From aef823dfc81ba25564a4a3d2c6410d00d1a69df7 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 22 May 2024 09:33:12 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-24vw-fq64-647q.json | 43 +++++++++ .../GHSA-28j2-gr4p-p982.json | 43 +++++++++ .../GHSA-2r2x-3jh4-chhv.json | 39 ++++++++ .../GHSA-34xf-292h-46f4.json | 47 ++++++++++ .../GHSA-35q9-qwff-qmh4.json | 43 +++++++++ .../GHSA-3c5v-hp3x-r94q.json | 59 ++++++++++++ .../GHSA-3pg2-q6q7-9rmm.json | 39 ++++++++ .../GHSA-45hj-5gpj-93h8.json | 63 +++++++++++++ .../GHSA-4fph-66x7-mxrv.json | 46 ++++++++++ .../GHSA-4fpw-6gvj-w9xf.json | 35 +++++++ .../GHSA-4v89-q9h7-p6vx.json | 67 ++++++++++++++ .../GHSA-5573-w6h2-wwx8.json | 39 ++++++++ .../GHSA-5g4g-hgmr-mqrx.json | 63 +++++++++++++ .../GHSA-5ggq-5m2f-79jm.json | 55 +++++++++++ .../GHSA-5p44-j78m-mc5m.json | 50 ++++++++++ .../GHSA-5px8-4qwx-4qj6.json | 55 +++++++++++ .../GHSA-6hjm-9p27-2qv2.json | 91 +++++++++++++++++++ .../GHSA-6vq2-rrj2-6jjh.json | 67 ++++++++++++++ .../GHSA-6w3g-x8mp-cp7x.json | 67 ++++++++++++++ .../GHSA-6x3x-fg57-3vcm.json | 43 +++++++++ .../GHSA-6xwm-63wf-q2q3.json | 55 +++++++++++ .../GHSA-7379-xh69-jh8v.json | 46 ++++++++++ .../GHSA-73gq-r5qh-jgmm.json | 42 +++++++++ .../GHSA-73h7-mvv6-m363.json | 42 +++++++++ .../GHSA-74c3-rgpv-v3qr.json | 42 +++++++++ .../GHSA-76m2-73wx-8hj7.json | 63 +++++++++++++ .../GHSA-784q-2fw8-cpw8.json | 46 ++++++++++ .../GHSA-78c9-2m2m-j8fh.json | 39 ++++++++ .../GHSA-7ghc-chxp-5r47.json | 39 ++++++++ .../GHSA-7p9j-prv8-54xc.json | 42 +++++++++ .../GHSA-7q72-fqh2-j6jv.json | 50 ++++++++++ .../GHSA-7qcg-gp93-223m.json | 39 ++++++++ .../GHSA-7xq6-r35j-j33m.json | 47 ++++++++++ .../GHSA-843h-74ff-22vf.json | 39 ++++++++ .../GHSA-86hr-63r2-f3c9.json | 39 ++++++++ .../GHSA-8g2p-p68f-4wqr.json | 43 +++++++++ .../GHSA-8g8j-p6r7-xj34.json | 39 ++++++++ .../GHSA-94jm-5577-cx4g.json | 39 ++++++++ .../GHSA-969w-fmcp-j8rq.json | 43 +++++++++ .../GHSA-9wf5-fqq4-6gwg.json | 39 ++++++++ .../GHSA-c425-5ghg-6j48.json | 47 ++++++++++ .../GHSA-c6p9-mw2r-7mc4.json | 43 +++++++++ .../GHSA-c84w-j8mj-57ch.json | 67 ++++++++++++++ .../GHSA-ccg7-gh5h-4h2c.json | 43 +++++++++ .../GHSA-cjpq-j9jr-vg53.json | 42 +++++++++ .../GHSA-cmcr-4938-mjgj.json | 39 ++++++++ .../GHSA-cqj4-2pfx-qgmr.json | 47 ++++++++++ .../GHSA-f639-593q-rjgw.json | 59 ++++++++++++ .../GHSA-fh33-v9vq-826f.json | 63 +++++++++++++ .../GHSA-fmqm-f3m4-fg43.json | 43 +++++++++ .../GHSA-fwfh-xm69-p46x.json | 42 +++++++++ .../GHSA-gr8j-3pfp-wwr2.json | 43 +++++++++ .../GHSA-h664-w632-w34v.json | 63 +++++++++++++ .../GHSA-h74g-q68m-46qw.json | 42 +++++++++ .../GHSA-h8c2-87vw-jwfw.json | 63 +++++++++++++ .../GHSA-h8rm-f377-9c5v.json | 43 +++++++++ .../GHSA-h8rv-gwgw-8xww.json | 43 +++++++++ .../GHSA-hh73-mjw2-25fw.json | 63 +++++++++++++ .../GHSA-hpj2-q4fg-98gf.json | 39 ++++++++ .../GHSA-hx2r-xg86-xj35.json | 39 ++++++++ .../GHSA-hxw5-pvw5-67pp.json | 39 ++++++++ .../GHSA-j7fq-277w-8778.json | 42 +++++++++ .../GHSA-m4gm-7759-99c8.json | 42 +++++++++ .../GHSA-p6hq-6vgx-547f.json | 63 +++++++++++++ .../GHSA-pg78-5grf-jf97.json | 42 +++++++++ .../GHSA-q3gr-2743-cwm5.json | 43 +++++++++ .../GHSA-q6h5-3vm3-9h46.json | 43 +++++++++ .../GHSA-qh22-5q6m-7h2p.json | 39 ++++++++ .../GHSA-qm36-7xcx-862v.json | 43 +++++++++ .../GHSA-r5hc-q3m9-jg75.json | 50 ++++++++++ .../GHSA-r7gr-mhrj-m5wq.json | 47 ++++++++++ .../GHSA-r7pj-34j8-6jgg.json | 47 ++++++++++ .../GHSA-rcc5-r3m3-9rvc.json | 63 +++++++++++++ .../GHSA-rcm4-5vxv-3g8q.json | 43 +++++++++ .../GHSA-rh2v-79c5-2v68.json | 67 ++++++++++++++ .../GHSA-rj64-24f8-r32g.json | 63 +++++++++++++ .../GHSA-vgjx-6ccw-c3f6.json | 63 +++++++++++++ .../GHSA-vh53-65cw-j6wx.json | 42 +++++++++ .../GHSA-vr9g-qp6c-282r.json | 39 ++++++++ .../GHSA-w98j-8cf9-vjpq.json | 54 +++++++++++ .../GHSA-wc2g-rvvj-x242.json | 63 +++++++++++++ .../GHSA-wh2p-rhh2-p26w.json | 46 ++++++++++ .../GHSA-ww7g-fw5c-855v.json | 42 +++++++++ .../GHSA-x4fx-qg56-6gp4.json | 42 +++++++++ .../GHSA-xgm7-3x53-gq2c.json | 63 +++++++++++++ .../GHSA-xjr2-g37g-hrjm.json | 39 ++++++++ .../GHSA-xvmj-27r5-9623.json | 43 +++++++++ .../GHSA-xwj2-c9hw-p6p6.json | 47 ++++++++++ 88 files changed, 4259 insertions(+) create mode 100644 advisories/unreviewed/2024/05/GHSA-24vw-fq64-647q/GHSA-24vw-fq64-647q.json create mode 100644 advisories/unreviewed/2024/05/GHSA-28j2-gr4p-p982/GHSA-28j2-gr4p-p982.json create mode 100644 advisories/unreviewed/2024/05/GHSA-2r2x-3jh4-chhv/GHSA-2r2x-3jh4-chhv.json create mode 100644 advisories/unreviewed/2024/05/GHSA-34xf-292h-46f4/GHSA-34xf-292h-46f4.json create mode 100644 advisories/unreviewed/2024/05/GHSA-35q9-qwff-qmh4/GHSA-35q9-qwff-qmh4.json create mode 100644 advisories/unreviewed/2024/05/GHSA-3c5v-hp3x-r94q/GHSA-3c5v-hp3x-r94q.json create mode 100644 advisories/unreviewed/2024/05/GHSA-3pg2-q6q7-9rmm/GHSA-3pg2-q6q7-9rmm.json create mode 100644 advisories/unreviewed/2024/05/GHSA-45hj-5gpj-93h8/GHSA-45hj-5gpj-93h8.json create mode 100644 advisories/unreviewed/2024/05/GHSA-4fph-66x7-mxrv/GHSA-4fph-66x7-mxrv.json create mode 100644 advisories/unreviewed/2024/05/GHSA-4fpw-6gvj-w9xf/GHSA-4fpw-6gvj-w9xf.json create mode 100644 advisories/unreviewed/2024/05/GHSA-4v89-q9h7-p6vx/GHSA-4v89-q9h7-p6vx.json create mode 100644 advisories/unreviewed/2024/05/GHSA-5573-w6h2-wwx8/GHSA-5573-w6h2-wwx8.json create mode 100644 advisories/unreviewed/2024/05/GHSA-5g4g-hgmr-mqrx/GHSA-5g4g-hgmr-mqrx.json create mode 100644 advisories/unreviewed/2024/05/GHSA-5ggq-5m2f-79jm/GHSA-5ggq-5m2f-79jm.json create mode 100644 advisories/unreviewed/2024/05/GHSA-5p44-j78m-mc5m/GHSA-5p44-j78m-mc5m.json create mode 100644 advisories/unreviewed/2024/05/GHSA-5px8-4qwx-4qj6/GHSA-5px8-4qwx-4qj6.json create mode 100644 advisories/unreviewed/2024/05/GHSA-6hjm-9p27-2qv2/GHSA-6hjm-9p27-2qv2.json create mode 100644 advisories/unreviewed/2024/05/GHSA-6vq2-rrj2-6jjh/GHSA-6vq2-rrj2-6jjh.json create mode 100644 advisories/unreviewed/2024/05/GHSA-6w3g-x8mp-cp7x/GHSA-6w3g-x8mp-cp7x.json create mode 100644 advisories/unreviewed/2024/05/GHSA-6x3x-fg57-3vcm/GHSA-6x3x-fg57-3vcm.json create mode 100644 advisories/unreviewed/2024/05/GHSA-6xwm-63wf-q2q3/GHSA-6xwm-63wf-q2q3.json create mode 100644 advisories/unreviewed/2024/05/GHSA-7379-xh69-jh8v/GHSA-7379-xh69-jh8v.json create mode 100644 advisories/unreviewed/2024/05/GHSA-73gq-r5qh-jgmm/GHSA-73gq-r5qh-jgmm.json create mode 100644 advisories/unreviewed/2024/05/GHSA-73h7-mvv6-m363/GHSA-73h7-mvv6-m363.json create mode 100644 advisories/unreviewed/2024/05/GHSA-74c3-rgpv-v3qr/GHSA-74c3-rgpv-v3qr.json create mode 100644 advisories/unreviewed/2024/05/GHSA-76m2-73wx-8hj7/GHSA-76m2-73wx-8hj7.json create mode 100644 advisories/unreviewed/2024/05/GHSA-784q-2fw8-cpw8/GHSA-784q-2fw8-cpw8.json create mode 100644 advisories/unreviewed/2024/05/GHSA-78c9-2m2m-j8fh/GHSA-78c9-2m2m-j8fh.json create mode 100644 advisories/unreviewed/2024/05/GHSA-7ghc-chxp-5r47/GHSA-7ghc-chxp-5r47.json create mode 100644 advisories/unreviewed/2024/05/GHSA-7p9j-prv8-54xc/GHSA-7p9j-prv8-54xc.json create mode 100644 advisories/unreviewed/2024/05/GHSA-7q72-fqh2-j6jv/GHSA-7q72-fqh2-j6jv.json create mode 100644 advisories/unreviewed/2024/05/GHSA-7qcg-gp93-223m/GHSA-7qcg-gp93-223m.json create mode 100644 advisories/unreviewed/2024/05/GHSA-7xq6-r35j-j33m/GHSA-7xq6-r35j-j33m.json create mode 100644 advisories/unreviewed/2024/05/GHSA-843h-74ff-22vf/GHSA-843h-74ff-22vf.json create mode 100644 advisories/unreviewed/2024/05/GHSA-86hr-63r2-f3c9/GHSA-86hr-63r2-f3c9.json create mode 100644 advisories/unreviewed/2024/05/GHSA-8g2p-p68f-4wqr/GHSA-8g2p-p68f-4wqr.json create mode 100644 advisories/unreviewed/2024/05/GHSA-8g8j-p6r7-xj34/GHSA-8g8j-p6r7-xj34.json create mode 100644 advisories/unreviewed/2024/05/GHSA-94jm-5577-cx4g/GHSA-94jm-5577-cx4g.json create mode 100644 advisories/unreviewed/2024/05/GHSA-969w-fmcp-j8rq/GHSA-969w-fmcp-j8rq.json create mode 100644 advisories/unreviewed/2024/05/GHSA-9wf5-fqq4-6gwg/GHSA-9wf5-fqq4-6gwg.json create mode 100644 advisories/unreviewed/2024/05/GHSA-c425-5ghg-6j48/GHSA-c425-5ghg-6j48.json create mode 100644 advisories/unreviewed/2024/05/GHSA-c6p9-mw2r-7mc4/GHSA-c6p9-mw2r-7mc4.json create mode 100644 advisories/unreviewed/2024/05/GHSA-c84w-j8mj-57ch/GHSA-c84w-j8mj-57ch.json create mode 100644 advisories/unreviewed/2024/05/GHSA-ccg7-gh5h-4h2c/GHSA-ccg7-gh5h-4h2c.json create mode 100644 advisories/unreviewed/2024/05/GHSA-cjpq-j9jr-vg53/GHSA-cjpq-j9jr-vg53.json create mode 100644 advisories/unreviewed/2024/05/GHSA-cmcr-4938-mjgj/GHSA-cmcr-4938-mjgj.json create mode 100644 advisories/unreviewed/2024/05/GHSA-cqj4-2pfx-qgmr/GHSA-cqj4-2pfx-qgmr.json create mode 100644 advisories/unreviewed/2024/05/GHSA-f639-593q-rjgw/GHSA-f639-593q-rjgw.json create mode 100644 advisories/unreviewed/2024/05/GHSA-fh33-v9vq-826f/GHSA-fh33-v9vq-826f.json create mode 100644 advisories/unreviewed/2024/05/GHSA-fmqm-f3m4-fg43/GHSA-fmqm-f3m4-fg43.json create mode 100644 advisories/unreviewed/2024/05/GHSA-fwfh-xm69-p46x/GHSA-fwfh-xm69-p46x.json create mode 100644 advisories/unreviewed/2024/05/GHSA-gr8j-3pfp-wwr2/GHSA-gr8j-3pfp-wwr2.json create mode 100644 advisories/unreviewed/2024/05/GHSA-h664-w632-w34v/GHSA-h664-w632-w34v.json create mode 100644 advisories/unreviewed/2024/05/GHSA-h74g-q68m-46qw/GHSA-h74g-q68m-46qw.json create mode 100644 advisories/unreviewed/2024/05/GHSA-h8c2-87vw-jwfw/GHSA-h8c2-87vw-jwfw.json create mode 100644 advisories/unreviewed/2024/05/GHSA-h8rm-f377-9c5v/GHSA-h8rm-f377-9c5v.json create mode 100644 advisories/unreviewed/2024/05/GHSA-h8rv-gwgw-8xww/GHSA-h8rv-gwgw-8xww.json create mode 100644 advisories/unreviewed/2024/05/GHSA-hh73-mjw2-25fw/GHSA-hh73-mjw2-25fw.json create mode 100644 advisories/unreviewed/2024/05/GHSA-hpj2-q4fg-98gf/GHSA-hpj2-q4fg-98gf.json create mode 100644 advisories/unreviewed/2024/05/GHSA-hx2r-xg86-xj35/GHSA-hx2r-xg86-xj35.json create mode 100644 advisories/unreviewed/2024/05/GHSA-hxw5-pvw5-67pp/GHSA-hxw5-pvw5-67pp.json create mode 100644 advisories/unreviewed/2024/05/GHSA-j7fq-277w-8778/GHSA-j7fq-277w-8778.json create mode 100644 advisories/unreviewed/2024/05/GHSA-m4gm-7759-99c8/GHSA-m4gm-7759-99c8.json create mode 100644 advisories/unreviewed/2024/05/GHSA-p6hq-6vgx-547f/GHSA-p6hq-6vgx-547f.json create mode 100644 advisories/unreviewed/2024/05/GHSA-pg78-5grf-jf97/GHSA-pg78-5grf-jf97.json create mode 100644 advisories/unreviewed/2024/05/GHSA-q3gr-2743-cwm5/GHSA-q3gr-2743-cwm5.json create mode 100644 advisories/unreviewed/2024/05/GHSA-q6h5-3vm3-9h46/GHSA-q6h5-3vm3-9h46.json create mode 100644 advisories/unreviewed/2024/05/GHSA-qh22-5q6m-7h2p/GHSA-qh22-5q6m-7h2p.json create mode 100644 advisories/unreviewed/2024/05/GHSA-qm36-7xcx-862v/GHSA-qm36-7xcx-862v.json create mode 100644 advisories/unreviewed/2024/05/GHSA-r5hc-q3m9-jg75/GHSA-r5hc-q3m9-jg75.json create mode 100644 advisories/unreviewed/2024/05/GHSA-r7gr-mhrj-m5wq/GHSA-r7gr-mhrj-m5wq.json create mode 100644 advisories/unreviewed/2024/05/GHSA-r7pj-34j8-6jgg/GHSA-r7pj-34j8-6jgg.json create mode 100644 advisories/unreviewed/2024/05/GHSA-rcc5-r3m3-9rvc/GHSA-rcc5-r3m3-9rvc.json create mode 100644 advisories/unreviewed/2024/05/GHSA-rcm4-5vxv-3g8q/GHSA-rcm4-5vxv-3g8q.json create mode 100644 advisories/unreviewed/2024/05/GHSA-rh2v-79c5-2v68/GHSA-rh2v-79c5-2v68.json create mode 100644 advisories/unreviewed/2024/05/GHSA-rj64-24f8-r32g/GHSA-rj64-24f8-r32g.json create mode 100644 advisories/unreviewed/2024/05/GHSA-vgjx-6ccw-c3f6/GHSA-vgjx-6ccw-c3f6.json create mode 100644 advisories/unreviewed/2024/05/GHSA-vh53-65cw-j6wx/GHSA-vh53-65cw-j6wx.json create mode 100644 advisories/unreviewed/2024/05/GHSA-vr9g-qp6c-282r/GHSA-vr9g-qp6c-282r.json create mode 100644 advisories/unreviewed/2024/05/GHSA-w98j-8cf9-vjpq/GHSA-w98j-8cf9-vjpq.json create mode 100644 advisories/unreviewed/2024/05/GHSA-wc2g-rvvj-x242/GHSA-wc2g-rvvj-x242.json create mode 100644 advisories/unreviewed/2024/05/GHSA-wh2p-rhh2-p26w/GHSA-wh2p-rhh2-p26w.json create mode 100644 advisories/unreviewed/2024/05/GHSA-ww7g-fw5c-855v/GHSA-ww7g-fw5c-855v.json create mode 100644 advisories/unreviewed/2024/05/GHSA-x4fx-qg56-6gp4/GHSA-x4fx-qg56-6gp4.json create mode 100644 advisories/unreviewed/2024/05/GHSA-xgm7-3x53-gq2c/GHSA-xgm7-3x53-gq2c.json create mode 100644 advisories/unreviewed/2024/05/GHSA-xjr2-g37g-hrjm/GHSA-xjr2-g37g-hrjm.json create mode 100644 advisories/unreviewed/2024/05/GHSA-xvmj-27r5-9623/GHSA-xvmj-27r5-9623.json create mode 100644 advisories/unreviewed/2024/05/GHSA-xwj2-c9hw-p6p6/GHSA-xwj2-c9hw-p6p6.json diff --git a/advisories/unreviewed/2024/05/GHSA-24vw-fq64-647q/GHSA-24vw-fq64-647q.json b/advisories/unreviewed/2024/05/GHSA-24vw-fq64-647q/GHSA-24vw-fq64-647q.json new file mode 100644 index 00000000000..8a438ccaa19 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-24vw-fq64-647q/GHSA-24vw-fq64-647q.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-24vw-fq64-647q", + "modified": "2024-05-22T09:31:44Z", + "published": "2024-05-22T09:31:44Z", + "aliases": [ + "CVE-2021-47438" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: Fix memory leak in mlx5_core_destroy_cq() error path\n\nPrior to this patch in case mlx5_core_destroy_cq() failed it returns\nwithout completing all destroy operations and that leads to memory leak.\nInstead, complete the destroy flow before return error.\n\nAlso move mlx5_debug_cq_remove() to the beginning of mlx5_core_destroy_cq()\nto be symmetrical with mlx5_core_create_cq().\n\nkmemleak complains on:\n\nunreferenced object 0xc000000038625100 (size 64):\n comm \"ethtool\", pid 28301, jiffies 4298062946 (age 785.380s)\n hex dump (first 32 bytes):\n 60 01 48 94 00 00 00 c0 b8 05 34 c3 00 00 00 c0 `.H.......4.....\n 02 00 00 00 00 00 00 00 00 db 7d c1 00 00 00 c0 ..........}.....\n backtrace:\n [<000000009e8643cb>] add_res_tree+0xd0/0x270 [mlx5_core]\n [<00000000e7cb8e6c>] mlx5_debug_cq_add+0x5c/0xc0 [mlx5_core]\n [<000000002a12918f>] mlx5_core_create_cq+0x1d0/0x2d0 [mlx5_core]\n [<00000000cef0a696>] mlx5e_create_cq+0x210/0x3f0 [mlx5_core]\n [<000000009c642c26>] mlx5e_open_cq+0xb4/0x130 [mlx5_core]\n [<0000000058dfa578>] mlx5e_ptp_open+0x7f4/0xe10 [mlx5_core]\n [<0000000081839561>] mlx5e_open_channels+0x9cc/0x13e0 [mlx5_core]\n [<0000000009cf05d4>] mlx5e_switch_priv_channels+0xa4/0x230\n[mlx5_core]\n [<0000000042bbedd8>] mlx5e_safe_switch_params+0x14c/0x300\n[mlx5_core]\n [<0000000004bc9db8>] set_pflag_tx_port_ts+0x9c/0x160 [mlx5_core]\n [<00000000a0553443>] mlx5e_set_priv_flags+0xd0/0x1b0 [mlx5_core]\n [<00000000a8f3d84b>] ethnl_set_privflags+0x234/0x2d0\n [<00000000fd27f27c>] genl_family_rcv_msg_doit+0x108/0x1d0\n [<00000000f495e2bb>] genl_family_rcv_msg+0xe4/0x1f0\n [<00000000646c5c2c>] genl_rcv_msg+0x78/0x120\n [<00000000d53e384e>] netlink_rcv_skb+0x74/0x1a0", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47438" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4f7bddf8c5c01cac74373443b13a68e1c6723a94" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/94b960b9deffc02fc0747afc01f72cc62ab099e3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ed8aafea4fec9c654e63445236e0b505e27ed3a7" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T07:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-28j2-gr4p-p982/GHSA-28j2-gr4p-p982.json b/advisories/unreviewed/2024/05/GHSA-28j2-gr4p-p982/GHSA-28j2-gr4p-p982.json new file mode 100644 index 00000000000..383a1bac4bf --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-28j2-gr4p-p982/GHSA-28j2-gr4p-p982.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-28j2-gr4p-p982", + "modified": "2024-05-22T09:31:45Z", + "published": "2024-05-22T09:31:45Z", + "aliases": [ + "CVE-2021-47473" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: qla2xxx: Fix a memory leak in an error path of qla2x00_process_els()\n\nCommit 8c0eb596baa5 (\"[SCSI] qla2xxx: Fix a memory leak in an error path of\nqla2x00_process_els()\"), intended to change:\n\n bsg_job->request->msgcode == FC_BSG_HST_ELS_NOLOGIN\n\n\n bsg_job->request->msgcode != FC_BSG_RPT_ELS\n\nbut changed it to:\n\n bsg_job->request->msgcode == FC_BSG_RPT_ELS\n\ninstead.\n\nChange the == to a != to avoid leaking the fcport structure or freeing\nunallocated memory.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47473" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7fb223d0ad801f633c78cbe42b1d1b55f5d163ad" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/96f0aebf29be25254fa585af43924e34aa21fd9a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a7fbb56e6c941d9f59437b96412a348e66388d3e" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T07:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-2r2x-3jh4-chhv/GHSA-2r2x-3jh4-chhv.json b/advisories/unreviewed/2024/05/GHSA-2r2x-3jh4-chhv/GHSA-2r2x-3jh4-chhv.json new file mode 100644 index 00000000000..c5988a53d7e --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-2r2x-3jh4-chhv/GHSA-2r2x-3jh4-chhv.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2r2x-3jh4-chhv", + "modified": "2024-05-22T09:31:45Z", + "published": "2024-05-22T09:31:45Z", + "aliases": [ + "CVE-2021-47455" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nptp: Fix possible memory leak in ptp_clock_register()\n\nI got memory leak as follows when doing fault injection test:\n\nunreferenced object 0xffff88800906c618 (size 8):\n comm \"i2c-idt82p33931\", pid 4421, jiffies 4294948083 (age 13.188s)\n hex dump (first 8 bytes):\n 70 74 70 30 00 00 00 00 ptp0....\n backtrace:\n [<00000000312ed458>] __kmalloc_track_caller+0x19f/0x3a0\n [<0000000079f6e2ff>] kvasprintf+0xb5/0x150\n [<0000000026aae54f>] kvasprintf_const+0x60/0x190\n [<00000000f323a5f7>] kobject_set_name_vargs+0x56/0x150\n [<000000004e35abdd>] dev_set_name+0xc0/0x100\n [<00000000f20cfe25>] ptp_clock_register+0x9f4/0xd30 [ptp]\n [<000000008bb9f0de>] idt82p33_probe.cold+0x8b6/0x1561 [ptp_idt82p33]\n\nWhen posix_clock_register() returns an error, the name allocated\nin dev_set_name() will be leaked, the put_device() should be used\nto give up the device reference, then the name will be freed in\nkobject_cleanup() and other memory will be freed in ptp_clock_release().", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47455" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4225fea1cb28370086e17e82c0f69bec2779dca0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/95c0a0c5ec8839f8f21672be786e87a100319ca8" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T07:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-34xf-292h-46f4/GHSA-34xf-292h-46f4.json b/advisories/unreviewed/2024/05/GHSA-34xf-292h-46f4/GHSA-34xf-292h-46f4.json new file mode 100644 index 00000000000..df78abe1f6e --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-34xf-292h-46f4/GHSA-34xf-292h-46f4.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-34xf-292h-46f4", + "modified": "2024-05-22T09:31:45Z", + "published": "2024-05-22T09:31:45Z", + "aliases": [ + "CVE-2021-47441" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmlxsw: thermal: Fix out-of-bounds memory accesses\n\nCurrently, mlxsw allows cooling states to be set above the maximum\ncooling state supported by the driver:\n\n # cat /sys/class/thermal/thermal_zone2/cdev0/type\n mlxsw_fan\n # cat /sys/class/thermal/thermal_zone2/cdev0/max_state\n 10\n # echo 18 > /sys/class/thermal/thermal_zone2/cdev0/cur_state\n # echo $?\n 0\n\nThis results in out-of-bounds memory accesses when thermal state\ntransition statistics are enabled (CONFIG_THERMAL_STATISTICS=y), as the\ntransition table is accessed with a too large index (state) [1].\n\nAccording to the thermal maintainer, it is the responsibility of the\ndriver to reject such operations [2].\n\nTherefore, return an error when the state to be set exceeds the maximum\ncooling state supported by the driver.\n\nTo avoid dead code, as suggested by the thermal maintainer [3],\npartially revert commit a421ce088ac8 (\"mlxsw: core: Extend cooling\ndevice with cooling levels\") that tried to interpret these invalid\ncooling states (above the maximum) in a special way. The cooling levels\narray is not removed in order to prevent the fans going below 20% PWM,\nwhich would cause them to get stuck at 0% PWM.\n\n[1]\nBUG: KASAN: slab-out-of-bounds in thermal_cooling_device_stats_update+0x271/0x290\nRead of size 4 at addr ffff8881052f7bf8 by task kworker/0:0/5\n\nCPU: 0 PID: 5 Comm: kworker/0:0 Not tainted 5.15.0-rc3-custom-45935-gce1adf704b14 #122\nHardware name: Mellanox Technologies Ltd. \"MSN2410-CB2FO\"/\"SA000874\", BIOS 4.6.5 03/08/2016\nWorkqueue: events_freezable_power_ thermal_zone_device_check\nCall Trace:\n dump_stack_lvl+0x8b/0xb3\n print_address_description.constprop.0+0x1f/0x140\n kasan_report.cold+0x7f/0x11b\n thermal_cooling_device_stats_update+0x271/0x290\n __thermal_cdev_update+0x15e/0x4e0\n thermal_cdev_update+0x9f/0xe0\n step_wise_throttle+0x770/0xee0\n thermal_zone_device_update+0x3f6/0xdf0\n process_one_work+0xa42/0x1770\n worker_thread+0x62f/0x13e0\n kthread+0x3ee/0x4e0\n ret_from_fork+0x1f/0x30\n\nAllocated by task 1:\n kasan_save_stack+0x1b/0x40\n __kasan_kmalloc+0x7c/0x90\n thermal_cooling_device_setup_sysfs+0x153/0x2c0\n __thermal_cooling_device_register.part.0+0x25b/0x9c0\n thermal_cooling_device_register+0xb3/0x100\n mlxsw_thermal_init+0x5c5/0x7e0\n __mlxsw_core_bus_device_register+0xcb3/0x19c0\n mlxsw_core_bus_device_register+0x56/0xb0\n mlxsw_pci_probe+0x54f/0x710\n local_pci_probe+0xc6/0x170\n pci_device_probe+0x2b2/0x4d0\n really_probe+0x293/0xd10\n __driver_probe_device+0x2af/0x440\n driver_probe_device+0x51/0x1e0\n __driver_attach+0x21b/0x530\n bus_for_each_dev+0x14c/0x1d0\n bus_add_driver+0x3ac/0x650\n driver_register+0x241/0x3d0\n mlxsw_sp_module_init+0xa2/0x174\n do_one_initcall+0xee/0x5f0\n kernel_init_freeable+0x45a/0x4de\n kernel_init+0x1f/0x210\n ret_from_fork+0x1f/0x30\n\nThe buggy address belongs to the object at ffff8881052f7800\n which belongs to the cache kmalloc-1k of size 1024\nThe buggy address is located 1016 bytes inside of\n 1024-byte region [ffff8881052f7800, ffff8881052f7c00)\nThe buggy address belongs to the page:\npage:0000000052355272 refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x1052f0\nhead:0000000052355272 order:3 compound_mapcount:0 compound_pincount:0\nflags: 0x200000000010200(slab|head|node=0|zone=2)\nraw: 0200000000010200 ffffea0005034800 0000000300000003 ffff888100041dc0\nraw: 0000000000000000 0000000000100010 00000001ffffffff 0000000000000000\npage dumped because: kasan: bad access detected\n\nMemory state around the buggy address:\n ffff8881052f7a80: 00 00 00 00 00 00 04 fc fc fc fc fc fc fc fc fc\n ffff8881052f7b00: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc\n>ffff8881052f7b80: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc\n ^\n ffff8881052f7c00: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc\n ffff8881052f7c80: fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc fc\n\n[2] https://lore.kernel.org/linux-pm/9aca37cb-1629-5c67-\n---truncated---", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47441" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/332fdf951df8b870e3da86b122ae304e2aabe88c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ae0993739e14a102d506aa09e11b0065f3144f10" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/df8e58716afb3bee2b59de66b1ba1033f2e26303" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e59d839743b50cb1d3f42a786bea48cc5621d254" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T07:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-35q9-qwff-qmh4/GHSA-35q9-qwff-qmh4.json b/advisories/unreviewed/2024/05/GHSA-35q9-qwff-qmh4/GHSA-35q9-qwff-qmh4.json new file mode 100644 index 00000000000..888114255e7 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-35q9-qwff-qmh4/GHSA-35q9-qwff-qmh4.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-35q9-qwff-qmh4", + "modified": "2024-05-22T09:31:44Z", + "published": "2024-05-22T09:31:44Z", + "aliases": [ + "CVE-2021-47439" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: dsa: microchip: Added the condition for scheduling ksz_mib_read_work\n\nWhen the ksz module is installed and removed using rmmod, kernel crashes\nwith null pointer dereferrence error. During rmmod, ksz_switch_remove\nfunction tries to cancel the mib_read_workqueue using\ncancel_delayed_work_sync routine and unregister switch from dsa.\n\nDuring dsa_unregister_switch it calls ksz_mac_link_down, which in turn\nreschedules the workqueue since mib_interval is non-zero.\nDue to which queue executed after mib_interval and it tries to access\ndp->slave. But the slave is unregistered in the ksz_switch_remove\nfunction. Hence kernel crashes.\n\nTo avoid this crash, before canceling the workqueue, resetted the\nmib_interval to 0.\n\nv1 -> v2:\n-Removed the if condition in ksz_mib_read_work", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47439" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/383239a33cf29ebee9ce0d4e0e5c900b77a16148" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ef1100ef20f29aec4e62abeccdb5bdbebba1e378" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f2e1de075018cf71bcd7d628e9f759cb8540b0c3" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T07:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-3c5v-hp3x-r94q/GHSA-3c5v-hp3x-r94q.json b/advisories/unreviewed/2024/05/GHSA-3c5v-hp3x-r94q/GHSA-3c5v-hp3x-r94q.json new file mode 100644 index 00000000000..922e0960b53 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-3c5v-hp3x-r94q/GHSA-3c5v-hp3x-r94q.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3c5v-hp3x-r94q", + "modified": "2024-05-22T09:31:44Z", + "published": "2024-05-22T09:31:44Z", + "aliases": [ + "CVE-2021-47435" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndm: fix mempool NULL pointer race when completing IO\n\ndm_io_dec_pending() calls end_io_acct() first and will then dec md\nin-flight pending count. But if a task is swapping DM table at same\ntime this can result in a crash due to mempool->elements being NULL:\n\ntask1 task2\ndo_resume\n ->do_suspend\n ->dm_wait_for_completion\n bio_endio\n\t\t\t\t ->clone_endio\n\t\t\t\t ->dm_io_dec_pending\n\t\t\t\t ->end_io_acct\n\t\t\t\t ->wakeup task1\n ->dm_swap_table\n ->__bind\n ->__bind_mempools\n ->bioset_exit\n ->mempool_exit\n ->free_io\n\n[ 67.330330] Unable to handle kernel NULL pointer dereference at\nvirtual address 0000000000000000\n......\n[ 67.330494] pstate: 80400085 (Nzcv daIf +PAN -UAO)\n[ 67.330510] pc : mempool_free+0x70/0xa0\n[ 67.330515] lr : mempool_free+0x4c/0xa0\n[ 67.330520] sp : ffffff8008013b20\n[ 67.330524] x29: ffffff8008013b20 x28: 0000000000000004\n[ 67.330530] x27: ffffffa8c2ff40a0 x26: 00000000ffff1cc8\n[ 67.330535] x25: 0000000000000000 x24: ffffffdada34c800\n[ 67.330541] x23: 0000000000000000 x22: ffffffdada34c800\n[ 67.330547] x21: 00000000ffff1cc8 x20: ffffffd9a1304d80\n[ 67.330552] x19: ffffffdada34c970 x18: 000000b312625d9c\n[ 67.330558] x17: 00000000002dcfbf x16: 00000000000006dd\n[ 67.330563] x15: 000000000093b41e x14: 0000000000000010\n[ 67.330569] x13: 0000000000007f7a x12: 0000000034155555\n[ 67.330574] x11: 0000000000000001 x10: 0000000000000001\n[ 67.330579] x9 : 0000000000000000 x8 : 0000000000000000\n[ 67.330585] x7 : 0000000000000000 x6 : ffffff80148b5c1a\n[ 67.330590] x5 : ffffff8008013ae0 x4 : 0000000000000001\n[ 67.330596] x3 : ffffff80080139c8 x2 : ffffff801083bab8\n[ 67.330601] x1 : 0000000000000000 x0 : ffffffdada34c970\n[ 67.330609] Call trace:\n[ 67.330616] mempool_free+0x70/0xa0\n[ 67.330627] bio_put+0xf8/0x110\n[ 67.330638] dec_pending+0x13c/0x230\n[ 67.330644] clone_endio+0x90/0x180\n[ 67.330649] bio_endio+0x198/0x1b8\n[ 67.330655] dec_pending+0x190/0x230\n[ 67.330660] clone_endio+0x90/0x180\n[ 67.330665] bio_endio+0x198/0x1b8\n[ 67.330673] blk_update_request+0x214/0x428\n[ 67.330683] scsi_end_request+0x2c/0x300\n[ 67.330688] scsi_io_completion+0xa0/0x710\n[ 67.330695] scsi_finish_command+0xd8/0x110\n[ 67.330700] scsi_softirq_done+0x114/0x148\n[ 67.330708] blk_done_softirq+0x74/0xd0\n[ 67.330716] __do_softirq+0x18c/0x374\n[ 67.330724] irq_exit+0xb4/0xb8\n[ 67.330732] __handle_domain_irq+0x84/0xc0\n[ 67.330737] gic_handle_irq+0x148/0x1b0\n[ 67.330744] el1_irq+0xe8/0x190\n[ 67.330753] lpm_cpuidle_enter+0x4f8/0x538\n[ 67.330759] cpuidle_enter_state+0x1fc/0x398\n[ 67.330764] cpuidle_enter+0x18/0x20\n[ 67.330772] do_idle+0x1b4/0x290\n[ 67.330778] cpu_startup_entry+0x20/0x28\n[ 67.330786] secondary_start_kernel+0x160/0x170\n\nFix this by:\n1) Establishing pointers to 'struct dm_io' members in\ndm_io_dec_pending() so that they may be passed into end_io_acct()\n_after_ free_io() is called.\n2) Moving end_io_acct() after free_io().", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47435" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6e506f07c5b561d673dd0b0d8f7f420cc48024fb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9e07272cca2ed76f7f6073f4444b1143828c8d87" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9fb7cd5c7fef0f1c982e3cd27745a0dec260eaed" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ad1393b92e5059218d055bfec8f4946d85ad04c4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d208b89401e073de986dc891037c5a668f5d5d95" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d29c78d3f9c5d2604548c1065bf1ec212728ea61" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d35aef9c60d310eff3eaddacce301efe877e2b7c" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T07:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-3pg2-q6q7-9rmm/GHSA-3pg2-q6q7-9rmm.json b/advisories/unreviewed/2024/05/GHSA-3pg2-q6q7-9rmm/GHSA-3pg2-q6q7-9rmm.json new file mode 100644 index 00000000000..132155ce09a --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-3pg2-q6q7-9rmm/GHSA-3pg2-q6q7-9rmm.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3pg2-q6q7-9rmm", + "modified": "2024-05-22T09:31:44Z", + "published": "2024-05-22T09:31:44Z", + "aliases": [ + "CVE-2021-47437" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\niio: adis16475: fix deadlock on frequency set\n\nWith commit 39c024b51b560\n(\"iio: adis16475: improve sync scale mode handling\"), two deadlocks were\nintroduced:\n 1) The call to 'adis_write_reg_16()' was not changed to it's unlocked\n version.\n 2) The lock was not being released on the success path of the function.\n\nThis change fixes both these issues.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47437" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/04e03b907022ebd876f422f17efcc2c6cc934dc6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9da1b86865ab4376408c58cd9fec332c8bdb5c73" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T07:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-45hj-5gpj-93h8/GHSA-45hj-5gpj-93h8.json b/advisories/unreviewed/2024/05/GHSA-45hj-5gpj-93h8/GHSA-45hj-5gpj-93h8.json new file mode 100644 index 00000000000..cfe85fd261f --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-45hj-5gpj-93h8/GHSA-45hj-5gpj-93h8.json @@ -0,0 +1,63 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-45hj-5gpj-93h8", + "modified": "2024-05-22T09:31:45Z", + "published": "2024-05-22T09:31:45Z", + "aliases": [ + "CVE-2021-47456" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: peak_pci: peak_pci_remove(): fix UAF\n\nWhen remove the module peek_pci, referencing 'chan' again after\nreleasing 'dev' will cause UAF.\n\nFix this by releasing 'dev' later.\n\nThe following log reveals it:\n\n[ 35.961814 ] BUG: KASAN: use-after-free in peak_pci_remove+0x16f/0x270 [peak_pci]\n[ 35.963414 ] Read of size 8 at addr ffff888136998ee8 by task modprobe/5537\n[ 35.965513 ] Call Trace:\n[ 35.965718 ] dump_stack_lvl+0xa8/0xd1\n[ 35.966028 ] print_address_description+0x87/0x3b0\n[ 35.966420 ] kasan_report+0x172/0x1c0\n[ 35.966725 ] ? peak_pci_remove+0x16f/0x270 [peak_pci]\n[ 35.967137 ] ? trace_irq_enable_rcuidle+0x10/0x170\n[ 35.967529 ] ? peak_pci_remove+0x16f/0x270 [peak_pci]\n[ 35.967945 ] __asan_report_load8_noabort+0x14/0x20\n[ 35.968346 ] peak_pci_remove+0x16f/0x270 [peak_pci]\n[ 35.968752 ] pci_device_remove+0xa9/0x250", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47456" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0e5afdc2315b0737edcf55bede4ee1640d2d464d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1248582e47a9f7ce0ecd156c39fc61f8b6aa3699" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1c616528ba4aeb1125a06b407572ab7b56acae38" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/28f28e4bc3a5e0051faa963f10b778ab38c1db69" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/34914971bb3244db4ce2be44e9438a9b30c56250" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/447d44cd2f67a20b596ede3ca3cd67086dfd9ca9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/949fe9b35570361bc6ee2652f89a0561b26eec98" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/adbda14730aacce41c0d3596415aa39ad63eafd9" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T07:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-4fph-66x7-mxrv/GHSA-4fph-66x7-mxrv.json b/advisories/unreviewed/2024/05/GHSA-4fph-66x7-mxrv/GHSA-4fph-66x7-mxrv.json new file mode 100644 index 00000000000..a31b2a9b184 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-4fph-66x7-mxrv/GHSA-4fph-66x7-mxrv.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4fph-66x7-mxrv", + "modified": "2024-05-22T09:31:46Z", + "published": "2024-05-22T09:31:46Z", + "aliases": [ + "CVE-2024-3927" + ], + "details": "The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Form Submission Admin Email Bypass in all versions up to, and including, 5.6.3. This is due to the plugin not properly checking for all variations of an administrators emails. This makes it possible for unauthenticated attackers to bypass the restriction using a +value when submitting the contact form.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3927" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/bdthemes-element-pack-lite/trunk/modules/contact-form/module.php#L102" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3089154" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/3a703fc4-6c61-442e-a637-515e9f501575?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T07:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-4fpw-6gvj-w9xf/GHSA-4fpw-6gvj-w9xf.json b/advisories/unreviewed/2024/05/GHSA-4fpw-6gvj-w9xf/GHSA-4fpw-6gvj-w9xf.json new file mode 100644 index 00000000000..a979d6ebb5c --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-4fpw-6gvj-w9xf/GHSA-4fpw-6gvj-w9xf.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4fpw-6gvj-w9xf", + "modified": "2024-05-22T09:31:46Z", + "published": "2024-05-22T09:31:46Z", + "aliases": [ + "CVE-2024-32988" + ], + "details": "'OfferBox' App for Android versions 2.0.0 to 2.3.17 and 'OfferBox' App for iOS versions 2.1.7 to 2.6.14 use a hard-coded secret key for JWT. Secret key for JWT may be retrieved if the application binary is reverse-engineered.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32988" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/jp/JVN83405304" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T08:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-4v89-q9h7-p6vx/GHSA-4v89-q9h7-p6vx.json b/advisories/unreviewed/2024/05/GHSA-4v89-q9h7-p6vx/GHSA-4v89-q9h7-p6vx.json new file mode 100644 index 00000000000..e21a83ffbaa --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-4v89-q9h7-p6vx/GHSA-4v89-q9h7-p6vx.json @@ -0,0 +1,67 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4v89-q9h7-p6vx", + "modified": "2024-05-22T09:31:46Z", + "published": "2024-05-22T09:31:46Z", + "aliases": [ + "CVE-2021-47474" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncomedi: vmk80xx: fix bulk-buffer overflow\n\nThe driver is using endpoint-sized buffers but must not assume that the\ntx and rx buffers are of equal size or a malicious device could overflow\nthe slab-allocated receive buffer when doing bulk transfers.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47474" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/063f576c43d589a4c153554b681d32b3f8317c7b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0866dcaa828c21bc2f94dac00e086078f11b5772" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1ae4715121a57bc6fa29fd992127b01907f2f993" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/47b4636ebdbeba2044b3db937c4d2b6a4fe3d0f2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/78cdfd62bd54af615fba9e3ca1ba35de39d3871d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7b0e356189327287d0eb98ec081bd6dd97068cd3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7cfb35db607760698d299fd1cf7402dfa8f09973" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b7fd7f3387f070215e6be341e68eb5c087eeecc0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e0e6a63fd97ad95fe05dfd77268a1952551e11a7" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T09:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-5573-w6h2-wwx8/GHSA-5573-w6h2-wwx8.json b/advisories/unreviewed/2024/05/GHSA-5573-w6h2-wwx8/GHSA-5573-w6h2-wwx8.json new file mode 100644 index 00000000000..b4db5e8be00 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-5573-w6h2-wwx8/GHSA-5573-w6h2-wwx8.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5573-w6h2-wwx8", + "modified": "2024-05-22T09:31:45Z", + "published": "2024-05-22T09:31:45Z", + "aliases": [ + "CVE-2021-47462" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/mempolicy: do not allow illegal MPOL_F_NUMA_BALANCING | MPOL_LOCAL in mbind()\n\nsyzbot reported access to unitialized memory in mbind() [1]\n\nIssue came with commit bda420b98505 (\"numa balancing: migrate on fault\namong multiple bound nodes\")\n\nThis commit added a new bit in MPOL_MODE_FLAGS, but only checked valid\ncombination (MPOL_F_NUMA_BALANCING can only be used with MPOL_BIND) in\ndo_set_mempolicy()\n\nThis patch moves the check in sanitize_mpol_flags() so that it is also\nused by mbind()\n\n [1]\n BUG: KMSAN: uninit-value in __mpol_equal+0x567/0x590 mm/mempolicy.c:2260\n __mpol_equal+0x567/0x590 mm/mempolicy.c:2260\n mpol_equal include/linux/mempolicy.h:105 [inline]\n vma_merge+0x4a1/0x1e60 mm/mmap.c:1190\n mbind_range+0xcc8/0x1e80 mm/mempolicy.c:811\n do_mbind+0xf42/0x15f0 mm/mempolicy.c:1333\n kernel_mbind mm/mempolicy.c:1483 [inline]\n __do_sys_mbind mm/mempolicy.c:1490 [inline]\n __se_sys_mbind+0x437/0xb80 mm/mempolicy.c:1486\n __x64_sys_mbind+0x19d/0x200 mm/mempolicy.c:1486\n do_syscall_x64 arch/x86/entry/common.c:51 [inline]\n do_syscall_64+0x54/0xd0 arch/x86/entry/common.c:82\n entry_SYSCALL_64_after_hwframe+0x44/0xae\n\n Uninit was created at:\n slab_alloc_node mm/slub.c:3221 [inline]\n slab_alloc mm/slub.c:3230 [inline]\n kmem_cache_alloc+0x751/0xff0 mm/slub.c:3235\n mpol_new mm/mempolicy.c:293 [inline]\n do_mbind+0x912/0x15f0 mm/mempolicy.c:1289\n kernel_mbind mm/mempolicy.c:1483 [inline]\n __do_sys_mbind mm/mempolicy.c:1490 [inline]\n __se_sys_mbind+0x437/0xb80 mm/mempolicy.c:1486\n __x64_sys_mbind+0x19d/0x200 mm/mempolicy.c:1486\n do_syscall_x64 arch/x86/entry/common.c:51 [inline]\n do_syscall_64+0x54/0xd0 arch/x86/entry/common.c:82\n entry_SYSCALL_64_after_hwframe+0x44/0xae\n =====================================================\n Kernel panic - not syncing: panic_on_kmsan set ...\n CPU: 0 PID: 15049 Comm: syz-executor.0 Tainted: G B 5.15.0-rc2-syzkaller #0\n Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011\n Call Trace:\n __dump_stack lib/dump_stack.c:88 [inline]\n dump_stack_lvl+0x1ff/0x28e lib/dump_stack.c:106\n dump_stack+0x25/0x28 lib/dump_stack.c:113\n panic+0x44f/0xdeb kernel/panic.c:232\n kmsan_report+0x2ee/0x300 mm/kmsan/report.c:186\n __msan_warning+0xd7/0x150 mm/kmsan/instrumentation.c:208\n __mpol_equal+0x567/0x590 mm/mempolicy.c:2260\n mpol_equal include/linux/mempolicy.h:105 [inline]\n vma_merge+0x4a1/0x1e60 mm/mmap.c:1190\n mbind_range+0xcc8/0x1e80 mm/mempolicy.c:811\n do_mbind+0xf42/0x15f0 mm/mempolicy.c:1333\n kernel_mbind mm/mempolicy.c:1483 [inline]\n __do_sys_mbind mm/mempolicy.c:1490 [inline]\n __se_sys_mbind+0x437/0xb80 mm/mempolicy.c:1486\n __x64_sys_mbind+0x19d/0x200 mm/mempolicy.c:1486\n do_syscall_x64 arch/x86/entry/common.c:51 [inline]\n do_syscall_64+0x54/0xd0 arch/x86/entry/common.c:82\n entry_SYSCALL_64_after_hwframe+0x44/0xae", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47462" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6d2aec9e123bb9c49cb5c7fc654f25f81e688e8c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9ee4e9ae98f1f262d6fae0d266cfdf3ba2c321d9" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T07:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-5g4g-hgmr-mqrx/GHSA-5g4g-hgmr-mqrx.json b/advisories/unreviewed/2024/05/GHSA-5g4g-hgmr-mqrx/GHSA-5g4g-hgmr-mqrx.json new file mode 100644 index 00000000000..230396c0cda --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-5g4g-hgmr-mqrx/GHSA-5g4g-hgmr-mqrx.json @@ -0,0 +1,63 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5g4g-hgmr-mqrx", + "modified": "2024-05-22T09:31:45Z", + "published": "2024-05-22T09:31:45Z", + "aliases": [ + "CVE-2021-47443" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nNFC: digital: fix possible memory leak in digital_tg_listen_mdaa()\n\n'params' is allocated in digital_tg_listen_mdaa(), but not free when\ndigital_send_cmd() failed, which will cause memory leak. Fix it by\nfreeing 'params' if digital_send_cmd() return failed.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47443" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3f2960b39f22e26cf8addae93c3f5884d1c183c9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/429054ec51e648d241a7e0b465cf44f6633334c5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/564249219e5b5673a8416b5181875d828c3f1e8c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/58e7dcc9ca29c14e44267a4d0ea61e3229124907" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7ab488d7228a9dceb2456867f1f0919decf6efed" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9881b0c860649f27ef2565deef011e516390f416" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a67d47e32c91e2b10402cb8c081774cbf08edb2e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b7b023e6ff567e991c31cd425b0e1d16779c938b" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T07:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-5ggq-5m2f-79jm/GHSA-5ggq-5m2f-79jm.json b/advisories/unreviewed/2024/05/GHSA-5ggq-5m2f-79jm/GHSA-5ggq-5m2f-79jm.json new file mode 100644 index 00000000000..efce3e7c9f9 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-5ggq-5m2f-79jm/GHSA-5ggq-5m2f-79jm.json @@ -0,0 +1,55 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5ggq-5m2f-79jm", + "modified": "2024-05-22T09:31:44Z", + "published": "2024-05-22T09:31:44Z", + "aliases": [ + "CVE-2021-47434" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nxhci: Fix command ring pointer corruption while aborting a command\n\nThe command ring pointer is located at [6:63] bits of the command\nring control register (CRCR). All the control bits like command stop,\nabort are located at [0:3] bits. While aborting a command, we read the\nCRCR and set the abort bit and write to the CRCR. The read will always\ngive command ring pointer as all zeros. So we essentially write only\nthe control bits. Since we split the 64 bit write into two 32 bit writes,\nthere is a possibility of xHC command ring stopped before the upper\ndword (all zeros) is written. If that happens, xHC updates the upper\ndword of its internal command ring pointer with all zeros. Next time,\nwhen the command ring is restarted, we see xHC memory access failures.\nFix this issue by only writing to the lower dword of CRCR where all\ncontrol bits are located.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47434" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/01c2dcb67e71c351006dd17cbba86c26b7f61eaf" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/22bcb65ea41072ab5d03c0c6290e04e0df6d09a0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/62c182b5e763e5f4062e72678e72ce3e02dd4d1b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/dec944bb7079b37968cf69c8a438f91f15c4cc61" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e54abefe703ab7c4e5983e889babd1447738ca42" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ff0e50d3564f33b7f4b35cadeabd951d66cfc570" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T07:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-5p44-j78m-mc5m/GHSA-5p44-j78m-mc5m.json b/advisories/unreviewed/2024/05/GHSA-5p44-j78m-mc5m/GHSA-5p44-j78m-mc5m.json new file mode 100644 index 00000000000..8021599b75c --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-5p44-j78m-mc5m/GHSA-5p44-j78m-mc5m.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5p44-j78m-mc5m", + "modified": "2024-05-22T09:31:47Z", + "published": "2024-05-22T09:31:47Z", + "aliases": [ + "CVE-2024-3495" + ], + "details": "The Country State City Dropdown CF7 plugin for WordPress is vulnerable to SQL Injection via the ‘cnt’ and 'sid' parameters in versions up to, and including, 2.7.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3495" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/country-state-city-auto-dropdown/trunk/includes/ajax-actions.php#L22" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/country-state-city-auto-dropdown/trunk/includes/ajax-actions.php#L8" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3089374%40country-state-city-auto-dropdown%2Ftrunk&old=3068802%40country-state-city-auto-dropdown%2Ftrunk&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/17dcacaf-0e2a-4bef-b944-fb7e43d25777?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T09:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-5px8-4qwx-4qj6/GHSA-5px8-4qwx-4qj6.json b/advisories/unreviewed/2024/05/GHSA-5px8-4qwx-4qj6/GHSA-5px8-4qwx-4qj6.json new file mode 100644 index 00000000000..80a01397879 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-5px8-4qwx-4qj6/GHSA-5px8-4qwx-4qj6.json @@ -0,0 +1,55 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5px8-4qwx-4qj6", + "modified": "2024-05-22T09:31:46Z", + "published": "2024-05-22T09:31:46Z", + "aliases": [ + "CVE-2021-47490" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/ttm: fix memleak in ttm_transfered_destroy\n\nWe need to cleanup the fences for ghost objects as well.\n\nBug: https://bugzilla.kernel.org/show_bug.cgi?id=214029\nBug: https://bugzilla.kernel.org/show_bug.cgi?id=214447", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47490" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0db55f9a1bafbe3dac750ea669de9134922389b5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/132a3d998d6753047f22152731fba2b0d6b463dd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/960b1fdfc39aba8f41e9e27b2de0c925c74182d9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bbc920fb320f1c241cc34ac85edaa0058922246a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bd99782f3ca491879e8524c89b1c0f40071903bd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c21b4002214c1c7e7b627b9b53375612f7aab6db" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T09:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-6hjm-9p27-2qv2/GHSA-6hjm-9p27-2qv2.json b/advisories/unreviewed/2024/05/GHSA-6hjm-9p27-2qv2/GHSA-6hjm-9p27-2qv2.json new file mode 100644 index 00000000000..3f7fbddf11b --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-6hjm-9p27-2qv2/GHSA-6hjm-9p27-2qv2.json @@ -0,0 +1,91 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6hjm-9p27-2qv2", + "modified": "2024-05-22T09:31:46Z", + "published": "2024-05-22T09:31:46Z", + "aliases": [ + "CVE-2021-47472" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: mdiobus: Fix memory leak in __mdiobus_register\n\nOnce device_register() failed, we should call put_device() to\ndecrement reference count for cleanup. Or it will cause memory\nleak.\n\nBUG: memory leak\nunreferenced object 0xffff888114032e00 (size 256):\n comm \"kworker/1:3\", pid 2960, jiffies 4294943572 (age 15.920s)\n hex dump (first 32 bytes):\n 00 00 00 00 00 00 00 00 08 2e 03 14 81 88 ff ff ................\n 08 2e 03 14 81 88 ff ff 90 76 65 82 ff ff ff ff .........ve.....\n backtrace:\n [] kmalloc include/linux/slab.h:591 [inline]\n [] kzalloc include/linux/slab.h:721 [inline]\n [] device_private_init drivers/base/core.c:3203 [inline]\n [] device_add+0x89b/0xdf0 drivers/base/core.c:3253\n [] __mdiobus_register+0xc3/0x450 drivers/net/phy/mdio_bus.c:537\n [] __devm_mdiobus_register+0x75/0xf0 drivers/net/phy/mdio_devres.c:87\n [] ax88772_init_mdio drivers/net/usb/asix_devices.c:676 [inline]\n [] ax88772_bind+0x330/0x480 drivers/net/usb/asix_devices.c:786\n [] usbnet_probe+0x3ff/0xdf0 drivers/net/usb/usbnet.c:1745\n [] usb_probe_interface+0x177/0x370 drivers/usb/core/driver.c:396\n [] call_driver_probe drivers/base/dd.c:517 [inline]\n [] really_probe.part.0+0xe7/0x380 drivers/base/dd.c:596\n [] really_probe drivers/base/dd.c:558 [inline]\n [] __driver_probe_device+0x10c/0x1e0 drivers/base/dd.c:751\n [] driver_probe_device+0x2a/0x120 drivers/base/dd.c:781\n [] __device_attach_driver+0xf6/0x140 drivers/base/dd.c:898\n [] bus_for_each_drv+0xb7/0x100 drivers/base/bus.c:427\n [] __device_attach+0x122/0x260 drivers/base/dd.c:969\n [] bus_probe_device+0xc6/0xe0 drivers/base/bus.c:487\n [] device_add+0x5fb/0xdf0 drivers/base/core.c:3359\n [] usb_set_configuration+0x9d9/0xb90 drivers/usb/core/message.c:2170\n [] usb_generic_driver_probe+0x8c/0xc0 drivers/usb/core/generic.c:238\n\nBUG: memory leak\nunreferenced object 0xffff888116f06900 (size 32):\n comm \"kworker/0:2\", pid 2670, jiffies 4294944448 (age 7.160s)\n hex dump (first 32 bytes):\n 75 73 62 2d 30 30 31 3a 30 30 33 00 00 00 00 00 usb-001:003.....\n 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n backtrace:\n [] kstrdup+0x36/0x70 mm/util.c:60\n [] kstrdup_const+0x53/0x80 mm/util.c:83\n [] kvasprintf_const+0xc2/0x110 lib/kasprintf.c:48\n [] kobject_set_name_vargs+0x3b/0xe0 lib/kobject.c:289\n [] dev_set_name+0x63/0x90 drivers/base/core.c:3147\n [] __mdiobus_register+0xbb/0x450 drivers/net/phy/mdio_bus.c:535\n [] __devm_mdiobus_register+0x75/0xf0 drivers/net/phy/mdio_devres.c:87\n [] ax88772_init_mdio drivers/net/usb/asix_devices.c:676 [inline]\n [] ax88772_bind+0x330/0x480 drivers/net/usb/asix_devices.c:786\n [] usbnet_probe+0x3ff/0xdf0 drivers/net/usb/usbnet.c:1745\n [] usb_probe_interface+0x177/0x370 drivers/usb/core/driver.c:396\n [] call_driver_probe drivers/base/dd.c:517 [inline]\n [] really_probe.part.0+0xe7/0x380 drivers/base/dd.c:596\n [] really_probe drivers/base/dd.c:558 [inline]\n [] __driver_probe_device+0x10c/0x1e0 drivers/base/dd.c:751\n [] driver_probe_device+0x2a/0x120 drivers/base/dd.c:781\n [] __device_attach_driver+0xf6/0x140 drivers/base/dd.c:898\n [] bus_for_each\n---truncated---", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47472" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0c4e87ba11eb331dca2315d484d08441b8c13193" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2bc10dca9432fadb09e45127e258fc7127fd346d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3a0dc2e35a5d6546b1db87fe985582dadc64fe7b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4ec0f9abc512cc02fb04daa89ccf6697e80ab417" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6a18d155d5b35ad50c8fac2be091212487ae58ec" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8121d0d4fd108280f5cd7b7fe8c6592adaa37be9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8ba94a7f7b9fc2a2b808ccceb99b77135deae21a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a9831afa2dc8a18205403907c41aa4e0950ac611" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ab609f25d19858513919369ff3d9a63c02cd9e2e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b0feaa8376f52357bf2fd020d0c471713a859728" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b89f4537d7fdbd0bafb6d8a66a484e0bc99871a4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bc5f2f3431ced08300e4cb3aff35f1da14c26433" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c828115a14eacbf42042770fd68543f134e89efa" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fd2400dd4f1b8bd7a309b1b424d9e0d188151b01" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fdbffd95c4ce94d2197c504008eaac46b16bc5a4" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T07:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-6vq2-rrj2-6jjh/GHSA-6vq2-rrj2-6jjh.json b/advisories/unreviewed/2024/05/GHSA-6vq2-rrj2-6jjh/GHSA-6vq2-rrj2-6jjh.json new file mode 100644 index 00000000000..660d985b69e --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-6vq2-rrj2-6jjh/GHSA-6vq2-rrj2-6jjh.json @@ -0,0 +1,67 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6vq2-rrj2-6jjh", + "modified": "2024-05-22T09:31:46Z", + "published": "2024-05-22T09:31:46Z", + "aliases": [ + "CVE-2021-47477" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncomedi: dt9812: fix DMA buffers on stack\n\nUSB transfer buffers are typically mapped for DMA and must not be\nallocated on the stack or transfers will fail.\n\nAllocate proper transfer buffers in the various command helpers and\nreturn an error on short transfers instead of acting on random stack\ndata.\n\nNote that this also fixes a stack info leak on systems where DMA is not\nused as 32 bytes are always sent to the device regardless of how short\nthe command is.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47477" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/20cebb8b620dc987e55ddc46801de986e081757e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/365a346cda82f51d835c49136a00a9df8a78c7f2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/39ea61037ae78f14fa121228dd962ea3280eacf3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3ac273d154d634e2034508a14db82a95d7ad12ed" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3efb7af8ac437085b6c776e5b54830b149d86efe" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/536de747bc48262225889a533db6650731ab25d3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/786f5b03450454557ff858a8bead5d7c0cbf78d6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8a52bc480992c7c9da3ebfea456af731f50a4b97" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a6af69768d5cb4b2528946d53be5fa19ade37723" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T09:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-6w3g-x8mp-cp7x/GHSA-6w3g-x8mp-cp7x.json b/advisories/unreviewed/2024/05/GHSA-6w3g-x8mp-cp7x/GHSA-6w3g-x8mp-cp7x.json new file mode 100644 index 00000000000..a46ff14e5ce --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-6w3g-x8mp-cp7x/GHSA-6w3g-x8mp-cp7x.json @@ -0,0 +1,67 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6w3g-x8mp-cp7x", + "modified": "2024-05-22T09:31:46Z", + "published": "2024-05-22T09:31:46Z", + "aliases": [ + "CVE-2021-47475" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncomedi: vmk80xx: fix transfer-buffer overflows\n\nThe driver uses endpoint-sized USB transfer buffers but up until\nrecently had no sanity checks on the sizes.\n\nCommit e1f13c879a7c (\"staging: comedi: check validity of wMaxPacketSize\nof usb endpoints found\") inadvertently fixed NULL-pointer dereferences\nwhen accessing the transfer buffers in case a malicious device has a\nzero wMaxPacketSize.\n\nMake sure to allocate buffers large enough to handle also the other\naccesses that are done without a size check (e.g. byte 18 in\nvmk80xx_cnt_insn_read() for the VMK8061_MODEL) to avoid writing beyond\nthe buffers, for example, when doing descriptor fuzzing.\n\nThe original driver was for a low-speed device with 8-byte buffers.\nSupport was later added for a device that uses bulk transfers and is\npresumably a full-speed device with a maximum 64-byte wMaxPacketSize.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47475" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/06ac746d57e6d32b062e220415c607b7e2e0fa50" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/199acd8c110e3ae62833c24f632b0bb1c9f012a9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/278484ae93297b1bb1ce755f9d3b6d95a48c7d47" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/33d7a470730dfe7c9bfc8da84575cf2cedd60d00" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/40d2a7e278e2e7c0a5fd7e997e7eb63945bf93f7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5229159f1d052821007aff1a1beb7873eacf1a9f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7a2021b896de1ad559d33b5c5cdd20b982242088" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a23461c47482fc232ffc9b819539d1f837adf2b1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ec85bcff4ed09260243d8f39faba99e1041718ba" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T09:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-6x3x-fg57-3vcm/GHSA-6x3x-fg57-3vcm.json b/advisories/unreviewed/2024/05/GHSA-6x3x-fg57-3vcm/GHSA-6x3x-fg57-3vcm.json new file mode 100644 index 00000000000..34c7e12c376 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-6x3x-fg57-3vcm/GHSA-6x3x-fg57-3vcm.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6x3x-fg57-3vcm", + "modified": "2024-05-22T09:31:44Z", + "published": "2024-05-22T09:31:44Z", + "aliases": [ + "CVE-2021-47433" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix abort logic in btrfs_replace_file_extents\n\nError injection testing uncovered a case where we'd end up with a\ncorrupt file system with a missing extent in the middle of a file. This\noccurs because the if statement to decide if we should abort is wrong.\n\nThe only way we would abort in this case is if we got a ret !=\n-EOPNOTSUPP and we called from the file clone code. However the\nprealloc code uses this path too. Instead we need to abort if there is\nan error, and the only error we _don't_ abort on is -EOPNOTSUPP and only\nif we came from the clone file code.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47433" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0e309e1152fc34ef75991d9d69b165dbf75bf26c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0e32a2b85c7d92ece86c17dfef390c5ed79c6378" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4afb912f439c4bc4e6a4f3e7547f2e69e354108f" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T07:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-6xwm-63wf-q2q3/GHSA-6xwm-63wf-q2q3.json b/advisories/unreviewed/2024/05/GHSA-6xwm-63wf-q2q3/GHSA-6xwm-63wf-q2q3.json new file mode 100644 index 00000000000..8c42fa5bf33 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-6xwm-63wf-q2q3/GHSA-6xwm-63wf-q2q3.json @@ -0,0 +1,55 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6xwm-63wf-q2q3", + "modified": "2024-05-22T09:31:44Z", + "published": "2024-05-22T09:31:44Z", + "aliases": [ + "CVE-2021-47436" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: musb: dsps: Fix the probe error path\n\nCommit 7c75bde329d7 (\"usb: musb: musb_dsps: request_irq() after\ninitializing musb\") has inverted the calls to\ndsps_setup_optional_vbus_irq() and dsps_create_musb_pdev() without\nupdating correctly the error path. dsps_create_musb_pdev() allocates and\nregisters a new platform device which must be unregistered and freed\nwith platform_device_unregister(), and this is missing upon\ndsps_setup_optional_vbus_irq() error.\n\nWhile on the master branch it seems not to trigger any issue, I observed\na kernel crash because of a NULL pointer dereference with a v5.10.70\nstable kernel where the patch mentioned above was backported. With this\nkernel version, -EPROBE_DEFER is returned the first time\ndsps_setup_optional_vbus_irq() is called which triggers the probe to\nerror out without unregistering the platform device. Unfortunately, on\nthe Beagle Bone Black Wireless, the platform device still living in the\nsystem is being used by the USB Ethernet gadget driver, which during the\nboot phase triggers the crash.\n\nMy limited knowledge of the musb world prevents me to revert this commit\nwhich was sent to silence a robot warning which, as far as I understand,\ndoes not make sense. The goal of this patch was to prevent an IRQ to\nfire before the platform device being registered. I think this cannot\never happen due to the fact that enabling the interrupts is done by the\n->enable() callback of the platform musb device, and this platform\ndevice must be already registered in order for the core or any other\nuser to use this callback.\n\nHence, I decided to fix the error path, which might prevent future\nerrors on mainline kernels while also fixing older ones.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47436" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5ed60a430fb5f3d93e7fef66264daef466b4d10c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9ab5d539bc975b8dcde86eca1b58d836b657732e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9d89e287116796bf987cc48f5c8632ef3048f8eb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c2115b2b16421d93d4993f3fe4c520e91d6fe801" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e923bce31ffefe4f60edfc6b84f62d4a858f3676" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ff9249aab39820be11b6975a10d94253b7d426fc" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T07:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-7379-xh69-jh8v/GHSA-7379-xh69-jh8v.json b/advisories/unreviewed/2024/05/GHSA-7379-xh69-jh8v/GHSA-7379-xh69-jh8v.json new file mode 100644 index 00000000000..5f30f76509c --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-7379-xh69-jh8v/GHSA-7379-xh69-jh8v.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7379-xh69-jh8v", + "modified": "2024-05-22T09:31:47Z", + "published": "2024-05-22T09:31:47Z", + "aliases": [ + "CVE-2024-4896" + ], + "details": "The WPB Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 1.0.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4896" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wpb-elementor-addons/trunk/templates/videos_grid.php#L323" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3088737/#file26" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/103dea33-0c30-460e-80e4-fead18928a62?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T09:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-73gq-r5qh-jgmm/GHSA-73gq-r5qh-jgmm.json b/advisories/unreviewed/2024/05/GHSA-73gq-r5qh-jgmm/GHSA-73gq-r5qh-jgmm.json new file mode 100644 index 00000000000..48fa0e05cfc --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-73gq-r5qh-jgmm/GHSA-73gq-r5qh-jgmm.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-73gq-r5qh-jgmm", + "modified": "2024-05-22T09:31:46Z", + "published": "2024-05-22T09:31:46Z", + "aliases": [ + "CVE-2024-2163" + ], + "details": "The Ninja Beaver Add-ons for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 2.4.5 due to insufficient input sanitization and output escaping on user supplied attributes such as urls. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2163" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/ninja-beaver-lite-addons-for-beaver-builder" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/1e257954-9e44-4939-8e01-efceb3c0953a?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T08:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-73h7-mvv6-m363/GHSA-73h7-mvv6-m363.json b/advisories/unreviewed/2024/05/GHSA-73h7-mvv6-m363/GHSA-73h7-mvv6-m363.json new file mode 100644 index 00000000000..f3828f7dbba --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-73h7-mvv6-m363/GHSA-73h7-mvv6-m363.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-73h7-mvv6-m363", + "modified": "2024-05-22T09:31:46Z", + "published": "2024-05-22T09:31:46Z", + "aliases": [ + "CVE-2024-3666" + ], + "details": "The Opal Estate Pro – Property Management and Submission plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the agent latitude and longitude parameters in all versions up to, and including, 1.7.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3666" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/opal-estate-pro" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/c4d5d58f-913a-4a26-8b2a-bfdd08033993?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T08:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-74c3-rgpv-v3qr/GHSA-74c3-rgpv-v3qr.json b/advisories/unreviewed/2024/05/GHSA-74c3-rgpv-v3qr/GHSA-74c3-rgpv-v3qr.json new file mode 100644 index 00000000000..29d43ff051a --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-74c3-rgpv-v3qr/GHSA-74c3-rgpv-v3qr.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-74c3-rgpv-v3qr", + "modified": "2024-05-22T09:31:46Z", + "published": "2024-05-22T09:31:46Z", + "aliases": [ + "CVE-2024-3663" + ], + "details": "The WP Scraper plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wp_scraper_multi_scrape_action() function in all versions up to, and including, 5.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to create arbitrary pages and posts.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3663" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wp-scraper/trunk/wp-scraper.php#L1426" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/1a4bc52d-5771-4e7b-a394-772f2a5edbd7?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T07:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-76m2-73wx-8hj7/GHSA-76m2-73wx-8hj7.json b/advisories/unreviewed/2024/05/GHSA-76m2-73wx-8hj7/GHSA-76m2-73wx-8hj7.json new file mode 100644 index 00000000000..6fb9790e731 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-76m2-73wx-8hj7/GHSA-76m2-73wx-8hj7.json @@ -0,0 +1,63 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-76m2-73wx-8hj7", + "modified": "2024-05-22T09:31:46Z", + "published": "2024-05-22T09:31:46Z", + "aliases": [ + "CVE-2021-47483" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nregmap: Fix possible double-free in regcache_rbtree_exit()\n\nIn regcache_rbtree_insert_to_block(), when 'present' realloc failed,\nthe 'blk' which is supposed to assign to 'rbnode->block' will be freed,\nso 'rbnode->block' points a freed memory, in the error handling path of\nregcache_rbtree_init(), 'rbnode->block' will be freed again in\nregcache_rbtree_exit(), KASAN will report double-free as follows:\n\nBUG: KASAN: double-free or invalid-free in kfree+0xce/0x390\nCall Trace:\n slab_free_freelist_hook+0x10d/0x240\n kfree+0xce/0x390\n regcache_rbtree_exit+0x15d/0x1a0\n regcache_rbtree_init+0x224/0x2c0\n regcache_init+0x88d/0x1310\n __regmap_init+0x3151/0x4a80\n __devm_regmap_init+0x7d/0x100\n madera_spi_probe+0x10f/0x333 [madera_spi]\n spi_probe+0x183/0x210\n really_probe+0x285/0xc30\n\nTo fix this, moving up the assignment of rbnode->block to immediately after\nthe reallocation has succeeded so that the data structure stays valid even\nif the second reallocation fails.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47483" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1cead23c1c0bc766dacb900a3b0269f651ad596f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/36e911a16b377bde0ad91a8c679069d0d310b1a6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3dae1a4eced3ee733d7222e69b8a55caf2d61091" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/50cc1462a668dc62949a1127388bc3af785ce047" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/55e6d8037805b3400096d621091dfbf713f97e83" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/758ced2c3878ff789801e6fee808e185c5cf08d6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e72dce9afbdbfa70d9b44f5908a50ff6c4858999" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fc081477b47dfc3a6cb50a96087fc29674013fc2" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T09:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-784q-2fw8-cpw8/GHSA-784q-2fw8-cpw8.json b/advisories/unreviewed/2024/05/GHSA-784q-2fw8-cpw8/GHSA-784q-2fw8-cpw8.json new file mode 100644 index 00000000000..f4c35df8267 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-784q-2fw8-cpw8/GHSA-784q-2fw8-cpw8.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-784q-2fw8-cpw8", + "modified": "2024-05-22T09:31:46Z", + "published": "2024-05-22T09:31:45Z", + "aliases": [ + "CVE-2024-2088" + ], + "details": "The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.4.3 via the 'nxs_getExpSettings' function. This makes it possible for authenticated attackers, with subscriber access and above, to extract sensitive data including social network API keys and secrets.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2088" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/social-networks-auto-poster-facebook-twitter-g/trunk/inc/nxs_functions_wp.php#L620" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3084635/social-networks-auto-poster-facebook-twitter-g/trunk/inc/nxs_functions_wp.php?contextall=1" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/70724bc7-c1f4-4965-8bba-99b2ed21d34b?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T07:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-78c9-2m2m-j8fh/GHSA-78c9-2m2m-j8fh.json b/advisories/unreviewed/2024/05/GHSA-78c9-2m2m-j8fh/GHSA-78c9-2m2m-j8fh.json new file mode 100644 index 00000000000..ab75b74c723 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-78c9-2m2m-j8fh/GHSA-78c9-2m2m-j8fh.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-78c9-2m2m-j8fh", + "modified": "2024-05-22T09:31:47Z", + "published": "2024-05-22T09:31:46Z", + "aliases": [ + "CVE-2021-47498" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndm rq: don't queue request to blk-mq during DM suspend\n\nDM uses blk-mq's quiesce/unquiesce to stop/start device mapper queue.\n\nBut blk-mq's unquiesce may come from outside events, such as elevator\nswitch, updating nr_requests or others, and request may come during\nsuspend, so simply ask for blk-mq to requeue it.\n\nFixes one kernel panic issue when running updating nr_requests and\ndm-mpath suspend/resume stress test.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47498" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8ca9745efe3528feb06ca4e117188038eea2d351" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b4459b11e84092658fa195a2587aff3b9637f0e7" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T09:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-7ghc-chxp-5r47/GHSA-7ghc-chxp-5r47.json b/advisories/unreviewed/2024/05/GHSA-7ghc-chxp-5r47/GHSA-7ghc-chxp-5r47.json new file mode 100644 index 00000000000..bafab76641f --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-7ghc-chxp-5r47/GHSA-7ghc-chxp-5r47.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7ghc-chxp-5r47", + "modified": "2024-05-22T09:31:46Z", + "published": "2024-05-22T09:31:46Z", + "aliases": [ + "CVE-2021-47481" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/mlx5: Initialize the ODP xarray when creating an ODP MR\n\nNormally the zero fill would hide the missing initialization, but an\nerrant set to desc_size in reg_create() causes a crash:\n\n BUG: unable to handle page fault for address: 0000000800000000\n PGD 0 P4D 0\n Oops: 0000 [#1] SMP PTI\n CPU: 5 PID: 890 Comm: ib_write_bw Not tainted 5.15.0-rc4+ #47\n Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014\n RIP: 0010:mlx5_ib_dereg_mr+0x14/0x3b0 [mlx5_ib]\n Code: 48 63 cd 4c 89 f7 48 89 0c 24 e8 37 30 03 e1 48 8b 0c 24 eb a0 90 0f 1f 44 00 00 41 56 41 55 41 54 55 53 48 89 fb 48 83 ec 30 <48> 8b 2f 65 48 8b 04 25 28 00 00 00 48 89 44 24 28 31 c0 8b 87 c8\n RSP: 0018:ffff88811afa3a60 EFLAGS: 00010286\n RAX: 000000000000001c RBX: 0000000800000000 RCX: 0000000000000000\n RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000800000000\n RBP: 0000000800000000 R08: 0000000000000000 R09: c0000000fffff7ff\n R10: ffff88811afa38f8 R11: ffff88811afa38f0 R12: ffffffffa02c7ac0\n R13: 0000000000000000 R14: ffff88811afa3cd8 R15: ffff88810772fa00\n FS: 00007f47b9080740(0000) GS:ffff88852cd40000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 0000000800000000 CR3: 000000010761e003 CR4: 0000000000370ea0\n DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n Call Trace:\n mlx5_ib_free_odp_mr+0x95/0xc0 [mlx5_ib]\n mlx5_ib_dereg_mr+0x128/0x3b0 [mlx5_ib]\n ib_dereg_mr_user+0x45/0xb0 [ib_core]\n ? xas_load+0x8/0x80\n destroy_hw_idr_uobject+0x1a/0x50 [ib_uverbs]\n uverbs_destroy_uobject+0x2f/0x150 [ib_uverbs]\n uobj_destroy+0x3c/0x70 [ib_uverbs]\n ib_uverbs_cmd_verbs+0x467/0xb00 [ib_uverbs]\n ? uverbs_finalize_object+0x60/0x60 [ib_uverbs]\n ? ttwu_queue_wakelist+0xa9/0xe0\n ? pty_write+0x85/0x90\n ? file_tty_write.isra.33+0x214/0x330\n ? process_echoes+0x60/0x60\n ib_uverbs_ioctl+0xa7/0x110 [ib_uverbs]\n __x64_sys_ioctl+0x10d/0x8e0\n ? vfs_write+0x17f/0x260\n do_syscall_64+0x3c/0x80\n entry_SYSCALL_64_after_hwframe+0x44/0xae\n\nAdd the missing xarray initialization and remove the desc_size set.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47481" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5508546631a0f555d7088203dec2614e41b5106e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5f6995295f65d1ee6f36d466d26afd98eb797afe" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T09:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-7p9j-prv8-54xc/GHSA-7p9j-prv8-54xc.json b/advisories/unreviewed/2024/05/GHSA-7p9j-prv8-54xc/GHSA-7p9j-prv8-54xc.json new file mode 100644 index 00000000000..a4520858d5e --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-7p9j-prv8-54xc/GHSA-7p9j-prv8-54xc.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7p9j-prv8-54xc", + "modified": "2024-05-22T09:31:47Z", + "published": "2024-05-22T09:31:47Z", + "aliases": [ + "CVE-2024-5031" + ], + "details": "The Memberpress plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 1.11.29 via the 'mepr-user-file' shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5031" + }, + { + "type": "WEB", + "url": "https://memberpress.com/change-log" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/80064e3b-6996-49eb-a475-0ffe0e894f9e?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T09:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-7q72-fqh2-j6jv/GHSA-7q72-fqh2-j6jv.json b/advisories/unreviewed/2024/05/GHSA-7q72-fqh2-j6jv/GHSA-7q72-fqh2-j6jv.json new file mode 100644 index 00000000000..8a0d6d5d521 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-7q72-fqh2-j6jv/GHSA-7q72-fqh2-j6jv.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7q72-fqh2-j6jv", + "modified": "2024-05-22T09:31:46Z", + "published": "2024-05-22T09:31:46Z", + "aliases": [ + "CVE-2024-5147" + ], + "details": "The WPZOOM Addons for Elementor (Templates, Widgets) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1.37 via the 'grid_style' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5147" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wpzoom-elementor-addons/trunk/includes/wpzoom-elementor-ajax-posts-grid.php#L105" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wpzoom-elementor-addons/trunk/includes/wpzoom-elementor-ajax-posts-grid.php#L112" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3090236#file6" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/f006bb33-d017-445b-9c02-bd848c199671?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T08:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-7qcg-gp93-223m/GHSA-7qcg-gp93-223m.json b/advisories/unreviewed/2024/05/GHSA-7qcg-gp93-223m/GHSA-7qcg-gp93-223m.json new file mode 100644 index 00000000000..7e2e71cd4c2 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-7qcg-gp93-223m/GHSA-7qcg-gp93-223m.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7qcg-gp93-223m", + "modified": "2024-05-22T09:31:45Z", + "published": "2024-05-22T09:31:45Z", + "aliases": [ + "CVE-2021-47467" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nkunit: fix reference count leak in kfree_at_end\n\nThe reference counting issue happens in the normal path of\nkfree_at_end(). When kunit_alloc_and_get_resource() is invoked, the\nfunction forgets to handle the returned resource object, whose refcount\nincreased inside, causing a refcount leak.\n\nFix this issue by calling kunit_alloc_resource() instead of\nkunit_alloc_and_get_resource().\n\nFixed the following when applying:\nShuah Khan \n\nCHECK: Alignment should match open parenthesis\n+\tkunit_alloc_resource(test, NULL, kfree_res_free, GFP_KERNEL,\n \t\t\t\t (void *)to_free);", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47467" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bbdd158b40b66a9403391a517f24ef6613573446" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f62314b1ced25c58b86e044fc951cd6a1ea234cf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T07:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-7xq6-r35j-j33m/GHSA-7xq6-r35j-j33m.json b/advisories/unreviewed/2024/05/GHSA-7xq6-r35j-j33m/GHSA-7xq6-r35j-j33m.json new file mode 100644 index 00000000000..5e5f01f0952 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-7xq6-r35j-j33m/GHSA-7xq6-r35j-j33m.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7xq6-r35j-j33m", + "modified": "2024-05-22T09:31:45Z", + "published": "2024-05-22T09:31:45Z", + "aliases": [ + "CVE-2021-47459" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: j1939: j1939_netdev_start(): fix UAF for rx_kref of j1939_priv\n\nIt will trigger UAF for rx_kref of j1939_priv as following.\n\n cpu0 cpu1\nj1939_sk_bind(socket0, ndev0, ...)\nj1939_netdev_start\n j1939_sk_bind(socket1, ndev0, ...)\n j1939_netdev_start\nj1939_priv_set\n j1939_priv_get_by_ndev_locked\nj1939_jsk_add\n.....\nj1939_netdev_stop\nkref_put_lock(&priv->rx_kref, ...)\n kref_get(&priv->rx_kref, ...)\n REFCOUNT_WARN(\"addition on 0;...\")\n\n====================================================\nrefcount_t: addition on 0; use-after-free.\nWARNING: CPU: 1 PID: 20874 at lib/refcount.c:25 refcount_warn_saturate+0x169/0x1e0\nRIP: 0010:refcount_warn_saturate+0x169/0x1e0\nCall Trace:\n j1939_netdev_start+0x68b/0x920\n j1939_sk_bind+0x426/0xeb0\n ? security_socket_bind+0x83/0xb0\n\nThe rx_kref's kref_get() and kref_put() should use j1939_netdev_lock to\nprotect.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47459" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6e8811707e2df0c6ba920f0cad3a3bca7b42132f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/864e77771a24c877aaf53aee019f78619cbcd668" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a0e47d2833b4f65e6c799f28c6b636d36b8b936d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d9d52a3ebd284882f5562c88e55991add5d01586" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T07:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-843h-74ff-22vf/GHSA-843h-74ff-22vf.json b/advisories/unreviewed/2024/05/GHSA-843h-74ff-22vf/GHSA-843h-74ff-22vf.json new file mode 100644 index 00000000000..1b369d9f4f3 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-843h-74ff-22vf/GHSA-843h-74ff-22vf.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-843h-74ff-22vf", + "modified": "2024-05-22T09:31:46Z", + "published": "2024-05-22T09:31:46Z", + "aliases": [ + "CVE-2021-47489" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: Fix even more out of bound writes from debugfs\n\nCVE-2021-42327 was fixed by:\n\ncommit f23750b5b3d98653b31d4469592935ef6364ad67\nAuthor: Thelford Williams \nDate: Wed Oct 13 16:04:13 2021 -0400\n\n drm/amdgpu: fix out of bounds write\n\nbut amdgpu_dm_debugfs.c contains more of the same issue so fix the\nremaining ones.\n\nv2:\n\t* Add missing fix in dp_max_bpc_write (Harry Wentland)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47489" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3f4e54bd312d3dafb59daf2b97ffa08abebe60f5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9eb4bdd554fc31a5ef6bf645a20ff21618ce45a9" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T09:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-86hr-63r2-f3c9/GHSA-86hr-63r2-f3c9.json b/advisories/unreviewed/2024/05/GHSA-86hr-63r2-f3c9/GHSA-86hr-63r2-f3c9.json new file mode 100644 index 00000000000..e9c910bf241 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-86hr-63r2-f3c9/GHSA-86hr-63r2-f3c9.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-86hr-63r2-f3c9", + "modified": "2024-05-22T09:31:46Z", + "published": "2024-05-22T09:31:46Z", + "aliases": [ + "CVE-2021-47484" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nocteontx2-af: Fix possible null pointer dereference.\n\nThis patch fixes possible null pointer dereference in files\n\"rvu_debugfs.c\" and \"rvu_nix.c\"", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47484" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c2d4c543f74c90f883e8ec62a31973ae8807d354" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f1e3cd1cc80204fd02b9e9843450925a2af90dc0" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T09:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-8g2p-p68f-4wqr/GHSA-8g2p-p68f-4wqr.json b/advisories/unreviewed/2024/05/GHSA-8g2p-p68f-4wqr/GHSA-8g2p-p68f-4wqr.json new file mode 100644 index 00000000000..46a7bc75db6 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-8g2p-p68f-4wqr/GHSA-8g2p-p68f-4wqr.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8g2p-p68f-4wqr", + "modified": "2024-05-22T09:31:46Z", + "published": "2024-05-22T09:31:46Z", + "aliases": [ + "CVE-2021-47491" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm: khugepaged: skip huge page collapse for special files\n\nThe read-only THP for filesystems will collapse THP for files opened\nreadonly and mapped with VM_EXEC. The intended usecase is to avoid TLB\nmisses for large text segments. But it doesn't restrict the file types\nso a THP could be collapsed for a non-regular file, for example, block\ndevice, if it is opened readonly and mapped with EXEC permission. This\nmay cause bugs, like [1] and [2].\n\nThis is definitely not the intended usecase, so just collapse THP for\nregular files in order to close the attack surface.\n\n[shy828301@gmail.com: fix vm_file check [3]]", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47491" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5fcb6fce74ffa614d964667110cf1a516c48c6d9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6d67b2a73b8e3a079c355bab3c1aef7d85a044b8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a4aeaa06d45e90f9b279f0b09de84bd00006e733" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T09:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-8g8j-p6r7-xj34/GHSA-8g8j-p6r7-xj34.json b/advisories/unreviewed/2024/05/GHSA-8g8j-p6r7-xj34/GHSA-8g8j-p6r7-xj34.json new file mode 100644 index 00000000000..e2b9d44be85 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-8g8j-p6r7-xj34/GHSA-8g8j-p6r7-xj34.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8g8j-p6r7-xj34", + "modified": "2024-05-22T09:31:45Z", + "published": "2024-05-22T09:31:45Z", + "aliases": [ + "CVE-2021-47449" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nice: fix locking for Tx timestamp tracking flush\n\nCommit 4dd0d5c33c3e (\"ice: add lock around Tx timestamp tracker flush\")\nadded a lock around the Tx timestamp tracker flow which is used to\ncleanup any left over SKBs and prepare for device removal.\n\nThis lock is problematic because it is being held around a call to\nice_clear_phy_tstamp. The clear function takes a mutex to send a PHY\nwrite command to firmware. This could lead to a deadlock if the mutex\nactually sleeps, and causes the following warning on a kernel with\npreemption debugging enabled:\n\n[ 715.419426] BUG: sleeping function called from invalid context at kernel/locking/mutex.c:573\n[ 715.427900] in_atomic(): 1, irqs_disabled(): 0, non_block: 0, pid: 3100, name: rmmod\n[ 715.435652] INFO: lockdep is turned off.\n[ 715.439591] Preemption disabled at:\n[ 715.439594] [<0000000000000000>] 0x0\n[ 715.446678] CPU: 52 PID: 3100 Comm: rmmod Tainted: G W OE 5.15.0-rc4+ #42 bdd7ec3018e725f159ca0d372ce8c2c0e784891c\n[ 715.458058] Hardware name: Intel Corporation S2600STQ/S2600STQ, BIOS SE5C620.86B.02.01.0010.010620200716 01/06/2020\n[ 715.468483] Call Trace:\n[ 715.470940] dump_stack_lvl+0x6a/0x9a\n[ 715.474613] ___might_sleep.cold+0x224/0x26a\n[ 715.478895] __mutex_lock+0xb3/0x1440\n[ 715.482569] ? stack_depot_save+0x378/0x500\n[ 715.486763] ? ice_sq_send_cmd+0x78/0x14c0 [ice 9a7e1ec00971c89ecd3fe0d4dc7da2b3786a421d]\n[ 715.494979] ? kfree+0xc1/0x520\n[ 715.498128] ? mutex_lock_io_nested+0x12a0/0x12a0\n[ 715.502837] ? kasan_set_free_info+0x20/0x30\n[ 715.507110] ? __kasan_slab_free+0x10b/0x140\n[ 715.511385] ? slab_free_freelist_hook+0xc7/0x220\n[ 715.516092] ? kfree+0xc1/0x520\n[ 715.519235] ? ice_deinit_lag+0x16c/0x220 [ice 9a7e1ec00971c89ecd3fe0d4dc7da2b3786a421d]\n[ 715.527359] ? ice_remove+0x1cf/0x6a0 [ice 9a7e1ec00971c89ecd3fe0d4dc7da2b3786a421d]\n[ 715.535133] ? pci_device_remove+0xab/0x1d0\n[ 715.539318] ? __device_release_driver+0x35b/0x690\n[ 715.544110] ? driver_detach+0x214/0x2f0\n[ 715.548035] ? bus_remove_driver+0x11d/0x2f0\n[ 715.552309] ? pci_unregister_driver+0x26/0x250\n[ 715.556840] ? ice_module_exit+0xc/0x2f [ice 9a7e1ec00971c89ecd3fe0d4dc7da2b3786a421d]\n[ 715.564799] ? __do_sys_delete_module.constprop.0+0x2d8/0x4e0\n[ 715.570554] ? do_syscall_64+0x3b/0x90\n[ 715.574303] ? entry_SYSCALL_64_after_hwframe+0x44/0xae\n[ 715.579529] ? start_flush_work+0x542/0x8f0\n[ 715.583719] ? ice_sq_send_cmd+0x78/0x14c0 [ice 9a7e1ec00971c89ecd3fe0d4dc7da2b3786a421d]\n[ 715.591923] ice_sq_send_cmd+0x78/0x14c0 [ice 9a7e1ec00971c89ecd3fe0d4dc7da2b3786a421d]\n[ 715.599960] ? wait_for_completion_io+0x250/0x250\n[ 715.604662] ? lock_acquire+0x196/0x200\n[ 715.608504] ? do_raw_spin_trylock+0xa5/0x160\n[ 715.612864] ice_sbq_rw_reg+0x1e6/0x2f0 [ice 9a7e1ec00971c89ecd3fe0d4dc7da2b3786a421d]\n[ 715.620813] ? ice_reset+0x130/0x130 [ice 9a7e1ec00971c89ecd3fe0d4dc7da2b3786a421d]\n[ 715.628497] ? __debug_check_no_obj_freed+0x1e8/0x3c0\n[ 715.633550] ? trace_hardirqs_on+0x1c/0x130\n[ 715.637748] ice_write_phy_reg_e810+0x70/0xf0 [ice 9a7e1ec00971c89ecd3fe0d4dc7da2b3786a421d]\n[ 715.646220] ? do_raw_spin_trylock+0xa5/0x160\n[ 715.650581] ? ice_ptp_release+0x910/0x910 [ice 9a7e1ec00971c89ecd3fe0d4dc7da2b3786a421d]\n[ 715.658797] ? ice_ptp_release+0x255/0x910 [ice 9a7e1ec00971c89ecd3fe0d4dc7da2b3786a421d]\n[ 715.667013] ice_clear_phy_tstamp+0x2c/0x110 [ice 9a7e1ec00971c89ecd3fe0d4dc7da2b3786a421d]\n[ 715.675403] ice_ptp_release+0x408/0x910 [ice 9a7e1ec00971c89ecd3fe0d4dc7da2b3786a421d]\n[ 715.683440] ice_remove+0x560/0x6a0 [ice 9a7e1ec00971c89ecd3fe0d4dc7da2b3786a421d]\n[ 715.691037] ? _raw_spin_unlock_irqrestore+0x46/0x73\n[ 715.696005] pci_device_remove+0xab/0x1d0\n[ 715.700018] __device_release_driver+0x35b/0x690\n[ 715.704637] driver_detach+0x214/0x2f0\n[ 715.708389] bus_remove_driver+0x11d/0x2f0\n[ 715.712489] pci_unregister_driver+0x26/0x250\n[ 71\n---truncated---", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47449" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4d4a223a86afe658cd878800f09458e8bb54415d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/61616be899975404df44c20ab902464b60882cd7" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T07:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-94jm-5577-cx4g/GHSA-94jm-5577-cx4g.json b/advisories/unreviewed/2024/05/GHSA-94jm-5577-cx4g/GHSA-94jm-5577-cx4g.json new file mode 100644 index 00000000000..fdf3099518b --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-94jm-5577-cx4g/GHSA-94jm-5577-cx4g.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-94jm-5577-cx4g", + "modified": "2024-05-22T09:31:45Z", + "published": "2024-05-22T09:31:45Z", + "aliases": [ + "CVE-2021-47447" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/msm/a3xx: fix error handling in a3xx_gpu_init()\n\nThese error paths returned 1 on failure, instead of a negative error\ncode. This would lead to an Oops in the caller. A second problem is\nthat the check for \"if (ret != -ENODATA)\" did not work because \"ret\" was\nset to 1.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47447" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3eda901995371d390ef82d0b6462f4ea8efbcfdf" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d59e44e7821a8f2bb6f2e846b9167397a5f01608" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T07:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-969w-fmcp-j8rq/GHSA-969w-fmcp-j8rq.json b/advisories/unreviewed/2024/05/GHSA-969w-fmcp-j8rq/GHSA-969w-fmcp-j8rq.json new file mode 100644 index 00000000000..4156e30f2d2 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-969w-fmcp-j8rq/GHSA-969w-fmcp-j8rq.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-969w-fmcp-j8rq", + "modified": "2024-05-22T09:31:45Z", + "published": "2024-05-22T09:31:45Z", + "aliases": [ + "CVE-2021-47444" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/edid: In connector_bad_edid() cap num_of_ext by num_blocks read\n\nIn commit e11f5bd8228f (\"drm: Add support for DP 1.4 Compliance edid\ncorruption test\") the function connector_bad_edid() started assuming\nthat the memory for the EDID passed to it was big enough to hold\n`edid[0x7e] + 1` blocks of data (1 extra for the base block). It\ncompletely ignored the fact that the function was passed `num_blocks`\nwhich indicated how much memory had been allocated for the EDID.\n\nLet's fix this by adding a bounds check.\n\nThis is important for handling the case where there's an error in the\nfirst block of the EDID. In that case we will call\nconnector_bad_edid() without having re-allocated memory based on\n`edid[0x7e]`.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47444" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/09f3946bb452918dbfb1982add56f9ffaae393dc" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/97794170b696856483f74b47bfb6049780d2d3a0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a7b45024f66f9ec769e8dbb1a51ae83cd05929c7" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T07:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-9wf5-fqq4-6gwg/GHSA-9wf5-fqq4-6gwg.json b/advisories/unreviewed/2024/05/GHSA-9wf5-fqq4-6gwg/GHSA-9wf5-fqq4-6gwg.json new file mode 100644 index 00000000000..59d238c69b8 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-9wf5-fqq4-6gwg/GHSA-9wf5-fqq4-6gwg.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9wf5-fqq4-6gwg", + "modified": "2024-05-22T09:31:45Z", + "published": "2024-05-22T09:31:45Z", + "aliases": [ + "CVE-2021-47446" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/msm/a4xx: fix error handling in a4xx_gpu_init()\n\nThis code returns 1 on error instead of a negative error. It leads to\nan Oops in the caller. A second problem is that the check for\n\"if (ret != -ENODATA)\" cannot be true because \"ret\" is set to 1.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47446" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3962d626eb3e3b23ebb2e2a61537fa764acbfe11" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/980d74e7d03ccf2eaa11d133416946bd880c7c08" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T07:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-c425-5ghg-6j48/GHSA-c425-5ghg-6j48.json b/advisories/unreviewed/2024/05/GHSA-c425-5ghg-6j48/GHSA-c425-5ghg-6j48.json new file mode 100644 index 00000000000..ccea2ca458e --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-c425-5ghg-6j48/GHSA-c425-5ghg-6j48.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c425-5ghg-6j48", + "modified": "2024-05-22T09:31:47Z", + "published": "2024-05-22T09:31:46Z", + "aliases": [ + "CVE-2021-47496" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/tls: Fix flipped sign in tls_err_abort() calls\n\nsk->sk_err appears to expect a positive value, a convention that ktls\ndoesn't always follow and that leads to memory corruption in other code.\nFor instance,\n\n [kworker]\n tls_encrypt_done(..., err=)\n tls_err_abort(.., err)\n sk->sk_err = err;\n\n [task]\n splice_from_pipe_feed\n ...\n tls_sw_do_sendpage\n if (sk->sk_err) {\n ret = -sk->sk_err; // ret is positive\n\n splice_from_pipe_feed (continued)\n ret = actor(...) // ret is still positive and interpreted as bytes\n // written, resulting in underflow of buf->len and\n // sd->len, leading to huge buf->offset and bogus\n // addresses computed in later calls to actor()\n\nFix all tls_err_abort() callers to pass a negative error code\nconsistently and centralize the error-prone sign flip there, throwing in\na warning to catch future misuse and uninlining the function so it\nreally does only warn once.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47496" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/da353fac65fede6b8b4cfe207f0d9408e3121105" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e0cfd5159f314d6b304d030363650b06a2299cbb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e41473543f75f7dbc5d605007e6f883f1bd13b9a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f3dec7e7ace38224f82cf83f0049159d067c2e19" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T09:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-c6p9-mw2r-7mc4/GHSA-c6p9-mw2r-7mc4.json b/advisories/unreviewed/2024/05/GHSA-c6p9-mw2r-7mc4/GHSA-c6p9-mw2r-7mc4.json new file mode 100644 index 00000000000..f4bdd33286d --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-c6p9-mw2r-7mc4/GHSA-c6p9-mw2r-7mc4.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c6p9-mw2r-7mc4", + "modified": "2024-05-22T09:31:46Z", + "published": "2024-05-22T09:31:46Z", + "aliases": [ + "CVE-2021-47494" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncfg80211: fix management registrations locking\n\nThe management registrations locking was broken, the list was\nlocked for each wdev, but cfg80211_mgmt_registrations_update()\niterated it without holding all the correct spinlocks, causing\nlist corruption.\n\nRather than trying to fix it with fine-grained locking, just\nmove the lock to the wiphy/rdev (still need the list on each\nwdev), we already need to hold the wdev lock to change it, so\nthere's no contention on the lock in any case. This trivially\nfixes the bug since we hold one wdev's lock already, and now\nwill hold the lock that protects all lists.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47494" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/09b1d5dc6ce1c9151777f6c4e128a59457704c97" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3c897f39b71fe68f90599f6a45b5f7bf5618420e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4c22227e39c7a0b4dab55617ee8d34d171fab8d4" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T09:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-c84w-j8mj-57ch/GHSA-c84w-j8mj-57ch.json b/advisories/unreviewed/2024/05/GHSA-c84w-j8mj-57ch/GHSA-c84w-j8mj-57ch.json new file mode 100644 index 00000000000..237d3fc7bfb --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-c84w-j8mj-57ch/GHSA-c84w-j8mj-57ch.json @@ -0,0 +1,67 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c84w-j8mj-57ch", + "modified": "2024-05-22T09:31:46Z", + "published": "2024-05-22T09:31:46Z", + "aliases": [ + "CVE-2021-47476" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncomedi: ni_usb6501: fix NULL-deref in command paths\n\nThe driver uses endpoint-sized USB transfer buffers but had no sanity\nchecks on the sizes. This can lead to zero-size-pointer dereferences or\noverflowed transfer buffers in ni6501_port_command() and\nni6501_counter_command() if a (malicious) device has smaller max-packet\nsizes than expected (or when doing descriptor fuzz testing).\n\nAdd the missing sanity checks to probe().", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47476" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4a9d43cb5d5f39fa39fc1da438517004cc95f7ea" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/58478143771b20ab219937b1c30a706590a59224" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/907767da8f3a925b060c740e0b5c92ea7dbec440" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/aa39738423503825625853b643b9e99d11c23816" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b0156b7c9649d8f55a2ce3d3258509f1b2a181c3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bc51111bf6e8e7b6cc94b133e4c291273a16acd1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d6a727a681a39ae4f73081a9bedb45d14f95bdd1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/df7b1238f3b599a0b9284249772cdfd1ea83a632" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ef143dc0c3defe56730ecd3a9de7b3e1d7e557c1" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T09:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-ccg7-gh5h-4h2c/GHSA-ccg7-gh5h-4h2c.json b/advisories/unreviewed/2024/05/GHSA-ccg7-gh5h-4h2c/GHSA-ccg7-gh5h-4h2c.json new file mode 100644 index 00000000000..27a69f7f678 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-ccg7-gh5h-4h2c/GHSA-ccg7-gh5h-4h2c.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ccg7-gh5h-4h2c", + "modified": "2024-05-22T09:31:46Z", + "published": "2024-05-22T09:31:46Z", + "aliases": [ + "CVE-2021-47487" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: fix out of bounds write\n\nSize can be any value and is user controlled resulting in overwriting the\n40 byte array wr_buf with an arbitrary length of data from buf.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47487" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5afa7898ab7a0ec9c28556a91df714bf3c2f725e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d3ed72495a59fbfb9377450c8dfe94389a6509a7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/eb3b6805e3e9d98b2507201fd061a231988ce623" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T09:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-cjpq-j9jr-vg53/GHSA-cjpq-j9jr-vg53.json b/advisories/unreviewed/2024/05/GHSA-cjpq-j9jr-vg53/GHSA-cjpq-j9jr-vg53.json new file mode 100644 index 00000000000..6193d4a7498 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-cjpq-j9jr-vg53/GHSA-cjpq-j9jr-vg53.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cjpq-j9jr-vg53", + "modified": "2024-05-22T09:31:46Z", + "published": "2024-05-22T09:31:46Z", + "aliases": [ + "CVE-2024-3671" + ], + "details": "The Print-O-Matic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'print-me' shortcode in all versions up to, and including, 2.1.10 due to insufficient input sanitization and output escaping on user supplied attributes such as 'tag'. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3671" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/print-o-matic" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/10ea8f3a-35d6-494e-90f6-9165320cf99c?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T08:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-cmcr-4938-mjgj/GHSA-cmcr-4938-mjgj.json b/advisories/unreviewed/2024/05/GHSA-cmcr-4938-mjgj/GHSA-cmcr-4938-mjgj.json new file mode 100644 index 00000000000..4141690069c --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-cmcr-4938-mjgj/GHSA-cmcr-4938-mjgj.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cmcr-4938-mjgj", + "modified": "2024-05-22T09:31:45Z", + "published": "2024-05-22T09:31:45Z", + "aliases": [ + "CVE-2021-47450" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: arm64: Fix host stage-2 PGD refcount\n\nThe KVM page-table library refcounts the pages of concatenated stage-2\nPGDs individually. However, when running KVM in protected mode, the\nhost's stage-2 PGD is currently managed by EL2 as a single high-order\ncompound page, which can cause the refcount of the tail pages to reach 0\nwhen they shouldn't, hence corrupting the page-table.\n\nFix this by introducing a new hyp_split_page() helper in the EL2 page\nallocator (matching the kernel's split_page() function), and make use of\nit from host_s2_zalloc_pages_exact().", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47450" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1d58a17ef54599506d44c45ac95be27273a4d2b1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b372264c66ef78f2cab44e877fbd765ad6d24c39" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T07:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-cqj4-2pfx-qgmr/GHSA-cqj4-2pfx-qgmr.json b/advisories/unreviewed/2024/05/GHSA-cqj4-2pfx-qgmr/GHSA-cqj4-2pfx-qgmr.json new file mode 100644 index 00000000000..9daf6164cd8 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-cqj4-2pfx-qgmr/GHSA-cqj4-2pfx-qgmr.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cqj4-2pfx-qgmr", + "modified": "2024-05-22T09:31:45Z", + "published": "2024-05-22T09:31:45Z", + "aliases": [ + "CVE-2021-47464" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\naudit: fix possible null-pointer dereference in audit_filter_rules\n\nFix possible null-pointer dereference in audit_filter_rules.\n\naudit_filter_rules() error: we previously assumed 'ctx' could be null", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47464" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/16802fa4c33eb1a8efb23f1e93365190e4047d05" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4e9e46a700201b4c85081fd478c99c692a9aaa0d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6e3ee990c90494561921c756481d0e2125d8b895" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d6f451f1f60c58d73038c7c3177066f8f084e2a2" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T07:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-f639-593q-rjgw/GHSA-f639-593q-rjgw.json b/advisories/unreviewed/2024/05/GHSA-f639-593q-rjgw/GHSA-f639-593q-rjgw.json new file mode 100644 index 00000000000..0c8c8b57038 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-f639-593q-rjgw/GHSA-f639-593q-rjgw.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f639-593q-rjgw", + "modified": "2024-05-22T09:31:45Z", + "published": "2024-05-22T09:31:45Z", + "aliases": [ + "CVE-2021-47460" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: fix data corruption after conversion from inline format\n\nCommit 6dbf7bb55598 (\"fs: Don't invalidate page buffers in\nblock_write_full_page()\") uncovered a latent bug in ocfs2 conversion\nfrom inline inode format to a normal inode format.\n\nThe code in ocfs2_convert_inline_data_to_extents() attempts to zero out\nthe whole cluster allocated for file data by grabbing, zeroing, and\ndirtying all pages covering this cluster. However these pages are\nbeyond i_size, thus writeback code generally ignores these dirty pages\nand no blocks were ever actually zeroed on the disk.\n\nThis oversight was fixed by commit 693c241a5f6a (\"ocfs2: No need to zero\npages past i_size.\") for standard ocfs2 write path, inline conversion\npath was apparently forgotten; the commit log also has a reasoning why\nthe zeroing actually is not needed.\n\nAfter commit 6dbf7bb55598, things became worse as writeback code stopped\ninvalidating buffers on pages beyond i_size and thus these pages end up\nwith clean PageDirty bit but with buffers attached to these pages being\nstill dirty. So when a file is converted from inline format, then\nwriteback triggers, and then the file is grown so that these pages\nbecome valid, the invalid dirtiness state is preserved,\nmark_buffer_dirty() does nothing on these pages (buffers are already\ndirty) but page is never written back because it is clean. So data\nwritten to these pages is lost once pages are reclaimed.\n\nSimple reproducer for the problem is:\n\n xfs_io -f -c \"pwrite 0 2000\" -c \"pwrite 2000 2000\" -c \"fsync\" \\\n -c \"pwrite 4000 2000\" ocfs2_file\n\nAfter unmounting and mounting the fs again, you can observe that end of\n'ocfs2_file' has lost its contents.\n\nFix the problem by not doing the pointless zeroing during conversion\nfrom inline format similarly as in the standard write path.\n\n[akpm@linux-foundation.org: fix whitespace, per Joseph]", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47460" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5314454ea3ff6fc746eaf71b9a7ceebed52888fa" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/560edd14de2bf9dbc0129681eeb4d5ef87cc105f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8e6bfb4f70168ddfd32fb6dc028ad52faaf1f32e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a3a089c241cd49b33a8cdd7fcb37cc87a086912a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b05caf023b14cbed9223bb5b48ecc7bffe38f632" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f1b98569e81c37d7e0deada7172f8f60860c1360" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fa9b6b6c953e3f6441ed6cf83b4c771dac2dae08" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T07:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-fh33-v9vq-826f/GHSA-fh33-v9vq-826f.json b/advisories/unreviewed/2024/05/GHSA-fh33-v9vq-826f/GHSA-fh33-v9vq-826f.json new file mode 100644 index 00000000000..ea2574aab02 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-fh33-v9vq-826f/GHSA-fh33-v9vq-826f.json @@ -0,0 +1,63 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fh33-v9vq-826f", + "modified": "2024-05-22T09:31:45Z", + "published": "2024-05-22T09:31:45Z", + "aliases": [ + "CVE-2021-47442" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nNFC: digital: fix possible memory leak in digital_in_send_sdd_req()\n\n'skb' is allocated in digital_in_send_sdd_req(), but not free when\ndigital_in_send_cmd() failed, which will cause memory leak. Fix it\nby freeing 'skb' if digital_in_send_cmd() return failed.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47442" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/071bdef36391958c89af5fa2172f691b31baa212" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/291c932fc3692e4d211a445ba8aa35663831bac7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2bde4aca56db9fe25405d39ddb062531493a65db" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/50cb95487c265187289810addec5093d4fed8329" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6432d7f1d1c3aa74cfe8f5e3afdf81b786c32e86" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/74569c78aa84f8c958f1334b465bc530906ec99a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/88c890b0b9a1fb9fcd01c61ada515e8b636c34f9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fcce6e5255474ca33c27dda0cdf9bf5087278873" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T07:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-fmqm-f3m4-fg43/GHSA-fmqm-f3m4-fg43.json b/advisories/unreviewed/2024/05/GHSA-fmqm-f3m4-fg43/GHSA-fmqm-f3m4-fg43.json new file mode 100644 index 00000000000..83acdb97547 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-fmqm-f3m4-fg43/GHSA-fmqm-f3m4-fg43.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fmqm-f3m4-fg43", + "modified": "2024-05-22T09:31:45Z", + "published": "2024-05-22T09:31:45Z", + "aliases": [ + "CVE-2021-47471" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm: mxsfb: Fix NULL pointer dereference crash on unload\n\nThe mxsfb->crtc.funcs may already be NULL when unloading the driver,\nin which case calling mxsfb_irq_disable() via drm_irq_uninstall() from\nmxsfb_unload() leads to NULL pointer dereference.\n\nSince all we care about is masking the IRQ and mxsfb->base is still\nvalid, just use that to clear and mask the IRQ.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47471" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3cfc183052c3dbf8eae57b6c1685dab00ed3db4a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b0e6db0656ddfd8bb57303c2ef61ee1c1cc694a8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f40c2281d2c0674d32ba732fee45222d76495472" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T07:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-fwfh-xm69-p46x/GHSA-fwfh-xm69-p46x.json b/advisories/unreviewed/2024/05/GHSA-fwfh-xm69-p46x/GHSA-fwfh-xm69-p46x.json new file mode 100644 index 00000000000..f3339ac583e --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-fwfh-xm69-p46x/GHSA-fwfh-xm69-p46x.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fwfh-xm69-p46x", + "modified": "2024-05-22T09:31:45Z", + "published": "2024-05-22T09:31:45Z", + "aliases": [ + "CVE-2024-1446" + ], + "details": "The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.4.3. This is due to missing or incorrect nonce validation on the nxssnap-reposter page. This makes it possible for unauthenticated attackers to delete arbitrary posts or pages via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1446" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3084635%40social-networks-auto-poster-facebook-twitter-g%2Ftrunk&old=3004433%40social-networks-auto-poster-facebook-twitter-g%2Ftrunk&sfp_email=&sfph_mail=#file17" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/306b23ee-7dcb-4281-a218-21168998c4b9?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T07:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-gr8j-3pfp-wwr2/GHSA-gr8j-3pfp-wwr2.json b/advisories/unreviewed/2024/05/GHSA-gr8j-3pfp-wwr2/GHSA-gr8j-3pfp-wwr2.json new file mode 100644 index 00000000000..060118003cb --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-gr8j-3pfp-wwr2/GHSA-gr8j-3pfp-wwr2.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gr8j-3pfp-wwr2", + "modified": "2024-05-22T09:31:46Z", + "published": "2024-05-22T09:31:46Z", + "aliases": [ + "CVE-2021-47493" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: fix race between searching chunks and release journal_head from buffer_head\n\nEncountered a race between ocfs2_test_bg_bit_allocatable() and\njbd2_journal_put_journal_head() resulting in the below vmcore.\n\n PID: 106879 TASK: ffff880244ba9c00 CPU: 2 COMMAND: \"loop3\"\n Call trace:\n panic\n oops_end\n no_context\n __bad_area_nosemaphore\n bad_area_nosemaphore\n __do_page_fault\n do_page_fault\n page_fault\n [exception RIP: ocfs2_block_group_find_clear_bits+316]\n ocfs2_block_group_find_clear_bits [ocfs2]\n ocfs2_cluster_group_search [ocfs2]\n ocfs2_search_chain [ocfs2]\n ocfs2_claim_suballoc_bits [ocfs2]\n __ocfs2_claim_clusters [ocfs2]\n ocfs2_claim_clusters [ocfs2]\n ocfs2_local_alloc_slide_window [ocfs2]\n ocfs2_reserve_local_alloc_bits [ocfs2]\n ocfs2_reserve_clusters_with_limit [ocfs2]\n ocfs2_reserve_clusters [ocfs2]\n ocfs2_lock_refcount_allocators [ocfs2]\n ocfs2_make_clusters_writable [ocfs2]\n ocfs2_replace_cow [ocfs2]\n ocfs2_refcount_cow [ocfs2]\n ocfs2_file_write_iter [ocfs2]\n lo_rw_aio\n loop_queue_work\n kthread_worker_fn\n kthread\n ret_from_fork\n\nWhen ocfs2_test_bg_bit_allocatable() called bh2jh(bg_bh), the\nbg_bh->b_private NULL as jbd2_journal_put_journal_head() raced and\nreleased the jounal head from the buffer head. Needed to take bit lock\nfor the bit 'BH_JournalHead' to fix this race.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47493" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2e382600e8856ea654677b5134ee66e03ea72bc2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5043fbd294f5909a080ade0f04b70a4da9e122b7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6f1b228529ae49b0f85ab89bcdb6c365df401558" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T09:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-h664-w632-w34v/GHSA-h664-w632-w34v.json b/advisories/unreviewed/2024/05/GHSA-h664-w632-w34v/GHSA-h664-w632-w34v.json new file mode 100644 index 00000000000..5c01f2beb6f --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-h664-w632-w34v/GHSA-h664-w632-w34v.json @@ -0,0 +1,63 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h664-w632-w34v", + "modified": "2024-05-22T09:31:45Z", + "published": "2024-05-22T09:31:45Z", + "aliases": [ + "CVE-2021-47445" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/msm: Fix null pointer dereference on pointer edp\n\nThe initialization of pointer dev dereferences pointer edp before\nedp is null checked, so there is a potential null pointer deference\nissue. Fix this by only dereferencing edp after edp has been null\nchecked.\n\nAddresses-Coverity: (\"Dereference before null check\")", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47445" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0cd063aa0a09822cc1620fc59a67fe2f9f6338ac" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2133c4fc8e1348dcb752f267a143fe2254613b34" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/46c8ddede0273d1d132beefa9de8b820326982be" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7f642b93710b6b1119bdff90be01e6b5a2a5d669" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/91a340768b012f5b910a203a805b97a345b3db37" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bacac7d26849c8e903ceb7466d9ce8dc3c2797eb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f175b9a83e5c252d7c74acddc792840016caae0a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f302be08e3de94db8863a0b2958b2bb3e8e998e6" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T07:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-h74g-q68m-46qw/GHSA-h74g-q68m-46qw.json b/advisories/unreviewed/2024/05/GHSA-h74g-q68m-46qw/GHSA-h74g-q68m-46qw.json new file mode 100644 index 00000000000..67910d0ce8a --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-h74g-q68m-46qw/GHSA-h74g-q68m-46qw.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h74g-q68m-46qw", + "modified": "2024-05-22T09:31:46Z", + "published": "2024-05-22T09:31:46Z", + "aliases": [ + "CVE-2024-4157" + ], + "details": "The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.1.15 via deserialization of untrusted input in the extractDynamicValues function. This makes it possible for authenticated attackers, with contributor-level access and above, to inject a PHP Object. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code. Successful exploitation requires the attacker to have \"View Form\" and \"Manage Form\" permissions, which must be explicitly set by an administrator. However, this requirement can be bypassed when this vulnerability is chained with CVE-2024-2771.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4157" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3081740/fluentform" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/8def156a-f2f2-4640-a1c9-c21c74e1f308?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T08:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-h8c2-87vw-jwfw/GHSA-h8c2-87vw-jwfw.json b/advisories/unreviewed/2024/05/GHSA-h8c2-87vw-jwfw/GHSA-h8c2-87vw-jwfw.json new file mode 100644 index 00000000000..345880768f0 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-h8c2-87vw-jwfw/GHSA-h8c2-87vw-jwfw.json @@ -0,0 +1,63 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h8c2-87vw-jwfw", + "modified": "2024-05-22T09:31:45Z", + "published": "2024-05-22T09:31:44Z", + "aliases": [ + "CVE-2021-47440" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: encx24j600: check error in devm_regmap_init_encx24j600\n\ndevm_regmap_init may return error which caused by like out of memory,\nthis will results in null pointer dereference later when reading\nor writing register:\n\ngeneral protection fault in encx24j600_spi_probe\nKASAN: null-ptr-deref in range [0x0000000000000090-0x0000000000000097]\nCPU: 0 PID: 286 Comm: spi-encx24j600- Not tainted 5.15.0-rc2-00142-g9978db750e31-dirty #11 9c53a778c1306b1b02359f3c2bbedc0222cba652\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.13.0-1ubuntu1.1 04/01/2014\nRIP: 0010:regcache_cache_bypass drivers/base/regmap/regcache.c:540\nCode: 54 41 89 f4 55 53 48 89 fb 48 83 ec 08 e8 26 94 a8 fe 48 8d bb a0 00 00 00 48 b8 00 00 00 00 00 fc ff df 48 89 fa 48 c1 ea 03 <80> 3c 02 00 0f 85 4a 03 00 00 4c 8d ab b0 00 00 00 48 8b ab a0 00\nRSP: 0018:ffffc900010476b8 EFLAGS: 00010207\nRAX: dffffc0000000000 RBX: fffffffffffffff4 RCX: 0000000000000000\nRDX: 0000000000000012 RSI: ffff888002de0000 RDI: 0000000000000094\nRBP: ffff888013c9a000 R08: 0000000000000000 R09: fffffbfff3f9cc6a\nR10: ffffc900010476e8 R11: fffffbfff3f9cc69 R12: 0000000000000001\nR13: 000000000000000a R14: ffff888013c9af54 R15: ffff888013c9ad08\nFS: 00007ffa984ab580(0000) GS:ffff88801fe00000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 000055a6384136c8 CR3: 000000003bbe6003 CR4: 0000000000770ef0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nPKRU: 55555554\nCall Trace:\n encx24j600_spi_probe drivers/net/ethernet/microchip/encx24j600.c:459\n spi_probe drivers/spi/spi.c:397\n really_probe drivers/base/dd.c:517\n __driver_probe_device drivers/base/dd.c:751\n driver_probe_device drivers/base/dd.c:782\n __device_attach_driver drivers/base/dd.c:899\n bus_for_each_drv drivers/base/bus.c:427\n __device_attach drivers/base/dd.c:971\n bus_probe_device drivers/base/bus.c:487\n device_add drivers/base/core.c:3364\n __spi_add_device drivers/spi/spi.c:599\n spi_add_device drivers/spi/spi.c:641\n spi_new_device drivers/spi/spi.c:717\n new_device_store+0x18c/0x1f1 [spi_stub 4e02719357f1ff33f5a43d00630982840568e85e]\n dev_attr_store drivers/base/core.c:2074\n sysfs_kf_write fs/sysfs/file.c:139\n kernfs_fop_write_iter fs/kernfs/file.c:300\n new_sync_write fs/read_write.c:508 (discriminator 4)\n vfs_write fs/read_write.c:594\n ksys_write fs/read_write.c:648\n do_syscall_64 arch/x86/entry/common.c:50\n entry_SYSCALL_64_after_hwframe arch/x86/entry/entry_64.S:113\n\nAdd error check in devm_regmap_init_encx24j600 to avoid this situation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47440" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/322c0e53496309e634d9db7349678eaad1d25b55" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4c2eb80fc90b05559ce6ed1b8dfb2348420b5644" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5e5494e6fc8a29c927e0478bec4a078a40da8901" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/66358471fa75a713fd76bc8a4bd74cb14cd50a4f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e19c10d6e07c59c96e90fe053a72683ad8b0397e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f03dca0c9e2297c84a018e306f8a9cd534ee4287" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f043fac1133a6c5ef960a8422c0f6dd711dee462" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fddc7f678d7fb93caa0d7bc512f968ff1e2bddbc" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T07:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-h8rm-f377-9c5v/GHSA-h8rm-f377-9c5v.json b/advisories/unreviewed/2024/05/GHSA-h8rm-f377-9c5v/GHSA-h8rm-f377-9c5v.json new file mode 100644 index 00000000000..dfeba2666f3 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-h8rm-f377-9c5v/GHSA-h8rm-f377-9c5v.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h8rm-f377-9c5v", + "modified": "2024-05-22T09:31:46Z", + "published": "2024-05-22T09:31:46Z", + "aliases": [ + "CVE-2021-47486" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nriscv, bpf: Fix potential NULL dereference\n\nThe bpf_jit_binary_free() function requires a non-NULL argument. When\nthe RISC-V BPF JIT fails to converge in NR_JIT_ITERATIONS steps,\njit_data->header will be NULL, which triggers a NULL\ndereference. Avoid this by checking the argument, prior calling the\nfunction.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47486" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/27de809a3d83a6199664479ebb19712533d6fd9b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cac6b043cea3e120f4fccec16f7381747cbfdc0d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e1b80a5ebe5431caeb20f88c32d4a024777a2d41" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T09:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-h8rv-gwgw-8xww/GHSA-h8rv-gwgw-8xww.json b/advisories/unreviewed/2024/05/GHSA-h8rv-gwgw-8xww/GHSA-h8rv-gwgw-8xww.json new file mode 100644 index 00000000000..d6952585dea --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-h8rv-gwgw-8xww/GHSA-h8rv-gwgw-8xww.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h8rv-gwgw-8xww", + "modified": "2024-05-22T09:31:45Z", + "published": "2024-05-22T09:31:45Z", + "aliases": [ + "CVE-2021-47457" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: isotp: isotp_sendmsg(): add result check for wait_event_interruptible()\n\nUsing wait_event_interruptible() to wait for complete transmission,\nbut do not check the result of wait_event_interruptible() which can be\ninterrupted. It will result in TX buffer has multiple accessors and\nthe later process interferes with the previous process.\n\nFollowing is one of the problems reported by syzbot.\n\n=============================================================\nWARNING: CPU: 0 PID: 0 at net/can/isotp.c:840 isotp_tx_timer_handler+0x2e0/0x4c0\nCPU: 0 PID: 0 Comm: swapper/0 Not tainted 5.13.0-rc7+ #68\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.13.0-1ubuntu1 04/01/2014\nRIP: 0010:isotp_tx_timer_handler+0x2e0/0x4c0\nCall Trace:\n \n ? isotp_setsockopt+0x390/0x390\n __hrtimer_run_queues+0xb8/0x610\n hrtimer_run_softirq+0x91/0xd0\n ? rcu_read_lock_sched_held+0x4d/0x80\n __do_softirq+0xe8/0x553\n irq_exit_rcu+0xf8/0x100\n sysvec_apic_timer_interrupt+0x9e/0xc0\n \n asm_sysvec_apic_timer_interrupt+0x12/0x20\n\nAdd result check for wait_event_interruptible() in isotp_sendmsg()\nto avoid multiple accessers for tx buffer.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47457" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/053bc12df0d6097c1126d0e14fa778a0a8faeb64" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9acf636215a6ce9362fe618e7da4913b8bfe84c8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a76abedd2be3926d6deba236a935c7f98abf9110" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T07:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-hh73-mjw2-25fw/GHSA-hh73-mjw2-25fw.json b/advisories/unreviewed/2024/05/GHSA-hh73-mjw2-25fw/GHSA-hh73-mjw2-25fw.json new file mode 100644 index 00000000000..13364f2938b --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-hh73-mjw2-25fw/GHSA-hh73-mjw2-25fw.json @@ -0,0 +1,63 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hh73-mjw2-25fw", + "modified": "2024-05-22T09:31:45Z", + "published": "2024-05-22T09:31:45Z", + "aliases": [ + "CVE-2021-47468" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nisdn: mISDN: Fix sleeping function called from invalid context\n\nThe driver can call card->isac.release() function from an atomic\ncontext.\n\nFix this by calling this function after releasing the lock.\n\nThe following log reveals it:\n\n[ 44.168226 ] BUG: sleeping function called from invalid context at kernel/workqueue.c:3018\n[ 44.168941 ] in_atomic(): 1, irqs_disabled(): 1, non_block: 0, pid: 5475, name: modprobe\n[ 44.169574 ] INFO: lockdep is turned off.\n[ 44.169899 ] irq event stamp: 0\n[ 44.170160 ] hardirqs last enabled at (0): [<0000000000000000>] 0x0\n[ 44.170627 ] hardirqs last disabled at (0): [] copy_process+0x132d/0x3e00\n[ 44.171240 ] softirqs last enabled at (0): [] copy_process+0x135a/0x3e00\n[ 44.171852 ] softirqs last disabled at (0): [<0000000000000000>] 0x0\n[ 44.172318 ] Preemption disabled at:\n[ 44.172320 ] [] nj_release+0x69/0x500 [netjet]\n[ 44.174441 ] Call Trace:\n[ 44.174630 ] dump_stack_lvl+0xa8/0xd1\n[ 44.174912 ] dump_stack+0x15/0x17\n[ 44.175166 ] ___might_sleep+0x3a2/0x510\n[ 44.175459 ] ? nj_release+0x69/0x500 [netjet]\n[ 44.175791 ] __might_sleep+0x82/0xe0\n[ 44.176063 ] ? start_flush_work+0x20/0x7b0\n[ 44.176375 ] start_flush_work+0x33/0x7b0\n[ 44.176672 ] ? trace_irq_enable_rcuidle+0x85/0x170\n[ 44.177034 ] ? kasan_quarantine_put+0xaa/0x1f0\n[ 44.177372 ] ? kasan_quarantine_put+0xaa/0x1f0\n[ 44.177711 ] __flush_work+0x11a/0x1a0\n[ 44.177991 ] ? flush_work+0x20/0x20\n[ 44.178257 ] ? lock_release+0x13c/0x8f0\n[ 44.178550 ] ? __kasan_check_write+0x14/0x20\n[ 44.178872 ] ? do_raw_spin_lock+0x148/0x360\n[ 44.179187 ] ? read_lock_is_recursive+0x20/0x20\n[ 44.179530 ] ? __kasan_check_read+0x11/0x20\n[ 44.179846 ] ? do_raw_spin_unlock+0x55/0x900\n[ 44.180168 ] ? ____kasan_slab_free+0x116/0x140\n[ 44.180505 ] ? _raw_spin_unlock_irqrestore+0x41/0x60\n[ 44.180878 ] ? skb_queue_purge+0x1a3/0x1c0\n[ 44.181189 ] ? kfree+0x13e/0x290\n[ 44.181438 ] flush_work+0x17/0x20\n[ 44.181695 ] mISDN_freedchannel+0xe8/0x100\n[ 44.182006 ] isac_release+0x210/0x260 [mISDNipac]\n[ 44.182366 ] nj_release+0xf6/0x500 [netjet]\n[ 44.182685 ] nj_remove+0x48/0x70 [netjet]\n[ 44.182989 ] pci_device_remove+0xa9/0x250", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47468" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/37e4f57b22cc5ebb3f80cf0f74fdeb487f082367" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4054b869dc263228d30a4755800b78f0f2ba0c89" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6510e80a0b81b5d814e3aea6297ba42f5e76f73c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6f95c97e0f9d6eb39c3f2cb45e8fa4268d1b372b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9f591cbdbed3d7822b2bdba89b34a6d7b434317d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a5b34409d3fc52114c828be4adbc30744fa3258b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ef269a8808cb1759245a98a7fe16fceaebad894c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f5966ba53013149bcf94e1536644a958dd00a026" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T07:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-hpj2-q4fg-98gf/GHSA-hpj2-q4fg-98gf.json b/advisories/unreviewed/2024/05/GHSA-hpj2-q4fg-98gf/GHSA-hpj2-q4fg-98gf.json new file mode 100644 index 00000000000..beb2b610dcd --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-hpj2-q4fg-98gf/GHSA-hpj2-q4fg-98gf.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hpj2-q4fg-98gf", + "modified": "2024-05-22T09:31:45Z", + "published": "2024-05-22T09:31:45Z", + "aliases": [ + "CVE-2021-47453" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nice: Avoid crash from unnecessary IDA free\n\nIn the remove path, there is an attempt to free the aux_idx IDA whether\nit was allocated or not. This can potentially cause a crash when\nunloading the driver on systems that do not initialize support for RDMA.\nBut, this free cannot be gated by the status bit for RDMA, since it is\nallocated if the driver detects support for RDMA at probe time, but the\ndriver can enter into a state where RDMA is not supported after the IDA\nhas been allocated at probe time and this would lead to a memory leak.\n\nInitialize aux_idx to an invalid value and check for a valid value when\nunloading to determine if an IDA free is necessary.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47453" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/73e30a62b19b9fbb4e6a3465c59da186630d5f2e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/777682e59840e24e6c5672197e6ffbcf4bff823b" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T07:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-hx2r-xg86-xj35/GHSA-hx2r-xg86-xj35.json b/advisories/unreviewed/2024/05/GHSA-hx2r-xg86-xj35/GHSA-hx2r-xg86-xj35.json new file mode 100644 index 00000000000..076da5ca94c --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-hx2r-xg86-xj35/GHSA-hx2r-xg86-xj35.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hx2r-xg86-xj35", + "modified": "2024-05-22T09:31:45Z", + "published": "2024-05-22T09:31:45Z", + "aliases": [ + "CVE-2021-47469" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nspi: Fix deadlock when adding SPI controllers on SPI buses\n\nCurrently we have a global spi_add_lock which we take when adding new\ndevices so that we can check that we're not trying to reuse a chip\nselect that's already controlled. This means that if the SPI device is\nitself a SPI controller and triggers the instantiation of further SPI\ndevices we trigger a deadlock as we try to register and instantiate\nthose devices while in the process of doing so for the parent controller\nand hence already holding the global spi_add_lock. Since we only care\nabout concurrency within a single SPI bus move the lock to be per\ncontroller, avoiding the deadlock.\n\nThis can be easily triggered in the case of spi-mux.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47469" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6098475d4cb48d821bdf453c61118c56e26294f0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/722ef19a161ce3fffb3d1b01ce2301c306639bdd" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T07:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-hxw5-pvw5-67pp/GHSA-hxw5-pvw5-67pp.json b/advisories/unreviewed/2024/05/GHSA-hxw5-pvw5-67pp/GHSA-hxw5-pvw5-67pp.json new file mode 100644 index 00000000000..c3edb136639 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-hxw5-pvw5-67pp/GHSA-hxw5-pvw5-67pp.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hxw5-pvw5-67pp", + "modified": "2024-05-22T09:31:45Z", + "published": "2024-05-22T09:31:45Z", + "aliases": [ + "CVE-2021-47452" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: skip netdev events generated on netns removal\n\nsyzbot reported following (harmless) WARN:\n\n WARNING: CPU: 1 PID: 2648 at net/netfilter/core.c:468\n nft_netdev_unregister_hooks net/netfilter/nf_tables_api.c:230 [inline]\n nf_tables_unregister_hook include/net/netfilter/nf_tables.h:1090 [inline]\n __nft_release_basechain+0x138/0x640 net/netfilter/nf_tables_api.c:9524\n nft_netdev_event net/netfilter/nft_chain_filter.c:351 [inline]\n nf_tables_netdev_event+0x521/0x8a0 net/netfilter/nft_chain_filter.c:382\n\nreproducer:\nunshare -n bash -c 'ip link add br0 type bridge; nft add table netdev t ; \\\n nft add chain netdev t ingress \\{ type filter hook ingress device \"br0\" \\\n priority 0\\; policy drop\\; \\}'\n\nProblem is that when netns device exit hooks create the UNREGISTER\nevent, the .pre_exit hook for nf_tables core has already removed the\nbase hook. Notifier attempts to do this again.\n\nThe need to do base hook unregister unconditionally was needed in the past,\nbecause notifier was last stage where reg->dev dereference was safe.\n\nNow that nf_tables does the hook removal in .pre_exit, this isn't\nneeded anymore.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47452" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/68a3765c659f809dcaac20030853a054646eb739" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/90c7c58aa2bd02c65a4c63b7dfe0b16eab12cf9f" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T07:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-j7fq-277w-8778/GHSA-j7fq-277w-8778.json b/advisories/unreviewed/2024/05/GHSA-j7fq-277w-8778/GHSA-j7fq-277w-8778.json new file mode 100644 index 00000000000..817eeb3f8a4 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-j7fq-277w-8778/GHSA-j7fq-277w-8778.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j7fq-277w-8778", + "modified": "2024-05-22T09:31:46Z", + "published": "2024-05-22T09:31:46Z", + "aliases": [ + "CVE-2024-0632" + ], + "details": "The Automatic Translator with Google Translate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom font setting in all versions up to, and including, 1.5.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0632" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/auto-translate" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/4727154c-c48f-4958-9520-cc5204927ee4?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T08:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-m4gm-7759-99c8/GHSA-m4gm-7759-99c8.json b/advisories/unreviewed/2024/05/GHSA-m4gm-7759-99c8/GHSA-m4gm-7759-99c8.json new file mode 100644 index 00000000000..780a9db9b58 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-m4gm-7759-99c8/GHSA-m4gm-7759-99c8.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m4gm-7759-99c8", + "modified": "2024-05-22T09:31:46Z", + "published": "2024-05-22T09:31:46Z", + "aliases": [ + "CVE-2023-6487" + ], + "details": "The LuckyWP Table of Contents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Header Title' field in all versions up to and including 2.1.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6487" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/luckywp-table-of-contents" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/88075c15-079f-4de2-8e15-374eb7b8c77b?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T08:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-p6hq-6vgx-547f/GHSA-p6hq-6vgx-547f.json b/advisories/unreviewed/2024/05/GHSA-p6hq-6vgx-547f/GHSA-p6hq-6vgx-547f.json new file mode 100644 index 00000000000..f4f73594c1d --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-p6hq-6vgx-547f/GHSA-p6hq-6vgx-547f.json @@ -0,0 +1,63 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p6hq-6vgx-547f", + "modified": "2024-05-22T09:31:45Z", + "published": "2024-05-22T09:31:45Z", + "aliases": [ + "CVE-2021-47458" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: mount fails with buffer overflow in strlen\n\nStarting with kernel 5.11 built with CONFIG_FORTIFY_SOURCE mouting an\nocfs2 filesystem with either o2cb or pcmk cluster stack fails with the\ntrace below. Problem seems to be that strings for cluster stack and\ncluster name are not guaranteed to be null terminated in the disk\nrepresentation, while strlcpy assumes that the source string is always\nnull terminated. This causes a read outside of the source string\ntriggering the buffer overflow detection.\n\n detected buffer overflow in strlen\n ------------[ cut here ]------------\n kernel BUG at lib/string.c:1149!\n invalid opcode: 0000 [#1] SMP PTI\n CPU: 1 PID: 910 Comm: mount.ocfs2 Not tainted 5.14.0-1-amd64 #1\n Debian 5.14.6-2\n RIP: 0010:fortify_panic+0xf/0x11\n ...\n Call Trace:\n ocfs2_initialize_super.isra.0.cold+0xc/0x18 [ocfs2]\n ocfs2_fill_super+0x359/0x19b0 [ocfs2]\n mount_bdev+0x185/0x1b0\n legacy_get_tree+0x27/0x40\n vfs_get_tree+0x25/0xb0\n path_mount+0x454/0xa20\n __x64_sys_mount+0x103/0x140\n do_syscall_64+0x3b/0xc0\n entry_SYSCALL_64_after_hwframe+0x44/0xae", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47458" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0e677ea5b7396f715a76b6b0ef441430e4c4b57f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/232ed9752510de4436468b653d145565669c8498" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4b74ddcc22ee6455946e80a9c4808801f8f8561e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7623b1035ca2d17bde0f6a086ad6844a34648df1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/93be0eeea14cf39235e585c8f56df3b3859deaad" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ac011cb3ff7a76b3e0e6e77158ee4ba2f929e1fb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b15fa9224e6e1239414525d8d556d824701849fc" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d3a83576378b4c904f711598dde2c5e881c4295c" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T07:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-pg78-5grf-jf97/GHSA-pg78-5grf-jf97.json b/advisories/unreviewed/2024/05/GHSA-pg78-5grf-jf97/GHSA-pg78-5grf-jf97.json new file mode 100644 index 00000000000..2355a042628 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-pg78-5grf-jf97/GHSA-pg78-5grf-jf97.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pg78-5grf-jf97", + "modified": "2024-05-22T09:31:46Z", + "published": "2024-05-22T09:31:46Z", + "aliases": [ + "CVE-2024-2119" + ], + "details": "The LuckyWP Table of Contents plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the attrs parameter in all versions up to, and including, 2.1.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2119" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/luckywp-table-of-contents" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/5ceb8f67-0c7a-4028-81b9-f2cdbcba1a80?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T08:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-q3gr-2743-cwm5/GHSA-q3gr-2743-cwm5.json b/advisories/unreviewed/2024/05/GHSA-q3gr-2743-cwm5/GHSA-q3gr-2743-cwm5.json new file mode 100644 index 00000000000..6f65ff7cf14 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-q3gr-2743-cwm5/GHSA-q3gr-2743-cwm5.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q3gr-2743-cwm5", + "modified": "2024-05-22T09:31:45Z", + "published": "2024-05-22T09:31:45Z", + "aliases": [ + "CVE-2021-47461" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nuserfaultfd: fix a race between writeprotect and exit_mmap()\n\nA race is possible when a process exits, its VMAs are removed by\nexit_mmap() and at the same time userfaultfd_writeprotect() is called.\n\nThe race was detected by KASAN on a development kernel, but it appears\nto be possible on vanilla kernels as well.\n\nUse mmget_not_zero() to prevent the race as done in other userfaultfd\noperations.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47461" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/149958ecd0627a9f1e9c678c25c665400054cd6a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3cda4bfffd4f755645577aaa9e96a606657b4525" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cb185d5f1ebf900f4ae3bf84cee212e6dd035aca" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T07:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-q6h5-3vm3-9h46/GHSA-q6h5-3vm3-9h46.json b/advisories/unreviewed/2024/05/GHSA-q6h5-3vm3-9h46/GHSA-q6h5-3vm3-9h46.json new file mode 100644 index 00000000000..c40bdf7abf7 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-q6h5-3vm3-9h46/GHSA-q6h5-3vm3-9h46.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q6h5-3vm3-9h46", + "modified": "2024-05-22T09:31:45Z", + "published": "2024-05-22T09:31:45Z", + "aliases": [ + "CVE-2021-47451" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: xt_IDLETIMER: fix panic that occurs when timer_type has garbage value\n\nCurrently, when the rule related to IDLETIMER is added, idletimer_tg timer\nstructure is initialized by kmalloc on executing idletimer_tg_create\nfunction. However, in this process timer->timer_type is not defined to\na specific value. Thus, timer->timer_type has garbage value and it occurs\nkernel panic. So, this commit fixes the panic by initializing\ntimer->timer_type using kzalloc instead of kmalloc.\n\nTest commands:\n # iptables -A OUTPUT -j IDLETIMER --timeout 1 --label test\n $ cat /sys/class/xt_idletimer/timers/test\n Killed\n\nSplat looks like:\n BUG: KASAN: user-memory-access in alarm_expires_remaining+0x49/0x70\n Read of size 8 at addr 0000002e8c7bc4c8 by task cat/917\n CPU: 12 PID: 917 Comm: cat Not tainted 5.14.0+ #3 79940a339f71eb14fc81aee1757a20d5bf13eb0e\n Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.13.0-1ubuntu1.1 04/01/2014\n Call Trace:\n dump_stack_lvl+0x6e/0x9c\n kasan_report.cold+0x112/0x117\n ? alarm_expires_remaining+0x49/0x70\n __asan_load8+0x86/0xb0\n alarm_expires_remaining+0x49/0x70\n idletimer_tg_show+0xe5/0x19b [xt_IDLETIMER 11219304af9316a21bee5ba9d58f76a6b9bccc6d]\n dev_attr_show+0x3c/0x60\n sysfs_kf_seq_show+0x11d/0x1f0\n ? device_remove_bin_file+0x20/0x20\n kernfs_seq_show+0xa4/0xb0\n seq_read_iter+0x29c/0x750\n kernfs_fop_read_iter+0x25a/0x2c0\n ? __fsnotify_parent+0x3d1/0x570\n ? iov_iter_init+0x70/0x90\n new_sync_read+0x2a7/0x3d0\n ? __x64_sys_llseek+0x230/0x230\n ? rw_verify_area+0x81/0x150\n vfs_read+0x17b/0x240\n ksys_read+0xd9/0x180\n ? vfs_write+0x460/0x460\n ? do_syscall_64+0x16/0xc0\n ? lockdep_hardirqs_on+0x79/0x120\n __x64_sys_read+0x43/0x50\n do_syscall_64+0x3b/0xc0\n entry_SYSCALL_64_after_hwframe+0x44/0xae\n RIP: 0033:0x7f0cdc819142\n Code: c0 e9 c2 fe ff ff 50 48 8d 3d 3a ca 0a 00 e8 f5 19 02 00 0f 1f 44 00 00 f3 0f 1e fa 64 8b 04 25 18 00 00 00 85 c0 75 10 0f 05 <48> 3d 00 f0 ff ff 77 56 c3 0f 1f 44 00 00 48 83 ec 28 48 89 54 24\n RSP: 002b:00007fff28eee5b8 EFLAGS: 00000246 ORIG_RAX: 0000000000000000\n RAX: ffffffffffffffda RBX: 0000000000020000 RCX: 00007f0cdc819142\n RDX: 0000000000020000 RSI: 00007f0cdc032000 RDI: 0000000000000003\n RBP: 00007f0cdc032000 R08: 00007f0cdc031010 R09: 0000000000000000\n R10: 0000000000000022 R11: 0000000000000246 R12: 00005607e9ee31f0\n R13: 0000000000000003 R14: 0000000000020000 R15: 0000000000020000", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47451" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2a670c323055282c9b72794a491d53cef86bbeaf" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/902c0b1887522a099aa4e1e6b4b476c2fe5dd13e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cae7cab804c943d723d52724a3aeb07a3f4a2650" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T07:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-qh22-5q6m-7h2p/GHSA-qh22-5q6m-7h2p.json b/advisories/unreviewed/2024/05/GHSA-qh22-5q6m-7h2p/GHSA-qh22-5q6m-7h2p.json new file mode 100644 index 00000000000..8839c5e41aa --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-qh22-5q6m-7h2p/GHSA-qh22-5q6m-7h2p.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qh22-5q6m-7h2p", + "modified": "2024-05-22T09:31:45Z", + "published": "2024-05-22T09:31:45Z", + "aliases": [ + "CVE-2021-47448" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: fix possible stall on recvmsg()\n\nrecvmsg() can enter an infinite loop if the caller provides the\nMSG_WAITALL, the data present in the receive queue is not sufficient to\nfulfill the request, and no more data is received by the peer.\n\nWhen the above happens, mptcp_wait_data() will always return with\nno wait, as the MPTCP_DATA_READY flag checked by such function is\nset and never cleared in such code path.\n\nLeveraging the above syzbot was able to trigger an RCU stall:\n\nrcu: INFO: rcu_preempt self-detected stall on CPU\nrcu: 0-...!: (10499 ticks this GP) idle=0af/1/0x4000000000000000 softirq=10678/10678 fqs=1\n (t=10500 jiffies g=13089 q=109)\nrcu: rcu_preempt kthread starved for 10497 jiffies! g13089 f0x0 RCU_GP_WAIT_FQS(5) ->state=0x0 ->cpu=1\nrcu: Unless rcu_preempt kthread gets sufficient CPU time, OOM is now expected behavior.\nrcu: RCU grace-period kthread stack dump:\ntask:rcu_preempt state:R running task stack:28696 pid: 14 ppid: 2 flags:0x00004000\nCall Trace:\n context_switch kernel/sched/core.c:4955 [inline]\n __schedule+0x940/0x26f0 kernel/sched/core.c:6236\n schedule+0xd3/0x270 kernel/sched/core.c:6315\n schedule_timeout+0x14a/0x2a0 kernel/time/timer.c:1881\n rcu_gp_fqs_loop+0x186/0x810 kernel/rcu/tree.c:1955\n rcu_gp_kthread+0x1de/0x320 kernel/rcu/tree.c:2128\n kthread+0x405/0x4f0 kernel/kthread.c:327\n ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:295\nrcu: Stack dump where RCU GP kthread last ran:\nSending NMI from CPU 0 to CPUs 1:\nNMI backtrace for cpu 1\nCPU: 1 PID: 8510 Comm: syz-executor827 Not tainted 5.15.0-rc2-next-20210920-syzkaller #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 01/01/2011\nRIP: 0010:bytes_is_nonzero mm/kasan/generic.c:84 [inline]\nRIP: 0010:memory_is_nonzero mm/kasan/generic.c:102 [inline]\nRIP: 0010:memory_is_poisoned_n mm/kasan/generic.c:128 [inline]\nRIP: 0010:memory_is_poisoned mm/kasan/generic.c:159 [inline]\nRIP: 0010:check_region_inline mm/kasan/generic.c:180 [inline]\nRIP: 0010:kasan_check_range+0xc8/0x180 mm/kasan/generic.c:189\nCode: 38 00 74 ed 48 8d 50 08 eb 09 48 83 c0 01 48 39 d0 74 7a 80 38 00 74 f2 48 89 c2 b8 01 00 00 00 48 85 d2 75 56 5b 5d 41 5c c3 <48> 85 d2 74 5e 48 01 ea eb 09 48 83 c0 01 48 39 d0 74 50 80 38 00\nRSP: 0018:ffffc9000cd676c8 EFLAGS: 00000283\nRAX: ffffed100e9a110e RBX: ffffed100e9a110f RCX: ffffffff88ea062a\nRDX: 0000000000000001 RSI: 0000000000000008 RDI: ffff888074d08870\nRBP: ffffed100e9a110e R08: 0000000000000001 R09: ffff888074d08877\nR10: ffffed100e9a110e R11: 0000000000000000 R12: ffff888074d08000\nR13: ffff888074d08000 R14: ffff888074d08088 R15: ffff888074d08000\nFS: 0000555556d8e300(0000) GS:ffff8880b9d00000(0000) knlGS:0000000000000000\nS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000000020000180 CR3: 0000000068909000 CR4: 00000000001506e0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nCall Trace:\n instrument_atomic_read_write include/linux/instrumented.h:101 [inline]\n test_and_clear_bit include/asm-generic/bitops/instrumented-atomic.h:83 [inline]\n mptcp_release_cb+0x14a/0x210 net/mptcp/protocol.c:3016\n release_sock+0xb4/0x1b0 net/core/sock.c:3204\n mptcp_wait_data net/mptcp/protocol.c:1770 [inline]\n mptcp_recvmsg+0xfd1/0x27b0 net/mptcp/protocol.c:2080\n inet6_recvmsg+0x11b/0x5e0 net/ipv6/af_inet6.c:659\n sock_recvmsg_nosec net/socket.c:944 [inline]\n ____sys_recvmsg+0x527/0x600 net/socket.c:2626\n ___sys_recvmsg+0x127/0x200 net/socket.c:2670\n do_recvmmsg+0x24d/0x6d0 net/socket.c:2764\n __sys_recvmmsg net/socket.c:2843 [inline]\n __do_sys_recvmmsg net/socket.c:2866 [inline]\n __se_sys_recvmmsg net/socket.c:2859 [inline]\n __x64_sys_recvmmsg+0x20b/0x260 net/socket.c:2859\n do_syscall_x64 arch/x86/entry/common.c:50 [inline]\n do_syscall_64+0x35/0xb0 arch/x86/entry/common.c:80\n entry_SYSCALL_64_after_hwframe+0x44/0xae\nRIP: 0033:0x7fc200d2\n---truncated---", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47448" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1a4554e94f0deff9fc1dc5addf93fa579cc29711" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/612f71d7328c14369924384ad2170aae2a6abd92" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T07:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-qm36-7xcx-862v/GHSA-qm36-7xcx-862v.json b/advisories/unreviewed/2024/05/GHSA-qm36-7xcx-862v/GHSA-qm36-7xcx-862v.json new file mode 100644 index 00000000000..8fb45337b8b --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-qm36-7xcx-862v/GHSA-qm36-7xcx-862v.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qm36-7xcx-862v", + "modified": "2024-05-22T09:31:46Z", + "published": "2024-05-22T09:31:46Z", + "aliases": [ + "CVE-2021-47492" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm, thp: bail out early in collapse_file for writeback page\n\nCurrently collapse_file does not explicitly check PG_writeback, instead,\npage_has_private and try_to_release_page are used to filter writeback\npages. This does not work for xfs with blocksize equal to or larger\nthan pagesize, because in such case xfs has no page->private.\n\nThis makes collapse_file bail out early for writeback page. Otherwise,\nxfs end_page_writeback will panic as follows.\n\n page:fffffe00201bcc80 refcount:0 mapcount:0 mapping:ffff0003f88c86a8 index:0x0 pfn:0x84ef32\n aops:xfs_address_space_operations [xfs] ino:30000b7 dentry name:\"libtest.so\"\n flags: 0x57fffe0000008027(locked|referenced|uptodate|active|writeback)\n raw: 57fffe0000008027 ffff80001b48bc28 ffff80001b48bc28 ffff0003f88c86a8\n raw: 0000000000000000 0000000000000000 00000000ffffffff ffff0000c3e9a000\n page dumped because: VM_BUG_ON_PAGE(((unsigned int) page_ref_count(page) + 127u <= 127u))\n page->mem_cgroup:ffff0000c3e9a000\n ------------[ cut here ]------------\n kernel BUG at include/linux/mm.h:1212!\n Internal error: Oops - BUG: 0 [#1] SMP\n Modules linked in:\n BUG: Bad page state in process khugepaged pfn:84ef32\n xfs(E)\n page:fffffe00201bcc80 refcount:0 mapcount:0 mapping:0 index:0x0 pfn:0x84ef32\n libcrc32c(E) rfkill(E) aes_ce_blk(E) crypto_simd(E) ...\n CPU: 25 PID: 0 Comm: swapper/25 Kdump: loaded Tainted: ...\n pstate: 60400005 (nZCv daif +PAN -UAO -TCO BTYPE=--)\n Call trace:\n end_page_writeback+0x1c0/0x214\n iomap_finish_page_writeback+0x13c/0x204\n iomap_finish_ioend+0xe8/0x19c\n iomap_writepage_end_bio+0x38/0x50\n bio_endio+0x168/0x1ec\n blk_update_request+0x278/0x3f0\n blk_mq_end_request+0x34/0x15c\n virtblk_request_done+0x38/0x74 [virtio_blk]\n blk_done_softirq+0xc4/0x110\n __do_softirq+0x128/0x38c\n __irq_exit_rcu+0x118/0x150\n irq_exit+0x1c/0x30\n __handle_domain_irq+0x8c/0xf0\n gic_handle_irq+0x84/0x108\n el1_irq+0xcc/0x180\n arch_cpu_idle+0x18/0x40\n default_idle_call+0x4c/0x1a0\n cpuidle_idle_call+0x168/0x1e0\n do_idle+0xb4/0x104\n cpu_startup_entry+0x30/0x9c\n secondary_start_kernel+0x104/0x180\n Code: d4210000 b0006161 910c8021 94013f4d (d4210000)\n ---[ end trace 4a88c6a074082f8c ]---\n Kernel panic - not syncing: Oops - BUG: Fatal exception in interrupt", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47492" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5e669d8ab30ab61dec3c36e27b4711f07611e6fc" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/69a7fa5cb0de06c8956b040f19a7248c8c8308ca" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/74c42e1baacf206338b1dd6b6199ac964512b5bb" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T09:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-r5hc-q3m9-jg75/GHSA-r5hc-q3m9-jg75.json b/advisories/unreviewed/2024/05/GHSA-r5hc-q3m9-jg75/GHSA-r5hc-q3m9-jg75.json new file mode 100644 index 00000000000..6a7fbf133af --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-r5hc-q3m9-jg75/GHSA-r5hc-q3m9-jg75.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r5hc-q3m9-jg75", + "modified": "2024-05-22T09:31:46Z", + "published": "2024-05-22T09:31:46Z", + "aliases": [ + "CVE-2024-2953" + ], + "details": "The LuckyWP Table of Contents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 2.1.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with Contributor permissions and above to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2953" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/luckywp-table-of-contents/tags/2.1.4/plugin/PostSettings.php#L207" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/luckywp-table-of-contents/tags/2.1.4/plugin/PostSettings.php#L209" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/luckywp-table-of-contents/tags/2.1.4/plugin/PostSettings.php#L210" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/b12c0524-d991-4f96-8646-f4203880558c?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T08:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-r7gr-mhrj-m5wq/GHSA-r7gr-mhrj-m5wq.json b/advisories/unreviewed/2024/05/GHSA-r7gr-mhrj-m5wq/GHSA-r7gr-mhrj-m5wq.json new file mode 100644 index 00000000000..12bfe235efa --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-r7gr-mhrj-m5wq/GHSA-r7gr-mhrj-m5wq.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r7gr-mhrj-m5wq", + "modified": "2024-05-22T09:31:46Z", + "published": "2024-05-22T09:31:46Z", + "aliases": [ + "CVE-2021-47479" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nstaging: rtl8712: fix use-after-free in rtl8712_dl_fw\n\nSyzbot reported use-after-free in rtl8712_dl_fw(). The problem was in\nrace condition between r871xu_dev_remove() ->ndo_open() callback.\n\nIt's easy to see from crash log, that driver accesses released firmware\nin ->ndo_open() callback. It may happen, since driver was releasing\nfirmware _before_ unregistering netdev. Fix it by moving\nunregister_netdev() before cleaning up resources.\n\nCall Trace:\n...\n rtl871x_open_fw drivers/staging/rtl8712/hal_init.c:83 [inline]\n rtl8712_dl_fw+0xd95/0xe10 drivers/staging/rtl8712/hal_init.c:170\n rtl8712_hal_init drivers/staging/rtl8712/hal_init.c:330 [inline]\n rtl871x_hal_init+0xae/0x180 drivers/staging/rtl8712/hal_init.c:394\n netdev_open+0xe6/0x6c0 drivers/staging/rtl8712/os_intfs.c:380\n __dev_open+0x2bc/0x4d0 net/core/dev.c:1484\n\nFreed by task 1306:\n...\n release_firmware+0x1b/0x30 drivers/base/firmware_loader/main.c:1053\n r871xu_dev_remove+0xcc/0x2c0 drivers/staging/rtl8712/usb_intf.c:599\n usb_unbind_interface+0x1d8/0x8d0 drivers/usb/core/driver.c:458", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47479" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a65c9afe9f2f55b7a7fb4a25ab654cd4139683a4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/befd23bd3b17f1a3f9c943a8580b47444c7c63ed" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c052cc1a069c3e575619cf64ec427eb41176ca70" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c430094541a80575259a94ff879063ef01473506" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T09:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-r7pj-34j8-6jgg/GHSA-r7pj-34j8-6jgg.json b/advisories/unreviewed/2024/05/GHSA-r7pj-34j8-6jgg/GHSA-r7pj-34j8-6jgg.json new file mode 100644 index 00000000000..96f2d596d22 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-r7pj-34j8-6jgg/GHSA-r7pj-34j8-6jgg.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r7pj-34j8-6jgg", + "modified": "2024-05-22T09:31:45Z", + "published": "2024-05-22T09:31:45Z", + "aliases": [ + "CVE-2021-47465" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: PPC: Book3S HV: Fix stack handling in idle_kvm_start_guest()\n\nIn commit 10d91611f426 (\"powerpc/64s: Reimplement book3s idle code in\nC\") kvm_start_guest() became idle_kvm_start_guest(). The old code\nallocated a stack frame on the emergency stack, but didn't use the\nframe to store anything, and also didn't store anything in its caller's\nframe.\n\nidle_kvm_start_guest() on the other hand is written more like a normal C\nfunction, it creates a frame on entry, and also stores CR/LR into its\ncallers frame (per the ABI). The problem is that there is no caller\nframe on the emergency stack.\n\nThe emergency stack for a given CPU is allocated with:\n\n paca_ptrs[i]->emergency_sp = alloc_stack(limit, i) + THREAD_SIZE;\n\nSo emergency_sp actually points to the first address above the emergency\nstack allocation for a given CPU, we must not store above it without\nfirst decrementing it to create a frame. This is different to the\nregular kernel stack, paca->kstack, which is initialised to point at an\ninitial frame that is ready to use.\n\nidle_kvm_start_guest() stores the backchain, CR and LR all of which\nwrite outside the allocation for the emergency stack. It then creates a\nstack frame and saves the non-volatile registers. Unfortunately the\nframe it creates is not large enough to fit the non-volatiles, and so\nthe saving of the non-volatile registers also writes outside the\nemergency stack allocation.\n\nThe end result is that we corrupt whatever is at 0-24 bytes, and 112-248\nbytes above the emergency stack allocation.\n\nIn practice this has gone unnoticed because the memory immediately above\nthe emergency stack happens to be used for other stack allocations,\neither another CPUs mc_emergency_sp or an IRQ stack. See the order of\ncalls to irqstack_early_init() and emergency_stack_init().\n\nThe low addresses of another stack are the top of that stack, and so are\nonly used if that stack is under extreme pressue, which essentially\nnever happens in practice - and if it did there's a high likelyhood we'd\ncrash due to that stack overflowing.\n\nStill, we shouldn't be corrupting someone else's stack, and it is purely\nluck that we aren't corrupting something else.\n\nTo fix it we save CR/LR into the caller's frame using the existing r1 on\nentry, we then create a SWITCH_FRAME_SIZE frame (which has space for\npt_regs) on the emergency stack with the backchain pointing to the\nexisting stack, and then finally we switch to the new frame on the\nemergency stack.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47465" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6d077c37c4643394b1bae9682da48164fc147ea8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/80bbb0bc3a0288442f7fe6fc514f4ee1cb06ccb7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9b4416c5095c20e110c82ae602c254099b83b72f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fbd724c49bead048ae9fc1a5b7bff2fb3e54f855" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T07:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-rcc5-r3m3-9rvc/GHSA-rcc5-r3m3-9rvc.json b/advisories/unreviewed/2024/05/GHSA-rcc5-r3m3-9rvc/GHSA-rcc5-r3m3-9rvc.json new file mode 100644 index 00000000000..ee0d71876f6 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-rcc5-r3m3-9rvc/GHSA-rcc5-r3m3-9rvc.json @@ -0,0 +1,63 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rcc5-r3m3-9rvc", + "modified": "2024-05-22T09:31:46Z", + "published": "2024-05-22T09:31:46Z", + "aliases": [ + "CVE-2021-47485" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nIB/qib: Protect from buffer overflow in struct qib_user_sdma_pkt fields\n\nOverflowing either addrlimit or bytes_togo can allow userspace to trigger\na buffer overflow of kernel memory. Check for overflows in all the places\ndoing math on user controlled buffers.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47485" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0d4395477741608d123dad51def9fe50b7ebe952" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0f8cdfff06829a0b0348b6debc29ff6a61967724" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3f57c3f67fd93b4da86aeffea1ca32c484d054ad" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/60833707b968d5ae02a75edb7886dcd4a957cf0d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/73d2892148aa4397a885b4f4afcfc5b27a325c42" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bda41654b6e0c125a624ca35d6d20beb8015b5d0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c3e17e58f571f34c51aeb17274ed02c2ed5cf780" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d39bf40e55e666b5905fdbd46a0dced030ce87be" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T09:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-rcm4-5vxv-3g8q/GHSA-rcm4-5vxv-3g8q.json b/advisories/unreviewed/2024/05/GHSA-rcm4-5vxv-3g8q/GHSA-rcm4-5vxv-3g8q.json new file mode 100644 index 00000000000..6c3fb37cdda --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-rcm4-5vxv-3g8q/GHSA-rcm4-5vxv-3g8q.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rcm4-5vxv-3g8q", + "modified": "2024-05-22T09:31:45Z", + "published": "2024-05-22T09:31:45Z", + "aliases": [ + "CVE-2021-47454" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\npowerpc/smp: do not decrement idle task preempt count in CPU offline\n\nWith PREEMPT_COUNT=y, when a CPU is offlined and then onlined again, we\nget:\n\nBUG: scheduling while atomic: swapper/1/0/0x00000000\nno locks held by swapper/1/0.\nCPU: 1 PID: 0 Comm: swapper/1 Not tainted 5.15.0-rc2+ #100\nCall Trace:\n dump_stack_lvl+0xac/0x108\n __schedule_bug+0xac/0xe0\n __schedule+0xcf8/0x10d0\n schedule_idle+0x3c/0x70\n do_idle+0x2d8/0x4a0\n cpu_startup_entry+0x38/0x40\n start_secondary+0x2ec/0x3a0\n start_secondary_prolog+0x10/0x14\n\nThis is because powerpc's arch_cpu_idle_dead() decrements the idle task's\npreempt count, for reasons explained in commit a7c2bb8279d2 (\"powerpc:\nRe-enable preemption before cpu_die()\"), specifically \"start_secondary()\nexpects a preempt_count() of 0.\"\n\nHowever, since commit 2c669ef6979c (\"powerpc/preempt: Don't touch the idle\ntask's preempt_count during hotplug\") and commit f1a0a376ca0c (\"sched/core:\nInitialize the idle task with preemption disabled\"), that justification no\nlonger holds.\n\nThe idle task isn't supposed to re-enable preemption, so remove the\nvestigial preempt_enable() from the CPU offline path.\n\nTested with pseries and powernv in qemu, and pseries on PowerVM.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47454" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3ea0b497a7a2fff6a4b7090310c9f52c91975934" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/53770a411559cf7bc0906d1df319cc533d2f4f58" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/787252a10d9422f3058df9a4821f389e5326c440" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T07:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-rh2v-79c5-2v68/GHSA-rh2v-79c5-2v68.json b/advisories/unreviewed/2024/05/GHSA-rh2v-79c5-2v68/GHSA-rh2v-79c5-2v68.json new file mode 100644 index 00000000000..e98c9c1e744 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-rh2v-79c5-2v68/GHSA-rh2v-79c5-2v68.json @@ -0,0 +1,67 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rh2v-79c5-2v68", + "modified": "2024-05-22T09:31:46Z", + "published": "2024-05-22T09:31:46Z", + "aliases": [ + "CVE-2021-47478" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nisofs: Fix out of bound access for corrupted isofs image\n\nWhen isofs image is suitably corrupted isofs_read_inode() can read data\nbeyond the end of buffer. Sanity-check the directory entry length before\nusing it.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47478" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/156ce5bb6cc43a80a743810199defb1dc3f55b7f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6e80e9314f8bb52d9eabe1907698718ff01120f5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/86d4aedcbc69c0f84551fb70f953c24e396de2d7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9ec33a9b8790c212cc926a88c5e2105f97f3f57e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/afbd40f425227e661d991757e11cc4db024e761f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b0ddff8d68f2e43857a84dce54c3deab181c8ae1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b2fa1f52d22c5455217b294629346ad23a744945" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e7fb722586a2936b37bdff096c095c30ca06404d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e96a1866b40570b5950cda8602c2819189c62a48" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T09:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-rj64-24f8-r32g/GHSA-rj64-24f8-r32g.json b/advisories/unreviewed/2024/05/GHSA-rj64-24f8-r32g/GHSA-rj64-24f8-r32g.json new file mode 100644 index 00000000000..882fcc71c54 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-rj64-24f8-r32g/GHSA-rj64-24f8-r32g.json @@ -0,0 +1,63 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rj64-24f8-r32g", + "modified": "2024-05-22T09:31:47Z", + "published": "2024-05-22T09:31:47Z", + "aliases": [ + "CVE-2021-47495" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusbnet: sanity check for maxpacket\n\nmaxpacket of 0 makes no sense and oopses as we need to divide\nby it. Give up.\n\nV2: fixed typo in log and stylistic issues", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47495" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/002d82227c0abe29118cf80f7e2f396b22d448ed" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/397430b50a363d8b7bdda00522123f82df6adc5e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/492140e45d2bf27c1014243f8616a9b612144e20" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/524f333e98138d909a0a0c574a9ff6737dce2767" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/693ecbe8f799405f8775719deedb1f76265d375a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/74b3b27cf9fecce00cd8918b7882fd81191d0aa4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7e8b6a4f18edee070213cb6a77118e8a412253c5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b9eba0a4a527e04d712f0e0401e5391ef124b33e" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T09:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-vgjx-6ccw-c3f6/GHSA-vgjx-6ccw-c3f6.json b/advisories/unreviewed/2024/05/GHSA-vgjx-6ccw-c3f6/GHSA-vgjx-6ccw-c3f6.json new file mode 100644 index 00000000000..648fc95053f --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-vgjx-6ccw-c3f6/GHSA-vgjx-6ccw-c3f6.json @@ -0,0 +1,63 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vgjx-6ccw-c3f6", + "modified": "2024-05-22T09:31:47Z", + "published": "2024-05-22T09:31:47Z", + "aliases": [ + "CVE-2021-47497" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnvmem: Fix shift-out-of-bound (UBSAN) with byte size cells\n\nIf a cell has 'nbits' equal to a multiple of BITS_PER_BYTE the logic\n\n *p &= GENMASK((cell->nbits%BITS_PER_BYTE) - 1, 0);\n\nwill become undefined behavior because nbits modulo BITS_PER_BYTE is 0, and we\nsubtract one from that making a large number that is then shifted more than the\nnumber of bits that fit into an unsigned long.\n\nUBSAN reports this problem:\n\n UBSAN: shift-out-of-bounds in drivers/nvmem/core.c:1386:8\n shift exponent 64 is too large for 64-bit type 'unsigned long'\n CPU: 6 PID: 7 Comm: kworker/u16:0 Not tainted 5.15.0-rc3+ #9\n Hardware name: Google Lazor (rev3+) with KB Backlight (DT)\n Workqueue: events_unbound deferred_probe_work_func\n Call trace:\n dump_backtrace+0x0/0x170\n show_stack+0x24/0x30\n dump_stack_lvl+0x64/0x7c\n dump_stack+0x18/0x38\n ubsan_epilogue+0x10/0x54\n __ubsan_handle_shift_out_of_bounds+0x180/0x194\n __nvmem_cell_read+0x1ec/0x21c\n nvmem_cell_read+0x58/0x94\n nvmem_cell_read_variable_common+0x4c/0xb0\n nvmem_cell_read_variable_le_u32+0x40/0x100\n a6xx_gpu_init+0x170/0x2f4\n adreno_bind+0x174/0x284\n component_bind_all+0xf0/0x264\n msm_drm_bind+0x1d8/0x7a0\n try_to_bring_up_master+0x164/0x1ac\n __component_add+0xbc/0x13c\n component_add+0x20/0x2c\n dp_display_probe+0x340/0x384\n platform_probe+0xc0/0x100\n really_probe+0x110/0x304\n __driver_probe_device+0xb8/0x120\n driver_probe_device+0x4c/0xfc\n __device_attach_driver+0xb0/0x128\n bus_for_each_drv+0x90/0xdc\n __device_attach+0xc8/0x174\n device_initial_probe+0x20/0x2c\n bus_probe_device+0x40/0xa4\n deferred_probe_work_func+0x7c/0xb8\n process_one_work+0x128/0x21c\n process_scheduled_works+0x40/0x54\n worker_thread+0x1ec/0x2a8\n kthread+0x138/0x158\n ret_from_fork+0x10/0x20\n\nFix it by making sure there are any bits to mask out.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47497" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0594f1d048d8dc338eb9a240021b1d00ae1eb082" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0e822e5413da1af28cca350cb1cb42b6133bdcae" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2df6c023050205c4d04ffc121bc549f65cb8d1df" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/57e48886401b14cd351423fabfec2cfd18df4f66" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5d388fa01fa6eb310ac023a363a6cb216d9d8fe9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/60df06bbdf497e37ed25ad40572c362e5b0998df" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/abcb8d33e4d2215ccde5ab5ccf9f730a59d79d97" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/eb0fc8e7170e61eaf65d28dee4a8baf4e86b19ca" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T09:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-vh53-65cw-j6wx/GHSA-vh53-65cw-j6wx.json b/advisories/unreviewed/2024/05/GHSA-vh53-65cw-j6wx/GHSA-vh53-65cw-j6wx.json new file mode 100644 index 00000000000..d8760253bbb --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-vh53-65cw-j6wx/GHSA-vh53-65cw-j6wx.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vh53-65cw-j6wx", + "modified": "2024-05-22T09:31:47Z", + "published": "2024-05-22T09:31:47Z", + "aliases": [ + "CVE-2024-5025" + ], + "details": "The Memberpress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘arglist’ parameter in all versions up to, and including, 1.11.29 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5025" + }, + { + "type": "WEB", + "url": "https://memberpress.com/change-log" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/f147641a-f430-4743-901e-539373dc10b7?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T09:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-vr9g-qp6c-282r/GHSA-vr9g-qp6c-282r.json b/advisories/unreviewed/2024/05/GHSA-vr9g-qp6c-282r/GHSA-vr9g-qp6c-282r.json new file mode 100644 index 00000000000..4d2352868fc --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-vr9g-qp6c-282r/GHSA-vr9g-qp6c-282r.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vr9g-qp6c-282r", + "modified": "2024-05-22T09:31:45Z", + "published": "2024-05-22T09:31:45Z", + "aliases": [ + "CVE-2021-47470" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm, slub: fix potential use-after-free in slab_debugfs_fops\n\nWhen sysfs_slab_add failed, we shouldn't call debugfs_slab_add() for s\nbecause s will be freed soon. And slab_debugfs_fops will use s later\nleading to a use-after-free.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47470" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/159d8cfbd0428d487c53be4722f33cdab0d25d83" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/67823a544414def2a36c212abadb55b23bcda00c" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T07:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-w98j-8cf9-vjpq/GHSA-w98j-8cf9-vjpq.json b/advisories/unreviewed/2024/05/GHSA-w98j-8cf9-vjpq/GHSA-w98j-8cf9-vjpq.json new file mode 100644 index 00000000000..3c44a2b9be2 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-w98j-8cf9-vjpq/GHSA-w98j-8cf9-vjpq.json @@ -0,0 +1,54 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w98j-8cf9-vjpq", + "modified": "2024-05-22T09:31:45Z", + "published": "2024-05-22T09:31:45Z", + "aliases": [ + "CVE-2024-1762" + ], + "details": "The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HTTP_USER_AGENT header in all versions up to, and including, 4.4.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the victim to select view \"All Cron Events\" in order for the injection to fire.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1762" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/social-networks-auto-poster-facebook-twitter-g/trunk/NextScripts_SNAP.php#L74" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/social-networks-auto-poster-facebook-twitter-g/trunk/inc/nxs_functions_engine.php#L117" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/social-networks-auto-poster-facebook-twitter-g/trunk/inc/nxs_functions_engine.php#L125" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3084635%40social-networks-auto-poster-facebook-twitter-g%2Ftrunk&old=3004433%40social-networks-auto-poster-facebook-twitter-g%2Ftrunk&sfp_email=&sfph_mail=#file17" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/8063a545-4792-4ab7-b188-0e51a0fcfed4?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T07:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-wc2g-rvvj-x242/GHSA-wc2g-rvvj-x242.json b/advisories/unreviewed/2024/05/GHSA-wc2g-rvvj-x242/GHSA-wc2g-rvvj-x242.json new file mode 100644 index 00000000000..d9da8dd87de --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-wc2g-rvvj-x242/GHSA-wc2g-rvvj-x242.json @@ -0,0 +1,63 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wc2g-rvvj-x242", + "modified": "2024-05-22T09:31:46Z", + "published": "2024-05-22T09:31:46Z", + "aliases": [ + "CVE-2021-47480" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: core: Put LLD module refcnt after SCSI device is released\n\nSCSI host release is triggered when SCSI device is freed. We have to make\nsure that the low-level device driver module won't be unloaded before SCSI\nhost instance is released because shost->hostt is required in the release\nhandler.\n\nMake sure to put LLD module refcnt after SCSI device is released.\n\nFixes a kernel panic of 'BUG: unable to handle page fault for address'\nreported by Changhui and Yi.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47480" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1105573d964f7b78734348466b01f5f6ba8a1813" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1ce287eff9f23181d5644db787f472463a61f68b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/61a0faa89f21861d1f8d059123b5c285a5d9ffee" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7b57c38d12aed1b5d92f74748bed25e0d041729f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8e4814a461787e15a31d322d9efbe0d4f6822428" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c2df161f69fb1c67f63adbd193368b47f511edc0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f2b85040acec9a928b4eb1b57a989324e8e38d3f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f30822c0b4c35ec86187ab055263943dc71a6836" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T09:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-wh2p-rhh2-p26w/GHSA-wh2p-rhh2-p26w.json b/advisories/unreviewed/2024/05/GHSA-wh2p-rhh2-p26w/GHSA-wh2p-rhh2-p26w.json new file mode 100644 index 00000000000..845b641685d --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-wh2p-rhh2-p26w/GHSA-wh2p-rhh2-p26w.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wh2p-rhh2-p26w", + "modified": "2024-05-22T09:31:47Z", + "published": "2024-05-22T09:31:46Z", + "aliases": [ + "CVE-2024-4362" + ], + "details": "The SiteOrigin Widgets Bundle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'siteorigin_widget' shortcode in all versions up to, and including, 1.60.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4362" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/so-widgets-bundle/trunk/base/inc/shortcode.php#L27" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3088997/so-widgets-bundle/trunk/base/inc/shortcode.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/b7926ec6-3441-4062-93b2-6c2120c9f406?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T09:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-ww7g-fw5c-855v/GHSA-ww7g-fw5c-855v.json b/advisories/unreviewed/2024/05/GHSA-ww7g-fw5c-855v/GHSA-ww7g-fw5c-855v.json new file mode 100644 index 00000000000..57a093c0734 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-ww7g-fw5c-855v/GHSA-ww7g-fw5c-855v.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ww7g-fw5c-855v", + "modified": "2024-05-22T09:31:47Z", + "published": "2024-05-22T09:31:46Z", + "aliases": [ + "CVE-2024-2036" + ], + "details": "The ApplyOnline – Application Form Builder and Manager plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the aol_modal_box AJAX action in all versions up to, and including, 2.6. This makes it possible for authenticated attackers, with subscriber access or higher, to view Application submissions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2036" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/apply-online" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/3eff4992-dbd4-4b9b-872e-1670ce7dab9d?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T09:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-x4fx-qg56-6gp4/GHSA-x4fx-qg56-6gp4.json b/advisories/unreviewed/2024/05/GHSA-x4fx-qg56-6gp4/GHSA-x4fx-qg56-6gp4.json new file mode 100644 index 00000000000..39d68d1381e --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-x4fx-qg56-6gp4/GHSA-x4fx-qg56-6gp4.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x4fx-qg56-6gp4", + "modified": "2024-05-22T09:31:46Z", + "published": "2024-05-22T09:31:45Z", + "aliases": [ + "CVE-2024-3198" + ], + "details": "The WP Font Awesome Share Icons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's \n'wpfai_social' shortcode in all versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3198" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/wp-font-awesome-share-icons" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/cd066a04-8094-4004-8a64-317c6bd4e101?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T07:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-xgm7-3x53-gq2c/GHSA-xgm7-3x53-gq2c.json b/advisories/unreviewed/2024/05/GHSA-xgm7-3x53-gq2c/GHSA-xgm7-3x53-gq2c.json new file mode 100644 index 00000000000..6c35f15ede5 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-xgm7-3x53-gq2c/GHSA-xgm7-3x53-gq2c.json @@ -0,0 +1,63 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xgm7-3x53-gq2c", + "modified": "2024-05-22T09:31:46Z", + "published": "2024-05-22T09:31:46Z", + "aliases": [ + "CVE-2021-47482" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: batman-adv: fix error handling\n\nSyzbot reported ODEBUG warning in batadv_nc_mesh_free(). The problem was\nin wrong error handling in batadv_mesh_init().\n\nBefore this patch batadv_mesh_init() was calling batadv_mesh_free() in case\nof any batadv_*_init() calls failure. This approach may work well, when\nthere is some kind of indicator, which can tell which parts of batadv are\ninitialized; but there isn't any.\n\nAll written above lead to cleaning up uninitialized fields. Even if we hide\nODEBUG warning by initializing bat_priv->nc.work, syzbot was able to hit\nGPF in batadv_nc_purge_paths(), because hash pointer in still NULL. [1]\n\nTo fix these bugs we can unwind batadv_*_init() calls one by one.\nIt is good approach for 2 reasons: 1) It fixes bugs on error handling\npath 2) It improves the performance, since we won't call unneeded\nbatadv_*_free() functions.\n\nSo, this patch makes all batadv_*_init() clean up all allocated memory\nbefore returning with an error to no call correspoing batadv_*_free()\nand open-codes batadv_mesh_free() with proper order to avoid touching\nuninitialized fields.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47482" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/07533f1a673ce1126d0a72ef1e4b5eaaa3dd6d20" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0c6b199f09be489c48622537a550787fc80aea73" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6422e8471890273994fe8cc6d452b0dcd2c9483e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6f68cd634856f8ca93bafd623ba5357e0f648c68" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a8f7359259dd5923adc6129284fdad12fc5db347" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b0a2cd38553c77928ef1646ed1518486b1e70ae8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e50f957652190b5a88a8ebce7e5ab14ebd0d3f00" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fbf150b16a3635634b7dfb7f229d8fcd643c6c51" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T09:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-xjr2-g37g-hrjm/GHSA-xjr2-g37g-hrjm.json b/advisories/unreviewed/2024/05/GHSA-xjr2-g37g-hrjm/GHSA-xjr2-g37g-hrjm.json new file mode 100644 index 00000000000..3326202c7b0 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-xjr2-g37g-hrjm/GHSA-xjr2-g37g-hrjm.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xjr2-g37g-hrjm", + "modified": "2024-05-22T09:31:45Z", + "published": "2024-05-22T09:31:45Z", + "aliases": [ + "CVE-2021-47463" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/secretmem: fix NULL page->mapping dereference in page_is_secretmem()\n\nCheck for a NULL page->mapping before dereferencing the mapping in\npage_is_secretmem(), as the page's mapping can be nullified while gup()\nis running, e.g. by reclaim or truncation.\n\n BUG: kernel NULL pointer dereference, address: 0000000000000068\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\n PGD 0 P4D 0\n Oops: 0000 [#1] PREEMPT SMP NOPTI\n CPU: 6 PID: 4173897 Comm: CPU 3/KVM Tainted: G W\n RIP: 0010:internal_get_user_pages_fast+0x621/0x9d0\n Code: <48> 81 7a 68 80 08 04 bc 0f 85 21 ff ff 8 89 c7 be\n RSP: 0018:ffffaa90087679b0 EFLAGS: 00010046\n RAX: ffffe3f37905b900 RBX: 00007f2dd561e000 RCX: ffffe3f37905b934\n RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffffe3f37905b900\n ...\n CR2: 0000000000000068 CR3: 00000004c5898003 CR4: 00000000001726e0\n Call Trace:\n get_user_pages_fast_only+0x13/0x20\n hva_to_pfn+0xa9/0x3e0\n try_async_pf+0xa1/0x270\n direct_page_fault+0x113/0xad0\n kvm_mmu_page_fault+0x69/0x680\n vmx_handle_exit+0xe1/0x5d0\n kvm_arch_vcpu_ioctl_run+0xd81/0x1c70\n kvm_vcpu_ioctl+0x267/0x670\n __x64_sys_ioctl+0x83/0xa0\n do_syscall_64+0x56/0x80\n entry_SYSCALL_64_after_hwframe+0x44/0xae", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47463" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/79f9bc5843142b649575f887dccdf1c07ad75c20" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b77ba1e02345bafd703f0d407bdbd88c3be1f767" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T07:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-xvmj-27r5-9623/GHSA-xvmj-27r5-9623.json b/advisories/unreviewed/2024/05/GHSA-xvmj-27r5-9623/GHSA-xvmj-27r5-9623.json new file mode 100644 index 00000000000..9b6c7d20a21 --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-xvmj-27r5-9623/GHSA-xvmj-27r5-9623.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xvmj-27r5-9623", + "modified": "2024-05-22T09:31:46Z", + "published": "2024-05-22T09:31:46Z", + "aliases": [ + "CVE-2021-47488" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncgroup: Fix memory leak caused by missing cgroup_bpf_offline\n\nWhen enabling CONFIG_CGROUP_BPF, kmemleak can be observed by running\nthe command as below:\n\n $mount -t cgroup -o none,name=foo cgroup cgroup/\n $umount cgroup/\n\nunreferenced object 0xc3585c40 (size 64):\n comm \"mount\", pid 425, jiffies 4294959825 (age 31.990s)\n hex dump (first 32 bytes):\n 01 00 00 80 84 8c 28 c0 00 00 00 00 00 00 00 00 ......(.........\n 00 00 00 00 00 00 00 00 6c 43 a0 c3 00 00 00 00 ........lC......\n backtrace:\n [] cgroup_bpf_inherit+0x44/0x24c\n [<1f03679c>] cgroup_setup_root+0x174/0x37c\n [] cgroup1_get_tree+0x2c0/0x4a0\n [] vfs_get_tree+0x24/0x108\n [] path_mount+0x384/0x988\n [] do_mount+0x64/0x9c\n [<208c9cfe>] sys_mount+0xfc/0x1f4\n [<06dd06e0>] ret_fast_syscall+0x0/0x48\n [] 0xbeb4daa8\n\nThis is because that since the commit 2b0d3d3e4fcf (\"percpu_ref: reduce\nmemory footprint of percpu_ref in fast path\") root_cgrp->bpf.refcnt.data\nis allocated by the function percpu_ref_init in cgroup_bpf_inherit which\nis called by cgroup_setup_root when mounting, but not freed along with\nroot_cgrp when umounting. Adding cgroup_bpf_offline which calls\npercpu_ref_kill to cgroup_kill_sb can free root_cgrp->bpf.refcnt.data in\numount path.\n\nThis patch also fixes the commit 4bfc0bb2c60e (\"bpf: decouple the lifetime\nof cgroup_bpf from cgroup itself\"). A cgroup_bpf_offline is needed to do a\ncleanup that frees the resources which are allocated by cgroup_bpf_inherit\nin cgroup_setup_root.\n\nAnd inside cgroup_bpf_offline, cgroup_get() is at the beginning and\ncgroup_put is at the end of cgroup_bpf_release which is called by\ncgroup_bpf_offline. So cgroup_bpf_offline can keep the balance of\ncgroup's refcount.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47488" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/01599bf7cc2b49c3d2be886cb438647dc25446ed" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/04f8ef5643bcd8bcde25dfdebef998aea480b2ba" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b529f88d93884cf8ccafda793ee3d27b82fa578d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T09:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/05/GHSA-xwj2-c9hw-p6p6/GHSA-xwj2-c9hw-p6p6.json b/advisories/unreviewed/2024/05/GHSA-xwj2-c9hw-p6p6/GHSA-xwj2-c9hw-p6p6.json new file mode 100644 index 00000000000..2ce505391ab --- /dev/null +++ b/advisories/unreviewed/2024/05/GHSA-xwj2-c9hw-p6p6/GHSA-xwj2-c9hw-p6p6.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xwj2-c9hw-p6p6", + "modified": "2024-05-22T09:31:46Z", + "published": "2024-05-22T09:31:45Z", + "aliases": [ + "CVE-2021-47466" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm, slub: fix potential memoryleak in kmem_cache_open()\n\nIn error path, the random_seq of slub cache might be leaked. Fix this\nby using __kmem_cache_release() to release all the relevant resources.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-47466" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/42b81946e3ac9ea0372ba16e05160dc11e02694f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4f5d1c29cfab5cb0ab885059818751bdef32e2bb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/568f906340b43120abd6fcc67c37396482f85930" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9037c57681d25e4dcc442d940d6dbe24dd31f461" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-05-22T07:15:11Z" + } +} \ No newline at end of file