From c85db383eb9b2792d7235b1f6ff65dbff6c0e9bc Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 8 May 2025 09:32:33 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-2jfj-pqmf-3wq3.json | 37 ++++++++++++ .../GHSA-3c86-6wjp-hf8m.json | 45 +++++++++++++++ .../GHSA-3g6q-j56q-qw54.json | 41 +++++++++++++ .../GHSA-3j4j-xg7r-jh7c.json | 36 ++++++++++++ .../GHSA-3vhw-gffp-6qr6.json | 37 ++++++++++++ .../GHSA-42fq-x79v-5vv5.json | 53 +++++++++++++++++ .../GHSA-4q4q-jv3m-fqjr.json | 45 +++++++++++++++ .../GHSA-4x4p-c635-2m6r.json | 37 ++++++++++++ .../GHSA-5427-cfr3-v9jm.json | 45 +++++++++++++++ .../GHSA-56c5-8gc7-wj67.json | 37 ++++++++++++ .../GHSA-5c72-frqm-r8r4.json | 41 +++++++++++++ .../GHSA-6qhx-rx44-6465.json | 37 ++++++++++++ .../GHSA-73cw-j3wh-rf6g.json | 37 ++++++++++++ .../GHSA-7mcp-f35c-w4mw.json | 36 ++++++++++++ .../GHSA-7wf9-8x5x-fv67.json | 49 ++++++++++++++++ .../GHSA-8fxr-4vx8-rh8m.json | 49 ++++++++++++++++ .../GHSA-cr4p-cqhr-xjwp.json | 37 ++++++++++++ .../GHSA-f4v2-fv46-7wx2.json | 57 +++++++++++++++++++ .../GHSA-fg4q-8p94-mj4j.json | 49 ++++++++++++++++ .../GHSA-gr82-7xxj-rqx8.json | 57 +++++++++++++++++++ .../GHSA-hf6g-cq6h-j3vg.json | 57 +++++++++++++++++++ .../GHSA-j5r6-fgq5-9wcx.json | 57 +++++++++++++++++++ .../GHSA-j7r8-r87g-9m3j.json | 44 ++++++++++++++ .../GHSA-jc2j-hqm3-7764.json | 37 ++++++++++++ .../GHSA-jmf7-45hm-82v2.json | 37 ++++++++++++ .../GHSA-jq2v-j4fw-m4mg.json | 33 +++++++++++ .../GHSA-mcjv-6q8c-83q6.json | 33 +++++++++++ .../GHSA-mcvh-54mc-g3gg.json | 36 ++++++++++++ .../GHSA-mr75-wq82-9hcw.json | 41 +++++++++++++ .../GHSA-p285-vxm3-73m7.json | 41 +++++++++++++ .../GHSA-pfmc-fx47-cpg8.json | 37 ++++++++++++ .../GHSA-qmpq-8rmr-c5hm.json | 36 ++++++++++++ .../GHSA-rc74-9j9p-c3xp.json | 41 +++++++++++++ .../GHSA-rpfr-3prf-w7f2.json | 57 +++++++++++++++++++ .../GHSA-v2qv-w894-wvxx.json | 57 +++++++++++++++++++ .../GHSA-v5fm-w222-68gq.json | 57 +++++++++++++++++++ .../GHSA-vjw7-4w34-rrq4.json | 37 ++++++++++++ .../GHSA-vp37-f5jx-gpcx.json | 45 +++++++++++++++ .../GHSA-wp83-78c2-q7f9.json | 41 +++++++++++++ .../GHSA-wrch-r746-jf7c.json | 37 ++++++++++++ 40 files changed, 1723 insertions(+) create mode 100644 advisories/unreviewed/2025/05/GHSA-2jfj-pqmf-3wq3/GHSA-2jfj-pqmf-3wq3.json create mode 100644 advisories/unreviewed/2025/05/GHSA-3c86-6wjp-hf8m/GHSA-3c86-6wjp-hf8m.json create mode 100644 advisories/unreviewed/2025/05/GHSA-3g6q-j56q-qw54/GHSA-3g6q-j56q-qw54.json create mode 100644 advisories/unreviewed/2025/05/GHSA-3j4j-xg7r-jh7c/GHSA-3j4j-xg7r-jh7c.json create mode 100644 advisories/unreviewed/2025/05/GHSA-3vhw-gffp-6qr6/GHSA-3vhw-gffp-6qr6.json create mode 100644 advisories/unreviewed/2025/05/GHSA-42fq-x79v-5vv5/GHSA-42fq-x79v-5vv5.json create mode 100644 advisories/unreviewed/2025/05/GHSA-4q4q-jv3m-fqjr/GHSA-4q4q-jv3m-fqjr.json create mode 100644 advisories/unreviewed/2025/05/GHSA-4x4p-c635-2m6r/GHSA-4x4p-c635-2m6r.json create mode 100644 advisories/unreviewed/2025/05/GHSA-5427-cfr3-v9jm/GHSA-5427-cfr3-v9jm.json create mode 100644 advisories/unreviewed/2025/05/GHSA-56c5-8gc7-wj67/GHSA-56c5-8gc7-wj67.json create mode 100644 advisories/unreviewed/2025/05/GHSA-5c72-frqm-r8r4/GHSA-5c72-frqm-r8r4.json create mode 100644 advisories/unreviewed/2025/05/GHSA-6qhx-rx44-6465/GHSA-6qhx-rx44-6465.json create mode 100644 advisories/unreviewed/2025/05/GHSA-73cw-j3wh-rf6g/GHSA-73cw-j3wh-rf6g.json create mode 100644 advisories/unreviewed/2025/05/GHSA-7mcp-f35c-w4mw/GHSA-7mcp-f35c-w4mw.json create mode 100644 advisories/unreviewed/2025/05/GHSA-7wf9-8x5x-fv67/GHSA-7wf9-8x5x-fv67.json create mode 100644 advisories/unreviewed/2025/05/GHSA-8fxr-4vx8-rh8m/GHSA-8fxr-4vx8-rh8m.json create mode 100644 advisories/unreviewed/2025/05/GHSA-cr4p-cqhr-xjwp/GHSA-cr4p-cqhr-xjwp.json create mode 100644 advisories/unreviewed/2025/05/GHSA-f4v2-fv46-7wx2/GHSA-f4v2-fv46-7wx2.json create mode 100644 advisories/unreviewed/2025/05/GHSA-fg4q-8p94-mj4j/GHSA-fg4q-8p94-mj4j.json create mode 100644 advisories/unreviewed/2025/05/GHSA-gr82-7xxj-rqx8/GHSA-gr82-7xxj-rqx8.json create mode 100644 advisories/unreviewed/2025/05/GHSA-hf6g-cq6h-j3vg/GHSA-hf6g-cq6h-j3vg.json create mode 100644 advisories/unreviewed/2025/05/GHSA-j5r6-fgq5-9wcx/GHSA-j5r6-fgq5-9wcx.json create mode 100644 advisories/unreviewed/2025/05/GHSA-j7r8-r87g-9m3j/GHSA-j7r8-r87g-9m3j.json create mode 100644 advisories/unreviewed/2025/05/GHSA-jc2j-hqm3-7764/GHSA-jc2j-hqm3-7764.json create mode 100644 advisories/unreviewed/2025/05/GHSA-jmf7-45hm-82v2/GHSA-jmf7-45hm-82v2.json create mode 100644 advisories/unreviewed/2025/05/GHSA-jq2v-j4fw-m4mg/GHSA-jq2v-j4fw-m4mg.json create mode 100644 advisories/unreviewed/2025/05/GHSA-mcjv-6q8c-83q6/GHSA-mcjv-6q8c-83q6.json create mode 100644 advisories/unreviewed/2025/05/GHSA-mcvh-54mc-g3gg/GHSA-mcvh-54mc-g3gg.json create mode 100644 advisories/unreviewed/2025/05/GHSA-mr75-wq82-9hcw/GHSA-mr75-wq82-9hcw.json create mode 100644 advisories/unreviewed/2025/05/GHSA-p285-vxm3-73m7/GHSA-p285-vxm3-73m7.json create mode 100644 advisories/unreviewed/2025/05/GHSA-pfmc-fx47-cpg8/GHSA-pfmc-fx47-cpg8.json create mode 100644 advisories/unreviewed/2025/05/GHSA-qmpq-8rmr-c5hm/GHSA-qmpq-8rmr-c5hm.json create mode 100644 advisories/unreviewed/2025/05/GHSA-rc74-9j9p-c3xp/GHSA-rc74-9j9p-c3xp.json create mode 100644 advisories/unreviewed/2025/05/GHSA-rpfr-3prf-w7f2/GHSA-rpfr-3prf-w7f2.json create mode 100644 advisories/unreviewed/2025/05/GHSA-v2qv-w894-wvxx/GHSA-v2qv-w894-wvxx.json create mode 100644 advisories/unreviewed/2025/05/GHSA-v5fm-w222-68gq/GHSA-v5fm-w222-68gq.json create mode 100644 advisories/unreviewed/2025/05/GHSA-vjw7-4w34-rrq4/GHSA-vjw7-4w34-rrq4.json create mode 100644 advisories/unreviewed/2025/05/GHSA-vp37-f5jx-gpcx/GHSA-vp37-f5jx-gpcx.json create mode 100644 advisories/unreviewed/2025/05/GHSA-wp83-78c2-q7f9/GHSA-wp83-78c2-q7f9.json create mode 100644 advisories/unreviewed/2025/05/GHSA-wrch-r746-jf7c/GHSA-wrch-r746-jf7c.json diff --git a/advisories/unreviewed/2025/05/GHSA-2jfj-pqmf-3wq3/GHSA-2jfj-pqmf-3wq3.json b/advisories/unreviewed/2025/05/GHSA-2jfj-pqmf-3wq3/GHSA-2jfj-pqmf-3wq3.json new file mode 100644 index 00000000000..df90d1b4659 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-2jfj-pqmf-3wq3/GHSA-2jfj-pqmf-3wq3.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2jfj-pqmf-3wq3", + "modified": "2025-05-08T09:30:25Z", + "published": "2025-05-08T09:30:25Z", + "aliases": [ + "CVE-2025-37827" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: zoned: return EIO on RAID1 block group write pointer mismatch\n\nThere was a bug report about a NULL pointer dereference in\n__btrfs_add_free_space_zoned() that ultimately happens because a\nconversion from the default metadata profile DUP to a RAID1 profile on two\ndisks.\n\nThe stack trace has the following signature:\n\n BTRFS error (device sdc): zoned: write pointer offset mismatch of zones in raid1 profile\n BUG: kernel NULL pointer dereference, address: 0000000000000058\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\n PGD 0 P4D 0\n Oops: Oops: 0000 [#1] PREEMPT SMP NOPTI\n RIP: 0010:__btrfs_add_free_space_zoned.isra.0+0x61/0x1a0\n RSP: 0018:ffffa236b6f3f6d0 EFLAGS: 00010246\n RAX: 0000000000000000 RBX: ffff96c8132f3400 RCX: 0000000000000001\n RDX: 0000000010000000 RSI: 0000000000000000 RDI: ffff96c8132f3410\n RBP: 0000000010000000 R08: 0000000000000003 R09: 0000000000000000\n R10: 0000000000000000 R11: 00000000ffffffff R12: 0000000000000000\n R13: ffff96c758f65a40 R14: 0000000000000001 R15: 000011aac0000000\n FS: 00007fdab1cb2900(0000) GS:ffff96e60ca00000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 0000000000000058 CR3: 00000001a05ae000 CR4: 0000000000350ef0\n Call Trace:\n \n ? __die_body.cold+0x19/0x27\n ? page_fault_oops+0x15c/0x2f0\n ? exc_page_fault+0x7e/0x180\n ? asm_exc_page_fault+0x26/0x30\n ? __btrfs_add_free_space_zoned.isra.0+0x61/0x1a0\n btrfs_add_free_space_async_trimmed+0x34/0x40\n btrfs_add_new_free_space+0x107/0x120\n btrfs_make_block_group+0x104/0x2b0\n btrfs_create_chunk+0x977/0xf20\n btrfs_chunk_alloc+0x174/0x510\n ? srso_return_thunk+0x5/0x5f\n btrfs_inc_block_group_ro+0x1b1/0x230\n btrfs_relocate_block_group+0x9e/0x410\n btrfs_relocate_chunk+0x3f/0x130\n btrfs_balance+0x8ac/0x12b0\n ? srso_return_thunk+0x5/0x5f\n ? srso_return_thunk+0x5/0x5f\n ? __kmalloc_cache_noprof+0x14c/0x3e0\n btrfs_ioctl+0x2686/0x2a80\n ? srso_return_thunk+0x5/0x5f\n ? ioctl_has_perm.constprop.0.isra.0+0xd2/0x120\n __x64_sys_ioctl+0x97/0xc0\n do_syscall_64+0x82/0x160\n ? srso_return_thunk+0x5/0x5f\n ? __memcg_slab_free_hook+0x11a/0x170\n ? srso_return_thunk+0x5/0x5f\n ? kmem_cache_free+0x3f0/0x450\n ? srso_return_thunk+0x5/0x5f\n ? srso_return_thunk+0x5/0x5f\n ? syscall_exit_to_user_mode+0x10/0x210\n ? srso_return_thunk+0x5/0x5f\n ? do_syscall_64+0x8e/0x160\n ? sysfs_emit+0xaf/0xc0\n ? srso_return_thunk+0x5/0x5f\n ? srso_return_thunk+0x5/0x5f\n ? seq_read_iter+0x207/0x460\n ? srso_return_thunk+0x5/0x5f\n ? vfs_read+0x29c/0x370\n ? srso_return_thunk+0x5/0x5f\n ? srso_return_thunk+0x5/0x5f\n ? syscall_exit_to_user_mode+0x10/0x210\n ? srso_return_thunk+0x5/0x5f\n ? do_syscall_64+0x8e/0x160\n ? srso_return_thunk+0x5/0x5f\n ? exc_page_fault+0x7e/0x180\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n RIP: 0033:0x7fdab1e0ca6d\n RSP: 002b:00007ffeb2b60c80 EFLAGS: 00000246 ORIG_RAX: 0000000000000010\n RAX: ffffffffffffffda RBX: 0000000000000003 RCX: 00007fdab1e0ca6d\n RDX: 00007ffeb2b60d80 RSI: 00000000c4009420 RDI: 0000000000000003\n RBP: 00007ffeb2b60cd0 R08: 0000000000000000 R09: 0000000000000013\n R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000\n R13: 00007ffeb2b6343b R14: 00007ffeb2b60d80 R15: 0000000000000001\n \n CR2: 0000000000000058\n ---[ end trace 0000000000000000 ]---\n\nThe 1st line is the most interesting here:\n\n BTRFS error (device sdc): zoned: write pointer offset mismatch of zones in raid1 profile\n\nWhen a RAID1 block-group is created and a write pointer mismatch between\nthe disks in the RAID set is detected, btrfs sets the alloc_offset to the\nlength of the block group marking it as full. Afterwards the code expects\nthat a balance operation will evacuate the data in this block-group and\nrepair the problems.\n\nBut before this is possible, the new space of this block-group will be\naccounted in the free space cache. But in __btrfs_\n---truncated---", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37827" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9a447f748f6c7287dad68fa91913cd382fa0fcc8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b0c26f47992672661340dd6ea931240213016609" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f4717a02cc422cf4bb2dbb280b154a1ae65c5f84" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T07:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-3c86-6wjp-hf8m/GHSA-3c86-6wjp-hf8m.json b/advisories/unreviewed/2025/05/GHSA-3c86-6wjp-hf8m/GHSA-3c86-6wjp-hf8m.json new file mode 100644 index 00000000000..92c20166842 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-3c86-6wjp-hf8m/GHSA-3c86-6wjp-hf8m.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3c86-6wjp-hf8m", + "modified": "2025-05-08T09:30:24Z", + "published": "2025-05-08T09:30:24Z", + "aliases": [ + "CVE-2025-37815" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmisc: microchip: pci1xxxx: Fix Kernel panic during IRQ handler registration\n\nResolve kernel panic while accessing IRQ handler associated with the\ngenerated IRQ. This is done by acquiring the spinlock and storing the\ncurrent interrupt state before handling the interrupt request using\ngeneric_handle_irq.\n\nA previous fix patch was submitted where 'generic_handle_irq' was\nreplaced with 'handle_nested_irq'. However, this change also causes\nthe kernel panic where after determining which GPIO triggered the\ninterrupt and attempting to call handle_nested_irq with the mapped\nIRQ number, leads to a failure in locating the registered handler.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37815" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1263d5f581908602c618c6665e683c4436383a09" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/12cc2193f2b9548e8ea5fbce8201b44158222edf" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/18eb77c75ed01439f96ae5c0f33461eb5134b907" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4e02059dc91068bc5017b8546f9ec3b930f6d6a6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/62957f58ab3aa7fa792dc6ff3575624062539a4d" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T07:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-3g6q-j56q-qw54/GHSA-3g6q-j56q-qw54.json b/advisories/unreviewed/2025/05/GHSA-3g6q-j56q-qw54/GHSA-3g6q-j56q-qw54.json new file mode 100644 index 00000000000..f04cf6c38fb --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-3g6q-j56q-qw54/GHSA-3g6q-j56q-qw54.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3g6q-j56q-qw54", + "modified": "2025-05-08T09:30:23Z", + "published": "2025-05-08T09:30:23Z", + "aliases": [ + "CVE-2025-37800" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndriver core: fix potential NULL pointer dereference in dev_uevent()\n\nIf userspace reads \"uevent\" device attribute at the same time as another\nthreads unbinds the device from its driver, change to dev->driver from a\nvalid pointer to NULL may result in crash. Fix this by using READ_ONCE()\nwhen fetching the pointer, and take bus' drivers klist lock to make sure\ndriver instance will not disappear while we access it.\n\nUse WRITE_ONCE() when setting the driver pointer to ensure there is no\ntearing.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37800" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/18daa52418e7e4629ed1703b64777294209d2622" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2b344e779d9afd0fcb5ee4000e4d0fc7d8d867eb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3781e4b83e174364998855de777e184cf0b62c40" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/abe56be73eb10a677d16066f65ff9d30251f5eee" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T07:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-3j4j-xg7r-jh7c/GHSA-3j4j-xg7r-jh7c.json b/advisories/unreviewed/2025/05/GHSA-3j4j-xg7r-jh7c/GHSA-3j4j-xg7r-jh7c.json new file mode 100644 index 00000000000..b7eb92415dc --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-3j4j-xg7r-jh7c/GHSA-3j4j-xg7r-jh7c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3j4j-xg7r-jh7c", + "modified": "2025-05-08T09:30:25Z", + "published": "2025-05-08T09:30:25Z", + "aliases": [ + "CVE-2025-1253" + ], + "details": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags.This issue affects Connext Professional: from 7.4.0 before 7.5.0, from 7.0.0 before 7.3.0.7, from 4.5 before 6.1.2.23.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1253" + }, + { + "type": "WEB", + "url": "https://www.rti.com/vulnerabilities/#cve-2025-1253" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T09:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-3vhw-gffp-6qr6/GHSA-3vhw-gffp-6qr6.json b/advisories/unreviewed/2025/05/GHSA-3vhw-gffp-6qr6/GHSA-3vhw-gffp-6qr6.json new file mode 100644 index 00000000000..22e789acdcd --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-3vhw-gffp-6qr6/GHSA-3vhw-gffp-6qr6.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3vhw-gffp-6qr6", + "modified": "2025-05-08T09:30:25Z", + "published": "2025-05-08T09:30:25Z", + "aliases": [ + "CVE-2025-37833" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/niu: Niu requires MSIX ENTRY_DATA fields touch before entry reads\n\nFix niu_try_msix() to not cause a fatal trap on sparc systems.\n\nSet PCI_DEV_FLAGS_MSIX_TOUCH_ENTRY_DATA_FIRST on the struct pci_dev to\nwork around a bug in the hardware or firmware.\n\nFor each vector entry in the msix table, niu chips will cause a fatal\ntrap if any registers in that entry are read before that entries'\nENTRY_DATA register is written to. Testing indicates writes to other\nregisters are not sufficient to prevent the fatal trap, however the value\ndoes not appear to matter. This only needs to happen once after power up,\nso simply rebooting into a kernel lacking this fix will NOT cause the\ntrap.\n\nNON-RESUMABLE ERROR: Reporting on cpu 64\nNON-RESUMABLE ERROR: TPC [0x00000000005f6900] \nNON-RESUMABLE ERROR: RAW [4010000000000016:00000e37f93e32ff:0000000202000080:ffffffffffffffff\nNON-RESUMABLE ERROR: 0000000800000000:0000000000000000:0000000000000000:0000000000000000]\nNON-RESUMABLE ERROR: handle [0x4010000000000016] stick [0x00000e37f93e32ff]\nNON-RESUMABLE ERROR: type [precise nonresumable]\nNON-RESUMABLE ERROR: attrs [0x02000080] < ASI sp-faulted priv >\nNON-RESUMABLE ERROR: raddr [0xffffffffffffffff]\nNON-RESUMABLE ERROR: insn effective address [0x000000c50020000c]\nNON-RESUMABLE ERROR: size [0x8]\nNON-RESUMABLE ERROR: asi [0x00]\nCPU: 64 UID: 0 PID: 745 Comm: kworker/64:1 Not tainted 6.11.5 #63\nWorkqueue: events work_for_cpu_fn\nTSTATE: 0000000011001602 TPC: 00000000005f6900 TNPC: 00000000005f6904 Y: 00000000 Not tainted\nTPC: \ng0: 00000000000002e9 g1: 000000000000000c g2: 000000c50020000c g3: 0000000000000100\ng4: ffff8000470307c0 g5: ffff800fec5be000 g6: ffff800047a08000 g7: 0000000000000000\no0: ffff800014feb000 o1: ffff800047a0b620 o2: 0000000000000011 o3: ffff800047a0b620\no4: 0000000000000080 o5: 0000000000000011 sp: ffff800047a0ad51 ret_pc: 00000000005f7128\nRPC: <__pci_enable_msix_range+0x3cc/0x460>\nl0: 000000000000000d l1: 000000000000c01f l2: ffff800014feb0a8 l3: 0000000000000020\nl4: 000000000000c000 l5: 0000000000000001 l6: 0000000020000000 l7: ffff800047a0b734\ni0: ffff800014feb000 i1: ffff800047a0b730 i2: 0000000000000001 i3: 000000000000000d\ni4: 0000000000000000 i5: 0000000000000000 i6: ffff800047a0ae81 i7: 00000000101888b0\nI7: \nCall Trace:\n[<00000000101888b0>] niu_try_msix.constprop.0+0xc0/0x130 [niu]\n[<000000001018f840>] niu_get_invariants+0x183c/0x207c [niu]\n[<00000000101902fc>] niu_pci_init_one+0x27c/0x2fc [niu]\n[<00000000005ef3e4>] local_pci_probe+0x28/0x74\n[<0000000000469240>] work_for_cpu_fn+0x8/0x1c\n[<000000000046b008>] process_scheduled_works+0x144/0x210\n[<000000000046b518>] worker_thread+0x13c/0x1c0\n[<00000000004710e0>] kthread+0xb8/0xc8\n[<00000000004060c8>] ret_from_fork+0x1c/0x2c\n[<0000000000000000>] 0x0\nKernel panic - not syncing: Non-resumable error.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37833" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/64903e4849a71cf7f7c7e5d45225ccefc1280929" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c187aaa9e79b4b6d86ac7ba941e579ad33df5538" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fbb429ddff5c8e479edcc7dde5a542c9295944e6" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T07:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-42fq-x79v-5vv5/GHSA-42fq-x79v-5vv5.json b/advisories/unreviewed/2025/05/GHSA-42fq-x79v-5vv5/GHSA-42fq-x79v-5vv5.json new file mode 100644 index 00000000000..ae3c64d1179 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-42fq-x79v-5vv5/GHSA-42fq-x79v-5vv5.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-42fq-x79v-5vv5", + "modified": "2025-05-08T09:30:23Z", + "published": "2025-05-08T09:30:23Z", + "aliases": [ + "CVE-2025-37803" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nudmabuf: fix a buf size overflow issue during udmabuf creation\n\nby casting size_limit_mb to u64 when calculate pglimit.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37803" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/021ba7f1babd029e714d13a6bf2571b08af96d0f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/13fe12c037b470321436deec393030c6153cfeb9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2b8419c6ecf69007dcff54ea0b9f0b215282c55a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/373512760e13fdaa726faa9502d0f5be2abb3d33" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3f6c9d66e0f8eb9679b57913aa64b4d2266f6fbe" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b2ff4e9c599b000833d16a917f519aa2e4a75de2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e84a08fc7e25cdad5d9a3def42cc770ff711193f" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T07:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-4q4q-jv3m-fqjr/GHSA-4q4q-jv3m-fqjr.json b/advisories/unreviewed/2025/05/GHSA-4q4q-jv3m-fqjr/GHSA-4q4q-jv3m-fqjr.json new file mode 100644 index 00000000000..79f8824d14e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4q4q-jv3m-fqjr/GHSA-4q4q-jv3m-fqjr.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4q4q-jv3m-fqjr", + "modified": "2025-05-08T09:30:24Z", + "published": "2025-05-08T09:30:24Z", + "aliases": [ + "CVE-2025-37818" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nLoongArch: Return NULL from huge_pte_offset() for invalid PMD\n\nLoongArch's huge_pte_offset() currently returns a pointer to a PMD slot\neven if the underlying entry points to invalid_pte_table (indicating no\nmapping). Callers like smaps_hugetlb_range() fetch this invalid entry\nvalue (the address of invalid_pte_table) via this pointer.\n\nThe generic is_swap_pte() check then incorrectly identifies this address\nas a swap entry on LoongArch, because it satisfies the \"!pte_present()\n&& !pte_none()\" conditions. This misinterpretation, combined with a\ncoincidental match by is_migration_entry() on the address bits, leads to\nkernel crashes in pfn_swap_entry_to_page().\n\nFix this at the architecture level by modifying huge_pte_offset() to\ncheck the PMD entry's content using pmd_none() before returning. If the\nentry is invalid (i.e., it points to invalid_pte_table), return NULL\ninstead of the pointer to the slot.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37818" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2ca9380b12711afe95b3589bd82b59623b3c96b3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/34256805720993e37adf6127371a1265aea8376a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/51424fd171cee6a33f01f7c66b8eb23ac42289d4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b49f085cd671addbda4802d6b9382513f7dd0f30" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bd51834d1cf65a2c801295d230c220aeebf87a73" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T07:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-4x4p-c635-2m6r/GHSA-4x4p-c635-2m6r.json b/advisories/unreviewed/2025/05/GHSA-4x4p-c635-2m6r/GHSA-4x4p-c635-2m6r.json new file mode 100644 index 00000000000..5a5645e83d0 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4x4p-c635-2m6r/GHSA-4x4p-c635-2m6r.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4x4p-c635-2m6r", + "modified": "2025-05-08T09:30:24Z", + "published": "2025-05-08T09:30:24Z", + "aliases": [ + "CVE-2025-37816" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmei: vsc: Fix fortify-panic caused by invalid counted_by() use\n\ngcc 15 honors the __counted_by(len) attribute on vsc_tp_packet.buf[]\nand the vsc-tp.c code is using this in a wrong way. len does not contain\nthe available size in the buffer, it contains the actual packet length\n*without* the crc. So as soon as vsc_tp_xfer() tries to add the crc to\nbuf[] the fortify-panic handler gets triggered:\n\n[ 80.842193] memcpy: detected buffer overflow: 4 byte write of buffer size 0\n[ 80.842243] WARNING: CPU: 4 PID: 272 at lib/string_helpers.c:1032 __fortify_report+0x45/0x50\n...\n[ 80.843175] __fortify_panic+0x9/0xb\n[ 80.843186] vsc_tp_xfer.cold+0x67/0x67 [mei_vsc_hw]\n[ 80.843210] ? seqcount_lockdep_reader_access.constprop.0+0x82/0x90\n[ 80.843229] ? lockdep_hardirqs_on+0x7c/0x110\n[ 80.843250] mei_vsc_hw_start+0x98/0x120 [mei_vsc]\n[ 80.843270] mei_reset+0x11d/0x420 [mei]\n\nThe easiest fix would be to just drop the counted-by but with the exception\nof the ack buffer in vsc_tp_xfer_helper() which only contains enough room\nfor the packet-header, all other uses of vsc_tp_packet always use a buffer\nof VSC_TP_MAX_XFER_SIZE bytes for the packet.\n\nInstead of just dropping the counted-by, split the vsc_tp_packet struct\ndefinition into a header and a full-packet definition and use a fixed\nsize buf[] in the packet definition, this way fortify-source buffer\noverrun checking still works when enabled.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37816" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/00f1cc14da0f06d2897b8c528df7c7dcf1b8da50" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3e243378f27cc7d11682a3ad720228b0723affa5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ac04663c67f244810b3492e9ecd9f7cdbefeca2d" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T07:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-5427-cfr3-v9jm/GHSA-5427-cfr3-v9jm.json b/advisories/unreviewed/2025/05/GHSA-5427-cfr3-v9jm/GHSA-5427-cfr3-v9jm.json new file mode 100644 index 00000000000..a67821003ce --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-5427-cfr3-v9jm/GHSA-5427-cfr3-v9jm.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5427-cfr3-v9jm", + "modified": "2025-05-08T09:30:25Z", + "published": "2025-05-08T09:30:25Z", + "aliases": [ + "CVE-2025-37820" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nxen-netfront: handle NULL returned by xdp_convert_buff_to_frame()\n\nThe function xdp_convert_buff_to_frame() may return NULL if it fails\nto correctly convert the XDP buffer into an XDP frame due to memory\nconstraints, internal errors, or invalid data. Failing to check for NULL\nmay lead to a NULL pointer dereference if the result is used later in\nprocessing, potentially causing crashes, data corruption, or undefined\nbehavior.\n\nOn XDP redirect failure, the associated page must be released explicitly\nif it was previously retained via get_page(). Failing to do so may result\nin a memory leak, as the pages reference count is not decremented.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37820" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5b83d30c63f9964acb1bc63eb8e670b9e0d2c240" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cc3628dcd851ddd8d418bf0c897024b4621ddc92" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cefd8a2e2de46209ce66e6d30c237eb59b6c5bfa" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d6a9c4e6f9b3ec3ad98468c950ad214af8a2efb9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/eefccd889df3b49d92e7349d94c4aa7e1ba19f6c" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T07:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-56c5-8gc7-wj67/GHSA-56c5-8gc7-wj67.json b/advisories/unreviewed/2025/05/GHSA-56c5-8gc7-wj67/GHSA-56c5-8gc7-wj67.json new file mode 100644 index 00000000000..286d73e18a9 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-56c5-8gc7-wj67/GHSA-56c5-8gc7-wj67.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-56c5-8gc7-wj67", + "modified": "2025-05-08T09:30:23Z", + "published": "2025-05-08T09:30:23Z", + "aliases": [ + "CVE-2025-37802" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix WARNING \"do not call blocking ops when !TASK_RUNNING\"\n\nwait_event_timeout() will set the state of the current\ntask to TASK_UNINTERRUPTIBLE, before doing the condition check. This\nmeans that ksmbd_durable_scavenger_alive() will try to acquire the mutex\nwhile already in a sleeping state. The scheduler warns us by giving\nthe following warning:\n\ndo not call blocking ops when !TASK_RUNNING; state=2 set at\n [<0000000061515a6f>] prepare_to_wait_event+0x9f/0x6c0\nWARNING: CPU: 2 PID: 4147 at kernel/sched/core.c:10099 __might_sleep+0x12f/0x160\n\nmutex lock is not needed in ksmbd_durable_scavenger_alive().", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37802" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1df0d4c616138784e033ad337961b6e1a6bcd999" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8f805b3746d2f41702c77cba22f94f8415fadd1a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cd161198e091e8a62b9bd631be970ea9a87d2d6a" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T07:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-5c72-frqm-r8r4/GHSA-5c72-frqm-r8r4.json b/advisories/unreviewed/2025/05/GHSA-5c72-frqm-r8r4/GHSA-5c72-frqm-r8r4.json new file mode 100644 index 00000000000..f464a46b04b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-5c72-frqm-r8r4/GHSA-5c72-frqm-r8r4.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5c72-frqm-r8r4", + "modified": "2025-05-08T09:30:25Z", + "published": "2025-05-08T09:30:25Z", + "aliases": [ + "CVE-2025-37819" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nirqchip/gic-v2m: Prevent use after free of gicv2m_get_fwnode()\n\nWith ACPI in place, gicv2m_get_fwnode() is registered with the pci\nsubsystem as pci_msi_get_fwnode_cb(), which may get invoked at runtime\nduring a PCI host bridge probe. But, the call back is wrongly marked as\n__init, causing it to be freed, while being registered with the PCI\nsubsystem and could trigger:\n\n Unable to handle kernel paging request at virtual address ffff8000816c0400\n gicv2m_get_fwnode+0x0/0x58 (P)\n pci_set_bus_msi_domain+0x74/0x88\n pci_register_host_bridge+0x194/0x548\n\nThis is easily reproducible on a Juno board with ACPI boot.\n\nRetain the function for later use.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37819" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2f2803e4b5e4df2b08d378deaab78b1681ef9b30" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3318dc299b072a0511d6dfd8367f3304fb6d9827" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3939d6f29d34cdb60e3f68b76e39e00a964a1d51" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/47bee0081b483b077c7560bc5358ad101f89c8ef" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T07:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-6qhx-rx44-6465/GHSA-6qhx-rx44-6465.json b/advisories/unreviewed/2025/05/GHSA-6qhx-rx44-6465/GHSA-6qhx-rx44-6465.json new file mode 100644 index 00000000000..61083b1c51a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-6qhx-rx44-6465/GHSA-6qhx-rx44-6465.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6qhx-rx44-6465", + "modified": "2025-05-08T09:30:25Z", + "published": "2025-05-08T09:30:25Z", + "aliases": [ + "CVE-2025-37832" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncpufreq: sun50i: prevent out-of-bounds access\n\nA KASAN enabled kernel reports an out-of-bounds access when handling the\nnvmem cell in the sun50i cpufreq driver:\n==================================================================\nBUG: KASAN: slab-out-of-bounds in sun50i_cpufreq_nvmem_probe+0x180/0x3d4\nRead of size 4 at addr ffff000006bf31e0 by task kworker/u16:1/38\n\nThis is because the DT specifies the nvmem cell as covering only two\nbytes, but we use a u32 pointer to read the value. DTs for other SoCs\nindeed specify 4 bytes, so we cannot just shorten the variable to a u16.\n\nFortunately nvmem_cell_read() allows to return the length of the nvmem\ncell, in bytes, so we can use that information to only access the valid\nportion of the data.\nTo cover multiple cell sizes, use memcpy() to copy the information into a\nzeroed u32 buffer, then also make sure we always read the data in little\nendian fashion, as this is how the data is stored in the SID efuses.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37832" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/14c8a418159e541d70dbf8fc71225d1623beaf0f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/40bf7f560ca4c2468d518cebf14561bc864f58f8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/dba5a1f963cf781c0b60f4b7f07465a6c687c27e" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T07:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-73cw-j3wh-rf6g/GHSA-73cw-j3wh-rf6g.json b/advisories/unreviewed/2025/05/GHSA-73cw-j3wh-rf6g/GHSA-73cw-j3wh-rf6g.json new file mode 100644 index 00000000000..162c61dde1f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-73cw-j3wh-rf6g/GHSA-73cw-j3wh-rf6g.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-73cw-j3wh-rf6g", + "modified": "2025-05-08T09:30:24Z", + "published": "2025-05-08T09:30:24Z", + "aliases": [ + "CVE-2025-37807" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Fix kmemleak warning for percpu hashmap\n\nVlad Poenaru reported the following kmemleak issue:\n\n unreferenced object 0x606fd7c44ac8 (size 32):\n backtrace (crc 0):\n pcpu_alloc_noprof+0x730/0xeb0\n bpf_map_alloc_percpu+0x69/0xc0\n prealloc_init+0x9d/0x1b0\n htab_map_alloc+0x363/0x510\n map_create+0x215/0x3a0\n __sys_bpf+0x16b/0x3e0\n __x64_sys_bpf+0x18/0x20\n do_syscall_64+0x7b/0x150\n entry_SYSCALL_64_after_hwframe+0x4b/0x53\n\nFurther investigation shows the reason is due to not 8-byte aligned\nstore of percpu pointer in htab_elem_set_ptr():\n *(void __percpu **)(l->key + key_size) = pptr;\n\nNote that the whole htab_elem alignment is 8 (for x86_64). If the key_size\nis 4, that means pptr is stored in a location which is 4 byte aligned but\nnot 8 byte aligned. In mm/kmemleak.c, scan_block() scans the memory based\non 8 byte stride, so it won't detect above pptr, hence reporting the memory\nleak.\n\nIn htab_map_alloc(), we already have\n\n htab->elem_size = sizeof(struct htab_elem) +\n round_up(htab->map.key_size, 8);\n if (percpu)\n htab->elem_size += sizeof(void *);\n else\n htab->elem_size += round_up(htab->map.value_size, 8);\n\nSo storing pptr with 8-byte alignment won't cause any problem and can fix\nkmemleak too.\n\nThe issue can be reproduced with bpf selftest as well:\n 1. Enable CONFIG_DEBUG_KMEMLEAK config\n 2. Add a getchar() before skel destroy in test_hash_map() in prog_tests/for_each.c.\n The purpose is to keep map available so kmemleak can be detected.\n 3. run './test_progs -t for_each/hash_map &' and a kmemleak should be reported.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37807" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/11ba7ce076e5903e7bdc1fd1498979c331b3c286" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1f1c29aa1934177349c17e3c32e68ec38a7a56df" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7758e308aeda1038aba1944f7302d34161b3effe" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T07:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7mcp-f35c-w4mw/GHSA-7mcp-f35c-w4mw.json b/advisories/unreviewed/2025/05/GHSA-7mcp-f35c-w4mw/GHSA-7mcp-f35c-w4mw.json new file mode 100644 index 00000000000..ca21bc49c07 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7mcp-f35c-w4mw/GHSA-7mcp-f35c-w4mw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7mcp-f35c-w4mw", + "modified": "2025-05-08T09:30:25Z", + "published": "2025-05-08T09:30:25Z", + "aliases": [ + "CVE-2025-1252" + ], + "details": "Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags.This issue affects Connext Professional: from 7.4.0 before 7.5.0, from 7.0.0 before 7.3.0.7, from 4.4 before 6.1.2.23.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1252" + }, + { + "type": "WEB", + "url": "https://www.rti.com/vulnerabilities/#cve-2025-1252" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T09:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7wf9-8x5x-fv67/GHSA-7wf9-8x5x-fv67.json b/advisories/unreviewed/2025/05/GHSA-7wf9-8x5x-fv67/GHSA-7wf9-8x5x-fv67.json new file mode 100644 index 00000000000..0a3136fc1fb --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7wf9-8x5x-fv67/GHSA-7wf9-8x5x-fv67.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7wf9-8x5x-fv67", + "modified": "2025-05-08T09:30:24Z", + "published": "2025-05-08T09:30:24Z", + "aliases": [ + "CVE-2025-37811" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: chipidea: ci_hdrc_imx: fix usbmisc handling\n\nusbmisc is an optional device property so it is totally valid for the\ncorresponding data->usbmisc_data to have a NULL value.\n\nCheck that before dereferencing the pointer.\n\nFound by Linux Verification Center (linuxtesting.org) with Svace static\nanalysis tool.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37811" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0ee460498ced49196149197c9f6d29a10e5e0798" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/121e9f80ea5478bca3a8f3f26593fd66f87da649" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2aa87bd825377f5073b76701780a902cd0fc725a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4e28f79e3dffa52d327b46d1a78dac16efb5810b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8060b719676e8c0e5a2222c2977ba0458d9d9535" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/887902ca73490f38c69fd6149ef361a041cf912f" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T07:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8fxr-4vx8-rh8m/GHSA-8fxr-4vx8-rh8m.json b/advisories/unreviewed/2025/05/GHSA-8fxr-4vx8-rh8m/GHSA-8fxr-4vx8-rh8m.json new file mode 100644 index 00000000000..69019c1cc6c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8fxr-4vx8-rh8m/GHSA-8fxr-4vx8-rh8m.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8fxr-4vx8-rh8m", + "modified": "2025-05-08T09:30:25Z", + "published": "2025-05-08T09:30:25Z", + "aliases": [ + "CVE-2025-37830" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncpufreq: scmi: Fix null-ptr-deref in scmi_cpufreq_get_rate()\n\ncpufreq_cpu_get_raw() can return NULL when the target CPU is not present\nin the policy->cpus mask. scmi_cpufreq_get_rate() does not check for\nthis case, which results in a NULL pointer dereference.\n\nAdd NULL check after cpufreq_cpu_get_raw() to prevent this issue.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37830" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/484d3f15cc6cbaa52541d6259778e715b2c83c54" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4e3d1c1925d8e752992cd893d03d974e6807ac16" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7ccfadfb2562337b4f0462a86a9746a6eea89718" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cfaca93b8fe317b7faa9af732e0ba8c9081fa018" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ea834c90aa7cc80a1b456f7a91432734d5087d16" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f9c5423855e3687262d881aeee5cfb3bc8577bff" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T07:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-cr4p-cqhr-xjwp/GHSA-cr4p-cqhr-xjwp.json b/advisories/unreviewed/2025/05/GHSA-cr4p-cqhr-xjwp/GHSA-cr4p-cqhr-xjwp.json new file mode 100644 index 00000000000..0b4b0dd818e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-cr4p-cqhr-xjwp/GHSA-cr4p-cqhr-xjwp.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cr4p-cqhr-xjwp", + "modified": "2025-05-08T09:30:25Z", + "published": "2025-05-08T09:30:25Z", + "aliases": [ + "CVE-2025-37826" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: ufs: core: Add NULL check in ufshcd_mcq_compl_pending_transfer()\n\nAdd a NULL check for the returned hwq pointer by ufshcd_mcq_req_to_hwq().\n\nThis is similar to the fix in commit 74736103fb41 (\"scsi: ufs: core: Fix\nufshcd_abort_one racing issue\").", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37826" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/08a966a917fe3d92150fa3cc15793ad5e57051eb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/700128d67d57bb1de4251e563ab85202def36c50" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/eeab6618037be84e438e9d6ed5d9a53502faf81f" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T07:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-f4v2-fv46-7wx2/GHSA-f4v2-fv46-7wx2.json b/advisories/unreviewed/2025/05/GHSA-f4v2-fv46-7wx2/GHSA-f4v2-fv46-7wx2.json new file mode 100644 index 00000000000..6d701ce6850 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-f4v2-fv46-7wx2/GHSA-f4v2-fv46-7wx2.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f4v2-fv46-7wx2", + "modified": "2025-05-08T09:30:25Z", + "published": "2025-05-08T09:30:25Z", + "aliases": [ + "CVE-2025-37829" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncpufreq: scpi: Fix null-ptr-deref in scpi_cpufreq_get_rate()\n\ncpufreq_cpu_get_raw() can return NULL when the target CPU is not present\nin the policy->cpus mask. scpi_cpufreq_get_rate() does not check for\nthis case, which results in a NULL pointer dereference.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37829" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/124bddf123311cd1f18bffd63a5d974468d59c67" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/19e0eaa62e8831f2bc0285fef3bf8faaa7f3e09b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/28fbd7b13b4d3074b16db913aedc9d8d37ab41e7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/73b24dc731731edf762f9454552cb3a5b7224949" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8fbaa76690f67a7cbad315f89d607b46e3e06ede" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ad4796f2da495b2cbbd0fccccbcbf63f2aeee613" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/da8ee91e532486055ecf88478d38c2f3dc234182" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fdf035d9c5436536ffcfea0ac6adeb5dda3c3a23" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T07:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-fg4q-8p94-mj4j/GHSA-fg4q-8p94-mj4j.json b/advisories/unreviewed/2025/05/GHSA-fg4q-8p94-mj4j/GHSA-fg4q-8p94-mj4j.json new file mode 100644 index 00000000000..dc5a50200ca --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-fg4q-8p94-mj4j/GHSA-fg4q-8p94-mj4j.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fg4q-8p94-mj4j", + "modified": "2025-05-08T09:30:24Z", + "published": "2025-05-08T09:30:23Z", + "aliases": [ + "CVE-2025-37805" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsound/virtio: Fix cancel_sync warnings on uninitialized work_structs\n\nBetty reported hitting the following warning:\n\n[ 8.709131][ T221] WARNING: CPU: 2 PID: 221 at kernel/workqueue.c:4182\n...\n[ 8.713282][ T221] Call trace:\n[ 8.713365][ T221] __flush_work+0x8d0/0x914\n[ 8.713468][ T221] __cancel_work_sync+0xac/0xfc\n[ 8.713570][ T221] cancel_work_sync+0x24/0x34\n[ 8.713667][ T221] virtsnd_remove+0xa8/0xf8 [virtio_snd ab15f34d0dd772f6d11327e08a81d46dc9c36276]\n[ 8.713868][ T221] virtsnd_probe+0x48c/0x664 [virtio_snd ab15f34d0dd772f6d11327e08a81d46dc9c36276]\n[ 8.714035][ T221] virtio_dev_probe+0x28c/0x390\n[ 8.714139][ T221] really_probe+0x1bc/0x4c8\n...\n\nIt seems we're hitting the error path in virtsnd_probe(), which\ntriggers a virtsnd_remove() which iterates over the substreams\ncalling cancel_work_sync() on the elapsed_period work_struct.\n\nLooking at the code, from earlier in:\nvirtsnd_probe()->virtsnd_build_devs()->virtsnd_pcm_parse_cfg()\n\nWe set snd->nsubstreams, allocate the snd->substreams, and if\nwe then hit an error on the info allocation or something in\nvirtsnd_ctl_query_info() fails, we will exit without having\ninitialized the elapsed_period work_struct.\n\nWhen that error path unwinds we then call virtsnd_remove()\nwhich as long as the substreams array is allocated, will iterate\nthrough calling cancel_work_sync() on the uninitialized work\nstruct hitting this warning.\n\nTakashi Iwai suggested this fix, which initializes the substreams\nstructure right after allocation, so that if we hit the error\npaths we avoid trying to cleanup uninitialized data.\n\nNote: I have not yet managed to reproduce the issue myself, so\nthis patch has had limited testing.\n\nFeedback or thoughts would be appreciated!", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37805" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3c7df2e27346eb40a0e86230db1ccab195c97cfe" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/54c7b864fbe4423a07b443a4ada0106052942116" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5be9407b41eae20eef9140f5cfbfcbc3d01aaf45" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/66046b586c0aaa9332483bcdbd76e3305d6138e9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9908498ce929a5a052b79bb7942f9ea317312ce4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e03b10c45c7675b6098190c6e7de1b656d8bcdbe" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T07:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-gr82-7xxj-rqx8/GHSA-gr82-7xxj-rqx8.json b/advisories/unreviewed/2025/05/GHSA-gr82-7xxj-rqx8/GHSA-gr82-7xxj-rqx8.json new file mode 100644 index 00000000000..f63702a0f04 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-gr82-7xxj-rqx8/GHSA-gr82-7xxj-rqx8.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gr82-7xxj-rqx8", + "modified": "2025-05-08T09:30:25Z", + "published": "2025-05-08T09:30:25Z", + "aliases": [ + "CVE-2025-37823" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet_sched: hfsc: Fix a potential UAF in hfsc_dequeue() too\n\nSimilarly to the previous patch, we need to safe guard hfsc_dequeue()\ntoo. But for this one, we don't have a reliable reproducer.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37823" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/11bccb054c1462fb069219f8e98e97a5a730758e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2f46d14919c39528c6e540ebc43f90055993eedc" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/68f256305ceb426d545a0dc31f83c2ab1d211a1e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6ccbda44e2cc3d26fd22af54c650d6d5d801addf" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/76c4c22c2437d3d3880efc0f62eca06ef078d290" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c6936266f8bf98a53f28ef9a820e6a501e946d09" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c6f035044104c6ff656f4565cd22938dc892528c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/da7936518996d290e2fcfcaf6cd7e15bfd87804a" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T07:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hf6g-cq6h-j3vg/GHSA-hf6g-cq6h-j3vg.json b/advisories/unreviewed/2025/05/GHSA-hf6g-cq6h-j3vg/GHSA-hf6g-cq6h-j3vg.json new file mode 100644 index 00000000000..f064486170a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-hf6g-cq6h-j3vg/GHSA-hf6g-cq6h-j3vg.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hf6g-cq6h-j3vg", + "modified": "2025-05-08T09:30:24Z", + "published": "2025-05-08T09:30:24Z", + "aliases": [ + "CVE-2025-37808" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: null - Use spin lock instead of mutex\n\nAs the null algorithm may be freed in softirq context through\naf_alg, use spin locks instead of mutexes to protect the default\nnull algorithm.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37808" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0486de3c1b8223138dcc614846bd76364f758de6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1b66a5920b7fc7cc6251192a3fcad115b6d75dd5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1dd4a8561d85dea545cf93f56efc48df8176e218" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8cf2945512a8c0ef74ddd5b5a4f6b6a2fb1a4efb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/dcc47a028c24e793ce6d6efebfef1a1e92f80297" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e27244cbe10658a66b8775be7f0acc4ad2f618d6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e307c54ac8198bf09652c72603ba6e6d97798410" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f7a5a5c8e1ec16a4b2041398abe95de0e14572ef" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T07:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-j5r6-fgq5-9wcx/GHSA-j5r6-fgq5-9wcx.json b/advisories/unreviewed/2025/05/GHSA-j5r6-fgq5-9wcx/GHSA-j5r6-fgq5-9wcx.json new file mode 100644 index 00000000000..3e3148e4f68 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-j5r6-fgq5-9wcx/GHSA-j5r6-fgq5-9wcx.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j5r6-fgq5-9wcx", + "modified": "2025-05-08T09:30:24Z", + "published": "2025-05-08T09:30:24Z", + "aliases": [ + "CVE-2025-37817" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmcb: fix a double free bug in chameleon_parse_gdd()\n\nIn chameleon_parse_gdd(), if mcb_device_register() fails, 'mdev'\nwould be released in mcb_device_register() via put_device().\nThus, goto 'err' label and free 'mdev' again causes a double free.\nJust return if mcb_device_register() fails.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37817" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4ffe8c9fb561e4427dd1a3056cd5b3685b74f78d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/59f993cd36b6e28a394ba3d977e8ffe5c9884e3b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7c7f1bfdb2249f854a736d9b79778c7e5a29a150" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/96838eb1836fd372e42be5db84f0b333b65146a6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bcc7d58ee5173e34306026bd01e1fbf75e169d37" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c5b8a549ef1fcc6066b037a3962c79d60465ba0b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d70184958b0ea8c0fd52e2b456654b503e769fc8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/df1a5d5c6134224f9298e5189230f9d29ae50cac" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T07:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-j7r8-r87g-9m3j/GHSA-j7r8-r87g-9m3j.json b/advisories/unreviewed/2025/05/GHSA-j7r8-r87g-9m3j/GHSA-j7r8-r87g-9m3j.json new file mode 100644 index 00000000000..2581206eadd --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-j7r8-r87g-9m3j/GHSA-j7r8-r87g-9m3j.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j7r8-r87g-9m3j", + "modified": "2025-05-08T09:30:25Z", + "published": "2025-05-08T09:30:25Z", + "aliases": [ + "CVE-2025-4127" + ], + "details": "The WP SEO Structured Data Schema plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Price Range’ parameter in all versions up to, and including, 2.7.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts that will execute whenever an administrator accesses the plugin settings page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4127" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wp-seo-structured-data-schema/trunk/lib/classes/KcSeoHelper.php#L7" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3289009/wp-seo-structured-data-schema" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/24f6c4e4-11c3-476f-9f50-42053b625ab8?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T07:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-jc2j-hqm3-7764/GHSA-jc2j-hqm3-7764.json b/advisories/unreviewed/2025/05/GHSA-jc2j-hqm3-7764/GHSA-jc2j-hqm3-7764.json new file mode 100644 index 00000000000..a590e196a4f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-jc2j-hqm3-7764/GHSA-jc2j-hqm3-7764.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jc2j-hqm3-7764", + "modified": "2025-05-08T09:30:25Z", + "published": "2025-05-08T09:30:25Z", + "aliases": [ + "CVE-2025-37822" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nriscv: uprobes: Add missing fence.i after building the XOL buffer\n\nThe XOL (execute out-of-line) buffer is used to single-step the\nreplaced instruction(s) for uprobes. The RISC-V port was missing a\nproper fence.i (i$ flushing) after constructing the XOL buffer, which\ncan result in incorrect execution of stale/broken instructions.\n\nThis was found running the BPF selftests \"test_progs:\nuprobe_autoattach, attach_probe\" on the Spacemit K1/X60, where the\nuprobes tests randomly blew up.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37822" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1dbb95a36499374c51b47ee8ae258a8862c20978" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7d1d19a11cfbfd8bae1d89cc010b2cc397cd0c48" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bcf6d3158c5902d92b6d62335af4422b7bf7c4e2" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T07:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-jmf7-45hm-82v2/GHSA-jmf7-45hm-82v2.json b/advisories/unreviewed/2025/05/GHSA-jmf7-45hm-82v2/GHSA-jmf7-45hm-82v2.json new file mode 100644 index 00000000000..509986fe98b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-jmf7-45hm-82v2/GHSA-jmf7-45hm-82v2.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jmf7-45hm-82v2", + "modified": "2025-05-08T09:30:25Z", + "published": "2025-05-08T09:30:25Z", + "aliases": [ + "CVE-2025-37834" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/vmscan: don't try to reclaim hwpoison folio\n\nSyzkaller reports a bug as follows:\n\nInjecting memory failure for pfn 0x18b00e at process virtual address 0x20ffd000\nMemory failure: 0x18b00e: dirty swapcache page still referenced by 2 users\nMemory failure: 0x18b00e: recovery action for dirty swapcache page: Failed\npage: refcount:2 mapcount:0 mapping:0000000000000000 index:0x20ffd pfn:0x18b00e\nmemcg:ffff0000dd6d9000\nanon flags: 0x5ffffe00482011(locked|dirty|arch_1|swapbacked|hwpoison|node=0|zone=2|lastcpupid=0xfffff)\nraw: 005ffffe00482011 dead000000000100 dead000000000122 ffff0000e232a7c9\nraw: 0000000000020ffd 0000000000000000 00000002ffffffff ffff0000dd6d9000\npage dumped because: VM_BUG_ON_FOLIO(!folio_test_uptodate(folio))\n------------[ cut here ]------------\nkernel BUG at mm/swap_state.c:184!\nInternal error: Oops - BUG: 00000000f2000800 [#1] SMP\nModules linked in:\nCPU: 0 PID: 60 Comm: kswapd0 Not tainted 6.6.0-gcb097e7de84e #3\nHardware name: linux,dummy-virt (DT)\npstate: 80400005 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)\npc : add_to_swap+0xbc/0x158\nlr : add_to_swap+0xbc/0x158\nsp : ffff800087f37340\nx29: ffff800087f37340 x28: fffffc00052c0380 x27: ffff800087f37780\nx26: ffff800087f37490 x25: ffff800087f37c78 x24: ffff800087f377a0\nx23: ffff800087f37c50 x22: 0000000000000000 x21: fffffc00052c03b4\nx20: 0000000000000000 x19: fffffc00052c0380 x18: 0000000000000000\nx17: 296f696c6f662865 x16: 7461646f7470755f x15: 747365745f6f696c\nx14: 6f6621284f494c4f x13: 0000000000000001 x12: ffff600036d8b97b\nx11: 1fffe00036d8b97a x10: ffff600036d8b97a x9 : dfff800000000000\nx8 : 00009fffc9274686 x7 : ffff0001b6c5cbd3 x6 : 0000000000000001\nx5 : ffff0000c25896c0 x4 : 0000000000000000 x3 : 0000000000000000\nx2 : 0000000000000000 x1 : ffff0000c25896c0 x0 : 0000000000000000\nCall trace:\n add_to_swap+0xbc/0x158\n shrink_folio_list+0x12ac/0x2648\n shrink_inactive_list+0x318/0x948\n shrink_lruvec+0x450/0x720\n shrink_node_memcgs+0x280/0x4a8\n shrink_node+0x128/0x978\n balance_pgdat+0x4f0/0xb20\n kswapd+0x228/0x438\n kthread+0x214/0x230\n ret_from_fork+0x10/0x20\n\nI can reproduce this issue with the following steps:\n\n1) When a dirty swapcache page is isolated by reclaim process and the\n page isn't locked, inject memory failure for the page. \n me_swapcache_dirty() clears uptodate flag and tries to delete from lru,\n but fails. Reclaim process will put the hwpoisoned page back to lru.\n\n2) The process that maps the hwpoisoned page exits, the page is deleted\n the page will never be freed and will be in the lru forever.\n\n3) If we trigger a reclaim again and tries to reclaim the page,\n add_to_swap() will trigger VM_BUG_ON_FOLIO due to the uptodate flag is\n cleared.\n\nTo fix it, skip the hwpoisoned page in shrink_folio_list(). Besides, the\nhwpoison folio may not be unmapped by hwpoison_user_mappings() yet, unmap\nit in shrink_folio_list(), otherwise the folio will fail to be unmaped by\nhwpoison_user_mappings() since the folio isn't in lru list.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37834" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1b0449544c6482179ac84530b61fc192a6527bfd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1c9798bf8145a92abf45aa9d38a6406d9eb8bdf0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/912e9f0300c3564b72a8808db406e313193a37ad" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T07:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-jq2v-j4fw-m4mg/GHSA-jq2v-j4fw-m4mg.json b/advisories/unreviewed/2025/05/GHSA-jq2v-j4fw-m4mg/GHSA-jq2v-j4fw-m4mg.json new file mode 100644 index 00000000000..9f19f43c3b4 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-jq2v-j4fw-m4mg/GHSA-jq2v-j4fw-m4mg.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jq2v-j4fw-m4mg", + "modified": "2025-05-08T09:30:24Z", + "published": "2025-05-08T09:30:24Z", + "aliases": [ + "CVE-2025-37821" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsched/eevdf: Fix se->slice being set to U64_MAX and resulting crash\n\nThere is a code path in dequeue_entities() that can set the slice of a\nsched_entity to U64_MAX, which sometimes results in a crash.\n\nThe offending case is when dequeue_entities() is called to dequeue a\ndelayed group entity, and then the entity's parent's dequeue is delayed.\nIn that case:\n\n1. In the if (entity_is_task(se)) else block at the beginning of\n dequeue_entities(), slice is set to\n cfs_rq_min_slice(group_cfs_rq(se)). If the entity was delayed, then\n it has no queued tasks, so cfs_rq_min_slice() returns U64_MAX.\n2. The first for_each_sched_entity() loop dequeues the entity.\n3. If the entity was its parent's only child, then the next iteration\n tries to dequeue the parent.\n4. If the parent's dequeue needs to be delayed, then it breaks from the\n first for_each_sched_entity() loop _without updating slice_.\n5. The second for_each_sched_entity() loop sets the parent's ->slice to\n the saved slice, which is still U64_MAX.\n\nThis throws off subsequent calculations with potentially catastrophic\nresults. A manifestation we saw in production was:\n\n6. In update_entity_lag(), se->slice is used to calculate limit, which\n ends up as a huge negative number.\n7. limit is used in se->vlag = clamp(vlag, -limit, limit). Because limit\n is negative, vlag > limit, so se->vlag is set to the same huge\n negative number.\n8. In place_entity(), se->vlag is scaled, which overflows and results in\n another huge (positive or negative) number.\n9. The adjusted lag is subtracted from se->vruntime, which increases or\n decreases se->vruntime by a huge number.\n10. pick_eevdf() calls entity_eligible()/vruntime_eligible(), which\n incorrectly returns false because the vruntime is so far from the\n other vruntimes on the queue, causing the\n (vruntime - cfs_rq->min_vruntime) * load calulation to overflow.\n11. Nothing appears to be eligible, so pick_eevdf() returns NULL.\n12. pick_next_entity() tries to dereference the return value of\n pick_eevdf() and crashes.\n\nDumping the cfs_rq states from the core dumps with drgn showed tell-tale\nhuge vruntime ranges and bogus vlag values, and I also traced se->slice\nbeing set to U64_MAX on live systems (which was usually \"benign\" since\nthe rest of the runqueue needed to be in a particular state to crash).\n\nFix it in dequeue_entities() by always setting slice from the first\nnon-empty cfs_rq.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37821" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/50a665496881262519f115f1bfe5822f30580eb0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bbce3de72be56e4b5f68924b7da9630cc89aa1a8" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T07:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-mcjv-6q8c-83q6/GHSA-mcjv-6q8c-83q6.json b/advisories/unreviewed/2025/05/GHSA-mcjv-6q8c-83q6/GHSA-mcjv-6q8c-83q6.json new file mode 100644 index 00000000000..0187e84a4eb --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-mcjv-6q8c-83q6/GHSA-mcjv-6q8c-83q6.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mcjv-6q8c-83q6", + "modified": "2025-05-08T09:30:25Z", + "published": "2025-05-08T09:30:25Z", + "aliases": [ + "CVE-2025-37825" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnvmet: fix out-of-bounds access in nvmet_enable_port\n\nWhen trying to enable a port that has no transport configured yet,\nnvmet_enable_port() uses NVMF_TRTYPE_MAX (255) to query the transports\narray, causing an out-of-bounds access:\n\n[ 106.058694] BUG: KASAN: global-out-of-bounds in nvmet_enable_port+0x42/0x1da\n[ 106.058719] Read of size 8 at addr ffffffff89dafa58 by task ln/632\n[...]\n[ 106.076026] nvmet: transport type 255 not supported\n\nSince commit 200adac75888, NVMF_TRTYPE_MAX is the default state as configured by\nnvmet_ports_make().\nAvoid this by checking for NVMF_TRTYPE_MAX before proceeding.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37825" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3d7aa0c7b4e96cd460826d932e44710cdeb3378b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/83c00860a37b3fcba8026cb344101f1b8af547cf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T07:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-mcvh-54mc-g3gg/GHSA-mcvh-54mc-g3gg.json b/advisories/unreviewed/2025/05/GHSA-mcvh-54mc-g3gg/GHSA-mcvh-54mc-g3gg.json new file mode 100644 index 00000000000..881b26de988 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-mcvh-54mc-g3gg/GHSA-mcvh-54mc-g3gg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mcvh-54mc-g3gg", + "modified": "2025-05-08T09:30:25Z", + "published": "2025-05-08T09:30:25Z", + "aliases": [ + "CVE-2025-40846" + ], + "details": "Improper Input Validation, the returnUrl parameter in Account Security Settings lacks proper input validation, allowing attackers to redirect users to malicious websites (Open Redirect) and inject JavaScript code to perform cross site scripting attack.\n\nThe vulnerability affects Halo versions up to 2.174.101 and all versions between 2.175.1 and 2.184.21", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:L/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:U/V:X/RE:L/U:Red" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-40846" + }, + { + "type": "WEB", + "url": "https://support.haloservicedesk.com/kb?id=2501" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T09:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-mr75-wq82-9hcw/GHSA-mr75-wq82-9hcw.json b/advisories/unreviewed/2025/05/GHSA-mr75-wq82-9hcw/GHSA-mr75-wq82-9hcw.json new file mode 100644 index 00000000000..e63598cbf4f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-mr75-wq82-9hcw/GHSA-mr75-wq82-9hcw.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mr75-wq82-9hcw", + "modified": "2025-05-08T09:30:25Z", + "published": "2025-05-08T09:30:25Z", + "aliases": [ + "CVE-2025-37828" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: ufs: mcq: Add NULL check in ufshcd_mcq_abort()\n\nA race can occur between the MCQ completion path and the abort handler:\nonce a request completes, __blk_mq_free_request() sets rq->mq_hctx to\nNULL, meaning the subsequent ufshcd_mcq_req_to_hwq() call in\nufshcd_mcq_abort() can return a NULL pointer. If this NULL pointer is\ndereferenced, the kernel will crash.\n\nAdd a NULL check for the returned hwq pointer. If hwq is NULL, log an\nerror and return FAILED, preventing a potential NULL-pointer\ndereference. As suggested by Bart, the ufshcd_cmd_inflight() check is\nremoved.\n\nThis is similar to the fix in commit 74736103fb41 (\"scsi: ufs: core: Fix\nufshcd_abort_one racing issue\").\n\nThis is found by our static analysis tool KNighter.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37828" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/47eec518aef3814f64a5da43df81bdd74d8c0041" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4c324085062919d4e21c69e5e78456dcec0052fe" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7d002f591486f5ef4bc02eb02025a53f931f0eb5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d6979fabe812a168d5053e5a41d5a2e9b8afd7bf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T07:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-p285-vxm3-73m7/GHSA-p285-vxm3-73m7.json b/advisories/unreviewed/2025/05/GHSA-p285-vxm3-73m7/GHSA-p285-vxm3-73m7.json new file mode 100644 index 00000000000..35090d2004e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-p285-vxm3-73m7/GHSA-p285-vxm3-73m7.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p285-vxm3-73m7", + "modified": "2025-05-08T09:30:25Z", + "published": "2025-05-08T09:30:25Z", + "aliases": [ + "CVE-2025-37831" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncpufreq: apple-soc: Fix null-ptr-deref in apple_soc_cpufreq_get_rate()\n\ncpufreq_cpu_get_raw() can return NULL when the target CPU is not present\nin the policy->cpus mask. apple_soc_cpufreq_get_rate() does not check\nfor this case, which results in a NULL pointer dereference.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37831" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/01e86ea22610d98ae6141e428019a6916e79f725" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1053dcf8a504d4933bb3f73df22bc363298d194b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9992649f6786921873a9b89dafa5e04d8c5fef2b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fbdba5f37413dbc09d82ad7235e5b7a2fb8e0f75" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T07:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-pfmc-fx47-cpg8/GHSA-pfmc-fx47-cpg8.json b/advisories/unreviewed/2025/05/GHSA-pfmc-fx47-cpg8/GHSA-pfmc-fx47-cpg8.json new file mode 100644 index 00000000000..0455e98f7f7 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-pfmc-fx47-cpg8/GHSA-pfmc-fx47-cpg8.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pfmc-fx47-cpg8", + "modified": "2025-05-08T09:30:24Z", + "published": "2025-05-08T09:30:24Z", + "aliases": [ + "CVE-2025-37809" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: typec: class: Fix NULL pointer access\n\nConcurrent calls to typec_partner_unlink_device can lead to a NULL pointer\ndereference. This patch adds a mutex to protect USB device pointers and\nprevent this issue. The same mutex protects both the device pointers and\nthe partner device registration.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37809" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1fdde62411fe65640e69bc55ea027d5b7b2f0093" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/de7c24febd21413ea8f49f61b36338b676c02852" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ec27386de23a511008c53aa2f3434ad180a3ca9a" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T07:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-qmpq-8rmr-c5hm/GHSA-qmpq-8rmr-c5hm.json b/advisories/unreviewed/2025/05/GHSA-qmpq-8rmr-c5hm/GHSA-qmpq-8rmr-c5hm.json new file mode 100644 index 00000000000..a743e1ddf04 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-qmpq-8rmr-c5hm/GHSA-qmpq-8rmr-c5hm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qmpq-8rmr-c5hm", + "modified": "2025-05-08T09:30:25Z", + "published": "2025-05-08T09:30:25Z", + "aliases": [ + "CVE-2025-1254" + ], + "details": "Out-of-bounds Read, Out-of-bounds Write vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers, Overflow Buffers.This issue affects Connext Professional: from 7.4.0 before 7.5.0, from 7.0.0 before 7.3.0.7, from 6.0.0 before 6.1.2.23.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1254" + }, + { + "type": "WEB", + "url": "https://www.rti.com/vulnerabilities/#cve-2025-1254" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T09:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rc74-9j9p-c3xp/GHSA-rc74-9j9p-c3xp.json b/advisories/unreviewed/2025/05/GHSA-rc74-9j9p-c3xp/GHSA-rc74-9j9p-c3xp.json new file mode 100644 index 00000000000..720ce907842 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-rc74-9j9p-c3xp/GHSA-rc74-9j9p-c3xp.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rc74-9j9p-c3xp", + "modified": "2025-05-08T09:30:24Z", + "published": "2025-05-08T09:30:24Z", + "aliases": [ + "CVE-2025-37813" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: xhci: Fix invalid pointer dereference in Etron workaround\n\nThis check is performed before prepare_transfer() and prepare_ring(), so\nenqueue can already point at the final link TRB of a segment. And indeed\nit will, some 0.4% of times this code is called.\n\nThen enqueue + 1 is an invalid pointer. It will crash the kernel right\naway or load some junk which may look like a link TRB and cause the real\nlink TRB to be replaced with a NOOP. This wouldn't end well.\n\nUse a functionally equivalent test which doesn't dereference the pointer\nand always gives correct result.\n\nSomething has crashed my machine twice in recent days while playing with\nan Etron HC, and a control transfer stress test ran for confirmation has\njust crashed it again. The same test passes with this patch applied.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37813" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0624e29c595b05e7a0e6d1c368f0a05799928e30" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/142273a49f2c315eabdbdf5a71c15e479b75ca91" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1ea050da5562af9b930d17cbbe9632d30f5df43a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bce3055b08e303e28a8751f6073066f5c33a0744" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T07:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rpfr-3prf-w7f2/GHSA-rpfr-3prf-w7f2.json b/advisories/unreviewed/2025/05/GHSA-rpfr-3prf-w7f2/GHSA-rpfr-3prf-w7f2.json new file mode 100644 index 00000000000..febc645f316 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-rpfr-3prf-w7f2/GHSA-rpfr-3prf-w7f2.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rpfr-3prf-w7f2", + "modified": "2025-05-08T09:30:24Z", + "published": "2025-05-08T09:30:24Z", + "aliases": [ + "CVE-2025-37810" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: dwc3: gadget: check that event count does not exceed event buffer length\n\nThe event count is read from register DWC3_GEVNTCOUNT.\nThere is a check for the count being zero, but not for exceeding the\nevent buffer length.\nCheck that event count does not exceed event buffer length,\navoiding an out-of-bounds access when memcpy'ing the event.\nCrash log:\nUnable to handle kernel paging request at virtual address ffffffc0129be000\npc : __memcpy+0x114/0x180\nlr : dwc3_check_event_buf+0xec/0x348\nx3 : 0000000000000030 x2 : 000000000000dfc4\nx1 : ffffffc0129be000 x0 : ffffff87aad60080\nCall trace:\n__memcpy+0x114/0x180\ndwc3_interrupt+0x24/0x34", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37810" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/015c39f38e69a491d2abd5e98869a500a9459b3b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/52a7c9d930b95aa8b1620edaba4818040c32631f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/63ccd26cd1f6600421795f6ca3e625076be06c9f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/99d655119b870ee60e4dbf310aa9a1ed8d9ede3d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a44547015287a19001384fe94dbff84c92ce4ee1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b43225948b231b3f331194010f84512bee4d9f59" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c0079630f268843a25ed75226169cba40e0d8880" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c4d80e41cb42008dceb35e5dbf52574d93beac0d" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T07:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-v2qv-w894-wvxx/GHSA-v2qv-w894-wvxx.json b/advisories/unreviewed/2025/05/GHSA-v2qv-w894-wvxx/GHSA-v2qv-w894-wvxx.json new file mode 100644 index 00000000000..5f20079c147 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-v2qv-w894-wvxx/GHSA-v2qv-w894-wvxx.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v2qv-w894-wvxx", + "modified": "2025-05-08T09:30:24Z", + "published": "2025-05-08T09:30:24Z", + "aliases": [ + "CVE-2025-37812" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: cdns3: Fix deadlock when using NCM gadget\n\nThe cdns3 driver has the same NCM deadlock as fixed in cdnsp by commit\n58f2fcb3a845 (\"usb: cdnsp: Fix deadlock issue during using NCM gadget\").\n\nUnder PREEMPT_RT the deadlock can be readily triggered by heavy network\ntraffic, for example using \"iperf --bidir\" over NCM ethernet link.\n\nThe deadlock occurs because the threaded interrupt handler gets\npreempted by a softirq, but both are protected by the same spinlock.\nPrevent deadlock by disabling softirq during threaded irq handler.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37812" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/09e90a9689a4aac7a2f726dc2aa472b0b37937b7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/48a62deb857f0694f611949015e70ad194d97159" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/59a760e4796a3cd88d8b9d7706e0a638de677751" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/74cd6e408a4c010e404832f0e4609d29bf1d0c41" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a1059896f2bfdcebcdc7153c3be2307ea319501f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b96239582531775f2fdcb14de29bdb6870fd4c8c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c27db84ed44e50ff90d9e3a2a25fae2e0a0fa015" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/eebfb64c624fc738b669100173344fb441c5e719" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T07:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-v5fm-w222-68gq/GHSA-v5fm-w222-68gq.json b/advisories/unreviewed/2025/05/GHSA-v5fm-w222-68gq/GHSA-v5fm-w222-68gq.json new file mode 100644 index 00000000000..f1b2f45c1c8 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-v5fm-w222-68gq/GHSA-v5fm-w222-68gq.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v5fm-w222-68gq", + "modified": "2025-05-08T09:30:25Z", + "published": "2025-05-08T09:30:25Z", + "aliases": [ + "CVE-2025-37824" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: fix NULL pointer dereference in tipc_mon_reinit_self()\n\nsyzbot reported:\n\ntipc: Node number set to 1055423674\nOops: general protection fault, probably for non-canonical address 0xdffffc0000000000: 0000 [#1] SMP KASAN NOPTI\nKASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]\nCPU: 3 UID: 0 PID: 6017 Comm: kworker/3:5 Not tainted 6.15.0-rc1-syzkaller-00246-g900241a5cc15 #0 PREEMPT(full)\nHardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2~bpo12+1 04/01/2014\nWorkqueue: events tipc_net_finalize_work\nRIP: 0010:tipc_mon_reinit_self+0x11c/0x210 net/tipc/monitor.c:719\n...\nRSP: 0018:ffffc9000356fb68 EFLAGS: 00010246\nRAX: 0000000000000000 RBX: 0000000000000000 RCX: 000000003ee87cba\nRDX: 0000000000000000 RSI: ffffffff8dbc56a7 RDI: ffff88804c2cc010\nRBP: dffffc0000000000 R08: 0000000000000001 R09: 0000000000000000\nR10: 0000000000000001 R11: 0000000000000000 R12: 0000000000000007\nR13: fffffbfff2111097 R14: ffff88804ead8000 R15: ffff88804ead9010\nFS: 0000000000000000(0000) GS:ffff888097ab9000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00000000f720eb00 CR3: 000000000e182000 CR4: 0000000000352ef0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nCall Trace:\n \n tipc_net_finalize+0x10b/0x180 net/tipc/net.c:140\n process_one_work+0x9cc/0x1b70 kernel/workqueue.c:3238\n process_scheduled_works kernel/workqueue.c:3319 [inline]\n worker_thread+0x6c8/0xf10 kernel/workqueue.c:3400\n kthread+0x3c2/0x780 kernel/kthread.c:464\n ret_from_fork+0x45/0x80 arch/x86/kernel/process.c:153\n ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245\n \n...\nRIP: 0010:tipc_mon_reinit_self+0x11c/0x210 net/tipc/monitor.c:719\n...\nRSP: 0018:ffffc9000356fb68 EFLAGS: 00010246\nRAX: 0000000000000000 RBX: 0000000000000000 RCX: 000000003ee87cba\nRDX: 0000000000000000 RSI: ffffffff8dbc56a7 RDI: ffff88804c2cc010\nRBP: dffffc0000000000 R08: 0000000000000001 R09: 0000000000000000\nR10: 0000000000000001 R11: 0000000000000000 R12: 0000000000000007\nR13: fffffbfff2111097 R14: ffff88804ead8000 R15: ffff88804ead9010\nFS: 0000000000000000(0000) GS:ffff888097ab9000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00000000f720eb00 CR3: 000000000e182000 CR4: 0000000000352ef0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n\nThere is a racing condition between workqueue created when enabling\nbearer and another thread created when disabling bearer right after\nthat as follow:\n\nenabling_bearer | disabling_bearer\n--------------- | ----------------\ntipc_disc_timeout() |\n{ | bearer_disable()\n ... | {\n schedule_work(&tn->work); | tipc_mon_delete()\n ... | {\n} | ...\n | write_lock_bh(&mon->lock);\n | mon->self = NULL;\n | write_unlock_bh(&mon->lock);\n | ...\n | }\ntipc_net_finalize_work() | }\n{ |\n ... |\n tipc_net_finalize() |\n { |\n ... |\n tipc_mon_reinit_self() |\n { |\n ... |\n write_lock_bh(&mon->lock); |\n mon->self->addr = tipc_own_addr(net); |\n write_unlock_bh(&mon->lock); |\n ... \n---truncated---", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37824" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0ceef62a328ce1288598c9242576292671f21e96" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4d5e1e2d3e9d70beff7beab44fd6ce91405a405e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5fd464fd24de93d0eca377554bf0ff2548f76f30" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a3df56010403b2cd26388096ebccf959d23c4dcc" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d63527e109e811ef11abb1c2985048fdb528b4cb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/dd6cb0a8575b00fbd503e96903184125176f4fa3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e6613b6d41f4010c4d484cbc7bfca690d8d522a2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e79e8e05aa46f90d21023f0ffe6f136ed6a20932" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T07:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vjw7-4w34-rrq4/GHSA-vjw7-4w34-rrq4.json b/advisories/unreviewed/2025/05/GHSA-vjw7-4w34-rrq4/GHSA-vjw7-4w34-rrq4.json new file mode 100644 index 00000000000..84e933f7435 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vjw7-4w34-rrq4/GHSA-vjw7-4w34-rrq4.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vjw7-4w34-rrq4", + "modified": "2025-05-08T09:30:24Z", + "published": "2025-05-08T09:30:24Z", + "aliases": [ + "CVE-2025-37814" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntty: Require CAP_SYS_ADMIN for all usages of TIOCL_SELMOUSEREPORT\n\nThis requirement was overeagerly loosened in commit 2f83e38a095f\n(\"tty: Permit some TIOCL_SETSEL modes without CAP_SYS_ADMIN\"), but as\nit turns out,\n\n (1) the logic I implemented there was inconsistent (apologies!),\n\n (2) TIOCL_SELMOUSEREPORT might actually be a small security risk\n after all, and\n\n (3) TIOCL_SELMOUSEREPORT is only meant to be used by the mouse\n daemon (GPM or Consolation), which runs as CAP_SYS_ADMIN\n already.\n\nIn more detail:\n\n1. The previous patch has inconsistent logic:\n\n In commit 2f83e38a095f (\"tty: Permit some TIOCL_SETSEL modes\n without CAP_SYS_ADMIN\"), we checked for sel_mode ==\n TIOCL_SELMOUSEREPORT, but overlooked that the lower four bits of\n this \"mode\" parameter were actually used as an additional way to\n pass an argument. So the patch did actually still require\n CAP_SYS_ADMIN, if any of the mouse button bits are set, but did not\n require it if none of the mouse buttons bits are set.\n\n This logic is inconsistent and was not intentional. We should have\n the same policies for using TIOCL_SELMOUSEREPORT independent of the\n value of the \"hidden\" mouse button argument.\n\n I sent a separate documentation patch to the man page list with\n more details on TIOCL_SELMOUSEREPORT:\n https://lore.kernel.org/all/20250223091342.35523-2-gnoack3000@gmail.com/\n\n2. TIOCL_SELMOUSEREPORT is indeed a potential security risk which can\n let an attacker simulate \"keyboard\" input to command line\n applications on the same terminal, like TIOCSTI and some other\n TIOCLINUX \"selection mode\" IOCTLs.\n\n By enabling mouse reporting on a terminal and then injecting mouse\n reports through TIOCL_SELMOUSEREPORT, an attacker can simulate\n mouse movements on the same terminal, similar to the TIOCSTI\n keystroke injection attacks that were previously possible with\n TIOCSTI and other TIOCL_SETSEL selection modes.\n\n Many programs (including libreadline/bash) are then prone to\n misinterpret these mouse reports as normal keyboard input because\n they do not expect input in the X11 mouse protocol form. The\n attacker does not have complete control over the escape sequence,\n but they can at least control the values of two consecutive bytes\n in the binary mouse reporting escape sequence.\n\n I went into more detail on that in the discussion at\n https://lore.kernel.org/all/20250221.0a947528d8f3@gnoack.org/\n\n It is not equally trivial to simulate arbitrary keystrokes as it\n was with TIOCSTI (commit 83efeeeb3d04 (\"tty: Allow TIOCSTI to be\n disabled\")), but the general mechanism is there, and together with\n the small number of existing legit use cases (see below), it would\n be better to revert back to requiring CAP_SYS_ADMIN for\n TIOCL_SELMOUSEREPORT, as it was already the case before\n commit 2f83e38a095f (\"tty: Permit some TIOCL_SETSEL modes without\n CAP_SYS_ADMIN\").\n\n3. TIOCL_SELMOUSEREPORT is only used by the mouse daemons (GPM or\n Consolation), and they are the only legit use case:\n\n To quote console_codes(4):\n\n The mouse tracking facility is intended to return\n xterm(1)-compatible mouse status reports. Because the console\n driver has no way to know the device or type of the mouse, these\n reports are returned in the console input stream only when the\n virtual terminal driver receives a mouse update ioctl. These\n ioctls must be generated by a mouse-aware user-mode application\n such as the gpm(8) daemon.\n\n Jared Finder has also confirmed in\n https://lore.kernel.org/all/491f3df9de6593df8e70dbe77614b026@finder.org/\n that Emacs does not call TIOCL_SELMOUSEREPORT directly, and it\n would be difficult to find good reasons for doing that, given that\n it would interfere with the reports that GPM is sending.\n\n More information on the interaction between GPM, terminals and th\n---truncated---", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37814" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6f021bc0083b96125fdbed6a60d7b4396c4d6dac" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9b50c9c97db953de756a39af83d4be4d7f618aa6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ee6a44da3c87cf64d67dd02be8c0127a5bf56175" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T07:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vp37-f5jx-gpcx/GHSA-vp37-f5jx-gpcx.json b/advisories/unreviewed/2025/05/GHSA-vp37-f5jx-gpcx/GHSA-vp37-f5jx-gpcx.json new file mode 100644 index 00000000000..b829f561650 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vp37-f5jx-gpcx/GHSA-vp37-f5jx-gpcx.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vp37-f5jx-gpcx", + "modified": "2025-05-08T09:30:23Z", + "published": "2025-05-08T09:30:23Z", + "aliases": [ + "CVE-2025-37801" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nspi: spi-imx: Add check for spi_imx_setupxfer()\n\nAdd check for the return value of spi_imx_setupxfer().\nspi_imx->rx and spi_imx->tx function pointer can be NULL when\nspi_imx_setupxfer() return error, and make NULL pointer dereference.\n\n Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000\n Call trace:\n 0x0\n spi_imx_pio_transfer+0x50/0xd8\n spi_imx_transfer_one+0x18c/0x858\n spi_transfer_one_message+0x43c/0x790\n __spi_pump_transfer_message+0x238/0x5d4\n __spi_sync+0x2b0/0x454\n spi_write_then_read+0x11c/0x200", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37801" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/055ef73bb1afc3f783a9a13b496770a781964a07" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/185d376875ea6fb4256b9dc97ee0b4d2b0fdd399" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2b4479eb462ecb39001b38dfb331fc6028dedac8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2fea0d6d7b5d27fbf55512d51851ba0a346ede52" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/951a04ab3a2db4029debfa48d380ef834b93207e" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T07:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-wp83-78c2-q7f9/GHSA-wp83-78c2-q7f9.json b/advisories/unreviewed/2025/05/GHSA-wp83-78c2-q7f9/GHSA-wp83-78c2-q7f9.json new file mode 100644 index 00000000000..dfc6ca79751 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-wp83-78c2-q7f9/GHSA-wp83-78c2-q7f9.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wp83-78c2-q7f9", + "modified": "2025-05-08T09:30:24Z", + "published": "2025-05-08T09:30:23Z", + "aliases": [ + "CVE-2025-37804" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nio_uring: always do atomic put from iowq\n\nio_uring always switches requests to atomic refcounting for iowq\nexecution before there is any parallilism by setting REQ_F_REFCOUNT,\nand the flag is not cleared until the request completes. That should be\nfine as long as the compiler doesn't make up a non existing value for\nthe flags, however KCSAN still complains when the request owner changes\noter flag bits:\n\nBUG: KCSAN: data-race in io_req_task_cancel / io_wq_free_work\n...\nread to 0xffff888117207448 of 8 bytes by task 3871 on cpu 0:\n req_ref_put_and_test io_uring/refs.h:22 [inline]\n\nSkip REQ_F_REFCOUNT checks for iowq, we know it's set.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37804" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3568fd9e440ea393c7d8bee253419ea11fd8e9d9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/390513642ee6763c7ada07f0a1470474986e6c1c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6d2753b46452a557a12f7ef1ef4ee6641b4e89d8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c5d4d103005d8926cdad344f9fc947e651c9f2f7" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T07:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-wrch-r746-jf7c/GHSA-wrch-r746-jf7c.json b/advisories/unreviewed/2025/05/GHSA-wrch-r746-jf7c/GHSA-wrch-r746-jf7c.json new file mode 100644 index 00000000000..2891c9ddd03 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-wrch-r746-jf7c/GHSA-wrch-r746-jf7c.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wrch-r746-jf7c", + "modified": "2025-05-08T09:30:24Z", + "published": "2025-05-08T09:30:24Z", + "aliases": [ + "CVE-2025-37806" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfs/ntfs3: Keep write operations atomic\n\nsyzbot reported a NULL pointer dereference in __generic_file_write_iter. [1]\n\nBefore the write operation is completed, the user executes ioctl[2] to clear\nthe compress flag of the file, which causes the is_compressed() judgment to\nreturn 0, further causing the program to enter the wrong process and call the\nwrong ops ntfs_aops_cmpr, which triggers the null pointer dereference of\nwrite_begin.\n\nUse inode lock to synchronize ioctl and write to avoid this case.\n\n[1]\nUnable to handle kernel NULL pointer dereference at virtual address 0000000000000000\nMem abort info:\n ESR = 0x0000000086000006\n EC = 0x21: IABT (current EL), IL = 32 bits\n SET = 0, FnV = 0\n EA = 0, S1PTW = 0\n FSC = 0x06: level 2 translation fault\nuser pgtable: 4k pages, 48-bit VAs, pgdp=000000011896d000\n[0000000000000000] pgd=0800000118b44403, p4d=0800000118b44403, pud=0800000117517403, pmd=0000000000000000\nInternal error: Oops: 0000000086000006 [#1] PREEMPT SMP\nModules linked in:\nCPU: 0 UID: 0 PID: 6427 Comm: syz-executor347 Not tainted 6.13.0-rc3-syzkaller-g573067a5a685 #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024\npstate: 80400005 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)\npc : 0x0\nlr : generic_perform_write+0x29c/0x868 mm/filemap.c:4055\nsp : ffff80009d4978a0\nx29: ffff80009d4979c0 x28: dfff800000000000 x27: ffff80009d497bc8\nx26: 0000000000000000 x25: ffff80009d497960 x24: ffff80008ba71c68\nx23: 0000000000000000 x22: ffff0000c655dac0 x21: 0000000000001000\nx20: 000000000000000c x19: 1ffff00013a92f2c x18: ffff0000e183aa1c\nx17: 0004060000000014 x16: ffff800083275834 x15: 0000000000000001\nx14: 0000000000000000 x13: 0000000000000001 x12: ffff0000c655dac0\nx11: 0000000000ff0100 x10: 0000000000ff0100 x9 : 0000000000000000\nx8 : 0000000000000000 x7 : 0000000000000000 x6 : 0000000000000000\nx5 : ffff80009d497980 x4 : ffff80009d497960 x3 : 0000000000001000\nx2 : 0000000000000000 x1 : ffff0000e183a928 x0 : ffff0000d60b0fc0\nCall trace:\n 0x0 (P)\n __generic_file_write_iter+0xfc/0x204 mm/filemap.c:4156\n ntfs_file_write_iter+0x54c/0x630 fs/ntfs3/file.c:1267\n new_sync_write fs/read_write.c:586 [inline]\n vfs_write+0x920/0xcf4 fs/read_write.c:679\n ksys_write+0x15c/0x26c fs/read_write.c:731\n __do_sys_write fs/read_write.c:742 [inline]\n __se_sys_write fs/read_write.c:739 [inline]\n __arm64_sys_write+0x7c/0x90 fs/read_write.c:739\n __invoke_syscall arch/arm64/kernel/syscall.c:35 [inline]\n invoke_syscall+0x98/0x2b8 arch/arm64/kernel/syscall.c:49\n el0_svc_common+0x130/0x23c arch/arm64/kernel/syscall.c:132\n do_el0_svc+0x48/0x58 arch/arm64/kernel/syscall.c:151\n el0_svc+0x54/0x168 arch/arm64/kernel/entry-common.c:744\n el0t_64_sync_handler+0x84/0x108 arch/arm64/kernel/entry-common.c:762\n\n[2]\nioctl$FS_IOC_SETFLAGS(r0, 0x40086602, &(0x7f00000000c0)=0x20)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37806" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/285cec318bf5a7a6c8ba999b2b6ec96f9a20590f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/464139e18f619aa14fb921a61721862f43421c54" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8db49e89a7f8b48ee59fa9ad32b6ed0879747df8" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-08T07:15:51Z" + } +} \ No newline at end of file