE-120", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-9fv2-j4fg-6v4w/GHSA-9fv2-j4fg-6v4w.json b/advisories/unreviewed/2024/03/GHSA-9fv2-j4fg-6v4w/GHSA-9fv2-j4fg-6v4w.json index 0d06b63f20c..3bbb5be75a9 100644 --- a/advisories/unreviewed/2024/03/GHSA-9fv2-j4fg-6v4w/GHSA-9fv2-j4fg-6v4w.json +++ b/advisories/unreviewed/2024/03/GHSA-9fv2-j4fg-6v4w/GHSA-9fv2-j4fg-6v4w.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-787" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-j5r8-f5xj-3h83/GHSA-j5r8-f5xj-3h83.json b/advisories/unreviewed/2024/03/GHSA-j5r8-f5xj-3h83/GHSA-j5r8-f5xj-3h83.json index 465c574cdcf..2a093271577 100644 --- a/advisories/unreviewed/2024/03/GHSA-j5r8-f5xj-3h83/GHSA-j5r8-f5xj-3h83.json +++ b/advisories/unreviewed/2024/03/GHSA-j5r8-f5xj-3h83/GHSA-j5r8-f5xj-3h83.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-126" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/03/GHSA-r456-h7vj-7pm5/GHSA-r456-h7vj-7pm5.json b/advisories/unreviewed/2024/03/GHSA-r456-h7vj-7pm5/GHSA-r456-h7vj-7pm5.json index 772626e7f0c..0f5ac88b7a7 100644 --- a/advisories/unreviewed/2024/03/GHSA-r456-h7vj-7pm5/GHSA-r456-h7vj-7pm5.json +++ b/advisories/unreviewed/2024/03/GHSA-r456-h7vj-7pm5/GHSA-r456-h7vj-7pm5.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-126" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/03/GHSA-v532-947m-m96r/GHSA-v532-947m-m96r.json b/advisories/unreviewed/2024/03/GHSA-v532-947m-m96r/GHSA-v532-947m-m96r.json index fc90dfb0b93..3e65bc43b75 100644 --- a/advisories/unreviewed/2024/03/GHSA-v532-947m-m96r/GHSA-v532-947m-m96r.json +++ b/advisories/unreviewed/2024/03/GHSA-v532-947m-m96r/GHSA-v532-947m-m96r.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-120" + "CWE-120", + "CWE-787" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-xcr6-9x44-6hpq/GHSA-xcr6-9x44-6hpq.json b/advisories/unreviewed/2024/03/GHSA-xcr6-9x44-6hpq/GHSA-xcr6-9x44-6hpq.json index 9a89c64323a..aa60d969931 100644 --- a/advisories/unreviewed/2024/03/GHSA-xcr6-9x44-6hpq/GHSA-xcr6-9x44-6hpq.json +++ b/advisories/unreviewed/2024/03/GHSA-xcr6-9x44-6hpq/GHSA-xcr6-9x44-6hpq.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-787", "CWE-823" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/03/GHSA-xjcp-9jxf-mc93/GHSA-xjcp-9jxf-mc93.json b/advisories/unreviewed/2024/03/GHSA-xjcp-9jxf-mc93/GHSA-xjcp-9jxf-mc93.json index e1deb67f801..63173657c59 100644 --- a/advisories/unreviewed/2024/03/GHSA-xjcp-9jxf-mc93/GHSA-xjcp-9jxf-mc93.json +++ b/advisories/unreviewed/2024/03/GHSA-xjcp-9jxf-mc93/GHSA-xjcp-9jxf-mc93.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-126" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/04/GHSA-4gqc-44f8-fcvg/GHSA-4gqc-44f8-fcvg.json b/advisories/unreviewed/2024/04/GHSA-4gqc-44f8-fcvg/GHSA-4gqc-44f8-fcvg.json index 0dc2ad82518..06c65372843 100644 --- a/advisories/unreviewed/2024/04/GHSA-4gqc-44f8-fcvg/GHSA-4gqc-44f8-fcvg.json +++ b/advisories/unreviewed/2024/04/GHSA-4gqc-44f8-fcvg/GHSA-4gqc-44f8-fcvg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4gqc-44f8-fcvg", - "modified": "2025-01-09T18:32:10Z", + "modified": "2025-01-10T18:31:37Z", "published": "2024-04-17T12:32:04Z", "aliases": [ "CVE-2024-26873" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: hisi_sas: Fix a deadlock issue related to automatic dump\n\nIf we issue a disabling PHY command, the device attached with it will go\noffline, if a 2 bit ECC error occurs at the same time, a hung task may be\nfound:\n\n[ 4613.652388] INFO: task kworker/u256:0:165233 blocked for more than 120 seconds.\n[ 4613.666297] \"echo 0 > /proc/sys/kernel/hung_task_timeout_secs\" disables this message.\n[ 4613.674809] task:kworker/u256:0 state:D stack: 0 pid:165233 ppid: 2 flags:0x00000208\n[ 4613.683959] Workqueue: 0000:74:02.0_disco_q sas_revalidate_domain [libsas]\n[ 4613.691518] Call trace:\n[ 4613.694678] __switch_to+0xf8/0x17c\n[ 4613.698872] __schedule+0x660/0xee0\n[ 4613.703063] schedule+0xac/0x240\n[ 4613.706994] schedule_timeout+0x500/0x610\n[ 4613.711705] __down+0x128/0x36c\n[ 4613.715548] down+0x240/0x2d0\n[ 4613.719221] hisi_sas_internal_abort_timeout+0x1bc/0x260 [hisi_sas_main]\n[ 4613.726618] sas_execute_internal_abort+0x144/0x310 [libsas]\n[ 4613.732976] sas_execute_internal_abort_dev+0x44/0x60 [libsas]\n[ 4613.739504] hisi_sas_internal_task_abort_dev.isra.0+0xbc/0x1b0 [hisi_sas_main]\n[ 4613.747499] hisi_sas_dev_gone+0x174/0x250 [hisi_sas_main]\n[ 4613.753682] sas_notify_lldd_dev_gone+0xec/0x2e0 [libsas]\n[ 4613.759781] sas_unregister_common_dev+0x4c/0x7a0 [libsas]\n[ 4613.765962] sas_destruct_devices+0xb8/0x120 [libsas]\n[ 4613.771709] sas_do_revalidate_domain.constprop.0+0x1b8/0x31c [libsas]\n[ 4613.778930] sas_revalidate_domain+0x60/0xa4 [libsas]\n[ 4613.784716] process_one_work+0x248/0x950\n[ 4613.789424] worker_thread+0x318/0x934\n[ 4613.793878] kthread+0x190/0x200\n[ 4613.797810] ret_from_fork+0x10/0x18\n[ 4613.802121] INFO: task kworker/u256:4:316722 blocked for more than 120 seconds.\n[ 4613.816026] \"echo 0 > /proc/sys/kernel/hung_task_timeout_secs\" disables this message.\n[ 4613.824538] task:kworker/u256:4 state:D stack: 0 pid:316722 ppid: 2 flags:0x00000208\n[ 4613.833670] Workqueue: 0000:74:02.0 hisi_sas_rst_work_handler [hisi_sas_main]\n[ 4613.841491] Call trace:\n[ 4613.844647] __switch_to+0xf8/0x17c\n[ 4613.848852] __schedule+0x660/0xee0\n[ 4613.853052] schedule+0xac/0x240\n[ 4613.856984] schedule_timeout+0x500/0x610\n[ 4613.861695] __down+0x128/0x36c\n[ 4613.865542] down+0x240/0x2d0\n[ 4613.869216] hisi_sas_controller_prereset+0x58/0x1fc [hisi_sas_main]\n[ 4613.876324] hisi_sas_rst_work_handler+0x40/0x8c [hisi_sas_main]\n[ 4613.883019] process_one_work+0x248/0x950\n[ 4613.887732] worker_thread+0x318/0x934\n[ 4613.892204] kthread+0x190/0x200\n[ 4613.896118] ret_from_fork+0x10/0x18\n[ 4613.900423] INFO: task kworker/u256:1:348985 blocked for more than 121 seconds.\n[ 4613.914341] \"echo 0 > /proc/sys/kernel/hung_task_timeout_secs\" disables this message.\n[ 4613.922852] task:kworker/u256:1 state:D stack: 0 pid:348985 ppid: 2 flags:0x00000208\n[ 4613.931984] Workqueue: 0000:74:02.0_event_q sas_port_event_worker [libsas]\n[ 4613.939549] Call trace:\n[ 4613.942702] __switch_to+0xf8/0x17c\n[ 4613.946892] __schedule+0x660/0xee0\n[ 4613.951083] schedule+0xac/0x240\n[ 4613.955015] schedule_timeout+0x500/0x610\n[ 4613.959725] wait_for_common+0x200/0x610\n[ 4613.964349] wait_for_completion+0x3c/0x5c\n[ 4613.969146] flush_workqueue+0x198/0x790\n[ 4613.973776] sas_porte_broadcast_rcvd+0x1e8/0x320 [libsas]\n[ 4613.979960] sas_port_event_worker+0x54/0xa0 [libsas]\n[ 4613.985708] process_one_work+0x248/0x950\n[ 4613.990420] worker_thread+0x318/0x934\n[ 4613.994868] kthread+0x190/0x200\n[ 4613.998800] ret_from_fork+0x10/0x18\n\nThis is because when the device goes offline, we obtain the hisi_hba\nsemaphore and send the ABORT_DEV command to the device. However, the\ninternal abort timed out due to the 2 bit ECC error and triggers automatic\ndump. In addition, since the hisi_hba semaphore has been obtained, the dump\ncannot be executed and the controller cannot be reset.\n\nTherefore, the deadlocks occur on the following circular dependencies\n---truncated---", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-667" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T11:15:09Z" diff --git a/advisories/unreviewed/2024/04/GHSA-fp6w-hx4c-x44g/GHSA-fp6w-hx4c-x44g.json b/advisories/unreviewed/2024/04/GHSA-fp6w-hx4c-x44g/GHSA-fp6w-hx4c-x44g.json index dd31ff5fcfe..39272c54e4f 100644 --- a/advisories/unreviewed/2024/04/GHSA-fp6w-hx4c-x44g/GHSA-fp6w-hx4c-x44g.json +++ b/advisories/unreviewed/2024/04/GHSA-fp6w-hx4c-x44g/GHSA-fp6w-hx4c-x44g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fp6w-hx4c-x44g", - "modified": "2024-06-26T00:31:36Z", + "modified": "2025-01-10T18:31:37Z", "published": "2024-04-04T09:30:35Z", "aliases": [ "CVE-2024-26782" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: fix double-free on socket dismantle\n\nwhen MPTCP server accepts an incoming connection, it clones its listener\nsocket. However, the pointer to 'inet_opt' for the new socket has the same\nvalue as the original one: as a consequence, on program exit it's possible\nto observe the following splat:\n\n BUG: KASAN: double-free in inet_sock_destruct+0x54f/0x8b0\n Free of addr ffff888485950880 by task swapper/25/0\n\n CPU: 25 PID: 0 Comm: swapper/25 Kdump: loaded Not tainted 6.8.0-rc1+ #609\n Hardware name: Supermicro SYS-6027R-72RF/X9DRH-7TF/7F/iTF/iF, BIOS 3.0 07/26/2013\n Call Trace:\n \n dump_stack_lvl+0x32/0x50\n print_report+0xca/0x620\n kasan_report_invalid_free+0x64/0x90\n __kasan_slab_free+0x1aa/0x1f0\n kfree+0xed/0x2e0\n inet_sock_destruct+0x54f/0x8b0\n __sk_destruct+0x48/0x5b0\n rcu_do_batch+0x34e/0xd90\n rcu_core+0x559/0xac0\n __do_softirq+0x183/0x5a4\n irq_exit_rcu+0x12d/0x170\n sysvec_apic_timer_interrupt+0x6b/0x80\n \n \n asm_sysvec_apic_timer_interrupt+0x16/0x20\n RIP: 0010:cpuidle_enter_state+0x175/0x300\n Code: 30 00 0f 84 1f 01 00 00 83 e8 01 83 f8 ff 75 e5 48 83 c4 18 44 89 e8 5b 5d 41 5c 41 5d 41 5e 41 5f c3 cc cc cc cc fb 45 85 ed <0f> 89 60 ff ff ff 48 c1 e5 06 48 c7 43 18 00 00 00 00 48 83 44 2b\n RSP: 0018:ffff888481cf7d90 EFLAGS: 00000202\n RAX: 0000000000000000 RBX: ffff88887facddc8 RCX: 0000000000000000\n RDX: 1ffff1110ff588b1 RSI: 0000000000000019 RDI: ffff88887fac4588\n RBP: 0000000000000004 R08: 0000000000000002 R09: 0000000000043080\n R10: 0009b02ea273363f R11: ffff88887fabf42b R12: ffffffff932592e0\n R13: 0000000000000004 R14: 0000000000000000 R15: 00000022c880ec80\n cpuidle_enter+0x4a/0xa0\n do_idle+0x310/0x410\n cpu_startup_entry+0x51/0x60\n start_secondary+0x211/0x270\n secondary_startup_64_no_verify+0x184/0x18b\n \n\n Allocated by task 6853:\n kasan_save_stack+0x1c/0x40\n kasan_save_track+0x10/0x30\n __kasan_kmalloc+0xa6/0xb0\n __kmalloc+0x1eb/0x450\n cipso_v4_sock_setattr+0x96/0x360\n netlbl_sock_setattr+0x132/0x1f0\n selinux_netlbl_socket_post_create+0x6c/0x110\n selinux_socket_post_create+0x37b/0x7f0\n security_socket_post_create+0x63/0xb0\n __sock_create+0x305/0x450\n __sys_socket_create.part.23+0xbd/0x130\n __sys_socket+0x37/0xb0\n __x64_sys_socket+0x6f/0xb0\n do_syscall_64+0x83/0x160\n entry_SYSCALL_64_after_hwframe+0x6e/0x76\n\n Freed by task 6858:\n kasan_save_stack+0x1c/0x40\n kasan_save_track+0x10/0x30\n kasan_save_free_info+0x3b/0x60\n __kasan_slab_free+0x12c/0x1f0\n kfree+0xed/0x2e0\n inet_sock_destruct+0x54f/0x8b0\n __sk_destruct+0x48/0x5b0\n subflow_ulp_release+0x1f0/0x250\n tcp_cleanup_ulp+0x6e/0x110\n tcp_v4_destroy_sock+0x5a/0x3a0\n inet_csk_destroy_sock+0x135/0x390\n tcp_fin+0x416/0x5c0\n tcp_data_queue+0x1bc8/0x4310\n tcp_rcv_state_process+0x15a3/0x47b0\n tcp_v4_do_rcv+0x2c1/0x990\n tcp_v4_rcv+0x41fb/0x5ed0\n ip_protocol_deliver_rcu+0x6d/0x9f0\n ip_local_deliver_finish+0x278/0x360\n ip_local_deliver+0x182/0x2c0\n ip_rcv+0xb5/0x1c0\n __netif_receive_skb_one_core+0x16e/0x1b0\n process_backlog+0x1e3/0x650\n __napi_poll+0xa6/0x500\n net_rx_action+0x740/0xbb0\n __do_softirq+0x183/0x5a4\n\n The buggy address belongs to the object at ffff888485950880\n which belongs to the cache kmalloc-64 of size 64\n The buggy address is located 0 bytes inside of\n 64-byte region [ffff888485950880, ffff8884859508c0)\n\n The buggy address belongs to the physical page:\n page:0000000056d1e95e refcount:1 mapcount:0 mapping:0000000000000000 index:0xffff888485950700 pfn:0x485950\n flags: 0x57ffffc0000800(slab|node=1|zone=2|lastcpupid=0x1fffff)\n page_type: 0xffffffff()\n raw: 0057ffffc0000800 ffff88810004c640 ffffea00121b8ac0 dead000000000006\n raw: ffff888485950700 0000000000200019 00000001ffffffff 0000000000000000\n page dumped because: kasan: bad access detected\n\n Memory state around the buggy address:\n ffff888485950780: fa fb fb\n---truncated---", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-415" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-04T09:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-mcvj-6jjv-7hw9/GHSA-mcvj-6jjv-7hw9.json b/advisories/unreviewed/2024/04/GHSA-mcvj-6jjv-7hw9/GHSA-mcvj-6jjv-7hw9.json index 276cade4800..1e3c8edb325 100644 --- a/advisories/unreviewed/2024/04/GHSA-mcvj-6jjv-7hw9/GHSA-mcvj-6jjv-7hw9.json +++ b/advisories/unreviewed/2024/04/GHSA-mcvj-6jjv-7hw9/GHSA-mcvj-6jjv-7hw9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mcvj-6jjv-7hw9", - "modified": "2024-04-28T15:30:30Z", + "modified": "2025-01-10T18:31:37Z", "published": "2024-04-28T15:30:29Z", "aliases": [ "CVE-2022-48649" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/slab_common: fix possible double free of kmem_cache\n\nWhen doing slub_debug test, kfence's 'test_memcache_typesafe_by_rcu'\nkunit test case cause a use-after-free error:\n\n BUG: KASAN: use-after-free in kobject_del+0x14/0x30\n Read of size 8 at addr ffff888007679090 by task kunit_try_catch/261\n\n CPU: 1 PID: 261 Comm: kunit_try_catch Tainted: G B N 6.0.0-rc5-next-20220916 #17\n Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014\n Call Trace:\n \n dump_stack_lvl+0x34/0x48\n print_address_description.constprop.0+0x87/0x2a5\n print_report+0x103/0x1ed\n kasan_report+0xb7/0x140\n kobject_del+0x14/0x30\n kmem_cache_destroy+0x130/0x170\n test_exit+0x1a/0x30\n kunit_try_run_case+0xad/0xc0\n kunit_generic_run_threadfn_adapter+0x26/0x50\n kthread+0x17b/0x1b0\n \n\nThe cause is inside kmem_cache_destroy():\n\nkmem_cache_destroy\n acquire lock/mutex\n shutdown_cache\n schedule_work(kmem_cache_release) (if RCU flag set)\n release lock/mutex\n kmem_cache_release (if RCU flag not set)\n\nIn some certain timing, the scheduled work could be run before\nthe next RCU flag checking, which can then get a wrong value\nand lead to double kmem_cache_release().\n\nFix it by caching the RCU flag inside protected area, just like 'refcnt'", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-415" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-28T13:15:07Z" diff --git a/advisories/unreviewed/2024/05/GHSA-3c4m-3xhw-2cr2/GHSA-3c4m-3xhw-2cr2.json b/advisories/unreviewed/2024/05/GHSA-3c4m-3xhw-2cr2/GHSA-3c4m-3xhw-2cr2.json index 5cfde943a2a..94e77ab165f 100644 --- a/advisories/unreviewed/2024/05/GHSA-3c4m-3xhw-2cr2/GHSA-3c4m-3xhw-2cr2.json +++ b/advisories/unreviewed/2024/05/GHSA-3c4m-3xhw-2cr2/GHSA-3c4m-3xhw-2cr2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3c4m-3xhw-2cr2", - "modified": "2024-06-27T15:30:39Z", + "modified": "2025-01-10T18:31:37Z", "published": "2024-05-17T15:31:11Z", "aliases": [ "CVE-2023-52691" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/pm: fix a double-free in si_dpm_init\n\nWhen the allocation of\nadev->pm.dpm.dyn_state.vddc_dependency_on_dispclk.entries fails,\namdgpu_free_extended_power_table is called to free some fields of adev.\nHowever, when the control flow returns to si_dpm_sw_init, it goes to\nlabel dpm_failed and calls si_dpm_fini, which calls\namdgpu_free_extended_power_table again and free those fields again. Thus\na double-free is triggered.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -56,8 +61,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-415" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-17T15:15:20Z" diff --git a/advisories/unreviewed/2024/05/GHSA-3pg2-q6q7-9rmm/GHSA-3pg2-q6q7-9rmm.json b/advisories/unreviewed/2024/05/GHSA-3pg2-q6q7-9rmm/GHSA-3pg2-q6q7-9rmm.json index 7896c17cb6d..10dbc276089 100644 --- a/advisories/unreviewed/2024/05/GHSA-3pg2-q6q7-9rmm/GHSA-3pg2-q6q7-9rmm.json +++ b/advisories/unreviewed/2024/05/GHSA-3pg2-q6q7-9rmm/GHSA-3pg2-q6q7-9rmm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3pg2-q6q7-9rmm", - "modified": "2024-05-22T09:31:44Z", + "modified": "2025-01-10T18:31:38Z", "published": "2024-05-22T09:31:44Z", "aliases": [ "CVE-2021-47437" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\niio: adis16475: fix deadlock on frequency set\n\nWith commit 39c024b51b560\n(\"iio: adis16475: improve sync scale mode handling\"), two deadlocks were\nintroduced:\n 1) The call to 'adis_write_reg_16()' was not changed to it's unlocked\n version.\n 2) The lock was not being released on the success path of the function.\n\nThis change fixes both these issues.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-667" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-22T07:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-5jrf-78p7-hw2r/GHSA-5jrf-78p7-hw2r.json b/advisories/unreviewed/2024/05/GHSA-5jrf-78p7-hw2r/GHSA-5jrf-78p7-hw2r.json index 2f5c470d930..d4e73f4dbc5 100644 --- a/advisories/unreviewed/2024/05/GHSA-5jrf-78p7-hw2r/GHSA-5jrf-78p7-hw2r.json +++ b/advisories/unreviewed/2024/05/GHSA-5jrf-78p7-hw2r/GHSA-5jrf-78p7-hw2r.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5jrf-78p7-hw2r", - "modified": "2024-05-21T18:31:22Z", + "modified": "2025-01-10T18:31:38Z", "published": "2024-05-21T18:31:22Z", "aliases": [ "CVE-2023-52851" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nIB/mlx5: Fix init stage error handling to avoid double free of same QP and UAF\n\nIn the unlikely event that workqueue allocation fails and returns NULL in\nmlx5_mkey_cache_init(), delete the call to\nmlx5r_umr_resource_cleanup() (which frees the QP) in\nmlx5_ib_stage_post_ib_reg_umr_init(). This will avoid attempted double\nfree of the same QP when __mlx5_ib_add() does its cleanup.\n\nResolves a splat:\n\n Syzkaller reported a UAF in ib_destroy_qp_user\n\n workqueue: Failed to create a rescuer kthread for wq \"mkey_cache\": -EINTR\n infiniband mlx5_0: mlx5_mkey_cache_init:981:(pid 1642):\n failed to create work queue\n infiniband mlx5_0: mlx5_ib_stage_post_ib_reg_umr_init:4075:(pid 1642):\n mr cache init failed -12\n ==================================================================\n BUG: KASAN: slab-use-after-free in ib_destroy_qp_user (drivers/infiniband/core/verbs.c:2073)\n Read of size 8 at addr ffff88810da310a8 by task repro_upstream/1642\n\n Call Trace:\n \n kasan_report (mm/kasan/report.c:590)\n ib_destroy_qp_user (drivers/infiniband/core/verbs.c:2073)\n mlx5r_umr_resource_cleanup (drivers/infiniband/hw/mlx5/umr.c:198)\n __mlx5_ib_add (drivers/infiniband/hw/mlx5/main.c:4178)\n mlx5r_probe (drivers/infiniband/hw/mlx5/main.c:4402)\n ...\n \n\n Allocated by task 1642:\n __kmalloc (./include/linux/kasan.h:198 mm/slab_common.c:1026\n mm/slab_common.c:1039)\n create_qp (./include/linux/slab.h:603 ./include/linux/slab.h:720\n ./include/rdma/ib_verbs.h:2795 drivers/infiniband/core/verbs.c:1209)\n ib_create_qp_kernel (drivers/infiniband/core/verbs.c:1347)\n mlx5r_umr_resource_init (drivers/infiniband/hw/mlx5/umr.c:164)\n mlx5_ib_stage_post_ib_reg_umr_init (drivers/infiniband/hw/mlx5/main.c:4070)\n __mlx5_ib_add (drivers/infiniband/hw/mlx5/main.c:4168)\n mlx5r_probe (drivers/infiniband/hw/mlx5/main.c:4402)\n ...\n\n Freed by task 1642:\n __kmem_cache_free (mm/slub.c:1826 mm/slub.c:3809 mm/slub.c:3822)\n ib_destroy_qp_user (drivers/infiniband/core/verbs.c:2112)\n mlx5r_umr_resource_cleanup (drivers/infiniband/hw/mlx5/umr.c:198)\n mlx5_ib_stage_post_ib_reg_umr_init (drivers/infiniband/hw/mlx5/main.c:4076\n drivers/infiniband/hw/mlx5/main.c:4065)\n __mlx5_ib_add (drivers/infiniband/hw/mlx5/main.c:4168)\n mlx5r_probe (drivers/infiniband/hw/mlx5/main.c:4402)\n ...", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-415" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T16:15:22Z" diff --git a/advisories/unreviewed/2024/05/GHSA-76g6-5v2w-pw2h/GHSA-76g6-5v2w-pw2h.json b/advisories/unreviewed/2024/05/GHSA-76g6-5v2w-pw2h/GHSA-76g6-5v2w-pw2h.json index b22c92e1917..f7bd16d3388 100644 --- a/advisories/unreviewed/2024/05/GHSA-76g6-5v2w-pw2h/GHSA-76g6-5v2w-pw2h.json +++ b/advisories/unreviewed/2024/05/GHSA-76g6-5v2w-pw2h/GHSA-76g6-5v2w-pw2h.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-76g6-5v2w-pw2h", - "modified": "2024-05-21T18:31:21Z", + "modified": "2025-01-10T18:31:37Z", "published": "2024-05-21T18:31:21Z", "aliases": [ "CVE-2023-52795" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nvhost-vdpa: fix use after free in vhost_vdpa_probe()\n\nThe put_device() calls vhost_vdpa_release_dev() which calls\nida_simple_remove() and frees \"v\". So this call to\nida_simple_remove() is a use after free and a double free.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-415" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T16:15:18Z" diff --git a/advisories/unreviewed/2024/05/GHSA-7rpw-5262-46cf/GHSA-7rpw-5262-46cf.json b/advisories/unreviewed/2024/05/GHSA-7rpw-5262-46cf/GHSA-7rpw-5262-46cf.json index e1cb85940c8..ba724087fac 100644 --- a/advisories/unreviewed/2024/05/GHSA-7rpw-5262-46cf/GHSA-7rpw-5262-46cf.json +++ b/advisories/unreviewed/2024/05/GHSA-7rpw-5262-46cf/GHSA-7rpw-5262-46cf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7rpw-5262-46cf", - "modified": "2024-05-20T12:30:27Z", + "modified": "2025-01-10T18:31:37Z", "published": "2024-05-20T12:30:27Z", "aliases": [ "CVE-2024-35953" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\naccel/ivpu: Fix deadlock in context_xa\n\nivpu_device->context_xa is locked both in kernel thread and IRQ context.\nIt requires XA_FLAGS_LOCK_IRQ flag to be passed during initialization\notherwise the lock could be acquired from a thread and interrupted by\nan IRQ that locks it for the second time causing the deadlock.\n\nThis deadlock was reported by lockdep and observed in internal tests.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-667" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-20T10:15:10Z" diff --git a/advisories/unreviewed/2024/05/GHSA-7xf4-2cch-q53v/GHSA-7xf4-2cch-q53v.json b/advisories/unreviewed/2024/05/GHSA-7xf4-2cch-q53v/GHSA-7xf4-2cch-q53v.json index e3c07520b4a..ad2e39c2ae5 100644 --- a/advisories/unreviewed/2024/05/GHSA-7xf4-2cch-q53v/GHSA-7xf4-2cch-q53v.json +++ b/advisories/unreviewed/2024/05/GHSA-7xf4-2cch-q53v/GHSA-7xf4-2cch-q53v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7xf4-2cch-q53v", - "modified": "2024-05-17T15:31:09Z", + "modified": "2025-01-10T18:31:37Z", "published": "2024-05-17T15:31:09Z", "aliases": [ "CVE-2023-52667" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: fix a potential double-free in fs_any_create_groups\n\nWhen kcalloc() for ft->g succeeds but kvzalloc() for in fails,\nfs_any_create_groups() will free ft->g. However, its caller\nfs_any_create_table() will free ft->g again through calling\nmlx5e_destroy_flow_table(), which will lead to a double-free.\nFix this by setting ft->g to NULL in fs_any_create_groups().", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-415" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-17T14:15:09Z" diff --git a/advisories/unreviewed/2024/05/GHSA-8wqr-cpqw-79wq/GHSA-8wqr-cpqw-79wq.json b/advisories/unreviewed/2024/05/GHSA-8wqr-cpqw-79wq/GHSA-8wqr-cpqw-79wq.json index 8703a7c22ab..3e5b0865efb 100644 --- a/advisories/unreviewed/2024/05/GHSA-8wqr-cpqw-79wq/GHSA-8wqr-cpqw-79wq.json +++ b/advisories/unreviewed/2024/05/GHSA-8wqr-cpqw-79wq/GHSA-8wqr-cpqw-79wq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8wqr-cpqw-79wq", - "modified": "2024-06-27T12:30:46Z", + "modified": "2025-01-10T18:31:37Z", "published": "2024-05-17T15:31:11Z", "aliases": [ "CVE-2023-52679" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nof: Fix double free in of_parse_phandle_with_args_map\n\nIn of_parse_phandle_with_args_map() the inner loop that\niterates through the map entries calls of_node_put(new)\nto free the reference acquired by the previous iteration\nof the inner loop. This assumes that the value of \"new\" is\nNULL on the first iteration of the inner loop.\n\nMake sure that this is true in all iterations of the outer\nloop by setting \"new\" to NULL after its value is assigned to \"cur\".\n\nExtend the unittest to detect the double free and add an additional\ntest case that actually triggers this path.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -56,8 +61,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-415" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-17T15:15:19Z" diff --git a/advisories/unreviewed/2024/05/GHSA-99mj-3x29-5mm3/GHSA-99mj-3x29-5mm3.json b/advisories/unreviewed/2024/05/GHSA-99mj-3x29-5mm3/GHSA-99mj-3x29-5mm3.json index 91c109282e7..259f573d4f9 100644 --- a/advisories/unreviewed/2024/05/GHSA-99mj-3x29-5mm3/GHSA-99mj-3x29-5mm3.json +++ b/advisories/unreviewed/2024/05/GHSA-99mj-3x29-5mm3/GHSA-99mj-3x29-5mm3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-99mj-3x29-5mm3", - "modified": "2024-05-17T15:31:09Z", + "modified": "2025-01-10T18:31:37Z", "published": "2024-05-17T15:31:09Z", "aliases": [ "CVE-2024-35795" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: fix deadlock while reading mqd from debugfs\n\nAn errant disk backup on my desktop got into debugfs and triggered the\nfollowing deadlock scenario in the amdgpu debugfs files. The machine\nalso hard-resets immediately after those lines are printed (although I\nwasn't able to reproduce that part when reading by hand):\n\n[ 1318.016074][ T1082] ======================================================\n[ 1318.016607][ T1082] WARNING: possible circular locking dependency detected\n[ 1318.017107][ T1082] 6.8.0-rc7-00015-ge0c8221b72c0 #17 Not tainted\n[ 1318.017598][ T1082] ------------------------------------------------------\n[ 1318.018096][ T1082] tar/1082 is trying to acquire lock:\n[ 1318.018585][ T1082] ffff98c44175d6a0 (&mm->mmap_lock){++++}-{3:3}, at: __might_fault+0x40/0x80\n[ 1318.019084][ T1082]\n[ 1318.019084][ T1082] but task is already holding lock:\n[ 1318.020052][ T1082] ffff98c4c13f55f8 (reservation_ww_class_mutex){+.+.}-{3:3}, at: amdgpu_debugfs_mqd_read+0x6a/0x250 [amdgpu]\n[ 1318.020607][ T1082]\n[ 1318.020607][ T1082] which lock already depends on the new lock.\n[ 1318.020607][ T1082]\n[ 1318.022081][ T1082]\n[ 1318.022081][ T1082] the existing dependency chain (in reverse order) is:\n[ 1318.023083][ T1082]\n[ 1318.023083][ T1082] -> #2 (reservation_ww_class_mutex){+.+.}-{3:3}:\n[ 1318.024114][ T1082] __ww_mutex_lock.constprop.0+0xe0/0x12f0\n[ 1318.024639][ T1082] ww_mutex_lock+0x32/0x90\n[ 1318.025161][ T1082] dma_resv_lockdep+0x18a/0x330\n[ 1318.025683][ T1082] do_one_initcall+0x6a/0x350\n[ 1318.026210][ T1082] kernel_init_freeable+0x1a3/0x310\n[ 1318.026728][ T1082] kernel_init+0x15/0x1a0\n[ 1318.027242][ T1082] ret_from_fork+0x2c/0x40\n[ 1318.027759][ T1082] ret_from_fork_asm+0x11/0x20\n[ 1318.028281][ T1082]\n[ 1318.028281][ T1082] -> #1 (reservation_ww_class_acquire){+.+.}-{0:0}:\n[ 1318.029297][ T1082] dma_resv_lockdep+0x16c/0x330\n[ 1318.029790][ T1082] do_one_initcall+0x6a/0x350\n[ 1318.030263][ T1082] kernel_init_freeable+0x1a3/0x310\n[ 1318.030722][ T1082] kernel_init+0x15/0x1a0\n[ 1318.031168][ T1082] ret_from_fork+0x2c/0x40\n[ 1318.031598][ T1082] ret_from_fork_asm+0x11/0x20\n[ 1318.032011][ T1082]\n[ 1318.032011][ T1082] -> #0 (&mm->mmap_lock){++++}-{3:3}:\n[ 1318.032778][ T1082] __lock_acquire+0x14bf/0x2680\n[ 1318.033141][ T1082] lock_acquire+0xcd/0x2c0\n[ 1318.033487][ T1082] __might_fault+0x58/0x80\n[ 1318.033814][ T1082] amdgpu_debugfs_mqd_read+0x103/0x250 [amdgpu]\n[ 1318.034181][ T1082] full_proxy_read+0x55/0x80\n[ 1318.034487][ T1082] vfs_read+0xa7/0x360\n[ 1318.034788][ T1082] ksys_read+0x70/0xf0\n[ 1318.035085][ T1082] do_syscall_64+0x94/0x180\n[ 1318.035375][ T1082] entry_SYSCALL_64_after_hwframe+0x46/0x4e\n[ 1318.035664][ T1082]\n[ 1318.035664][ T1082] other info that might help us debug this:\n[ 1318.035664][ T1082]\n[ 1318.036487][ T1082] Chain exists of:\n[ 1318.036487][ T1082] &mm->mmap_lock --> reservation_ww_class_acquire --> reservation_ww_class_mutex\n[ 1318.036487][ T1082]\n[ 1318.037310][ T1082] Possible unsafe locking scenario:\n[ 1318.037310][ T1082]\n[ 1318.037838][ T1082] CPU0 CPU1\n[ 1318.038101][ T1082] ---- ----\n[ 1318.038350][ T1082] lock(reservation_ww_class_mutex);\n[ 1318.038590][ T1082] lock(reservation_ww_class_acquire);\n[ 1318.038839][ T1082] lock(reservation_ww_class_mutex);\n[ 1318.039083][ T1082] rlock(&mm->mmap_lock);\n[ 1318.039328][ T1082]\n[ 1318.039328][ T1082] *** DEADLOCK ***\n[ 1318.039328][ T1082]\n[ 1318.040029][ T1082] 1 lock held by tar/1082:\n[ 1318.040259][ T1082] #0: ffff98c4c13f55f8 (reservation_ww_class_mutex){+.+.}-{3:3}, at: amdgpu_debugfs_mqd_read+0x6a/0x250 [amdgpu]\n[ 1318.040560][ T1082]\n[ 1318.040560][ T1082] stack backtrace:\n[\n---truncated---", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-667" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-17T14:15:11Z" diff --git a/advisories/unreviewed/2024/05/GHSA-c4cj-x9mv-wwgx/GHSA-c4cj-x9mv-wwgx.json b/advisories/unreviewed/2024/05/GHSA-c4cj-x9mv-wwgx/GHSA-c4cj-x9mv-wwgx.json index 13295d45103..aee8359a777 100644 --- a/advisories/unreviewed/2024/05/GHSA-c4cj-x9mv-wwgx/GHSA-c4cj-x9mv-wwgx.json +++ b/advisories/unreviewed/2024/05/GHSA-c4cj-x9mv-wwgx/GHSA-c4cj-x9mv-wwgx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c4cj-x9mv-wwgx", - "modified": "2024-05-20T12:30:30Z", + "modified": "2025-01-10T18:31:37Z", "published": "2024-05-20T12:30:30Z", "aliases": [ "CVE-2024-35998" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb3: fix lock ordering potential deadlock in cifs_sync_mid_result\n\nCoverity spotted that the cifs_sync_mid_result function could deadlock\n\n\"Thread deadlock (ORDER_REVERSAL) lock_order: Calling spin_lock acquires\nlock TCP_Server_Info.srv_lock while holding lock TCP_Server_Info.mid_lock\"\n\nAddresses-Coverity: 1590401 (\"Thread deadlock (ORDER_REVERSAL)\")", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-667" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-20T10:15:14Z" diff --git a/advisories/unreviewed/2024/05/GHSA-cwwg-93gv-4r7h/GHSA-cwwg-93gv-4r7h.json b/advisories/unreviewed/2024/05/GHSA-cwwg-93gv-4r7h/GHSA-cwwg-93gv-4r7h.json index 7e5ca4334ef..34bb4e859cf 100644 --- a/advisories/unreviewed/2024/05/GHSA-cwwg-93gv-4r7h/GHSA-cwwg-93gv-4r7h.json +++ b/advisories/unreviewed/2024/05/GHSA-cwwg-93gv-4r7h/GHSA-cwwg-93gv-4r7h.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cwwg-93gv-4r7h", - "modified": "2024-06-27T12:30:45Z", + "modified": "2025-01-10T18:31:37Z", "published": "2024-05-17T15:31:09Z", "aliases": [ "CVE-2024-35806" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsoc: fsl: qbman: Always disable interrupts when taking cgr_lock\n\nsmp_call_function_single disables IRQs when executing the callback. To\nprevent deadlocks, we must disable IRQs when taking cgr_lock elsewhere.\nThis is already done by qman_update_cgr and qman_delete_cgr; fix the\nother lockers.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -60,8 +65,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-667" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-17T14:15:14Z" diff --git a/advisories/unreviewed/2024/05/GHSA-hg9c-4q92-whw7/GHSA-hg9c-4q92-whw7.json b/advisories/unreviewed/2024/05/GHSA-hg9c-4q92-whw7/GHSA-hg9c-4q92-whw7.json index f73bdec669b..25338e652ae 100644 --- a/advisories/unreviewed/2024/05/GHSA-hg9c-4q92-whw7/GHSA-hg9c-4q92-whw7.json +++ b/advisories/unreviewed/2024/05/GHSA-hg9c-4q92-whw7/GHSA-hg9c-4q92-whw7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hg9c-4q92-whw7", - "modified": "2024-05-17T15:31:08Z", + "modified": "2025-01-10T18:31:37Z", "published": "2024-05-17T15:31:08Z", "aliases": [ "CVE-2024-35784" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix deadlock with fiemap and extent locking\n\nWhile working on the patchset to remove extent locking I got a lockdep\nsplat with fiemap and pagefaulting with my new extent lock replacement\nlock.\n\nThis deadlock exists with our normal code, we just don't have lockdep\nannotations with the extent locking so we've never noticed it.\n\nSince we're copying the fiemap extent to user space on every iteration\nwe have the chance of pagefaulting. Because we hold the extent lock for\nthe entire range we could mkwrite into a range in the file that we have\nmmap'ed. This would deadlock with the following stack trace\n\n[<0>] lock_extent+0x28d/0x2f0\n[<0>] btrfs_page_mkwrite+0x273/0x8a0\n[<0>] do_page_mkwrite+0x50/0xb0\n[<0>] do_fault+0xc1/0x7b0\n[<0>] __handle_mm_fault+0x2fa/0x460\n[<0>] handle_mm_fault+0xa4/0x330\n[<0>] do_user_addr_fault+0x1f4/0x800\n[<0>] exc_page_fault+0x7c/0x1e0\n[<0>] asm_exc_page_fault+0x26/0x30\n[<0>] rep_movs_alternative+0x33/0x70\n[<0>] _copy_to_user+0x49/0x70\n[<0>] fiemap_fill_next_extent+0xc8/0x120\n[<0>] emit_fiemap_extent+0x4d/0xa0\n[<0>] extent_fiemap+0x7f8/0xad0\n[<0>] btrfs_fiemap+0x49/0x80\n[<0>] __x64_sys_ioctl+0x3e1/0xb50\n[<0>] do_syscall_64+0x94/0x1a0\n[<0>] entry_SYSCALL_64_after_hwframe+0x6e/0x76\n\nI wrote an fstest to reproduce this deadlock without my replacement lock\nand verified that the deadlock exists with our existing locking.\n\nTo fix this simply don't take the extent lock for the entire duration of\nthe fiemap. This is safe in general because we keep track of where we\nare when we're searching the tree, so if an ordered extent updates in\nthe middle of our fiemap call we'll still emit the correct extents\nbecause we know what offset we were on before.\n\nThe only place we maintain the lock is searching delalloc. Since the\ndelalloc stuff can change during writeback we want to lock the extent\nrange so we have a consistent view of delalloc at the time we're\nchecking to see if we need to set the delalloc flag.\n\nWith this patch applied we no longer deadlock with my testcase.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-667" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-17T13:15:58Z" diff --git a/advisories/unreviewed/2024/05/GHSA-hx2r-xg86-xj35/GHSA-hx2r-xg86-xj35.json b/advisories/unreviewed/2024/05/GHSA-hx2r-xg86-xj35/GHSA-hx2r-xg86-xj35.json index f4abdd8d18e..a5cbfd6c9f1 100644 --- a/advisories/unreviewed/2024/05/GHSA-hx2r-xg86-xj35/GHSA-hx2r-xg86-xj35.json +++ b/advisories/unreviewed/2024/05/GHSA-hx2r-xg86-xj35/GHSA-hx2r-xg86-xj35.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hx2r-xg86-xj35", - "modified": "2024-11-17T15:30:44Z", + "modified": "2025-01-10T18:31:37Z", "published": "2024-05-22T09:31:45Z", "aliases": [ "CVE-2021-47469" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nspi: Fix deadlock when adding SPI controllers on SPI buses\n\nCurrently we have a global spi_add_lock which we take when adding new\ndevices so that we can check that we're not trying to reuse a chip\nselect that's already controlled. This means that if the SPI device is\nitself a SPI controller and triggers the instantiation of further SPI\ndevices we trigger a deadlock as we try to register and instantiate\nthose devices while in the process of doing so for the parent controller\nand hence already holding the global spi_add_lock. Since we only care\nabout concurrency within a single SPI bus move the lock to be per\ncontroller, avoiding the deadlock.\n\nThis can be easily triggered in the case of spi-mux.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-667" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-22T07:15:11Z" diff --git a/advisories/unreviewed/2024/05/GHSA-w36h-73v6-wg8q/GHSA-w36h-73v6-wg8q.json b/advisories/unreviewed/2024/05/GHSA-w36h-73v6-wg8q/GHSA-w36h-73v6-wg8q.json index 25b2489dc5c..1d7e38825f3 100644 --- a/advisories/unreviewed/2024/05/GHSA-w36h-73v6-wg8q/GHSA-w36h-73v6-wg8q.json +++ b/advisories/unreviewed/2024/05/GHSA-w36h-73v6-wg8q/GHSA-w36h-73v6-wg8q.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-w36h-73v6-wg8q", - "modified": "2024-05-17T15:31:08Z", + "modified": "2025-01-10T18:31:37Z", "published": "2024-05-17T15:31:08Z", "aliases": [ "CVE-2024-35786" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/nouveau: fix stale locked mutex in nouveau_gem_ioctl_pushbuf\n\nIf VM_BIND is enabled on the client the legacy submission ioctl can't be\nused, however if a client tries to do so regardless it will return an\nerror. In this case the clients mutex remained unlocked leading to a\ndeadlock inside nouveau_drm_postclose or any other nouveau ioctl call.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-667" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-17T13:15:58Z" diff --git a/advisories/unreviewed/2024/05/GHSA-x5fc-mwch-j73r/GHSA-x5fc-mwch-j73r.json b/advisories/unreviewed/2024/05/GHSA-x5fc-mwch-j73r/GHSA-x5fc-mwch-j73r.json index 7678ce83012..456d1d2b4cf 100644 --- a/advisories/unreviewed/2024/05/GHSA-x5fc-mwch-j73r/GHSA-x5fc-mwch-j73r.json +++ b/advisories/unreviewed/2024/05/GHSA-x5fc-mwch-j73r/GHSA-x5fc-mwch-j73r.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x5fc-mwch-j73r", - "modified": "2024-05-21T15:31:43Z", + "modified": "2025-01-10T18:31:37Z", "published": "2024-05-21T15:31:43Z", "aliases": [ "CVE-2021-47349" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmwifiex: bring down link before deleting interface\n\nWe can deadlock when rmmod'ing the driver or going through firmware\nreset, because the cfg80211_unregister_wdev() has to bring down the link\nfor us, ... which then grab the same wiphy lock.\n\nnl80211_del_interface() already handles a very similar case, with a nice\ndescription:\n\n /*\n * We hold RTNL, so this is safe, without RTNL opencount cannot\n * reach 0, and thus the rdev cannot be deleted.\n *\n * We need to do it for the dev_close(), since that will call\n * the netdev notifiers, and we need to acquire the mutex there\n * but don't know if we get there from here or from some other\n * place (e.g. \"ip link set ... down\").\n */\n mutex_unlock(&rdev->wiphy.mtx);\n...\n\nDo similarly for mwifiex teardown, by ensuring we bring the link down\nfirst.\n\nSample deadlock trace:\n\n[ 247.103516] INFO: task rmmod:2119 blocked for more than 123 seconds.\n[ 247.110630] Not tainted 5.12.4 #5\n[ 247.115796] \"echo 0 > /proc/sys/kernel/hung_task_timeout_secs\" disables this message.\n[ 247.124557] task:rmmod state:D stack: 0 pid: 2119 ppid: 2114 flags:0x00400208\n[ 247.133905] Call trace:\n[ 247.136644] __switch_to+0x130/0x170\n[ 247.140643] __schedule+0x714/0xa0c\n[ 247.144548] schedule_preempt_disabled+0x88/0xf4\n[ 247.149714] __mutex_lock_common+0x43c/0x750\n[ 247.154496] mutex_lock_nested+0x5c/0x68\n[ 247.158884] cfg80211_netdev_notifier_call+0x280/0x4e0 [cfg80211]\n[ 247.165769] raw_notifier_call_chain+0x4c/0x78\n[ 247.170742] call_netdevice_notifiers_info+0x68/0xa4\n[ 247.176305] __dev_close_many+0x7c/0x138\n[ 247.180693] dev_close_many+0x7c/0x10c\n[ 247.184893] unregister_netdevice_many+0xfc/0x654\n[ 247.190158] unregister_netdevice_queue+0xb4/0xe0\n[ 247.195424] _cfg80211_unregister_wdev+0xa4/0x204 [cfg80211]\n[ 247.201816] cfg80211_unregister_wdev+0x20/0x2c [cfg80211]\n[ 247.208016] mwifiex_del_virtual_intf+0xc8/0x188 [mwifiex]\n[ 247.214174] mwifiex_uninit_sw+0x158/0x1b0 [mwifiex]\n[ 247.219747] mwifiex_remove_card+0x38/0xa0 [mwifiex]\n[ 247.225316] mwifiex_pcie_remove+0xd0/0xe0 [mwifiex_pcie]\n[ 247.231451] pci_device_remove+0x50/0xe0\n[ 247.235849] device_release_driver_internal+0x110/0x1b0\n[ 247.241701] driver_detach+0x5c/0x9c\n[ 247.245704] bus_remove_driver+0x84/0xb8\n[ 247.250095] driver_unregister+0x3c/0x60\n[ 247.254486] pci_unregister_driver+0x2c/0x90\n[ 247.259267] cleanup_module+0x18/0xcdc [mwifiex_pcie]", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-667" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T15:15:21Z" diff --git a/advisories/unreviewed/2024/05/GHSA-x5vm-26pp-xff5/GHSA-x5vm-26pp-xff5.json b/advisories/unreviewed/2024/05/GHSA-x5vm-26pp-xff5/GHSA-x5vm-26pp-xff5.json index 422da2720cb..1e58ce8925b 100644 --- a/advisories/unreviewed/2024/05/GHSA-x5vm-26pp-xff5/GHSA-x5vm-26pp-xff5.json +++ b/advisories/unreviewed/2024/05/GHSA-x5vm-26pp-xff5/GHSA-x5vm-26pp-xff5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x5vm-26pp-xff5", - "modified": "2024-05-21T18:31:19Z", + "modified": "2025-01-10T18:31:37Z", "published": "2024-05-21T18:31:19Z", "aliases": [ "CVE-2023-52737" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: lock the inode in shared mode before starting fiemap\n\nCurrently fiemap does not take the inode's lock (VFS lock), it only locks\na file range in the inode's io tree. This however can lead to a deadlock\nif we have a concurrent fsync on the file and fiemap code triggers a fault\nwhen accessing the user space buffer with fiemap_fill_next_extent(). The\ndeadlock happens on the inode's i_mmap_lock semaphore, which is taken both\nby fsync and btrfs_page_mkwrite(). This deadlock was recently reported by\nsyzbot and triggers a trace like the following:\n\n task:syz-executor361 state:D stack:20264 pid:5668 ppid:5119 flags:0x00004004\n Call Trace:\n \n context_switch kernel/sched/core.c:5293 [inline]\n __schedule+0x995/0xe20 kernel/sched/core.c:6606\n schedule+0xcb/0x190 kernel/sched/core.c:6682\n wait_on_state fs/btrfs/extent-io-tree.c:707 [inline]\n wait_extent_bit+0x577/0x6f0 fs/btrfs/extent-io-tree.c:751\n lock_extent+0x1c2/0x280 fs/btrfs/extent-io-tree.c:1742\n find_lock_delalloc_range+0x4e6/0x9c0 fs/btrfs/extent_io.c:488\n writepage_delalloc+0x1ef/0x540 fs/btrfs/extent_io.c:1863\n __extent_writepage+0x736/0x14e0 fs/btrfs/extent_io.c:2174\n extent_write_cache_pages+0x983/0x1220 fs/btrfs/extent_io.c:3091\n extent_writepages+0x219/0x540 fs/btrfs/extent_io.c:3211\n do_writepages+0x3c3/0x680 mm/page-writeback.c:2581\n filemap_fdatawrite_wbc+0x11e/0x170 mm/filemap.c:388\n __filemap_fdatawrite_range mm/filemap.c:421 [inline]\n filemap_fdatawrite_range+0x175/0x200 mm/filemap.c:439\n btrfs_fdatawrite_range fs/btrfs/file.c:3850 [inline]\n start_ordered_ops fs/btrfs/file.c:1737 [inline]\n btrfs_sync_file+0x4ff/0x1190 fs/btrfs/file.c:1839\n generic_write_sync include/linux/fs.h:2885 [inline]\n btrfs_do_write_iter+0xcd3/0x1280 fs/btrfs/file.c:1684\n call_write_iter include/linux/fs.h:2189 [inline]\n new_sync_write fs/read_write.c:491 [inline]\n vfs_write+0x7dc/0xc50 fs/read_write.c:584\n ksys_write+0x177/0x2a0 fs/read_write.c:637\n do_syscall_x64 arch/x86/entry/common.c:50 [inline]\n do_syscall_64+0x3d/0xb0 arch/x86/entry/common.c:80\n entry_SYSCALL_64_after_hwframe+0x63/0xcd\n RIP: 0033:0x7f7d4054e9b9\n RSP: 002b:00007f7d404fa2f8 EFLAGS: 00000246 ORIG_RAX: 0000000000000001\n RAX: ffffffffffffffda RBX: 00007f7d405d87a0 RCX: 00007f7d4054e9b9\n RDX: 0000000000000090 RSI: 0000000020000000 RDI: 0000000000000006\n RBP: 00007f7d405a51d0 R08: 0000000000000000 R09: 0000000000000000\n R10: 0000000000000000 R11: 0000000000000246 R12: 61635f65646f6e69\n R13: 65646f7475616f6e R14: 7261637369646f6e R15: 00007f7d405d87a8\n \n INFO: task syz-executor361:5697 blocked for more than 145 seconds.\n Not tainted 6.2.0-rc3-syzkaller-00376-g7c6984405241 #0\n \"echo 0 > /proc/sys/kernel/hung_task_timeout_secs\" disables this message.\n task:syz-executor361 state:D stack:21216 pid:5697 ppid:5119 flags:0x00004004\n Call Trace:\n \n context_switch kernel/sched/core.c:5293 [inline]\n __schedule+0x995/0xe20 kernel/sched/core.c:6606\n schedule+0xcb/0x190 kernel/sched/core.c:6682\n rwsem_down_read_slowpath+0x5f9/0x930 kernel/locking/rwsem.c:1095\n __down_read_common+0x54/0x2a0 kernel/locking/rwsem.c:1260\n btrfs_page_mkwrite+0x417/0xc80 fs/btrfs/inode.c:8526\n do_page_mkwrite+0x19e/0x5e0 mm/memory.c:2947\n wp_page_shared+0x15e/0x380 mm/memory.c:3295\n handle_pte_fault mm/memory.c:4949 [inline]\n __handle_mm_fault mm/memory.c:5073 [inline]\n handle_mm_fault+0x1b79/0x26b0 mm/memory.c:5219\n do_user_addr_fault+0x69b/0xcb0 arch/x86/mm/fault.c:1428\n handle_page_fault arch/x86/mm/fault.c:1519 [inline]\n exc_page_fault+0x7a/0x110 arch/x86/mm/fault.c:1575\n asm_exc_page_fault+0x22/0x30 arch/x86/include/asm/idtentry.h:570\n RIP: 0010:copy_user_short_string+0xd/0x40 arch/x86/lib/copy_user_64.S:233\n Code: 74 0a 89 (...)\n RSP: 0018:ffffc9000570f330 EFLAGS: 000502\n---truncated---", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-667" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T16:15:13Z" diff --git a/advisories/unreviewed/2024/06/GHSA-hqhp-cmjh-x8q9/GHSA-hqhp-cmjh-x8q9.json b/advisories/unreviewed/2024/06/GHSA-hqhp-cmjh-x8q9/GHSA-hqhp-cmjh-x8q9.json index 8efac378ab9..997cbd54483 100644 --- a/advisories/unreviewed/2024/06/GHSA-hqhp-cmjh-x8q9/GHSA-hqhp-cmjh-x8q9.json +++ b/advisories/unreviewed/2024/06/GHSA-hqhp-cmjh-x8q9/GHSA-hqhp-cmjh-x8q9.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-918" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-p237-w2mf-8cwm/GHSA-p237-w2mf-8cwm.json b/advisories/unreviewed/2024/06/GHSA-p237-w2mf-8cwm/GHSA-p237-w2mf-8cwm.json index 8c43cc337f8..e26bff79dfd 100644 --- a/advisories/unreviewed/2024/06/GHSA-p237-w2mf-8cwm/GHSA-p237-w2mf-8cwm.json +++ b/advisories/unreviewed/2024/06/GHSA-p237-w2mf-8cwm/GHSA-p237-w2mf-8cwm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p237-w2mf-8cwm", - "modified": "2024-06-27T12:30:47Z", + "modified": "2025-01-10T18:31:38Z", "published": "2024-06-19T15:30:54Z", "aliases": [ "CVE-2024-38589" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetrom: fix possible dead-lock in nr_rt_ioctl()\n\nsyzbot loves netrom, and found a possible deadlock in nr_rt_ioctl [1]\n\nMake sure we always acquire nr_node_list_lock before nr_node_lock(nr_node)\n\n[1]\nWARNING: possible circular locking dependency detected\n6.9.0-rc7-syzkaller-02147-g654de42f3fc6 #0 Not tainted\n------------------------------------------------------\nsyz-executor350/5129 is trying to acquire lock:\n ffff8880186e2070 (&nr_node->node_lock){+...}-{2:2}, at: spin_lock_bh include/linux/spinlock.h:356 [inline]\n ffff8880186e2070 (&nr_node->node_lock){+...}-{2:2}, at: nr_node_lock include/net/netrom.h:152 [inline]\n ffff8880186e2070 (&nr_node->node_lock){+...}-{2:2}, at: nr_dec_obs net/netrom/nr_route.c:464 [inline]\n ffff8880186e2070 (&nr_node->node_lock){+...}-{2:2}, at: nr_rt_ioctl+0x1bb/0x1090 net/netrom/nr_route.c:697\n\nbut task is already holding lock:\n ffffffff8f7053b8 (nr_node_list_lock){+...}-{2:2}, at: spin_lock_bh include/linux/spinlock.h:356 [inline]\n ffffffff8f7053b8 (nr_node_list_lock){+...}-{2:2}, at: nr_dec_obs net/netrom/nr_route.c:462 [inline]\n ffffffff8f7053b8 (nr_node_list_lock){+...}-{2:2}, at: nr_rt_ioctl+0x10a/0x1090 net/netrom/nr_route.c:697\n\nwhich lock already depends on the new lock.\n\nthe existing dependency chain (in reverse order) is:\n\n-> #1 (nr_node_list_lock){+...}-{2:2}:\n lock_acquire+0x1ed/0x550 kernel/locking/lockdep.c:5754\n __raw_spin_lock_bh include/linux/spinlock_api_smp.h:126 [inline]\n _raw_spin_lock_bh+0x35/0x50 kernel/locking/spinlock.c:178\n spin_lock_bh include/linux/spinlock.h:356 [inline]\n nr_remove_node net/netrom/nr_route.c:299 [inline]\n nr_del_node+0x4b4/0x820 net/netrom/nr_route.c:355\n nr_rt_ioctl+0xa95/0x1090 net/netrom/nr_route.c:683\n sock_do_ioctl+0x158/0x460 net/socket.c:1222\n sock_ioctl+0x629/0x8e0 net/socket.c:1341\n vfs_ioctl fs/ioctl.c:51 [inline]\n __do_sys_ioctl fs/ioctl.c:904 [inline]\n __se_sys_ioctl+0xfc/0x170 fs/ioctl.c:890\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xf5/0x240 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\n-> #0 (&nr_node->node_lock){+...}-{2:2}:\n check_prev_add kernel/locking/lockdep.c:3134 [inline]\n check_prevs_add kernel/locking/lockdep.c:3253 [inline]\n validate_chain+0x18cb/0x58e0 kernel/locking/lockdep.c:3869\n __lock_acquire+0x1346/0x1fd0 kernel/locking/lockdep.c:5137\n lock_acquire+0x1ed/0x550 kernel/locking/lockdep.c:5754\n __raw_spin_lock_bh include/linux/spinlock_api_smp.h:126 [inline]\n _raw_spin_lock_bh+0x35/0x50 kernel/locking/spinlock.c:178\n spin_lock_bh include/linux/spinlock.h:356 [inline]\n nr_node_lock include/net/netrom.h:152 [inline]\n nr_dec_obs net/netrom/nr_route.c:464 [inline]\n nr_rt_ioctl+0x1bb/0x1090 net/netrom/nr_route.c:697\n sock_do_ioctl+0x158/0x460 net/socket.c:1222\n sock_ioctl+0x629/0x8e0 net/socket.c:1341\n vfs_ioctl fs/ioctl.c:51 [inline]\n __do_sys_ioctl fs/ioctl.c:904 [inline]\n __se_sys_ioctl+0xfc/0x170 fs/ioctl.c:890\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xf5/0x240 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nother info that might help us debug this:\n\n Possible unsafe locking scenario:\n\n CPU0 CPU1\n ---- ----\n lock(nr_node_list_lock);\n lock(&nr_node->node_lock);\n lock(nr_node_list_lock);\n lock(&nr_node->node_lock);\n\n *** DEADLOCK ***\n\n1 lock held by syz-executor350/5129:\n #0: ffffffff8f7053b8 (nr_node_list_lock){+...}-{2:2}, at: spin_lock_bh include/linux/spinlock.h:356 [inline]\n #0: ffffffff8f7053b8 (nr_node_list_lock){+...}-{2:2}, at: nr_dec_obs net/netrom/nr_route.c:462 [inline]\n #0: ffffffff8f70\n---truncated---", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -56,8 +61,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-667" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-19T14:15:19Z" diff --git a/advisories/unreviewed/2024/06/GHSA-pqqr-79q5-9qwg/GHSA-pqqr-79q5-9qwg.json b/advisories/unreviewed/2024/06/GHSA-pqqr-79q5-9qwg/GHSA-pqqr-79q5-9qwg.json index d542dbba475..2f89bc4d59b 100644 --- a/advisories/unreviewed/2024/06/GHSA-pqqr-79q5-9qwg/GHSA-pqqr-79q5-9qwg.json +++ b/advisories/unreviewed/2024/06/GHSA-pqqr-79q5-9qwg/GHSA-pqqr-79q5-9qwg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pqqr-79q5-9qwg", - "modified": "2024-06-21T15:31:05Z", + "modified": "2025-01-10T18:31:38Z", "published": "2024-06-17T18:31:34Z", "aliases": [ "CVE-2024-36973" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmisc: microchip: pci1xxxx: fix double free in the error handling of gp_aux_bus_probe()\n\nWhen auxiliary_device_add() returns error and then calls\nauxiliary_device_uninit(), callback function\ngp_auxiliary_device_release() calls ida_free() and\nkfree(aux_device_wrapper) to free memory. We should't\ncall them again in the error handling path.\n\nFix this by skipping the redundant cleanup functions.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-415" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-17T18:15:17Z" diff --git a/advisories/unreviewed/2024/12/GHSA-2hwq-42hc-rhqv/GHSA-2hwq-42hc-rhqv.json b/advisories/unreviewed/2024/12/GHSA-2hwq-42hc-rhqv/GHSA-2hwq-42hc-rhqv.json index 9fd2042da11..816772f2b75 100644 --- a/advisories/unreviewed/2024/12/GHSA-2hwq-42hc-rhqv/GHSA-2hwq-42hc-rhqv.json +++ b/advisories/unreviewed/2024/12/GHSA-2hwq-42hc-rhqv/GHSA-2hwq-42hc-rhqv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2hwq-42hc-rhqv", - "modified": "2024-12-27T15:31:52Z", + "modified": "2025-01-10T18:31:38Z", "published": "2024-12-27T15:31:52Z", "aliases": [ "CVE-2024-53213" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: usb: lan78xx: Fix double free issue with interrupt buffer allocation\n\nIn lan78xx_probe(), the buffer `buf` was being freed twice: once\nimplicitly through `usb_free_urb(dev->urb_intr)` with the\n`URB_FREE_BUFFER` flag and again explicitly by `kfree(buf)`. This caused\na double free issue.\n\nTo resolve this, reordered `kmalloc()` and `usb_alloc_urb()` calls to\nsimplify the initialization sequence and removed the redundant\n`kfree(buf)`. Now, `buf` is allocated after `usb_alloc_urb()`, ensuring\nit is correctly managed by `usb_fill_int_urb()` and freed by\n`usb_free_urb()` as intended.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-415" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T14:15:29Z" diff --git a/advisories/unreviewed/2024/12/GHSA-8896-pxp4-28pj/GHSA-8896-pxp4-28pj.json b/advisories/unreviewed/2024/12/GHSA-8896-pxp4-28pj/GHSA-8896-pxp4-28pj.json index 56840354e3f..d58ddd26f1e 100644 --- a/advisories/unreviewed/2024/12/GHSA-8896-pxp4-28pj/GHSA-8896-pxp4-28pj.json +++ b/advisories/unreviewed/2024/12/GHSA-8896-pxp4-28pj/GHSA-8896-pxp4-28pj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8896-pxp4-28pj", - "modified": "2025-01-09T18:32:13Z", + "modified": "2025-01-10T18:31:38Z", "published": "2024-12-29T09:30:47Z", "aliases": [ "CVE-2024-56716" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetdevsim: prevent bad user input in nsim_dev_health_break_write()\n\nIf either a zero count or a large one is provided, kernel can crash.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-1284" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-29T09:15:06Z" diff --git a/advisories/unreviewed/2024/12/GHSA-93c3-577v-mcj3/GHSA-93c3-577v-mcj3.json b/advisories/unreviewed/2024/12/GHSA-93c3-577v-mcj3/GHSA-93c3-577v-mcj3.json index 9366fbae2f9..ac7efafa483 100644 --- a/advisories/unreviewed/2024/12/GHSA-93c3-577v-mcj3/GHSA-93c3-577v-mcj3.json +++ b/advisories/unreviewed/2024/12/GHSA-93c3-577v-mcj3/GHSA-93c3-577v-mcj3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-93c3-577v-mcj3", - "modified": "2024-12-17T18:33:50Z", + "modified": "2025-01-10T18:31:38Z", "published": "2024-12-17T18:33:50Z", "aliases": [ "CVE-2024-49819" diff --git a/advisories/unreviewed/2024/12/GHSA-c7fp-8j89-w969/GHSA-c7fp-8j89-w969.json b/advisories/unreviewed/2024/12/GHSA-c7fp-8j89-w969/GHSA-c7fp-8j89-w969.json index 1408c9a1d55..f1fa311781e 100644 --- a/advisories/unreviewed/2024/12/GHSA-c7fp-8j89-w969/GHSA-c7fp-8j89-w969.json +++ b/advisories/unreviewed/2024/12/GHSA-c7fp-8j89-w969/GHSA-c7fp-8j89-w969.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c7fp-8j89-w969", - "modified": "2024-12-29T09:30:47Z", + "modified": "2025-01-10T18:31:38Z", "published": "2024-12-29T09:30:47Z", "aliases": [ "CVE-2024-56717" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: mscc: ocelot: fix incorrect IFH SRC_PORT field in ocelot_ifh_set_basic()\n\nPackets injected by the CPU should have a SRC_PORT field equal to the\nCPU port module index in the Analyzer block (ocelot->num_phys_ports).\n\nThe blamed commit copied the ocelot_ifh_set_basic() call incorrectly\nfrom ocelot_xmit_common() in net/dsa/tag_ocelot.c. Instead of calling\nwith \"x\", it calls with BIT_ULL(x), but the field is not a port mask,\nbut rather a single port index.\n\n[ side note: this is the technical debt of code duplication :( ]\n\nThe error used to be silent and doesn't appear to have other\nuser-visible manifestations, but with new changes in the packing\nlibrary, it now fails loudly as follows:\n\n------------[ cut here ]------------\nCannot store 0x40 inside bits 46-43 - will truncate\nsja1105 spi2.0: xmit timed out\nWARNING: CPU: 1 PID: 102 at lib/packing.c:98 __pack+0x90/0x198\nsja1105 spi2.0: timed out polling for tstamp\nCPU: 1 UID: 0 PID: 102 Comm: felix_xmit\nTainted: G W N 6.13.0-rc1-00372-gf706b85d972d-dirty #2605\nCall trace:\n __pack+0x90/0x198 (P)\n __pack+0x90/0x198 (L)\n packing+0x78/0x98\n ocelot_ifh_set_basic+0x260/0x368\n ocelot_port_inject_frame+0xa8/0x250\n felix_port_deferred_xmit+0x14c/0x258\n kthread_worker_fn+0x134/0x350\n kthread+0x114/0x138\n\nThe code path pertains to the ocelot switchdev driver and to the felix\nsecondary DSA tag protocol, ocelot-8021q. Here seen with ocelot-8021q.\n\nThe messenger (packing) is not really to blame, so fix the original\ncommit instead.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -33,7 +38,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-29T09:15:06Z" diff --git a/advisories/unreviewed/2024/12/GHSA-hwhg-f3ff-q3c4/GHSA-hwhg-f3ff-q3c4.json b/advisories/unreviewed/2024/12/GHSA-hwhg-f3ff-q3c4/GHSA-hwhg-f3ff-q3c4.json index ae85ffceac9..f2f08d8a3c9 100644 --- a/advisories/unreviewed/2024/12/GHSA-hwhg-f3ff-q3c4/GHSA-hwhg-f3ff-q3c4.json +++ b/advisories/unreviewed/2024/12/GHSA-hwhg-f3ff-q3c4/GHSA-hwhg-f3ff-q3c4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hwhg-f3ff-q3c4", - "modified": "2024-12-12T21:30:47Z", + "modified": "2025-01-10T18:31:38Z", "published": "2024-12-12T21:30:47Z", "aliases": [ "CVE-2024-49147" diff --git a/advisories/unreviewed/2024/12/GHSA-j7fv-qwjv-4xh9/GHSA-j7fv-qwjv-4xh9.json b/advisories/unreviewed/2024/12/GHSA-j7fv-qwjv-4xh9/GHSA-j7fv-qwjv-4xh9.json index 1de2577d612..77e981fbe4c 100644 --- a/advisories/unreviewed/2024/12/GHSA-j7fv-qwjv-4xh9/GHSA-j7fv-qwjv-4xh9.json +++ b/advisories/unreviewed/2024/12/GHSA-j7fv-qwjv-4xh9/GHSA-j7fv-qwjv-4xh9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-j7fv-qwjv-4xh9", - "modified": "2024-12-27T15:31:52Z", + "modified": "2025-01-10T18:31:38Z", "published": "2024-12-27T15:31:52Z", "aliases": [ "CVE-2024-53227" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: bfa: Fix use-after-free in bfad_im_module_exit()\n\nBUG: KASAN: slab-use-after-free in __lock_acquire+0x2aca/0x3a20\nRead of size 8 at addr ffff8881082d80c8 by task modprobe/25303\n\nCall Trace:\n \n dump_stack_lvl+0x95/0xe0\n print_report+0xcb/0x620\n kasan_report+0xbd/0xf0\n __lock_acquire+0x2aca/0x3a20\n lock_acquire+0x19b/0x520\n _raw_spin_lock+0x2b/0x40\n attribute_container_unregister+0x30/0x160\n fc_release_transport+0x19/0x90 [scsi_transport_fc]\n bfad_im_module_exit+0x23/0x60 [bfa]\n bfad_init+0xdb/0xff0 [bfa]\n do_one_initcall+0xdc/0x550\n do_init_module+0x22d/0x6b0\n load_module+0x4e96/0x5ff0\n init_module_from_file+0xcd/0x130\n idempotent_init_module+0x330/0x620\n __x64_sys_finit_module+0xb3/0x110\n do_syscall_64+0xc1/0x1d0\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n \n\nAllocated by task 25303:\n kasan_save_stack+0x24/0x50\n kasan_save_track+0x14/0x30\n __kasan_kmalloc+0x7f/0x90\n fc_attach_transport+0x4f/0x4740 [scsi_transport_fc]\n bfad_im_module_init+0x17/0x80 [bfa]\n bfad_init+0x23/0xff0 [bfa]\n do_one_initcall+0xdc/0x550\n do_init_module+0x22d/0x6b0\n load_module+0x4e96/0x5ff0\n init_module_from_file+0xcd/0x130\n idempotent_init_module+0x330/0x620\n __x64_sys_finit_module+0xb3/0x110\n do_syscall_64+0xc1/0x1d0\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nFreed by task 25303:\n kasan_save_stack+0x24/0x50\n kasan_save_track+0x14/0x30\n kasan_save_free_info+0x3b/0x60\n __kasan_slab_free+0x38/0x50\n kfree+0x212/0x480\n bfad_im_module_init+0x7e/0x80 [bfa]\n bfad_init+0x23/0xff0 [bfa]\n do_one_initcall+0xdc/0x550\n do_init_module+0x22d/0x6b0\n load_module+0x4e96/0x5ff0\n init_module_from_file+0xcd/0x130\n idempotent_init_module+0x330/0x620\n __x64_sys_finit_module+0xb3/0x110\n do_syscall_64+0xc1/0x1d0\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nAbove issue happens as follows:\n\nbfad_init\n error = bfad_im_module_init()\n fc_release_transport(bfad_im_scsi_transport_template);\n if (error)\n goto ext;\n\next:\n bfad_im_module_exit();\n fc_release_transport(bfad_im_scsi_transport_template);\n --> Trigger double release\n\nDon't call bfad_im_module_exit() if bfad_im_module_init() failed.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -52,8 +57,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T14:15:30Z" diff --git a/advisories/unreviewed/2024/12/GHSA-q325-c4qh-6g3c/GHSA-q325-c4qh-6g3c.json b/advisories/unreviewed/2024/12/GHSA-q325-c4qh-6g3c/GHSA-q325-c4qh-6g3c.json index 03cf5059050..cb35ce43670 100644 --- a/advisories/unreviewed/2024/12/GHSA-q325-c4qh-6g3c/GHSA-q325-c4qh-6g3c.json +++ b/advisories/unreviewed/2024/12/GHSA-q325-c4qh-6g3c/GHSA-q325-c4qh-6g3c.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-q325-c4qh-6g3c", - "modified": "2024-12-29T09:30:47Z", + "modified": "2025-01-10T18:31:38Z", "published": "2024-12-29T09:30:47Z", "aliases": [ "CVE-2024-56718" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/smc: protect link down work from execute after lgr freed\n\nlink down work may be scheduled before lgr freed but execute\nafter lgr freed, which may result in crash. So it is need to\nhold a reference before shedule link down work, and put the\nreference after work executed or canceled.\n\nThe relevant crash call stack as follows:\n list_del corruption. prev->next should be ffffb638c9c0fe20,\n but was 0000000000000000\n ------------[ cut here ]------------\n kernel BUG at lib/list_debug.c:51!\n invalid opcode: 0000 [#1] SMP NOPTI\n CPU: 6 PID: 978112 Comm: kworker/6:119 Kdump: loaded Tainted: G #1\n Hardware name: Alibaba Cloud Alibaba Cloud ECS, BIOS 2221b89 04/01/2014\n Workqueue: events smc_link_down_work [smc]\n RIP: 0010:__list_del_entry_valid.cold+0x31/0x47\n RSP: 0018:ffffb638c9c0fdd8 EFLAGS: 00010086\n RAX: 0000000000000054 RBX: ffff942fb75e5128 RCX: 0000000000000000\n RDX: ffff943520930aa0 RSI: ffff94352091fc80 RDI: ffff94352091fc80\n RBP: 0000000000000000 R08: 0000000000000000 R09: ffffb638c9c0fc38\n R10: ffffb638c9c0fc30 R11: ffffffffa015eb28 R12: 0000000000000002\n R13: ffffb638c9c0fe20 R14: 0000000000000001 R15: ffff942f9cd051c0\n FS: 0000000000000000(0000) GS:ffff943520900000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 00007f4f25214000 CR3: 000000025fbae004 CR4: 00000000007706e0\n DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n PKRU: 55555554\n Call Trace:\n rwsem_down_write_slowpath+0x17e/0x470\n smc_link_down_work+0x3c/0x60 [smc]\n process_one_work+0x1ac/0x350\n worker_thread+0x49/0x2f0\n ? rescuer_thread+0x360/0x360\n kthread+0x118/0x140\n ? __kthread_bind_mask+0x60/0x60\n ret_from_fork+0x1f/0x30", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -33,7 +38,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-29T09:15:07Z" diff --git a/advisories/unreviewed/2024/12/GHSA-wqfp-fvw2-67qm/GHSA-wqfp-fvw2-67qm.json b/advisories/unreviewed/2024/12/GHSA-wqfp-fvw2-67qm/GHSA-wqfp-fvw2-67qm.json index 9b33afb23f8..aae120d32b0 100644 --- a/advisories/unreviewed/2024/12/GHSA-wqfp-fvw2-67qm/GHSA-wqfp-fvw2-67qm.json +++ b/advisories/unreviewed/2024/12/GHSA-wqfp-fvw2-67qm/GHSA-wqfp-fvw2-67qm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wqfp-fvw2-67qm", - "modified": "2024-12-17T12:31:38Z", + "modified": "2025-01-10T18:31:38Z", "published": "2024-12-17T12:31:38Z", "aliases": [ "CVE-2024-12024" diff --git a/advisories/unreviewed/2025/01/GHSA-223j-7cj4-4cw7/GHSA-223j-7cj4-4cw7.json b/advisories/unreviewed/2025/01/GHSA-223j-7cj4-4cw7/GHSA-223j-7cj4-4cw7.json index 6ef8ba8afb2..8319156b875 100644 --- a/advisories/unreviewed/2025/01/GHSA-223j-7cj4-4cw7/GHSA-223j-7cj4-4cw7.json +++ b/advisories/unreviewed/2025/01/GHSA-223j-7cj4-4cw7/GHSA-223j-7cj4-4cw7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-223j-7cj4-4cw7", - "modified": "2025-01-09T21:31:31Z", + "modified": "2025-01-10T18:31:40Z", "published": "2025-01-09T21:31:31Z", "aliases": [ "CVE-2024-13278" ], "details": "Incorrect Authorization vulnerability in Drupal Diff allows Functionality Misuse.This issue affects Diff: from 0.0.0 before 1.8.0.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-863" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-09T20:15:36Z" diff --git a/advisories/unreviewed/2025/01/GHSA-2mxq-9vvh-j4jv/GHSA-2mxq-9vvh-j4jv.json b/advisories/unreviewed/2025/01/GHSA-2mxq-9vvh-j4jv/GHSA-2mxq-9vvh-j4jv.json new file mode 100644 index 00000000000..3c9172bc841 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2mxq-9vvh-j4jv/GHSA-2mxq-9vvh-j4jv.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2mxq-9vvh-j4jv", + "modified": "2025-01-10T18:31:41Z", + "published": "2025-01-10T18:31:41Z", + "aliases": [ + "CVE-2024-57222" + ], + "details": "Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_cancel_wps function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57222" + }, + { + "type": "WEB", + "url": "https://github.com/yanggao017/vuln/blob/main/Linksys/E7350/CI_5_apcli_cancel_wps/README.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-10T18:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-2q57-gr73-v7pg/GHSA-2q57-gr73-v7pg.json b/advisories/unreviewed/2025/01/GHSA-2q57-gr73-v7pg/GHSA-2q57-gr73-v7pg.json index 26b7e70f700..650bd8af376 100644 --- a/advisories/unreviewed/2025/01/GHSA-2q57-gr73-v7pg/GHSA-2q57-gr73-v7pg.json +++ b/advisories/unreviewed/2025/01/GHSA-2q57-gr73-v7pg/GHSA-2q57-gr73-v7pg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2q57-gr73-v7pg", - "modified": "2025-01-09T21:31:31Z", + "modified": "2025-01-10T18:31:40Z", "published": "2025-01-09T21:31:31Z", "aliases": [ "CVE-2024-42898" ], "details": "A cross-site scripting (XSS) vulnerability in Nagios XI 2024R1.1.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter in the Account Settings page.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-09T20:15:38Z" diff --git a/advisories/unreviewed/2025/01/GHSA-2wf3-32wx-c338/GHSA-2wf3-32wx-c338.json b/advisories/unreviewed/2025/01/GHSA-2wf3-32wx-c338/GHSA-2wf3-32wx-c338.json index a6edc263340..7667efa1be6 100644 --- a/advisories/unreviewed/2025/01/GHSA-2wf3-32wx-c338/GHSA-2wf3-32wx-c338.json +++ b/advisories/unreviewed/2025/01/GHSA-2wf3-32wx-c338/GHSA-2wf3-32wx-c338.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2wf3-32wx-c338", - "modified": "2025-01-10T00:30:36Z", + "modified": "2025-01-10T18:31:40Z", "published": "2025-01-09T21:31:31Z", "aliases": [ "CVE-2024-54761" ], "details": "BigAnt Office Messenger 5.6.06 is vulnerable to SQL Injection via the 'dev_code' parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-09T20:15:38Z" diff --git a/advisories/unreviewed/2025/01/GHSA-43p5-738g-gr8j/GHSA-43p5-738g-gr8j.json b/advisories/unreviewed/2025/01/GHSA-43p5-738g-gr8j/GHSA-43p5-738g-gr8j.json new file mode 100644 index 00000000000..63147e4d793 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-43p5-738g-gr8j/GHSA-43p5-738g-gr8j.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-43p5-738g-gr8j", + "modified": "2025-01-10T18:31:41Z", + "published": "2025-01-10T18:31:41Z", + "aliases": [ + "CVE-2024-29970" + ], + "details": "Fortanix Enclave OS 3.36.1941-EM has an interface vulnerability that leads to state corruption via injected signals.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29970" + }, + { + "type": "WEB", + "url": "https://github.com/ahoi-attacks/sigy/blob/main/pocs/enclaveos/cve.md" + }, + { + "type": "WEB", + "url": "https://support.fortanix.com/hc/en-us/sections/360012461751-Enclave-OS" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-10T16:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-44c7-chxm-hq3q/GHSA-44c7-chxm-hq3q.json b/advisories/unreviewed/2025/01/GHSA-44c7-chxm-hq3q/GHSA-44c7-chxm-hq3q.json new file mode 100644 index 00000000000..d2a31b61b9d --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-44c7-chxm-hq3q/GHSA-44c7-chxm-hq3q.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-44c7-chxm-hq3q", + "modified": "2025-01-10T18:31:41Z", + "published": "2025-01-10T18:31:41Z", + "aliases": [ + "CVE-2024-57223" + ], + "details": "Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_wps_gen_pincode function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57223" + }, + { + "type": "WEB", + "url": "https://github.com/yanggao017/vuln/blob/main/Linksys/E7350/CI_6_apcli_wps_gen_pincode/README.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-10T18:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-4vhm-33mh-2464/GHSA-4vhm-33mh-2464.json b/advisories/unreviewed/2025/01/GHSA-4vhm-33mh-2464/GHSA-4vhm-33mh-2464.json new file mode 100644 index 00000000000..67f91f73d08 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-4vhm-33mh-2464/GHSA-4vhm-33mh-2464.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4vhm-33mh-2464", + "modified": "2025-01-10T18:31:41Z", + "published": "2025-01-10T18:31:41Z", + "aliases": [ + "CVE-2024-54847" + ], + "details": "An issue in CP Plus CP-VNR-3104 B3223P22C02424 allows attackers to access the Diffie-Hellman (DH) parameters and access sensitive data or execute a man-in-the-middle attack.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3817" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54847" + }, + { + "type": "WEB", + "url": "https://github.com/Yashodhanvivek/CP-VNR-3104-NVR-Vulnerabilties/blob/main/CPPlus_CP-VNR-3104_Security_Assessment.pdf" + }, + { + "type": "WEB", + "url": "https://payatu.com/blog/solving-the-problem-of-encrypted-firmware" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-10T17:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-57r5-pmvw-w26w/GHSA-57r5-pmvw-w26w.json b/advisories/unreviewed/2025/01/GHSA-57r5-pmvw-w26w/GHSA-57r5-pmvw-w26w.json index f08bf7a5dd4..fb76b6c6fff 100644 --- a/advisories/unreviewed/2025/01/GHSA-57r5-pmvw-w26w/GHSA-57r5-pmvw-w26w.json +++ b/advisories/unreviewed/2025/01/GHSA-57r5-pmvw-w26w/GHSA-57r5-pmvw-w26w.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-57r5-pmvw-w26w", - "modified": "2025-01-09T21:31:30Z", + "modified": "2025-01-10T18:31:39Z", "published": "2025-01-09T21:31:30Z", "aliases": [ "CVE-2024-13253" ], "details": "Incorrect Authorization vulnerability in Drupal Advanced PWA inc Push Notifications allows Forceful Browsing.This issue affects Advanced PWA inc Push Notifications: from 0.0.0 before 1.5.0.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-863" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-09T19:15:19Z" diff --git a/advisories/unreviewed/2025/01/GHSA-5gmr-qprr-xg68/GHSA-5gmr-qprr-xg68.json b/advisories/unreviewed/2025/01/GHSA-5gmr-qprr-xg68/GHSA-5gmr-qprr-xg68.json new file mode 100644 index 00000000000..ce3cb8341fe --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-5gmr-qprr-xg68/GHSA-5gmr-qprr-xg68.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5gmr-qprr-xg68", + "modified": "2025-01-10T18:31:41Z", + "published": "2025-01-10T18:31:41Z", + "aliases": [ + "CVE-2024-57224" + ], + "details": "Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pin_wps function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57224" + }, + { + "type": "WEB", + "url": "https://github.com/yanggao017/vuln/blob/main/Linksys/E7350/CI_3_apcli_do_enr_pin_wps/README.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-10T18:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-5jr8-vjmp-fp54/GHSA-5jr8-vjmp-fp54.json b/advisories/unreviewed/2025/01/GHSA-5jr8-vjmp-fp54/GHSA-5jr8-vjmp-fp54.json new file mode 100644 index 00000000000..0f45106a715 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-5jr8-vjmp-fp54/GHSA-5jr8-vjmp-fp54.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5jr8-vjmp-fp54", + "modified": "2025-01-10T18:31:41Z", + "published": "2025-01-10T18:31:41Z", + "aliases": [ + "CVE-2024-54846" + ], + "details": "An issue in CP Plus CP-VNR-3104 B3223P22C02424 allows attackers to obtain the EC private key and access sensitive data or execute a man-in-the-middle attack.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-15522" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54846" + }, + { + "type": "WEB", + "url": "https://github.com/Yashodhanvivek/CP-VNR-3104-NVR-Vulnerabilties/blob/main/CPPlus_CP-VNR-3104_Security_Assessment.pdf" + }, + { + "type": "WEB", + "url": "https://payatu.com/blog/solving-the-problem-of-encrypted-firmware" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-10T17:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-5rcq-gp73-g9jv/GHSA-5rcq-gp73-g9jv.json b/advisories/unreviewed/2025/01/GHSA-5rcq-gp73-g9jv/GHSA-5rcq-gp73-g9jv.json index bfd4d371ba7..7358f0e2130 100644 --- a/advisories/unreviewed/2025/01/GHSA-5rcq-gp73-g9jv/GHSA-5rcq-gp73-g9jv.json +++ b/advisories/unreviewed/2025/01/GHSA-5rcq-gp73-g9jv/GHSA-5rcq-gp73-g9jv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5rcq-gp73-g9jv", - "modified": "2025-01-09T21:31:30Z", + "modified": "2025-01-10T18:31:39Z", "published": "2025-01-09T21:31:30Z", "aliases": [ "CVE-2024-13250" ], "details": "Cross-Site Request Forgery (CSRF) vulnerability in Drupal Drupal Symfony Mailer Lite allows Cross Site Request Forgery.This issue affects Drupal Symfony Mailer Lite: from 0.0.0 before 1.0.6.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-352" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-09T19:15:18Z" diff --git a/advisories/unreviewed/2025/01/GHSA-623r-49cc-q6vj/GHSA-623r-49cc-q6vj.json b/advisories/unreviewed/2025/01/GHSA-623r-49cc-q6vj/GHSA-623r-49cc-q6vj.json index f64977e3206..b394eb94acf 100644 --- a/advisories/unreviewed/2025/01/GHSA-623r-49cc-q6vj/GHSA-623r-49cc-q6vj.json +++ b/advisories/unreviewed/2025/01/GHSA-623r-49cc-q6vj/GHSA-623r-49cc-q6vj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-623r-49cc-q6vj", - "modified": "2025-01-09T21:31:31Z", + "modified": "2025-01-10T18:31:40Z", "published": "2025-01-09T21:31:31Z", "aliases": [ "CVE-2024-13289" ], "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Cookiebot + GTM allows Cross-Site Scripting (XSS).This issue affects Cookiebot + GTM: from 0.0.0 before 1.0.18.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-09T21:15:26Z" diff --git a/advisories/unreviewed/2025/01/GHSA-66jf-c5vq-qxfv/GHSA-66jf-c5vq-qxfv.json b/advisories/unreviewed/2025/01/GHSA-66jf-c5vq-qxfv/GHSA-66jf-c5vq-qxfv.json new file mode 100644 index 00000000000..19ccbc849f3 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-66jf-c5vq-qxfv/GHSA-66jf-c5vq-qxfv.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-66jf-c5vq-qxfv", + "modified": "2025-01-10T18:31:41Z", + "published": "2025-01-10T18:31:41Z", + "aliases": [ + "CVE-2024-54687" + ], + "details": "Vtiger CRM v.6.1 and before is vulnerable to Cross Site Scripting (XSS) via the Documents module and function uploadAndSaveFile in CRMEntity.php.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54687" + }, + { + "type": "WEB", + "url": "https://andrea0.medium.com" + }, + { + "type": "WEB", + "url": "https://andrea0.medium.com/analysis-of-cve-2024-54687-9d82f4c0eaa8" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-10T18:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-6g2w-ww3w-xh3x/GHSA-6g2w-ww3w-xh3x.json b/advisories/unreviewed/2025/01/GHSA-6g2w-ww3w-xh3x/GHSA-6g2w-ww3w-xh3x.json new file mode 100644 index 00000000000..90e8bd92f51 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-6g2w-ww3w-xh3x/GHSA-6g2w-ww3w-xh3x.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6g2w-ww3w-xh3x", + "modified": "2025-01-10T18:31:41Z", + "published": "2025-01-10T18:31:41Z", + "aliases": [ + "CVE-2024-57212" + ], + "details": "TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the opmode parameter in the action_reboot function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57212" + }, + { + "type": "WEB", + "url": "https://github.com/yanggao017/vuln/blob/main/TOTOLINK/A6000R/CI_10_action_reboot/README.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-10T17:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-6h86-6h56-2j4j/GHSA-6h86-6h56-2j4j.json b/advisories/unreviewed/2025/01/GHSA-6h86-6h56-2j4j/GHSA-6h86-6h56-2j4j.json index 3b3e1a1532b..0e95971712f 100644 --- a/advisories/unreviewed/2025/01/GHSA-6h86-6h56-2j4j/GHSA-6h86-6h56-2j4j.json +++ b/advisories/unreviewed/2025/01/GHSA-6h86-6h56-2j4j/GHSA-6h86-6h56-2j4j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6h86-6h56-2j4j", - "modified": "2025-01-09T21:31:31Z", + "modified": "2025-01-10T18:31:40Z", "published": "2025-01-09T21:31:31Z", "aliases": [ "CVE-2024-13287" ], "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Views SVG Animation allows Cross-Site Scripting (XSS).This issue affects Views SVG Animation: from 0.0.0 before 1.0.1.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-09T20:15:37Z" diff --git a/advisories/unreviewed/2025/01/GHSA-6hq6-3pp3-9598/GHSA-6hq6-3pp3-9598.json b/advisories/unreviewed/2025/01/GHSA-6hq6-3pp3-9598/GHSA-6hq6-3pp3-9598.json index 00e6cd70f74..68aeaad6455 100644 --- a/advisories/unreviewed/2025/01/GHSA-6hq6-3pp3-9598/GHSA-6hq6-3pp3-9598.json +++ b/advisories/unreviewed/2025/01/GHSA-6hq6-3pp3-9598/GHSA-6hq6-3pp3-9598.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6hq6-3pp3-9598", - "modified": "2025-01-09T21:31:32Z", + "modified": "2025-01-10T18:31:40Z", "published": "2025-01-09T21:31:32Z", "aliases": [ "CVE-2024-13304" ], "details": "Cross-Site Request Forgery (CSRF) vulnerability in Drupal Minify JS allows Cross Site Request Forgery.This issue affects Minify JS: from 0.0.0 before 3.0.3.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-352" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-09T21:15:28Z" diff --git a/advisories/unreviewed/2025/01/GHSA-7429-74cp-cgh9/GHSA-7429-74cp-cgh9.json b/advisories/unreviewed/2025/01/GHSA-7429-74cp-cgh9/GHSA-7429-74cp-cgh9.json index dae6a797133..2006c8029cc 100644 --- a/advisories/unreviewed/2025/01/GHSA-7429-74cp-cgh9/GHSA-7429-74cp-cgh9.json +++ b/advisories/unreviewed/2025/01/GHSA-7429-74cp-cgh9/GHSA-7429-74cp-cgh9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7429-74cp-cgh9", - "modified": "2025-01-10T15:31:34Z", + "modified": "2025-01-10T18:31:40Z", "published": "2025-01-10T15:31:34Z", "aliases": [ "CVE-2025-23022" ], "details": "FreeType 2.8.1 has a signed integer overflow in cf2_doFlex in cff/cf2intrp.c.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-190" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-10T15:15:16Z" diff --git a/advisories/unreviewed/2025/01/GHSA-7649-pgpq-cpch/GHSA-7649-pgpq-cpch.json b/advisories/unreviewed/2025/01/GHSA-7649-pgpq-cpch/GHSA-7649-pgpq-cpch.json index 4c2d4fd2fdb..5ec51f68234 100644 --- a/advisories/unreviewed/2025/01/GHSA-7649-pgpq-cpch/GHSA-7649-pgpq-cpch.json +++ b/advisories/unreviewed/2025/01/GHSA-7649-pgpq-cpch/GHSA-7649-pgpq-cpch.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7649-pgpq-cpch", - "modified": "2025-01-09T21:31:30Z", + "modified": "2025-01-10T18:31:39Z", "published": "2025-01-09T21:31:30Z", "aliases": [ "CVE-2024-13258" ], "details": "Incorrect Authorization vulnerability in Drupal Drupal REST & JSON API Authentication allows Forceful Browsing.This issue affects Drupal REST & JSON API Authentication: from 0.0.0 before 2.0.13.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-863" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-09T19:15:19Z" diff --git a/advisories/unreviewed/2025/01/GHSA-7q27-3v2r-ccj9/GHSA-7q27-3v2r-ccj9.json b/advisories/unreviewed/2025/01/GHSA-7q27-3v2r-ccj9/GHSA-7q27-3v2r-ccj9.json index ee475b57279..2522b01e44a 100644 --- a/advisories/unreviewed/2025/01/GHSA-7q27-3v2r-ccj9/GHSA-7q27-3v2r-ccj9.json +++ b/advisories/unreviewed/2025/01/GHSA-7q27-3v2r-ccj9/GHSA-7q27-3v2r-ccj9.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-126" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2025/01/GHSA-8244-g8gx-36rj/GHSA-8244-g8gx-36rj.json b/advisories/unreviewed/2025/01/GHSA-8244-g8gx-36rj/GHSA-8244-g8gx-36rj.json index d31e53b754b..2c9b25e3bb4 100644 --- a/advisories/unreviewed/2025/01/GHSA-8244-g8gx-36rj/GHSA-8244-g8gx-36rj.json +++ b/advisories/unreviewed/2025/01/GHSA-8244-g8gx-36rj/GHSA-8244-g8gx-36rj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8244-g8gx-36rj", - "modified": "2025-01-09T21:31:31Z", + "modified": "2025-01-10T18:31:40Z", "published": "2025-01-09T21:31:31Z", "aliases": [ "CVE-2024-13285" ], "details": "Vulnerability in Drupal wkhtmltopdf.This issue affects wkhtmltopdf: *.*.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-09T20:15:37Z" diff --git a/advisories/unreviewed/2025/01/GHSA-92r5-r4ww-c543/GHSA-92r5-r4ww-c543.json b/advisories/unreviewed/2025/01/GHSA-92r5-r4ww-c543/GHSA-92r5-r4ww-c543.json new file mode 100644 index 00000000000..91789c2ee92 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-92r5-r4ww-c543/GHSA-92r5-r4ww-c543.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-92r5-r4ww-c543", + "modified": "2025-01-10T18:31:41Z", + "published": "2025-01-10T18:31:41Z", + "aliases": [ + "CVE-2024-57211" + ], + "details": "TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the modifyOne parameter in the enable_wsh function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57211" + }, + { + "type": "WEB", + "url": "https://github.com/yanggao017/vuln/blob/main/TOTOLINK/A6000R/CI_11_enable_wsh/README.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-10T17:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-932w-6jv2-mm8q/GHSA-932w-6jv2-mm8q.json b/advisories/unreviewed/2025/01/GHSA-932w-6jv2-mm8q/GHSA-932w-6jv2-mm8q.json index 127ee217d1e..333421e22bf 100644 --- a/advisories/unreviewed/2025/01/GHSA-932w-6jv2-mm8q/GHSA-932w-6jv2-mm8q.json +++ b/advisories/unreviewed/2025/01/GHSA-932w-6jv2-mm8q/GHSA-932w-6jv2-mm8q.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-932w-6jv2-mm8q", - "modified": "2025-01-09T21:31:30Z", + "modified": "2025-01-10T18:31:39Z", "published": "2025-01-09T21:31:30Z", "aliases": [ "CVE-2024-13257" ], "details": "Incorrect Authorization vulnerability in Drupal Commerce View Receipt allows Forceful Browsing.This issue affects Commerce View Receipt: from 0.0.0 before 1.0.3.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-863" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-09T19:15:19Z" diff --git a/advisories/unreviewed/2025/01/GHSA-99h6-9pr2-5g94/GHSA-99h6-9pr2-5g94.json b/advisories/unreviewed/2025/01/GHSA-99h6-9pr2-5g94/GHSA-99h6-9pr2-5g94.json index 0ab2b45e260..e8f79e71ac2 100644 --- a/advisories/unreviewed/2025/01/GHSA-99h6-9pr2-5g94/GHSA-99h6-9pr2-5g94.json +++ b/advisories/unreviewed/2025/01/GHSA-99h6-9pr2-5g94/GHSA-99h6-9pr2-5g94.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-99h6-9pr2-5g94", - "modified": "2025-01-09T21:31:31Z", + "modified": "2025-01-10T18:31:39Z", "published": "2025-01-09T21:31:31Z", "aliases": [ "CVE-2024-13264" ], "details": "Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno module allows PHP Local File Inclusion.This issue affects Opigno module: from 0.0.0 before 3.1.2.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-96" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-09T20:15:35Z" diff --git a/advisories/unreviewed/2025/01/GHSA-9j33-5mgw-847x/GHSA-9j33-5mgw-847x.json b/advisories/unreviewed/2025/01/GHSA-9j33-5mgw-847x/GHSA-9j33-5mgw-847x.json index 23cdd2a7516..348318cbd6c 100644 --- a/advisories/unreviewed/2025/01/GHSA-9j33-5mgw-847x/GHSA-9j33-5mgw-847x.json +++ b/advisories/unreviewed/2025/01/GHSA-9j33-5mgw-847x/GHSA-9j33-5mgw-847x.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9j33-5mgw-847x", - "modified": "2025-01-09T21:31:32Z", + "modified": "2025-01-10T18:31:40Z", "published": "2025-01-09T21:31:32Z", "aliases": [ "CVE-2024-13305" ], "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Entity Form Steps allows Cross-Site Scripting (XSS).This issue affects Entity Form Steps: from 0.0.0 before 1.1.4.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-09T21:15:28Z" diff --git a/advisories/unreviewed/2025/01/GHSA-9j66-pm9j-3fvj/GHSA-9j66-pm9j-3fvj.json b/advisories/unreviewed/2025/01/GHSA-9j66-pm9j-3fvj/GHSA-9j66-pm9j-3fvj.json index 28739bbb750..9491fa2e8d9 100644 --- a/advisories/unreviewed/2025/01/GHSA-9j66-pm9j-3fvj/GHSA-9j66-pm9j-3fvj.json +++ b/advisories/unreviewed/2025/01/GHSA-9j66-pm9j-3fvj/GHSA-9j66-pm9j-3fvj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9j66-pm9j-3fvj", - "modified": "2025-01-09T21:31:32Z", + "modified": "2025-01-10T18:31:40Z", "published": "2025-01-09T21:31:32Z", "aliases": [ "CVE-2024-13302" ], "details": "Incorrect Authorization vulnerability in Drupal Pages Restriction Access allows Forceful Browsing.This issue affects Pages Restriction Access: from 2.0.0 before 2.0.3.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-863" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-09T21:15:28Z" diff --git a/advisories/unreviewed/2025/01/GHSA-9q24-c9h6-h244/GHSA-9q24-c9h6-h244.json b/advisories/unreviewed/2025/01/GHSA-9q24-c9h6-h244/GHSA-9q24-c9h6-h244.json index 08c7456a23b..40f9b55bd72 100644 --- a/advisories/unreviewed/2025/01/GHSA-9q24-c9h6-h244/GHSA-9q24-c9h6-h244.json +++ b/advisories/unreviewed/2025/01/GHSA-9q24-c9h6-h244/GHSA-9q24-c9h6-h244.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9q24-c9h6-h244", - "modified": "2025-01-09T21:31:31Z", + "modified": "2025-01-10T18:31:40Z", "published": "2025-01-09T21:31:31Z", "aliases": [ "CVE-2024-13280" ], "details": "Insufficient Session Expiration vulnerability in Drupal Persistent Login allows Forceful Browsing.This issue affects Persistent Login: from 0.0.0 before 1.8.0, from 2.0.* before 2.2.2.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-613" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-09T20:15:36Z" diff --git a/advisories/unreviewed/2025/01/GHSA-c4hf-853m-qmw7/GHSA-c4hf-853m-qmw7.json b/advisories/unreviewed/2025/01/GHSA-c4hf-853m-qmw7/GHSA-c4hf-853m-qmw7.json new file mode 100644 index 00000000000..5681f869a98 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-c4hf-853m-qmw7/GHSA-c4hf-853m-qmw7.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c4hf-853m-qmw7", + "modified": "2025-01-10T18:31:41Z", + "published": "2025-01-10T18:31:41Z", + "aliases": [ + "CVE-2024-6662" + ], + "details": "Websites managed by MegaBIP in versions below 5.15 are vulnerable to Cross-Site Request Forgery (CSRF) as the form available under \"/edytor/index.php?id=7,7,0\" lacks protection mechanisms.\nA user could be tricked into visiting a malicious website, which would send POST request to this endpoint. If the victim is a logged in administrator, this could lead to creation of new accounts and granting of administrative permissions.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6662" + }, + { + "type": "WEB", + "url": "https://cert.pl/en/posts/2024/09/CVE-2024-6662" + }, + { + "type": "WEB", + "url": "https://megabip.pl" + }, + { + "type": "WEB", + "url": "https://www.gov.pl/web/cyfryzacja/rekomendacja-pelnomocnika-rzadu-ds-cyberbezpieczenstwa-dotyczaca-biuletynow-informacji-publicznej" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-10T18:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-cc53-v8jq-4w68/GHSA-cc53-v8jq-4w68.json b/advisories/unreviewed/2025/01/GHSA-cc53-v8jq-4w68/GHSA-cc53-v8jq-4w68.json new file mode 100644 index 00000000000..5d9d2c2cc2b --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-cc53-v8jq-4w68/GHSA-cc53-v8jq-4w68.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cc53-v8jq-4w68", + "modified": "2025-01-10T18:31:41Z", + "published": "2025-01-10T18:31:41Z", + "aliases": [ + "CVE-2024-46210" + ], + "details": "An arbitrary file upload vulnerability in the MediaPool module of Redaxo CMS v5.17.1 allows attackers to execute arbitrary code via uploading a crafted file.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46210" + }, + { + "type": "WEB", + "url": "https://gist.github.com/h4ckr4v3n/26eaa57d94f749b597ede8b404c234df" + }, + { + "type": "WEB", + "url": "https://github.com/h4ckr4v3n/research_redaxo_5_17_1.git" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-10T16:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-ch9r-7w7v-gg4p/GHSA-ch9r-7w7v-gg4p.json b/advisories/unreviewed/2025/01/GHSA-ch9r-7w7v-gg4p/GHSA-ch9r-7w7v-gg4p.json index a59e141f03c..afb8d6a5cff 100644 --- a/advisories/unreviewed/2025/01/GHSA-ch9r-7w7v-gg4p/GHSA-ch9r-7w7v-gg4p.json +++ b/advisories/unreviewed/2025/01/GHSA-ch9r-7w7v-gg4p/GHSA-ch9r-7w7v-gg4p.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-ch9r-7w7v-gg4p", - "modified": "2025-01-09T21:31:32Z", + "modified": "2025-01-10T18:31:40Z", "published": "2025-01-09T21:31:31Z", "aliases": [ "CVE-2024-13292" ], "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Tooltip allows Cross-Site Scripting (XSS).This issue affects Tooltip: from 0.0.0 before 1.1.2.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-09T21:15:26Z" diff --git a/advisories/unreviewed/2025/01/GHSA-cp64-2mhv-pqv9/GHSA-cp64-2mhv-pqv9.json b/advisories/unreviewed/2025/01/GHSA-cp64-2mhv-pqv9/GHSA-cp64-2mhv-pqv9.json new file mode 100644 index 00000000000..895fc6949e5 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-cp64-2mhv-pqv9/GHSA-cp64-2mhv-pqv9.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cp64-2mhv-pqv9", + "modified": "2025-01-10T18:31:41Z", + "published": "2025-01-10T18:31:41Z", + "aliases": [ + "CVE-2024-57226" + ], + "details": "Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the iface parameter in the vif_enable function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57226" + }, + { + "type": "WEB", + "url": "https://github.com/yanggao017/vuln/blob/main/Linksys/E7350/CI_2_vif_enable/README.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-10T18:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-f56q-8frx-6rwq/GHSA-f56q-8frx-6rwq.json b/advisories/unreviewed/2025/01/GHSA-f56q-8frx-6rwq/GHSA-f56q-8frx-6rwq.json index 4695cd32737..1cf02e3a4cd 100644 --- a/advisories/unreviewed/2025/01/GHSA-f56q-8frx-6rwq/GHSA-f56q-8frx-6rwq.json +++ b/advisories/unreviewed/2025/01/GHSA-f56q-8frx-6rwq/GHSA-f56q-8frx-6rwq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-f56q-8frx-6rwq", - "modified": "2025-01-09T21:31:32Z", + "modified": "2025-01-10T18:31:40Z", "published": "2025-01-09T21:31:32Z", "aliases": [ "CVE-2024-13303" ], "details": "Missing Authorization vulnerability in Drupal Download All Files allows Forceful Browsing.This issue affects Download All Files: from 0.0.0 before 2.0.2.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-862" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-09T21:15:28Z" diff --git a/advisories/unreviewed/2025/01/GHSA-f6c3-7j6r-gqx3/GHSA-f6c3-7j6r-gqx3.json b/advisories/unreviewed/2025/01/GHSA-f6c3-7j6r-gqx3/GHSA-f6c3-7j6r-gqx3.json index 3f62606aeee..f3daf487ce3 100644 --- a/advisories/unreviewed/2025/01/GHSA-f6c3-7j6r-gqx3/GHSA-f6c3-7j6r-gqx3.json +++ b/advisories/unreviewed/2025/01/GHSA-f6c3-7j6r-gqx3/GHSA-f6c3-7j6r-gqx3.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-f6r6-892j-cp9p/GHSA-f6r6-892j-cp9p.json b/advisories/unreviewed/2025/01/GHSA-f6r6-892j-cp9p/GHSA-f6r6-892j-cp9p.json index b88bf25c7f9..5cd60be1a21 100644 --- a/advisories/unreviewed/2025/01/GHSA-f6r6-892j-cp9p/GHSA-f6r6-892j-cp9p.json +++ b/advisories/unreviewed/2025/01/GHSA-f6r6-892j-cp9p/GHSA-f6r6-892j-cp9p.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-f6r6-892j-cp9p", - "modified": "2025-01-09T21:31:32Z", + "modified": "2025-01-10T18:31:40Z", "published": "2025-01-09T21:31:32Z", "aliases": [ "CVE-2024-13301" ], "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal OAuth & OpenID Connect Single Sign On – SSO (OAuth/OIDC Client) allows Cross-Site Scripting (XSS).This issue affects OAuth & OpenID Connect Single Sign On – SSO (OAuth/OIDC Client): from 3.0.0 before 3.44.0, from 4.0.0 before 4.0.19.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-09T21:15:28Z" diff --git a/advisories/unreviewed/2025/01/GHSA-f9mx-3gv3-xr48/GHSA-f9mx-3gv3-xr48.json b/advisories/unreviewed/2025/01/GHSA-f9mx-3gv3-xr48/GHSA-f9mx-3gv3-xr48.json new file mode 100644 index 00000000000..1bc093cf4cb --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-f9mx-3gv3-xr48/GHSA-f9mx-3gv3-xr48.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f9mx-3gv3-xr48", + "modified": "2025-01-10T18:31:41Z", + "published": "2025-01-10T18:31:41Z", + "aliases": [ + "CVE-2024-54849" + ], + "details": "An issue in CP Plus CP-VNR-3104 B3223P22C02424 allows attackers to obtain the second RSA private key and access sensitive data or execute a man-in-the-middle attack.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-15522" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54849" + }, + { + "type": "WEB", + "url": "https://payatu.com/blog/solving-the-problem-of-encrypted-firmware" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-10T17:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-fjgg-qw2x-496w/GHSA-fjgg-qw2x-496w.json b/advisories/unreviewed/2025/01/GHSA-fjgg-qw2x-496w/GHSA-fjgg-qw2x-496w.json index e8f3d530899..3fe958198ff 100644 --- a/advisories/unreviewed/2025/01/GHSA-fjgg-qw2x-496w/GHSA-fjgg-qw2x-496w.json +++ b/advisories/unreviewed/2025/01/GHSA-fjgg-qw2x-496w/GHSA-fjgg-qw2x-496w.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fjgg-qw2x-496w", - "modified": "2025-01-09T21:31:31Z", + "modified": "2025-01-10T18:31:40Z", "published": "2025-01-09T21:31:31Z", "aliases": [ "CVE-2024-13282" ], "details": "Incorrect Authorization vulnerability in Drupal Block permissions allows Forceful Browsing.This issue affects Block permissions: from 1.0.0 before 1.2.0.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-863" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-09T20:15:37Z" diff --git a/advisories/unreviewed/2025/01/GHSA-g6xh-8j45-qj24/GHSA-g6xh-8j45-qj24.json b/advisories/unreviewed/2025/01/GHSA-g6xh-8j45-qj24/GHSA-g6xh-8j45-qj24.json index 53317d68488..fff5527d366 100644 --- a/advisories/unreviewed/2025/01/GHSA-g6xh-8j45-qj24/GHSA-g6xh-8j45-qj24.json +++ b/advisories/unreviewed/2025/01/GHSA-g6xh-8j45-qj24/GHSA-g6xh-8j45-qj24.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-g6xh-8j45-qj24", - "modified": "2025-01-09T21:31:32Z", + "modified": "2025-01-10T18:31:40Z", "published": "2025-01-09T21:31:32Z", "aliases": [ "CVE-2024-13296" ], "details": "Deserialization of Untrusted Data vulnerability in Drupal Mailjet allows Object Injection.This issue affects Mailjet: from 0.0.0 before 4.0.1.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-502" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-09T21:15:27Z" diff --git a/advisories/unreviewed/2025/01/GHSA-gpg3-74g9-p8jj/GHSA-gpg3-74g9-p8jj.json b/advisories/unreviewed/2025/01/GHSA-gpg3-74g9-p8jj/GHSA-gpg3-74g9-p8jj.json index 3a67e7dc3f5..a6c57c2757b 100644 --- a/advisories/unreviewed/2025/01/GHSA-gpg3-74g9-p8jj/GHSA-gpg3-74g9-p8jj.json +++ b/advisories/unreviewed/2025/01/GHSA-gpg3-74g9-p8jj/GHSA-gpg3-74g9-p8jj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gpg3-74g9-p8jj", - "modified": "2025-01-10T00:30:36Z", + "modified": "2025-01-10T18:31:40Z", "published": "2025-01-10T00:30:36Z", "aliases": [ "CVE-2024-46464" ], "details": "In PRIMX ZED Enterprise up to 2024.3, technical files stored in local folders with common user access can be manipulated to render the host computer unavailable or to execute programs with an elevation of privilege.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-276" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-09T22:15:28Z" diff --git a/advisories/unreviewed/2025/01/GHSA-gqf5-wjqv-v83c/GHSA-gqf5-wjqv-v83c.json b/advisories/unreviewed/2025/01/GHSA-gqf5-wjqv-v83c/GHSA-gqf5-wjqv-v83c.json index 2909fe7ec30..8b63181a75f 100644 --- a/advisories/unreviewed/2025/01/GHSA-gqf5-wjqv-v83c/GHSA-gqf5-wjqv-v83c.json +++ b/advisories/unreviewed/2025/01/GHSA-gqf5-wjqv-v83c/GHSA-gqf5-wjqv-v83c.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gqf5-wjqv-v83c", - "modified": "2025-01-09T21:31:29Z", + "modified": "2025-01-10T18:31:39Z", "published": "2025-01-09T21:31:29Z", "aliases": [ "CVE-2024-13239" ], "details": "Weak Authentication vulnerability in Drupal Two-factor Authentication (TFA) allows Authentication Abuse.This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.5.0.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-1390" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-09T19:15:17Z" diff --git a/advisories/unreviewed/2025/01/GHSA-h469-6c92-pgvf/GHSA-h469-6c92-pgvf.json b/advisories/unreviewed/2025/01/GHSA-h469-6c92-pgvf/GHSA-h469-6c92-pgvf.json new file mode 100644 index 00000000000..495c7a4abbd --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-h469-6c92-pgvf/GHSA-h469-6c92-pgvf.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h469-6c92-pgvf", + "modified": "2025-01-10T18:31:41Z", + "published": "2025-01-10T18:31:41Z", + "aliases": [ + "CVE-2024-57225" + ], + "details": "Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the devname parameter in the reset_wifi function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57225" + }, + { + "type": "WEB", + "url": "https://github.com/yanggao017/vuln/blob/main/Linksys/E7350/CI_7_reset_wifi/README.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-10T18:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-h6w8-m65g-549g/GHSA-h6w8-m65g-549g.json b/advisories/unreviewed/2025/01/GHSA-h6w8-m65g-549g/GHSA-h6w8-m65g-549g.json index 0a0bf2214d6..a75ccb55545 100644 --- a/advisories/unreviewed/2025/01/GHSA-h6w8-m65g-549g/GHSA-h6w8-m65g-549g.json +++ b/advisories/unreviewed/2025/01/GHSA-h6w8-m65g-549g/GHSA-h6w8-m65g-549g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h6w8-m65g-549g", - "modified": "2025-01-09T21:31:31Z", + "modified": "2025-01-10T18:31:40Z", "published": "2025-01-09T21:31:31Z", "aliases": [ "CVE-2024-13279" ], "details": "Session Fixation vulnerability in Drupal Two-factor Authentication (TFA) allows Session Fixation.This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.8.0.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-384" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-09T20:15:36Z" diff --git a/advisories/unreviewed/2025/01/GHSA-h8j9-776h-g7wr/GHSA-h8j9-776h-g7wr.json b/advisories/unreviewed/2025/01/GHSA-h8j9-776h-g7wr/GHSA-h8j9-776h-g7wr.json index 3c582fa3fc1..f6cf323c290 100644 --- a/advisories/unreviewed/2025/01/GHSA-h8j9-776h-g7wr/GHSA-h8j9-776h-g7wr.json +++ b/advisories/unreviewed/2025/01/GHSA-h8j9-776h-g7wr/GHSA-h8j9-776h-g7wr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h8j9-776h-g7wr", - "modified": "2025-01-09T21:31:29Z", + "modified": "2025-01-10T18:31:39Z", "published": "2025-01-09T21:31:29Z", "aliases": [ "CVE-2024-13240" ], "details": "Improper Access Control vulnerability in Drupal Open Social allows Collect Data from Common Resource Locations.This issue affects Open Social: from 0.0.0 before 12.05.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-284" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-09T19:15:17Z" diff --git a/advisories/unreviewed/2025/01/GHSA-hpr9-7q5c-v2vc/GHSA-hpr9-7q5c-v2vc.json b/advisories/unreviewed/2025/01/GHSA-hpr9-7q5c-v2vc/GHSA-hpr9-7q5c-v2vc.json new file mode 100644 index 00000000000..d2c67fd95e7 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-hpr9-7q5c-v2vc/GHSA-hpr9-7q5c-v2vc.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hpr9-7q5c-v2vc", + "modified": "2025-01-10T18:31:41Z", + "published": "2025-01-10T18:31:41Z", + "aliases": [ + "CVE-2024-57228" + ], + "details": "Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the iface parameter in the vif_disable function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57228" + }, + { + "type": "WEB", + "url": "https://github.com/yanggao017/vuln/blob/main/Linksys/E7350/CI_1_vif_disable/README.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-10T18:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-hqjc-qgf5-4m63/GHSA-hqjc-qgf5-4m63.json b/advisories/unreviewed/2025/01/GHSA-hqjc-qgf5-4m63/GHSA-hqjc-qgf5-4m63.json index 35703475fb8..f31d66aa607 100644 --- a/advisories/unreviewed/2025/01/GHSA-hqjc-qgf5-4m63/GHSA-hqjc-qgf5-4m63.json +++ b/advisories/unreviewed/2025/01/GHSA-hqjc-qgf5-4m63/GHSA-hqjc-qgf5-4m63.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hqjc-qgf5-4m63", - "modified": "2025-01-09T21:31:29Z", + "modified": "2025-01-10T18:31:39Z", "published": "2025-01-09T21:31:29Z", "aliases": [ "CVE-2024-13242" ], "details": "Exposed Dangerous Method or Function vulnerability in Drupal Swift Mailer allows Resource Location Spoofing.This issue affects Swift Mailer: *.*.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-749" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-09T19:15:18Z" diff --git a/advisories/unreviewed/2025/01/GHSA-hw79-cp29-3x6c/GHSA-hw79-cp29-3x6c.json b/advisories/unreviewed/2025/01/GHSA-hw79-cp29-3x6c/GHSA-hw79-cp29-3x6c.json new file mode 100644 index 00000000000..199f4cc1ddb --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-hw79-cp29-3x6c/GHSA-hw79-cp29-3x6c.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hw79-cp29-3x6c", + "modified": "2025-01-10T18:31:41Z", + "published": "2025-01-10T18:31:41Z", + "aliases": [ + "CVE-2025-22949" + ], + "details": "Tenda ac9 v1.0 firmware v15.03.05.19 is vulnerable to command injection in /goform/SetSambaCfg, which may lead to remote arbitrary code execution.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22949" + }, + { + "type": "WEB", + "url": "https://noisy-caravel-a9a.notion.site/Tenda_AC9V1-0_V15-03-05-19_formSetSambaConf_doSystemCmd_CI-16f898c94eac80d5801bdaf777ac2b27" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-10T16:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-hwc6-hhj2-hp24/GHSA-hwc6-hhj2-hp24.json b/advisories/unreviewed/2025/01/GHSA-hwc6-hhj2-hp24/GHSA-hwc6-hhj2-hp24.json index bf8e1036c41..f2934b08548 100644 --- a/advisories/unreviewed/2025/01/GHSA-hwc6-hhj2-hp24/GHSA-hwc6-hhj2-hp24.json +++ b/advisories/unreviewed/2025/01/GHSA-hwc6-hhj2-hp24/GHSA-hwc6-hhj2-hp24.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hwc6-hhj2-hp24", - "modified": "2025-01-09T21:31:31Z", + "modified": "2025-01-10T18:31:40Z", "published": "2025-01-09T21:31:31Z", "aliases": [ "CVE-2024-13286" ], "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal SVG Embed allows Cross-Site Scripting (XSS).This issue affects SVG Embed: from 0.0.0 before 2.1.2.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-09T20:15:37Z" diff --git a/advisories/unreviewed/2025/01/GHSA-hwhf-72f8-crgh/GHSA-hwhf-72f8-crgh.json b/advisories/unreviewed/2025/01/GHSA-hwhf-72f8-crgh/GHSA-hwhf-72f8-crgh.json index 268a81a7a56..00c842010cc 100644 --- a/advisories/unreviewed/2025/01/GHSA-hwhf-72f8-crgh/GHSA-hwhf-72f8-crgh.json +++ b/advisories/unreviewed/2025/01/GHSA-hwhf-72f8-crgh/GHSA-hwhf-72f8-crgh.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-126" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2025/01/GHSA-j6c4-8pwx-h3g3/GHSA-j6c4-8pwx-h3g3.json b/advisories/unreviewed/2025/01/GHSA-j6c4-8pwx-h3g3/GHSA-j6c4-8pwx-h3g3.json index c2c96944db6..537b62eab9e 100644 --- a/advisories/unreviewed/2025/01/GHSA-j6c4-8pwx-h3g3/GHSA-j6c4-8pwx-h3g3.json +++ b/advisories/unreviewed/2025/01/GHSA-j6c4-8pwx-h3g3/GHSA-j6c4-8pwx-h3g3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-j6c4-8pwx-h3g3", - "modified": "2025-01-09T21:31:30Z", + "modified": "2025-01-10T18:31:39Z", "published": "2025-01-09T21:31:30Z", "aliases": [ "CVE-2024-13244" ], "details": "Cross-Site Request Forgery (CSRF) vulnerability in Drupal Migrate Tools allows Cross Site Request Forgery.This issue affects Migrate Tools: from 0.0.0 before 6.0.3.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-352" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-09T19:15:18Z" diff --git a/advisories/unreviewed/2025/01/GHSA-jf66-v4fg-qpqx/GHSA-jf66-v4fg-qpqx.json b/advisories/unreviewed/2025/01/GHSA-jf66-v4fg-qpqx/GHSA-jf66-v4fg-qpqx.json index 4f816f9deb8..4dc3b6a141d 100644 --- a/advisories/unreviewed/2025/01/GHSA-jf66-v4fg-qpqx/GHSA-jf66-v4fg-qpqx.json +++ b/advisories/unreviewed/2025/01/GHSA-jf66-v4fg-qpqx/GHSA-jf66-v4fg-qpqx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jf66-v4fg-qpqx", - "modified": "2025-01-09T21:31:30Z", + "modified": "2025-01-10T18:31:39Z", "published": "2025-01-09T21:31:30Z", "aliases": [ "CVE-2024-13255" ], "details": "Exposure of Sensitive Information Through Data Queries vulnerability in Drupal RESTful Web Services allows Forceful Browsing.This issue affects RESTful Web Services: from 7.X-2.0 before 7.X-2.10.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-202" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-09T19:15:19Z" diff --git a/advisories/unreviewed/2025/01/GHSA-jffw-3h47-42r7/GHSA-jffw-3h47-42r7.json b/advisories/unreviewed/2025/01/GHSA-jffw-3h47-42r7/GHSA-jffw-3h47-42r7.json index b53d65609ff..d15da3e6255 100644 --- a/advisories/unreviewed/2025/01/GHSA-jffw-3h47-42r7/GHSA-jffw-3h47-42r7.json +++ b/advisories/unreviewed/2025/01/GHSA-jffw-3h47-42r7/GHSA-jffw-3h47-42r7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jffw-3h47-42r7", - "modified": "2025-01-09T21:31:31Z", + "modified": "2025-01-10T18:31:40Z", "published": "2025-01-09T21:31:31Z", "aliases": [ "CVE-2024-54762" ], "details": "Ruoyi v.4.7.9 and before contains an authenticated SQL injection vulnerability. This is because the filterKeyword method does not completely filter SQL injection keywords, resulting in the risk of SQL injection.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-09T20:15:39Z" diff --git a/advisories/unreviewed/2025/01/GHSA-jfhf-w467-c85w/GHSA-jfhf-w467-c85w.json b/advisories/unreviewed/2025/01/GHSA-jfhf-w467-c85w/GHSA-jfhf-w467-c85w.json new file mode 100644 index 00000000000..2cd014b9dd5 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-jfhf-w467-c85w/GHSA-jfhf-w467-c85w.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jfhf-w467-c85w", + "modified": "2025-01-10T18:31:41Z", + "published": "2025-01-10T18:31:41Z", + "aliases": [ + "CVE-2024-50807" + ], + "details": "Trippo Responsive Filemanager 9.14.0 is vulnerable to Cross Site Scripting (XSS) via file upload using the svg and pdf extensions.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50807" + }, + { + "type": "WEB", + "url": "https://gist.github.com/HackShiv/4254db89214913867aa8dd5c1ec09b7e" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-10T16:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-m53w-jm38-mh7q/GHSA-m53w-jm38-mh7q.json b/advisories/unreviewed/2025/01/GHSA-m53w-jm38-mh7q/GHSA-m53w-jm38-mh7q.json index b20c5c76661..ff493ea7433 100644 --- a/advisories/unreviewed/2025/01/GHSA-m53w-jm38-mh7q/GHSA-m53w-jm38-mh7q.json +++ b/advisories/unreviewed/2025/01/GHSA-m53w-jm38-mh7q/GHSA-m53w-jm38-mh7q.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-m53w-jm38-mh7q", - "modified": "2025-01-09T21:31:30Z", + "modified": "2025-01-10T18:31:39Z", "published": "2025-01-09T21:31:30Z", "aliases": [ "CVE-2024-13243" ], "details": "Missing Authorization vulnerability in Drupal Entity Delete Log allows Forceful Browsing.This issue affects Entity Delete Log: from 0.0.0 before 1.1.1.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-862" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-09T19:15:18Z" diff --git a/advisories/unreviewed/2025/01/GHSA-m7p9-xw5x-w2c4/GHSA-m7p9-xw5x-w2c4.json b/advisories/unreviewed/2025/01/GHSA-m7p9-xw5x-w2c4/GHSA-m7p9-xw5x-w2c4.json index a320d8712e7..ceb20ae706d 100644 --- a/advisories/unreviewed/2025/01/GHSA-m7p9-xw5x-w2c4/GHSA-m7p9-xw5x-w2c4.json +++ b/advisories/unreviewed/2025/01/GHSA-m7p9-xw5x-w2c4/GHSA-m7p9-xw5x-w2c4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-m7p9-xw5x-w2c4", - "modified": "2025-01-08T18:30:48Z", + "modified": "2025-01-10T18:31:39Z", "published": "2025-01-08T18:30:48Z", "aliases": [ "CVE-2024-56770" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: netem: account for backlog updates from child qdisc\n\nIn general, 'qlen' of any classful qdisc should keep track of the\nnumber of packets that the qdisc itself and all of its children holds.\nIn case of netem, 'qlen' only accounts for the packets in its internal\ntfifo. When netem is used with a child qdisc, the child qdisc can use\n'qdisc_tree_reduce_backlog' to inform its parent, netem, about created\nor dropped SKBs. This function updates 'qlen' and the backlog statistics\nof netem, but netem does not account for changes made by a child qdisc.\n'qlen' then indicates the wrong number of packets in the tfifo.\nIf a child qdisc creates new SKBs during enqueue and informs its parent\nabout this, netem's 'qlen' value is increased. When netem dequeues the\nnewly created SKBs from the child, the 'qlen' in netem is not updated.\nIf 'qlen' reaches the configured sch->limit, the enqueue function stops\nworking, even though the tfifo is not full.\n\nReproduce the bug:\nEnsure that the sender machine has GSO enabled. Configure netem as root\nqdisc and tbf as its child on the outgoing interface of the machine\nas follows:\n$ tc qdisc add dev root handle 1: netem delay 100ms limit 100\n$ tc qdisc add dev parent 1:0 tbf rate 50Mbit burst 1542 latency 50ms\n\nSend bulk TCP traffic out via this interface, e.g., by running an iPerf3\nclient on the machine. Check the qdisc statistics:\n$ tc -s qdisc show dev \n\nStatistics after 10s of iPerf3 TCP test before the fix (note that\nnetem's backlog > limit, netem stopped accepting packets):\nqdisc netem 1: root refcnt 2 limit 1000 delay 100ms\n Sent 2767766 bytes 1848 pkt (dropped 652, overlimits 0 requeues 0)\n backlog 4294528236b 1155p requeues 0\nqdisc tbf 10: parent 1:1 rate 50Mbit burst 1537b lat 50ms\n Sent 2767766 bytes 1848 pkt (dropped 327, overlimits 7601 requeues 0)\n backlog 0b 0p requeues 0\n\nStatistics after the fix:\nqdisc netem 1: root refcnt 2 limit 1000 delay 100ms\n Sent 37766372 bytes 24974 pkt (dropped 9, overlimits 0 requeues 0)\n backlog 0b 0p requeues 0\nqdisc tbf 10: parent 1:1 rate 50Mbit burst 1537b lat 50ms\n Sent 37766372 bytes 24974 pkt (dropped 327, overlimits 96017 requeues 0)\n backlog 0b 0p requeues 0\n\ntbf segments the GSO SKBs (tbf_segment) and updates the netem's 'qlen'.\nThe interface fully stops transferring packets and \"locks\". In this case,\nthe child qdisc and tfifo are empty, but 'qlen' indicates the tfifo is at\nits limit and no more packets are accepted.\n\nThis patch adds a counter for the entries in the tfifo. Netem's 'qlen' is\nonly decreased when a packet is returned by its dequeue function, and not\nduring enqueuing into the child qdisc. External updates to 'qlen' are thus\naccounted for and only the behavior of the backlog statistics changes. As\nin other qdiscs, 'qlen' then keeps track of how many packets are held in\nnetem and all of its children. As before, sch->limit remains as the\nmaximum number of packets in the tfifo. The same applies to netem's\nbacklog statistics.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -45,7 +50,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-08T17:15:15Z" diff --git a/advisories/unreviewed/2025/01/GHSA-m8wx-qw6g-2vhr/GHSA-m8wx-qw6g-2vhr.json b/advisories/unreviewed/2025/01/GHSA-m8wx-qw6g-2vhr/GHSA-m8wx-qw6g-2vhr.json index 558eddf0a80..b5aa81baf58 100644 --- a/advisories/unreviewed/2025/01/GHSA-m8wx-qw6g-2vhr/GHSA-m8wx-qw6g-2vhr.json +++ b/advisories/unreviewed/2025/01/GHSA-m8wx-qw6g-2vhr/GHSA-m8wx-qw6g-2vhr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-m8wx-qw6g-2vhr", - "modified": "2025-01-09T21:31:31Z", + "modified": "2025-01-10T18:31:40Z", "published": "2025-01-09T21:31:31Z", "aliases": [ "CVE-2024-13277" ], "details": "Incorrect Authorization vulnerability in Drupal Smart IP Ban allows Forceful Browsing.This issue affects Smart IP Ban: from 7.X-1.0 before 7.X-1.1.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-863" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-09T20:15:36Z" diff --git a/advisories/unreviewed/2025/01/GHSA-mmx8-rpcx-mqx8/GHSA-mmx8-rpcx-mqx8.json b/advisories/unreviewed/2025/01/GHSA-mmx8-rpcx-mqx8/GHSA-mmx8-rpcx-mqx8.json new file mode 100644 index 00000000000..d536280fbfd --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-mmx8-rpcx-mqx8/GHSA-mmx8-rpcx-mqx8.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mmx8-rpcx-mqx8", + "modified": "2025-01-10T18:31:41Z", + "published": "2025-01-10T18:31:41Z", + "aliases": [ + "CVE-2024-57227" + ], + "details": "Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apcli_do_enr_pbc_wps function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57227" + }, + { + "type": "WEB", + "url": "https://github.com/yanggao017/vuln/blob/main/Linksys/E7350/CI_4_apcli_do_enr_pbc_wps/README.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-10T18:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-p3jr-34v8-m9x2/GHSA-p3jr-34v8-m9x2.json b/advisories/unreviewed/2025/01/GHSA-p3jr-34v8-m9x2/GHSA-p3jr-34v8-m9x2.json index ad47888effd..cf3324ff7fa 100644 --- a/advisories/unreviewed/2025/01/GHSA-p3jr-34v8-m9x2/GHSA-p3jr-34v8-m9x2.json +++ b/advisories/unreviewed/2025/01/GHSA-p3jr-34v8-m9x2/GHSA-p3jr-34v8-m9x2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p3jr-34v8-m9x2", - "modified": "2025-01-09T21:31:31Z", + "modified": "2025-01-10T18:31:39Z", "published": "2025-01-09T21:31:31Z", "aliases": [ "CVE-2024-13260" ], "details": "Cross-Site Request Forgery (CSRF) vulnerability in Drupal Migrate queue importer allows Cross Site Request Forgery.This issue affects Migrate queue importer: from 0.0.0 before 2.1.1.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-352" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-09T20:15:34Z" diff --git a/advisories/unreviewed/2025/01/GHSA-ph42-w6gw-p84w/GHSA-ph42-w6gw-p84w.json b/advisories/unreviewed/2025/01/GHSA-ph42-w6gw-p84w/GHSA-ph42-w6gw-p84w.json index dc1b983acf0..2751afc9622 100644 --- a/advisories/unreviewed/2025/01/GHSA-ph42-w6gw-p84w/GHSA-ph42-w6gw-p84w.json +++ b/advisories/unreviewed/2025/01/GHSA-ph42-w6gw-p84w/GHSA-ph42-w6gw-p84w.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-ph42-w6gw-p84w", - "modified": "2025-01-10T00:30:36Z", + "modified": "2025-01-10T18:31:40Z", "published": "2025-01-10T00:30:36Z", "aliases": [ "CVE-2023-28354" ], "details": "An issue was discovered in Opsview Monitor Agent 6.8. An unauthenticated remote attacker can call check_nrpe against affected targets, specifying known NRPE plugins, which in default installations are configured to accept command control characters and pass them to command-line interpreters for NRPE plugin execution. This allows the attacker to escape NRPE plugin execution and execute commands remotely on the target as NT_AUTHORITY\\SYSTEM.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-09T22:15:26Z" diff --git a/advisories/unreviewed/2025/01/GHSA-pm3j-6f7c-8v2q/GHSA-pm3j-6f7c-8v2q.json b/advisories/unreviewed/2025/01/GHSA-pm3j-6f7c-8v2q/GHSA-pm3j-6f7c-8v2q.json new file mode 100644 index 00000000000..0c2ea6a50fc --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-pm3j-6f7c-8v2q/GHSA-pm3j-6f7c-8v2q.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pm3j-6f7c-8v2q", + "modified": "2025-01-10T18:31:41Z", + "published": "2025-01-10T18:31:41Z", + "aliases": [ + "CVE-2024-54848" + ], + "details": "Improper handling and storage of certificates in CP Plus CP-VNR-3104 B3223P22C02424 allow attackers to decrypt communications or execute a man-in-the-middle attacks.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-21551" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54848" + }, + { + "type": "WEB", + "url": "https://capec.mitre.org/data/definitions/233" + }, + { + "type": "WEB", + "url": "https://github.com/Yashodhanvivek/CP-VNR-3104-NVR-Vulnerabilties/blob/main/CPPlus_CP-VNR-3104_Security_Assessment.pdf" + }, + { + "type": "WEB", + "url": "https://payatu.com/blog/solving-the-problem-of-encrypted-firmware" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-10T17:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-pwgw-g9f5-ghw2/GHSA-pwgw-g9f5-ghw2.json b/advisories/unreviewed/2025/01/GHSA-pwgw-g9f5-ghw2/GHSA-pwgw-g9f5-ghw2.json index 982994fae57..b1e6f91d72f 100644 --- a/advisories/unreviewed/2025/01/GHSA-pwgw-g9f5-ghw2/GHSA-pwgw-g9f5-ghw2.json +++ b/advisories/unreviewed/2025/01/GHSA-pwgw-g9f5-ghw2/GHSA-pwgw-g9f5-ghw2.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-qffj-hqp2-qrxm/GHSA-qffj-hqp2-qrxm.json b/advisories/unreviewed/2025/01/GHSA-qffj-hqp2-qrxm/GHSA-qffj-hqp2-qrxm.json index 9bae9834b2e..7698e64bdda 100644 --- a/advisories/unreviewed/2025/01/GHSA-qffj-hqp2-qrxm/GHSA-qffj-hqp2-qrxm.json +++ b/advisories/unreviewed/2025/01/GHSA-qffj-hqp2-qrxm/GHSA-qffj-hqp2-qrxm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qffj-hqp2-qrxm", - "modified": "2025-01-09T21:31:30Z", + "modified": "2025-01-10T18:31:39Z", "published": "2025-01-09T21:31:30Z", "aliases": [ "CVE-2024-13259" ], "details": "Insertion of Sensitive Information Into Sent Data vulnerability in Drupal Image Sizes allows Forceful Browsing.This issue affects Image Sizes: from 0.0.0 before 3.0.2.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-201" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-09T19:15:19Z" diff --git a/advisories/unreviewed/2025/01/GHSA-r79f-v7w7-jv39/GHSA-r79f-v7w7-jv39.json b/advisories/unreviewed/2025/01/GHSA-r79f-v7w7-jv39/GHSA-r79f-v7w7-jv39.json new file mode 100644 index 00000000000..7b624f46d53 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-r79f-v7w7-jv39/GHSA-r79f-v7w7-jv39.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r79f-v7w7-jv39", + "modified": "2025-01-10T18:31:41Z", + "published": "2025-01-10T18:31:41Z", + "aliases": [ + "CVE-2024-57214" + ], + "details": "TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the devname parameter in the reset_wifi function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57214" + }, + { + "type": "WEB", + "url": "https://github.com/yanggao017/vuln/tree/main/TOTOLINK/A6000R/CI_8_reset_wifi" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-10T17:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-rj9h-wxr6-mwg8/GHSA-rj9h-wxr6-mwg8.json b/advisories/unreviewed/2025/01/GHSA-rj9h-wxr6-mwg8/GHSA-rj9h-wxr6-mwg8.json index 396d14c20bb..beed5755886 100644 --- a/advisories/unreviewed/2025/01/GHSA-rj9h-wxr6-mwg8/GHSA-rj9h-wxr6-mwg8.json +++ b/advisories/unreviewed/2025/01/GHSA-rj9h-wxr6-mwg8/GHSA-rj9h-wxr6-mwg8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rj9h-wxr6-mwg8", - "modified": "2025-01-09T21:31:32Z", + "modified": "2025-01-10T18:31:40Z", "published": "2025-01-09T21:31:32Z", "aliases": [ "CVE-2024-13297" ], "details": "Deserialization of Untrusted Data vulnerability in Drupal Eloqua allows Object Injection.This issue affects Eloqua: from 7.X-* before 7.X-1.15.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-502" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-09T21:15:27Z" diff --git a/advisories/unreviewed/2025/01/GHSA-rjpg-qpwf-xp3r/GHSA-rjpg-qpwf-xp3r.json b/advisories/unreviewed/2025/01/GHSA-rjpg-qpwf-xp3r/GHSA-rjpg-qpwf-xp3r.json index 9ba3c0475f3..d7f8291d7b2 100644 --- a/advisories/unreviewed/2025/01/GHSA-rjpg-qpwf-xp3r/GHSA-rjpg-qpwf-xp3r.json +++ b/advisories/unreviewed/2025/01/GHSA-rjpg-qpwf-xp3r/GHSA-rjpg-qpwf-xp3r.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-787", "CWE-823" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2025/01/GHSA-vpg3-wxv6-fm2j/GHSA-vpg3-wxv6-fm2j.json b/advisories/unreviewed/2025/01/GHSA-vpg3-wxv6-fm2j/GHSA-vpg3-wxv6-fm2j.json index d569336d68f..a2b6d4a302e 100644 --- a/advisories/unreviewed/2025/01/GHSA-vpg3-wxv6-fm2j/GHSA-vpg3-wxv6-fm2j.json +++ b/advisories/unreviewed/2025/01/GHSA-vpg3-wxv6-fm2j/GHSA-vpg3-wxv6-fm2j.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-126" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2025/01/GHSA-vqg8-4hg9-xrq5/GHSA-vqg8-4hg9-xrq5.json b/advisories/unreviewed/2025/01/GHSA-vqg8-4hg9-xrq5/GHSA-vqg8-4hg9-xrq5.json new file mode 100644 index 00000000000..c7a87a546a4 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-vqg8-4hg9-xrq5/GHSA-vqg8-4hg9-xrq5.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vqg8-4hg9-xrq5", + "modified": "2025-01-10T18:31:41Z", + "published": "2025-01-10T18:31:41Z", + "aliases": [ + "CVE-2024-57213" + ], + "details": "TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the newpasswd parameter in the action_passwd function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57213" + }, + { + "type": "WEB", + "url": "https://github.com/yanggao017/vuln/blob/main/TOTOLINK/A6000R/CI_9_action_passwd/README.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-10T17:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-vw53-vc7r-68m2/GHSA-vw53-vc7r-68m2.json b/advisories/unreviewed/2025/01/GHSA-vw53-vc7r-68m2/GHSA-vw53-vc7r-68m2.json index 1ac74c81526..e21ee219e63 100644 --- a/advisories/unreviewed/2025/01/GHSA-vw53-vc7r-68m2/GHSA-vw53-vc7r-68m2.json +++ b/advisories/unreviewed/2025/01/GHSA-vw53-vc7r-68m2/GHSA-vw53-vc7r-68m2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vw53-vc7r-68m2", - "modified": "2025-01-09T21:31:32Z", + "modified": "2025-01-10T18:31:40Z", "published": "2025-01-09T21:31:32Z", "aliases": [ "CVE-2024-13298" ], "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Tarte au Citron allows Cross-Site Scripting (XSS).This issue affects Tarte au Citron: from 2.0.0 before 2.0.5.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-09T21:15:27Z" diff --git a/advisories/unreviewed/2025/01/GHSA-w3q9-jjpq-m527/GHSA-w3q9-jjpq-m527.json b/advisories/unreviewed/2025/01/GHSA-w3q9-jjpq-m527/GHSA-w3q9-jjpq-m527.json index dc48b4bbb11..f1c64f90c4f 100644 --- a/advisories/unreviewed/2025/01/GHSA-w3q9-jjpq-m527/GHSA-w3q9-jjpq-m527.json +++ b/advisories/unreviewed/2025/01/GHSA-w3q9-jjpq-m527/GHSA-w3q9-jjpq-m527.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-w3q9-jjpq-m527", - "modified": "2025-01-09T21:31:30Z", + "modified": "2025-01-10T18:31:39Z", "published": "2025-01-09T21:31:30Z", "aliases": [ "CVE-2024-13251" ], "details": "Incorrect Privilege Assignment vulnerability in Drupal Registration role allows Privilege Escalation.This issue affects Registration role: from 0.0.0 before 2.0.1.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-266" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-09T19:15:19Z" diff --git a/advisories/unreviewed/2025/01/GHSA-w5c9-x85v-xrxm/GHSA-w5c9-x85v-xrxm.json b/advisories/unreviewed/2025/01/GHSA-w5c9-x85v-xrxm/GHSA-w5c9-x85v-xrxm.json index d22940d621a..3ceae937b6a 100644 --- a/advisories/unreviewed/2025/01/GHSA-w5c9-x85v-xrxm/GHSA-w5c9-x85v-xrxm.json +++ b/advisories/unreviewed/2025/01/GHSA-w5c9-x85v-xrxm/GHSA-w5c9-x85v-xrxm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-w5c9-x85v-xrxm", - "modified": "2025-01-08T18:30:48Z", + "modified": "2025-01-10T18:31:39Z", "published": "2025-01-08T18:30:48Z", "aliases": [ "CVE-2024-56771" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmtd: spinand: winbond: Fix 512GW, 01GW, 01JW and 02JW ECC information\n\nThese four chips:\n* W25N512GW\n* W25N01GW\n* W25N01JW\n* W25N02JW\nall require a single bit of ECC strength and thus feature an on-die\nHamming-like ECC engine. There is no point in filling a ->get_status()\ncallback for them because the main ECC status bytes are located in\nstandard places, and retrieving the number of bitflips in case of\ncorrected chunk is both useless and unsupported (if there are bitflips,\nthen there is 1 at most, so no need to query the chip for that).\n\nWithout this change, a kernel warning triggers every time a bit flips.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -25,7 +30,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-08T18:15:17Z" diff --git a/advisories/unreviewed/2025/01/GHSA-w5hh-gh28-cppg/GHSA-w5hh-gh28-cppg.json b/advisories/unreviewed/2025/01/GHSA-w5hh-gh28-cppg/GHSA-w5hh-gh28-cppg.json new file mode 100644 index 00000000000..122b6b96b59 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-w5hh-gh28-cppg/GHSA-w5hh-gh28-cppg.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w5hh-gh28-cppg", + "modified": "2025-01-10T18:31:41Z", + "published": "2025-01-10T18:31:41Z", + "aliases": [ + "CVE-2024-6880" + ], + "details": "During MegaBIP installation process, a user is encouraged to change a default path to administrative portal, as keeping it secret is listed by the author as one of the protection mechanisms. \nPublicly available source code of \"/registered.php\" discloses that path, allowing an attacker to attempt further attacks.  \n\nThis issue affects MegaBIP software versions below 5.15", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6880" + }, + { + "type": "WEB", + "url": "https://cert.pl/en/posts/2024/09/CVE-2024-6680" + }, + { + "type": "WEB", + "url": "https://megabip.pl" + }, + { + "type": "WEB", + "url": "https://www.gov.pl/web/cyfryzacja/rekomendacja-pelnomocnika-rzadu-ds-cyberbezpieczenstwa-dotyczaca-biuletynow-informacji-publicznej" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-538" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-10T18:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-wj4g-3v6m-x76m/GHSA-wj4g-3v6m-x76m.json b/advisories/unreviewed/2025/01/GHSA-wj4g-3v6m-x76m/GHSA-wj4g-3v6m-x76m.json new file mode 100644 index 00000000000..62cde0ae43a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-wj4g-3v6m-x76m/GHSA-wj4g-3v6m-x76m.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wj4g-3v6m-x76m", + "modified": "2025-01-10T18:31:41Z", + "published": "2025-01-10T18:31:41Z", + "aliases": [ + "CVE-2024-25371" + ], + "details": "Gramine before a390e33e16ed374a40de2344562a937f289be2e1 suffers from an Interface vulnerability due to mismatching SW signals vs HW exceptions.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25371" + }, + { + "type": "WEB", + "url": "https://github.com/gramineproject/gramine/commit/a390e33e16ed374a40de2344562a937f289be2e1" + }, + { + "type": "WEB", + "url": "https://github.com/ahoi-attacks/sigy/blob/main/pocs/gramine/cve.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-10T16:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-wjhm-v52r-7x9g/GHSA-wjhm-v52r-7x9g.json b/advisories/unreviewed/2025/01/GHSA-wjhm-v52r-7x9g/GHSA-wjhm-v52r-7x9g.json index 58e61ed0dc1..c0d1e5a6658 100644 --- a/advisories/unreviewed/2025/01/GHSA-wjhm-v52r-7x9g/GHSA-wjhm-v52r-7x9g.json +++ b/advisories/unreviewed/2025/01/GHSA-wjhm-v52r-7x9g/GHSA-wjhm-v52r-7x9g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wjhm-v52r-7x9g", - "modified": "2025-01-09T21:31:30Z", + "modified": "2025-01-10T18:31:39Z", "published": "2025-01-09T21:31:30Z", "aliases": [ "CVE-2024-13254" ], "details": "Insertion of Sensitive Information Into Sent Data vulnerability in Drupal REST Views allows Forceful Browsing.This issue affects REST Views: from 0.0.0 before 3.0.1.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-201" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-09T19:15:19Z" diff --git a/advisories/unreviewed/2025/01/GHSA-x58x-7p55-7r3g/GHSA-x58x-7p55-7r3g.json b/advisories/unreviewed/2025/01/GHSA-x58x-7p55-7r3g/GHSA-x58x-7p55-7r3g.json index e5f07e12ea9..09ec7739bdb 100644 --- a/advisories/unreviewed/2025/01/GHSA-x58x-7p55-7r3g/GHSA-x58x-7p55-7r3g.json +++ b/advisories/unreviewed/2025/01/GHSA-x58x-7p55-7r3g/GHSA-x58x-7p55-7r3g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x58x-7p55-7r3g", - "modified": "2025-01-10T15:31:34Z", + "modified": "2025-01-10T18:31:40Z", "published": "2025-01-10T15:31:34Z", "aliases": [ "CVE-2024-57687" ], "details": "An OS Command Injection vulnerability was found in /landrecordsys/admin/dashboard.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the \"Cookie\" GET request parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-10T14:15:29Z" diff --git a/advisories/unreviewed/2025/01/GHSA-x5v3-33m6-c266/GHSA-x5v3-33m6-c266.json b/advisories/unreviewed/2025/01/GHSA-x5v3-33m6-c266/GHSA-x5v3-33m6-c266.json index aed48da9cae..758edaec9d2 100644 --- a/advisories/unreviewed/2025/01/GHSA-x5v3-33m6-c266/GHSA-x5v3-33m6-c266.json +++ b/advisories/unreviewed/2025/01/GHSA-x5v3-33m6-c266/GHSA-x5v3-33m6-c266.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x5v3-33m6-c266", - "modified": "2025-01-09T21:31:31Z", + "modified": "2025-01-10T18:31:40Z", "published": "2025-01-09T21:31:31Z", "aliases": [ "CVE-2024-13281" ], "details": "Incorrect Authorization vulnerability in Drupal Monster Menus allows Forceful Browsing.This issue affects Monster Menus: from 0.0.0 before 9.3.2.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-863" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-09T20:15:37Z" diff --git a/advisories/unreviewed/2025/01/GHSA-x5wr-hg6v-9cj3/GHSA-x5wr-hg6v-9cj3.json b/advisories/unreviewed/2025/01/GHSA-x5wr-hg6v-9cj3/GHSA-x5wr-hg6v-9cj3.json new file mode 100644 index 00000000000..c7abf58d626 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-x5wr-hg6v-9cj3/GHSA-x5wr-hg6v-9cj3.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x5wr-hg6v-9cj3", + "modified": "2025-01-10T18:31:41Z", + "published": "2025-01-10T18:31:41Z", + "aliases": [ + "CVE-2024-29971" + ], + "details": "Scontain SCONE 5.8.0 has an interface vulnerability that leads to state corruption via injected signals.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29971" + }, + { + "type": "WEB", + "url": "https://github.com/ahoi-attacks/sigy/blob/main/pocs/scone/cve.md" + }, + { + "type": "WEB", + "url": "https://scontain.com" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-10T16:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-x7f5-x9wp-mgqw/GHSA-x7f5-x9wp-mgqw.json b/advisories/unreviewed/2025/01/GHSA-x7f5-x9wp-mgqw/GHSA-x7f5-x9wp-mgqw.json index f6a19a9a2b6..05a404d435f 100644 --- a/advisories/unreviewed/2025/01/GHSA-x7f5-x9wp-mgqw/GHSA-x7f5-x9wp-mgqw.json +++ b/advisories/unreviewed/2025/01/GHSA-x7f5-x9wp-mgqw/GHSA-x7f5-x9wp-mgqw.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-126" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2025/01/GHSA-xcc9-qmcp-vmhx/GHSA-xcc9-qmcp-vmhx.json b/advisories/unreviewed/2025/01/GHSA-xcc9-qmcp-vmhx/GHSA-xcc9-qmcp-vmhx.json new file mode 100644 index 00000000000..718b1a7978d --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-xcc9-qmcp-vmhx/GHSA-xcc9-qmcp-vmhx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xcc9-qmcp-vmhx", + "modified": "2025-01-10T18:31:41Z", + "published": "2025-01-10T18:31:41Z", + "aliases": [ + "CVE-2025-23078" + ], + "details": "Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - Breadcrumbs2 extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - Breadcrumbs2 extension: from 1.39.X before 1.39.11, from 1.41.X before 1.41.5, from 1.42.X before 1.42.4.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23078" + }, + { + "type": "WEB", + "url": "https://gerrit.wikimedia.org/r/q/I7878f8f7bc067080f80427b90f8d85337f172711" + }, + { + "type": "WEB", + "url": "https://phabricator.wikimedia.org/T382043" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-10T18:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-xff5-h82c-43q2/GHSA-xff5-h82c-43q2.json b/advisories/unreviewed/2025/01/GHSA-xff5-h82c-43q2/GHSA-xff5-h82c-43q2.json index 3f646b6030f..8b261f5ea9a 100644 --- a/advisories/unreviewed/2025/01/GHSA-xff5-h82c-43q2/GHSA-xff5-h82c-43q2.json +++ b/advisories/unreviewed/2025/01/GHSA-xff5-h82c-43q2/GHSA-xff5-h82c-43q2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xff5-h82c-43q2", - "modified": "2025-01-09T21:31:31Z", + "modified": "2025-01-10T18:31:39Z", "published": "2025-01-09T21:31:31Z", "aliases": [ "CVE-2024-13276" ], "details": "Insertion of Sensitive Information Into Sent Data vulnerability in Drupal File Entity (fieldable files) allows Forceful Browsing.This issue affects File Entity (fieldable files): from 7.X-* before 7.X-2.39.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-201" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-09T20:15:36Z" diff --git a/advisories/unreviewed/2025/01/GHSA-xh2f-mpwc-mhh4/GHSA-xh2f-mpwc-mhh4.json b/advisories/unreviewed/2025/01/GHSA-xh2f-mpwc-mhh4/GHSA-xh2f-mpwc-mhh4.json index cda295a1569..f1e49c7edcd 100644 --- a/advisories/unreviewed/2025/01/GHSA-xh2f-mpwc-mhh4/GHSA-xh2f-mpwc-mhh4.json +++ b/advisories/unreviewed/2025/01/GHSA-xh2f-mpwc-mhh4/GHSA-xh2f-mpwc-mhh4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xh2f-mpwc-mhh4", - "modified": "2025-01-09T21:31:31Z", + "modified": "2025-01-10T18:31:40Z", "published": "2025-01-09T21:31:31Z", "aliases": [ "CVE-2024-13284" ], "details": "Cross-Site Request Forgery (CSRF) vulnerability in Drupal Gutenberg allows Cross Site Request Forgery.This issue affects Gutenberg: from 0.0.0 before 2.13.0, from 3.0.0 before 3.0.5.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-352" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-09T20:15:37Z" diff --git a/advisories/unreviewed/2025/01/GHSA-xhf8-2ffc-9gh2/GHSA-xhf8-2ffc-9gh2.json b/advisories/unreviewed/2025/01/GHSA-xhf8-2ffc-9gh2/GHSA-xhf8-2ffc-9gh2.json index 5adae5e5af5..6bd84bcb969 100644 --- a/advisories/unreviewed/2025/01/GHSA-xhf8-2ffc-9gh2/GHSA-xhf8-2ffc-9gh2.json +++ b/advisories/unreviewed/2025/01/GHSA-xhf8-2ffc-9gh2/GHSA-xhf8-2ffc-9gh2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xhf8-2ffc-9gh2", - "modified": "2025-01-09T21:31:30Z", + "modified": "2025-01-10T18:31:39Z", "published": "2025-01-09T21:31:30Z", "aliases": [ "CVE-2024-13256" ], "details": "Insufficient Granularity of Access Control vulnerability in Drupal Email Contact allows Forceful Browsing.This issue affects Email Contact: from 0.0.0 before 2.0.4.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-1220" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-09T19:15:19Z" diff --git a/advisories/unreviewed/2025/01/GHSA-xw4g-gmmj-5g3m/GHSA-xw4g-gmmj-5g3m.json b/advisories/unreviewed/2025/01/GHSA-xw4g-gmmj-5g3m/GHSA-xw4g-gmmj-5g3m.json index 746564646e3..44ecfc84d3a 100644 --- a/advisories/unreviewed/2025/01/GHSA-xw4g-gmmj-5g3m/GHSA-xw4g-gmmj-5g3m.json +++ b/advisories/unreviewed/2025/01/GHSA-xw4g-gmmj-5g3m/GHSA-xw4g-gmmj-5g3m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xw4g-gmmj-5g3m", - "modified": "2025-01-09T21:31:29Z", + "modified": "2025-01-10T18:31:39Z", "published": "2025-01-09T21:31:29Z", "aliases": [ "CVE-2024-13241" ], "details": "Improper Authorization vulnerability in Drupal Open Social allows Collect Data from Common Resource Locations.This issue affects Open Social: from 0.0.0 before 12.0.5.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-285" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-09T19:15:17Z"