diff --git a/advisories/github-reviewed/2025/04/GHSA-5w6v-399v-w3cc/GHSA-5w6v-399v-w3cc.json b/advisories/github-reviewed/2025/04/GHSA-5w6v-399v-w3cc/GHSA-5w6v-399v-w3cc.json new file mode 100644 index 00000000000..4dc0df6c092 --- /dev/null +++ b/advisories/github-reviewed/2025/04/GHSA-5w6v-399v-w3cc/GHSA-5w6v-399v-w3cc.json @@ -0,0 +1,62 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5w6v-399v-w3cc", + "modified": "2025-04-21T21:55:56Z", + "published": "2025-04-21T21:55:56Z", + "aliases": [], + "summary": "Nokogiri updates packaged libxml2 to v2.13.8 to resolve CVE-2025-32414 and CVE-2025-32415", + "details": "## Summary\n\nNokogiri v1.18.8 upgrades its dependency libxml2 to [v2.13.8](https://gitlab.gnome.org/GNOME/libxml2/-/releases/v2.13.8).\n\nlibxml2 v2.13.8 addresses:\n\n- CVE-2025-32414\n - described at https://gitlab.gnome.org/GNOME/libxml2/-/issues/889\n- CVE-2025-32415\n - described at https://gitlab.gnome.org/GNOME/libxml2/-/issues/890\n\n## Impact\n\n### CVE-2025-32414: No impact\n\nIn libxml2 before 2.13.8 and 2.14.x before 2.14.2, out-of-bounds memory access can occur in the Python API (Python bindings) because of an incorrect return value. This occurs in xmlPythonFileRead and xmlPythonFileReadRaw because of a difference between bytes and characters.\n\n**There is no impact** from this CVE for Nokogiri users.\n\n\n### CVE-2025-32415: Low impact\n\nIn libxml2 before 2.13.8 and 2.14.x before 2.14.2, xmlSchemaIDCFillNodeTables in xmlschemas.c has a heap-based buffer under-read. To exploit this, a crafted XML document must be validated against an XML schema with certain identity constraints, or a crafted XML schema must be used.\n\nIn the upstream issue, further context is provided by the maintainer:\n\n> The bug affects validation against untrusted XML Schemas (.xsd) and validation of untrusted\n> documents against trusted Schemas if they make use of xsd:keyref in combination with recursively\n> defined types that have additional identity constraints.\n\nMITRE has published a severity score of 2.9 LOW (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L) for this CVE.", + "severity": [], + "affected": [ + { + "package": { + "ecosystem": "RubyGems", + "name": "nokogiri" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.18.8" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-5w6v-399v-w3cc" + }, + { + "type": "PACKAGE", + "url": "https://github.com/sparklemotion/nokogiri" + }, + { + "type": "WEB", + "url": "https://gitlab.gnome.org/GNOME/libxml2/-/issues/889" + }, + { + "type": "WEB", + "url": "https://gitlab.gnome.org/GNOME/libxml2/-/issues/890" + }, + { + "type": "WEB", + "url": "https://gitlab.gnome.org/GNOME/libxml2/-/releases/v2.13.8" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1395" + ], + "severity": "LOW", + "github_reviewed": true, + "github_reviewed_at": "2025-04-21T21:55:56Z", + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2025/04/GHSA-7m35-vw2c-696v/GHSA-7m35-vw2c-696v.json b/advisories/github-reviewed/2025/04/GHSA-7m35-vw2c-696v/GHSA-7m35-vw2c-696v.json new file mode 100644 index 00000000000..962e74fac73 --- /dev/null +++ b/advisories/github-reviewed/2025/04/GHSA-7m35-vw2c-696v/GHSA-7m35-vw2c-696v.json @@ -0,0 +1,84 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7m35-vw2c-696v", + "modified": "2025-04-21T21:55:26Z", + "published": "2025-04-21T03:30:18Z", + "aliases": [ + "CVE-2025-43971" + ], + "summary": "GoBGP panics due to a zero value for softwareVersionLen", + "details": "An issue was discovered in GoBGP before 3.35.0. pkg/packet/bgp/bgp.go allows attackers to cause a panic via a zero value for softwareVersionLen.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Go", + "name": "github.com/osrg/gobgp" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "database_specific": { + "last_known_affected_version_range": "< 3.35.0" + } + }, + { + "package": { + "ecosystem": "Go", + "name": "github.com/osrg/gobgp/v3" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.35.0" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43971" + }, + { + "type": "WEB", + "url": "https://github.com/osrg/gobgp/commit/08a001e06d90e8bcc190084c66992f46f62c0986" + }, + { + "type": "PACKAGE", + "url": "https://github.com/osrg/gobgp" + }, + { + "type": "WEB", + "url": "https://github.com/osrg/gobgp/compare/v3.34.0...v3.35.0" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-193" + ], + "severity": "HIGH", + "github_reviewed": true, + "github_reviewed_at": "2025-04-21T21:55:26Z", + "nvd_published_at": "2025-04-21T01:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2025/04/GHSA-c5jg-wr5v-2wp2/GHSA-c5jg-wr5v-2wp2.json b/advisories/github-reviewed/2025/04/GHSA-c5jg-wr5v-2wp2/GHSA-c5jg-wr5v-2wp2.json new file mode 100644 index 00000000000..efb24b8c9c3 --- /dev/null +++ b/advisories/github-reviewed/2025/04/GHSA-c5jg-wr5v-2wp2/GHSA-c5jg-wr5v-2wp2.json @@ -0,0 +1,84 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c5jg-wr5v-2wp2", + "modified": "2025-04-21T21:55:39Z", + "published": "2025-04-21T03:30:19Z", + "aliases": [ + "CVE-2025-43973" + ], + "summary": "GoBGP does not verify that the input length", + "details": "An issue was discovered in GoBGP before 3.35.0. pkg/packet/rtr/rtr.go does not verify that the input length corresponds to a situation in which all bytes are available for an RTR message.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Go", + "name": "github.com/osrg/gobgp" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "database_specific": { + "last_known_affected_version_range": "< 3.35.0" + } + }, + { + "package": { + "ecosystem": "Go", + "name": "github.com/osrg/gobgp/v3" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.35.0" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43973" + }, + { + "type": "WEB", + "url": "https://github.com/osrg/gobgp/commit/5693c58a4815cc6327b8d3b6980f0e5aced28abe" + }, + { + "type": "PACKAGE", + "url": "https://github.com/osrg/gobgp" + }, + { + "type": "WEB", + "url": "https://github.com/osrg/gobgp/compare/v3.34.0...v3.35.0" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-193" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2025-04-21T21:55:39Z", + "nvd_published_at": "2025-04-21T01:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2025/04/GHSA-hqhq-hp5x-xp3w/GHSA-hqhq-hp5x-xp3w.json b/advisories/github-reviewed/2025/04/GHSA-hqhq-hp5x-xp3w/GHSA-hqhq-hp5x-xp3w.json new file mode 100644 index 00000000000..813d56d9883 --- /dev/null +++ b/advisories/github-reviewed/2025/04/GHSA-hqhq-hp5x-xp3w/GHSA-hqhq-hp5x-xp3w.json @@ -0,0 +1,84 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hqhq-hp5x-xp3w", + "modified": "2025-04-21T21:55:19Z", + "published": "2025-04-21T03:30:18Z", + "aliases": [ + "CVE-2025-43970" + ], + "summary": "GoBGP does not properly check the input length", + "details": "An issue was discovered in GoBGP before 3.35.0. pkg/packet/mrt/mrt.go does not properly check the input length, e.g., by ensuring that there are 12 bytes or 36 bytes (depending on the address family).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Go", + "name": "github.com/osrg/gobgp" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "database_specific": { + "last_known_affected_version_range": "< 3.35.0" + } + }, + { + "package": { + "ecosystem": "Go", + "name": "github.com/osrg/gobgp/v3" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.35.0" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43970" + }, + { + "type": "WEB", + "url": "https://github.com/osrg/gobgp/commit/5153bafbe8dbe1a2f02a70bbf0365e98b80e47b0" + }, + { + "type": "PACKAGE", + "url": "https://github.com/osrg/gobgp" + }, + { + "type": "WEB", + "url": "https://github.com/osrg/gobgp/compare/v3.34.0...v3.35.0" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1284" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2025-04-21T21:55:19Z", + "nvd_published_at": "2025-04-21T01:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2025/04/GHSA-mfvv-mgf6-q25r/GHSA-mfvv-mgf6-q25r.json b/advisories/github-reviewed/2025/04/GHSA-mfvv-mgf6-q25r/GHSA-mfvv-mgf6-q25r.json new file mode 100644 index 00000000000..1242c55c198 --- /dev/null +++ b/advisories/github-reviewed/2025/04/GHSA-mfvv-mgf6-q25r/GHSA-mfvv-mgf6-q25r.json @@ -0,0 +1,84 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mfvv-mgf6-q25r", + "modified": "2025-04-21T21:55:34Z", + "published": "2025-04-21T03:30:19Z", + "aliases": [ + "CVE-2025-43972" + ], + "summary": "GoBGP crashes in the flowspec parser", + "details": "An issue was discovered in GoBGP before 3.35.0. An attacker can cause a crash in the pkg/packet/bgp/bgp.go flowspec parser by sending fewer than 20 bytes in a certain context.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Go", + "name": "github.com/osrg/gobgp" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ], + "database_specific": { + "last_known_affected_version_range": "< 3.35.0" + } + }, + { + "package": { + "ecosystem": "Go", + "name": "github.com/osrg/gobgp/v3" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.35.0" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43972" + }, + { + "type": "WEB", + "url": "https://github.com/osrg/gobgp/commit/ca7383f450f7b296c5389feceef2467de5ab6e5a" + }, + { + "type": "PACKAGE", + "url": "https://github.com/osrg/gobgp" + }, + { + "type": "WEB", + "url": "https://github.com/osrg/gobgp/compare/v3.34.0...v3.35.0" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1284" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2025-04-21T21:55:33Z", + "nvd_published_at": "2025-04-21T01:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7m35-vw2c-696v/GHSA-7m35-vw2c-696v.json b/advisories/unreviewed/2025/04/GHSA-7m35-vw2c-696v/GHSA-7m35-vw2c-696v.json deleted file mode 100644 index 341d9172d66..00000000000 --- a/advisories/unreviewed/2025/04/GHSA-7m35-vw2c-696v/GHSA-7m35-vw2c-696v.json +++ /dev/null @@ -1,40 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-7m35-vw2c-696v", - "modified": "2025-04-21T03:30:18Z", - "published": "2025-04-21T03:30:18Z", - "aliases": [ - "CVE-2025-43971" - ], - "details": "An issue was discovered in GoBGP before 3.35.0. pkg/packet/bgp/bgp.go allows attackers to cause a panic via a zero value for softwareVersionLen.", - "severity": [ - { - "type": "CVSS_V3", - "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" - } - ], - "affected": [], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43971" - }, - { - "type": "WEB", - "url": "https://github.com/osrg/gobgp/commit/08a001e06d90e8bcc190084c66992f46f62c0986" - }, - { - "type": "WEB", - "url": "https://github.com/osrg/gobgp/compare/v3.34.0...v3.35.0" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-193" - ], - "severity": "HIGH", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2025-04-21T01:15:45Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-c5jg-wr5v-2wp2/GHSA-c5jg-wr5v-2wp2.json b/advisories/unreviewed/2025/04/GHSA-c5jg-wr5v-2wp2/GHSA-c5jg-wr5v-2wp2.json deleted file mode 100644 index 17419e792ac..00000000000 --- a/advisories/unreviewed/2025/04/GHSA-c5jg-wr5v-2wp2/GHSA-c5jg-wr5v-2wp2.json +++ /dev/null @@ -1,40 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-c5jg-wr5v-2wp2", - "modified": "2025-04-21T03:30:19Z", - "published": "2025-04-21T03:30:19Z", - "aliases": [ - "CVE-2025-43973" - ], - "details": "An issue was discovered in GoBGP before 3.35.0. pkg/packet/rtr/rtr.go does not verify that the input length corresponds to a situation in which all bytes are available for an RTR message.", - "severity": [ - { - "type": "CVSS_V3", - "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H" - } - ], - "affected": [], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43973" - }, - { - "type": "WEB", - "url": "https://github.com/osrg/gobgp/commit/5693c58a4815cc6327b8d3b6980f0e5aced28abe" - }, - { - "type": "WEB", - "url": "https://github.com/osrg/gobgp/compare/v3.34.0...v3.35.0" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-193" - ], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2025-04-21T01:15:45Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hqhq-hp5x-xp3w/GHSA-hqhq-hp5x-xp3w.json b/advisories/unreviewed/2025/04/GHSA-hqhq-hp5x-xp3w/GHSA-hqhq-hp5x-xp3w.json deleted file mode 100644 index de138922d2f..00000000000 --- a/advisories/unreviewed/2025/04/GHSA-hqhq-hp5x-xp3w/GHSA-hqhq-hp5x-xp3w.json +++ /dev/null @@ -1,40 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-hqhq-hp5x-xp3w", - "modified": "2025-04-21T03:30:18Z", - "published": "2025-04-21T03:30:18Z", - "aliases": [ - "CVE-2025-43970" - ], - "details": "An issue was discovered in GoBGP before 3.35.0. pkg/packet/mrt/mrt.go does not properly check the input length, e.g., by ensuring that there are 12 bytes or 36 bytes (depending on the address family).", - "severity": [ - { - "type": "CVSS_V3", - "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L" - } - ], - "affected": [], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43970" - }, - { - "type": "WEB", - "url": "https://github.com/osrg/gobgp/commit/5153bafbe8dbe1a2f02a70bbf0365e98b80e47b0" - }, - { - "type": "WEB", - "url": "https://github.com/osrg/gobgp/compare/v3.34.0...v3.35.0" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-1284" - ], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2025-04-21T01:15:45Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-mfvv-mgf6-q25r/GHSA-mfvv-mgf6-q25r.json b/advisories/unreviewed/2025/04/GHSA-mfvv-mgf6-q25r/GHSA-mfvv-mgf6-q25r.json deleted file mode 100644 index dd6c3458cf3..00000000000 --- a/advisories/unreviewed/2025/04/GHSA-mfvv-mgf6-q25r/GHSA-mfvv-mgf6-q25r.json +++ /dev/null @@ -1,40 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-mfvv-mgf6-q25r", - "modified": "2025-04-21T03:30:19Z", - "published": "2025-04-21T03:30:19Z", - "aliases": [ - "CVE-2025-43972" - ], - "details": "An issue was discovered in GoBGP before 3.35.0. An attacker can cause a crash in the pkg/packet/bgp/bgp.go flowspec parser by sending fewer than 20 bytes in a certain context.", - "severity": [ - { - "type": "CVSS_V3", - "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H" - } - ], - "affected": [], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43972" - }, - { - "type": "WEB", - "url": "https://github.com/osrg/gobgp/commit/ca7383f450f7b296c5389feceef2467de5ab6e5a" - }, - { - "type": "WEB", - "url": "https://github.com/osrg/gobgp/compare/v3.34.0...v3.35.0" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-1284" - ], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2025-04-21T01:15:45Z" - } -} \ No newline at end of file