diff --git a/advisories/github-reviewed/2024/03/GHSA-5667-3wch-7q7w/GHSA-5667-3wch-7q7w.json b/advisories/github-reviewed/2024/03/GHSA-5667-3wch-7q7w/GHSA-5667-3wch-7q7w.json index ef09d58e48d..6c19c291065 100644 --- a/advisories/github-reviewed/2024/03/GHSA-5667-3wch-7q7w/GHSA-5667-3wch-7q7w.json +++ b/advisories/github-reviewed/2024/03/GHSA-5667-3wch-7q7w/GHSA-5667-3wch-7q7w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5667-3wch-7q7w", - "modified": "2024-04-02T19:28:13Z", + "modified": "2024-04-03T15:30:41Z", "published": "2024-03-27T09:30:40Z", "aliases": [ "CVE-2024-1023" @@ -76,6 +76,10 @@ "type": "WEB", "url": "https://github.com/eclipse-vertx/vert.x/commit/dd6f64302b56cd4d3dcf61efaaf174b5f6ce676d" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:1662" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-1023" diff --git a/advisories/github-reviewed/2024/03/GHSA-7g97-7r3c-5cc6/GHSA-7g97-7r3c-5cc6.json b/advisories/github-reviewed/2024/03/GHSA-7g97-7r3c-5cc6/GHSA-7g97-7r3c-5cc6.json index ecb4c19080b..a51b1a62c04 100644 --- a/advisories/github-reviewed/2024/03/GHSA-7g97-7r3c-5cc6/GHSA-7g97-7r3c-5cc6.json +++ b/advisories/github-reviewed/2024/03/GHSA-7g97-7r3c-5cc6/GHSA-7g97-7r3c-5cc6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7g97-7r3c-5cc6", - "modified": "2024-03-13T18:10:58Z", + "modified": "2024-04-03T15:30:40Z", "published": "2024-03-13T12:31:06Z", "aliases": [ "CVE-2024-1979" @@ -52,6 +52,10 @@ "type": "WEB", "url": "https://github.com/quarkusio/quarkus/commit/5bc05ee35365a905f0e9e37f248c38688a81caaf" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:1662" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-1979" diff --git a/advisories/github-reviewed/2024/04/GHSA-9ph3-v2vh-3qx7/GHSA-9ph3-v2vh-3qx7.json b/advisories/github-reviewed/2024/04/GHSA-9ph3-v2vh-3qx7/GHSA-9ph3-v2vh-3qx7.json index 4eef430768f..47ac6e57467 100644 --- a/advisories/github-reviewed/2024/04/GHSA-9ph3-v2vh-3qx7/GHSA-9ph3-v2vh-3qx7.json +++ b/advisories/github-reviewed/2024/04/GHSA-9ph3-v2vh-3qx7/GHSA-9ph3-v2vh-3qx7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9ph3-v2vh-3qx7", - "modified": "2024-04-02T16:15:47Z", + "modified": "2024-04-03T15:30:41Z", "published": "2024-04-02T09:30:42Z", "aliases": [ "CVE-2024-1300" @@ -79,6 +79,10 @@ "type": "WEB", "url": "https://github.com/eclipse-vertx/vert.x/commit/7ad34ea9d78f85e26b231ee3ec8d492d10046479" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2024:1662" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-1300" diff --git a/advisories/unreviewed/2024/02/GHSA-63f3-2rgp-79qx/GHSA-63f3-2rgp-79qx.json b/advisories/unreviewed/2024/02/GHSA-63f3-2rgp-79qx/GHSA-63f3-2rgp-79qx.json index f1e592a10b4..46730143199 100644 --- a/advisories/unreviewed/2024/02/GHSA-63f3-2rgp-79qx/GHSA-63f3-2rgp-79qx.json +++ b/advisories/unreviewed/2024/02/GHSA-63f3-2rgp-79qx/GHSA-63f3-2rgp-79qx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-63f3-2rgp-79qx", - "modified": "2024-03-14T21:30:51Z", + "modified": "2024-04-03T15:30:40Z", "published": "2024-02-21T15:30:45Z", "aliases": [ "CVE-2024-26585" @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26585" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/196f198ca6fce04ba6ce262f5a0e4d567d7d219d" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/6db22d6c7a6dc914b12c0469b94eb639b6a8a146" diff --git a/advisories/unreviewed/2024/02/GHSA-rjjw-vjj8-q96x/GHSA-rjjw-vjj8-q96x.json b/advisories/unreviewed/2024/02/GHSA-rjjw-vjj8-q96x/GHSA-rjjw-vjj8-q96x.json index 4d9c9c89bc8..1a46c0edc22 100644 --- a/advisories/unreviewed/2024/02/GHSA-rjjw-vjj8-q96x/GHSA-rjjw-vjj8-q96x.json +++ b/advisories/unreviewed/2024/02/GHSA-rjjw-vjj8-q96x/GHSA-rjjw-vjj8-q96x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rjjw-vjj8-q96x", - "modified": "2024-02-28T03:30:30Z", + "modified": "2024-04-03T15:30:40Z", "published": "2024-02-21T15:30:45Z", "aliases": [ "CVE-2024-26584" @@ -30,6 +30,10 @@ "type": "WEB", "url": "https://git.kernel.org/stable/c/ab6397f072e5097f267abf5cb08a8004e6b17694" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cd1bbca03f3c1d845ce274c0d0a66de8e5929f72" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EZOU3745CWCDZ7EMKMXB2OEEIB5Q3IWM" diff --git a/advisories/unreviewed/2024/03/GHSA-79wp-fmwh-x929/GHSA-79wp-fmwh-x929.json b/advisories/unreviewed/2024/03/GHSA-79wp-fmwh-x929/GHSA-79wp-fmwh-x929.json index 8c8d7e20f1c..f33167ad8ae 100644 --- a/advisories/unreviewed/2024/03/GHSA-79wp-fmwh-x929/GHSA-79wp-fmwh-x929.json +++ b/advisories/unreviewed/2024/03/GHSA-79wp-fmwh-x929/GHSA-79wp-fmwh-x929.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-79wp-fmwh-x929", - "modified": "2024-03-21T12:31:56Z", + "modified": "2024-04-03T15:30:41Z", "published": "2024-03-21T12:31:56Z", "aliases": [ "CVE-2024-26642" @@ -21,6 +21,18 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/16603605b667b70da974bea8216c93e7db043bf1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/72c1efe3f247a581667b7d368fff3bd9a03cd57a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8e07c16695583a66e81f67ce4c46e94dece47ba7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c0c2176d1814b92ea4c8e7eb7c9cd94cd99c1b12" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/03/GHSA-ph5r-c8gc-xg6f/GHSA-ph5r-c8gc-xg6f.json b/advisories/unreviewed/2024/03/GHSA-ph5r-c8gc-xg6f/GHSA-ph5r-c8gc-xg6f.json index 6066fc9ed43..6490d838383 100644 --- a/advisories/unreviewed/2024/03/GHSA-ph5r-c8gc-xg6f/GHSA-ph5r-c8gc-xg6f.json +++ b/advisories/unreviewed/2024/03/GHSA-ph5r-c8gc-xg6f/GHSA-ph5r-c8gc-xg6f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ph5r-c8gc-xg6f", - "modified": "2024-03-21T12:31:56Z", + "modified": "2024-04-03T15:30:41Z", "published": "2024-03-21T12:31:56Z", "aliases": [ "CVE-2024-26643" @@ -18,9 +18,21 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26643" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/406b0241d0eb598a0b330ab20ae325537d8d8163" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5224afbc30c3ca9ba23e752f0f138729b2c48dd8" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/552705a3650bbf46a22b1adedc1b04181490fc36" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b2d6f9a5b1cf968f1eaa71085ceeb09c2cb276b1" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/04/GHSA-2595-73wg-wgrp/GHSA-2595-73wg-wgrp.json b/advisories/unreviewed/2024/04/GHSA-2595-73wg-wgrp/GHSA-2595-73wg-wgrp.json new file mode 100644 index 00000000000..f74d77cdf53 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-2595-73wg-wgrp/GHSA-2595-73wg-wgrp.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2595-73wg-wgrp", + "modified": "2024-04-03T15:30:42Z", + "published": "2024-04-03T15:30:42Z", + "aliases": [ + "CVE-2023-52638" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: j1939: prevent deadlock by changing j1939_socks_lock to rwlock\n\nThe following 3 locks would race against each other, causing the\ndeadlock situation in the Syzbot bug report:\n\n- j1939_socks_lock\n- active_session_list_lock\n- sk_session_queue_lock\n\nA reasonable fix is to change j1939_socks_lock to an rwlock, since in\nthe rare situations where a write lock is required for the linked list\nthat j1939_socks_lock is protecting, the code does not attempt to\nacquire any more locks. This would break the circular lock dependency,\nwhere, for example, the current thread already locks j1939_socks_lock\nand attempts to acquire sk_session_queue_lock, and at the same time,\nanother thread attempts to acquire j1939_socks_lock while holding\nsk_session_queue_lock.\n\nNOTE: This patch along does not fix the unregister_netdevice bug\nreported by Syzbot; instead, it solves a deadlock situation to prepare\nfor one or more further patches to actually fix the Syzbot bug, which\nappears to be a reference counting problem within the j1939 codebase.\n\n[mkl: remove unrelated newline change]", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52638" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/03358aba991668d3bb2c65b3c82aa32c36851170" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/26dfe112ec2e95fe0099681f6aec33da13c2dd8e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/559b6322f9480bff68cfa98d108991e945a4f284" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6cdedc18ba7b9dacc36466e27e3267d201948c8d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/aedda066d717a0b4335d7e0a00b2e3a61e40afcf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T15:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-25pf-crf2-9cqg/GHSA-25pf-crf2-9cqg.json b/advisories/unreviewed/2024/04/GHSA-25pf-crf2-9cqg/GHSA-25pf-crf2-9cqg.json new file mode 100644 index 00000000000..0945bc05282 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-25pf-crf2-9cqg/GHSA-25pf-crf2-9cqg.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-25pf-crf2-9cqg", + "modified": "2024-04-03T15:30:42Z", + "published": "2024-04-03T15:30:42Z", + "aliases": [ + "CVE-2024-26699" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Fix array-index-out-of-bounds in dcn35_clkmgr\n\n[Why]\nThere is a potential memory access violation while\niterating through array of dcn35 clks.\n\n[How]\nLimit iteration per array size.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26699" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/46806e59a87790760870d216f54951a5b4d545bc" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ca400d8e0c1c9d79c08dfb6b7f966e26c8cae7fb" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T15:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-2mrh-g8f4-xvjv/GHSA-2mrh-g8f4-xvjv.json b/advisories/unreviewed/2024/04/GHSA-2mrh-g8f4-xvjv/GHSA-2mrh-g8f4-xvjv.json new file mode 100644 index 00000000000..d5b0c1e3571 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-2mrh-g8f4-xvjv/GHSA-2mrh-g8f4-xvjv.json @@ -0,0 +1,55 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2mrh-g8f4-xvjv", + "modified": "2024-04-03T15:30:42Z", + "published": "2024-04-03T15:30:42Z", + "aliases": [ + "CVE-2024-26695" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: ccp - Fix null pointer dereference in __sev_platform_shutdown_locked\n\nThe SEV platform device can be shutdown with a null psp_master,\ne.g., using DEBUG_TEST_DRIVER_REMOVE. Found using KASAN:\n\n[ 137.148210] ccp 0000:23:00.1: enabling device (0000 -> 0002)\n[ 137.162647] ccp 0000:23:00.1: no command queues available\n[ 137.170598] ccp 0000:23:00.1: sev enabled\n[ 137.174645] ccp 0000:23:00.1: psp enabled\n[ 137.178890] general protection fault, probably for non-canonical address 0xdffffc000000001e: 0000 [#1] PREEMPT SMP DEBUG_PAGEALLOC KASAN NOPTI\n[ 137.182693] KASAN: null-ptr-deref in range [0x00000000000000f0-0x00000000000000f7]\n[ 137.182693] CPU: 93 PID: 1 Comm: swapper/0 Not tainted 6.8.0-rc1+ #311\n[ 137.182693] RIP: 0010:__sev_platform_shutdown_locked+0x51/0x180\n[ 137.182693] Code: 08 80 3c 08 00 0f 85 0e 01 00 00 48 8b 1d 67 b6 01 08 48 b8 00 00 00 00 00 fc ff df 48 8d bb f0 00 00 00 48 89 f9 48 c1 e9 03 <80> 3c 01 00 0f 85 fe 00 00 00 48 8b 9b f0 00 00 00 48 85 db 74 2c\n[ 137.182693] RSP: 0018:ffffc900000cf9b0 EFLAGS: 00010216\n[ 137.182693] RAX: dffffc0000000000 RBX: 0000000000000000 RCX: 000000000000001e\n[ 137.182693] RDX: 0000000000000000 RSI: 0000000000000008 RDI: 00000000000000f0\n[ 137.182693] RBP: ffffc900000cf9c8 R08: 0000000000000000 R09: fffffbfff58f5a66\n[ 137.182693] R10: ffffc900000cf9c8 R11: ffffffffac7ad32f R12: ffff8881e5052c28\n[ 137.182693] R13: ffff8881e5052c28 R14: ffff8881758e43e8 R15: ffffffffac64abf8\n[ 137.182693] FS: 0000000000000000(0000) GS:ffff889de7000000(0000) knlGS:0000000000000000\n[ 137.182693] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 137.182693] CR2: 0000000000000000 CR3: 0000001cf7c7e000 CR4: 0000000000350ef0\n[ 137.182693] Call Trace:\n[ 137.182693] \n[ 137.182693] ? show_regs+0x6c/0x80\n[ 137.182693] ? __die_body+0x24/0x70\n[ 137.182693] ? die_addr+0x4b/0x80\n[ 137.182693] ? exc_general_protection+0x126/0x230\n[ 137.182693] ? asm_exc_general_protection+0x2b/0x30\n[ 137.182693] ? __sev_platform_shutdown_locked+0x51/0x180\n[ 137.182693] sev_firmware_shutdown.isra.0+0x1e/0x80\n[ 137.182693] sev_dev_destroy+0x49/0x100\n[ 137.182693] psp_dev_destroy+0x47/0xb0\n[ 137.182693] sp_destroy+0xbb/0x240\n[ 137.182693] sp_pci_remove+0x45/0x60\n[ 137.182693] pci_device_remove+0xaa/0x1d0\n[ 137.182693] device_remove+0xc7/0x170\n[ 137.182693] really_probe+0x374/0xbe0\n[ 137.182693] ? srso_return_thunk+0x5/0x5f\n[ 137.182693] __driver_probe_device+0x199/0x460\n[ 137.182693] driver_probe_device+0x4e/0xd0\n[ 137.182693] __driver_attach+0x191/0x3d0\n[ 137.182693] ? __pfx___driver_attach+0x10/0x10\n[ 137.182693] bus_for_each_dev+0x100/0x190\n[ 137.182693] ? __pfx_bus_for_each_dev+0x10/0x10\n[ 137.182693] ? __kasan_check_read+0x15/0x20\n[ 137.182693] ? srso_return_thunk+0x5/0x5f\n[ 137.182693] ? _raw_spin_unlock+0x27/0x50\n[ 137.182693] driver_attach+0x41/0x60\n[ 137.182693] bus_add_driver+0x2a8/0x580\n[ 137.182693] driver_register+0x141/0x480\n[ 137.182693] __pci_register_driver+0x1d6/0x2a0\n[ 137.182693] ? srso_return_thunk+0x5/0x5f\n[ 137.182693] ? esrt_sysfs_init+0x1cd/0x5d0\n[ 137.182693] ? __pfx_sp_mod_init+0x10/0x10\n[ 137.182693] sp_pci_init+0x22/0x30\n[ 137.182693] sp_mod_init+0x14/0x30\n[ 137.182693] ? __pfx_sp_mod_init+0x10/0x10\n[ 137.182693] do_one_initcall+0xd1/0x470\n[ 137.182693] ? __pfx_do_one_initcall+0x10/0x10\n[ 137.182693] ? parameq+0x80/0xf0\n[ 137.182693] ? srso_return_thunk+0x5/0x5f\n[ 137.182693] ? __kmalloc+0x3b0/0x4e0\n[ 137.182693] ? kernel_init_freeable+0x92d/0x1050\n[ 137.182693] ? kasan_populate_vmalloc_pte+0x171/0x190\n[ 137.182693] ? srso_return_thunk+0x5/0x5f\n[ 137.182693] kernel_init_freeable+0xa64/0x1050\n[ 137.182693] ? __pfx_kernel_init+0x10/0x10\n[ 137.182693] kernel_init+0x24/0x160\n[ 137.182693] ? __switch_to_asm+0x3e/0x70\n[ 137.182693] ret_from_fork+0x40/0x80\n[ 137.182693] ? __pfx_kernel_init+0x1\n---truncated---", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26695" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/58054faf3bd29cd0b949b77efcb6157f66f401ed" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7535ec350a5f09b5756a7607f5582913f21200f4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8731fe001a60581794ed9cf65da8cd304846a6fb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/88aa493f393d2ee38ac140e1f6ac1881346e85d4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b5909f197f3b26aebedca7d8ac7b688fd993a266" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ccb88e9549e7cfd8bcd511c538f437e20026e983" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T15:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-2vp9-gjfg-fmgw/GHSA-2vp9-gjfg-fmgw.json b/advisories/unreviewed/2024/04/GHSA-2vp9-gjfg-fmgw/GHSA-2vp9-gjfg-fmgw.json new file mode 100644 index 00000000000..f2b6bd1a4a6 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-2vp9-gjfg-fmgw/GHSA-2vp9-gjfg-fmgw.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2vp9-gjfg-fmgw", + "modified": "2024-04-03T15:30:43Z", + "published": "2024-04-03T15:30:43Z", + "aliases": [ + "CVE-2024-26710" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\npowerpc/kasan: Limit KASAN thread size increase to 32KB\n\nKASAN is seen to increase stack usage, to the point that it was reported\nto lead to stack overflow on some 32-bit machines (see link).\n\nTo avoid overflows the stack size was doubled for KASAN builds in\ncommit 3e8635fb2e07 (\"powerpc/kasan: Force thread size increase with\nKASAN\").\n\nHowever with a 32KB stack size to begin with, the doubling leads to a\n64KB stack, which causes build errors:\n arch/powerpc/kernel/switch.S:249: Error: operand out of range (0x000000000000fe50 is not between 0xffffffffffff8000 and 0x0000000000007fff)\n\nAlthough the asm could be reworked, in practice a 32KB stack seems\nsufficient even for KASAN builds - the additional usage seems to be in\nthe 2-3KB range for a 64-bit KASAN build.\n\nSo only increase the stack for KASAN if the stack size is < 32KB.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26710" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4297217bcf1f0948a19c2bacc6b68d92e7778ad9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4cc31fa07445879a13750cb061bb8c2654975fcb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b29b16bd836a838b7690f80e37f8376414c74cbe" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T15:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-2w67-3g2f-j7p2/GHSA-2w67-3g2f-j7p2.json b/advisories/unreviewed/2024/04/GHSA-2w67-3g2f-j7p2/GHSA-2w67-3g2f-j7p2.json new file mode 100644 index 00000000000..491c209db38 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-2w67-3g2f-j7p2/GHSA-2w67-3g2f-j7p2.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2w67-3g2f-j7p2", + "modified": "2024-04-03T15:30:42Z", + "published": "2024-04-03T15:30:42Z", + "aliases": [ + "CVE-2023-52637" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncan: j1939: Fix UAF in j1939_sk_match_filter during setsockopt(SO_J1939_FILTER)\n\nLock jsk->sk to prevent UAF when setsockopt(..., SO_J1939_FILTER, ...)\nmodifies jsk->filters while receiving packets.\n\nFollowing trace was seen on affected system:\n ==================================================================\n BUG: KASAN: slab-use-after-free in j1939_sk_recv_match_one+0x1af/0x2d0 [can_j1939]\n Read of size 4 at addr ffff888012144014 by task j1939/350\n\n CPU: 0 PID: 350 Comm: j1939 Tainted: G W OE 6.5.0-rc5 #1\n Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.13.0-1ubuntu1.1 04/01/2014\n Call Trace:\n print_report+0xd3/0x620\n ? kasan_complete_mode_report_info+0x7d/0x200\n ? j1939_sk_recv_match_one+0x1af/0x2d0 [can_j1939]\n kasan_report+0xc2/0x100\n ? j1939_sk_recv_match_one+0x1af/0x2d0 [can_j1939]\n __asan_load4+0x84/0xb0\n j1939_sk_recv_match_one+0x1af/0x2d0 [can_j1939]\n j1939_sk_recv+0x20b/0x320 [can_j1939]\n ? __kasan_check_write+0x18/0x20\n ? __pfx_j1939_sk_recv+0x10/0x10 [can_j1939]\n ? j1939_simple_recv+0x69/0x280 [can_j1939]\n ? j1939_ac_recv+0x5e/0x310 [can_j1939]\n j1939_can_recv+0x43f/0x580 [can_j1939]\n ? __pfx_j1939_can_recv+0x10/0x10 [can_j1939]\n ? raw_rcv+0x42/0x3c0 [can_raw]\n ? __pfx_j1939_can_recv+0x10/0x10 [can_j1939]\n can_rcv_filter+0x11f/0x350 [can]\n can_receive+0x12f/0x190 [can]\n ? __pfx_can_rcv+0x10/0x10 [can]\n can_rcv+0xdd/0x130 [can]\n ? __pfx_can_rcv+0x10/0x10 [can]\n __netif_receive_skb_one_core+0x13d/0x150\n ? __pfx___netif_receive_skb_one_core+0x10/0x10\n ? __kasan_check_write+0x18/0x20\n ? _raw_spin_lock_irq+0x8c/0xe0\n __netif_receive_skb+0x23/0xb0\n process_backlog+0x107/0x260\n __napi_poll+0x69/0x310\n net_rx_action+0x2a1/0x580\n ? __pfx_net_rx_action+0x10/0x10\n ? __pfx__raw_spin_lock+0x10/0x10\n ? handle_irq_event+0x7d/0xa0\n __do_softirq+0xf3/0x3f8\n do_softirq+0x53/0x80\n \n \n __local_bh_enable_ip+0x6e/0x70\n netif_rx+0x16b/0x180\n can_send+0x32b/0x520 [can]\n ? __pfx_can_send+0x10/0x10 [can]\n ? __check_object_size+0x299/0x410\n raw_sendmsg+0x572/0x6d0 [can_raw]\n ? __pfx_raw_sendmsg+0x10/0x10 [can_raw]\n ? apparmor_socket_sendmsg+0x2f/0x40\n ? __pfx_raw_sendmsg+0x10/0x10 [can_raw]\n sock_sendmsg+0xef/0x100\n sock_write_iter+0x162/0x220\n ? __pfx_sock_write_iter+0x10/0x10\n ? __rtnl_unlock+0x47/0x80\n ? security_file_permission+0x54/0x320\n vfs_write+0x6ba/0x750\n ? __pfx_vfs_write+0x10/0x10\n ? __fget_light+0x1ca/0x1f0\n ? __rcu_read_unlock+0x5b/0x280\n ksys_write+0x143/0x170\n ? __pfx_ksys_write+0x10/0x10\n ? __kasan_check_read+0x15/0x20\n ? fpregs_assert_state_consistent+0x62/0x70\n __x64_sys_write+0x47/0x60\n do_syscall_64+0x60/0x90\n ? do_syscall_64+0x6d/0x90\n ? irqentry_exit+0x3f/0x50\n ? exc_page_fault+0x79/0xf0\n entry_SYSCALL_64_after_hwframe+0x6e/0xd8\n\n Allocated by task 348:\n kasan_save_stack+0x2a/0x50\n kasan_set_track+0x29/0x40\n kasan_save_alloc_info+0x1f/0x30\n __kasan_kmalloc+0xb5/0xc0\n __kmalloc_node_track_caller+0x67/0x160\n j1939_sk_setsockopt+0x284/0x450 [can_j1939]\n __sys_setsockopt+0x15c/0x2f0\n __x64_sys_setsockopt+0x6b/0x80\n do_syscall_64+0x60/0x90\n entry_SYSCALL_64_after_hwframe+0x6e/0xd8\n\n Freed by task 349:\n kasan_save_stack+0x2a/0x50\n kasan_set_track+0x29/0x40\n kasan_save_free_info+0x2f/0x50\n __kasan_slab_free+0x12e/0x1c0\n __kmem_cache_free+0x1b9/0x380\n kfree+0x7a/0x120\n j1939_sk_setsockopt+0x3b2/0x450 [can_j1939]\n __sys_setsockopt+0x15c/0x2f0\n __x64_sys_setsockopt+0x6b/0x80\n do_syscall_64+0x60/0x90\n entry_SYSCALL_64_after_hwframe+0x6e/0xd8", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52637" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/08de58abedf6e69396e1207e4f99ef8904b2b532" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/41ccb5bcbf03f02d820bc6ea8390811859f558f8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4dd684d4bb3cd5454e0bf6e2a1bdfbd5c9c872ed" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/978e50ef8c38dc71bd14d1b0143d554ff5d188ba" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/efe7cf828039aedb297c1f9920b638fffee6aabc" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f84e7534457dcd7835be743517c35378bb4e7c50" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fc74b9cb789cae061bbca7b203a3842e059f6b5d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T15:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-2xw4-f54v-r826/GHSA-2xw4-f54v-r826.json b/advisories/unreviewed/2024/04/GHSA-2xw4-f54v-r826/GHSA-2xw4-f54v-r826.json new file mode 100644 index 00000000000..c8f8e9e541e --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-2xw4-f54v-r826/GHSA-2xw4-f54v-r826.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2xw4-f54v-r826", + "modified": "2024-04-03T15:30:41Z", + "published": "2024-04-03T15:30:41Z", + "aliases": [ + "CVE-2024-3257" + ], + "details": "A vulnerability was found in SourceCodester Internship Portal Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file admin/edit_activity_query.php. The manipulation of the argument title/description/start/end leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-259106 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3257" + }, + { + "type": "WEB", + "url": "https://github.com/thisissuperann/Vul/blob/main/Internship-Portal-Management-System-07" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259106" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259106" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.309218" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T13:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-3c53-5p2q-p9qm/GHSA-3c53-5p2q-p9qm.json b/advisories/unreviewed/2024/04/GHSA-3c53-5p2q-p9qm/GHSA-3c53-5p2q-p9qm.json new file mode 100644 index 00000000000..67a9d13fd67 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-3c53-5p2q-p9qm/GHSA-3c53-5p2q-p9qm.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3c53-5p2q-p9qm", + "modified": "2024-04-03T15:30:42Z", + "published": "2024-04-03T15:30:42Z", + "aliases": [ + "CVE-2024-3259" + ], + "details": "A vulnerability was found in SourceCodester Internship Portal Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file admin/delete_activity.php. The manipulation of the argument activity_id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259108.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3259" + }, + { + "type": "WEB", + "url": "https://github.com/thisissuperann/Vul/blob/main/Internship-Portal-Management-System-09" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259108" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259108" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.309220" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T14:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-3w39-v724-v74w/GHSA-3w39-v724-v74w.json b/advisories/unreviewed/2024/04/GHSA-3w39-v724-v74w/GHSA-3w39-v724-v74w.json new file mode 100644 index 00000000000..dbfa0b7e08a --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-3w39-v724-v74w/GHSA-3w39-v724-v74w.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3w39-v724-v74w", + "modified": "2024-04-03T15:30:42Z", + "published": "2024-04-03T15:30:42Z", + "aliases": [ + "CVE-2024-26693" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: iwlwifi: mvm: fix a crash when we run out of stations\n\nA DoS tool that injects loads of authentication frames made our AP\ncrash. The iwl_mvm_is_dup() function couldn't find the per-queue\ndup_data which was not allocated.\n\nThe root cause for that is that we ran out of stations in the firmware\nand we didn't really add the station to the firmware, yet we didn't\nreturn an error to mac80211.\nMac80211 was thinking that we have the station and because of that,\nsta_info::uploaded was set to 1. This allowed\nieee80211_find_sta_by_ifaddr() to return a valid station object, but\nthat ieee80211_sta didn't have any iwl_mvm_sta object initialized and\nthat caused the crash mentioned earlier when we got Rx on that station.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26693" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/00f4eb31b8193f6070ce24df636883f9c104ca95" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b7198383ef2debe748118996f627452281cf27d7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c12f0f4d4caf23b1bfdc2602b6b70d56bdcd6aa7" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T15:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-449p-2gc5-j7r3/GHSA-449p-2gc5-j7r3.json b/advisories/unreviewed/2024/04/GHSA-449p-2gc5-j7r3/GHSA-449p-2gc5-j7r3.json new file mode 100644 index 00000000000..64a5cad6530 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-449p-2gc5-j7r3/GHSA-449p-2gc5-j7r3.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-449p-2gc5-j7r3", + "modified": "2024-04-03T15:30:43Z", + "published": "2024-04-03T15:30:43Z", + "aliases": [ + "CVE-2024-26713" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\npowerpc/pseries/iommu: Fix iommu initialisation during DLPAR add\n\nWhen a PCI device is dynamically added, the kernel oopses with a NULL\npointer dereference:\n\n BUG: Kernel NULL pointer dereference on read at 0x00000030\n Faulting instruction address: 0xc0000000006bbe5c\n Oops: Kernel access of bad area, sig: 11 [#1]\n LE PAGE_SIZE=64K MMU=Radix SMP NR_CPUS=2048 NUMA pSeries\n Modules linked in: rpadlpar_io rpaphp rpcsec_gss_krb5 auth_rpcgss nfsv4 dns_resolver nfs lockd grace fscache netfs xsk_diag bonding nft_compat nf_tables nfnetlink rfkill binfmt_misc dm_multipath rpcrdma sunrpc rdma_ucm ib_srpt ib_isert iscsi_target_mod target_core_mod ib_umad ib_iser libiscsi scsi_transport_iscsi ib_ipoib rdma_cm iw_cm ib_cm mlx5_ib ib_uverbs ib_core pseries_rng drm drm_panel_orientation_quirks xfs libcrc32c mlx5_core mlxfw sd_mod t10_pi sg tls ibmvscsi ibmveth scsi_transport_srp vmx_crypto pseries_wdt psample dm_mirror dm_region_hash dm_log dm_mod fuse\n CPU: 17 PID: 2685 Comm: drmgr Not tainted 6.7.0-203405+ #66\n Hardware name: IBM,9080-HEX POWER10 (raw) 0x800200 0xf000006 of:IBM,FW1060.00 (NH1060_008) hv:phyp pSeries\n NIP: c0000000006bbe5c LR: c000000000a13e68 CTR: c0000000000579f8\n REGS: c00000009924f240 TRAP: 0300 Not tainted (6.7.0-203405+)\n MSR: 8000000000009033 CR: 24002220 XER: 20040006\n CFAR: c000000000a13e64 DAR: 0000000000000030 DSISR: 40000000 IRQMASK: 0\n ...\n NIP sysfs_add_link_to_group+0x34/0x94\n LR iommu_device_link+0x5c/0x118\n Call Trace:\n iommu_init_device+0x26c/0x318 (unreliable)\n iommu_device_link+0x5c/0x118\n iommu_init_device+0xa8/0x318\n iommu_probe_device+0xc0/0x134\n iommu_bus_notifier+0x44/0x104\n notifier_call_chain+0xb8/0x19c\n blocking_notifier_call_chain+0x64/0x98\n bus_notify+0x50/0x7c\n device_add+0x640/0x918\n pci_device_add+0x23c/0x298\n of_create_pci_dev+0x400/0x884\n of_scan_pci_dev+0x124/0x1b0\n __of_scan_bus+0x78/0x18c\n pcibios_scan_phb+0x2a4/0x3b0\n init_phb_dynamic+0xb8/0x110\n dlpar_add_slot+0x170/0x3b8 [rpadlpar_io]\n add_slot_store.part.0+0xb4/0x130 [rpadlpar_io]\n kobj_attr_store+0x2c/0x48\n sysfs_kf_write+0x64/0x78\n kernfs_fop_write_iter+0x1b0/0x290\n vfs_write+0x350/0x4a0\n ksys_write+0x84/0x140\n system_call_exception+0x124/0x330\n system_call_vectored_common+0x15c/0x2ec\n\nCommit a940904443e4 (\"powerpc/iommu: Add iommu_ops to report capabilities\nand allow blocking domains\") broke DLPAR add of PCI devices.\n\nThe above added iommu_device structure to pci_controller. During\nsystem boot, PCI devices are discovered and this newly added iommu_device\nstructure is initialized by a call to iommu_device_register().\n\nDuring DLPAR add of a PCI device, a new pci_controller structure is\nallocated but there are no calls made to iommu_device_register()\ninterface.\n\nFix is to register the iommu device during DLPAR add as well.\n\n[mpe: Trim oops and tweak some change log wording]", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26713" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9978d5b744e0227afe19e3bcb4c5f75442dde753" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d4f762d6403f7419de90d7749fa83dd92ffb0e1d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ed8b94f6e0acd652ce69bd69d678a0c769172df8" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T15:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-4fj7-85cf-9m8p/GHSA-4fj7-85cf-9m8p.json b/advisories/unreviewed/2024/04/GHSA-4fj7-85cf-9m8p/GHSA-4fj7-85cf-9m8p.json new file mode 100644 index 00000000000..d5837d73418 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-4fj7-85cf-9m8p/GHSA-4fj7-85cf-9m8p.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4fj7-85cf-9m8p", + "modified": "2024-04-03T15:30:43Z", + "published": "2024-04-03T15:30:43Z", + "aliases": [ + "CVE-2024-26706" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nparisc: Fix random data corruption from exception handler\n\nThe current exception handler implementation, which assists when accessing\nuser space memory, may exhibit random data corruption if the compiler decides\nto use a different register than the specified register %r29 (defined in\nASM_EXCEPTIONTABLE_REG) for the error code. If the compiler choose another\nregister, the fault handler will nevertheless store -EFAULT into %r29 and thus\ntrash whatever this register is used for.\nLooking at the assembly I found that this happens sometimes in emulate_ldd().\n\nTo solve the issue, the easiest solution would be if it somehow is\npossible to tell the fault handler which register is used to hold the error\ncode. Using %0 or %1 in the inline assembly is not posssible as it will show\nup as e.g. %r29 (with the \"%r\" prefix), which the GNU assembler can not\nconvert to an integer.\n\nThis patch takes another, better and more flexible approach:\nWe extend the __ex_table (which is out of the execution path) by one 32-word.\nIn this word we tell the compiler to insert the assembler instruction\n\"or %r0,%r0,%reg\", where %reg references the register which the compiler\nchoosed for the error return code.\nIn case of an access failure, the fault handler finds the __ex_table entry and\ncan examine the opcode. The used register is encoded in the lowest 5 bits, and\nthe fault handler can then store -EFAULT into this register.\n\nSince we extend the __ex_table to 3 words we can't use the BUILDTIME_TABLE_SORT\nconfig option any longer.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26706" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/23027309b099ffc4efca5477009a11dccbdae592" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8b1d72395635af45410b66cc4c4ab37a12c4a831" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ce31d79aa1f13a2345791f84935281a2c194e003" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fa69a8063f8b27f3c7434a0d4f464a76a62f24d2" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T15:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-4vrw-qvhf-f547/GHSA-4vrw-qvhf-f547.json b/advisories/unreviewed/2024/04/GHSA-4vrw-qvhf-f547/GHSA-4vrw-qvhf-f547.json new file mode 100644 index 00000000000..cbd1702c096 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-4vrw-qvhf-f547/GHSA-4vrw-qvhf-f547.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4vrw-qvhf-f547", + "modified": "2024-04-03T15:30:41Z", + "published": "2024-04-03T15:30:41Z", + "aliases": [ + "CVE-2024-25046" + ], + "details": "IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to a denial of service by an authenticated user using a specially crafted query. IBM X-Force ID: 282953.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25046" + }, + { + "type": "WEB", + "url": "https://https://exchange.xforce.ibmcloud.com/vulnerabilities/282953" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7145726" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T13:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-5c46-ggmc-6j5m/GHSA-5c46-ggmc-6j5m.json b/advisories/unreviewed/2024/04/GHSA-5c46-ggmc-6j5m/GHSA-5c46-ggmc-6j5m.json new file mode 100644 index 00000000000..5d17d736311 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-5c46-ggmc-6j5m/GHSA-5c46-ggmc-6j5m.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5c46-ggmc-6j5m", + "modified": "2024-04-03T15:30:42Z", + "published": "2024-04-03T15:30:42Z", + "aliases": [ + "CVE-2024-26690" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: stmmac: protect updates of 64-bit statistics counters\n\nAs explained by a comment in , write side of struct\nu64_stats_sync must ensure mutual exclusion, or one seqcount update could\nbe lost on 32-bit platforms, thus blocking readers forever. Such lockups\nhave been observed in real world after stmmac_xmit() on one CPU raced with\nstmmac_napi_poll_tx() on another CPU.\n\nTo fix the issue without introducing a new lock, split the statics into\nthree parts:\n\n1. fields updated only under the tx queue lock,\n2. fields updated only during NAPI poll,\n3. fields updated only from interrupt context,\n\nUpdates to fields in the first two groups are already serialized through\nother locks. It is sufficient to split the existing struct u64_stats_sync\nso that each group has its own.\n\nNote that tx_set_ic_bit is updated from both contexts. Split this counter\nso that each context gets its own, and calculate their sum to get the total\nvalue in stmmac_get_ethtool_stats().\n\nFor the third group, multiple interrupts may be processed by different CPUs\nat the same time, but interrupts on the same CPU will not nest. Move fields\nfrom this group to a newly created per-cpu struct stmmac_pcpu_stats.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26690" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/38cc3c6dcc09dc3a1800b5ec22aef643ca11eab8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9680b2ab54ba8d72581100e8c45471306101836e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e6af0f082a4b87b99ad033003be2a904a1791b3f" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T15:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-5fg3-793p-9qxp/GHSA-5fg3-793p-9qxp.json b/advisories/unreviewed/2024/04/GHSA-5fg3-793p-9qxp/GHSA-5fg3-793p-9qxp.json new file mode 100644 index 00000000000..34afe3ab734 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-5fg3-793p-9qxp/GHSA-5fg3-793p-9qxp.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5fg3-793p-9qxp", + "modified": "2024-04-03T15:30:41Z", + "published": "2024-04-03T15:30:41Z", + "aliases": [ + "CVE-2024-30571" + ], + "details": "An information leak in the BRS_top.html component of Netgear R6850 v1.1.0.88 allows attackers to obtain sensitive information without any authentication required.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30571" + }, + { + "type": "WEB", + "url": "https://github.com/funny-mud-peee/IoT-vuls/blob/main/netgear%20R6850/Info%20Leak%20in%20Netgear-R6850%EF%BC%88BRS_top.html%EF%BC%89.md" + }, + { + "type": "WEB", + "url": "https://www.netgear.com/about/security" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T13:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-5q37-x55w-w66j/GHSA-5q37-x55w-w66j.json b/advisories/unreviewed/2024/04/GHSA-5q37-x55w-w66j/GHSA-5q37-x55w-w66j.json new file mode 100644 index 00000000000..551999bc5f9 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-5q37-x55w-w66j/GHSA-5q37-x55w-w66j.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5q37-x55w-w66j", + "modified": "2024-04-03T15:30:41Z", + "published": "2024-04-03T15:30:41Z", + "aliases": [ + "CVE-2024-0394" + ], + "details": "Rapid7 Minerva Armor versions below 4.5.5 suffer from a privilege escalation vulnerability whereby an authenticated attacker can elevate privileges and execute arbitrary code with SYSTEM privilege.  The vulnerability is caused by the product's implementation of OpenSSL's`OPENSSLDIR` parameter where it is set to a path accessible to low-privileged users.  The vulnerability has been remediated and fixed in version 4.5.5. \n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0394" + }, + { + "type": "WEB", + "url": "https://www.rapid7.com/blog/post/2024/04/03/cve-2024-0394-rapid7-minerva-armor-privilege-escalation-fixed" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T14:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-5qvv-jjxx-82r8/GHSA-5qvv-jjxx-82r8.json b/advisories/unreviewed/2024/04/GHSA-5qvv-jjxx-82r8/GHSA-5qvv-jjxx-82r8.json new file mode 100644 index 00000000000..49395b5ba89 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-5qvv-jjxx-82r8/GHSA-5qvv-jjxx-82r8.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5qvv-jjxx-82r8", + "modified": "2024-04-03T15:30:43Z", + "published": "2024-04-03T15:30:43Z", + "aliases": [ + "CVE-2024-26718" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndm-crypt, dm-verity: disable tasklets\n\nTasklets have an inherent problem with memory corruption. The function\ntasklet_action_common calls tasklet_trylock, then it calls the tasklet\ncallback and then it calls tasklet_unlock. If the tasklet callback frees\nthe structure that contains the tasklet or if it calls some code that may\nfree it, tasklet_unlock will write into free memory.\n\nThe commits 8e14f610159d and d9a02e016aaf try to fix it for dm-crypt, but\nit is not a sufficient fix and the data corruption can still happen [1].\nThere is no fix for dm-verity and dm-verity will write into free memory\nwith every tasklet-processed bio.\n\nThere will be atomic workqueues implemented in the kernel 6.9 [2]. They\nwill have better interface and they will not suffer from the memory\ncorruption problem.\n\nBut we need something that stops the memory corruption now and that can be\nbackported to the stable kernels. So, I'm proposing this commit that\ndisables tasklets in both dm-crypt and dm-verity. This commit doesn't\nremove the tasklet support, because the tasklet code will be reused when\natomic workqueues will be implemented.\n\n[1] https://lore.kernel.org/all/d390d7ee-f142-44d3-822a-87949e14608b@suse.de/T/\n[2] https://lore.kernel.org/lkml/20240130091300.2968534-1-tj@kernel.org/", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26718" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0a9bab391e336489169b95cb0d4553d921302189" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0c45a20cbe68bc4d681734f5c03891124a274257" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/30884a44e0cedc3dfda8c22432f3ba4078ec2d94" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5735a2671ffb70ea29ca83969fe01316ee2ed6fc" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T15:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-5rcw-5rq5-g5x2/GHSA-5rcw-5rq5-g5x2.json b/advisories/unreviewed/2024/04/GHSA-5rcw-5rq5-g5x2/GHSA-5rcw-5rq5-g5x2.json new file mode 100644 index 00000000000..6bc00eabc64 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-5rcw-5rq5-g5x2/GHSA-5rcw-5rq5-g5x2.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5rcw-5rq5-g5x2", + "modified": "2024-04-03T15:30:41Z", + "published": "2024-04-03T15:30:41Z", + "aliases": [ + "CVE-2024-25096" + ], + "details": "Improper Control of Generation of Code ('Code Injection') vulnerability in Canto Inc. Canto allows Code Injection.This issue affects Canto: from n/a through 3.0.7.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25096" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/canto/wordpress-canto-plugin-3-0-6-unauthenticated-remote-code-execution-rce-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T13:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-68q2-g7rv-mr2f/GHSA-68q2-g7rv-mr2f.json b/advisories/unreviewed/2024/04/GHSA-68q2-g7rv-mr2f/GHSA-68q2-g7rv-mr2f.json new file mode 100644 index 00000000000..fb010108147 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-68q2-g7rv-mr2f/GHSA-68q2-g7rv-mr2f.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-68q2-g7rv-mr2f", + "modified": "2024-04-03T15:30:43Z", + "published": "2024-04-03T15:30:43Z", + "aliases": [ + "CVE-2024-26723" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nlan966x: Fix crash when adding interface under a lag\n\nThere is a crash when adding one of the lan966x interfaces under a lag\ninterface. The issue can be reproduced like this:\nip link add name bond0 type bond miimon 100 mode balance-xor\nip link set dev eth0 master bond0\n\nThe reason is because when adding a interface under the lag it would go\nthrough all the ports and try to figure out which other ports are under\nthat lag interface. And the issue is that lan966x can have ports that are\nNULL pointer as they are not probed. So then iterating over these ports\nit would just crash as they are NULL pointers.\nThe fix consists in actually checking for NULL pointers before accessing\nsomething from the ports. Like we do in other places.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26723" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/15faa1f67ab405d47789d4702f587ec7df7ef03e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2a492f01228b7d091dfe38974ef40dccf8f9f2f1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/48fae67d837488c87379f0c9f27df7391718477c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b9357489c46c7a43999964628db8b47d3a1f8672" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T15:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-6m7r-j2xg-cvhq/GHSA-6m7r-j2xg-cvhq.json b/advisories/unreviewed/2024/04/GHSA-6m7r-j2xg-cvhq/GHSA-6m7r-j2xg-cvhq.json new file mode 100644 index 00000000000..197f89bc6de --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-6m7r-j2xg-cvhq/GHSA-6m7r-j2xg-cvhq.json @@ -0,0 +1,63 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6m7r-j2xg-cvhq", + "modified": "2024-04-03T15:30:43Z", + "published": "2024-04-03T15:30:43Z", + "aliases": [ + "CVE-2024-26704" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\next4: fix double-free of blocks due to wrong extents moved_len\n\nIn ext4_move_extents(), moved_len is only updated when all moves are\nsuccessfully executed, and only discards orig_inode and donor_inode\npreallocations when moved_len is not zero. When the loop fails to exit\nafter successfully moving some extents, moved_len is not updated and\nremains at 0, so it does not discard the preallocations.\n\nIf the moved extents overlap with the preallocated extents, the\noverlapped extents are freed twice in ext4_mb_release_inode_pa() and\next4_process_freed_data() (as described in commit 94d7c16cbbbd (\"ext4:\nFix double-free of blocks with EXT4_IOC_MOVE_EXT\")), and bb_free is\nincremented twice. Hence when trim is executed, a zero-division bug is\ntriggered in mb_update_avg_fragment_size() because bb_free is not zero\nand bb_fragments is zero.\n\nTherefore, update move_len after each extent move to avoid the issue.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26704" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/185eab30486ba3e7bf8b9c2e049c79a06ffd2bc1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2883940b19c38d5884c8626483811acf4d7e148f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/55583e899a5357308274601364741a83e78d6ac4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/559ddacb90da1d8786dd8ec4fd76bbfa404eaef6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/afba9d11320dad5ce222ac8964caf64b7b4bedb1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/afbcad9ae7d6d11608399188f03a837451b6b3a1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b4fbb89d722cbb16beaaea234b7230faaaf68c71" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d033a555d9a1cf53dbf3301af7199cc4a4c8f537" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T15:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-6qgw-mcc6-7rxw/GHSA-6qgw-mcc6-7rxw.json b/advisories/unreviewed/2024/04/GHSA-6qgw-mcc6-7rxw/GHSA-6qgw-mcc6-7rxw.json new file mode 100644 index 00000000000..86ccf73514e --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-6qgw-mcc6-7rxw/GHSA-6qgw-mcc6-7rxw.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6qgw-mcc6-7rxw", + "modified": "2024-04-03T15:30:44Z", + "published": "2024-04-03T15:30:44Z", + "aliases": [ + "CVE-2024-28275" + ], + "details": "Puwell Cloud Tech Co, Ltd 360Eyes Pro v3.9.5.16(3090516) was discovered to transmit sensitive information in cleartext. This vulnerability allows attackers to intercept and access sensitive information, including users' credentials and password change requests.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28275" + }, + { + "type": "WEB", + "url": "https://paste.sr.ht/~edaigle/0b4a037fbd3166c8c72fee18efaa7decaf75b0ab" + }, + { + "type": "WEB", + "url": "https://paste.sr.ht/~edaigle/c9637d682b65e6501efb1324bba7787a2f775ff4" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T15:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-6rc6-fqrr-7x25/GHSA-6rc6-fqrr-7x25.json b/advisories/unreviewed/2024/04/GHSA-6rc6-fqrr-7x25/GHSA-6rc6-fqrr-7x25.json new file mode 100644 index 00000000000..e3d268a0a89 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-6rc6-fqrr-7x25/GHSA-6rc6-fqrr-7x25.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6rc6-fqrr-7x25", + "modified": "2024-04-03T15:30:41Z", + "published": "2024-04-03T15:30:41Z", + "aliases": [ + "CVE-2024-27201" + ], + "details": "An improper input validation vulnerability exists in the OAS Engine User Configuration functionality of Open Automation Software OAS Platform V19.00.0057. A specially crafted series of network requests can lead to unexpected data in the configuration. An attacker can send a sequence of requests to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27201" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-1949" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-1949" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T14:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-6x84-2fmj-5fc8/GHSA-6x84-2fmj-5fc8.json b/advisories/unreviewed/2024/04/GHSA-6x84-2fmj-5fc8/GHSA-6x84-2fmj-5fc8.json new file mode 100644 index 00000000000..248bf7af492 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-6x84-2fmj-5fc8/GHSA-6x84-2fmj-5fc8.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6x84-2fmj-5fc8", + "modified": "2024-04-03T15:30:41Z", + "published": "2024-04-03T15:30:41Z", + "aliases": [ + "CVE-2024-3256" + ], + "details": "A vulnerability has been found in SourceCodester Internship Portal Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file admin/edit_activity.php. The manipulation of the argument activity_id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-259105 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3256" + }, + { + "type": "WEB", + "url": "https://github.com/thisissuperann/Vul/blob/main/Internship-Portal-Management-System-06" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259105" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259105" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.309217" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T13:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-78j7-xmw6-68gr/GHSA-78j7-xmw6-68gr.json b/advisories/unreviewed/2024/04/GHSA-78j7-xmw6-68gr/GHSA-78j7-xmw6-68gr.json new file mode 100644 index 00000000000..898ace29414 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-78j7-xmw6-68gr/GHSA-78j7-xmw6-68gr.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-78j7-xmw6-68gr", + "modified": "2024-04-03T15:30:43Z", + "published": "2024-04-03T15:30:43Z", + "aliases": [ + "CVE-2024-26716" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: core: Prevent null pointer dereference in update_port_device_state\n\nCurrently, the function update_port_device_state gets the usb_hub from\nudev->parent by calling usb_hub_to_struct_hub.\nHowever, in case the actconfig or the maxchild is 0, the usb_hub would\nbe NULL and upon further accessing to get port_dev would result in null\npointer dereference.\n\nFix this by introducing an if check after the usb_hub is populated.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26716" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/12783c0b9e2c7915a50d5ec829630ff2da50472c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/465b545d1d7ef282192ddd4439b08279bdb13f6f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ed85777c640cf9e6920bb1b60ed8cd48e1f4d873" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T15:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-798v-p58f-mw7j/GHSA-798v-p58f-mw7j.json b/advisories/unreviewed/2024/04/GHSA-798v-p58f-mw7j/GHSA-798v-p58f-mw7j.json new file mode 100644 index 00000000000..261ce346e98 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-798v-p58f-mw7j/GHSA-798v-p58f-mw7j.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-798v-p58f-mw7j", + "modified": "2024-04-03T15:30:43Z", + "published": "2024-04-03T15:30:43Z", + "aliases": [ + "CVE-2024-26726" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: don't drop extent_map for free space inode on write error\n\nWhile running the CI for an unrelated change I hit the following panic\nwith generic/648 on btrfs_holes_spacecache.\n\nassertion failed: block_start != EXTENT_MAP_HOLE, in fs/btrfs/extent_io.c:1385\n------------[ cut here ]------------\nkernel BUG at fs/btrfs/extent_io.c:1385!\ninvalid opcode: 0000 [#1] PREEMPT SMP NOPTI\nCPU: 1 PID: 2695096 Comm: fsstress Kdump: loaded Tainted: G W 6.8.0-rc2+ #1\nRIP: 0010:__extent_writepage_io.constprop.0+0x4c1/0x5c0\nCall Trace:\n \n extent_write_cache_pages+0x2ac/0x8f0\n extent_writepages+0x87/0x110\n do_writepages+0xd5/0x1f0\n filemap_fdatawrite_wbc+0x63/0x90\n __filemap_fdatawrite_range+0x5c/0x80\n btrfs_fdatawrite_range+0x1f/0x50\n btrfs_write_out_cache+0x507/0x560\n btrfs_write_dirty_block_groups+0x32a/0x420\n commit_cowonly_roots+0x21b/0x290\n btrfs_commit_transaction+0x813/0x1360\n btrfs_sync_file+0x51a/0x640\n __x64_sys_fdatasync+0x52/0x90\n do_syscall_64+0x9c/0x190\n entry_SYSCALL_64_after_hwframe+0x6e/0x76\n\nThis happens because we fail to write out the free space cache in one\ninstance, come back around and attempt to write it again. However on\nthe second pass through we go to call btrfs_get_extent() on the inode to\nget the extent mapping. Because this is a new block group, and with the\nfree space inode we always search the commit root to avoid deadlocking\nwith the tree, we find nothing and return a EXTENT_MAP_HOLE for the\nrequested range.\n\nThis happens because the first time we try to write the space cache out\nwe hit an error, and on an error we drop the extent mapping. This is\nnormal for normal files, but the free space cache inode is special. We\nalways expect the extent map to be correct. Thus the second time\nthrough we end up with a bogus extent map.\n\nSince we're deprecating this feature, the most straightforward way to\nfix this is to simply skip dropping the extent map range for this failed\nrange.\n\nI shortened the test by using error injection to stress the area to make\nit easier to reproduce. With this patch in place we no longer panic\nwith my error injection test.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26726" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/02f2b95b00bf57d20320ee168b30fb7f3db8e555" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5571e41ec6e56e35f34ae9f5b3a335ef510e0ade" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7bddf18f474f166c19f91b2baf67bf7c5eda03f7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a4b7741c8302e28073bfc6dd1c2e73598e5e535e" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T15:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-7g56-3wmh-7x3p/GHSA-7g56-3wmh-7x3p.json b/advisories/unreviewed/2024/04/GHSA-7g56-3wmh-7x3p/GHSA-7g56-3wmh-7x3p.json new file mode 100644 index 00000000000..048767592f1 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-7g56-3wmh-7x3p/GHSA-7g56-3wmh-7x3p.json @@ -0,0 +1,55 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7g56-3wmh-7x3p", + "modified": "2024-04-03T15:30:42Z", + "published": "2024-04-03T15:30:42Z", + "aliases": [ + "CVE-2024-26698" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nhv_netvsc: Fix race condition between netvsc_probe and netvsc_remove\n\nIn commit ac5047671758 (\"hv_netvsc: Disable NAPI before closing the\nVMBus channel\"), napi_disable was getting called for all channels,\nincluding all subchannels without confirming if they are enabled or not.\n\nThis caused hv_netvsc getting hung at napi_disable, when netvsc_probe()\nhas finished running but nvdev->subchan_work has not started yet.\nnetvsc_subchan_work() -> rndis_set_subchannel() has not created the\nsub-channels and because of that netvsc_sc_open() is not running.\nnetvsc_remove() calls cancel_work_sync(&nvdev->subchan_work), for which\nnetvsc_subchan_work did not run.\n\nnetif_napi_add() sets the bit NAPI_STATE_SCHED because it ensures NAPI\ncannot be scheduled. Then netvsc_sc_open() -> napi_enable will clear the\nNAPIF_STATE_SCHED bit, so it can be scheduled. napi_disable() does the\nopposite.\n\nNow during netvsc_device_remove(), when napi_disable is called for those\nsubchannels, napi_disable gets stuck on infinite msleep.\n\nThis fix addresses this problem by ensuring that napi_disable() is not\ngetting called for non-enabled NAPI struct.\nBut netif_napi_del() is still necessary for these non-enabled NAPI struct\nfor cleanup purpose.\n\nCall trace:\n[ 654.559417] task:modprobe state:D stack: 0 pid: 2321 ppid: 1091 flags:0x00004002\n[ 654.568030] Call Trace:\n[ 654.571221] \n[ 654.573790] __schedule+0x2d6/0x960\n[ 654.577733] schedule+0x69/0xf0\n[ 654.581214] schedule_timeout+0x87/0x140\n[ 654.585463] ? __bpf_trace_tick_stop+0x20/0x20\n[ 654.590291] msleep+0x2d/0x40\n[ 654.593625] napi_disable+0x2b/0x80\n[ 654.597437] netvsc_device_remove+0x8a/0x1f0 [hv_netvsc]\n[ 654.603935] rndis_filter_device_remove+0x194/0x1c0 [hv_netvsc]\n[ 654.611101] ? do_wait_intr+0xb0/0xb0\n[ 654.615753] netvsc_remove+0x7c/0x120 [hv_netvsc]\n[ 654.621675] vmbus_remove+0x27/0x40 [hv_vmbus]", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26698" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0e8875de9dad12805ff66e92cd5edea6a421f1cd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/22a77c0f5b8233237731df3288d067af51a2fd7b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/48a8ccccffbae10c91d31fc872db5c31aba07518" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7656372ae190e54e8c8cf1039725a5ea59fdf84a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9ec807e7b6f5fcf9499f3baa69f254bb239a847f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e0526ec5360a48ad3ab2e26e802b0532302a7e11" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T15:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-7pq6-8v5c-6wmr/GHSA-7pq6-8v5c-6wmr.json b/advisories/unreviewed/2024/04/GHSA-7pq6-8v5c-6wmr/GHSA-7pq6-8v5c-6wmr.json index 1d0902e4b1b..2cc75e01390 100644 --- a/advisories/unreviewed/2024/04/GHSA-7pq6-8v5c-6wmr/GHSA-7pq6-8v5c-6wmr.json +++ b/advisories/unreviewed/2024/04/GHSA-7pq6-8v5c-6wmr/GHSA-7pq6-8v5c-6wmr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7pq6-8v5c-6wmr", - "modified": "2024-04-01T09:30:31Z", + "modified": "2024-04-03T15:30:41Z", "published": "2024-04-01T09:30:31Z", "aliases": [ "CVE-2024-26653" @@ -18,9 +18,17 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26653" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/420babea4f1881a7c4ea22a8e218b8c6895d3f21" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/7c9631969287a5366bc8e39cd5abff154b35fb80" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8a9f653cc852677003c23ee8075e3ed8fb4743c9" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/04/GHSA-7r36-7f54-54ff/GHSA-7r36-7f54-54ff.json b/advisories/unreviewed/2024/04/GHSA-7r36-7f54-54ff/GHSA-7r36-7f54-54ff.json new file mode 100644 index 00000000000..920fb4e7989 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-7r36-7f54-54ff/GHSA-7r36-7f54-54ff.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7r36-7f54-54ff", + "modified": "2024-04-03T15:30:41Z", + "published": "2024-04-03T15:30:41Z", + "aliases": [ + "CVE-2024-30572" + ], + "details": "Netgear R6850 1.1.0.88 was discovered to contain a command injection vulnerability via the ntp_server parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30572" + }, + { + "type": "WEB", + "url": "https://github.com/funny-mud-peee/IoT-vuls/blob/main/netgear%20R6850/Netgear-R6850%20V1.1.0.88%20Command%20Injection%28ntp_server%29.md" + }, + { + "type": "WEB", + "url": "https://www.netgear.com/about/security" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T13:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-7xq6-jm62-ww8g/GHSA-7xq6-jm62-ww8g.json b/advisories/unreviewed/2024/04/GHSA-7xq6-jm62-ww8g/GHSA-7xq6-jm62-ww8g.json new file mode 100644 index 00000000000..e54f6f80568 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-7xq6-jm62-ww8g/GHSA-7xq6-jm62-ww8g.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7xq6-jm62-ww8g", + "modified": "2024-04-03T15:30:42Z", + "published": "2024-04-03T15:30:42Z", + "aliases": [ + "CVE-2024-26687" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nxen/events: close evtchn after mapping cleanup\n\nshutdown_pirq and startup_pirq are not taking the\nirq_mapping_update_lock because they can't due to lock inversion. Both\nare called with the irq_desc->lock being taking. The lock order,\nhowever, is first irq_mapping_update_lock and then irq_desc->lock.\n\nThis opens multiple races:\n- shutdown_pirq can be interrupted by a function that allocates an event\n channel:\n\n CPU0 CPU1\n shutdown_pirq {\n xen_evtchn_close(e)\n __startup_pirq {\n EVTCHNOP_bind_pirq\n -> returns just freed evtchn e\n set_evtchn_to_irq(e, irq)\n }\n xen_irq_info_cleanup() {\n set_evtchn_to_irq(e, -1)\n }\n }\n\n Assume here event channel e refers here to the same event channel\n number.\n After this race the evtchn_to_irq mapping for e is invalid (-1).\n\n- __startup_pirq races with __unbind_from_irq in a similar way. Because\n __startup_pirq doesn't take irq_mapping_update_lock it can grab the\n evtchn that __unbind_from_irq is currently freeing and cleaning up. In\n this case even though the event channel is allocated, its mapping can\n be unset in evtchn_to_irq.\n\nThe fix is to first cleanup the mappings and then close the event\nchannel. In this way, when an event channel gets allocated it's\npotential previous evtchn_to_irq mappings are guaranteed to be unset already.\nThis is also the reverse order of the allocation where first the event\nchannel is allocated and then the mappings are setup.\n\nOn a 5.10 kernel prior to commit 3fcdaf3d7634 (\"xen/events: modify internal\n[un]bind interfaces\"), we hit a BUG like the following during probing of NVMe\ndevices. The issue is that during nvme_setup_io_queues, pci_free_irq\nis called for every device which results in a call to shutdown_pirq.\nWith many nvme devices it's therefore likely to hit this race during\nboot because there will be multiple calls to shutdown_pirq and\nstartup_pirq are running potentially in parallel.\n\n ------------[ cut here ]------------\n blkfront: xvda: barrier or flush: disabled; persistent grants: enabled; indirect descriptors: enabled; bounce buffer: enabled\n kernel BUG at drivers/xen/events/events_base.c:499!\n invalid opcode: 0000 [#1] SMP PTI\n CPU: 44 PID: 375 Comm: kworker/u257:23 Not tainted 5.10.201-191.748.amzn2.x86_64 #1\n Hardware name: Xen HVM domU, BIOS 4.11.amazon 08/24/2006\n Workqueue: nvme-reset-wq nvme_reset_work\n RIP: 0010:bind_evtchn_to_cpu+0xdf/0xf0\n Code: 5d 41 5e c3 cc cc cc cc 44 89 f7 e8 2b 55 ad ff 49 89 c5 48 85 c0 0f 84 64 ff ff ff 4c 8b 68 30 41 83 fe ff 0f 85 60 ff ff ff <0f> 0b 66 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 0f 1f 44 00 00\n RSP: 0000:ffffc9000d533b08 EFLAGS: 00010046\n RAX: 0000000000000000 RBX: 0000000000000000 RCX: 0000000000000006\n RDX: 0000000000000028 RSI: 00000000ffffffff RDI: 00000000ffffffff\n RBP: ffff888107419680 R08: 0000000000000000 R09: ffffffff82d72b00\n R10: 0000000000000000 R11: 0000000000000000 R12: 00000000000001ed\n R13: 0000000000000000 R14: 00000000ffffffff R15: 0000000000000002\n FS: 0000000000000000(0000) GS:ffff88bc8b500000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 0000000000000000 CR3: 0000000002610001 CR4: 00000000001706e0\n DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n Call Trace:\n ? show_trace_log_lvl+0x1c1/0x2d9\n ? show_trace_log_lvl+0x1c1/0x2d9\n ? set_affinity_irq+0xdc/0x1c0\n ? __die_body.cold+0x8/0xd\n ? die+0x2b/0x50\n ? do_trap+0x90/0x110\n ? bind_evtchn_to_cpu+0xdf/0xf0\n ? do_error_trap+0x65/0x80\n ? bind_evtchn_to_cpu+0xdf/0xf0\n ? exc_invalid_op+0x4e/0x70\n ? bind_evtchn_to_cpu+0xdf/0xf0\n ? asm_exc_invalid_op+0x12/0x20\n ? bind_evtchn_to_cpu+0xdf/0x\n---truncated---", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26687" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/20980195ec8d2e41653800c45c8c367fa1b1f2b4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/585a344af6bcac222608a158fc2830ff02712af5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9be71aa12afa91dfe457b3fb4a444c42b1ee036b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fa765c4b4aed2d64266b694520ecb025c862c5a9" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T15:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-82mq-c3x3-cpp9/GHSA-82mq-c3x3-cpp9.json b/advisories/unreviewed/2024/04/GHSA-82mq-c3x3-cpp9/GHSA-82mq-c3x3-cpp9.json new file mode 100644 index 00000000000..43011eb1678 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-82mq-c3x3-cpp9/GHSA-82mq-c3x3-cpp9.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-82mq-c3x3-cpp9", + "modified": "2024-04-03T15:30:42Z", + "published": "2024-04-03T15:30:42Z", + "aliases": [ + "CVE-2023-52639" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: s390: vsie: fix race during shadow creation\n\nRight now it is possible to see gmap->private being zero in\nkvm_s390_vsie_gmap_notifier resulting in a crash. This is due to the\nfact that we add gmap->private == kvm after creation:\n\nstatic int acquire_gmap_shadow(struct kvm_vcpu *vcpu,\n struct vsie_page *vsie_page)\n{\n[...]\n gmap = gmap_shadow(vcpu->arch.gmap, asce, edat);\n if (IS_ERR(gmap))\n return PTR_ERR(gmap);\n gmap->private = vcpu->kvm;\n\nLet children inherit the private field of the parent.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52639" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/28bb27824f25f36e5f80229a358d66ee09244082" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5df3b81a567eb565029563f26f374ae3803a1dfc" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f5572c0323cf8b4f1f0618178648a25b8fb8a380" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fe752331d4b361d43cfd0b89534b4b2176057c32" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T15:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-8vch-c6pw-5chh/GHSA-8vch-c6pw-5chh.json b/advisories/unreviewed/2024/04/GHSA-8vch-c6pw-5chh/GHSA-8vch-c6pw-5chh.json new file mode 100644 index 00000000000..e1ac8596a07 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-8vch-c6pw-5chh/GHSA-8vch-c6pw-5chh.json @@ -0,0 +1,55 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8vch-c6pw-5chh", + "modified": "2024-04-03T15:30:43Z", + "published": "2024-04-03T15:30:43Z", + "aliases": [ + "CVE-2024-26712" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\npowerpc/kasan: Fix addr error caused by page alignment\n\nIn kasan_init_region, when k_start is not page aligned, at the begin of\nfor loop, k_cur = k_start & PAGE_MASK is less than k_start, and then\n`va = block + k_cur - k_start` is less than block, the addr va is invalid,\nbecause the memory address space from va to block is not alloced by\nmemblock_alloc, which will not be reserved by memblock_reserve later, it\nwill be used by other places.\n\nAs a result, memory overwriting occurs.\n\nfor example:\nint __init __weak kasan_init_region(void *start, size_t size)\n{\n[...]\n\t/* if say block(dcd97000) k_start(feef7400) k_end(feeff3fe) */\n\tblock = memblock_alloc(k_end - k_start, PAGE_SIZE);\n\t[...]\n\tfor (k_cur = k_start & PAGE_MASK; k_cur < k_end; k_cur += PAGE_SIZE) {\n\t\t/* at the begin of for loop\n\t\t * block(dcd97000) va(dcd96c00) k_cur(feef7000) k_start(feef7400)\n\t\t * va(dcd96c00) is less than block(dcd97000), va is invalid\n\t\t */\n\t\tvoid *va = block + k_cur - k_start;\n\t\t[...]\n\t}\n[...]\n}\n\nTherefore, page alignment is performed on k_start before\nmemblock_alloc() to ensure the validity of the VA address.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26712" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0516c06b19dc64807c10e01bb99b552bdf2d7dbe" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0c09912dd8387e228afcc5e34ac5d79b1e3a1058" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/230e89b5ad0a33f530a2a976b3e5e4385cb27882" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2738e0aa2fb24a7ab9c878d912dc2b239738c6c6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4a7aee96200ad281a5cc4cf5c7a2e2a49d2b97b0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/70ef2ba1f4286b2b73675aeb424b590c92d57b25" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T15:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-97mp-32j5-q87r/GHSA-97mp-32j5-q87r.json b/advisories/unreviewed/2024/04/GHSA-97mp-32j5-q87r/GHSA-97mp-32j5-q87r.json new file mode 100644 index 00000000000..b0a59f8fe5e --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-97mp-32j5-q87r/GHSA-97mp-32j5-q87r.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-97mp-32j5-q87r", + "modified": "2024-04-03T15:30:43Z", + "published": "2024-04-03T15:30:43Z", + "aliases": [ + "CVE-2024-26715" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: dwc3: gadget: Fix NULL pointer dereference in dwc3_gadget_suspend\n\nIn current scenario if Plug-out and Plug-In performed continuously\nthere could be a chance while checking for dwc->gadget_driver in\ndwc3_gadget_suspend, a NULL pointer dereference may occur.\n\nCall Stack:\n\n\tCPU1: CPU2:\n\tgadget_unbind_driver dwc3_suspend_common\n\tdwc3_gadget_stop dwc3_gadget_suspend\n dwc3_disconnect_gadget\n\nCPU1 basically clears the variable and CPU2 checks the variable.\nConsider CPU1 is running and right before gadget_driver is cleared\nand in parallel CPU2 executes dwc3_gadget_suspend where it finds\ndwc->gadget_driver which is not NULL and resumes execution and then\nCPU1 completes execution. CPU2 executes dwc3_disconnect_gadget where\nit checks dwc->gadget_driver is already NULL because of which the\nNULL pointer deference occur.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26715" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/36695d5eeeefe5a64b47d0336e7c8fc144e78182" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/57e2e42ccd3cd6183228269715ed032f44536751" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/61a348857e869432e6a920ad8ea9132e8d44c316" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/88936ceab6b426f1312327e9ef849c215c6007a7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c7ebd8149ee519d27232e6e4940e9c02071b568b" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T15:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-98w9-jqjv-x727/GHSA-98w9-jqjv-x727.json b/advisories/unreviewed/2024/04/GHSA-98w9-jqjv-x727/GHSA-98w9-jqjv-x727.json new file mode 100644 index 00000000000..539582021da --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-98w9-jqjv-x727/GHSA-98w9-jqjv-x727.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-98w9-jqjv-x727", + "modified": "2024-04-03T15:30:41Z", + "published": "2024-04-03T15:30:41Z", + "aliases": [ + "CVE-2024-24976" + ], + "details": "A denial of service vulnerability exists in the OAS Engine File Data Source Configuration functionality of Open Automation Software OAS Platform V19.00.0057. A specially crafted series of network requests can cause the running program to stop. An attacker can send a sequence of requests to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24976" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-1948" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-1948" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-130" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T14:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-9fgf-m63q-p2m6/GHSA-9fgf-m63q-p2m6.json b/advisories/unreviewed/2024/04/GHSA-9fgf-m63q-p2m6/GHSA-9fgf-m63q-p2m6.json new file mode 100644 index 00000000000..1135b8a2cca --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-9fgf-m63q-p2m6/GHSA-9fgf-m63q-p2m6.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9fgf-m63q-p2m6", + "modified": "2024-04-03T15:30:41Z", + "published": "2024-04-03T15:30:41Z", + "aliases": [ + "CVE-2024-30568" + ], + "details": "Netgear R6850 1.1.0.88 was discovered to contain a command injection vulnerability via the c4-IPAddr parameter.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30568" + }, + { + "type": "WEB", + "url": "https://github.com/funny-mud-peee/IoT-vuls/blob/main/netgear%20R6850/Netgear-R6850%20V1.1.0.88%20Command%20Injection%28ping_test%29.md" + }, + { + "type": "WEB", + "url": "https://www.netgear.com/about/security" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T13:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-9xp8-8c5r-6wfh/GHSA-9xp8-8c5r-6wfh.json b/advisories/unreviewed/2024/04/GHSA-9xp8-8c5r-6wfh/GHSA-9xp8-8c5r-6wfh.json new file mode 100644 index 00000000000..d54ca75383f --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-9xp8-8c5r-6wfh/GHSA-9xp8-8c5r-6wfh.json @@ -0,0 +1,55 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9xp8-8c5r-6wfh", + "modified": "2024-04-03T15:30:42Z", + "published": "2024-04-03T15:30:42Z", + "aliases": [ + "CVE-2024-26689" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nceph: prevent use-after-free in encode_cap_msg()\n\nIn fs/ceph/caps.c, in encode_cap_msg(), \"use after free\" error was\ncaught by KASAN at this line - 'ceph_buffer_get(arg->xattr_buf);'. This\nimplies before the refcount could be increment here, it was freed.\n\nIn same file, in \"handle_cap_grant()\" refcount is decremented by this\nline - 'ceph_buffer_put(ci->i_xattrs.blob);'. It appears that a race\noccurred and resource was freed by the latter line before the former\nline could increment it.\n\nencode_cap_msg() is called by __send_cap() and __send_cap() is called by\nceph_check_caps() after calling __prep_cap(). __prep_cap() is where\narg->xattr_buf is assigned to ci->i_xattrs.blob. This is the spot where\nthe refcount must be increased to prevent \"use after free\" error.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26689" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/70e329b440762390258a6fe8c0de93c9fdd56c77" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7958c1bf5b03c6f1f58e724dbdec93f8f60b96fc" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8180d0c27b93a6eb60da1b08ea079e3926328214" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ae20db45e482303a20e56f2db667a9d9c54ac7e7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cda4672da1c26835dcbd7aec2bfed954eda9b5ef" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f3f98d7d84b31828004545e29fd7262b9f444139" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T15:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-c8f2-2f6p-gpgc/GHSA-c8f2-2f6p-gpgc.json b/advisories/unreviewed/2024/04/GHSA-c8f2-2f6p-gpgc/GHSA-c8f2-2f6p-gpgc.json new file mode 100644 index 00000000000..3ccc2e3e643 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-c8f2-2f6p-gpgc/GHSA-c8f2-2f6p-gpgc.json @@ -0,0 +1,55 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c8f2-2f6p-gpgc", + "modified": "2024-04-03T15:30:43Z", + "published": "2024-04-03T15:30:43Z", + "aliases": [ + "CVE-2024-26707" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: hsr: remove WARN_ONCE() in send_hsr_supervision_frame()\n\nSyzkaller reported [1] hitting a warning after failing to allocate\nresources for skb in hsr_init_skb(). Since a WARN_ONCE() call will\nnot help much in this case, it might be prudent to switch to\nnetdev_warn_once(). At the very least it will suppress syzkaller\nreports such as [1].\n\nJust in case, use netdev_warn_once() in send_prp_supervision_frame()\nfor similar reasons.\n\n[1]\nHSR: Could not send supervision frame\nWARNING: CPU: 1 PID: 85 at net/hsr/hsr_device.c:294 send_hsr_supervision_frame+0x60a/0x810 net/hsr/hsr_device.c:294\nRIP: 0010:send_hsr_supervision_frame+0x60a/0x810 net/hsr/hsr_device.c:294\n...\nCall Trace:\n \n hsr_announce+0x114/0x370 net/hsr/hsr_device.c:382\n call_timer_fn+0x193/0x590 kernel/time/timer.c:1700\n expire_timers kernel/time/timer.c:1751 [inline]\n __run_timers+0x764/0xb20 kernel/time/timer.c:2022\n run_timer_softirq+0x58/0xd0 kernel/time/timer.c:2035\n __do_softirq+0x21a/0x8de kernel/softirq.c:553\n invoke_softirq kernel/softirq.c:427 [inline]\n __irq_exit_rcu kernel/softirq.c:632 [inline]\n irq_exit_rcu+0xb7/0x120 kernel/softirq.c:644\n sysvec_apic_timer_interrupt+0x95/0xb0 arch/x86/kernel/apic/apic.c:1076\n \n \n asm_sysvec_apic_timer_interrupt+0x1a/0x20 arch/x86/include/asm/idtentry.h:649\n...\n\nThis issue is also found in older kernels (at least up to 5.10).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26707" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0d8011a878fdf96123bc0d6a12e2fe7ced5fddfb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/37e8c97e539015637cb920d3e6f1e404f707a06e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/547545e50c913861219947ce490c68a1776b9b51" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/56440799fc4621c279df16176f83a995d056023a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/923dea2a7ea9e1ef5ac4031fba461c1cc92e32b8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/de769423b2f053182a41317c4db5a927e90622a0" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T15:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-cmxf-xmv7-xjq8/GHSA-cmxf-xmv7-xjq8.json b/advisories/unreviewed/2024/04/GHSA-cmxf-xmv7-xjq8/GHSA-cmxf-xmv7-xjq8.json index 46bd6b249d7..c98c25a8099 100644 --- a/advisories/unreviewed/2024/04/GHSA-cmxf-xmv7-xjq8/GHSA-cmxf-xmv7-xjq8.json +++ b/advisories/unreviewed/2024/04/GHSA-cmxf-xmv7-xjq8/GHSA-cmxf-xmv7-xjq8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cmxf-xmv7-xjq8", - "modified": "2024-04-02T09:30:40Z", + "modified": "2024-04-03T15:30:41Z", "published": "2024-04-02T09:30:40Z", "aliases": [ "CVE-2024-26656" @@ -21,6 +21,18 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/22207fd5c80177b860279653d017474b2812af5e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/22f665ecfd1225afa1309ace623157d12bb9bb0c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/af054a5fb24a144f99895afce9519d709891894c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e87e08c94c9541b4e18c4c13f2f605935f512605" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/04/GHSA-cwr2-26gq-v2xr/GHSA-cwr2-26gq-v2xr.json b/advisories/unreviewed/2024/04/GHSA-cwr2-26gq-v2xr/GHSA-cwr2-26gq-v2xr.json new file mode 100644 index 00000000000..b6312950f5a --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-cwr2-26gq-v2xr/GHSA-cwr2-26gq-v2xr.json @@ -0,0 +1,63 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cwr2-26gq-v2xr", + "modified": "2024-04-03T15:30:42Z", + "published": "2024-04-03T15:30:42Z", + "aliases": [ + "CVE-2024-26696" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: fix hang in nilfs_lookup_dirty_data_buffers()\n\nSyzbot reported a hang issue in migrate_pages_batch() called by mbind()\nand nilfs_lookup_dirty_data_buffers() called in the log writer of nilfs2.\n\nWhile migrate_pages_batch() locks a folio and waits for the writeback to\ncomplete, the log writer thread that should bring the writeback to\ncompletion picks up the folio being written back in\nnilfs_lookup_dirty_data_buffers() that it calls for subsequent log\ncreation and was trying to lock the folio. Thus causing a deadlock.\n\nIn the first place, it is unexpected that folios/pages in the middle of\nwriteback will be updated and become dirty. Nilfs2 adds a checksum to\nverify the validity of the log being written and uses it for recovery at\nmount, so data changes during writeback are suppressed. Since this is\nbroken, an unclean shutdown could potentially cause recovery to fail.\n\nInvestigation revealed that the root cause is that the wait for writeback\ncompletion in nilfs_page_mkwrite() is conditional, and if the backing\ndevice does not require stable writes, data may be modified without\nwaiting.\n\nFix these issues by making nilfs_page_mkwrite() wait for writeback to\nfinish regardless of the stable write requirement of the backing device.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26696" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/228742b2ddfb99dfd71e5a307e6088ab6836272e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/38296afe3c6ee07319e01bb249aa4bb47c07b534" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7e9b622bd0748cc104d66535b76d9b3535f9dc0f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8494ba2c9ea00a54d5b50e69b22c55a8958bce32" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/862ee4422c38be5c249844a684b00d0dbe9d1e46" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/98a4026b22ff440c7f47056481bcbbe442f607d6" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e38585401d464578d30f5868ff4ca54475c34f7d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ea5ddbc11613b55e5128c85f57b08f907abd9b28" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T15:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-f6g6-gf5g-h3f3/GHSA-f6g6-gf5g-h3f3.json b/advisories/unreviewed/2024/04/GHSA-f6g6-gf5g-h3f3/GHSA-f6g6-gf5g-h3f3.json new file mode 100644 index 00000000000..c0bdd9e827b --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-f6g6-gf5g-h3f3/GHSA-f6g6-gf5g-h3f3.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f6g6-gf5g-h3f3", + "modified": "2024-04-03T15:30:43Z", + "published": "2024-04-03T15:30:43Z", + "aliases": [ + "CVE-2024-26700" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Fix MST Null Ptr for RV\n\nThe change try to fix below error specific to RV platform:\n\nBUG: kernel NULL pointer dereference, address: 0000000000000008\nPGD 0 P4D 0\nOops: 0000 [#1] PREEMPT SMP NOPTI\nCPU: 4 PID: 917 Comm: sway Not tainted 6.3.9-arch1-1 #1 124dc55df4f5272ccb409f39ef4872fc2b3376a2\nHardware name: LENOVO 20NKS01Y00/20NKS01Y00, BIOS R12ET61W(1.31 ) 07/28/2022\nRIP: 0010:drm_dp_atomic_find_time_slots+0x5e/0x260 [drm_display_helper]\nCode: 01 00 00 48 8b 85 60 05 00 00 48 63 80 88 00 00 00 3b 43 28 0f 8d 2e 01 00 00 48 8b 53 30 48 8d 04 80 48 8d 04 c2 48 8b 40 18 <48> 8>\nRSP: 0018:ffff960cc2df77d8 EFLAGS: 00010293\nRAX: 0000000000000000 RBX: ffff8afb87e81280 RCX: 0000000000000224\nRDX: ffff8afb9ee37c00 RSI: ffff8afb8da1a578 RDI: ffff8afb87e81280\nRBP: ffff8afb83d67000 R08: 0000000000000001 R09: ffff8afb9652f850\nR10: ffff960cc2df7908 R11: 0000000000000002 R12: 0000000000000000\nR13: ffff8afb8d7688a0 R14: ffff8afb8da1a578 R15: 0000000000000224\nFS: 00007f4dac35ce00(0000) GS:ffff8afe30b00000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 0000000000000008 CR3: 000000010ddc6000 CR4: 00000000003506e0\nCall Trace:\n \n ? __die+0x23/0x70\n ? page_fault_oops+0x171/0x4e0\n ? plist_add+0xbe/0x100\n ? exc_page_fault+0x7c/0x180\n ? asm_exc_page_fault+0x26/0x30\n ? drm_dp_atomic_find_time_slots+0x5e/0x260 [drm_display_helper 0e67723696438d8e02b741593dd50d80b44c2026]\n ? drm_dp_atomic_find_time_slots+0x28/0x260 [drm_display_helper 0e67723696438d8e02b741593dd50d80b44c2026]\n compute_mst_dsc_configs_for_link+0x2ff/0xa40 [amdgpu 62e600d2a75e9158e1cd0a243bdc8e6da040c054]\n ? fill_plane_buffer_attributes+0x419/0x510 [amdgpu 62e600d2a75e9158e1cd0a243bdc8e6da040c054]\n compute_mst_dsc_configs_for_state+0x1e1/0x250 [amdgpu 62e600d2a75e9158e1cd0a243bdc8e6da040c054]\n amdgpu_dm_atomic_check+0xecd/0x1190 [amdgpu 62e600d2a75e9158e1cd0a243bdc8e6da040c054]\n drm_atomic_check_only+0x5c5/0xa40\n drm_mode_atomic_ioctl+0x76e/0xbc0\n ? _copy_to_user+0x25/0x30\n ? drm_ioctl+0x296/0x4b0\n ? __pfx_drm_mode_atomic_ioctl+0x10/0x10\n drm_ioctl_kernel+0xcd/0x170\n drm_ioctl+0x26d/0x4b0\n ? __pfx_drm_mode_atomic_ioctl+0x10/0x10\n amdgpu_drm_ioctl+0x4e/0x90 [amdgpu 62e600d2a75e9158e1cd0a243bdc8e6da040c054]\n __x64_sys_ioctl+0x94/0xd0\n do_syscall_64+0x60/0x90\n ? do_syscall_64+0x6c/0x90\n entry_SYSCALL_64_after_hwframe+0x72/0xdc\nRIP: 0033:0x7f4dad17f76f\nCode: 00 48 89 44 24 18 31 c0 48 8d 44 24 60 c7 04 24 10 00 00 00 48 89 44 24 08 48 8d 44 24 20 48 89 44 24 10 b8 10 00 00 00 0f 05 <89> c>\nRSP: 002b:00007ffd9ae859f0 EFLAGS: 00000246 ORIG_RAX: 0000000000000010\nRAX: ffffffffffffffda RBX: 000055e255a55900 RCX: 00007f4dad17f76f\nRDX: 00007ffd9ae85a90 RSI: 00000000c03864bc RDI: 000000000000000b\nRBP: 00007ffd9ae85a90 R08: 0000000000000003 R09: 0000000000000003\nR10: 0000000000000000 R11: 0000000000000246 R12: 00000000c03864bc\nR13: 000000000000000b R14: 000055e255a7fc60 R15: 000055e255a01eb0\n \nModules linked in: rfcomm snd_seq_dummy snd_hrtimer snd_seq snd_seq_device ccm cmac algif_hash algif_skcipher af_alg joydev mousedev bnep >\n typec libphy k10temp ipmi_msghandler roles i2c_scmi acpi_cpufreq mac_hid nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_mas>\nCR2: 0000000000000008\n---[ end trace 0000000000000000 ]---\nRIP: 0010:drm_dp_atomic_find_time_slots+0x5e/0x260 [drm_display_helper]\nCode: 01 00 00 48 8b 85 60 05 00 00 48 63 80 88 00 00 00 3b 43 28 0f 8d 2e 01 00 00 48 8b 53 30 48 8d 04 80 48 8d 04 c2 48 8b 40 18 <48> 8>\nRSP: 0018:ffff960cc2df77d8 EFLAGS: 00010293\nRAX: 0000000000000000 RBX: ffff8afb87e81280 RCX: 0000000000000224\nRDX: ffff8afb9ee37c00 RSI: ffff8afb8da1a578 RDI: ffff8afb87e81280\nRBP: ffff8afb83d67000 R08: 0000000000000001 R09: ffff8afb9652f850\nR10: ffff960cc2df7908 R11: 0000000000000002 R12: 0000000000000000\nR13: ffff8afb8d7688a0 R14: ffff8afb8da1a578 R15: 0000000000000224\nFS: 00007f4dac35ce00(0000) GS:ffff8afe30b00000(0000\n---truncated---", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26700" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/01d992088dce3945f70f49f34b0b911c5213c238" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5cd7185d2db76c42a9b7e69adad9591d9fca093f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7407c61f43b66e90ad127d0cdd13cbc9d87141a5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e6a7df96facdcf5b1f71eb3ec26f2f9f6ad61e57" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T15:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-fg2w-r2w5-mgjw/GHSA-fg2w-r2w5-mgjw.json b/advisories/unreviewed/2024/04/GHSA-fg2w-r2w5-mgjw/GHSA-fg2w-r2w5-mgjw.json new file mode 100644 index 00000000000..e0ce1f02cf4 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-fg2w-r2w5-mgjw/GHSA-fg2w-r2w5-mgjw.json @@ -0,0 +1,51 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fg2w-r2w5-mgjw", + "modified": "2024-04-03T15:30:43Z", + "published": "2024-04-03T15:30:43Z", + "aliases": [ + "CVE-2024-26717" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: i2c-hid-of: fix NULL-deref on failed power up\n\nA while back the I2C HID implementation was split in an ACPI and OF\npart, but the new OF driver never initialises the client pointer which\nis dereferenced on power-up failures.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26717" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/00aab7dcb2267f2aef59447602f34501efe1a07f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4cad91344a62536a2949873bad6365fbb6232776" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/62f5d219edbd174829aa18d4b3d97cd5fefbb783" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d7d7a0e3b6f5adc45f23667cbb919e99093a5b5c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e28d6b63aeecbda450935fb58db0e682ea8212d3" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T15:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-fr3q-v98q-fwq5/GHSA-fr3q-v98q-fwq5.json b/advisories/unreviewed/2024/04/GHSA-fr3q-v98q-fwq5/GHSA-fr3q-v98q-fwq5.json index 6ee6ee9dd2a..3d6f2bc7e81 100644 --- a/advisories/unreviewed/2024/04/GHSA-fr3q-v98q-fwq5/GHSA-fr3q-v98q-fwq5.json +++ b/advisories/unreviewed/2024/04/GHSA-fr3q-v98q-fwq5/GHSA-fr3q-v98q-fwq5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fr3q-v98q-fwq5", - "modified": "2024-04-02T09:30:40Z", + "modified": "2024-04-03T15:30:41Z", "published": "2024-04-02T09:30:40Z", "aliases": [ "CVE-2024-26657" @@ -18,6 +18,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26657" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/54b5b7275dfdec35812ccce70930cd7c4ee612b2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/74cd204c7afe498aa9dcc3ebf0ecac53d477a429" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/f34e8bb7d6c6626933fe993e03ed59ae85e16abb" diff --git a/advisories/unreviewed/2024/04/GHSA-h7gp-37f7-qxv5/GHSA-h7gp-37f7-qxv5.json b/advisories/unreviewed/2024/04/GHSA-h7gp-37f7-qxv5/GHSA-h7gp-37f7-qxv5.json new file mode 100644 index 00000000000..46bb79769a2 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-h7gp-37f7-qxv5/GHSA-h7gp-37f7-qxv5.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h7gp-37f7-qxv5", + "modified": "2024-04-03T15:30:41Z", + "published": "2024-04-03T15:30:41Z", + "aliases": [ + "CVE-2024-3258" + ], + "details": "A vulnerability was found in SourceCodester Internship Portal Management System 1.0. It has been classified as critical. This affects an unknown part of the file admin/add_activity.php. The manipulation of the argument title/description/start/end leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259107.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3258" + }, + { + "type": "WEB", + "url": "https://github.com/thisissuperann/Vul/blob/main/Internship-Portal-Management-System-08" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.259107" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.259107" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.309219" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T13:16:03Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-j9gv-7x6c-3hqg/GHSA-j9gv-7x6c-3hqg.json b/advisories/unreviewed/2024/04/GHSA-j9gv-7x6c-3hqg/GHSA-j9gv-7x6c-3hqg.json new file mode 100644 index 00000000000..ac31d6c63c5 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-j9gv-7x6c-3hqg/GHSA-j9gv-7x6c-3hqg.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j9gv-7x6c-3hqg", + "modified": "2024-04-03T15:30:42Z", + "published": "2024-04-03T15:30:42Z", + "aliases": [ + "CVE-2023-5755" + ], + "details": "Rejected reason: **REJECT** Duplicate of CVE-2023-46784. Please refer to CVE-2023-46784.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5755" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T15:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-jc4v-c4mw-rmf8/GHSA-jc4v-c4mw-rmf8.json b/advisories/unreviewed/2024/04/GHSA-jc4v-c4mw-rmf8/GHSA-jc4v-c4mw-rmf8.json new file mode 100644 index 00000000000..bfe47e506fe --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-jc4v-c4mw-rmf8/GHSA-jc4v-c4mw-rmf8.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jc4v-c4mw-rmf8", + "modified": "2024-04-03T15:30:42Z", + "published": "2024-04-03T15:30:42Z", + "aliases": [ + "CVE-2024-26692" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: Fix regression in writes when non-standard maximum write size negotiated\n\nThe conversion to netfs in the 6.3 kernel caused a regression when\nmaximum write size is set by the server to an unexpected value which is\nnot a multiple of 4096 (similarly if the user overrides the maximum\nwrite size by setting mount parm \"wsize\", but sets it to a value that\nis not a multiple of 4096). When negotiated write size is not a\nmultiple of 4096 the netfs code can skip the end of the final\npage when doing large sequential writes, causing data corruption.\n\nThis section of code is being rewritten/removed due to a large\nnetfs change, but until that point (ie for the 6.3 kernel until now)\nwe can not support non-standard maximum write sizes.\n\nAdd a warning if a user specifies a wsize on mount that is not\na multiple of 4096 (and round down), also add a change where we\nround down the maximum write size if the server negotiates a value\nthat is not a multiple of 4096 (we also have to check to make sure that\nwe do not round it down to zero).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26692" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4145ccff546ea868428b3e0fe6818c6261b574a9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4860abb91f3d7fbaf8147d54782149bb1fc45892" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/63c35afd50e28b49c5b75542045a8c42b696dab9" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T15:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-jgpw-6hf2-c2m5/GHSA-jgpw-6hf2-c2m5.json b/advisories/unreviewed/2024/04/GHSA-jgpw-6hf2-c2m5/GHSA-jgpw-6hf2-c2m5.json new file mode 100644 index 00000000000..1daca147843 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-jgpw-6hf2-c2m5/GHSA-jgpw-6hf2-c2m5.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jgpw-6hf2-c2m5", + "modified": "2024-04-03T15:30:43Z", + "published": "2024-04-03T15:30:43Z", + "aliases": [ + "CVE-2024-26725" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndpll: fix possible deadlock during netlink dump operation\n\nRecently, I've been hitting following deadlock warning during dpll pin\ndump:\n\n[52804.637962] ======================================================\n[52804.638536] WARNING: possible circular locking dependency detected\n[52804.639111] 6.8.0-rc2jiri+ #1 Not tainted\n[52804.639529] ------------------------------------------------------\n[52804.640104] python3/2984 is trying to acquire lock:\n[52804.640581] ffff88810e642678 (nlk_cb_mutex-GENERIC){+.+.}-{3:3}, at: netlink_dump+0xb3/0x780\n[52804.641417]\n but task is already holding lock:\n[52804.642010] ffffffff83bde4c8 (dpll_lock){+.+.}-{3:3}, at: dpll_lock_dumpit+0x13/0x20\n[52804.642747]\n which lock already depends on the new lock.\n\n[52804.643551]\n the existing dependency chain (in reverse order) is:\n[52804.644259]\n -> #1 (dpll_lock){+.+.}-{3:3}:\n[52804.644836] lock_acquire+0x174/0x3e0\n[52804.645271] __mutex_lock+0x119/0x1150\n[52804.645723] dpll_lock_dumpit+0x13/0x20\n[52804.646169] genl_start+0x266/0x320\n[52804.646578] __netlink_dump_start+0x321/0x450\n[52804.647056] genl_family_rcv_msg_dumpit+0x155/0x1e0\n[52804.647575] genl_rcv_msg+0x1ed/0x3b0\n[52804.648001] netlink_rcv_skb+0xdc/0x210\n[52804.648440] genl_rcv+0x24/0x40\n[52804.648831] netlink_unicast+0x2f1/0x490\n[52804.649290] netlink_sendmsg+0x36d/0x660\n[52804.649742] __sock_sendmsg+0x73/0xc0\n[52804.650165] __sys_sendto+0x184/0x210\n[52804.650597] __x64_sys_sendto+0x72/0x80\n[52804.651045] do_syscall_64+0x6f/0x140\n[52804.651474] entry_SYSCALL_64_after_hwframe+0x46/0x4e\n[52804.652001]\n -> #0 (nlk_cb_mutex-GENERIC){+.+.}-{3:3}:\n[52804.652650] check_prev_add+0x1ae/0x1280\n[52804.653107] __lock_acquire+0x1ed3/0x29a0\n[52804.653559] lock_acquire+0x174/0x3e0\n[52804.653984] __mutex_lock+0x119/0x1150\n[52804.654423] netlink_dump+0xb3/0x780\n[52804.654845] __netlink_dump_start+0x389/0x450\n[52804.655321] genl_family_rcv_msg_dumpit+0x155/0x1e0\n[52804.655842] genl_rcv_msg+0x1ed/0x3b0\n[52804.656272] netlink_rcv_skb+0xdc/0x210\n[52804.656721] genl_rcv+0x24/0x40\n[52804.657119] netlink_unicast+0x2f1/0x490\n[52804.657570] netlink_sendmsg+0x36d/0x660\n[52804.658022] __sock_sendmsg+0x73/0xc0\n[52804.658450] __sys_sendto+0x184/0x210\n[52804.658877] __x64_sys_sendto+0x72/0x80\n[52804.659322] do_syscall_64+0x6f/0x140\n[52804.659752] entry_SYSCALL_64_after_hwframe+0x46/0x4e\n[52804.660281]\n other info that might help us debug this:\n\n[52804.661077] Possible unsafe locking scenario:\n\n[52804.661671] CPU0 CPU1\n[52804.662129] ---- ----\n[52804.662577] lock(dpll_lock);\n[52804.662924] lock(nlk_cb_mutex-GENERIC);\n[52804.663538] lock(dpll_lock);\n[52804.664073] lock(nlk_cb_mutex-GENERIC);\n[52804.664490]\n\nThe issue as follows: __netlink_dump_start() calls control->start(cb)\nwith nlk->cb_mutex held. In control->start(cb) the dpll_lock is taken.\nThen nlk->cb_mutex is released and taken again in netlink_dump(), while\ndpll_lock still being held. That leads to ABBA deadlock when another\nCPU races with the same operation.\n\nFix this by moving dpll_lock taking into dumpit() callback which ensures\ncorrect lock taking order.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26725" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/087739cbd0d0b87b6cec2c0799436ac66e24acc8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/53c0441dd2c44ee93fddb5473885fd41e4bc2361" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T15:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-m586-22m6-88g8/GHSA-m586-22m6-88g8.json b/advisories/unreviewed/2024/04/GHSA-m586-22m6-88g8/GHSA-m586-22m6-88g8.json new file mode 100644 index 00000000000..6ca55770b7f --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-m586-22m6-88g8/GHSA-m586-22m6-88g8.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m586-22m6-88g8", + "modified": "2024-04-03T15:30:41Z", + "published": "2024-04-03T15:30:41Z", + "aliases": [ + "CVE-2023-25699" + ], + "details": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in VideoWhisper.Com VideoWhisper Live Streaming Integration allows OS Command Injection.This issue affects VideoWhisper Live Streaming Integration: from n/a through 5.5.15.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25699" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/videowhisper-live-streaming-integration/wordpress-broadcast-live-video-live-streaming-html5-webrtc-hls-rtsp-rtmp-plugin-5-5-15-remote-code-execution-rce?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T13:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-m7cw-25xq-j5wg/GHSA-m7cw-25xq-j5wg.json b/advisories/unreviewed/2024/04/GHSA-m7cw-25xq-j5wg/GHSA-m7cw-25xq-j5wg.json new file mode 100644 index 00000000000..d4d0f56ab5e --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-m7cw-25xq-j5wg/GHSA-m7cw-25xq-j5wg.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m7cw-25xq-j5wg", + "modified": "2024-04-03T15:30:43Z", + "published": "2024-04-03T15:30:43Z", + "aliases": [ + "CVE-2024-26724" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: DPLL, Fix possible use after free after delayed work timer triggers\n\nI managed to hit following use after free warning recently:\n\n[ 2169.711665] ==================================================================\n[ 2169.714009] BUG: KASAN: slab-use-after-free in __run_timers.part.0+0x179/0x4c0\n[ 2169.716293] Write of size 8 at addr ffff88812b326a70 by task swapper/4/0\n\n[ 2169.719022] CPU: 4 PID: 0 Comm: swapper/4 Not tainted 6.8.0-rc2jiri+ #2\n[ 2169.720974] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014\n[ 2169.722457] Call Trace:\n[ 2169.722756] \n[ 2169.723024] dump_stack_lvl+0x58/0xb0\n[ 2169.723417] print_report+0xc5/0x630\n[ 2169.723807] ? __virt_addr_valid+0x126/0x2b0\n[ 2169.724268] kasan_report+0xbe/0xf0\n[ 2169.724667] ? __run_timers.part.0+0x179/0x4c0\n[ 2169.725116] ? __run_timers.part.0+0x179/0x4c0\n[ 2169.725570] __run_timers.part.0+0x179/0x4c0\n[ 2169.726003] ? call_timer_fn+0x320/0x320\n[ 2169.726404] ? lock_downgrade+0x3a0/0x3a0\n[ 2169.726820] ? kvm_clock_get_cycles+0x14/0x20\n[ 2169.727257] ? ktime_get+0x92/0x150\n[ 2169.727630] ? lapic_next_deadline+0x35/0x60\n[ 2169.728069] run_timer_softirq+0x40/0x80\n[ 2169.728475] __do_softirq+0x1a1/0x509\n[ 2169.728866] irq_exit_rcu+0x95/0xc0\n[ 2169.729241] sysvec_apic_timer_interrupt+0x6b/0x80\n[ 2169.729718] \n[ 2169.729993] \n[ 2169.730259] asm_sysvec_apic_timer_interrupt+0x16/0x20\n[ 2169.730755] RIP: 0010:default_idle+0x13/0x20\n[ 2169.731190] Code: c0 08 00 00 00 4d 29 c8 4c 01 c7 4c 29 c2 e9 72 ff ff ff cc cc cc cc 8b 05 9a 7f 1f 02 85 c0 7e 07 0f 00 2d cf 69 43 00 fb f4 c3 66 66 2e 0f 1f 84 00 00 00 00 00 65 48 8b 04 25 c0 93 04 00\n[ 2169.732759] RSP: 0018:ffff888100dbfe10 EFLAGS: 00000242\n[ 2169.733264] RAX: 0000000000000001 RBX: ffff888100d9c200 RCX: ffffffff8241bd62\n[ 2169.733925] RDX: ffffed109a848b15 RSI: 0000000000000004 RDI: ffffffff8127ac55\n[ 2169.734566] RBP: 0000000000000004 R08: 0000000000000000 R09: ffffed109a848b14\n[ 2169.735200] R10: ffff8884d42458a3 R11: 000000000000ba7e R12: ffffffff83d7d3a0\n[ 2169.735835] R13: 1ffff110201b7fc6 R14: 0000000000000000 R15: ffff888100d9c200\n[ 2169.736478] ? ct_kernel_exit.constprop.0+0xa2/0xc0\n[ 2169.736954] ? do_idle+0x285/0x290\n[ 2169.737323] default_idle_call+0x63/0x90\n[ 2169.737730] do_idle+0x285/0x290\n[ 2169.738089] ? arch_cpu_idle_exit+0x30/0x30\n[ 2169.738511] ? mark_held_locks+0x1a/0x80\n[ 2169.738917] ? lockdep_hardirqs_on_prepare+0x12e/0x200\n[ 2169.739417] cpu_startup_entry+0x30/0x40\n[ 2169.739825] start_secondary+0x19a/0x1c0\n[ 2169.740229] ? set_cpu_sibling_map+0xbd0/0xbd0\n[ 2169.740673] secondary_startup_64_no_verify+0x15d/0x16b\n[ 2169.741179] \n\n[ 2169.741686] Allocated by task 1098:\n[ 2169.742058] kasan_save_stack+0x1c/0x40\n[ 2169.742456] kasan_save_track+0x10/0x30\n[ 2169.742852] __kasan_kmalloc+0x83/0x90\n[ 2169.743246] mlx5_dpll_probe+0xf5/0x3c0 [mlx5_dpll]\n[ 2169.743730] auxiliary_bus_probe+0x62/0xb0\n[ 2169.744148] really_probe+0x127/0x590\n[ 2169.744534] __driver_probe_device+0xd2/0x200\n[ 2169.744973] device_driver_attach+0x6b/0xf0\n[ 2169.745402] bind_store+0x90/0xe0\n[ 2169.745761] kernfs_fop_write_iter+0x1df/0x2a0\n[ 2169.746210] vfs_write+0x41f/0x790\n[ 2169.746579] ksys_write+0xc7/0x160\n[ 2169.746947] do_syscall_64+0x6f/0x140\n[ 2169.747333] entry_SYSCALL_64_after_hwframe+0x46/0x4e\n\n[ 2169.748049] Freed by task 1220:\n[ 2169.748393] kasan_save_stack+0x1c/0x40\n[ 2169.748789] kasan_save_track+0x10/0x30\n[ 2169.749188] kasan_save_free_info+0x3b/0x50\n[ 2169.749621] poison_slab_object+0x106/0x180\n[ 2169.750044] __kasan_slab_free+0x14/0x50\n[ 2169.750451] kfree+0x118/0x330\n[ 2169.750792] mlx5_dpll_remove+0xf5/0x110 [mlx5_dpll]\n[ 2169.751271] auxiliary_bus_remove+0x2e/0x40\n[ 2169.751694] device_release_driver_internal+0x24b/0x2e0\n[ 2169.752191] unbind_store+0xa6/0xb0\n[ 2169.752563] kernfs_fo\n---truncated---", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26724" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1596126ea50228f0ed96697bae4e9368fda02c56" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/aa1eec2f546f2afa8c98ec41e5d8ee488165d685" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T15:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-m8xg-hgh7-rwh3/GHSA-m8xg-hgh7-rwh3.json b/advisories/unreviewed/2024/04/GHSA-m8xg-hgh7-rwh3/GHSA-m8xg-hgh7-rwh3.json new file mode 100644 index 00000000000..7b835e37e75 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-m8xg-hgh7-rwh3/GHSA-m8xg-hgh7-rwh3.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m8xg-hgh7-rwh3", + "modified": "2024-04-03T15:30:41Z", + "published": "2024-04-03T15:30:41Z", + "aliases": [ + "CVE-2024-22178" + ], + "details": "A file write vulnerability exists in the OAS Engine Save Security Configuration functionality of Open Automation Software OAS Platform V19.00.0057. A specially crafted series of network requests can lead to arbitrary file creation or overwrite. An attacker can send a sequence of requests to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22178" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-1951" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-1951" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-73" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T14:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-mccq-9gc6-hm85/GHSA-mccq-9gc6-hm85.json b/advisories/unreviewed/2024/04/GHSA-mccq-9gc6-hm85/GHSA-mccq-9gc6-hm85.json new file mode 100644 index 00000000000..0468ed04dfd --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-mccq-9gc6-hm85/GHSA-mccq-9gc6-hm85.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mccq-9gc6-hm85", + "modified": "2024-04-03T15:30:43Z", + "published": "2024-04-03T15:30:43Z", + "aliases": [ + "CVE-2024-26703" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntracing/timerlat: Move hrtimer_init to timerlat_fd open()\n\nCurrently, the timerlat's hrtimer is initialized at the first read of\ntimerlat_fd, and destroyed at close(). It works, but it causes an error\nif the user program open() and close() the file without reading.\n\nHere's an example:\n\n # echo NO_OSNOISE_WORKLOAD > /sys/kernel/debug/tracing/osnoise/options\n # echo timerlat > /sys/kernel/debug/tracing/current_tracer\n\n # cat < ./timerlat_load.py\n # !/usr/bin/env python3\n\n timerlat_fd = open(\"/sys/kernel/tracing/osnoise/per_cpu/cpu0/timerlat_fd\", 'r')\n timerlat_fd.close();\n EOF\n\n # ./taskset -c 0 ./timerlat_load.py\n\n\n BUG: kernel NULL pointer dereference, address: 0000000000000010\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\n PGD 0 P4D 0\n Oops: 0000 [#1] PREEMPT SMP NOPTI\n CPU: 1 PID: 2673 Comm: python3 Not tainted 6.6.13-200.fc39.x86_64 #1\n Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-1.fc39 04/01/2014\n RIP: 0010:hrtimer_active+0xd/0x50\n Code: 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 f3 0f 1e fa 0f 1f 44 00 00 48 8b 57 30 <8b> 42 10 a8 01 74 09 f3 90 8b 42 10 a8 01 75 f7 80 7f 38 00 75 1d\n RSP: 0018:ffffb031009b7e10 EFLAGS: 00010286\n RAX: 000000000002db00 RBX: ffff9118f786db08 RCX: 0000000000000000\n RDX: 0000000000000000 RSI: ffff9117a0e64400 RDI: ffff9118f786db08\n RBP: ffff9118f786db80 R08: ffff9117a0ddd420 R09: ffff9117804d4f70\n R10: 0000000000000000 R11: 0000000000000000 R12: ffff9118f786db08\n R13: ffff91178fdd5e20 R14: ffff9117840978c0 R15: 0000000000000000\n FS: 00007f2ffbab1740(0000) GS:ffff9118f7840000(0000) knlGS:0000000000000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 0000000000000010 CR3: 00000001b402e000 CR4: 0000000000750ee0\n PKRU: 55555554\n Call Trace:\n \n ? __die+0x23/0x70\n ? page_fault_oops+0x171/0x4e0\n ? srso_alias_return_thunk+0x5/0x7f\n ? avc_has_extended_perms+0x237/0x520\n ? exc_page_fault+0x7f/0x180\n ? asm_exc_page_fault+0x26/0x30\n ? hrtimer_active+0xd/0x50\n hrtimer_cancel+0x15/0x40\n timerlat_fd_release+0x48/0xe0\n __fput+0xf5/0x290\n __x64_sys_close+0x3d/0x80\n do_syscall_64+0x60/0x90\n ? srso_alias_return_thunk+0x5/0x7f\n ? __x64_sys_ioctl+0x72/0xd0\n ? srso_alias_return_thunk+0x5/0x7f\n ? syscall_exit_to_user_mode+0x2b/0x40\n ? srso_alias_return_thunk+0x5/0x7f\n ? do_syscall_64+0x6c/0x90\n ? srso_alias_return_thunk+0x5/0x7f\n ? exit_to_user_mode_prepare+0x142/0x1f0\n ? srso_alias_return_thunk+0x5/0x7f\n ? syscall_exit_to_user_mode+0x2b/0x40\n ? srso_alias_return_thunk+0x5/0x7f\n ? do_syscall_64+0x6c/0x90\n entry_SYSCALL_64_after_hwframe+0x6e/0xd8\n RIP: 0033:0x7f2ffb321594\n Code: 00 f7 d8 64 89 01 48 83 c8 ff c3 66 2e 0f 1f 84 00 00 00 00 00 90 f3 0f 1e fa 80 3d d5 cd 0d 00 00 74 13 b8 03 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 3c c3 0f 1f 00 55 48 89 e5 48 83 ec 10 89 7d\n RSP: 002b:00007ffe8d8eef18 EFLAGS: 00000202 ORIG_RAX: 0000000000000003\n RAX: ffffffffffffffda RBX: 00007f2ffba4e668 RCX: 00007f2ffb321594\n RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000003\n RBP: 00007ffe8d8eef40 R08: 0000000000000000 R09: 0000000000000000\n R10: 55c926e3167eae79 R11: 0000000000000202 R12: 0000000000000003\n R13: 00007ffe8d8ef030 R14: 0000000000000000 R15: 00007f2ffba4e668\n \n CR2: 0000000000000010\n ---[ end trace 0000000000000000 ]---\n\nMove hrtimer_init to timerlat_fd open() to avoid this problem.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26703" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1389358bb008e7625942846e9f03554319b7fecc" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2354d29986ebd138f89c2b73fecf8237e0a4ad6b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5f703935fdb559642d85b2088442ee55a557ae6d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T15:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-mgx5-jrhq-g7rg/GHSA-mgx5-jrhq-g7rg.json b/advisories/unreviewed/2024/04/GHSA-mgx5-jrhq-g7rg/GHSA-mgx5-jrhq-g7rg.json new file mode 100644 index 00000000000..68ee944e2ad --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-mgx5-jrhq-g7rg/GHSA-mgx5-jrhq-g7rg.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mgx5-jrhq-g7rg", + "modified": "2024-04-03T15:30:42Z", + "published": "2024-04-03T15:30:42Z", + "aliases": [ + "CVE-2024-26686" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfs/proc: do_task_stat: use sig->stats_lock to gather the threads/children stats\n\nlock_task_sighand() can trigger a hard lockup. If NR_CPUS threads call\ndo_task_stat() at the same time and the process has NR_THREADS, it will\nspin with irqs disabled O(NR_CPUS * NR_THREADS) time.\n\nChange do_task_stat() to use sig->stats_lock to gather the statistics\noutside of ->siglock protected section, in the likely case this code will\nrun lockless.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26686" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/27978243f165b44e342f28f449b91327944ea071" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7601df8031fd67310af891897ef6cc0df4209305" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cf4b8c39b9a0bd81c47afc7ef62914a62dd5ec4d" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T15:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-mq9q-ghqw-348q/GHSA-mq9q-ghqw-348q.json b/advisories/unreviewed/2024/04/GHSA-mq9q-ghqw-348q/GHSA-mq9q-ghqw-348q.json new file mode 100644 index 00000000000..fc92e6ef17e --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-mq9q-ghqw-348q/GHSA-mq9q-ghqw-348q.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mq9q-ghqw-348q", + "modified": "2024-04-03T15:30:43Z", + "published": "2024-04-03T15:30:43Z", + "aliases": [ + "CVE-2024-26709" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\npowerpc/iommu: Fix the missing iommu_group_put() during platform domain attach\n\nThe function spapr_tce_platform_iommu_attach_dev() is missing to call\niommu_group_put() when the domain is already set. This refcount leak\nshows up with BUG_ON() during DLPAR remove operation as:\n\n KernelBug: Kernel bug in state 'None': kernel BUG at arch/powerpc/platforms/pseries/iommu.c:100!\n Oops: Exception in kernel mode, sig: 5 [#1]\n LE PAGE_SIZE=64K MMU=Radix SMP NR_CPUS=8192 NUMA pSeries\n \n Hardware name: IBM,9080-HEX POWER10 (raw) 0x800200 0xf000006 of:IBM,FW1060.00 (NH1060_016) hv:phyp pSeries\n NIP: c0000000000ff4d4 LR: c0000000000ff4cc CTR: 0000000000000000\n REGS: c0000013aed5f840 TRAP: 0700 Tainted: G I (6.8.0-rc3-autotest-g99bd3cb0d12e)\n MSR: 8000000000029033 CR: 44002402 XER: 20040000\n CFAR: c000000000a0d170 IRQMASK: 0\n ...\n NIP iommu_reconfig_notifier+0x94/0x200\n LR iommu_reconfig_notifier+0x8c/0x200\n Call Trace:\n iommu_reconfig_notifier+0x8c/0x200 (unreliable)\n notifier_call_chain+0xb8/0x19c\n blocking_notifier_call_chain+0x64/0x98\n of_reconfig_notify+0x44/0xdc\n of_detach_node+0x78/0xb0\n ofdt_write.part.0+0x86c/0xbb8\n proc_reg_write+0xf4/0x150\n vfs_write+0xf8/0x488\n ksys_write+0x84/0x140\n system_call_exception+0x138/0x330\n system_call_vectored_common+0x15c/0x2ec\n\nThe patch adds the missing iommu_group_put() call.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26709" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0846dd77c8349ec92ca0079c9c71d130f34cb192" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c90fdea9cac9eb419fc266e75d625cb60c8f7f6c" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T15:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-mr94-wr92-4hf6/GHSA-mr94-wr92-4hf6.json b/advisories/unreviewed/2024/04/GHSA-mr94-wr92-4hf6/GHSA-mr94-wr92-4hf6.json new file mode 100644 index 00000000000..4031732a7bb --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-mr94-wr92-4hf6/GHSA-mr94-wr92-4hf6.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mr94-wr92-4hf6", + "modified": "2024-04-03T15:30:41Z", + "published": "2024-04-03T15:30:41Z", + "aliases": [ + "CVE-2024-25030" + ], + "details": "IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 281677.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25030" + }, + { + "type": "WEB", + "url": "https://https://exchange.xforce.ibmcloud.com/vulnerabilities/281677" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7145725" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T13:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-p46w-8mq5-8mgj/GHSA-p46w-8mq5-8mgj.json b/advisories/unreviewed/2024/04/GHSA-p46w-8mq5-8mgj/GHSA-p46w-8mq5-8mgj.json new file mode 100644 index 00000000000..b9fc60a7b16 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-p46w-8mq5-8mgj/GHSA-p46w-8mq5-8mgj.json @@ -0,0 +1,63 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p46w-8mq5-8mgj", + "modified": "2024-04-03T15:30:43Z", + "published": "2024-04-03T15:30:43Z", + "aliases": [ + "CVE-2024-26722" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: rt5645: Fix deadlock in rt5645_jack_detect_work()\n\nThere is a path in rt5645_jack_detect_work(), where rt5645->jd_mutex\nis left locked forever. That may lead to deadlock\nwhen rt5645_jack_detect_work() is called for the second time.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26722" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/050ad2ca0ac169dd9e552075d2c6af1bbb46534c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1f0d7792e9023e8658e901b7b76a555f6aa052ec" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3dd2d99e2352903d0e0b8769e6c9b8293c7454b2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/422d5243b9f780abd3d39da2b746e3915677b07d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4a98bc739d0753a5810ce5630943cd7614c7717e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6ef5d5b92f7117b324efaac72b3db27ae8bb3082" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d14b8e2005f36319df9412d42037416d64827f6b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ed5b8b735369b40d6c1f8ef3e62d369f74b4c491" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T15:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-p939-fx2c-j96p/GHSA-p939-fx2c-j96p.json b/advisories/unreviewed/2024/04/GHSA-p939-fx2c-j96p/GHSA-p939-fx2c-j96p.json new file mode 100644 index 00000000000..d02a5f656ad --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-p939-fx2c-j96p/GHSA-p939-fx2c-j96p.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p939-fx2c-j96p", + "modified": "2024-04-03T15:30:43Z", + "published": "2024-04-03T15:30:43Z", + "aliases": [ + "CVE-2024-26708" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: really cope with fastopen race\n\nFastopen and PM-trigger subflow shutdown can race, as reported by\nsyzkaller.\n\nIn my first attempt to close such race, I missed the fact that\nthe subflow status can change again before the subflow_state_change\ncallback is invoked.\n\nAddress the issue additionally copying with all the states directly\nreachable from TCP_FIN_WAIT1.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26708" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/337cebbd850f94147cee05252778f8f78b8c337f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4bfe217e075d04e63c092df9d40c608e598c2ef2" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e158fb9679d15a2317ec13b4f6301bd26265df2f" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T15:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-p9j3-r5pw-645f/GHSA-p9j3-r5pw-645f.json b/advisories/unreviewed/2024/04/GHSA-p9j3-r5pw-645f/GHSA-p9j3-r5pw-645f.json new file mode 100644 index 00000000000..573b744af7e --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-p9j3-r5pw-645f/GHSA-p9j3-r5pw-645f.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p9j3-r5pw-645f", + "modified": "2024-04-03T15:30:42Z", + "published": "2024-04-03T15:30:42Z", + "aliases": [ + "CVE-2024-26691" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: arm64: Fix circular locking dependency\n\nThe rule inside kvm enforces that the vcpu->mutex is taken *inside*\nkvm->lock. The rule is violated by the pkvm_create_hyp_vm() which acquires\nthe kvm->lock while already holding the vcpu->mutex lock from\nkvm_vcpu_ioctl(). Avoid the circular locking dependency altogether by\nprotecting the hyp vm handle with the config_lock, much like we already\ndo for other forms of VM-scoped data.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26691" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/10c02aad111df02088d1a81792a709f6a7eca6cc" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3ab1c40a1e915e350d9181a4603af393141970cc" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3d16cebf01127f459dcfeb79ed77bd68b124c228" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T15:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-pcg2-4fqf-rwm2/GHSA-pcg2-4fqf-rwm2.json b/advisories/unreviewed/2024/04/GHSA-pcg2-4fqf-rwm2/GHSA-pcg2-4fqf-rwm2.json new file mode 100644 index 00000000000..7ea038d87c1 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-pcg2-4fqf-rwm2/GHSA-pcg2-4fqf-rwm2.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pcg2-4fqf-rwm2", + "modified": "2024-04-03T15:30:41Z", + "published": "2024-04-03T15:30:41Z", + "aliases": [ + "CVE-2024-27254" + ], + "details": "IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, and 11.5 federated server is vulnerable to denial of service with a specially crafted query under certain conditions. IBM X-Force ID: 283813.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27254" + }, + { + "type": "WEB", + "url": "https://https://exchange.xforce.ibmcloud.com/vulnerabilities/283813" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7145727" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T13:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-pgc5-vrj2-c9w5/GHSA-pgc5-vrj2-c9w5.json b/advisories/unreviewed/2024/04/GHSA-pgc5-vrj2-c9w5/GHSA-pgc5-vrj2-c9w5.json index 797d2d36d9d..9cdfb8613b1 100644 --- a/advisories/unreviewed/2024/04/GHSA-pgc5-vrj2-c9w5/GHSA-pgc5-vrj2-c9w5.json +++ b/advisories/unreviewed/2024/04/GHSA-pgc5-vrj2-c9w5/GHSA-pgc5-vrj2-c9w5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pgc5-vrj2-c9w5", - "modified": "2024-04-01T09:30:31Z", + "modified": "2024-04-03T15:30:41Z", "published": "2024-04-01T09:30:31Z", "aliases": [ "CVE-2024-26654" @@ -21,6 +21,22 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/051e0840ffa8ab25554d6b14b62c9ab9e4901457" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3c907bf56905de7d27b329afaf59c2fb35d17b04" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/61d4787692c1fccdc268ffa7a891f9c149f50901" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9d66ae0e7bb78b54e1e0525456c6b54e1d132046" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e955e8a7f38a856fc6534ba4e6bffd4d5cc80ac3" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/04/GHSA-pgrq-g235-jm37/GHSA-pgrq-g235-jm37.json b/advisories/unreviewed/2024/04/GHSA-pgrq-g235-jm37/GHSA-pgrq-g235-jm37.json new file mode 100644 index 00000000000..16f982e6db8 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-pgrq-g235-jm37/GHSA-pgrq-g235-jm37.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pgrq-g235-jm37", + "modified": "2024-04-03T15:30:41Z", + "published": "2024-04-03T15:30:41Z", + "aliases": [ + "CVE-2024-30569" + ], + "details": "An information leak in currentsetting.htm of Netgear R6850 v1.1.0.88 allows attackers to obtain sensitive information without any authentication required.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30569" + }, + { + "type": "WEB", + "url": "https://github.com/funny-mud-peee/IoT-vuls/blob/main/netgear%20R6850/Info%20Leak%20in%20Netgear-R6850%EF%BC%88currentsetting.htm%EF%BC%89.md" + }, + { + "type": "WEB", + "url": "https://www.netgear.com/about/security" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T13:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-qfmr-mqxf-7859/GHSA-qfmr-mqxf-7859.json b/advisories/unreviewed/2024/04/GHSA-qfmr-mqxf-7859/GHSA-qfmr-mqxf-7859.json new file mode 100644 index 00000000000..fc986fe7a5f --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-qfmr-mqxf-7859/GHSA-qfmr-mqxf-7859.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qfmr-mqxf-7859", + "modified": "2024-04-03T15:30:41Z", + "published": "2024-04-03T15:30:41Z", + "aliases": [ + "CVE-2024-22360" + ], + "details": "IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to a denial of service with a specially crafted query on certain columnar tables. IBM X-Force ID: 280905.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22360" + }, + { + "type": "WEB", + "url": "https://https://exchange.xforce.ibmcloud.com/vulnerabilities/280905" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7145730" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T13:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-qpw5-gvf2-cq42/GHSA-qpw5-gvf2-cq42.json b/advisories/unreviewed/2024/04/GHSA-qpw5-gvf2-cq42/GHSA-qpw5-gvf2-cq42.json index 94fd6a2f896..314616b3aa3 100644 --- a/advisories/unreviewed/2024/04/GHSA-qpw5-gvf2-cq42/GHSA-qpw5-gvf2-cq42.json +++ b/advisories/unreviewed/2024/04/GHSA-qpw5-gvf2-cq42/GHSA-qpw5-gvf2-cq42.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qpw5-gvf2-cq42", - "modified": "2024-04-01T15:30:29Z", + "modified": "2024-04-03T15:30:41Z", "published": "2024-04-01T15:30:29Z", "aliases": [ "CVE-2024-26655" @@ -18,9 +18,17 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26655" }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0200dd7ed2335469955d7e69cc1a6fa7df1f3847" + }, { "type": "WEB", "url": "https://git.kernel.org/stable/c/5b4cdd9c5676559b8a7c944ac5269b914b8c0bb8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a88649b49523e8cbe95254440d803e38c19d2341" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/04/GHSA-qrpr-37g9-38rr/GHSA-qrpr-37g9-38rr.json b/advisories/unreviewed/2024/04/GHSA-qrpr-37g9-38rr/GHSA-qrpr-37g9-38rr.json new file mode 100644 index 00000000000..f82f72151a4 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-qrpr-37g9-38rr/GHSA-qrpr-37g9-38rr.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qrpr-37g9-38rr", + "modified": "2024-04-03T15:30:41Z", + "published": "2024-04-03T15:30:41Z", + "aliases": [ + "CVE-2024-24707" + ], + "details": "Improper Control of Generation of Code ('Code Injection') vulnerability in Cwicly Builder, SL. Cwicly allows Code Injection.This issue affects Cwicly: from n/a through 1.4.0.2.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24707" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/vulnerability/cwicly/wordpress-cwicly-plugin-1-4-0-2-remote-code-execution-rce-vulnerability?_s_id=cve" + }, + { + "type": "WEB", + "url": "https://snicco.io/vulnerability-disclosure/cwicly/remote-code-execution-cwicly-1-4-0-2?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T13:16:01Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-r75p-pc87-v9rp/GHSA-r75p-pc87-v9rp.json b/advisories/unreviewed/2024/04/GHSA-r75p-pc87-v9rp/GHSA-r75p-pc87-v9rp.json new file mode 100644 index 00000000000..39059d161d5 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-r75p-pc87-v9rp/GHSA-r75p-pc87-v9rp.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r75p-pc87-v9rp", + "modified": "2024-04-03T15:30:41Z", + "published": "2024-04-03T15:30:41Z", + "aliases": [ + "CVE-2023-52296" + ], + "details": "IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to denial of service when querying a specific UDF built-in function concurrently. IBM X-Force ID: 278547.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52296" + }, + { + "type": "WEB", + "url": "https://https://exchange.xforce.ibmcloud.com/vulnerabilities/278547" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7145722" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T13:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-rcfj-rrgg-6fvh/GHSA-rcfj-rrgg-6fvh.json b/advisories/unreviewed/2024/04/GHSA-rcfj-rrgg-6fvh/GHSA-rcfj-rrgg-6fvh.json new file mode 100644 index 00000000000..86b4f153030 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-rcfj-rrgg-6fvh/GHSA-rcfj-rrgg-6fvh.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rcfj-rrgg-6fvh", + "modified": "2024-04-03T15:30:41Z", + "published": "2024-04-03T15:30:41Z", + "aliases": [ + "CVE-2023-38729" + ], + "details": "IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server)10.5, 11.1, and 11.5 is vulnerable to sensitive information disclosure when using ADMIN_CMD with IMPORT or EXPORT. IBM X-Force ID: 262259.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38729" + }, + { + "type": "WEB", + "url": "https://https://exchange.xforce.ibmcloud.com/vulnerabilities/262259" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7145721" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T13:16:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-rvjh-mwxw-g897/GHSA-rvjh-mwxw-g897.json b/advisories/unreviewed/2024/04/GHSA-rvjh-mwxw-g897/GHSA-rvjh-mwxw-g897.json new file mode 100644 index 00000000000..f390e2816e7 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-rvjh-mwxw-g897/GHSA-rvjh-mwxw-g897.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rvjh-mwxw-g897", + "modified": "2024-04-03T15:30:43Z", + "published": "2024-04-03T15:30:43Z", + "aliases": [ + "CVE-2024-26702" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\niio: magnetometer: rm3100: add boundary check for the value read from RM3100_REG_TMRC\n\nRecently, we encounter kernel crash in function rm3100_common_probe\ncaused by out of bound access of array rm3100_samp_rates (because of\nunderlying hardware failures). Add boundary check to prevent out of\nbound access.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26702" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/176256ff8abff29335ecff905a09fb49e8dcf513" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1d8c67e94e9e977603473a543d4f322cf2c4aa01" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/36a49290d7e6d554020057a409747a092b1d3b56" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/57d05dbbcd0b3dc0c252103b43012eef5d6430d1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7200170e88e3ec54d9e9c63f07514c3cead11481" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/792595bab4925aa06532a14dd256db523eb4fa5e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8d5838a473e8e6d812257c69745f5920e4924a60" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T15:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-vfrw-8352-324f/GHSA-vfrw-8352-324f.json b/advisories/unreviewed/2024/04/GHSA-vfrw-8352-324f/GHSA-vfrw-8352-324f.json new file mode 100644 index 00000000000..dfc01edf6d5 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-vfrw-8352-324f/GHSA-vfrw-8352-324f.json @@ -0,0 +1,47 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vfrw-8352-324f", + "modified": "2024-04-03T15:30:43Z", + "published": "2024-04-03T15:30:43Z", + "aliases": [ + "CVE-2024-26714" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ninterconnect: qcom: sc8180x: Mark CO0 BCM keepalive\n\nThe CO0 BCM needs to be up at all times, otherwise some hardware (like\nthe UFS controller) loses its connection to the rest of the SoC,\nresulting in a hang of the platform, accompanied by a spectacular\nlogspam.\n\nMark it as keepalive to prevent such cases.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26714" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6616d3c4f8284a7b3ef978c916566bd240cea1c7" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7a3a70dd08e4b7dffc2f86f2c68fc3812804b9d0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/85e985a4f46e462a37f1875cb74ed380e7c0c2e0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d8e36ff40cf9dadb135f3a97341c02c9a7afcc43" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T15:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-vhpg-m2r9-345p/GHSA-vhpg-m2r9-345p.json b/advisories/unreviewed/2024/04/GHSA-vhpg-m2r9-345p/GHSA-vhpg-m2r9-345p.json new file mode 100644 index 00000000000..7604b96319c --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-vhpg-m2r9-345p/GHSA-vhpg-m2r9-345p.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vhpg-m2r9-345p", + "modified": "2024-04-03T15:30:42Z", + "published": "2024-04-03T15:30:42Z", + "aliases": [ + "CVE-2024-26694" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: iwlwifi: fix double-free bug\n\nThe storage for the TLV PC register data wasn't done like all\nthe other storage in the drv->fw area, which is cleared at the\nend of deallocation. Therefore, the freeing must also be done\ndifferently, explicitly NULL'ing it out after the free, since\notherwise there's a nasty double-free bug here if a file fails\nto load after this has been parsed, and we get another free\nlater (e.g. because no other file exists.) Fix that by adding\nthe missing NULL assignment.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26694" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/353d321f63f7dbfc9ef58498cc732c9fe886a596" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ab9d4bb9a1892439b3123fc52b19e32b9cdf80ad" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d24eb9a27bea8fe5237fa71be274391d9d51eff2" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T15:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-vjhf-6xfr-5p9g/GHSA-vjhf-6xfr-5p9g.json b/advisories/unreviewed/2024/04/GHSA-vjhf-6xfr-5p9g/GHSA-vjhf-6xfr-5p9g.json new file mode 100644 index 00000000000..6071b72217e --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-vjhf-6xfr-5p9g/GHSA-vjhf-6xfr-5p9g.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vjhf-6xfr-5p9g", + "modified": "2024-04-03T15:30:42Z", + "published": "2024-04-03T15:30:42Z", + "aliases": [ + "CVE-2024-31420" + ], + "details": "A NULL pointer dereference flaw was found in KubeVirt. This flaw allows an attacker who has access to a virtual machine guest on a node with DownwardMetrics enabled to cause a denial of service by issuing a high number of calls to vm-dump-metrics --virtio.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31420" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-31420" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2272951" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T14:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-w4xh-qvw9-wq8w/GHSA-w4xh-qvw9-wq8w.json b/advisories/unreviewed/2024/04/GHSA-w4xh-qvw9-wq8w/GHSA-w4xh-qvw9-wq8w.json new file mode 100644 index 00000000000..3ace80c3c9a --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-w4xh-qvw9-wq8w/GHSA-w4xh-qvw9-wq8w.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w4xh-qvw9-wq8w", + "modified": "2024-04-03T15:30:41Z", + "published": "2024-04-03T15:30:41Z", + "aliases": [ + "CVE-2024-21870" + ], + "details": "A file write vulnerability exists in the OAS Engine Tags Configuration functionality of Open Automation Software OAS Platform V19.00.0057. A specially crafted series of network requests can lead to arbitrary file creation or overwrite. An attacker can send a sequence of requests to trigger this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21870" + }, + { + "type": "WEB", + "url": "https://talosintelligence.com/vulnerability_reports/TALOS-2024-1950" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-1950" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-73" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T14:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-w9mj-34hr-82rj/GHSA-w9mj-34hr-82rj.json b/advisories/unreviewed/2024/04/GHSA-w9mj-34hr-82rj/GHSA-w9mj-34hr-82rj.json new file mode 100644 index 00000000000..9ab90124291 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-w9mj-34hr-82rj/GHSA-w9mj-34hr-82rj.json @@ -0,0 +1,55 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w9mj-34hr-82rj", + "modified": "2024-04-03T15:30:44Z", + "published": "2024-04-03T15:30:44Z", + "aliases": [ + "CVE-2024-26727" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: do not ASSERT() if the newly created subvolume already got read\n\n[BUG]\nThere is a syzbot crash, triggered by the ASSERT() during subvolume\ncreation:\n\n assertion failed: !anon_dev, in fs/btrfs/disk-io.c:1319\n ------------[ cut here ]------------\n kernel BUG at fs/btrfs/disk-io.c:1319!\n invalid opcode: 0000 [#1] PREEMPT SMP KASAN\n RIP: 0010:btrfs_get_root_ref.part.0+0x9aa/0xa60\n \n btrfs_get_new_fs_root+0xd3/0xf0\n create_subvol+0xd02/0x1650\n btrfs_mksubvol+0xe95/0x12b0\n __btrfs_ioctl_snap_create+0x2f9/0x4f0\n btrfs_ioctl_snap_create+0x16b/0x200\n btrfs_ioctl+0x35f0/0x5cf0\n __x64_sys_ioctl+0x19d/0x210\n do_syscall_64+0x3f/0xe0\n entry_SYSCALL_64_after_hwframe+0x63/0x6b\n ---[ end trace 0000000000000000 ]---\n\n[CAUSE]\nDuring create_subvol(), after inserting root item for the newly created\nsubvolume, we would trigger btrfs_get_new_fs_root() to get the\nbtrfs_root of that subvolume.\n\nThe idea here is, we have preallocated an anonymous device number for\nthe subvolume, thus we can assign it to the new subvolume.\n\nBut there is really nothing preventing things like backref walk to read\nthe new subvolume.\nIf that happens before we call btrfs_get_new_fs_root(), the subvolume\nwould be read out, with a new anonymous device number assigned already.\n\nIn that case, we would trigger ASSERT(), as we really expect no one to\nread out that subvolume (which is not yet accessible from the fs).\nBut things like backref walk is still possible to trigger the read on\nthe subvolume.\n\nThus our assumption on the ASSERT() is not correct in the first place.\n\n[FIX]\nFix it by removing the ASSERT(), and just free the @anon_dev, reset it\nto 0, and continue.\n\nIf the subvolume tree is read out by something else, it should have\nalready get a new anon_dev assigned thus we only need to free the\npreallocated one.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26727" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3f5d47eb163bceb1b9e613c9003bae5fefc0046f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5a172344bfdabb46458e03708735d7b1a918c468" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/66b317a2fc45b2ef66527ee3f8fa08fb5beab88d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/833775656d447c545133a744a0ed1e189ce61430" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e03ee2fe873eb68c1f9ba5112fee70303ebf9dfb" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e31546b0f34af21738c4ceac47d662c00ee6382f" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T15:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-wcqp-hrg4-jgjg/GHSA-wcqp-hrg4-jgjg.json b/advisories/unreviewed/2024/04/GHSA-wcqp-hrg4-jgjg/GHSA-wcqp-hrg4-jgjg.json new file mode 100644 index 00000000000..dc98050bfc7 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-wcqp-hrg4-jgjg/GHSA-wcqp-hrg4-jgjg.json @@ -0,0 +1,63 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wcqp-hrg4-jgjg", + "modified": "2024-04-03T15:30:43Z", + "published": "2024-04-03T15:30:43Z", + "aliases": [ + "CVE-2024-26720" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/writeback: fix possible divide-by-zero in wb_dirty_limits(), again\n\n(struct dirty_throttle_control *)->thresh is an unsigned long, but is\npassed as the u32 divisor argument to div_u64(). On architectures where\nunsigned long is 64 bytes, the argument will be implicitly truncated.\n\nUse div64_u64() instead of div_u64() so that the value used in the \"is\nthis a safe division\" check is the same as the divisor.\n\nAlso, remove redundant cast of the numerator to u64, as that should happen\nimplicitly.\n\nThis would be difficult to exploit in memcg domain, given the ratio-based\narithmetic domain_drity_limits() uses, but is much easier in global\nwriteback domain with a BDI_CAP_STRICTLIMIT-backing device, using e.g. \nvm.dirty_bytes=(1<<32)*PAGE_SIZE so that dtc->thresh == (1<<32)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26720" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/16b1025eaa8fc223ab4273ece20d1c3a4211a95d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1f12e4b3284d6c863f272eb2de0d4248ed211cf4" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5099871b370335809c0fd1abad74d9c7c205d43f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/65977bed167a92e87085e757fffa5798f7314c9f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/81e7d2530d458548b90a5c5e76b77ad5e5d1c0df" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9319b647902cbd5cc884ac08a8a6d54ce111fc78" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c593d26fb5d577ef31b6e49a31e08ae3ebc1bc1e" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ec18ec230301583395576915d274b407743d8f6c" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T15:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-wfcg-p9mh-53w7/GHSA-wfcg-p9mh-53w7.json b/advisories/unreviewed/2024/04/GHSA-wfcg-p9mh-53w7/GHSA-wfcg-p9mh-53w7.json new file mode 100644 index 00000000000..5f922e3e76c --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-wfcg-p9mh-53w7/GHSA-wfcg-p9mh-53w7.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wfcg-p9mh-53w7", + "modified": "2024-04-03T15:30:42Z", + "published": "2024-04-03T15:30:42Z", + "aliases": [ + "CVE-2024-26688" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nfs,hugetlb: fix NULL pointer dereference in hugetlbs_fill_super\n\nWhen configuring a hugetlb filesystem via the fsconfig() syscall, there is\na possible NULL dereference in hugetlbfs_fill_super() caused by assigning\nNULL to ctx->hstate in hugetlbfs_parse_param() when the requested pagesize\nis non valid.\n\nE.g: Taking the following steps:\n\n fd = fsopen(\"hugetlbfs\", FSOPEN_CLOEXEC);\n fsconfig(fd, FSCONFIG_SET_STRING, \"pagesize\", \"1024\", 0);\n fsconfig(fd, FSCONFIG_CMD_CREATE, NULL, NULL, 0);\n\nGiven that the requested \"pagesize\" is invalid, ctxt->hstate will be replaced\nwith NULL, losing its previous value, and we will print an error:\n\n ...\n ...\n case Opt_pagesize:\n ps = memparse(param->string, &rest);\n ctx->hstate = h;\n if (!ctx->hstate) {\n pr_err(\"Unsupported page size %lu MB\\n\", ps / SZ_1M);\n return -EINVAL;\n }\n return 0;\n ...\n ...\n\nThis is a problem because later on, we will dereference ctxt->hstate in\nhugetlbfs_fill_super()\n\n ...\n ...\n sb->s_blocksize = huge_page_size(ctx->hstate);\n ...\n ...\n\nCausing below Oops.\n\nFix this by replacing cxt->hstate value only when then pagesize is known\nto be valid.\n\n kernel: hugetlbfs: Unsupported page size 0 MB\n kernel: BUG: kernel NULL pointer dereference, address: 0000000000000028\n kernel: #PF: supervisor read access in kernel mode\n kernel: #PF: error_code(0x0000) - not-present page\n kernel: PGD 800000010f66c067 P4D 800000010f66c067 PUD 1b22f8067 PMD 0\n kernel: Oops: 0000 [#1] PREEMPT SMP PTI\n kernel: CPU: 4 PID: 5659 Comm: syscall Tainted: G E 6.8.0-rc2-default+ #22 5a47c3fef76212addcc6eb71344aabc35190ae8f\n kernel: Hardware name: Intel Corp. GROVEPORT/GROVEPORT, BIOS GVPRCRB1.86B.0016.D04.1705030402 05/03/2017\n kernel: RIP: 0010:hugetlbfs_fill_super+0xb4/0x1a0\n kernel: Code: 48 8b 3b e8 3e c6 ed ff 48 85 c0 48 89 45 20 0f 84 d6 00 00 00 48 b8 ff ff ff ff ff ff ff 7f 4c 89 e7 49 89 44 24 20 48 8b 03 <8b> 48 28 b8 00 10 00 00 48 d3 e0 49 89 44 24 18 48 8b 03 8b 40 28\n kernel: RSP: 0018:ffffbe9960fcbd48 EFLAGS: 00010246\n kernel: RAX: 0000000000000000 RBX: ffff9af5272ae780 RCX: 0000000000372004\n kernel: RDX: ffffffffffffffff RSI: ffffffffffffffff RDI: ffff9af555e9b000\n kernel: RBP: ffff9af52ee66b00 R08: 0000000000000040 R09: 0000000000370004\n kernel: R10: ffffbe9960fcbd48 R11: 0000000000000040 R12: ffff9af555e9b000\n kernel: R13: ffffffffa66b86c0 R14: ffff9af507d2f400 R15: ffff9af507d2f400\n kernel: FS: 00007ffbc0ba4740(0000) GS:ffff9b0bd7000000(0000) knlGS:0000000000000000\n kernel: CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n kernel: CR2: 0000000000000028 CR3: 00000001b1ee0000 CR4: 00000000001506f0\n kernel: Call Trace:\n kernel: \n kernel: ? __die_body+0x1a/0x60\n kernel: ? page_fault_oops+0x16f/0x4a0\n kernel: ? search_bpf_extables+0x65/0x70\n kernel: ? fixup_exception+0x22/0x310\n kernel: ? exc_page_fault+0x69/0x150\n kernel: ? asm_exc_page_fault+0x22/0x30\n kernel: ? __pfx_hugetlbfs_fill_super+0x10/0x10\n kernel: ? hugetlbfs_fill_super+0xb4/0x1a0\n kernel: ? hugetlbfs_fill_super+0x28/0x1a0\n kernel: ? __pfx_hugetlbfs_fill_super+0x10/0x10\n kernel: vfs_get_super+0x40/0xa0\n kernel: ? __pfx_bpf_lsm_capable+0x10/0x10\n kernel: vfs_get_tree+0x25/0xd0\n kernel: vfs_cmd_create+0x64/0xe0\n kernel: __x64_sys_fsconfig+0x395/0x410\n kernel: do_syscall_64+0x80/0x160\n kernel: ? syscall_exit_to_user_mode+0x82/0x240\n kernel: ? do_syscall_64+0x8d/0x160\n kernel: ? syscall_exit_to_user_mode+0x82/0x240\n kernel: ? do_syscall_64+0x8d/0x160\n kernel: ? exc_page_fault+0x69/0x150\n kernel: entry_SYSCALL_64_after_hwframe+0x6e/0x76\n kernel: RIP: 0033:0x7ffbc0cb87c9\n kernel: Code: 00 90 90 90 90 90 90 90 90 90 90 90 90 90 90 66 90 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 8b 0d 97 96 0d 00 f7 d8 64 89 01 48\n kernel: RSP: 002b:00007ffc29d2f388 EFLAGS: 00000206 ORIG_RAX: 00000000000001af\n kernel: RAX: fffffffffff\n---truncated---", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26688" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/13c5a9fb07105557a1fa9efdb4f23d7ef30b7274" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1dde8ef4b7a749ae1bc73617c91775631d167557" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/22850c9950a4e43a67299755d11498f3292d02ff" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2e2c07104b4904aed1389a59b25799b95a85b5b9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/79d72c68c58784a3e1cd2378669d51bfd0cb7498" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/80d852299987a8037be145a94f41874228f1a773" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ec78418801ef7b0c22cd6a30145ec480dd48db39" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T15:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-wh9w-6vgj-372j/GHSA-wh9w-6vgj-372j.json b/advisories/unreviewed/2024/04/GHSA-wh9w-6vgj-372j/GHSA-wh9w-6vgj-372j.json new file mode 100644 index 00000000000..36babc5a290 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-wh9w-6vgj-372j/GHSA-wh9w-6vgj-372j.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wh9w-6vgj-372j", + "modified": "2024-04-03T15:30:43Z", + "published": "2024-04-03T15:30:43Z", + "aliases": [ + "CVE-2024-26719" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnouveau: offload fence uevents work to workqueue\n\nThis should break the deadlock between the fctx lock and the irq lock.\n\nThis offloads the processing off the work from the irq into a workqueue.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26719" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/39126abc5e20611579602f03b66627d7cd1422f0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/985d053f7633d8b539ab1531738d538efac678a9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/cc0037fa592d56e4abb9c7d1c52c4d2dc25cd906" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T15:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-wppr-m5h5-pr8g/GHSA-wppr-m5h5-pr8g.json b/advisories/unreviewed/2024/04/GHSA-wppr-m5h5-pr8g/GHSA-wppr-m5h5-pr8g.json new file mode 100644 index 00000000000..c067623c7bf --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-wppr-m5h5-pr8g/GHSA-wppr-m5h5-pr8g.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wppr-m5h5-pr8g", + "modified": "2024-04-03T15:30:41Z", + "published": "2024-04-03T15:30:41Z", + "aliases": [ + "CVE-2024-30570" + ], + "details": "An information leak in debuginfo.htm of Netgear R6850 v1.1.0.88 allows attackers to obtain sensitive information without any authentication required.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30570" + }, + { + "type": "WEB", + "url": "https://github.com/funny-mud-peee/IoT-vuls/blob/main/netgear%20R6850/Info%20Leak%20in%20Netgear-R6850%EF%BC%88debuginfo.htm%EF%BC%89.md" + }, + { + "type": "WEB", + "url": "https://www.netgear.com/about/security" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T13:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-wr7h-84qc-v963/GHSA-wr7h-84qc-v963.json b/advisories/unreviewed/2024/04/GHSA-wr7h-84qc-v963/GHSA-wr7h-84qc-v963.json new file mode 100644 index 00000000000..b5bd9ff625f --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-wr7h-84qc-v963/GHSA-wr7h-84qc-v963.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wr7h-84qc-v963", + "modified": "2024-04-03T15:30:43Z", + "published": "2024-04-03T15:30:43Z", + "aliases": [ + "CVE-2024-26721" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/i915/dsc: Fix the macro that calculates DSCC_/DSCA_ PPS reg address\n\nCommit bd077259d0a9 (\"drm/i915/vdsc: Add function to read any PPS\nregister\") defines a new macro to calculate the DSC PPS register\naddresses with PPS number as an input. This macro correctly calculates\nthe addresses till PPS 11 since the addresses increment by 4. So in that\ncase the following macro works correctly to give correct register\naddress:\n\n_MMIO(_DSCA_PPS_0 + (pps) * 4)\n\nHowever after PPS 11, the register address for PPS 12 increments by 12\nbecause of RC Buffer memory allocation in between. Because of this\ndiscontinuity in the address space, the macro calculates wrong addresses\nfor PPS 12 - 16 resulting into incorrect DSC PPS parameter value\nread/writes causing DSC corruption.\n\nThis fixes it by correcting this macro to add the offset of 12 for PPS\n>=12.\n\nv3: Add correct paranthesis for pps argument (Jani Nikula)\n\n(cherry picked from commit 6074be620c31dc2ae11af96a1a5ea95580976fb5)", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26721" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/962ac2dce56bb3aad1f82a4bbe3ada57a020287c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/ff5999fb03f467e1e7159f0ddb199c787f7512b9" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T15:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-xf3h-rpgf-fmvp/GHSA-xf3h-rpgf-fmvp.json b/advisories/unreviewed/2024/04/GHSA-xf3h-rpgf-fmvp/GHSA-xf3h-rpgf-fmvp.json new file mode 100644 index 00000000000..8650a062560 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-xf3h-rpgf-fmvp/GHSA-xf3h-rpgf-fmvp.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xf3h-rpgf-fmvp", + "modified": "2024-04-03T15:30:43Z", + "published": "2024-04-03T15:30:43Z", + "aliases": [ + "CVE-2024-26711" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\niio: adc: ad4130: zero-initialize clock init data\n\nThe clk_init_data struct does not have all its members\ninitialized, causing issues when trying to expose the internal\nclock on the CLK pin.\n\nFix this by zero-initializing the clk_init_data struct.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26711" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/02876e2df02f8b17a593d77a0a7879a8109b27e1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/0e0dab37750926d4fb0144edb1c1ea0612fea273" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a22b0a2be69a36511cb5b37d948b651ddf7debf3" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T15:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-xg7r-7865-v6c7/GHSA-xg7r-7865-v6c7.json b/advisories/unreviewed/2024/04/GHSA-xg7r-7865-v6c7/GHSA-xg7r-7865-v6c7.json new file mode 100644 index 00000000000..04a3d3ba15a --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-xg7r-7865-v6c7/GHSA-xg7r-7865-v6c7.json @@ -0,0 +1,63 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xg7r-7865-v6c7", + "modified": "2024-04-03T15:30:42Z", + "published": "2024-04-03T15:30:42Z", + "aliases": [ + "CVE-2024-26697" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: fix data corruption in dsync block recovery for small block sizes\n\nThe helper function nilfs_recovery_copy_block() of\nnilfs_recovery_dsync_blocks(), which recovers data from logs created by\ndata sync writes during a mount after an unclean shutdown, incorrectly\ncalculates the on-page offset when copying repair data to the file's page\ncache. In environments where the block size is smaller than the page\nsize, this flaw can cause data corruption and leak uninitialized memory\nbytes during the recovery process.\n\nFix these issues by correcting this byte offset calculation on the page.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26697" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/120f7fa2008e3bd8b7680b4ab5df942decf60fd5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2000016bab499074e6248ea85aeea7dd762355d9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2e1480538ef60bfee5473dfe02b1ecbaf1a4aa0d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/364a66be2abdcd4fd426ffa44d9b8f40aafb3caa" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5278c3eb6bf5896417572b52adb6be9d26e92f65" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/67b8bcbaed4777871bb0dcc888fb02a614a98ab1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/9c9c68d64fd3284f7097ed6ae057c8441f39fcd3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a6efe6dbaaf504f5b3f8a5c3f711fe54e7dda0ba" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T15:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-xq4m-hfgr-r2x5/GHSA-xq4m-hfgr-r2x5.json b/advisories/unreviewed/2024/04/GHSA-xq4m-hfgr-r2x5/GHSA-xq4m-hfgr-r2x5.json new file mode 100644 index 00000000000..8b839fc7f48 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-xq4m-hfgr-r2x5/GHSA-xq4m-hfgr-r2x5.json @@ -0,0 +1,63 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xq4m-hfgr-r2x5", + "modified": "2024-04-03T15:30:42Z", + "published": "2024-04-03T15:30:42Z", + "aliases": [ + "CVE-2024-26685" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnilfs2: fix potential bug in end_buffer_async_write\n\nAccording to a syzbot report, end_buffer_async_write(), which handles the\ncompletion of block device writes, may detect abnormal condition of the\nbuffer async_write flag and cause a BUG_ON failure when using nilfs2.\n\nNilfs2 itself does not use end_buffer_async_write(). But, the async_write\nflag is now used as a marker by commit 7f42ec394156 (\"nilfs2: fix issue\nwith race condition of competition between segments for dirty blocks\") as\na means of resolving double list insertion of dirty blocks in\nnilfs_lookup_dirty_data_buffers() and nilfs_lookup_node_buffers() and the\nresulting crash.\n\nThis modification is safe as long as it is used for file data and b-tree\nnode blocks where the page caches are independent. However, it was\nirrelevant and redundant to also introduce async_write for segment summary\nand super root blocks that share buffers with the backing device. This\nled to the possibility that the BUG_ON check in end_buffer_async_write\nwould fail as described above, if independent writebacks of the backing\ndevice occurred in parallel.\n\nThe use of async_write for segment summary buffers has already been\nremoved in a previous change.\n\nFix this issue by removing the manipulation of the async_write flag for\nthe remaining super root block buffer.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26685" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2c3bdba00283a6c7a5b19481a59a730f46063803" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/5bc09b397cbf1221f8a8aacb1152650c9195b02b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/626daab3811b772086aef1bf8eed3ffe6f523eff" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/6589f0f72f8edd1fa11adce4eedbd3615f2e78ab" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/8fa90634ec3e9cc50f42dd605eec60f2d146ced8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/c4a09fdac625e64abe478dcf88bfa20406616928" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/d31c8721e816eff5ca6573cc487754f357c093cd" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/f3e4963566f58726d3265a727116a42b591f6596" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T15:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-xrr8-23jx-fjvc/GHSA-xrr8-23jx-fjvc.json b/advisories/unreviewed/2024/04/GHSA-xrr8-23jx-fjvc/GHSA-xrr8-23jx-fjvc.json new file mode 100644 index 00000000000..271b974608a --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-xrr8-23jx-fjvc/GHSA-xrr8-23jx-fjvc.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xrr8-23jx-fjvc", + "modified": "2024-04-03T15:30:41Z", + "published": "2024-04-03T15:30:41Z", + "aliases": [ + "CVE-2024-31419" + ], + "details": "An information disclosure flaw was found in OpenShift Virtualization. The DownwardMetrics feature was introduced to expose host metrics to virtual machine guests and is enabled by default. This issue could expose limited host metrics of a node to any guest in any namespace without being explicitly enabled by an administrator.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-31419" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2024-31419" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2272948" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-497" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T14:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-xv6f-4q9w-8q96/GHSA-xv6f-4q9w-8q96.json b/advisories/unreviewed/2024/04/GHSA-xv6f-4q9w-8q96/GHSA-xv6f-4q9w-8q96.json new file mode 100644 index 00000000000..89b160cbb59 --- /dev/null +++ b/advisories/unreviewed/2024/04/GHSA-xv6f-4q9w-8q96/GHSA-xv6f-4q9w-8q96.json @@ -0,0 +1,43 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xv6f-4q9w-8q96", + "modified": "2024-04-03T15:30:43Z", + "published": "2024-04-03T15:30:43Z", + "aliases": [ + "CVE-2024-26705" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nparisc: BTLB: Fix crash when setting up BTLB at CPU bringup\n\nWhen using hotplug and bringing up a 32-bit CPU, ask the firmware about the\nBTLB information to set up the static (block) TLB entries.\n\nFor that write access to the static btlb_info struct is needed, but\nsince it is marked __ro_after_init the kernel segfaults with missing\nwrite permissions.\n\nFix the crash by dropping the __ro_after_init annotation.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26705" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/54944f45470af5965fb9c28cf962ec30f38a8f5b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/913b9d443a0180cf0de3548f1ab3149378998486" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/aa52be55276614d33f22fbe7da36c40d6432d10b" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-04-03T15:15:53Z" + } +} \ No newline at end of file