diff --git a/advisories/unreviewed/2023/07/GHSA-6578-hf9h-23c9/GHSA-6578-hf9h-23c9.json b/advisories/unreviewed/2023/07/GHSA-6578-hf9h-23c9/GHSA-6578-hf9h-23c9.json index 67ed2fe90be..872e80ba193 100644 --- a/advisories/unreviewed/2023/07/GHSA-6578-hf9h-23c9/GHSA-6578-hf9h-23c9.json +++ b/advisories/unreviewed/2023/07/GHSA-6578-hf9h-23c9/GHSA-6578-hf9h-23c9.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-8xf7-6cv9-64f7/GHSA-8xf7-6cv9-64f7.json b/advisories/unreviewed/2024/02/GHSA-8xf7-6cv9-64f7/GHSA-8xf7-6cv9-64f7.json index 0c086594216..23878eec5b4 100644 --- a/advisories/unreviewed/2024/02/GHSA-8xf7-6cv9-64f7/GHSA-8xf7-6cv9-64f7.json +++ b/advisories/unreviewed/2024/02/GHSA-8xf7-6cv9-64f7/GHSA-8xf7-6cv9-64f7.json @@ -52,7 +52,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-cf5h-fpjr-xpm5/GHSA-cf5h-fpjr-xpm5.json b/advisories/unreviewed/2024/02/GHSA-cf5h-fpjr-xpm5/GHSA-cf5h-fpjr-xpm5.json index fbeb39926f9..353686b841d 100644 --- a/advisories/unreviewed/2024/02/GHSA-cf5h-fpjr-xpm5/GHSA-cf5h-fpjr-xpm5.json +++ b/advisories/unreviewed/2024/02/GHSA-cf5h-fpjr-xpm5/GHSA-cf5h-fpjr-xpm5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cf5h-fpjr-xpm5", - "modified": "2024-02-29T06:30:32Z", + "modified": "2024-11-05T18:31:58Z", "published": "2024-02-29T06:30:32Z", "aliases": [ "CVE-2023-52479" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: fix uaf in smb20_oplock_break_ack\n\ndrop reference after use opinfo.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-29T06:15:45Z" diff --git a/advisories/unreviewed/2024/02/GHSA-frwj-xv69-m7pr/GHSA-frwj-xv69-m7pr.json b/advisories/unreviewed/2024/02/GHSA-frwj-xv69-m7pr/GHSA-frwj-xv69-m7pr.json index 1011776cb1b..a033d820b4d 100644 --- a/advisories/unreviewed/2024/02/GHSA-frwj-xv69-m7pr/GHSA-frwj-xv69-m7pr.json +++ b/advisories/unreviewed/2024/02/GHSA-frwj-xv69-m7pr/GHSA-frwj-xv69-m7pr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-frwj-xv69-m7pr", - "modified": "2024-02-29T00:30:22Z", + "modified": "2024-11-05T18:31:58Z", "published": "2024-02-29T00:30:21Z", "aliases": [ "CVE-2023-45873" ], "details": "An issue was discovered in Couchbase Server through 7.2.2. A data reader may cause a denial of service (application exist) because of the OOM killer.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-28T22:15:26Z" diff --git a/advisories/unreviewed/2024/02/GHSA-hxqj-hr64-7vf7/GHSA-hxqj-hr64-7vf7.json b/advisories/unreviewed/2024/02/GHSA-hxqj-hr64-7vf7/GHSA-hxqj-hr64-7vf7.json index bc1ad27f8e3..9f9fcce99fa 100644 --- a/advisories/unreviewed/2024/02/GHSA-hxqj-hr64-7vf7/GHSA-hxqj-hr64-7vf7.json +++ b/advisories/unreviewed/2024/02/GHSA-hxqj-hr64-7vf7/GHSA-hxqj-hr64-7vf7.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-276" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-jhxw-wgr6-6rqc/GHSA-jhxw-wgr6-6rqc.json b/advisories/unreviewed/2024/02/GHSA-jhxw-wgr6-6rqc/GHSA-jhxw-wgr6-6rqc.json index 1602804aff0..1e4fdbe78ac 100644 --- a/advisories/unreviewed/2024/02/GHSA-jhxw-wgr6-6rqc/GHSA-jhxw-wgr6-6rqc.json +++ b/advisories/unreviewed/2024/02/GHSA-jhxw-wgr6-6rqc/GHSA-jhxw-wgr6-6rqc.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-276" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-r5qg-76hh-gr9p/GHSA-r5qg-76hh-gr9p.json b/advisories/unreviewed/2024/02/GHSA-r5qg-76hh-gr9p/GHSA-r5qg-76hh-gr9p.json index a675a1e3bca..2517342980c 100644 --- a/advisories/unreviewed/2024/02/GHSA-r5qg-76hh-gr9p/GHSA-r5qg-76hh-gr9p.json +++ b/advisories/unreviewed/2024/02/GHSA-r5qg-76hh-gr9p/GHSA-r5qg-76hh-gr9p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r5qg-76hh-gr9p", - "modified": "2024-02-26T18:30:28Z", + "modified": "2024-11-05T18:31:57Z", "published": "2024-02-21T06:30:32Z", "aliases": [ "CVE-2024-1676" ], "details": "Inappropriate implementation in Navigation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Low)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-21T04:15:08Z" diff --git a/advisories/unreviewed/2024/02/GHSA-w267-2gcr-ggcp/GHSA-w267-2gcr-ggcp.json b/advisories/unreviewed/2024/02/GHSA-w267-2gcr-ggcp/GHSA-w267-2gcr-ggcp.json index 970f1a4e7d8..8936e663e2b 100644 --- a/advisories/unreviewed/2024/02/GHSA-w267-2gcr-ggcp/GHSA-w267-2gcr-ggcp.json +++ b/advisories/unreviewed/2024/02/GHSA-w267-2gcr-ggcp/GHSA-w267-2gcr-ggcp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w267-2gcr-ggcp", - "modified": "2024-03-04T09:30:28Z", + "modified": "2024-11-05T18:31:57Z", "published": "2024-02-20T15:31:04Z", "aliases": [ "CVE-2024-1546" ], "details": "When storing and re-accessing data on a networking channel, the length of buffers may have been confused, resulting in an out-of-bounds memory read. This vulnerability affects Firefox < 123 and Firefox ESR < 115.8.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-20T14:15:08Z" diff --git a/advisories/unreviewed/2024/03/GHSA-2fv8-55wf-gg3v/GHSA-2fv8-55wf-gg3v.json b/advisories/unreviewed/2024/03/GHSA-2fv8-55wf-gg3v/GHSA-2fv8-55wf-gg3v.json index 0bbee2aebd3..5120d59c754 100644 --- a/advisories/unreviewed/2024/03/GHSA-2fv8-55wf-gg3v/GHSA-2fv8-55wf-gg3v.json +++ b/advisories/unreviewed/2024/03/GHSA-2fv8-55wf-gg3v/GHSA-2fv8-55wf-gg3v.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-3gf3-x9x8-839v/GHSA-3gf3-x9x8-839v.json b/advisories/unreviewed/2024/03/GHSA-3gf3-x9x8-839v/GHSA-3gf3-x9x8-839v.json index c89755899cb..761c3a5b810 100644 --- a/advisories/unreviewed/2024/03/GHSA-3gf3-x9x8-839v/GHSA-3gf3-x9x8-839v.json +++ b/advisories/unreviewed/2024/03/GHSA-3gf3-x9x8-839v/GHSA-3gf3-x9x8-839v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3gf3-x9x8-839v", - "modified": "2024-03-27T06:30:32Z", + "modified": "2024-11-05T18:31:58Z", "published": "2024-03-27T06:30:32Z", "aliases": [ "CVE-2023-46046" ], "details": "An issue in MiniZinc before 2.8.0 allows a NULL pointer dereference via ti_expr in a crafted .mzn file. NOTE: this is disputed because there is no common libminizinc use case in which an unattended process is supposed to run forever to process a series of atttacker-controlled .mzn files.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-27T05:15:47Z" diff --git a/advisories/unreviewed/2024/03/GHSA-3q2c-pvp5-3cqp/GHSA-3q2c-pvp5-3cqp.json b/advisories/unreviewed/2024/03/GHSA-3q2c-pvp5-3cqp/GHSA-3q2c-pvp5-3cqp.json index e580f39556d..d9825464ee6 100644 --- a/advisories/unreviewed/2024/03/GHSA-3q2c-pvp5-3cqp/GHSA-3q2c-pvp5-3cqp.json +++ b/advisories/unreviewed/2024/03/GHSA-3q2c-pvp5-3cqp/GHSA-3q2c-pvp5-3cqp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3q2c-pvp5-3cqp", - "modified": "2024-05-01T18:30:35Z", + "modified": "2024-11-05T18:31:58Z", "published": "2024-03-06T00:31:26Z", "aliases": [ "CVE-2024-24783" ], "details": "Verifying a certificate chain which contains a certificate with an unknown public key algorithm will cause Certificate.Verify to panic. This affects all crypto/tls clients, and servers that set Config.ClientAuth to VerifyClientCertIfGiven or RequireAndVerifyClientCert. The default behavior is for TLS servers to not verify client certificates.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-05T23:15:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-49h9-qx93-p659/GHSA-49h9-qx93-p659.json b/advisories/unreviewed/2024/03/GHSA-49h9-qx93-p659/GHSA-49h9-qx93-p659.json index 31104393f6d..cab053d8af5 100644 --- a/advisories/unreviewed/2024/03/GHSA-49h9-qx93-p659/GHSA-49h9-qx93-p659.json +++ b/advisories/unreviewed/2024/03/GHSA-49h9-qx93-p659/GHSA-49h9-qx93-p659.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-49h9-qx93-p659", - "modified": "2024-03-27T09:30:39Z", + "modified": "2024-11-05T18:31:58Z", "published": "2024-03-27T09:30:39Z", "aliases": [ "CVE-2023-25364" ], "details": "Opswat Metadefender Core before 5.2.1 does not properly defend against potential HTML injection and XSS attacks.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-27T07:15:47Z" diff --git a/advisories/unreviewed/2024/03/GHSA-7523-56gq-473q/GHSA-7523-56gq-473q.json b/advisories/unreviewed/2024/03/GHSA-7523-56gq-473q/GHSA-7523-56gq-473q.json index 8ceab666e20..fa13bb909d7 100644 --- a/advisories/unreviewed/2024/03/GHSA-7523-56gq-473q/GHSA-7523-56gq-473q.json +++ b/advisories/unreviewed/2024/03/GHSA-7523-56gq-473q/GHSA-7523-56gq-473q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7523-56gq-473q", - "modified": "2024-03-13T21:31:02Z", + "modified": "2024-11-05T18:31:58Z", "published": "2024-03-08T03:31:25Z", "aliases": [ "CVE-2024-23255" ], "details": "An authentication issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14.4, iOS 17.4 and iPadOS 17.4. Photos in the Hidden Photos Album may be viewed without authentication.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -33,9 +36,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-863" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-08T02:15:48Z" diff --git a/advisories/unreviewed/2024/03/GHSA-9wr4-x5hv-2rw2/GHSA-9wr4-x5hv-2rw2.json b/advisories/unreviewed/2024/03/GHSA-9wr4-x5hv-2rw2/GHSA-9wr4-x5hv-2rw2.json index 5c4a39831b7..8b8741c5ec8 100644 --- a/advisories/unreviewed/2024/03/GHSA-9wr4-x5hv-2rw2/GHSA-9wr4-x5hv-2rw2.json +++ b/advisories/unreviewed/2024/03/GHSA-9wr4-x5hv-2rw2/GHSA-9wr4-x5hv-2rw2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9wr4-x5hv-2rw2", - "modified": "2024-03-15T21:30:43Z", + "modified": "2024-11-05T18:31:58Z", "published": "2024-03-15T21:30:43Z", "aliases": [ "CVE-2021-47114" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: fix data corruption by fallocate\n\nWhen fallocate punches holes out of inode size, if original isize is in\nthe middle of last cluster, then the part from isize to the end of the\ncluster will be zeroed with buffer write, at that time isize is not yet\nupdated to match the new size, if writeback is kicked in, it will invoke\nocfs2_writepage()->block_write_full_page() where the pages out of inode\nsize will be dropped. That will cause file corruption. Fix this by\nzero out eof blocks when extending the inode size.\n\nRunning the following command with qemu-image 4.2.1 can get a corrupted\ncoverted image file easily.\n\n qemu-img convert -p -t none -T none -f qcow2 $qcow_image \\\n -O qcow2 -o compat=1.1 $qcow_image.conv\n\nThe usage of fallocate in qemu is like this, it first punches holes out\nof inode size, then extend the inode size.\n\n fallocate(11, FALLOC_FL_KEEP_SIZE|FALLOC_FL_PUNCH_HOLE, 2276196352, 65536) = 0\n fallocate(11, 0, 2276196352, 65536) = 0\n\nv1: https://www.spinics.net/lists/linux-fsdevel/msg193999.html\nv2: https://lore.kernel.org/linux-fsdevel/20210525093034.GB4112@quack2.suse.cz/T/", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -55,7 +58,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-15T21:15:06Z" diff --git a/advisories/unreviewed/2024/03/GHSA-c534-6v46-r777/GHSA-c534-6v46-r777.json b/advisories/unreviewed/2024/03/GHSA-c534-6v46-r777/GHSA-c534-6v46-r777.json index ad44efc38e3..da17a6055b3 100644 --- a/advisories/unreviewed/2024/03/GHSA-c534-6v46-r777/GHSA-c534-6v46-r777.json +++ b/advisories/unreviewed/2024/03/GHSA-c534-6v46-r777/GHSA-c534-6v46-r777.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c534-6v46-r777", - "modified": "2024-03-14T00:31:05Z", + "modified": "2024-11-05T18:31:58Z", "published": "2024-03-08T03:31:25Z", "aliases": [ "CVE-2024-23291" ], "details": "A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in tvOS 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, watchOS 10.4. A malicious app may be able to observe user data in log entries related to accessibility notifications.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -51,7 +54,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-08T02:15:50Z" diff --git a/advisories/unreviewed/2024/03/GHSA-g754-37wh-7wv7/GHSA-g754-37wh-7wv7.json b/advisories/unreviewed/2024/03/GHSA-g754-37wh-7wv7/GHSA-g754-37wh-7wv7.json index 2b1a8942a91..c51b039c019 100644 --- a/advisories/unreviewed/2024/03/GHSA-g754-37wh-7wv7/GHSA-g754-37wh-7wv7.json +++ b/advisories/unreviewed/2024/03/GHSA-g754-37wh-7wv7/GHSA-g754-37wh-7wv7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g754-37wh-7wv7", - "modified": "2024-03-03T00:30:30Z", + "modified": "2024-11-05T18:31:58Z", "published": "2024-03-03T00:30:30Z", "aliases": [ "CVE-2023-52502" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: nfc: fix races in nfc_llcp_sock_get() and nfc_llcp_sock_get_sn()\n\nSili Luo reported a race in nfc_llcp_sock_get(), leading to UAF.\n\nGetting a reference on the socket found in a lookup while\nholding a lock should happen before releasing the lock.\n\nnfc_llcp_sock_get_sn() has a similar problem.\n\nFinally nfc_llcp_recv_snl() needs to make sure the socket\nfound by nfc_llcp_sock_from_sn() does not disappear.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H" + } ], "affected": [ @@ -51,7 +54,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-02T22:15:47Z" diff --git a/advisories/unreviewed/2024/03/GHSA-mf3p-gmch-hc8x/GHSA-mf3p-gmch-hc8x.json b/advisories/unreviewed/2024/03/GHSA-mf3p-gmch-hc8x/GHSA-mf3p-gmch-hc8x.json index 01566e8cc81..9078bd285de 100644 --- a/advisories/unreviewed/2024/03/GHSA-mf3p-gmch-hc8x/GHSA-mf3p-gmch-hc8x.json +++ b/advisories/unreviewed/2024/03/GHSA-mf3p-gmch-hc8x/GHSA-mf3p-gmch-hc8x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mf3p-gmch-hc8x", - "modified": "2024-03-26T15:30:48Z", + "modified": "2024-11-05T18:31:58Z", "published": "2024-03-26T12:31:27Z", "aliases": [ "CVE-2024-28034" ], "details": "Cross-site scripting vulnerability exists in Mini Thread Version 3.33βi. An arbitrary script may be executed on the web browser of the user accessing the website that uses the product. Note that the developer was unreachable, therefore, users should consider stop using Mini Thread Version 3.33βi.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-26T10:15:09Z" diff --git a/advisories/unreviewed/2024/03/GHSA-vpgg-8ccq-gwhg/GHSA-vpgg-8ccq-gwhg.json b/advisories/unreviewed/2024/03/GHSA-vpgg-8ccq-gwhg/GHSA-vpgg-8ccq-gwhg.json index 253c6fcbbe0..5f4fc84ee5f 100644 --- a/advisories/unreviewed/2024/03/GHSA-vpgg-8ccq-gwhg/GHSA-vpgg-8ccq-gwhg.json +++ b/advisories/unreviewed/2024/03/GHSA-vpgg-8ccq-gwhg/GHSA-vpgg-8ccq-gwhg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vpgg-8ccq-gwhg", - "modified": "2024-03-25T09:32:36Z", + "modified": "2024-11-05T18:31:58Z", "published": "2024-03-25T09:32:35Z", "aliases": [ "CVE-2021-47153" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ni2c: i801: Don't generate an interrupt on bus reset\n\nNow that the i2c-i801 driver supports interrupts, setting the KILL bit\nin a attempt to recover from a timed out transaction triggers an\ninterrupt. Unfortunately, the interrupt handler (i801_isr) is not\nprepared for this situation and will try to process the interrupt as\nif it was signaling the end of a successful transaction. In the case\nof a block transaction, this can result in an out-of-range memory\naccess.\n\nThis condition was reproduced several times by syzbot:\nhttps://syzkaller.appspot.com/bug?extid=ed71512d469895b5b34e\nhttps://syzkaller.appspot.com/bug?extid=8c8dedc0ba9e03f6c79e\nhttps://syzkaller.appspot.com/bug?extid=c8ff0b6d6c73d81b610e\nhttps://syzkaller.appspot.com/bug?extid=33f6c360821c399d69eb\nhttps://syzkaller.appspot.com/bug?extid=be15dc0b1933f04b043a\nhttps://syzkaller.appspot.com/bug?extid=b4d3fd1dfd53e90afd79\n\nSo disable interrupts while trying to reset the bus. Interrupts will\nbe enabled again for the following transaction.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H" + } ], "affected": [ @@ -55,7 +58,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-25T09:15:09Z" diff --git a/advisories/unreviewed/2024/03/GHSA-x7cq-pgcc-cqqm/GHSA-x7cq-pgcc-cqqm.json b/advisories/unreviewed/2024/03/GHSA-x7cq-pgcc-cqqm/GHSA-x7cq-pgcc-cqqm.json index 67b0e5128ec..8f0c191eec9 100644 --- a/advisories/unreviewed/2024/03/GHSA-x7cq-pgcc-cqqm/GHSA-x7cq-pgcc-cqqm.json +++ b/advisories/unreviewed/2024/03/GHSA-x7cq-pgcc-cqqm/GHSA-x7cq-pgcc-cqqm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-x7cq-pgcc-cqqm", - "modified": "2024-03-25T09:32:35Z", + "modified": "2024-11-05T18:31:58Z", "published": "2024-03-25T09:32:35Z", "aliases": [ "CVE-2021-47137" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: lantiq: fix memory corruption in RX ring\n\nIn a situation where memory allocation or dma mapping fails, an\ninvalid address is programmed into the descriptor. This can lead\nto memory corruption. If the memory allocation fails, DMA should\nreuse the previous skb and mapping and drop the packet. This patch\nalso increments rx drop counter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-770" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-25T09:15:08Z" diff --git a/advisories/unreviewed/2024/03/GHSA-xqc9-rv8w-5v6g/GHSA-xqc9-rv8w-5v6g.json b/advisories/unreviewed/2024/03/GHSA-xqc9-rv8w-5v6g/GHSA-xqc9-rv8w-5v6g.json index c2f4bd3c201..070f7b597bb 100644 --- a/advisories/unreviewed/2024/03/GHSA-xqc9-rv8w-5v6g/GHSA-xqc9-rv8w-5v6g.json +++ b/advisories/unreviewed/2024/03/GHSA-xqc9-rv8w-5v6g/GHSA-xqc9-rv8w-5v6g.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xqc9-rv8w-5v6g", - "modified": "2024-03-11T21:31:25Z", + "modified": "2024-11-05T18:31:58Z", "published": "2024-03-11T21:31:25Z", "aliases": [ "CVE-2024-22010" ], "details": "In dvfs_plugin_caller of fvp.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-11T19:15:47Z" diff --git a/advisories/unreviewed/2024/04/GHSA-29f2-7m5v-qfqv/GHSA-29f2-7m5v-qfqv.json b/advisories/unreviewed/2024/04/GHSA-29f2-7m5v-qfqv/GHSA-29f2-7m5v-qfqv.json index ef77f930169..3ae714c16ab 100644 --- a/advisories/unreviewed/2024/04/GHSA-29f2-7m5v-qfqv/GHSA-29f2-7m5v-qfqv.json +++ b/advisories/unreviewed/2024/04/GHSA-29f2-7m5v-qfqv/GHSA-29f2-7m5v-qfqv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-29f2-7m5v-qfqv", - "modified": "2024-04-05T21:32:44Z", + "modified": "2024-11-05T18:31:58Z", "published": "2024-04-05T21:32:44Z", "aliases": [ "CVE-2024-29751" ], "details": "In asn1_ec_pkey_parse_p384 of asn1_common.c, there is a possible OOB Read due to a missing null check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-05T20:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-3cm8-rv8m-x9gf/GHSA-3cm8-rv8m-x9gf.json b/advisories/unreviewed/2024/04/GHSA-3cm8-rv8m-x9gf/GHSA-3cm8-rv8m-x9gf.json index 1571d7b44d8..0517813e367 100644 --- a/advisories/unreviewed/2024/04/GHSA-3cm8-rv8m-x9gf/GHSA-3cm8-rv8m-x9gf.json +++ b/advisories/unreviewed/2024/04/GHSA-3cm8-rv8m-x9gf/GHSA-3cm8-rv8m-x9gf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-3cm8-rv8m-x9gf", - "modified": "2024-04-03T18:30:40Z", + "modified": "2024-11-05T18:31:58Z", "published": "2024-04-03T18:30:40Z", "aliases": [ "CVE-2023-44040" ], "details": "In VeridiumID before 3.5.0, the identity provider page is susceptible to a cross-site scripting (XSS) vulnerability that can be exploited by an internal unauthenticated attacker for JavaScript execution in the context of the user trying to authenticate.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T17:15:47Z" diff --git a/advisories/unreviewed/2024/04/GHSA-4jw4-4g69-7273/GHSA-4jw4-4g69-7273.json b/advisories/unreviewed/2024/04/GHSA-4jw4-4g69-7273/GHSA-4jw4-4g69-7273.json index 7dc13757f7f..3017c5dcebb 100644 --- a/advisories/unreviewed/2024/04/GHSA-4jw4-4g69-7273/GHSA-4jw4-4g69-7273.json +++ b/advisories/unreviewed/2024/04/GHSA-4jw4-4g69-7273/GHSA-4jw4-4g69-7273.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4jw4-4g69-7273", - "modified": "2024-04-08T09:31:13Z", + "modified": "2024-11-05T18:31:58Z", "published": "2024-04-08T09:31:13Z", "aliases": [ "CVE-2023-52553" ], "details": "Race condition vulnerability in the Wi-Fi module.\nImpact: Successful exploitation of this vulnerability will affect availability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ "CWE-362" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-08T09:15:09Z" diff --git a/advisories/unreviewed/2024/04/GHSA-5cg8-xmcq-jx69/GHSA-5cg8-xmcq-jx69.json b/advisories/unreviewed/2024/04/GHSA-5cg8-xmcq-jx69/GHSA-5cg8-xmcq-jx69.json index 68968676916..970abd2f76e 100644 --- a/advisories/unreviewed/2024/04/GHSA-5cg8-xmcq-jx69/GHSA-5cg8-xmcq-jx69.json +++ b/advisories/unreviewed/2024/04/GHSA-5cg8-xmcq-jx69/GHSA-5cg8-xmcq-jx69.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-8vch-c6pw-5chh/GHSA-8vch-c6pw-5chh.json b/advisories/unreviewed/2024/04/GHSA-8vch-c6pw-5chh/GHSA-8vch-c6pw-5chh.json index 3bd25fbe539..9bf49adcb4e 100644 --- a/advisories/unreviewed/2024/04/GHSA-8vch-c6pw-5chh/GHSA-8vch-c6pw-5chh.json +++ b/advisories/unreviewed/2024/04/GHSA-8vch-c6pw-5chh/GHSA-8vch-c6pw-5chh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8vch-c6pw-5chh", - "modified": "2024-06-26T00:31:36Z", + "modified": "2024-11-05T18:31:58Z", "published": "2024-04-03T15:30:43Z", "aliases": [ "CVE-2024-26712" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\npowerpc/kasan: Fix addr error caused by page alignment\n\nIn kasan_init_region, when k_start is not page aligned, at the begin of\nfor loop, k_cur = k_start & PAGE_MASK is less than k_start, and then\n`va = block + k_cur - k_start` is less than block, the addr va is invalid,\nbecause the memory address space from va to block is not alloced by\nmemblock_alloc, which will not be reserved by memblock_reserve later, it\nwill be used by other places.\n\nAs a result, memory overwriting occurs.\n\nfor example:\nint __init __weak kasan_init_region(void *start, size_t size)\n{\n[...]\n\t/* if say block(dcd97000) k_start(feef7400) k_end(feeff3fe) */\n\tblock = memblock_alloc(k_end - k_start, PAGE_SIZE);\n\t[...]\n\tfor (k_cur = k_start & PAGE_MASK; k_cur < k_end; k_cur += PAGE_SIZE) {\n\t\t/* at the begin of for loop\n\t\t * block(dcd97000) va(dcd96c00) k_cur(feef7000) k_start(feef7400)\n\t\t * va(dcd96c00) is less than block(dcd97000), va is invalid\n\t\t */\n\t\tvoid *va = block + k_cur - k_start;\n\t\t[...]\n\t}\n[...]\n}\n\nTherefore, page alignment is performed on k_start before\nmemblock_alloc() to ensure the validity of the VA address.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -51,7 +54,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T15:15:53Z" diff --git a/advisories/unreviewed/2024/04/GHSA-9pfj-cx2g-pfp8/GHSA-9pfj-cx2g-pfp8.json b/advisories/unreviewed/2024/04/GHSA-9pfj-cx2g-pfp8/GHSA-9pfj-cx2g-pfp8.json index 080486dba79..d637c3c8b85 100644 --- a/advisories/unreviewed/2024/04/GHSA-9pfj-cx2g-pfp8/GHSA-9pfj-cx2g-pfp8.json +++ b/advisories/unreviewed/2024/04/GHSA-9pfj-cx2g-pfp8/GHSA-9pfj-cx2g-pfp8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9pfj-cx2g-pfp8", - "modified": "2024-04-17T12:32:05Z", + "modified": "2024-11-05T18:31:58Z", "published": "2024-04-17T12:32:05Z", "aliases": [ "CVE-2024-26890" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: btrtl: fix out of bounds memory access\n\nThe problem is detected by KASAN.\nbtrtl driver uses private hci data to store 'struct btrealtek_data'.\nIf btrtl driver is used with btusb, then memory for private hci data\nis allocated in btusb. But no private data is allocated after hci_dev,\nwhen btrtl is used with hci_h5.\n\nThis commit adds memory allocation for hci_h5 case.\n\n ==================================================================\n BUG: KASAN: slab-out-of-bounds in btrtl_initialize+0x6cc/0x958 [btrtl]\n Write of size 8 at addr ffff00000f5a5748 by task kworker/u9:0/76\n\n Hardware name: Pine64 PinePhone (1.2) (DT)\n Workqueue: hci0 hci_power_on [bluetooth]\n Call trace:\n dump_backtrace+0x9c/0x128\n show_stack+0x20/0x38\n dump_stack_lvl+0x48/0x60\n print_report+0xf8/0x5d8\n kasan_report+0x90/0xd0\n __asan_store8+0x9c/0xc0\n \t [btrtl]\n h5_btrtl_setup+0xd0/0x2f8 [hci_uart]\n h5_setup+0x50/0x80 [hci_uart]\n hci_uart_setup+0xd4/0x260 [hci_uart]\n hci_dev_open_sync+0x1cc/0xf68 [bluetooth]\n hci_dev_do_open+0x34/0x90 [bluetooth]\n hci_power_on+0xc4/0x3c8 [bluetooth]\n process_one_work+0x328/0x6f0\n worker_thread+0x410/0x778\n kthread+0x168/0x178\n ret_from_fork+0x10/0x20\n\n Allocated by task 53:\n kasan_save_stack+0x3c/0x68\n kasan_save_track+0x20/0x40\n kasan_save_alloc_info+0x68/0x78\n __kasan_kmalloc+0xd4/0xd8\n __kmalloc+0x1b4/0x3b0\n hci_alloc_dev_priv+0x28/0xa58 [bluetooth]\n hci_uart_register_device+0x118/0x4f8 [hci_uart]\n h5_serdev_probe+0xf4/0x178 [hci_uart]\n serdev_drv_probe+0x54/0xa0\n really_probe+0x254/0x588\n __driver_probe_device+0xc4/0x210\n driver_probe_device+0x64/0x160\n __driver_attach_async_helper+0x88/0x158\n async_run_entry_fn+0xd0/0x388\n process_one_work+0x328/0x6f0\n worker_thread+0x410/0x778\n kthread+0x168/0x178\n ret_from_fork+0x10/0x20\n\n Last potentially related work creation:\n kasan_save_stack+0x3c/0x68\n __kasan_record_aux_stack+0xb0/0x150\n kasan_record_aux_stack_noalloc+0x14/0x20\n __queue_work+0x33c/0x960\n queue_work_on+0x98/0xc0\n hci_recv_frame+0xc8/0x1e8 [bluetooth]\n h5_complete_rx_pkt+0x2c8/0x800 [hci_uart]\n h5_rx_payload+0x98/0xb8 [hci_uart]\n h5_recv+0x158/0x3d8 [hci_uart]\n hci_uart_receive_buf+0xa0/0xe8 [hci_uart]\n ttyport_receive_buf+0xac/0x178\n flush_to_ldisc+0x130/0x2c8\n process_one_work+0x328/0x6f0\n worker_thread+0x410/0x778\n kthread+0x168/0x178\n ret_from_fork+0x10/0x20\n\n Second to last potentially related work creation:\n kasan_save_stack+0x3c/0x68\n __kasan_record_aux_stack+0xb0/0x150\n kasan_record_aux_stack_noalloc+0x14/0x20\n __queue_work+0x788/0x960\n queue_work_on+0x98/0xc0\n __hci_cmd_sync_sk+0x23c/0x7a0 [bluetooth]\n __hci_cmd_sync+0x24/0x38 [bluetooth]\n btrtl_initialize+0x760/0x958 [btrtl]\n h5_btrtl_setup+0xd0/0x2f8 [hci_uart]\n h5_setup+0x50/0x80 [hci_uart]\n hci_uart_setup+0xd4/0x260 [hci_uart]\n hci_dev_open_sync+0x1cc/0xf68 [bluetooth]\n hci_dev_do_open+0x34/0x90 [bluetooth]\n hci_power_on+0xc4/0x3c8 [bluetooth]\n process_one_work+0x328/0x6f0\n worker_thread+0x410/0x778\n kthread+0x168/0x178\n ret_from_fork+0x10/0x20\n ==================================================================", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T11:15:10Z" diff --git a/advisories/unreviewed/2024/04/GHSA-mqqf-w892-86vp/GHSA-mqqf-w892-86vp.json b/advisories/unreviewed/2024/04/GHSA-mqqf-w892-86vp/GHSA-mqqf-w892-86vp.json index 7829e852c8c..9eaaaa9c0be 100644 --- a/advisories/unreviewed/2024/04/GHSA-mqqf-w892-86vp/GHSA-mqqf-w892-86vp.json +++ b/advisories/unreviewed/2024/04/GHSA-mqqf-w892-86vp/GHSA-mqqf-w892-86vp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mqqf-w892-86vp", - "modified": "2024-06-26T00:31:36Z", + "modified": "2024-11-05T18:31:58Z", "published": "2024-04-03T18:30:42Z", "aliases": [ "CVE-2024-26747" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: roles: fix NULL pointer issue when put module's reference\n\nIn current design, usb role class driver will get usb_role_switch parent's\nmodule reference after the user get usb_role_switch device and put the\nreference after the user put the usb_role_switch device. However, the\nparent device of usb_role_switch may be removed before the user put the\nusb_role_switch. If so, then, NULL pointer issue will be met when the user\nput the parent module's reference.\n\nThis will save the module pointer in structure of usb_role_switch. Then,\nwe don't need to find module by iterating long relations.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -49,9 +52,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T17:15:51Z" diff --git a/advisories/unreviewed/2024/04/GHSA-p33p-qh45-v5wf/GHSA-p33p-qh45-v5wf.json b/advisories/unreviewed/2024/04/GHSA-p33p-qh45-v5wf/GHSA-p33p-qh45-v5wf.json index 21a00e24468..8df3cde97cc 100644 --- a/advisories/unreviewed/2024/04/GHSA-p33p-qh45-v5wf/GHSA-p33p-qh45-v5wf.json +++ b/advisories/unreviewed/2024/04/GHSA-p33p-qh45-v5wf/GHSA-p33p-qh45-v5wf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p33p-qh45-v5wf", - "modified": "2024-04-08T03:30:52Z", + "modified": "2024-11-05T18:31:58Z", "published": "2024-04-08T03:30:52Z", "aliases": [ "CVE-2023-52351" ], "details": "In ril service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-787" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-08T03:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-p3h5-5h52-p2q2/GHSA-p3h5-5h52-p2q2.json b/advisories/unreviewed/2024/04/GHSA-p3h5-5h52-p2q2/GHSA-p3h5-5h52-p2q2.json index 584a60b39c2..9bc565ffcc8 100644 --- a/advisories/unreviewed/2024/04/GHSA-p3h5-5h52-p2q2/GHSA-p3h5-5h52-p2q2.json +++ b/advisories/unreviewed/2024/04/GHSA-p3h5-5h52-p2q2/GHSA-p3h5-5h52-p2q2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p3h5-5h52-p2q2", - "modified": "2024-04-22T21:31:02Z", + "modified": "2024-11-05T18:31:58Z", "published": "2024-04-22T21:31:02Z", "aliases": [ "CVE-2024-29368" ], "details": "An issue discovered in moziloCMS v2.0 allows attackers to bypass file upload restrictions and run arbitrary code by changing the file extension after upload via crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-434" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-22T21:15:49Z" diff --git a/advisories/unreviewed/2024/04/GHSA-rvjh-mwxw-g897/GHSA-rvjh-mwxw-g897.json b/advisories/unreviewed/2024/04/GHSA-rvjh-mwxw-g897/GHSA-rvjh-mwxw-g897.json index 6d6935ea08d..f7bc2ffed6e 100644 --- a/advisories/unreviewed/2024/04/GHSA-rvjh-mwxw-g897/GHSA-rvjh-mwxw-g897.json +++ b/advisories/unreviewed/2024/04/GHSA-rvjh-mwxw-g897/GHSA-rvjh-mwxw-g897.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rvjh-mwxw-g897", - "modified": "2024-06-26T00:31:36Z", + "modified": "2024-11-05T18:31:58Z", "published": "2024-04-03T15:30:43Z", "aliases": [ "CVE-2024-26702" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\niio: magnetometer: rm3100: add boundary check for the value read from RM3100_REG_TMRC\n\nRecently, we encounter kernel crash in function rm3100_common_probe\ncaused by out of bound access of array rm3100_samp_rates (because of\nunderlying hardware failures). Add boundary check to prevent out of\nbound access.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-125" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T15:15:53Z" diff --git a/advisories/unreviewed/2024/05/GHSA-58qf-7xxx-pw82/GHSA-58qf-7xxx-pw82.json b/advisories/unreviewed/2024/05/GHSA-58qf-7xxx-pw82/GHSA-58qf-7xxx-pw82.json index 4b88755f6d6..432840c6149 100644 --- a/advisories/unreviewed/2024/05/GHSA-58qf-7xxx-pw82/GHSA-58qf-7xxx-pw82.json +++ b/advisories/unreviewed/2024/05/GHSA-58qf-7xxx-pw82/GHSA-58qf-7xxx-pw82.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-328" + "CWE-328", + "CWE-922" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-5c84-c56q-jq6c/GHSA-5c84-c56q-jq6c.json b/advisories/unreviewed/2024/05/GHSA-5c84-c56q-jq6c/GHSA-5c84-c56q-jq6c.json index e82695e7898..e6e402d0e62 100644 --- a/advisories/unreviewed/2024/05/GHSA-5c84-c56q-jq6c/GHSA-5c84-c56q-jq6c.json +++ b/advisories/unreviewed/2024/05/GHSA-5c84-c56q-jq6c/GHSA-5c84-c56q-jq6c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5c84-c56q-jq6c", - "modified": "2024-05-21T18:31:23Z", + "modified": "2024-11-05T18:31:59Z", "published": "2024-05-21T18:31:23Z", "aliases": [ "CVE-2023-52855" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: dwc2: fix possible NULL pointer dereference caused by driver concurrency\n\nIn _dwc2_hcd_urb_enqueue(), \"urb->hcpriv = NULL\" is executed without\nholding the lock \"hsotg->lock\". In _dwc2_hcd_urb_dequeue():\n\n spin_lock_irqsave(&hsotg->lock, flags);\n ...\n\tif (!urb->hcpriv) {\n\t\tdev_dbg(hsotg->dev, \"## urb->hcpriv is NULL ##\\n\");\n\t\tgoto out;\n\t}\n rc = dwc2_hcd_urb_dequeue(hsotg, urb->hcpriv); // Use urb->hcpriv\n ...\nout:\n spin_unlock_irqrestore(&hsotg->lock, flags);\n\nWhen _dwc2_hcd_urb_enqueue() and _dwc2_hcd_urb_dequeue() are\nconcurrently executed, the NULL check of \"urb->hcpriv\" can be executed\nbefore \"urb->hcpriv = NULL\". After urb->hcpriv is NULL, it can be used\nin the function call to dwc2_hcd_urb_dequeue(), which can cause a NULL\npointer dereference.\n\nThis possible bug is found by an experimental static analysis tool\ndeveloped by myself. This tool analyzes the locking APIs to extract\nfunction pairs that can be concurrently executed, and then analyzes the\ninstructions in the paired functions to identify possible concurrency\nbugs including data races and atomicity violations. The above possible\nbug is reported, when my tool analyzes the source code of Linux 6.5.\n\nTo fix this possible bug, \"urb->hcpriv = NULL\" should be executed with\nholding the lock \"hsotg->lock\". After using this patch, my tool never\nreports the possible bug, with the kernelconfiguration allyesconfig for\nx86_64. Because I have no associated hardware, I cannot test the patch\nin runtime testing, and just verify it according to the code logic.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -57,9 +60,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T16:15:22Z" diff --git a/advisories/unreviewed/2024/05/GHSA-6j2j-fwgf-fcf6/GHSA-6j2j-fwgf-fcf6.json b/advisories/unreviewed/2024/05/GHSA-6j2j-fwgf-fcf6/GHSA-6j2j-fwgf-fcf6.json index fb92d526d2f..c52f2c3ea6a 100644 --- a/advisories/unreviewed/2024/05/GHSA-6j2j-fwgf-fcf6/GHSA-6j2j-fwgf-fcf6.json +++ b/advisories/unreviewed/2024/05/GHSA-6j2j-fwgf-fcf6/GHSA-6j2j-fwgf-fcf6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6j2j-fwgf-fcf6", - "modified": "2024-05-21T18:31:22Z", + "modified": "2024-11-05T18:31:59Z", "published": "2024-05-21T18:31:22Z", "aliases": [ "CVE-2023-52828" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Detect IP == ksym.end as part of BPF program\n\nNow that bpf_throw kfunc is the first such call instruction that has\nnoreturn semantics within the verifier, this also kicks in dead code\nelimination in unprecedented ways. For one, any instruction following\na bpf_throw call will never be marked as seen. Moreover, if a callchain\nends up throwing, any instructions after the call instruction to the\neventually throwing subprog in callers will also never be marked as\nseen.\n\nThe tempting way to fix this would be to emit extra 'int3' instructions\nwhich bump the jited_len of a program, and ensure that during runtime\nwhen a program throws, we can discover its boundaries even if the call\ninstruction to bpf_throw (or to subprogs that always throw) is emitted\nas the final instruction in the program.\n\nAn example of such a program would be this:\n\ndo_something():\n\t...\n\tr0 = 0\n\texit\n\nfoo():\n\tr1 = 0\n\tcall bpf_throw\n\tr0 = 0\n\texit\n\nbar(cond):\n\tif r1 != 0 goto pc+2\n\tcall do_something\n\texit\n\tcall foo\n\tr0 = 0 // Never seen by verifier\n\texit\t//\n\nmain(ctx):\n\tr1 = ...\n\tcall bar\n\tr0 = 0\n\texit\n\nHere, if we do end up throwing, the stacktrace would be the following:\n\nbpf_throw\nfoo\nbar\nmain\n\nIn bar, the final instruction emitted will be the call to foo, as such,\nthe return address will be the subsequent instruction (which the JIT\nemits as int3 on x86). This will end up lying outside the jited_len of\nthe program, thus, when unwinding, we will fail to discover the return\naddress as belonging to any program and end up in a panic due to the\nunreliable stack unwinding of BPF programs that we never expect.\n\nTo remedy this case, make bpf_prog_ksym_find treat IP == ksym.end as\npart of the BPF program, so that is_bpf_text_address returns true when\nsuch a case occurs, and we are able to unwind reliably when the final\ninstruction ends up being a call instruction.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L" + } ], "affected": [ @@ -47,7 +50,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T16:15:20Z" diff --git a/advisories/unreviewed/2024/05/GHSA-7qcg-gp93-223m/GHSA-7qcg-gp93-223m.json b/advisories/unreviewed/2024/05/GHSA-7qcg-gp93-223m/GHSA-7qcg-gp93-223m.json index 7e2e71cd4c2..33b82b41984 100644 --- a/advisories/unreviewed/2024/05/GHSA-7qcg-gp93-223m/GHSA-7qcg-gp93-223m.json +++ b/advisories/unreviewed/2024/05/GHSA-7qcg-gp93-223m/GHSA-7qcg-gp93-223m.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7qcg-gp93-223m", - "modified": "2024-05-22T09:31:45Z", + "modified": "2024-11-05T18:31:59Z", "published": "2024-05-22T09:31:45Z", "aliases": [ "CVE-2021-47467" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nkunit: fix reference count leak in kfree_at_end\n\nThe reference counting issue happens in the normal path of\nkfree_at_end(). When kunit_alloc_and_get_resource() is invoked, the\nfunction forgets to handle the returned resource object, whose refcount\nincreased inside, causing a refcount leak.\n\nFix this issue by calling kunit_alloc_resource() instead of\nkunit_alloc_and_get_resource().\n\nFixed the following when applying:\nShuah Khan \n\nCHECK: Alignment should match open parenthesis\n+\tkunit_alloc_resource(test, NULL, kfree_res_free, GFP_KERNEL,\n \t\t\t\t (void *)to_free);", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } ], "affected": [ @@ -31,7 +34,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-22T07:15:11Z" diff --git a/advisories/unreviewed/2024/05/GHSA-8j5q-6cq4-63x9/GHSA-8j5q-6cq4-63x9.json b/advisories/unreviewed/2024/05/GHSA-8j5q-6cq4-63x9/GHSA-8j5q-6cq4-63x9.json index d495f205b12..10cb7d137b2 100644 --- a/advisories/unreviewed/2024/05/GHSA-8j5q-6cq4-63x9/GHSA-8j5q-6cq4-63x9.json +++ b/advisories/unreviewed/2024/05/GHSA-8j5q-6cq4-63x9/GHSA-8j5q-6cq4-63x9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8j5q-6cq4-63x9", - "modified": "2024-05-14T18:30:48Z", + "modified": "2024-11-05T18:31:59Z", "published": "2024-05-14T18:30:48Z", "aliases": [ "CVE-2024-33875" ], "details": "HDF5 Library through 1.14.3 has a heap-based buffer overflow in H5O__layout_encode in H5Olayout.c, resulting in the corruption of the instruction pointer.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-14T15:38:10Z" diff --git a/advisories/unreviewed/2024/05/GHSA-g77r-j94w-3wm3/GHSA-g77r-j94w-3wm3.json b/advisories/unreviewed/2024/05/GHSA-g77r-j94w-3wm3/GHSA-g77r-j94w-3wm3.json index 728d81eb0f8..0d2c94528b5 100644 --- a/advisories/unreviewed/2024/05/GHSA-g77r-j94w-3wm3/GHSA-g77r-j94w-3wm3.json +++ b/advisories/unreviewed/2024/05/GHSA-g77r-j94w-3wm3/GHSA-g77r-j94w-3wm3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g77r-j94w-3wm3", - "modified": "2024-05-01T15:30:34Z", + "modified": "2024-11-05T18:31:58Z", "published": "2024-05-01T15:30:34Z", "aliases": [ "CVE-2023-52653" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nSUNRPC: fix a memleak in gss_import_v2_context\n\nThe ctx->mech_used.data allocated by kmemdup is not freed in neither\ngss_import_v2_context nor it only caller gss_krb5_import_sec_context,\nwhich frees ctx on error.\n\nThus, this patch reform the last call of gss_import_v2_context to the\ngss_krb5_import_ctx_v2, preventing the memleak while keepping the return\nformation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -39,7 +42,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-01T13:15:48Z" diff --git a/advisories/unreviewed/2024/05/GHSA-j4gv-c6jh-pvhm/GHSA-j4gv-c6jh-pvhm.json b/advisories/unreviewed/2024/05/GHSA-j4gv-c6jh-pvhm/GHSA-j4gv-c6jh-pvhm.json index 8790a86a111..6a6f0d62540 100644 --- a/advisories/unreviewed/2024/05/GHSA-j4gv-c6jh-pvhm/GHSA-j4gv-c6jh-pvhm.json +++ b/advisories/unreviewed/2024/05/GHSA-j4gv-c6jh-pvhm/GHSA-j4gv-c6jh-pvhm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j4gv-c6jh-pvhm", - "modified": "2024-05-01T15:30:36Z", + "modified": "2024-11-05T18:31:58Z", "published": "2024-05-01T15:30:36Z", "aliases": [ "CVE-2024-27062" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnouveau: lock the client object tree.\n\nIt appears the client object tree has no locking unless I've missed\nsomething else. Fix races around adding/removing client objects,\nmostly vram bar mappings.\n\n 4562.099306] general protection fault, probably for non-canonical address 0x6677ed422bceb80c: 0000 [#1] PREEMPT SMP PTI\n[ 4562.099314] CPU: 2 PID: 23171 Comm: deqp-vk Not tainted 6.8.0-rc6+ #27\n[ 4562.099324] Hardware name: Gigabyte Technology Co., Ltd. Z390 I AORUS PRO WIFI/Z390 I AORUS PRO WIFI-CF, BIOS F8 11/05/2021\n[ 4562.099330] RIP: 0010:nvkm_object_search+0x1d/0x70 [nouveau]\n[ 4562.099503] Code: 90 90 90 90 90 90 90 90 90 90 90 90 90 66 0f 1f 00 0f 1f 44 00 00 48 89 f8 48 85 f6 74 39 48 8b 87 a0 00 00 00 48 85 c0 74 12 <48> 8b 48 f8 48 39 ce 73 15 48 8b 40 10 48 85 c0 75 ee 48 c7 c0 fe\n[ 4562.099506] RSP: 0000:ffffa94cc420bbf8 EFLAGS: 00010206\n[ 4562.099512] RAX: 6677ed422bceb814 RBX: ffff98108791f400 RCX: ffff9810f26b8f58\n[ 4562.099517] RDX: 0000000000000000 RSI: ffff9810f26b9158 RDI: ffff98108791f400\n[ 4562.099519] RBP: ffff9810f26b9158 R08: 0000000000000000 R09: 0000000000000000\n[ 4562.099521] R10: ffffa94cc420bc48 R11: 0000000000000001 R12: ffff9810f02a7cc0\n[ 4562.099526] R13: 0000000000000000 R14: 00000000000000ff R15: 0000000000000007\n[ 4562.099528] FS: 00007f629c5017c0(0000) GS:ffff98142c700000(0000) knlGS:0000000000000000\n[ 4562.099534] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 4562.099536] CR2: 00007f629a882000 CR3: 000000017019e004 CR4: 00000000003706f0\n[ 4562.099541] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n[ 4562.099542] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n[ 4562.099544] Call Trace:\n[ 4562.099555] \n[ 4562.099573] ? die_addr+0x36/0x90\n[ 4562.099583] ? exc_general_protection+0x246/0x4a0\n[ 4562.099593] ? asm_exc_general_protection+0x26/0x30\n[ 4562.099600] ? nvkm_object_search+0x1d/0x70 [nouveau]\n[ 4562.099730] nvkm_ioctl+0xa1/0x250 [nouveau]\n[ 4562.099861] nvif_object_map_handle+0xc8/0x180 [nouveau]\n[ 4562.099986] nouveau_ttm_io_mem_reserve+0x122/0x270 [nouveau]\n[ 4562.100156] ? dma_resv_test_signaled+0x26/0xb0\n[ 4562.100163] ttm_bo_vm_fault_reserved+0x97/0x3c0 [ttm]\n[ 4562.100182] ? __mutex_unlock_slowpath+0x2a/0x270\n[ 4562.100189] nouveau_ttm_fault+0x69/0xb0 [nouveau]\n[ 4562.100356] __do_fault+0x32/0x150\n[ 4562.100362] do_fault+0x7c/0x560\n[ 4562.100369] __handle_mm_fault+0x800/0xc10\n[ 4562.100382] handle_mm_fault+0x17c/0x3e0\n[ 4562.100388] do_user_addr_fault+0x208/0x860\n[ 4562.100395] exc_page_fault+0x7f/0x200\n[ 4562.100402] asm_exc_page_fault+0x26/0x30\n[ 4562.100412] RIP: 0033:0x9b9870\n[ 4562.100419] Code: 85 a8 f7 ff ff 8b 8d 80 f7 ff ff 89 08 e9 18 f2 ff ff 0f 1f 84 00 00 00 00 00 44 89 32 e9 90 fa ff ff 0f 1f 84 00 00 00 00 00 <44> 89 32 e9 f8 f1 ff ff 0f 1f 84 00 00 00 00 00 66 44 89 32 e9 e7\n[ 4562.100422] RSP: 002b:00007fff9ba2dc70 EFLAGS: 00010246\n[ 4562.100426] RAX: 0000000000000004 RBX: 000000000dd65e10 RCX: 000000fff0000000\n[ 4562.100428] RDX: 00007f629a882000 RSI: 00007f629a882000 RDI: 0000000000000066\n[ 4562.100432] RBP: 00007fff9ba2e570 R08: 0000000000000000 R09: 0000000123ddf000\n[ 4562.100434] R10: 0000000000000001 R11: 0000000000000246 R12: 000000007fffffff\n[ 4562.100436] R13: 0000000000000000 R14: 0000000000000000 R15: 0000000000000000\n[ 4562.100446] \n[ 4562.100448] Modules linked in: nf_conntrack_netbios_ns nf_conntrack_broadcast nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 ip_set nf_tables libcrc32c nfnetlink cmac bnep sunrpc iwlmvm intel_rapl_msr intel_rapl_common snd_sof_pci_intel_cnl x86_pkg_temp_thermal intel_powerclamp snd_sof_intel_hda_common mac80211 coretemp snd_soc_acpi_intel_match kvm_intel snd_soc_acpi snd_soc_hdac_hda snd_sof_pci snd_sof_xtensa_dsp snd_sof_intel_hda_mlink \n---truncated---", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-01T13:15:50Z" diff --git a/advisories/unreviewed/2024/05/GHSA-jhg5-q2mj-r9vh/GHSA-jhg5-q2mj-r9vh.json b/advisories/unreviewed/2024/05/GHSA-jhg5-q2mj-r9vh/GHSA-jhg5-q2mj-r9vh.json index 5957d625aa1..98a2e7569bf 100644 --- a/advisories/unreviewed/2024/05/GHSA-jhg5-q2mj-r9vh/GHSA-jhg5-q2mj-r9vh.json +++ b/advisories/unreviewed/2024/05/GHSA-jhg5-q2mj-r9vh/GHSA-jhg5-q2mj-r9vh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jhg5-q2mj-r9vh", - "modified": "2024-05-21T15:31:42Z", + "modified": "2024-11-05T18:31:59Z", "published": "2024-05-21T15:31:42Z", "aliases": [ "CVE-2021-47312" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: Fix dereference of null pointer flow\n\nIn the case where chain->flags & NFT_CHAIN_HW_OFFLOAD is false then\nnft_flow_rule_create is not called and flow is NULL. The subsequent\nerror handling execution via label err_destroy_flow_rule will lead\nto a null pointer dereference on flow when calling nft_flow_rule_destroy.\nSince the error path to err_destroy_flow_rule has to cater for null\nand non-null flows, only call nft_flow_rule_destroy if flow is non-null\nto fix this issue.\n\nAddresses-Coverity: (\"Explicity null dereference\")", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T15:15:18Z" diff --git a/advisories/unreviewed/2024/05/GHSA-m9gp-fqr3-w459/GHSA-m9gp-fqr3-w459.json b/advisories/unreviewed/2024/05/GHSA-m9gp-fqr3-w459/GHSA-m9gp-fqr3-w459.json index 6dd2c5ca307..3b443cdb309 100644 --- a/advisories/unreviewed/2024/05/GHSA-m9gp-fqr3-w459/GHSA-m9gp-fqr3-w459.json +++ b/advisories/unreviewed/2024/05/GHSA-m9gp-fqr3-w459/GHSA-m9gp-fqr3-w459.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m9gp-fqr3-w459", - "modified": "2024-05-21T18:31:22Z", + "modified": "2024-11-05T18:31:59Z", "published": "2024-05-21T18:31:22Z", "aliases": [ "CVE-2023-52825" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdkfd: Fix a race condition of vram buffer unref in svm code\n\nprange->svm_bo unref can happen in both mmu callback and a callback after\nmigrate to system ram. Both are async call in different tasks. Sync svm_bo\nunref operation to avoid random \"use-after-free\".", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -41,9 +44,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-362" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T16:15:20Z" diff --git a/advisories/unreviewed/2024/05/GHSA-p672-9qr7-4cmf/GHSA-p672-9qr7-4cmf.json b/advisories/unreviewed/2024/05/GHSA-p672-9qr7-4cmf/GHSA-p672-9qr7-4cmf.json index 0be61a2a0ac..1292eb60e86 100644 --- a/advisories/unreviewed/2024/05/GHSA-p672-9qr7-4cmf/GHSA-p672-9qr7-4cmf.json +++ b/advisories/unreviewed/2024/05/GHSA-p672-9qr7-4cmf/GHSA-p672-9qr7-4cmf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p672-9qr7-4cmf", - "modified": "2024-05-03T03:30:47Z", + "modified": "2024-11-05T18:31:58Z", "published": "2024-05-01T06:31:43Z", "aliases": [ "CVE-2024-27005" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ninterconnect: Don't access req_list while it's being manipulated\n\nThe icc_lock mutex was split into separate icc_lock and icc_bw_lock\nmutexes in [1] to avoid lockdep splats. However, this didn't adequately\nprotect access to icc_node::req_list.\n\nThe icc_set_bw() function will eventually iterate over req_list while\nonly holding icc_bw_lock, but req_list can be modified while only\nholding icc_lock. This causes races between icc_set_bw(), of_icc_get(),\nand icc_put().\n\nExample A:\n\n CPU0 CPU1\n ---- ----\n icc_set_bw(path_a)\n mutex_lock(&icc_bw_lock);\n icc_put(path_b)\n mutex_lock(&icc_lock);\n aggregate_requests()\n hlist_for_each_entry(r, ...\n hlist_del(...\n \n\nExample B:\n\n CPU0 CPU1\n ---- ----\n icc_set_bw(path_a)\n mutex_lock(&icc_bw_lock);\n path_b = of_icc_get()\n of_icc_get_by_index()\n mutex_lock(&icc_lock);\n path_find()\n path_init()\n aggregate_requests()\n hlist_for_each_entry(r, ...\n hlist_add_head(...\n \n\nFix this by ensuring icc_bw_lock is always held before manipulating\nicc_node::req_list. The additional places icc_bw_lock is held don't\nperform any memory allocations, so we should still be safe from the\noriginal lockdep splats that motivated the separate locks.\n\n[1] commit af42269c3523 (\"interconnect: Fix locking for runpm vs reclaim\")", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H" + } ], "affected": [ @@ -47,7 +50,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-01T06:15:18Z" diff --git a/advisories/unreviewed/2024/05/GHSA-v86r-5x9g-5q8j/GHSA-v86r-5x9g-5q8j.json b/advisories/unreviewed/2024/05/GHSA-v86r-5x9g-5q8j/GHSA-v86r-5x9g-5q8j.json index 0b680be6405..a8dd6add545 100644 --- a/advisories/unreviewed/2024/05/GHSA-v86r-5x9g-5q8j/GHSA-v86r-5x9g-5q8j.json +++ b/advisories/unreviewed/2024/05/GHSA-v86r-5x9g-5q8j/GHSA-v86r-5x9g-5q8j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v86r-5x9g-5q8j", - "modified": "2024-06-26T00:31:43Z", + "modified": "2024-11-05T18:31:59Z", "published": "2024-05-19T12:30:39Z", "aliases": [ "CVE-2024-35940" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\npstore/zone: Add a null pointer check to the psz_kmsg_read\n\nkasprintf() returns a pointer to dynamically allocated memory\nwhich can be NULL upon failure. Ensure the allocation was successful\nby checking the pointer validity.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -49,9 +52,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-476" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-19T11:15:49Z" diff --git a/advisories/unreviewed/2024/06/GHSA-723f-c7g3-864c/GHSA-723f-c7g3-864c.json b/advisories/unreviewed/2024/06/GHSA-723f-c7g3-864c/GHSA-723f-c7g3-864c.json index 95c094729e9..e5ffc660af3 100644 --- a/advisories/unreviewed/2024/06/GHSA-723f-c7g3-864c/GHSA-723f-c7g3-864c.json +++ b/advisories/unreviewed/2024/06/GHSA-723f-c7g3-864c/GHSA-723f-c7g3-864c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-723f-c7g3-864c", - "modified": "2024-06-25T21:31:17Z", + "modified": "2024-11-05T18:31:59Z", "published": "2024-06-25T21:31:17Z", "aliases": [ "CVE-2024-34400" ], "details": "An issue was discovered in VirtoSoftware Virto Kanban Board Web Part before 5.3.5.1 for SharePoint 2019. There is /_layouts/15/Virto.KanbanTaskManager/api/KanbanData.ashx LinkTitle2 XSS.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-25T21:15:59Z" diff --git a/advisories/unreviewed/2024/06/GHSA-hf2g-j6wm-qrrx/GHSA-hf2g-j6wm-qrrx.json b/advisories/unreviewed/2024/06/GHSA-hf2g-j6wm-qrrx/GHSA-hf2g-j6wm-qrrx.json index 899098bb1cf..5428fa188c6 100644 --- a/advisories/unreviewed/2024/06/GHSA-hf2g-j6wm-qrrx/GHSA-hf2g-j6wm-qrrx.json +++ b/advisories/unreviewed/2024/06/GHSA-hf2g-j6wm-qrrx/GHSA-hf2g-j6wm-qrrx.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hf2g-j6wm-qrrx", - "modified": "2024-06-25T15:31:09Z", + "modified": "2024-11-05T18:31:59Z", "published": "2024-06-25T15:31:09Z", "aliases": [ "CVE-2024-39276" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\next4: fix mb_cache_entry's e_refcnt leak in ext4_xattr_block_cache_find()\n\nSyzbot reports a warning as follows:\n\n============================================\nWARNING: CPU: 0 PID: 5075 at fs/mbcache.c:419 mb_cache_destroy+0x224/0x290\nModules linked in:\nCPU: 0 PID: 5075 Comm: syz-executor199 Not tainted 6.9.0-rc6-gb947cc5bf6d7\nRIP: 0010:mb_cache_destroy+0x224/0x290 fs/mbcache.c:419\nCall Trace:\n \n ext4_put_super+0x6d4/0xcd0 fs/ext4/super.c:1375\n generic_shutdown_super+0x136/0x2d0 fs/super.c:641\n kill_block_super+0x44/0x90 fs/super.c:1675\n ext4_kill_sb+0x68/0xa0 fs/ext4/super.c:7327\n[...]\n============================================\n\nThis is because when finding an entry in ext4_xattr_block_cache_find(), if\next4_sb_bread() returns -ENOMEM, the ce's e_refcnt, which has already grown\nin the __entry_find(), won't be put away, and eventually trigger the above\nissue in mb_cache_destroy() due to reference count leakage.\n\nSo call mb_cache_entry_put() on the -ENOMEM error branch as a quick fix.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -55,7 +58,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-25T15:15:13Z" diff --git a/advisories/unreviewed/2024/06/GHSA-hfr2-rr32-h89p/GHSA-hfr2-rr32-h89p.json b/advisories/unreviewed/2024/06/GHSA-hfr2-rr32-h89p/GHSA-hfr2-rr32-h89p.json index db3d877eaca..a0277241157 100644 --- a/advisories/unreviewed/2024/06/GHSA-hfr2-rr32-h89p/GHSA-hfr2-rr32-h89p.json +++ b/advisories/unreviewed/2024/06/GHSA-hfr2-rr32-h89p/GHSA-hfr2-rr32-h89p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hfr2-rr32-h89p", - "modified": "2024-06-19T15:30:54Z", + "modified": "2024-11-05T18:31:59Z", "published": "2024-06-19T15:30:54Z", "aliases": [ "CVE-2021-47580" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: scsi_debug: Fix type in min_t to avoid stack OOB\n\nChange min_t() to use type \"u32\" instead of type \"int\" to avoid stack out\nof bounds. With min_t() type \"int\" the values get sign extended and the\nlarger value gets used causing stack out of bounds.\n\nBUG: KASAN: stack-out-of-bounds in memcpy include/linux/fortify-string.h:191 [inline]\nBUG: KASAN: stack-out-of-bounds in sg_copy_buffer+0x1de/0x240 lib/scatterlist.c:976\nRead of size 127 at addr ffff888072607128 by task syz-executor.7/18707\n\nCPU: 1 PID: 18707 Comm: syz-executor.7 Not tainted 5.15.0-syzk #1\nHardware name: Red Hat KVM, BIOS 1.13.0-2\nCall Trace:\n __dump_stack lib/dump_stack.c:88 [inline]\n dump_stack_lvl+0x89/0xb5 lib/dump_stack.c:106\n print_address_description.constprop.9+0x28/0x160 mm/kasan/report.c:256\n __kasan_report mm/kasan/report.c:442 [inline]\n kasan_report.cold.14+0x7d/0x117 mm/kasan/report.c:459\n check_region_inline mm/kasan/generic.c:183 [inline]\n kasan_check_range+0x1a3/0x210 mm/kasan/generic.c:189\n memcpy+0x23/0x60 mm/kasan/shadow.c:65\n memcpy include/linux/fortify-string.h:191 [inline]\n sg_copy_buffer+0x1de/0x240 lib/scatterlist.c:976\n sg_copy_from_buffer+0x33/0x40 lib/scatterlist.c:1000\n fill_from_dev_buffer.part.34+0x82/0x130 drivers/scsi/scsi_debug.c:1162\n fill_from_dev_buffer drivers/scsi/scsi_debug.c:1888 [inline]\n resp_readcap16+0x365/0x3b0 drivers/scsi/scsi_debug.c:1887\n schedule_resp+0x4d8/0x1a70 drivers/scsi/scsi_debug.c:5478\n scsi_debug_queuecommand+0x8c9/0x1ec0 drivers/scsi/scsi_debug.c:7533\n scsi_dispatch_cmd drivers/scsi/scsi_lib.c:1520 [inline]\n scsi_queue_rq+0x16b0/0x2d40 drivers/scsi/scsi_lib.c:1699\n blk_mq_dispatch_rq_list+0xb9b/0x2700 block/blk-mq.c:1639\n __blk_mq_sched_dispatch_requests+0x28f/0x590 block/blk-mq-sched.c:325\n blk_mq_sched_dispatch_requests+0x105/0x190 block/blk-mq-sched.c:358\n __blk_mq_run_hw_queue+0xe5/0x150 block/blk-mq.c:1761\n __blk_mq_delay_run_hw_queue+0x4f8/0x5c0 block/blk-mq.c:1838\n blk_mq_run_hw_queue+0x18d/0x350 block/blk-mq.c:1891\n blk_mq_sched_insert_request+0x3db/0x4e0 block/blk-mq-sched.c:474\n blk_execute_rq_nowait+0x16b/0x1c0 block/blk-exec.c:62\n sg_common_write.isra.18+0xeb3/0x2000 drivers/scsi/sg.c:836\n sg_new_write.isra.19+0x570/0x8c0 drivers/scsi/sg.c:774\n sg_ioctl_common+0x14d6/0x2710 drivers/scsi/sg.c:939\n sg_ioctl+0xa2/0x180 drivers/scsi/sg.c:1165\n vfs_ioctl fs/ioctl.c:51 [inline]\n __do_sys_ioctl fs/ioctl.c:874 [inline]\n __se_sys_ioctl fs/ioctl.c:860 [inline]\n __x64_sys_ioctl+0x19d/0x220 fs/ioctl.c:860\n do_syscall_x64 arch/x86/entry/common.c:50 [inline]\n do_syscall_64+0x3a/0x80 arch/x86/entry/common.c:80\n entry_SYSCALL_64_after_hwframe+0x44/0xae", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L" + } ], "affected": [ @@ -35,7 +38,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-19T15:15:52Z" diff --git a/advisories/unreviewed/2024/06/GHSA-j3f4-rf7c-whp5/GHSA-j3f4-rf7c-whp5.json b/advisories/unreviewed/2024/06/GHSA-j3f4-rf7c-whp5/GHSA-j3f4-rf7c-whp5.json index f956b0262d5..678770f122f 100644 --- a/advisories/unreviewed/2024/06/GHSA-j3f4-rf7c-whp5/GHSA-j3f4-rf7c-whp5.json +++ b/advisories/unreviewed/2024/06/GHSA-j3f4-rf7c-whp5/GHSA-j3f4-rf7c-whp5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j3f4-rf7c-whp5", - "modified": "2024-06-27T00:31:04Z", + "modified": "2024-11-05T18:31:59Z", "published": "2024-06-27T00:31:04Z", "aliases": [ "CVE-2024-37571" ], "details": "Buffer Overflow vulnerability in SAS Broker 9.2 build 1495 allows attackers to cause denial of service or obtain sensitive information via crafted payload to the '_debug' parameter.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-26T22:15:10Z" diff --git a/advisories/unreviewed/2024/06/GHSA-ppv3-rxm7-w9p5/GHSA-ppv3-rxm7-w9p5.json b/advisories/unreviewed/2024/06/GHSA-ppv3-rxm7-w9p5/GHSA-ppv3-rxm7-w9p5.json index 5d0ef21ca12..d0cb13497b1 100644 --- a/advisories/unreviewed/2024/06/GHSA-ppv3-rxm7-w9p5/GHSA-ppv3-rxm7-w9p5.json +++ b/advisories/unreviewed/2024/06/GHSA-ppv3-rxm7-w9p5/GHSA-ppv3-rxm7-w9p5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-ppv3-rxm7-w9p5", - "modified": "2024-06-21T12:31:20Z", + "modified": "2024-11-05T18:31:59Z", "published": "2024-06-21T12:31:20Z", "aliases": [ "CVE-2024-38628" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: u_audio: Fix race condition use of controls after free during gadget unbind.\n\nHang on to the control IDs instead of pointers since those are correctly\nhandled with locks.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -37,9 +40,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-362" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-21T11:15:11Z" diff --git a/advisories/unreviewed/2024/06/GHSA-v9jr-v6vm-vm67/GHSA-v9jr-v6vm-vm67.json b/advisories/unreviewed/2024/06/GHSA-v9jr-v6vm-vm67/GHSA-v9jr-v6vm-vm67.json index 334bd13296a..1d39dbdb617 100644 --- a/advisories/unreviewed/2024/06/GHSA-v9jr-v6vm-vm67/GHSA-v9jr-v6vm-vm67.json +++ b/advisories/unreviewed/2024/06/GHSA-v9jr-v6vm-vm67/GHSA-v9jr-v6vm-vm67.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v9jr-v6vm-vm67", - "modified": "2024-06-24T15:31:44Z", + "modified": "2024-11-05T18:31:59Z", "published": "2024-06-24T15:31:44Z", "aliases": [ "CVE-2024-34027" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: compress: fix to cover {reserve,release}_compress_blocks() w/ cp_rwsem lock\n\nIt needs to cover {reserve,release}_compress_blocks() w/ cp_rwsem lock\nto avoid racing with checkpoint, otherwise, filesystem metadata including\nblkaddr in dnode, inode fields and .total_valid_block_count may be\ncorrupted after SPO case.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -45,9 +48,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-770" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-24T14:15:11Z" diff --git a/advisories/unreviewed/2024/07/GHSA-6mmr-3476-3p9f/GHSA-6mmr-3476-3p9f.json b/advisories/unreviewed/2024/07/GHSA-6mmr-3476-3p9f/GHSA-6mmr-3476-3p9f.json index f48932dc988..d216c827977 100644 --- a/advisories/unreviewed/2024/07/GHSA-6mmr-3476-3p9f/GHSA-6mmr-3476-3p9f.json +++ b/advisories/unreviewed/2024/07/GHSA-6mmr-3476-3p9f/GHSA-6mmr-3476-3p9f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-6mmr-3476-3p9f", - "modified": "2024-07-17T00:32:54Z", + "modified": "2024-11-05T18:31:59Z", "published": "2024-07-17T00:32:54Z", "aliases": [ "CVE-2023-7013" ], "details": "Inappropriate implementation in Compositing in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to potentially spoof security UI via a crafted HTML page. (Chromium security severity: Medium)", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-1021" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-07-16T23:15:11Z" diff --git a/advisories/unreviewed/2024/07/GHSA-hmx6-p7wx-42x3/GHSA-hmx6-p7wx-42x3.json b/advisories/unreviewed/2024/07/GHSA-hmx6-p7wx-42x3/GHSA-hmx6-p7wx-42x3.json index 4f8459571dd..dee360193a7 100644 --- a/advisories/unreviewed/2024/07/GHSA-hmx6-p7wx-42x3/GHSA-hmx6-p7wx-42x3.json +++ b/advisories/unreviewed/2024/07/GHSA-hmx6-p7wx-42x3/GHSA-hmx6-p7wx-42x3.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-j9wf-jqvx-9wrw/GHSA-j9wf-jqvx-9wrw.json b/advisories/unreviewed/2024/07/GHSA-j9wf-jqvx-9wrw/GHSA-j9wf-jqvx-9wrw.json index a0119d99f1c..9a8a4a2960c 100644 --- a/advisories/unreviewed/2024/07/GHSA-j9wf-jqvx-9wrw/GHSA-j9wf-jqvx-9wrw.json +++ b/advisories/unreviewed/2024/07/GHSA-j9wf-jqvx-9wrw/GHSA-j9wf-jqvx-9wrw.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-276" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/08/GHSA-rj66-wvw5-rcvp/GHSA-rj66-wvw5-rcvp.json b/advisories/unreviewed/2024/08/GHSA-rj66-wvw5-rcvp/GHSA-rj66-wvw5-rcvp.json index 98d57efdb2f..33fc42de1f3 100644 --- a/advisories/unreviewed/2024/08/GHSA-rj66-wvw5-rcvp/GHSA-rj66-wvw5-rcvp.json +++ b/advisories/unreviewed/2024/08/GHSA-rj66-wvw5-rcvp/GHSA-rj66-wvw5-rcvp.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-459" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-2m59-x3qc-r6mm/GHSA-2m59-x3qc-r6mm.json b/advisories/unreviewed/2024/10/GHSA-2m59-x3qc-r6mm/GHSA-2m59-x3qc-r6mm.json index c16cf96aed1..370920ea392 100644 --- a/advisories/unreviewed/2024/10/GHSA-2m59-x3qc-r6mm/GHSA-2m59-x3qc-r6mm.json +++ b/advisories/unreviewed/2024/10/GHSA-2m59-x3qc-r6mm/GHSA-2m59-x3qc-r6mm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2m59-x3qc-r6mm", - "modified": "2024-10-25T09:32:00Z", + "modified": "2024-11-05T18:32:01Z", "published": "2024-10-25T09:32:00Z", "aliases": [ "CVE-2024-9302" diff --git a/advisories/unreviewed/2024/10/GHSA-59xx-g8cv-87qw/GHSA-59xx-g8cv-87qw.json b/advisories/unreviewed/2024/10/GHSA-59xx-g8cv-87qw/GHSA-59xx-g8cv-87qw.json index dc7585f9ff6..8c976697c16 100644 --- a/advisories/unreviewed/2024/10/GHSA-59xx-g8cv-87qw/GHSA-59xx-g8cv-87qw.json +++ b/advisories/unreviewed/2024/10/GHSA-59xx-g8cv-87qw/GHSA-59xx-g8cv-87qw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-59xx-g8cv-87qw", - "modified": "2024-10-28T18:31:41Z", + "modified": "2024-11-05T18:32:02Z", "published": "2024-10-28T18:31:41Z", "aliases": [ "CVE-2024-10469" ], "details": "VINCE versions before 3.0.9 is vulnerable to exposure of User information to authenticated users.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-276" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-28T16:15:03Z" diff --git a/advisories/unreviewed/2024/10/GHSA-5p85-p472-x7wv/GHSA-5p85-p472-x7wv.json b/advisories/unreviewed/2024/10/GHSA-5p85-p472-x7wv/GHSA-5p85-p472-x7wv.json index af948854016..a4b26d3af79 100644 --- a/advisories/unreviewed/2024/10/GHSA-5p85-p472-x7wv/GHSA-5p85-p472-x7wv.json +++ b/advisories/unreviewed/2024/10/GHSA-5p85-p472-x7wv/GHSA-5p85-p472-x7wv.json @@ -36,7 +36,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-770" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/10/GHSA-mjhm-5r72-mjx7/GHSA-mjhm-5r72-mjx7.json b/advisories/unreviewed/2024/10/GHSA-mjhm-5r72-mjx7/GHSA-mjhm-5r72-mjx7.json index c2b77767513..d45074ac873 100644 --- a/advisories/unreviewed/2024/10/GHSA-mjhm-5r72-mjx7/GHSA-mjhm-5r72-mjx7.json +++ b/advisories/unreviewed/2024/10/GHSA-mjhm-5r72-mjx7/GHSA-mjhm-5r72-mjx7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mjhm-5r72-mjx7", - "modified": "2024-10-24T21:31:04Z", + "modified": "2024-11-05T18:32:01Z", "published": "2024-10-24T21:31:04Z", "aliases": [ "CVE-2024-48423" ], "details": "An issue in assimp v.5.4.3 allows a local attacker to execute arbitrary code via the CallbackToLogRedirector function within the Assimp library.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-10-24T21:15:14Z" diff --git a/advisories/unreviewed/2024/10/GHSA-v7rc-8rwm-q37q/GHSA-v7rc-8rwm-q37q.json b/advisories/unreviewed/2024/10/GHSA-v7rc-8rwm-q37q/GHSA-v7rc-8rwm-q37q.json index 660f99e7e6e..9788a4caf63 100644 --- a/advisories/unreviewed/2024/10/GHSA-v7rc-8rwm-q37q/GHSA-v7rc-8rwm-q37q.json +++ b/advisories/unreviewed/2024/10/GHSA-v7rc-8rwm-q37q/GHSA-v7rc-8rwm-q37q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v7rc-8rwm-q37q", - "modified": "2024-10-25T09:32:01Z", + "modified": "2024-11-05T18:32:01Z", "published": "2024-10-25T09:32:01Z", "aliases": [ "CVE-2024-10150" diff --git a/advisories/unreviewed/2024/11/GHSA-242c-pm42-hqwq/GHSA-242c-pm42-hqwq.json b/advisories/unreviewed/2024/11/GHSA-242c-pm42-hqwq/GHSA-242c-pm42-hqwq.json index cd891bc994e..c5226d50726 100644 --- a/advisories/unreviewed/2024/11/GHSA-242c-pm42-hqwq/GHSA-242c-pm42-hqwq.json +++ b/advisories/unreviewed/2024/11/GHSA-242c-pm42-hqwq/GHSA-242c-pm42-hqwq.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-242c-pm42-hqwq", - "modified": "2024-11-05T15:30:38Z", + "modified": "2024-11-05T18:32:10Z", "published": "2024-11-05T15:30:38Z", "aliases": [ "CVE-2024-52015" ], "details": "Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a stack overflow via the pptp_user_ip parameter at bsw_pptp.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-05T15:15:26Z" diff --git a/advisories/unreviewed/2024/11/GHSA-24c8-3jp4-h926/GHSA-24c8-3jp4-h926.json b/advisories/unreviewed/2024/11/GHSA-24c8-3jp4-h926/GHSA-24c8-3jp4-h926.json new file mode 100644 index 00000000000..ffa3060ab94 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-24c8-3jp4-h926/GHSA-24c8-3jp4-h926.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-24c8-3jp4-h926", + "modified": "2024-11-05T18:32:12Z", + "published": "2024-11-05T18:32:12Z", + "aliases": [ + "CVE-2024-50114" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: arm64: Unregister redistributor for failed vCPU creation\n\nAlex reports that syzkaller has managed to trigger a use-after-free when\ntearing down a VM:\n\n BUG: KASAN: slab-use-after-free in kvm_put_kvm+0x300/0xe68 virt/kvm/kvm_main.c:5769\n Read of size 8 at addr ffffff801c6890d0 by task syz.3.2219/10758\n\n CPU: 3 UID: 0 PID: 10758 Comm: syz.3.2219 Not tainted 6.11.0-rc6-dirty #64\n Hardware name: linux,dummy-virt (DT)\n Call trace:\n dump_backtrace+0x17c/0x1a8 arch/arm64/kernel/stacktrace.c:317\n show_stack+0x2c/0x3c arch/arm64/kernel/stacktrace.c:324\n __dump_stack lib/dump_stack.c:93 [inline]\n dump_stack_lvl+0x94/0xc0 lib/dump_stack.c:119\n print_report+0x144/0x7a4 mm/kasan/report.c:377\n kasan_report+0xcc/0x128 mm/kasan/report.c:601\n __asan_report_load8_noabort+0x20/0x2c mm/kasan/report_generic.c:381\n kvm_put_kvm+0x300/0xe68 virt/kvm/kvm_main.c:5769\n kvm_vm_release+0x4c/0x60 virt/kvm/kvm_main.c:1409\n __fput+0x198/0x71c fs/file_table.c:422\n ____fput+0x20/0x30 fs/file_table.c:450\n task_work_run+0x1cc/0x23c kernel/task_work.c:228\n do_notify_resume+0x144/0x1a0 include/linux/resume_user_mode.h:50\n el0_svc+0x64/0x68 arch/arm64/kernel/entry-common.c:169\n el0t_64_sync_handler+0x90/0xfc arch/arm64/kernel/entry-common.c:730\n el0t_64_sync+0x190/0x194 arch/arm64/kernel/entry.S:598\n\nUpon closer inspection, it appears that we do not properly tear down the\nMMIO registration for a vCPU that fails creation late in the game, e.g.\na vCPU w/ the same ID already exists in the VM.\n\nIt is important to consider the context of commit that introduced this bug\nby moving the unregistration out of __kvm_vgic_vcpu_destroy(). That\nchange correctly sought to avoid an srcu v. config_lock inversion by\nbreaking up the vCPU teardown into two parts, one guarded by the\nconfig_lock.\n\nFix the use-after-free while avoiding lock inversion by adding a\nspecial-cased unregistration to __kvm_vgic_vcpu_destroy(). This is safe\nbecause failed vCPUs are torn down outside of the config_lock.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50114" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6bcc2890b883ba1d16b8942937750565f6e9db0d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ae8f8b37610269009326f4318df161206c59843e" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T18:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-27r6-xq24-p9x8/GHSA-27r6-xq24-p9x8.json b/advisories/unreviewed/2024/11/GHSA-27r6-xq24-p9x8/GHSA-27r6-xq24-p9x8.json index 72ad3012360..7472d4244f2 100644 --- a/advisories/unreviewed/2024/11/GHSA-27r6-xq24-p9x8/GHSA-27r6-xq24-p9x8.json +++ b/advisories/unreviewed/2024/11/GHSA-27r6-xq24-p9x8/GHSA-27r6-xq24-p9x8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-27r6-xq24-p9x8", - "modified": "2024-11-04T18:31:23Z", + "modified": "2024-11-05T18:32:05Z", "published": "2024-11-04T18:31:23Z", "aliases": [ "CVE-2024-34887" ], "details": "Insufficiently protected credentials in AD/LDAP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to send AD/LDAP administrators account passwords to an arbitrary server via HTTP POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-522" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-04T18:15:04Z" diff --git a/advisories/unreviewed/2024/11/GHSA-2fqv-9f8v-r6j4/GHSA-2fqv-9f8v-r6j4.json b/advisories/unreviewed/2024/11/GHSA-2fqv-9f8v-r6j4/GHSA-2fqv-9f8v-r6j4.json new file mode 100644 index 00000000000..f97fec6ecd8 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-2fqv-9f8v-r6j4/GHSA-2fqv-9f8v-r6j4.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2fqv-9f8v-r6j4", + "modified": "2024-11-05T18:32:12Z", + "published": "2024-11-05T18:32:12Z", + "aliases": [ + "CVE-2024-50103" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: qcom: Fix NULL Dereference in asoc_qcom_lpass_cpu_platform_probe()\n\nA devm_kzalloc() in asoc_qcom_lpass_cpu_platform_probe() could\npossibly return NULL pointer. NULL Pointer Dereference may be\ntriggerred without addtional check.\nAdd a NULL check for the returned pointer.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50103" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1e235d02d803660777ec911a2c467ae41f8539f5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/49da1463c9e3d2082276c3e0e2a8b65a88711cd2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/73cc3f905ca9aa95694eea3dfa1acadc90686368" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a8e691fe1894c8bdf815a6171ee22ae7da8b18aa" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e19bf49e903337641fc230d430d49813e3199902" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T18:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-2hfc-prjx-wjcx/GHSA-2hfc-prjx-wjcx.json b/advisories/unreviewed/2024/11/GHSA-2hfc-prjx-wjcx/GHSA-2hfc-prjx-wjcx.json new file mode 100644 index 00000000000..289372a7f15 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-2hfc-prjx-wjcx/GHSA-2hfc-prjx-wjcx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2hfc-prjx-wjcx", + "modified": "2024-11-05T18:32:11Z", + "published": "2024-11-05T18:32:11Z", + "aliases": [ + "CVE-2024-48312" + ], + "details": "WebLaudos v20.8 (118) was discovered to contain a cross-site scripting (XSS) vulnerability via the login page.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48312" + }, + { + "type": "WEB", + "url": "https://medium.com/%40wagneralves_87750/poc-cve-weblaudos-d1ec40cfc183" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T17:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-36v8-8g3p-wx3p/GHSA-36v8-8g3p-wx3p.json b/advisories/unreviewed/2024/11/GHSA-36v8-8g3p-wx3p/GHSA-36v8-8g3p-wx3p.json new file mode 100644 index 00000000000..6a65185251e --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-36v8-8g3p-wx3p/GHSA-36v8-8g3p-wx3p.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-36v8-8g3p-wx3p", + "modified": "2024-11-05T18:32:11Z", + "published": "2024-11-05T18:32:11Z", + "aliases": [ + "CVE-2024-9579" + ], + "details": "A potential vulnerability was discovered in certain Poly video conferencing devices. The firmware flaw does not properly sanitize user input. The exploitation of this vulnerability is dependent on a layered attack and cannot be exploited by itself.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9579" + }, + { + "type": "WEB", + "url": "https://support.hp.com/us-en/document/ish_11536495-11536533-16/hpsbpy03900" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T17:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-387f-x58r-3vw7/GHSA-387f-x58r-3vw7.json b/advisories/unreviewed/2024/11/GHSA-387f-x58r-3vw7/GHSA-387f-x58r-3vw7.json index d1d852de918..e8b65ff0e76 100644 --- a/advisories/unreviewed/2024/11/GHSA-387f-x58r-3vw7/GHSA-387f-x58r-3vw7.json +++ b/advisories/unreviewed/2024/11/GHSA-387f-x58r-3vw7/GHSA-387f-x58r-3vw7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-387f-x58r-3vw7", - "modified": "2024-11-05T15:30:36Z", + "modified": "2024-11-05T18:32:08Z", "published": "2024-11-05T15:30:36Z", "aliases": [ "CVE-2024-50993" ], "details": "Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the sysNewPasswd parameter at admin_account.cgi. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-05T15:15:23Z" diff --git a/advisories/unreviewed/2024/11/GHSA-426m-8vmg-c647/GHSA-426m-8vmg-c647.json b/advisories/unreviewed/2024/11/GHSA-426m-8vmg-c647/GHSA-426m-8vmg-c647.json index ae17d10a082..8b8a45f9509 100644 --- a/advisories/unreviewed/2024/11/GHSA-426m-8vmg-c647/GHSA-426m-8vmg-c647.json +++ b/advisories/unreviewed/2024/11/GHSA-426m-8vmg-c647/GHSA-426m-8vmg-c647.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-426m-8vmg-c647", - "modified": "2024-11-01T18:31:33Z", + "modified": "2024-11-05T18:32:04Z", "published": "2024-11-01T18:31:33Z", "aliases": [ "CVE-2024-48217" ], "details": "An Insecure Direct Object Reference (IDOR) in the dashboard of SiSMART v7.4.0 allows attackers to execute a horizontal-privilege escalation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,9 +28,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-639" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-01T17:15:17Z" diff --git a/advisories/unreviewed/2024/11/GHSA-436q-824j-g5cx/GHSA-436q-824j-g5cx.json b/advisories/unreviewed/2024/11/GHSA-436q-824j-g5cx/GHSA-436q-824j-g5cx.json new file mode 100644 index 00000000000..0eb6a7e9335 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-436q-824j-g5cx/GHSA-436q-824j-g5cx.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-436q-824j-g5cx", + "modified": "2024-11-05T18:32:12Z", + "published": "2024-11-05T18:32:12Z", + "aliases": [ + "CVE-2024-50132" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntracing/probes: Fix MAX_TRACE_ARGS limit handling\n\nWhen creating a trace_probe we would set nr_args prior to truncating the\narguments to MAX_TRACE_ARGS. However, we would only initialize arguments\nup to the limit.\n\nThis caused invalid memory access when attempting to set up probes with\nmore than 128 fetchargs.\n\n BUG: kernel NULL pointer dereference, address: 0000000000000020\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\n PGD 0 P4D 0\n Oops: Oops: 0000 [#1] PREEMPT SMP PTI\n CPU: 0 UID: 0 PID: 1769 Comm: cat Not tainted 6.11.0-rc7+ #8\n Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-1.fc39 04/01/2014\n RIP: 0010:__set_print_fmt+0x134/0x330\n\nResolve the issue by applying the MAX_TRACE_ARGS limit earlier. Return\nan error when there are too many arguments instead of silently\ntruncating.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50132" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/08ccd1a57c4d3882e9a877eb2dcc66e50a3b0279" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6bc24db74fe4788cc7c2f30a113fc6aafba225a3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/73f35080477e893aa6f4c8d388352b871b288fbc" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T18:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-4cf2-cxp3-rjr7/GHSA-4cf2-cxp3-rjr7.json b/advisories/unreviewed/2024/11/GHSA-4cf2-cxp3-rjr7/GHSA-4cf2-cxp3-rjr7.json new file mode 100644 index 00000000000..f2747ea4139 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-4cf2-cxp3-rjr7/GHSA-4cf2-cxp3-rjr7.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4cf2-cxp3-rjr7", + "modified": "2024-11-05T18:32:11Z", + "published": "2024-11-05T18:32:11Z", + "aliases": [ + "CVE-2024-51132" + ], + "details": "An XML External Entity (XXE) vulnerability in HAPI FHIR before v6.4.0 allows attackers to access sensitive information or execute arbitrary code via supplying a crafted request containing malicious XML entities.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51132" + }, + { + "type": "WEB", + "url": "https://github.com/JAckLosingHeart/CVE-2024-51132-POC" + }, + { + "type": "WEB", + "url": "https://github.com/hapifhir/org.hl7.fhir.core" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T17:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-4fw5-75q7-v8g7/GHSA-4fw5-75q7-v8g7.json b/advisories/unreviewed/2024/11/GHSA-4fw5-75q7-v8g7/GHSA-4fw5-75q7-v8g7.json index 050ee633f30..0cef165dd5d 100644 --- a/advisories/unreviewed/2024/11/GHSA-4fw5-75q7-v8g7/GHSA-4fw5-75q7-v8g7.json +++ b/advisories/unreviewed/2024/11/GHSA-4fw5-75q7-v8g7/GHSA-4fw5-75q7-v8g7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4fw5-75q7-v8g7", - "modified": "2024-11-05T15:30:37Z", + "modified": "2024-11-05T18:32:09Z", "published": "2024-11-05T15:30:37Z", "aliases": [ "CVE-2024-50996" ], "details": "Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a stack overflow via the bpa_server parameter at genie_bpa.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-05T15:15:23Z" diff --git a/advisories/unreviewed/2024/11/GHSA-4p84-57xr-x7v6/GHSA-4p84-57xr-x7v6.json b/advisories/unreviewed/2024/11/GHSA-4p84-57xr-x7v6/GHSA-4p84-57xr-x7v6.json index 2ea572b6a23..4b8c1c9895d 100644 --- a/advisories/unreviewed/2024/11/GHSA-4p84-57xr-x7v6/GHSA-4p84-57xr-x7v6.json +++ b/advisories/unreviewed/2024/11/GHSA-4p84-57xr-x7v6/GHSA-4p84-57xr-x7v6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4p84-57xr-x7v6", - "modified": "2024-11-05T06:30:33Z", + "modified": "2024-11-05T18:32:05Z", "published": "2024-11-05T06:30:33Z", "aliases": [ "CVE-2024-5578" ], "details": "The Table of Contents Plus WordPress plugin through 2408 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-05T06:15:05Z" diff --git a/advisories/unreviewed/2024/11/GHSA-4pq4-59v5-5mpm/GHSA-4pq4-59v5-5mpm.json b/advisories/unreviewed/2024/11/GHSA-4pq4-59v5-5mpm/GHSA-4pq4-59v5-5mpm.json new file mode 100644 index 00000000000..88038ace894 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-4pq4-59v5-5mpm/GHSA-4pq4-59v5-5mpm.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4pq4-59v5-5mpm", + "modified": "2024-11-05T18:32:11Z", + "published": "2024-11-05T18:32:11Z", + "aliases": [ + "CVE-2024-50092" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: netconsole: fix wrong warning\n\nA warning is triggered when there is insufficient space in the buffer\nfor userdata. However, this is not an issue since userdata will be sent\nin the next iteration.\n\nCurrent warning message:\n\n ------------[ cut here ]------------\n WARNING: CPU: 13 PID: 3013042 at drivers/net/netconsole.c:1122 write_ext_msg+0x3b6/0x3d0\n ? write_ext_msg+0x3b6/0x3d0\n console_flush_all+0x1e9/0x330\n\nThe code incorrectly issues a warning when this_chunk is zero, which is\na valid scenario. The warning should only be triggered when this_chunk\nis negative.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50092" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/712a3af3710263444217df54e7f337f99df198d2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d94785bb46b6167382b1de3290eccc91fa98df53" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T17:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-4r2j-6r55-j9g2/GHSA-4r2j-6r55-j9g2.json b/advisories/unreviewed/2024/11/GHSA-4r2j-6r55-j9g2/GHSA-4r2j-6r55-j9g2.json index fea5ddc966d..0e8a2fd2fe7 100644 --- a/advisories/unreviewed/2024/11/GHSA-4r2j-6r55-j9g2/GHSA-4r2j-6r55-j9g2.json +++ b/advisories/unreviewed/2024/11/GHSA-4r2j-6r55-j9g2/GHSA-4r2j-6r55-j9g2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4r2j-6r55-j9g2", - "modified": "2024-11-05T15:30:38Z", + "modified": "2024-11-05T18:32:11Z", "published": "2024-11-05T15:30:38Z", "aliases": [ "CVE-2024-52018" ], "details": "Netgear XR300 v1.0.3.78 was discovered to contain a command injection vulnerability in the system_name parameter at genie_dyn.cgi. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-05T15:15:26Z" diff --git a/advisories/unreviewed/2024/11/GHSA-4vm6-5rvv-5jfp/GHSA-4vm6-5rvv-5jfp.json b/advisories/unreviewed/2024/11/GHSA-4vm6-5rvv-5jfp/GHSA-4vm6-5rvv-5jfp.json index 3db3cf33d54..e577a52ce3f 100644 --- a/advisories/unreviewed/2024/11/GHSA-4vm6-5rvv-5jfp/GHSA-4vm6-5rvv-5jfp.json +++ b/advisories/unreviewed/2024/11/GHSA-4vm6-5rvv-5jfp/GHSA-4vm6-5rvv-5jfp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-4vm6-5rvv-5jfp", - "modified": "2024-11-04T18:31:22Z", + "modified": "2024-11-05T18:32:05Z", "published": "2024-11-04T18:31:22Z", "aliases": [ "CVE-2024-34882" ], "details": "Insufficiently protected credentials in SMTP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to send SMTP account passwords to an arbitrary server via HTTP POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-522" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-04T18:15:04Z" diff --git a/advisories/unreviewed/2024/11/GHSA-562f-24cq-ggcj/GHSA-562f-24cq-ggcj.json b/advisories/unreviewed/2024/11/GHSA-562f-24cq-ggcj/GHSA-562f-24cq-ggcj.json new file mode 100644 index 00000000000..73f4aaf6868 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-562f-24cq-ggcj/GHSA-562f-24cq-ggcj.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-562f-24cq-ggcj", + "modified": "2024-11-05T18:32:12Z", + "published": "2024-11-05T18:32:12Z", + "aliases": [ + "CVE-2024-50112" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/lam: Disable ADDRESS_MASKING in most cases\n\nLinear Address Masking (LAM) has a weakness related to transient\nexecution as described in the SLAM paper[1]. Unless Linear Address\nSpace Separation (LASS) is enabled this weakness may be exploitable.\n\nUntil kernel adds support for LASS[2], only allow LAM for COMPILE_TEST,\nor when speculation mitigations have been disabled at compile time,\notherwise keep LAM disabled.\n\nThere are no processors in market that support LAM yet, so currently\nnobody is affected by this issue.\n\n[1] SLAM: https://download.vusec.net/papers/slam_sp24.pdf\n[2] LASS: https://lore.kernel.org/lkml/20230609183632.48706-1-alexander.shishkin@linux.intel.com/\n\n[ dhansen: update SPECULATION_MITIGATIONS -> CPU_MITIGATIONS ]", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50112" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3267cb6d3a174ff83d6287dcd5b0047bbd912452" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/60a5ba560f296ad8da153f6ad3f70030bfa3958f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/690599066488d16db96ac0d6340f9372fc56f337" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T18:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-5mc8-q53p-h4pr/GHSA-5mc8-q53p-h4pr.json b/advisories/unreviewed/2024/11/GHSA-5mc8-q53p-h4pr/GHSA-5mc8-q53p-h4pr.json new file mode 100644 index 00000000000..d0c6285b68f --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-5mc8-q53p-h4pr/GHSA-5mc8-q53p-h4pr.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5mc8-q53p-h4pr", + "modified": "2024-11-05T18:32:12Z", + "published": "2024-11-05T18:32:12Z", + "aliases": [ + "CVE-2024-50118" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: reject ro->rw reconfiguration if there are hard ro requirements\n\n[BUG]\nSyzbot reports the following crash:\n\n BTRFS info (device loop0 state MCS): disabling free space tree\n BTRFS info (device loop0 state MCS): clearing compat-ro feature flag for FREE_SPACE_TREE (0x1)\n BTRFS info (device loop0 state MCS): clearing compat-ro feature flag for FREE_SPACE_TREE_VALID (0x2)\n Oops: general protection fault, probably for non-canonical address 0xdffffc0000000003: 0000 [#1] PREEMPT SMP KASAN NOPTI\n KASAN: null-ptr-deref in range [0x0000000000000018-0x000000000000001f]\n Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2~bpo12+1 04/01/2014\n RIP: 0010:backup_super_roots fs/btrfs/disk-io.c:1691 [inline]\n RIP: 0010:write_all_supers+0x97a/0x40f0 fs/btrfs/disk-io.c:4041\n Call Trace:\n \n btrfs_commit_transaction+0x1eae/0x3740 fs/btrfs/transaction.c:2530\n btrfs_delete_free_space_tree+0x383/0x730 fs/btrfs/free-space-tree.c:1312\n btrfs_start_pre_rw_mount+0xf28/0x1300 fs/btrfs/disk-io.c:3012\n btrfs_remount_rw fs/btrfs/super.c:1309 [inline]\n btrfs_reconfigure+0xae6/0x2d40 fs/btrfs/super.c:1534\n btrfs_reconfigure_for_mount fs/btrfs/super.c:2020 [inline]\n btrfs_get_tree_subvol fs/btrfs/super.c:2079 [inline]\n btrfs_get_tree+0x918/0x1920 fs/btrfs/super.c:2115\n vfs_get_tree+0x90/0x2b0 fs/super.c:1800\n do_new_mount+0x2be/0xb40 fs/namespace.c:3472\n do_mount fs/namespace.c:3812 [inline]\n __do_sys_mount fs/namespace.c:4020 [inline]\n __se_sys_mount+0x2d6/0x3c0 fs/namespace.c:3997\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xf3/0x230 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\n[CAUSE]\nTo support mounting different subvolume with different RO/RW flags for\nthe new mount APIs, btrfs introduced two workaround to support this feature:\n\n- Skip mount option/feature checks if we are mounting a different\n subvolume\n\n- Reconfigure the fs to RW if the initial mount is RO\n\nCombining these two, we can have the following sequence:\n\n- Mount the fs ro,rescue=all,clear_cache,space_cache=v1\n rescue=all will mark the fs as hard read-only, so no v2 cache clearing\n will happen.\n\n- Mount a subvolume rw of the same fs.\n We go into btrfs_get_tree_subvol(), but fc_mount() returns EBUSY\n because our new fc is RW, different from the original fs.\n\n Now we enter btrfs_reconfigure_for_mount(), which switches the RO flag\n first so that we can grab the existing fs_info.\n Then we reconfigure the fs to RW.\n\n- During reconfiguration, option/features check is skipped\n This means we will restart the v2 cache clearing, and convert back to\n v1 cache.\n This will trigger fs writes, and since the original fs has \"rescue=all\"\n option, it skips the csum tree read.\n\n And eventually causing NULL pointer dereference in super block\n writeback.\n\n[FIX]\nFor reconfiguration caused by different subvolume RO/RW flags, ensure we\nalways run btrfs_check_options() to ensure we have proper hard RO\nrequirements met.\n\nIn fact the function btrfs_check_options() doesn't really do many\ncomplex checks, but hard RO requirement and some feature dependency\nchecks, thus there is no special reason not to do the check for mount\nreconfiguration.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50118" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/23724398b55d9570f6ae79dd2ea026fff8896bf1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3c36a72c1d27de6618c1c480c793d9924640f5bb" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T18:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-5q3c-q96r-vr6x/GHSA-5q3c-q96r-vr6x.json b/advisories/unreviewed/2024/11/GHSA-5q3c-q96r-vr6x/GHSA-5q3c-q96r-vr6x.json index 44849224623..6e41daa7262 100644 --- a/advisories/unreviewed/2024/11/GHSA-5q3c-q96r-vr6x/GHSA-5q3c-q96r-vr6x.json +++ b/advisories/unreviewed/2024/11/GHSA-5q3c-q96r-vr6x/GHSA-5q3c-q96r-vr6x.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5q3c-q96r-vr6x", - "modified": "2024-11-05T15:30:37Z", + "modified": "2024-11-05T18:32:09Z", "published": "2024-11-05T15:30:37Z", "aliases": [ "CVE-2024-51001" ], "details": "Netgear R8500 v1.0.2.160 was discovered to contain a stack overflow via the sysDNSHost parameter at ddns.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-05T15:15:24Z" diff --git a/advisories/unreviewed/2024/11/GHSA-5wr9-cjhq-wwg7/GHSA-5wr9-cjhq-wwg7.json b/advisories/unreviewed/2024/11/GHSA-5wr9-cjhq-wwg7/GHSA-5wr9-cjhq-wwg7.json new file mode 100644 index 00000000000..ead3183ad53 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-5wr9-cjhq-wwg7/GHSA-5wr9-cjhq-wwg7.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5wr9-cjhq-wwg7", + "modified": "2024-11-05T18:32:11Z", + "published": "2024-11-05T18:32:11Z", + "aliases": [ + "CVE-2023-29117" + ], + "details": "Waybox Enel X web management API authentication could be bypassed and provide administrator’s privileges over the Waybox system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29117" + }, + { + "type": "WEB", + "url": "https://support-emobility.enelx.com/content/dam/enelxmobility/italia/documenti/manuali-schede-tecniche/Waybox-3-Security-Bulletin-06-2024-V1.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T16:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-5wrv-fw78-wwh3/GHSA-5wrv-fw78-wwh3.json b/advisories/unreviewed/2024/11/GHSA-5wrv-fw78-wwh3/GHSA-5wrv-fw78-wwh3.json new file mode 100644 index 00000000000..94d70ae3073 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-5wrv-fw78-wwh3/GHSA-5wrv-fw78-wwh3.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5wrv-fw78-wwh3", + "modified": "2024-11-05T18:32:12Z", + "published": "2024-11-05T18:32:12Z", + "aliases": [ + "CVE-2024-50106" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: fix race between laundromat and free_stateid\n\nThere is a race between laundromat handling of revoked delegations\nand a client sending free_stateid operation. Laundromat thread\nfinds that delegation has expired and needs to be revoked so it\nmarks the delegation stid revoked and it puts it on a reaper list\nbut then it unlock the state lock and the actual delegation revocation\nhappens without the lock. Once the stid is marked revoked a racing\nfree_stateid processing thread does the following (1) it calls\nlist_del_init() which removes it from the reaper list and (2) frees\nthe delegation stid structure. The laundromat thread ends up not\ncalling the revoke_delegation() function for this particular delegation\nbut that means it will no release the lock lease that exists on\nthe file.\n\nNow, a new open for this file comes in and ends up finding that\nlease list isn't empty and calls nfsd_breaker_owns_lease() which ends\nup trying to derefence a freed delegation stateid. Leading to the\nfollowint use-after-free KASAN warning:\n\nkernel: ==================================================================\nkernel: BUG: KASAN: slab-use-after-free in nfsd_breaker_owns_lease+0x140/0x160 [nfsd]\nkernel: Read of size 8 at addr ffff0000e73cd0c8 by task nfsd/6205\nkernel:\nkernel: CPU: 2 UID: 0 PID: 6205 Comm: nfsd Kdump: loaded Not tainted 6.11.0-rc7+ #9\nkernel: Hardware name: Apple Inc. Apple Virtualization Generic Platform, BIOS 2069.0.0.0.0 08/03/2024\nkernel: Call trace:\nkernel: dump_backtrace+0x98/0x120\nkernel: show_stack+0x1c/0x30\nkernel: dump_stack_lvl+0x80/0xe8\nkernel: print_address_description.constprop.0+0x84/0x390\nkernel: print_report+0xa4/0x268\nkernel: kasan_report+0xb4/0xf8\nkernel: __asan_report_load8_noabort+0x1c/0x28\nkernel: nfsd_breaker_owns_lease+0x140/0x160 [nfsd]\nkernel: nfsd_file_do_acquire+0xb3c/0x11d0 [nfsd]\nkernel: nfsd_file_acquire_opened+0x84/0x110 [nfsd]\nkernel: nfs4_get_vfs_file+0x634/0x958 [nfsd]\nkernel: nfsd4_process_open2+0xa40/0x1a40 [nfsd]\nkernel: nfsd4_open+0xa08/0xe80 [nfsd]\nkernel: nfsd4_proc_compound+0xb8c/0x2130 [nfsd]\nkernel: nfsd_dispatch+0x22c/0x718 [nfsd]\nkernel: svc_process_common+0x8e8/0x1960 [sunrpc]\nkernel: svc_process+0x3d4/0x7e0 [sunrpc]\nkernel: svc_handle_xprt+0x828/0xe10 [sunrpc]\nkernel: svc_recv+0x2cc/0x6a8 [sunrpc]\nkernel: nfsd+0x270/0x400 [nfsd]\nkernel: kthread+0x288/0x310\nkernel: ret_from_fork+0x10/0x20\n\nThis patch proposes a fixed that's based on adding 2 new additional\nstid's sc_status values that help coordinate between the laundromat\nand other operations (nfsd4_free_stateid() and nfsd4_delegreturn()).\n\nFirst to make sure, that once the stid is marked revoked, it is not\nremoved by the nfsd4_free_stateid(), the laundromat take a reference\non the stateid. Then, coordinating whether the stid has been put\non the cl_revoked list or we are processing FREE_STATEID and need to\nmake sure to remove it from the list, each check that state and act\naccordingly. If laundromat has added to the cl_revoke list before\nthe arrival of FREE_STATEID, then nfsd4_free_stateid() knows to remove\nit from the list. If nfsd4_free_stateid() finds that operations arrived\nbefore laundromat has placed it on cl_revoke list, it marks the state\nfreed and then laundromat will no longer add it to the list.\n\nAlso, for nfsd4_delegreturn() when looking for the specified stid,\nwe need to access stid that are marked removed or freeable, it means\nthe laundromat has started processing it but hasn't finished and this\ndelegreturn needs to return nfserr_deleg_revoked and not\nnfserr_bad_stateid. The latter will not trigger a FREE_STATEID and the\nlack of it will leave this stid on the cl_revoked list indefinitely.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50106" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8dd91e8d31febf4d9cca3ae1bb4771d33ae7ee5a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/967faa26f313a62e7bebc55d5b8122eaee43b929" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T18:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-5wxq-6p7v-m87w/GHSA-5wxq-6p7v-m87w.json b/advisories/unreviewed/2024/11/GHSA-5wxq-6p7v-m87w/GHSA-5wxq-6p7v-m87w.json new file mode 100644 index 00000000000..379ddb4a627 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-5wxq-6p7v-m87w/GHSA-5wxq-6p7v-m87w.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5wxq-6p7v-m87w", + "modified": "2024-11-05T18:32:12Z", + "published": "2024-11-05T18:32:12Z", + "aliases": [ + "CVE-2024-50117" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd: Guard against bad data for ATIF ACPI method\n\nIf a BIOS provides bad data in response to an ATIF method call\nthis causes a NULL pointer dereference in the caller.\n\n```\n? show_regs (arch/x86/kernel/dumpstack.c:478 (discriminator 1))\n? __die (arch/x86/kernel/dumpstack.c:423 arch/x86/kernel/dumpstack.c:434)\n? page_fault_oops (arch/x86/mm/fault.c:544 (discriminator 2) arch/x86/mm/fault.c:705 (discriminator 2))\n? do_user_addr_fault (arch/x86/mm/fault.c:440 (discriminator 1) arch/x86/mm/fault.c:1232 (discriminator 1))\n? acpi_ut_update_object_reference (drivers/acpi/acpica/utdelete.c:642)\n? exc_page_fault (arch/x86/mm/fault.c:1542)\n? asm_exc_page_fault (./arch/x86/include/asm/idtentry.h:623)\n? amdgpu_atif_query_backlight_caps.constprop.0 (drivers/gpu/drm/amd/amdgpu/amdgpu_acpi.c:387 (discriminator 2)) amdgpu\n? amdgpu_atif_query_backlight_caps.constprop.0 (drivers/gpu/drm/amd/amdgpu/amdgpu_acpi.c:386 (discriminator 1)) amdgpu\n```\n\nIt has been encountered on at least one system, so guard for it.\n\n(cherry picked from commit c9b7c809b89f24e9372a4e7f02d64c950b07fdee)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50117" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1d7175f9c57b1abf9ecfbdfd53ea760761f52ffe" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6032287747f874b52dc8b9d7490e2799736e035f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/975ede2a7bec52b5da1428829b3439667c8a234b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bf58f03931fdcf7b3c45cb76ac13244477a60f44" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cd67af3c1762de4c2483ae4dbdd98f9ea8fa56e3" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T18:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-5x44-vxm3-fqv4/GHSA-5x44-vxm3-fqv4.json b/advisories/unreviewed/2024/11/GHSA-5x44-vxm3-fqv4/GHSA-5x44-vxm3-fqv4.json index ba2a706e520..eb2c4e9c81e 100644 --- a/advisories/unreviewed/2024/11/GHSA-5x44-vxm3-fqv4/GHSA-5x44-vxm3-fqv4.json +++ b/advisories/unreviewed/2024/11/GHSA-5x44-vxm3-fqv4/GHSA-5x44-vxm3-fqv4.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-5x44-vxm3-fqv4", - "modified": "2024-11-05T15:30:36Z", + "modified": "2024-11-05T18:32:09Z", "published": "2024-11-05T15:30:36Z", "aliases": [ "CVE-2024-50995" ], "details": "Netgear R8500 v1.0.2.160 was discovered to contain a stack overflow via the share_name parameter at usb_remote_smb_conf.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-05T15:15:23Z" diff --git a/advisories/unreviewed/2024/11/GHSA-6352-5p2f-gv84/GHSA-6352-5p2f-gv84.json b/advisories/unreviewed/2024/11/GHSA-6352-5p2f-gv84/GHSA-6352-5p2f-gv84.json new file mode 100644 index 00000000000..5359df50c55 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-6352-5p2f-gv84/GHSA-6352-5p2f-gv84.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6352-5p2f-gv84", + "modified": "2024-11-05T18:32:12Z", + "published": "2024-11-05T18:32:12Z", + "aliases": [ + "CVE-2024-50101" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\niommu/vt-d: Fix incorrect pci_for_each_dma_alias() for non-PCI devices\n\nPreviously, the domain_context_clear() function incorrectly called\npci_for_each_dma_alias() to set up context entries for non-PCI devices.\nThis could lead to kernel hangs or other unexpected behavior.\n\nAdd a check to only call pci_for_each_dma_alias() for PCI devices. For\nnon-PCI devices, domain_context_clear_one() is called directly.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50101" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/04d6826ba7ba81213422276e96c90c6565169e1c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0bd9a30c22afb5da203386b811ec31429d2caa78" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6e02a277f1db24fa039e23783c8921c7b0e5b1b3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cbfa3a83eba05240ce37839ed48280a05e8e8f6c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fe2e0b6cd00abea3efac66de1da22d844364c1b0" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T18:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-66q2-ffpq-62mp/GHSA-66q2-ffpq-62mp.json b/advisories/unreviewed/2024/11/GHSA-66q2-ffpq-62mp/GHSA-66q2-ffpq-62mp.json new file mode 100644 index 00000000000..c48d41d4661 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-66q2-ffpq-62mp/GHSA-66q2-ffpq-62mp.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-66q2-ffpq-62mp", + "modified": "2024-11-05T18:32:12Z", + "published": "2024-11-05T18:32:12Z", + "aliases": [ + "CVE-2024-50100" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: gadget: dummy-hcd: Fix \"task hung\" problem\n\nThe syzbot fuzzer has been encountering \"task hung\" problems ever\nsince the dummy-hcd driver was changed to use hrtimers instead of\nregular timers. It turns out that the problems are caused by a subtle\ndifference between the timer_pending() and hrtimer_active() APIs.\n\nThe changeover blindly replaced the first by the second. However,\ntimer_pending() returns True when the timer is queued but not when its\ncallback is running, whereas hrtimer_active() returns True when the\nhrtimer is queued _or_ its callback is running. This difference\noccasionally caused dummy_urb_enqueue() to think that the callback\nroutine had not yet started when in fact it was almost finished. As a\nresult the hrtimer was not restarted, which made it impossible for the\ndriver to dequeue later the URB that was just enqueued. This caused\nusb_kill_urb() to hang, and things got worse from there.\n\nSince hrtimers have no API for telling when they are queued and the\ncallback isn't running, the driver must keep track of this for itself.\nThat's what this patch does, adding a new \"timer_pending\" flag and\nsetting or clearing it at the appropriate times.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50100" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5189df7b8088268012882c220d6aca4e64981348" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f828205ee3e4ddc712a13fba6c9902d51e91ddaf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T18:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-683q-j7j9-j863/GHSA-683q-j7j9-j863.json b/advisories/unreviewed/2024/11/GHSA-683q-j7j9-j863/GHSA-683q-j7j9-j863.json index 8ad9cc4316f..89e670c64e1 100644 --- a/advisories/unreviewed/2024/11/GHSA-683q-j7j9-j863/GHSA-683q-j7j9-j863.json +++ b/advisories/unreviewed/2024/11/GHSA-683q-j7j9-j863/GHSA-683q-j7j9-j863.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-683q-j7j9-j863", - "modified": "2024-11-05T15:30:37Z", + "modified": "2024-11-05T18:32:10Z", "published": "2024-11-05T15:30:37Z", "aliases": [ "CVE-2024-51007" ], "details": "Netgear XR300 v1.0.3.78 was discovered to contain a stack overflow via the passphrase parameter at wireless.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-05T15:15:24Z" diff --git a/advisories/unreviewed/2024/11/GHSA-6j2q-qr5r-m5gg/GHSA-6j2q-qr5r-m5gg.json b/advisories/unreviewed/2024/11/GHSA-6j2q-qr5r-m5gg/GHSA-6j2q-qr5r-m5gg.json new file mode 100644 index 00000000000..3bb02589522 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-6j2q-qr5r-m5gg/GHSA-6j2q-qr5r-m5gg.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6j2q-qr5r-m5gg", + "modified": "2024-11-05T18:32:11Z", + "published": "2024-11-05T18:32:11Z", + "aliases": [ + "CVE-2023-29126" + ], + "details": "The Waybox Enel X web management application contains a PHP-type juggling vulnerability that may allow a brute force process and under certain conditions bypass authentication.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29126" + }, + { + "type": "WEB", + "url": "https://support-emobility.enelx.com/content/dam/enelxmobility/italia/documenti/manuali-schede-tecniche/Waybox-3-Security-Bulletin-06-2024-V1.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1287" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T16:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-6pww-m6h5-jfm6/GHSA-6pww-m6h5-jfm6.json b/advisories/unreviewed/2024/11/GHSA-6pww-m6h5-jfm6/GHSA-6pww-m6h5-jfm6.json new file mode 100644 index 00000000000..f4c72ec4fff --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-6pww-m6h5-jfm6/GHSA-6pww-m6h5-jfm6.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6pww-m6h5-jfm6", + "modified": "2024-11-05T18:32:12Z", + "published": "2024-11-05T18:32:12Z", + "aliases": [ + "CVE-2024-50124" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: ISO: Fix UAF on iso_sock_timeout\n\nconn->sk maybe have been unlinked/freed while waiting for iso_conn_lock\nso this checks if the conn->sk is still valid by checking if it part of\niso_sk_list.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50124" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/14bcb721d241e62fdd18f6f434a2ed2ab6e71a9b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/246b435ad668596aa0e2bbb9d491b6413861211a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/876ac72d535fa94f4ac57bba651987c6f990f646" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d75aad1d3143ca68cda52ff80ac392e1bbd84325" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T18:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-772q-fwqp-96rg/GHSA-772q-fwqp-96rg.json b/advisories/unreviewed/2024/11/GHSA-772q-fwqp-96rg/GHSA-772q-fwqp-96rg.json new file mode 100644 index 00000000000..b129ff5920d --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-772q-fwqp-96rg/GHSA-772q-fwqp-96rg.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-772q-fwqp-96rg", + "modified": "2024-11-05T18:32:13Z", + "published": "2024-11-05T18:32:13Z", + "aliases": [ + "CVE-2024-50135" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnvme-pci: fix race condition between reset and nvme_dev_disable()\n\nnvme_dev_disable() modifies the dev->online_queues field, therefore\nnvme_pci_update_nr_queues() should avoid racing against it, otherwise\nwe could end up passing invalid values to blk_mq_update_nr_hw_queues().\n\n WARNING: CPU: 39 PID: 61303 at drivers/pci/msi/api.c:347\n pci_irq_get_affinity+0x187/0x210\n Workqueue: nvme-reset-wq nvme_reset_work [nvme]\n RIP: 0010:pci_irq_get_affinity+0x187/0x210\n Call Trace:\n \n ? blk_mq_pci_map_queues+0x87/0x3c0\n ? pci_irq_get_affinity+0x187/0x210\n blk_mq_pci_map_queues+0x87/0x3c0\n nvme_pci_map_queues+0x189/0x460 [nvme]\n blk_mq_update_nr_hw_queues+0x2a/0x40\n nvme_reset_work+0x1be/0x2a0 [nvme]\n\nFix the bug by locking the shutdown_lock mutex before using\ndev->online_queues. Give up if nvme_dev_disable() is running or if\nit has been executed already.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50135" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/26bc0a81f64ce00fc4342c38eeb2eddaad084dd2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4ed32cc0939b64e3d7b48c8c0d63ea038775f304" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b33e49a5f254474b33ce98fd45dd0ffdc247a0be" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T18:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-79wp-x2px-mc9v/GHSA-79wp-x2px-mc9v.json b/advisories/unreviewed/2024/11/GHSA-79wp-x2px-mc9v/GHSA-79wp-x2px-mc9v.json index ae74ce2d234..8bf8251216f 100644 --- a/advisories/unreviewed/2024/11/GHSA-79wp-x2px-mc9v/GHSA-79wp-x2px-mc9v.json +++ b/advisories/unreviewed/2024/11/GHSA-79wp-x2px-mc9v/GHSA-79wp-x2px-mc9v.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-79wp-x2px-mc9v", - "modified": "2024-11-05T15:30:38Z", + "modified": "2024-11-05T18:32:11Z", "published": "2024-11-05T15:30:38Z", "aliases": [ "CVE-2024-52023" ], "details": "Netgear XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 was discovered to contain a stack overflow via the pppoe_localip parameter at pppoe2.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-05T15:15:27Z" diff --git a/advisories/unreviewed/2024/11/GHSA-7h26-mwqv-pxpv/GHSA-7h26-mwqv-pxpv.json b/advisories/unreviewed/2024/11/GHSA-7h26-mwqv-pxpv/GHSA-7h26-mwqv-pxpv.json index 3a45e197c09..64bf6b774a2 100644 --- a/advisories/unreviewed/2024/11/GHSA-7h26-mwqv-pxpv/GHSA-7h26-mwqv-pxpv.json +++ b/advisories/unreviewed/2024/11/GHSA-7h26-mwqv-pxpv/GHSA-7h26-mwqv-pxpv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7h26-mwqv-pxpv", - "modified": "2024-11-05T15:30:38Z", + "modified": "2024-11-05T18:32:11Z", "published": "2024-11-05T15:30:38Z", "aliases": [ "CVE-2024-52029" ], "details": "Netgear R7000P v1.3.3.154 was discovered to contain a stack overflow via the pptp_user_netmask parameter at genie_pptp.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-05T15:15:27Z" diff --git a/advisories/unreviewed/2024/11/GHSA-7mpv-9qrc-wxrj/GHSA-7mpv-9qrc-wxrj.json b/advisories/unreviewed/2024/11/GHSA-7mpv-9qrc-wxrj/GHSA-7mpv-9qrc-wxrj.json index f8161e70b6e..26538e683f3 100644 --- a/advisories/unreviewed/2024/11/GHSA-7mpv-9qrc-wxrj/GHSA-7mpv-9qrc-wxrj.json +++ b/advisories/unreviewed/2024/11/GHSA-7mpv-9qrc-wxrj/GHSA-7mpv-9qrc-wxrj.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-7mpv-9qrc-wxrj", - "modified": "2024-11-05T15:30:37Z", + "modified": "2024-11-05T18:32:10Z", "published": "2024-11-05T15:30:37Z", "aliases": [ "CVE-2024-51017" ], "details": "Netgear R7000P v1.3.3.154 was discovered to contain a stack overflow via the l2tp_user_netmask parameter at l2tp.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-05T15:15:25Z" diff --git a/advisories/unreviewed/2024/11/GHSA-7pjg-f6p5-3g9h/GHSA-7pjg-f6p5-3g9h.json b/advisories/unreviewed/2024/11/GHSA-7pjg-f6p5-3g9h/GHSA-7pjg-f6p5-3g9h.json new file mode 100644 index 00000000000..eb84c554494 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-7pjg-f6p5-3g9h/GHSA-7pjg-f6p5-3g9h.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7pjg-f6p5-3g9h", + "modified": "2024-11-05T18:32:13Z", + "published": "2024-11-05T18:32:12Z", + "aliases": [ + "CVE-2024-50131" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: Consider the NULL character when validating the event length\n\nstrlen() returns a string length excluding the null byte. If the string\nlength equals to the maximum buffer length, the buffer will have no\nspace for the NULL terminating character.\n\nThis commit checks this condition and returns failure for it.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50131" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0b6e2e22cb23105fcb171ab92f0f7516c69c8471" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5fd942598ddeed9a212d1ff41f9f5b47bcc990a7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a14a075a14af8d622c576145455702591bdde09d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b86b0d6eea204116e4185acc35041ca4ff11a642" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f4ed40d1c669bba1a54407d8182acdc405683f29" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T18:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-86gw-29cv-399p/GHSA-86gw-29cv-399p.json b/advisories/unreviewed/2024/11/GHSA-86gw-29cv-399p/GHSA-86gw-29cv-399p.json new file mode 100644 index 00000000000..c9fce69dfc3 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-86gw-29cv-399p/GHSA-86gw-29cv-399p.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-86gw-29cv-399p", + "modified": "2024-11-05T18:32:13Z", + "published": "2024-11-05T18:32:13Z", + "aliases": [ + "CVE-2024-50136" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: Unregister notifier on eswitch init failure\n\nIt otherwise remains registered and a subsequent attempt at eswitch\nenabling might trigger warnings of the sort:\n\n[ 682.589148] ------------[ cut here ]------------\n[ 682.590204] notifier callback eswitch_vport_event [mlx5_core] already registered\n[ 682.590256] WARNING: CPU: 13 PID: 2660 at kernel/notifier.c:31 notifier_chain_register+0x3e/0x90\n[...snipped]\n[ 682.610052] Call Trace:\n[ 682.610369] \n[ 682.610663] ? __warn+0x7c/0x110\n[ 682.611050] ? notifier_chain_register+0x3e/0x90\n[ 682.611556] ? report_bug+0x148/0x170\n[ 682.611977] ? handle_bug+0x36/0x70\n[ 682.612384] ? exc_invalid_op+0x13/0x60\n[ 682.612817] ? asm_exc_invalid_op+0x16/0x20\n[ 682.613284] ? notifier_chain_register+0x3e/0x90\n[ 682.613789] atomic_notifier_chain_register+0x25/0x40\n[ 682.614322] mlx5_eswitch_enable_locked+0x1d4/0x3b0 [mlx5_core]\n[ 682.614965] mlx5_eswitch_enable+0xc9/0x100 [mlx5_core]\n[ 682.615551] mlx5_device_enable_sriov+0x25/0x340 [mlx5_core]\n[ 682.616170] mlx5_core_sriov_configure+0x50/0x170 [mlx5_core]\n[ 682.616789] sriov_numvfs_store+0xb0/0x1b0\n[ 682.617248] kernfs_fop_write_iter+0x117/0x1a0\n[ 682.617734] vfs_write+0x231/0x3f0\n[ 682.618138] ksys_write+0x63/0xe0\n[ 682.618536] do_syscall_64+0x4c/0x100\n[ 682.618958] entry_SYSCALL_64_after_hwframe+0x4b/0x53", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50136" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1da9cfd6c41c2e6bbe624d0568644e1521c33e12" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/599147722c5778c96292e2fbff4103abbdb45b1f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9f2ccb6f3888bec45c00121ee43e4e72423b12c1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e58fb7ddbab6635191c26dea1af26b91cce00866" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T18:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-8cmh-6vqw-c3j2/GHSA-8cmh-6vqw-c3j2.json b/advisories/unreviewed/2024/11/GHSA-8cmh-6vqw-c3j2/GHSA-8cmh-6vqw-c3j2.json index b4fa2cb38a3..5785ea8596f 100644 --- a/advisories/unreviewed/2024/11/GHSA-8cmh-6vqw-c3j2/GHSA-8cmh-6vqw-c3j2.json +++ b/advisories/unreviewed/2024/11/GHSA-8cmh-6vqw-c3j2/GHSA-8cmh-6vqw-c3j2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8cmh-6vqw-c3j2", - "modified": "2024-11-05T15:30:37Z", + "modified": "2024-11-05T18:32:09Z", "published": "2024-11-05T15:30:37Z", "aliases": [ "CVE-2024-50997" ], "details": "Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a stack overflow via the pptp_user_ip parameter at pptp.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-05T15:15:23Z" diff --git a/advisories/unreviewed/2024/11/GHSA-8vx7-5vg4-3p7c/GHSA-8vx7-5vg4-3p7c.json b/advisories/unreviewed/2024/11/GHSA-8vx7-5vg4-3p7c/GHSA-8vx7-5vg4-3p7c.json index 1902da9acd7..775e3e07cbe 100644 --- a/advisories/unreviewed/2024/11/GHSA-8vx7-5vg4-3p7c/GHSA-8vx7-5vg4-3p7c.json +++ b/advisories/unreviewed/2024/11/GHSA-8vx7-5vg4-3p7c/GHSA-8vx7-5vg4-3p7c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-8vx7-5vg4-3p7c", - "modified": "2024-11-05T15:30:38Z", + "modified": "2024-11-05T18:32:10Z", "published": "2024-11-05T15:30:37Z", "aliases": [ "CVE-2024-51022" ], "details": "Netgear XR300 v1.0.3.78 was discovered to contain a stack overflow via the ssid parameter in bridge_wireless_main.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-05T15:15:25Z" diff --git a/advisories/unreviewed/2024/11/GHSA-927w-m77q-8hq6/GHSA-927w-m77q-8hq6.json b/advisories/unreviewed/2024/11/GHSA-927w-m77q-8hq6/GHSA-927w-m77q-8hq6.json index 3b293e5904d..dbc846e8d24 100644 --- a/advisories/unreviewed/2024/11/GHSA-927w-m77q-8hq6/GHSA-927w-m77q-8hq6.json +++ b/advisories/unreviewed/2024/11/GHSA-927w-m77q-8hq6/GHSA-927w-m77q-8hq6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-927w-m77q-8hq6", - "modified": "2024-11-05T15:30:36Z", + "modified": "2024-11-05T18:32:09Z", "published": "2024-11-05T15:30:36Z", "aliases": [ "CVE-2024-50994" ], "details": "Netgear R8500 v1.0.2.160 was discovered to contain multiple stack overflow vulnerabilities in the component ipv6_fix.cgi via the ipv6_wan_ipaddr, ipv6_lan_ipaddr, ipv6_wan_length, and ipv6_lan_length parameters. These vulnerabilities allow attackers to cause a Denial of Service (DoS) via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-05T15:15:23Z" diff --git a/advisories/unreviewed/2024/11/GHSA-92v4-4f89-wr92/GHSA-92v4-4f89-wr92.json b/advisories/unreviewed/2024/11/GHSA-92v4-4f89-wr92/GHSA-92v4-4f89-wr92.json new file mode 100644 index 00000000000..78e328f57b3 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-92v4-4f89-wr92/GHSA-92v4-4f89-wr92.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-92v4-4f89-wr92", + "modified": "2024-11-05T18:32:12Z", + "published": "2024-11-05T18:32:12Z", + "aliases": [ + "CVE-2024-50128" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: wwan: fix global oob in wwan_rtnl_policy\n\nThe variable wwan_rtnl_link_ops assign a *bigger* maxtype which leads to\na global out-of-bounds read when parsing the netlink attributes. Exactly\nsame bug cause as the oob fixed in commit b33fb5b801c6 (\"net: qualcomm:\nrmnet: fix global oob in rmnet_policy\").\n\n==================================================================\nBUG: KASAN: global-out-of-bounds in validate_nla lib/nlattr.c:388 [inline]\nBUG: KASAN: global-out-of-bounds in __nla_validate_parse+0x19d7/0x29a0 lib/nlattr.c:603\nRead of size 1 at addr ffffffff8b09cb60 by task syz.1.66276/323862\n\nCPU: 0 PID: 323862 Comm: syz.1.66276 Not tainted 6.1.70 #1\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.13.0-1ubuntu1.1 04/01/2014\nCall Trace:\n \n __dump_stack lib/dump_stack.c:88 [inline]\n dump_stack_lvl+0x177/0x231 lib/dump_stack.c:106\n print_address_description mm/kasan/report.c:284 [inline]\n print_report+0x14f/0x750 mm/kasan/report.c:395\n kasan_report+0x139/0x170 mm/kasan/report.c:495\n validate_nla lib/nlattr.c:388 [inline]\n __nla_validate_parse+0x19d7/0x29a0 lib/nlattr.c:603\n __nla_parse+0x3c/0x50 lib/nlattr.c:700\n nla_parse_nested_deprecated include/net/netlink.h:1269 [inline]\n __rtnl_newlink net/core/rtnetlink.c:3514 [inline]\n rtnl_newlink+0x7bc/0x1fd0 net/core/rtnetlink.c:3623\n rtnetlink_rcv_msg+0x794/0xef0 net/core/rtnetlink.c:6122\n netlink_rcv_skb+0x1de/0x420 net/netlink/af_netlink.c:2508\n netlink_unicast_kernel net/netlink/af_netlink.c:1326 [inline]\n netlink_unicast+0x74b/0x8c0 net/netlink/af_netlink.c:1352\n netlink_sendmsg+0x882/0xb90 net/netlink/af_netlink.c:1874\n sock_sendmsg_nosec net/socket.c:716 [inline]\n __sock_sendmsg net/socket.c:728 [inline]\n ____sys_sendmsg+0x5cc/0x8f0 net/socket.c:2499\n ___sys_sendmsg+0x21c/0x290 net/socket.c:2553\n __sys_sendmsg net/socket.c:2582 [inline]\n __do_sys_sendmsg net/socket.c:2591 [inline]\n __se_sys_sendmsg+0x19e/0x270 net/socket.c:2589\n do_syscall_x64 arch/x86/entry/common.c:51 [inline]\n do_syscall_64+0x45/0x90 arch/x86/entry/common.c:81\n entry_SYSCALL_64_after_hwframe+0x63/0xcd\nRIP: 0033:0x7f67b19a24ad\nRSP: 002b:00007f67b17febb8 EFLAGS: 00000246 ORIG_RAX: 000000000000002e\nRAX: ffffffffffffffda RBX: 00007f67b1b45f80 RCX: 00007f67b19a24ad\nRDX: 0000000000000000 RSI: 0000000020005e40 RDI: 0000000000000004\nRBP: 00007f67b1a1e01d R08: 0000000000000000 R09: 0000000000000000\nR10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000\nR13: 00007ffd2513764f R14: 00007ffd251376e0 R15: 00007f67b17fed40\n \n\nThe buggy address belongs to the variable:\n wwan_rtnl_policy+0x20/0x40\n\nThe buggy address belongs to the physical page:\npage:ffffea00002c2700 refcount:1 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0xb09c\nflags: 0xfff00000001000(reserved|node=0|zone=1|lastcpupid=0x7ff)\nraw: 00fff00000001000 ffffea00002c2708 ffffea00002c2708 0000000000000000\nraw: 0000000000000000 0000000000000000 00000001ffffffff 0000000000000000\npage dumped because: kasan: bad access detected\npage_owner info is not present (never set?)\n\nMemory state around the buggy address:\n ffffffff8b09ca00: 05 f9 f9 f9 05 f9 f9 f9 00 01 f9 f9 00 01 f9 f9\n ffffffff8b09ca80: 00 00 00 05 f9 f9 f9 f9 00 00 03 f9 f9 f9 f9 f9\n>ffffffff8b09cb00: 00 00 00 00 05 f9 f9 f9 00 00 00 00 f9 f9 f9 f9\n ^\n ffffffff8b09cb80: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00\n==================================================================\n\nAccording to the comment of `nla_parse_nested_deprecated`, use correct size\n`IFLA_WWAN_MAX` here to fix this issue.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50128" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/47dd5447cab8ce30a847a0337d5341ae4c7476a7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/69076f8435c1c5dae5f814eaf4c361d1f00b22a3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9683804e36668f6093fb06e202eed2f188ba437e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a3ffce63dcc0c208edd4d196e17baed22ebcb643" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c9a0aed51977198df005d0a623090e38e2d77d7b" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T18:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-935g-fc8j-74rf/GHSA-935g-fc8j-74rf.json b/advisories/unreviewed/2024/11/GHSA-935g-fc8j-74rf/GHSA-935g-fc8j-74rf.json new file mode 100644 index 00000000000..c038c59699f --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-935g-fc8j-74rf/GHSA-935g-fc8j-74rf.json @@ -0,0 +1,55 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-935g-fc8j-74rf", + "modified": "2024-11-05T18:32:11Z", + "published": "2024-11-05T18:32:11Z", + "aliases": [ + "CVE-2024-50095" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/mad: Improve handling of timed out WRs of mad agent\n\nCurrent timeout handler of mad agent acquires/releases mad_agent_priv\nlock for every timed out WRs. This causes heavy locking contention\nwhen higher no. of WRs are to be handled inside timeout handler.\n\nThis leads to softlockup with below trace in some use cases where\nrdma-cm path is used to establish connection between peer nodes\n\nTrace:\n-----\n BUG: soft lockup - CPU#4 stuck for 26s! [kworker/u128:3:19767]\n CPU: 4 PID: 19767 Comm: kworker/u128:3 Kdump: loaded Tainted: G OE\n ------- --- 5.14.0-427.13.1.el9_4.x86_64 #1\n Hardware name: Dell Inc. PowerEdge R740/01YM03, BIOS 2.4.8 11/26/2019\n Workqueue: ib_mad1 timeout_sends [ib_core]\n RIP: 0010:__do_softirq+0x78/0x2ac\n RSP: 0018:ffffb253449e4f98 EFLAGS: 00000246\n RAX: 00000000ffffffff RBX: 0000000000000000 RCX: 000000000000001f\n RDX: 000000000000001d RSI: 000000003d1879ab RDI: fff363b66fd3a86b\n RBP: ffffb253604cbcd8 R08: 0000009065635f3b R09: 0000000000000000\n R10: 0000000000000040 R11: ffffb253449e4ff8 R12: 0000000000000000\n R13: 0000000000000000 R14: 0000000000000000 R15: 0000000000000040\n FS: 0000000000000000(0000) GS:ffff8caa1fc80000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 00007fd9ec9db900 CR3: 0000000891934006 CR4: 00000000007706e0\n DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n PKRU: 55555554\n Call Trace:\n \n ? show_trace_log_lvl+0x1c4/0x2df\n ? show_trace_log_lvl+0x1c4/0x2df\n ? __irq_exit_rcu+0xa1/0xc0\n ? watchdog_timer_fn+0x1b2/0x210\n ? __pfx_watchdog_timer_fn+0x10/0x10\n ? __hrtimer_run_queues+0x127/0x2c0\n ? hrtimer_interrupt+0xfc/0x210\n ? __sysvec_apic_timer_interrupt+0x5c/0x110\n ? sysvec_apic_timer_interrupt+0x37/0x90\n ? asm_sysvec_apic_timer_interrupt+0x16/0x20\n ? __do_softirq+0x78/0x2ac\n ? __do_softirq+0x60/0x2ac\n __irq_exit_rcu+0xa1/0xc0\n sysvec_call_function_single+0x72/0x90\n \n \n asm_sysvec_call_function_single+0x16/0x20\n RIP: 0010:_raw_spin_unlock_irq+0x14/0x30\n RSP: 0018:ffffb253604cbd88 EFLAGS: 00000247\n RAX: 000000000001960d RBX: 0000000000000002 RCX: ffff8cad2a064800\n RDX: 000000008020001b RSI: 0000000000000001 RDI: ffff8cad5d39f66c\n RBP: ffff8cad5d39f600 R08: 0000000000000001 R09: 0000000000000000\n R10: ffff8caa443e0c00 R11: ffffb253604cbcd8 R12: ffff8cacb8682538\n R13: 0000000000000005 R14: ffffb253604cbd90 R15: ffff8cad5d39f66c\n cm_process_send_error+0x122/0x1d0 [ib_cm]\n timeout_sends+0x1dd/0x270 [ib_core]\n process_one_work+0x1e2/0x3b0\n ? __pfx_worker_thread+0x10/0x10\n worker_thread+0x50/0x3a0\n ? __pfx_worker_thread+0x10/0x10\n kthread+0xdd/0x100\n ? __pfx_kthread+0x10/0x10\n ret_from_fork+0x29/0x50\n \n\nSimplified timeout handler by creating local list of timed out WRs\nand invoke send handler post creating the list. The new method acquires/\nreleases lock once to fetch the list and hence helps to reduce locking\ncontetiong when processing higher no. of WRs", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50095" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2a777679b8ccd09a9a65ea0716ef10365179caac" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3e799fa463508abe7a738ce5d0f62a8dfd05262a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7022a517bf1ca37ef5a474365bcc5eafd345a13a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/713adaf0ecfc49405f6e5d9e409d984f628de818" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a195a42dd25ca4f12489687065d00be64939409f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e80eadb3604a92d2d086e956b8b2692b699d4d0a" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T17:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-9ffw-88h4-2w7x/GHSA-9ffw-88h4-2w7x.json b/advisories/unreviewed/2024/11/GHSA-9ffw-88h4-2w7x/GHSA-9ffw-88h4-2w7x.json new file mode 100644 index 00000000000..9717f2aed19 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-9ffw-88h4-2w7x/GHSA-9ffw-88h4-2w7x.json @@ -0,0 +1,55 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9ffw-88h4-2w7x", + "modified": "2024-11-05T18:32:11Z", + "published": "2024-11-05T18:32:11Z", + "aliases": [ + "CVE-2024-50096" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnouveau/dmem: Fix vulnerability in migrate_to_ram upon copy error\n\nThe `nouveau_dmem_copy_one` function ensures that the copy push command is\nsent to the device firmware but does not track whether it was executed\nsuccessfully.\n\nIn the case of a copy error (e.g., firmware or hardware failure), the\ncopy push command will be sent via the firmware channel, and\n`nouveau_dmem_copy_one` will likely report success, leading to the\n`migrate_to_ram` function returning a dirty HIGH_USER page to the user.\n\nThis can result in a security vulnerability, as a HIGH_USER page that may\ncontain sensitive or corrupted data could be returned to the user.\n\nTo prevent this vulnerability, we allocate a zero page. Thus, in case of\nan error, a non-dirty (zero) page will be returned to the user.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50096" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/614bfb2050982d23d53d0d51c4079dba0437c883" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/697e3ddcf1f8b68bd531fc34eead27c000bdf3e1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/73f75d2b5aee5a735cf64b8ab4543d5c20dbbdd9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/835745a377a4519decd1a36d6b926e369b3033e2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8c3de9282dde21ce3c1bf1bde3166a4510547aa9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ab4d113b6718b076046018292f821d5aa4b844f8" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T17:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-9hvc-wrqf-m74c/GHSA-9hvc-wrqf-m74c.json b/advisories/unreviewed/2024/11/GHSA-9hvc-wrqf-m74c/GHSA-9hvc-wrqf-m74c.json new file mode 100644 index 00000000000..879aeec29d4 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-9hvc-wrqf-m74c/GHSA-9hvc-wrqf-m74c.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9hvc-wrqf-m74c", + "modified": "2024-11-05T18:32:11Z", + "published": "2024-11-05T18:32:11Z", + "aliases": [ + "CVE-2023-29119" + ], + "details": "Waybox Enel X web management application could execute arbitrary requests on the internal database via /admin/dbstore.php.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29119" + }, + { + "type": "WEB", + "url": "https://support-emobility.enelx.com/content/dam/enelxmobility/italia/documenti/manuali-schede-tecniche/Waybox-3-Security-Bulletin-06-2024-V1.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T16:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-9qjp-g446-qv5p/GHSA-9qjp-g446-qv5p.json b/advisories/unreviewed/2024/11/GHSA-9qjp-g446-qv5p/GHSA-9qjp-g446-qv5p.json index 4f51e0d746b..4ee779e51f3 100644 --- a/advisories/unreviewed/2024/11/GHSA-9qjp-g446-qv5p/GHSA-9qjp-g446-qv5p.json +++ b/advisories/unreviewed/2024/11/GHSA-9qjp-g446-qv5p/GHSA-9qjp-g446-qv5p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-9qjp-g446-qv5p", - "modified": "2024-11-04T21:30:32Z", + "modified": "2024-11-05T18:32:05Z", "published": "2024-11-04T21:30:32Z", "aliases": [ "CVE-2024-34885" ], "details": "Insufficiently protected credentials in SMTP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to read SMTP accounts passwords via HTTP GET request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-522" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-04T19:15:06Z" diff --git a/advisories/unreviewed/2024/11/GHSA-c5r9-g2wg-76jp/GHSA-c5r9-g2wg-76jp.json b/advisories/unreviewed/2024/11/GHSA-c5r9-g2wg-76jp/GHSA-c5r9-g2wg-76jp.json index db4e0437bfc..328ce8b94d9 100644 --- a/advisories/unreviewed/2024/11/GHSA-c5r9-g2wg-76jp/GHSA-c5r9-g2wg-76jp.json +++ b/advisories/unreviewed/2024/11/GHSA-c5r9-g2wg-76jp/GHSA-c5r9-g2wg-76jp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c5r9-g2wg-76jp", - "modified": "2024-11-05T15:30:37Z", + "modified": "2024-11-05T18:32:09Z", "published": "2024-11-05T15:30:37Z", "aliases": [ "CVE-2024-51003" ], "details": "Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to multiple stack overflow vulnerabilities in the component ap_mode.cgi via the apmode_dns1_pri and apmode_dns1_sec parameters. These vulnerabilities allow attackers to cause a Denial of Service (DoS) via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-05T15:15:24Z" diff --git a/advisories/unreviewed/2024/11/GHSA-c64g-wm7p-fxqp/GHSA-c64g-wm7p-fxqp.json b/advisories/unreviewed/2024/11/GHSA-c64g-wm7p-fxqp/GHSA-c64g-wm7p-fxqp.json new file mode 100644 index 00000000000..6e900953349 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-c64g-wm7p-fxqp/GHSA-c64g-wm7p-fxqp.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c64g-wm7p-fxqp", + "modified": "2024-11-05T18:32:12Z", + "published": "2024-11-05T18:32:12Z", + "aliases": [ + "CVE-2024-50122" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nPCI: Hold rescan lock while adding devices during host probe\n\nSince adding the PCI power control code, we may end up with a race between\nthe pwrctl platform device rescanning the bus and host controller probe\nfunctions. The latter need to take the rescan lock when adding devices or\nwe may end up in an undefined state having two incompletely added devices\nand hit the following crash when trying to remove the device over sysfs:\n\n Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000\n Internal error: Oops: 0000000096000004 [#1] SMP\n Call trace:\n __pi_strlen+0x14/0x150\n kernfs_find_ns+0x80/0x13c\n kernfs_remove_by_name_ns+0x54/0xf0\n sysfs_remove_bin_file+0x24/0x34\n pci_remove_resource_files+0x3c/0x84\n pci_remove_sysfs_dev_files+0x28/0x38\n pci_stop_bus_device+0x8c/0xd8\n pci_stop_bus_device+0x40/0xd8\n pci_stop_and_remove_bus_device_locked+0x28/0x48\n remove_store+0x70/0xb0\n dev_attr_store+0x20/0x38\n sysfs_kf_write+0x58/0x78\n kernfs_fop_write_iter+0xe8/0x184\n vfs_write+0x2dc/0x308\n ksys_write+0x7c/0xec", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50122" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1d59d474e1cb7d4fdf87dfaf96f44647f13ea590" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d4f38a0e7cc94615f63cf7765ca117e5cc2773ae" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T18:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-c884-h6q9-jjwg/GHSA-c884-h6q9-jjwg.json b/advisories/unreviewed/2024/11/GHSA-c884-h6q9-jjwg/GHSA-c884-h6q9-jjwg.json new file mode 100644 index 00000000000..237d24d5eec --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-c884-h6q9-jjwg/GHSA-c884-h6q9-jjwg.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c884-h6q9-jjwg", + "modified": "2024-11-05T18:32:11Z", + "published": "2024-11-05T18:32:11Z", + "aliases": [ + "CVE-2024-50098" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: ufs: core: Set SDEV_OFFLINE when UFS is shut down\n\nThere is a history of deadlock if reboot is performed at the beginning\nof booting. SDEV_QUIESCE was set for all LU's scsi_devices by UFS\nshutdown, and at that time the audio driver was waiting on\nblk_mq_submit_bio() holding a mutex_lock while reading the fw binary.\nAfter that, a deadlock issue occurred while audio driver shutdown was\nwaiting for mutex_unlock of blk_mq_submit_bio(). To solve this, set\nSDEV_OFFLINE for all LUs except WLUN, so that any I/O that comes down\nafter a UFS shutdown will return an error.\n\n[ 31.907781]I[0: swapper/0: 0] 1 130705007 1651079834 11289729804 0 D( 2) 3 ffffff882e208000 * init [device_shutdown]\n[ 31.907793]I[0: swapper/0: 0] Mutex: 0xffffff8849a2b8b0: owner[0xffffff882e28cb00 kworker/6:0 :49]\n[ 31.907806]I[0: swapper/0: 0] Call trace:\n[ 31.907810]I[0: swapper/0: 0] __switch_to+0x174/0x338\n[ 31.907819]I[0: swapper/0: 0] __schedule+0x5ec/0x9cc\n[ 31.907826]I[0: swapper/0: 0] schedule+0x7c/0xe8\n[ 31.907834]I[0: swapper/0: 0] schedule_preempt_disabled+0x24/0x40\n[ 31.907842]I[0: swapper/0: 0] __mutex_lock+0x408/0xdac\n[ 31.907849]I[0: swapper/0: 0] __mutex_lock_slowpath+0x14/0x24\n[ 31.907858]I[0: swapper/0: 0] mutex_lock+0x40/0xec\n[ 31.907866]I[0: swapper/0: 0] device_shutdown+0x108/0x280\n[ 31.907875]I[0: swapper/0: 0] kernel_restart+0x4c/0x11c\n[ 31.907883]I[0: swapper/0: 0] __arm64_sys_reboot+0x15c/0x280\n[ 31.907890]I[0: swapper/0: 0] invoke_syscall+0x70/0x158\n[ 31.907899]I[0: swapper/0: 0] el0_svc_common+0xb4/0xf4\n[ 31.907909]I[0: swapper/0: 0] do_el0_svc+0x2c/0xb0\n[ 31.907918]I[0: swapper/0: 0] el0_svc+0x34/0xe0\n[ 31.907928]I[0: swapper/0: 0] el0t_64_sync_handler+0x68/0xb4\n[ 31.907937]I[0: swapper/0: 0] el0t_64_sync+0x1a0/0x1a4\n\n[ 31.908774]I[0: swapper/0: 0] 49 0 11960702 11236868007 0 D( 2) 6 ffffff882e28cb00 * kworker/6:0 [__bio_queue_enter]\n[ 31.908783]I[0: swapper/0: 0] Call trace:\n[ 31.908788]I[0: swapper/0: 0] __switch_to+0x174/0x338\n[ 31.908796]I[0: swapper/0: 0] __schedule+0x5ec/0x9cc\n[ 31.908803]I[0: swapper/0: 0] schedule+0x7c/0xe8\n[ 31.908811]I[0: swapper/0: 0] __bio_queue_enter+0xb8/0x178\n[ 31.908818]I[0: swapper/0: 0] blk_mq_submit_bio+0x194/0x67c\n[ 31.908827]I[0: swapper/0: 0] __submit_bio+0xb8/0x19c", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50098" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/19a198b67767d952c8f3d0cf24eb3100522a8223" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7774d23622416dbbbdb21bf342b3f0d92cf1dc0f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7bd9af254275fad7071d85f04616560deb598d7d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7de759fceacff5660abf9590d11114215a9d5f3c" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T18:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-cggp-gq97-wfj7/GHSA-cggp-gq97-wfj7.json b/advisories/unreviewed/2024/11/GHSA-cggp-gq97-wfj7/GHSA-cggp-gq97-wfj7.json index 706dc4f11a4..38bd9880380 100644 --- a/advisories/unreviewed/2024/11/GHSA-cggp-gq97-wfj7/GHSA-cggp-gq97-wfj7.json +++ b/advisories/unreviewed/2024/11/GHSA-cggp-gq97-wfj7/GHSA-cggp-gq97-wfj7.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cggp-gq97-wfj7", - "modified": "2024-11-05T15:30:38Z", + "modified": "2024-11-05T18:32:10Z", "published": "2024-11-05T15:30:37Z", "aliases": [ "CVE-2024-52013" ], "details": "Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a stack overflow via the pptp_user_ip parameter at wiz_pptp.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-05T15:15:26Z" diff --git a/advisories/unreviewed/2024/11/GHSA-cjm2-6jxj-2465/GHSA-cjm2-6jxj-2465.json b/advisories/unreviewed/2024/11/GHSA-cjm2-6jxj-2465/GHSA-cjm2-6jxj-2465.json new file mode 100644 index 00000000000..d214f9c4016 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-cjm2-6jxj-2465/GHSA-cjm2-6jxj-2465.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cjm2-6jxj-2465", + "modified": "2024-11-05T18:32:11Z", + "published": "2024-11-05T18:32:11Z", + "aliases": [ + "CVE-2024-50093" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nthermal: intel: int340x: processor: Fix warning during module unload\n\nThe processor_thermal driver uses pcim_device_enable() to enable a PCI\ndevice, which means the device will be automatically disabled on driver\ndetach. Thus there is no need to call pci_disable_device() again on it.\n\nWith recent PCI device resource management improvements, e.g. commit\nf748a07a0b64 (\"PCI: Remove legacy pcim_release()\"), this problem is\nexposed and triggers the warining below.\n\n [ 224.010735] proc_thermal_pci 0000:00:04.0: disabling already-disabled device\n [ 224.010747] WARNING: CPU: 8 PID: 4442 at drivers/pci/pci.c:2250 pci_disable_device+0xe5/0x100\n ...\n [ 224.010844] Call Trace:\n [ 224.010845] \n [ 224.010847] ? show_regs+0x6d/0x80\n [ 224.010851] ? __warn+0x8c/0x140\n [ 224.010854] ? pci_disable_device+0xe5/0x100\n [ 224.010856] ? report_bug+0x1c9/0x1e0\n [ 224.010859] ? handle_bug+0x46/0x80\n [ 224.010862] ? exc_invalid_op+0x1d/0x80\n [ 224.010863] ? asm_exc_invalid_op+0x1f/0x30\n [ 224.010867] ? pci_disable_device+0xe5/0x100\n [ 224.010869] ? pci_disable_device+0xe5/0x100\n [ 224.010871] ? kfree+0x21a/0x2b0\n [ 224.010873] pcim_disable_device+0x20/0x30\n [ 224.010875] devm_action_release+0x16/0x20\n [ 224.010878] release_nodes+0x47/0xc0\n [ 224.010880] devres_release_all+0x9f/0xe0\n [ 224.010883] device_unbind_cleanup+0x12/0x80\n [ 224.010885] device_release_driver_internal+0x1ca/0x210\n [ 224.010887] driver_detach+0x4e/0xa0\n [ 224.010889] bus_remove_driver+0x6f/0xf0\n [ 224.010890] driver_unregister+0x35/0x60\n [ 224.010892] pci_unregister_driver+0x44/0x90\n [ 224.010894] proc_thermal_pci_driver_exit+0x14/0x5f0 [processor_thermal_device_pci]\n ...\n [ 224.010921] ---[ end trace 0000000000000000 ]---\n\nRemove the excess pci_disable_device() calls.\n\n[ rjw: Subject and changelog edits ]", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50093" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/434525a864136c928b54fd2512b4c0167c207463" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8403021b6f32d68a7e3a6b8428ecaf5c153a9974" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/99ca0b57e49fb73624eede1c4396d9e3d10ccf14" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b4ab78f4adeaf6c98be5d375518dd4fb666eac5e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/dd64ea03375618684477f946be4f5e253f8676c2" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T17:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-cjrc-86h3-3hxh/GHSA-cjrc-86h3-3hxh.json b/advisories/unreviewed/2024/11/GHSA-cjrc-86h3-3hxh/GHSA-cjrc-86h3-3hxh.json index 03e46b4f92d..4c88ea8ad31 100644 --- a/advisories/unreviewed/2024/11/GHSA-cjrc-86h3-3hxh/GHSA-cjrc-86h3-3hxh.json +++ b/advisories/unreviewed/2024/11/GHSA-cjrc-86h3-3hxh/GHSA-cjrc-86h3-3hxh.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cjrc-86h3-3hxh", - "modified": "2024-11-05T06:30:34Z", + "modified": "2024-11-05T18:32:05Z", "published": "2024-11-05T06:30:34Z", "aliases": [ "CVE-2024-7876" ], "details": "The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin WordPress plugin before 1.6.7.55 does not sanitise and escape some of its Appointment Type settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-05T06:15:05Z" diff --git a/advisories/unreviewed/2024/11/GHSA-cmv3-c9g2-j3g5/GHSA-cmv3-c9g2-j3g5.json b/advisories/unreviewed/2024/11/GHSA-cmv3-c9g2-j3g5/GHSA-cmv3-c9g2-j3g5.json index 1e78a3b7e66..f5cd646bcb8 100644 --- a/advisories/unreviewed/2024/11/GHSA-cmv3-c9g2-j3g5/GHSA-cmv3-c9g2-j3g5.json +++ b/advisories/unreviewed/2024/11/GHSA-cmv3-c9g2-j3g5/GHSA-cmv3-c9g2-j3g5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cmv3-c9g2-j3g5", - "modified": "2024-11-05T15:30:37Z", + "modified": "2024-11-05T18:32:10Z", "published": "2024-11-05T15:30:37Z", "aliases": [ "CVE-2024-51006" ], "details": "Netgear R8500 v1.0.2.160 was discovered to contain a stack overflow via the ipv6_static_ip parameter in the ipv6_tunnel function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-05T15:15:24Z" diff --git a/advisories/unreviewed/2024/11/GHSA-cp44-cqrx-8mr2/GHSA-cp44-cqrx-8mr2.json b/advisories/unreviewed/2024/11/GHSA-cp44-cqrx-8mr2/GHSA-cp44-cqrx-8mr2.json new file mode 100644 index 00000000000..302d344f211 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-cp44-cqrx-8mr2/GHSA-cp44-cqrx-8mr2.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cp44-cqrx-8mr2", + "modified": "2024-11-05T18:32:12Z", + "published": "2024-11-05T18:32:12Z", + "aliases": [ + "CVE-2024-50125" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: SCO: Fix UAF on sco_sock_timeout\n\nconn->sk maybe have been unlinked/freed while waiting for sco_conn_lock\nso this checks if the conn->sk is still valid by checking if it part of\nsco_sk_list.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50125" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1bf4470a3939c678fb822073e9ea77a0560bc6bb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/80b05fbfa998480fb3d5299d93eab946f51e9c36" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9ddda5d967e84796e7df1b54a55f36b4b9f21079" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d30803f6a972b5b9e26d1d43b583c7ec151de04b" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T18:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-cv53-45x5-8276/GHSA-cv53-45x5-8276.json b/advisories/unreviewed/2024/11/GHSA-cv53-45x5-8276/GHSA-cv53-45x5-8276.json index c1e453a6334..100f43f6ed7 100644 --- a/advisories/unreviewed/2024/11/GHSA-cv53-45x5-8276/GHSA-cv53-45x5-8276.json +++ b/advisories/unreviewed/2024/11/GHSA-cv53-45x5-8276/GHSA-cv53-45x5-8276.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cv53-45x5-8276", - "modified": "2024-11-05T15:30:38Z", + "modified": "2024-11-05T18:32:11Z", "published": "2024-11-05T15:30:38Z", "aliases": [ "CVE-2024-52021" ], "details": "Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the wan_gateway parameter at bsw_fix.cgi. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-05T15:15:26Z" diff --git a/advisories/unreviewed/2024/11/GHSA-cwr8-h375-g4q5/GHSA-cwr8-h375-g4q5.json b/advisories/unreviewed/2024/11/GHSA-cwr8-h375-g4q5/GHSA-cwr8-h375-g4q5.json index 0671d252381..c92c138b408 100644 --- a/advisories/unreviewed/2024/11/GHSA-cwr8-h375-g4q5/GHSA-cwr8-h375-g4q5.json +++ b/advisories/unreviewed/2024/11/GHSA-cwr8-h375-g4q5/GHSA-cwr8-h375-g4q5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cwr8-h375-g4q5", - "modified": "2024-11-05T15:30:37Z", + "modified": "2024-11-05T18:32:10Z", "published": "2024-11-05T15:30:37Z", "aliases": [ "CVE-2024-51008" ], "details": "Netgear XR300 v1.0.3.78 was discovered to contain a command injection vulnerability in the system_name parameter at wiz_dyn.cgi. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-05T15:15:24Z" diff --git a/advisories/unreviewed/2024/11/GHSA-cx3q-ggpf-wqc5/GHSA-cx3q-ggpf-wqc5.json b/advisories/unreviewed/2024/11/GHSA-cx3q-ggpf-wqc5/GHSA-cx3q-ggpf-wqc5.json index ae44aac05f4..edade275628 100644 --- a/advisories/unreviewed/2024/11/GHSA-cx3q-ggpf-wqc5/GHSA-cx3q-ggpf-wqc5.json +++ b/advisories/unreviewed/2024/11/GHSA-cx3q-ggpf-wqc5/GHSA-cx3q-ggpf-wqc5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-cx3q-ggpf-wqc5", - "modified": "2024-11-05T15:30:38Z", + "modified": "2024-11-05T18:32:10Z", "published": "2024-11-05T15:30:37Z", "aliases": [ "CVE-2024-51019" ], "details": "Netgear R7000P v1.3.3.154 was discovered to contain a stack overflow via the pppoe_localnetmask parameter at pppoe.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-05T15:15:25Z" diff --git a/advisories/unreviewed/2024/11/GHSA-fjw7-947f-3xx6/GHSA-fjw7-947f-3xx6.json b/advisories/unreviewed/2024/11/GHSA-fjw7-947f-3xx6/GHSA-fjw7-947f-3xx6.json new file mode 100644 index 00000000000..6398375ccfa --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-fjw7-947f-3xx6/GHSA-fjw7-947f-3xx6.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fjw7-947f-3xx6", + "modified": "2024-11-05T18:32:12Z", + "published": "2024-11-05T18:32:12Z", + "aliases": [ + "CVE-2024-50105" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: qcom: sc7280: Fix missing Soundwire runtime stream alloc\n\nCommit 15c7fab0e047 (\"ASoC: qcom: Move Soundwire runtime stream alloc to\nsoundcards\") moved the allocation of Soundwire stream runtime from the\nQualcomm Soundwire driver to each individual machine sound card driver,\nexcept that it forgot to update SC7280 card.\n\nJust like for other Qualcomm sound cards using Soundwire, the card\ndriver should allocate and release the runtime. Otherwise sound\nplayback will result in a NULL pointer dereference or other effect of\nuninitialized memory accesses (which was confirmed on SDM845 having\nsimilar issue).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50105" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/176a41ebec42a921277cd34e8c0c2e776a9dd6c4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/db7e59e6a39a4d3d54ca8197c796557e6d480b0d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T18:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-fq9r-775m-mfr3/GHSA-fq9r-775m-mfr3.json b/advisories/unreviewed/2024/11/GHSA-fq9r-775m-mfr3/GHSA-fq9r-775m-mfr3.json new file mode 100644 index 00000000000..3973e42bdf7 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-fq9r-775m-mfr3/GHSA-fq9r-775m-mfr3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fq9r-775m-mfr3", + "modified": "2024-11-05T18:32:11Z", + "published": "2024-11-05T18:32:11Z", + "aliases": [ + "CVE-2023-29125" + ], + "details": "A heap buffer overflow could be triggered by sending a specific packet to TCP port 7700.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29125" + }, + { + "type": "WEB", + "url": "https://support-emobility.enelx.com/content/dam/enelxmobility/italia/documenti/manuali-schede-tecniche/Waybox-3-Security-Bulletin-06-2024-V1.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T16:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-frj8-xg2w-q7rw/GHSA-frj8-xg2w-q7rw.json b/advisories/unreviewed/2024/11/GHSA-frj8-xg2w-q7rw/GHSA-frj8-xg2w-q7rw.json index 2b46b7b9547..846e2fb67a5 100644 --- a/advisories/unreviewed/2024/11/GHSA-frj8-xg2w-q7rw/GHSA-frj8-xg2w-q7rw.json +++ b/advisories/unreviewed/2024/11/GHSA-frj8-xg2w-q7rw/GHSA-frj8-xg2w-q7rw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-frj8-xg2w-q7rw", - "modified": "2024-11-05T15:30:38Z", + "modified": "2024-11-05T18:32:11Z", "published": "2024-11-05T15:30:38Z", "aliases": [ "CVE-2024-52020" ], "details": "Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the wan_gateway parameter at wiz_fix2.cgi. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-05T15:15:26Z" diff --git a/advisories/unreviewed/2024/11/GHSA-g679-7h82-27hc/GHSA-g679-7h82-27hc.json b/advisories/unreviewed/2024/11/GHSA-g679-7h82-27hc/GHSA-g679-7h82-27hc.json new file mode 100644 index 00000000000..73e98e26e7a --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-g679-7h82-27hc/GHSA-g679-7h82-27hc.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g679-7h82-27hc", + "modified": "2024-11-05T18:32:12Z", + "published": "2024-11-05T18:32:12Z", + "aliases": [ + "CVE-2024-50120" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: Handle kstrdup failures for passwords\n\nIn smb3_reconfigure(), after duplicating ctx->password and\nctx->password2 with kstrdup(), we need to check for allocation\nfailures.\n\nIf ses->password allocation fails, return -ENOMEM.\nIf ses->password2 allocation fails, free ses->password, set it\nto NULL, and return -ENOMEM.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50120" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/35488799b0ab6e4327f82e1d9209a60805665b37" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/35dbac8c328d6afe937cd45ecd41d209d0b9f8b8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9a5dd61151399ad5a5d69aad28ab164734c1e3bc" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T18:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-g6xg-7v4w-32vg/GHSA-g6xg-7v4w-32vg.json b/advisories/unreviewed/2024/11/GHSA-g6xg-7v4w-32vg/GHSA-g6xg-7v4w-32vg.json index bccb778289e..e15859570f5 100644 --- a/advisories/unreviewed/2024/11/GHSA-g6xg-7v4w-32vg/GHSA-g6xg-7v4w-32vg.json +++ b/advisories/unreviewed/2024/11/GHSA-g6xg-7v4w-32vg/GHSA-g6xg-7v4w-32vg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-g6xg-7v4w-32vg", - "modified": "2024-11-05T15:30:37Z", + "modified": "2024-11-05T18:32:10Z", "published": "2024-11-05T15:30:37Z", "aliases": [ "CVE-2024-51020" ], "details": "Netgear R7000P v1.3.3.154 was discovered to contain a stack overflow via the apn parameter at usbISP_detail_edit.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-05T15:15:25Z" diff --git a/advisories/unreviewed/2024/11/GHSA-gm2r-w7cj-r54r/GHSA-gm2r-w7cj-r54r.json b/advisories/unreviewed/2024/11/GHSA-gm2r-w7cj-r54r/GHSA-gm2r-w7cj-r54r.json new file mode 100644 index 00000000000..57d850e04bb --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-gm2r-w7cj-r54r/GHSA-gm2r-w7cj-r54r.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gm2r-w7cj-r54r", + "modified": "2024-11-05T18:32:11Z", + "published": "2024-11-05T18:32:11Z", + "aliases": [ + "CVE-2024-51362" + ], + "details": "The LSC Smart Connect Indoor IP Camera V7.6.32 is vulnerable to an information disclosure issue where live camera footage can be accessed through the RTSP protocol on port 8554 without requiring authentication. This allows unauthorized users with network access to view the camera's feed, potentially compromising user privacy and security. No credentials or special permissions are required, and access can be gained remotely over the network.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51362" + }, + { + "type": "WEB", + "url": "https://shinxyy.github.io/blogs/CVE_2024_51362.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T17:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-gmmh-hrwh-ff24/GHSA-gmmh-hrwh-ff24.json b/advisories/unreviewed/2024/11/GHSA-gmmh-hrwh-ff24/GHSA-gmmh-hrwh-ff24.json new file mode 100644 index 00000000000..0b752e2283a --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-gmmh-hrwh-ff24/GHSA-gmmh-hrwh-ff24.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gmmh-hrwh-ff24", + "modified": "2024-11-05T18:32:12Z", + "published": "2024-11-05T18:32:12Z", + "aliases": [ + "CVE-2024-50119" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncifs: fix warning when destroy 'cifs_io_request_pool'\n\nThere's a issue as follows:\nWARNING: CPU: 1 PID: 27826 at mm/slub.c:4698 free_large_kmalloc+0xac/0xe0\nRIP: 0010:free_large_kmalloc+0xac/0xe0\nCall Trace:\n \n ? __warn+0xea/0x330\n mempool_destroy+0x13f/0x1d0\n init_cifs+0xa50/0xff0 [cifs]\n do_one_initcall+0xdc/0x550\n do_init_module+0x22d/0x6b0\n load_module+0x4e96/0x5ff0\n init_module_from_file+0xcd/0x130\n idempotent_init_module+0x330/0x620\n __x64_sys_finit_module+0xb3/0x110\n do_syscall_64+0xc1/0x1d0\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\nObviously, 'cifs_io_request_pool' is not created by mempool_create().\nSo just use mempool_exit() to revert 'cifs_io_request_pool'.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50119" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2ce1007f42b8a6a0814386cb056feb28dc6d6091" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/726416a253c51037636ecc65ad3dada3d02dcaea" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T18:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-gq6w-g8w8-jh8j/GHSA-gq6w-g8w8-jh8j.json b/advisories/unreviewed/2024/11/GHSA-gq6w-g8w8-jh8j/GHSA-gq6w-g8w8-jh8j.json new file mode 100644 index 00000000000..f513a255157 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-gq6w-g8w8-jh8j/GHSA-gq6w-g8w8-jh8j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gq6w-g8w8-jh8j", + "modified": "2024-11-05T18:32:11Z", + "published": "2024-11-05T18:32:11Z", + "aliases": [ + "CVE-2023-29122" + ], + "details": "Under certain conditions, access to service libraries is granted to account they should not have access to.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29122" + }, + { + "type": "WEB", + "url": "https://support-emobility.enelx.com/content/dam/enelxmobility/italia/documenti/manuali-schede-tecniche/Waybox-3-Security-Bulletin-06-2024-V1.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-708" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T16:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-gv3h-6f48-rrfp/GHSA-gv3h-6f48-rrfp.json b/advisories/unreviewed/2024/11/GHSA-gv3h-6f48-rrfp/GHSA-gv3h-6f48-rrfp.json index 3eafced2b94..73211e18090 100644 --- a/advisories/unreviewed/2024/11/GHSA-gv3h-6f48-rrfp/GHSA-gv3h-6f48-rrfp.json +++ b/advisories/unreviewed/2024/11/GHSA-gv3h-6f48-rrfp/GHSA-gv3h-6f48-rrfp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gv3h-6f48-rrfp", - "modified": "2024-11-05T15:30:38Z", + "modified": "2024-11-05T18:32:11Z", "published": "2024-11-05T15:30:38Z", "aliases": [ "CVE-2024-52022" ], "details": "Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a command injection vulnerability in the component wlg_adv.cgi via the apmode_gateway parameter. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-05T15:15:27Z" diff --git a/advisories/unreviewed/2024/11/GHSA-gw9j-jrgv-94wc/GHSA-gw9j-jrgv-94wc.json b/advisories/unreviewed/2024/11/GHSA-gw9j-jrgv-94wc/GHSA-gw9j-jrgv-94wc.json index 5dab9be0e7b..34fd78bcb94 100644 --- a/advisories/unreviewed/2024/11/GHSA-gw9j-jrgv-94wc/GHSA-gw9j-jrgv-94wc.json +++ b/advisories/unreviewed/2024/11/GHSA-gw9j-jrgv-94wc/GHSA-gw9j-jrgv-94wc.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-gw9j-jrgv-94wc", - "modified": "2024-11-05T15:30:37Z", + "modified": "2024-11-05T18:32:09Z", "published": "2024-11-05T15:30:37Z", "aliases": [ "CVE-2024-51000" ], "details": "Netgear R8500 v1.0.2.160 was discovered to contain multiple stack overflow vulnerabilities in the component wireless.cgi via the opmode, opmode_an, and opmode_an_2 parameters. These vulnerabilities allow attackers to cause a Denial of Service (DoS) via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-05T15:15:24Z" diff --git a/advisories/unreviewed/2024/11/GHSA-h4jp-rw7w-8x59/GHSA-h4jp-rw7w-8x59.json b/advisories/unreviewed/2024/11/GHSA-h4jp-rw7w-8x59/GHSA-h4jp-rw7w-8x59.json index 22e90ef1181..d13c6cb637b 100644 --- a/advisories/unreviewed/2024/11/GHSA-h4jp-rw7w-8x59/GHSA-h4jp-rw7w-8x59.json +++ b/advisories/unreviewed/2024/11/GHSA-h4jp-rw7w-8x59/GHSA-h4jp-rw7w-8x59.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h4jp-rw7w-8x59", - "modified": "2024-11-05T15:30:34Z", + "modified": "2024-11-05T18:32:08Z", "published": "2024-11-05T15:30:34Z", "aliases": [ "CVE-2024-7059" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7059" }, + { + "type": "WEB", + "url": "https://resources.genetec.com/security-advisories" + }, { "type": "WEB", "url": "https://resources.genetec.com/security-advisories/high-severity-vulnerability-affecting-security-center-web-sdk-role" diff --git a/advisories/unreviewed/2024/11/GHSA-h7g6-mwmp-g4cj/GHSA-h7g6-mwmp-g4cj.json b/advisories/unreviewed/2024/11/GHSA-h7g6-mwmp-g4cj/GHSA-h7g6-mwmp-g4cj.json new file mode 100644 index 00000000000..f21ce946ea6 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-h7g6-mwmp-g4cj/GHSA-h7g6-mwmp-g4cj.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h7g6-mwmp-g4cj", + "modified": "2024-11-05T18:32:12Z", + "published": "2024-11-05T18:32:12Z", + "aliases": [ + "CVE-2024-50109" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmd/raid10: fix null ptr dereference in raid10_size()\n\nIn raid10_run() if raid10_set_queue_limits() succeed, the return value\nis set to zero, and if following procedures failed raid10_run() will\nreturn zero while mddev->private is still NULL, causing null ptr\ndereference in raid10_size().\n\nFix the problem by only overwrite the return value if\nraid10_set_queue_limits() failed.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50109" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/825711e00117fc686ab89ac36a9a7b252dc349c6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b3054db2fd2d35f2eb3b4b5fb1407792f465391c" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T18:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-hfx7-8xw8-65g8/GHSA-hfx7-8xw8-65g8.json b/advisories/unreviewed/2024/11/GHSA-hfx7-8xw8-65g8/GHSA-hfx7-8xw8-65g8.json new file mode 100644 index 00000000000..39ede05836b --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-hfx7-8xw8-65g8/GHSA-hfx7-8xw8-65g8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hfx7-8xw8-65g8", + "modified": "2024-11-05T18:32:11Z", + "published": "2024-11-05T18:32:11Z", + "aliases": [ + "CVE-2024-49522" + ], + "details": "Substance3D - Painter versions 10.0.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49522" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/substance3d_painter/apsb24-52.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T17:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-hg63-44hg-r9q3/GHSA-hg63-44hg-r9q3.json b/advisories/unreviewed/2024/11/GHSA-hg63-44hg-r9q3/GHSA-hg63-44hg-r9q3.json index 8a8418316b1..6757a38a859 100644 --- a/advisories/unreviewed/2024/11/GHSA-hg63-44hg-r9q3/GHSA-hg63-44hg-r9q3.json +++ b/advisories/unreviewed/2024/11/GHSA-hg63-44hg-r9q3/GHSA-hg63-44hg-r9q3.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hg63-44hg-r9q3", - "modified": "2024-11-05T06:30:34Z", + "modified": "2024-11-05T18:32:05Z", "published": "2024-11-05T06:30:34Z", "aliases": [ "CVE-2024-7877" ], "details": "The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin WordPress plugin before 1.6.7.55 does not sanitise and escape some of its Notification settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-05T06:15:05Z" diff --git a/advisories/unreviewed/2024/11/GHSA-hm8p-5985-v4pm/GHSA-hm8p-5985-v4pm.json b/advisories/unreviewed/2024/11/GHSA-hm8p-5985-v4pm/GHSA-hm8p-5985-v4pm.json index 2f519f90f61..8b628a1e23f 100644 --- a/advisories/unreviewed/2024/11/GHSA-hm8p-5985-v4pm/GHSA-hm8p-5985-v4pm.json +++ b/advisories/unreviewed/2024/11/GHSA-hm8p-5985-v4pm/GHSA-hm8p-5985-v4pm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hm8p-5985-v4pm", - "modified": "2024-11-05T15:30:37Z", + "modified": "2024-11-05T18:32:10Z", "published": "2024-11-05T15:30:37Z", "aliases": [ "CVE-2024-51014" ], "details": "Netgear XR300 v1.0.3.78 was discovered to contain a stack overflow via the ssid_an parameter in bridge_wireless_main.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-05T15:15:25Z" diff --git a/advisories/unreviewed/2024/11/GHSA-hmq5-8v4p-mm6q/GHSA-hmq5-8v4p-mm6q.json b/advisories/unreviewed/2024/11/GHSA-hmq5-8v4p-mm6q/GHSA-hmq5-8v4p-mm6q.json index 62adeaac629..fb88cf60af7 100644 --- a/advisories/unreviewed/2024/11/GHSA-hmq5-8v4p-mm6q/GHSA-hmq5-8v4p-mm6q.json +++ b/advisories/unreviewed/2024/11/GHSA-hmq5-8v4p-mm6q/GHSA-hmq5-8v4p-mm6q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hmq5-8v4p-mm6q", - "modified": "2024-11-04T18:31:23Z", + "modified": "2024-11-05T18:32:05Z", "published": "2024-11-04T18:31:23Z", "aliases": [ "CVE-2024-34883" ], "details": "Insufficiently protected credentials in DAV server settings in 1C-Bitrix Bitrix24 23.300.100 allow remote administrators to read proxy-server accounts passwords via HTTP GET request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-522" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-04T18:15:04Z" diff --git a/advisories/unreviewed/2024/11/GHSA-hx43-x8j5-92gq/GHSA-hx43-x8j5-92gq.json b/advisories/unreviewed/2024/11/GHSA-hx43-x8j5-92gq/GHSA-hx43-x8j5-92gq.json new file mode 100644 index 00000000000..f6b39966963 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-hx43-x8j5-92gq/GHSA-hx43-x8j5-92gq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hx43-x8j5-92gq", + "modified": "2024-11-05T18:32:11Z", + "published": "2024-11-05T18:32:11Z", + "aliases": [ + "CVE-2023-29120" + ], + "details": "Waybox Enel X web management application could be used to execute arbitrary OS commands and provide administrator’s privileges over the Waybox system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29120" + }, + { + "type": "WEB", + "url": "https://support-emobility.enelx.com/content/dam/enelxmobility/italia/documenti/manuali-schede-tecniche/Waybox-3-Security-Bulletin-06-2024-V1.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T16:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-j6w2-m443-3c2h/GHSA-j6w2-m443-3c2h.json b/advisories/unreviewed/2024/11/GHSA-j6w2-m443-3c2h/GHSA-j6w2-m443-3c2h.json index 54f64370bec..85ae4a76de1 100644 --- a/advisories/unreviewed/2024/11/GHSA-j6w2-m443-3c2h/GHSA-j6w2-m443-3c2h.json +++ b/advisories/unreviewed/2024/11/GHSA-j6w2-m443-3c2h/GHSA-j6w2-m443-3c2h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-j6w2-m443-3c2h", - "modified": "2024-11-05T15:30:37Z", + "modified": "2024-11-05T18:32:09Z", "published": "2024-11-05T15:30:37Z", "aliases": [ "CVE-2024-50999" ], "details": "Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the sysNewPasswd parameter at password.cgi. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-05T15:15:23Z" diff --git a/advisories/unreviewed/2024/11/GHSA-jcvh-w2rh-mxx9/GHSA-jcvh-w2rh-mxx9.json b/advisories/unreviewed/2024/11/GHSA-jcvh-w2rh-mxx9/GHSA-jcvh-w2rh-mxx9.json index 60195bb8bda..eaee21914c2 100644 --- a/advisories/unreviewed/2024/11/GHSA-jcvh-w2rh-mxx9/GHSA-jcvh-w2rh-mxx9.json +++ b/advisories/unreviewed/2024/11/GHSA-jcvh-w2rh-mxx9/GHSA-jcvh-w2rh-mxx9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jcvh-w2rh-mxx9", - "modified": "2024-11-05T15:30:37Z", + "modified": "2024-11-05T18:32:10Z", "published": "2024-11-05T15:30:37Z", "aliases": [ "CVE-2024-51004" ], "details": "Netgear R8500 v1.0.2.160 and R7000P v1.3.3.154 were discovered to multiple stack overflow vulnerabilities in the component usb_device.cgi via the cifs_user, read_access, and write_access parameters. These vulnerabilities allow attackers to cause a Denial of Service (DoS) via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-05T15:15:24Z" diff --git a/advisories/unreviewed/2024/11/GHSA-jjp3-6vrp-pvh6/GHSA-jjp3-6vrp-pvh6.json b/advisories/unreviewed/2024/11/GHSA-jjp3-6vrp-pvh6/GHSA-jjp3-6vrp-pvh6.json new file mode 100644 index 00000000000..e51226e620a --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-jjp3-6vrp-pvh6/GHSA-jjp3-6vrp-pvh6.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jjp3-6vrp-pvh6", + "modified": "2024-11-05T18:32:12Z", + "published": "2024-11-05T18:32:12Z", + "aliases": [ + "CVE-2024-50108" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Disable PSR-SU on Parade 08-01 TCON too\n\nStuart Hayhurst has found that both at bootup and fullscreen VA-API video\nis leading to black screens for around 1 second and kernel WARNING [1] traces\nwhen calling dmub_psr_enable() with Parade 08-01 TCON.\n\nThese symptoms all go away with PSR-SU disabled for this TCON, so disable\nit for now while DMUB traces [2] from the failure can be analyzed and the failure\nstate properly root caused.\n\n(cherry picked from commit afb634a6823d8d9db23c5fb04f79c5549349628b)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50108" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5660bcc4dd533005248577d5042f1c48cce2b443" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ba1959f71117b27f3099ee789e0815360b4081dd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c79e0a18e4b301401bb745702830be9041cfbf04" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fc6afa07b5e251148fb37600ee06e1a7007178c3" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T18:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-jq3v-ccgp-cvrg/GHSA-jq3v-ccgp-cvrg.json b/advisories/unreviewed/2024/11/GHSA-jq3v-ccgp-cvrg/GHSA-jq3v-ccgp-cvrg.json new file mode 100644 index 00000000000..970f89127d5 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-jq3v-ccgp-cvrg/GHSA-jq3v-ccgp-cvrg.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jq3v-ccgp-cvrg", + "modified": "2024-11-05T18:32:13Z", + "published": "2024-11-05T18:32:13Z", + "aliases": [ + "CVE-2024-50138" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Use raw_spinlock_t in ringbuf\n\nThe function __bpf_ringbuf_reserve is invoked from a tracepoint, which\ndisables preemption. Using spinlock_t in this context can lead to a\n\"sleep in atomic\" warning in the RT variant. This issue is illustrated\nin the example below:\n\nBUG: sleeping function called from invalid context at kernel/locking/spinlock_rt.c:48\nin_atomic(): 1, irqs_disabled(): 0, non_block: 0, pid: 556208, name: test_progs\npreempt_count: 1, expected: 0\nRCU nest depth: 1, expected: 1\nINFO: lockdep is turned off.\nPreemption disabled at:\n[] migrate_enable+0xc0/0x39c\nCPU: 7 PID: 556208 Comm: test_progs Tainted: G\nHardware name: Qualcomm SA8775P Ride (DT)\nCall trace:\n dump_backtrace+0xac/0x130\n show_stack+0x1c/0x30\n dump_stack_lvl+0xac/0xe8\n dump_stack+0x18/0x30\n __might_resched+0x3bc/0x4fc\n rt_spin_lock+0x8c/0x1a4\n __bpf_ringbuf_reserve+0xc4/0x254\n bpf_ringbuf_reserve_dynptr+0x5c/0xdc\n bpf_prog_ac3d15160d62622a_test_read_write+0x104/0x238\n trace_call_bpf+0x238/0x774\n perf_call_bpf_enter.isra.0+0x104/0x194\n perf_syscall_enter+0x2f8/0x510\n trace_sys_enter+0x39c/0x564\n syscall_trace_enter+0x220/0x3c0\n do_el0_svc+0x138/0x1dc\n el0_svc+0x54/0x130\n el0t_64_sync_handler+0x134/0x150\n el0t_64_sync+0x17c/0x180\n\nSwitch the spinlock to raw_spinlock_t to avoid this error.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50138" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5eb34999d118e69a20dc0c6556f315fcb0a1f8d3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8b62645b09f870d70c7910e7550289d444239a46" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ca30e682e5d6de44d12c4610767811c9a21d59ba" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T18:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-jqqc-7468-4f66/GHSA-jqqc-7468-4f66.json b/advisories/unreviewed/2024/11/GHSA-jqqc-7468-4f66/GHSA-jqqc-7468-4f66.json new file mode 100644 index 00000000000..197b22678bf --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-jqqc-7468-4f66/GHSA-jqqc-7468-4f66.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jqqc-7468-4f66", + "modified": "2024-11-05T18:32:13Z", + "published": "2024-11-05T18:32:13Z", + "aliases": [ + "CVE-2024-50134" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/vboxvideo: Replace fake VLA at end of vbva_mouse_pointer_shape with real VLA\n\nReplace the fake VLA at end of the vbva_mouse_pointer_shape shape with\na real VLA to fix a \"memcpy: detected field-spanning write error\" warning:\n\n[ 13.319813] memcpy: detected field-spanning write (size 16896) of single field \"p->data\" at drivers/gpu/drm/vboxvideo/hgsmi_base.c:154 (size 4)\n[ 13.319841] WARNING: CPU: 0 PID: 1105 at drivers/gpu/drm/vboxvideo/hgsmi_base.c:154 hgsmi_update_pointer_shape+0x192/0x1c0 [vboxvideo]\n[ 13.320038] Call Trace:\n[ 13.320173] hgsmi_update_pointer_shape [vboxvideo]\n[ 13.320184] vbox_cursor_atomic_update [vboxvideo]\n\nNote as mentioned in the added comment it seems the original length\ncalculation for the allocated and send hgsmi buffer is 4 bytes too large.\nChanging this is not the goal of this patch, so this behavior is kept.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50134" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/34a422274b693507025a7db21519865d1862afcb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7458a6cdaebb3dc59af8578ee354fae78a154c4a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9eb32bd23bbcec44bcbef27b7f282b7a7f3d0391" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d92b90f9a54d9300a6e883258e79f36dab53bfae" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fae9dc12c61ce23cf29d09824a741b7b1ff8f01f" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T18:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-jrj5-q7r9-2m35/GHSA-jrj5-q7r9-2m35.json b/advisories/unreviewed/2024/11/GHSA-jrj5-q7r9-2m35/GHSA-jrj5-q7r9-2m35.json index a65fb6ec25b..f8e8cade4f9 100644 --- a/advisories/unreviewed/2024/11/GHSA-jrj5-q7r9-2m35/GHSA-jrj5-q7r9-2m35.json +++ b/advisories/unreviewed/2024/11/GHSA-jrj5-q7r9-2m35/GHSA-jrj5-q7r9-2m35.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jrj5-q7r9-2m35", - "modified": "2024-11-05T15:30:37Z", + "modified": "2024-11-05T18:32:09Z", "published": "2024-11-05T15:30:37Z", "aliases": [ "CVE-2024-51002" ], "details": "Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a stack overflow via the l2tp_user_ip parameter at l2tp.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-05T15:15:24Z" diff --git a/advisories/unreviewed/2024/11/GHSA-jvqw-pf7r-4f2p/GHSA-jvqw-pf7r-4f2p.json b/advisories/unreviewed/2024/11/GHSA-jvqw-pf7r-4f2p/GHSA-jvqw-pf7r-4f2p.json index 22844e6a2b1..a9664a39032 100644 --- a/advisories/unreviewed/2024/11/GHSA-jvqw-pf7r-4f2p/GHSA-jvqw-pf7r-4f2p.json +++ b/advisories/unreviewed/2024/11/GHSA-jvqw-pf7r-4f2p/GHSA-jvqw-pf7r-4f2p.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-jvqw-pf7r-4f2p", - "modified": "2024-11-05T15:30:37Z", + "modified": "2024-11-05T18:32:10Z", "published": "2024-11-05T15:30:37Z", "aliases": [ "CVE-2024-51018" ], "details": "Netgear R7000P v1.3.3.154 was discovered to contain a stack overflow via the pptp_user_netmask parameter at pptp.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-05T15:15:25Z" diff --git a/advisories/unreviewed/2024/11/GHSA-jxxc-79rj-gvh4/GHSA-jxxc-79rj-gvh4.json b/advisories/unreviewed/2024/11/GHSA-jxxc-79rj-gvh4/GHSA-jxxc-79rj-gvh4.json new file mode 100644 index 00000000000..070deb5c39a --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-jxxc-79rj-gvh4/GHSA-jxxc-79rj-gvh4.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jxxc-79rj-gvh4", + "modified": "2024-11-05T18:32:11Z", + "published": "2024-11-05T18:32:11Z", + "aliases": [ + "CVE-2024-50091" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndm vdo: don't refer to dedupe_context after releasing it\n\nClear the dedupe_context pointer in a data_vio whenever ownership of\nthe context is lost, so that vdo can't examine it accidentally.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50091" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0808ebf2f80b962e75741a41ced372a7116f1e26" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/63ef073084c67878d7a92e15ad055172da3f05a3" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T17:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-m2pm-j5cr-9fm9/GHSA-m2pm-j5cr-9fm9.json b/advisories/unreviewed/2024/11/GHSA-m2pm-j5cr-9fm9/GHSA-m2pm-j5cr-9fm9.json index eb82e1a5960..512f66e710b 100644 --- a/advisories/unreviewed/2024/11/GHSA-m2pm-j5cr-9fm9/GHSA-m2pm-j5cr-9fm9.json +++ b/advisories/unreviewed/2024/11/GHSA-m2pm-j5cr-9fm9/GHSA-m2pm-j5cr-9fm9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m2pm-j5cr-9fm9", - "modified": "2024-11-05T15:30:38Z", + "modified": "2024-11-05T18:32:10Z", "published": "2024-11-05T15:30:38Z", "aliases": [ "CVE-2024-51021" ], "details": "Netgear XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 was discovered to contain a command injection vulnerability via the wan_gateway parameter at genie_fix2.cgi. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-05T15:15:25Z" diff --git a/advisories/unreviewed/2024/11/GHSA-m4xx-f75v-xfq3/GHSA-m4xx-f75v-xfq3.json b/advisories/unreviewed/2024/11/GHSA-m4xx-f75v-xfq3/GHSA-m4xx-f75v-xfq3.json new file mode 100644 index 00000000000..a276481cde6 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-m4xx-f75v-xfq3/GHSA-m4xx-f75v-xfq3.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m4xx-f75v-xfq3", + "modified": "2024-11-05T18:32:11Z", + "published": "2024-11-05T18:32:11Z", + "aliases": [ + "CVE-2024-50094" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsfc: Don't invoke xdp_do_flush() from netpoll.\n\nYury reported a crash in the sfc driver originated from\nnetpoll_send_udp(). The netconsole sends a message and then netpoll\ninvokes the driver's NAPI function with a budget of zero. It is\ndedicated to allow driver to free TX resources, that it may have used\nwhile sending the packet.\n\nIn the netpoll case the driver invokes xdp_do_flush() unconditionally,\nleading to crash because bpf_net_context was never assigned.\n\nInvoke xdp_do_flush() only if budget is not zero.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50094" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/55e802468e1d38dec8e25a2fdb6078d45b647e8c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/65d4fc76d75c136744e67754d20feda609e7b793" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T17:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-m9gh-794q-vjjj/GHSA-m9gh-794q-vjjj.json b/advisories/unreviewed/2024/11/GHSA-m9gh-794q-vjjj/GHSA-m9gh-794q-vjjj.json new file mode 100644 index 00000000000..87894d1e19b --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-m9gh-794q-vjjj/GHSA-m9gh-794q-vjjj.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m9gh-794q-vjjj", + "modified": "2024-11-05T18:32:12Z", + "published": "2024-11-05T18:32:12Z", + "aliases": [ + "CVE-2024-50123" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Add the missing BPF_LINK_TYPE invocation for sockmap\n\nThere is an out-of-bounds read in bpf_link_show_fdinfo() for the sockmap\nlink fd. Fix it by adding the missing BPF_LINK_TYPE invocation for\nsockmap link\n\nAlso add comments for bpf_link_type to prevent missing updates in the\nfuture.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50123" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6d79f12c0ce2bc8ff5f109093df1734bd6450615" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c2f803052bc7a7feb2e03befccc8e49b6ff1f5f5" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T18:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-mhcq-hvgj-xm2h/GHSA-mhcq-hvgj-xm2h.json b/advisories/unreviewed/2024/11/GHSA-mhcq-hvgj-xm2h/GHSA-mhcq-hvgj-xm2h.json new file mode 100644 index 00000000000..bfca357dc0d --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-mhcq-hvgj-xm2h/GHSA-mhcq-hvgj-xm2h.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mhcq-hvgj-xm2h", + "modified": "2024-11-05T18:32:12Z", + "published": "2024-11-05T18:32:12Z", + "aliases": [ + "CVE-2024-50102" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86: fix user address masking non-canonical speculation issue\n\nIt turns out that AMD has a \"Meltdown Lite(tm)\" issue with non-canonical\naccesses in kernel space. And so using just the high bit to decide\nwhether an access is in user space or kernel space ends up with the good\nold \"leak speculative data\" if you have the right gadget using the\nresult:\n\n CVE-2020-12965 “Transient Execution of Non-Canonical Accesses“\n\nNow, the kernel surrounds the access with a STAC/CLAC pair, and those\ninstructions end up serializing execution on older Zen architectures,\nwhich closes the speculation window.\n\nBut that was true only up until Zen 5, which renames the AC bit [1].\nThat improves performance of STAC/CLAC a lot, but also means that the\nspeculation window is now open.\n\nNote that this affects not just the new address masking, but also the\nregular valid_user_address() check used by access_ok(), and the asm\nversion of the sign bit check in the get_user() helpers.\n\nIt does not affect put_user() or clear_user() variants, since there's no\nspeculative result to be used in a gadget for those operations.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50102" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/291313693677a345d4f50aae3c68e28b469f601e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/86e6b1547b3d013bc392adf775b89318441403c2" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T18:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-mjgv-4grg-pfrr/GHSA-mjgv-4grg-pfrr.json b/advisories/unreviewed/2024/11/GHSA-mjgv-4grg-pfrr/GHSA-mjgv-4grg-pfrr.json new file mode 100644 index 00000000000..62c08ae1459 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-mjgv-4grg-pfrr/GHSA-mjgv-4grg-pfrr.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mjgv-4grg-pfrr", + "modified": "2024-11-05T18:32:12Z", + "published": "2024-11-05T18:32:12Z", + "aliases": [ + "CVE-2024-50115" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: nSVM: Ignore nCR3[4:0] when loading PDPTEs from memory\n\nIgnore nCR3[4:0] when loading PDPTEs from memory for nested SVM, as bits\n4:0 of CR3 are ignored when PAE paging is used, and thus VMRUN doesn't\nenforce 32-byte alignment of nCR3.\n\nIn the absolute worst case scenario, failure to ignore bits 4:0 can result\nin an out-of-bounds read, e.g. if the target page is at the end of a\nmemslot, and the VMM isn't using guard pages.\n\nPer the APM:\n\n The CR3 register points to the base address of the page-directory-pointer\n table. The page-directory-pointer table is aligned on a 32-byte boundary,\n with the low 5 address bits 4:0 assumed to be 0.\n\nAnd the SDM's much more explicit:\n\n 4:0 Ignored\n\nNote, KVM gets this right when loading PDPTRs, it's only the nSVM flow\nthat is broken.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50115" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2c4adc9b192a0815fe58a62bc0709449416cc884" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/426682afec71ea3f889b972d038238807b9443e4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/58cb697d80e669c56197f703e188867c8c54c494" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6876793907cbe19d42e9edc8c3315a21e06c32ae" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f559b2e9c5c5308850544ab59396b7d53cfc67bd" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T18:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-mx28-rfqr-gwv8/GHSA-mx28-rfqr-gwv8.json b/advisories/unreviewed/2024/11/GHSA-mx28-rfqr-gwv8/GHSA-mx28-rfqr-gwv8.json new file mode 100644 index 00000000000..c5b18f518fd --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-mx28-rfqr-gwv8/GHSA-mx28-rfqr-gwv8.json @@ -0,0 +1,55 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mx28-rfqr-gwv8", + "modified": "2024-11-05T18:32:11Z", + "published": "2024-11-05T18:32:11Z", + "aliases": [ + "CVE-2024-50089" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nunicode: Don't special case ignorable code points\n\nWe don't need to handle them separately. Instead, just let them\ndecompose/casefold to themselves.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50089" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/21526498d25e54bda3c650f756493d63fd9131b7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/39fffca572844d733b137a0ff9eacd67b9b0c8e3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5c26d2f1d3f5e4be3e196526bead29ecb139cf91" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/651b954cd8d5b0a358ceb47c93876bb6201224e4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/876d3577a5b353e482d9228d45fa0d82bf1af53a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ac20736861f3c9c8e0a78273a4c57e9bcb0d8cc6" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T17:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-p3qx-8gpx-2q8q/GHSA-p3qx-8gpx-2q8q.json b/advisories/unreviewed/2024/11/GHSA-p3qx-8gpx-2q8q/GHSA-p3qx-8gpx-2q8q.json index ee68645154d..6af735a5fa8 100644 --- a/advisories/unreviewed/2024/11/GHSA-p3qx-8gpx-2q8q/GHSA-p3qx-8gpx-2q8q.json +++ b/advisories/unreviewed/2024/11/GHSA-p3qx-8gpx-2q8q/GHSA-p3qx-8gpx-2q8q.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p3qx-8gpx-2q8q", - "modified": "2024-11-05T15:30:37Z", + "modified": "2024-11-05T18:32:10Z", "published": "2024-11-05T15:30:37Z", "aliases": [ "CVE-2024-51011" ], "details": "Netgear XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 was discovered to contain a stack overflow via the pppoe_localip parameter at pppoe.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-05T15:15:24Z" diff --git a/advisories/unreviewed/2024/11/GHSA-p3xc-gj2p-m8xh/GHSA-p3xc-gj2p-m8xh.json b/advisories/unreviewed/2024/11/GHSA-p3xc-gj2p-m8xh/GHSA-p3xc-gj2p-m8xh.json new file mode 100644 index 00000000000..fc7810ed692 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-p3xc-gj2p-m8xh/GHSA-p3xc-gj2p-m8xh.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p3xc-gj2p-m8xh", + "modified": "2024-11-05T18:32:12Z", + "published": "2024-11-05T18:32:12Z", + "aliases": [ + "CVE-2024-50113" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfirewire: core: fix invalid port index for parent device\n\nIn a commit 24b7f8e5cd65 (\"firewire: core: use helper functions for self\nID sequence\"), the enumeration over self ID sequence was refactored with\nsome helper functions with KUnit tests. These helper functions are\nguaranteed to work expectedly by the KUnit tests, however their application\nincludes a mistake to assign invalid value to the index of port connected\nto parent device.\n\nThis bug affects the case that any extra node devices which has three or\nmore ports are connected to 1394 OHCI controller. In the case, the path\nto update the tree cache could hits WARN_ON(), and gets general protection\nfault due to the access to invalid address computed by the invalid value.\n\nThis commit fixes the bug to assign correct port index.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50113" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/90753a38bc3d058820981f812a908a99f7b337c1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f6a6780e0b9bbcf311a727afed06fee533a5e957" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T18:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-p597-59q3-qvc8/GHSA-p597-59q3-qvc8.json b/advisories/unreviewed/2024/11/GHSA-p597-59q3-qvc8/GHSA-p597-59q3-qvc8.json index 78556e72055..9fab9cfadd4 100644 --- a/advisories/unreviewed/2024/11/GHSA-p597-59q3-qvc8/GHSA-p597-59q3-qvc8.json +++ b/advisories/unreviewed/2024/11/GHSA-p597-59q3-qvc8/GHSA-p597-59q3-qvc8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p597-59q3-qvc8", - "modified": "2024-11-05T15:30:37Z", + "modified": "2024-11-05T18:32:10Z", "published": "2024-11-05T15:30:37Z", "aliases": [ "CVE-2024-51009" ], "details": "Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the wan_gateway parameter at ether.cgi. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-05T15:15:24Z" diff --git a/advisories/unreviewed/2024/11/GHSA-pccx-2485-w69f/GHSA-pccx-2485-w69f.json b/advisories/unreviewed/2024/11/GHSA-pccx-2485-w69f/GHSA-pccx-2485-w69f.json new file mode 100644 index 00000000000..f75f6170009 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-pccx-2485-w69f/GHSA-pccx-2485-w69f.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pccx-2485-w69f", + "modified": "2024-11-05T18:32:11Z", + "published": "2024-11-05T18:32:11Z", + "aliases": [ + "CVE-2023-29116" + ], + "details": "Under certain conditions, through a request directed to the Waybox Enel X web management application, information like Waybox OS version or service configuration details could be obtained.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29116" + }, + { + "type": "WEB", + "url": "https://support-emobility.enelx.com/content/dam/enelxmobility/italia/documenti/manuali-schede-tecniche/Waybox-3-Security-Bulletin-06-2024-V1.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T16:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-pcmq-5pjg-9prg/GHSA-pcmq-5pjg-9prg.json b/advisories/unreviewed/2024/11/GHSA-pcmq-5pjg-9prg/GHSA-pcmq-5pjg-9prg.json index 763690944e8..12e28092757 100644 --- a/advisories/unreviewed/2024/11/GHSA-pcmq-5pjg-9prg/GHSA-pcmq-5pjg-9prg.json +++ b/advisories/unreviewed/2024/11/GHSA-pcmq-5pjg-9prg/GHSA-pcmq-5pjg-9prg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pcmq-5pjg-9prg", - "modified": "2024-11-05T06:30:34Z", + "modified": "2024-11-05T18:32:05Z", "published": "2024-11-05T06:30:34Z", "aliases": [ "CVE-2024-9689" ], "details": "The Post From Frontend WordPress plugin through 1.0.0 does not have CSRF check when deleting posts, which could allow attackers to make logged in admin perform such action via a CSRF attack", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-05T06:15:06Z" diff --git a/advisories/unreviewed/2024/11/GHSA-pf38-5qmv-cmhv/GHSA-pf38-5qmv-cmhv.json b/advisories/unreviewed/2024/11/GHSA-pf38-5qmv-cmhv/GHSA-pf38-5qmv-cmhv.json index 9e33d64fabb..89223b7a7e1 100644 --- a/advisories/unreviewed/2024/11/GHSA-pf38-5qmv-cmhv/GHSA-pf38-5qmv-cmhv.json +++ b/advisories/unreviewed/2024/11/GHSA-pf38-5qmv-cmhv/GHSA-pf38-5qmv-cmhv.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pf38-5qmv-cmhv", - "modified": "2024-11-05T15:30:37Z", + "modified": "2024-11-05T18:32:10Z", "published": "2024-11-05T15:30:37Z", "aliases": [ "CVE-2024-51010" ], "details": "Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a command injection vulnerability in the component ap_mode.cgi via the apmode_gateway parameter. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-05T15:15:24Z" diff --git a/advisories/unreviewed/2024/11/GHSA-pj67-hxcx-g74v/GHSA-pj67-hxcx-g74v.json b/advisories/unreviewed/2024/11/GHSA-pj67-hxcx-g74v/GHSA-pj67-hxcx-g74v.json new file mode 100644 index 00000000000..d69b4313309 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-pj67-hxcx-g74v/GHSA-pj67-hxcx-g74v.json @@ -0,0 +1,55 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pj67-hxcx-g74v", + "modified": "2024-11-05T18:32:11Z", + "published": "2024-11-05T18:32:11Z", + "aliases": [ + "CVE-2024-50099" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\narm64: probes: Remove broken LDR (literal) uprobe support\n\nThe simulate_ldr_literal() and simulate_ldrsw_literal() functions are\nunsafe to use for uprobes. Both functions were originally written for\nuse with kprobes, and access memory with plain C accesses. When uprobes\nwas added, these were reused unmodified even though they cannot safely\naccess user memory.\n\nThere are three key problems:\n\n1) The plain C accesses do not have corresponding extable entries, and\n thus if they encounter a fault the kernel will treat these as\n unintentional accesses to user memory, resulting in a BUG() which\n will kill the kernel thread, and likely lead to further issues (e.g.\n lockup or panic()).\n\n2) The plain C accesses are subject to HW PAN and SW PAN, and so when\n either is in use, any attempt to simulate an access to user memory\n will fault. Thus neither simulate_ldr_literal() nor\n simulate_ldrsw_literal() can do anything useful when simulating a\n user instruction on any system with HW PAN or SW PAN.\n\n3) The plain C accesses are privileged, as they run in kernel context,\n and in practice can access a small range of kernel virtual addresses.\n The instructions they simulate have a range of +/-1MiB, and since the\n simulated instructions must itself be a user instructions in the\n TTBR0 address range, these can address the final 1MiB of the TTBR1\n acddress range by wrapping downwards from an address in the first\n 1MiB of the TTBR0 address range.\n\n In contemporary kernels the last 8MiB of TTBR1 address range is\n reserved, and accesses to this will always fault, meaning this is no\n worse than (1).\n\n Historically, it was theoretically possible for the linear map or\n vmemmap to spill into the final 8MiB of the TTBR1 address range, but\n in practice this is extremely unlikely to occur as this would\n require either:\n\n * Having enough physical memory to fill the entire linear map all the\n way to the final 1MiB of the TTBR1 address range.\n\n * Getting unlucky with KASLR randomization of the linear map such\n that the populated region happens to overlap with the last 1MiB of\n the TTBR address range.\n\n ... and in either case if we were to spill into the final page there\n would be larger problems as the final page would alias with error\n pointers.\n\nPractically speaking, (1) and (2) are the big issues. Given there have\nbeen no reports of problems since the broken code was introduced, it\nappears that no-one is relying on probing these instructions with\nuprobes.\n\nAvoid these issues by not allowing uprobes on LDR (literal) and LDRSW\n(literal), limiting the use of simulate_ldr_literal() and\nsimulate_ldrsw_literal() to kprobes. Attempts to place uprobes on LDR\n(literal) and LDRSW (literal) will be rejected as\narm_probe_decode_insn() will return INSN_REJECTED. In future we can\nconsider introducing working uprobes support for these instructions, but\nthis will require more significant work.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50099" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/20cde998315a3d2df08e26079a3ea7501abce6db" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3728b4eb27910ffedd173018279a970705f2e03a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9f1e7735474e7457a4d919a517900e46868ae5f6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/acc450aa07099d071b18174c22a1119c57da8227" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ad4bc35a6d22e9ff9b67d0d0c38bce654232f195" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bae792617a7e911477f67a3aff850ad4ddf51572" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T18:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-pjg9-f4hq-p885/GHSA-pjg9-f4hq-p885.json b/advisories/unreviewed/2024/11/GHSA-pjg9-f4hq-p885/GHSA-pjg9-f4hq-p885.json index d097d79ab9d..075d1f9d40b 100644 --- a/advisories/unreviewed/2024/11/GHSA-pjg9-f4hq-p885/GHSA-pjg9-f4hq-p885.json +++ b/advisories/unreviewed/2024/11/GHSA-pjg9-f4hq-p885/GHSA-pjg9-f4hq-p885.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-pjg9-f4hq-p885", - "modified": "2024-11-05T15:30:37Z", + "modified": "2024-11-05T18:32:10Z", "published": "2024-11-05T15:30:37Z", "aliases": [ "CVE-2024-51016" ], "details": "Netgear XR300 v1.0.3.78 was discovered to contain a stack overflow via the addName%d parameter in usb_approve.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-05T15:15:25Z" diff --git a/advisories/unreviewed/2024/11/GHSA-q634-78mh-cmgq/GHSA-q634-78mh-cmgq.json b/advisories/unreviewed/2024/11/GHSA-q634-78mh-cmgq/GHSA-q634-78mh-cmgq.json new file mode 100644 index 00000000000..29ed4cede5c --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-q634-78mh-cmgq/GHSA-q634-78mh-cmgq.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q634-78mh-cmgq", + "modified": "2024-11-05T18:32:11Z", + "published": "2024-11-05T18:32:11Z", + "aliases": [ + "CVE-2023-29118" + ], + "details": "Waybox Enel X web management application could execute arbitrary requests on the internal database via /admin/versions.php.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29118" + }, + { + "type": "WEB", + "url": "https://support-emobility.enelx.com/content/dam/enelxmobility/italia/documenti/manuali-schede-tecniche/Waybox-3-Security-Bulletin-06-2024-V1.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T16:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-q79j-6grx-x9p9/GHSA-q79j-6grx-x9p9.json b/advisories/unreviewed/2024/11/GHSA-q79j-6grx-x9p9/GHSA-q79j-6grx-x9p9.json index 21b711b7a03..fe286315326 100644 --- a/advisories/unreviewed/2024/11/GHSA-q79j-6grx-x9p9/GHSA-q79j-6grx-x9p9.json +++ b/advisories/unreviewed/2024/11/GHSA-q79j-6grx-x9p9/GHSA-q79j-6grx-x9p9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q79j-6grx-x9p9", - "modified": "2024-11-05T06:30:34Z", + "modified": "2024-11-05T18:32:05Z", "published": "2024-11-05T06:30:34Z", "aliases": [ "CVE-2024-9883" ], "details": "The Pods WordPress plugin before 3.2.7.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-05T06:15:06Z" diff --git a/advisories/unreviewed/2024/11/GHSA-q7wx-38r3-hr6h/GHSA-q7wx-38r3-hr6h.json b/advisories/unreviewed/2024/11/GHSA-q7wx-38r3-hr6h/GHSA-q7wx-38r3-hr6h.json index 3b80b889edd..a9de4b556ba 100644 --- a/advisories/unreviewed/2024/11/GHSA-q7wx-38r3-hr6h/GHSA-q7wx-38r3-hr6h.json +++ b/advisories/unreviewed/2024/11/GHSA-q7wx-38r3-hr6h/GHSA-q7wx-38r3-hr6h.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q7wx-38r3-hr6h", - "modified": "2024-11-05T15:30:37Z", + "modified": "2024-11-05T18:32:10Z", "published": "2024-11-05T15:30:37Z", "aliases": [ "CVE-2024-51012" ], "details": "Netgear R8500 v1.0.2.160 was discovered to contain a stack overflow via the ipv6_pri_dns parameter at ipv6_fix.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-05T15:15:25Z" diff --git a/advisories/unreviewed/2024/11/GHSA-qh6f-g265-fmxf/GHSA-qh6f-g265-fmxf.json b/advisories/unreviewed/2024/11/GHSA-qh6f-g265-fmxf/GHSA-qh6f-g265-fmxf.json new file mode 100644 index 00000000000..f2f198de1d5 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-qh6f-g265-fmxf/GHSA-qh6f-g265-fmxf.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qh6f-g265-fmxf", + "modified": "2024-11-05T18:32:12Z", + "published": "2024-11-05T18:32:12Z", + "aliases": [ + "CVE-2024-50126" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: sched: use RCU read-side critical section in taprio_dump()\n\nFix possible use-after-free in 'taprio_dump()' by adding RCU\nread-side critical section there. Never seen on x86 but\nfound on a KASAN-enabled arm64 system when investigating\nhttps://syzkaller.appspot.com/bug?extid=b65e0af58423fc8a73aa:\n\n[T15862] BUG: KASAN: slab-use-after-free in taprio_dump+0xa0c/0xbb0\n[T15862] Read of size 4 at addr ffff0000d4bb88f8 by task repro/15862\n[T15862]\n[T15862] CPU: 0 UID: 0 PID: 15862 Comm: repro Not tainted 6.11.0-rc1-00293-gdefaf1a2113a-dirty #2\n[T15862] Hardware name: QEMU QEMU Virtual Machine, BIOS edk2-20240524-5.fc40 05/24/2024\n[T15862] Call trace:\n[T15862] dump_backtrace+0x20c/0x220\n[T15862] show_stack+0x2c/0x40\n[T15862] dump_stack_lvl+0xf8/0x174\n[T15862] print_report+0x170/0x4d8\n[T15862] kasan_report+0xb8/0x1d4\n[T15862] __asan_report_load4_noabort+0x20/0x2c\n[T15862] taprio_dump+0xa0c/0xbb0\n[T15862] tc_fill_qdisc+0x540/0x1020\n[T15862] qdisc_notify.isra.0+0x330/0x3a0\n[T15862] tc_modify_qdisc+0x7b8/0x1838\n[T15862] rtnetlink_rcv_msg+0x3c8/0xc20\n[T15862] netlink_rcv_skb+0x1f8/0x3d4\n[T15862] rtnetlink_rcv+0x28/0x40\n[T15862] netlink_unicast+0x51c/0x790\n[T15862] netlink_sendmsg+0x79c/0xc20\n[T15862] __sock_sendmsg+0xe0/0x1a0\n[T15862] ____sys_sendmsg+0x6c0/0x840\n[T15862] ___sys_sendmsg+0x1ac/0x1f0\n[T15862] __sys_sendmsg+0x110/0x1d0\n[T15862] __arm64_sys_sendmsg+0x74/0xb0\n[T15862] invoke_syscall+0x88/0x2e0\n[T15862] el0_svc_common.constprop.0+0xe4/0x2a0\n[T15862] do_el0_svc+0x44/0x60\n[T15862] el0_svc+0x50/0x184\n[T15862] el0t_64_sync_handler+0x120/0x12c\n[T15862] el0t_64_sync+0x190/0x194\n[T15862]\n[T15862] Allocated by task 15857:\n[T15862] kasan_save_stack+0x3c/0x70\n[T15862] kasan_save_track+0x20/0x3c\n[T15862] kasan_save_alloc_info+0x40/0x60\n[T15862] __kasan_kmalloc+0xd4/0xe0\n[T15862] __kmalloc_cache_noprof+0x194/0x334\n[T15862] taprio_change+0x45c/0x2fe0\n[T15862] tc_modify_qdisc+0x6a8/0x1838\n[T15862] rtnetlink_rcv_msg+0x3c8/0xc20\n[T15862] netlink_rcv_skb+0x1f8/0x3d4\n[T15862] rtnetlink_rcv+0x28/0x40\n[T15862] netlink_unicast+0x51c/0x790\n[T15862] netlink_sendmsg+0x79c/0xc20\n[T15862] __sock_sendmsg+0xe0/0x1a0\n[T15862] ____sys_sendmsg+0x6c0/0x840\n[T15862] ___sys_sendmsg+0x1ac/0x1f0\n[T15862] __sys_sendmsg+0x110/0x1d0\n[T15862] __arm64_sys_sendmsg+0x74/0xb0\n[T15862] invoke_syscall+0x88/0x2e0\n[T15862] el0_svc_common.constprop.0+0xe4/0x2a0\n[T15862] do_el0_svc+0x44/0x60\n[T15862] el0_svc+0x50/0x184\n[T15862] el0t_64_sync_handler+0x120/0x12c\n[T15862] el0t_64_sync+0x190/0x194\n[T15862]\n[T15862] Freed by task 6192:\n[T15862] kasan_save_stack+0x3c/0x70\n[T15862] kasan_save_track+0x20/0x3c\n[T15862] kasan_save_free_info+0x4c/0x80\n[T15862] poison_slab_object+0x110/0x160\n[T15862] __kasan_slab_free+0x3c/0x74\n[T15862] kfree+0x134/0x3c0\n[T15862] taprio_free_sched_cb+0x18c/0x220\n[T15862] rcu_core+0x920/0x1b7c\n[T15862] rcu_core_si+0x10/0x1c\n[T15862] handle_softirqs+0x2e8/0xd64\n[T15862] __do_softirq+0x14/0x20", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50126" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5d282467245f267c0b9ada3f7f309ff838521536" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b22db8b8befe90b61c98626ca1a2fbb0505e9fe3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e4369cb6acf6b895ac2453cc1cdf2f4326122c6d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T18:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-qmvj-5x98-pxr6/GHSA-qmvj-5x98-pxr6.json b/advisories/unreviewed/2024/11/GHSA-qmvj-5x98-pxr6/GHSA-qmvj-5x98-pxr6.json index 7e136bf51d7..6e4bd6deca7 100644 --- a/advisories/unreviewed/2024/11/GHSA-qmvj-5x98-pxr6/GHSA-qmvj-5x98-pxr6.json +++ b/advisories/unreviewed/2024/11/GHSA-qmvj-5x98-pxr6/GHSA-qmvj-5x98-pxr6.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qmvj-5x98-pxr6", - "modified": "2024-11-05T15:30:38Z", + "modified": "2024-11-05T18:32:11Z", "published": "2024-11-05T15:30:38Z", "aliases": [ "CVE-2024-52030" ], "details": "Netgear R7000P v1.3.3.154 was discovered to contain a stack overflow via the pptp_user_netmask parameter at ru_wan_flow.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-05T15:15:27Z" diff --git a/advisories/unreviewed/2024/11/GHSA-qq43-74jj-93fp/GHSA-qq43-74jj-93fp.json b/advisories/unreviewed/2024/11/GHSA-qq43-74jj-93fp/GHSA-qq43-74jj-93fp.json new file mode 100644 index 00000000000..14960200c96 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-qq43-74jj-93fp/GHSA-qq43-74jj-93fp.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qq43-74jj-93fp", + "modified": "2024-11-05T18:32:11Z", + "published": "2024-11-05T18:32:11Z", + "aliases": [ + "CVE-2024-50090" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe/oa: Fix overflow in oa batch buffer\n\nBy default xe_bb_create_job() appends a MI_BATCH_BUFFER_END to batch\nbuffer, this is not a problem if batch buffer is only used once but\noa reuses the batch buffer for the same metric and at each call\nit appends a MI_BATCH_BUFFER_END, printing the warning below and then\noverflowing.\n\n[ 381.072016] ------------[ cut here ]------------\n[ 381.072019] xe 0000:00:02.0: [drm] Assertion `bb->len * 4 + bb_prefetch(q->gt) <= size` failed!\n platform: LUNARLAKE subplatform: 1\n graphics: Xe2_LPG / Xe2_HPG 20.04 step B0\n media: Xe2_LPM / Xe2_HPM 20.00 step B0\n tile: 0 VRAM 0 B\n GT: 0 type 1\n\nSo here checking if batch buffer already have MI_BATCH_BUFFER_END if\nnot append it.\n\nv2:\n- simply fix, suggestion from Ashutosh\n\n(cherry picked from commit 9ba0e0f30ca42a98af3689460063edfb6315718a)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50090" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6c10ba06bb1b48acce6d4d9c1e33beb9954f1788" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bcb5be3421705e682b0b32073ad627056d6bc2a2" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T17:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-r2xm-57h8-c29j/GHSA-r2xm-57h8-c29j.json b/advisories/unreviewed/2024/11/GHSA-r2xm-57h8-c29j/GHSA-r2xm-57h8-c29j.json new file mode 100644 index 00000000000..9e43af9ad89 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-r2xm-57h8-c29j/GHSA-r2xm-57h8-c29j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r2xm-57h8-c29j", + "modified": "2024-11-05T18:32:11Z", + "published": "2024-11-05T18:32:11Z", + "aliases": [ + "CVE-2023-29121" + ], + "details": "Waybox Enel TCF Agent service could be used to get administrator’s privileges over the Waybox system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29121" + }, + { + "type": "WEB", + "url": "https://support-emobility.enelx.com/content/dam/enelxmobility/italia/documenti/manuali-schede-tecniche/Waybox-3-Security-Bulletin-06-2024-V1.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T16:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-r8p4-whj5-6jwg/GHSA-r8p4-whj5-6jwg.json b/advisories/unreviewed/2024/11/GHSA-r8p4-whj5-6jwg/GHSA-r8p4-whj5-6jwg.json index 8bfdc862086..9a0f7344887 100644 --- a/advisories/unreviewed/2024/11/GHSA-r8p4-whj5-6jwg/GHSA-r8p4-whj5-6jwg.json +++ b/advisories/unreviewed/2024/11/GHSA-r8p4-whj5-6jwg/GHSA-r8p4-whj5-6jwg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-r8p4-whj5-6jwg", - "modified": "2024-11-05T15:30:38Z", + "modified": "2024-11-05T18:32:10Z", "published": "2024-11-05T15:30:38Z", "aliases": [ "CVE-2024-52016" ], "details": "Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to multiple stack overflow vulnerabilities in the component wlg_adv.cgi via the apmode_dns1_pri and apmode_dns1_sec parameters. These vulnerabilities allow attackers to cause a Denial of Service (DoS) via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-05T15:15:26Z" diff --git a/advisories/unreviewed/2024/11/GHSA-rcj3-p7jf-6xjp/GHSA-rcj3-p7jf-6xjp.json b/advisories/unreviewed/2024/11/GHSA-rcj3-p7jf-6xjp/GHSA-rcj3-p7jf-6xjp.json index 4cb59468d8c..c62a7a86128 100644 --- a/advisories/unreviewed/2024/11/GHSA-rcj3-p7jf-6xjp/GHSA-rcj3-p7jf-6xjp.json +++ b/advisories/unreviewed/2024/11/GHSA-rcj3-p7jf-6xjp/GHSA-rcj3-p7jf-6xjp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rcj3-p7jf-6xjp", - "modified": "2024-11-05T15:30:38Z", + "modified": "2024-11-05T18:32:11Z", "published": "2024-11-05T15:30:38Z", "aliases": [ "CVE-2024-52026" ], "details": "Netgear XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 was discovered to contain a stack overflow via the pppoe_localip parameter at bsw_pppoe.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-05T15:15:27Z" diff --git a/advisories/unreviewed/2024/11/GHSA-rprp-m5gh-mh5c/GHSA-rprp-m5gh-mh5c.json b/advisories/unreviewed/2024/11/GHSA-rprp-m5gh-mh5c/GHSA-rprp-m5gh-mh5c.json index d4fcb991a13..b8c54f23312 100644 --- a/advisories/unreviewed/2024/11/GHSA-rprp-m5gh-mh5c/GHSA-rprp-m5gh-mh5c.json +++ b/advisories/unreviewed/2024/11/GHSA-rprp-m5gh-mh5c/GHSA-rprp-m5gh-mh5c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rprp-m5gh-mh5c", - "modified": "2024-11-05T15:30:37Z", + "modified": "2024-11-05T18:32:10Z", "published": "2024-11-05T15:30:37Z", "aliases": [ "CVE-2024-51005" ], "details": "Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the share_name parameter at usb_remote_smb_conf.cgi. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-05T15:15:24Z" diff --git a/advisories/unreviewed/2024/11/GHSA-rvr8-cw39-527c/GHSA-rvr8-cw39-527c.json b/advisories/unreviewed/2024/11/GHSA-rvr8-cw39-527c/GHSA-rvr8-cw39-527c.json index 878f611fad5..d42d0d0001b 100644 --- a/advisories/unreviewed/2024/11/GHSA-rvr8-cw39-527c/GHSA-rvr8-cw39-527c.json +++ b/advisories/unreviewed/2024/11/GHSA-rvr8-cw39-527c/GHSA-rvr8-cw39-527c.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rvr8-cw39-527c", - "modified": "2024-11-05T15:30:38Z", + "modified": "2024-11-05T18:32:11Z", "published": "2024-11-05T15:30:38Z", "aliases": [ "CVE-2024-52024" ], "details": "Netgear XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 was discovered to contain a stack overflow via the pppoe_localip parameter at wizpppoe.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-05T15:15:27Z" diff --git a/advisories/unreviewed/2024/11/GHSA-v3c2-xj8g-4r72/GHSA-v3c2-xj8g-4r72.json b/advisories/unreviewed/2024/11/GHSA-v3c2-xj8g-4r72/GHSA-v3c2-xj8g-4r72.json index a26f7769fa8..1222e82bf88 100644 --- a/advisories/unreviewed/2024/11/GHSA-v3c2-xj8g-4r72/GHSA-v3c2-xj8g-4r72.json +++ b/advisories/unreviewed/2024/11/GHSA-v3c2-xj8g-4r72/GHSA-v3c2-xj8g-4r72.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v3c2-xj8g-4r72", - "modified": "2024-11-05T15:30:37Z", + "modified": "2024-11-05T18:32:09Z", "published": "2024-11-05T15:30:37Z", "aliases": [ "CVE-2024-50998" ], "details": "Netgear R8500 v1.0.2.160 was discovered to contain multiple stack overflow vulnerabilities in the component openvpn.cgi via the openvpn_service_port and openvpn_service_port_tun parameters. These vulnerabilities allow attackers to cause a Denial of Service (DoS) via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-05T15:15:23Z" diff --git a/advisories/unreviewed/2024/11/GHSA-v7wq-2339-37p8/GHSA-v7wq-2339-37p8.json b/advisories/unreviewed/2024/11/GHSA-v7wq-2339-37p8/GHSA-v7wq-2339-37p8.json index f97ace49431..32a0878431a 100644 --- a/advisories/unreviewed/2024/11/GHSA-v7wq-2339-37p8/GHSA-v7wq-2339-37p8.json +++ b/advisories/unreviewed/2024/11/GHSA-v7wq-2339-37p8/GHSA-v7wq-2339-37p8.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-v7wq-2339-37p8", - "modified": "2024-11-05T15:30:38Z", + "modified": "2024-11-05T18:32:11Z", "published": "2024-11-05T15:30:38Z", "aliases": [ "CVE-2024-52025" ], "details": "Netgear XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 was discovered to contain a stack overflow via the pppoe_localip parameter at geniepppoe.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-05T15:15:27Z" diff --git a/advisories/unreviewed/2024/11/GHSA-v85x-rrgc-699v/GHSA-v85x-rrgc-699v.json b/advisories/unreviewed/2024/11/GHSA-v85x-rrgc-699v/GHSA-v85x-rrgc-699v.json new file mode 100644 index 00000000000..167eda3eec9 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-v85x-rrgc-699v/GHSA-v85x-rrgc-699v.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v85x-rrgc-699v", + "modified": "2024-11-05T18:32:13Z", + "published": "2024-11-05T18:32:13Z", + "aliases": [ + "CVE-2024-50137" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nreset: starfive: jh71x0: Fix accessing the empty member on JH7110 SoC\n\ndata->asserted will be NULL on JH7110 SoC since commit 82327b127d41\n(\"reset: starfive: Add StarFive JH7110 reset driver\") was added. Add\nthe judgment condition to avoid errors when calling reset_control_status\non JH7110 SoC.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50137" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2cf59663660799ce16f4dfbed97cdceac7a7fa11" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c923f1fb8ae8627322d167b73bb4f978404a05de" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T18:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-v95w-jfg2-cj6w/GHSA-v95w-jfg2-cj6w.json b/advisories/unreviewed/2024/11/GHSA-v95w-jfg2-cj6w/GHSA-v95w-jfg2-cj6w.json new file mode 100644 index 00000000000..24f77e5894e --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-v95w-jfg2-cj6w/GHSA-v95w-jfg2-cj6w.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v95w-jfg2-cj6w", + "modified": "2024-11-05T18:32:12Z", + "published": "2024-11-05T18:32:12Z", + "aliases": [ + "CVE-2024-50104" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: qcom: sdm845: add missing soundwire runtime stream alloc\n\nDuring the migration of Soundwire runtime stream allocation from\nthe Qualcomm Soundwire controller to SoC's soundcard drivers the sdm845\nsoundcard was forgotten.\n\nAt this point any playback attempt or audio daemon startup, for instance\non sdm845-db845c (Qualcomm RB3 board), will result in stream pointer\nNULL dereference:\n\n Unable to handle kernel NULL pointer dereference at virtual\n address 0000000000000020\n Mem abort info:\n ESR = 0x0000000096000004\n EC = 0x25: DABT (current EL), IL = 32 bits\n SET = 0, FnV = 0\n EA = 0, S1PTW = 0\n FSC = 0x04: level 0 translation fault\n Data abort info:\n ISV = 0, ISS = 0x00000004, ISS2 = 0x00000000\n CM = 0, WnR = 0, TnD = 0, TagAccess = 0\n GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0\n user pgtable: 4k pages, 48-bit VAs, pgdp=0000000101ecf000\n [0000000000000020] pgd=0000000000000000, p4d=0000000000000000\n Internal error: Oops: 0000000096000004 [#1] PREEMPT SMP\n Modules linked in: ...\n CPU: 5 UID: 0 PID: 1198 Comm: aplay\n Not tainted 6.12.0-rc2-qcomlt-arm64-00059-g9d78f315a362-dirty #18\n Hardware name: Thundercomm Dragonboard 845c (DT)\n pstate: 60400005 (nZCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n pc : sdw_stream_add_slave+0x44/0x380 [soundwire_bus]\n lr : sdw_stream_add_slave+0x44/0x380 [soundwire_bus]\n sp : ffff80008a2035c0\n x29: ffff80008a2035c0 x28: ffff80008a203978 x27: 0000000000000000\n x26: 00000000000000c0 x25: 0000000000000000 x24: ffff1676025f4800\n x23: ffff167600ff1cb8 x22: ffff167600ff1c98 x21: 0000000000000003\n x20: ffff167607316000 x19: ffff167604e64e80 x18: 0000000000000000\n x17: 0000000000000000 x16: ffffcec265074160 x15: 0000000000000000\n x14: 0000000000000000 x13: 0000000000000000 x12: 0000000000000000\n x11: 0000000000000000 x10: 0000000000000000 x9 : 0000000000000000\n x8 : 0000000000000000 x7 : 0000000000000000 x6 : ffff167600ff1cec\n x5 : ffffcec22cfa2010 x4 : 0000000000000000 x3 : 0000000000000003\n x2 : ffff167613f836c0 x1 : 0000000000000000 x0 : ffff16761feb60b8\n Call trace:\n sdw_stream_add_slave+0x44/0x380 [soundwire_bus]\n wsa881x_hw_params+0x68/0x80 [snd_soc_wsa881x]\n snd_soc_dai_hw_params+0x3c/0xa4\n __soc_pcm_hw_params+0x230/0x660\n dpcm_be_dai_hw_params+0x1d0/0x3f8\n dpcm_fe_dai_hw_params+0x98/0x268\n snd_pcm_hw_params+0x124/0x460\n snd_pcm_common_ioctl+0x998/0x16e8\n snd_pcm_ioctl+0x34/0x58\n __arm64_sys_ioctl+0xac/0xf8\n invoke_syscall+0x48/0x104\n el0_svc_common.constprop.0+0x40/0xe0\n do_el0_svc+0x1c/0x28\n el0_svc+0x34/0xe0\n el0t_64_sync_handler+0x120/0x12c\n el0t_64_sync+0x190/0x194\n Code: aa0403fb f9418400 9100e000 9400102f (f8420f22)\n ---[ end trace 0000000000000000 ]---\n\n0000000000006108 :\n 6108: d503233f paciasp\n 610c: a9b97bfd stp x29, x30, [sp, #-112]!\n 6110: 910003fd mov x29, sp\n 6114: a90153f3 stp x19, x20, [sp, #16]\n 6118: a9025bf5 stp x21, x22, [sp, #32]\n 611c: aa0103f6 mov x22, x1\n 6120: 2a0303f5 mov w21, w3\n 6124: a90363f7 stp x23, x24, [sp, #48]\n 6128: aa0003f8 mov x24, x0\n 612c: aa0203f7 mov x23, x2\n 6130: a9046bf9 stp x25, x26, [sp, #64]\n 6134: aa0403f9 mov x25, x4 <-- x4 copied to x25\n 6138: a90573fb stp x27, x28, [sp, #80]\n 613c: aa0403fb mov x27, x4\n 6140: f9418400 ldr x0, [x0, #776]\n 6144: 9100e000 add x0, x0, #0x38\n 6148: 94000000 bl 0 \n 614c: f8420f22 ldr x2, [x25, #32]! <-- offset 0x44\n ^^^\nThis is 0x6108 + offset 0x44 from the beginning of sdw_stream_add_slave()\nwhere data abort happens.\nwsa881x_hw_params() is called with stream = NULL and passes it further\nin register x4 (5th argu\n---truncated---", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50104" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d0e806b0cc6260b59c65e606034a63145169c04c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fc34d36879f87e5a3813fb66655b8bdb90c7b0d8" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T18:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-vg97-cmqr-w7w5/GHSA-vg97-cmqr-w7w5.json b/advisories/unreviewed/2024/11/GHSA-vg97-cmqr-w7w5/GHSA-vg97-cmqr-w7w5.json index c314b1465eb..1cc39892b3c 100644 --- a/advisories/unreviewed/2024/11/GHSA-vg97-cmqr-w7w5/GHSA-vg97-cmqr-w7w5.json +++ b/advisories/unreviewed/2024/11/GHSA-vg97-cmqr-w7w5/GHSA-vg97-cmqr-w7w5.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vg97-cmqr-w7w5", - "modified": "2024-11-05T15:30:38Z", + "modified": "2024-11-05T18:32:10Z", "published": "2024-11-05T15:30:38Z", "aliases": [ "CVE-2024-52017" ], "details": "Netgear XR300 v1.0.3.78 was discovered to contain a stack overflow via the passphrase parameter at bridge_wireless_main.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-05T15:15:26Z" diff --git a/advisories/unreviewed/2024/11/GHSA-vhp8-3pj4-3mvp/GHSA-vhp8-3pj4-3mvp.json b/advisories/unreviewed/2024/11/GHSA-vhp8-3pj4-3mvp/GHSA-vhp8-3pj4-3mvp.json index 3ec4a04d1a2..67754d084f7 100644 --- a/advisories/unreviewed/2024/11/GHSA-vhp8-3pj4-3mvp/GHSA-vhp8-3pj4-3mvp.json +++ b/advisories/unreviewed/2024/11/GHSA-vhp8-3pj4-3mvp/GHSA-vhp8-3pj4-3mvp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vhp8-3pj4-3mvp", - "modified": "2024-11-05T15:30:38Z", + "modified": "2024-11-05T18:32:11Z", "published": "2024-11-05T15:30:38Z", "aliases": [ "CVE-2024-52028" ], "details": "Netgear R7000P v1.3.3.154 was discovered to contain a stack overflow via the pptp_user_netmask parameter at wiz_pptp.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-05T15:15:27Z" diff --git a/advisories/unreviewed/2024/11/GHSA-vvg3-j47v-x7p2/GHSA-vvg3-j47v-x7p2.json b/advisories/unreviewed/2024/11/GHSA-vvg3-j47v-x7p2/GHSA-vvg3-j47v-x7p2.json index 5bc1d9471a9..ef28858726f 100644 --- a/advisories/unreviewed/2024/11/GHSA-vvg3-j47v-x7p2/GHSA-vvg3-j47v-x7p2.json +++ b/advisories/unreviewed/2024/11/GHSA-vvg3-j47v-x7p2/GHSA-vvg3-j47v-x7p2.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vvg3-j47v-x7p2", - "modified": "2024-11-05T15:30:38Z", + "modified": "2024-11-05T18:32:11Z", "published": "2024-11-05T15:30:38Z", "aliases": [ "CVE-2024-52019" ], "details": "Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the wan_gateway parameter at genie_fix2.cgi. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-78" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-05T15:15:26Z" diff --git a/advisories/unreviewed/2024/11/GHSA-vx62-xr6m-q866/GHSA-vx62-xr6m-q866.json b/advisories/unreviewed/2024/11/GHSA-vx62-xr6m-q866/GHSA-vx62-xr6m-q866.json new file mode 100644 index 00000000000..05c7c015b04 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-vx62-xr6m-q866/GHSA-vx62-xr6m-q866.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vx62-xr6m-q866", + "modified": "2024-11-05T18:32:12Z", + "published": "2024-11-05T18:32:12Z", + "aliases": [ + "CVE-2024-50107" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86/intel/pmc: Fix pmc_core_iounmap to call iounmap for valid addresses\n\nCommit 50c6dbdfd16e (\"x86/ioremap: Improve iounmap() address range checks\")\nintroduces a WARN when adrress ranges of iounmap are invalid. On Thinkpad\nP1 Gen 7 (Meteor Lake-P) this caused the following warning to appear:\n\nWARNING: CPU: 7 PID: 713 at arch/x86/mm/ioremap.c:461 iounmap+0x58/0x1f0\nModules linked in: rfkill(+) snd_timer(+) fjes(+) snd soundcore intel_pmc_core(+)\nint3403_thermal(+) int340x_thermal_zone intel_vsec pmt_telemetry acpi_pad pmt_class\nacpi_tad int3400_thermal acpi_thermal_rel joydev loop nfnetlink zram xe drm_suballoc_helper\nnouveau i915 mxm_wmi drm_ttm_helper gpu_sched drm_gpuvm drm_exec drm_buddy i2c_algo_bit\ncrct10dif_pclmul crc32_pclmul ttm crc32c_intel polyval_clmulni rtsx_pci_sdmmc ucsi_acpi\npolyval_generic mmc_core hid_multitouch drm_display_helper ghash_clmulni_intel typec_ucsi\nnvme sha512_ssse3 video sha256_ssse3 nvme_core intel_vpu sha1_ssse3 rtsx_pci cec typec\nnvme_auth i2c_hid_acpi i2c_hid wmi pinctrl_meteorlake serio_raw ip6_tables ip_tables fuse\nCPU: 7 UID: 0 PID: 713 Comm: (udev-worker) Not tainted 6.12.0-rc2iounmap+ #42\nHardware name: LENOVO 21KWCTO1WW/21KWCTO1WW, BIOS N48ET19W (1.06 ) 07/18/2024\nRIP: 0010:iounmap+0x58/0x1f0\nCode: 85 6a 01 00 00 48 8b 05 e6 e2 28 04 48 39 c5 72 19 eb 26 cc cc cc 48 ba 00 00 00 00 00 00 32 00 48 8d 44 02 ff 48 39 c5 72 23 <0f> 0b 48 83 c4 08 5b 5d 41 5c c3 cc cc cc cc 48 ba 00 00 00 00 00\nRSP: 0018:ffff888131eff038 EFLAGS: 00010207\nRAX: ffffc90000000000 RBX: 0000000000000000 RCX: ffff888e33b80000\nRDX: dffffc0000000000 RSI: ffff888e33bc29c0 RDI: 0000000000000000\nRBP: 0000000000000000 R08: ffff8881598a8000 R09: ffff888e2ccedc10\nR10: 0000000000000003 R11: ffffffffb3367634 R12: 00000000fe000000\nR13: ffff888101d0da28 R14: ffffffffc2e437e0 R15: ffff888110b03b28\nFS: 00007f3c1d4b3980(0000) GS:ffff888e33b80000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00005651cfc93578 CR3: 0000000124e4c002 CR4: 0000000000f70ef0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000ffff07f0 DR7: 0000000000000400\nPKRU: 55555554\nCall Trace:\n\n? __warn.cold+0xb6/0x176\n? iounmap+0x58/0x1f0\n? report_bug+0x1f4/0x2b0\n? handle_bug+0x58/0x90\n? exc_invalid_op+0x17/0x40\n? asm_exc_invalid_op+0x1a/0x20\n? iounmap+0x58/0x1f0\npmc_core_ssram_get_pmc+0x477/0x6c0 [intel_pmc_core]\n? __pfx_pmc_core_ssram_get_pmc+0x10/0x10 [intel_pmc_core]\n? __pfx_do_pci_enable_device+0x10/0x10\n? pci_wait_for_pending+0x60/0x110\n? pci_enable_device_flags+0x1e3/0x2e0\n? __pfx_mtl_core_init+0x10/0x10 [intel_pmc_core]\npmc_core_ssram_init+0x7f/0x110 [intel_pmc_core]\nmtl_core_init+0xda/0x130 [intel_pmc_core]\n? __mutex_init+0xb9/0x130\npmc_core_probe+0x27e/0x10b0 [intel_pmc_core]\n? _raw_spin_lock_irqsave+0x96/0xf0\n? __pfx_pmc_core_probe+0x10/0x10 [intel_pmc_core]\n? __pfx_mutex_unlock+0x10/0x10\n? __pfx_mutex_lock+0x10/0x10\n? device_pm_check_callbacks+0x82/0x370\n? acpi_dev_pm_attach+0x234/0x2b0\nplatform_probe+0x9f/0x150\nreally_probe+0x1e0/0x8a0\n__driver_probe_device+0x18c/0x370\n? __pfx___driver_attach+0x10/0x10\ndriver_probe_device+0x4a/0x120\n__driver_attach+0x190/0x4a0\n? __pfx___driver_attach+0x10/0x10\nbus_for_each_dev+0x103/0x180\n? __pfx_bus_for_each_dev+0x10/0x10\n? klist_add_tail+0x136/0x270\nbus_add_driver+0x2fc/0x540\ndriver_register+0x1a5/0x360\n? __pfx_pmc_core_driver_init+0x10/0x10 [intel_pmc_core]\ndo_one_initcall+0xa4/0x380\n? __pfx_do_one_initcall+0x10/0x10\n? kasan_unpoison+0x44/0x70\ndo_init_module+0x296/0x800\nload_module+0x5090/0x6ce0\n? __pfx_load_module+0x10/0x10\n? ima_post_read_file+0x193/0x200\n? __pfx_ima_post_read_file+0x10/0x10\n? rw_verify_area+0x152/0x4c0\n? kernel_read_file+0x257/0x750\n? __pfx_kernel_read_file+0x10/0x10\n? __pfx_filemap_get_read_batch+0x10/0x10\n? init_module_from_file+0xd1/0x130\ninit_module_from_file+0xd1/0x130\n? __pfx_init_module_from_file+0x10/0\n---truncated---", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50107" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/01c473e64cafe2231e51be140446388024e669e8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/48771da48072823956b271dddd568492c13d8170" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T18:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-w2rm-ghcp-rwrp/GHSA-w2rm-ghcp-rwrp.json b/advisories/unreviewed/2024/11/GHSA-w2rm-ghcp-rwrp/GHSA-w2rm-ghcp-rwrp.json index 90132c9f0f3..7464f2ed278 100644 --- a/advisories/unreviewed/2024/11/GHSA-w2rm-ghcp-rwrp/GHSA-w2rm-ghcp-rwrp.json +++ b/advisories/unreviewed/2024/11/GHSA-w2rm-ghcp-rwrp/GHSA-w2rm-ghcp-rwrp.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w2rm-ghcp-rwrp", - "modified": "2024-11-05T15:30:37Z", + "modified": "2024-11-05T18:32:10Z", "published": "2024-11-05T15:30:37Z", "aliases": [ "CVE-2024-51013" ], "details": "Netgear R7000P v1.3.3.154 was discovered to contain a stack overflow via the RADIUSAddr%d_wla parameter at wireless.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-05T15:15:25Z" diff --git a/advisories/unreviewed/2024/11/GHSA-w6g3-r938-vj7f/GHSA-w6g3-r938-vj7f.json b/advisories/unreviewed/2024/11/GHSA-w6g3-r938-vj7f/GHSA-w6g3-r938-vj7f.json index d2058e314f7..cd55d4c0499 100644 --- a/advisories/unreviewed/2024/11/GHSA-w6g3-r938-vj7f/GHSA-w6g3-r938-vj7f.json +++ b/advisories/unreviewed/2024/11/GHSA-w6g3-r938-vj7f/GHSA-w6g3-r938-vj7f.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-w6g3-r938-vj7f", - "modified": "2024-11-04T21:30:32Z", + "modified": "2024-11-05T18:32:05Z", "published": "2024-11-04T21:30:32Z", "aliases": [ "CVE-2024-34891" ], "details": "Insufficiently protected credentials in DAV server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to read Exchange account passwords via HTTP GET request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-312" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-04T19:15:06Z" diff --git a/advisories/unreviewed/2024/11/GHSA-w824-fqw5-9rp4/GHSA-w824-fqw5-9rp4.json b/advisories/unreviewed/2024/11/GHSA-w824-fqw5-9rp4/GHSA-w824-fqw5-9rp4.json new file mode 100644 index 00000000000..0913e3cffa6 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-w824-fqw5-9rp4/GHSA-w824-fqw5-9rp4.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w824-fqw5-9rp4", + "modified": "2024-11-05T18:32:12Z", + "published": "2024-11-05T18:32:12Z", + "aliases": [ + "CVE-2024-50111" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nLoongArch: Enable IRQ if do_ale() triggered in irq-enabled context\n\nUnaligned access exception can be triggered in irq-enabled context such\nas user mode, in this case do_ale() may call get_user() which may cause\nsleep. Then we will get:\n\n BUG: sleeping function called from invalid context at arch/loongarch/kernel/access-helper.h:7\n in_atomic(): 0, irqs_disabled(): 1, non_block: 0, pid: 129, name: modprobe\n preempt_count: 0, expected: 0\n RCU nest depth: 0, expected: 0\n CPU: 0 UID: 0 PID: 129 Comm: modprobe Tainted: G W 6.12.0-rc1+ #1723\n Tainted: [W]=WARN\n Stack : 9000000105e0bd48 0000000000000000 9000000003803944 9000000105e08000\n 9000000105e0bc70 9000000105e0bc78 0000000000000000 0000000000000000\n 9000000105e0bc78 0000000000000001 9000000185e0ba07 9000000105e0b890\n ffffffffffffffff 9000000105e0bc78 73924b81763be05b 9000000100194500\n 000000000000020c 000000000000000a 0000000000000000 0000000000000003\n 00000000000023f0 00000000000e1401 00000000072f8000 0000007ffbb0e260\n 0000000000000000 0000000000000000 9000000005437650 90000000055d5000\n 0000000000000000 0000000000000003 0000007ffbb0e1f0 0000000000000000\n 0000005567b00490 0000000000000000 9000000003803964 0000007ffbb0dfec\n 00000000000000b0 0000000000000007 0000000000000003 0000000000071c1d\n ...\n Call Trace:\n [<9000000003803964>] show_stack+0x64/0x1a0\n [<9000000004c57464>] dump_stack_lvl+0x74/0xb0\n [<9000000003861ab4>] __might_resched+0x154/0x1a0\n [<900000000380c96c>] emulate_load_store_insn+0x6c/0xf60\n [<9000000004c58118>] do_ale+0x78/0x180\n [<9000000003801bc8>] handle_ale+0x128/0x1e0\n\nSo enable IRQ if unaligned access exception is triggered in irq-enabled\ncontext to fix it.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50111" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/69cc6fad5df4ce652d969be69acc60e269e5eea1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8915ed160dbd32b5ef5864df9a9fc11db83a77bb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/afbfb3568d78082078acc8bb2b29bb47af87253c" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T18:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-wcw6-xhvq-24qp/GHSA-wcw6-xhvq-24qp.json b/advisories/unreviewed/2024/11/GHSA-wcw6-xhvq-24qp/GHSA-wcw6-xhvq-24qp.json new file mode 100644 index 00000000000..0c8d1862e3f --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-wcw6-xhvq-24qp/GHSA-wcw6-xhvq-24qp.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wcw6-xhvq-24qp", + "modified": "2024-11-05T18:32:12Z", + "published": "2024-11-05T18:32:12Z", + "aliases": [ + "CVE-2024-50116" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: fix kernel bug due to missing clearing of buffer delay flag\n\nSyzbot reported that after nilfs2 reads a corrupted file system image\nand degrades to read-only, the BUG_ON check for the buffer delay flag\nin submit_bh_wbc() may fail, causing a kernel bug.\n\nThis is because the buffer delay flag is not cleared when clearing the\nbuffer state flags to discard a page/folio or a buffer head. So, fix\nthis.\n\nThis became necessary when the use of nilfs2's own page clear routine\nwas expanded. This state inconsistency does not occur if the buffer\nis written normally by log writing.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50116" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/27524f65621f490184f2ace44cd8e5f3685af4a3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6ed469df0bfbef3e4b44fca954a781919db9f7ab" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/743c78d455e784097011ea958b27396001181567" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/822203f6355f4b322d21e7115419f6b98284be25" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c6f58ff2d4c552927fe9a187774e668ebba6c7aa" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T18:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-wg7j-6r9g-jjch/GHSA-wg7j-6r9g-jjch.json b/advisories/unreviewed/2024/11/GHSA-wg7j-6r9g-jjch/GHSA-wg7j-6r9g-jjch.json index 90ddd26ca9d..807a3e81ace 100644 --- a/advisories/unreviewed/2024/11/GHSA-wg7j-6r9g-jjch/GHSA-wg7j-6r9g-jjch.json +++ b/advisories/unreviewed/2024/11/GHSA-wg7j-6r9g-jjch/GHSA-wg7j-6r9g-jjch.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wg7j-6r9g-jjch", - "modified": "2024-11-05T15:30:37Z", + "modified": "2024-11-05T18:32:10Z", "published": "2024-11-05T15:30:37Z", "aliases": [ "CVE-2024-51015" ], "details": "Netgear R7000P v1.3.3.154 was discovered to contain a command injection vulnerability via the device_name2 parameter at operation_mode.cgi. This vulnerability allows attackers to execute arbitrary OS commands via a crafted request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-05T15:15:25Z" diff --git a/advisories/unreviewed/2024/11/GHSA-wggq-gr89-33vp/GHSA-wggq-gr89-33vp.json b/advisories/unreviewed/2024/11/GHSA-wggq-gr89-33vp/GHSA-wggq-gr89-33vp.json new file mode 100644 index 00000000000..6eec9d81b64 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-wggq-gr89-33vp/GHSA-wggq-gr89-33vp.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wggq-gr89-33vp", + "modified": "2024-11-05T18:32:11Z", + "published": "2024-11-05T18:32:11Z", + "aliases": [ + "CVE-2024-50097" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: fec: don't save PTP state if PTP is unsupported\n\nSome platforms (such as i.MX25 and i.MX27) do not support PTP, so on\nthese platforms fec_ptp_init() is not called and the related members\nin fep are not initialized. However, fec_ptp_save_state() is called\nunconditionally, which causes the kernel to panic. Therefore, add a\ncondition so that fec_ptp_save_state() is not called if PTP is not\nsupported.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50097" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3192e8d4a1ef9fc9bd7a59cdce51543367e5edd6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6be063071a457767ee229db13f019c2ec03bfe44" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7745e14f4c036ce94a5eb05d06e49b0d84b306f9" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T17:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-wqmj-2mp9-xqmr/GHSA-wqmj-2mp9-xqmr.json b/advisories/unreviewed/2024/11/GHSA-wqmj-2mp9-xqmr/GHSA-wqmj-2mp9-xqmr.json new file mode 100644 index 00000000000..a8d21c509db --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-wqmj-2mp9-xqmr/GHSA-wqmj-2mp9-xqmr.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wqmj-2mp9-xqmr", + "modified": "2024-11-05T18:32:12Z", + "published": "2024-11-05T18:32:12Z", + "aliases": [ + "CVE-2024-50130" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: bpf: must hold reference on net namespace\n\nBUG: KASAN: slab-use-after-free in __nf_unregister_net_hook+0x640/0x6b0\nRead of size 8 at addr ffff8880106fe400 by task repro/72=\nbpf_nf_link_release+0xda/0x1e0\nbpf_link_free+0x139/0x2d0\nbpf_link_release+0x68/0x80\n__fput+0x414/0xb60\n\nEric says:\n It seems that bpf was able to defer the __nf_unregister_net_hook()\n after exit()/close() time.\n Perhaps a netns reference is missing, because the netns has been\n dismantled/freed already.\n bpf_nf_link_attach() does :\n link->net = net;\n But I do not see a reference being taken on net.\n\nAdd such a reference and release it after hook unreg.\nNote that I was unable to get syzbot reproducer to work, so I\ndo not know if this resolves this splat.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50130" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1230fe7ad3974f7bf6c78901473e039b34d4fb1f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d0d7939543a1b3bb93af9a18d258a774daf8f162" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f41bd93b3e0508edc7ba820357f949071dcc0acc" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T18:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-wr5h-8pg2-5j9q/GHSA-wr5h-8pg2-5j9q.json b/advisories/unreviewed/2024/11/GHSA-wr5h-8pg2-5j9q/GHSA-wr5h-8pg2-5j9q.json new file mode 100644 index 00000000000..c40c6b70abf --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-wr5h-8pg2-5j9q/GHSA-wr5h-8pg2-5j9q.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wr5h-8pg2-5j9q", + "modified": "2024-11-05T18:32:12Z", + "published": "2024-11-05T18:32:12Z", + "aliases": [ + "CVE-2024-50129" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: pse-pd: Fix out of bound for loop\n\nAdjust the loop limit to prevent out-of-bounds access when iterating over\nPI structures. The loop should not reach the index pcdev->nr_lines since\nwe allocate exactly pcdev->nr_lines number of PI structures. This fix\nensures proper bounds are maintained during iterations.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50129" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/50ea68146d82f34b3ad80d8290ef8222136dedd7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f2767a41959e60763949c73ee180e40c686e807e" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T18:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-wrcm-3w95-9w36/GHSA-wrcm-3w95-9w36.json b/advisories/unreviewed/2024/11/GHSA-wrcm-3w95-9w36/GHSA-wrcm-3w95-9w36.json new file mode 100644 index 00000000000..7c0ddb7d773 --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-wrcm-3w95-9w36/GHSA-wrcm-3w95-9w36.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wrcm-3w95-9w36", + "modified": "2024-11-05T18:32:12Z", + "published": "2024-11-05T18:32:12Z", + "aliases": [ + "CVE-2024-50121" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: cancel nfsd_shrinker_work using sync mode in nfs4_state_shutdown_net\n\nIn the normal case, when we excute `echo 0 > /proc/fs/nfsd/threads`, the\nfunction `nfs4_state_destroy_net` in `nfs4_state_shutdown_net` will\nrelease all resources related to the hashed `nfs4_client`. If the\n`nfsd_client_shrinker` is running concurrently, the `expire_client`\nfunction will first unhash this client and then destroy it. This can\nlead to the following warning. Additionally, numerous use-after-free\nerrors may occur as well.\n\nnfsd_client_shrinker echo 0 > /proc/fs/nfsd/threads\n\nexpire_client nfsd_shutdown_net\n unhash_client ...\n nfs4_state_shutdown_net\n /* won't wait shrinker exit */\n /* cancel_work(&nn->nfsd_shrinker_work)\n * nfsd_file for this /* won't destroy unhashed client1 */\n * client1 still alive nfs4_state_destroy_net\n */\n\n nfsd_file_cache_shutdown\n /* trigger warning */\n kmem_cache_destroy(nfsd_file_slab)\n kmem_cache_destroy(nfsd_file_mark_slab)\n /* release nfsd_file and mark */\n __destroy_client\n\n====================================================================\nBUG nfsd_file (Not tainted): Objects remaining in nfsd_file on\n__kmem_cache_shutdown()\n--------------------------------------------------------------------\nCPU: 4 UID: 0 PID: 764 Comm: sh Not tainted 6.12.0-rc3+ #1\n\n dump_stack_lvl+0x53/0x70\n slab_err+0xb0/0xf0\n __kmem_cache_shutdown+0x15c/0x310\n kmem_cache_destroy+0x66/0x160\n nfsd_file_cache_shutdown+0xac/0x210 [nfsd]\n nfsd_destroy_serv+0x251/0x2a0 [nfsd]\n nfsd_svc+0x125/0x1e0 [nfsd]\n write_threads+0x16a/0x2a0 [nfsd]\n nfsctl_transaction_write+0x74/0xa0 [nfsd]\n vfs_write+0x1a5/0x6d0\n ksys_write+0xc1/0x160\n do_syscall_64+0x5f/0x170\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\n====================================================================\nBUG nfsd_file_mark (Tainted: G B W ): Objects remaining\nnfsd_file_mark on __kmem_cache_shutdown()\n--------------------------------------------------------------------\n\n dump_stack_lvl+0x53/0x70\n slab_err+0xb0/0xf0\n __kmem_cache_shutdown+0x15c/0x310\n kmem_cache_destroy+0x66/0x160\n nfsd_file_cache_shutdown+0xc8/0x210 [nfsd]\n nfsd_destroy_serv+0x251/0x2a0 [nfsd]\n nfsd_svc+0x125/0x1e0 [nfsd]\n write_threads+0x16a/0x2a0 [nfsd]\n nfsctl_transaction_write+0x74/0xa0 [nfsd]\n vfs_write+0x1a5/0x6d0\n ksys_write+0xc1/0x160\n do_syscall_64+0x5f/0x170\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\nTo resolve this issue, cancel `nfsd_shrinker_work` using synchronous\nmode in nfs4_state_shutdown_net.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50121" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/add1df5eba163a3a6ece11cb85890e2e410baaea" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d5ff2fb2e7167e9483846e34148e60c0c016a1f6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f965dc0f099a54fca100acf6909abe52d0c85328" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T18:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-x3fm-x4jg-jw2h/GHSA-x3fm-x4jg-jw2h.json b/advisories/unreviewed/2024/11/GHSA-x3fm-x4jg-jw2h/GHSA-x3fm-x4jg-jw2h.json new file mode 100644 index 00000000000..23c16f391df --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-x3fm-x4jg-jw2h/GHSA-x3fm-x4jg-jw2h.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x3fm-x4jg-jw2h", + "modified": "2024-11-05T18:32:13Z", + "published": "2024-11-05T18:32:12Z", + "aliases": [ + "CVE-2024-50133" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nLoongArch: Don't crash in stack_top() for tasks without vDSO\n\nNot all tasks have a vDSO mapped, for example kthreads never do. If such\na task ever ends up calling stack_top(), it will derefence the NULL vdso\npointer and crash.\n\nThis can for example happen when using kunit:\n\n\t[<9000000000203874>] stack_top+0x58/0xa8\n\t[<90000000002956cc>] arch_pick_mmap_layout+0x164/0x220\n\t[<90000000003c284c>] kunit_vm_mmap_init+0x108/0x12c\n\t[<90000000003c1fbc>] __kunit_add_resource+0x38/0x8c\n\t[<90000000003c2704>] kunit_vm_mmap+0x88/0xc8\n\t[<9000000000410b14>] usercopy_test_init+0xbc/0x25c\n\t[<90000000003c1db4>] kunit_try_run_case+0x5c/0x184\n\t[<90000000003c3d54>] kunit_generic_run_threadfn_adapter+0x24/0x48\n\t[<900000000022e4bc>] kthread+0xc8/0xd4\n\t[<9000000000200ce8>] ret_from_kernel_thread+0xc/0xa4", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50133" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/041cc3860b06770357876d1114d615333b0fbf31" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/134475a9ab8487527238d270639a8cb74c10aab2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a67d4a02bf43e15544179895ede7d5f97b84b550" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a94c197d4d749954dfaa37e907fcc8c04e4aad7e" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T18:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-x848-x286-ccwf/GHSA-x848-x286-ccwf.json b/advisories/unreviewed/2024/11/GHSA-x848-x286-ccwf/GHSA-x848-x286-ccwf.json new file mode 100644 index 00000000000..02804d18c3e --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-x848-x286-ccwf/GHSA-x848-x286-ccwf.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x848-x286-ccwf", + "modified": "2024-11-05T18:32:12Z", + "published": "2024-11-05T18:32:12Z", + "aliases": [ + "CVE-2024-50127" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: sched: fix use-after-free in taprio_change()\n\nIn 'taprio_change()', 'admin' pointer may become dangling due to sched\nswitch / removal caused by 'advance_sched()', and critical section\nprotected by 'q->current_entry_lock' is too small to prevent from such\na scenario (which causes use-after-free detected by KASAN). Fix this\nby prefer 'rcu_replace_pointer()' over 'rcu_assign_pointer()' to update\n'admin' immediately before an attempt to schedule freeing.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50127" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0d4c0d2844e4eac3aed647f948fd7e60eea56a61" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2240f9376f20f8b6463232b4ca7292569217237f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/999612996df28d81f163dad530d7f8026e03aec6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f504465970aebb2467da548f7c1efbbf36d0f44b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fe371f084073e8672a2d7d46b335c3c060d1e301" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T18:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/11/GHSA-xf32-4q4v-xc47/GHSA-xf32-4q4v-xc47.json b/advisories/unreviewed/2024/11/GHSA-xf32-4q4v-xc47/GHSA-xf32-4q4v-xc47.json index 4d315e88d9a..3a681811255 100644 --- a/advisories/unreviewed/2024/11/GHSA-xf32-4q4v-xc47/GHSA-xf32-4q4v-xc47.json +++ b/advisories/unreviewed/2024/11/GHSA-xf32-4q4v-xc47/GHSA-xf32-4q4v-xc47.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-xf32-4q4v-xc47", - "modified": "2024-11-05T15:30:38Z", + "modified": "2024-11-05T18:32:10Z", "published": "2024-11-05T15:30:38Z", "aliases": [ "CVE-2024-52014" ], "details": "Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a stack overflow via the pptp_user_ip parameter at genie_pptp.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -29,9 +32,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-120" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-11-05T15:15:26Z" diff --git a/advisories/unreviewed/2024/11/GHSA-xfw2-qh29-p3mm/GHSA-xfw2-qh29-p3mm.json b/advisories/unreviewed/2024/11/GHSA-xfw2-qh29-p3mm/GHSA-xfw2-qh29-p3mm.json new file mode 100644 index 00000000000..225e89b391d --- /dev/null +++ b/advisories/unreviewed/2024/11/GHSA-xfw2-qh29-p3mm/GHSA-xfw2-qh29-p3mm.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xfw2-qh29-p3mm", + "modified": "2024-11-05T18:32:12Z", + "published": "2024-11-05T18:32:12Z", + "aliases": [ + "CVE-2024-50110" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: fix one more kernel-infoleak in algo dumping\n\nDuring fuzz testing, the following issue was discovered:\n\nBUG: KMSAN: kernel-infoleak in _copy_to_iter+0x598/0x2a30\n _copy_to_iter+0x598/0x2a30\n __skb_datagram_iter+0x168/0x1060\n skb_copy_datagram_iter+0x5b/0x220\n netlink_recvmsg+0x362/0x1700\n sock_recvmsg+0x2dc/0x390\n __sys_recvfrom+0x381/0x6d0\n __x64_sys_recvfrom+0x130/0x200\n x64_sys_call+0x32c8/0x3cc0\n do_syscall_64+0xd8/0x1c0\n entry_SYSCALL_64_after_hwframe+0x79/0x81\n\nUninit was stored to memory at:\n copy_to_user_state_extra+0xcc1/0x1e00\n dump_one_state+0x28c/0x5f0\n xfrm_state_walk+0x548/0x11e0\n xfrm_dump_sa+0x1e0/0x840\n netlink_dump+0x943/0x1c40\n __netlink_dump_start+0x746/0xdb0\n xfrm_user_rcv_msg+0x429/0xc00\n netlink_rcv_skb+0x613/0x780\n xfrm_netlink_rcv+0x77/0xc0\n netlink_unicast+0xe90/0x1280\n netlink_sendmsg+0x126d/0x1490\n __sock_sendmsg+0x332/0x3d0\n ____sys_sendmsg+0x863/0xc30\n ___sys_sendmsg+0x285/0x3e0\n __x64_sys_sendmsg+0x2d6/0x560\n x64_sys_call+0x1316/0x3cc0\n do_syscall_64+0xd8/0x1c0\n entry_SYSCALL_64_after_hwframe+0x79/0x81\n\nUninit was created at:\n __kmalloc+0x571/0xd30\n attach_auth+0x106/0x3e0\n xfrm_add_sa+0x2aa0/0x4230\n xfrm_user_rcv_msg+0x832/0xc00\n netlink_rcv_skb+0x613/0x780\n xfrm_netlink_rcv+0x77/0xc0\n netlink_unicast+0xe90/0x1280\n netlink_sendmsg+0x126d/0x1490\n __sock_sendmsg+0x332/0x3d0\n ____sys_sendmsg+0x863/0xc30\n ___sys_sendmsg+0x285/0x3e0\n __x64_sys_sendmsg+0x2d6/0x560\n x64_sys_call+0x1316/0x3cc0\n do_syscall_64+0xd8/0x1c0\n entry_SYSCALL_64_after_hwframe+0x79/0x81\n\nBytes 328-379 of 732 are uninitialized\nMemory access of size 732 starts at ffff88800e18e000\nData copied to user address 00007ff30f48aff0\n\nCPU: 2 PID: 18167 Comm: syz-executor.0 Not tainted 6.8.11 #1\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014\n\nFixes copying of xfrm algorithms where some random\ndata of the structure fields can end up in userspace.\nPadding in structures may be filled with random (possibly sensitve)\ndata and should never be given directly to user-space.\n\nA similar issue was resolved in the commit\n8222d5910dae (\"xfrm: Zero padding when dumping algos and encap\")\n\nFound by Linux Verification Center (linuxtesting.org) with Syzkaller.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50110" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1e8fbd2441cb2ea28d6825f2985bf7d84af060bb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/610d4cea9b442b22b4820695fc3335e64849725e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6889cd2a93e1e3606b3f6e958aa0924e836de4d2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c73bca72b84b453c8d26a5e7673b20adb294bf54" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/dc2ad8e8818e4bf1a93db78d81745b4877b32972" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-05T18:15:14Z" + } +} \ No newline at end of file