From a8f7f79f6b792162561fc8865c0671f072ba58cb Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 6 Jan 2025 21:32:10 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-pq9p-pc3p-9hm4.json | 6 +++- .../GHSA-3p37-hv77-x3rp.json | 3 +- .../GHSA-cv7g-qpjc-66p7.json | 13 +++++-- .../GHSA-fw99-8m5g-58p8.json | 2 +- .../GHSA-mrfm-jxgf-2h6v.json | 2 +- .../GHSA-3qjc-qh2q-vhxr.json | 4 ++- .../GHSA-3xm7-hgh9-chcw.json | 4 ++- .../GHSA-68x9-xqgp-fp8j.json | 4 ++- .../GHSA-888h-rm2r-vrc7.json | 6 +++- .../GHSA-c54q-fx7w-pxf4.json | 4 ++- .../GHSA-cgpv-8243-q33x.json | 4 ++- .../GHSA-gw29-86rq-2225.json | 4 ++- .../GHSA-hhhm-g2cc-rvhw.json | 4 ++- .../GHSA-hj2h-4jxv-fcgr.json | 4 ++- .../GHSA-j9rr-cmhw-qc36.json | 4 ++- .../GHSA-m635-gpvm-5hcf.json | 4 ++- .../GHSA-pchq-gvxg-rprr.json | 4 ++- .../GHSA-vh29-m7wq-7x2h.json | 4 ++- .../GHSA-5px8-4qwx-4qj6.json | 15 +++++--- .../GHSA-5w29-44gv-2g38.json | 15 +++++--- .../GHSA-76m2-73wx-8hj7.json | 15 +++++--- .../GHSA-7rxw-gv4w-f8w6.json | 15 +++++--- .../GHSA-843h-74ff-22vf.json | 15 +++++--- .../GHSA-8r4c-vj8m-g96m.json | 15 +++++--- .../GHSA-97cf-h8mh-89rg.json | 15 +++++--- .../GHSA-cw5r-8wj2-xpqf.json | 15 +++++--- .../GHSA-ffvm-4h72-qwr5.json | 15 +++++--- .../GHSA-h7cv-m349-g3xp.json | 15 +++++--- .../GHSA-hmqq-g55h-wvgf.json | 15 +++++--- .../GHSA-jhvm-33ww-x3q9.json | 15 +++++--- .../GHSA-jp9q-c7f4-2fxf.json | 15 +++++--- .../GHSA-qm6m-jh59-wxwp.json | 15 +++++--- .../GHSA-rcc5-r3m3-9rvc.json | 15 +++++--- .../GHSA-vr35-f6m3-rh89.json | 15 +++++--- .../GHSA-vrmw-4324-6mfp.json | 15 +++++--- .../GHSA-wjg2-c8g7-rjjr.json | 15 +++++--- .../GHSA-wpg8-rfjm-9g3w.json | 15 +++++--- .../GHSA-j52p-q7q4-9vwc.json | 15 +++++--- .../GHSA-22x4-j6vj-fmm5.json | 15 +++++--- .../GHSA-2398-v7wm-x7gr.json | 11 ++++-- .../GHSA-23x6-w5q4-2mqw.json | 15 +++++--- .../GHSA-2cxg-hjm3-xmvr.json | 15 +++++--- .../GHSA-2x5w-q4pc-79qx.json | 11 ++++-- .../GHSA-48hg-p6jq-42h2.json | 15 +++++--- .../GHSA-48x4-xr25-pcvw.json | 15 +++++--- .../GHSA-4g6f-5r4h-c449.json | 15 +++++--- .../GHSA-4whv-g373-hpgc.json | 15 +++++--- .../GHSA-4xh3-3533-7mmv.json | 11 ++++-- .../GHSA-7m9x-pr76-7p23.json | 11 ++++-- .../GHSA-7v7h-rp2j-g295.json | 11 ++++-- .../GHSA-8p58-276h-xqq5.json | 15 +++++--- .../GHSA-ghqp-926m-7jrx.json | 15 +++++--- .../GHSA-gxfg-mr5m-frxc.json | 11 ++++-- .../GHSA-h3qm-53p9-w8c6.json | 15 +++++--- .../GHSA-jcjf-6896-f99g.json | 15 +++++--- .../GHSA-jm3q-3f7r-g7wc.json | 11 ++++-- .../GHSA-r49r-4qq2-h5rj.json | 15 +++++--- .../GHSA-rvhx-c29r-93j7.json | 11 ++++-- .../GHSA-rxv4-87wm-f3xr.json | 15 +++++--- .../GHSA-w92r-fpr6-76rv.json | 3 +- .../GHSA-x8gq-4mj9-v7xj.json | 15 +++++--- .../GHSA-xpv3-x3xh-h28r.json | 11 ++++-- .../GHSA-2p95-8xvm-2pjx.json | 33 +++++++++++++++++ .../GHSA-2r77-fvv3-mm9j.json | 15 +++++--- .../GHSA-6gg3-5p97-3cp8.json | 11 ++++-- .../GHSA-8q2f-m3g8-m8qm.json | 33 +++++++++++++++++ .../GHSA-95j3-6wrj-9v4c.json | 36 +++++++++++++++++++ .../GHSA-f48j-vwm8-858j.json | 33 +++++++++++++++++ .../GHSA-j77f-79w9-rghc.json | 11 ++++-- .../GHSA-m78c-qx99-mvw9.json | 33 +++++++++++++++++ .../GHSA-pcw8-6g3c-prx8.json | 36 +++++++++++++++++++ .../GHSA-wpxf-7pwx-p92p.json | 11 ++++-- .../GHSA-x3hv-xrrp-rmx2.json | 36 +++++++++++++++++++ .../GHSA-x492-3p6g-fmvm.json | 15 +++++--- 74 files changed, 794 insertions(+), 201 deletions(-) create mode 100644 advisories/unreviewed/2025/01/GHSA-2p95-8xvm-2pjx/GHSA-2p95-8xvm-2pjx.json create mode 100644 advisories/unreviewed/2025/01/GHSA-8q2f-m3g8-m8qm/GHSA-8q2f-m3g8-m8qm.json create mode 100644 advisories/unreviewed/2025/01/GHSA-95j3-6wrj-9v4c/GHSA-95j3-6wrj-9v4c.json create mode 100644 advisories/unreviewed/2025/01/GHSA-f48j-vwm8-858j/GHSA-f48j-vwm8-858j.json create mode 100644 advisories/unreviewed/2025/01/GHSA-m78c-qx99-mvw9/GHSA-m78c-qx99-mvw9.json create mode 100644 advisories/unreviewed/2025/01/GHSA-pcw8-6g3c-prx8/GHSA-pcw8-6g3c-prx8.json create mode 100644 advisories/unreviewed/2025/01/GHSA-x3hv-xrrp-rmx2/GHSA-x3hv-xrrp-rmx2.json diff --git a/advisories/github-reviewed/2024/12/GHSA-pq9p-pc3p-9hm4/GHSA-pq9p-pc3p-9hm4.json b/advisories/github-reviewed/2024/12/GHSA-pq9p-pc3p-9hm4/GHSA-pq9p-pc3p-9hm4.json index 907a1040e0a..86909b761e2 100644 --- a/advisories/github-reviewed/2024/12/GHSA-pq9p-pc3p-9hm4/GHSA-pq9p-pc3p-9hm4.json +++ b/advisories/github-reviewed/2024/12/GHSA-pq9p-pc3p-9hm4/GHSA-pq9p-pc3p-9hm4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pq9p-pc3p-9hm4", - "modified": "2024-12-27T18:02:42Z", + "modified": "2025-01-06T21:30:50Z", "published": "2024-12-27T03:31:23Z", "aliases": [ "CVE-2024-9774" @@ -44,6 +44,10 @@ "type": "WEB", "url": "https://bugs.tryton.org/python-sql/93" }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2332734" + }, { "type": "WEB", "url": "https://discuss.tryton.org/t/security-release-for-issue-93/7889" diff --git a/advisories/unreviewed/2022/05/GHSA-3p37-hv77-x3rp/GHSA-3p37-hv77-x3rp.json b/advisories/unreviewed/2022/05/GHSA-3p37-hv77-x3rp/GHSA-3p37-hv77-x3rp.json index c1ec0715f4c..7bebf8166bc 100644 --- a/advisories/unreviewed/2022/05/GHSA-3p37-hv77-x3rp/GHSA-3p37-hv77-x3rp.json +++ b/advisories/unreviewed/2022/05/GHSA-3p37-hv77-x3rp/GHSA-3p37-hv77-x3rp.json @@ -138,7 +138,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-77" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-cv7g-qpjc-66p7/GHSA-cv7g-qpjc-66p7.json b/advisories/unreviewed/2022/05/GHSA-cv7g-qpjc-66p7/GHSA-cv7g-qpjc-66p7.json index 6b4b376762d..8d61ab62f3c 100644 --- a/advisories/unreviewed/2022/05/GHSA-cv7g-qpjc-66p7/GHSA-cv7g-qpjc-66p7.json +++ b/advisories/unreviewed/2022/05/GHSA-cv7g-qpjc-66p7/GHSA-cv7g-qpjc-66p7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cv7g-qpjc-66p7", - "modified": "2022-05-02T06:21:11Z", + "modified": "2025-01-06T21:30:47Z", "published": "2022-05-02T06:21:11Z", "aliases": [ "CVE-2010-1297" ], "details": "Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted SWF content, related to authplay.dll and the ActionScript Virtual Machine 2 (AVM2) newfunction instruction, as exploited in the wild in June 2010.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -188,7 +193,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-fw99-8m5g-58p8/GHSA-fw99-8m5g-58p8.json b/advisories/unreviewed/2022/05/GHSA-fw99-8m5g-58p8/GHSA-fw99-8m5g-58p8.json index b9bc644cb65..6935b15290f 100644 --- a/advisories/unreviewed/2022/05/GHSA-fw99-8m5g-58p8/GHSA-fw99-8m5g-58p8.json +++ b/advisories/unreviewed/2022/05/GHSA-fw99-8m5g-58p8/GHSA-fw99-8m5g-58p8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fw99-8m5g-58p8", - "modified": "2022-05-14T00:03:19Z", + "modified": "2025-01-06T21:30:48Z", "published": "2022-05-14T00:03:19Z", "aliases": [ "CVE-2012-4681" diff --git a/advisories/unreviewed/2022/05/GHSA-mrfm-jxgf-2h6v/GHSA-mrfm-jxgf-2h6v.json b/advisories/unreviewed/2022/05/GHSA-mrfm-jxgf-2h6v/GHSA-mrfm-jxgf-2h6v.json index 42b8c77f9bf..1f5a0aede74 100644 --- a/advisories/unreviewed/2022/05/GHSA-mrfm-jxgf-2h6v/GHSA-mrfm-jxgf-2h6v.json +++ b/advisories/unreviewed/2022/05/GHSA-mrfm-jxgf-2h6v/GHSA-mrfm-jxgf-2h6v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mrfm-jxgf-2h6v", - "modified": "2022-05-17T03:28:58Z", + "modified": "2025-01-06T21:30:47Z", "published": "2022-05-17T03:28:58Z", "aliases": [ "CVE-2014-3120" diff --git a/advisories/unreviewed/2023/06/GHSA-3qjc-qh2q-vhxr/GHSA-3qjc-qh2q-vhxr.json b/advisories/unreviewed/2023/06/GHSA-3qjc-qh2q-vhxr/GHSA-3qjc-qh2q-vhxr.json index 9370af88f9c..a4b22b6aaac 100644 --- a/advisories/unreviewed/2023/06/GHSA-3qjc-qh2q-vhxr/GHSA-3qjc-qh2q-vhxr.json +++ b/advisories/unreviewed/2023/06/GHSA-3qjc-qh2q-vhxr/GHSA-3qjc-qh2q-vhxr.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-3xm7-hgh9-chcw/GHSA-3xm7-hgh9-chcw.json b/advisories/unreviewed/2023/06/GHSA-3xm7-hgh9-chcw/GHSA-3xm7-hgh9-chcw.json index 3dd6bffd81e..9e4d37137c6 100644 --- a/advisories/unreviewed/2023/06/GHSA-3xm7-hgh9-chcw/GHSA-3xm7-hgh9-chcw.json +++ b/advisories/unreviewed/2023/06/GHSA-3xm7-hgh9-chcw/GHSA-3xm7-hgh9-chcw.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-68x9-xqgp-fp8j/GHSA-68x9-xqgp-fp8j.json b/advisories/unreviewed/2023/06/GHSA-68x9-xqgp-fp8j/GHSA-68x9-xqgp-fp8j.json index c4bd76f1ab6..9f194796e1e 100644 --- a/advisories/unreviewed/2023/06/GHSA-68x9-xqgp-fp8j/GHSA-68x9-xqgp-fp8j.json +++ b/advisories/unreviewed/2023/06/GHSA-68x9-xqgp-fp8j/GHSA-68x9-xqgp-fp8j.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-888h-rm2r-vrc7/GHSA-888h-rm2r-vrc7.json b/advisories/unreviewed/2023/06/GHSA-888h-rm2r-vrc7/GHSA-888h-rm2r-vrc7.json index a58736363e3..cc328440536 100644 --- a/advisories/unreviewed/2023/06/GHSA-888h-rm2r-vrc7/GHSA-888h-rm2r-vrc7.json +++ b/advisories/unreviewed/2023/06/GHSA-888h-rm2r-vrc7/GHSA-888h-rm2r-vrc7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-888h-rm2r-vrc7", - "modified": "2023-11-25T12:30:22Z", + "modified": "2025-01-06T21:30:49Z", "published": "2023-06-08T21:30:27Z", "aliases": [ "CVE-2023-29404" @@ -46,6 +46,10 @@ { "type": "WEB", "url": "https://security.gentoo.org/glsa/202311-09" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20241115-0009" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/06/GHSA-c54q-fx7w-pxf4/GHSA-c54q-fx7w-pxf4.json b/advisories/unreviewed/2023/06/GHSA-c54q-fx7w-pxf4/GHSA-c54q-fx7w-pxf4.json index 79e3639b81f..d0fa95e0056 100644 --- a/advisories/unreviewed/2023/06/GHSA-c54q-fx7w-pxf4/GHSA-c54q-fx7w-pxf4.json +++ b/advisories/unreviewed/2023/06/GHSA-c54q-fx7w-pxf4/GHSA-c54q-fx7w-pxf4.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-346" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-cgpv-8243-q33x/GHSA-cgpv-8243-q33x.json b/advisories/unreviewed/2023/06/GHSA-cgpv-8243-q33x/GHSA-cgpv-8243-q33x.json index 5f212fe8dc8..5e37c3eb46c 100644 --- a/advisories/unreviewed/2023/06/GHSA-cgpv-8243-q33x/GHSA-cgpv-8243-q33x.json +++ b/advisories/unreviewed/2023/06/GHSA-cgpv-8243-q33x/GHSA-cgpv-8243-q33x.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-346" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-gw29-86rq-2225/GHSA-gw29-86rq-2225.json b/advisories/unreviewed/2023/06/GHSA-gw29-86rq-2225/GHSA-gw29-86rq-2225.json index a086aa53c88..cb3e679d3c6 100644 --- a/advisories/unreviewed/2023/06/GHSA-gw29-86rq-2225/GHSA-gw29-86rq-2225.json +++ b/advisories/unreviewed/2023/06/GHSA-gw29-86rq-2225/GHSA-gw29-86rq-2225.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-hhhm-g2cc-rvhw/GHSA-hhhm-g2cc-rvhw.json b/advisories/unreviewed/2023/06/GHSA-hhhm-g2cc-rvhw/GHSA-hhhm-g2cc-rvhw.json index 97d8cc27b4f..9a04613db12 100644 --- a/advisories/unreviewed/2023/06/GHSA-hhhm-g2cc-rvhw/GHSA-hhhm-g2cc-rvhw.json +++ b/advisories/unreviewed/2023/06/GHSA-hhhm-g2cc-rvhw/GHSA-hhhm-g2cc-rvhw.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-922" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-hj2h-4jxv-fcgr/GHSA-hj2h-4jxv-fcgr.json b/advisories/unreviewed/2023/06/GHSA-hj2h-4jxv-fcgr/GHSA-hj2h-4jxv-fcgr.json index 800706cb3e0..36e82d88a5b 100644 --- a/advisories/unreviewed/2023/06/GHSA-hj2h-4jxv-fcgr/GHSA-hj2h-4jxv-fcgr.json +++ b/advisories/unreviewed/2023/06/GHSA-hj2h-4jxv-fcgr/GHSA-hj2h-4jxv-fcgr.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-922" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-j9rr-cmhw-qc36/GHSA-j9rr-cmhw-qc36.json b/advisories/unreviewed/2023/06/GHSA-j9rr-cmhw-qc36/GHSA-j9rr-cmhw-qc36.json index 363bd3caf77..60c06453ec0 100644 --- a/advisories/unreviewed/2023/06/GHSA-j9rr-cmhw-qc36/GHSA-j9rr-cmhw-qc36.json +++ b/advisories/unreviewed/2023/06/GHSA-j9rr-cmhw-qc36/GHSA-j9rr-cmhw-qc36.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-m635-gpvm-5hcf/GHSA-m635-gpvm-5hcf.json b/advisories/unreviewed/2023/06/GHSA-m635-gpvm-5hcf/GHSA-m635-gpvm-5hcf.json index acaa8779f3a..6eae94d4224 100644 --- a/advisories/unreviewed/2023/06/GHSA-m635-gpvm-5hcf/GHSA-m635-gpvm-5hcf.json +++ b/advisories/unreviewed/2023/06/GHSA-m635-gpvm-5hcf/GHSA-m635-gpvm-5hcf.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-pchq-gvxg-rprr/GHSA-pchq-gvxg-rprr.json b/advisories/unreviewed/2023/06/GHSA-pchq-gvxg-rprr/GHSA-pchq-gvxg-rprr.json index b77a552cab6..a737f62a414 100644 --- a/advisories/unreviewed/2023/06/GHSA-pchq-gvxg-rprr/GHSA-pchq-gvxg-rprr.json +++ b/advisories/unreviewed/2023/06/GHSA-pchq-gvxg-rprr/GHSA-pchq-gvxg-rprr.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-346" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-vh29-m7wq-7x2h/GHSA-vh29-m7wq-7x2h.json b/advisories/unreviewed/2023/06/GHSA-vh29-m7wq-7x2h/GHSA-vh29-m7wq-7x2h.json index 7c72714d17a..db190174b7a 100644 --- a/advisories/unreviewed/2023/06/GHSA-vh29-m7wq-7x2h/GHSA-vh29-m7wq-7x2h.json +++ b/advisories/unreviewed/2023/06/GHSA-vh29-m7wq-7x2h/GHSA-vh29-m7wq-7x2h.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-346" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-5px8-4qwx-4qj6/GHSA-5px8-4qwx-4qj6.json b/advisories/unreviewed/2024/05/GHSA-5px8-4qwx-4qj6/GHSA-5px8-4qwx-4qj6.json index a18c3c23b52..069a60e7670 100644 --- a/advisories/unreviewed/2024/05/GHSA-5px8-4qwx-4qj6/GHSA-5px8-4qwx-4qj6.json +++ b/advisories/unreviewed/2024/05/GHSA-5px8-4qwx-4qj6/GHSA-5px8-4qwx-4qj6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5px8-4qwx-4qj6", - "modified": "2024-05-22T09:31:46Z", + "modified": "2025-01-06T21:30:49Z", "published": "2024-05-22T09:31:46Z", "aliases": [ "CVE-2021-47490" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/ttm: fix memleak in ttm_transfered_destroy\n\nWe need to cleanup the fences for ghost objects as well.\n\nBug: https://bugzilla.kernel.org/show_bug.cgi?id=214029\nBug: https://bugzilla.kernel.org/show_bug.cgi?id=214447", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-22T09:15:10Z" diff --git a/advisories/unreviewed/2024/05/GHSA-5w29-44gv-2g38/GHSA-5w29-44gv-2g38.json b/advisories/unreviewed/2024/05/GHSA-5w29-44gv-2g38/GHSA-5w29-44gv-2g38.json index 76dcd7d95b7..b0e144717d7 100644 --- a/advisories/unreviewed/2024/05/GHSA-5w29-44gv-2g38/GHSA-5w29-44gv-2g38.json +++ b/advisories/unreviewed/2024/05/GHSA-5w29-44gv-2g38/GHSA-5w29-44gv-2g38.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5w29-44gv-2g38", - "modified": "2024-05-21T18:31:19Z", + "modified": "2025-01-06T21:30:49Z", "published": "2024-05-21T18:31:19Z", "aliases": [ "CVE-2023-52708" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmmc: mmc_spi: fix error handling in mmc_spi_probe()\n\nIf mmc_add_host() fails, it doesn't need to call mmc_remove_host(),\nor it will cause null-ptr-deref, because of deleting a not added\ndevice in mmc_remove_host().\n\nTo fix this, goto label 'fail_glue_init', if mmc_add_host() fails,\nand change the label 'fail_add_host' to 'fail_gpiod_request'.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T16:15:13Z" diff --git a/advisories/unreviewed/2024/05/GHSA-76m2-73wx-8hj7/GHSA-76m2-73wx-8hj7.json b/advisories/unreviewed/2024/05/GHSA-76m2-73wx-8hj7/GHSA-76m2-73wx-8hj7.json index 8d74943623b..b2610604046 100644 --- a/advisories/unreviewed/2024/05/GHSA-76m2-73wx-8hj7/GHSA-76m2-73wx-8hj7.json +++ b/advisories/unreviewed/2024/05/GHSA-76m2-73wx-8hj7/GHSA-76m2-73wx-8hj7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-76m2-73wx-8hj7", - "modified": "2024-05-22T09:31:46Z", + "modified": "2025-01-06T21:30:49Z", "published": "2024-05-22T09:31:46Z", "aliases": [ "CVE-2021-47483" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nregmap: Fix possible double-free in regcache_rbtree_exit()\n\nIn regcache_rbtree_insert_to_block(), when 'present' realloc failed,\nthe 'blk' which is supposed to assign to 'rbnode->block' will be freed,\nso 'rbnode->block' points a freed memory, in the error handling path of\nregcache_rbtree_init(), 'rbnode->block' will be freed again in\nregcache_rbtree_exit(), KASAN will report double-free as follows:\n\nBUG: KASAN: double-free or invalid-free in kfree+0xce/0x390\nCall Trace:\n slab_free_freelist_hook+0x10d/0x240\n kfree+0xce/0x390\n regcache_rbtree_exit+0x15d/0x1a0\n regcache_rbtree_init+0x224/0x2c0\n regcache_init+0x88d/0x1310\n __regmap_init+0x3151/0x4a80\n __devm_regmap_init+0x7d/0x100\n madera_spi_probe+0x10f/0x333 [madera_spi]\n spi_probe+0x183/0x210\n really_probe+0x285/0xc30\n\nTo fix this, moving up the assignment of rbnode->block to immediately after\nthe reallocation has succeeded so that the data structure stays valid even\nif the second reallocation fails.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-415" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-22T09:15:10Z" diff --git a/advisories/unreviewed/2024/05/GHSA-7rxw-gv4w-f8w6/GHSA-7rxw-gv4w-f8w6.json b/advisories/unreviewed/2024/05/GHSA-7rxw-gv4w-f8w6/GHSA-7rxw-gv4w-f8w6.json index 6ef10780d61..a5730744cfb 100644 --- a/advisories/unreviewed/2024/05/GHSA-7rxw-gv4w-f8w6/GHSA-7rxw-gv4w-f8w6.json +++ b/advisories/unreviewed/2024/05/GHSA-7rxw-gv4w-f8w6/GHSA-7rxw-gv4w-f8w6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7rxw-gv4w-f8w6", - "modified": "2024-05-21T18:31:23Z", + "modified": "2025-01-06T21:30:49Z", "published": "2024-05-21T18:31:23Z", "aliases": [ "CVE-2023-52877" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: typec: tcpm: Fix NULL pointer dereference in tcpm_pd_svdm()\n\nIt is possible that typec_register_partner() returns ERR_PTR on failure.\nWhen port->partner is an error, a NULL pointer dereference may occur as\nshown below.\n\n[91222.095236][ T319] typec port0: failed to register partner (-17)\n...\n[91225.061491][ T319] Unable to handle kernel NULL pointer dereference\nat virtual address 000000000000039f\n[91225.274642][ T319] pc : tcpm_pd_data_request+0x310/0x13fc\n[91225.274646][ T319] lr : tcpm_pd_data_request+0x298/0x13fc\n[91225.308067][ T319] Call trace:\n[91225.308070][ T319] tcpm_pd_data_request+0x310/0x13fc\n[91225.308073][ T319] tcpm_pd_rx_handler+0x100/0x9e8\n[91225.355900][ T319] kthread_worker_fn+0x178/0x58c\n[91225.355902][ T319] kthread+0x150/0x200\n[91225.355905][ T319] ret_from_fork+0x10/0x30\n\nAdd a check for port->partner to avoid dereferencing a NULL pointer.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T16:15:24Z" diff --git a/advisories/unreviewed/2024/05/GHSA-843h-74ff-22vf/GHSA-843h-74ff-22vf.json b/advisories/unreviewed/2024/05/GHSA-843h-74ff-22vf/GHSA-843h-74ff-22vf.json index 105336d7e1a..82e851cd708 100644 --- a/advisories/unreviewed/2024/05/GHSA-843h-74ff-22vf/GHSA-843h-74ff-22vf.json +++ b/advisories/unreviewed/2024/05/GHSA-843h-74ff-22vf/GHSA-843h-74ff-22vf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-843h-74ff-22vf", - "modified": "2024-05-22T09:31:46Z", + "modified": "2025-01-06T21:30:49Z", "published": "2024-05-22T09:31:46Z", "aliases": [ "CVE-2021-47489" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: Fix even more out of bound writes from debugfs\n\nCVE-2021-42327 was fixed by:\n\ncommit f23750b5b3d98653b31d4469592935ef6364ad67\nAuthor: Thelford Williams \nDate: Wed Oct 13 16:04:13 2021 -0400\n\n drm/amdgpu: fix out of bounds write\n\nbut amdgpu_dm_debugfs.c contains more of the same issue so fix the\nremaining ones.\n\nv2:\n\t* Add missing fix in dp_max_bpc_write (Harry Wentland)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-22T09:15:10Z" diff --git a/advisories/unreviewed/2024/05/GHSA-8r4c-vj8m-g96m/GHSA-8r4c-vj8m-g96m.json b/advisories/unreviewed/2024/05/GHSA-8r4c-vj8m-g96m/GHSA-8r4c-vj8m-g96m.json index 038d49f7295..c5ba8d3bd6e 100644 --- a/advisories/unreviewed/2024/05/GHSA-8r4c-vj8m-g96m/GHSA-8r4c-vj8m-g96m.json +++ b/advisories/unreviewed/2024/05/GHSA-8r4c-vj8m-g96m/GHSA-8r4c-vj8m-g96m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8r4c-vj8m-g96m", - "modified": "2024-05-21T18:31:23Z", + "modified": "2025-01-06T21:30:49Z", "published": "2024-05-21T18:31:23Z", "aliases": [ "CVE-2023-52875" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nclk: mediatek: clk-mt2701: Add check for mtk_alloc_clk_data\n\nAdd the check for the return value of mtk_alloc_clk_data() in order to\navoid NULL pointer dereference.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -52,8 +57,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T16:15:24Z" diff --git a/advisories/unreviewed/2024/05/GHSA-97cf-h8mh-89rg/GHSA-97cf-h8mh-89rg.json b/advisories/unreviewed/2024/05/GHSA-97cf-h8mh-89rg/GHSA-97cf-h8mh-89rg.json index 63cb7142812..7561e1cc9d2 100644 --- a/advisories/unreviewed/2024/05/GHSA-97cf-h8mh-89rg/GHSA-97cf-h8mh-89rg.json +++ b/advisories/unreviewed/2024/05/GHSA-97cf-h8mh-89rg/GHSA-97cf-h8mh-89rg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-97cf-h8mh-89rg", - "modified": "2024-05-21T18:31:23Z", + "modified": "2025-01-06T21:30:49Z", "published": "2024-05-21T18:31:23Z", "aliases": [ "CVE-2023-52876" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nclk: mediatek: clk-mt7629-eth: Add check for mtk_alloc_clk_data\n\nAdd the check for the return value of mtk_alloc_clk_data() in order to\navoid NULL pointer dereference.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T16:15:24Z" diff --git a/advisories/unreviewed/2024/05/GHSA-cw5r-8wj2-xpqf/GHSA-cw5r-8wj2-xpqf.json b/advisories/unreviewed/2024/05/GHSA-cw5r-8wj2-xpqf/GHSA-cw5r-8wj2-xpqf.json index b64387afc69..50bdfc3b67d 100644 --- a/advisories/unreviewed/2024/05/GHSA-cw5r-8wj2-xpqf/GHSA-cw5r-8wj2-xpqf.json +++ b/advisories/unreviewed/2024/05/GHSA-cw5r-8wj2-xpqf/GHSA-cw5r-8wj2-xpqf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cw5r-8wj2-xpqf", - "modified": "2024-05-21T18:31:19Z", + "modified": "2025-01-06T21:30:49Z", "published": "2024-05-21T18:31:19Z", "aliases": [ "CVE-2023-52707" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsched/psi: Fix use-after-free in ep_remove_wait_queue()\n\nIf a non-root cgroup gets removed when there is a thread that registered\ntrigger and is polling on a pressure file within the cgroup, the polling\nwaitqueue gets freed in the following path:\n\n do_rmdir\n cgroup_rmdir\n kernfs_drain_open_files\n cgroup_file_release\n cgroup_pressure_release\n psi_trigger_destroy\n\nHowever, the polling thread still has a reference to the pressure file and\nwill access the freed waitqueue when the file is closed or upon exit:\n\n fput\n ep_eventpoll_release\n ep_free\n ep_remove_wait_queue\n remove_wait_queue\n\nThis results in use-after-free as pasted below.\n\nThe fundamental problem here is that cgroup_file_release() (and\nconsequently waitqueue's lifetime) is not tied to the file's real lifetime.\nUsing wake_up_pollfree() here might be less than ideal, but it is in line\nwith the comment at commit 42288cb44c4b (\"wait: add wake_up_pollfree()\")\nsince the waitqueue's lifetime is not tied to file's one and can be\nconsidered as another special case. While this would be fixable by somehow\nmaking cgroup_file_release() be tied to the fput(), it would require\nsizable refactoring at cgroups or higher layer which might be more\njustifiable if we identify more cases like this.\n\n BUG: KASAN: use-after-free in _raw_spin_lock_irqsave+0x60/0xc0\n Write of size 4 at addr ffff88810e625328 by task a.out/4404\n\n\tCPU: 19 PID: 4404 Comm: a.out Not tainted 6.2.0-rc6 #38\n\tHardware name: Amazon EC2 c5a.8xlarge/, BIOS 1.0 10/16/2017\n\tCall Trace:\n\t\n\tdump_stack_lvl+0x73/0xa0\n\tprint_report+0x16c/0x4e0\n\tkasan_report+0xc3/0xf0\n\tkasan_check_range+0x2d2/0x310\n\t_raw_spin_lock_irqsave+0x60/0xc0\n\tremove_wait_queue+0x1a/0xa0\n\tep_free+0x12c/0x170\n\tep_eventpoll_release+0x26/0x30\n\t__fput+0x202/0x400\n\ttask_work_run+0x11d/0x170\n\tdo_exit+0x495/0x1130\n\tdo_group_exit+0x100/0x100\n\tget_signal+0xd67/0xde0\n\tarch_do_signal_or_restart+0x2a/0x2b0\n\texit_to_user_mode_prepare+0x94/0x100\n\tsyscall_exit_to_user_mode+0x20/0x40\n\tdo_syscall_64+0x52/0x90\n\tentry_SYSCALL_64_after_hwframe+0x63/0xcd\n\t\n\n Allocated by task 4404:\n\n\tkasan_set_track+0x3d/0x60\n\t__kasan_kmalloc+0x85/0x90\n\tpsi_trigger_create+0x113/0x3e0\n\tpressure_write+0x146/0x2e0\n\tcgroup_file_write+0x11c/0x250\n\tkernfs_fop_write_iter+0x186/0x220\n\tvfs_write+0x3d8/0x5c0\n\tksys_write+0x90/0x110\n\tdo_syscall_64+0x43/0x90\n\tentry_SYSCALL_64_after_hwframe+0x63/0xcd\n\n Freed by task 4407:\n\n\tkasan_set_track+0x3d/0x60\n\tkasan_save_free_info+0x27/0x40\n\t____kasan_slab_free+0x11d/0x170\n\tslab_free_freelist_hook+0x87/0x150\n\t__kmem_cache_free+0xcb/0x180\n\tpsi_trigger_destroy+0x2e8/0x310\n\tcgroup_file_release+0x4f/0xb0\n\tkernfs_drain_open_files+0x165/0x1f0\n\tkernfs_drain+0x162/0x1a0\n\t__kernfs_remove+0x1fb/0x310\n\tkernfs_remove_by_name_ns+0x95/0xe0\n\tcgroup_addrm_files+0x67f/0x700\n\tcgroup_destroy_locked+0x283/0x3c0\n\tcgroup_rmdir+0x29/0x100\n\tkernfs_iop_rmdir+0xd1/0x140\n\tvfs_rmdir+0xfe/0x240\n\tdo_rmdir+0x13d/0x280\n\t__x64_sys_rmdir+0x2c/0x30\n\tdo_syscall_64+0x43/0x90\n\tentry_SYSCALL_64_after_hwframe+0x63/0xcd", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T16:15:12Z" diff --git a/advisories/unreviewed/2024/05/GHSA-ffvm-4h72-qwr5/GHSA-ffvm-4h72-qwr5.json b/advisories/unreviewed/2024/05/GHSA-ffvm-4h72-qwr5/GHSA-ffvm-4h72-qwr5.json index 4b3c1fd3ba5..8432f1a26b5 100644 --- a/advisories/unreviewed/2024/05/GHSA-ffvm-4h72-qwr5/GHSA-ffvm-4h72-qwr5.json +++ b/advisories/unreviewed/2024/05/GHSA-ffvm-4h72-qwr5/GHSA-ffvm-4h72-qwr5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-ffvm-4h72-qwr5", - "modified": "2024-05-21T18:31:20Z", + "modified": "2025-01-06T21:30:49Z", "published": "2024-05-21T18:31:20Z", "aliases": [ "CVE-2023-52751" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix use-after-free in smb2_query_info_compound()\n\nThe following UAF was triggered when running fstests generic/072 with\nKASAN enabled against Windows Server 2022 and mount options\n'multichannel,max_channels=2,vers=3.1.1,mfsymlinks,noperm'\n\n BUG: KASAN: slab-use-after-free in smb2_query_info_compound+0x423/0x6d0 [cifs]\n Read of size 8 at addr ffff888014941048 by task xfs_io/27534\n\n CPU: 0 PID: 27534 Comm: xfs_io Not tainted 6.6.0-rc7 #1\n Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS\n rel-1.16.2-3-gd478f380-rebuilt.opensuse.org 04/01/2014\n Call Trace:\n dump_stack_lvl+0x4a/0x80\n print_report+0xcf/0x650\n ? srso_alias_return_thunk+0x5/0x7f\n ? srso_alias_return_thunk+0x5/0x7f\n ? __phys_addr+0x46/0x90\n kasan_report+0xda/0x110\n ? smb2_query_info_compound+0x423/0x6d0 [cifs]\n ? smb2_query_info_compound+0x423/0x6d0 [cifs]\n smb2_query_info_compound+0x423/0x6d0 [cifs]\n ? __pfx_smb2_query_info_compound+0x10/0x10 [cifs]\n ? srso_alias_return_thunk+0x5/0x7f\n ? __stack_depot_save+0x39/0x480\n ? kasan_save_stack+0x33/0x60\n ? kasan_set_track+0x25/0x30\n ? ____kasan_slab_free+0x126/0x170\n smb2_queryfs+0xc2/0x2c0 [cifs]\n ? __pfx_smb2_queryfs+0x10/0x10 [cifs]\n ? __pfx___lock_acquire+0x10/0x10\n smb311_queryfs+0x210/0x220 [cifs]\n ? __pfx_smb311_queryfs+0x10/0x10 [cifs]\n ? srso_alias_return_thunk+0x5/0x7f\n ? __lock_acquire+0x480/0x26c0\n ? lock_release+0x1ed/0x640\n ? srso_alias_return_thunk+0x5/0x7f\n ? do_raw_spin_unlock+0x9b/0x100\n cifs_statfs+0x18c/0x4b0 [cifs]\n statfs_by_dentry+0x9b/0xf0\n fd_statfs+0x4e/0xb0\n __do_sys_fstatfs+0x7f/0xe0\n ? __pfx___do_sys_fstatfs+0x10/0x10\n ? srso_alias_return_thunk+0x5/0x7f\n ? lockdep_hardirqs_on_prepare+0x136/0x200\n ? srso_alias_return_thunk+0x5/0x7f\n do_syscall_64+0x3f/0x90\n entry_SYSCALL_64_after_hwframe+0x6e/0xd8\n\n Allocated by task 27534:\n kasan_save_stack+0x33/0x60\n kasan_set_track+0x25/0x30\n __kasan_kmalloc+0x8f/0xa0\n open_cached_dir+0x71b/0x1240 [cifs]\n smb2_query_info_compound+0x5c3/0x6d0 [cifs]\n smb2_queryfs+0xc2/0x2c0 [cifs]\n smb311_queryfs+0x210/0x220 [cifs]\n cifs_statfs+0x18c/0x4b0 [cifs]\n statfs_by_dentry+0x9b/0xf0\n fd_statfs+0x4e/0xb0\n __do_sys_fstatfs+0x7f/0xe0\n do_syscall_64+0x3f/0x90\n entry_SYSCALL_64_after_hwframe+0x6e/0xd8\n\n Freed by task 27534:\n kasan_save_stack+0x33/0x60\n kasan_set_track+0x25/0x30\n kasan_save_free_info+0x2b/0x50\n ____kasan_slab_free+0x126/0x170\n slab_free_freelist_hook+0xd0/0x1e0\n __kmem_cache_free+0x9d/0x1b0\n open_cached_dir+0xff5/0x1240 [cifs]\n smb2_query_info_compound+0x5c3/0x6d0 [cifs]\n smb2_queryfs+0xc2/0x2c0 [cifs]\n\nThis is a race between open_cached_dir() and cached_dir_lease_break()\nwhere the cache entry for the open directory handle receives a lease\nbreak while creating it. And before returning from open_cached_dir(),\nwe put the last reference of the new @cfid because of\n!@cfid->has_lease.\n\nBesides the UAF, while running xfstests a lot of missed lease breaks\nhave been noticed in tests that run several concurrent statfs(2) calls\non those cached fids\n\n CIFS: VFS: \\\\w22-root1.gandalf.test No task to wake, unknown frame...\n CIFS: VFS: \\\\w22-root1.gandalf.test Cmd: 18 Err: 0x0 Flags: 0x1...\n CIFS: VFS: \\\\w22-root1.gandalf.test smb buf 00000000715bfe83 len 108\n CIFS: VFS: Dump pending requests:\n CIFS: VFS: \\\\w22-root1.gandalf.test No task to wake, unknown frame...\n CIFS: VFS: \\\\w22-root1.gandalf.test Cmd: 18 Err: 0x0 Flags: 0x1...\n CIFS: VFS: \\\\w22-root1.gandalf.test smb buf 000000005aa7316e len 108\n ...\n\nTo fix both, in open_cached_dir() ensure that @cfid->has_lease is set\nright before sending out compounded request so that any potential\nlease break will be get processed by demultiplex thread while we're\nstill caching @cfid. And, if open failed for some reason, re-check\n@cfid->has_lease to decide whether or not put lease reference.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T16:15:14Z" diff --git a/advisories/unreviewed/2024/05/GHSA-h7cv-m349-g3xp/GHSA-h7cv-m349-g3xp.json b/advisories/unreviewed/2024/05/GHSA-h7cv-m349-g3xp/GHSA-h7cv-m349-g3xp.json index dd2e3330ef0..88bba3be76e 100644 --- a/advisories/unreviewed/2024/05/GHSA-h7cv-m349-g3xp/GHSA-h7cv-m349-g3xp.json +++ b/advisories/unreviewed/2024/05/GHSA-h7cv-m349-g3xp/GHSA-h7cv-m349-g3xp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h7cv-m349-g3xp", - "modified": "2024-05-21T18:31:20Z", + "modified": "2025-01-06T21:30:49Z", "published": "2024-05-21T18:31:20Z", "aliases": [ "CVE-2023-52766" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ni3c: mipi-i3c-hci: Fix out of bounds access in hci_dma_irq_handler\n\nDo not loop over ring headers in hci_dma_irq_handler() that are not\nallocated and enabled in hci_dma_init(). Otherwise out of bounds access\nwill occur from rings->headers[i] access when i >= number of allocated\nring headers.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T16:15:15Z" diff --git a/advisories/unreviewed/2024/05/GHSA-hmqq-g55h-wvgf/GHSA-hmqq-g55h-wvgf.json b/advisories/unreviewed/2024/05/GHSA-hmqq-g55h-wvgf/GHSA-hmqq-g55h-wvgf.json index a9244232eff..a61eecf1feb 100644 --- a/advisories/unreviewed/2024/05/GHSA-hmqq-g55h-wvgf/GHSA-hmqq-g55h-wvgf.json +++ b/advisories/unreviewed/2024/05/GHSA-hmqq-g55h-wvgf/GHSA-hmqq-g55h-wvgf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hmqq-g55h-wvgf", - "modified": "2024-05-21T18:31:19Z", + "modified": "2025-01-06T21:30:49Z", "published": "2024-05-21T18:31:19Z", "aliases": [ "CVE-2023-52706" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ngpio: sim: fix a memory leak\n\nFix an inverted logic bug in gpio_sim_remove_hogs() that leads to GPIO\nhog structures never being freed.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T16:15:12Z" diff --git a/advisories/unreviewed/2024/05/GHSA-jhvm-33ww-x3q9/GHSA-jhvm-33ww-x3q9.json b/advisories/unreviewed/2024/05/GHSA-jhvm-33ww-x3q9/GHSA-jhvm-33ww-x3q9.json index c2559b068f2..3720db61f69 100644 --- a/advisories/unreviewed/2024/05/GHSA-jhvm-33ww-x3q9/GHSA-jhvm-33ww-x3q9.json +++ b/advisories/unreviewed/2024/05/GHSA-jhvm-33ww-x3q9/GHSA-jhvm-33ww-x3q9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jhvm-33ww-x3q9", - "modified": "2024-05-21T18:31:19Z", + "modified": "2025-01-06T21:30:49Z", "published": "2024-05-21T18:31:19Z", "aliases": [ "CVE-2023-52744" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/irdma: Fix potential NULL-ptr-dereference\n\nin_dev_get() can return NULL which will cause a failure once idev is\ndereferenced in in_dev_for_each_ifa_rtnl(). This patch adds a\ncheck for NULL value in idev beforehand.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T16:15:14Z" diff --git a/advisories/unreviewed/2024/05/GHSA-jp9q-c7f4-2fxf/GHSA-jp9q-c7f4-2fxf.json b/advisories/unreviewed/2024/05/GHSA-jp9q-c7f4-2fxf/GHSA-jp9q-c7f4-2fxf.json index e7cd836fdec..e1dd2d79f9f 100644 --- a/advisories/unreviewed/2024/05/GHSA-jp9q-c7f4-2fxf/GHSA-jp9q-c7f4-2fxf.json +++ b/advisories/unreviewed/2024/05/GHSA-jp9q-c7f4-2fxf/GHSA-jp9q-c7f4-2fxf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jp9q-c7f4-2fxf", - "modified": "2024-05-21T18:31:20Z", + "modified": "2025-01-06T21:30:49Z", "published": "2024-05-21T18:31:20Z", "aliases": [ "CVE-2023-52757" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix potential deadlock when releasing mids\n\nAll release_mid() callers seem to hold a reference of @mid so there is\nno need to call kref_put(&mid->refcount, __release_mid) under\n@server->mid_lock spinlock. If they don't, then an use-after-free bug\nwould have occurred anyways.\n\nBy getting rid of such spinlock also fixes a potential deadlock as\nshown below\n\nCPU 0 CPU 1\n------------------------------------------------------------------\ncifs_demultiplex_thread() cifs_debug_data_proc_show()\n release_mid()\n spin_lock(&server->mid_lock);\n spin_lock(&cifs_tcp_ses_lock)\n\t\t\t\t spin_lock(&server->mid_lock)\n __release_mid()\n smb2_find_smb_tcon()\n spin_lock(&cifs_tcp_ses_lock) *deadlock*", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T16:15:15Z" diff --git a/advisories/unreviewed/2024/05/GHSA-qm6m-jh59-wxwp/GHSA-qm6m-jh59-wxwp.json b/advisories/unreviewed/2024/05/GHSA-qm6m-jh59-wxwp/GHSA-qm6m-jh59-wxwp.json index e2d15a6fbaf..f171ec22261 100644 --- a/advisories/unreviewed/2024/05/GHSA-qm6m-jh59-wxwp/GHSA-qm6m-jh59-wxwp.json +++ b/advisories/unreviewed/2024/05/GHSA-qm6m-jh59-wxwp/GHSA-qm6m-jh59-wxwp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qm6m-jh59-wxwp", - "modified": "2024-05-21T18:31:20Z", + "modified": "2025-01-06T21:30:49Z", "published": "2024-05-21T18:31:20Z", "aliases": [ "CVE-2023-52749" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nspi: Fix null dereference on suspend\n\nA race condition exists where a synchronous (noqueue) transfer can be\nactive during a system suspend. This can cause a null pointer\ndereference exception to occur when the system resumes.\n\nExample order of events leading to the exception:\n1. spi_sync() calls __spi_transfer_message_noqueue() which sets\n ctlr->cur_msg\n2. Spi transfer begins via spi_transfer_one_message()\n3. System is suspended interrupting the transfer context\n4. System is resumed\n6. spi_controller_resume() calls spi_start_queue() which resets cur_msg\n to NULL\n7. Spi transfer context resumes and spi_finalize_current_message() is\n called which dereferences cur_msg (which is now NULL)\n\nWait for synchronous transfers to complete before suspending by\nacquiring the bus mutex and setting/checking a suspend flag.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-362" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T16:15:14Z" diff --git a/advisories/unreviewed/2024/05/GHSA-rcc5-r3m3-9rvc/GHSA-rcc5-r3m3-9rvc.json b/advisories/unreviewed/2024/05/GHSA-rcc5-r3m3-9rvc/GHSA-rcc5-r3m3-9rvc.json index 528867e2081..3734c85e6e4 100644 --- a/advisories/unreviewed/2024/05/GHSA-rcc5-r3m3-9rvc/GHSA-rcc5-r3m3-9rvc.json +++ b/advisories/unreviewed/2024/05/GHSA-rcc5-r3m3-9rvc/GHSA-rcc5-r3m3-9rvc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rcc5-r3m3-9rvc", - "modified": "2024-05-22T09:31:46Z", + "modified": "2025-01-06T21:30:49Z", "published": "2024-05-22T09:31:46Z", "aliases": [ "CVE-2021-47485" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nIB/qib: Protect from buffer overflow in struct qib_user_sdma_pkt fields\n\nOverflowing either addrlimit or bytes_togo can allow userspace to trigger\na buffer overflow of kernel memory. Check for overflows in all the places\ndoing math on user controlled buffers.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-22T09:15:10Z" diff --git a/advisories/unreviewed/2024/05/GHSA-vr35-f6m3-rh89/GHSA-vr35-f6m3-rh89.json b/advisories/unreviewed/2024/05/GHSA-vr35-f6m3-rh89/GHSA-vr35-f6m3-rh89.json index e23d8e91772..b6aa0174a0c 100644 --- a/advisories/unreviewed/2024/05/GHSA-vr35-f6m3-rh89/GHSA-vr35-f6m3-rh89.json +++ b/advisories/unreviewed/2024/05/GHSA-vr35-f6m3-rh89/GHSA-vr35-f6m3-rh89.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vr35-f6m3-rh89", - "modified": "2024-05-21T18:31:20Z", + "modified": "2025-01-06T21:30:49Z", "published": "2024-05-21T18:31:20Z", "aliases": [ "CVE-2023-52767" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntls: fix NULL deref on tls_sw_splice_eof() with empty record\n\nsyzkaller discovered that if tls_sw_splice_eof() is executed as part of\nsendfile() when the plaintext/ciphertext sk_msg are empty, the send path\ngets confused because the empty ciphertext buffer does not have enough\nspace for the encryption overhead. This causes tls_push_record() to go on\nthe `split = true` path (which is only supposed to be used when interacting\nwith an attached BPF program), and then get further confused and hit the\ntls_merge_open_record() path, which then assumes that there must be at\nleast one populated buffer element, leading to a NULL deref.\n\nIt is possible to have empty plaintext/ciphertext buffers if we previously\nbailed from tls_sw_sendmsg_locked() via the tls_trim_both_msgs() path.\ntls_sw_push_pending_record() already handles this case correctly; let's do\nthe same check in tls_sw_splice_eof().", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T16:15:15Z" diff --git a/advisories/unreviewed/2024/05/GHSA-vrmw-4324-6mfp/GHSA-vrmw-4324-6mfp.json b/advisories/unreviewed/2024/05/GHSA-vrmw-4324-6mfp/GHSA-vrmw-4324-6mfp.json index e9edcae968a..5895d480afb 100644 --- a/advisories/unreviewed/2024/05/GHSA-vrmw-4324-6mfp/GHSA-vrmw-4324-6mfp.json +++ b/advisories/unreviewed/2024/05/GHSA-vrmw-4324-6mfp/GHSA-vrmw-4324-6mfp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vrmw-4324-6mfp", - "modified": "2024-05-21T18:31:20Z", + "modified": "2025-01-06T21:30:49Z", "published": "2024-05-21T18:31:20Z", "aliases": [ "CVE-2023-52770" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: split initial and dynamic conditions for extent_cache\n\nLet's allocate the extent_cache tree without dynamic conditions to avoid a\nmissing condition causing a panic as below.\n\n # create a file w/ a compressed flag\n # disable the compression\n # panic while updating extent_cache\n\nF2FS-fs (dm-64): Swapfile: last extent is not aligned to section\nF2FS-fs (dm-64): Swapfile (3) is not align to section: 1) creat(), 2) ioctl(F2FS_IOC_SET_PIN_FILE), 3) fallocate(2097152 * N)\nAdding 124996k swap on ./swap-file. Priority:0 extents:2 across:17179494468k\n==================================================================\nBUG: KASAN: null-ptr-deref in instrument_atomic_read_write out/common/include/linux/instrumented.h:101 [inline]\nBUG: KASAN: null-ptr-deref in atomic_try_cmpxchg_acquire out/common/include/asm-generic/atomic-instrumented.h:705 [inline]\nBUG: KASAN: null-ptr-deref in queued_write_lock out/common/include/asm-generic/qrwlock.h:92 [inline]\nBUG: KASAN: null-ptr-deref in __raw_write_lock out/common/include/linux/rwlock_api_smp.h:211 [inline]\nBUG: KASAN: null-ptr-deref in _raw_write_lock+0x5a/0x110 out/common/kernel/locking/spinlock.c:295\nWrite of size 4 at addr 0000000000000030 by task syz-executor154/3327\n\nCPU: 0 PID: 3327 Comm: syz-executor154 Tainted: G O 5.10.185 #1\nHardware name: emulation qemu-x86/qemu-x86, BIOS 2023.01-21885-gb3cc1cd24d 01/01/2023\nCall Trace:\n __dump_stack out/common/lib/dump_stack.c:77 [inline]\n dump_stack_lvl+0x17e/0x1c4 out/common/lib/dump_stack.c:118\n __kasan_report+0x16c/0x260 out/common/mm/kasan/report.c:415\n kasan_report+0x51/0x70 out/common/mm/kasan/report.c:428\n kasan_check_range+0x2f3/0x340 out/common/mm/kasan/generic.c:186\n __kasan_check_write+0x14/0x20 out/common/mm/kasan/shadow.c:37\n instrument_atomic_read_write out/common/include/linux/instrumented.h:101 [inline]\n atomic_try_cmpxchg_acquire out/common/include/asm-generic/atomic-instrumented.h:705 [inline]\n queued_write_lock out/common/include/asm-generic/qrwlock.h:92 [inline]\n __raw_write_lock out/common/include/linux/rwlock_api_smp.h:211 [inline]\n _raw_write_lock+0x5a/0x110 out/common/kernel/locking/spinlock.c:295\n __drop_extent_tree+0xdf/0x2f0 out/common/fs/f2fs/extent_cache.c:1155\n f2fs_drop_extent_tree+0x17/0x30 out/common/fs/f2fs/extent_cache.c:1172\n f2fs_insert_range out/common/fs/f2fs/file.c:1600 [inline]\n f2fs_fallocate+0x19fd/0x1f40 out/common/fs/f2fs/file.c:1764\n vfs_fallocate+0x514/0x9b0 out/common/fs/open.c:310\n ksys_fallocate out/common/fs/open.c:333 [inline]\n __do_sys_fallocate out/common/fs/open.c:341 [inline]\n __se_sys_fallocate out/common/fs/open.c:339 [inline]\n __x64_sys_fallocate+0xb8/0x100 out/common/fs/open.c:339\n do_syscall_64+0x35/0x50 out/common/arch/x86/entry/common.c:46", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T16:15:16Z" diff --git a/advisories/unreviewed/2024/05/GHSA-wjg2-c8g7-rjjr/GHSA-wjg2-c8g7-rjjr.json b/advisories/unreviewed/2024/05/GHSA-wjg2-c8g7-rjjr/GHSA-wjg2-c8g7-rjjr.json index ceba53b7ca1..463c13e56f0 100644 --- a/advisories/unreviewed/2024/05/GHSA-wjg2-c8g7-rjjr/GHSA-wjg2-c8g7-rjjr.json +++ b/advisories/unreviewed/2024/05/GHSA-wjg2-c8g7-rjjr/GHSA-wjg2-c8g7-rjjr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wjg2-c8g7-rjjr", - "modified": "2024-05-21T18:31:23Z", + "modified": "2025-01-06T21:30:49Z", "published": "2024-05-21T18:31:23Z", "aliases": [ "CVE-2023-52873" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nclk: mediatek: clk-mt6779: Add check for mtk_alloc_clk_data\n\nAdd the check for the return value of mtk_alloc_clk_data() in order to\navoid NULL pointer dereference.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T16:15:24Z" diff --git a/advisories/unreviewed/2024/05/GHSA-wpg8-rfjm-9g3w/GHSA-wpg8-rfjm-9g3w.json b/advisories/unreviewed/2024/05/GHSA-wpg8-rfjm-9g3w/GHSA-wpg8-rfjm-9g3w.json index 556ecdacccf..66507d531d7 100644 --- a/advisories/unreviewed/2024/05/GHSA-wpg8-rfjm-9g3w/GHSA-wpg8-rfjm-9g3w.json +++ b/advisories/unreviewed/2024/05/GHSA-wpg8-rfjm-9g3w/GHSA-wpg8-rfjm-9g3w.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wpg8-rfjm-9g3w", - "modified": "2024-05-21T18:31:19Z", + "modified": "2025-01-06T21:30:49Z", "published": "2024-05-21T18:31:19Z", "aliases": [ "CVE-2023-52741" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncifs: Fix use-after-free in rdata->read_into_pages()\n\nWhen the network status is unstable, use-after-free may occur when\nread data from the server.\n\n BUG: KASAN: use-after-free in readpages_fill_pages+0x14c/0x7e0\n\n Call Trace:\n \n dump_stack_lvl+0x38/0x4c\n print_report+0x16f/0x4a6\n kasan_report+0xb7/0x130\n readpages_fill_pages+0x14c/0x7e0\n cifs_readv_receive+0x46d/0xa40\n cifs_demultiplex_thread+0x121c/0x1490\n kthread+0x16b/0x1a0\n ret_from_fork+0x2c/0x50\n \n\n Allocated by task 2535:\n kasan_save_stack+0x22/0x50\n kasan_set_track+0x25/0x30\n __kasan_kmalloc+0x82/0x90\n cifs_readdata_direct_alloc+0x2c/0x110\n cifs_readdata_alloc+0x2d/0x60\n cifs_readahead+0x393/0xfe0\n read_pages+0x12f/0x470\n page_cache_ra_unbounded+0x1b1/0x240\n filemap_get_pages+0x1c8/0x9a0\n filemap_read+0x1c0/0x540\n cifs_strict_readv+0x21b/0x240\n vfs_read+0x395/0x4b0\n ksys_read+0xb8/0x150\n do_syscall_64+0x3f/0x90\n entry_SYSCALL_64_after_hwframe+0x72/0xdc\n\n Freed by task 79:\n kasan_save_stack+0x22/0x50\n kasan_set_track+0x25/0x30\n kasan_save_free_info+0x2e/0x50\n __kasan_slab_free+0x10e/0x1a0\n __kmem_cache_free+0x7a/0x1a0\n cifs_readdata_release+0x49/0x60\n process_one_work+0x46c/0x760\n worker_thread+0x2a4/0x6f0\n kthread+0x16b/0x1a0\n ret_from_fork+0x2c/0x50\n\n Last potentially related work creation:\n kasan_save_stack+0x22/0x50\n __kasan_record_aux_stack+0x95/0xb0\n insert_work+0x2b/0x130\n __queue_work+0x1fe/0x660\n queue_work_on+0x4b/0x60\n smb2_readv_callback+0x396/0x800\n cifs_abort_connection+0x474/0x6a0\n cifs_reconnect+0x5cb/0xa50\n cifs_readv_from_socket.cold+0x22/0x6c\n cifs_read_page_from_socket+0xc1/0x100\n readpages_fill_pages.cold+0x2f/0x46\n cifs_readv_receive+0x46d/0xa40\n cifs_demultiplex_thread+0x121c/0x1490\n kthread+0x16b/0x1a0\n ret_from_fork+0x2c/0x50\n\nThe following function calls will cause UAF of the rdata pointer.\n\nreadpages_fill_pages\n cifs_read_page_from_socket\n cifs_readv_from_socket\n cifs_reconnect\n __cifs_reconnect\n cifs_abort_connection\n mid->callback() --> smb2_readv_callback\n queue_work(&rdata->work) # if the worker completes first,\n # the rdata is freed\n cifs_readv_complete\n kref_put\n cifs_readdata_release\n kfree(rdata)\n return rdata->... # UAF in readpages_fill_pages()\n\nSimilarly, this problem also occurs in the uncache_fill_pages().\n\nFix this by adjusts the order of condition judgment in the return\nstatement.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T16:15:14Z" diff --git a/advisories/unreviewed/2024/06/GHSA-j52p-q7q4-9vwc/GHSA-j52p-q7q4-9vwc.json b/advisories/unreviewed/2024/06/GHSA-j52p-q7q4-9vwc/GHSA-j52p-q7q4-9vwc.json index aea5babc91a..b19dc2e32dc 100644 --- a/advisories/unreviewed/2024/06/GHSA-j52p-q7q4-9vwc/GHSA-j52p-q7q4-9vwc.json +++ b/advisories/unreviewed/2024/06/GHSA-j52p-q7q4-9vwc/GHSA-j52p-q7q4-9vwc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-j52p-q7q4-9vwc", - "modified": "2024-06-20T12:31:21Z", + "modified": "2025-01-06T21:30:50Z", "published": "2024-06-20T12:31:21Z", "aliases": [ "CVE-2022-48746" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: Fix handling of wrong devices during bond netevent\n\nCurrent implementation of bond netevent handler only check if\nthe handled netdev is VF representor and it missing a check if\nthe VF representor is on the same phys device of the bond handling\nthe netevent.\n\nFix by adding the missing check and optimizing the check if\nthe netdev is VF representor so it will not access uninitialized\nprivate data and crashes.\n\nBUG: kernel NULL pointer dereference, address: 000000000000036c\nPGD 0 P4D 0\nOops: 0000 [#1] SMP NOPTI\nWorkqueue: eth3bond0 bond_mii_monitor [bonding]\nRIP: 0010:mlx5e_is_uplink_rep+0xc/0x50 [mlx5_core]\nRSP: 0018:ffff88812d69fd60 EFLAGS: 00010282\nRAX: 0000000000000000 RBX: ffff8881cf800000 RCX: 0000000000000000\nRDX: ffff88812d69fe10 RSI: 000000000000001b RDI: ffff8881cf800880\nRBP: ffff8881cf800000 R08: 00000445cabccf2b R09: 0000000000000008\nR10: 0000000000000004 R11: 0000000000000008 R12: ffff88812d69fe10\nR13: 00000000fffffffe R14: ffff88820c0f9000 R15: 0000000000000000\nFS: 0000000000000000(0000) GS:ffff88846fb00000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 000000000000036c CR3: 0000000103d80006 CR4: 0000000000370ea0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nCall Trace:\n mlx5e_eswitch_uplink_rep+0x31/0x40 [mlx5_core]\n mlx5e_rep_is_lag_netdev+0x94/0xc0 [mlx5_core]\n mlx5e_rep_esw_bond_netevent+0xeb/0x3d0 [mlx5_core]\n raw_notifier_call_chain+0x41/0x60\n call_netdevice_notifiers_info+0x34/0x80\n netdev_lower_state_changed+0x4e/0xa0\n bond_mii_monitor+0x56b/0x640 [bonding]\n process_one_work+0x1b9/0x390\n worker_thread+0x4d/0x3d0\n ? rescuer_thread+0x350/0x350\n kthread+0x124/0x150\n ? set_kthread_struct+0x40/0x40\n ret_from_fork+0x1f/0x30", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-20T12:15:12Z" diff --git a/advisories/unreviewed/2024/12/GHSA-22x4-j6vj-fmm5/GHSA-22x4-j6vj-fmm5.json b/advisories/unreviewed/2024/12/GHSA-22x4-j6vj-fmm5/GHSA-22x4-j6vj-fmm5.json index 4c67dd7851c..9c1e7bfd059 100644 --- a/advisories/unreviewed/2024/12/GHSA-22x4-j6vj-fmm5/GHSA-22x4-j6vj-fmm5.json +++ b/advisories/unreviewed/2024/12/GHSA-22x4-j6vj-fmm5/GHSA-22x4-j6vj-fmm5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-22x4-j6vj-fmm5", - "modified": "2024-12-27T15:31:56Z", + "modified": "2025-01-06T21:30:51Z", "published": "2024-12-27T15:31:56Z", "aliases": [ "CVE-2024-56664" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf, sockmap: Fix race between element replace and close()\n\nElement replace (with a socket different from the one stored) may race\nwith socket's close() link popping & unlinking. __sock_map_delete()\nunconditionally unrefs the (wrong) element:\n\n// set map[0] = s0\nmap_update_elem(map, 0, s0)\n\n// drop fd of s0\nclose(s0)\n sock_map_close()\n lock_sock(sk) (s0!)\n sock_map_remove_links(sk)\n link = sk_psock_link_pop()\n sock_map_unlink(sk, link)\n sock_map_delete_from_link\n // replace map[0] with s1\n map_update_elem(map, 0, s1)\n sock_map_update_elem\n (s1!) lock_sock(sk)\n sock_map_update_common\n psock = sk_psock(sk)\n spin_lock(&stab->lock)\n osk = stab->sks[idx]\n sock_map_add_link(..., &stab->sks[idx])\n sock_map_unref(osk, &stab->sks[idx])\n psock = sk_psock(osk)\n sk_psock_put(sk, psock)\n if (refcount_dec_and_test(&psock))\n sk_psock_drop(sk, psock)\n spin_unlock(&stab->lock)\n unlock_sock(sk)\n __sock_map_delete\n spin_lock(&stab->lock)\n sk = *psk // s1 replaced s0; sk == s1\n if (!sk_test || sk_test == sk) // sk_test (s0) != sk (s1); no branch\n sk = xchg(psk, NULL)\n if (sk)\n sock_map_unref(sk, psk) // unref s1; sks[idx] will dangle\n psock = sk_psock(sk)\n sk_psock_put(sk, psock)\n if (refcount_dec_and_test())\n sk_psock_drop(sk, psock)\n spin_unlock(&stab->lock)\n release_sock(sk)\n\nThen close(map) enqueues bpf_map_free_deferred, which finally calls\nsock_map_free(). This results in some refcount_t warnings along with\na KASAN splat [1].\n\nFix __sock_map_delete(), do not allow sock_map_unref() on elements that\nmay have been replaced.\n\n[1]:\nBUG: KASAN: slab-use-after-free in sock_map_free+0x10e/0x330\nWrite of size 4 at addr ffff88811f5b9100 by task kworker/u64:12/1063\n\nCPU: 14 UID: 0 PID: 1063 Comm: kworker/u64:12 Not tainted 6.12.0+ #125\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS Arch Linux 1.16.3-1-1 04/01/2014\nWorkqueue: events_unbound bpf_map_free_deferred\nCall Trace:\n \n dump_stack_lvl+0x68/0x90\n print_report+0x174/0x4f6\n kasan_report+0xb9/0x190\n kasan_check_range+0x10f/0x1e0\n sock_map_free+0x10e/0x330\n bpf_map_free_deferred+0x173/0x320\n process_one_work+0x846/0x1420\n worker_thread+0x5b3/0xf80\n kthread+0x29e/0x360\n ret_from_fork+0x2d/0x70\n ret_from_fork_asm+0x1a/0x30\n \n\nAllocated by task 1202:\n kasan_save_stack+0x1e/0x40\n kasan_save_track+0x10/0x30\n __kasan_slab_alloc+0x85/0x90\n kmem_cache_alloc_noprof+0x131/0x450\n sk_prot_alloc+0x5b/0x220\n sk_alloc+0x2c/0x870\n unix_create1+0x88/0x8a0\n unix_create+0xc5/0x180\n __sock_create+0x241/0x650\n __sys_socketpair+0x1ce/0x420\n __x64_sys_socketpair+0x92/0x100\n do_syscall_64+0x93/0x180\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\nFreed by task 46:\n kasan_save_stack+0x1e/0x40\n kasan_save_track+0x10/0x30\n kasan_save_free_info+0x37/0x60\n __kasan_slab_free+0x4b/0x70\n kmem_cache_free+0x1a1/0x590\n __sk_destruct+0x388/0x5a0\n sk_psock_destroy+0x73e/0xa50\n process_one_work+0x846/0x1420\n worker_thread+0x5b3/0xf80\n kthread+0x29e/0x360\n ret_from_fork+0x2d/0x70\n ret_from_fork_asm+0x1a/0x30\n\nThe bu\n---truncated---", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-362" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T15:15:26Z" diff --git a/advisories/unreviewed/2024/12/GHSA-2398-v7wm-x7gr/GHSA-2398-v7wm-x7gr.json b/advisories/unreviewed/2024/12/GHSA-2398-v7wm-x7gr/GHSA-2398-v7wm-x7gr.json index 3beeb50612f..d44e2cb694d 100644 --- a/advisories/unreviewed/2024/12/GHSA-2398-v7wm-x7gr/GHSA-2398-v7wm-x7gr.json +++ b/advisories/unreviewed/2024/12/GHSA-2398-v7wm-x7gr/GHSA-2398-v7wm-x7gr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2398-v7wm-x7gr", - "modified": "2024-12-29T12:30:41Z", + "modified": "2025-01-06T21:30:51Z", "published": "2024-12-29T12:30:41Z", "aliases": [ "CVE-2024-56756" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnvme-pci: fix freeing of the HMB descriptor table\n\nThe HMB descriptor table is sized to the maximum number of descriptors\nthat could be used for a given device, but __nvme_alloc_host_mem could\nbreak out of the loop earlier on memory allocation failure and end up\nusing less descriptors than planned for, which leads to an incorrect\nsize passed to dma_free_coherent.\n\nIn practice this was not showing up because the number of descriptors\ntends to be low and the dma coherent allocator always allocates and\nfrees at least a page.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -49,7 +54,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-29T12:15:09Z" diff --git a/advisories/unreviewed/2024/12/GHSA-23x6-w5q4-2mqw/GHSA-23x6-w5q4-2mqw.json b/advisories/unreviewed/2024/12/GHSA-23x6-w5q4-2mqw/GHSA-23x6-w5q4-2mqw.json index df001385a8e..d03f5d9e8eb 100644 --- a/advisories/unreviewed/2024/12/GHSA-23x6-w5q4-2mqw/GHSA-23x6-w5q4-2mqw.json +++ b/advisories/unreviewed/2024/12/GHSA-23x6-w5q4-2mqw/GHSA-23x6-w5q4-2mqw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-23x6-w5q4-2mqw", - "modified": "2024-12-27T15:31:56Z", + "modified": "2025-01-06T21:30:50Z", "published": "2024-12-27T15:31:56Z", "aliases": [ "CVE-2024-56658" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: defer final 'struct net' free in netns dismantle\n\nIlya reported a slab-use-after-free in dst_destroy [1]\n\nIssue is in xfrm6_net_init() and xfrm4_net_init() :\n\nThey copy xfrm[46]_dst_ops_template into net->xfrm.xfrm[46]_dst_ops.\n\nBut net structure might be freed before all the dst callbacks are\ncalled. So when dst_destroy() calls later :\n\nif (dst->ops->destroy)\n dst->ops->destroy(dst);\n\ndst->ops points to the old net->xfrm.xfrm[46]_dst_ops, which has been freed.\n\nSee a relevant issue fixed in :\n\nac888d58869b (\"net: do not delay dst_entries_add() in dst_release()\")\n\nA fix is to queue the 'struct net' to be freed after one\nanother cleanup_net() round (and existing rcu_barrier())\n\n[1]\n\nBUG: KASAN: slab-use-after-free in dst_destroy (net/core/dst.c:112)\nRead of size 8 at addr ffff8882137ccab0 by task swapper/37/0\nDec 03 05:46:18 kernel:\nCPU: 37 UID: 0 PID: 0 Comm: swapper/37 Kdump: loaded Not tainted 6.12.0 #67\nHardware name: Red Hat KVM/RHEL, BIOS 1.16.1-1.el9 04/01/2014\nCall Trace:\n \ndump_stack_lvl (lib/dump_stack.c:124)\nprint_address_description.constprop.0 (mm/kasan/report.c:378)\n? dst_destroy (net/core/dst.c:112)\nprint_report (mm/kasan/report.c:489)\n? dst_destroy (net/core/dst.c:112)\n? kasan_addr_to_slab (mm/kasan/common.c:37)\nkasan_report (mm/kasan/report.c:603)\n? dst_destroy (net/core/dst.c:112)\n? rcu_do_batch (kernel/rcu/tree.c:2567)\ndst_destroy (net/core/dst.c:112)\nrcu_do_batch (kernel/rcu/tree.c:2567)\n? __pfx_rcu_do_batch (kernel/rcu/tree.c:2491)\n? lockdep_hardirqs_on_prepare (kernel/locking/lockdep.c:4339 kernel/locking/lockdep.c:4406)\nrcu_core (kernel/rcu/tree.c:2825)\nhandle_softirqs (kernel/softirq.c:554)\n__irq_exit_rcu (kernel/softirq.c:589 kernel/softirq.c:428 kernel/softirq.c:637)\nirq_exit_rcu (kernel/softirq.c:651)\nsysvec_apic_timer_interrupt (arch/x86/kernel/apic/apic.c:1049 arch/x86/kernel/apic/apic.c:1049)\n \n \nasm_sysvec_apic_timer_interrupt (./arch/x86/include/asm/idtentry.h:702)\nRIP: 0010:default_idle (./arch/x86/include/asm/irqflags.h:37 ./arch/x86/include/asm/irqflags.h:92 arch/x86/kernel/process.c:743)\nCode: 00 4d 29 c8 4c 01 c7 4c 29 c2 e9 6e ff ff ff 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 66 90 0f 00 2d c7 c9 27 00 fb f4 c3 cc cc cc cc 66 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 90\nRSP: 0018:ffff888100d2fe00 EFLAGS: 00000246\nRAX: 00000000001870ed RBX: 1ffff110201a5fc2 RCX: ffffffffb61a3e46\nRDX: 0000000000000000 RSI: 0000000000000000 RDI: ffffffffb3d4d123\nRBP: 0000000000000000 R08: 0000000000000001 R09: ffffed11c7e1835d\nR10: ffff888e3f0c1aeb R11: 0000000000000000 R12: 0000000000000000\nR13: ffff888100d20000 R14: dffffc0000000000 R15: 0000000000000000\n? ct_kernel_exit.constprop.0 (kernel/context_tracking.c:148)\n? cpuidle_idle_call (kernel/sched/idle.c:186)\ndefault_idle_call (./include/linux/cpuidle.h:143 kernel/sched/idle.c:118)\ncpuidle_idle_call (kernel/sched/idle.c:186)\n? __pfx_cpuidle_idle_call (kernel/sched/idle.c:168)\n? lock_release (kernel/locking/lockdep.c:467 kernel/locking/lockdep.c:5848)\n? lockdep_hardirqs_on_prepare (kernel/locking/lockdep.c:4347 kernel/locking/lockdep.c:4406)\n? tsc_verify_tsc_adjust (arch/x86/kernel/tsc_sync.c:59)\ndo_idle (kernel/sched/idle.c:326)\ncpu_startup_entry (kernel/sched/idle.c:423 (discriminator 1))\nstart_secondary (arch/x86/kernel/smpboot.c:202 arch/x86/kernel/smpboot.c:282)\n? __pfx_start_secondary (arch/x86/kernel/smpboot.c:232)\n? soft_restart_cpu (arch/x86/kernel/head_64.S:452)\ncommon_startup_64 (arch/x86/kernel/head_64.S:414)\n \nDec 03 05:46:18 kernel:\nAllocated by task 12184:\nkasan_save_stack (mm/kasan/common.c:48)\nkasan_save_track (./arch/x86/include/asm/current.h:49 mm/kasan/common.c:60 mm/kasan/common.c:69)\n__kasan_slab_alloc (mm/kasan/common.c:319 mm/kasan/common.c:345)\nkmem_cache_alloc_noprof (mm/slub.c:4085 mm/slub.c:4134 mm/slub.c:4141)\ncopy_net_ns (net/core/net_namespace.c:421 net/core/net_namespace.c:480)\ncreate_new_namespaces\n---truncated---", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T15:15:25Z" diff --git a/advisories/unreviewed/2024/12/GHSA-2cxg-hjm3-xmvr/GHSA-2cxg-hjm3-xmvr.json b/advisories/unreviewed/2024/12/GHSA-2cxg-hjm3-xmvr/GHSA-2cxg-hjm3-xmvr.json index 4dc4e99a3db..22851b2c185 100644 --- a/advisories/unreviewed/2024/12/GHSA-2cxg-hjm3-xmvr/GHSA-2cxg-hjm3-xmvr.json +++ b/advisories/unreviewed/2024/12/GHSA-2cxg-hjm3-xmvr/GHSA-2cxg-hjm3-xmvr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2cxg-hjm3-xmvr", - "modified": "2024-12-29T12:30:41Z", + "modified": "2025-01-06T21:30:51Z", "published": "2024-12-29T12:30:41Z", "aliases": [ "CVE-2024-56755" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfs/fscache: Add a memory barrier for FSCACHE_VOLUME_CREATING\n\nIn fscache_create_volume(), there is a missing memory barrier between the\nbit-clearing operation and the wake-up operation. This may cause a\nsituation where, after a wake-up, the bit-clearing operation hasn't been\ndetected yet, leading to an indefinite wait. The triggering process is as\nfollows:\n\n [cookie1] [cookie2] [volume_work]\nfscache_perform_lookup\n fscache_create_volume\n fscache_perform_lookup\n fscache_create_volume\n\t\t\t fscache_create_volume_work\n cachefiles_acquire_volume\n clear_and_wake_up_bit\n test_and_set_bit\n test_and_set_bit\n goto maybe_wait\n goto no_wait\n\nIn the above process, cookie1 and cookie2 has the same volume. When cookie1\nenters the -no_wait- process, it will clear the bit and wake up the waiting\nprocess. If a barrier is missing, it may cause cookie2 to remain in the\n-wait- process indefinitely.\n\nIn commit 3288666c7256 (\"fscache: Use clear_and_wake_up_bit() in\nfscache_create_volume_work()\"), barriers were added to similar operations\nin fscache_create_volume_work(), but fscache_create_volume() was missed.\n\nBy combining the clear and wake operations into clear_and_wake_up_bit() to\nfix this issue.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-29T12:15:09Z" diff --git a/advisories/unreviewed/2024/12/GHSA-2x5w-q4pc-79qx/GHSA-2x5w-q4pc-79qx.json b/advisories/unreviewed/2024/12/GHSA-2x5w-q4pc-79qx/GHSA-2x5w-q4pc-79qx.json index 2394ef0f9a7..4d12816b0eb 100644 --- a/advisories/unreviewed/2024/12/GHSA-2x5w-q4pc-79qx/GHSA-2x5w-q4pc-79qx.json +++ b/advisories/unreviewed/2024/12/GHSA-2x5w-q4pc-79qx/GHSA-2x5w-q4pc-79qx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2x5w-q4pc-79qx", - "modified": "2024-12-27T15:31:56Z", + "modified": "2025-01-06T21:30:50Z", "published": "2024-12-27T15:31:56Z", "aliases": [ "CVE-2024-56665" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf,perf: Fix invalid prog_array access in perf_event_detach_bpf_prog\n\nSyzbot reported [1] crash that happens for following tracing scenario:\n\n - create tracepoint perf event with attr.inherit=1, attach it to the\n process and set bpf program to it\n - attached process forks -> chid creates inherited event\n\n the new child event shares the parent's bpf program and tp_event\n (hence prog_array) which is global for tracepoint\n\n - exit both process and its child -> release both events\n - first perf_event_detach_bpf_prog call will release tp_event->prog_array\n and second perf_event_detach_bpf_prog will crash, because\n tp_event->prog_array is NULL\n\nThe fix makes sure the perf_event_detach_bpf_prog checks prog_array\nis valid before it tries to remove the bpf program from it.\n\n[1] https://lore.kernel.org/bpf/Z1MR6dCIKajNS6nU@krava/T/#m91dbf0688221ec7a7fc95e896a7ef9ff93b0b8ad", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -33,7 +38,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T15:15:26Z" diff --git a/advisories/unreviewed/2024/12/GHSA-48hg-p6jq-42h2/GHSA-48hg-p6jq-42h2.json b/advisories/unreviewed/2024/12/GHSA-48hg-p6jq-42h2/GHSA-48hg-p6jq-42h2.json index 97b4bcd5e2d..9e9c3173d79 100644 --- a/advisories/unreviewed/2024/12/GHSA-48hg-p6jq-42h2/GHSA-48hg-p6jq-42h2.json +++ b/advisories/unreviewed/2024/12/GHSA-48hg-p6jq-42h2/GHSA-48hg-p6jq-42h2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-48hg-p6jq-42h2", - "modified": "2024-12-27T15:31:56Z", + "modified": "2025-01-06T21:30:50Z", "published": "2024-12-27T15:31:56Z", "aliases": [ "CVE-2024-56663" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: nl80211: fix NL80211_ATTR_MLO_LINK_ID off-by-one\n\nSince the netlink attribute range validation provides inclusive\nchecking, the *max* of attribute NL80211_ATTR_MLO_LINK_ID should be\nIEEE80211_MLD_MAX_NUM_LINKS - 1 otherwise causing an off-by-one.\n\nOne crash stack for demonstration:\n==================================================================\nBUG: KASAN: wild-memory-access in ieee80211_tx_control_port+0x3b6/0xca0 net/mac80211/tx.c:5939\nRead of size 6 at addr 001102080000000c by task fuzzer.386/9508\n\nCPU: 1 PID: 9508 Comm: syz.1.386 Not tainted 6.1.70 #2\nCall Trace:\n \n __dump_stack lib/dump_stack.c:88 [inline]\n dump_stack_lvl+0x177/0x231 lib/dump_stack.c:106\n print_report+0xe0/0x750 mm/kasan/report.c:398\n kasan_report+0x139/0x170 mm/kasan/report.c:495\n kasan_check_range+0x287/0x290 mm/kasan/generic.c:189\n memcpy+0x25/0x60 mm/kasan/shadow.c:65\n ieee80211_tx_control_port+0x3b6/0xca0 net/mac80211/tx.c:5939\n rdev_tx_control_port net/wireless/rdev-ops.h:761 [inline]\n nl80211_tx_control_port+0x7b3/0xc40 net/wireless/nl80211.c:15453\n genl_family_rcv_msg_doit+0x22e/0x320 net/netlink/genetlink.c:756\n genl_family_rcv_msg net/netlink/genetlink.c:833 [inline]\n genl_rcv_msg+0x539/0x740 net/netlink/genetlink.c:850\n netlink_rcv_skb+0x1de/0x420 net/netlink/af_netlink.c:2508\n genl_rcv+0x24/0x40 net/netlink/genetlink.c:861\n netlink_unicast_kernel net/netlink/af_netlink.c:1326 [inline]\n netlink_unicast+0x74b/0x8c0 net/netlink/af_netlink.c:1352\n netlink_sendmsg+0x882/0xb90 net/netlink/af_netlink.c:1874\n sock_sendmsg_nosec net/socket.c:716 [inline]\n __sock_sendmsg net/socket.c:728 [inline]\n ____sys_sendmsg+0x5cc/0x8f0 net/socket.c:2499\n ___sys_sendmsg+0x21c/0x290 net/socket.c:2553\n __sys_sendmsg net/socket.c:2582 [inline]\n __do_sys_sendmsg net/socket.c:2591 [inline]\n __se_sys_sendmsg+0x19e/0x270 net/socket.c:2589\n do_syscall_x64 arch/x86/entry/common.c:51 [inline]\n do_syscall_64+0x45/0x90 arch/x86/entry/common.c:81\n entry_SYSCALL_64_after_hwframe+0x63/0xcd\n\nUpdate the policy to ensure correct validation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-193" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T15:15:26Z" diff --git a/advisories/unreviewed/2024/12/GHSA-48x4-xr25-pcvw/GHSA-48x4-xr25-pcvw.json b/advisories/unreviewed/2024/12/GHSA-48x4-xr25-pcvw/GHSA-48x4-xr25-pcvw.json index e61ec6f0b9b..247bf00e98b 100644 --- a/advisories/unreviewed/2024/12/GHSA-48x4-xr25-pcvw/GHSA-48x4-xr25-pcvw.json +++ b/advisories/unreviewed/2024/12/GHSA-48x4-xr25-pcvw/GHSA-48x4-xr25-pcvw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-48x4-xr25-pcvw", - "modified": "2024-12-27T15:31:56Z", + "modified": "2025-01-06T21:30:50Z", "published": "2024-12-27T15:31:56Z", "aliases": [ "CVE-2024-56662" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nacpi: nfit: vmalloc-out-of-bounds Read in acpi_nfit_ctl\n\nFix an issue detected by syzbot with KASAN:\n\nBUG: KASAN: vmalloc-out-of-bounds in cmd_to_func drivers/acpi/nfit/\ncore.c:416 [inline]\nBUG: KASAN: vmalloc-out-of-bounds in acpi_nfit_ctl+0x20e8/0x24a0\ndrivers/acpi/nfit/core.c:459\n\nThe issue occurs in cmd_to_func when the call_pkg->nd_reserved2\narray is accessed without verifying that call_pkg points to a buffer\nthat is appropriately sized as a struct nd_cmd_pkg. This can lead\nto out-of-bounds access and undefined behavior if the buffer does not\nhave sufficient space.\n\nTo address this, a check was added in acpi_nfit_ctl() to ensure that\nbuf is not NULL and that buf_len is less than sizeof(*call_pkg)\nbefore accessing it. This ensures safe access to the members of\ncall_pkg, including the nd_reserved2 array.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T15:15:26Z" diff --git a/advisories/unreviewed/2024/12/GHSA-4g6f-5r4h-c449/GHSA-4g6f-5r4h-c449.json b/advisories/unreviewed/2024/12/GHSA-4g6f-5r4h-c449/GHSA-4g6f-5r4h-c449.json index c2150b88fcb..0bbf7bfecf4 100644 --- a/advisories/unreviewed/2024/12/GHSA-4g6f-5r4h-c449/GHSA-4g6f-5r4h-c449.json +++ b/advisories/unreviewed/2024/12/GHSA-4g6f-5r4h-c449/GHSA-4g6f-5r4h-c449.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4g6f-5r4h-c449", - "modified": "2024-12-27T15:31:56Z", + "modified": "2025-01-06T21:30:50Z", "published": "2024-12-27T15:31:56Z", "aliases": [ "CVE-2024-56661" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: fix NULL deref in cleanup_bearer()\n\nsyzbot found [1] that after blamed commit, ub->ubsock->sk\nwas NULL when attempting the atomic_dec() :\n\natomic_dec(&tipc_net(sock_net(ub->ubsock->sk))->wq_count);\n\nFix this by caching the tipc_net pointer.\n\n[1]\n\nOops: general protection fault, probably for non-canonical address 0xdffffc0000000006: 0000 [#1] PREEMPT SMP KASAN PTI\nKASAN: null-ptr-deref in range [0x0000000000000030-0x0000000000000037]\nCPU: 0 UID: 0 PID: 5896 Comm: kworker/0:3 Not tainted 6.13.0-rc1-next-20241203-syzkaller #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024\nWorkqueue: events cleanup_bearer\n RIP: 0010:read_pnet include/net/net_namespace.h:387 [inline]\n RIP: 0010:sock_net include/net/sock.h:655 [inline]\n RIP: 0010:cleanup_bearer+0x1f7/0x280 net/tipc/udp_media.c:820\nCode: 18 48 89 d8 48 c1 e8 03 42 80 3c 28 00 74 08 48 89 df e8 3c f7 99 f6 48 8b 1b 48 83 c3 30 e8 f0 e4 60 00 48 89 d8 48 c1 e8 03 <42> 80 3c 28 00 74 08 48 89 df e8 1a f7 99 f6 49 83 c7 e8 48 8b 1b\nRSP: 0018:ffffc9000410fb70 EFLAGS: 00010206\nRAX: 0000000000000006 RBX: 0000000000000030 RCX: ffff88802fe45a00\nRDX: 0000000000000001 RSI: 0000000000000008 RDI: ffffc9000410f900\nRBP: ffff88807e1f0908 R08: ffffc9000410f907 R09: 1ffff92000821f20\nR10: dffffc0000000000 R11: fffff52000821f21 R12: ffff888031d19980\nR13: dffffc0000000000 R14: dffffc0000000000 R15: ffff88807e1f0918\nFS: 0000000000000000(0000) GS:ffff8880b8600000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000556ca050b000 CR3: 0000000031c0c000 CR4: 00000000003526f0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T15:15:25Z" diff --git a/advisories/unreviewed/2024/12/GHSA-4whv-g373-hpgc/GHSA-4whv-g373-hpgc.json b/advisories/unreviewed/2024/12/GHSA-4whv-g373-hpgc/GHSA-4whv-g373-hpgc.json index 89a9013bf8b..e59a28d680f 100644 --- a/advisories/unreviewed/2024/12/GHSA-4whv-g373-hpgc/GHSA-4whv-g373-hpgc.json +++ b/advisories/unreviewed/2024/12/GHSA-4whv-g373-hpgc/GHSA-4whv-g373-hpgc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4whv-g373-hpgc", - "modified": "2024-12-27T15:31:56Z", + "modified": "2025-01-06T21:30:50Z", "published": "2024-12-27T15:31:56Z", "aliases": [ "CVE-2024-56660" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: DR, prevent potential error pointer dereference\n\nThe dr_domain_add_vport_cap() function generally returns NULL on error\nbut sometimes we want it to return ERR_PTR(-EBUSY) so the caller can\nretry. The problem here is that \"ret\" can be either -EBUSY or -ENOMEM\nand if it's and -ENOMEM then the error pointer is propogated back and\neventually dereferenced in dr_ste_v0_build_src_gvmi_qpn_tag().", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T15:15:25Z" diff --git a/advisories/unreviewed/2024/12/GHSA-4xh3-3533-7mmv/GHSA-4xh3-3533-7mmv.json b/advisories/unreviewed/2024/12/GHSA-4xh3-3533-7mmv/GHSA-4xh3-3533-7mmv.json index 8382465e5e9..17d01c46073 100644 --- a/advisories/unreviewed/2024/12/GHSA-4xh3-3533-7mmv/GHSA-4xh3-3533-7mmv.json +++ b/advisories/unreviewed/2024/12/GHSA-4xh3-3533-7mmv/GHSA-4xh3-3533-7mmv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4xh3-3533-7mmv", - "modified": "2024-12-27T15:31:56Z", + "modified": "2025-01-06T21:30:50Z", "published": "2024-12-27T15:31:56Z", "aliases": [ "CVE-2024-56655" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: do not defer rule destruction via call_rcu\n\nnf_tables_chain_destroy can sleep, it can't be used from call_rcu\ncallbacks.\n\nMoreover, nf_tables_rule_release() is only safe for error unwinding,\nwhile transaction mutex is held and the to-be-desroyed rule was not\nexposed to either dataplane or dumps, as it deactives+frees without\nthe required synchronize_rcu() in-between.\n\nnft_rule_expr_deactivate() callbacks will change ->use counters\nof other chains/sets, see e.g. nft_lookup .deactivate callback, these\nmust be serialized via transaction mutex.\n\nAlso add a few lockdep asserts to make this more explicit.\n\nCalling synchronize_rcu() isn't ideal, but fixing this without is hard\nand way more intrusive. As-is, we can get:\n\nWARNING: .. net/netfilter/nf_tables_api.c:5515 nft_set_destroy+0x..\nWorkqueue: events nf_tables_trans_destroy_work\nRIP: 0010:nft_set_destroy+0x3fe/0x5c0\nCall Trace:\n \n nf_tables_trans_destroy_work+0x6b7/0xad0\n process_one_work+0x64a/0xce0\n worker_thread+0x613/0x10d0\n\nIn case the synchronize_rcu becomes an issue, we can explore alternatives.\n\nOne way would be to allocate nft_trans_rule objects + one nft_trans_chain\nobject, deactivate the rules + the chain and then defer the freeing to the\nnft destroy workqueue. We'd still need to keep the synchronize_rcu path as\na fallback to handle -ENOMEM corner cases though.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -29,7 +34,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T15:15:25Z" diff --git a/advisories/unreviewed/2024/12/GHSA-7m9x-pr76-7p23/GHSA-7m9x-pr76-7p23.json b/advisories/unreviewed/2024/12/GHSA-7m9x-pr76-7p23/GHSA-7m9x-pr76-7p23.json index 2d657ee5067..50899836ee4 100644 --- a/advisories/unreviewed/2024/12/GHSA-7m9x-pr76-7p23/GHSA-7m9x-pr76-7p23.json +++ b/advisories/unreviewed/2024/12/GHSA-7m9x-pr76-7p23/GHSA-7m9x-pr76-7p23.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7m9x-pr76-7p23", - "modified": "2024-12-29T12:30:41Z", + "modified": "2025-01-06T21:30:51Z", "published": "2024-12-29T12:30:41Z", "aliases": [ "CVE-2024-56754" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: caam - Fix the pointer passed to caam_qi_shutdown()\n\nThe type of the last parameter given to devm_add_action_or_reset() is\n\"struct caam_drv_private *\", but in caam_qi_shutdown(), it is casted to\n\"struct device *\".\n\nPass the correct parameter to devm_add_action_or_reset() so that the\nresources are released as expected.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -45,7 +50,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-29T12:15:08Z" diff --git a/advisories/unreviewed/2024/12/GHSA-7v7h-rp2j-g295/GHSA-7v7h-rp2j-g295.json b/advisories/unreviewed/2024/12/GHSA-7v7h-rp2j-g295/GHSA-7v7h-rp2j-g295.json index 9b256d32057..4ebbd5de4dd 100644 --- a/advisories/unreviewed/2024/12/GHSA-7v7h-rp2j-g295/GHSA-7v7h-rp2j-g295.json +++ b/advisories/unreviewed/2024/12/GHSA-7v7h-rp2j-g295/GHSA-7v7h-rp2j-g295.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7v7h-rp2j-g295", - "modified": "2024-12-27T15:31:56Z", + "modified": "2025-01-06T21:30:50Z", "published": "2024-12-27T15:31:56Z", "aliases": [ "CVE-2024-56659" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: lapb: increase LAPB_HEADER_LEN\n\nIt is unclear if net/lapb code is supposed to be ready for 8021q.\n\nWe can at least avoid crashes like the following :\n\nskbuff: skb_under_panic: text:ffffffff8aabe1f6 len:24 put:20 head:ffff88802824a400 data:ffff88802824a3fe tail:0x16 end:0x140 dev:nr0.2\n------------[ cut here ]------------\n kernel BUG at net/core/skbuff.c:206 !\nOops: invalid opcode: 0000 [#1] PREEMPT SMP KASAN PTI\nCPU: 1 UID: 0 PID: 5508 Comm: dhcpcd Not tainted 6.12.0-rc7-syzkaller-00144-g66418447d27b #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/30/2024\n RIP: 0010:skb_panic net/core/skbuff.c:206 [inline]\n RIP: 0010:skb_under_panic+0x14b/0x150 net/core/skbuff.c:216\nCode: 0d 8d 48 c7 c6 2e 9e 29 8e 48 8b 54 24 08 8b 0c 24 44 8b 44 24 04 4d 89 e9 50 41 54 41 57 41 56 e8 1a 6f 37 02 48 83 c4 20 90 <0f> 0b 0f 1f 00 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 f3\nRSP: 0018:ffffc90002ddf638 EFLAGS: 00010282\nRAX: 0000000000000086 RBX: dffffc0000000000 RCX: 7a24750e538ff600\nRDX: 0000000000000000 RSI: 0000000000000201 RDI: 0000000000000000\nRBP: ffff888034a86650 R08: ffffffff8174b13c R09: 1ffff920005bbe60\nR10: dffffc0000000000 R11: fffff520005bbe61 R12: 0000000000000140\nR13: ffff88802824a400 R14: ffff88802824a3fe R15: 0000000000000016\nFS: 00007f2a5990d740(0000) GS:ffff8880b8700000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 000000110c2631fd CR3: 0000000029504000 CR4: 00000000003526f0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nCall Trace:\n \n skb_push+0xe5/0x100 net/core/skbuff.c:2636\n nr_header+0x36/0x320 net/netrom/nr_dev.c:69\n dev_hard_header include/linux/netdevice.h:3148 [inline]\n vlan_dev_hard_header+0x359/0x480 net/8021q/vlan_dev.c:83\n dev_hard_header include/linux/netdevice.h:3148 [inline]\n lapbeth_data_transmit+0x1f6/0x2a0 drivers/net/wan/lapbether.c:257\n lapb_data_transmit+0x91/0xb0 net/lapb/lapb_iface.c:447\n lapb_transmit_buffer+0x168/0x1f0 net/lapb/lapb_out.c:149\n lapb_establish_data_link+0x84/0xd0\n lapb_device_event+0x4e0/0x670\n notifier_call_chain+0x19f/0x3e0 kernel/notifier.c:93\n __dev_notify_flags+0x207/0x400\n dev_change_flags+0xf0/0x1a0 net/core/dev.c:8922\n devinet_ioctl+0xa4e/0x1aa0 net/ipv4/devinet.c:1188\n inet_ioctl+0x3d7/0x4f0 net/ipv4/af_inet.c:1003\n sock_do_ioctl+0x158/0x460 net/socket.c:1227\n sock_ioctl+0x626/0x8e0 net/socket.c:1346\n vfs_ioctl fs/ioctl.c:51 [inline]\n __do_sys_ioctl fs/ioctl.c:907 [inline]\n __se_sys_ioctl+0xf9/0x170 fs/ioctl.c:893\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -45,7 +50,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T15:15:25Z" diff --git a/advisories/unreviewed/2024/12/GHSA-8p58-276h-xqq5/GHSA-8p58-276h-xqq5.json b/advisories/unreviewed/2024/12/GHSA-8p58-276h-xqq5/GHSA-8p58-276h-xqq5.json index c7ceaf7d3d9..90ccb05c0e5 100644 --- a/advisories/unreviewed/2024/12/GHSA-8p58-276h-xqq5/GHSA-8p58-276h-xqq5.json +++ b/advisories/unreviewed/2024/12/GHSA-8p58-276h-xqq5/GHSA-8p58-276h-xqq5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8p58-276h-xqq5", - "modified": "2024-12-27T15:31:55Z", + "modified": "2025-01-06T21:30:50Z", "published": "2024-12-27T15:31:55Z", "aliases": [ "CVE-2024-56652" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe/reg_sr: Remove register pool\n\nThat pool implementation doesn't really work: if the krealloc happens to\nmove the memory and return another address, the entries in the xarray\nbecome invalid, leading to use-after-free later:\n\n\tBUG: KASAN: slab-use-after-free in xe_reg_sr_apply_mmio+0x570/0x760 [xe]\n\tRead of size 4 at addr ffff8881244b2590 by task modprobe/2753\n\n\tAllocated by task 2753:\n\t kasan_save_stack+0x39/0x70\n\t kasan_save_track+0x14/0x40\n\t kasan_save_alloc_info+0x37/0x60\n\t __kasan_kmalloc+0xc3/0xd0\n\t __kmalloc_node_track_caller_noprof+0x200/0x6d0\n\t krealloc_noprof+0x229/0x380\n\nSimplify the code to fix the bug. A better pooling strategy may be added\nback later if needed.\n\n(cherry picked from commit e5283bd4dfecbd3335f43b62a68e24dae23f59e4)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T15:15:25Z" diff --git a/advisories/unreviewed/2024/12/GHSA-ghqp-926m-7jrx/GHSA-ghqp-926m-7jrx.json b/advisories/unreviewed/2024/12/GHSA-ghqp-926m-7jrx/GHSA-ghqp-926m-7jrx.json index 8613f4acc5d..7ca4c731bad 100644 --- a/advisories/unreviewed/2024/12/GHSA-ghqp-926m-7jrx/GHSA-ghqp-926m-7jrx.json +++ b/advisories/unreviewed/2024/12/GHSA-ghqp-926m-7jrx/GHSA-ghqp-926m-7jrx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-ghqp-926m-7jrx", - "modified": "2024-12-27T15:31:55Z", + "modified": "2025-01-06T21:30:50Z", "published": "2024-12-27T15:31:55Z", "aliases": [ "CVE-2024-56646" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: avoid possible NULL deref in modify_prefix_route()\n\nsyzbot found a NULL deref [1] in modify_prefix_route(), caused by one\nfib6_info without a fib6_table pointer set.\n\nThis can happen for net->ipv6.fib6_null_entry\n\n[1]\nOops: general protection fault, probably for non-canonical address 0xdffffc0000000006: 0000 [#1] PREEMPT SMP KASAN NOPTI\nKASAN: null-ptr-deref in range [0x0000000000000030-0x0000000000000037]\nCPU: 1 UID: 0 PID: 5837 Comm: syz-executor888 Not tainted 6.12.0-syzkaller-09567-g7eef7e306d3c #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024\n RIP: 0010:__lock_acquire+0xe4/0x3c40 kernel/locking/lockdep.c:5089\nCode: 08 84 d2 0f 85 15 14 00 00 44 8b 0d ca 98 f5 0e 45 85 c9 0f 84 b4 0e 00 00 48 b8 00 00 00 00 00 fc ff df 4c 89 e2 48 c1 ea 03 <80> 3c 02 00 0f 85 96 2c 00 00 49 8b 04 24 48 3d a0 07 7f 93 0f 84\nRSP: 0018:ffffc900035d7268 EFLAGS: 00010006\nRAX: dffffc0000000000 RBX: 0000000000000000 RCX: 0000000000000000\nRDX: 0000000000000006 RSI: 1ffff920006bae5f RDI: 0000000000000030\nRBP: 0000000000000000 R08: 0000000000000001 R09: 0000000000000001\nR10: ffffffff90608e17 R11: 0000000000000001 R12: 0000000000000030\nR13: ffff888036334880 R14: 0000000000000000 R15: 0000000000000000\nFS: 0000555579e90380(0000) GS:ffff8880b8700000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007ffc59cc4278 CR3: 0000000072b54000 CR4: 00000000003526f0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nCall Trace:\n \n lock_acquire.part.0+0x11b/0x380 kernel/locking/lockdep.c:5849\n __raw_spin_lock_bh include/linux/spinlock_api_smp.h:126 [inline]\n _raw_spin_lock_bh+0x33/0x40 kernel/locking/spinlock.c:178\n spin_lock_bh include/linux/spinlock.h:356 [inline]\n modify_prefix_route+0x30b/0x8b0 net/ipv6/addrconf.c:4831\n inet6_addr_modify net/ipv6/addrconf.c:4923 [inline]\n inet6_rtm_newaddr+0x12c7/0x1ab0 net/ipv6/addrconf.c:5055\n rtnetlink_rcv_msg+0x3c7/0xea0 net/core/rtnetlink.c:6920\n netlink_rcv_skb+0x16b/0x440 net/netlink/af_netlink.c:2541\n netlink_unicast_kernel net/netlink/af_netlink.c:1321 [inline]\n netlink_unicast+0x53c/0x7f0 net/netlink/af_netlink.c:1347\n netlink_sendmsg+0x8b8/0xd70 net/netlink/af_netlink.c:1891\n sock_sendmsg_nosec net/socket.c:711 [inline]\n __sock_sendmsg net/socket.c:726 [inline]\n ____sys_sendmsg+0xaaf/0xc90 net/socket.c:2583\n ___sys_sendmsg+0x135/0x1e0 net/socket.c:2637\n __sys_sendmsg+0x16e/0x220 net/socket.c:2669\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xcd/0x250 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\nRIP: 0033:0x7fd1dcef8b79\nCode: 28 00 00 00 75 05 48 83 c4 28 c3 e8 c1 17 00 00 90 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b8 ff ff ff f7 d8 64 89 01 48\nRSP: 002b:00007ffc59cc4378 EFLAGS: 00000246 ORIG_RAX: 000000000000002e\nRAX: ffffffffffffffda RBX: 0000000000000000 RCX: 00007fd1dcef8b79\nRDX: 0000000000040040 RSI: 0000000020000140 RDI: 0000000000000004\nRBP: 00000000000113fd R08: 0000000000000006 R09: 0000000000000006\nR10: 0000000000000006 R11: 0000000000000246 R12: 00007ffc59cc438c\nR13: 431bde82d7b634db R14: 0000000000000001 R15: 0000000000000001\n ", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T15:15:24Z" diff --git a/advisories/unreviewed/2024/12/GHSA-gxfg-mr5m-frxc/GHSA-gxfg-mr5m-frxc.json b/advisories/unreviewed/2024/12/GHSA-gxfg-mr5m-frxc/GHSA-gxfg-mr5m-frxc.json index 4be1efda5f7..f9624ed8903 100644 --- a/advisories/unreviewed/2024/12/GHSA-gxfg-mr5m-frxc/GHSA-gxfg-mr5m-frxc.json +++ b/advisories/unreviewed/2024/12/GHSA-gxfg-mr5m-frxc/GHSA-gxfg-mr5m-frxc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gxfg-mr5m-frxc", - "modified": "2024-12-29T12:30:41Z", + "modified": "2025-01-06T21:30:51Z", "published": "2024-12-29T12:30:41Z", "aliases": [ "CVE-2024-56752" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/nouveau/gr/gf100: Fix missing unlock in gf100_gr_chan_new()\n\nWhen the call to gf100_grctx_generate() fails, unlock gr->fecs.mutex\nbefore returning the error.\n\nFixes smatch warning:\n\ndrivers/gpu/drm/nouveau/nvkm/engine/gr/gf100.c:480 gf100_gr_chan_new() warn: inconsistent returns '&gr->fecs.mutex'.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -33,7 +38,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-29T12:15:08Z" diff --git a/advisories/unreviewed/2024/12/GHSA-h3qm-53p9-w8c6/GHSA-h3qm-53p9-w8c6.json b/advisories/unreviewed/2024/12/GHSA-h3qm-53p9-w8c6/GHSA-h3qm-53p9-w8c6.json index 258a6654936..06ba046b0b0 100644 --- a/advisories/unreviewed/2024/12/GHSA-h3qm-53p9-w8c6/GHSA-h3qm-53p9-w8c6.json +++ b/advisories/unreviewed/2024/12/GHSA-h3qm-53p9-w8c6/GHSA-h3qm-53p9-w8c6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h3qm-53p9-w8c6", - "modified": "2024-12-27T15:31:55Z", + "modified": "2025-01-06T21:30:50Z", "published": "2024-12-27T15:31:55Z", "aliases": [ "CVE-2024-56649" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: enetc: Do not configure preemptible TCs if SIs do not support\n\nBoth ENETC PF and VF drivers share enetc_setup_tc_mqprio() to configure\nMQPRIO. And enetc_setup_tc_mqprio() calls enetc_change_preemptible_tcs()\nto configure preemptible TCs. However, only PF is able to configure\npreemptible TCs. Because only PF has related registers, while VF does not\nhave these registers. So for VF, its hw->port pointer is NULL. Therefore,\nVF will access an invalid pointer when accessing a non-existent register,\nwhich will cause a crash issue. The simplified log is as follows.\n\nroot@ls1028ardb:~# tc qdisc add dev eno0vf0 parent root handle 100: \\\nmqprio num_tc 4 map 0 0 1 1 2 2 3 3 queues 1@0 1@1 1@2 1@3 hw 1\n[ 187.290775] Unable to handle kernel paging request at virtual address 0000000000001f00\n[ 187.424831] pc : enetc_mm_commit_preemptible_tcs+0x1c4/0x400\n[ 187.430518] lr : enetc_mm_commit_preemptible_tcs+0x30c/0x400\n[ 187.511140] Call trace:\n[ 187.513588] enetc_mm_commit_preemptible_tcs+0x1c4/0x400\n[ 187.518918] enetc_setup_tc_mqprio+0x180/0x214\n[ 187.523374] enetc_vf_setup_tc+0x1c/0x30\n[ 187.527306] mqprio_enable_offload+0x144/0x178\n[ 187.531766] mqprio_init+0x3ec/0x668\n[ 187.535351] qdisc_create+0x15c/0x488\n[ 187.539023] tc_modify_qdisc+0x398/0x73c\n[ 187.542958] rtnetlink_rcv_msg+0x128/0x378\n[ 187.547064] netlink_rcv_skb+0x60/0x130\n[ 187.550910] rtnetlink_rcv+0x18/0x24\n[ 187.554492] netlink_unicast+0x300/0x36c\n[ 187.558425] netlink_sendmsg+0x1a8/0x420\n[ 187.606759] ---[ end trace 0000000000000000 ]---\n\nIn addition, some PFs also do not support configuring preemptible TCs,\nsuch as eno1 and eno3 on LS1028A. It won't crash like it does for VFs,\nbut we should prevent these PFs from accessing these unimplemented\nregisters.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T15:15:24Z" diff --git a/advisories/unreviewed/2024/12/GHSA-jcjf-6896-f99g/GHSA-jcjf-6896-f99g.json b/advisories/unreviewed/2024/12/GHSA-jcjf-6896-f99g/GHSA-jcjf-6896-f99g.json index 53799d4f0c0..432266c8cf6 100644 --- a/advisories/unreviewed/2024/12/GHSA-jcjf-6896-f99g/GHSA-jcjf-6896-f99g.json +++ b/advisories/unreviewed/2024/12/GHSA-jcjf-6896-f99g/GHSA-jcjf-6896-f99g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jcjf-6896-f99g", - "modified": "2024-12-27T15:31:55Z", + "modified": "2025-01-06T21:30:50Z", "published": "2024-12-27T15:31:55Z", "aliases": [ "CVE-2024-56651" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: hi311x: hi3110_can_ist(): fix potential use-after-free\n\nThe commit a22bd630cfff (\"can: hi311x: do not report txerr and rxerr\nduring bus-off\") removed the reporting of rxerr and txerr even in case\nof correct operation (i. e. not bus-off).\n\nThe error count information added to the CAN frame after netif_rx() is\na potential use after free, since there is no guarantee that the skb\nis in the same state. It might be freed or reused.\n\nFix the issue by postponing the netif_rx() call in case of txerr and\nrxerr reporting.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T15:15:24Z" diff --git a/advisories/unreviewed/2024/12/GHSA-jm3q-3f7r-g7wc/GHSA-jm3q-3f7r-g7wc.json b/advisories/unreviewed/2024/12/GHSA-jm3q-3f7r-g7wc/GHSA-jm3q-3f7r-g7wc.json index 8a4ae630da1..9782e86f0c6 100644 --- a/advisories/unreviewed/2024/12/GHSA-jm3q-3f7r-g7wc/GHSA-jm3q-3f7r-g7wc.json +++ b/advisories/unreviewed/2024/12/GHSA-jm3q-3f7r-g7wc/GHSA-jm3q-3f7r-g7wc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jm3q-3f7r-g7wc", - "modified": "2024-12-27T15:31:56Z", + "modified": "2025-01-06T21:30:50Z", "published": "2024-12-27T15:31:56Z", "aliases": [ "CVE-2024-56656" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbnxt_en: Fix aggregation ID mask to prevent oops on 5760X chips\n\nThe 5760X (P7) chip's HW GRO/LRO interface is very similar to that of\nthe previous generation (5750X or P5). However, the aggregation ID\nfields in the completion structures on P7 have been redefined from\n16 bits to 12 bits. The freed up 4 bits are redefined for part of the\nmetadata such as the VLAN ID. The aggregation ID mask was not modified\nwhen adding support for P7 chips. Including the extra 4 bits for the\naggregation ID can potentially cause the driver to store or fetch the\npacket header of GRO/LRO packets in the wrong TPA buffer. It may hit\nthe BUG() condition in __skb_pull() because the SKB contains no valid\npacket header:\n\nkernel BUG at include/linux/skbuff.h:2766!\nOops: invalid opcode: 0000 1 PREEMPT SMP NOPTI\nCPU: 4 UID: 0 PID: 0 Comm: swapper/4 Kdump: loaded Tainted: G OE 6.12.0-rc2+ #7\nTainted: [O]=OOT_MODULE, [E]=UNSIGNED_MODULE\nHardware name: Dell Inc. PowerEdge R760/0VRV9X, BIOS 1.0.1 12/27/2022\nRIP: 0010:eth_type_trans+0xda/0x140\nCode: 80 00 00 00 eb c1 8b 47 70 2b 47 74 48 8b 97 d0 00 00 00 83 f8 01 7e 1b 48 85 d2 74 06 66 83 3a ff 74 09 b8 00 04 00 00 eb a5 <0f> 0b b8 00 01 00 00 eb 9c 48 85 ff 74 eb 31 f6 b9 02 00 00 00 48\nRSP: 0018:ff615003803fcc28 EFLAGS: 00010283\nRAX: 00000000000022d2 RBX: 0000000000000003 RCX: ff2e8c25da334040\nRDX: 0000000000000040 RSI: ff2e8c25c1ce8000 RDI: ff2e8c25869f9000\nRBP: ff2e8c258c31c000 R08: ff2e8c25da334000 R09: 0000000000000001\nR10: ff2e8c25da3342c0 R11: ff2e8c25c1ce89c0 R12: ff2e8c258e0990b0\nR13: ff2e8c25bb120000 R14: ff2e8c25c1ce89c0 R15: ff2e8c25869f9000\nFS: 0000000000000000(0000) GS:ff2e8c34be300000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 000055f05317e4c8 CR3: 000000108bac6006 CR4: 0000000000773ef0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe07f0 DR7: 0000000000000400\nPKRU: 55555554\nCall Trace:\n \n ? die+0x33/0x90\n ? do_trap+0xd9/0x100\n ? eth_type_trans+0xda/0x140\n ? do_error_trap+0x65/0x80\n ? eth_type_trans+0xda/0x140\n ? exc_invalid_op+0x4e/0x70\n ? eth_type_trans+0xda/0x140\n ? asm_exc_invalid_op+0x16/0x20\n ? eth_type_trans+0xda/0x140\n bnxt_tpa_end+0x10b/0x6b0 [bnxt_en]\n ? bnxt_tpa_start+0x195/0x320 [bnxt_en]\n bnxt_rx_pkt+0x902/0xd90 [bnxt_en]\n ? __bnxt_tx_int.constprop.0+0x89/0x300 [bnxt_en]\n ? kmem_cache_free+0x343/0x440\n ? __bnxt_tx_int.constprop.0+0x24f/0x300 [bnxt_en]\n __bnxt_poll_work+0x193/0x370 [bnxt_en]\n bnxt_poll_p5+0x9a/0x300 [bnxt_en]\n ? try_to_wake_up+0x209/0x670\n __napi_poll+0x29/0x1b0\n\nFix it by redefining the aggregation ID mask for P5_PLUS chips to be\n12 bits. This will work because the maximum aggregation ID is less\nthan 4096 on all P5_PLUS chips.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -25,7 +30,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T15:15:25Z" diff --git a/advisories/unreviewed/2024/12/GHSA-r49r-4qq2-h5rj/GHSA-r49r-4qq2-h5rj.json b/advisories/unreviewed/2024/12/GHSA-r49r-4qq2-h5rj/GHSA-r49r-4qq2-h5rj.json index 05781bd88a7..68e68f5b456 100644 --- a/advisories/unreviewed/2024/12/GHSA-r49r-4qq2-h5rj/GHSA-r49r-4qq2-h5rj.json +++ b/advisories/unreviewed/2024/12/GHSA-r49r-4qq2-h5rj/GHSA-r49r-4qq2-h5rj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-r49r-4qq2-h5rj", - "modified": "2024-12-27T15:31:56Z", + "modified": "2025-01-06T21:30:50Z", "published": "2024-12-27T15:31:55Z", "aliases": [ "CVE-2024-56650" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: x_tables: fix LED ID check in led_tg_check()\n\nSyzbot has reported the following BUG detected by KASAN:\n\nBUG: KASAN: slab-out-of-bounds in strlen+0x58/0x70\nRead of size 1 at addr ffff8881022da0c8 by task repro/5879\n...\nCall Trace:\n \n dump_stack_lvl+0x241/0x360\n ? __pfx_dump_stack_lvl+0x10/0x10\n ? __pfx__printk+0x10/0x10\n ? _printk+0xd5/0x120\n ? __virt_addr_valid+0x183/0x530\n ? __virt_addr_valid+0x183/0x530\n print_report+0x169/0x550\n ? __virt_addr_valid+0x183/0x530\n ? __virt_addr_valid+0x183/0x530\n ? __virt_addr_valid+0x45f/0x530\n ? __phys_addr+0xba/0x170\n ? strlen+0x58/0x70\n kasan_report+0x143/0x180\n ? strlen+0x58/0x70\n strlen+0x58/0x70\n kstrdup+0x20/0x80\n led_tg_check+0x18b/0x3c0\n xt_check_target+0x3bb/0xa40\n ? __pfx_xt_check_target+0x10/0x10\n ? stack_depot_save_flags+0x6e4/0x830\n ? nft_target_init+0x174/0xc30\n nft_target_init+0x82d/0xc30\n ? __pfx_nft_target_init+0x10/0x10\n ? nf_tables_newrule+0x1609/0x2980\n ? nf_tables_newrule+0x1609/0x2980\n ? rcu_is_watching+0x15/0xb0\n ? nf_tables_newrule+0x1609/0x2980\n ? nf_tables_newrule+0x1609/0x2980\n ? __kmalloc_noprof+0x21a/0x400\n nf_tables_newrule+0x1860/0x2980\n ? __pfx_nf_tables_newrule+0x10/0x10\n ? __nla_parse+0x40/0x60\n nfnetlink_rcv+0x14e5/0x2ab0\n ? __pfx_validate_chain+0x10/0x10\n ? __pfx_nfnetlink_rcv+0x10/0x10\n ? __lock_acquire+0x1384/0x2050\n ? netlink_deliver_tap+0x2e/0x1b0\n ? __pfx_lock_release+0x10/0x10\n ? netlink_deliver_tap+0x2e/0x1b0\n netlink_unicast+0x7f8/0x990\n ? __pfx_netlink_unicast+0x10/0x10\n ? __virt_addr_valid+0x183/0x530\n ? __check_object_size+0x48e/0x900\n netlink_sendmsg+0x8e4/0xcb0\n ? __pfx_netlink_sendmsg+0x10/0x10\n ? aa_sock_msg_perm+0x91/0x160\n ? __pfx_netlink_sendmsg+0x10/0x10\n __sock_sendmsg+0x223/0x270\n ____sys_sendmsg+0x52a/0x7e0\n ? __pfx_____sys_sendmsg+0x10/0x10\n __sys_sendmsg+0x292/0x380\n ? __pfx___sys_sendmsg+0x10/0x10\n ? lockdep_hardirqs_on_prepare+0x43d/0x780\n ? __pfx_lockdep_hardirqs_on_prepare+0x10/0x10\n ? exc_page_fault+0x590/0x8c0\n ? do_syscall_64+0xb6/0x230\n do_syscall_64+0xf3/0x230\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n...\n \n\nSince an invalid (without '\\0' byte at all) byte sequence may be passed\nfrom userspace, add an extra check to ensure that such a sequence is\nrejected as possible ID and so never passed to 'kstrdup()' and further.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T15:15:24Z" diff --git a/advisories/unreviewed/2024/12/GHSA-rvhx-c29r-93j7/GHSA-rvhx-c29r-93j7.json b/advisories/unreviewed/2024/12/GHSA-rvhx-c29r-93j7/GHSA-rvhx-c29r-93j7.json index 020e10db77d..a5a1b68dd5c 100644 --- a/advisories/unreviewed/2024/12/GHSA-rvhx-c29r-93j7/GHSA-rvhx-c29r-93j7.json +++ b/advisories/unreviewed/2024/12/GHSA-rvhx-c29r-93j7/GHSA-rvhx-c29r-93j7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rvhx-c29r-93j7", - "modified": "2024-12-27T15:31:55Z", + "modified": "2025-01-06T21:30:50Z", "published": "2024-12-27T15:31:55Z", "aliases": [ "CVE-2024-56647" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: Fix icmp host relookup triggering ip_rt_bug\n\narp link failure may trigger ip_rt_bug while xfrm enabled, call trace is:\n\nWARNING: CPU: 0 PID: 0 at net/ipv4/route.c:1241 ip_rt_bug+0x14/0x20\nModules linked in:\nCPU: 0 UID: 0 PID: 0 Comm: swapper/0 Not tainted 6.12.0-rc6-00077-g2e1b3cc9d7f7\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996),\nBIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014\nRIP: 0010:ip_rt_bug+0x14/0x20\nCall Trace:\n \n ip_send_skb+0x14/0x40\n __icmp_send+0x42d/0x6a0\n ipv4_link_failure+0xe2/0x1d0\n arp_error_report+0x3c/0x50\n neigh_invalidate+0x8d/0x100\n neigh_timer_handler+0x2e1/0x330\n call_timer_fn+0x21/0x120\n __run_timer_base.part.0+0x1c9/0x270\n run_timer_softirq+0x4c/0x80\n handle_softirqs+0xac/0x280\n irq_exit_rcu+0x62/0x80\n sysvec_apic_timer_interrupt+0x77/0x90\n\nThe script below reproduces this scenario:\nip xfrm policy add src 0.0.0.0/0 dst 0.0.0.0/0 \\\n\tdir out priority 0 ptype main flag localok icmp\nip l a veth1 type veth\nip a a 192.168.141.111/24 dev veth0\nip l s veth0 up\nping 192.168.141.155 -c 1\n\nicmp_route_lookup() create input routes for locally generated packets\nwhile xfrm relookup ICMP traffic.Then it will set input route\n(dst->out = ip_rt_bug) to skb for DESTUNREACH.\n\nFor ICMP err triggered by locally generated packets, dst->dev of output\nroute is loopback. Generally, xfrm relookup verification is not required\non loopback interfaces (net.ipv4.conf.lo.disable_xfrm = 1).\n\nSkip icmp relookup for locally generated packets to fix it.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -25,7 +30,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T15:15:24Z" diff --git a/advisories/unreviewed/2024/12/GHSA-rxv4-87wm-f3xr/GHSA-rxv4-87wm-f3xr.json b/advisories/unreviewed/2024/12/GHSA-rxv4-87wm-f3xr/GHSA-rxv4-87wm-f3xr.json index e77af46d271..6df3e673847 100644 --- a/advisories/unreviewed/2024/12/GHSA-rxv4-87wm-f3xr/GHSA-rxv4-87wm-f3xr.json +++ b/advisories/unreviewed/2024/12/GHSA-rxv4-87wm-f3xr/GHSA-rxv4-87wm-f3xr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rxv4-87wm-f3xr", - "modified": "2024-12-29T12:30:41Z", + "modified": "2025-01-06T21:30:51Z", "published": "2024-12-29T12:30:41Z", "aliases": [ "CVE-2024-56753" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/gfx9: Add Cleaner Shader Deinitialization in gfx_v9_0 Module\n\nThis commit addresses an omission in the previous patch related to the\ncleaner shader support for GFX9 hardware. Specifically, it adds the\nnecessary deinitialization code for the cleaner shader in the\ngfx_v9_0_sw_fini function.\n\nThe added line amdgpu_gfx_cleaner_shader_sw_fini(adev); ensures that any\nallocated resources for the cleaner shader are freed correctly, avoiding\npotential memory leaks and ensuring that the GPU state is clean for the\nnext initialization sequence.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-29T12:15:08Z" diff --git a/advisories/unreviewed/2024/12/GHSA-w92r-fpr6-76rv/GHSA-w92r-fpr6-76rv.json b/advisories/unreviewed/2024/12/GHSA-w92r-fpr6-76rv/GHSA-w92r-fpr6-76rv.json index 0907304cebd..5f1bce5cd5b 100644 --- a/advisories/unreviewed/2024/12/GHSA-w92r-fpr6-76rv/GHSA-w92r-fpr6-76rv.json +++ b/advisories/unreviewed/2024/12/GHSA-w92r-fpr6-76rv/GHSA-w92r-fpr6-76rv.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-120" + "CWE-120", + "CWE-1394" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-x8gq-4mj9-v7xj/GHSA-x8gq-4mj9-v7xj.json b/advisories/unreviewed/2024/12/GHSA-x8gq-4mj9-v7xj/GHSA-x8gq-4mj9-v7xj.json index 936a731e896..d10ff4285e2 100644 --- a/advisories/unreviewed/2024/12/GHSA-x8gq-4mj9-v7xj/GHSA-x8gq-4mj9-v7xj.json +++ b/advisories/unreviewed/2024/12/GHSA-x8gq-4mj9-v7xj/GHSA-x8gq-4mj9-v7xj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x8gq-4mj9-v7xj", - "modified": "2024-12-27T15:31:55Z", + "modified": "2025-01-06T21:30:50Z", "published": "2024-12-27T15:31:55Z", "aliases": [ "CVE-2024-56648" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: hsr: avoid potential out-of-bound access in fill_frame_info()\n\nsyzbot is able to feed a packet with 14 bytes, pretending\nit is a vlan one.\n\nSince fill_frame_info() is relying on skb->mac_len already,\nextend the check to cover this case.\n\nBUG: KMSAN: uninit-value in fill_frame_info net/hsr/hsr_forward.c:709 [inline]\n BUG: KMSAN: uninit-value in hsr_forward_skb+0x9ee/0x3b10 net/hsr/hsr_forward.c:724\n fill_frame_info net/hsr/hsr_forward.c:709 [inline]\n hsr_forward_skb+0x9ee/0x3b10 net/hsr/hsr_forward.c:724\n hsr_dev_xmit+0x2f0/0x350 net/hsr/hsr_device.c:235\n __netdev_start_xmit include/linux/netdevice.h:5002 [inline]\n netdev_start_xmit include/linux/netdevice.h:5011 [inline]\n xmit_one net/core/dev.c:3590 [inline]\n dev_hard_start_xmit+0x247/0xa20 net/core/dev.c:3606\n __dev_queue_xmit+0x366a/0x57d0 net/core/dev.c:4434\n dev_queue_xmit include/linux/netdevice.h:3168 [inline]\n packet_xmit+0x9c/0x6c0 net/packet/af_packet.c:276\n packet_snd net/packet/af_packet.c:3146 [inline]\n packet_sendmsg+0x91ae/0xa6f0 net/packet/af_packet.c:3178\n sock_sendmsg_nosec net/socket.c:711 [inline]\n __sock_sendmsg+0x30f/0x380 net/socket.c:726\n __sys_sendto+0x594/0x750 net/socket.c:2197\n __do_sys_sendto net/socket.c:2204 [inline]\n __se_sys_sendto net/socket.c:2200 [inline]\n __x64_sys_sendto+0x125/0x1d0 net/socket.c:2200\n x64_sys_call+0x346a/0x3c30 arch/x86/include/generated/asm/syscalls_64.h:45\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xcd/0x1e0 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nUninit was created at:\n slab_post_alloc_hook mm/slub.c:4091 [inline]\n slab_alloc_node mm/slub.c:4134 [inline]\n kmem_cache_alloc_node_noprof+0x6bf/0xb80 mm/slub.c:4186\n kmalloc_reserve+0x13d/0x4a0 net/core/skbuff.c:587\n __alloc_skb+0x363/0x7b0 net/core/skbuff.c:678\n alloc_skb include/linux/skbuff.h:1323 [inline]\n alloc_skb_with_frags+0xc8/0xd00 net/core/skbuff.c:6612\n sock_alloc_send_pskb+0xa81/0xbf0 net/core/sock.c:2881\n packet_alloc_skb net/packet/af_packet.c:2995 [inline]\n packet_snd net/packet/af_packet.c:3089 [inline]\n packet_sendmsg+0x74c6/0xa6f0 net/packet/af_packet.c:3178\n sock_sendmsg_nosec net/socket.c:711 [inline]\n __sock_sendmsg+0x30f/0x380 net/socket.c:726\n __sys_sendto+0x594/0x750 net/socket.c:2197\n __do_sys_sendto net/socket.c:2204 [inline]\n __se_sys_sendto net/socket.c:2200 [inline]\n __x64_sys_sendto+0x125/0x1d0 net/socket.c:2200\n x64_sys_call+0x346a/0x3c30 arch/x86/include/generated/asm/syscalls_64.h:45\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xcd/0x1e0 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-908" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T15:15:24Z" diff --git a/advisories/unreviewed/2024/12/GHSA-xpv3-x3xh-h28r/GHSA-xpv3-x3xh-h28r.json b/advisories/unreviewed/2024/12/GHSA-xpv3-x3xh-h28r/GHSA-xpv3-x3xh-h28r.json index 0a1d1d9d480..0705d9c913a 100644 --- a/advisories/unreviewed/2024/12/GHSA-xpv3-x3xh-h28r/GHSA-xpv3-x3xh-h28r.json +++ b/advisories/unreviewed/2024/12/GHSA-xpv3-x3xh-h28r/GHSA-xpv3-x3xh-h28r.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xpv3-x3xh-h28r", - "modified": "2024-12-27T15:31:56Z", + "modified": "2025-01-06T21:30:50Z", "published": "2024-12-27T15:31:56Z", "aliases": [ "CVE-2024-56657" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: control: Avoid WARN() for symlink errors\n\nUsing WARN() for showing the error of symlink creations don't give\nmore information than telling that something goes wrong, since the\nusual code path is a lregister callback from each control element\ncreation. More badly, the use of WARN() rather confuses fuzzer as if\nit were serious issues.\n\nThis patch downgrades the warning messages to use the normal dev_err()\ninstead of WARN(). For making it clearer, add the function name to\nthe prefix, too.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -29,7 +34,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-27T15:15:25Z" diff --git a/advisories/unreviewed/2025/01/GHSA-2p95-8xvm-2pjx/GHSA-2p95-8xvm-2pjx.json b/advisories/unreviewed/2025/01/GHSA-2p95-8xvm-2pjx/GHSA-2p95-8xvm-2pjx.json new file mode 100644 index 00000000000..7da00573ce0 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2p95-8xvm-2pjx/GHSA-2p95-8xvm-2pjx.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2p95-8xvm-2pjx", + "modified": "2025-01-06T21:30:51Z", + "published": "2025-01-06T21:30:51Z", + "aliases": [ + "CVE-2024-46209" + ], + "details": "A stored cross-site scripting (XSS) vulnerability in the component /media/test.html of REDAXO CMS v5.17.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the password parameter.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46209" + }, + { + "type": "WEB", + "url": "https://github.com/h4ckr4v3n/CVE-2024-46209/blob/main/REDAXO%20Stored%20XSS%20%2B%20RCE.pdf" + }, + { + "type": "WEB", + "url": "https://github.com/h4ckr4v3n/research_redaxo_5_17_1.git" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-06T19:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-2r77-fvv3-mm9j/GHSA-2r77-fvv3-mm9j.json b/advisories/unreviewed/2025/01/GHSA-2r77-fvv3-mm9j/GHSA-2r77-fvv3-mm9j.json index 0d24073304d..fde25b6a334 100644 --- a/advisories/unreviewed/2025/01/GHSA-2r77-fvv3-mm9j/GHSA-2r77-fvv3-mm9j.json +++ b/advisories/unreviewed/2025/01/GHSA-2r77-fvv3-mm9j/GHSA-2r77-fvv3-mm9j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2r77-fvv3-mm9j", - "modified": "2025-01-06T18:31:04Z", + "modified": "2025-01-06T21:30:51Z", "published": "2025-01-06T18:31:04Z", "aliases": [ "CVE-2024-55529" ], "details": "Z-BlogPHP 1.7.3 is vulnerable to arbitrary code execution via \\zb_users\\theme\\shell\\template.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-06T18:15:22Z" diff --git a/advisories/unreviewed/2025/01/GHSA-6gg3-5p97-3cp8/GHSA-6gg3-5p97-3cp8.json b/advisories/unreviewed/2025/01/GHSA-6gg3-5p97-3cp8/GHSA-6gg3-5p97-3cp8.json index 50725930741..084bdd55352 100644 --- a/advisories/unreviewed/2025/01/GHSA-6gg3-5p97-3cp8/GHSA-6gg3-5p97-3cp8.json +++ b/advisories/unreviewed/2025/01/GHSA-6gg3-5p97-3cp8/GHSA-6gg3-5p97-3cp8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6gg3-5p97-3cp8", - "modified": "2025-01-02T06:30:47Z", + "modified": "2025-01-06T21:30:51Z", "published": "2025-01-02T06:30:47Z", "aliases": [ "CVE-2024-12595" ], "details": "The AHAthat Plugin WordPress plugin through 1.6 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-02T06:15:07Z" diff --git a/advisories/unreviewed/2025/01/GHSA-8q2f-m3g8-m8qm/GHSA-8q2f-m3g8-m8qm.json b/advisories/unreviewed/2025/01/GHSA-8q2f-m3g8-m8qm/GHSA-8q2f-m3g8-m8qm.json new file mode 100644 index 00000000000..6fec3f9a655 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-8q2f-m3g8-m8qm/GHSA-8q2f-m3g8-m8qm.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8q2f-m3g8-m8qm", + "modified": "2025-01-06T21:30:51Z", + "published": "2025-01-06T21:30:51Z", + "aliases": [ + "CVE-2024-55407" + ], + "details": "An issue in the DeviceloControl function of ITE Tech. Inc ITE IO Access v1.0.0.0 allows attackers to perform arbitrary port read and write actions via supplying crafted IOCTL requests.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55407" + }, + { + "type": "WEB", + "url": "https://github.com/heyheysky/vulnerable-driver/blob/master/CVE-2024-55407/CVE-2024-55407_Winio64.sys_README.md" + }, + { + "type": "WEB", + "url": "http://ite.com" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-06T19:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-95j3-6wrj-9v4c/GHSA-95j3-6wrj-9v4c.json b/advisories/unreviewed/2025/01/GHSA-95j3-6wrj-9v4c/GHSA-95j3-6wrj-9v4c.json new file mode 100644 index 00000000000..2d6c5907f2e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-95j3-6wrj-9v4c/GHSA-95j3-6wrj-9v4c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-95j3-6wrj-9v4c", + "modified": "2025-01-06T21:30:51Z", + "published": "2025-01-06T21:30:51Z", + "aliases": [ + "CVE-2024-55074" + ], + "details": "The edit profile function of Grocy through 4.3.0 allows stored XSS and resultant privilege escalation by uploading a crafted HTML or SVG file, a different issue than CVE-2024-8370.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55074" + }, + { + "type": "WEB", + "url": "https://m10x.de/posts/2024/11/all-your-recipe-are-belong-to-us-part-1/3-stored-xss-csrf-and-broken-access-control-vulnerabilities-in-grocy" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-06T20:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-f48j-vwm8-858j/GHSA-f48j-vwm8-858j.json b/advisories/unreviewed/2025/01/GHSA-f48j-vwm8-858j/GHSA-f48j-vwm8-858j.json new file mode 100644 index 00000000000..b9d9c9445d5 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-f48j-vwm8-858j/GHSA-f48j-vwm8-858j.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f48j-vwm8-858j", + "modified": "2025-01-06T21:30:51Z", + "published": "2025-01-06T21:30:51Z", + "aliases": [ + "CVE-2024-55408" + ], + "details": "An issue in the AsusSAIO.sys component of ASUS System Analysis IO v1.0.0 allows attackers to perform arbitrary read and write actions via supplying crafted IOCTL requests.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55408" + }, + { + "type": "WEB", + "url": "https://github.com/heyheysky/vulnerable-driver/blob/master/CVE-2024-55408/CVE-2024-55408_AsusSAIO.sys_README.md" + }, + { + "type": "WEB", + "url": "http://asus.com" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-06T19:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-j77f-79w9-rghc/GHSA-j77f-79w9-rghc.json b/advisories/unreviewed/2025/01/GHSA-j77f-79w9-rghc/GHSA-j77f-79w9-rghc.json index 2498befc311..9bc2ee92547 100644 --- a/advisories/unreviewed/2025/01/GHSA-j77f-79w9-rghc/GHSA-j77f-79w9-rghc.json +++ b/advisories/unreviewed/2025/01/GHSA-j77f-79w9-rghc/GHSA-j77f-79w9-rghc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-j77f-79w9-rghc", - "modified": "2025-01-02T06:30:47Z", + "modified": "2025-01-06T21:30:51Z", "published": "2025-01-02T06:30:47Z", "aliases": [ "CVE-2024-11184" ], "details": "The wp-enable-svg WordPress plugin through 0.7 does not sanitize SVG files when uploaded, allowing for authors and above to upload SVGs containing malicious scripts", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-02T06:15:06Z" diff --git a/advisories/unreviewed/2025/01/GHSA-m78c-qx99-mvw9/GHSA-m78c-qx99-mvw9.json b/advisories/unreviewed/2025/01/GHSA-m78c-qx99-mvw9/GHSA-m78c-qx99-mvw9.json new file mode 100644 index 00000000000..559ab93e17d --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-m78c-qx99-mvw9/GHSA-m78c-qx99-mvw9.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m78c-qx99-mvw9", + "modified": "2025-01-06T21:30:51Z", + "published": "2025-01-06T21:30:51Z", + "aliases": [ + "CVE-2024-35498" + ], + "details": "A cross-site scripting (XSS) vulnerability in Grav v1.7.45 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35498" + }, + { + "type": "WEB", + "url": "https://github.com/r4vanan/Stored-xss-Grav-v1.7.45" + }, + { + "type": "WEB", + "url": "https://r4vanan.medium.com/a-quick-dive-into-xss-vulnerability-in-grav-cms-v1-7-45-cve-2024-35498-fc236b7d74a0" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-06T19:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-pcw8-6g3c-prx8/GHSA-pcw8-6g3c-prx8.json b/advisories/unreviewed/2025/01/GHSA-pcw8-6g3c-prx8/GHSA-pcw8-6g3c-prx8.json new file mode 100644 index 00000000000..7ce4d02fd09 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-pcw8-6g3c-prx8/GHSA-pcw8-6g3c-prx8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pcw8-6g3c-prx8", + "modified": "2025-01-06T21:30:51Z", + "published": "2025-01-06T21:30:51Z", + "aliases": [ + "CVE-2024-55075" + ], + "details": "Grocy through 4.3.0 allows remote attackers to obtain sensitive information via direct requests to pages that are not shown in the UI, such as calendar and recipes.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55075" + }, + { + "type": "WEB", + "url": "https://m10x.de/posts/2024/11/all-your-recipe-are-belong-to-us-part-1/3-stored-xss-csrf-and-broken-access-control-vulnerabilities-in-grocy" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-425" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-06T21:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-wpxf-7pwx-p92p/GHSA-wpxf-7pwx-p92p.json b/advisories/unreviewed/2025/01/GHSA-wpxf-7pwx-p92p/GHSA-wpxf-7pwx-p92p.json index 6a4bb001a70..861eb1087ad 100644 --- a/advisories/unreviewed/2025/01/GHSA-wpxf-7pwx-p92p/GHSA-wpxf-7pwx-p92p.json +++ b/advisories/unreviewed/2025/01/GHSA-wpxf-7pwx-p92p/GHSA-wpxf-7pwx-p92p.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wpxf-7pwx-p92p", - "modified": "2025-01-02T06:30:47Z", + "modified": "2025-01-06T21:30:51Z", "published": "2025-01-02T06:30:47Z", "aliases": [ "CVE-2024-11357" ], "details": "The goodlayers-core WordPress plugin before 2.0.10 does not sanitise and escape some of its settings, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-02T06:15:07Z" diff --git a/advisories/unreviewed/2025/01/GHSA-x3hv-xrrp-rmx2/GHSA-x3hv-xrrp-rmx2.json b/advisories/unreviewed/2025/01/GHSA-x3hv-xrrp-rmx2/GHSA-x3hv-xrrp-rmx2.json new file mode 100644 index 00000000000..d79906751ad --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-x3hv-xrrp-rmx2/GHSA-x3hv-xrrp-rmx2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x3hv-xrrp-rmx2", + "modified": "2025-01-06T21:30:51Z", + "published": "2025-01-06T21:30:51Z", + "aliases": [ + "CVE-2024-55076" + ], + "details": "Grocy through 4.3.0 has no CSRF protection, as demonstrated by changing the Administrator's password.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55076" + }, + { + "type": "WEB", + "url": "https://m10x.de/posts/2024/11/all-your-recipe-are-belong-to-us-part-1/3-stored-xss-csrf-and-broken-access-control-vulnerabilities-in-grocy" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-06T21:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-x492-3p6g-fmvm/GHSA-x492-3p6g-fmvm.json b/advisories/unreviewed/2025/01/GHSA-x492-3p6g-fmvm/GHSA-x492-3p6g-fmvm.json index 6debfddf889..052a8cdbfc4 100644 --- a/advisories/unreviewed/2025/01/GHSA-x492-3p6g-fmvm/GHSA-x492-3p6g-fmvm.json +++ b/advisories/unreviewed/2025/01/GHSA-x492-3p6g-fmvm/GHSA-x492-3p6g-fmvm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x492-3p6g-fmvm", - "modified": "2025-01-06T18:31:04Z", + "modified": "2025-01-06T21:30:51Z", "published": "2025-01-06T18:31:04Z", "aliases": [ "CVE-2024-46073" ], "details": "A reflected Cross-Site Scripting (XSS) vulnerability exists in the login page of IceHRM v32.4.0.OS. The vulnerability is due to improper sanitization of the \"next\" parameter, which is included in the application's response without adequate escaping. An attacker can exploit this flaw by tricking a user into visiting a specially crafted URL, causing the execution of arbitrary JavaScript code in the context of the victim's browser. The issue occurs even though the application has sanitization mechanisms in place.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-06T18:15:19Z"